Trusted communication method, device, equipment, medium and system based on SIM (Subscriber Identity Module) card
By combining SIM card with certificate chain technology, using SIM card to store user identity information and keys, identity authentication and communication encryption are realized, and the existing trusted communication technology is solved, and a stable, easy-to-use and intuitive trusted communication method is provided.
Patent Information
- Application Number
- CN202510176400.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-27
AI Technical Summary
The existing trusted communication technologies have high complexity and poor compatibility, resulting in limited application scope.
By combining the user identity module (SIM card) with the certificate chain technology, the SIM card stores user identity information and keys, and realizes identity authentication and communication encryption through the certificate chain technology, providing a trusted communication method based on the SIM card.
A stable, easy to use and intuitive trusted communication method is realized, effectively preventing identity impersonation, improving user experience, and simplifying the identity authentication process.
Smart Images

Figure CN120050627A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of mobile communication technologies, and in particular, to a trusted communication method, apparatus, device, medium, and system based on a SIM card. Background Art
[0002] With the development of technology, communication security has also been increasingly threatened. To address this severe threat, trusted communication technologies have emerged. Trusted communication technologies build a strong defense line through the upgrade of communication platforms and the entire ecological infrastructure of intelligent terminals, effectively resisting telecom fraud and cyberattacks, and escorting communication security.
[0003] Existing trusted communication technologies mainly include quantum communication, identity authentication based on cryptographic tokens, encrypted call technology, identity verification based on voiceprint recognition, and authentication of telephone systems based on cryptography. These technologies have their own advantages in terms of security.
[0004] However, existing trusted communication technologies have high complexity and poor compatibility, which reduces the wide applicability of trusted communication. Summary of the Invention
[0005] This application provides a trusted communication method, apparatus, device, medium, and system based on a SIM card to solve the technical problem that existing trusted communication technology methods have high complexity and poor compatibility, which in turn limits the application scope of trusted communication.
[0006] In a first aspect, this application provides a trusted communication method based on a SIM card, including:
[0007] Receiving trusted communication request information to obtain the calling and called user information in the trusted communication request information;
[0008] Verifying the calling and called user information according to the user index information and public-private key information in the SIM card to obtain user identity verification information, where the SIM card stores user index information, public-private key information, and certificate information for trusted communication;
[0009] If the user identity verification information meets the preset trusted communication requirements, allow the calling and called users to perform trusted communication through the SIM card.
[0010] Optionally, in the method as described above, before receiving the trusted communication request information to obtain the calling and called user information in the trusted communication request information, the method further includes:
[0011] Obtaining the public-private key information for trusted communication;
[0012] Determining the certificate information and user index information for performing the trusted communication;
[0013] Send the public-private key information, the certificate information, and the user index information to the SIM card to complete the storage of the user identity.
[0014] Optionally, in the method as described above, determining the certificate information and user index information for the trusted communication includes:
[0015] Receive the certificate application information and user identity information for the trusted communication;
[0016] Authenticate the user identity information according to the trusted communication APP to obtain an authentication result;
[0017] If the authentication result indicates that the user identity information meets the preset identity requirements, determine the user index information;
[0018] Determine the certificate information for the trusted communication according to the certificate application information and the user index information.
[0019] Optionally, in the method as described above, the user index information includes the user's mobile phone number, user identity information, and user identity information digest value.
[0020] Optionally, in the method as described above, the information verification of the calling and called user information according to the user index information and public-private key information in the SIM card to obtain the user identity verification information includes:
[0021] Determine the user identity information digest value of the calling user and the user identity information digest value of the called user according to the user index information in the SIM card;
[0022] Obtain the user identity verification information of the calling user according to the public-private key information in the SIM card and the user identity information digest value of the calling user;
[0023] Obtain the user identity verification information of the called user according to the public key information in the public-private key information and the user identity information digest value of the called user.
[0024] Optionally, in the method as described above, the obtaining the user identity verification information of the calling user according to the public-private key information in the SIM card and the user identity information digest value of the calling user includes:
[0025] Concatenate the user identity information digest value of the calling user with the time stamp to obtain the data to be signed of the calling user;
[0026] Perform signature verification processing on the data to be signed using the public-private key information to obtain the user identity verification information of the calling user.
[0027] Optionally, in the method described above, the preset trusted communication requirement is that both the calling user and the called user are under the same communication service provider.
[0028] In a second aspect, the present application provides a trusted communication device based on a SIM card, including:
[0029] An information receiving module, configured to receive trusted communication request information and obtain the calling and called user information in the trusted communication request information;
[0030] A user identity authentication module, configured to authenticate the calling and called user information according to the user index information and the public and private key information in the SIM card, and obtain user identity authentication information;
[0031] A trusted communication module, configured to allow the calling and called users to perform trusted communication through the SIM card if the user identity authentication information meets the preset trusted communication requirements.
[0032] In a third aspect, the present application provides an electronic device, including: a processor and a memory communicatively connected to the processor;
[0033] The memory stores computer-executable instructions;
[0034] The processor executes the computer-executable instructions stored in the memory to implement the method of the embodiments of the present application.
[0035] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the method of the embodiments of the present application.
[0036] In a fifth aspect, the present application provides a trusted communication system based on a SIM card, including a computer program, and when the computer program product is executed by a processor, it implements the method according to any one of the first aspects.
[0037] The trusted communication method, device, equipment, medium and system provided by the present application receive trusted communication request information to obtain the calling and called user information in the trusted communication request information; authenticate the calling and called user information according to the user index information and the public and private key information in the SIM card to obtain user identity authentication information, where the SIM card stores user index information, public and private key information and certificate information for trusted communication; if the user identity authentication information meets the preset trusted communication requirements, allow the calling and called users to perform trusted communication through the SIM card, providing a stable, easy-to-use and intuitive trusted communication method, effectively preventing identity impersonation, and improving the user experience at the same time. Description of the Drawings
[0038] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.
[0039] Figure 1 Schematic diagram of the architecture of the SIM card-based trusted communication system provided for this application;
[0040] Figure 2 Schematic diagram of the process of the first embodiment of the SIM card-based trusted communication method proposed for this application;
[0041] Figure 3 Schematic diagram of the process of the second embodiment of the SIM card-based trusted communication method proposed for this application;
[0042] Figure 4 Schematic diagram of the process of the third embodiment of the SIM card-based trusted communication method proposed for this application;
[0043] Figure 5 Overall flowchart of the SIM card-based trusted communication method provided for this application;
[0044] Figure 6 Schematic diagram of the structure of the SIM card-based trusted communication device provided for this application;
[0045] Figure 7 Schematic diagram of the structure of the electronic device provided for the embodiments of this application.
[0046] Through the above accompanying drawings, specific embodiments of this application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of this application in any way, but to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. Detailed implementation manners
[0047] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numerals in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with this application. On the contrary, they are merely examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.
[0048] Existing trusted communication technologies have many deficiencies in the telephone call scenario. Quantum communication technology is difficult, has poor stability, high costs, and may increase call latency. Identity authentication technology based on cryptographic tokens is complex to implement and may affect the timeliness of calls. Encrypted call technology is complex to set up and is not user-friendly for ordinary users. Technology based on voiceprint recognition is vulnerable to environmental noise interference and involves privacy and data security issues. Telephone system authentication based on cryptography has high requirements for computing resources and may affect call quality. Generally speaking, existing technologies have problems such as inconvenient use, high costs, poor stability, and limited scope of application, and there is an urgent need for a new type of trusted communication technology that is economical, stable, easy to use, and intuitive.
[0049] In view of the problems of inconvenient use, high costs, poor stability, and limited scope of application existing in the existing trusted communication technologies, this technical solution innovatively combines the Subscriber Identity Module (SIM) card with the certificate chain technology. The SIM card is used as a secure carrier to store user identity information and keys, and identity verification and communication encryption are achieved through the certificate chain technology, providing a stable, easy-to-use, and intuitive trusted communication method, effectively preventing identity impersonation, and improving the user experience at the same time.
[0050] The following uses specific embodiments to elaborate in detail on the technical solution of this application and how the technical solution of this application solves the above technical problems. These specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0051] Figure 1 It is a schematic diagram of the architecture of the SIM card-based trusted communication system provided by this application. As Figure 1 shown, the SIM card-based trusted communication system includes a trusted communication service root Certificate Authority (CA) S101, a trusted communication service provider S102, a trusted service access provider S103, a user trusted communication application (APP) S104, and a user SIM card S105.
[0052] Among them, the basis of the SIM card-based trusted communication method proposed in this application is the certificate chain system. The trusted communication service root CA S101 is an industry-recognized CA, a primary CA (such as CFCA, GlobalSign, GSMA, etc.), and is responsible for issuing certificates to secondary CAs (i.e., trusted communication service providers).
[0053] The trusted communication service provider S102 is responsible for issuing certificates to the SIM cards accessing the service in this application and for verifying the identities of the calling user and the called user during trusted calls.
[0054] The trusted service access provider S103 is equivalent to institutions such as enterprises, public institutions, and industry associations, and is responsible for introducing the trusted identities of trusted communication service users and providing guarantees for their identities.
[0055] In the trusted communication service, the user's trusted communication APP S104 is the bridge for communication between the trusted communication service provider and the user's SIM card. The APDU instruction is sent to the user's trusted communication APP via HTTP through the TSM platform of the trusted communication service provider, and then sent to the trusted communication Applet in the user's SIM card through the OMA interface. Another function of the user's trusted communication APP is to present the user identity information to the called user and the calling user after verification.
[0056] The user's SIM card S105 is used to store the certificate issued by the trusted communication service provider and is the core role in user identity verification.
[0057] Figure 2 This is the flowchart of the first embodiment of the SIM card-based trusted communication method proposed in this application. As Figure 2 shown, it includes:
[0058] S201. Receive the trusted communication request information and obtain the calling and called user information in the trusted communication request information.
[0059] Among them, the trusted communication request information refers to the communication request initiated by the user, including the identity information of the calling user (i.e., the party initiating the communication) and the called user (i.e., the party receiving the communication), such as the mobile phone number, etc.
[0060] Exemplarily, the calling user enters the mobile phone number of the called user on the APP or other terminal devices and selects the identity to be used, such as personal identity or enterprise identity. The APP or the terminal device sends the request information to the trusted communication application of the SIM card.
[0061] S202. Verify the calling and called user information according to the user index information and public-private key information in the SIM card to obtain the user identity verification information.
[0062] Among them, the user index information refers to the user identity-related data stored in the SIM card, including mobile phone number, identity information, identity information digest value, etc. The public and private key information is a key pair used for encryption and authentication. The private key is used for signing, and the public key is used for signature verification. Specifically, the SIM card stores the user index information, public and private key information, and certificate information for trusted communication, and the certificate information is the identity authentication information issued by the trusted communication service provider to ensure the credibility of the public key. The user identity authentication information is the data generated after the SIM card signs the identity information digest value with the private key and is used to verify the user's identity.
[0063] In the embodiment of the present application, the SIM card reads the identity index information of the calling and called users, extracts the corresponding identity information digest value, signs it in combination with the time stamp to obtain the signature data, then encrypts it with the public key of the trusted communication service provider, and finally returns it to the APP or the corresponding terminal device.
[0064] S203. If the user identity authentication information meets the preset trusted communication requirements, the calling and called users are allowed to conduct trusted communication through the SIM card.
[0065] Among them, the preset trusted communication requirements refer to the conditions that both communication parties must meet, such as whether they belong to the same communication service provider, whether they have completed identity authentication, etc. In the embodiment of the present application, the preset trusted communication requirement is that both the calling user and the called user are under the same communication service access provider. Specifically, the APP or the terminal device sends the encrypted identity authentication data to the trusted communication service provider. The service provider decrypts it with the private key and verifies the signature with the public key of the calling user to confirm the authenticity of the user identity. If the verification passes and meets the preset trusted communication requirements, the calling and called users are allowed to communicate.
[0066] The embodiment of the present application realizes the two-way identity authentication of the calling user and the called user through the user index information, public and private key system, and identity information digest value in the SIM card. Using private key signature and public key signature verification ensures the integrity and immutability of the identity information, effectively preventing identity fraud and fraudulent communication.
[0067] Figure 3 It is a schematic flowchart of Embodiment 2 of the trusted communication method based on the SIM card proposed in the present application. As Figure 3 shown, on the basis of Figure 2 the embodiment, according to the user index information and public and private key information in the SIM card, the information of the calling and called users is verified to obtain the user identity authentication information, including:
[0068] S301. According to the user index information in the SIM card, determine the user identity information digest value of the calling user and the user identity information digest value of the called user.
[0069] Among them, the user index information is the user identity data stored in the SIM card, including the mobile phone number, user identity information, and user identity information digest value. Among them, the mobile phone number is used to uniquely identify the communication user. The user identity information includes the user name, employee number, or enterprise ID, etc. The user identity information digest value is the digest data obtained by performing a hash calculation on the user identity information for identity verification.
[0070] In the embodiment of the present application, the calling user enters the mobile phone number of the called user in the APP and selects the currently used identity (such as personal identity, enterprise identity). The APP sends this request to the trusted communication application inside the SIM card, and the trusted communication application inside the SIM card can parse the user identity index information. Specifically, the user index information (mobile phone number, identity information, identity information digest value) is stored in the SIM card. The trusted communication application inside the SIM card looks up the corresponding user identity information digest value according to the identity selected by the calling user, parses the mobile phone number of the called user, and then queries the identity information digest value of the called user from the SIM card database or the trusted communication service provider database.
[0071] S302. Obtain the user identity verification information of the calling user according to the public-private key information in the SIM card and the user identity information digest value of the calling user.
[0072] Among them, the public-private key information includes public key information and private key information. The public key information is managed and stored by the trusted communication service provider for verifying the user identity signature. The private key information is stored in the SIM card and can only be used by the user himself / herself to sign the identity data. The user identity verification information of the calling user is generated by the SIM card application of the calling user, and the identity information digest value is digitally signed using the private key to ensure the integrity of the data and the authenticity of the identity. Specifically, after receiving the verification information, the trusted communication service provider performs signature verification through the public key to confirm the validity of the identity.
[0073] Further, obtaining the user identity verification information of the calling user according to the public-private key information in the SIM card and the user identity information digest value of the calling user includes:
[0074] Concatenate the user identity information digest value of the calling user with the timestamp to obtain the data to be signed of the calling user.
[0075] Among them, the timestamp can record the current time to prevent replay attacks. That is, without a timestamp, an attacker can intercept and resend the same signature data to forge identity information. The data to be signed is formed by concatenating the identity information digest value and the timestamp to ensure the uniqueness of the data for each authentication. Specifically, the purpose of signing is to ensure the integrity of the data, and it is uniquely generated by the SIM card holder to prevent forgery. During the signing process, the SIM card uses the private key to encrypt the data to be signed, generates the signature data, and then returns the signature data together with the original data for subsequent identity verification.
[0076] In this step, the SIM card application reads the identity information index of the calling user from the storage area, calculates the identity information digest value, and then reads the current system time to generate a timestamp. The identity information digest value and the timestamp are concatenated as strings to form the data to be signed.
[0077] The data to be signed is processed for signature verification using the public and private key information to obtain the user identity verification information of the calling user.
[0078] In this step, a suitable signature algorithm can be selected, and then the private key of the SIM card is used for signing to generate a binary signature data of a fixed length. The data to be signed and the signature data are encapsulated to form an identity verification data structure, and the SIM card application sends this identity verification data structure to the APP or the corresponding terminal device, and the APP or the corresponding terminal device then forwards the data to the trusted communication service provider for signature verification.
[0079] Specifically, after receiving the identity verification data, the trusted communication service provider extracts the data to be signed and the signature data; uses the public key for signature verification. If the signature verification is successful, it is confirmed that the signature is issued by a legitimate SIM card and the data has not been tampered with. Then, for identity matching, the trusted communication service provider checks whether the identity information of the calling user matches the preset trusted communication requirements (such as the same operator, internal enterprise communication, etc.). If the matching is successful, the communication connection is continued; otherwise, the request is rejected.
[0080] S303. Obtain the user identity verification information of the called user according to the public key information in the public and private key information and the identity information digest value of the called user.
[0081] In this step, after receiving the authentication request from the calling user, the trusted communication service provider looks up the user index information of the called user. Through the SIM card or the server database, it obtains the identity information digest value of the called user. Secondly, the trusted communication service provider uses the trusted public key to verify the signature of the identity information digest value of the called user. This process ensures the authenticity of the called user's identity and prevents identity fraud. Finally, the trusted communication service provider compares the identity information of the calling user and the called user. If the authentication passes, it allows the establishment of a trusted communication connection. If the authentication fails, it rejects the communication request and notifies the calling user.
[0082] Based on the public-private key system in the SIM card, this embodiment of the application realizes the secure authentication of the calling user through the user identity information digest value, timestamp splicing, and private key signature, ensuring the integrity, immutability, and anti-counterfeiting of identity data. Combined with the public key signature verification mechanism of the trusted communication service provider, it effectively prevents identity fraud, data tampering, and replay attacks. At the same time, it supports secure encrypted transmission, greatly improving the communication security and credibility, and is applicable to enterprise secure communication, operator-level identity authentication, and high-security scenarios.
[0083] Figure 4 It is a schematic flowchart of Embodiment 3 of the trusted communication method based on the SIM card proposed in this application. As Figure 4 shown, on the basis of the Figure 2 embodiment, before receiving the trusted communication request information and obtaining the calling and called user information in the trusted communication request information, the method further includes:
[0084] S401. Obtain the public and private key information of trusted communication.
[0085] Among them, in the trusted communication system, the public and private key information (i.e., the public and private key pair) is generated by the trusted communication SIM card application. The SIM card application generates a pair of asymmetric keys (public key and private key), where the public key is used for certificate application, and the private key is used for signature and decryption. The generation of the public and private key pair is the basis of trusted communication, ensuring the security of communication and the credibility of identity.
[0086] Specifically, read the generated public and private key pair from the SIM card application, or obtain the public and private key information through the interaction between the trusted communication APP and the SIM card application.
[0087] S402. Determine the certificate information and user index information for trusted communication.
[0088] This step includes receiving the certificate application information and user identity information of the trusted communication; authenticating the user identity information according to the trusted communication APP to obtain the authentication result; if the authentication result indicates that the user identity information meets the preset identity requirements, determining the user index information; and determining the certificate information for the trusted communication according to the certificate application information and the user index information.
[0089] Specifically, the trusted communication service provider will receive the certificate application information and user identity information from the trusted communication service access provider (such as Company A or Association B). Among them, the user identity information includes the employee's proof materials, mobile phone number, etc. Then, the trusted communication APP will display the user identity information (such as employee identity or membership identity) to the user for confirmation. After the user confirms, the APP will send the identity information to the SIM card application for further processing.
[0090] For the SIM card application, the SIM card application will generate an identity index and associate the index with the user identity digest value. Among them, the identity index is the unique identifier of the user in the trusted communication system, used to distinguish different identities (such as employee identity and membership identity). Then, the trusted communication service provider will issue a certificate for the user according to the certificate application information and the user index information. The certificate information includes the user's public key, identity index, and the signature of the trusted communication service provider, etc.
[0091] S403. Send the public-private key information, certificate information, and user index information to the SIM card to complete the storage of the user identity.
[0092] In this step, the trusted communication APP will send the certificate information and the public key of the trusted communication service provider to the SIM card application, and the SIM card application will store this information. Specifically, the SIM card application will associate and store the user index information with the user identity digest value. In this way, the user's public and private keys, certificate information, identity index, etc. are stored in the SIM card, completing the storage of the user identity.
[0093] After the storage is completed, the SIM card application will return the execution result, and the trusted communication service provider will also associate and store the mobile phone number, certificate, user identity information, etc.
[0094] Through the generation of the public-private key pair, the issuance of the certificate, the association of the user identity information and the storage in the SIM card, the embodiments of the present application realize the secure management of the user's multiple identities and the trusted communication, ensure the authenticity and uniqueness of the user identity, support the multiple identity management of the same user in different scenarios (such as employees and members); ensure the security of communication through encryption technology and certificate mechanism; simplify the identity authentication process and improve the user experience; at the same time, all key information is stored in the SIM card, enhancing the security of data and privacy protection.
[0095] Figure 5 This is the overall flowchart of the trusted communication method based on the SIM card provided by this application. As Figure 5 shown, it includes:
[0096] S501. The trusted communication service root CA issues a certificate to the trusted communication service provider.
[0097] S502. The trusted communication service provider issues a certificate to the trusted communication SIM card application, and realizes the adaptation and storage of the mobile phone number, certificate, identity information, identity information digest value, and identity information index in each unit.
[0098] S503. The calling user selects the identity to be used in the APP to prepare for making a call, and the trusted communication service provider verifies the identity of the calling user.
[0099] S504. The trusted communication service provider verifies the identity of the called user and presents the result to the calling user.
[0100] S505. The calling user confirms to make a call, and the called user's APP presents the identity of the calling user, completing the trusted communication.
[0101] Figure 6 This is the structural schematic diagram of the trusted communication device based on the SIM card provided by this application. As Figure 6 shown, the trusted communication device 60 based on the SIM card includes an information receiving module 601, a user identity verification module 602, and a trusted communication module 603, where:
[0102] The information receiving module 601 is used to receive the trusted communication request information and obtain the calling and called user information in the trusted communication request information;
[0103] The user identity verification module 602 is used to perform identity verification on the calling and called user information according to the user index information and public and private key information in the SIM card to obtain the user identity verification information;
[0104] The trusted communication module 603 is used to allow the calling and called users to perform trusted communication through the SIM card if the user identity verification information meets the preset trusted communication requirements.
[0105] Specifically, the information receiving module 601 is further used to:
[0106] Obtain the public and private key information for trusted communication;
[0107] Determine the certificate information and user index information for performing trusted communication;
[0108] Send the public and private key information, certificate information, and user index information to the SIM card to complete the storage of the user identity.
[0109] Specifically, the information receiving module 601 is further configured to:
[0110] Receive the certificate application information and user identity information of the trusted communication;
[0111] Authenticate the user identity information according to the trusted communication APP to obtain an authentication result;
[0112] If the authentication result indicates that the user identity information meets the preset identity requirements, determine the user index information;
[0113] Determine the certificate information for the trusted communication according to the certificate application information and the user index information.
[0114] Specifically, the user index information includes the user's mobile phone number, user identity information, and the user identity information digest value.
[0115] Furthermore, the user authentication module 602 is further specifically configured to:
[0116] Determine the user identity information digest value of the calling user and the user identity information digest value of the called user according to the user index information in the SIM card;
[0117] Obtain the user authentication information of the calling user according to the public and private key information in the SIM card and the user identity information digest value of the calling user;
[0118] Obtain the user authentication information of the called user according to the public key information in the public and private key information and the user identity information digest value of the called user.
[0119] Furthermore, the user authentication module 602 is further specifically configured to:
[0120] Concatenate the user identity information digest value of the calling user with the timestamp to obtain the data to be signed of the calling user;
[0121] Perform signature verification processing on the data to be signed by using the public and private key information to obtain the user authentication information of the calling user.
[0122] Specifically, the preset trusted communication requirement is that both the calling user and the called user are under the same communication service access provider.
[0123] Figure 7 It is a schematic structural diagram of the electronic device provided in the embodiment of the present application. As Figure 7 shown, the electronic device 70 includes:
[0124] The electronic device 70 may include components such as a processor 701 with one or more processing cores, a memory 702 with one or more computer-readable storage media, and a communication component 703. Among them, the processor 701, the memory 702, and the communication component 703 are connected through a bus 704.
[0125] In a specific implementation process, at least one processor 701 executes computer-executable instructions stored in the memory 702, so that at least one processor 701 executes the above SIM card-based trusted communication method.
[0126] For the specific implementation process of the processor 701, reference can be made to the above method embodiments. Their implementation principles and technical effects are similar, and will not be elaborated here in this embodiment.
[0127] In the above Figure 7 In the illustrated embodiment, it should be understood that the processor may be a central processing unit (English: Central Processing Unit, abbreviated: CPU), or other general-purpose processors, digital signal processors (English: Digital Signal Processor, abbreviated: DSP), application specific integrated circuits (English: Application Specific Integrated Circuit, abbreviated: ASIC), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0128] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0129] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.
[0130] In some embodiments, a computer program product is further provided, including a computer program or instructions, which, when executed by a processor, implement the steps in any of the above-described SIM card-based trusted communication methods.
[0131] For the specific implementation of each of the above operations, reference may be made to the previous embodiments, which will not be elaborated herein.
[0132] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions, or by controlling relevant hardware through instructions. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0133] Therefore, an embodiment of the present application provides a computer-readable storage medium, in which multiple instructions are stored, and these instructions can be loaded by a processor to execute the steps in any of the SIM card-based trusted communication methods provided by the embodiments of the present application.
[0134] Among them, the storage medium may include: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or optical disk, etc.
[0135] According to one aspect of the present application, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium.
[0136] Since the instructions stored in the storage medium can execute the steps in any of the SIM card-based trusted communication methods provided by the embodiments of the present application, the beneficial effects that can be achieved by any of the SIM card-based trusted communication methods provided by the embodiments of the present application can be realized. For details, reference may be made to the previous embodiments, which will not be elaborated herein.
[0137] This embodiment further provides a SIM card-based trusted communication system, including a computer program, which, when executed by a processor, implements the SIM card-based trusted communication method provided in any of the above embodiments.
[0138] Those skilled in the art will readily think of other implementation manners of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include the common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0139] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0140] It should be understood that the foregoing device embodiments are merely illustrative, and the devices of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.
[0141] In addition, unless otherwise specified, in each embodiment of this application, the functional units / modules can be integrated in one unit / module, or each unit / module can exist physically alone, or two or more units / modules can be integrated together. The above integrated unit / module can be implemented in the form of hardware or in the form of a software program module.
[0142] When the integrated unit / module is implemented in the form of hardware, the hardware can be a digital circuit, an analog circuit, etc. The physical implementation of the hardware structure includes but is not limited to transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic storage medium or magneto-optical storage medium, such as resistive random access memory RRAM (Resistive Random Access Memory), dynamic random access memory DRAM (Dynamic Random Access Memory), static random access memory SRAM (Static Random-Access Memory), enhanced dynamic random access memory EDRAM (Enhanced Dynamic Random Access Memory), high-bandwidth memory HBM (High-Bandwidth Memory), hybrid memory cube HMC (Hybrid Memory Cube), etc.
[0143] When the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present application. The aforementioned memory includes various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.
[0144] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as falling within the scope described in this specification.
[0145] Those skilled in the art will readily think of other implementation manners of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include the common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0146] It should be understood that the present application is not limited to the exact structure already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A trusted communication method based on a SIM card, characterized in that: include: Receiving trusted communication request information, and obtaining calling and called user information in the trusted communication request information; According to the user index information and public and private key information in the SIM card, the calling and called user information are verified to obtain user identity authentication information, wherein the SIM card stores the user index information, public and private key information and certificate information of the trusted communication; If the user identity verification information meets the preset trusted communication requirement, the calling and called users are allowed to perform trusted communication through the SIM card.
2. The trusted communication method according to claim 1, characterized in that: Before receiving the trusted communication request information and obtaining the calling and called user information in the trusted communication request information, the method further includes: Obtain public and private key information for trusted communications; Determining certificate information and user index information for performing the trusted communication; The public and private key information, the certificate information and the user index information are sent to the SIM card to complete the storage of the user identity.
3. The trusted communication method according to claim 2, characterized in that: The determining of the certificate information and user index information for the trusted communication includes: Receive certificate application information and user identity information for trusted communication; According to the trusted communication APP, the user identity information is authenticated to obtain a verification result; If the verification result indicates that the user identity information meets the preset identity requirement, determining the user index information; The certificate information for performing the trusted communication is determined according to the certificate application information and the user index information.
4. The trusted communication method according to any one of claims 1 to 3, characterized in that: The user index information includes the user's mobile phone number, user identity information and a summary value of the user identity information.
5. The trusted communication method according to claim 1, characterized in that: The method of verifying the calling and called user information according to the user index information and the public and private key information in the SIM card to obtain the user identity authentication information includes: Determine the summary value of the user identity information of the calling user and the summary value of the user identity information of the called user according to the user index information in the SIM card; Obtaining user identity authentication information of the calling user according to the public and private key information in the SIM card and the user identity information summary value of the calling user; The user identity authentication information of the called user is obtained according to the public key information in the public-private key information and the user identity information digest value of the called user.
6. The trusted communication method according to claim 5, characterized in that: The obtaining the user identity authentication information of the calling user according to the public and private key information in the SIM card and the user identity information summary value of the calling user includes: Concatenate the user identity information summary value of the calling user with the timestamp to obtain the data to be signed of the calling user; The public and private key information is used to perform a signature verification process on the data to be signed to obtain the user identity verification information of the calling user.
7. The trusted communication method according to claim 1, characterized in that: The preset trusted communication requires that the calling user and the called user are both in the same communication service access provider.
8. A trusted communication device based on a SIM card, characterized in that: include: An information receiving module, used to receive the trusted communication request information and obtain the calling and called user information in the trusted communication request information; A user identity authentication module is used to authenticate the calling and called user information according to the user index information and public and private key information in the SIM card to obtain user identity authentication information; The trusted communication module is used to allow the calling and called users to perform trusted communication through the SIM card if the user identity verification information meets the preset trusted communication requirements.
9. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.
11. A trusted communication system based on a SIM card, characterized in that: The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.