Method and system for expanding operator mobile phone number identification in multi-identification network system
The MIN network framework expands operator phone number identifiers through authentication, single sign-on, and network addressing, addressing the limitations of single-identifier systems and enabling secure cross-space identity and data interoperability.
Patent Information
- Application Number
- CN202510797298.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-06-16
AI Technical Summary
Existing operators' mobile phone numbers use a single communication identifier, which is difficult to meet the needs of identity and data interoperability across physical and virtual spaces.
The identification of the operator's mobile phone number is expanded through the MIN network, including mobile phone number authentication, single sign-in, identity signature and signature verification, and network packet addressing. The MIN client and MIN-SDK toolkit are used to realize mobile phone number access, login and identity management.
It realizes the identification expansion of operator mobile phone numbers, meets the identity and data interoperability needs of mobile phone numbers across physical spaces and virtual spaces, and provides unified identity authentication and secure communication across domains.
Smart Images

Figure CN120321654A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for expanding the identification of a carrier's mobile phone number, in particular to a method for expanding the identification of a carrier's mobile phone number in a multi-identification network system, and further relates to a system adopting the method for expanding the identification of a carrier's mobile phone number in the multi-identification network system. Background Art
[0002] The concept of network digital identity has naturally formed with the popularization of the Internet and communication network processes. So far, there is no unified concept and accurate definition of network digital identity globally. Different definitions of digital identity exist on the Internet side and the communication network side, and the differences mainly stem from different observation perspectives, development needs, and construction ideas for digital identity.
[0003] From the perspective of the Internet, the International Organization for Standardization and the International Electrotechnical Commission believe that digital identity is to solve the identification and trust of digital space objects, use network information systems for secure transmission, storage, use, and management, and endow objects with unique corresponding digital identifiers and associated attribute declarations, etc. From the perspective of the communication network, the Telecommunication Standardization Sector of the International Telecommunication Union believes that digital identity is an identifier of an individual or entity in a digital communication and network environment, allowing it to be authenticated and accessed in various online services and applications.
[0004] With the rapid development of the Internet and the communication network, the integration speed of the two has accelerated, and they have jointly become the key core components and important infrastructure supporting the digital world. Especially after network digital identity enters the "digital identity application period", network digital identity has become a key link in the construction of the trust system and the support of digital ecological governance in the digital world, both in terms of the definition of digital identity and in practical applications.
[0005] In the wave of the digital economy, digital identity is gradually becoming the bridge and link connecting the physical world and the digital world. With the innovation of technology and the expansion of application scenarios, the scope, capabilities, and concept of digital identity have undergone a comprehensive upgrade, and its importance has become increasingly prominent. Digital identity is not only a mapping of an entity's behavior in the digital space but also the foundation of all activities in the digital world.
[0006] The scope, capabilities, and concepts of digital identity are upgraded, leading to the expansion of the connotations and extensions of digital identity subjects, carriers, and functions. First, in terms of the connotation of digital identity subjects, it expands from the narrow sense of "natural persons" to the broad sense of "humans, machines, and things", and from physical entities such as "humans, machines, and things" to virtual entities such as "data elements and digital humans", with the coverage gradually expanding and the entities involved increasing. Second, in terms of the connotation of digital identity carriers, in addition to "digitized" legal identity documents such as electronic ID cards, electronic passports, and electronic social security cards, it also includes "digitized" identity credentials such as phone numbers, email addresses, various account vouchers, biometric features, and QR codes, making the types of identity carriers more diverse. Third, in terms of the connotation of digital identity functions, in addition to the function of "proving who I am", it also expands the function of "proving the rights and attributes I possess". Through the three core modules of identity identification, identity attributes, and identity vouchers, the expansion of digital identity functions is realized, that is, it is necessary to uniquely identify an entity through multiple identifiers, describe the entity's characteristics through attributes, and provide evidence to verify the entity's identity attributes through vouchers. The three together constitute the basis of digital identity, ensuring the correct registration, issuance, verification, and management of identities.
[0007] Therefore, whether it is Internet identity or communication network identity, there is an urgent need for a digital identity definition and mechanism that can penetrate various industries and has certain inherent attributes of global interoperability to meet the identity and data interoperability needs across physical and virtual spaces, while ensuring the trustworthiness, interoperability, security, and privacy protection of digital identity, providing a basis for building a more secure, open, and interconnected digital world.
[0008] However, the existing operator mobile phone numbers generally still use traditional IP addresses, which are limited to single-level network positioning and use a single communication identifier. This existing solution is difficult to meet the identity and data interoperability needs across physical and virtual spaces. Therefore, there is an urgent need to provide a solution that can expand the identifier of operator mobile phone numbers. Summary of the Invention
[0009] The technical problem to be solved by the present invention is to provide a method for expanding the identifier of operator mobile phone numbers in a multi-identifier network system, aiming to expand the identifier of operator mobile phone numbers through the MIN network to overcome the defect that the existing operator mobile phone numbers use a single communication identifier and meet the identity and data interoperability needs of mobile phone numbers across physical and virtual spaces. On this basis, a system adopting the method for expanding the identifier of operator mobile phone numbers in the multi-identifier network system is further provided.
[0010] In response to this, the present invention provides a method for expanding the identifier of operator mobile phone numbers in a multi-identifier network system, including the following steps: Step S1: Implement the authentication of the mobile phone number through the MIN client, and complete the access of the mobile phone number to the MIN network. The MIN client refers to the multi-identity network system client, and the MIN network refers to the multi-identity network system, which is the abbreviation of the Cog-MIN network; Step S2: Implement single sign-on for the mobile phone number through the MIN-SDK toolkit. The MIN-SDK toolkit refers to the multi-identity network system toolkit; Step S3: Perform identity signature and verification in the MIN network; Step S4: Perform network group addressing in the MIN network using the mobile phone number; Among them, the said Step S1 includes the following sub-steps: Step S101: The user downloads, installs, and opens the MIN client; Step S102: Through the MIN client's integration of the SDK software development toolkit call, use the getPhonelnfo prefetch number interface to obtain the mobile phone number and return the prefetch number result; Step S103: The MIN client calls the loginAuth login interface to obtain user authorization and render the authorization page; Step S104: The MIN client prompts the user to authorize the mobile phone number to log in to the MIN client. After confirming the authorization to log in, obtain and return the authorization login token; Step S105: The MIN client generates account information and sends a registration and login request to the multi-identity router MIR, carrying the authorization login token and account information. The multi-identity router MIR forwards this request to the multi-identity management system MIS to send the registration and login request; Step S106: Query the authorized mobile phone number from the SIM card authentication server for registration and login; Step S107: Gradually return the registration and login results, maintain the login status in the MIN client, and prompt the user that the registration and login are successful.
[0011] A further improvement of the present invention is that the said Step S106 includes the following sub-steps: Step S1061: The multi-identity router MIR sends the request carrying the authorization login token to the security management system VMS, and the security management system VMS queries the authorized mobile phone number from the SIM card authentication server; Step S1062: The SIM card authentication server returns the authorized mobile phone number to the security management system MIS, and then forwards the authorized mobile phone number to the multi-identity management system MIS; Step S1063: Register and log in the user identity corresponding to the authorized mobile phone number in the MIN network through the multi-identity management system MIS.
[0012] A further improvement of the present invention lies in that the step S2 includes the following sub-steps: Step S201, the user accesses the APP application, requests to open the MIN channel, and calls the MIN-SDK toolkit to query the login status of the current user; Step S202, if the login status of the current user is not logged in, the APP application sends the user's authorization login token to the MIN-SDK toolkit to request single sign-on; the MIN-SDK toolkit sends the carried authorization login token to the MIN server to request to complete the user's single sign-on operation; the MIN server refers to the multi-identifier network system server; Step S203, the MIN server requests the operator server to obtain the user information corresponding to the authorization login token according to the received authorization login token; the operator server parses the user information and returns the user's mobile phone number and related data to the MIN server; Step S204, the MIN server completes the user registration or login operation according to the returned user information, and records the user's identity information in the identity management system of the multi-identifier network system; Step S205, after the MIN server completes the registration or login operation, it returns the response of the user's successful login to the MIN-SDK toolkit. After receiving the response of the successful login, the MIN-SDK toolkit sends the notification of the user's successful login to the APP application; Step S206, the APP application starts the MIN channel according to the user's login status and notifies the user that it has been successfully started.
[0013] A further improvement of the present invention lies in that in the step S2, it is judged whether it is the first time to realize single sign-on of the mobile phone number. If so, the user registration process of single sign-on is triggered; if not, the user login process of single sign-on is triggered; the user registration process of single sign-on includes the following sub-steps: Step A1, after the user inputs relevant information, first initialize the keychain KeyChain based on the KeyManager instance to obtain the identity of the current user, and then call the SM2 cryptographic algorithm to randomly generate a public-private key pair; Step A2, after the user enters the username and plain text password, the combined string of the username and plain text password is first subjected to SM3 hash calculation, and a 32-byte hash result hash32 is obtained through SM3 hash calculation; then the first 16 bytes of the hash result hash32 are taken to form a byte array hash16 as the SM4 key, and the user private key PrivateKey is subjected to SM4 encryption, and the encryption process adopts ECB_Padding mode to obtain the encrypted user private key EncryptedPrivateKey; Step A3, first register in the multi-identity management system MIS to host the user key; then register in the security management system VMS to manage the user's virtual private network VPN permissions.
[0014] A further improvement of the present invention is that the user login process of the single sign-on includes the following sub-steps: Step B1, after the user enters the user name, password and mobile phone number, and receives and fills in the verification code, the entered password is first processed by MD5 hashing, and then the processed password, user name, mobile phone number and verification code are encapsulated into a login request in JSON format, and finally the multi-identity management system interface MISRequestAPI is called to pass the login request to the multi-identity management system MIS; Step B2, first perform SM3 hash calculation on the original plaintext key, then take the first 16 bytes after SM3 hash calculation as the key, perform SM4 decryption on the user private key EncryptedPrivateKey, and the decoding process adopts ECB_Padding mode.
[0015] A further improvement of the present invention is that step S3 includes the following sub-steps: Step S301, signing based on the user's private key. After confirming that the private key is not empty, first select the corresponding signature method according to the public key generation algorithm in the KeyParam key parameter, then convert the private key to the private key type of the SM2 algorithm, and call the p.Sign digital signature method to sign; Step S302, implement signature verification based on the user's public key. After verifying that the public key is not empty, first select the corresponding verification method according to the public key generation algorithm in the KeyParam key parameter, then convert the public key to the public key type of the SM2 algorithm, and call the p.Sign verification method for verification.
[0016] A further improvement of the present invention is that step S4 includes the following sub-steps: Step S401, receiving data of a multi-identification network packet; Step S402: Read the data link layer data segment and decode the multi-identifier network packet through TLV encoding. The multi-identifier network packet includes four regions, namely the identifier region, the signature region, the read-only region, and the variable region. Each region consists of one or more TLV-encoded triples. TLV encoding divides the binary data block into three intervals. The frontmost interval is the Type field, indicating the type of the current data block. The middle interval is the Length field, indicating the length of the Value field. The last interval is the Value field, used to store the data block. Step S403: Determine whether the decoding of the multi-identifier network packet is successful. If not, discard the multi-identifier network packet and end the processing flow. If so, jump to step S404. Step S404: Check the destination identifier region field of the multi-identifier network packet and determine whether there is a next unprocessed identifier in the destination identifier region. If there is no identifier or the identifier has been processed in the destination identifier region, discard the multi-identifier network packet and end the processing flow. If there is a next unprocessed identifier in the destination identifier, jump to step S405. Step S405: Read the next unprocessed identifier and determine whether the current multi-identifier router can resolve and process this identifier based on the identifier type number of this identifier. If not, that is, it cannot resolve and process this identifier, return to step S304 to continue determining whether there is a next unprocessed identifier in the destination identifier region. If so, jump to step S406. Step S406: Invoke the processing flow, read and parse the value of this identifier, and based on the value of this identifier and the identifier type number, call the corresponding processing function to process the multi-identifier network packet, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet out from the specified port. Step S407: Determine whether the processing of the multi-identifier network packet is successful. If not, return to step S404 to continue determining whether there is a next unprocessed identifier in the destination identifier region. If so, end the processing flow.
[0017] A further improvement of the present invention is that it further includes a global identity authentication step, and the global identity authentication step includes the following sub-steps: Step C1: Calculate the unique global identifier of the mobile phone number through the formula , where represents the hash function, represents the mobile phone number, represents the random seed generated based on the super SIM card, represents the master key generated based on the random seed and the super SIM card; Step C2, when the mobile phone number is used cross-border and for roaming access, verify the legality and integrity of the identity through the on-chain log. The process of verifying the legality and integrity of the identity uses the formula to implement, where represents the verification result, represents the session token, represents the timestamp; Step C3, when the mobile phone number is used cross-border and for roaming access, generate an encrypted log for each cross-domain operation through the formula where represents the content of the i th cross-domain operation, represents the string of the cross-domain operation time point, represents the digital signature of the cross-domain operation.
[0018] A further improvement of the present invention is that it further includes a signature and encryption verification step for implementing end-to-end encrypted communication and performing digital signature, data encryption, and decryption operations; the signature and encryption verification step includes the following sub-steps: Step D1, perform digital signature through the formula where represents the unique signature generated during the network interaction process, represents using the private key to perform digital signature, represents the payload, represents the string of the cross-domain operation time point; Step D2, perform data encryption through the formula where represents the ciphertext after asymmetric encryption, represents using the public key to perform asymmetric encryption, represents the original data to be encrypted; Step D3, perform a decryption operation through the formula where represents using the private key to perform a decoding operation.
[0019] The present invention also provides a system for expanding the operator mobile phone number identifier in a multi-identifier network system, which adopts the method for expanding the operator mobile phone number identifier in the multi-identifier network system as described above, and includes: A mobile phone number authentication module, which realizes the authentication of the mobile phone number through the MIN client and completes the access of the mobile phone number to the MIN network; The mobile phone number single sign-on module realizes the single sign-on of the mobile phone number through the MIN-SDK toolkit, where the MIN-SDK toolkit refers to the multi-identifier network system toolkit; The identity signature and verification module performs identity signature and verification in the MIN network; The network grouping addressing module performs network grouping addressing in the MIN network through the mobile phone number.
[0020] Compared with the prior art, the beneficial effects of the present invention are as follows: First, the mobile phone number authentication is realized through the MIN client, and the mobile phone number is connected to the MIN network. Then, the single sign-on of the mobile phone number is realized through the MIN-SDK toolkit, and identity signature and verification are performed in the MIN network. Finally, network grouping addressing is performed in the MIN network through the mobile phone number, thereby effectively expanding the identifier of the operator's mobile phone number based on the MIN network. The present invention can well overcome the defect that the operator's mobile phone number uses a single communication identifier in the prior art. By combining the operator's mobile phone number and the MIN network, the identifier expansion of the operator's mobile phone number is realized, cross-domain unified identity authentication is achieved, and the identity and data intercommunication requirements of the mobile phone number across physical space and virtual space are met. Brief Description of the Drawings
[0021] Figure 1 It is a schematic diagram of the working process of an embodiment of the present invention; Figure 2 It is a schematic diagram of the process of performing mobile phone number authentication in an embodiment of the present invention; Figure 3 It is a schematic diagram of the process of performing single sign-on of the mobile phone number in an embodiment of the present invention; Figure 4 It is a schematic diagram of the network grouping of the MIN network in an embodiment of the present invention; Figure 5 It is a flowchart of the network grouping processing in an embodiment of the present invention; Figure 6 It is a schematic diagram of the concurrent processing of the multi-identifier router in an embodiment of the present invention. Detailed Embodiments
[0022] Before introducing the detailed embodiments of the present invention in detail, the key terms of the present invention and related technologies are described.
[0023] CT refers to Communication Technology, representing communication technology; IT refers to Internet Technology, representing internet technology; ESN refers to Equipment Serial Number, representing the device serial number; SIM refers to Subscriber Identity Model, representing the customer identification module; IMEI refers to International Mobile equipment Identity, representing the international mobile equipment identity; TMSI refers to Temporary Mobile Subscriber Identity, representing the temporary mobile subscriber identity; URI refers to Uniform Resource Identifier, representing the uniform resource identifier; SUPI refers to subscription permanent identifier, representing the user permanent identifier; SUCI refers to Subscription Concealed Identifier, representing the user concealed identifier; PEI refers to Permanent Equipment Identifier, representing the permanent equipment identifier; NSSAI refers to Single Network Slice Selection Assistance Information, representing the single network slice selection assistance information; IMSI refers to International Mobile Subscriber Identification Number, representing the international mobile subscriber identification number; Cog-MIN refers to Cognitive Multi-Identifier Network, representing the multi-identifier network system, abbreviated as MIN (Multi-Identifier Network) in this invention; MIR refers to Multi-Identifier Router, representing the multi-identifier router; MIS refers to Multi-Identifier System, that is, the multi-identifier management system.
[0024] Regarding the multi-identification network system, a multi-identification management mechanism that integrates the future network and the existing IP network is adopted, which is innovative and cutting-edge. The multi-identification network system described in the present invention refers to the MIN network, the full name of which is the Cog-MIN network, i.e., the Cognitive Multi-Identifier Network. It is the world's first system that supports the construction of a multilateral co-managed sovereign Internet. The MIN network supports multilateral co-management of top-level identifiers and territorial autonomy of subordinate identifiers. It breaks through the limitations of the traditional centralized Internet in structure, and achieves higher security, cross-domain interoperability, and traceability of on-chain behavior.
[0025] Therefore, the MIN network not only supports the coexistence of multiple identities, but also realizes multilateral co-management of multi-identity networks through blockchain technology, enhancing the security and sustainability of the network.
[0026] The core concept of the MIN network is to achieve the sovereignty and interoperability of cyberspace by supporting multiple identifiers (such as identity, content, and geographic location) and decentralized management. The MIN network is mainly composed of a multi-identifier management system (MIS) and a multi-identifier router (MIR): In the multi-identifier management system (MIS), the identification management system of the MIN network is governed by a multilateral co-managed alliance chain mechanism, using a voting method based on one country, one vote to manage top-level identification domain names; each country manages itself through an extensible hierarchical alliance chain. The multi-identifier router (MIR) supports multiple identifiers, including identity, content, service, and IP, to achieve a parallel coexistence network layer. MIN uses the HPT algorithm of hash tables and prefix trees to support multi-identifier translation and addressing of tens of billions of entries.
[0027] MIN network has the following outstanding advantages: 1. Multiple identifier support: MIN supports the coexistence of multiple identifiers (such as identity, content, IP, etc.), and can flexibly use different identifiers for addressing and routing according to application scenarios. This enables MIN to not only meet the needs of traditional Internet, but also adapt to emerging fields such as the Internet of Things, Industrial Internet, and Internet of Vehicles.
[0028] 2. Decentralized governance: MIN adopts blockchain technology and alliance chain voting mechanism to ensure the fairness and transparency of global network management, avoiding the unilateral monopoly problem brought about by the current centralized DNS management; III. High security and data traceability. The MIN network realizes the traceability of data by using asymmetric encryption technology, ensuring the security of data transmission and privacy protection. The design of MIN endows it with inherent security features, enabling it to defend against various network attacks. MIN integrates a variety of security technologies, such as signature cryptography, authentication, and behavior detection, to build a dynamic security protection model and effectively resist various network attacks.
[0029] IV. Scalability and flexibility. The multi-identifier routing mechanism and the hierarchical management structure based on the consortium blockchain of MIN endow it with high scalability. Whether in a small-scale enterprise private network or a global sovereign Internet scenario, MIN can provide flexible solutions.
[0030] V. Compatibility with existing network systems. MIN is compatible with existing network architectures such as IPv4 and IPv6, supports gradual evolution and transition, and does not require a complete replacement of existing network devices, reducing migration costs.
[0031] VI. Identity-driven. MIN takes identity as the core identifier, supports the registration and verification of users' real identities, enhancing the security and transparency of the network. The binding of the identity identifier to the device ensures the traceability of network behavior.
[0032] Therefore, MIN (abbreviation for Multi-Identifier Network System or Multi-Identifier Network) has broad application prospects, especially in the fields of global Internet governance, security, and emerging technologies. Its core advantages are multilateral co-governance and decentralized management. Combining the support of multi-identifiers and a powerful security mechanism, it can adapt to the development needs of future networks.
[0033] Generally speaking, the MIN network system provides a secure, flexible, and cost-effective network solution through features such as multi-identifier management, decentralized governance, identity-driven, and data traceability. It not only enhances the security and transparency of the network but also promotes international cooperation and technological innovation, meeting the diverse needs of modern networks. With the continuous change of the network environment, the application prospects of MIN will be even broader.
[0034] Regarding the development of digital identities in communication networks, CT communication network technology and digital identity technology are integrated and developed. The first-generation mobile communication technology, 1G, began to use digital identity technology to identify entities, but there were significant security vulnerabilities.
[0035] The second-generation mobile communication technology, 2G, realized the solution of separating the identity identification of "mobile phone and SIM card", effectively reducing security risks. The second-generation mobile communication network technology, 2G, represented by GSM, pioneered the "separation of mobile phone and SIM card" method, and the mobile phone and the SIM card together constitute the mobile communication terminal device.
[0036] The third-generation mobile communication technology 3G provides two-way authentication capabilities while further enriching the types of service identifiers. The third-generation mobile communication network technology 3G, represented by WCDMA, upgrades the SIM card to the Universal Subscriber Identity Module USIM and further supports two-way authentication between the terminal and the network. The 3G mobile communication network enriches and expands two types of services for users, namely circuit switching CS and packet switching PS, so that the service identifiers not only cover the MSISDN in the CS domain but also include the access point name APN in the PS domain.
[0037] The fourth-generation mobile communication technology 4G introduces a new IP multimedia identity to achieve IP-based unified communication and identity management. The fourth-generation mobile communication network technology 4G, represented by LTE, stops the development and evolution of the CS domain, and the IP multimedia subsystem IMS domain undertakes audio and video services.
[0038] The fifth-generation mobile communication technology 5G introduces new service identifiers to achieve secure and flexible network slicing services and unified user identity management. In the fifth-generation mobile communication network technology 5G, the Subscriber Permanent Identifier SUPI is equivalent to the IMSI in LTE, with the same format as the IMSI, but the SUPI will never be transmitted over the air interface to prevent tracking users by eavesdropping on wireless signals. The Subscriber Concealed Identifier SUCI is a privacy protection identifier that contains the concealed SUPI and can be transmitted over the air interface. Each terminal device accessing the 5G mobile communication network should have a Permanent Equipment Identifier PEI, corresponding to the IMEI in the LTE network.
[0039] Generally speaking, in the evolution process from 1G to 5G, the integration of digital identity technology and mobile communication networks has been continuously deepened, effectively realizing the separation and independent development of device identifiers, user identifiers, and service identifiers. Although the system centered on user identifiers is expected to continue to exist, with the diversification of network terminals and the continuous expansion of service types, the specific forms of user identifiers, the types of device identifiers, and service identifiers will all experience more innovations and changes accordingly. Correspondingly, the digital identity technology in mobile networks will also follow this development trend and continue to evolve to adapt to new challenges and requirements.
[0040] In an existing technology related to the present invention, the Internet Protocol (IP), also known as the Internet protocol, is a network layer communication protocol in the Internet protocol packet and is used for packet switching across network boundaries. Its routing function enables interconnection and essentially establishes the Internet.
[0041] IP is the main protocol in the network layer of the TCP / IP protocol suite. Its task is to deliver data packets from the source host to the destination host based only on the IP address in the packet header. To this end, the IP protocol defines the packet structure for encapsulating the data to be transmitted. It also defines the addressing method for labeling datagrams with source and destination information.
[0042] The characteristic of the IP address method is to assign a network address to each terminal, and each packet carries this address as the basis for network nodes to forward packets. The currently widely used IPv4 packet structure uses 32 bits as the address field, which is roughly equivalent to only 9 decimal digits. Now, almost all telephone numbers in large cities in our country have adopted 8-digit numbering. It is certain that using a 32-bit address field to identify terminals worldwide is insufficient. Therefore, in the early 1990s, this address crisis problem was realized, and the IETF began the standardization work of IPv6. IPv6 uses 128 bits as the address field. It seems that this numbering resource will meet the actual needs for a quite long period. The work of expanding the address field seems very natural, but the other two issues associated with the expansion of the address field are quite interesting. One is the promotion of IPv6, and the other is the difficulty brought by the IP network address method to high-speed packet forwarding. The promotion speed of IPv6 is extremely slow. On the one hand, this reflects that through CIDR address segmentation, address reuse through proxy servers, and dynamic address allocation by ISPs, IPv4 can still cope with the current actual needs. But more importantly, it reflects that the IP address method is too involved with the operation mode of the network. It requires changing the communication programs of users and the packet forwarding modules of routers, almost affecting all devices on the network. The number upgrade work that can be completed overnight on the traditional telephone network may take more than ten years to complete on the IP network.
[0043] On the traditional telecommunication network, the numbers for identifying transceiver terminals and the channel identifiers for guiding information forwarding are relatively separated. The potential transceiver terminals may be in the tens of millions or even hundreds of millions, while the operations involved in information forwarding by a switch or router are just the selection of dozens, at most hundreds of output ports. Like in the IP network, to find a suitable port among no more than a thousand output ports, it is necessary to search tens of millions of records.
[0044] The following are the disadvantages of this related prior art: The security issues of the IP network include two aspects: network security and information security. Network security refers to the attack or damage of the public facilities providing network services, such as the settings of domain name servers or routers being damaged, or their services being maliciously blocked, etc. Information security refers to the leakage or rewriting of the information transmitted on the Internet or stored on the server, etc. How to encrypt information and how to set up a secure and effective information access method are issues related to the network, and they themselves are not network problems. Since information is exposed on the network in electronic form, it is more difficult to maintain its security on the network.
[0045] Moreover, the introduction of the TCP / IP protocol seemingly solved the basic criterion problem for data transmission in the vast Internet, and established a set of basic rules for data transmission. However, due to this solution being based on the principle of non-repetition, the disordered and complex IP combinations impose a burden on computer operators and are difficult to handle a series of disordered numbers easily. Therefore, the disordered and complex IP addresses indirectly raise the threshold for using the Internet and become one of the limiting factors for Internet applications.
[0046] In another prior art related to the present invention, the Named Data Networking (NDN) is adopted. It was proposed in 2010, and its predecessor is the Content-Centric Networking (CCN). It uses a receiver-driven pull-based communication semantics to replace the sender-driven push-based communication semantics in the IP network. In NDN, content consumers obtain content by sending interest packets to the network. Any intermediate router or content producer that caches the corresponding content will respond with a data packet when it receives an Interest. Each Interest can pull one Data, and there is a one-to-one correspondence between Interest and Data.
[0047] NDN designs a Pending Interest Table (PIT) to support a stateful forwarding plane. Each PIT entry records from which network interface the Interest is received. All PIT entry records on the Interest forwarding path construct a reverse path, and the corresponding Data only needs to return along the reverse path constructed by the PIT. Through this pull-based interaction, NDN realizes the decoupling of content and producers, and can better support the business scenario of content distribution. To protect the security of content, NDN requires the Producer to sign each sent Data, which enables consumers to trust the content itself without caring about how and where the content is obtained. Since NDN adopts a subversive architecture design, its compatibility with the existing network architecture remains to be examined.
[0048] This existing technology has the following disadvantages: Although NDN enhances data integrity, source authentication, and correctness through the content signature mechanism, it still faces many privacy and security risks: name privacy, the hierarchical name in the Interest packet can disclose content information. Especially when the name structure is very intuitive, it may lead to the leakage of user privacy; cache privacy, attackers can obtain access information about the content in the cache through timing analysis; content privacy, although the data packet is signed, the content itself is not encrypted, so data leakage cannot be prevented; signature privacy, the signature can expose the identity of the producer, thereby infringing on the privacy of individuals or organizations.
[0049] In addition, NDN may face various forms of attacks, including Denial of Service (DoS) attacks, protocol attacks, and timing attacks. Among them, for the Denial of Service (DoS) attack, the DoS attack makes the router's PIT table overflow by sending a large number of Interest packets, thus blocking legitimate requests. Since the Interest packet of NDN does not contain the source address, it is difficult to trace the attacker. The attacker can generate a large number of invalid Interest packets through a botnet, resulting in cache pollution, bandwidth consumption, and exhaustion of network resources. For protocol attacks and timing attacks, protocol attacks use the prefix matching mechanism of NDN to infer the content requested by consumers, thereby infringing on name privacy. Timing attacks infer whether the content is cached by measuring the response time, thus obtaining cache privacy.
[0050] Therefore, the present invention aims to combine the operator's mobile phone number with the multi-identifier network system MIN, i.e., the MIN network, based on the multi-lateral co-management, so as to achieve the identifier expansion of the operator's mobile phone number, and further achieve the cross-domain unified identity authentication of the operator's mobile phone number, meeting the requirements of identity and data intercommunication of mobile phone numbers across physical spaces and virtual spaces. Through the identifier expansion of the operator's mobile phone number based on the MIN network, the mobile phone number is used as an effective network identifier to access the MIN network, and identity authentication and communication are realized, which can well overcome the defect that the operator's mobile phone number adopts a single communication identifier in the prior art.
[0051] In the technical solution proposed by the present invention, the existing mobile phone number can be used to access the MIN network, and identity registration and login can be performed, enabling users to directly use their mobile phone numbers as the only identifier to achieve identity authentication and communication in the MIN network. The mobile phone number will be registered as the only identifier in the identifier management system of the MIN network. The identifier management system in the MIN network will be connected to the operator's database in real time to verify the legality of the mobile phone number and ensure the uniqueness and accuracy of the user identity.
[0052] In this process, the mobile phone number not only acts as a traditional communication identifier but can also be associated with other network identifiers of the user (such as device identifier, IP address, etc.) to achieve cross-domain unified identity authentication. This means that users only need one mobile phone number to achieve identity authentication and access globally, across platforms and across networks. No matter where the user is, as long as there is a network connection, the user can log in to the MIN network through the mobile phone number to conduct secure communication and data interaction.
[0053] Next, in conjunction with the accompanying drawings, a more preferred embodiment of the present invention will be further described in detail.
[0054] As Figures 1 to 6 shown, the present invention provides a method for expanding the identifier of the operator's mobile phone number in a multi-identifier network system, including the following steps: Step S1, authenticate the mobile phone number through the MIN client to complete the access of the mobile phone number to the MIN network. The MIN client refers to the multi-identifier network system client, and the MIN network refers to the multi-identifier network system, abbreviated as the MIN network; Step S2, achieve single sign-on of the mobile phone number through the MIN-SDK toolkit. The MIN-SDK toolkit refers to the multi-identifier network system toolkit; Step S3, perform identity signature and signature verification in the MIN network; Step S4, perform network grouping addressing in the MIN network through the mobile phone number.
[0055] Step S1 in this embodiment is used to authenticate the mobile phone number through the MIN client, access the mobile phone number to the MIN network, and perform network communication. As Figure 2 shown, step S1 includes the following sub-steps: Step S101, the user downloads, installs, and opens the MIN client; Step S102, through the call of the SDK software development kit integrated in the MIN client, use the getPhonelnfo prefetch number interface provided by the SDK software development kit to obtain the mobile phone number and return the prefetch number result; the SDK software development kit is abbreviated as SDK; Step S103, the MIN client calls the loginAuth login interface provided by the SDK to obtain user authorization and render the authorization page; the authorization page is used to prompt the user that the MIN client will obtain the mobile phone number from them, and it can continue to be used only after the user agrees by default; Step S104, the MIN client prompts the user to authorize the mobile phone number to log in to the MIN client. After confirming the authorized login, obtain and return the authorized login token token; Step S105, the MIN client generates account information, and sends a registration and login request to the multi-identifier router MIR with the authorized login token token and account information. The multi-identifier router MIR forwards the request to the multi-identifier management system MIS to send the registration and login request; Step S106, query the authorized mobile phone number from the SIM card authentication server to perform registration and login; Step S107, gradually return the registration and login results, maintain the login state on the MIN client, and prompt the user that the registration and login are successful.
[0056] This embodiment mainly conducts research on the application of mobile phone numbers in the MIN network architecture system. First, the authentication of mobile phone numbers is integrated in the Cog-MIN client (abbreviated as MIN client), and then the functions of the MIN client are packaged to form an SDK, that is, using the MIN-SDK toolkit, the functions are encapsulated into SDKs suitable for different operating systems, such as Android, IOS, and HarmonyOS, etc. Finally, the mobile phone number is upgraded to one of the addressing identifiers, and a new definition is added that the mobile phone number is the MIN network identifier, and the routing and forwarding and parsing functions of the background system are adjusted.
[0057] Preferably, step S102 in this embodiment includes the following sub-steps: Step S1021, through the integration of the SDK software development kit in the MIN client, use the getPhonelnfo prefetch number interface provided by the SDK to obtain the mobile phone number; Step S1022: Prefetch a number through the gateway of the SIM card authentication server, and return the prefetch result. Step S1023: Determine whether the prefetch is successful. If not, jump to the SIM quick process to implement the quick authentication of the SIM card. If so, jump to Step S103.
[0058] In this embodiment, the process of integrating the SDK (Software Development Kit) into the MIN client in Step S1021 is preferably as follows: First, introduce the SDK as a dependency library into the project of the MIN client, and add the dependency item of the SDK to the build.gradle core configuration file of the project. Then, implement the interaction with the SDK in the local area through method calls. For example, import the relevant modules or classes of the SDK in the code, initialize according to the SDK documentation, and implement the required functions by calling the methods provided by the SDK, including obtaining data, initiating requests, etc.
[0059] The SIM quick process described in this embodiment refers to directly authenticating through the SIM card. First, pass in the mobile phone number to request SIM card authentication, return and cache the transaction ID, and set the operation result as pending. Then, asynchronously notify the user to confirm the authorization, and modify the cached operation result according to the transaction ID. Finally, pass in the transaction ID, poll to judge the user authorization result, and complete registration and login. Of course, this process is only one of the preferred implementation manners.
[0060] Preferably, Step S106 in this embodiment includes the following sub-steps: Step S1061: The multi-identifier router MIR sends a request carrying the authorization login token token to the security management system VMS, and the security management system VMS queries the authorized mobile phone number from the SIM card authentication server; this authorized mobile phone number is a mobile phone number. Step S1062: The SIM card authentication server returns the authorized mobile phone number to the security management system VMS, and then forwards the authorized mobile phone number to the multi-identifier management system MIS. Step S1063: Register and log in the user identity corresponding to the authorized mobile phone number in the MIN network through the multi-identifier management system MIS.
[0061] Step S2 in this embodiment is used to implement single sign-on of the mobile phone number in the MIN network and allow the mobile phone number to communicate in the MIN network of other systems. Specifically, as Figure 3 shown, Step S2 includes the following sub-steps: Step S201: The user accesses the APP application, requests to open the MIN channel, and calls the MIN-SDK toolkit to query the login status of the current user. Figure 3Steps 1 to 4 therein; The MIN-SDK toolkit refers to the SDK software development toolkit integrated in the multi-identity network system; Step S202, if the current user's login status is not logged in, then send the user's authorization login token "token" through the APP application to the MIN-SDK toolkit, and request single sign-on (SSO), corresponding to Figure 3 Step 5 therein; The MIN-SDK toolkit sends the carried authorization login token "token" to the MIN server to request to complete the user's single sign-on operation; The MIN server refers to the multi-identity network system server; Step S203, the MIN server requests the operator server to obtain the user information corresponding to the authorization login token "token" according to the received authorization login token "token", corresponding to Figure 3 Steps 6 and 7 therein; The operator server parses the user information and returns the user's mobile phone number and related data to the MIN server; Step S204, the MIN server completes the user registration or login operation in the system according to the returned user information, and records the user's identity information in the identity management system of the multi-identity network system, corresponding to Figure 3 Steps 8 and 9 therein; Step S205, after the MIN server completes the registration or login operation, it returns the response of the user's successful login to the MIN-SDK toolkit. After receiving the response of the successful login, the MIN-SDK toolkit sends the notification that the user has successfully logged in to the APP application, corresponding to Figure 3 Steps 10 and 11; Step S206, the APP application starts the MIN channel according to the user's login status and notifies the user that it has been successfully started, corresponding to Figure 3 Steps 12 and 13. At this time, other operations can be performed.
[0062] In step S2 of this embodiment, it is judged whether the user is the first to achieve single sign-on of the mobile phone number. If so, it means that the user first accesses the MIN network and triggers the user registration process of single sign-on; If not, the user login process of single sign-on is triggered.
[0063] The user registration process of the single sign-on described in this embodiment includes the following sub-steps: Step A1 is used to generate a public-private key pair. After the user enters relevant information, the key chain KeyChain is initialized based on the KeyManager instance to obtain the identity of the current user, and then the SM2 cryptographic algorithm is called to randomly generate a public-private key pair. The KeyManager instance is responsible for managing the generation and storage of keys. The key chain KeyChain refers to the instance of the key chain, which is used to store and manage the user's keys. The relevant information entered by the user includes the authorized mobile phone number, the authorized login token, and the account information. Step A2 is used to encrypt the user identity; after the user enters the user name and plain text password, the combined string of the user name and plain text password is first subjected to SM3 hash calculation, and a 32-byte hash result hash32 is obtained through SM3 hash calculation; then the first 16 bytes of the hash result hash32 are taken to form a byte array hash16 as the SM4 key, and the user private key PrivateKey is subjected to SM4 encryption, and the encryption process adopts ECB_Padding mode to obtain the encrypted user private key EncryptedPrivateKey; ECB_Padding mode refers to the ECB mode combined with a padding mechanism, and the ECB mode refers to Electronic Codebook Mode, that is, a block cipher; and the padding mechanism refers to Padding, in a block cipher, the length of the plaintext must be an integer multiple of the block length, and row padding is performed when the plaintext length is insufficient; Step A3 is used to execute the registration request; first register in the multi-identity management system MIS to host the user key; then register in the security management system VMS to manage the user's virtual private network VPN permissions.
[0064] Since the user identity and public key are unique, after the background of the multi-identity management system MIS receives the registration request, it checks the local uniqueness of these two fields and issues a certificate for the identity if it passes.
[0065] The registration request of this application is encapsulated twice for the multi-identity management system MIS and the security management system VMS. In the current Android version, registration can be performed only through the security management system VMS, and the security management system VMS interacts with the multi-identity management system MIS.
[0066] The user login process of the single sign-on described in this embodiment includes the following sub-steps: Step B1, after the user inputs the username, password, and mobile phone number, and receives and fills in the verification code, first perform MD5 hash processing on the input password, then encapsulate the hashed password, username, mobile phone number, and verification code into a JSON-formatted login request, and finally call the multi-identifier management system interface MISRequestAPI to pass the login request to the multi-identifier management system MIS; the implementation process of the multi-identifier management system interface MISRequestAPI is: take the JSON-formatted login request as the payload, package it into a common MIN package format, and send the packaged MIN package to the multi-identifier management system MIS to complete the transmission of the login request; Step B2, obtain the encrypted identity data from the multi-identifier management system MIS and decrypt it, save the identity data locally, then construct the login information and send it to the security management system VMS and wait for a response; corresponding to the user identity encryption process implemented in Step A2, in this embodiment, first perform SM3 hash calculation on the original plaintext key, then take the first 16 bytes after the SM3 hash calculation as the key, and perform SM4 decryption on the user private key EncryptedPrivateKey. The decoding process uses the ECB_Padding mode.
[0067] Step S3 in this embodiment is used to implement identity signature and verification in the MIN network. The step S3 includes the following sub-steps: Step S301, implement signature based on the user private key. After confirming that the private key is not empty, first select the corresponding signature method according to the public key generation algorithm in the KeyParam key parameter, then perform type conversion on the private key (such as id.Prikey) to convert it into the private key type of the SM2 algorithm, such as the parameter p of the sm2.Sm2PrivateKey type, and call the p.Sign digital signature method to perform the signature; where KeyParam is the key parameter used to specify the public key generation algorithm; the SM2 algorithm is a public key cryptography algorithm based on elliptic curves, used for digital signature and encryption; the signature in this embodiment defaults to the SM2WithSM3 algorithm; Step S302, implement verification based on the user public key. After verifying that the public key is not empty, first select the corresponding verification method according to the public key generation algorithm in the KeyParam key parameter, then perform type conversion on the public key (such as id.Pubkey) to convert it into the public key type of the SM2 algorithm, such as the parameter p of the sm2.Sm2PublicKey type, and call the p.Sign verification method to perform the verification. The verification in this embodiment defaults to the SM2WithSM3 algorithm.
[0068] Step S4 in this embodiment is used to implement the network grouping addressing process of the mobile phone number in the MIN network. As Figure 5As shown, step S4 preferably includes the following sub-steps: Step S401, receiving data of a multi-identifier network packet; Step S402, reading the data link layer data segment and decoding the multi-identifier network packet through TLV encoding; wherein, as Figure 4 shown, the multi-identifier network packet includes four regions, namely the identifier region, the signature region, the read-only region, and the variable region; each region consists of one or more TLV-encoded triples (i.e., Type / Length / Value). The TLV encoding divides the binary data block into three intervals. The outermost interval is the Type field, indicating the type of the current data block; the middle interval is the Length field, indicating the length of the Value field; and the last interval is the Value field, used to store the data block. Step S403, determining whether the decoding of the multi-identifier network packet is successful. If not, discard the multi-identifier network packet and end the processing flow; if so, jump to step S404; Step S404, checking the destination identifier region field of the multi-identifier network packet and determining whether there is a next unprocessed identifier in the destination identifier region. If there is no identifier in the destination identifier region or the identifier has been processed, discard the multi-identifier network packet and end the processing flow; if there is a next unprocessed identifier in the destination identifier, jump to step S405; Step S405, reading the next unprocessed identifier and determining whether the current multi-identifier router can resolve and process the identifier based on the identifier type number of the identifier. If not, that is, the identifier cannot be resolved and processed, return to step S304 to continue determining whether there is a next unprocessed identifier in the destination identifier region; if so, jump to step S406; Step S406, calling the processing flow, reading and parsing the value of the identifier, and calling the corresponding processing function to process the multi-identifier network packet according to the value of the identifier and the identifier type number, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet from the specified port. Step S407, determining whether the processing of the multi-identifier network packet is successful. If not, return to step S404 to continue determining whether there is a next unprocessed identifier in the destination identifier region; if so, end the processing flow.
[0069] This embodiment gives the network packet processing process of a single thread (single processor) through steps S401 to S407, and gives the flowchart of a network packet forwarder processing a network packet, as Figure 5 shown, to illustrate the complete process of a single-core router processing a network packet.
[0070] Since the support of multiple identifiers by the multi-identity router MIR can be completely isolated from each other, in the software-implemented forwarder, a multi-core processor can be used to forward network packets carrying different identifiers. Therefore, in step S4 of this embodiment, when a multi-identity network packet carrying multiple identifiers enters the multi-identity router MIR, the multi-identity router MIR processes the multiple identifiers concurrently, such as Figure 6 The FIB table refers to the Forwarding Information Base, i.e., the query forwarding table, which is used to implement query and forwarding processing in the identification processing unit.
[0071] In this embodiment, the process of the multi-identity router MIR concurrently processing multiple identifiers includes: Step E1, extracting all the identifiers in the multi-identity network group, and determining the identifier types supported by the multi-identity router MIR through the identifier filter; Step E2, duplicating according to the number of supported identifiers and sending them to different identifier processing units for processing. After receiving the processing tasks, different identifier processing units independently complete the processing of multi-identifier network groups and then summarize the processing results to the decision unit; Step E3: the decision unit selects a processing result to be adopted according to the sequence of the identifiers in the multi-identifier network group.
[0072] For example, in Figure 6 In the example, the identifiers 101 and 103 carried in the multi-identifier network packet are both identifier types supported by the current router, so the incoming network packet is copied into two copies and distributed to two different identifier processing units for processing, and different identifier processing units can independently run on different CPUs or different CPU cores. After receiving the multi-identifier network packet processing task, different identifier processing units independently complete the processing of the multi-identifier network packet, and each identifier processing unit summarizes the processing results to the decision unit.
[0073] like Figure 6 As shown, the priority of identifier 103 in the network packet is higher than that of identifier 101. Therefore, if the processing result of identifier 103 is normal, that is, the result of the identifier processing unit is not to discard the multi-identifier network packet, the decision unit adopts the processing result of the identifier processing unit corresponding to identifier 103, and ignores the result of the identifier processing unit corresponding to identifier 101. Only when the processing result corresponding to identifier 103 is to discard the multi-identifier network packet, the decision unit adopts the processing result of the identifier processing unit corresponding to identifier 101.
[0074] Therefore, in the parallel multi-identity router MIR of this embodiment, all the identifiers in the multi-identity network group are first extracted, and different identifier processing units independently complete the processing of the multi-identity network group after receiving the processing task of the multi-identity network group, and then each identifier processing unit summarizes the processing results to the decision unit. The decision unit decides which identifier processing unit's processing result to use according to the order of each identifier in the multi-identity network group.
[0075] In summary, this embodiment first implements the authentication of the mobile phone number through the MIN client, completes the access of the mobile phone number to the MIN network, then implements the single sign-on of the mobile phone number through the MIN-SDK toolkit, and performs identity signing and verification in the MIN network. Finally, the network group addressing is performed in the MIN network through the mobile phone number, and the identification of the operator's mobile phone number is effectively expanded based on the MIN network. This embodiment can well overcome the defect of the operator's mobile phone number using a single communication identifier in the prior art. By combining the operator's mobile phone number and the MIN network, the identification of the operator's mobile phone number is expanded, and unified identity authentication across domains is realized, meeting the identity and data intercommunication requirements of the mobile phone number across physical space and across virtual space.
[0076] This embodiment proposes a method and system for extending the operator's mobile phone number identification based on the MIN network, by mapping the traditional mobile phone number to the multi-identification network, and using the traditional mobile phone number as one of the main identifiers of the MIN network, to achieve global interconnection, identity authentication and secure communication capabilities under the sovereign Internet. This embodiment breaks the network architecture limitation that the traditional IP address is limited to a single-level network positioning and a single mapping. Through the architecture system of the MIN network, it supports the unified mapping and collaborative resolution of multiple types of identification (such as mobile phone numbers, device identification and location identification), supports the multilateral co-management of top-level identification and the territorial autonomy of lower-level identification, and structurally breaks through the limitations of the traditional centralized Internet, achieving higher security, cross-domain interoperability and traceability of on-chain behavior, and realizing a cross-domain, trusted and highly secure global identity authentication and data access mechanism.
[0077] Mathematical model analysis shows that in the MIN network, each mobile phone number (MSISDN) will be mapped to a globally unique identifier when accessing the network. , and multi-dimensionally associates with device identification (IMEI), IP address, and SIM card ID to form a multi-identification trusted authentication mechanism. Assume that the success probability of a single-point attack in a traditional IP network is , in this embodiment, the attack success probability after multi-dimensional identification mapping can be expressed as: ,in: Indicates the safety improvement factor after each mark is added; Indicates the number of additional identification dimensions, such as device ID, location identification, dynamic session ID, etc.
[0078] When the number of identification dimensions Increases to more than 5, the attack probability of traditional IP will decrease exponentially, showing a security protection ability far higher than that of traditional network architectures. At the same time, the MIN network also introduces a cross-domain authentication mechanism based on digital customs. When a mobile phone number is used across borders and accessed through roaming, the legitimacy and integrity of the identity are verified through the on-chain log. For details, see the content of the following global identity authentication steps.
[0079] This embodiment preferably further includes a global identity authentication step, and the global identity authentication step includes the following sub-steps: Step C1, calculate the unique global identifier of the mobile phone number through the formula , where , represents a hash function, represents the mobile phone number, represents a random seed generated based on the super SIM card, represents the master key generated based on the random seed and the super SIM card; in the MIN network, each mobile phone number has global addressing capabilities, supporting cross-regional roaming and global trusted authentication; Step C2, when the mobile phone number is used across borders and accessed through roaming, verify the legitimacy and integrity of the identity through the on-chain log. The process of verifying the legitimacy and integrity of the identity is implemented using the formula , where represents the verification result, represents the session token, represents the timestamp; Step C3, when the mobile phone number is used across borders and accessed through roaming, generate an encrypted log for each cross-domain operation through the formula , where , represents the i th cross-domain operation content, represents the string of the cross-domain operation time point, represents the digital signature of the cross-domain operation.
[0080] In step C1 of this embodiment, the generation process of the random seed includes: first generating an initial random number based on the secure random number module in the super SIM card; then processing the initial random number through a perturbation function, such as through XOR (exclusive OR) mixing operation and non-linear transformation (such as a hash function), etc., to generate the final random seed . The master key The generation process includes: based on a random seed and the unique ID of the super SIM card, the master key of the super SIM card is calculated through a key derivation function (Key Derivation Function, KDF). For example, using the formula =HKDF( IKM = R ∥SIM_ID, salt, info, L) to calculate and generate the master key of the super SIM card HKDF (HMAC-based Key Derivation Function) is a key derivation function based on HMAC (Hash-based Message Authentication Code). IKM = R ∥SIM_ID means using the random seed and the unique ID of the super SIM card as the input key material IKM salt represents the salt value, info represents the context information used to distinguish key derivation scenarios, and L represents the length of the generated key.
[0081] By verifying the legality and integrity of the identity, all authentication behaviors are recorded in the blockchain log jointly managed by multiple parties, which is tamper-proof and globally synchronized for updates. Even in case of attacks or malicious misuse, the complete path of such behavior can be traced back to ensure the network security rights and interests of users.
[0082] This embodiment also combines the national cryptography security chip and the hardware encryption storage ability of the super SIM card to propose a triple authentication model of "mobile phone number + national cryptography chip + PKI". The user's mobile phone number will not only be the entry for communication, but also a unified network identity globally, supporting encrypted communication and data interaction between any trusted nodes in the MIN network.
[0083] In the global identity authentication step, a digital customs cross-domain authentication mechanism is also added. For cross-border access and roaming communication, this embodiment proposes a digital customs authentication mechanism, which combines the blockchain jointly managed by multiple parties to record user identity verification and data exchange operations. During the authentication process, each cross-domain operation will generate an encrypted log expressed as: . This encrypted log is tamper-proof and supports traceability and auditing.
[0084] Preferably, this embodiment further includes signature and encryption verification steps for implementing end-to-end encrypted communication and performing digital signature, data encryption, and decryption operations. It should be noted that traditional mobile phone numbers do not have encryption functions. Therefore, this embodiment adds signature and encryption verification steps. The signature and encryption verification steps include the following sub-steps: Step D1, perform digital signature through the formula where, represents the unique signature generated during the network interaction process, represents using the private key to perform digital signature, represents the payload, represents the string of the cross-domain operation time point; Step D2, perform data encryption through the formula where, represents the ciphertext after asymmetric encryption, represents using the public key to perform asymmetric encryption, represents the original data to be encrypted; Step D3, perform decryption operation through the formula where, represents using the private key to perform decoding operation.
[0085] This embodiment also provides a system for expanding the operator mobile phone number identifier in a multi-identifier network system, which adopts the method for expanding the operator mobile phone number identifier in the multi-identifier network system as described above, and includes: A mobile phone number authentication module that realizes the authentication of the mobile phone number through the MIN client and completes the access of the mobile phone number to the MIN network; A mobile phone number single sign-on module that realizes the single sign-on of the mobile phone number through the MIN-SDK toolkit, and the MIN-SDK toolkit refers to the multi-identifier network system toolkit; An identity signature and verification module that performs identity signature and verification in the MIN network; A network packet addressing module that performs network packet addressing in the MIN network through the mobile phone number.
[0086] The above content is a further detailed description of the present invention in combination with specific preferred implementation manners. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention belongs, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.
Claims
1. A method for expanding the mobile operator phone number identifier in a multi-identifier network system, characterized in that It includes the following steps: Step S1, authenticate the mobile phone number through the MIN client to complete the access of the mobile phone number to the MIN network. The MIN client refers to the multi-identity network system client, and the MIN network refers to the multi-identity network system; Step S2, implement single sign-on for the mobile phone number through the MIN-SDK toolkit. The MIN-SDK toolkit refers to the multi-identity network system toolkit; Step S3, perform identity signature and verification in the MIN network; Step S4, perform network grouping addressing in the MIN network through the mobile phone number; Among them, the said Step S1 includes the following sub-steps: Step S101, the user downloads, installs and opens the MIN client; Step S102, through the call of the SDK software development toolkit integrated by the MIN client, use the getPhonelnfo prefetch number interface to obtain the mobile phone number and return the prefetch number result; Step S103, the MIN client calls the loginAuth login interface to obtain user authorization and render the authorization page; Step S104, the MIN client prompts the user to authorize the mobile phone number to log in to the MIN client. After confirming the authorization to log in, obtain and return the authorization login token; Step S105, the MIN client generates account information and sends a registration and login request to the multi-identity router MIR with the authorization login token and account information. The multi-identity router MIR forwards the request to the multi-identity management system MIS to send the registration and login request; Step S106, query the authorized mobile phone number from the SIM card authentication server for registration and login; Step S107, gradually return the registration and login results, maintain the login status in the MIN client, and prompt the user that the registration and login are successful.
2. The method for expanding the mobile operator phone number identifier in the multi-identifier network system according to claim 1, characterized in that, The said Step S106 includes the following sub-steps: Step S1061, the multi-identity router MIR sends the request carrying the authorization login token to the security management system VMS, and the security management system VMS queries the authorized mobile phone number from the SIM card authentication server; Step S1062, the SIM card authentication server returns the authorized mobile phone number to the security management system VMS, and then forwards the authorized mobile phone number to the multi-identity management system MIS; Step S1063, register and log in the user identity corresponding to the authorized mobile phone number in the MIN network through the multi-identity management system MIS.
3. The method for expanding the mobile operator phone number identifier in the multi-identifier network system according to claim 1, wherein The said Step S2 includes the following sub-steps: Step S201, the user accesses the APP application, requests to open the MIN channel, and calls the MIN-SDK toolkit to query the login status of the current user; Step S202, if the login status of the current user is not logged in, send the user's authorization login token through the APP application to the MIN-SDK toolkit to request single sign-on; the MIN-SDK toolkit sends the carried authorization login token to the MIN server to request to complete the single sign-on operation of the user; The MIN server refers to the multi-identity network system server; Step S203, the MIN server requests the operator server to obtain the user information corresponding to the authorization login token according to the received authorization login token; The operator server parses the user information and returns the user's mobile phone number and related data to the MIN server; Step S204, the MIN server completes the user registration or login operation according to the returned user information, and records the user's identity information in the identity management system of the multi-identity network system; Step S205, after the MIN server completes the registration or login operation, it returns a successful login response to the MIN-SDK toolkit. After receiving the successful login response, the MIN-SDK toolkit sends a notification of successful login to the APP application; Step S206, the APP application starts the MIN channel according to the user's login status and notifies the user that the startup has been successful.
4. The method for expanding the mobile operator phone number identifier in the multi-identifier network system according to any one of claims 1 to 3, characterized in that In step S2, it is determined whether it is the first time to implement single sign-on for a mobile phone number. If so, the user registration process of the single sign-on is triggered; if not, the user login process of the single sign-on is triggered; the user registration process of the single sign-on includes the following sub-steps: Step A1: After the user inputs relevant information, the key chain KeyChain is initialized based on the KeyManager instance to obtain the identity of the current user, and then the SM2 cryptographic algorithm is called to randomly generate a public and private key pair; Step A2, after the user enters the username and plain text password, the combined string of the username and plain text password is first subjected to SM3 hash calculation, and a 32-byte hash result hash32 is obtained through SM3 hash calculation; then the first 16 bytes of the hash result hash32 are taken to form a byte array hash16 as the SM4 key, and the user private key PrivateKey is subjected to SM4 encryption, and the encryption process adopts ECB_Padding mode to obtain the encrypted user private key EncryptedPrivateKey; Step A3, first register in the multi-identity management system MIS and host the user key; Then register on the security management system VMS to manage the user's virtual private network VPN permissions.
5. The method for expanding the mobile operator phone number identifier in the multi-identifier network system according to claim 4, wherein, The single sign-on user login process includes the following sub-steps: Step B1, after the user enters the user name, password and mobile phone number, and receives and fills in the verification code, the entered password is first hashed with MD5, and then the hashed password, the user name, mobile phone number and verification code are encapsulated into a login request in JSON format, and finally the multi-identity management system interface MISRequestAPI is called to pass the login request to the multi-identity management system MIS; Step B2, first perform SM3 hash calculation on the original plaintext key, then take the first 16 bytes after SM3 hash calculation as the key, perform SM4 decryption on the user private key EncryptedPrivateKey, and the decoding process adopts ECB_Padding mode.
6. The method for expanding the mobile operator phone number identifier in the multi-identifier network system according to any one of claims 1 to 3, characterized in that, The step S3 comprises the following sub-steps: Step S301: Implement signature based on the user's private key. After confirming that the private key is not empty, first select the corresponding signature method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the private key to the private key type of the SM2 algorithm, and call the p.Sign digital signature method to perform the signature; Step S302: Implement signature verification based on the user's public key. After verifying that the public key is not empty, first select the corresponding verification method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the public key to the public key type of the SM2 algorithm, and call the p.Sign verification method to perform the verification.
7. The method for expanding the mobile operator phone number identifier in the multi-identifier network system according to any one of claims 1 to 3, characterized in that The said Step S4 includes the following sub-steps: Step S401: Receive the data of the multi-identifier network packet; Step S402: Read the data link layer data segment and decode the multi-identifier network packet through TLV encoding; wherein, the multi-identifier network packet includes four regions, namely the identifier region, the signature region, the read-only region, and the variable region; each region consists of one or more TLV-encoded triples. TLV encoding divides the binary data block into three intervals. The frontmost interval is the Type field, indicating the type of the current data block; the middle interval is the Length field, indicating the length of the Value field; the last interval is the Value field, used to store the data block; Step S403: Determine whether the decoding of the multi-identifier network packet is successful. If not, discard the multi-identifier network packet and end the processing flow; if so, jump to Step S404; Step S404: Check the destination identifier area field of the multi-identifier network packet and determine whether there is a next unprocessed identifier in the destination identifier area; if there is no identifier or the identifier has been processed in the destination identifier area, discard the multi-identifier network packet and end the processing flow; if there is a next unprocessed identifier in the destination identifier, jump to Step S405; Step S405: Read the next unprocessed identifier, and determine whether the current multi-identifier router can resolve and process this identifier based on the identifier type number of this identifier. If not, that is, it cannot resolve and process this identifier, then return to Step S304 to continue determining whether there is a next unprocessed identifier in the destination identifier area; if so, jump to Step S406; Step S406: Call the processing flow, read and parse the value of this identifier, and call the corresponding processing function to process the multi-identifier network packet according to the value of this identifier and the identifier type number, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet from the specified port; Step S407: Determine whether the processing of the multi-identifier network packet is successful. If not, return to Step S404 to continue determining whether there is a next unprocessed identifier in the destination identifier area; if so, end the processing flow.
8. The method for expanding the mobile operator phone number identifier in the multi-identifier network system according to any one of claims 1 to 3, characterized in that, It further includes a global identity authentication step, and the said global identity authentication step includes the following sub-steps: Step C1, through the formula calculate the unique global identifier of the mobile phone number , where represents a hash function, represents the mobile phone number, represents a random seed generated based on the super SIM card, represents the master key generated based on the random seed and the super SIM card; Step C2, when the mobile phone number is used across borders and for roaming access, verify the legality and integrity of the identity through the on-chain log. The process of verifying the legality and integrity of the identity uses the formula to implement, where represents the verification result, represents the session token, represents the timestamp; Step C3, when the mobile phone number is used across borders and accessed through roaming, generate an encrypted log for each cross-domain operation through the formula where represents the content of the th cross-domain operation, i represents a string of the time point of the cross-domain operation, and represents the digital signature of the cross-domain operation. 9. The method for expanding the mobile operator phone number identifier in the multi-identifier network system according to any one of claims 1 to 3, characterized in that It further includes a signature and encryption verification step for implementing end-to-end encrypted communication and performing digital signature, data encryption, and decryption operations; the said signature and encryption verification step includes the following sub-steps: Step D1, through the formula perform digital signature, where represents the unique signature generated during the network interaction process, represents using the private key to perform digital signature, represents the payload, represents the string of the cross-domain operation time point; Step D2, through the formula perform data encryption, where represents the ciphertext after asymmetric encryption, represents using the public key to perform asymmetric encryption, represents the original data to be encrypted; Step D3, through the formula perform the decryption operation, where represents the use of the private key to perform the decoding operation.
10. A system for expanding the mobile operator phone number identifier in a multi-identifier network system, characterized in that, A method for expanding the operator mobile phone number identifier in the multi-identifier network system according to any one of claims 1 to 9 is adopted, and it includes: A mobile phone number authentication module, which realizes the authentication of the mobile phone number through the MIN client and completes the access of the mobile phone number to the MIN network; A mobile phone number single sign-on module, which realizes the single sign-on of the mobile phone number through the MIN-SDK toolkit, and the MIN-SDK toolkit refers to the multi-identifier network system toolkit; An identity signature and verification module, which performs identity signature and verification in the MIN network; A network packet addressing module, which performs network packet addressing in the MIN network through the mobile phone number.
Citation Information
Patent Citations
Method and system for supporting continuous evolution of packet communication network addressing routing identifier
CN112804152A
Method for multi-identifier login of an instant messaging system
US20060059240A1
Systems and methods for private authentication with helper networks
WO2022036097A1
Cited By
Method, device and encryption method for realizing switching of user communication three-code identification of mobile communication network
CN121310126A