User network access safety protection method and device and related equipment

By using quantum keys to encrypt the mobile user identification code, and splicing it with the user's permanent identification information to generate the user's hidden identification code, the risk of the public key algorithm being cracked by quantum computers in the prior art is solved, and higher data security and privacy protection are achieved.

CN120128912APending Publication Date: 2025-06-10CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510265426.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The public key algorithm used in existing 5G networks encrypts the user's unique identity, which faces huge risks of being cracked by quantum computers and cannot effectively resist future quantum attacks.

Method used

The mobile user identification code is encrypted using quantum keys, and the ciphertext tag is generated, and then the user's permanent identification information is spliced ​​and combined with the ciphertext tag, generating the user's hidden identification code, and forwarding it to the core network device.

Benefits of technology

It significantly improves the security and privacy protection of user data, ensures the security of key transmission, and resists any computing attacks, and in theory, data security can be maintained in the future quantum computer era.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128912A_ABST
    Figure CN120128912A_ABST
Patent Text Reader

Abstract

The invention provides a user network access security protection method and device and related equipment, and relates to the technical field of network security, the method comprises the following steps: a network access registration request is sent, the network access registration request comprises user permanent identification information corresponding to target user equipment, the user permanent identification information comprises a mobile user identification code, and the mobile user identification code corresponds to the target user equipment; the quantum encryption protection scheme is used for indicating that the network access registration request is subjected to security protection in a quantum encryption mode; encrypting the mobile subscriber identification code according to a pre-obtained quantum key, and generating a ciphertext tag corresponding to the mobile subscriber identification code; and splicing and combining the user permanent identification information of the target user equipment and the ciphertext label to generate a user hidden identification code of the target user equipment, and forwarding the user hidden identification code to the core network equipment. According to the invention, the problem that encryption of the unique identity identifier of the user by using a public key algorithm is possibly cracked in the prior art can be overcome.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In the current 5G network, when a terminal initiates an access registration and initial authentication request to the 5G core network, it will carry a Subscription Permanent Identifier (SUPI) so that the 5G core network can identify the user's identity to complete the access verification. In previous generations before 5G, SUPI was transmitted in plain text. In 5G, in order to prevent SUPI from being illegally intercepted, a public key algorithm is introduced to encrypt SUPI to generate a Subscription Concealed Identifier (SUCI). After the SUCI is transmitted to the 5G core network, the Unified Data Management (UDM) in the 5G core network uses the public key algorithm to recover the SUPI to achieve user identity recognition.

[0003] The above security for SUPI protection depends on Elliptic Curve Cryptography (ECC), especially the security of the Elliptic Curve Diffie-Hellman (ECDH) protocol. However, the public key algorithm faces a huge risk of being "cracked" by quantum computers within the next decade. The SUPI protected by the public key algorithm will no longer be secure. In future 5G / 6G networks, a new SUPI encryption scheme is needed to resist quantum attacks and ensure the identity security of user access to the network.

[0004] The prior art encrypts the user's unique identity identifier using the public key algorithm in the standard to ensure user access security. As Figure 1 shown, the SUCI in the prior art consists of six parts, including a flag of the SUPI type, a home network identifier, a routing identifier, a protection scheme identifier, a public key identifier, and a protection scheme output. Only the protection scheme output contains the ciphertext result of the actual encryption of the Mobile Subscriber Identification Number (MSIN), and the other five parts are in plain text. As Figure 1 shown, the protection scheme provided in the current standard uses the ECC public key algorithm to encrypt and provide integrity protection for the MSIN. Then, the ECC public key, the encrypted MSIN ciphertext result, and the integrity protection value are used as the output of the protection scheme and become the sixth part of the SUCI structure.

[0005] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present disclosure. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0006] The present disclosure provides a user network access security protection method, apparatus and related equipment, which at least to some extent overcome the problem that the encryption of the user's unique identity identifier using a public key algorithm in the related art may be cracked.

[0007] Other features and advantages of the present disclosure will become apparent from the following detailed description, or be learned in part through the practice of the present disclosure.

[0008] According to one aspect of the present disclosure, a user network access security protection method is provided, which is applied to a user device and includes: sending a network access registration request, where the network access registration request includes user permanent identifier information corresponding to the target user device, the user permanent identifier information includes a mobile subscriber identification code, and a quantum encryption protection scheme for indicating that the network access registration request will be protected by quantum encryption; encrypting the mobile subscriber identification code according to a pre-acquired quantum key to generate a ciphertext tag corresponding to the mobile subscriber identification code; splicing and combining the user permanent identifier information of the target user device with the ciphertext tag to generate a user hidden identification code of the target user device, and forwarding the user hidden identification code to a core network device.

[0009] In some exemplary embodiments of the present disclosure, based on the foregoing solution, the user hidden identification code of the target user device includes: a protection scheme identifier and a quantum key identifier. Before splicing and combining the user permanent identifier information of the target user device with the ciphertext tag to generate the user hidden identification code of the target user device, the method further includes: storing the quantum encryption protection scheme in a memory corresponding to a pre-set protection scheme identifier; storing the quantum key in a memory corresponding to the pre-set quantum key identifier.

[0010] In some exemplary embodiments of the present disclosure, based on the foregoing solution, encrypting the mobile subscriber identification code according to the quantum key to generate a ciphertext tag corresponding to the mobile subscriber identification code includes: encrypting the mobile subscriber identification code according to the quantum key to generate ciphertext data; performing integrity protection processing on the quantum key based on a hash-based message authentication code function to generate an integrity tag; splicing and combining the ciphertext data with the integrity tag to generate a ciphertext tag corresponding to the mobile subscriber identification code.

[0011] In some exemplary embodiments of the present disclosure, based on the foregoing solution, the user hidden identification code of the target user device further includes: a protection scheme output identifier. Before splicing and combining the user permanent identification information of the target user device with the ciphertext label to generate the user hidden identification code of the target user device, the method further includes: storing the ciphertext label in a memory corresponding to a pre-set protection scheme output identifier.

[0012] In some exemplary embodiments of the present disclosure, based on the foregoing solution, before encrypting the mobile subscriber identification number according to a pre-obtained quantum key, the method further includes: connecting the target user device to a security terminal to obtain a quantum key for the target user device to communicate with a core network device, where the security terminal is used to write the quantum key.

[0013] According to another aspect of the present disclosure, there is also provided a user network access security protection method, which is applied to a core network device and includes: receiving a user hidden identification code of a target user device forwarded by the target user device; parsing the user hidden identification code of the target user device to determine the user permanent identification information and a ciphertext label of the target user device, where the ciphertext label includes a quantum key and the encrypted mobile subscriber identification number of the target user device; decrypting the encrypted mobile subscriber identification number of the target user device based on the quantum key.

[0014] In some exemplary embodiments of the present disclosure, based on the foregoing solution, parsing the user hidden identification code of the target user device to determine the user permanent identification information and the ciphertext label of the target user device includes: parsing the user hidden identification code of the target user device to obtain a protection scheme identifier and a quantum key identifier in the user hidden identification code of the target user device; determining the quantum encryption protection scheme and the quantum key corresponding to the quantum encryption protection scheme according to the protection scheme identifier and the quantum key identifier.

[0015] According to another aspect of the present disclosure, there is also provided a user network access security protection device, which is applied to a user device and includes: a network access registration request sending module, configured to send a network access registration request, where the network access registration request includes user permanent identification information corresponding to the target user device, the user permanent identification information includes a mobile subscriber identification code, and a quantum encryption protection scheme for indicating that the network access registration request will be securely protected by means of quantum encryption; a ciphertext tag generation module, configured to encrypt the mobile subscriber identification code according to a pre-acquired quantum key to generate a ciphertext tag corresponding to the mobile subscriber identification code; a user hidden identification code generation module, configured to splice and combine the user permanent identification information of the target user device with the ciphertext tag to generate a user hidden identification code of the target user device, and forward the user hidden identification code to a core network device.

[0016] According to another aspect of the present disclosure, there is also provided a user network access security protection device, which is applied to a core network device and includes: a user hidden identification code receiving module, configured to receive a user hidden identification code of a target user device forwarded by the target user device; a user hidden identification code parsing module, configured to parse the user hidden identification code of the target user device to determine the user permanent identification information and the ciphertext tag of the target user device, where the ciphertext tag includes a quantum key and the encrypted mobile subscriber identification code of the target user device; a mobile subscriber identification code decryption module, configured to decrypt the mobile subscriber identification code of the target user device based on the quantum key.

[0017] According to still another aspect of the present disclosure, there is also provided a user network access security protection system, which is applied to a user device and includes: a protection scheme selector, configured to generate a security level policy for network access registration of a target user device and determine a network access protection scheme, where the network access protection scheme includes: an unencrypted protection scheme, a profile A protection scheme, a profile B protection scheme, and a quantum encryption protection scheme; a quantum key management unit, configured to store a quantum key identifier, a quantum key, and a quantum key usage status; a user hidden identification code forwarding terminal: according to the selection result of the network access protection scheme, select a quantum key invocation type, invoke the quantum key and the quantum key identifier corresponding to the selection result of the network access protection scheme from the quantum key management unit, use quantum encryption to generate a ciphertext tag corresponding to the mobile subscriber identification code, splice and combine the user permanent identification information of the target user device with the ciphertext tag to generate a user hidden identification code of the target user device, and forward the user hidden identification code to a core network device.

[0018] According to another aspect of the present disclosure, there is also provided a user network access security protection system, which is applied to a core network device and includes: a protection scheme matching unit for determining a key acquisition method and a decryption method according to a protection scheme identifier; a quantum key identification unit: extracting a quantum key identifier from a user hidden identification code and retrieving a corresponding quantum key in a quantum key module according to the quantum key identifier; a user hidden identification code decryption terminal for performing a decryption operation on the user hidden identification code by using the quantum key to determine a mobile user identification code of a target user device.

[0019] According to another aspect of the present disclosure, there is also provided an electronic device, including: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above user network access security protection methods by executing the executable instructions.

[0020] According to yet another aspect of the present disclosure, there is also provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements any one of the above user network access security protection methods.

[0021] According to another aspect of the present disclosure, there is also provided a computer program product, including: a computer program or instruction, and when the computer program or instruction is executed by a processor, it implements the user network access security protection method of any one of the above.

[0022] In an embodiment of the present disclosure, a user network access security protection method, device and related equipment are provided. By encrypting and protecting a mobile user identification code of a user with a quantum key to obtain a ciphertext label, and then performing a splicing and combination process on a user permanent identification information of a target user device and the ciphertext label to generate a user hidden identification code of the target user device, the security and privacy protection of data in the target user device can be significantly improved. Further, the quantum key is generated and distributed by a quantum key distribution device by using the characteristics of quantum mechanics, which can ensure the security of key transmission. And an important characteristic of the quantum key is that its security is based on physical laws rather than computational complexity. Therefore, in theory, it can resist any computational attack and ensure the security of user data.

[0023] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0025] Figure 1 Showing the schematic diagram of the six - part structure of SUCI in the related art;

[0026] Figure 2 Showing the schematic diagram of an exemplary application system architecture of a user network access security protection method in an embodiment of the present disclosure;

[0027] Figure 3 Showing the schematic diagram of a user network access security protection method applied to a user equipment in an embodiment of the present disclosure;

[0028] Figure 4 Showing the schematic diagram of the six - part structure of SUCI in an embodiment of the present disclosure;

[0029] Figure 5 Showing the schematic diagram of a user network access security protection method applied to a core network device in an embodiment of the present disclosure;

[0030] Figure 6 Showing the schematic diagram of the implementation process of a user network access security protection method in an embodiment of the present disclosure;

[0031] Figure 7 Showing the schematic diagram of a user network access security protection device applied to a user equipment in an embodiment of the present disclosure;

[0032] Figure 8 Showing the schematic diagram of a user network access security protection device applied to a core network device in an embodiment of the present disclosure;

[0033] Fig. 9 Showing the schematic diagram of a user network access security protection system applied to a user equipment in an embodiment of the present disclosure;

[0034] Fig.10 Showing the schematic diagram of a user network access security protection system applied to a core network device in an embodiment of the present disclosure;

[0035] Fig.11 Showing the schematic diagram of an electronic device applying a user network access security protection method in an embodiment of the present disclosure. Detailed implementation manners

[0036] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.

[0037] In addition, the features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present disclosure. However, those skilled in the art will recognize that the technical solutions of the present disclosure can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be employed. In other instances, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present disclosure.

[0038] The flowchart shown in the accompanying drawings is merely illustrative and not necessarily inclusive of all content and operations / steps, nor is it necessarily to be executed in the order described. For example, some operations / steps may be decomposed, while some operations / steps may be combined or partially combined, so the actual execution order may change according to the actual situation.

[0039] As Figure 2 shown, the system architecture includes a terminal device 201, a network 202, and a network-side device 203; wherein, the network-side device 203 can be a user equipment or a core network device.

[0040] The network 202 is used to provide a medium for the communication link between the terminal device 201 and the network-side device 203, and can be a wired network or a wireless network.

[0041] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is usually the Internet, but can also be any network, including but not limited to any combination of a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network. In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPSec), etc. can be used to encrypt all or some of the links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.

[0042] Optionally, the terminal device in the embodiments of the present disclosure can also be referred to as a UE (User Equipment). In specific implementations, the terminal device can be a mobile phone, a tablet personal computer, a laptop computer, a personal digital assistant (PDA), a mobile Internet device (MID), a wearable device, or a vehicle-mounted device, etc. It should be noted that the specific type of the terminal device is not limited in the embodiments of the present invention.

[0043] The network-side device can be a base station, a relay or an access point, etc. The base station can be a base station of 5G and later versions (for example: 5G NR NB), or a base station in other communication systems (for example: eNB base station). It should be noted that the specific type of the network-side device is not limited in the embodiments of the present disclosure.

[0044] Those skilled in the art can know that Figure 2The numbers of the terminal devices, networks, and servers in [it] are merely illustrative. According to actual needs, there can be any number of terminal devices, networks, and servers. The embodiments of the present disclosure do not limit this.

[0045] Under the above system architecture, an embodiment of the present disclosure provides a user network access security protection method, and this method can be executed by any electronic device with computing and processing capabilities.

[0046] In some embodiments, the user network access security protection method provided in the embodiments of the present disclosure can be executed by the terminal device of the above system architecture; in other embodiments, the user network access security protection method provided in the embodiments of the present disclosure can be executed by the server in the above system architecture; in other embodiments, the user network access security protection method provided in the embodiments of the present disclosure can be implemented by the terminal device and the server in the above system architecture through interaction.

[0047] Figure 3 The following shows a schematic diagram of a user network access security protection method in an embodiment of the present disclosure, which is applied to a user device. This method includes the following steps:

[0048] S302: Send a network access registration request. The network access registration request includes the user permanent identification information corresponding to the target user device. The user permanent identification information includes the mobile subscriber identification code, and a quantum encryption protection scheme for indicating that the network access registration request will be protected by quantum encryption.

[0049] It should be noted that the access registration request in the embodiments of the present disclosure can be an access registration request sent by any user equipment. In some embodiments, it can be a request initiated by user equipment such as a mobile phone or a tablet computer when accessing a mobile communication network. The access registration request in the embodiments of the present disclosure is used for identity authentication and registration in the network. Through the access registration request, the user equipment can obtain necessary network resources and service permissions. Secondly, the user permanent identifier (Subscription Permanent Identifier, SUPI) information in the embodiments of the present disclosure is composed of SUPI-related information. Specifically, the access registration request includes: SUPI type, home network or serving network, routing information, etc. More specifically, SUPI includes multiple formats. For example, in the case of the SUPI in the format of International Mobile Subscriber Identity (IMSI), it includes the mobile subscriber identity. The home network or serving network refers to the mobile network operator with which the user equipment initially subscribed and obtained services. The routing information refers to the path through which data packets are transmitted in the network and the information of relevant network nodes. These information will be determined by the access and mobility management function of the core network through query when the access registration request sent by the target user equipment. And, the quantum encryption in the embodiments of the present disclosure is a technology that uses the principles of quantum mechanics to generate and distribute encryption keys. Different from the traditional encryption method based on mathematical problems, the security of quantum encryption depends on physical laws, especially the non-clonability and measurement disturbance of quantum states. Therefore, no matter how much the future computing power (including quantum computers) is improved, the quantum encryption method can resist the attacks of future quantum computers and cannot crack the encryption key of quantum encryption.

[0050] S304, encrypt the mobile subscriber identity according to the pre-obtained quantum key to generate a ciphertext label corresponding to the mobile subscriber identity.

[0051] It should be noted that since neither the user equipment nor the unified data management (UDM) network element of the core network is suitable for directly connecting to the quantum key distribution device, the method for the user equipment and the virtualized network element of the core network to obtain quantum keys is as follows: for the user equipment, the user can go to the business hall to obtain quantum keys; for the unified data management network element of the core network, obtain quantum keys through the key management node in the quantum network.

[0052] In some embodiments, the ciphertext tag in the embodiments of the present disclosure not only includes the encrypted mobile subscriber identification number, but also includes a message authentication code in the ciphertext tag to ensure that the ciphertext tag is not tampered with during transmission. A hash value calculated from the encrypted mobile subscriber identification number and the quantum key. The receiving party can verify the message authentication code to confirm the integrity of the data.

[0053] S306. Concatenate and combine the user permanent identification information of the target user device with the ciphertext tag to generate a user hidden identification code of the target user device, and forward the user hidden identification code to the core network device.

[0054] It should be noted that the embodiments of the present disclosure splice and combine the SUPI type, the home network, the routing information, the quantum encryption protection scheme, the quantum key, and the ciphertext tag to obtain the user hidden identification code of the target user device, and forward the user hidden identification code of the target user device to the core network device.

[0055] In the user network access security protection method provided in the embodiments of the present disclosure, first, an access registration request is sent. The access registration request includes the user permanent identification information corresponding to the target user device. The user permanent identification information includes the mobile subscriber identification number and a quantum encryption protection scheme for indicating that the access registration request will be protected by quantum encryption. Secondly, the mobile subscriber identification number is encrypted according to the pre-obtained quantum key to generate a ciphertext tag corresponding to the mobile subscriber identification number. Finally, the user permanent identification information of the target user device is concatenated and combined with the ciphertext tag to generate a user hidden identification code of the target user device, and the user hidden identification code is forwarded to the core network device. Compared with the method of encrypting the user's unique identity identifier using a public key algorithm in the related art, which may face a huge risk of being "cracked" by a quantum computer in the next decade, the embodiments of the present disclosure encrypt and protect the mobile subscriber identification number of the user through a quantum key to obtain a ciphertext tag, and then concatenate and combine the user permanent identification information of the target user device with the ciphertext tag to generate a user hidden identification code of the target user device, which can significantly improve the security and privacy protection of the data in the target user device. Further, the quantum key is generated and distributed by the quantum key distribution device using the characteristics of quantum mechanics, which can ensure the security of the key transmission. An important characteristic of the quantum key is that its security is based on physical laws rather than computational complexity. Therefore, in theory, it can resist any computational attack and ensure the security of user data.

[0056] In some embodiments, the user hidden identification code of the target user equipment in the embodiments of the present disclosure includes: a protection scheme identifier and a quantum key identifier. Before splicing and combining the permanent identification information of the user of the target user equipment with the ciphertext label to generate the user hidden identification code of the target user equipment, the user network access security protection method in the embodiments of the present disclosure further includes: storing the quantum encryption protection scheme in the memory corresponding to the preset protection scheme identifier; storing the quantum key in the memory corresponding to the preset quantum key identifier. Specifically, as Figure 4 shown, in the embodiments of the present disclosure, a protection scheme identifier capable of storing a quantum encryption protection scheme is added to the protection scheme identifier bit of the original SUCI, indicating that the user side and the core network side recognize that this network access registration request will use quantum encryption for security protection; the original public key identifier bit is optimized and extended to a key identifier bit, and a quantum key identifier is added, which is used to indicate that the core network UDM network element retrieves the quantum key in the current round of target user network access protection process according to the quantum key identifier, and uses the quantum key to decrypt and perform integrity verification on the SUCI, realizing one-time-one-key encryption.

[0057] In some embodiments, before encrypting the mobile subscriber identification number according to the quantum key to generate the ciphertext label of the target user equipment, the user network access security protection method in the embodiments of the present disclosure further includes: associating the encryption protection scheme with the protection scheme identifier; associating the quantum key with the quantum key identifier. Specifically, by associating the encryption protection scheme with the protection scheme identifier in the embodiments of the present disclosure, the corresponding encryption policy can be efficiently specified and applied in network communication to ensure the secure transmission of data; in addition, by associating the quantum key with the quantum key identifier, the quantum key can be effectively managed and distributed to ensure its correct use in communication.

[0058] In some embodiments, encrypting the mobile subscriber identification number according to the quantum key to generate the ciphertext label corresponding to the mobile subscriber identification number includes: encrypting the mobile subscriber identification number according to the quantum key to generate ciphertext data; performing integrity protection processing on the quantum key based on the hash-based message authentication code function to generate an integrity label; splicing and combining the ciphertext data with the integrity label to generate the ciphertext label corresponding to the mobile subscriber identification number. Specifically, using the quantum key and the encrypted mobile subscriber identification number to generate the integrity label in the embodiments of the present disclosure can significantly improve the security and integrity of user data. It can not only effectively hide the sensitive information of the target user equipment and prevent it from being leaked during the communication process, but also prevent the mobile subscriber identification number from being tampered with during the transmission process by verifying the integrity label.

[0059] In some embodiments, as Figure 4As shown, the embodiments of the present disclosure also optimize the output structure of the quantum protection scheme. The output no longer carries the ECC public key and consists of two parts: the ciphertext result and the integrity tag.

[0060] In some embodiments, before encrypting the mobile subscriber identification number according to the pre-acquired quantum key, the user network access security protection method in the embodiments of the present disclosure further includes: the target user equipment connects to the security terminal to obtain the quantum key for the target user equipment to communicate with the core network equipment, where the security terminal is used to write the quantum key. Specifically, since the user equipment is not suitable for directly docking with the quantum key distribution device in the embodiments of the present disclosure, the method for the target user equipment to obtain the quantum key is: the security terminal directly docks with the quantum key distribution device, and the user goes to the business hall to connect with the security terminal, and writes the quantum key distributed by the quantum key distribution device into the target user equipment through the security terminal.

[0061] Figure 5 The figure shows a schematic diagram of a user network access security protection method in the embodiments of the present disclosure, which is applied to the core network equipment. The method includes the following steps:

[0062] S502, receive the user hidden identification code forwarded by the target user equipment;

[0063] S504, analyze the user hidden identification code of the target user equipment to determine the user permanent identification information and the ciphertext tag of the target user equipment. The ciphertext tag includes the quantum key and the encrypted mobile subscriber identification number of the target user equipment;

[0064] S506, decrypt the mobile subscriber identification number of the target user equipment based on the quantum key.

[0065] In some embodiments, decrypting the mobile subscriber identification number of the target user equipment by the quantum key in the embodiments of the present disclosure can significantly improve the security and privacy protection of the communication system. Specifically, by encrypting and decrypting the mobile subscriber identification number of the target user equipment, it can effectively prevent the user's sensitive information from being eavesdropped or leaked during the transmission process. Only by having the correct quantum key can the original mobile subscriber identification number of the target user equipment be decrypted, improving the security of the mobile subscriber identification number of the target user equipment during the transmission process.

[0066] In some embodiments, the disclosed embodiment parses the user hidden identification code of the target user device to determine the user permanent identification information and ciphertext label of the target user device, including: parsing the user hidden identification code of the target user device to obtain the protection scheme identifier and quantum key identifier in the user hidden identification code of the target user device; determining the quantum encryption protection scheme and the quantum key corresponding to the quantum encryption protection scheme according to the protection scheme identifier and the quantum key identifier. Specifically, the core network device in the disclosed embodiment receives the user hidden identification code of the target user device forwarded by the target user device, wherein the UDM network element in the core network device parses the user hidden identification code of the target user device, retrieves the protection scheme identifier in the user hidden identification code to determine that the current network registration request uses the quantum encryption scheme to decrypt the user hidden identification code; queries the corresponding quantum key according to the quantum key identifier, uses the quantum key to decrypt the mobile user identification code of the target user device, and restores the complete user permanent identification information; then selects the subsequent main authentication method according to the user permanent identification information of the target user device, and executes the standard authentication process.

[0067] In some embodiments, Figure 6 As shown, the user network access security protection method in the embodiment of the present disclosure specifically includes:

[0068] S602, the target user equipment initiates a network registration request and determines that the quantum encryption protection scheme is used for identity protection in this network access;

[0069] S604, determining the encryption protection scheme, calling the quantum key, using the quantum key to encrypt the mobile subscriber identification number (MSIN) and generate an integrity tag, and obtaining a ciphertext tag composed of the MSIN ciphertext result and the integrity tag;

[0070] S606, combining the SUPI type identifier, the primary network identifier, the routing identifier, the quantum encryption protection scheme identifier, the quantum key identifier, and the ciphertext label to generate a SUCI;

[0071] S608, the target user equipment forwards the request and the carried SUCI to the core network home network;

[0072] S610, UDM receives the registration request, parses the SUCI, retrieves the protection scheme identification bit to determine whether to use the quantum encryption protection scheme to decrypt the SUCI this time;

[0073] S612, UDM queries the corresponding quantum key according to the quantum key identifier;

[0074] S614. The UDM decrypts the MSIN plaintext using the quantum key and restores the complete SUPI.

[0075] S616. The UDM selects the subsequent primary authentication method based on the SUPI and executes the standard authentication process.

[0076] In some embodiments, on the basis of retaining the six - part structure of the SUCI, the embodiments of the present disclosure add a quantum encryption protection scheme identifier and a quantum key identifier, and add a judgment instruction for the protection scheme before generating the SUCI. The call type of the key identifier is judged according to the protection scheme type, that is, the ECC public key or the quantum key is called according to different protection scheme levels.

[0077] Based on the same inventive concept, embodiments of the present disclosure also provide a user network access security protection device as described in the following embodiments. Since the principle of solving problems in this device embodiment is similar to that of the above - mentioned method embodiment, the implementation of this device embodiment can refer to the implementation of the above - mentioned method embodiment, and repeated parts will not be elaborated.

[0078] Figure 7 The following shows a schematic diagram of a user network access security protection device in the embodiments of the present disclosure, which is applied to a user equipment. The device includes:

[0079] An access registration request sending module 701, configured to send an access registration request. The access registration request includes user permanent identification information corresponding to the target user equipment. The user permanent identification information includes a mobile subscriber identification code, and a quantum encryption protection scheme used to indicate that the access registration request will be protected by quantum encryption.

[0080] A ciphertext label generating module 702, configured to encrypt the mobile subscriber identification code according to the pre - obtained quantum key to generate a ciphertext label corresponding to the mobile subscriber identification code.

[0081] A user hidden identification code generating module 703, configured to splice and combine the user permanent identification information of the target user equipment and the ciphertext label to generate a user hidden identification code of the target user equipment, and forward the user hidden identification code to the core network equipment.

[0082] In an embodiment of the present disclosure, a user network access security protection device is provided. An access registration request sending module sends an access registration request, where the access registration request includes user permanent identification information corresponding to a target user device. The user permanent identification information includes an International Mobile Subscriber Identity (IMSI), and a quantum encryption protection scheme for indicating that the access registration request will be securely protected by using quantum encryption; a ciphertext tag generation module encrypts the International Mobile Subscriber Identity (IMSI) according to a pre-acquired quantum key to generate a ciphertext tag corresponding to the International Mobile Subscriber Identity (IMSI); a user hidden identification code generation module splices and combines the user permanent identification information of the target user device with the ciphertext tag to generate a user hidden identification code of the target user device, and forwards the user hidden identification code to a core network device. Compared with the method of encrypting a user's unique identity identifier by using a public key algorithm in the related art, which may face a huge risk of being "cracked" by a quantum computer within the next decade, in the embodiment of the present disclosure, the International Mobile Subscriber Identity (IMSI) of the user is encrypted and protected by a quantum key to obtain a ciphertext tag, and then the user permanent identification information of the target user device and the ciphertext tag are spliced and combined to generate a user hidden identification code of the target user device, which can significantly improve the security and privacy protection of data in the target user device. Further, the quantum key is generated and distributed by a quantum key distribution device by using the characteristics of quantum mechanics, which can ensure the security of key transmission. An important characteristic of the quantum key is that its security is based on physical laws rather than computational complexity. Therefore, in theory, it can resist any computational attack and ensure the security of user data.

[0083] In some embodiments, the user hidden identification code of the target user device in the embodiment of the present disclosure includes: a protection scheme identifier and a quantum key identifier. The user network access security protection device in the embodiment of the present disclosure further includes: a first storage module, configured to store the quantum encryption protection scheme in a memory corresponding to a pre-set protection scheme identifier before splicing and combining the user permanent identification information of the target user device with the ciphertext tag to generate a user hidden identification code of the target user device; a second storage module, configured to store the quantum key in a memory corresponding to a pre-set quantum key identifier.

[0084] In some embodiments, the ciphertext tag generation module in the embodiment of the present disclosure is further configured to encrypt the International Mobile Subscriber Identity (IMSI) according to the quantum key to generate ciphertext data; perform integrity protection processing on the quantum key by using a Hash-based Message Authentication Code (HMAC) function to generate an integrity tag; splice and combine the ciphertext data with the integrity tag to generate a ciphertext tag corresponding to the International Mobile Subscriber Identity (IMSI).

[0085] In some embodiments, the user hidden identification code of the target user device in the embodiments of the present disclosure further includes: a protection scheme output identifier. The user network access security protection device in the embodiments of the present disclosure further includes: a third storage module, configured to store the ciphertext label in the memory corresponding to the pre-set protection scheme output identifier before splicing and combining the permanent user identification information of the target user device with the ciphertext label to generate the user hidden identification code of the target user device.

[0086] In some embodiments, the user network access security protection device in the embodiments of the present disclosure further includes: a quantum key acquisition module, configured to connect the target user device to a security terminal to obtain a quantum key for the target user device to communicate with the core network device before encrypting the mobile subscriber identification number according to the pre-acquired quantum key, where the security terminal is used to write the quantum key.

[0087] Figure 8 FIG. shows a schematic diagram of a user network access security protection device in the embodiments of the present disclosure, which is applied to a core network device. The device includes:

[0088] A user hidden identification code receiving module 801, configured to receive the user hidden identification code of the target user device;

[0089] A user hidden identification code parsing module 802, configured to parse the user hidden identification code of the target user device to determine the permanent user identification information of the target user device and the ciphertext label, where the ciphertext label includes a quantum key and the encrypted mobile subscriber identification number of the target user device;

[0090] A mobile subscriber identification number decryption module 803, configured to decrypt the mobile subscriber identification number of the target user device based on the quantum key.

[0091] In some embodiments, decrypting the mobile subscriber identification number of the target user device by the mobile subscriber identification number decryption module in the embodiments of the present disclosure can significantly improve the security and privacy protection of the communication system. Specifically, by encrypting and decrypting the mobile subscriber identification number of the target user device, it can effectively prevent the user's sensitive information from being eavesdropped or leaked during transmission. Only by having the correct quantum key can the original mobile subscriber identification number of the target user device be decrypted, improving the security of the mobile subscriber identification number of the target user device during transmission.

[0092] Based on the same inventive concept, an embodiment of the present disclosure also provides a user network access security protection system, as described in the following embodiments. Since the principle of solving problems in this system embodiment is similar to that of the above method embodiment, the implementation of this system embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0093] Fig. 9A schematic diagram of a user network access security protection system according to an embodiment of the present disclosure, which is applied to a user device. The system includes:

[0094] A protection scheme selector, configured to generate a security level policy for the network access registration of the target user device and determine a network access protection scheme. The network access protection scheme includes: an unencrypted protection scheme, a configuration file A protection scheme, a configuration file B protection scheme, and a quantum encryption protection scheme;

[0095] A quantum key management unit, configured to store a quantum key identifier, a quantum key, and a quantum key usage status;

[0096] A user hidden identification code forwarding terminal: According to the selection result of the network access protection scheme, select a quantum key invocation type, invoke the quantum key and the quantum key identifier corresponding to the selection result of the network access protection scheme from the quantum key management unit, use quantum encryption to generate a ciphertext tag corresponding to the mobile subscriber identification number, splice and combine the permanent user identification information of the target user device with the ciphertext tag to generate a user hidden identification code of the target user device, and forward the user hidden identification code to the core network device.

[0097] In some embodiments, the embodiment of the present disclosure completes the selection and judgment of the protection scheme, the invocation of the quantum key, and the SUCI assembly through the cooperation of the protection scheme selector, the user hidden identification code forwarding terminal, and the quantum key management unit.

[0098] Fig.10 A schematic diagram of a user network access security protection system according to an embodiment of the present disclosure, which is applied to a core network device. The system includes:

[0099] A protection scheme matching unit, configured to determine a key acquisition method and a decryption method according to a protection scheme identifier;

[0100] A quantum key identification unit: Extract the quantum key identifier from the user hidden identification code, and retrieve the corresponding quantum key in the quantum key module according to the quantum key identifier;

[0101] A user hidden identification code decryption terminal, configured to perform a decryption operation on the user hidden identification code using the quantum key to determine the mobile subscriber identification number of the target user device.

[0102] In some embodiments, the core network device of the embodiment of the present disclosure completes the retrieval of the quantum key and the recovery of the SUPI through the cooperation of the quantum key identification unit and the user hidden identification code decryption terminal.

[0103] In some embodiments, a quantum protection scheme is added to the SUCI structure in the embodiments of the present disclosure, which is applicable to future 5G / 6G scenarios and coexists with the other three protection schemes in the existing network. For terminals and core networks that do not enable the quantum encryption function, the original SUPI encryption scheme based on the public key algorithm can be used. For application scenarios with high security requirements that need to consider resistance to quantum attacks, the quantum encryption scheme can be enabled through policy configuration. The patent is universal in implementation and has a high compatibility with the existing network.

[0104] Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, method, or program product. Therefore, various aspects of the present disclosure can be specifically implemented in the following forms: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module", or "system" here.

[0105] Based on the same inventive concept, an electronic device is also provided in the embodiments of the present disclosure. The electronic device includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the user network access security protection method of any one of the above via executing the executable instructions. Since the principle of solving problems in the embodiment of this electronic device is similar to that of the above method embodiment, the implementation of the embodiment of this electronic device can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0106] Next, refer to Fig.11 to describe the electronic device 1100 according to this embodiment of the present disclosure. Fig.11 The shown electronic device 1100 is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present disclosure.

[0107] As Fig.11 shown, the electronic device 1100 is presented in the form of a general computing device. The components of the electronic device 1100 may include but are not limited to: at least one of the above processing units 1101, at least one of the above storage units 1102, and a bus 1103 connecting different system components (including the storage unit 1102 and the processing unit 1101).

[0108] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 1101, so that the processing unit 1101 executes the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.

[0109] In some embodiments, when the electronic device is used to control, for example, the user network access security protection method of the present disclosure above, the processing unit 1101 may execute the following steps of the above method embodiment:

[0110] Send an access network registration request, where the access network registration request includes the user permanent identification information corresponding to the target user equipment. The user permanent identification information includes a mobile subscriber identification code, and a quantum encryption protection scheme for indicating that the access network registration request will be protected by quantum encryption; encrypt the mobile subscriber identification code according to the pre-obtained quantum key to generate a ciphertext tag corresponding to the mobile subscriber identification code; splice and combine the user permanent identification information of the target user equipment with the ciphertext tag to generate a user hidden identification code of the target user equipment, and forward the user hidden identification code to the core network device.

[0111] The storage unit 1102 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 11021 and / or a cache storage unit 11022, and may further include a read-only storage unit (ROM) 11023.

[0112] The storage unit 1102 may further include a program / utilities 11024 having a set (at least one) of program modules 11025. Such program modules 11025 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0113] The bus 1103 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus structures.

[0114] The electronic device 1100 may also communicate with one or more external devices 1104 (such as a keyboard, a pointing device, a Bluetooth device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 1100, and / or communicate with any device that enables the electronic device 1100 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication may be through an input / output (I / O) interface 1105. And, the electronic device 1100 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 1106. As shown in the figure, the network adapter 1106 communicates with other modules of the electronic device 1100 through the bus 1103. It should be understood that although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 1100, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0115] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0116] Based on the same inventive concept, an embodiment of the present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the user network access security protection method of any one of the above. Since the principle of solving problems in this computer-readable storage medium embodiment is similar to that of the above method embodiment, the implementation of this computer-readable storage medium embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0117] More specific examples of the computer-readable storage medium in the present disclosure may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0118] In the present disclosure, the computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, and this readable medium may send, propagate, or transmit a program used by or in combination with an instruction execution system, apparatus, or device.

[0119] Optionally, the program code included on the computer-readable storage medium may be transmitted by any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.

[0120] In specific implementation, program code for performing the operations of the present disclosure can be written in any combination of one or more programming languages. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as an independent software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0121] Based on the same inventive concept, embodiments of the present disclosure also provide a computer program product, including: a computer program or instruction, which when executed by a processor implements the user network access security protection method in any one of the above method embodiments. Since the principle of solving problems in this computer program product embodiment is similar to that of the above method embodiments, the implementation of this computer program product embodiment can refer to the implementation of the above method embodiments, and the repeated parts will not be elaborated again.

[0122] It should be noted that although several modules or units of devices for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0123] In addition, although the steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that these steps must be executed in that specific order, or that all the steps shown must be executed to achieve the desired result. Additionally or alternatively, some steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution, etc.

[0124] Those skilled in the art can easily understand from the description of the above embodiments that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0125] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only illustrative, and the true scope and spirit of the present disclosure are pointed out by the appended claims.

Claims

1. A user network access security protection method, characterized in that: Applied to user equipment, including: Sending a network registration request, the network registration request including user permanent identification information corresponding to the target user equipment, the user permanent identification information including a mobile user identification code, and a quantum encryption protection scheme for indicating that the network registration request will be securely protected by quantum encryption; Encrypting the mobile user identification code according to the pre-acquired quantum key to generate a ciphertext label corresponding to the mobile user identification code; The user permanent identification information of the target user equipment is concatenated and combined with the ciphertext tag to generate a user hidden identification code of the target user equipment, and the user hidden identification code is forwarded to the core network device.

2. The user network security protection method according to claim 1, characterized in that: The hidden user identification code of the target user device includes: a protection scheme identifier and a quantum key identifier. Before the user permanent identification information of the target user device is concatenated and combined with the ciphertext label to generate the hidden user identification code of the target user device, the method further includes: Storing the quantum encryption protection scheme in a memory corresponding to a preset protection scheme identifier; The quantum key is stored in a memory corresponding to the preset quantum key identifier.

3. The user network security protection method according to claim 2, characterized in that: The mobile user identification code is encrypted according to the quantum key to generate a ciphertext label corresponding to the mobile user identification code, including: Encrypting the mobile user identification code according to the quantum key to generate ciphertext data; Performing integrity protection processing on the quantum key based on a hash-based message authentication code function to generate an integrity tag; The ciphertext data and the integrity label are concatenated and combined to generate a ciphertext label corresponding to the mobile user identification code.

4. The user network security protection method according to claim 3 is characterized in that: The hidden user identification code of the target user device also includes: a protection scheme output identifier, before the user permanent identification information of the target user device is spliced ​​and combined with the ciphertext tag to generate the hidden user identification code of the target user device, the method also includes: The ciphertext tag is stored in a memory corresponding to a preset protection scheme output identifier.

5. The user network access security protection method according to claim 3, characterized in that: Before encrypting the mobile user identification code according to the pre-acquired quantum key, the method further includes: The target user equipment is connected to a security terminal to obtain a quantum key for communication between the target user equipment and a core network device, wherein the security terminal is used to write the quantum key.

6. A user network security protection method, characterized in that: Applied to core network equipment, including: Receiving a hidden user identification code of a target user device forwarded by the target user device; Parsing the hidden user identification code of the target user device to determine the permanent user identification information and a ciphertext label of the target user device, wherein the ciphertext label includes a quantum key and an encrypted mobile user identification code of the target user device; The mobile user identification code of the target user equipment is decrypted based on the quantum key.

7. The user network access security protection method according to claim 5, characterized in that: Parsing the hidden user identification code of the target user device to determine the permanent user identification information and the ciphertext label of the target user device includes: Parsing the hidden user identification code of the target user device to obtain a protection scheme identifier and a quantum key identifier in the hidden user identification code of the target user device; According to the protection scheme identifier and the quantum key identifier, the quantum encryption protection scheme and the quantum key corresponding to the quantum encryption protection scheme are determined.

8. A user network access security protection device, characterized in that: Applied to user equipment, including: A network access registration request sending module, used to send a network access registration request, wherein the network access registration request includes user permanent identification information corresponding to a target user device, wherein the user permanent identification information includes a mobile user identification code, and a quantum encryption protection scheme for indicating that the network access registration request will be securely protected by quantum encryption; A ciphertext label generation module, used to encrypt the mobile user identification code according to a pre-acquired quantum key to generate a ciphertext label corresponding to the mobile user identification code; The user hidden identification code generation module is used to concatenate and combine the user permanent identification information of the target user device with the ciphertext label to generate a user hidden identification code of the target user device, and forward the user hidden identification code to the core network device.

9. A user network access security protection device, characterized in that: Applied to core network equipment, including: A user hidden identification code receiving module, used to receive a user hidden identification code of a target user device forwarded by the target user device; A user hidden identification code parsing module, used to parse the user hidden identification code of the target user device, and determine the user permanent identification information and ciphertext label of the target user device, wherein the ciphertext label includes a quantum key and a mobile user identification code of the target user device after encryption; A mobile user identification code decryption module is used to decrypt the mobile user identification code of the target user equipment based on the quantum key.

10. A user network security protection system, characterized in that: Applied to user equipment, including: A protection scheme selector, used to generate a security level policy for network registration of a target user device and determine a network access protection scheme, wherein the network access protection scheme includes: a non-encrypted protection scheme, a configuration file A protection scheme, a configuration file B protection scheme, and a quantum encryption protection scheme; A quantum key management unit, used to store quantum key identification, quantum key, and quantum key usage status; User hidden identification code forwarding terminal: select the quantum key call type according to the selection result of the network access protection scheme, call the quantum key and quantum key identification corresponding to the selection result of the network access protection scheme to the quantum key management unit, use quantum encryption to generate a ciphertext label corresponding to the mobile user identification code, concatenate and combine the user permanent identification information of the target user device with the ciphertext label, generate a user hidden identification code of the target user device, and forward the user hidden identification code to the core network device.

11. A user network security protection system, characterized in that: Applied to core network equipment, including: A protection scheme matching unit, used to determine a key acquisition method and a decryption method according to the protection scheme identifier; Quantum key identification unit: extracts the quantum key identifier in the user's hidden identification code, and retrieves the corresponding quantum key in the quantum key module according to the quantum key identifier; The user hidden identification code decryption terminal is used to use the quantum key to perform a decryption operation on the user hidden identification code to determine the mobile user identification code of the target user device.

12. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to execute the user network access security protection method according to any one of claims 1 to 7 by executing the executable instructions.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the user network access security protection method described in any one of claims 1 to 7 is implemented.

14. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the user network access security protection method described in any one of claims 1 to 7.

Citation Information

Cited By

  • Network access registration method and device and related equipment

    CN120768549A

  • Network registration method and device and related equipment

    CN120768549B