Method and system for using trusted anonymous account in multi-identifier network system

A SIM card-based system generates secure keys and chain codes within a multi-identifier network using SM3 and SM2 algorithms, addressing centralized identity authentication issues and enhancing network security for cross-domain trust and anonymous access.

CN120321641AActive Publication Date: 2025-07-15PEKING UNIV SHENZHEN GRADUATE SCHOOL +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510813108.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-15
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

Identity authentication in traditional networks depends on centralized management, and its anonymity is difficult to ensure and data security is fragile, which cannot meet the needs of network digital identities to achieve cross-domain mutual trust and anonymous access.

Method used

SIM cards are introduced as trusted hardware carriers to generate master keys and main chain codes, combined with multi-identification network system, generate trusted anonymous accounts through random number seeds, and identity signatures and verifications are performed in the MIN network to realize network packet addressing.

Benefits of technology

A trusted anonymous account is built, which supports cross-platform and cross-network authentication access, avoids the risk of privacy leakage of traditional centralized accounts, realizes cross-domain mutual trust and anonymous access, and improves the security and anonymity of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321641A_ABST
    Figure CN120321641A_ABST
Patent Text Reader

Abstract

The invention provides a method and system for using a trusted anonymous account in a multi-identification network system, and the method comprises the following sub-steps: S1, generating a mnemonic symbol and a random number seed, and generating a master key and a main chain code of an SIM card through the random number seed; s2, submitting the master key of the SIM card to an accounting node of the identification space to which the master key belongs, and realizing SIM card key registration; s3, calling private network resources of the MIN network by the user; s4, performing identity signature and signature verification in the MIN network; and S5, the SIM card performs network packet addressing in the MIN network. According to the invention, the SIM card is introduced as a trusted hardware carrier, and is matched with a multi-identifier network system of a sovereignty network and a national secret algorithm to generate a master key and a main chain code so as to construct a trusted anonymous account, and the anonymous account can support cross-platform and cross-network authentication access in the multi-identifier network system, so that the security of the anonymous account is improved. And the actual application requirements of cross-domain mutual trust and anonymous access of the network digital identity are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for using a trusted account in a network, and particularly to a method for using a trusted anonymous account in a multi-identity network system, and further to a system adopting the method for using a trusted anonymous account in a multi-identity network system. Background Art

[0002] The concept of network digital identity has naturally formed with the popularization of the Internet and communication network processes. So far, there is no unified concept and accurate definition of network digital identity globally, and there are different definitions of digital identity on the Internet side and the communication network side.

[0003] For example, from the perspective of the Internet side, it is considered that digital identity is a code distributed by the resident identity network authentication service system to the network certificate application system for identifying the personal identity of residents; or, it is considered that digital identity is to solve the identification and trust of digital space objects, and use the network information system for secure transmission, storage, use and management, and assign a unique corresponding digital identifier and associated attribute declarations to the object, etc.

[0004] On the communication network side, the Telecommunication Standardization Sector of the International Telecommunication Union believes that digital identity is an identifier of an individual or entity in a digital communication and network environment, allowing it to be authenticated and accessed in various online services and applications.

[0005] With the rapid development of the Internet and communication networks, the speed of their integration has accelerated, and they have jointly become the key core components and important infrastructure supporting the digital world. Especially after network digital identity enters the "digital identity application period", whether in the definition of digital identity or in actual applications, network digital identity has become a key link in the construction of the trust system in the digital world and the support of digital ecological governance, posing higher challenges and requirements for achieving cross-domain mutual trust and anonymous access.

[0006] However, in the current traditional network, there are obvious technical problems such as identity authentication relying on centralized management, difficult to guarantee anonymity, and vulnerable data security, which cannot meet the actual application requirements of network digital identity for achieving cross-domain mutual trust and anonymous access. Therefore, how to provide a solution for trusted anonymous accounts to overcome the above technical problems of the current traditional network is particularly important. Summary of the Invention

[0007] The technical problem to be solved by the present invention is to provide a method for using a trusted anonymous account in a multi-identity network system, aiming to introduce the SIM card as a trusted hardware carrier, cooperate with the multi-identity network system of the sovereign network, generate a master key and a master chain code to construct a trusted anonymous account, solve the technical problems of identity authentication relying on centralized management, difficult to guarantee anonymity, and vulnerable data security in the traditional network, and meet the actual application requirements of cross-domain mutual trust and anonymous access for network digital identities. On this basis, a system adopting the method for using a trusted anonymous account in a multi-identity network system is further provided.

[0008] For this, the present invention provides a method for using a trusted anonymous account in a multi-identity network system, including the following sub-steps: Step S1, generate a mnemonic and a random number seed, and generate the master key and master chain code of the SIM card through the random number seed; Step S2, submit the master key of the SIM card to the accounting node of the affiliated identity space to implement SIM card key registration; Step S3, the user calls the private network resources of the MIN network; Step S4, perform identity signature and signature verification in the MIN network; Step S5, the SIM card performs network packet addressing in the MIN network; Among them, the step S1 includes the following sub-steps: Step S101, first, generate a random number, then convert the random number into a mnemonic, and determine the random number seed through the mnemonic; Step S102, perform iterative calculation based on the random number seed, generate an intermediate value, and perform combination and calculation through the intermediate value to generate the master key and master chain code corresponding to the SIM card.

[0009] A further improvement of the present invention lies in that the step S101 includes the following sub-steps: Step S1011, generate and return a 128-bit first random number; Step S1012, obtain a 132-bit second random number through the SM3 hash algorithm and the Chinese character table, and convert the second random number into 12 Chinese mnemonics; Step S1013, send the Chinese mnemonics back to the user for confirmation, and use the second random number corresponding to the Chinese mnemonics confirmed by the user as the random number seed.

[0010] A further improvement of the present invention lies in that, in the step S1012, first, the first random number is hashed by the SM3 hashing algorithm, then the first 4-bit data of the hashing result is taken and concatenated with the first random number; then, the 132-bit second random number obtained after concatenation is divided into 12 groups of strings; finally, the 12 groups of strings are respectively transformed by the Chinese character table into 12 Chinese mnemonics.

[0011] A further improvement of the present invention lies in that the step S102 includes the following sub-steps: Step S1021, first, iterative operations are performed based on the random number seed by the SM3 hashing algorithm, and intermediate values to intermediate value are generated. At this time , where i represents the serial number of the iterative operation and S represents the random number seed; then, the master private key is calculated through the formula ; finally, the master private key is processed by the SM2 algorithm to obtain the master public key corresponding to the SIM card; Step S1022, first, iterative operations are performed based on the random number seed by the SM3 hashing algorithm, and intermediate values to intermediate value are generated. At this time , where i represents the serial number of the iterative operation and S represents the random number seed; then, the master chain code is calculated through the formula ; finally, the master chain code of the SIM card is obtained.

[0012] A further improvement of the present invention lies in that the step S2 includes the following sub-steps: Step S201, submit the master key of the SIM card to the accounting nodes of the affiliated identity space; Step S202, after the accounting node receives the key registration request sent by the client, it will check the request format of the key registration request and verify the content of the key registration request; Step S203, after the verification is passed, the accounting node encapsulates the key registration request as a normal transaction and puts it into the transaction pool; Step S204, at the beginning of each round of consensus, all accounting nodes take out the normal transactions from the transaction pool, generate a block, and then send the block to all voting nodes. The voting nodes that receive the block verify the block header and each transaction content; Step S205, when the voting nodes receive all the blocks or wait until the timeout, they will package the voting information of all the blocks and send it to the rotating accounting node; Step S206: The rotating accounting node counts the voting information of each voting node, deletes the block that has received more rejection votes than the preset threshold, where the preset threshold is half of the number of voting nodes; and approves the block that has received more approval votes than the preset threshold. Step S207: After the voting situation of all blocks is counted, the rotating accounting node generates a block group header, writes the counted vote situation and block hash value, sets the timestamp, and publishes the block group header to the blockchain network. Step S208: After all nodes in the blockchain network receive the block group header sent by the rotating accounting node, they first perform verification. Until the verification passes, they submit the block group and update the parameters, extract the key registration information from the transactions of the block, and store it in the user information table.

[0013] A further improvement of the present invention is that step S3 includes the following sub-steps: Step S301: Start MIN-VPN, perform two-way authentication between MIN-VPN and MIN-Proxy. If the authentication is successful, the startup is successful; if the authentication fails, the startup fails. MIN-VPN refers to the dedicated network architecture of the multi-identifier network system, and MIN-Proxy refers to the dedicated network proxy used in the multi-identifier network system to forward requests and responses. Step S302: The user enters the user account and password on the MIN-VPN login interface to log in. Check whether the MIN identity corresponding to the user exists locally through MIN-VPN. If it exists, send the user account, password, and MIN identity flag to the VMS server. At this time, the MIN identity flag is "exists"; if it does not exist, return to step S1 to generate the master key for the user using the SIM card, and send the user account, password, MIN identity flag, and master public key to the VMS server. At this time, the MIN identity flag is "does not exist". MIN refers to the multi-identifier network system, and the VMS server refers to the server of the VPN management system. Step S303: After receiving the information, the VMS server forwards the user account and password to the directory service AD to authenticate the user information. If the authentication fails, return the login failure to MIN-VPN. If the authentication is successful, jump to step S304. Step S304: If the MIN identity flag is "does not exist", send the user's master public key to the multi-identifier management system MIS to register the MIN identity, and return the MIN identity and token; if the MIN identity flag is "exists", directly return the MIN identity and token. Step S305: After MIN-VPN receives the login success message, construct a multi-identifier network packet containing the user account and token, read the master private key, and sign the multi-identifier network packet. Step S306: Connect to the VPN-Server and send a signed multi-identifier network packet. The multi-identifier router MIR requests the user's MIN certificate from the multi-identifier management system MIS based on the obtained user account. VPN-Server refers to the virtual private network server. Step S307: Before the multi-identifier router MIR forwards the multi-identifier network packet to the VPN-Server, verify the signature of the multi-identifier network packet. Step S308: If the signature verification passes, the user account and token are successfully sent to the VPN-Server. Step S309: The VPN-Server receives the user account and token, sends the token and user account to the VMS server. The VMS server successfully verifies the token, retrieves the user access control list and returns it to the VPN-Server. Step S310: The MIN-VPN successfully connects to the VPN-Server. When the user clicks to access the website, the VPN-Server receives the multi-identifier network packet, retrieves the user access control list, and performs permission control.

[0014] A further improvement of the present invention is that the step S4 includes the following sub-steps: Step S401: Implement signature based on the user's main private key. After confirming that the main private key is not empty, first select the corresponding signature method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the main private key to the private key type of the SM2 algorithm, and call the p.Sign digital signature method for signature. Step S402: Implement signature verification based on the user's main public key. After verifying that the main public key is not empty, first select the corresponding verification method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the main public key to the public key type of the SM2 algorithm, and call the p.Sign verification method for verification.

[0015] A further improvement of the present invention is that the step S5 includes the following sub-steps: Step S501: The multi-identifier network packet flows in. Step S502: Read the data link layer data segment and decode the multi-identifier network packet through TLV encoding. The multi-identifier network packet includes four regions, namely the identifier region, the signature region, the read-only region, and the variable region. Each region consists of one or more TLV-encoded triples. TLV encoding divides the binary data block into three intervals. The leftmost interval is the Type field, indicating the type of the current data block. The middle interval is the Length field, indicating the length of the Value field. The last interval is the Value field, used to store the data block. Step S503: Determine whether the decoding of the multi-identifier network packet is successful. If not, discard the multi-identifier network packet and end the processing flow; if so, jump to step S504; Step S504: Check the destination identifier area field of the multi-identifier network packet and determine whether there is a next unprocessed identifier in the destination identifier area. If there is no identifier or the identifier has been processed in the destination identifier area, discard the multi-identifier network packet and end the processing flow; if there is a next unprocessed identifier in the destination identifier, jump to step S505; Step S505: Read the next unprocessed identifier, and determine whether the current multi-identifier router can resolve and process this identifier based on the identifier type number of this identifier. If not, that is, it cannot resolve and process this identifier, return to step S504 to continue determining whether there is a next unprocessed identifier in the destination identifier area; if so, jump to step S506; Step S506: Call the processing flow, read and parse the value of this identifier, and call the corresponding processing function to process the multi-identifier network packet according to the value of this identifier and the identifier type number, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet from the specified port; Step S507: Determine whether the processing of the multi-identifier network packet is successful. If not, return to step S504 to continue determining whether there is a next unprocessed identifier in the destination identifier area; if so, end the processing flow.

[0016] A further improvement of the present invention is that it further includes an anonymous account mapping and log recording step, and the anonymous account mapping and log recording step includes: Step A1: Through the formula Map each anonymous account registered in the MIN network to a globally unique anonymous account through the SIM card ; where represents the hash function, represents the master private key, represents the master chain code, represents the user information; Step A2: In the case of a network attack or data leakage, the multi-party co-management log system in the multi-identifier network system will automatically record the attack behavior through the formula The automatically recorded logs adopt the blockchain chain structure, represents the j th transaction, j represents the serial number of the transaction, represents the j −1 log hash value of the previous operation.

[0017] The present invention also provides a system for using a trusted anonymous account in a multi-identity network system, which adopts the method for using a trusted anonymous account in a multi-identity network system as described above and includes: A SIM card master key generation module, configured to generate a mnemonic and a random number seed, and generate a master key and a master chain code of the SIM card through the random number seed; A SIM card key registration module, configured to submit the master key of the SIM card to the accounting node of the affiliated identity space to implement SIM card key registration; A MIN network private network resource invocation module, configured to invoke the private network resources of the MIN network; A MIN network identity signature and verification module, configured to perform identity signature and verification in the MIN network; A network packet addressing module, configured to perform network packet addressing for the SIM card in the MIN network.

[0018] Compared with the prior art, the beneficial effects of the present invention are as follows: First, a mnemonic and a random number seed are generated, and a master key and a master chain code of the SIM card are generated through the random number seed. Then, the master key of the SIM card is submitted to the accounting node of the affiliated identity space to implement SIM card key registration, so as to invoke the private network resources of the MIN network, perform identity signature and verification in the MIN network, and implement network packet addressing for the SIM card in the MIN network. Therefore, the present invention introduces the SIM card as a trusted hardware carrier, and cooperates with the multi-identity network system and the national cryptography algorithm of the sovereign network to generate a master key and a master chain code to construct a trusted anonymous account. This anonymous account can support cross-platform and cross-network authentication and access in the multi-identity network system, avoiding the privacy leakage risk of traditional centralized accounts, solving the technical problems of identity authentication relying on centralized management, difficulty in ensuring anonymity, and vulnerability of data security in traditional networks, and meeting the actual application requirements of cross-domain mutual trust and anonymous access for network digital identities. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 is a schematic diagram of the working process of an embodiment of the present invention; Figure 2 is a schematic diagram of the mnemonic confirmation process of an embodiment of the present invention; Figure 3 is a schematic diagram of the master key generation process of an embodiment of the present invention; Figure 4 is a schematic diagram of the private network resource invocation link of the MIN network of an embodiment of the present invention; Figure 5 is a schematic diagram of the multi-identity network packet of an embodiment of the present invention; Figure 6 is a flowchart of the multi-identity network packet processing of an embodiment of the present invention; Figure 7 It is a schematic diagram of concurrent processing of a multi-identifier router according to an embodiment of the present invention. Specific embodiments

[0020] Before introducing the specific embodiments of the present invention in detail, the key terms and related technologies of the present invention will be described first.

[0021] CT refers to Communication Technology, representing communication technology; IT refers to Internet Technology, representing Internet technology; ESN refers to Equipment Serial Number, representing the equipment serial number; SIM refers to Subscriber Identity Model, representing the customer identification module; IMEI refers to International Mobile equipment Identity, representing the international mobile equipment identification; TMSI refers to Temporary Mobile Subscriber Identity, representing the temporary mobile user identification; URI refers to Uniform Resource Identifier, representing the uniform resource identifier; SUPI refers to subscription permanent identifier, representing the user permanent identifier; SUCI refers to Subscription Concealed Identifier, representing the user hidden identifier; PEI refers to Permanent Equipment Identifier, representing the permanent equipment identifier; S-NSSAI refers to Single Network Slice Selection Assistance Information, representing the single network slice selection support information; TAID refers to Trusted Anonymous Identity, representing the trusted anonymous identity solution.

[0022] In the integrated development of CT communication network technology and digital identity technology, the first-generation mobile communication technology 1G began to use digital identity technology to identify entities, but there were relatively large security vulnerabilities. The first-generation mobile communication network technology 1G represented by AMPS, although it belongs to an analog cellular mobile communication system, users and terminal devices still use digital identifiers within the system.

[0023] The second-generation mobile communication technology 2G implemented a solution for separating the identity identification of "phone and card", effectively reducing security risks. The second-generation mobile communication network technology 2G represented by GSM pioneered the "phone and card" separation method, and the mobile phone and the SIM card together constitute the mobile communication terminal device.

[0024] The third-generation mobile communication technology 3G provides two-way authentication capabilities while further enriching the types of service identifiers. The third-generation mobile communication network technology 3G, represented by WCDMA, upgrades the SIM card to the Universal Subscriber Identity Module USIM and further supports two-way authentication between the terminal and the network. The 3G mobile communication network enriches and expands two types of services for users, namely circuit switching CS and packet switching PS, so that the service identifiers not only cover the MSISDN in the CS domain but also include the access point name APN in the PS domain.

[0025] The fourth-generation mobile communication technology 4G introduces a new IP multimedia identity to achieve IP-based unified communication and identity management. The fourth-generation mobile communication network technology 4G, represented by LTE, stops the development and evolution of the CS domain, and the IP multimedia subsystem IMS domain undertakes voice and video services.

[0026] The fifth-generation mobile communication technology 5G introduces new service identifiers to achieve secure and flexible network slicing services and unified user identity management. In the fifth-generation mobile communication network technology 5G, the user permanent identifier SUPI is equivalent to the IMSI in LTE, with the same format as the IMSI, but the SUPI will never be transmitted over the air interface to prevent tracking users by eavesdropping on wireless signals. The user hidden identifier SUCI is a privacy protection identifier containing the hidden SUPI and can be transmitted over the air interface. Each terminal device accessing the 5G mobile communication network should have a permanent device identifier PEI, corresponding to the IMEI in the LTE network.

[0027] Generally speaking, during the evolution from 1G to 5G, the integration of digital identity technology and mobile communication networks has been continuously deepened, effectively realizing the separation and independent development of device identifiers, user identifiers, and service identifiers. Although the system centered on user identifiers is expected to continue to exist, with the diversification of network terminals and the continuous expansion of service types, the specific form of user identifiers, the types of device identifiers, and service identifiers will all experience more innovations and changes accordingly. Correspondingly, the digital identity technology in mobile networks will also follow this development trend and continue to evolve to adapt to new challenges and requirements.

[0028] In the trusted anonymous identity solution, the CT system mainly focuses on areas such as the user's number account, card key, and HLR (Home Location Register) user center, and pays attention to functions such as account management, permission management, identity authentication, and communication encryption and decryption. At the IT system level, it covers the user's number account, card key, and IDaaS (Identity as a Service) user center, etc., and also emphasizes account management, permission management, and identity authentication, while also extending to the requirements of business encryption and decryption. This two-way design combines the core capabilities of the communication field and the information technology field, laying a foundation for building a secure and unified identity management system.

[0029] In the TAID solution architecture, the entire system starts with user authentication and runs through the authorized circulation and management of data. Specifically, business applications A, B, and C are respectively connected to data permission management to ensure that user data can be stored and calculated in a trusted manner. At the same time, the account center, risk center, permission center, authentication center, and audit center together constitute the core modules, which are respectively responsible for account life cycle management, business risk control, functional permission control, account authentication, and audit traceability. This clearly defined division of labor further enhances the security and stability of the system.

[0030] In addition, the centralized unified trusted account system based on passwords demonstrates significant advantages. First, the unified mobile phone number account is combined with real-name authentication, and the legality and security of the account are ensured through electronic signature technology; second, the super SIM card is embedded with a password security chip and combined with a password resource pool to provide computing power support, effectively enhancing the password protection ability of the system; finally, the mobile network has a wide coverage, the computing power network provides data operation services, and the blockchain platform provides guarantees for the trusted storage and circulation of data. The coordinated operation of these infrastructures lays a solid foundation for the future development of related fields.

[0031] Regarding the multi-identifier network system, a multi-identifier management mechanism that integrates future networks and existing IP networks is adopted. The multi-identifier network system, abbreviated as MIN or MIN network, where MIN is the abbreviation of Multi-Identifier Network, is the world's first system that supports the construction of a multilateral co-governed sovereign Internet, aiming to solve the security, governance, and evolution problems faced by the current Internet architecture. The core concept of the MIN network is to achieve the sovereignty independence and interoperability of the cyberspace by supporting multiple identifiers (such as identity identifiers, content identifiers, geographical location identifiers, etc.) and decentralized management.

[0032] The Multi-Identifier Network (MIN) is the world's first system that supports the construction of a multilateral co-governed sovereign Internet, aiming to solve the security, governance, and evolution problems faced by the current Internet architecture. The core concept of the MIN network is to achieve the sovereignty independence and interoperability of the cyberspace by supporting multiple identifiers (such as identity identifiers, content identifiers, geographical location identifiers, etc.) and decentralized management. The MIN network mainly consists of a Multi-Identifier System (MIS) and a Multi-Identifier Router (MIR). Among them, in the Multi-Identifier System (MIS, namely Multi-Identifier System), the identity management system of the MIN network is governed by a multilateral co-governed consortium chain mechanism, and a voting method based on one country, one vote is used to manage the top-level identifier domain names; within each country, it is autonomously managed through an extensible hierarchical consortium chain. The Multi-Identifier Router (MIR, namely Multi-Identifier Router) supports multiple identifiers, including identity, content, service, and IP, etc., to implement a parallel co-existing network layer. MIN adopts the HPT algorithm of hash table and prefix tree, and supports multi-identifier translation and addressing of tens of billions of entries.

[0033] The MIN network has the following outstanding advantages: I. Support for multiple identifiers. MIN supports the parallel existence of multiple identifiers (such as identity, content, IP, etc.), and can flexibly use different identifiers for addressing and routing according to the application scenario. This enables MIN to not only meet the needs of the traditional Internet but also adapt to emerging fields such as the Internet of Things, Industrial Internet, and Internet of Vehicles.

[0034] II. Decentralized governance. MIN adopts blockchain technology and a consortium chain voting mechanism to ensure the fairness and transparency of global network management, and avoids the unilateral monopoly problem brought by the current centralized DNS management. III. High security and data traceability. The MIN network realizes the traceability of data by using asymmetric encryption technology, ensuring the security of data transmission and privacy protection. The design of MIN makes it have inherent security features and can defend against various network attacks. MIN integrates a variety of security technologies, such as signature cryptography, authentication, and behavior detection, etc., to build a dynamic security protection model to effectively resist various network attacks.

[0035] IV. Scalability and flexibility. The multi-identifier routing mechanism and the hierarchical management structure based on the consortium chain of MIN make it highly scalable. Whether in a small-scale enterprise private network or a global sovereign Internet scenario, MIN can provide flexible solutions.

[0036] V. Compatibility with existing network systems. MIN is compatible with existing network architectures such as IPv4 and IPv6, supports gradual evolution and transition, and does not require a complete replacement of existing network devices, reducing the migration cost.

[0037] 6. Identity-driven. MIN uses identity as the core identifier, supports the registration and verification of users' real identities, enhances the security and transparency of the network. The binding of the identity identifier to the device ensures the traceability of network behaviors.

[0038] Generally speaking, the core advantages of MIN are multi-party co-governance and decentralized management. Combined with the support of multiple identifiers and a strong security mechanism, it has the characteristics of multi-identifier management, decentralized governance, identity-driven, and data traceability, enabling it to meet the development needs of future networks.

[0039] In an existing technology related to the present invention, the Internet Protocol (IP) is adopted. Also known as the Internet protocol, it is the network layer communication protocol in the Internet protocol packet and is used for packet switching across network boundaries. Its routing function realizes interconnection and essentially establishes the Internet.

[0040] IP is the main protocol in the network layer of the TCP / IP protocol suite. Its task is to transfer data packets from the source host to the destination host only according to the IP address in the data packet header. For this purpose, the IP protocol defines the data packet structure for encapsulating the data to be transferred. It also defines the addressing method for labeling datagrams with source and destination information.

[0041] The characteristic of the IP address method is to assign a network address to each terminal, and each packet carries this address as the basis for network nodes to forward packets. The currently widely used IPv4 packet structure uses 32 bits as the address field, which is roughly equivalent to only 9 decimal digits. Now, almost all the telephone numbers in big cities in our country have adopted 8-digit numbers. It is certain that using a 32-bit address field to identify terminals worldwide is not enough. Therefore, the address crisis problem was realized in the early 1990s, and the IETF began the standardization work of IPv6. IPv6 uses 128 bits as the address field. It seems that this numbering resource will meet the actual needs for a quite long time. The work of expanding the address field seems very natural, but the other two problems associated with the expansion of the address field are quite interesting. One is the popularization of IPv6, and the other is the difficulty brought by the IP network address method to high-speed packet forwarding. The popularization speed of IPv6 is extremely slow. On the one hand, this reflects that through the address segmentation of CIDR, the address reuse through proxy servers, and the dynamic address allocation through ISPs, IPv4 can still cope with the current actual needs. But more importantly, it reflects that the IP address method is too involved with the operation mode of the network. It requires replacing the communication programs of users and changing the packet forwarding modules of routers, almost affecting all devices on the network. The number upgrade work that can be completed overnight on the traditional telephone network may take more than a decade to be completed on the IP network.

[0042] On a traditional telecommunications network, the number identifying the transceiver terminal and the channel identifier guiding information forwarding are relatively separated. This makes sense because the potential transceiver terminals may number in the tens of millions or even hundreds of millions, while the operations of information forwarding involved in a switch or router are merely the selection of dozens, at most a hundred or so output ports. Just like in an IP network, in order to find a suitable port out of no more than a thousand output ports, tens of millions of records need to be searched.

[0043] This related prior art has the following drawbacks: The security issues of the IP network include two aspects: network security and information security. Network security refers to the attack or damage of the public facilities providing network services, such as the settings of domain name servers or routers being damaged, or their services being maliciously blocked, etc. Information security refers to the leakage or rewriting of the information transmitted on the Internet or stored on the server, etc. How to encrypt information and how to set up a secure and effective information access method are issues related to the network, but they are not network issues themselves. Since information is exposed on the network in electronic form, it is more difficult to maintain its security on the network.

[0044] Moreover, the introduction of the TCP / IP protocol seemingly solved the problem of the basic rules for data transmission in the vast Internet, and established a set of basic rules for data transmission. To facilitate the determination of the location of each computer and find an identifiable destination for data transmission, the IP protocol addresses each node on the network, and this address is the IP address. The IP address adopts a four-segment dotted decimal as the writing rule, such as "211.214.1.XXX". However, based on the principle of non-repetition, the disordered and complex IP combinations impose a burden on computer operators and it is difficult to easily handle a series of disordered numbers. In this way, the disordered and complex IP addresses indirectly raise the threshold for using the Internet and become one of the limiting factors for Internet applications.

[0045] In another prior art related to the present invention, the Named Data Networking (NDN) is adopted. It was proposed in 2010, and its predecessor is the Content-Centric Networking (CCN). It uses receiver-driven pull communication semantics to replace the sender-driven push communication semantics in the IP network. In NDN, content consumers obtain content by sending interest packets (Interest) into the network. Any intermediate router or content producer (Producer) that caches the corresponding content will respond with a data packet (Data) when it receives an Interest. Each Interest can pull one Data, and there is a one-to-one correspondence between Interest and Data. NDN designs a Pending Interest Table (PIT) to support a stateful forwarding plane. Each PIT entry records from which network interface the Interest is received. All PIT entry records on the Interest forwarding path construct a reverse path, and the corresponding Data only needs to return along the reverse path constructed by the PIT. Through this pull-based interaction, NDN realizes the decoupling of content and producers, and can better support the business scenario of content distribution. To protect the security of content, NDN requires the Producer to sign each sent Data, which enables consumers to trust the content itself without caring about how and where the content is obtained. Due to the disruptive architecture design of NDN, its compatibility with the existing network architecture remains to be studied.

[0046] This prior art has the following disadvantages: Although NDN enhances the integrity, origin authentication, and correctness of data through the content signature mechanism, it still faces many privacy and security risks: name privacy, the hierarchical name in the interest packet can disclose content information. Especially when the name structure is very intuitive, it may lead to the leakage of user privacy; cache privacy, attackers can obtain access information about the content in the cache through timing analysis; content privacy, although the data packet is signed, the content itself is not encrypted, so data leakage cannot be prevented; signature privacy, the signature can expose the identity of the producer, thereby infringing on the privacy of individuals or organizations.

[0047] In addition, NDN may face various forms of attacks, including denial-of-service (DoS) attacks, protocol attacks, and timing attacks. Among them, for the denial-of-service (DoS) attack, the DoS attack makes the PIT table of the router overflow by sending a large number of interest packets, thus blocking legitimate requests. Since the interest packets of NDN do not contain source addresses, it is difficult to trace the attacker. The attacker can generate a large number of invalid interest packets through a botnet, resulting in cache pollution, bandwidth consumption, and exhaustion of network resources. For protocol and timing attacks, the protocol attack uses the prefix matching mechanism of NDN to infer the content requested by the consumer, thereby infringing on name privacy. The timing attack measures the response time to infer whether the content is cached, thereby obtaining cache privacy.

[0048] For this reason, the present invention proposes a method for using a trusted anonymous account in a multi-identifier network system, using a SIM card to access the MIN network for identity registration and login. First, in step S1, the SIM card is used to generate a master key, and the process is divided into two steps: the first step is to output a random number seed after the user confirms the mnemonic corresponding to the random number generated by the card application; the second step is to calculate the master key and the master chain code through the random number seed, thereby ensuring the security and calculation efficiency of key generation. The multi-identifier management system MIS in the MIN network will be docked with the operator's database in real time to verify the legality of the anonymous account corresponding to the master key and the master chain code, ensuring the uniqueness and accuracy of the user identity.

[0049] In this process, with the anonymous account as the identity and the card as the security hardware, a trusted account system with the real-name mobile phone number as the ID is constructed to provide unified user identity, trusted authentication of the SIM card, and authentication of ability invocation, realizing cross-platform account data interconnection and compliance output of ability data. The present invention can be based on the national secret security chip and key storage capacity of the super SIM card, combined with PKI asymmetric encryption technology and cryptographic algorithms, to be built into a new type of mobile intelligent password key, which can provide high-security identity authentication and data encrypted transmission and other capabilities in application scenarios such as the human network and the Internet of Things.

[0050] In the multi-identifier network system, various data exist in the form of identifiers. For example, when an individual registers an identity identifier, the multi-identifier management system MIS needs to be provided with the applied prefix, user level, user name, real name, phone number, ID number, fingerprint, face, iris data, public key, description information, and the timestamp of the submitted application.

[0051] When an institution registers an identity identifier, it needs to provide information such as the institution code, address, legal person name, ID number, and bank account. The multi-identifier router MIR, etc., can register the device identity identifier. When registering, a public key with appropriate strength needs to be provided, and an electronic signature is made for the submitted application.

[0052] When a user registers their user identity identifier, in addition to the user's basic information, they also need to provide their identity public key to the multi-identifier management system MIS. After the multi-identifier management system MIS passes the registration request, it will issue a certificate for the user and lock it on the blockchain. Thereafter, all interaction information between the user and the multi-identifier management system MIS needs to be signed by the user with the private key, and the multi-identifier management system MIS will verify it. Only after the verification passes can further operations be carried out. It should be noted that each registered prefix corresponds to a unique MIN certificate. At the same time, the multi-identifier management system MIS provides an interface for querying the user's MIN certificate externally. The multi-identifier router MI can obtain the MIN certificate corresponding to a certain prefix from the multi-identifier management system MIS, so as to perform security verification on the interest packet, etc.

[0053] The following further describes in detail the preferred embodiments of the present invention with reference to the accompanying drawings.

[0054] As Figures 1 to 7 shown, this embodiment provides a method for using a trusted anonymous account in a multi-identifier network system, including the following sub-steps: Step S1, generate a mnemonic and a random number seed, and generate the master key and master chain code of the SIM card through the random number seed; Step S2, submit the master key of the SIM card to the accounting node of the affiliated identifier space to implement SIM card key registration; Step S3, the user calls the private network resources of the MIN network; Step S4, perform identity signature and signature verification in the MIN network; Step S5, the SIM card performs network packet addressing in the MIN network; Among them, the said step S1 includes the following sub-steps: Step S101, first, generate a random number, then convert the random number into a mnemonic, and determine the random number seed through the mnemonic; Step S102, perform iterative calculation based on the random number seed, generate an intermediate value, and perform combination and calculation through the intermediate value to generate the master key and master chain code corresponding to the SIM card.

[0055] The said step S101 in this embodiment is used to generate a mnemonic and a random number seed. As Figure 2 shown, preferably includes the following sub-steps: Step S1011, the SIM card application generates and returns a 128-bit first random number E, and returns the first random number E to the service application; Step S1012, obtain a 132-bit second random number through the SM3 hash algorithm and the Chinese character table, and convert the second random number into 12 Chinese mnemonics for the user to understand and confirm; Step S1013: Send the Chinese mnemonic back to the user for confirmation, and use the second random number corresponding to the confirmed Chinese mnemonic by the user as the random number seed. S 。

[0056] More preferably, as Figure 2 shown, in step S1012 of this embodiment, first perform a hashing process on the first random number E through the SM3 hashing algorithm, then take the first 4-bit data of the hashing result C, and splice it with the first random number E; then, divide the 132-bit second random number obtained after splicing into 12 groups of strings; finally, convert the 12 groups of strings into 12 Chinese mnemonics respectively through the Chinese character table. The process of converting into Chinese mnemonics is as follows: preset a Chinese character table in the system, for example, preset a Chinese character table containing 2048 different Chinese characters, and then map the 11-bit strings into different Chinese characters according to the preset mapping rules. The Chinese character table and its mapping rules in this embodiment can both be set and adjusted according to the actual situation.

[0057] Step S102 in this embodiment is used to generate the master key; the master key includes the master public key and the master private key. In step S102, the SIM card application is based on the confirmed 132-bit random number seed S , preferably using the PBKDF2 key derivation algorithm based on the SM3 hashing algorithm, to generate the master private key, the master public key, and the corresponding master chain code. The number of iterations of this algorithm is 128 to ensure the high security of the generated key. At the same time, to ensure the calculation efficiency, this embodiment further simplifies the complexity of the key generation algorithm, so that the entire key generation process can be completed in about 1 second.

[0058] Specifically, as Figure 3 shown, step S102 in this embodiment includes the following sub-steps: Step S1021: First, perform iterative operations on the random number seed through the SM3 hashing algorithm, and generate intermediate values to intermediate value by the formula , at this time , i represents the serial number of the iterative operation, S represents the random number seed; then, calculate the master private key through the formula master private key , and the master private key is denoted as ; finally, process the master private key through the SM2 algorithm to obtain the master public key corresponding to the SIM card; Step S1022: First, perform iterative operations on the random number seed through the SM3 hashing algorithm, and generate intermediate values Generate an intermediate value To the intermediate value At this time , i Indicates the serial number of the iterative operation, S Indicates the random number seed; then, through the formula master chain code , calculate the master chain code of the SIM card . The master chain code of the SIM card described in this embodiment is used to derive sub-keys in subsequent steps, so as to support hierarchical identity management and authentication operations in a multi-identifier network system.

[0059] Therefore, this embodiment combines the advantages of the SM3 hash algorithm and the computing power of the SIM card, and provides a secure and efficient master key generation scheme for the specific application environment of this embodiment. Moreover, this master key generation scheme can be completely completed inside the SIM card without relying on an external network, effectively avoiding man-in-the-middle attacks and information leakage problems during data transmission, and providing a better foundation for data protection and privacy security.

[0060] Step S2 described in this embodiment is used to implement SIM card key registration.

[0061] When a user registers an identity, a registration client is used, which can be either an IP node or a MIN node.

[0062] Step S2 described in this embodiment preferably includes the following sub-steps: Step S201, submit the master key of the SIM card to the accounting node of the affiliated identity space; Step S202, after the accounting node receives the key registration request sent by the client, it will check the request format of the key registration request and verify the content of the key registration request; during this process, first check whether the user information already exists in the local database and perform basic verification on some content, such as verifying the user ID number and mobile phone number, etc. As long as the result of any of the above steps is negative, such as the request format is incorrect or the content verification fails, an error message will be returned to the client; Step S203, after the verification is passed, the accounting node will encapsulate the key registration request as an ordinary transaction and put it into the transaction pool; encapsulating it as an ordinary transaction means encapsulating it in the decentralized structure of a conventional blockchain, and the encapsulated block contains information such as transaction records and hash values.

[0063] Step S204. At the beginning of each round of consensus, all accounting nodes retrieve ordinary transactions from the transaction pool, generate a block, and then send the block to all voting nodes. The voting nodes that receive the block verify the block header and each transaction content. The verification of each transaction is carried out according to the rules preset by the voting nodes, such as verifying keywords according to a custom filtering list, etc., to form a voting result. Step S205. When the voting nodes have received all the blocks or waited until timeout, they package the voting information of all the blocks and send it to the rotating accounting node. Step S206. The rotating accounting node counts the voting information of each voting node, deletes the blocks for which the number of rejected votes received exceeds the preset threshold, and the preset threshold is half of the number of voting nodes; recognizes the blocks for which the number of approved votes received exceeds the preset threshold. Therefore, for a certain block, if the number of rejected votes received exceeds half of the number of voting nodes, the block in memory is deleted; if the number of approved votes received exceeds half of the number of voting nodes, the block is recognized. Step S207. After the voting situation of all the blocks is counted, the rotating accounting node generates a block group header, writes the counted vote situation and the block hash value, sets the timestamp, and publishes the block group header to the blockchain network. Step S208. After all the nodes in the blockchain network receive the block group header sent by the rotating accounting node, they first verify it. Until the verification passes, they submit the block group and update the parameters, extract the key registration information from the transactions of the block, and store it in the user information table. If the verification fails, it is discarded.

[0064] Step S3 in this embodiment is used for users to call the MIN network private network resources, such as Figure 4 As shown, preferably includes the following sub-steps: Step S301. Start the MIN-VPN and perform two-way authentication between the MIN-VPN and the MIN-Proxy; if the authentication is successful, the startup is successful; if the authentication fails, the startup fails; MIN-VPN refers to the dedicated virtual private network architecture of the multi-identifier network system, and MIN-Proxy refers to the dedicated network proxy server of the multi-identifier network system for forwarding requests and responses, which is used to convert network packets and forward them to the VPN-Server. The VPN-Server does not support IP communication, and the two-way authentication adopted in this embodiment is based on IP communication. Step S302: The user enters the user account and password on the MIN-VPN login interface, clicks / to log in. MIN-VPN checks whether the corresponding MIN identity of the user exists locally. If it exists, the user account, password, and MIN identity flag are sent to the VMS server. At this time, the MIN identity flag is "exists"; if it does not exist, return to Step S1 to generate the master key for the user using the SIM card, and send the user account, password, MIN identity flag, and master public key to the VMS server. At this time, the MIN identity flag is "does not exist"; the VMS server refers to the server of the VPN management system, and VMS is the abbreviation of Virtual Management System. Step S303: After receiving the information, the VMS server forwards the user account and password to the Directory Service AD to authenticate the user information. If the authentication fails, return a login failure to MIN-VPN. If the authentication is successful, jump to Step S304; AD refers to Active Directory. Step S304: If the MIN identity flag is "does not exist", send the user's master public key to the Multi-Identity Management System MIS to register the MIN identity and return the MIN identity and token; if the MIN identity flag is "exists", directly return the MIN identity and token. Step S305: MIN-VPN receives the login success message, creates a blank multi-identity network packet, adds the user account and token as fields to the multi-identity network packet, constructs a multi-identity network packet containing the user account and token, reads the master private key, and signs the multi-identity network packet, that is, implement signature based on the user's master private key through Step S401; the multi-identity network packet is also called the multi-identity network packet. Step S306: Connect to the VPN-Server, send the signed multi-identity network packet. The Multi-Identity Router MIR requests the user's MIN certificate from the Multi-Identity Management System MIS according to the obtained user account. The MIN certificate refers to the multi-identity network certificate including the user's public key, which is used to obtain the user's master public key and verify the correctness of the signature in the message according to the master public key; VPN-Server refers to the Virtual Private Network Server. Step S307: Before the Multi-Identity Router MIR forwards the multi-identity network packet to the VPN-Server, verify the signature of the multi-identity network packet, that is, implement signature verification based on the user's master public key through Step S402. Step S308: If the signature verification passes, the user account and token are successfully sent to the VPN-Server. Step S309: The VPN-Server receives the user account and the token, sends the token and the user account to the VMS server. After the VMS server successfully validates the token, it retrieves the user access control list (ACL, Access Control List) and returns it to the VPN-Server. Step S310: The MIN-VPN successfully connects to the VPN-Server. When the user clicks to access a website, the VPN-Server receives the multi-identity network packet, retrieves the user access control list, and performs permission control.

[0065] In step S301 of this embodiment, during the mutual authentication between the MIN-VPN and the MIN-Proxy, a MIN-Proxy dedicated network proxy server based on TLS / SSL is used to implement mutual authentication. First, the MIN client sends its client certificate to the MIN-Proxy. Then, after receiving the client certificate, the MIN-Proxy verifies it and requests the server certificate from the VPN-Server after verifying the client certificate. Finally, the MIN client obtains the server certificate of the VPN-Server through the VPN-Proxy and verifies the server certificate, thus completing the mutual authentication process.

[0066] Step S4 in this embodiment is used to implement MIN network identity signature and signature verification. The step S4 preferably includes the following sub-steps: Step S401: Implement signature based on the user's main private key calculated in step S102. After confirming that the main private key is not empty, first select the corresponding signature method according to the public key generation algorithm in the KeyParam key parameter, then convert the main private key (such as id.Prikey) to the private key type of the SM2 algorithm, such as the parameter p of the sm2.Sm2PrivateKey type, and call the p.Sign digital signature method for signature. Here, KeyParam is the key parameter used to specify the public key generation algorithm; the SM2 algorithm is a public key cryptography algorithm based on elliptic curves, used for digital signature and encryption; the signature in this embodiment defaults to the SM2WithSM3 algorithm. Step S402: Implement signature verification based on the user's main public key calculated in step S102. After verifying that the main public key is not empty, first select the corresponding verification method according to the public key generation algorithm in the KeyParam key parameter, then convert the main public key (such as id.Pubkey) to the public key type of the SM2 algorithm, such as the parameter p of the sm2.Sm2PublicKey type, and call the p.Sign verification method for verification. The verification in this embodiment defaults to the SM2WithSM3 algorithm.

[0067] Step S5 in this embodiment is used to implement the network packet addressing process of the SIM card in the MIN. As Figure 6 shown, step S5 preferably includes the following sub-steps: Step S501, multiple-identification network packets flow in; Step S502, read a data link layer data segment from the network, and decode the multiple-identification network packets through TLV encoding; among them, the multiple-identification network packets include four regions, as Figure 5 shown, the four regions are the identification region, the signature region, the read-only region, and the variable region respectively; each region is composed of one or more TLV-encoded triples (i.e., Type / Length / Value). TLV encoding divides the binary data block into three intervals. The interval at the very front is the Type field, indicating the type of the current data block; the middle interval is the Length field, indicating the length of the Value field; the last interval is the Value field, used to store the data block; Step S503, determine whether the decoding of the multiple-identification network packets is successful. If not, discard the multiple-identification network packets and end the processing flow; if so, jump to step S504; Step S504, check the destination identification area field of the multiple-identification network packets, and determine whether there is a next unprocessed identification in the destination identification area; if there is no identification in the destination identification area or the identification has been processed, discard the multiple-identification network packets and end the processing flow; if there is a next unprocessed identification in the destination identification, jump to step S505; Step S505, read the next unprocessed identification, and determine whether the current multiple-identification router can resolve and process this identification through the identification type number of this identification. If not, that is, it cannot resolve and process this identification, return to step S504 to continue to determine whether there is a next unprocessed identification in the destination identification area; if so, jump to step S506; Step S506, process the multiple-identification network packets according to the identification semantics, that is, call the processing flow, read and resolve the value of this identification, and according to the value of this identification and the identification type number, call the corresponding processing function to process the multiple-identification network packets, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packets from the specified port; Step S507, determine whether the processing of the multiple-identification network packets is successful. If not, return to step S504 to continue to determine whether there is a next unprocessed identification in the destination identification area; if so, end the processing flow.

[0068] This embodiment gives the network packet processing process of a single thread (single processor) through steps S501 to S507, and gives the flowchart of a network packet forwarder processing a network packet, asFigure 6 The figure shows the complete process of a single-core router processing a network packet.

[0069] Since the support of multiple identifiers by the multi-identity router MIR can be completely isolated from each other, in the software-implemented forwarder, a multi-core processor can be used to forward network packets carrying different identifiers. Therefore, in step S5 of this embodiment, when a multi-identity network packet carrying multiple identifiers enters the multi-identity router MIR, the multi-identity router MIR processes the multiple identifiers concurrently, such as Figure 7 The FIB table refers to the Forwarding Information Base, i.e., the query forwarding table, which is used to implement query and forwarding processing in the identification processing unit.

[0070] In this embodiment, the process of the multi-identity router MIR concurrently processing multiple identifiers includes: Step B1, extracting all the identifiers in the multi-identity network group, and determining the identifier types supported by the multi-identity router MIR through an identifier filter; Step B2, duplicating according to the number of supported identifiers and sending them to different identifier processing units for processing. After receiving the processing tasks, different identifier processing units independently complete the processing of multi-identifier network groups and then summarize the processing results to the decision unit; Step B3: The decision unit selects a processing result to be adopted according to the sequence of the identifiers in the multi-identifier network group.

[0071] For example, in Figure 7 In the example, the identifiers 101 and 103 carried in the multi-identifier network packet are both identifier types supported by the current router, so the incoming network packet is copied into two copies and distributed to two different identifier processing units for processing, and different identifier processing units can independently run on different CPUs or different CPU cores. After receiving the multi-identifier network packet processing task, different identifier processing units independently complete the processing of the multi-identifier network packet, and each identifier processing unit summarizes the processing results to the decision unit.

[0072] like Figure 7 As shown, the priority of identifier 103 in the network packet is higher than that of identifier 101. Therefore, if the processing result of identifier 103 is normal, that is, the result of the identifier processing unit is not to discard the multi-identifier network packet, the decision unit adopts the processing result of the identifier processing unit corresponding to identifier 103, and ignores the result of the identifier processing unit corresponding to identifier 101. Only when the processing result corresponding to identifier 103 is to discard the multi-identifier network packet, the decision unit adopts the processing result of the identifier processing unit corresponding to identifier 101.

[0073] Therefore, in the parallel multi-identity router MIR of this embodiment, all the identifiers in the multi-identity network group are first extracted, and different identifier processing units independently complete the processing of the multi-identity network group after receiving the processing task of the multi-identity network group, and then each identifier processing unit summarizes the processing results to the decision unit. The decision unit decides which identifier processing unit's processing result to use according to the order of each identifier in the multi-identity network group.

[0074] In this embodiment, first, a mnemonic and a random number seed are generated, and the master key and the master chain code of the SIM card are generated by the random number seed, and then the master key of the SIM card is submitted to the accounting node of the identity space to which it belongs, so as to realize the key registration of the SIM card, so as to call the private network resources of the MIN network, perform the MIN network identity signature and signature verification, and realize the network group addressing of the SIM card in the MIN network. Therefore, the SIM card is introduced as a trusted hardware carrier, and the multi-identity network system and the national secret algorithm of the sovereign network are used to generate the master key and the master chain code to build a trusted anonymous account. The anonymous account can support cross-platform and cross-network authentication access in the multi-identity network system, avoid the privacy leakage risk of traditional centralized accounts, solve the technical problems of identity authentication relying on centralized management, difficulty in ensuring anonymity, and fragile data security in traditional networks, and meet the actual application requirements of network digital identity to realize cross-domain mutual trust and anonymous access. The system architecture designed in this embodiment can support the multilateral co-management of global top-level identities and the territorial independent management of subordinate identities, effectively realizing cross-domain mutual trust and anonymous access.

[0075] Mathematical modeling analysis shows that in the MIN network, the security and anonymity of identity authentication are exponentially improved. Assuming that the probability of identity being impersonated in the traditional IP network is In this embodiment, the random number generated by the SIM card is and the master private key , combined with the main chain code Perform identity mapping. Master private key By the initial random seed S Generate, see step S1 for details. Random number R Generated dynamically within the SIM card by each specific mapping instance.

[0076] This embodiment also preferably includes anonymous account mapping and log recording steps, and the anonymous account mapping and log recording steps include step A1 and step A2.

[0077] Step A1, by formula Map each anonymous account registered to the MIN network to a unique anonymous account through the SIM card ;in, represents a hash function, represents the master private key, represents the master chain code, represents user information, which includes information such as the user's mobile phone number and ID number.

[0078] This embodiment breaks through the single addressing mechanism of traditional IP networks and realizes the coexistence and dynamic mapping of multiple identifiers, namely identity identifier (ID), content identifier (CID), and location identifier (LID) on the basis of a multi-identifier network system, ensuring the sovereignty independence, mutual trust, and interconnection of the network space.

[0079] This embodiment randomly generates a mnemonic phrase in step S1 and derives the master key and the master chain code , and then obtains a unique anonymous account through the mapping of the hash algorithm . This anonymous account supports cross-platform and cross-network authentication access, completely avoiding the privacy leakage risk of traditional centralized accounts. On this basis, in the network access and data interaction of step S3, a two-way authentication process based on PKI (Public Key Infrastructure) and national cryptography algorithms (such as SM2 / SM4 algorithms) is designed, which not only ensures the anonymity of access but also enables the synchronous completion of data encryption and identity verification. Specifically, when the anonymous account makes a network request, the system will perform on-chain verification, and the verification process does not expose the real identity and only completes the authorization confirmation through zero-knowledge proof.

[0080] Preferably, this embodiment adopts a trusted anonymous authentication and cross-domain mutual recognition mechanism. By introducing PKI asymmetric encryption and zero-knowledge proof (ZKP) technologies, when a user accesses the MIN network, identity authentication and resource access permission allocation can be completed without exposing the real identity. At the same time, through the hardware isolation of the SIM card and on-chain log storage, the integrity of the access path is guaranteed and the security is high.

[0081] In step A2 of this embodiment, in the case of a network attack or data leakage, the multi-party co-governed log system in the multi-identifier network system will automatically record the attack behavior through the formula . The automatically recorded logs adopt the blockchain chain structure, and all operations are immutable; represents the j th transaction, represents the log hash value of the j −1th operation, j represents the serial number of the transaction. This not only supports the rapid traceability of attack behaviors but also can be used as legal evidence in the network space.

[0082] This embodiment realizes distributed on-chain logging and behavior tracing. The MIN network has a blockchain log jointly managed by multiple parties built in. Every operation of the anonymous account is synchronously recorded and cannot be tampered with. When an attack event occurs, the system can quickly trace the source based on the timestamp and signature verification, providing the attacker's behavior path and evidence chain.

[0083] This embodiment also provides a system for using a trusted anonymous account in a multi-identity network system. It adopts the method for using a trusted anonymous account in a multi-identity network system as described above and includes: A SIM card master key generation module, which is used to generate a mnemonic and a random number seed, and generate the SIM card's master key and master chain code through the random number seed; A SIM card key registration module, which is used to submit the SIM card's master key to the accounting node of the affiliated identity space to realize SIM card key registration; A MIN network private network resource invocation module, which is used to invoke the private network resources of the MIN network; A MIN network identity signature and verification module, which is used to perform identity signature and verification in the MIN network; A network packet addressing module, which is used for the SIM card to perform network packet addressing in the MIN network.

[0084] The above content is a further detailed description of the present invention in combination with specific preferred embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention belongs, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should all be regarded as belonging to the protection scope of the present invention.

Claims

1. A method for using a trusted anonymous account in a multi-identity network system, characterized in that, It includes the following sub-steps: Step S1, generate mnemonics and a random number seed, and generate the master key and master chain code of the SIM card through the random number seed; Step S2, submit the master key of the SIM card to the accounting node of the affiliated identity space to implement SIM card key registration; Step S3, the user calls the private network resources of the MIN network; Step S4, perform identity signature and signature verification in the MIN network; Step S5, the SIM card performs network packet addressing in the MIN network; Among them, the step S1 includes the following sub-steps: Step S101, first, generate a random number, then convert the random number into mnemonics, and determine the random number seed through the mnemonics; Step S102, perform iterative calculation based on the random number seed to generate intermediate values, and perform combination and calculation through the intermediate values to generate the master key and master chain code corresponding to the SIM card.

2. The method of using a trusted anonymous account in a multi-identifier network system according to claim 1, wherein The step S101 includes the following sub-steps: Step S1011, generate and return a 128-bit first random number; Step S1012, obtain a 132-bit second random number through the SM3 hash algorithm and the Chinese character table, and convert the second random number into 12 Chinese mnemonics; Step S1013, send the Chinese mnemonics back to the user for confirmation, and use the second random number corresponding to the Chinese mnemonics confirmed by the user as the random number seed.

3. The method for using a trusted anonymous account in a multi - identity network system according to claim 2, characterized in that, In the step S1012, first perform hash processing on the first random number through the SM3 hash algorithm, then take the first 4-bit data of the result of the hash processing and splice it with the first random number; then, divide the 132-bit second random number obtained after splicing into 12 groups of strings; finally, convert the 12 groups of strings into 12 Chinese mnemonics through the Chinese character table.

4. The method for using a trusted anonymous account in a multi-identity network system according to claim 2, wherein The step S102 includes the following sub-steps: Step S1021, first, perform iterative operations based on the random number seed through the SM3 hashing algorithm, and through the formula Generate intermediate values To intermediate value , at this time , i represents the serial number of the iterative operation, and S represents the random number seed; then, through the formula of the main private key , calculate the main private key; finally, process the main private key through the SM2 algorithm to obtain the main public key corresponding to the SIM card; Step S1022. First, perform iterative operations based on the random number seed through the SM3 hashing algorithm, and through the formula Generate intermediate values To intermediate value , at this time , i represents the serial number of the iterative operation, and S represents the random number seed; then, through the formula master chain code , calculate the master chain code of the SIM card.

5. The method for using a trusted anonymous account in a multi-identity network system according to any one of claims 1 to 4, characterized in that, The step S2 includes the following sub-steps: Step S201, submit the master key of the SIM card to the accounting node of the affiliated identity space; Step S202, after the accounting node receives the key registration request sent by the client, it will check the request format of the key registration request and verify the content of the key registration request; Step S203, after the verification passes, the accounting node encapsulates the key registration request as a normal transaction and puts it into the transaction pool; Step S204, at the beginning of each round of consensus, all accounting nodes take out the normal transactions from the transaction pool, generate a block, and then send the block to all voting nodes. The voting nodes that receive the block verify the block header and each transaction content; Step S205, when the voting nodes receive all the blocks or wait until the timeout, they will pack the voting information of all the blocks and send it to the rotating accounting node; Step S206, the rotating accounting node counts the voting information of each voting node, deletes the blocks that receive more than the preset threshold of rejection votes (the preset threshold is half of the number of voting nodes), and approves the blocks that receive more than the preset threshold of approval votes; Step S207: After the voting situation of all blocks is counted, the rotating bookkeeping node generates a block group header, writes the counted vote situation and block hash value, sets the timestamp, and publishes the block group header to the blockchain network; Step S208: After all nodes in the blockchain network receive the block group header sent by the rotating bookkeeping node, they first perform verification. Until the verification passes, they submit the block group and update the parameters, extract the key registration information from the transactions of the blocks, and store it in the user information table.

6. The method for using a trusted anonymous account in a multi-identifier network system according to any one of claims 1 to 4, characterized in that Step S3 includes the following sub-steps: Step S301: Start MIN-VPN, perform two-way authentication between MIN-VPN and MIN-Proxy. If the authentication is successful, the startup is successful; if the authentication fails, the startup fails. MIN-VPN refers to the dedicated network architecture of the multi-identifier network system, and MIN-Proxy refers to the dedicated network proxy used in the multi-identifier network system to forward requests and responses; Step S302: The user enters the user account and password on the MIN-VPN login interface to log in. Through MIN-VPN, check whether the MIN identity corresponding to the user exists locally. If it exists, send the user account, password, and MIN identity flag to the VMS server. At this time, the MIN identity flag is "exists"; if it does not exist, return to Step S1 to generate the master key for the user using the SIM card, and send the user account, password, MIN identity flag, and master public key to the VMS server. At this time, the MIN identity flag is "does not exist". MIN refers to the multi-identifier network system, and the VMS server refers to the server of the VPN management system; Step S303: After receiving the information, the VMS server forwards the user account and password to the directory service AD to authenticate the user information. If the authentication fails, return "login failed" to MIN-VPN. If the authentication is successful, jump to Step S304; Step S304: If the MIN identity flag is "does not exist", send the user's master public key to the multi-identifier management system MIS to register the MIN identity, and return the MIN identity and token; if the MIN identity flag is "exists", directly return the MIN identity and token; Step S305: MIN-VPN receives the login success message, constructs a multi-identifier network packet containing the user account and token, reads the master private key, and signs the multi-identifier network packet; Step S306: Connect to the VPN-Server, send the signed multi-identifier network packet. The multi-identifier router MIR requests the MIN certificate of the user from the multi-identifier management system MIS according to the obtained user account. VPN-Server refers to the virtual private network server; Step S307: Before the multi-identifier router MIR forwards the multi-identifier network packet to the VPN-Server, verify the signature of the multi-identifier network packet; Step S308: If the signature verification passes, the user account and token are successfully sent to the VPN-Server; Step S309: The VPN-Server receives the user account and token, sends the token and user account to the VMS server. After the VMS server successfully verifies the token, it retrieves the user access control list and returns it to the VPN-Server. Step S310: MIN-VPN successfully connects to the VPN-Server. When the user clicks to access a website, the VPN-Server receives the multi-identifier network packet, retrieves the user access control list, and performs permission control.

7. The method of using a trusted anonymous account in a multi-identity network system according to any one of claims 1 to 4, characterized in that, The said step S4 includes the following sub-steps: Step S401: Implement signature based on the user's main private key. After confirming that the main private key is not empty, first select the corresponding signature method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the main private key to the private key type of the SM2 algorithm, and call the p.Sign digital signature method for signature. Step S402: Implement signature verification based on the user's main public key. After verifying that the main public key is not empty, first select the corresponding verification method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the main public key to the public key type of the SM2 algorithm, and call the p.Sign verification method for verification.

8. The method of using a trusted anonymous account in a multi-identifier network system according to any one of claims 1 to 4, characterized in that, The said step S5 includes the following sub-steps: Step S501: The multi-identifier network packet flows in. Step S502: Read the data link layer data segment and decode the multi-identifier network packet through TLV encoding. Among them, the multi-identifier network packet includes four regions, namely the identifier region, the signature region, the read-only region, and the variable region. Each region consists of one or more TLV-encoded triples. TLV encoding divides the binary data block into three intervals. The frontmost interval is the Type field, indicating the type of the current data block; the middle interval is the Length field, indicating the length of the Value field; the last interval is the Value field, used to store the data block. Step S503: Determine whether the decoding of the multi-identifier network packet is successful. If not, discard the multi-identifier network packet and end the processing flow; if so, jump to step S504. Step S504: Check the destination identifier region field of the multi-identifier network packet and determine whether there is a next unprocessed identifier in the destination identifier region. If there is no identifier or the identifier has been processed in the destination identifier region, discard the multi-identifier network packet and end the processing flow; if there is a next unprocessed identifier in the destination identifier, jump to step S505. Step S505: Read the next unprocessed identifier and determine whether the current multi-identifier router can resolve and process this identifier through the identifier type number of this identifier. If not, that is, it cannot resolve and process this identifier, return to step S504 to continue determining whether there is a next unprocessed identifier in the destination identifier region; if so, jump to step S506. Step S506: Invoke the processing flow, read and parse the value of the identifier, and according to the value of the identifier and the identifier type number, call the corresponding processing function to process the multi-identifier network packet, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet out from the specified port; Step S507: Determine whether the processing of the multi-identifier network packet is successful. If not, return to Step S504 to continue to determine whether there is a next unprocessed identifier in the destination identifier area; if so, the processing flow ends.

9. The method for using a trusted anonymous account in a multi-identity network system according to any one of claims 1 to 4, characterized in that, It further includes an anonymous account mapping and logging step, and the anonymous account mapping and logging step includes: Step A1, through the formula Map each anonymous account registered to the MIN network to a globally unique anonymous account through the SIM card ; where represents the hash function, represents the master private key, represents the master chain code, represents the user information; Step A2, in the event of a cyber-attack or data breach, the multi-signature network system's multi-party co-management log system will use the formula to automatically record the attack behavior. The automatically recorded logs adopt a blockchain chain structure. represents the j th transaction. j represents the serial number of the transaction. represents the j log hash value of the -1th operation.

10. A system using a trusted anonymous account in a multi-identity network system, characterized in that, The method of using a trusted anonymous account in a multi-identifier network system as described in any one of claims 1 to 9 is adopted, and it includes: The SIM card generates a master key module, which is used to generate a mnemonic and a random number seed, and generates the master key and the master chain code of the SIM card through the random number seed; The SIM card key registration module is used to submit the master key of the SIM card to the accounting node of the affiliated identifier space to implement SIM card key registration; The MIN network private network resource invocation module is used to invoke the private network resources of the MIN network; The MIN network identity signature and verification module is used to perform identity signature and verification in the MIN network; The network packet addressing module is used for the SIM card to perform network packet addressing in the MIN network.

Citation Information

Patent Citations

  • A method for obtaining the accounting right in a certain time period in a block chain network

    CN109255713A

  • User account privacy protection method and system

    CN114697019A

  • Method for Providing Safety Electronic Signature by using Secure Operating System

    KR101628615B1