User identity privacy protection method and related equipment

By receiving user registration requests from user terminals and transmitting identity information through transitively, the problems of identity authentication and privacy protection of new devices are solved, and effective protection of user identity information and authentication of new devices are realized.

CN120151828AActive Publication Date: 2025-06-13CHINA TELECOM CORP LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510622405.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-06-13
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

The user identity identification of new devices is different from that of traditional devices, and uses non-standard authentication methods and protocols, which makes it difficult for existing authentication methods and user identity identification protection mechanisms to be applicable to new devices, and cannot effectively authenticate and protect user privacy, which easily leads to identity information leakage.

Method used

Provide a method for privacy protection of user identity. By receiving user registration requests from user terminals, subscribed identity information is determined based on user identity hidden identity, and transmitted to the identity authentication server for decryption and identity authentication, ensuring that user identity always exists in a hidden form and reducing the risk of information leakage.

Benefits of technology

It effectively protects user identity privacy, solves the problem of easy leakage of user identity information, and ensures identity authentication and privacy protection of new devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151828A_ABST
    Figure CN120151828A_ABST
Patent Text Reader

Abstract

The invention provides a user identity privacy protection method and related equipment, and is applied to the technical field of wireless communication. The method comprises the following steps: receiving a user registration request from a user terminal, wherein the user registration request comprises a user identity hiding identifier; determining subscription identity information of the user terminal in the network according to the user identity hidden identifier; transmitting the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier, performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; and receiving an identity authentication result returned by the identity authentication server, and sending the identity authentication result to the user terminal. The risk that the user identity information is stolen or abused in the transmission and processing process is reduced, the user identity privacy is effectively protected, and the problem that the user identity information is prone to leakage is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] With the development of mobile communication, the types of network - connected devices are diversified, including new types of devices such as Virtual Reality (VR) and non - Universal Subscriber Identity Module (non – USIM) terminals. In the face of new communication scenarios, since the user identity identifiers of new devices are different from those of traditional devices, and non - standard authentication methods and protocols are adopted, the authentication methods and protocols based on supporting conventional devices are not suitable for new devices.

[0003] Due to this mismatch, related technologies cannot effectively authenticate new devices. At the same time, due to the differences between the user identity identifiers of new devices and traditional devices, the existing user identity identifier protection mechanisms are also difficult to apply to new devices, cannot well protect the privacy of new device users, and are prone to the leakage of user identity identifiers, leading to privacy attacks and the exposure of identity information.

[0004] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] The present disclosure provides a user identity privacy protection method and related devices, which encrypt and protect the user identity, avoiding the leakage of user identity privacy.

[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or be learned in part through the practice of the present disclosure.

[0007] According to one aspect of the present disclosure, there is provided a user identity privacy protection method applied to a core network element. The method includes: receiving a user registration request from a user terminal, where the user registration request includes a user identity hidden identifier; determining the subscription identity information of the user terminal in the network according to the user identity hidden identifier; transmitting the user identity hidden identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hidden identifier, performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server, and sending the identity authentication result to the user terminal.

[0008] In some embodiments, determining the subscription identity information of a user terminal in a network according to the user identity hiding identifier includes: obtaining an association relationship table of the user identity hiding identifier and the subscription identity information; and determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier in the association relationship table.

[0009] In some embodiments, the user registration request further includes at least one of the following: the operation type, operation time, and operation location of the user terminal; determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier includes: determining the access right of the user identity hiding identifier to the association relationship table according to the operation type and / or the operation time and / or the operation location of the user terminal; and determining the subscription identity information of the user terminal in the network according to the access right and the user identity hiding identifier.

[0010] In some embodiments, the method further includes: transparently transmitting the subscription identity information to an identity authentication server, so that the identity authentication server decrypts the user identity hiding identifier to obtain a user identity identifier, and performs identity authentication according to the user identity identifier and the subscription identity information.

[0011] In some embodiments, before transparently transmitting the user identity hiding identifier to the identity authentication server according to the subscription identity information, it further includes: adding an association verification code to the user identity hiding identifier and the subscription identity information; transparently transmitting the user identity hiding identifier to the identity authentication server according to the subscription identity information includes: transparently transmitting the user identity hiding identifier, the subscription identity information, and the association verification code to the identity authentication server.

[0012] In some embodiments, the user identity hiding identifier is obtained by encrypting a user identity identifier through any one of the following encryption algorithms: a hash algorithm, a mapping table, and a post-quantum cryptography algorithm.

[0013] In some embodiments, the identity authentication result is associated with the user identity hiding identifier.

[0014] In some embodiments, the core network element is an access and mobility management function network element, and the identity authentication server is a 3A authentication server.

[0015] In some embodiments, the manner of performing identity authentication includes performing identity authentication based on an Extensible Authentication Protocol or performing identity authentication based on database identity information.

[0016] According to another aspect of the present disclosure, there is also provided a user identity privacy protection device, which is applied to a core network element. The device includes: a first receiving module, configured to receive a user registration request from a user terminal, where the user registration request includes a user identity hiding identifier; a determination module, configured to determine the subscription identity information of the user terminal in the network according to the user identity hiding identifier; a pass-through module, configured to pass through the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier, performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; and a second receiving module, configured to receive the identity authentication result returned by the identity authentication server and send the identity authentication result to the user terminal.

[0017] According to another aspect of the present disclosure, there is also provided an electronic device, which includes: a processor; and a memory, configured to store executable instructions of the processor; wherein, the processor is configured to execute the user identity privacy protection method according to any one of the above by executing the executable instructions.

[0018] According to another aspect of the present disclosure, there is also provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the user identity privacy protection method according to any one of the above is implemented.

[0019] According to another aspect of the present disclosure, there is also provided a computer program product, including: a computer program or instruction, and when the computer program or instruction is executed by a processor, the user identity privacy protection method according to any one of the above is implemented.

[0020] The user identity privacy protection method and related devices provided in the embodiments of the present disclosure. The method includes: receiving a user registration request from a user terminal, where the user registration request includes a user identity hiding identifier; determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier; passing through the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier, performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server and sending the identity authentication result to the user terminal. In the entire identity authentication process of the present disclosure, the user identity identifier always exists in the form of a user identity hiding identifier, reducing the risk of the identity information being stolen or misused during transmission and processing, effectively protecting the user identity privacy, and solving the problem of easy leakage of user identity information.

[0021] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present disclosure. Description of the Drawings

[0022] The drawings herein are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0023] Figure 1 Schematic diagram of the system architecture of a user identity privacy protection method in an embodiment of the present disclosure; Figure 2 Flowchart of a user identity privacy protection method in an embodiment of the present disclosure; Figure 3 Flowchart of a method for determining subscription identity information in an embodiment of the present disclosure; Figure 4 Flowchart of an identity authentication method in an embodiment of the present disclosure; Figure 5 Signaling diagram of a user identity privacy protection method in an embodiment of the present disclosure; Figure 6 Specific flowchart of a user identity privacy protection method in an embodiment of the present disclosure; Figure 7 Schematic diagram of a user identity privacy protection device in an embodiment of the present disclosure; Figure 8 Block diagram of the structure of an electronic device in an embodiment of the present disclosure. Detailed Embodiments

[0024] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.

[0025] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0026] As the services of the mobile communication network are continuously expanding, the types of devices accessing the network are increasing. Previously, it was mainly terminal devices embedded with Universal Subscriber Identity Module (USIM) cards and Internet of Things (IoT) terminals. Now, devices such as VR devices, non-USIM terminals, and even biometrics and digital identities can also access the network. These new devices are for future communication scenarios, such as immersive communication and ubiquitous connection. The network system should support the authentication and privacy protection of new devices. Once the user identity identifier is leaked, problems such as user privacy attacks and the exposure of user identity information will occur. However, these new devices do not support the authentication methods and protocols specified in the current standards. Moreover, without a USIM card, the user identity identifier of the device is also different from that of previous devices. For example, the identifiers of traditional devices focus more on the identification of the hardware itself. Without a USIM card, the user identity identifier may be more related to specific settings or initial configurations inside the device, and is used to distinguish and manage the device in a specific network or system environment. Its coding rules, scope of action, and the identifiers related to the Subscriber Identity Module (SIM) card are different to adapt to different usage scenarios and management requirements. However, there is no user identity privacy protection method for the above new devices in the related technologies.

[0027] In view of this, the present disclosure provides a method for protecting user identity privacy, which is applied to a core network element. The method includes: receiving a user registration request from a user terminal, where the user registration request includes a user identity hiding identifier; determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier; transmitting the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier, performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server and sending the identity authentication result to the user terminal. In the entire identity authentication process of the present disclosure, the user identity identifier always exists in the form of a user identity hiding identifier, reducing the risk of the identity information being stolen or misused during transmission and processing, effectively protecting the user identity privacy, and solving the problem of easy leakage of user identity information.

[0028] For ease of understanding, before introducing the embodiments of the present disclosure, several terms involved in the embodiments of the present disclosure are first explained as follows: Virtual Reality (VR) terminal: The hardware device of virtual reality technology, such as VR helmets, VR glasses, etc. Through these terminals, users can immerse themselves in a computer-generated three-dimensional virtual environment and experience immersive vision, hearing, etc. It is widely used in many fields such as games, education, and medical care.

[0029] Non-Universal Subscriber Identity Module (non-USIM) terminal: The Universal Subscriber Identity Module (USIM) is used to identify user identities and other operations in a mobile network. A non-USIM terminal is a terminal device that does not adopt such a universal module. Such terminals may be used in specific networks, specific functional requirements, or special application scenarios, and there are differences from ordinary mobile devices using USIM in terms of network access, function implementation, etc.

[0030] Core network element: It is a key component that constitutes the core part of a mobile communication network. It is responsible for processing and managing data and control information in the network to ensure that user terminals can communicate smoothly.

[0031] Access and Mobility Management Function (AMF): It is responsible for user access and mobility management, including processing user equipment access requests, mobility management, and radio resource allocation and other functions.

[0032] Generic Public Subscription Identifier (GPSI): An identifier used to uniquely identify a user in a network. Its function is to ensure the identity consistency of the user in the network. When a user accesses different data networks, there may be multiple GPSI identifiers. This is because different data networks may have their own identification systems. To identify the same user in these networks, different GPSI identifiers will be assigned to the user. However, these identifiers all point to the same real user to ensure the identity coherence and consistency of the user across different networks.

[0033] 3A Authentication Server (Authentication Authorization Accounting, AAA): Authentication is the process of verifying a user's identity, such as verifying whether you are a legitimate user through a username and password. Authorization is to determine the resources and operation permissions that a user can access after authentication. For example, some users can only read files but not modify them. Accounting is to statistically count and charge (if there is a charging requirement) the usage of network services and other resources by users, recording data such as usage duration and traffic for settlement. Enterprises or network operators manage user access permissions, ensure network security, reasonably allocate resources, and conduct cost accounting through a 3A authentication server.

[0034] Extended Reality (XR) Communication: A new type of communication method that integrates multiple technologies. XR includes Virtual Reality (VR), Augmented Reality (AR), and Mixed Reality (MR). VR is a completely virtual environment; AR is to superimpose virtual information on the real world; MR is the integration of the two. In terms of communication, it transmits data through a high-speed network. For example, a 5G network can transmit a large amount of images, videos, and other data with low latency, enabling users to obtain an immersive experience. Through XR technology, users can interact in a scenario where virtual and real blend, such as feeling as if they are in the same space in remote collaboration and learning knowledge vividly in an educational scenario.

[0035] Ubiquitous Link: It refers to a connection state that exists extensively and ubiquitously. In the field of information technology, ubiquitous link means that various devices, systems, people, etc. can achieve connection and interaction anytime and anywhere. For example, in the Internet of Things, numerous devices achieve ubiquitous link through various network technologies (such as wireless networking, Bluetooth, ZigBee technology, etc.). Sensors can be connected to the network and transmit the collected data to the cloud or other processing centers. The information exchange between people anytime and anywhere with the help of mobile terminals such as smartphones through social software is also an embodiment of ubiquitous link. It breaks the limitations of time and space, enabling information and resources to be shared and circulated within a wider range, greatly improving efficiency and convenience.

[0036] Fused Heterogeneous Networks: It means connecting and integrating multiple different types (heterogeneous) of networks. These different types of networks may have different topological structures, such as star-shaped, bus-shaped, etc.; different transmission media, such as optical fibers, twisted pairs; different protocols, such as TCP / IP, Bluetooth protocol, etc. The purpose of fusion is to achieve resource sharing and complementary advantages. For example, in the Internet of Things, fusing sensor networks (low power consumption, short distance), Wi-Fi networks (high-speed indoor coverage), and cellular networks (wide-area coverage) enables devices to switch networks according to their own needs, ensuring the timeliness of data transmission, expanding the coverage area, and reducing the overall cost.

[0037] The following will describe in detail the specific implementation manners of the embodiments of the present disclosure with reference to the accompanying drawings.

[0038] Figure 1 The exemplary application system architecture diagram in which the user identity privacy protection method in the embodiments of the present disclosure can be applied is shown. As Figure 1 shown, the system architecture includes a terminal device 101, a network 102, and a network-side device 103.

[0039] The network 102 is used as a medium to provide a communication link between the terminal device 101 and the network-side device 103, and can be a wired network or a wireless network.

[0040] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is usually the Internet, but can also be any network, including but not limited to any combination of a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network. In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPSec), etc. can be used to encrypt all or some of the links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.

[0041] Optionally, the terminal device in the embodiments of the present disclosure may also be referred to as a UE (User Equipment). In specific implementations, the terminal device may be a virtual reality terminal, a non-universal subscriber identity module terminal, an Internet of Things (IoT) device, a wearable device, or a vehicle-mounted device, etc. It should be noted that the specific type of the terminal device is not limited in the embodiments of the present invention.

[0042] The network-side device may be a base station, a relay, or an access point, etc. The base station may be a base station of 5G and later versions (for example: 5G NR NB), or a base station in other communication systems (for example: eNB base station). It should be noted that the specific type of the network-side device is not limited in the embodiments of the present disclosure.

[0043] Those skilled in the art can know that Figure 1 the numbers of the terminals, networks, and network-side devices in are merely illustrative. According to actual needs, there can be any number of terminals, networks, and network-side devices. The embodiments of the present disclosure do not limit this.

[0044] Under the above system architecture, an embodiment of the present disclosure provides a method for protecting user identity privacy, which can be executed by any electronic device with computing and processing capabilities.

[0045] In some embodiments, the method for protecting user identity privacy provided in the embodiments of the present disclosure can be executed by the network-side device in the above system architecture; in other embodiments, the method for protecting user identity privacy provided in the embodiments of the present disclosure can be implemented by the interaction between the terminal device and the network-side device in the above system architecture.

[0046] Figure 2 The flowchart of a method for protecting user identity privacy in an embodiment of the present disclosure is shown, which is applied to a core network element. As Figure 2 shown, the method for protecting user identity privacy provided in the embodiments of the present disclosure includes the following steps: S202, receiving a user registration request from a user terminal, where the user registration request includes a user identity concealment identifier.

[0047] In this embodiment, the user terminal is a device used by the user to interact with the system, such as a virtual reality terminal, a non-universal subscriber identity module terminal, an Internet of Things device, a wearable device, or a vehicle-mounted device, etc. The user registration request is request information sent by the user terminal to a certain system, platform, or service to initiate the registration of an account. The user identity concealment identifier (UserIdentity Concealed, UIC) is an identifier used to conceal the user's real identity, which can be a special string of codes, etc. Among them, the virtual reality terminal is, for example, a VR helmet, a VR glasses, etc.; the Internet of Things device is, for example, a smart meter, a smart camera, etc.; the wearable device is, for example, a smart watch, a smart bracelet; the vehicle-mounted device is, for example, a vehicle-mounted navigator, a vehicle-mounted entertainment system, etc.

[0048] Specifically, the user terminal sends a user registration request to the core network, which carries the user identity concealment identifier. The core network element receives this user registration request containing the user identity concealment identifier.

[0049] In some embodiments, the core network element is specifically an access and mobility management function network element. The access and mobility management function network element AMF is mainly responsible for the access management of the terminal device. For example, when the user terminal searches for a network, AMF participates in it and decides whether it can access the network. At the same time, it also manages the mobility of the terminal. For example, when the user terminal moves between different base station coverage areas, AMF coordinates handover and other operations to ensure that the communication is not interrupted, and undertakes key management and control tasks related to access and mobility in the entire core network function system.

[0050] In some embodiments, the user identity concealment identifier is obtained by encrypting the user identity identifier through any one of the following encryption algorithms: hash algorithm, mapping table, and post-quantum cryptography algorithm.

[0051] In this embodiment, the User Identity (UID) is a unique identifier for identifying a user. The hash algorithm maps data of any length to a hash value of a fixed length. It is one-way, meaning it is difficult to restore the original data from the hash value. When used for user identity hiding identification, the user identity is taken as input to obtain a seemingly random hash value to represent the identity, thus achieving a hiding effect. The mapping table is a pre-set correspondence table. By establishing the mapping relationship between the user identity and another value (the user identity hiding identifier), the true identity identifier can be converted into a hiding identifier according to this mapping table, achieving the hiding effect. The post-quantum cryptography algorithm is an encryption algorithm developed in response to the threat of quantum computing. In the scenario of user identity hiding identification, using its special encryption mechanism, such as based on mathematical structures like lattices, the user identity is encrypted into a hiding identifier that is difficult to crack.

[0052] Specifically, the user terminal encrypts the user identity using at least one of the hash algorithm, the mapping table, and the post-quantum cryptography algorithm to obtain the user identity hiding identifier.

[0053] In some embodiments, considering that traditional encryption algorithms are based on mathematical problems, such as asymmetric encryption algorithms based on large integer factorization, but quantum computers have strong computing power and can quickly crack these problems, threatening communication security. Post-quantum encryption algorithms are based on new mathematical problems, such as lattice cryptography, which are difficult for quantum computers to efficiently crack. In a communication system, using a post-quantum encryption algorithm to encrypt the user identity to obtain the user identity hiding identifier, even if future quantum computing technology develops and matures, attackers will be difficult to obtain the correct key through the user identity hiding identifier to decrypt the communication content, thus ensuring the security of the user identity in the era of quantum computing and resisting the threats it brings.

[0054] S204, determine the subscription identity information of the user terminal in the network according to the user identity hiding identifier.

[0055] In this embodiment, the subscription identity information of the user terminal in the network refers to the legal identity attributes registered by the user with the network operator or service provider, usually bound to service functions. For example: The subscription identity information can be the Generic Public Subscription Identifier (GPSI) of the user terminal in the network: public identifiers such as email addresses, used in scenarios such as service billing and service activation.

[0056] Specifically, the link between the user identity hiding identifier and the subscription identity information (e.g., General Public User Identity) corresponds the internal identifier of the user with the externally recognizable public identifier, so as to achieve accurate identification of the user identity and service provision. In this embodiment, through the user identity hiding identifier, on the premise of protecting the user's real identity, it is securely associated with the user's subscription identity information (e.g., GPSI) in the network, thus supporting the normal operation of network services and ensuring privacy compliance at the same time.

[0057] S206, transmit the user identity hiding identifier to the identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier, conducts identity authentication, and returns the identity authentication result to the core network element based on the subscription identity information.

[0058] In this embodiment, transmission refers to the core network element transparently forwarding the user identity hiding identifier without any processing on the user identity hiding identifier. Therefore, the core network element does not know the user identity identifier corresponding to the user identity hiding identifier, which can effectively protect the user privacy and prevent the user identity information from being leaked or misused during the transmission process. And it can also reduce the space and processing resources required for the core network element to store and manage the real identity of each user, that is, the user identity identifier.

[0059] The identity authentication server is responsible for receiving the transmitted information, decrypting the user identity hiding identifier by using the corresponding decryption key and / or encryption algorithm, so as to obtain the original user identity identifier-related data. The identity authentication server further compares and verifies the decrypted user identity identifier and other information with the legitimate user information database stored by itself. Check whether things such as username, password, digital certificate, etc. match, etc., to determine the legitimacy of the user identity. If the identity authentication is successful or failed, the identity authentication server will send a message containing the authentication result (success or failure and related additional information) back to the core network element based on the subscription identity information (such as the permissions corresponding to the user package), and the core network element will perform corresponding processing on the subsequent operations of the user accordingly.

[0060] In some embodiments, the identity authentication server is a 3A authentication server, also called an AAA authentication server. The AAA authentication server can complete authentication and management in an external data network rather than in the core network, sharing the workload and reducing the management pressure on the core network.

[0061] In some embodiments, the ways for the identity authentication server to conduct identity authentication include identity authentication based on the Extensible Authentication Protocol or identity authentication based on database identity information.

[0062] In this embodiment, the Extensible Authentication Protocol (EAP) is a network authentication framework. It provides a standard method for transmitting authentication information between network devices. When performing identity authentication based on the Extensible Authentication Protocol, authentication information is exchanged between the identity authentication server and the user terminal. Specifically, the EAP architecture can be used to complete authentication between the user terminal and the 3A authentication server. It allows the user terminal and the 3A authentication server to exchange information through a series of authentication methods. The user terminal initiates an authentication request to the 3A authentication server, and the EAP protocol defines the message format and interaction process in this process. For example, in the common EAP-TLS method, the user terminal provides a user identity hidden identifier as the information to be authenticated, and the 3A authentication server decides whether to pass the authentication after verification, thereby establishing a secure connection and realizing operations such as the interaction permission management of the user terminal and network resources.

[0063] In this embodiment, identity authentication based on database identity information is to compare and verify the identity information provided by the user (such as username, password, etc.) with the identity data stored in the database. As a repository of information, the database has pre-stored the identity-related information of legitimate users. When the user terminal initiates an authentication request, the 3A authentication server obtains the user hidden identity identifier and decrypts it to obtain the user identity identifier, and then searches for matching records in the database. If there is a corresponding record for the user identity identifier in the database and the verification information such as the password is also consistent, the authentication passes; otherwise, it fails. This method can effectively confirm the user's identity by leveraging the reliable storage and efficient query capabilities of the database.

[0064] In some embodiments, considering the problems that it is difficult to ensure the accuracy, security, or integrity of identity authentication relying solely on the user identity hidden identifier. The subscription identity information is transparently transmitted to the identity authentication server, and the identity authentication server uses its own capabilities to decrypt the user identity hidden identifier to obtain the real identity identifier, and then combines the subscription identity information to accurately determine whether the user identity is legal, thereby completing the identity authentication and improving the reliability of identity authentication. That is, the method provided in this embodiment further includes: transparently transmitting the subscription identity information to the identity authentication server, so that the identity authentication server decrypts the user identity hidden identifier to obtain the user identity identifier, and performs identity authentication based on the user identity identifier and the subscription identity information.

[0065] In some embodiments, the identity authentication result is associated with the user identity hidden identifier. In subsequent operations, the user can be identified as having passed the authentication through the user identity hidden identifier, which not only protects the user's privacy (without directly exposing the real identity), but also enables relevant business operations based on the authentication situation.

[0066] S208, receive the identity authentication result returned by the identity authentication server and send the identity authentication result to the user terminal.

[0067] In the above embodiment, throughout the identity authentication process, the user identity identifier always exists in the form of a user identity hidden identifier, reducing the risk of the identity information being stolen or misused during transmission and processing, effectively protecting the user identity privacy, and solving the problem of easy leakage of user identity information.

[0068] Figure 3 The flowchart of a method for determining subscription identity information in an embodiment of the present disclosure is shown. As Figure 3 shown, the method for determining subscription identity information provided in the embodiment of the present disclosure includes the following steps: S302, obtain the association relationship table of the user identity hidden identifier and the subscription identity information.

[0069] In this embodiment, the association means establishing a logical binding relationship between the user identity hidden identifier and the subscription identity information (such as GPSI) through technical means (such as a mapping table, an encrypted link). The identity mapping database of the core network element stores the association relationship table of the user identity hidden identifier and the subscription identity information.

[0070] In some embodiments, during the process of establishing the association between the user identity hidden identifier and the subscription identity information, the core network element can only authorize the core network element for reverse association, and external entities cannot decrypt it. In addition, the user identity hidden identifier can be updated regularly to prevent long-term tracking.

[0071] S304, determine the subscription identity information of the user terminal in the network according to the user identity hidden identifier in the association relationship table.

[0072] In this embodiment, query the subscription identity information associated and bound with the user identity hidden identifier from the association relationship table. For example, decrypt it through a key or perform a reverse lookup in a hash table. After finding the subscription identity information of the user terminal in the network, return the subscription identity attributes of the user for subsequent service processing (such as charging, service activation, identity authentication). In this way, the external system can only obtain the subscription identity attributes required for the service and cannot trace the true identity of the user.

[0073] In some embodiments, in order to prevent illegal operations and unauthorized use of the association relationship, thereby ensuring the security, stability, and user identity privacy of the entire communication network. The core network element can also verify the legitimacy of the user terminal to ensure that only authorized services can perform the association operation.

[0074] Therefore, the user registration request provided in this embodiment further includes at least one of the following: the operation type, operation time, and operation location of the user terminal; determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier, including: determining the access right of the user identity hiding identifier to the associated relationship table according to the operation type and / or operation time and / or operation location of the user terminal; determining the subscription identity information of the user terminal in the network according to the access right and the user identity hiding identifier.

[0075] In this embodiment, the operation type of the user terminal refers to the types of operations performed by the user terminal during the registration process, such as creating an account, modifying information, etc. The operation time is the moment when the user terminal performs registration-related operations, which can be used to analyze the user behavior pattern, etc. The operation location is the geographical location where the user terminal performs the registration operation, which may affect service provision, etc.

[0076] In this embodiment, when determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier, the obtained associated relationship table is used to find the entry corresponding to the hiding identifier in the table, so as to determine the subscription identity information of the associated user terminal in the network. This can protect the user identity privacy because what is directly contacted is the user identity hiding identifier rather than the real user identity identifier.

[0077] Figure 4 The flowchart of a method for identity authentication in an embodiment of the present disclosure is shown, as Figure 4 shown, the identity authentication method provided in the embodiment of the present disclosure includes the following steps: S402, adding an associated verification code to the user identity hiding identifier and the subscription identity information.

[0078] In this embodiment, the associated verification code is a code used to establish the association between the two and perform verification. After adding the associated verification code to the user identity hiding identifier and the subscription identity information, while protecting the user's hidden identity, it can ensure the accuracy and relevance of the subscription identity information, facilitating accurate identity recognition and operation verification in a specific system or service.

[0079] Therefore, before transmitting the user identity hiding identifier to the identity authentication server according to the subscription identity information in this embodiment, by adding an associated verification code to the user identity hiding identifier and the subscription identity information, the security and reliability are guaranteed.

[0080] S404, transmitting the user identity hiding identifier, the subscription identity information, and the associated verification code to the identity authentication server.

[0081] In this embodiment, the identity authentication server can verify the consistency and legality of the association relationship between the previous user identity hiding identifier and the subscription identity information by virtue of the associated verification code, enhancing the security.

[0082] Figure 5 Shows a signaling diagram of a user identity privacy protection method in an embodiment of the present disclosure, as Figure 5 shown, the user identity privacy protection method includes: S501. The user terminal sends a registration request to the AMF, and the registration request includes a user identity hiding identifier.

[0083] S502. The AMF sends an authentication request to the AAA, and the authentication request includes a user identity hiding identifier and a general public user identifier.

[0084] In this embodiment, the AMF determines the general public user identifier according to the user identity hiding identifier. The AAA function is implemented in a cloud computing environment.

[0085] S503. The user terminal and the AAA perform user identity authentication.

[0086] In this embodiment, the AAA decrypts the user identity hiding identifier to perform user identity authentication.

[0087] S504. The AAA sends an authentication response to the AMF, and the authentication response includes a user identity hiding identifier and a general public user identifier.

[0088] In this embodiment, the authentication response is used to indicate the authentication result of the user identity authentication.

[0089] S505. The AMF sends a registration response to the user terminal.

[0090] In this embodiment, the registration response may include a status identifier indicating success or failure of registration, informing the user terminal whether the registration is successful; it may also include network resource related information assigned to the user terminal, such as a specific network slice identifier, etc.; it may also contain some security related parameters or key information for security guarantee of subsequent communication, etc. This embodiment does not limit the content included in the registration response.

[0091] Figure 6 Shows a specific method flow chart of a user identity privacy protection method in an embodiment of the present disclosure, as Figure 6 shown, the user identity privacy protection method includes: S601. The user terminal device encrypts the user identity identifier into a user identity hiding identifier.

[0092] In this embodiment, specific encryption methods can adopt traditional hash algorithms or mapping tables, etc., or can also adopt post-quantum cryptographic algorithms to complete the protection to resist future quantum computing attacks.

[0093] S602. The user terminal sends a registration request including a user identity hiding identifier to the AMF network element.

[0094] S603. After the AMF network element receives a registration request, it links to the general public user identifier of the user in the network according to the user identity hiding identifier.

[0095] In this embodiment, the AMF transparently forwards the user identity hiding identifier of the network element and is unaware of the user identity identifier corresponding to the user identity hiding identifier.

[0096] S604. The AMF network element sends the user identity hiding identifier and the general public user identifier to the AAA authentication server.

[0097] S605. The AAA authentication server decrypts the user identity hiding identifier into a user identity identifier.

[0098] In this embodiment, according to the processes of S601 to S605, encryption protection is completed for the user identity identifier, avoiding linkability and traceability attacks that may be caused by privacy leakage.

[0099] S606. The AAA authentication server performs identity authentication.

[0100] In this embodiment, the AAA authentication server can perform identity authentication based on the EAP architecture to complete the identity authentication between the user terminal and the AAA; or it can use the method of matching database identity information to complete the identity authentication. If the identity authentication result matches, the identity authentication is successful, and the user terminal is granted the permission to access the network; if the identity authentication result does not match, the identity authentication fails, and network access will be denied.

[0101] S607. The AAA authentication server sends the authentication result to the AMF network element.

[0102] In this embodiment, the authentication result is identified by the user identity hiding identifier.

[0103] In this embodiment, for the application scenarios in future communication networks, the AAA authentication server in the external data network completes point-to-point identity authentication and identity management. The core network element only transparently forwards the user identity hiding identifier and is unaware of the user's true identity, that is, the user identity identifier, further reducing the exposure surface of the user identity, and at the same time saving storage space and management threads in the network.

[0104] It should be noted that the application scenarios of the above embodiments of the present disclosure include but are not limited to the following application scenarios: immersive extended display communication; ubiquitous link scenario, multi-type terminal devices accessing a converged heterogeneous network.

[0105] It should be noted that the acquisition, storage, use, processing, etc. of data in the technical solution of the present disclosure all comply with the relevant provisions of national laws and regulations. In the embodiments of the present disclosure, various types of data such as personal identity data, operation data, and behavior data related to individuals, customers, and groups have been authorized.

[0106] Based on the same inventive concept, an apparatus for protecting user identity privacy is also provided in the embodiments of the present disclosure, as described in the following embodiments. Since the principle of solving problems in this apparatus embodiment is similar to that in the above method embodiment, the implementation of this apparatus embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be elaborated.

[0107] Figure 7 The following shows a schematic diagram of an apparatus for protecting user identity privacy in the embodiments of the present disclosure, as Figure 7 shown, the apparatus includes: a first receiving module 71, a determining module 72, a transparent transmission module 73, and a second receiving module 74; The first receiving module 71 is configured to receive a user registration request from a user terminal, where the user registration request includes a user identity hiding identifier; the determining module 72 is configured to determine the subscription identity information of the user terminal in the network according to the user identity hiding identifier; the transparent transmission module 73 is configured to transparently transmit the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier, performs identity authentication, and returns an identity authentication result to a core network element based on the subscription identity information; the second receiving module 74 is configured to receive the identity authentication result returned by the identity authentication server and send the identity authentication result to the user terminal.

[0108] In some embodiments, the determining module 72 is specifically configured to: obtain an association relationship table of the user identity hiding identifier and the subscription identity information; determine the subscription identity information of the user terminal in the network according to the user identity hiding identifier in the association relationship table.

[0109] In some embodiments, the user registration request further includes at least one of the following: an operation type of the user terminal, an operation time, and an operation location; the determining module 72 is specifically configured to: determine an access right of the user identity hiding identifier to the association relationship table according to the operation type and / or the operation time and / or the operation location of the user terminal; determine the subscription identity information of the user terminal in the network according to the access right and the user identity hiding identifier.

[0110] In some embodiments, the pass-through module 73 is further configured to: pass through the subscription identity information to the identity authentication server, so that the identity authentication server decrypts the user identity hidden identifier to obtain a user identity identifier, and performs identity authentication based on the user identity identifier and the subscription identity information.

[0111] In some embodiments, before passing through the user identity hidden identifier to the identity authentication server according to the subscription identity information, the pass-through module 73 is further configured to: add an associated verification code to the user identity hidden identifier and the subscription identity information, and pass through the user identity hidden identifier, the subscription identity information, and the associated verification code to the identity authentication server.

[0112] In some embodiments, the user identity hidden identifier is obtained by encrypting the user identity identifier through any one of the following encryption algorithms: hash algorithm, mapping table, and post-quantum cryptography algorithm.

[0113] In some embodiments, the identity authentication result is associated with the user identity hidden identifier.

[0114] In some embodiments, the core network element is an access and mobility management function network element, and the identity authentication server is a 3A authentication server.

[0115] In some embodiments, the method for performing identity authentication includes performing identity authentication based on an extensible authentication protocol or performing identity authentication based on database identity information.

[0116] It should be noted here that the examples and application scenarios implemented by each module in the above device embodiments are the same as the corresponding steps in the method embodiments, but are not limited to the content disclosed in the above method embodiments. It should be noted that the above modules, as part of the device, can be executed in a computer system such as a set of computer-executable instructions.

[0117] Those skilled in the art of the present technology can understand that various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module", or "system" here.

[0118] Based on the same inventive concept, embodiments of the present disclosure also provide an electronic device, which includes: a processor; and a memory for storing executable instructions of the processor; wherein, the processor is configured to execute the user identity privacy protection method of any one of the above via executing the executable instructions. Since the principle of solving problems in the embodiments of this electronic device is similar to that of the above method embodiments, the implementation of the embodiments of this electronic device can refer to the implementation of the above method embodiments, and the repeated parts will not be elaborated.

[0119] The following refers to Figure 8 to describe the electronic device 800 according to this embodiment of the present disclosure. Figure 8 The electronic device 800 shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0120] As Figure 8 shown, the electronic device 800 is presented in the form of a general-purpose computing device. The components of the electronic device 800 may include but are not limited to: at least one of the above processing units 810, at least one of the above storage units 820, and a bus 830 connecting different system components (including the storage unit 820 and the processing unit 810).

[0121] Among them, the storage unit stores program codes, and the program codes can be executed by the processing unit 810, so that the processing unit 810 executes the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification. For example, the processing unit 810 may execute the following steps of the above method embodiment: receiving a user registration request from a user terminal, where the user registration request includes a user identity hiding identifier; determining subscription identity information of the user terminal in the network according to the user identity hiding identifier; transmitting the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier and performs identity authentication, and returns an identity authentication result to a core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server and sending the identity authentication result to the user terminal.

[0122] The storage unit 820 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 8201 and / or a cache storage unit 8202, and may further include a read-only storage unit (ROM) 8203.

[0123] The storage unit 820 may also include a program / utilities 8204 having a set (at least one) of program modules 8205. Such program modules 8205 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0124] The bus 830 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus structures.

[0125] The electronic device 800 may also communicate with one or more external devices 840 (such as a keyboard, a pointing device, a Bluetooth device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 800, and / or may communicate with any device that enables the electronic device 800 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication may be carried out through the input / output (I / O) interface 850. Moreover, the electronic device 800 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 860. As shown in the figure, the network adapter 860 communicates with other modules of the electronic device 800 through the bus 830. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 800, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0126] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which may be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which may be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0127] Based on the same inventive concept, embodiments of the present disclosure also provide a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, it implements the user identity privacy protection method of any one of the above. Since the principle of solving problems in the embodiments of the computer-readable storage medium is similar to that of the above method embodiments, the implementation of the embodiments of the computer-readable storage medium can refer to the implementation of the above method embodiments, and the repeated parts will not be described again.

[0128] More specific examples of the computer-readable storage medium in the present disclosure may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs or flash memories), optical fibers, portable compact disk read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the above.

[0129] In the present disclosure, the computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, and this readable medium may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0130] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination of the above.

[0131] In specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages. The programming languages include object-oriented programming languages - such as Java, C++, etc., and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).

[0132] Based on the same inventive concept, embodiments of the present disclosure also provide a computer program product, including: a computer program or instructions, which, when executed by a processor, implement the user identity privacy protection method of any one of the above method embodiments. Since the principle of solving problems in this computer program product embodiment is similar to that of the above method embodiments, the implementation of this computer program product embodiment can refer to the implementation of the above method embodiments, and the repeated parts will not be elaborated.

[0133] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the above-described modules or units can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0134] In addition, although the steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that these steps must be executed in that specific order, or that all the steps shown must be executed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.

[0135] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described here can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0136] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed by the present disclosure. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.

Claims

1. A user identity privacy protection method, characterized in that: Applied to a core network element, the method comprises: Receiving a user registration request from a user terminal, wherein the user registration request includes a user identity hiding identifier; Determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier; transparently transmitting the user identity hiding identifier to the identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier and performs identity authentication, and returns the identity authentication result to the core network element based on the subscription identity information; Receive the identity authentication result returned by the identity authentication server, and send the identity authentication result to the user terminal.

2. The user identity privacy protection method according to claim 1, characterized in that: The determining, according to the user identity hiding identifier, the subscription identity information of the user terminal in the network includes: Obtaining an association table between the user identity hiding identifier and the subscription identity information; According to the user identity hiding identifier in the association relationship table, the subscription identity information of the user terminal in the network is determined.

3. The user identity privacy protection method according to claim 2, characterized in that: The user registration request also includes at least one of the following: the operation type, operation time and operation location of the user terminal; The determining, according to the user identity hiding identifier, the subscription identity information of the user terminal in the network includes: Determining the access permission of the user identity hiding identifier to the association relationship table according to the operation type and / or the operation time and / or the operation location of the user terminal; The subscription identity information of the user terminal in the network is determined according to the access authority and the user identity hiding identifier.

4. The user identity privacy protection method according to claim 1, characterized in that: The method further includes: transparently transmitting the subscription identity information to an identity authentication server, so that the identity authentication server decrypts the user identity hidden identifier to obtain a user identity identifier, and performs identity authentication according to the user identity identifier and the subscription identity information.

5. The user identity privacy protection method according to claim 4, characterized in that: Before transparently transmitting the user identity hiding identifier to the identity authentication server according to the subscription identity information, the method further includes: Adding an associated verification code to the user identity hiding identifier and the subscription identity information; The step of transparently transmitting the user identity hiding identifier to the identity authentication server according to the subscription identity information includes: The user identity hiding identifier, the subscription identity information and the associated verification code are transparently transmitted to the identity authentication server.

6. The user identity privacy protection method according to claim 1, characterized in that: The user identity hiding identifier is obtained by encrypting the user identity identifier through any one of the following encryption algorithms: hash algorithm, mapping table and post-quantum cryptography algorithm.

7. The user identity privacy protection method according to claim 1, characterized in that: The identity authentication result is associated with the user identity hiding identifier.

8. The user identity privacy protection method according to claim 1, characterized in that: The core network element is an access and mobility management function network element, and the identity authentication server is a 3A authentication server.

9. The user identity privacy protection method according to claim 1, characterized in that: The method of performing identity authentication includes performing identity authentication based on an extended authentication protocol or performing identity authentication based on database identity information.

10. A user identity privacy protection device, characterized in that: Applied to a core network element, the device comprises: A first receiving module, configured to receive a user registration request from a user terminal, wherein the user registration request includes a user identity hiding identifier; A determination module, configured to determine the subscription identity information of the user terminal in the network according to the user identity hiding identifier; A transparent transmission module, configured to transparently transmit the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier, performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; The second receiving module is used to receive the identity authentication result returned by the identity authentication server and send the identity authentication result to the user terminal.

11. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; Wherein, the processor is configured to execute the user identity privacy protection method described in any one of claims 1 to 9 by executing the executable instructions.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the user identity privacy protection method described in any one of claims 1 to 9 is implemented.

13. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the user identity privacy protection method described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Method and device for verifying user equipment identifier in authentication process

    CN110798833A

  • Private network cross-network authentication method and device

    CN114070597A

  • Subscription retrieval for anonymous identification

    CN115885531A

  • Security of non-3GPP access to 3GPP-based non-public network

    WO2024165759A1