User identity privacy protection method and related device
By encrypting the user's identity identifier as a hidden identifier and transmitting it to the identity authentication server for decryption and authentication, the problem of easy leakage of user identity information on new devices is solved, and user identity privacy is effectively protected.
Patent Information
- Application Number
- CN202510622405.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-14
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-05-14
AI Technical Summary
Existing user identity protection mechanisms are difficult to apply to new devices, leading to easy leakage of user identity information and failing to effectively protect user privacy on new devices.
By receiving user registration requests from user terminals, the system uses hash algorithms, mapping tables, and post-quantum cryptography algorithms to encrypt user identity identifiers as hidden identifiers, determines the subscriber identity information, and transmits it to the identity authentication server for decryption and authentication, ensuring that user identity privacy is not stolen or abused during transmission and processing.
It effectively protects user identity privacy, reduces the risk of identity information leakage, and ensures the security of user identity information during transmission and processing.
Smart Images

Figure CN120151828B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of wireless communication, and particularly relates to a user identity privacy protection method and related equipment. BACKGROUND
[0002] With the development of mobile communication, the diversification of network access devices, including new devices such as virtual reality (VR) and non-universal subscriber identity module (non-USIM) terminals. In the face of new communication scenarios, due to the difference between the user identity of the new device and the traditional device, and the use of non-standard authentication methods and protocols, the authentication methods and protocols based on supporting conventional devices are not suitable for new devices.
[0003] Due to this mismatch, the related art cannot effectively authenticate new devices. At the same time, due to the difference between the user identity of the new device and the traditional device, the existing user identity protection mechanism is also difficult to apply to the new device, and cannot well protect the user privacy of the new device, which is easy to cause the user identity identifier to be leaked and cause privacy attacks and identity information exposure.
[0004] It should be noted that the information disclosed in the above background section is only used to strengthen the understanding of the background of the present disclosure, and therefore can include information that does not constitute prior art known to those of ordinary skill in the art. SUMMARY
[0005] The present disclosure provides a user identity privacy protection method and related equipment, which encrypts and protects the user identity, avoiding user identity privacy leakage.
[0006] Other characteristics and advantages of the present disclosure will become apparent from the following detailed description, or will be learned by practice of the present disclosure.
[0007] According to one aspect of the present disclosure, a user identity privacy protection method is provided, applied to a core network element, the method comprising: receiving a user registration request from a user terminal, the user registration request comprising a user identity hiding identifier; determining subscription identity information of the user terminal in the network according to the user identity hiding identifier; transmitting the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier and performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server, and sending the identity authentication result to the user terminal.
[0008] In some embodiments, the determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier comprises: obtaining a correlation table of the user identity hiding identifier and the subscription identity information; and determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier in the correlation table.
[0009] In some embodiments, the user registration request further comprises at least one of the following: an operation type, an operation time and an operation location of the user terminal; and the determining the subscription identity information of the user terminal in the network according to the user identity hiding identifier comprises: determining an access right of the user identity hiding identifier to the correlation table according to the operation type and / or the operation time and / or the operation location of the user terminal; and determining the subscription identity information of the user terminal in the network according to the access right and the user identity hiding identifier.
[0010] In some embodiments, the method further comprises: transmitting the subscription identity information to an identity authentication server in a transparent manner, so that the identity authentication server decrypts the user identity hiding identifier to obtain a user identity identifier, and performs identity authentication according to the user identity identifier and the subscription identity information.
[0011] In some embodiments, before the transmitting the user identity hiding identifier to the identity authentication server in a transparent manner according to the subscription identity information, the method further comprises: adding a correlation check code to the user identity hiding identifier and the subscription identity information; and the transmitting the user identity hiding identifier to the identity authentication server in a transparent manner according to the subscription identity information comprises: transmitting the user identity hiding identifier, the subscription identity information and the correlation check code to the identity authentication server in a transparent manner.
[0012] In some embodiments, the user identity hiding identifier is obtained by encrypting a user identity identifier by using any one of the following encryption algorithms: a hash algorithm, a mapping table and a post-quantum cryptography algorithm.
[0013] In some embodiments, the identity authentication result is associated with the user identity hiding identifier.
[0014] In some embodiments, the core network element is an access and mobility management function network element, and the identity authentication server is a 3A authentication server.
[0015] In some embodiments, the identity authentication manner comprises an identity authentication based on an extended authentication protocol or an identity authentication based on database identity information.
[0016] According to another aspect of the present disclosure, there is also provided a user identity privacy protection apparatus applied to a core network element, the apparatus comprising: a first receiving module configured to receive a user registration request from a user terminal, the user registration request comprising a user identity hiding identifier; a determining module configured to determine subscription identity information of the user terminal in a network according to the user identity hiding identifier; a transparent transmission module configured to transparently transmit the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier and performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; and a second receiving module configured to receive the identity authentication result returned by the identity authentication server and send the identity authentication result to the user terminal.
[0017] According to another aspect of the present disclosure, there is also provided an electronic device comprising: a processor; and a memory configured to store executable instructions of the processor; wherein the processor is configured to execute any of the above-mentioned user identity privacy protection methods via execution of the executable instructions.
[0018] According to another aspect of the present disclosure, there is also provided a computer readable storage medium having a computer program stored thereon, the computer program being executed by a processor to implement any of the above-mentioned user identity privacy protection methods.
[0019] According to another aspect of the present disclosure, there is also provided a computer program product comprising: a computer program or instructions, the computer program or instructions being executed by a processor to implement any of the above-mentioned user identity privacy protection methods.
[0020] The user identity privacy protection method and related device provided in the embodiments of the present disclosure. The method comprises: receiving a user registration request from a user terminal, the user registration request comprising a user identity hiding identifier; determining subscription identity information of the user terminal in a network according to the user identity hiding identifier; transparently transmitting the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier and performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; and receiving the identity authentication result returned by the identity authentication server and sending the identity authentication result to the user terminal. In the entire identity authentication process, the user identity identifier always exists in the form of the user identity hiding identifier, reducing the risk of identity information being stolen or misused in the transmission and processing process, effectively protecting the user identity privacy, and solving the problem of easy leakage of user identity information.
[0021] It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0022] The accompanying drawings, which are incorporated in and form a part of the specification, illustrate one or more embodiments of the present disclosure and, together with the description, serve to explain the principles of the disclosure. It is to be understood that other drawings can be obtained from these drawings by virtue of the drawings merely being a few embodiments of the present disclosure, and other drawings can be obtained by those of ordinary skill in the art without any creative effort.
[0023] Figure 1 A schematic diagram of a system architecture of a user identity privacy protection method in an embodiment of the present disclosure is shown.
[0024] Figure 2 A flowchart of a user identity privacy protection method in an embodiment of the present disclosure is shown.
[0025] Figure 3 A flowchart of a method for determining subscription identity information in an embodiment of the present disclosure is shown.
[0026] Figure 4 A flowchart of a method for identity authentication in an embodiment of the present disclosure is shown.
[0027] Figure 5 A signaling diagram of a user identity privacy protection method in an embodiment of the present disclosure is shown.
[0028] Figure 6 A specific method flowchart of a user identity privacy protection method in an embodiment of the present disclosure is shown.
[0029] Figure 7 A schematic diagram of a user identity privacy protection apparatus in an embodiment of the present disclosure is shown.
[0030] Figure 8 A structural block diagram of an electronic device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0031] Example implementations will now be described more fully with reference to the accompanying drawings. Example implementations may, however, be implemented in many different forms and should not be construed as limited to the implementations set forth herein; rather, these implementations are provided so that this disclosure will be thorough and complete, and will fully convey the scope of example implementations to those skilled in the art. Features described in the description, structures, or characteristics may be combined in any suitable manner in one or more implementations.
[0032] Furthermore, the accompanying drawings are only schematic and are non-limiting. Identical components have been given the same reference numerals in the various drawings and the same reference designators have been used throughout for like components, and description of the same will not be repeated unless new features are present. Some of the blocks in the drawings are function blocks that represent functions implemented by software, hardware or a combination of software and hardware. These function blocks can be implemented with software and stored in a memory or an integrated circuit, or they can be implemented with hardware, or they can be implemented with a combination of software and hardware.
[0033] With the expansion of mobile communication network services, more and more types of devices are connected to the network. Previously, terminal devices embedded with Universal Subscriber Identity Module (USIM) cards and Internet of Things (IoT) terminals were mainly connected to the network, and now, new devices such as VR devices, non-USIM terminals, and even biometrics and digital identities can also be connected to the network. These new devices are for future communication scenarios, such as immersive communication and ubiquitous connectivity. Network systems should support authentication and privacy protection for new devices, and once user identity is leaked, it will cause user privacy attacks and user identity information exposure. However, these new devices do not support the authentication methods and protocols specified in the current standards. Moreover, without a USIM card, the user identity of the device is also different from that of previous devices. For example, the identity of traditional devices focuses more on the identification of the hardware itself. Without a USIM card, the user identity may be more related to specific settings or initial configurations inside the device, used to distinguish and manage the device in a specific network or system environment, and its coding rules, scope of action, and traditional SIM card-based identity are different, to adapt to different use scenarios and management needs. However, there is no user identity privacy protection method for the above new devices in the related art.
[0034] Therefore, the present disclosure provides a user identity privacy protection method applied to a core network element, which comprises: receiving a user registration request from a user terminal, the user registration request comprising a user identity hiding identifier; determining subscription identity information of the user terminal in the network according to the user identity hiding identifier; transmitting the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier, performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server, and sending the identity authentication result to the user terminal. In the entire identity authentication process, the user identity identifier always exists in the form of the user identity hiding identifier, reducing the risk of identity information being stolen or misused in the transmission and processing process, effectively protecting the user identity privacy, and solving the problem of easy leakage of user identity information.
[0035] For ease of understanding, before introducing the embodiments of the present disclosure, first, several terms involved in the embodiments of the present disclosure are explained as follows:
[0036] Virtual Reality (VR) terminal: hardware device of virtual reality technology, such as VR helmet, VR glasses, etc. Through these terminals, users can immerse in a three-dimensional virtual environment generated by a computer, and experience visual, auditory, etc. in-game, education, medical treatment, etc. in many fields.
[0037] Non-Universal Subscriber Identity Module (non-USIM) terminal: Universal Subscriber Identity Module (USIM) is used for identifying user identity and other operations in mobile networks. The non-USIM terminal is a terminal device that does not use such a universal module. Such terminals may be used in specific networks, specific functional requirements or special application scenarios, and there are differences in network access, function implementation, etc. with ordinary mobile devices using USIM.
[0038] Core network element: a key component that constitutes the core part of a mobile communication network. It is responsible for processing and managing data and control information in the network, ensuring smooth communication of user terminals.
[0039] Access and Mobility Management Function (AMF): responsible for user access and mobility management, including processing user device access requests, mobility management, and wireless resource allocation functions.
[0040] Generic Public Subscription Identifier (GPSI): An identifier used to uniquely identify a user in a network, which serves to ensure the consistency of the user's identity in the network. When a user accesses different data networks, there may be multiple GPSI identifiers. This is because different data networks may have their own identification systems, and in order to identify the same user in these networks, different GPSI identifiers will be assigned to the user. But these identifiers all point to the same real user, to ensure the coherence and consistency of the user's identity between different networks.
[0041] 3A Authentication Authorization Accounting (AAA): Authentication is the process of confirming the identity of a user, such as verifying whether you are a legitimate user through a username and password. Authorization, on the other hand, determines the resources and operating permissions that a user can access after authentication, such as some users can only read files but cannot modify them. Accounting is the process of counting and charging (if there is a need for charging) the user's use of network services and other resources, recording data such as usage time and traffic to settle the cost. Enterprises or network operators manage user access permissions, ensure network security, allocate resources reasonably, and perform cost accounting through 3A authentication servers.
[0042] Extended Reality (XR) communication: A new type of communication that combines multiple technologies. XR includes Virtual Reality (VR), Augmented Reality (AR), and Mixed Reality (MR). VR is a completely virtual environment; AR is the superimposition of virtual information on the real world; MR is the fusion of the two. In terms of communication, it relies on high-speed network transmission of data. For example, 5G networks can transmit large amounts of image and video data with low latency, allowing users to have an immersive experience. Through XR technology, users can interact in a virtual and real-world integrated environment, such as feeling as if they are in the same space in remote collaboration, or learning knowledge in an immersive way in an educational scenario.
[0043] Ubiquitous connectivity: a state of widespread and ubiquitous connectivity. In the field of information technology, ubiquitous connectivity means that various devices, systems, people, etc. can achieve connection interaction anytime and anywhere. For example, in the Internet of Things, a large number of devices achieve ubiquitous connectivity through various network technologies (such as wireless networking, Bluetooth, Zigbee technology, etc.). Sensors can be connected to the network and transmit collected data to the cloud or other processing centers. People can use mobile terminals such as smart phones to exchange information anytime and anywhere through social software, which is also an embodiment of ubiquitous connectivity. It breaks the time and space constraints, allowing information and resources to be shared and circulated in a wider range, greatly improving efficiency and convenience.
[0044] Fusion heterogeneous network: is to connect and integrate multiple different types (heterogeneous) of networks. These different types of networks may have different topologies, such as star, bus, etc.; different transmission media, such as optical fiber, twisted pair; different protocols, such as TCP / IP, Bluetooth protocol, etc. The purpose of fusion is to realize resource sharing and complementary advantages. For example, in the Internet of Things, the fusion of sensor networks (low power, short distance), Wi-Fi networks (indoor high-speed coverage), and cellular networks (wide-area coverage) enables devices to switch networks according to their own needs, ensuring timely data transmission, expanding coverage, and reducing overall costs.
[0045] The specific implementation of the embodiments of the present disclosure will be described in detail below in conjunction with the drawings.
[0046] Figure 1 An exemplary application system architecture diagram to which the user identity privacy protection method in the embodiments of the present disclosure can be applied is shown. As shown in the figure, the system architecture includes a terminal device 101, a network 102, and a network side device 103. Figure 1
[0047] The network 102 is a medium for providing a communication link between the terminal device 101 and the network side device 103, which can be a wired network or a wireless network.
[0048] Optionally, the wireless or wired networks described above use standard communications technologies and / or protocols. The network typically connects to the Internet but can also include hardwired and / or wireless networks that are wired / wireless / fiber, etc. and / or any combination thereof. These networks can also be secured networks such as virtual private networks (VPNs). In still other embodiments, the data can be represented using technologies and / or formats including, but not limited to, Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. In addition to standard communications technologies and / or protocols described above, communications technologies and / or protocols not yet developed as of the filing date of this document can also be employed in the systems and methods described herein. For example, custom and / or proprietary data communications technologies and / or protocols can also be used.
[0049] Optionally, the terminal device in the embodiments of the present disclosure can also be referred to as a UE (User Equipment), and in specific implementation, the terminal device can be a virtual reality terminal, a non-universal subscriber identity module terminal, an Internet of Things (IoT) device, a wearable device or a vehicle-mounted device, and the like. It should be noted that the specific type of the terminal device is not limited in the embodiments of the present disclosure.
[0050] The network side device can be a base station, a relay or an access point, and the like. The base station can be a base station of 5G and later versions (for example: 5G NR NB), or a base station in other communication systems (for example: eNB base station), and it should be noted that the specific type of the network side device is not limited in the embodiments of the present disclosure.
[0051] Those skilled in the art can know that, Figure 1 The number of terminals, networks and network side devices in the above description is only illustrative, and according to actual needs, there can be any number of terminals, networks and network side devices. The embodiments of the present disclosure do not limit this.
[0052] Under the above system architecture, the method for protecting user identity privacy provided in the embodiments of the present disclosure can be executed by any electronic device with computing processing capability.
[0053] In some embodiments, the method for protecting user identity privacy provided in the embodiments of the present disclosure can be executed by the network side device in the above system architecture; in other embodiments, the method for protecting user identity privacy provided in the embodiments of the present disclosure can be realized by the terminal device and the network side device in the above system architecture through interaction.
[0054] Figure 2 A flow chart of a method for protecting user identity privacy is shown in the embodiments of the present disclosure, which is applied to a core network element. As shown in Figure 2 The method for protecting user identity privacy provided in the embodiments of the present disclosure includes the following steps:
[0055] S202, receiving a user registration request from a user terminal, the user registration request including a user identity concealed identifier.
[0056] In the present embodiment, the user terminal is a device used by the user to interact with the system, such as a virtual reality terminal, a non-universal subscriber identity module terminal, an Internet of Things device, a wearable device, or a vehicle-mounted device, etc. The user registration request is a request information initiated by the user terminal to register an account to a certain system, platform or service. The user identity concealed identifier (UIC) is used to hide the real identity of the user, which can be a special code or the like. Among them, the virtual reality terminal is, for example, a VR headset, a VR glasses, etc.; the Internet of Things device is, for example, a smart meter, a smart camera, etc.; the wearable device is, for example, a smart watch, a smart bracelet, etc.; the vehicle-mounted device is, for example, a vehicle-mounted navigation instrument, a vehicle-mounted entertainment system, etc.
[0057] Specifically, the user terminal initiates a user registration request to the core network, which carries the user identity concealed identifier. The core network element receives the user registration request containing the user identity concealed identifier.
[0058] In some embodiments, the core network element is specifically an access and mobility management function element, and the access and mobility management function element AMF is mainly responsible for the access management of the terminal device, such as when the user terminal searches for the network, the AMF participates in it to decide whether the user terminal can access the network. At the same time, the mobility of the terminal is also managed, such as when the user terminal moves between different base station coverage areas, the AMF coordinates the switching operation to ensure uninterrupted communication, and undertakes the key management and control tasks related to access and mobility in the entire core network function system.
[0059] In some embodiments, the user identity hidden identifier is obtained by encrypting the user identity identifier by any one of the following encryption algorithms: a hash algorithm, a mapping table and a post-quantum cryptographic algorithm.
[0060] In this embodiment, the user identity identifier (UID) is a unique identifier used to identify the user identity. The hash algorithm is to map data of any length to a fixed-length hash value. It has a one-way nature, that is, it is difficult to restore the original data from the hash value. When used for user identity hidden identifier, the user identity identifier is taken as input, and a seemingly random hash value is obtained to represent the identifier, which plays a hiding role. The mapping table is a pre-set correspondence table. By establishing the mapping relationship between the user identity identifier and another value (user identity hidden identifier), the real identity identifier can be converted into a hidden identifier according to the mapping table, achieving a hiding effect. The post-quantum cryptographic algorithm is an encryption algorithm developed to cope with the threat of quantum computing. In the scenario of user identity hidden identifier, the user identity identifier is encrypted into a hidden identifier that is difficult to crack by using its special encryption mechanism, such as mathematical structure based on lattice.
[0061] Specifically, the user terminal encrypts the user identity identifier by at least one of the hash algorithm, the mapping table and the post-quantum cryptographic algorithm to obtain the user identity hidden identifier.
[0062] In some embodiments, considering that traditional encryption algorithms are based on mathematical problems, such as asymmetric encryption algorithms based on large integer factorization, but quantum computers have strong computing power and can quickly crack these problems, threatening communication security. The post-quantum encryption algorithm is based on new mathematical problems, such as lattice cryptography, which is difficult for quantum computers to crack efficiently. In the communication system, the user identity hidden identifier is obtained by encrypting the user identity identifier by the post-quantum encryption algorithm, so even if the quantum computing technology matures in the future, it is difficult for attackers to obtain the correct key to decrypt the communication content through the user identity hidden identifier, thereby ensuring the security of the user identity identifier in the quantum computing era and resisting the threat brought by it.
[0063] S204, determining the subscription identity information of the user terminal in the network according to the user identity hidden identifier.
[0064] In this embodiment, the subscription identity information of the user terminal in the network refers to the legal identity attribute of the user registered with the network operator or service provider, which is usually bound to the business function. For example, the subscription identity information can be the generic public subscription identifier (GPSI) of the user terminal in the network: such as a public identifier such as an email, which is used in business billing, service opening and other scenarios.
[0065] Specifically, the link between the user identity hiding identifier and the subscription identity information (e.g., a general public user identifier) is to correspond the internal identifier of the user to the externally identifiable public identifier, so as to realize accurate identification of the user identity and service provision. The embodiment realizes, by means of the user identity hiding identifier, safe association to the subscription identity information (e.g., GPSI) of the user in the network under the premise of protection of the real identity of the user, so as to support normal operation of network services while ensuring privacy compliance.
[0066] In S206, the user identity hiding identifier is transparently transmitted to the identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier and performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information.
[0067] In the embodiment, the transparent transmission means that the core network element transparently forwards the user identity hiding identifier without any processing, so that the core network element does not know the user identity identifier corresponding to the user identity hiding identifier, which can effectively protect the privacy of the user and prevent the user identity information from being leaked or misused in the transmission process. Moreover, the space and processing resources required for the core network element to store and manage the real identity of each user, i.e., the user identity identifier, can be reduced.
[0068] The identity authentication server is responsible for receiving the transparently transmitted information, decrypting the user identity hiding identifier by using a corresponding decryption key and / or encryption algorithm, so as to obtain the original user identity identifier related data. The identity authentication server further compares and verifies the decrypted user identity identifier and other information with the legal user information database stored by itself, checks whether the username, password, digital certificate, etc. match, and determines the legality of the user identity. If the identity authentication succeeds or fails, the identity authentication server sends a message containing the authentication result (success or failure and related additional information) back to the core network element based on the subscription identity information (such as the permissions corresponding to the user package), and the core network element performs corresponding processing on the subsequent operation of the user according to the message.
[0069] In some embodiments, the identity authentication server is a 3A authentication server, also called a AAA authentication server. The AAA authentication server can complete authentication and management in an external data network rather than in the core network, thereby sharing the work load and reducing the management pressure of the core network.
[0070] In some embodiments, the identity authentication server performs identity authentication in a manner including performing identity authentication based on an extended authentication protocol or performing identity authentication based on database identity information.
[0071] In this embodiment, the Extensible Authentication Protocol (EAP) is a network authentication framework. It provides a standard method for passing authentication information between network devices. When identity authentication is based on the Extensible Authentication Protocol, the identity authentication server and the user terminal interact authentication information. Specifically, the EAP architecture can be used to complete authentication between the user terminal and the 3A authentication server. It allows the user terminal and the 3A authentication server to interact information through a series of authentication methods. The user terminal initiates an authentication request to the 3A authentication server, and the EAP protocol defines the message format and interaction process in this process. For example, the common EAP-TLS method, the user terminal provides a user identity hiding identifier as the authentication information, and the 3A authentication server verifies whether to pass the authentication, thereby establishing a secure connection and implementing user terminal and network resource interaction permission management and other operations.
[0072] In this embodiment, identity authentication based on database identity information is to compare and verify the identity information provided by the user (such as username, password, etc.) with the identity data stored in the database. The database, as an information repository, pre-stores the identity-related information of legitimate users. When the user terminal initiates an authentication request, the 3A authentication server obtains the user identity hiding identifier and decrypts it to obtain the user identity identifier, and then searches for a matching record in the database. If the user identity identifier has a corresponding record in the database, and the password and other verification information are consistent, the authentication is passed; otherwise, it fails. This method can effectively confirm the user identity with the help of the reliable storage and efficient query capability of the database.
[0073] In some embodiments, considering that it is difficult to ensure the accuracy, security, or integrity of identity authentication by relying solely on the user identity hiding identifier. The subscription identity information is transparently transmitted to the identity authentication server, and the identity authentication server decrypts the user identity hiding identifier to obtain the real identity identifier, and then combines the subscription identity information to accurately determine whether the user identity is legal, thereby completing identity authentication and improving the reliability of identity authentication. That is, the method provided in this embodiment further includes: transparently transmitting the subscription identity information to the identity authentication server, so that the identity authentication server decrypts the user identity hiding identifier to obtain the user identity identifier, and performs identity authentication according to the user identity identifier and the subscription identity information.
[0074] In some embodiments, the identity authentication result is associated with the user identity hiding identifier. In this way, in subsequent operations, the user can be identified as having passed the authentication through the user identity hiding identifier, which not only protects the user's privacy (without directly exposing the real identity), but also enables related business operations based on the authentication situation.
[0075] S208, receiving the identity authentication result returned by the identity authentication server, and sending the identity authentication result to the user terminal.
[0076] In the above embodiment, in the whole identity authentication process, the user identity identifier always exists in the form of the user identity hidden identifier, reducing the risk of identity information being stolen or misused in the transmission and processing process, effectively protecting the user identity privacy, and solving the problem of easy leakage of user identity information.
[0077] Figure 3 A flowchart of a method for determining subscription identity information in the embodiment of the present disclosure is shown in FIG. 3. Figure 3 As shown in FIG. 3, the method for determining subscription identity information provided in the embodiment of the present disclosure includes the following steps:
[0078] S302, obtaining an association relationship table of the user identity hidden identifier and the subscription identity information.
[0079] In the embodiment, the association refers to establishing a logical binding relationship between the user identity hidden identifier and the subscription identity information (such as GPSI) through technical means (such as a mapping table and an encrypted link). The identity mapping database of the core network element stores the association relationship table of the user identity hidden identifier and the subscription identity information.
[0080] In some embodiments, in the process of establishing the association between the user identity hidden identifier and the subscription identity information, the core network element can only authorize the core network element to reversely associate, and external entities cannot decrypt, and in addition, the user identity hidden identifier can be updated regularly to prevent long-term tracking.
[0081] S304, determining the subscription identity information of the user terminal in the network according to the user identity hidden identifier in the association relationship table.
[0082] In the embodiment, the subscription identity information associated and bound with the user identity hidden identifier is queried from the association relationship table, for example, by key decryption or hash table reverse lookup. When the subscription identity information of the user terminal in the network is found, the subscription identity attribute of the user is returned for subsequent business processing (such as charging, service opening, and identity authentication). In this way, the external system can only obtain the subscription identity attribute required by the business, and cannot trace the real identity of the user.
[0083] In some embodiments, in order to prevent illegal operations and unauthorized use of the association relationship, the security, stability, and user identity privacy of the whole communication network are ensured. The core network element can also verify the legitimacy of the user terminal to ensure that only authorized services can perform the association operation.
[0084] Therefore, the user registration request provided by the embodiment further includes at least one of the operation type, the operation time, and the operation location of the user terminal; the subscription identity information of the user terminal in the network is determined according to the user identity hiding identifier, including: determining the access right of the user identity hiding identifier to the association relationship table according to the operation type and / or the operation time and / or the operation location of the user terminal; and determining the subscription identity information of the user terminal in the network according to the access right and the user identity hiding identifier.
[0085] In the embodiment, the operation type of the user terminal refers to the operation type of the user terminal in the registration process, such as creating an account, modifying information, etc. The operation time is the time when the user terminal performs the registration-related operation, which can be used to analyze the user behavior rule, etc. The operation location is the geographic location where the user terminal performs the registration operation, which can affect the service provision, etc.
[0086] In the embodiment, when the subscription identity information of the user terminal in the network is to be determined according to the user identity hiding identifier, the association relationship table is used to find the corresponding entry of the hiding identifier in the table, so as to determine the subscription identity information of the user terminal in the network related thereto. In this way, the user identity privacy can be protected, because the user identity hiding identifier is directly contacted instead of the real user identity identifier.
[0087] Figure 4 A flowchart of a method for identity authentication in the embodiment of the disclosure is shown in FIG. 1. Figure 4 As shown in FIG. 1, the method for identity authentication provided in the embodiment of the disclosure includes the following steps:
[0088] S402, adding an association verification code to the user identity hiding identifier and the subscription identity information.
[0089] In the embodiment, the association verification code is a code for establishing the association between the user identity hiding identifier and the subscription identity information and verifying the association. After the association verification code is added to the user identity hiding identifier and the subscription identity information, the accuracy and the association of the subscription identity information can be ensured while the user identity is hidden, so as to facilitate the accurate identity recognition and operation verification in a specific system or service.
[0090] Therefore, the embodiment adds the association verification code to the user identity hiding identifier and the subscription identity information before the user identity hiding identifier is transparently transmitted to the identity authentication server according to the subscription identity information, so as to guarantee the security and the reliability.
[0091] S404, transparently transmitting the user identity hiding identifier, the subscription identity information, and the association verification code to the identity authentication server.
[0092] In the embodiment, the identity authentication server can verify the consistency and legality of the association between the user identity hiding identifier and the subscription identity information by means of the association verification code, thereby enhancing security.
[0093] Figure 5 A signaling diagram of a user identity privacy protection method in the embodiment of the present disclosure is shown in FIG. 5. Figure 5 As shown in FIG. 5, the user identity privacy protection method comprises the following steps.
[0094] S501, the user terminal sends a registration request to the AMF, wherein the registration request comprises a user identity hiding identifier.
[0095] S502, the AMF sends an authentication request to the AAA, wherein the authentication request comprises the user identity hiding identifier and a generic public user identifier.
[0096] In the embodiment, the AMF determines the generic public user identifier according to the user identity hiding identifier. The AAA function is implemented in a cloud computing environment.
[0097] S503, the user terminal and the AAA perform user identity authentication.
[0098] In the embodiment, the AAA performs user identity authentication by decrypting the user identity hiding identifier.
[0099] S504, the AAA sends an authentication response to the AMF, wherein the authentication response comprises the user identity hiding identifier and the generic public user identifier.
[0100] In the embodiment, the authentication response is used to indicate the authentication result of the user identity authentication.
[0101] S505, the AMF sends a registration response to the user terminal.
[0102] In the embodiment, the registration response comprises a status identifier which can indicate registration success or failure, and informs the user terminal whether the registration is successful. The registration response can also comprise network resource related information allocated to the user terminal, such as a specific network slice identifier, and can also comprise some security related parameters or key information for security guarantee in subsequent communication. The embodiment does not limit the content of the registration response.
[0103] Figure 6 A specific method flowchart of a user identity privacy protection method in the embodiment of the present disclosure is shown in FIG. 6. Figure 6 As shown in FIG. 6, the user identity privacy protection method comprises the following steps.
[0104] S601, the user terminal device encrypts a user identity identifier into a user identity hiding identifier.
[0105] In this embodiment, the specific encryption method can adopt a traditional hash algorithm or a mapping table, etc., or a post-quantum cryptography algorithm to complete protection, so as to resist future quantum computing attacks.
[0106] S602, the user terminal sends a registration request containing the user identity hiding identifier to the AMF network element.
[0107] S603, after receiving the registration request, the AMF network element links to the general public user identifier of the user in the network according to the user identity hiding identifier.
[0108] In this embodiment, the AMF is transparently forwarded to the user identity hiding identifier, and it does not know the user identity identifier corresponding to the user identity hiding identifier.
[0109] S604, the AMF network element sends the user identity hiding identifier and the general public user identifier to the AAA authentication server.
[0110] S605, the AAA authentication server decrypts the user identity hiding identifier into the user identity identifier.
[0111] In this embodiment, according to the processes of S601-S605, the encryption protection is completed for the user identity identifier, and the privacy leakage is avoided to cause linkability and traceability attacks.
[0112] S606, the AAA authentication server performs identity authentication.
[0113] In this embodiment, the AAA authentication server can complete the identity authentication between the user terminal and the AAA based on the EAP architecture; or can complete the identity authentication by using the database identity information matching method. If the identity authentication result matches, the identity authentication is successful, and the user terminal is granted the access permission of the network; if the identity authentication result does not match, the identity authentication fails, and the network access is rejected.
[0114] S607, the AAA authentication server sends the authentication result to the AMF network element.
[0115] In this embodiment, the authentication result is identified by the user identity hiding identifier.
[0116] In this embodiment, for the application scenario in the future communication network, the AAA authentication server in the external data network completes the point-to-point identity authentication and identity management, and the core network element only transparently forwards the user identity hiding identifier, and it does not know the user real identity, that is, the user identity identifier, further reduces the exposure surface of the user identity, and saves the storage space and management thread in the network.
[0117] It should be noted that the application scenarios of the above embodiments of the present disclosure include but are not limited to the following application scenarios: immersive extended display communication; ubiquitous link scenario, multi-type terminal device access to a fusion heterogeneous network.
[0118] It should be noted that the acquisition, storage, use, processing, etc. of data in the technical solutions of the present disclosure comply with relevant provisions of national laws and regulations. The personal identity data, operation data, behavior data, etc. of individuals, customers and crowds, etc. acquired in the embodiments of the present disclosure are authorized.
[0119] Based on the same inventive concept, the present disclosure also provides a user identity privacy protection device, as described in the following embodiments. Since the principles of the device embodiments for solving problems are similar to the above-mentioned method embodiments, the implementation of the device embodiments can be referred to the implementation of the above-mentioned method embodiments, and the repeated parts will not be described here.
[0120] Figure 7 A schematic diagram of a user identity privacy protection device in an embodiment of the present disclosure is shown, as shown in Figure 7 The device includes a first receiving module 71, a determination module 72, a transparent transmission module 73 and a second receiving module 74.
[0121] The first receiving module 71 is configured to receive a user registration request from a user terminal, wherein the user registration request includes a user identity hiding identifier. The determination module 72 is configured to determine subscription identity information of the user terminal in a network according to the user identity hiding identifier. The transparent transmission module 73 is configured to transparently transmit the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier and performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information. The second receiving module 74 is configured to receive the identity authentication result returned by the identity authentication server, and send the identity authentication result to the user terminal.
[0122] In some embodiments, the determination module 72 is specifically configured to: acquire an association relationship table of the user identity hiding identifier and the subscription identity information; and determine the subscription identity information of the user terminal in the network according to the user identity hiding identifier in the association relationship table.
[0123] In some embodiments, the user registration request further comprises at least one of: an operation type, an operation time and an operation location of the user terminal; the determining module 72 is specifically configured to: determine the access right of the user identity hiding identifier to the association table according to the operation type and / or the operation time and / or the operation location of the user terminal; and determine the subscription identity information of the user terminal in the network according to the access right and the user identity hiding identifier.
[0124] In some embodiments, the transparent transmission module 73 is further configured to: transparently transmit the subscription identity information to an identity authentication server, so that the identity authentication server decrypts the user identity hiding identifier to obtain a user identity identifier, and performs identity authentication according to the user identity identifier and the subscription identity information.
[0125] In some embodiments, before the user identity hiding identifier is transparently transmitted to the identity authentication server according to the subscription identity information, the transparent transmission module 73 is further configured to: add an association check code to the user identity hiding identifier and the subscription identity information, and transparently transmit the user identity hiding identifier, the subscription identity information and the association check code to the identity authentication server.
[0126] In some embodiments, the user identity hiding identifier is obtained by encrypting a user identity identifier by using any one of the following encryption algorithms: a hash algorithm, a mapping table and a post-quantum cryptography algorithm.
[0127] In some embodiments, the identity authentication result is associated with the user identity hiding identifier.
[0128] In some embodiments, the core network element is an access and mobility management function network element, and the identity authentication server is a 3A authentication server.
[0129] In some embodiments, the identity authentication manner comprises identity authentication based on an extended authentication protocol or identity authentication based on database identity information.
[0130] It should be noted that each module in the above apparatus embodiments and the corresponding steps in the method embodiments have the same examples and application scenarios, but are not limited to the contents disclosed in the above method embodiments. It should be noted that the above modules as part of the apparatus can be executed in a computer system such as a group of computer executable instructions.
[0131] Those skilled in the art can understand that each aspect of the present disclosure can be implemented in the form of a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system" here.
[0132] Based on the same inventive concept, the embodiments of the present disclosure further provide an electronic device, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the user identity privacy protection method of any one of the above by executing the executable instructions. Since the principle of solving problems of the electronic device embodiments is similar to that of the above method embodiments, the implementation of the electronic device embodiments can be referred to the implementation of the above method embodiments, and the repeated parts will not be described here.
[0133] The electronic device 800 according to this implementation of the present disclosure will be described below with reference to Figure 8 Figure 8 The displayed electronic device 800 is only an example and should not impose any limitation on the functions and use range of the embodiments of the present disclosure.
[0134] As Figure 8 shown, the electronic device 800 is in the form of a general computing device. The components of the electronic device 800 can include, but are not limited to, the above-mentioned at least one processing unit 810, the above-mentioned at least one storage unit 820, and a bus 830 connecting different system components, including the storage unit 820 and the processing unit 810.
[0135] The storage unit stores program codes which can be executed by the processing unit 810, so that the processing unit 810 executes the steps according to various exemplary embodiments of the present disclosure described in the above “Exemplary Method” section of the present specification. For example, the processing unit 810 can execute the following steps of the above method embodiments: receiving a user registration request from a user terminal, the user registration request including a user identity hiding identifier; determining subscription identity information of the user terminal in the network according to the user identity hiding identifier; transmitting the user identity hiding identifier to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the user identity hiding identifier and performs identity authentication, and returns an identity authentication result to a core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server, and sending the identity authentication result to the user terminal.
[0136] The storage unit 820 can include a readable medium in the form of a volatile storage unit, such as a random access memory (RAM) 8201 and / or a cache memory unit 8202, and can further include a read-only memory (ROM) 8203.
[0137] The storage unit 820 also includes a number of program modules 8205 that are stored in the memory 8204, including but not limited to an operating system, one or more application programs, other program modules, and program data, each of which or a combination of which can include implementation of a network environment.
[0138] The bus 830 can represent one or more of several types of bus structures, including a storage unit bus or bus controller, a peripheral bus, a graphics acceleration port, a processing unit bus, or a local bus using any of a variety of bus architectures.
[0139] The electronic device 800 can also communicate with one or more external devices 840 such as a keyboard or pointing device, a Bluetooth device, etc.; other devices that enable a user to interact with the electronic device 800; and / or one or more devices that enable the electronic device 800 to communicate with one or more other computing devices. Such communication can occur via an input / output (I / O) interface 850. Still yet, the electronic device 800 can communicate with one or more networks such as a local area network (LAN), a general wide area network (WAN), and / or a public network (e.g., the Internet) via a network adapter 860. As depicted, the network adapter 860 communicates with the other components of the electronic device 800 via the bus 830. It should be appreciated that although the network adapter 860 is depicted as a single component, the network adapter 860 can include a plurality of components, such as a plurality of network interfaces, each adapted to communicate with one or more types of networks and / or one or more other components of the electronic device 800. It should also be appreciated that although the network adapter 860 is depicted as communicating with the other components of the electronic device 800 via the bus 830, the network adapter 860 can be in communication with the other components of the electronic device 800 in a manner other than via the bus 830, such as via a point-to-point connection.
[0140] Those skilled in the art will readily understand that the example embodiments described herein can be implemented by software and / or by software in combination with the necessary hardware. Thus, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash disk, a mobile hard disk, or the like) or a network, and includes a number of instructions to make a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) execute the methods according to the embodiments of the present disclosure.
[0141] Based on the same inventive concept, the disclosure embodiments also provide a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the user identity privacy protection method of any one of the above. Since the principle of solving problems of the computer readable storage medium embodiment is similar to that of the above method embodiments, the implementation of the computer readable storage medium embodiment can be referred to the implementation of the above method embodiments, and the repeated parts will not be described here.
[0142] More specific examples of the computer readable storage medium in the present disclosure can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0143] In the present disclosure, the computer readable storage medium can include a data signal carried in a baseband or as a part of a carrier wave, in which readable program codes are borne. Such a propagated data signal can take multiple forms, including but not limited to electro-magnetic signal, optical signal, or any suitable combination of the foregoing. The readable signal medium can also be any readable medium that can send, propagate or transmit program codes for use by or in connection with an instruction execution system, apparatus or device.
[0144] Optionally, the program codes contained in the computer readable storage medium can be transmitted by any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.
[0145] In specific implementation, the program codes for performing the operations of the present disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" language or similar programming languages. The program codes can be executed entirely on a user computing device, partially on a user device, as an independent software package, partially on a user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case involving a remote computing device, the remote computing device can be connected to the user computing device through any kind of network, including local area network (LAN) or wide area network (WAN), or can be connected to an external computing device (for example, connected to the Internet through an Internet service provider).
[0146] Based on the same inventive concept, the embodiments of the present disclosure also provide a computer program product, comprising a computer program product, comprising: a computer program or instructions, which, when executed by a processor, implements the user identity privacy protection method of any one of the above method embodiments. Since the principles of the computer program product embodiment for solving problems are similar to those of the above method embodiments, the implementation of the computer program product embodiment can be referred to the implementation of the above method embodiments, and the repeated parts will not be described here.
[0147] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, such division is not mandatory. Indeed, according to embodiments of the present disclosure, the features and functionalities of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functionalities of one module or unit described above can be further divided into several modules or units embodied.
[0148] Furthermore, although the various steps of the methods of the present disclosure are described in a particular order in the figures, this is not required or implied as to the order of execution of the steps, nor is it required that all of the steps be executed to achieve the desired result. Additionally or alternatively, certain steps can be omitted, multiple steps can be combined into one step, one step can be broken into multiple steps, etc.
[0149] From the above description of the embodiments, those skilled in the art will readily appreciate that the example embodiments described herein can be implemented by software and / or by hardware. Embodiments according to the present disclosure can therefore be realized in a software product stored in a non-transitory storage medium (which can be a CD-ROM, a USB, a mobile hard disk, etc.) or on a network, including a number of instructions for making a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) execute methods according to the embodiments of the present disclosure.
[0150] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure following the general principles thereof and including such departures from the present disclosure that come within known use or custom in the art. The specification and examples are to be regarded as exemplary only, and the true scope and spirit of the present disclosure are indicated by the appended claims.
Claims
1. A user identity privacy protection method, characterized in that, Applied to a core network element, the method comprises: receiving a user registration request from a user terminal, the user registration request comprising a user identity concealment identifier (UIC), wherein the user terminal is a device without a universal subscriber identity module (USIM) card, and the UIC is obtained by encrypting a user identity identifier (UID) using at least one of a hash algorithm, a mapping table and a post-quantum cryptography algorithm; determining subscription identity information of the user terminal in a network according to the UIC, wherein the subscription identity information of the user terminal in the network is a general public subscription identifier (GPSI); transmitting the UIC to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the UIC and performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server and transmitting the identity authentication result to the user terminal.
2. The user identity privacy protection method of claim 1, wherein, The method further comprises: transmitting the subscription identity information to the identity authentication server, so that the identity authentication server decrypts the UIC to obtain the UID and performs identity authentication according to the UID and the subscription identity information. The method further comprises, before transmitting the UIC to the identity authentication server according to the subscription identity information: adding an association check code to the UIC and the subscription identity information.
3. The user identity privacy protection method of claim 2, wherein, The method further comprises: transmitting the UIC, the subscription identity information and the association check code to the identity authentication server. The UIC is obtained by encrypting the UID using any one of a hash algorithm, a mapping table and a post-quantum cryptography algorithm. The identity authentication result is associated with the UIC.
4. The user identity privacy protection method of claim 1, wherein, The method further comprises:
5. The user identity privacy protection method of claim 4, wherein, receiving a user registration request from a user terminal, the user registration request comprising a user identity concealment identifier (UIC), wherein the user terminal is a device without a universal subscriber identity module (USIM) card, and the UIC is obtained by encrypting a user identity identifier (UID) using at least one of a hash algorithm, a mapping table and a post-quantum cryptography algorithm; determining subscription identity information of the user terminal in a network according to the UIC, wherein the subscription identity information of the user terminal in the network is a general public subscription identifier (GPSI); transmitting the UIC to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the UIC and performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server and transmitting the identity authentication result to the user terminal.
6. The user identity privacy protection method of claim 1, wherein, The method further comprises: transmitting the subscription identity information to the identity authentication server, so that the identity authentication server decrypts the UIC to obtain the UID and performs identity authentication according to the UID and the subscription identity information.
7. The user identity privacy protection method of claim 1, wherein, The method further comprises, before transmitting the UIC to the identity authentication server according to the subscription identity information: adding an association check code to the UIC and the subscription identity information. The method further comprises: transmitting the UIC, the subscription identity information and the association check code to the identity authentication server. The UIC is obtained by encrypting the UID using any one of a hash algorithm, a mapping table and a post-quantum cryptography algorithm. The identity authentication result is associated with the UIC. The method further comprises: receiving a user registration request from a user terminal, the user registration request comprising a user identity concealment identifier (UIC), wherein the user terminal is a device without a universal subscriber identity module (USIM) card, and the UIC is obtained by encrypting a user identity identifier (UID) using at least one of a hash algorithm, a mapping table and a post-quantum cryptography algorithm; determining subscription identity information of the user terminal in a network according to the UIC, wherein the subscription identity information of the user terminal in the network is a general public subscription identifier (GPSI); transmitting the UIC to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the UIC and performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; receiving the identity authentication result returned by the identity authentication server and transmitting the identity authentication result to the user terminal. The method further comprises: transmitting the subscription identity information to the identity authentication server, so that the identity authentication server decrypts the UIC to obtain the UID and performs identity authentication according to the UID and the subscription identity information.
8. The user identity privacy protection method of claim 1, wherein, The core network element is an access and mobility management function network element, and the identity authentication server is a 3A authentication server.
9. The user identity privacy protection method of claim 1, wherein, The identity authentication manner includes identity authentication based on an extended authentication protocol or identity authentication based on database identity information.
10. A user identity privacy protection apparatus, characterized by comprising: The apparatus is applied to a core network element, and the apparatus includes: A first receiving module configured to receive a user registration request from a user terminal, the user registration request including a user identity concealment identifier (UIC), wherein the user terminal is a device without a universal subscriber identity module (USIM) card, and the UIC is obtained by encrypting a user identity identifier (UID) using at least one of a hash algorithm, a mapping table, and a post-quantum cryptography algorithm; A determining module configured to determine subscription identity information of the user terminal in a network according to the UIC, wherein the subscription identity information of the user terminal in the network is a general public subscription identifier (GPSI); A transparent transmission module configured to transparently transmit the UIC to an identity authentication server according to the subscription identity information, so that the identity authentication server decrypts the UIC and performs identity authentication, and returns an identity authentication result to the core network element based on the subscription identity information; A second receiving module configured to receive the identity authentication result returned by the identity authentication server and send the identity authentication result to the user terminal.
11. An electronic device, comprising: comprise: a processor; and a memory configured to store executable instructions of the processor; wherein the processor is configured to execute the user identity privacy protection method according to any one of claims 1 to 9 by executing the executable instructions.
12. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the user identity privacy protection method according to any one of claims 1 to 9.
13. A computer program product, comprising: The computer program or instructions are executed by the processor to implement the user identity privacy protection method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Method and device for verifying user equipment identifier in authentication process
CN110798833A