User identity information protection method and device and related equipment

By using a hybrid strategy of generating shared keys in 5G networks, the problems of quantum computing attacks and quantum key distribution efficiency faced by the elliptic curve encryption algorithm are solved, and efficient and secure user identity information protection is achieved.

CN120091309APending Publication Date: 2025-06-03CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510237620.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

User terminals in 5G networks need to report identity information through encryption when accessing to protect privacy, but the existing elliptic curve encryption algorithms are threatened by quantum computing attacks, and the low generation rate and high storage costs of quantum key distribution are difficult to meet the real-time access needs of massive terminals.

Method used

The key negotiation algorithm and/or the quantum key algorithm are used to generate the shared key between the terminal and the network side. By dynamically selecting a hybrid strategy including the key negotiation algorithm and the quantum key algorithm, a first shared key is generated for encrypting the user's identity information, and a second shared key is generated through the identification and parameters of the target protection policy for decryption.

Benefits of technology

It effectively avoids the security risks brought by quantum computing, solves the problem of inability to encrypt plain text user identity information due to insufficient quantum keys, and realizes efficient and secure protection of user identity information in 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120091309A_ABST
    Figure CN120091309A_ABST
Patent Text Reader

Abstract

The invention provides a user identity information protection method and device and related equipment, and relates to the technical field of communication. The method comprises: in response to an identity registration request of a terminal, selecting a target protection strategy from a plurality of information protection strategies, the target protection strategy generating a terminal and network side shared key by using a key negotiation algorithm and / or a quantum key algorithm, generating a first shared key based on the target protection strategy, and sending the first shared key to the terminal; encrypting plaintext user identity information of the terminal by using the first shared key to obtain encrypted user identity information; and sending the encrypted user identity information, the identifier of the target protection strategy and the corresponding parameters to a network side, so that the network side generates a second shared key based on the identifier of the target protection strategy and the corresponding parameters, and decrypts the encrypted user identity information by using the second shared key to obtain plaintext user identity information. The security risk caused by quantum calculation can be effectively avoided, and the problem of insufficient quantum keys is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In a 5G network, when a user terminal accesses, it needs to report its identity information in an encrypted manner to protect privacy. The current solution uses the elliptic curve encryption algorithm to encrypt the user's permanent identification code to generate a user masked identification code. The network side restores the user's permanent identification code by decrypting the user masked identification code to complete the identity authentication. This process relies on the implementation of the elliptic curve key exchange algorithm, which can effectively prevent the privacy leakage problem caused by the plaintext transmission of the user's permanent identification code. Although the elliptic curve encryption algorithm has high security in the traditional computing model, its long-term static public key faces a serious threat of quantum computing attacks. A quantum computer can crack the private key of the elliptic curve encryption algorithm, resulting in the permanent leakage of the user's identity.

[0003] In related technologies, quantum key distribution can achieve "one-time pad" anti-quantum attacks. However, due to problems such as low quantum key generation rate, high storage cost, and complex network deployment, it is difficult to meet the needs of real-time access of a large number of 5G terminals. Therefore, there is an urgent need for an identity encryption mechanism that can resist quantum computing attacks and does not rely on frequent quantum key updates to balance the contradiction between security and usability.

[0004] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present disclosure. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] The present disclosure provides a method, device, and related equipment for protecting user identity information, which can effectively avoid the security risks brought by quantum computing and solve the problem that the plaintext user identity information cannot be encrypted due to insufficient quantum keys.

[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or will be learned in part through the practice of the present disclosure.

[0007] According to one aspect of the present disclosure, a method for protecting user identity information is provided, which is applied to a terminal. The method includes: in response to an identity registration request of the terminal, selecting a target protection policy from multiple information protection policies, wherein the target protection policy uses a key negotiation algorithm and / or a quantum key algorithm to generate a shared key between the terminal and the network side, and the policy information of the target protection policy includes: an identifier of the target protection policy and corresponding parameters; generating a first shared key based on the target protection policy, and encrypting the plaintext user identity information of the terminal using the first shared key to obtain encrypted user identity information; sending the encrypted user identity information, the identifier of the target protection policy and the corresponding parameters to the network side, so that the network side generates a second shared key based on the identifier of the target protection policy and the corresponding parameters, and decrypts the encrypted user identity information using the second shared key to obtain the plaintext user identity information.

[0008] In some embodiments, when the terminal includes a user identification module card, before selecting a target protection policy from multiple information protection policies, the method further includes: in response to filling a quantum key into the user identification module card, storing the quantum key in the user identification module card; or, in response to the user identification module card connecting to a quantum key distribution network through a quantum communication channel, obtaining a quantum key from the quantum key distribution network and storing the quantum key in the user identification module card; wherein the user identification module card is used to generate a corresponding quantum key identifier for each received quantum key.

[0009] In some embodiments, before selecting a target protection policy from multiple information protection policies, the method further includes: obtaining configuration information of the terminal, where the configuration information is used to indicate the priority of information protection policies supported by the terminal; the step of selecting a target protection policy from multiple information protection policies includes: selecting a target protection policy from multiple information protection policies according to the priority of information protection policies supported by the terminal.

[0010] In some embodiments, before selecting a target protection policy from multiple information protection policies, the method further includes: obtaining the remaining amount of the quantum key stored in the user identification module card; the step of selecting a target protection policy from multiple information protection policies includes: when the remaining amount of the quantum key stored in the user identification module card is less than or equal to a preset threshold, determining a key negotiation algorithm as the target protection policy among the multiple information protection policies.

[0011] In some embodiments, when the target protection policy includes a quantum key algorithm, the corresponding parameters of the target protection policy include the quantum key identifier corresponding to the quantum key.

[0012] In some embodiments, when the target protection policy is a key agreement algorithm and a quantum key algorithm, the parameters corresponding to the target protection policy further include an exclusive OR (XOR) identifier for the key agreement algorithm and the quantum key algorithm, and the XOR identifier is used to indicate the XOR algorithm for the key agreement algorithm and the quantum key algorithm; generating a first shared key based on the target protection policy includes: determining a target quantum key according to the quantum key identifier in the parameters corresponding to the target protection policy; determining a target XOR algorithm according to the XOR identifier in the parameters corresponding to the target protection policy; and generating the first shared key according to the key agreement algorithm, the target quantum key, and the target XOR algorithm.

[0013] In some embodiments, encrypting the plaintext user identity information of the terminal using the first shared key to obtain encrypted user identity information includes: generating a first confidentiality key and a first integrity key using the first shared key; and encrypting the plaintext user identity information of the terminal based on the first confidentiality key and the first integrity key to obtain the encrypted user identity information.

[0014] According to another aspect of the present disclosure, there is also provided a method for protecting user identity information, which is applied to the network side. The method includes: in response to an identity registration request of a terminal, obtaining the encrypted user identity information sent by the terminal, the identifier of the target protection policy, and the corresponding parameters, where the encrypted user identity information is obtained by encrypting the plaintext user identity information of the terminal using a first shared key, the first shared key is generated based on the parameters corresponding to the target protection policy, and the target protection policy is selected from multiple information protection policies; generating a second shared key based on the identifier of the target protection policy and the corresponding parameters; and decrypting the encrypted user identity information using the second shared key to obtain the plaintext user identity information of the terminal.

[0015] In some embodiments, generating a second shared key based on the identifier of the target protection policy and the corresponding parameters includes: determining the target protection policy based on the identifier of the target protection policy and the corresponding parameters; generating the second shared key using the target protection policy; and decrypting the encrypted user identity information using the second shared key to obtain the plaintext user identity information of the terminal includes: generating a second confidentiality key using the second shared key; and decrypting the encrypted user identity information based on the second confidentiality key to obtain the plaintext user identity information of the terminal.

[0016] In some embodiments, the method further includes: querying the subscription data of the terminal according to the plaintext user identity information of the terminal, and selecting an authentication method; and triggering an authentication operation of the terminal based on the subscription data and the authentication method.

[0017] According to another aspect of the present disclosure, there is also provided a user identity information protection device, which is applied to a terminal. The device includes: a selection module, configured to select a target protection policy from multiple information protection policies in response to an identity registration request of the terminal, wherein the target protection policy uses a key negotiation algorithm and / or a quantum key algorithm to generate a shared key between the terminal and the network side, and the policy information of the target protection policy includes: an identifier of the target protection policy and corresponding parameters; a first generation module, configured to generate a first shared key based on the target protection policy, and encrypt the plaintext user identity information of the terminal by using the first shared key to obtain encrypted user identity information; a sending module, configured to send the encrypted user identity information, the identifier of the target protection policy and the corresponding parameters to the network side, so that the network side generates a second shared key based on the identifier of the target protection policy and the corresponding parameters, and decrypts the encrypted user identity information by using the second shared key to obtain the plaintext user identity information.

[0018] According to another aspect of the present disclosure, there is also provided a user identity information protection device, which is applied to the network side. The device includes: an acquisition module, configured to acquire the encrypted user identity information, the identifier of the target protection policy and the corresponding parameters sent by the terminal in response to an identity registration request of the terminal, wherein the encrypted user identity information is obtained by encrypting the plaintext user identity information of the terminal by using a first shared key, the first shared key is generated based on the parameters corresponding to the target protection policy, and the target protection policy is selected from multiple information protection policies; a second generation module, configured to generate a second shared key based on the identifier of the target protection policy and the corresponding parameters; a decryption module, configured to decrypt the encrypted user identity information by using the second shared key to obtain the plaintext user identity information of the terminal.

[0019] According to another aspect of the present disclosure, there is also provided an electronic device, which includes: a processor; and a memory, configured to store executable instructions of the processor; wherein the processor is configured to execute the user identity information protection method according to any one of the above by executing the executable instructions.

[0020] According to another aspect of the present disclosure, there is also provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the user identity information protection method according to any one of the above is implemented.

[0021] According to another aspect of the present disclosure, there is also provided a computer program product, including: a computer program or instruction, which, when executed by a processor, implements the user identity information protection method of any one of the above.

[0022] A user identity information protection method, device and related equipment provided in an embodiment of the present disclosure are applied to a terminal. The method includes: in response to an identity registration request of the terminal, selecting a target protection strategy from multiple information protection strategies, where the target protection strategy uses a key negotiation algorithm and / or a quantum key algorithm to generate a shared key between the terminal and the network side, and the policy information of the target protection strategy includes: the identifier of the target protection strategy and the corresponding parameters; generating a first shared key based on the target protection strategy, and encrypting the plaintext user identity information of the terminal using the first shared key to obtain encrypted user identity information; sending the encrypted user identity information, the identifier of the target protection strategy and the corresponding parameters to the network side, so that the network side generates a second shared key based on the identifier of the target protection strategy and the corresponding parameters, and decrypts the encrypted user identity information using the second shared key to obtain the plaintext user identity information. By dynamically selecting a hybrid strategy including a key negotiation algorithm and a quantum key algorithm to generate a shared key, it can effectively avoid the security risks brought by quantum computing and solve the problem that the plaintext user identity information cannot be encrypted due to insufficient quantum keys.

[0023] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The drawings here are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0025] Figure 1 Schematic diagram of the system architecture of a user identity information protection method in an embodiment of the present disclosure;

[0026] Figure 2 Schematic diagram of a user identity information protection method in a related art in an embodiment of the present disclosure;

[0027] Figure 3 Flowchart of a user identity information protection method in an embodiment of the present disclosure;

[0028] Figure 4 Flowchart of a method for selecting a target protection strategy in an embodiment of the present disclosure;

[0029] Figure 5 The flowchart of a method for selecting a target protection policy in an embodiment of the present disclosure is shown;

[0030] Figure 6 The flowchart of a method for generating a first shared key in an embodiment of the present disclosure is shown;

[0031] Figure 7 The flowchart of a method for protecting user identity information in an embodiment of the present disclosure is shown;

[0032] Figure 8 The schematic diagram of a method for protecting user identity information in an embodiment of the present disclosure is shown;

[0033] Figure 9 The specific system schematic diagram of a method for protecting user identity information in an embodiment of the present disclosure is shown;

[0034] Figure 10 The signaling diagram of a method for protecting user identity information in an embodiment of the present disclosure is shown;

[0035] Figure 11 The schematic diagram of a device for protecting user identity information in an embodiment of the present disclosure is shown;

[0036] Figure 12 The schematic diagram of a device for protecting user identity information in an embodiment of the present disclosure is shown;

[0037] Figure 13 The structural block diagram of an electronic device in an embodiment of the present disclosure is shown. Detailed implementation manners

[0038] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.

[0039] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus their repeated description will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0040] For ease of understanding, before introducing the embodiments of the present disclosure, several terms involved in the embodiments of the present disclosure are first explained as follows:

[0041] User Equipment (UE): Terminal devices such as mobile phones are the interfaces for users to access the network.

[0042] User Identity Module (UIM): It is a smart card that stores user-related information. In the field of mobile communication, the UIM card is used to identify the user's identity, including the user's number, security authentication information, etc., just like a key to open the service permissions of a specific user in the mobile network.

[0043] Universal Subscriber Identity Module (Subscriber Identity Module Card): It is an upgraded form of the UIM. In addition to the basic function of identifying the user's identity like the UIM card, the Subscriber Identity Module Card can also support more high-speed data services and multimedia services. For example, in 3G, 4G, and even 5G networks, the Subscriber Identity Module Card allows users to use complex functions such as video calls and high-speed Internet access more smoothly, and there is also a further improvement in terms of security.

[0044] Core network: It is the central nervous system of the mobile network, responsible for managing functions such as user authentication, billing, and data routing.

[0045] Access and Mobility Management Function (AMF): In the 5G core network, it is responsible for managing user access and mobility-related matters, such as registration management.

[0046] Security Anchor Function (SEAF): It mainly processes security-related anchoring functions to ensure network security.

[0047] Authentication Server Function (AUSF): It is responsible for authenticating the user's identity.

[0048] Unified Data Management (UDM): It is used to manage information such as the user's subscribed data.

[0049] Access and Mobility Policy Function (ARPF): It formulates access and mobility-related policies.

[0050] Subscription Permanent Identifier (SUPI): It is a long-term invariant identifier used to uniquely identify a user in a communication network. In modern communication systems such as 5G networks, SUPI is closely associated with the user's identity, just like each person's unique ID number. For example, for a user with a mobile phone number, SUPI remains unchanged across different network device interactions and different service scenarios, ensuring that the network can accurately identify the user's identity, provide corresponding services to legitimate users, and safeguard network security to prevent identity theft and other situations.

[0051] Subscription Concealed Identifier (SUCI): It is a technical identifier used to protect the privacy of a user's identity in a mobile network. In scenarios such as 5G networks, when a user equipment (UE) interacts with the network, SUCI replaces the user's true permanent identifier (such as the International Mobile Subscriber Identity IMSI) for processes such as initial registration. It undergoes encryption and obfuscation processing, making it impossible for the network to directly identify the user's true identity during the early interaction stage.

[0052] Elliptic Curve Diffie-Hellman (ECDH): It is a key agreement protocol based on elliptic curve cryptography. An elliptic curve is a special algebraic curve. In ECDH, the two communicating parties use points on the elliptic curve to generate public-private key pairs. Each party generates its own private key (a random number) and the corresponding public key (a point on the elliptic curve calculated based on the private key). Then they exchange public keys with each other and obtain a shared secret value through a specific operation in combination with their own private keys. This shared secret value can be used for subsequent symmetric encryption and other operations.

[0053] The following will describe in detail the specific implementation manners of the embodiments of the present disclosure with reference to the accompanying drawings.

[0054] As Figure 1 shown, the system architecture includes a terminal device 101, a network 102, and a network-side device 103.

[0055] The network 102 is used to provide a medium for the communication link between the terminal device 101 and the network-side device 103, which can be a wired network or a wireless network.

[0056] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is usually the Internet, but can also be any network, including but not limited to any combination of a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network. In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPSec), etc. can be used to encrypt all or some of the links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.

[0057] Optionally, the terminal device in the embodiments of the present disclosure can also be referred to as a UE (User Equipment). In specific implementations, the terminal device can be a mobile phone, a tablet personal computer, a laptop computer, a personal digital assistant (PDA), a mobile Internet device (MID), a wearable device, or a vehicle-mounted device, etc. It should be noted that the specific type of the terminal device is not limited in the embodiments of the present invention.

[0058] The network-side device can be a base station, a relay, or an access point, etc. The base station can be a base station of 5G and later versions (for example: 5G NR NB), or a base station in other communication systems (for example: eNB base station). It should be noted that the specific type of the network-side device is not limited in the embodiments of the present disclosure.

[0059] Those skilled in the art can know that Figure 1The numbers of terminals, networks, and network-side devices in [it] are merely illustrative. According to actual needs, there can be any number of terminals, networks, and network-side devices. The embodiments of the present disclosure do not limit this.

[0060] Under the above system architecture, an embodiment of the present disclosure provides a method for protecting user identity information, and this method can be executed by any electronic device with computing and processing capabilities.

[0061] In some embodiments, the method for protecting user identity information provided in the embodiments of the present disclosure can be executed by the terminal device of the above system architecture; in other embodiments, the method for protecting user identity information provided in the embodiments of the present disclosure can be executed by the server in the above system architecture; in other embodiments, the method for protecting user identity information provided in the embodiments of the present disclosure can be implemented by the terminal device and the server in the above system architecture through interaction.

[0062] Figure 2 Shows a schematic diagram of a method for protecting user identity information in a related art provided by an embodiment of the present disclosure. Combining Figure 2 As shown, taking the network side as the 5G core network as an example, the user terminal includes a Universal Subscriber Identity Module (UIM). The UIM card and the 5G core network respectively generate a pair of long-term public and private keys using their own Elliptic Curve Cryptography (ECC) algorithms. Among them, the public key can be made public, and the private key is secretly stored by itself.

[0063] The user terminal and the 5G core network negotiate a shared key (i.e., a symmetric key) based on the long-term public and private keys using the Elliptic Curve Diffie-Hellman Key Exchange (ECDH) algorithm. Specifically, the user terminal calculates using its own long-term private key and the long-term public key of the core network side, and the core network side calculates using its own long-term private key and the long-term public key of the user terminal. Through the elliptic curve discrete logarithm problem, the user terminal and the core network side can finally obtain the same symmetric key (i.e., the shared key). This shared key can be used for operations such as data encryption and decryption in subsequent communications. The terminal side and the core network side encrypt the Subscription Permanent Identifier (SUPI) of the user based on the shared key and then transmit it. In this way, even if the data is intercepted, it cannot be decrypted to obtain the SUPI without the shared key, thereby preventing it from being illegally stolen. However, the long-term static ECC public key is at risk of being cracked by a quantum computer, and the data encrypted based on this ECC public key may be decrypted, and related security mechanisms such as identity authentication will be damaged, resulting in the SUPI no longer being secure.

[0064] Figure 3 Shows a flowchart of a method for protecting user identity information in an embodiment of the present disclosure, which is applied to a terminal. AsFigure 3 As shown, the user identity information protection method provided in the embodiments of the present disclosure includes the following steps:

[0065] S302, in response to an identity registration request of the terminal, select a target protection strategy from multiple information protection strategies.

[0066] In this embodiment, the identity registration request refers to a signal sent by a terminal (such as a mobile phone, a tablet computer, etc.) to a relevant system to indicate its own identity and request registration, so as to obtain corresponding services or permissions in the system. The information protection strategy is a set of rules and methods for protecting information security, and there are multiple strategies available here. The target protection strategy is a specific strategy selected from multiple information protection strategies for the operations related to this identity registration. The target protection strategy uses a key negotiation algorithm and / or a quantum key algorithm to generate a shared key between the terminal and the network side, and the strategy information of the target protection strategy includes: the identifier of the target protection strategy and the corresponding parameters.

[0067] Specifically, the key negotiation algorithm is an algorithm that allows two communicating parties to negotiate a shared key in an insecure network environment. For example, in the ECDH key negotiation algorithm, both parties each have a public-private key pair on an elliptic curve. The two parties exchange their public keys. One party performs a specific calculation using its own private key and the other party's public key, and the other party does the same operation, and finally obtains the same shared key. The quantum key algorithm is a key distribution algorithm based on the principles of quantum mechanics. It utilizes the characteristics of quantum states, such as the no-cloning theorem of quantum. The sender encodes the information on the quantum state and sends it to the receiver. Due to the special nature of the quantum state, any eavesdropping will change the quantum state and thus be detected.

[0068] Table 1 shows a schematic table of multiple information protection strategies provided in the embodiments of the present disclosure.

[0069] Table 1

[0070] Identification Shared key source A ECDH key agreement algorithm B Quantum key algorithm C ECDH key agreement algorithm ⊕ Quantum key algorithm

[0071] Combined with Table 1, the identifiers of the information protection strategies can be A, B, and C. Among them, information protection strategy A is the ECDH key negotiation algorithm, information protection strategy B is the quantum key algorithm, and information protection strategy C is a combination of using the ECDH key negotiation algorithm and the quantum key algorithm. The ECDH key negotiation algorithm can generate a shared key through key negotiation; the quantum key algorithm utilizes quantum characteristics and can pre-inject quantum keys as shared keys; the combination of the ECDH key negotiation algorithm and the quantum key algorithm can perform an exclusive OR operation on the key negotiated by the ECDH key negotiation algorithm and the pre-injected quantum key for combination.

[0072] In some embodiments, when the target protection policy includes a quantum key algorithm, the parameters corresponding to the target protection policy include the quantum key identifier corresponding to the quantum key.

[0073] In this embodiment, when the target protection policy includes a quantum key algorithm, the UIM card or USIM card of the terminal is pre-filled with quantum keys, and each quantum key has its unique identifier. The quantum key identifier is an identification mark for the quantum key, used to accurately distinguish a specific quantum key among many quantum keys, so as to correctly call and use the corresponding quantum key during encryption, decryption operations, or key management processes.

[0074] Table 2 shows another schematic table of multiple information protection policies provided by the embodiments of the present disclosure.

[0075] Table 2

[0076] Identification Shared key source Quantum key identification A ECDH key agreement algorithm B Quantum key algorithm QKID1 C ECDH key agreement algorithm ⊕ Quantum key algorithm QKID2

[0077] As shown in conjunction with Table 2, when the target protection policy includes a quantum key algorithm, for example, the information protection policy B is a quantum key algorithm, and the corresponding quantum key identifier is QKID1; the information protection policy C is a combination of using the ECDH key negotiation algorithm and the quantum key algorithm, and the corresponding quantum key identifier is QKID2.

[0078] S304, generate a first shared key based on the target protection policy, and use the first shared key to encrypt the plaintext user identity information of the terminal to obtain encrypted user identity information.

[0079] In this embodiment, the first shared key is a key generated by the user terminal based on the target protection policy. The plaintext user identity information is the original, unencrypted user identity information. For example, SUPI, which is the true identity identifier of the user terminal in the network, exists in plaintext form when not encrypted and is easily stolen or tampered with. The encrypted user identity information is the result obtained by encrypting the plaintext user identity information (such as SUPI) using the first shared key, such as SUCI. SUCI is a ciphertext form, which increases the security of the identity information and prevents the real identity from being easily obtained when the information is leaked.

[0080] Specifically, generating a first shared key based on the target protection policy and encrypting the plaintext user identity information of the terminal using the first shared key to obtain the encrypted user identity information specifically includes: deriving a confidentiality key and an integrity key from the first shared key, and performing an encryption calculation on the plaintext user identity information of the terminal using the confidentiality key and the integrity key to obtain the encrypted user identity information. Among them, the confidentiality key is used to ensure information confidentiality and prevent information leakage; the integrity key is used to ensure that the information has not been tampered with. The confidentiality key converts the plaintext into ciphertext through a specific encryption algorithm, making the information content difficult to understand; the integrity key adds verification information to the encryption process or result to ensure that the encrypted identity information has not been modified during transmission or storage, and finally obtains the encrypted user identity information.

[0081] S306. Send the encrypted user identity information, the identifier of the target protection policy, and the corresponding parameters to the network side, so that the network side generates a second shared key based on the identifier of the target protection policy and the corresponding parameters, and decrypts the encrypted user identity information using the second shared key to obtain the plaintext user identity information.

[0082] In this embodiment, the identifier of the target protection policy is used to distinguish different protection policies, and the parameters corresponding to the target protection policy are values or conditions that specifically define how the policy is implemented, etc. The network side can generate a second shared key according to the identifier of the target protection policy and the corresponding parameters. The second shared key is a key generated according to the relevant content of the target protection policy, and is specifically used for decrypting the encrypted user identity information. The second shared key is the same as the first shared key. The network side refers to a network-related server or management system, etc., which is responsible for receiving information, generating keys, and decrypting operations in this process.

[0083] In this embodiment, a hybrid mode combining traditional key negotiation algorithms and quantum key distribution is adopted. While reducing the high-frequency dependence on quantum keys, quantum keys are used to enhance the security of key links, avoiding global identity leakage caused by the cracking of a single static key. Secondly, through the policy dynamic adaptation mechanism, the terminal and the network side can generate short-term shared keys in real-time synchronization based on the policy identifier and parameters, eliminating the existence of long-term static keys and restricting the attack window through the key timeliness, significantly enhancing the anti-quantum attack ability.

[0084] In some embodiments, there are multiple possible ways to obtain quantum keys. Generally speaking, quantum keys are stored in the user identification module. It should be noted that the user identification module can be integrated into the terminal or separately set on the user identification module card. The user identification module card can be installed on the terminal. The user identification module card can be a UIM card or a USIM card. Therefore, when the terminal includes a user identification module card, before selecting a target protection strategy from multiple information protection strategies, it further includes: in response to injecting quantum keys into the user identification module card, storing the quantum keys in the user identification module card; or, in response to the user identification module card connecting to the quantum key distribution network through a quantum communication channel, obtaining quantum keys from the quantum key distribution network and storing the quantum keys in the user identification module card; wherein, the user identification module card is used to generate corresponding quantum key identifiers for each received quantum key.

[0085] In some embodiments, there are multiple possible implementation ways to select a target protection strategy from multiple information protection strategies. For example, considering that some terminals do not have quantum key-related functions, if a target protection strategy is selected, only those that the terminal can support can be considered, which is due to hardware capability limitations. Another example is that considering the limited quantum keys, such as when the available quantum keys are 0, the protection strategy without the quantum key algorithm becomes the first choice because relevant algorithms cannot be used without quantum keys. Still another example is that there may be a preset default priority in the terminal, and the target protection strategy is selected according to this established order. Further, in order to flexibly respond to different requirements and scenarios, the priority of selecting the target protection strategy can be set artificially, so that a suitable target protection strategy can be quickly determined under different conditions.

[0086] In some embodiments, Figure 4 The flowchart of a method for selecting a target protection strategy provided by an embodiment of the present disclosure is shown. Combining Figure 4 as shown, the method for selecting a target protection strategy provided by an embodiment of the present disclosure includes the following steps:

[0087] S402, obtain the configuration information of the terminal, where the configuration information is used to indicate the priority of the information protection strategies supported by the terminal.

[0088] In this embodiment, due to different hardware configurations of the terminal, such as different processor performances and memory sizes. The hardware conditions affect the information protection strategy because a terminal with low hardware performance is difficult to support complex encryption strategies. For example, some terminals do not have quantum key functions. When selecting a target protection strategy, it is necessary to consider the strategies that the terminal can support based on the terminal configuration information, which is restricted by the hardware capabilities. That is to say, the terminal hardware configuration determines which information protection strategies it can adapt to, and obtaining the configuration information is to determine this adaptation relationship so as to reasonably select the protection strategy.

[0089] S404. Select a target protection policy from multiple information protection policies according to the priority of the information protection policy supported by the terminal.

[0090] In this embodiment, by adding multiple information protection policies, reasonably selecting the target protection policy can ensure the information security of the terminal, adapt to the hardware conditions, and avoid the situation that the terminal runs poorly due to problems such as too high policies. It can realize the transition from 5G SUPI protection to anti-quantum computing. At the same time, it solves the risk of SUPI encryption unavailability caused by insufficient quantum keys.

[0091] In some embodiments, Figure 5 The flowchart of another method for selecting a target protection policy provided by an embodiment of the present disclosure is shown. Combining Figure 5 As shown, the method for selecting a target protection policy provided by an embodiment of the present disclosure includes the following steps:

[0092] S502. Obtain the remaining amount of the quantum key stored in the user identification module card.

[0093] S504. When the remaining amount of the quantum key stored in the user identification module card is less than or equal to a preset threshold, determine the key negotiation algorithm as the target protection policy among multiple information protection policies.

[0094] In this embodiment, since the quantum key is limited, the preset threshold is a pre-set quantity standard used to measure the boundary of the remaining amount of the quantum key. For example, when the remaining amount of the quantum key is 0, the key negotiation algorithm is selected from multiple information protection policies as the current target protection policy.

[0095] In this embodiment, due to the limited quantum key, when the remaining amount is greater than the preset threshold, there are more available keys, and an information protection policy including the quantum key can be adopted; when the remaining amount is less than or equal to the threshold, the key negotiation algorithm is selected as the target protection policy, which can ensure that there is still a suitable protection policy under the condition of limited quantum key resources and guarantee information security.

[0096] In some embodiments, when the target protection strategy is a key agreement algorithm and a quantum key algorithm, the key negotiated by the key agreement algorithm can be combined with the pre-filled quantum key by an XOR operation, and the XOR operation is a bit operation. In binary, for two corresponding binary bits, if they are the same, they are 0, and if they are different, they are 1. For example, the binary numbers 1010 and 1100 are XORed, and the result is 0 if the first bit 1 and 1 are the same, and the result is 1 if the second bit 0 and 1 are different, and so on to get the result 0110. Combining the key negotiated by the key agreement algorithm with the pre-filled quantum key by an XOR operation is to use the characteristics of XOR to fuse the two keys. Doing so can increase the complexity and security of the key to a certain extent, change the original structure of the key, and make it difficult for a single key to be cracked or analyze the characteristics of the combined key.

[0097] It should be noted that there are many possible ways to implement the XOR operation between the key negotiated by the key agreement algorithm and the pre-filled quantum key. For example, when the key negotiated by the key agreement algorithm is the same length as the pre-filled quantum key, the XOR value can be obtained by bit-by-bit XOR. For another example, when the key negotiated by the key agreement algorithm is different in length from the pre-filled quantum key, part of the key can be intercepted from the longer party and bit-by-bit XORed with the shorter party to obtain the XOR value, where there are many possible ways to intercept part of the key from the longer party, such as intercepting from the beginning or intercepting from a specified number of bits. For example, when the key negotiated by the key agreement algorithm is different from the length of the pre-filled quantum key, the shorter length can be filled with zeros and XORed bit by bit with the key of the longer length to obtain an XOR value, wherein there are multiple possible implementations of the zero-filling operation on the shorter length, such as forward filling, adding zeros to the front of the shorter sequence to make its length consistent with the longer sequence, or backward filling: adding zeros to the back of the shorter sequence, or interpolation filling, inserting zeros in the middle of the sequence according to specific rules. It can be understood that the above multiple XOR operation rules can be pre-stored on the terminal and the network side, and both parties pre-set the same XOR operation rules. When the key negotiated by the key agreement algorithm is XORed with the pre-filled quantum key, both parties can perform the XOR operation according to the pre-set XOR operation rules.

[0098] In some embodiments, to further enhance the security of the secret key, the two parties may not pre-set a specific XOR operation rule, but instead select an XOR operation rule from multiple XOR operation rules. The XOR operation rule may specifically include an XOR identifier and XOR parameters, where the XOR parameters are used to indicate the way of interception or padding. Therefore, when the target protection policy is a key agreement algorithm and a quantum key algorithm, the parameters corresponding to the target protection policy further include the XOR identifier of the key agreement algorithm and the quantum key algorithm, and the XOR identifier is used to indicate the XOR algorithm of the key agreement algorithm and the quantum key algorithm. Figure 6 The flowchart of a method for generating a first shared key provided by an embodiment of the present disclosure is shown. In combination with Figure 6 As shown, the method for generating a first shared key provided by an embodiment of the present disclosure includes the following steps:

[0099] S602, determine the target quantum key according to the quantum key identifier in the parameters corresponding to the target protection policy.

[0100] In this embodiment, the quantum key identifier is a tag used to identify a specific quantum key. In the user identification module of the terminal, there are multiple quantum keys, and the quantum key identifier can accurately point to the target quantum key. The target quantum key is a specific quantum key determined according to the quantum key identifier.

[0101] S604, determine the target XOR algorithm according to the XOR identifier in the parameters corresponding to the target protection policy.

[0102] The XOR identifier is a tag indicating a specific XOR algorithm. The target XOR algorithm is the XOR algorithm for data processing determined according to the XOR identifier. The XOR operation is often used for data encryption, obfuscation, etc., and participates in the generation of the shared key together with the quantum key here.

[0103] S606, generate a first shared key according to the key agreement algorithm, the target quantum key, and the target XOR algorithm.

[0104] In this embodiment, the terminal obtains a public key and a private key through the key agreement algorithm. The private key obtained by the terminal through the key agreement algorithm is a random number, and the public key obtained by the terminal through the key agreement algorithm is calculated from the private key obtained by the terminal through the key agreement algorithm. The public key obtained by the terminal through the key agreement algorithm is XOR-calculated with the target quantum key through the target XOR algorithm to obtain a target XOR value, that is, a first shared key is generated.

[0105] In this embodiment, by combining the key agreement result, the target quantum key, and a specific XOR algorithm to generate a shared key, the security of the key is improved.

[0106] Based on the same inventive concept, Figure 7Disclosed is a method for protecting user identity information provided by an embodiment of the present disclosure, which is applied to the network side. The method for protecting user identity information provided by the embodiment of the present disclosure includes the following steps:

[0107] S702: In response to an identity registration request from a terminal, obtain the encrypted user identity information, the identifier of the target protection policy, and the corresponding parameters sent by the terminal.

[0108] In this embodiment, the encrypted user identity information is obtained by encrypting the plaintext user identity information of the terminal using a first shared key. The first shared key is generated based on the parameters corresponding to the target protection policy, and the target protection policy is selected from multiple information protection policies.

[0109] S704: Generate a second shared key based on the identifier of the target protection policy and the corresponding parameters.

[0110] In this embodiment, multiple target protection policies can be pre-stored on the network side, which are the same as the target protection policies stored on the terminal. The multiple target protection policies pre-stored on the network side include the identifier of the target protection policy and the corresponding parameters, where the corresponding parameters may specifically include a quantum key identifier and an exclusive OR identifier. In some embodiments, generating a second shared key based on the identifier of the target protection policy and the corresponding parameters specifically includes: determining the target protection policy based on the identifier of the target protection policy and the corresponding parameters; generating a second shared key using the target protection policy. The process of generating a second shared key using the target protection policy is similar to the process of generating a first shared key using the target protection policy, and will not be elaborated here. It should be noted that the second shared key and the first shared key on the network side are the same.

[0111] S706: Decrypt the encrypted user identity information using the second shared key to obtain the plaintext user identity information of the terminal.

[0112] In this embodiment, the encrypted user identity information is encrypted by the terminal using the first shared key, and the second shared key and the first shared key are the same. Therefore, the network side can decrypt the encrypted user identity information using the second shared key to obtain the plaintext user identity information of the terminal.

[0113] In some embodiments, the method for protecting user identity information provided by the present disclosure further includes: querying the subscription data of the terminal according to the plaintext user identity information of the terminal, and selecting an authentication method; triggering an authentication operation of the terminal based on the subscription data and the authentication method.

[0114] In some embodiments, the authentication of the terminal can be implemented through the AKA (Authentication and Key Agreement) process. AKA is an authentication and key management process, including but not limited to the following authentication methods: 5G-AKA (5G Authentication and Key Management), EAP-AKA (Extensible Authentication Protocol, Authentication and Key Management), and EAP-TLS (Extensible Authentication Protocol, Transport Layer Security).

[0115] Specifically, as an authentication method, it includes: the UDM / ARPF shall create a 5G HE AV (5G Authentication Vector) and return it to the AUSF. The AUSF calculates the 5G AV and the expected corresponding hash value HXRES from the 5G HE AV received from the UDM / ARPF. The AUSF returns the 5G SE AV (5G Session and Service Authentication Vector) to the SEAF (Security Anchor Function). The SEAF sends parameters such as RAND and AUTN to the UE in the NAS message authentication request. When receiving RAND and AUTN, the USIM verifies the freshness of the 5G AV by checking whether AUTN can be accepted. The USIM calculates a response RES, and the USIM returns RES, CK, and IK to the ME. The UE returns RES to the SEAF in the NAS message authentication response. The SEAF then calculates HRES and compares HRES with HXRES. If they are consistent, the authentication can be regarded as successful.

[0116] In some embodiments, Figure 8 The schematic diagram shows a method for protecting user identity information provided by an embodiment of the present disclosure. Combining Figure 8 As shown, taking the 5G core network as the network side as an example, the user terminal includes a UIM card. The user terminal injects a quantum key through a key injection machine in the operator's business hall and generates a quantum key identifier. Among them, the quantum key in the key injection machine is distributed by the key distribution node of the quantum key distribution QKD network. The 5G core network also obtains the quantum key through the key distribution node of the quantum key distribution QKD network and generates a quantum key identifier. At the same time, the terminal and the 5G core network generate a SUPI information protection strategy (that is, the generation method of the shared key: generated by the ECDH key negotiation algorithm, using the injected quantum key, or generated by the exclusive OR of the symmetric key of the ECDH key negotiation algorithm and the quantum key). In response to the identity registration request of the user terminal, the user terminal selects a target protection strategy and sends the identifier of the target protection strategy to the 5G core network. After receiving the identifier of the target protection strategy sent by the user terminal, the 5G core network determines the target protection strategy based on the identifier of the target protection strategy, generates a shared key, and then realizes the encrypted transmission of the SUPI.

[0117] In this embodiment, not only is the one-time one-time encryption of the SUPI achieved, but also attacks by quantum computing can be resisted. At the same time, the problem that SUPI encryption cannot be performed due to insufficient quantum keys is solved.

[0118] In some embodiments, Figure 9 FIG. shows a schematic diagram of the system architecture of a user identity information protection method provided by an embodiment of the present disclosure. Combining Figure 9 As shown, taking the 5G core network as an example of the network side, the system may include a user equipment UE 1, a Next Generation Node B (gNB) 2, and a 5G core network 3. Among them, UE 1 includes a Universal Subscriber Identity Module (USIM) and a Mobile Equipment (ME). The ME / USIM card includes a policy storage and selection module 11, a first shared key generation module 12, and an encryption module 13; the 5G core network 3 includes a UDM network element, and the UDM network element includes a policy recognition and storage module 31, a second shared key generation module 32, and a SUPI decryption module 33; the gNB is a key device in the 5G network and is responsible for providing wireless access services for 5G terminals (such as 5G mobile phones, etc.). The gNB realizes high-speed data transmission through new radio access technology, and processes uplink and downlink signals, including operations such as modulation, coding, demodulation, and decoding, to ensure that signals are accurately transmitted between the terminal and the core network. The gNB is connected to the 5G core network through a backhaul link, transfers the data of the terminal to the core network for further processing, such as routing to the Internet or other network services, and allocates wireless resources for the terminal, such as frequency bands, power, etc., to meet the needs of different terminals and ensure the overall performance of the network.

[0119] Specifically, a large number of quantum keys and quantum key identifiers are filled in the USIM card through the business hall (the keys can be refilled at the business hall when used up). At the same time, the UE stores multiple information protection strategies. The multiple information protection strategies are mainly the generation methods of shared keys: generating a shared key using the standard Elliptic Curve Diffie-Hellman (ECDH) key agreement algorithm, using the filled quantum keys, or using the exclusive OR value of the shared key generated by the ECDH key agreement algorithm and the quantum keys. During the registration process initiated by the UE, the UE selects a target protection strategy from the multiple information protection strategies stored in the policy storage and selection module 11, and then uses the first shared key generation module 12 to generate a first shared key based on the target protection strategy. The encryption module 13 encrypts the SUPI of the terminal using the first shared key to obtain a SUCI, and sends it to the 5G core network through a registration request message (the registration request message includes the identifier of the target protection strategy, and if quantum keys are used, the quantum key identifier needs to be carried).

[0120] The 5G core network obtains a large number of quantum keys and quantum key identifiers through the quantum key distribution (QKD) network key distribution nodes. In the UDM network element, the mark of the target protection policy and the quantum key identifier information are obtained from the registration request message sent by the UE. The policy recognition and storage module 31 determines the target protection policy based on the identifier of the target protection policy and the corresponding parameters. If a quantum key is used, the corresponding quantum key is retrieved based on the quantum key identifier. Then, the second shared key generation module 32 generates a second shared key based on the target protection policy. The SUPI decryption module 33 decrypts the SUCI using the same algorithm and shared key as the UE to obtain the SUPI.

[0121] In some embodiments, Figure 10 A signaling diagram showing a method for protecting user identity information provided by an embodiment of the present disclosure is presented. In combination with Figure 10 As shown, as a method for protecting user identity information, it includes: The UE pre-fills a large number of quantum key machine key identifiers, selects a SUPI target protection policy from multiple information protection policies, generates a first shared key based on the target protection policy. The target protection policy uses a key negotiation algorithm and / or a quantum key algorithm to generate a shared key between the terminal and the network side. The policy information of the target protection policy includes: the identifier of the target protection policy and the corresponding parameters; Derive a first confidentiality key and a first integrity key using the first shared key, and encrypt the SUPI of the UE using the first confidentiality key and the first integrity key to generate a SUCI; Create an initial registration request and send it to the AFM / SEAF. The AFM / SEAF sends the initial registration request to the AUSF, and the AUSF sends the initial registration request to the UDM / ARPF. Among them, the initial registration request includes the SUCI, the identifier of the SUPI target protection policy, and the corresponding parameters. If a quantum key is used, the corresponding parameter is the quantum key identifier. A large number of quantum key machine key identifiers are pre-obtained in the UDM / ARPF. After receiving the initial registration request, the UDM / ARPF uses the identifier of the SUPI target protection policy and the corresponding parameters carried in the initial registration request to identify the SUPI target protection policy, and then generates a second shared key based on the SUPI target protection policy. Among them, the target protection policy uses a key negotiation algorithm and / or a quantum key algorithm to generate a shared key between the terminal and the network side. Then, generate a second confidentiality key and a second integrity key using the second shared key, and decrypt to generate the SUPI. Further, the UDM / ARPF queries the subscription data based on the SUPI and selects an authentication method, and then triggers the AKA authentication. By executing the AKA authentication process, if the AKA authentication is successful, a UE registration success message is returned.

[0122] Based on the same inventive concept, an embodiment of the present disclosure also provides a user identity information protection device as described in the following embodiments. Since the principle of problem-solving in this device embodiment is similar to that of the above method embodiment, the implementation of this device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be elaborated again.

[0123] Figure 11 The following shows a schematic diagram of a user identity information protection device in an embodiment of the present disclosure, as Figure 11 shown, the device includes: a selection module 111, a first generation module 112, and a sending module 113.

[0124] The selection module 111 is configured to select a target protection policy from multiple information protection policies in response to an identity registration request of the terminal. Among them, the target protection policy generates a shared key between the terminal and the network side by using a key negotiation algorithm and / or a quantum key algorithm, and the policy information of the target protection policy includes: the identifier of the target protection policy and the corresponding parameters; the first generation module 112 is configured to generate a first shared key based on the target protection policy, and encrypt the plaintext user identity information of the terminal by using the first shared key to obtain encrypted user identity information; the sending module 113 is configured to send the encrypted user identity information, the identifier of the target protection policy, and the corresponding parameters to the network side, so that the network side generates a second shared key based on the identifier of the target protection policy and the corresponding parameters, and decrypts the encrypted user identity information by using the second shared key to obtain the plaintext user identity information.

[0125] In some embodiments, when the terminal includes a user identification module card, the selection module 111 is further configured to: in response to filling the user identification module card with a quantum key, store the quantum key in the user identification module card; or, in response to the user identification module card being connected to a quantum key distribution network through a quantum communication channel, obtain a quantum key from the quantum key distribution network and store the quantum key in the user identification module card; wherein, the user identification module card is used to generate a corresponding quantum key identifier for each received quantum key.

[0126] In some embodiments, the selection module 111 is further configured to: obtain configuration information of the terminal, where the configuration information is used to indicate the priority of information protection policies supported by the terminal; the selection module 111 is configured to: select a target protection policy from multiple information protection policies according to the priority of information protection policies supported by the terminal.

[0127] In some embodiments, the selection module 111 is further configured to: obtain the remaining amount of the quantum key stored in the user identification module card; the selection module 111 is configured to: when the remaining amount of the quantum key stored in the user identification module card is less than or equal to a preset threshold, determine the key negotiation algorithm as the target protection policy among the multiple information protection policies.

[0128] In some embodiments, when the target protection policy includes a quantum key algorithm, the parameters corresponding to the target protection policy include the quantum key identifier corresponding to the quantum key.

[0129] In some embodiments, when the target protection policy is a key negotiation algorithm and a quantum key algorithm, the parameters corresponding to the target protection policy further include the exclusive OR identifier of the key negotiation algorithm and the quantum key algorithm, and the exclusive OR identifier is used to indicate the exclusive OR algorithm of the key negotiation algorithm and the quantum key algorithm; the first generation module 112 is configured to: determine the target quantum key according to the quantum key identifier in the parameters corresponding to the target protection policy; determine the target exclusive OR algorithm according to the exclusive OR identifier in the parameters corresponding to the target protection policy; generate a first shared key according to the key negotiation algorithm, the target quantum key, and the target exclusive OR algorithm.

[0130] In some embodiments, the first generation module 112 is configured to: generate a first confidentiality key and a first integrity key by using the first shared key; encrypt the plaintext user identity information of the terminal based on the first confidentiality key and the first integrity key to obtain the encrypted user identity information.

[0131] Figure 12 FIG. shows a schematic diagram of a user identity information protection device according to an embodiment of the present disclosure, as Figure 12 shown, the device includes: an acquisition module 121, a second generation module 122, and a decryption module 123.

[0132] The acquisition module 121 is configured to, in response to an identity registration request of the terminal, obtain the encrypted user identity information, the identifier of the target protection policy, and the corresponding parameters sent by the terminal, where the encrypted user identity information is obtained by encrypting the plaintext user identity information of the terminal by using the first shared key, the first shared key is generated based on the parameters corresponding to the target protection policy, and the target protection policy is selected from multiple information protection policies; the second generation module 122 is configured to generate a second shared key based on the identifier of the target protection policy and the corresponding parameters; the decryption module 123 is configured to decrypt the encrypted user identity information by using the second shared key to obtain the plaintext user identity information of the terminal.

[0133] In some embodiments, the second generation module 122 is configured to determine a target protection policy based on the identifier and corresponding parameters of the target protection policy; generate a second shared key by using the target protection policy; and decrypt the encrypted user identity information by using the second shared key to obtain the plaintext user identity information of the terminal, including: generating a second confidentiality key by using the second shared key; and decrypting the encrypted user identity information based on the second confidentiality key to obtain the plaintext user identity information of the terminal.

[0134] In some embodiments, the apparatus further includes an authentication module configured to: query the subscription data of the terminal according to the plaintext user identity information of the terminal, and select an authentication method; and trigger an authentication operation of the terminal based on the subscription data and the authentication method.

[0135] It should be noted here that the examples and application scenarios implemented by each module in the above apparatus embodiments are the same as the corresponding steps in the method embodiments, but are not limited to the content disclosed in the above method embodiments. It should be noted that the above modules, as a part of the apparatus, can be executed in a computer system such as a set of computer executable instructions.

[0136] Those skilled in the art can understand that various aspects of the present disclosure can be specifically implemented in the following forms, that is: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module" or "system" here.

[0137] Based on the same inventive concept, an electronic device is further provided in the embodiments of the present disclosure. The electronic device includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the user identity information protection method of any one of the above via executing the executable instructions. Since the principle of solving problems in the embodiment of this electronic device is similar to that in the above method embodiment, the implementation of the embodiment of this electronic device can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0138] Next, refer to Figure 13 to describe the electronic device 1300 according to this embodiment of the present disclosure. Figure 13 The shown electronic device 1300 is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present disclosure.

[0139] As Figure 13As shown, the electronic device 1300 is presented in the form of a general-purpose computing device. The components of the electronic device 1300 may include, but are not limited to: at least one of the above-mentioned processing units 1310, at least one of the above-mentioned storage units 1320, and a bus 1330 that connects different system components (including the storage unit 1320 and the processing unit 1310).

[0140] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 1310, so that the processing unit 1310 executes the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Method" section of this specification. For example, the processing unit 1310 may execute the following steps of the above method embodiment: in response to an identity registration request of the terminal, select a target protection policy from multiple information protection policies, where the target protection policy uses a key negotiation algorithm and / or a quantum key algorithm to generate a shared key between the terminal and the network side, and the policy information of the target protection policy includes: the identifier of the target protection policy and the corresponding parameters; generate a first shared key based on the target protection policy, and use the first shared key to encrypt the plaintext user identity information of the terminal to obtain encrypted user identity information; send the encrypted user identity information, the identifier of the target protection policy and the corresponding parameters to the network side, so that the network side generates a second shared key based on the identifier of the target protection policy and the corresponding parameters, and uses the second shared key to decrypt the encrypted user identity information to obtain the plaintext user identity information.

[0141] The storage unit 1320 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 13201 and / or a cache storage unit 13202, and may further include a read-only storage unit (ROM) 13203.

[0142] The storage unit 1320 may also include a program / utilities 13204 having a set (at least one) of program modules 13205. Such program modules 13205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0143] The bus 1330 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of the various bus structures.

[0144] The electronic device 1300 can also communicate with one or more external devices 1340 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 1300, and / or communicate with any device that enables the electronic device 1300 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 1350. Moreover, the electronic device 1300 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 1360. As shown in the figure, the network adapter 1360 communicates with other modules of the electronic device 1300 through the bus 1330. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 1300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0145] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or can be implemented by the way of software in combination with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0146] Based on the same inventive concept, an embodiment of the present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the user identity information protection method of any one of the above. Since the principle of solving problems in this embodiment of the computer-readable storage medium is similar to that of the above method embodiment, the implementation of this embodiment of the computer-readable storage medium can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0147] More specific examples of the computer-readable storage medium in the present disclosure can include but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0148] In the present disclosure, a computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0149] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination of the above.

[0150] In specific implementations, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0151] Based on the same inventive concept, embodiments of the present disclosure also provide a computer program product, including: a computer program or instruction, which when executed by a processor implements the user identity information protection method in any one of the above method embodiments. Since the principle of solving problems in this computer program product embodiment is similar to that of the above method embodiments, the implementation of this computer program product embodiment can refer to the implementation of the above method embodiments, and the repeated parts will not be described again.

[0152] It should be noted that although several modules or units of a device for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the above-mentioned modules or units may be embodied in one module or unit. Conversely, the features and functions of one module or unit described above may be further divided and embodied by multiple modules or units.

[0153] In addition, although the various steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in that specific order, or that all of the steps shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.

[0154] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the methods according to the embodiments of the present disclosure.

[0155] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed by the present disclosure. The specification and examples are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.

Claims

1. A method for protecting user identity information, characterized in that: Applied to a terminal, the method comprises: In response to the identity registration request of the terminal, a target protection policy is selected from a plurality of information protection policies, wherein the target protection policy uses a key agreement algorithm and / or a quantum key algorithm to generate a shared key between the terminal and the network side, and the policy information of the target protection policy includes: an identifier of the target protection policy and corresponding parameters; Generate a first shared key based on the target protection strategy, and use the first shared key to encrypt the plaintext user identity information of the terminal to obtain encrypted user identity information; The encrypted user identity information, the identifier of the target protection policy and the corresponding parameters are sent to the network side, so that the network side generates a second shared key based on the identifier of the target protection policy and the corresponding parameters, and uses the second shared key to decrypt the encrypted user identity information to obtain the plaintext user identity information.

2. The user identity information protection method according to claim 1, characterized in that: When the terminal includes a user identification module card, before selecting a target protection strategy from a plurality of information protection strategies, the method further includes: In response to injecting the quantum key into the subscriber identity module card, storing the quantum key in the subscriber identity module card; or, In response to the subscriber identity module card being connected to a quantum key distribution network through a quantum communication channel, obtaining a quantum key from the quantum key distribution network and storing the quantum key in the subscriber identity module card; The user identification module card is used to generate a corresponding quantum key identifier for each received quantum key.

3. The user identity information protection method according to claim 1, characterized in that: Before selecting a target protection strategy from a plurality of information protection strategies, the method further includes: Acquire configuration information of the terminal, where the configuration information is used to indicate the priority of information protection policies supported by the terminal; The selecting a target protection strategy from a plurality of information protection strategies includes: A target protection policy is selected from a plurality of information protection policies according to the priorities of the information protection policies supported by the terminal.

4. The user identity information protection method according to claim 2, characterized in that: Before selecting a target protection strategy from a plurality of information protection strategies, the method further includes: Obtaining the remaining amount of the quantum key stored in the user identification module card; The selecting a target protection strategy from a plurality of information protection strategies includes: When the remaining amount of the quantum key stored in the user identification module card is less than or equal to a preset threshold, a key agreement algorithm is determined as a target protection strategy among the multiple information protection strategies.

5. The user identity information protection method according to claim 1, characterized in that: When the target protection strategy includes a quantum key algorithm, the parameters corresponding to the target protection strategy include a quantum key identifier corresponding to the quantum key.

6. The user identity information protection method according to claim 5, characterized in that: When the target protection strategy is a key agreement algorithm and a quantum key algorithm, the parameter corresponding to the target protection strategy further includes an XOR identifier of the key agreement algorithm and the quantum key algorithm, where the XOR identifier is used to indicate the XOR algorithm of the key agreement algorithm and the quantum key algorithm; The generating a first shared key based on the target protection strategy includes: Determine the target quantum key according to the quantum key identifier in the parameter corresponding to the target protection strategy; Determine a target XOR algorithm according to the XOR identifier in the parameter corresponding to the target protection strategy; A first shared key is generated according to the key agreement algorithm, the target quantum key and the target XOR algorithm, where the first shared key is used to generate a first confidentiality key and a first integrity key.

7. A method for protecting user identity information, characterized in that: Applied to the network side, the method includes: In response to an identity registration request of a terminal, obtaining encrypted user identity information, an identifier of a target protection policy, and corresponding parameters sent by the terminal, wherein the encrypted user identity information is obtained by encrypting plaintext user identity information of the terminal using a first shared key, the first shared key is generated based on parameters corresponding to the target protection policy, and the target protection policy is selected from a plurality of information protection policies; Generate a second shared key based on the identifier of the target protection policy and corresponding parameters; The encrypted user identity information is decrypted using the second shared key to obtain the plaintext user identity information of the terminal.

8. The user identity information protection method according to claim 7, characterized in that: The generating a second shared key based on the identifier of the target protection policy and the corresponding parameters includes: Determining a target protection strategy based on an identifier of the target protection strategy and corresponding parameters; generating a second shared key using the target protection strategy; The decrypting the encrypted user identity information by using the second shared key to obtain the plaintext user identity information of the terminal includes: generating a second confidentiality key using the second shared key; The encrypted user identity information is decrypted based on the second confidentiality key to obtain the plaintext user identity information of the terminal.

9. The user identity information protection method according to claim 7, characterized in that: The method further comprises: Query the contract data of the terminal according to the plain text user identity information of the terminal, and select an authentication method; An authentication operation of the terminal is triggered based on the contract data and the authentication method.

10. A user identity information protection device, characterized in that: Applied to a terminal, the device comprises: A selection module, configured to select a target protection strategy from a plurality of information protection strategies in response to an identity registration request of the terminal, wherein the target protection strategy uses a key agreement algorithm and / or a quantum key algorithm to generate a shared key between the terminal and the network side, and the policy information of the target protection strategy includes: an identifier of the target protection strategy and corresponding parameters; A first generating module, configured to generate a first shared key based on the target protection policy, and encrypt the plaintext user identity information of the terminal using the first shared key to obtain encrypted user identity information; A sending module is used to send the encrypted user identity information, the identifier of the target protection policy and the corresponding parameters to the network side, so that the network side generates a second shared key based on the identifier of the target protection policy and the corresponding parameters, and uses the second shared key to decrypt the encrypted user identity information to obtain the plaintext user identity information.

11. A user identity information protection device, characterized in that: Applied to the network side, the device includes: an acquisition module, configured to, in response to an identity registration request of a terminal, acquire encrypted user identity information, an identifier of a target protection policy, and corresponding parameters sent by the terminal, wherein the encrypted user identity information is obtained by encrypting the plaintext user identity information of the terminal using a first shared key, the first shared key is generated based on parameters corresponding to the target protection policy, and the target protection policy is selected from a plurality of information protection policies; A second generating module, used to generate a second shared key based on the identifier of the target protection policy and corresponding parameters; The decryption module is used to decrypt the encrypted user identity information using the second shared key to obtain the plaintext user identity information of the terminal.

12. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to execute the user identity information protection method described in any one of claims 1 to 6 or the user identity information protection method described in any one of claims 7 to 9 by executing the executable instructions.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for protecting user identity information described in any one of claims 1 to 6 or the method for protecting user identity information described in any one of claims 7 to 9 is implemented.

14. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the user identity information protection method described in any one of claims 1 to 6 or the user identity information protection method described in any one of claims 7 to 9.

Citation Information

Cited By

  • User identity information protection method and apparatus, and related device

    WO2026179321A1