Rapid password token transmission method and system
By introducing a shared exchange group mechanism and hash table, the rapidity and security of password token delivery in multi-operator scenarios are solved, and the rapid transmission among multi-operators is achieved, and the implementation of trusted communication specifications is supported.
Patent Information
- Application Number
- CN202510604853.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-07-11
AI Technical Summary
In the multi-operator scenario, the existing technology has failed to effectively solve the problem of fast delivery of password tokens, and it is necessary to take into account user privacy protection and delivery delay within a reasonable range.
The shared exchange group mechanism of the intermediate layer is introduced, and through token messaging services and exchange rings, the password tokens are quickly passed between multiple operators, and shared exchange nodes and hash tables are used for quick search and delivery.
Under the premise of being compatible with the trusted communication specification, the rapid transmission of password tokens in multi-operator scenarios is realized, and the implementation of the trusted communication specification is supported.
Smart Images

Figure CN120301604A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and particularly relates to a method and system for fast transfer of password tokens between multiple operators. Background Art
[0002] In modern communication systems, identity authentication is a key link to ensure secure interaction between communication parties. The national standard "Information Security Technology - Technical Specification for Caller User Trusted Identity Authentication Based on Password Tokens" (GB / T 43779—2024, hereinafter referred to as the "Trusted Communication Specification") uses a digital certificate system to achieve the issuance of trusted identities for communication entities and end-to-end trusted identity authentication, and can effectively block harassing and fraudulent calls in the form of a "whitelist". In the standard, the identity authentication and call process is as follows: First, the identity credential issuance authorization center and the identity credential issuance center issue identity credentials for trusted users. When the calling user uses the mobile terminal application to select a trusted identity to initiate a call, the calling terminal will obtain the trusted identity credential and construct a password token, and then send the token to the token message transfer service. When the called user answers the call, the called user will query the password token sent by the caller from the token message transfer service through an index and verify its legitimacy. After verification, the called terminal will display the trusted identity information of the calling user on the user interface to help the user determine whether to answer the call.
[0003] In trusted communication, the role of the token message transfer service is to act as an intermediary for the transfer of password tokens from the calling user to the called user, which plays a crucial role in enabling the called user to obtain and verify the identity of the calling user in a timely manner. However, the trusted communication standard does not cover how password tokens are transferred from one operator to another when multiple operators provide trusted communication services simultaneously. Due to services such as number portability, it is not possible to simply determine the operator to which a user belongs based on the phone number, and moreover, the operator providing trusted communication may not necessarily be the user's local telecommunications operator. In addition, in trusted communication, the transfer of password tokens also needs to take into account user privacy protection and keep the transfer delay within a reasonable range. Therefore, it is necessary to design a fast transfer technology for password tokens in a multi-operator scenario. Summary of the Invention
[0004] In view of this, the "end-to-end" password token fast transfer method and system proposed by the present invention can achieve fast transfer of token messages in a multi-operator scenario while meeting the trusted communication standard by introducing an intermediate layer and adopting a shared exchange group mechanism.
[0005] To achieve the above object, the technical solution of the present invention is realized as follows:
[0006] A method for rapid transmission of "end-to-end" password tokens. The entities participating in the rapid transmission of password tokens include the calling terminal, the token message transmission service, the token message transmission switching ring, and the called terminal. Among them: Each operator includes several switching nodes, and the token message transmission switching ring is composed of multiple switching nodes of each operator. The password token is constructed by the calling terminal and is used for the called terminal to verify the identity of the calling terminal user. Its content includes a query index, time, signature value, etc. The transmission of the password token includes two processes: uploading and querying, which are specifically as follows:
[0007] a) Password token upload process: ① The calling terminal constructs a password token, sends the password token to the token message transmission service, and then initiates a call request to the called terminal. The construction method and composition of the password token refer to the trusted communication specification; ② After receiving the password token sent by the calling terminal, the token message transmission service caches the received password token locally. At the same time, it selects a set of switching nodes in the token message transmission switching ring according to the query index in the password token and transmits the password token to all switching nodes in the set; ③ After receiving the password token, the switching nodes in the token message transmission switching ring cache the received password token locally.
[0008] b) Password token query process: ① After receiving the call request, the called terminal generates a query index (the same as the query index in the password token) according to the call information, generates a query request according to the generated query index, and sends it to the token message transmission service to query the password token with the generated query index. The method for generating the query index refers to the trusted communication specification; ② After receiving the query request, the token message transmission service checks whether the queried password token is cached locally. If so, it directly returns the password token to the called terminal. Otherwise, it selects a set of switching nodes in the token message transmission switching ring according to the query index and forwards the query request to all switching nodes in the set; ③ After receiving the query request, the switching node checks whether the queried password token is cached locally. If so, it returns the password token to the token message transmission service. Otherwise, it ignores the request; ④ After receiving the query response from the switching node, the token message transmission service returns the password token in the response to the called terminal.
[0009] In the method for rapid transmission of "end-to-end" password tokens, the address of the token message transmission service is built into the terminal. There can be multiple token message transmission services. The token message transmission services connected by the calling terminal and the called terminal can be different. The operator is the operator of the token message transmission service; all token message transmission services share a token message transmission switching ring for transmitting password tokens between multiple terminals connected to different token message transmission services; the token message transmission switching ring is composed of multiple switching nodes. The switching nodes have a unified interface and support uploading and querying password tokens.
[0010] The token messaging service maintains a token hash table for storing password tokens and can quickly find password tokens according to query indices. When receiving a password token sent by a calling terminal, it directly uses the query index in the password token as the hash value and puts the password token into the token hash table. When receiving a password token query request, it directly uses the query index sent by the terminal as the hash value to quickly find whether there is a corresponding password token in the token hash table.
[0011] The switching nodes in the token messaging switching ring maintain a token hash table for storing password tokens and can quickly find password tokens according to query indices. When receiving a password token sent by the token messaging service, it directly uses the query index in the password token as the hash value and puts the password token into the token hash table. When receiving a password token query request, it directly uses the query index sent by the token messaging service as the hash value to quickly find whether there is a corresponding password token in the token hash table.
[0012] After receiving a query request, when the password token being queried is not cached locally, the token messaging service needs to select a set of switching nodes in the token messaging switching ring according to the query index.
[0013] All token messaging services share a switching node selection policy and a switching node selection algorithm. The switching node selection policy determines an integer t not less than 1, and the switching node selection algorithm generates t integers according to the query index. When it is necessary to select a set of switching nodes according to the query index, the token messaging service generates t integers according to the same switching node selection policy and switching node selection algorithm based on the query index, and then uses these integers modulo the size of the switching node list of the token messaging switching ring to obtain t sequence numbers, so as to select the switching nodes corresponding to the sequence numbers.
[0014] Mutual authentication is performed between the token messaging service and the switching nodes in the token messaging switching ring, and a secure channel for token upload and query is established.
[0015] An "end-to-end" password token fast transfer system, including a terminal component, a token message transfer service component, and a token message transfer exchange node component. Among them: The terminal component is installed on the user terminal, including the APP on the mobile terminal and the APP on the fixed terminal; the token message transfer service component runs on the server side and provides the upload and query services of the password token for the terminal component; the token message transfer exchange node component runs on the server side and provides the upload and query services of the password token for the token message transfer service component; the token message transfer service component can be operated by different operators, and at the same time, different operators each operate a certain number of token message transfer exchange node components, and these node components together form a unified token message transfer exchange ring.
[0016] For the components in the "end-to-end" password token fast transfer system, when the terminal component makes an external call from the terminal, it generates a password token and transfers the password token to the token message transfer service component; when receiving an incoming call, it generates a query index according to the call information, queries the password token from the token message transfer service component, verifies the queried password token, and displays the verification result and user identity information to the user.
[0017] The token message transfer service component provides the upload and query services of the password token for the terminal component; maintains a token hash table for storing the password token, and shares a token message transfer exchange ring exchange node list with other token message transfer service components; when receiving a password token upload request from the terminal component, directly uses the query index in the password token as the hash value, and puts the password token into the token hash table, so as to locally cache the received password token. At the same time, according to the query index in the password token, selects a set of exchange node components in the token message transfer exchange ring exchange node list, and transfers the password token to all the exchange node components in this set; when receiving a password token query request from the terminal component, directly uses the query index sent by the token message transfer service as the hash value to quickly search in the token hash table whether there is a corresponding password token. If so, directly returns the password token to the terminal component. Otherwise, according to the query index, selects a set of exchange node components in the token message transfer exchange node list, and forwards the query request to all the exchange node components in this set; when receiving a query response from the exchange node component, returns the password token in the response to the terminal component.
[0018] The token message passing exchange link node component provides the upload and query services of the password token for the token message passing service component; maintains a token hash table for storing the password token, and together with other token message passing exchange link node components, forms a token message passing exchange link; when receiving a password token upload request from the token message passing service component, directly uses the query index in the password token as the hash value, and puts the password token into the token hash table, so as to cache the received password token locally; when receiving a query request from the token message passing service component, checks whether the queried password token is cached locally, if so, returns the password token to the token message passing service component, otherwise ignores the request.
[0019] Compared with the prior art, the positive effects of the present invention are as follows:
[0020] On the premise of being compatible with the trusted communication specification, it supports the rapid transfer of password tokens between the token message passing services of multiple operators, and can support the implementation of the trusted communication specification. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a schematic diagram of the composition of an "end-to-end" password token rapid transfer method of the present invention.
[0022] Figure 2 It is a schematic diagram of the password token upload process of the present invention.
[0023] Figure 3 It is a schematic diagram of the password token query process of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] Aiming at the problems existing in the prior art, the present invention proposes a method, a system and a solution suitable for completing the transfer of password tokens from the calling terminal to the called terminal in a multi-operator scenario.
[0025] In order to make the technical solutions of the present invention clearer and more understandable, the following examples are given with reference to the accompanying drawings, and the solutions of the present invention are further described in detail.
[0026] Figure 1 It is a schematic diagram of the composition of an "end-to-end" password token rapid transfer method of the present invention, as Figure 1As shown in the figure, it includes the calling terminal, the token messaging service, the token messaging switching ring, and the called terminal. Among them: The calling terminal and the called terminal components are installed on the user terminal, including the APP on the mobile terminal and the APP on the fixed terminal. The token messaging service component runs on the server side and can be operated by different operators, providing services for uploading and querying password tokens to the terminal components. There can be multiple token messaging services, and the token messaging services connected by the calling terminal and the called terminal can be different. The token messaging switching link node component runs on the server side and provides services for uploading and querying password tokens to the token messaging service component. Different operators each operate a certain number of token messaging switching link node components, and these node components together form a unified token messaging switching ring. All token messaging services share a token messaging switching ring for transmitting password tokens between terminals connected to different token messaging services.
[0027] Figure 2 This is a schematic diagram of the password token upload process of the present invention. As Figure 2 shown, it includes steps 201) to 203), specifically as follows:
[0028] 201) The calling terminal constructs a password token, sends the password token to the token messaging service, and then initiates a call request to the called terminal;
[0029] 202) After receiving the password token sent by the calling terminal, the token messaging service caches the received password token locally. At the same time, it selects a set of switching nodes in the token messaging switching ring according to the query index in the password token, and passes the password token to all the switching nodes in the set;
[0030] 203) After receiving the password token, the switching nodes in the token messaging switching ring cache the received password token locally.
[0031] Through the process shown in the above steps, the process of uploading the password token from the calling terminal to the switching nodes in the token messaging switching ring can be completed. In the above steps, security measures such as identity authentication, integrity protection, and confidentiality protection are not considered. In actual applications, additional messages and data can be added to the process according to the scenario requirements to achieve security protection.
[0032] Figure 3 This is a schematic diagram of the password token query process of the present invention. As Figure 3 shown, it includes steps 301) to 304), specifically as follows:
[0033] 301) After receiving the call request, the called terminal generates a query index according to the call information and queries the token messaging service for the password token with the generated query index;
[0034] 302) After the token messaging service receives a query request, it checks whether the queried password token is cached locally. If so, it directly returns the password token to the called terminal. Otherwise, it selects a set of switching nodes in the token messaging switching ring according to the query index and forwards the query request to all the switching nodes in this set;
[0035] 304) After the switching node receives the query request, it checks whether the queried password token is cached locally. If so, it returns the password token to the token messaging service. Otherwise, it ignores the request;
[0036] 304) After the token messaging service receives the query response from the switching node, it returns the password token in the response to the called terminal.
[0037] Through the process shown in the above steps, the process of the called terminal querying the password token from the switching nodes in the token messaging switching ring can be completed. In the above steps, security measures such as identity authentication, integrity protection, and confidentiality protection are not considered. In actual applications, additional messages and data can be added to the process according to the scenario requirements to achieve security protection.
[0038] In summary, the above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for quickly transmitting a password token, the steps comprising: 1) The switching nodes of each operator are constructed into a token message transmission switching ring; Each of the operators includes a number of switching nodes; 2) Password token upload phase: the calling terminal constructs a password token and sends it to the token messaging service, and then initiates a call request to the called terminal; the token messaging service locally caches the password token, and selects a switching node set in the token messaging switching ring according to the query index in the password token, and transmits the password token to each switching node in the switching node set; the switching node locally caches the received password token; 3) Password token query stage: the called terminal generates a query index according to the received call request, generates a query request according to the generated query index and sends it to the token messaging service to query the password token with the generated query index; the token messaging service checks whether the queried password token is cached locally, and if so, directly returns the password token to the called terminal; otherwise, selects a switching node set in the token messaging switching ring according to the query index in the query request, and forwards the query request to each switching node in the switching node set; after receiving the query request, the switching node checks whether the queried password token is cached locally, and if so, returns the password token to the token messaging service; After receiving the query response from the switching node, the token messaging service returns the cryptographic token in the query response to the called terminal.
2. The method according to claim 1, wherein The method for selecting a switch node set in the token messaging switch ring is as follows: each of the token messaging services shares a switch node selection strategy and a switch node selection algorithm; the token messaging service first determines an integer t not less than 1 according to the switch node selection strategy, and then uses the switch node selection algorithm to generate t integers according to the query index, and then uses the t integers modulo the size of the switch node list of the token messaging switch ring to obtain t serial number values, and selects the switch nodes whose switch node numbers are the same as the t serial number values as the switch node set.
3. The method according to claim 1, characterized in that, The token messaging service maintains a token hash table for storing password tokens, which is used to quickly find password tokens according to a query index; When the token messaging service receives the password token sent by the calling terminal, it directly uses the query index in the password token as the hash value and puts the password token into the token hash table; When the token messaging service receives the query request, it directly uses the query index in the query request as a hash value to quickly search in the token hash table whether there is a corresponding cryptographic token.
4. The method according to claim 1, wherein The exchange node maintains a token hash table for storing password tokens, and is used to quickly find password tokens according to the query index; when the exchange node receives the password token sent by the token messaging service, the query index in the password token is directly used as the hash value to put the password token into the token hash table; When the switching node receives the query request, it directly uses the query index in the query request as a hash value to quickly search in the token hash table to check if there is a corresponding password token.
5. The method according to claim 1, characterized in that, Each operator provides a token messaging service; The address of the token messaging service is built into the terminal, and the terminal includes a calling terminal and a called terminal; each of the token messaging services shares the token messaging switching ring.
6. The method according to claim 1, characterized in that, The switching node has a unified interface and supports uploading and querying password tokens.
7. A rapid password token transfer system, characterized in that It includes a terminal component, a token messaging service component, and a token messaging switching link node component; among them, the terminal component is installed on the user terminal and includes a calling terminal and a called terminal; The token messaging switching link node component is used to build the switching nodes of each operator into a token messaging switching ring; each operator includes several switching nodes; The calling terminal is used to build a password token and send it to the token messaging service component, and then initiate a call request to the called terminal; The called terminal is used to generate a query index according to the received call request, generate a check request according to the generated check index and send it to the token messaging service component; The token messaging service component is used to locally cache the password token during the password token upload phase, and select a set of switching nodes in the token messaging switching ring according to the query index in the password token, and transfer the password token to each switching node in the set of switching nodes; and is used to check whether the queried password token is locally cached according to the check request during the password token query phase. If so, it directly returns the password token to the called terminal. Otherwise, it selects a set of switching nodes in the token messaging switching ring according to the query index in the check request, forwards the query request to each switching node in the set of switching nodes, and then returns the password token in the query response to the called terminal after receiving the query response from the switching node; The switching node is used to locally cache the received password token, and check whether the queried password token is locally cached after receiving the query request. If so, it returns the password token to the token messaging service component.