Method and system for extending operator mobile phone number identification in a multi-identification network system

The identification of operator mobile phone numbers is expanded through the MIN network, and the cross-domain unified identity authentication of mobile phone numbers is realized, which solves the identifier defects of operator mobile phone numbers in cross-space interoperability, meets the requirements of identity and data interoperability across physical space and virtual space, and enhances the security and trustworthiness of the network.

CN120321654BActive Publication Date: 2025-08-29PEKING UNIV SHENZHEN GRADUATE SCHOOL +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510797298.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-08-29
Estimated Expiration
2045-06-16

AI Technical Summary

Technical Problem

Existing operators' mobile phone numbers use a single communication identifier, which is difficult to meet the needs of identity and data interoperability across physical and virtual spaces.

Method used

The identification of the operator's mobile phone number is expanded through the MIN network, including mobile phone number authentication, single sign-in, identity signature and signature verification, and network packet addressing. The MIN client and MIN-SDK toolkit are used to achieve mobile phone number access and login, and identity registration and login are combined with the multi-identity management system.

Benefits of technology

It realizes cross-domain unified identity authentication for operator mobile phone numbers, meets the needs of interoperability between mobile phone numbers across physical space and virtual space, and enhances the security and trustworthiness of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321654B_ABST
    Figure CN120321654B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for extending the operator mobile phone number identification in a multi-identity network system, comprising the following steps: step S1, implementing mobile phone number authentication through a MIN client, completing the mobile phone number access to the MIN network, the MIN client refers to the multi-identity network system client, the MIN network refers to the multi-identity network system, referred to as the MIN network; step S2, implementing single sign-on of the mobile phone number through the MIN‑SDK toolkit, the MIN‑SDK toolkit refers to the multi-identity network system toolkit; step S3, performing identity signing and signature verification in the MIN network; step S4, performing network group addressing in the MIN network through the mobile phone number. The present invention, by combining the operator mobile phone number and the MIN network, can realize the identification extension of the operator mobile phone number, realize cross-domain unified identity authentication, and meet the identity and data interoperability requirements of the mobile phone number across physical space and virtual space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for extending operator mobile phone number identification, in particular to a method for extending operator mobile phone number identification in a multi-identification network system, and further to a system adopting the method for extending operator mobile phone number identification in a multi-identification network system. Background Art

[0002] The concept of network digital identity (NDI) naturally emerged with the popularization of the Internet and communication networks. To date, there is no unified concept and accurate definition of NDI globally. The Internet and communication networks have different definitions of digital identity. The differences mainly stem from different perspectives on digital identity, development needs, and construction ideas.

[0003] From the perspective of the internet, the International Organization for Standardization and the International Electrotechnical Commission (IEC) believe that digital identity addresses the identification and trust of objects in digital spaces, using network information systems for secure transmission, storage, use, and management, assigning unique digital identifiers and associated attribute declarations to objects. From the perspective of communications networks, the International Telecommunication Union's Standardization Bureau (ITU-S) defines digital identity as the identification of an individual or entity in digital communications and network environments, enabling authentication and access to various online services and applications.

[0004] With the rapid development of the Internet and communication networks, the integration of the two has accelerated, and they have become key core components and important infrastructure supporting the digital world. Especially after network digital identity entered the "digital identity application period", whether from the definition of digital identity or in actual application, network digital identity has become a key link in the construction of the trust system in the digital world and supporting digital ecological governance.

[0005] In the digital economy, digital identity is gradually becoming the bridge and link between the physical and digital worlds. With technological innovation and the expansion of application scenarios, the scope, capabilities, and concepts of digital identity have undergone a comprehensive upgrade, and its importance has become increasingly prominent. Digital identity is not only a reflection of physical behavior in the digital space, but also the foundation of all activities in the digital world.

[0006] The expansion of the scope, capabilities, and concepts of digital identity has led to an expansion in the meaning and extension of digital identity subjects, carriers, and functions. First, the definition of digital identity subjects has expanded from the narrow definition of "natural persons" to the broader definition of "humans, machines, and objects," and from physical entities such as "humans, machines, and objects" to virtual entities such as "data elements and digital humans." This has gradually broadened the scope of coverage and involved an increasing number of entities. Second, the definition of digital identity carriers has expanded beyond "digital" legal ID documents such as electronic ID cards, e-passports, and e-social security cards to include "digital" identity credentials such as phone numbers, email addresses, various account credentials, biometrics, and QR codes, enriching the types of identity carriers. Third, the functional connotation of digital identity has expanded beyond "proving who I am" to "proving my rights and attributes." This expansion is achieved through three core modules: identity identifiers, identity attributes, and identity credentials. This expansion requires multiple identifiers to uniquely identify an entity, attributes to describe its characteristics, and credentials to provide evidence verifying its identity attributes. Together, these three elements form the foundation of digital identity, ensuring the proper registration, issuance, verification, and management of identities.

[0007] Therefore, whether it is Internet identity or communication network identity, there is an urgent need for a digital identity definition and mechanism that can connect various industries and has certain global interoperability inherent properties to meet the identity and data interoperability needs across physical and virtual spaces, while ensuring the trustworthiness, interoperability, security and privacy protection of digital identity, providing a foundation for building a more secure, open and interconnected digital world.

[0008] However, existing carrier mobile phone numbers generally still use traditional IP addresses, which are limited to a single level of network location and employ a single communication identifier. This existing solution cannot meet the needs of identity and data interoperability across physical and virtual spaces. Therefore, a solution that can expand carrier mobile phone number identification is urgently needed. Summary of the Invention

[0009] The technical problem to be solved by this invention is to provide a method for extending the identification of operator mobile phone numbers in a multi-identity network system. This method aims to extend the identification of operator mobile phone numbers through the MIN network, thereby overcoming the drawback of the existing technology of using a single communication identifier for operator mobile phone numbers and meeting the needs for identity and data interoperability across physical and virtual spaces for mobile phone numbers. Furthermore, a system that utilizes this method for extending the identification of operator mobile phone numbers in a multi-identity network system is also provided.

[0010] To this end, the present invention provides a method for extending operator mobile phone number identifiers in a multi-identity network system, comprising the following steps:

[0011] Step S1: authenticating the mobile phone number through the MIN client to connect the mobile phone number to the MIN network. The MIN client refers to the multi-identity network system client, and the MIN network refers to the multi-identity network system, namely, the Cog-MIN network.

[0012] Step S2: Implementing single sign-on for mobile phone numbers through the MIN-SDK toolkit, which refers to a multi-identity network system toolkit.

[0013] Step S3: identity signing and signature verification in the MIN network;

[0014] Step S4, performing network group addressing in the MIN network through the mobile phone number;

[0015] Wherein, the step S1 includes the following sub-steps:

[0016] Step S101: The user downloads, installs and opens the MIN client;

[0017] Step S102: Using the getPhonelnfo pre-retrieval interface to obtain a mobile phone number through the call of the MIN client integrated SDK software development kit, and returning the pre-retrieval result;

[0018] Step S103: The MIN client calls the loginAuth login interface to obtain user authorization and render the authorization page;

[0019] Step S104: The MIN client prompts the user to authorize the mobile phone number to log in to the MIN client. After confirming the authorized login, the client obtains and returns the authorized login token.

[0020] Step S105: The MIN client generates account information and sends a registration and login request to the multi-identity router MIR with the authorization login token and account information. The multi-identity router MIR forwards the request to the multi-identity management system MIS to send the registration and login request.

[0021] Step S106: Query the authorized mobile phone number from the number card authentication server, register and log in;

[0022] Step S107, gradually returning the registration and login results, maintaining the login status in the MIN client, and prompting the user that the registration and login are successful.

[0023] A further improvement of the present invention is that step S106 includes the following sub-steps:

[0024] Step S1061: The multi-identity router MIR sends a request with an authorization login token to the security management system VMS, which then queries the number card authentication server for the authorized mobile phone number.

[0025] Step S1062: The number card authentication server returns the authorized mobile phone number to the security management system MIS, and then forwards the authorized mobile phone number to the multi-identity management system MIS;

[0026] Step S1063: register and log in the user identity corresponding to the authorized mobile phone number in the MIN network through the multi-identity management system MIS.

[0027] A further improvement of the present invention is that step S2 includes the following sub-steps:

[0028] Step S201: The user accesses the APP application, requests to open the MIN channel, and calls the MIN-SDK toolkit to query the current user's login status;

[0029] Step S202: If the current user's login status is not logged in, the APP application sends the user's authorized login token to the MIN-SDK toolkit to request single sign-on; the MIN-SDK toolkit sends the carried authorized login token to the MIN server to request the completion of the user's single sign-on operation; the MIN server refers to the multi-identity network system server;

[0030] Step S203: The MIN server requests the operator server to obtain the user information corresponding to the received authorization login token based on the authorization login token; the operator server parses the user information and returns the user's mobile phone number and related data to the MIN server;

[0031] Step S204: The MIN server completes the user registration or login operation based on the returned user information and records the user's identity information in the identity management system of the multi-identity network system;

[0032] Step S205: After the MIN server completes the registration or login operation, it returns a successful login response to the MIN-SDK toolkit. After receiving the successful login response, the MIN-SDK toolkit sends a successful login notification to the APP application.

[0033] Step S206: The APP application starts the MIN channel according to the user's login status and notifies the user that the startup has been successful.

[0034] A further improvement of the present invention is that in step S2, it is determined whether it is the first time to implement single sign-on using a mobile phone number. If so, a user registration process for single sign-on is triggered; if not, a user login process for single sign-on is triggered; the user registration process for single sign-on includes the following sub-steps:

[0035] Step A1: After the user enters relevant information, the key chain KeyChain is initialized based on the KeyManager instance to obtain the current user's identity, and then the SM2 cryptographic algorithm is called to randomly generate a public and private key pair;

[0036] In step A2, after the user enters their username and plaintext password, the combined string of the username and plaintext password is first hashed using SM3. A 32-byte hash result, hash32, is obtained through SM3 hashing. The first 16 bytes of hash32 are then taken to form a byte array, hash16, which serves as the SM4 key. The user's private key, PrivateKey, is then encrypted using SM4 encryption in ECB_Padding mode to obtain the encrypted user private key, EncryptedPrivateKey.

[0037] Step A3: first register in the multi-identity management system MIS to host the user key; then register in the security management system VMS to manage the user's virtual private network VPN permissions.

[0038] A further improvement of the present invention is that the user login process of the single sign-on includes the following sub-steps:

[0039] Step B1: After the user enters their username, password, and mobile phone number, and receives and fills in a verification code, the password is first hashed with MD5. The hashed password, username, mobile phone number, and verification code are then encapsulated into a login request in JSON format. Finally, the multi-identity management system interface MISRequestAPI is called to pass the login request to the multi-identity management system MIS.

[0040] In step B2, first perform SM3 hash calculation on the original plaintext key, then take the first 16 bytes after SM3 hash calculation as the key, and perform SM4 decryption on the user private key EncryptedPrivateKey. The decoding process adopts ECB_Padding mode.

[0041] A further improvement of the present invention is that step S3 includes the following sub-steps:

[0042] Step S301: Signing based on the user's private key. After confirming that the private key is not empty, the corresponding signature method is selected according to the public key generation algorithm in the KeyParam key parameter. The private key is then type-converted to the private key type of the SM2 algorithm, and the p.Sign digital signature method is called to sign.

[0043] Step S302: Verify the signature based on the user's public key. After verifying that the public key is not empty, first select the corresponding verification method based on the public key generation algorithm in the KeyParam key parameter, then convert the public key to the public key type of the SM2 algorithm, and call the p.Sign verification method for verification.

[0044] A further improvement of the present invention is that step S4 includes the following sub-steps:

[0045] Step S401, receiving data of a multi-identification network packet;

[0046] Step S402: Read the data link layer data segment and decode the multi-identifier network packet using TLV encoding. The multi-identifier network packet includes four areas: an identification area, a signature area, a read-only area, and a variable area. Each area consists of one or more TLV-encoded triplets. The TLV encoding divides the binary data block into three intervals: the first interval is the Type field, indicating the type of the current data block; the middle interval is the Length field, indicating the length of the Value field; and the last interval is the Value field, which is used to store the data block.

[0047] Step S403, determining whether the decoding of the multi-identifier network packet is successful. If not, the multi-identifier network packet is discarded and the processing flow ends; if yes, jump to step S404;

[0048] Step S404: Check the destination identifier field of the multi-identifier network packet to determine whether there is a next unprocessed identifier in the destination identifier field; if there is no identifier in the destination identifier field or the identifier has been processed, discard the multi-identifier network packet and the processing flow ends; if there is a next unprocessed identifier in the destination identifier field, jump to step S405;

[0049] Step S405: Read the next unprocessed identifier and determine whether the current multi-identity router can parse and process the identifier based on the identifier type number of the identifier. If not, that is, it cannot parse and process the identifier, then return to step S304 to continue to determine whether there is another unprocessed identifier in the destination identifier area; if so, jump to step S406;

[0050] Step S406: Invoke the processing flow, read and parse the value of the identifier, and call the corresponding processing function based on the identifier value and the identifier type number to process the multi-identifier network packet, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet out of the specified port;

[0051] Step S407, determine whether the processing of the multi-identifier network group is successful. If not, return to step S404 to continue to determine whether there is an unprocessed identifier in the destination identifier area; if so, the processing flow ends.

[0052] A further improvement of the present invention is that it further includes a global identity authentication step, which includes the following sub-steps:

[0053] Step C1, by formula Calculate the unique global identifier of a mobile phone number ,in, represents a hash function, Indicates a mobile phone number. Indicates the random seed generated based on the Super SIM card. Indicates that based on random seeds and the master key generated by the Super SIM card;

[0054] Step C2: When a mobile phone number is used across borders and roaming, the legitimacy and integrity of the identity are verified through the on-chain log. The legitimacy and integrity of the identity are verified using the formula To achieve this, Indicates the verification result. Represents a session token, Indicates a timestamp;

[0055] Step C3: When a mobile phone number is used across borders and roaming access is performed, the formula Generate encrypted logs for each cross-domain operation ,in, Indicates the i The content of the cross-domain operation, A string indicating the time point of the cross-domain operation. Indicates the digital signature of a cross-domain operation.

[0056] A further improvement of the present invention is that it further includes a signature and encryption verification step for implementing end-to-end encrypted communication and performing digital signature, data encryption, and decryption operations; the signature and encryption verification step includes the following sub-steps:

[0057] Step D1, by formula Digital signature, where Represents the unique signature generated during the network interaction process. Indicates the use of private key Digitally sign, Represents the payload, A string indicating the time point of the cross-domain operation;

[0058] Step D2, by formula Data encryption is performed, wherein, Represents the ciphertext after asymmetric encryption, Indicates the use of public key Perform asymmetric encryption, Indicates the encrypted original data;

[0059] Step D3, by formula Perform decryption operation, where Indicates the use of private key Perform decoding operation.

[0060] The present invention also provides a system for extending operator mobile phone number identification in a multi-identification network system, which adopts the method for extending operator mobile phone number identification in a multi-identification network system as described above and includes:

[0061] Mobile phone number authentication module, which realizes mobile phone number authentication through MIN client and completes the mobile phone number access to MIN network;

[0062] The mobile phone number single sign-on module implements single sign-on for mobile phone numbers through the MIN-SDK toolkit, which refers to the multi-identity network system toolkit;

[0063] Identity signature and verification module, which performs identity signature and verification in the MIN network;

[0064] The network packet addressing module performs network packet addressing in the MIN network through mobile phone numbers.

[0065] Compared with the prior art, the present invention has the following advantages: first, mobile phone number authentication is implemented through the MIN client, completing the mobile phone number's access to the MIN network; then, single sign-on for the mobile phone number is implemented through the MIN-SDK toolkit, and identity signature and signature verification are performed on the MIN network; finally, network group addressing is performed on the MIN network through the mobile phone number, thereby effectively expanding the identification of the operator's mobile phone number based on the MIN network. The present invention can effectively overcome the defect of the prior art that operator mobile phone numbers use a single communication identifier. By combining the operator mobile phone number and the MIN network, the identification of the operator mobile phone number is expanded, achieving unified cross-domain identity authentication, and meeting the identity and data interoperability requirements of mobile phone numbers across physical and virtual spaces. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 This is a schematic diagram of the workflow of an embodiment of the present invention;

[0067] Figure 2 This is a flow chart of mobile phone number authentication according to an embodiment of the present invention;

[0068] Figure 3 This is a flow chart of single sign-on using a mobile phone number according to an embodiment of the present invention;

[0069] Figure 4 This is a schematic diagram of network grouping of a MIN network according to an embodiment of the present invention;

[0070] Figure 5 is a flow chart of network packet processing according to an embodiment of the present invention;

[0071] Figure 6 This is a schematic diagram of concurrent processing of a multi-identity router according to an embodiment of the present invention. DETAILED DESCRIPTION

[0072] Before describing the specific embodiments of the present invention in detail, the key terms and related technologies of the present invention are first explained.

[0073] CT refers to Communication Technology; IT refers to Internet Technology; ESN refers to Equipment Serial Number; SIM refers to Subscriber Identity Model; IMEI refers to International Mobile Equipment Identity; TMSI refers to Temporary Mobile Subscriber Identity; URI refers to Uniform Resource Identifier; SUPI refers to subscription permanent identifier; SUCI refers to Subscription Concealed Identifier; PEI refers to Permanent Equipment Identifier; NSSAI refers to Single Network Slice Selection Assistance Information; IMSI refers to International Mobile Subscriber Identification Number; Cog-MIN refers to Cognitive Multi-Identifier Network, which is referred to as MIN (Multi-Identifier) ​​in this invention. Network); MIR refers to Multi-IdentifierRouter, which means multi-identifier router; MIS refers to Multi-Identifier System, which means multi-identifier management system.

[0074] The multi-identifier network system utilizes an innovative and cutting-edge multi-identifier management mechanism that integrates future networks with existing IP networks. The multi-identifier network system described in this invention refers to the MIN network, also known as the Cog-MIN network, which stands for Cognitive Multi-Identifier Network. Its structure transcends the limitations of the traditional centralized internet, achieving higher security, cross-domain interoperability, and on-chain behavior traceability.

[0075] Therefore, the MIN network not only supports the coexistence of multiple identities, but also realizes multilateral co-management of multi-identity networks through blockchain technology, enhancing the security and sustainability of the network.

[0076] The core concept of the MIN network is to achieve sovereignty, independence, and interoperability in cyberspace by supporting multiple identifiers (such as identity, content, and geolocation) and decentralized management. The MIN network primarily consists of a Multi-Identifier System (MIS) and a Multi-Identifier Router (MIR). Within the Multi-Identifier System (MIS), the MIN network's identifier management system is governed through a multilaterally managed consortium chain mechanism, using a one-country-one-vote voting system to manage top-level identifier domain names. Each country maintains internal autonomy through a scalable, hierarchical consortium chain. The Multi-Identifier Router (MIR) supports multiple identifiers, including identity, content, services, and IP, enabling parallel coexistence in the network layer. MIN utilizes the HPT algorithm, a hash table and prefix tree, to support multi-identifier translation and addressing for tens of billions of entries.

[0077] The MIN network has the following outstanding advantages:

[0078] MIN supports multiple identifiers (such as identity, content, and IP) and can flexibly use different identifiers for addressing and routing based on the application scenario. This allows MIN to not only meet the needs of the traditional Internet, but also adapt to emerging fields such as the Internet of Things, Industrial Internet, and Internet of Vehicles.

[0079] Second, decentralized governance: MIN uses blockchain technology and a consortium chain voting mechanism to ensure fairness and transparency in global network management, avoiding the unilateral monopoly problem brought about by the current centralized DNS management.

[0080] 3. High security and data traceability. The MIN network uses asymmetric encryption technology to achieve data traceability, ensuring the security and privacy of data transmission. MIN's design provides inherent security features and can defend against various network attacks. MIN integrates multiple security technologies, such as signature cryptography, identity verification, and behavior detection, to build a dynamic security protection model to effectively resist various network attacks.

[0081] MIN's multi-identity routing mechanism and hierarchical management structure based on the alliance chain make it highly scalable. Whether in small-scale enterprise private networks or global sovereign Internet scenarios, MIN can provide flexible solutions.

[0082] 5. Compatible with existing network systems. MIN is compatible with existing IPv4 and IPv6 network architectures, supports gradual evolution and transition, and does not require complete replacement of existing network equipment, reducing migration costs.

[0083] 6. Identity-driven: MIN uses identity as its core identifier, supports the registration and verification of users' real identities, and enhances network security and transparency. The binding of identity identifiers to devices ensures the traceability of network behavior.

[0084] Therefore, MIN (short for Multi-Identifier Network System or Multi-Identifier Network) has broad application prospects, particularly in global internet governance, security, and emerging technologies. Its core advantages are multilateral co-management and decentralized management, combined with the support of multiple identifiers and strong security mechanisms, making it adaptable to the development needs of future networks.

[0085] Overall, the MIN network system, through its multi-identity management, decentralized governance, identity-driven, and data traceability, provides a secure, flexible, and cost-effective network solution. It not only enhances network security and transparency, but also promotes international cooperation and technological innovation, adapting to the diverse needs of modern networks. As the network environment continues to evolve, the application prospects of MIN will become even broader.

[0086] Regarding the development of digital identity in communication networks, CT communication network technology and digital identity technology are integrated and developed. The first generation of mobile communication technology, 1G, began to use digital identity technology to identify entities, but it had major security vulnerabilities.

[0087] The second generation of mobile communication technology (2G) has achieved a solution to separate the "device" and "SIM" identity, effectively reducing security risks. The second generation of mobile communication network technology, represented by GSM, pioneered the use of a "device-SIM" separation method, with the mobile phone and SIM card together forming the mobile communication terminal device.

[0088] Third-generation mobile communication technology (3G) provides two-way authentication capabilities and further enriches service identification types. 3G, represented by WCDMA, upgrades the SIM card to the Universal Subscriber Identity Module (USIM) and further supports two-way authentication between the terminal and the network. 3G mobile communication networks offer users a richer and expanded range of services, including circuit-switched (CS) and packet-switched (PS). Service identification now includes not only the MSISDN in the CS domain but also the access point name (APN) in the PS domain.

[0089] Fourth-generation mobile communication technology (4G) introduced new IP multimedia identities, enabling IP-based unified communications and identity management. 4G, represented by LTE, halted the evolution of the CS domain, with the IP Multimedia Subsystem (IMS) domain taking over audio and video services.

[0090] 5G, the fifth generation of mobile communications technology, introduces new service identifiers to enable secure and flexible network slicing services and unified user identity management. In 5G, the User Permanent Identifier (SUPI) is equivalent to the IMSI in LTE. While its format is identical to the IMSI, the SUPI is never transmitted over the air interface to prevent user tracking through wireless signal monitoring. The User Hidden Identifier (SUCI) is a privacy-preserving identifier that includes the hidden SUPI and can be transmitted over the air interface. Every terminal device accessing the 5G mobile communications network must have a Permanent Equipment Identifier (PEI), which corresponds to the IMEI in LTE networks.

[0091] Overall, the evolution from 1G to 5G has seen the continuous deepening of the integration of digital identity technology and mobile communication networks, effectively achieving the separation and independent development of device, user, and service identification. While the user-centric system is expected to persist, the increasing diversification of network terminals and the continued expansion of service types will lead to further innovation and change in the specific forms of user, device, and service identification. Accordingly, digital identity technology in mobile networks will also follow this trend, evolving to meet new challenges and demands.

[0092] One prior art technique related to the present invention utilizes the Internet Protocol (IP), also known as the Internet Protocol. This is the network layer communication protocol within the Internet Protocol package, used for packet switching across network boundaries. Its routing function enables interconnection and essentially establishes the Internet.

[0093] IP is the primary protocol at the network layer of the TCP / IP protocol suite. Its mission is to deliver data packets from a source host to a destination host based solely on the IP address in the packet header. To accomplish this, the IP protocol defines the packet structure that encapsulates the data to be delivered. It also defines the addressing method used to label datagrams with source and destination information.

[0094] The characteristic of the IP address system is that each terminal is assigned a network address. Each packet carries this address, which serves as the basis for network nodes to forward packets. The currently widely used IPv4 packet structure uses a 32-bit address field, which is roughly equivalent to a 9-digit decimal number. With telephone numbers in major Chinese cities now almost all using 8-bit numbers, a 32-bit address field is undoubtedly insufficient for terminal identification worldwide. Consequently, recognizing this address crisis in the early 1990s, the IETF began work on IPv6 specifications. IPv6 uses a 128-bit address field, and it appears that this numbering resource will meet practical needs for a considerable period of time. While expanding the address field seems natural, two other issues related to this expansion are of particular interest: the promotion of IPv6 and the difficulties that the IP network's addressing scheme presents for high-speed packet forwarding. The promotion of IPv6 is extremely slow. On the one hand, this reflects that IPv4 can still cope with current practical needs through CIDR address segmentation, address reuse of proxy servers, and dynamic address allocation by ISPs. But on a larger scale, it reflects that the IP address method is too closely related to the way the network operates. It requires changing the user's communication program and the packet forwarding module of the router, which affects almost all devices on the network. The number upgrade work that can be completed overnight on the traditional telephone network may take more than ten years to complete on the IP network.

[0095] In traditional telecommunications networks, the numbers that identify transceiver terminals and the channel identifiers that guide information forwarding are relatively separate. Potential transceiver terminals may number in the tens or even hundreds of millions, while a switch or router's information forwarding operations involve merely selecting from a few dozen, or at most a few hundred, output ports. On IP networks, finding a suitable output port among no more than a thousand requires searching through tens of millions of records.

[0096] This related prior art suffers from the following shortcomings: IP network security issues encompass both network security and information security. Network security refers to the ability of public infrastructure providing network services to be attacked or damaged, such as compromised domain name servers or routers, or maliciously blocked. Information security, on the other hand, refers to the ability of information transmitted online or stored on servers to be leaked or overwritten. Information encryption and secure, effective access methods are network-related issues, not inherently network-related ones. Because information is exposed electronically on the network, maintaining its security is more difficult.

[0097] The introduction of the TCP / IP protocol seemingly solved the fundamental problem of data transmission across the vast internet, establishing a set of basic rules for data transmission. However, because this scheme was based on the principle of non-repetition, disordered and complex IP combinations placed a burden on computer operators, who struggled to easily process a series of random numbers. Consequently, disordered and complex IP addresses indirectly raised the barrier to internet use and became a limiting factor in its application.

[0098] Another existing technology related to the present invention uses Named Data Networking (NDN), which was proposed in 2010. Its predecessor is Content-Centric Networking (CCN). It uses receiver-driven pull-type communication semantics to replace the sender-driven push-type communication semantics in IP networks. In NDN, content consumers (Consumers) obtain content by sending interest packets (Interest) to the network. Any intermediate router or content producer (Producer) that caches the corresponding content will respond with a data packet (Data) upon receiving the Interest. Each Interest can pull a piece of Data, and there is a one-to-one correspondence between Interest and Data.

[0099] NDN has designed a pending interest table (PIT) to support a stateful forwarding plane. Each PIT entry records the network interface from which the interest was received. All PIT entry records on the interest forwarding path construct a reverse path. The corresponding data only needs to be returned along the reverse path constructed by the PIT. Through this pull-based interaction, NDN achieves the decoupling of content and producers, which can better support the business scenario of content distribution. To protect the security of content, NDN requires producers to sign each data they send, so that consumers can trust the content itself without worrying about how and where the content was obtained. Because NDN adopts a disruptive architectural design, its compatibility with existing network architecture remains to be studied.

[0100] This existing technology has the following shortcomings: Although NDN enhances data integrity, source authentication, and correctness through a content signing mechanism, it still faces many privacy and security risks: Name privacy, hierarchical names in interest packets can leak content information, especially when the name structure is very intuitive, which may lead to user privacy leakage; cache privacy, attackers can obtain access information about cached content through timing analysis; content privacy, although the data packet is signed, the content itself is not encrypted, so it cannot prevent data leakage; signature privacy, the signature can reveal the identity of the producer, thereby infringing the privacy of individuals or organizations.

[0101] Furthermore, NDN may be subject to various attacks, including denial of service (DoS) attacks, protocol attacks, and timing attacks. Denial of service (DoS) attacks involve sending a large number of Interest packets, overflowing the router's PIT table and thereby blocking legitimate requests. Because NDN Interest packets do not contain source addresses, attackers are difficult to track. Attackers can generate large numbers of invalid Interest packets through botnets, leading to cache contamination, bandwidth consumption, and network resource exhaustion. Protocol attacks exploit NDN's prefix matching mechanism to infer the content requested by consumers, thereby violating name privacy. Timing attacks, on the other hand, measure response times to infer whether content is cached, thereby gaining cache privacy.

[0102] Therefore, the present invention aims to combine operator mobile phone numbers with the MIN network based on a multilaterally managed multi-identity network system (MIN), namely the MIN network, to achieve identification extension for operator mobile phone numbers, thereby realizing unified cross-domain identity authentication for operator mobile phone numbers and meeting the identity and data interoperability requirements of mobile phone numbers across physical and virtual spaces. By extending the identification of operator mobile phone numbers based on the MIN network, the present invention connects mobile phone numbers to the MIN network as a valid network identifier, and achieves identity authentication and communication, which can effectively overcome the shortcomings of the existing technology of using a single communication identifier for operator mobile phone numbers.

[0103] In the technical solution proposed by the present invention, users can access the MIN network through existing mobile phone numbers and perform identity registration and login, so that users can directly use their mobile phone numbers as unique identifiers to realize identity authentication and communication in the MIN network. The mobile phone number will be registered as a unique identifier in the identity management system of the MIN network. The identity management system in the MIN network will be connected to the operator database in real time to verify the legitimacy of the mobile phone number and ensure the uniqueness and accuracy of the user identity.

[0104] In this process, mobile phone numbers not only serve as traditional communication identifiers but can also be associated with other user network identifiers (such as device identifiers and IP addresses) to achieve unified cross-domain identity authentication. This means that users only need a single mobile phone number to achieve identity authentication and access globally, across platforms, and across networks. Regardless of where the user is, as long as they have an Internet connection, they can log in to the MIN network through their mobile phone number and conduct secure communications and data exchange.

[0105] The preferred embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.

[0106] like Figures 1 to 6 As shown, the present invention provides a method for extending operator mobile phone number identification in a multi-identity network system, comprising the following steps:

[0107] Step S1: authenticating the mobile phone number through the MIN client to connect the mobile phone number to the MIN network. The MIN client refers to a multi-identity network system client, and the MIN network refers to a multi-identity network system, referred to as the MIN network.

[0108] Step S2: Implementing single sign-on for mobile phone numbers through the MIN-SDK toolkit, which refers to a multi-identity network system toolkit.

[0109] Step S3: identity signing and signature verification in the MIN network;

[0110] Step S4: performing network group addressing in the MIN network through the mobile phone number.

[0111] In this embodiment, step S1 is used to authenticate the mobile phone number through the MIN client, connect the mobile phone number to the MIN network, and perform network communication. Figure 2 As shown, step S1 includes the following sub-steps:

[0112] Step S101: The user downloads, installs and opens the MIN client;

[0113] Step S102: using the getPhonelnfo pre-retrieval interface provided by the SDK software development kit through the call of the MIN client integrated SDK software development kit to obtain the mobile phone number and return the pre-retrieval result; the SDK software development kit is referred to as SDK;

[0114] Step S103: The MIN client calls the loginAuth login interface provided by the SDK to obtain user authorization and render the authorization page; the authorization page is used to prompt the user that the MIN client will obtain the mobile phone number from the user, and by default, the user can continue to use the phone number only after the user agrees;

[0115] Step S104: The MIN client prompts the user to authorize the mobile phone number to log in to the MIN client. After confirming the authorized login, the client obtains and returns the authorized login token.

[0116] Step S105: The MIN client generates account information and sends a registration and login request to the multi-identity router MIR with the authorization login token and account information. The multi-identity router MIR forwards the request to the multi-identity management system MIS to send the registration and login request.

[0117] Step S106: Query the authorized mobile phone number from the number card authentication server, register and log in;

[0118] Step S107, gradually returning the registration and login results, maintaining the login status in the MIN client, and prompting the user that the registration and login are successful.

[0119] This embodiment mainly studies the application of mobile phone numbers in the MIN network architecture system. First, mobile phone number authentication is integrated into the Cog-MIN client (hereinafter referred to as the MIN client). Then, the functions of the MIN client are packaged into an SDK. That is, the MIN-SDK toolkit is used to encapsulate the functions into SDKs suitable for different operating systems, such as Android, iOS, and Hongmeng system. Finally, the mobile phone number is upgraded to one of the addressing identifiers, and the mobile phone number is newly defined as the MIN network identifier. The routing, forwarding, and resolution functions of the background system are adjusted.

[0120] Preferably, step S102 in this embodiment includes the following sub-steps:

[0121] Step S1021: Using the MIN client integrated SDK software development kit, use the getPhonelnfo pre-retrieval interface provided by the SDK to obtain the mobile phone number;

[0122] Step S1022: pre-retrieve the number through the gateway of the number card authentication server and return the pre-retrieval result;

[0123] Step S1023, determine whether the pre-number is successful. If not, jump to the SIM quick process to implement quick authentication of the SIM card; if so, jump to step S103.

[0124] The process of integrating the SDK software development kit (SDK) through the MIN client in step S1021 of this embodiment is preferably as follows: first, the SDK is introduced into the MIN client project as a dependent library, and the SDK dependency is added to the project's build.gradle core configuration file; then, interaction with the SDK is implemented locally through method calls, for example: relevant modules or classes of the SDK are imported into the code, initialized according to the SDK documentation, and the required functions are implemented by calling the methods provided by the SDK, including obtaining data, initiating requests, etc.

[0125] The SIM Express process described in this embodiment involves direct authentication via the SIM card. First, the phone number is entered to request SIM card authentication. The transaction ID is returned and cached, and the operation result is set as pending. Next, the user is asynchronously notified to confirm authorization, and the cached operation result is modified based on the transaction ID. Finally, the transaction ID is entered, and the user's authorization result is polled to complete registration and login. This process is, of course, only one preferred implementation.

[0126] Preferably, step S106 in this embodiment includes the following sub-steps:

[0127] Step S1061: The multi-identity router MIR sends a request for an authorized login token to the security management system VMS, which then queries the number card authentication server for an authorized mobile phone number. The authorized mobile phone number is a mobile phone number.

[0128] Step S1062: The number card authentication server returns the authorized mobile phone number to the security management system VMS, and then forwards the authorized mobile phone number to the multi-identity management system MIS;

[0129] Step S1063: register and log in the user identity corresponding to the authorized mobile phone number in the MIN network through the multi-identity management system MIS.

[0130] The step S2 of this embodiment is used to implement single sign-on of the mobile phone number in the MIN network, allowing the mobile phone number to communicate in the MIN network of other systems. Figure 3 As shown, step S2 includes the following sub-steps:

[0131] Step S201: The user accesses the APP application, requests to open the MIN channel, and calls the MIN-SDK toolkit to query the current user's login status. Figure 3 Steps 1 to 4 in the MIN-SDK toolkit; the MIN-SDK toolkit refers to the SDK software development toolkit integrated in the multi-identity network system;

[0132] Step S202: If the current user's login status is not logged in, the APP application carries the user's authorized login token and sends it to the MIN-SDK toolkit to request single sign-on (SS0). Figure 3 Step 5 of the MIN-SDK toolkit sends the authorization login token it carries to the MIN server, requesting the completion of the user's single sign-on operation; the MIN server refers to the multi-identity network system server;

[0133] Step S203: The MIN server requests the operator server to obtain the user information corresponding to the authorization login token according to the received authorization login token. Figure 3 Steps 6 and 7 in the MIN service; the operator server parses the user information and returns the user's mobile phone number and related data to the MIN server;

[0134] Step S204: The MIN server completes the user registration or login operation in the system based on the returned user information, and records the user's identity information in the identity management system of the multi-identity network system. Figure 3 Steps 8 and 9 in the

[0135] Step S205: After the MIN server completes the registration or login operation, it returns the successful login response to the MIN-SDK toolkit. After receiving the successful login response, the MIN-SDK toolkit sends a notification that the user has successfully logged in to the APP application. Figure 3 Steps 10 and 11;

[0136] Step S206: The APP application starts the MIN channel according to the user's login status and notifies the user that the startup is successful. Figure 3 At this point, you can proceed with other operations.

[0137] In step S2 of this embodiment, it is determined whether the user is implementing single sign-on using a mobile phone number for the first time. If so, it means that the user is accessing the MIN network for the first time, triggering the user registration process of single sign-on; if not, the user login process of single sign-on is triggered.

[0138] The user registration process for single sign-on in this embodiment includes the following sub-steps:

[0139] Step A1 is used to generate a public-private key pair. After the user enters relevant information, the key chain KeyChain is initialized based on the KeyManager instance to obtain the current user's identity. Then, the SM2 cryptographic algorithm is called to randomly generate a public-private key pair. The KeyManager instance is responsible for managing the generation and storage of keys. The key chain KeyChain refers to the key chain instance used to store and manage the user's keys. The relevant information entered by the user includes the authorized mobile phone number, authorized login token, and account information.

[0140] Step A2 is used to encrypt the user identity. After the user enters their username and plaintext password, the combined string of the username and plaintext password is first hashed using SM3. A 32-byte hash result, hash32, is obtained through the SM3 hash calculation. The first 16 bytes of the hash result, hash32, are then used to form a byte array, hash16, which is used as the SM4 key. The user's private key, PrivateKey, is then encrypted using SM4 encryption. The encryption process uses the ECB_Padding mode to obtain the encrypted user private key, EncryptedPrivateKey. The ECB_Padding mode refers to the ECB mode combined with a padding mechanism. The ECB mode refers to the Electronic Codebook Mode, i.e., a block cipher. The padding mechanism refers to padding. In a block cipher, the length of the plaintext must be an integer multiple of the block length. Row padding is performed when the plaintext length is insufficient.

[0141] Step A3 is used to execute the registration request; first register in the multi-identity management system MIS to host the user key; then register in the security management system VMS to manage the user's virtual private network VPN permissions.

[0142] Since user identity and public key are unique, after the background of the multi-identity management system MIS receives the registration request, it checks the local uniqueness of these two fields and issues a certificate for the identity if it passes.

[0143] The registration request of this application is encapsulated twice for the multi-identity management system MIS and the security management system VMS. In the current Android version, registration can be performed only through the security management system VMS, and the security management system VMS interacts with the multi-identity management system MIS.

[0144] The user login process of the single sign-on in this embodiment includes the following sub-steps:

[0145] Step B1: After the user enters their username, password, and mobile phone number, and receives and fills in the verification code, the password is first hashed with MD5. The hashed password, username, mobile phone number, and verification code are then encapsulated into a login request in JSON format. Finally, the multi-identity management system interface MISRequestAPI is called to pass the login request to the multi-identity management system MIS. The implementation process of the multi-identity management system interface MISRequestAPI is as follows: the login request in JSON format is used as the payload, packaged into a universal MIN package format, and the packaged MIN package is sent to the multi-identity management system MIS to complete the transmission of the login request.

[0146] Step B2, obtain the encrypted identity data from the multi-identity management system MIS and decrypt it, save the identity data locally, reconstruct the login information, send it to the security management system VMS and wait for a response; corresponding to the user identity encryption process implemented in step A2, this embodiment first performs SM3 hash calculation on the original plaintext key, and then takes the first 16 bytes after SM3 hash calculation as the key, and performs SM4 decryption on the user private key EncryptedPrivateKey, and the decoding process adopts ECB_Padding mode.

[0147] Step S3 of this embodiment is used to implement identity signing and signature verification in the MIN network. Step S3 includes the following sub-steps:

[0148] Step S301: Signing is performed based on the user's private key. After confirming that the private key is not empty, the corresponding signature method is first selected according to the public key generation algorithm in the KeyParam key parameter. Then, the private key (such as id.Prikey) is type-converted to the private key type of the SM2 algorithm, such as the parameter p of the sm2.Sm2PrivateKey type, and the p.Sign digital signature method is called to sign. Among them, KeyParam is a key parameter used to specify the public key generation algorithm. The SM2 algorithm is a public key cryptography algorithm based on elliptic curves and is used for digital signatures and encryption. The signature of this embodiment uses the SM2WithSM3 algorithm by default.

[0149] Step S302 verifies the signature based on the user's public key. After verifying that the public key is not null, the corresponding verification method is selected based on the public key generation algorithm in the KeyParam key parameter. The public key (such as id.Pubkey) is then converted to the SM2 algorithm public key type, such as the parameter p of the sm2.Sm2PublicKey type. The p.Sign verification method is then called for verification. This embodiment uses the SM2WithSM3 algorithm by default.

[0150] Step S4 in this embodiment is used to implement the network group addressing process of the mobile phone number in the MIN network. Figure 5 As shown, step S4 preferably includes the following sub-steps:

[0151] Step S401, receiving data of a multi-identification network packet;

[0152] Step S402, read the data link layer data segment, and decode the multi-identifier network packet through TLV encoding; wherein, Figure 4 As shown in the figure, the multi-identifier network group consists of four areas: the identification area, the signature area, the read-only area, and the variable area. Each area consists of one or more TLV-encoded triplets (i.e., Type / Length / Value). TLV encoding divides the binary data block into three intervals. The first interval is the Type field, which indicates the type of the current data block; the middle interval is the Length field, which indicates the length of the Value field; and the last interval is the Value field, which is used to store the data block.

[0153] Step S403, determining whether the decoding of the multi-identifier network packet is successful. If not, the multi-identifier network packet is discarded and the processing flow ends; if yes, jump to step S404;

[0154] Step S404: Check the destination identifier field of the multi-identifier network packet to determine whether there is a next unprocessed identifier in the destination identifier field; if there is no identifier in the destination identifier field or the identifier has been processed, discard the multi-identifier network packet and the processing flow ends; if there is a next unprocessed identifier in the destination identifier field, jump to step S405;

[0155] Step S405: Read the next unprocessed identifier and determine whether the current multi-identity router can parse and process the identifier based on the identifier type number of the identifier. If not, that is, it cannot parse and process the identifier, then return to step S304 to continue to determine whether there is another unprocessed identifier in the destination identifier area; if so, jump to step S406;

[0156] Step S406: Invoke the processing flow, read and parse the value of the identifier, and call the corresponding processing function based on the identifier value and the identifier type number to process the multi-identifier network packet, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet out of the specified port;

[0157] Step S407, determine whether the processing of the multi-identifier network group is successful. If not, return to step S404 to continue to determine whether there is an unprocessed identifier in the destination identifier area; if so, the processing flow ends.

[0158] This embodiment provides a single-thread (single-processor) network packet processing process through steps S401 to S407, and provides a flow chart of a network packet forwarder processing a network packet. Figure 5 The figure shows the complete process of a single-core router processing a network packet.

[0159] Since the support of multiple identifiers by the multi-identity router MIR can be completely isolated from each other, in the software-implemented forwarder, a multi-core processor can be used to forward network packets carrying different identifiers. Therefore, in step S4 of this embodiment, when a multi-identity network packet carrying multiple identifiers enters the multi-identity router MIR, the multi-identity router MIR processes the multiple identifiers concurrently, such as Figure 6 The FIB table refers to the Forwarding Information Base, which is a query forwarding table used to implement query and forwarding processing in the identification processing unit.

[0160] In this embodiment, the process of concurrently processing multiple identifiers by the multi-identity router MIR includes:

[0161] Step E1, extracting all identifiers in the multi-identity network group, and determining the identifier types supported by the multi-identity router MIR through an identifier filter;

[0162] Step E2: Duplicate the data according to the number of supported identifiers and send them to different identifier processing units for processing. After receiving the processing task, different identifier processing units independently complete the processing of the multi-identifier network group and then summarize the processing results to the decision unit.

[0163] In step E3, the decision unit selects a processing result to be adopted according to the order of the identifiers in the multi-identifier network group.

[0164] For example, in Figure 6 In this example, identifiers 101 and 103 carried in the multi-identifier network packet are both identifier types supported by the current router. Therefore, the incoming network packet is duplicated and distributed to two different identifier processing units for processing. These different identifier processing units can independently run on different CPUs or CPU cores. After receiving the multi-identifier network packet processing task, each identifier processing unit independently completes processing of the multi-identifier network packet and aggregates the processing results to the decision unit.

[0165] like Figure 6As shown, identifier 103 has a higher priority in the network packet than identifier 101. Therefore, if the processing result of identifier 103 is normal, that is, the result of the identifier processing unit is not to discard the multi-identifier network packet, the decision unit adopts the processing result of the identifier processing unit corresponding to identifier 103 and ignores the result of the identifier processing unit corresponding to identifier 101. Only when the processing result corresponding to identifier 103 is to discard the multi-identifier network packet does the decision unit adopt the processing result of the identifier processing unit corresponding to identifier 101.

[0166] Therefore, in the parallel multi-identity router (MIR) of this embodiment, all identifiers in the multi-identity network group are first extracted. After receiving the processing task for the multi-identity network group, different identifier processing units independently complete the processing of the multi-identity network group. Subsequently, each identifier processing unit summarizes the processing results to the decision unit. The decision unit determines which identifier processing unit's processing result to use based on the order of the identifiers in the multi-identity network group.

[0167] In summary, this embodiment first implements mobile phone number authentication through the MIN client, completing the mobile phone number's connection to the MIN network. Then, the MIN-SDK toolkit is used to implement single sign-on for the mobile phone number, and identity signature and signature verification are performed on the MIN network. Finally, network group addressing is performed on the MIN network through the mobile phone number, effectively expanding the identification of the operator's mobile phone number based on the MIN network. This embodiment can effectively overcome the drawback of the prior art of using a single communication identifier for operator mobile phone numbers. By combining the operator mobile phone number with the MIN network, the identification of the operator mobile phone number is expanded, achieving unified cross-domain identity authentication, and meeting the identity and data interoperability requirements of mobile phone numbers across physical and virtual spaces.

[0168] This embodiment proposes a method and system for expanding operator mobile phone number identification based on the MIN network. By mapping traditional mobile phone numbers to a multi-identity network and using traditional mobile phone numbers as one of the primary identifiers of the MIN network, global interconnection, identity authentication, and secure communication capabilities are achieved under the sovereign internet. This embodiment breaks the limitations of traditional IP addresses, which are limited to single-level network positioning and single mapping. Through the MIN network's architecture, it supports the unified mapping and collaborative resolution of multiple types of identifiers (such as mobile phone numbers, device identifiers, and location identifiers). This structurally breaks through the limitations of the traditional centralized internet, achieving higher security, cross-domain interoperability, and on-chain behavior traceability, and realizing a cross-domain, trusted, and highly secure global identity authentication and data access mechanism.

[0169] Mathematical model analysis shows that in the MIN network, each mobile phone number (MSISDN) will be mapped to a globally unique identifier when accessing the network. , and multi-dimensionally associate it with the device identification (IMEI), IP address, and SIM card ID to form a multi-identification trusted authentication mechanism. Assume that the success probability of a single-point attack in a traditional IP network is In this embodiment, the attack success probability after multi-dimensional identification mapping can be expressed as: ,in: Indicates the safety improvement factor after each mark is added; Indicates the number of additional identification dimensions, such as device ID, location ID, and dynamic session ID.

[0170] When the number of dimensions is identified When it increases to 5 or more, the probability of attack from traditional IP addresses decreases exponentially, demonstrating a security protection capability far superior to that of traditional network architectures. At the same time, the MIN network has also introduced a cross-domain authentication mechanism based on digital customs. When mobile phone numbers are used across borders and roaming accesses, the legitimacy and integrity of the identity are verified through on-chain logs. For details, see the global identity authentication steps below.

[0171] This embodiment also preferably includes a global identity authentication step, which includes the following sub-steps:

[0172] Step C1, by formula Calculate the unique global identifier of a mobile phone number ,in, represents a hash function, Indicates a mobile phone number. Indicates the random seed generated based on the Super SIM card. Indicates that based on random seeds and the master key generated by the Super SIM card; in the MIN network, each mobile phone number has global addressing capabilities, supporting cross-regional roaming and global trusted authentication;

[0173] Step C2: When a mobile phone number is used across borders and roaming, the legitimacy and integrity of the identity are verified through the on-chain log. The legitimacy and integrity of the identity are verified using the formula To achieve this, Indicates the verification result. Represents a session token, Indicates a timestamp;

[0174] Step C3: When a mobile phone number is used across borders and roaming access is performed, the formula Generate encrypted logs for each cross-domain operation ,in, Indicates the i The content of the cross-domain operation, A string indicating the time point of the cross-domain operation. Indicates the digital signature of a cross-domain operation.

[0175] In step C1 of this embodiment, the random seed The generation process includes: firstly, generating an initial random number based on the secure random number module in the super SIM card; then processing the initial random number through a perturbation function, such as through XOR (exclusive OR) mixed operations and nonlinear transformations (such as hash functions), to generate the final random seed. . Master Key The generation process includes: based on random seeds The unique ID of the super SIM card is used to generate the master key of the super SIM card through the key derivation function (KDF) , for example, using the formula =HKDF( IKM = R SIM_ID, salt, info, L) calculates and generates the master key of the super SIM card HKDF (HMAC-based Key Derivation Function) is a key derivation function based on HMAC (Hash-based Message Authentication Code). IKM = R SIM_ID means random seed and the unique ID of the super SIM card as input key material IKM , salt represents the salt value, info represents the context information used to distinguish the key derivation scenarios, and L represents the generated key length.

[0176] By verifying the legitimacy and integrity of identities, all authentication actions are recorded in a multilaterally managed blockchain log that is tamper-proof and globally updated. Even in the event of an attack or malicious impersonation, the entire path of the action can be traced, protecting users' cybersecurity rights and interests.

[0177] This embodiment also combines the super SIM card's national secret security chip and hardware encryption storage capabilities to propose a triple authentication model of "mobile phone number + national secret chip + PKI". The user's mobile phone number will not only be the entrance to communication, but also a unified network identity worldwide, supporting encrypted communication and data interaction between any trusted nodes in the MIN network.

[0178] In the global identity authentication step, a digital customs cross-domain authentication mechanism is also added. For cross-border access and roaming communications, this embodiment proposes a digital customs authentication mechanism, combined with blockchain multilateral co-managed logs, to record user identity authentication and data exchange operations. During the authentication process, each cross-domain operation will generate an encrypted log represented as: This encrypted log is tamper-proof and supports traceability and auditing.

[0179] Preferably, this embodiment also includes a signature and encryption verification step for implementing end-to-end encrypted communication, performing digital signatures, data encryption, and decryption operations. It should be noted that traditional mobile phone numbers do not have encryption capabilities, so this embodiment adds a signature and encryption verification step. The signature and encryption verification step includes the following sub-steps:

[0180] Step D1, by formula Digitally sign, where Represents the unique signature generated during the network interaction process. Indicates the use of private key Digitally sign, Represents the payload, A string indicating the time point of the cross-domain operation;

[0181] Step D2, by formula Data encryption is performed, wherein Represents the ciphertext after asymmetric encryption, Indicates the use of public key Perform asymmetric encryption, Indicates the encrypted original data;

[0182] Step D3, by formula Perform decryption operation, where Indicates the use of private key Perform decoding operation.

[0183] This embodiment further provides a system for extending operator mobile phone number identifiers in a multi-identity network system, which adopts the method for extending operator mobile phone number identifiers in a multi-identity network system as described above, and includes:

[0184] Mobile phone number authentication module, which realizes mobile phone number authentication through MIN client and completes the mobile phone number access to MIN network;

[0185] The mobile phone number single sign-on module implements single sign-on for mobile phone numbers through the MIN-SDK toolkit, which refers to the multi-identity network system toolkit;

[0186] Identity signature and verification module, which performs identity signature and verification in the MIN network;

[0187] The network packet addressing module performs network packet addressing in the MIN network through mobile phone numbers.

[0188] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A method for extending operator mobile phone number identification in a multi-identity network system, characterized in that: The following steps are involved: Step S1: authenticating a mobile phone number through a MIN client to connect the mobile phone number to the MIN network. The MIN client refers to a multi-identity network system client, and the MIN network refers to a multi-identity network system. Step S2: Implementing single sign-on for mobile phone numbers through the MIN-SDK toolkit, which refers to a multi-identity network system toolkit. Step S3: identity signing and signature verification in the MIN network; Step S4, performing network group addressing in the MIN network through the mobile phone number; Wherein, the step S1 includes the following sub-steps: Step S101: The user downloads, installs and opens the MIN client; Step S102: Using the getPhonelnfo pre-retrieval interface to obtain a mobile phone number through the call of the MIN client integrated SDK software development kit, and returning the pre-retrieval result; Step S103: The MIN client calls the loginAuth login interface to obtain user authorization and render the authorization page; Step S104: The MIN client prompts the user to authorize the mobile phone number to log in to the MIN client. After confirming the authorized login, the client obtains and returns the authorized login token. Step S105: The MIN client generates account information and sends a registration and login request to the multi-identity router MIR with the authorization login token and account information. The multi-identity router MIR forwards the request to the multi-identity management system MIS to send the registration and login request. Step S106: Query the authorized mobile phone number from the number card authentication server, register and log in; Step S107, gradually returning the registration and login results, maintaining the login status in the MIN client, and prompting the user that the registration and login are successful.

2. The method for extending operator mobile phone number identification in a multi-identity network system according to claim 1, characterized in that: The step S106 includes the following sub-steps: Step S1061: The multi-identity router MIR sends a request with an authorization login token to the security management system VMS, which then queries the number card authentication server for the authorized mobile phone number. Step S1062: The number card authentication server returns the authorized mobile phone number to the security management system VMS, and then forwards the authorized mobile phone number to the multi-identity management system MIS; Step S1063: register and log in the user identity corresponding to the authorized mobile phone number in the MIN network through the multi-identity management system MIS.

3. The method for extending operator mobile phone number identifiers in a multi-identity network system according to claim 1, characterized in that: The step S2 includes the following sub-steps: Step S201: The user accesses the APP application, requests to open the MIN channel, and calls the MIN-SDK toolkit to query the current user's login status; Step S202: If the current user's login status is not logged in, the APP application sends the user's authorized login token to the MIN-SDK toolkit to request single sign-on; the MIN-SDK toolkit sends the carried authorized login token to the MIN server to request the completion of the user's single sign-on operation; MIN server refers to the multi-identity network system server; Step S203: The MIN server requests the operator server to obtain the user information corresponding to the received authorization login token based on the authorization login token. The operator's server parses the user information and returns the user's mobile phone number and related data to the MIN server; Step S204: The MIN server completes the user registration or login operation based on the returned user information and records the user's identity information in the identity management system of the multi-identity network system; Step S205: After the MIN server completes the registration or login operation, it returns a successful login response to the MIN-SDK toolkit. After receiving the successful login response, the MIN-SDK toolkit sends a notification of the successful login to the APP application; Step S206: The APP application starts the MIN channel according to the user's login status and notifies the user that the startup is successful.

4. The method for extending operator mobile phone number identification in a multi-identity network system according to any one of claims 1 to 3, characterized in that: In step S2, it is determined whether it is the first time to implement single sign-on using a mobile phone number. If so, a user registration process for single sign-on is triggered; if not, a user login process for single sign-on is triggered. The user registration process for single sign-on includes the following sub-steps: Step A1: After the user enters relevant information, the key chain KeyChain is initialized based on the KeyManager instance to obtain the current user's identity, and then the SM2 cryptographic algorithm is called to randomly generate a public and private key pair; In step A2, after the user enters their username and plaintext password, the combined string of the username and plaintext password is first hashed using SM3. A 32-byte hash result, hash32, is obtained through SM3 hashing. The first 16 bytes of hash32 are then taken to form a byte array, hash16, which serves as the SM4 key. The user's private key, PrivateKey, is then encrypted using SM4 encryption in ECB_Padding mode to obtain the encrypted user private key, EncryptedPrivateKey. Step A3: first register in the multi-identity management system MIS and escrow the user key; Then register on the security management system VMS to manage the user's virtual private network VPN permissions.

5. The method for extending operator mobile phone number identification in a multi-identity network system according to claim 4, characterized in that: The single sign-on user login process includes the following sub-steps: Step B1: After the user enters their username, password, and mobile phone number, and receives and fills in a verification code, the password is first hashed with MD5. The hashed password, username, mobile phone number, and verification code are then packaged into a JSON-formatted login request. Finally, the multi-identity management system interface MISRequestAPI is called to pass the login request to the multi-identity management system MIS. In step B2, first perform SM3 hash calculation on the original plaintext key, then take the first 16 bytes after SM3 hash calculation as the key, and perform SM4 decryption on the user private key EncryptedPrivateKey. The decoding process adopts ECB_Padding mode.

6. The method for extending operator mobile phone number identification in a multi-identity network system according to any one of claims 1 to 3, characterized in that: The step S3 includes the following sub-steps: Step S301: Signing based on the user's private key. After confirming that the private key is not empty, the corresponding signature method is selected according to the public key generation algorithm in the KeyParam key parameter. The private key is then type-converted to the private key type of the SM2 algorithm, and the p.Sign digital signature method is called to sign. Step S302: Verify the signature based on the user's public key. After verifying that the public key is not empty, first select the corresponding verification method based on the public key generation algorithm in the KeyParam key parameter, then convert the public key to the public key type of the SM2 algorithm, and call the p.Sign verification method for verification.

7. The method for extending operator mobile phone number identification in a multi-identity network system according to any one of claims 1 to 3, characterized in that: The step S4 includes the following sub-steps: Step S401, receiving data of a multi-identification network packet; Step S402: Read the data link layer data segment and decode the multi-identifier network packet using TLV encoding. The multi-identifier network packet includes four areas: an identification area, a signature area, a read-only area, and a variable area. Each area consists of one or more TLV-encoded triplets. The TLV encoding divides the binary data block into three intervals: the first interval is the Type field, indicating the type of the current data block; the middle interval is the Length field, indicating the length of the Value field; and the last interval is the Value field, which is used to store the data block. Step S403, determining whether the decoding of the multi-identifier network packet is successful. If not, the multi-identifier network packet is discarded and the processing flow ends; if yes, jump to step S404; Step S404: Check the destination identifier field of the multi-identifier network packet to determine whether there is a next unprocessed identifier in the destination identifier field; if there is no identifier in the destination identifier field or the identifier has been processed, discard the multi-identifier network packet and the processing flow ends; if there is a next unprocessed identifier in the destination identifier field, jump to step S405; Step S405: Read the next unprocessed identifier and determine whether the current multi-identity router can parse and process the identifier based on the identifier type number of the identifier. If not, that is, it cannot parse and process the identifier, then return to step S304 to continue to determine whether there is another unprocessed identifier in the destination identifier area; if so, jump to step S406; Step S406: Invoke the processing flow, read and parse the value of the identifier, and call the corresponding processing function based on the identifier value and the identifier type number to process the multi-identifier network packet, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet out of the specified port; Step S407, determine whether the processing of the multi-identifier network group is successful. If not, return to step S404 to continue to determine whether there is an unprocessed identifier in the destination identifier area; if so, the processing flow ends.

8. The method for extending operator mobile phone number identifiers in a multi-identity network system according to any one of claims 1 to 3, characterized in that: The global identity authentication step is further included, and the global identity authentication step includes the following sub-steps: Step C1, by formula Calculate the unique global identifier of a mobile phone number ,in, represents a hash function, Indicates a mobile phone number. Indicates the random seed generated based on the Super SIM card. Indicates that based on random seeds and the master key generated by the Super SIM card; Step C2: When a mobile phone number is used across borders and roaming, the legitimacy and integrity of the identity are verified through the on-chain log. The legitimacy and integrity of the identity are verified using the formula To achieve, Indicates the verification result. Represents a session token, Indicates a timestamp; Step C3: When a mobile phone number is used across borders and roaming access is performed, the formula Generate encrypted logs for each cross-domain operation ,in, Indicates the i The content of the cross-domain operation, A string indicating the time point of the cross-domain operation. Indicates the digital signature of a cross-domain operation.

9. The method for extending operator mobile phone number identification in a multi-identity network system according to any one of claims 1 to 3, characterized in that: It also includes a signature and encryption verification step for implementing end-to-end encrypted communication, performing digital signature, data encryption, and decryption operations; the signature and encryption verification step includes the following sub-steps: Step D1, by formula Digitally sign, where Represents the unique signature generated during the network interaction process. Indicates the use of private key Digitally sign, Represents the payload, A string indicating the time point of the cross-domain operation; Step D2, by formula Data encryption is performed, wherein Represents the ciphertext after asymmetric encryption, Indicates the use of public key Perform asymmetric encryption, Indicates the encrypted original data; Step D3, by formula Perform decryption operation, where Indicates the use of private key Perform decoding operation.

10. A system for extending operator mobile phone number identification in a multi-identity network system, characterized in that: The method for extending operator mobile phone number identification in a multi-identification network system according to any one of claims 1 to 9 is adopted, and includes: Mobile phone number authentication module, which realizes mobile phone number authentication through MIN client and completes the mobile phone number access to MIN network; The mobile phone number single sign-on module implements single sign-on for mobile phone numbers through the MIN-SDK toolkit, which refers to the multi-identity network system toolkit; Identity signature and verification module, which performs identity signature and verification in the MIN network; The network packet addressing module performs network packet addressing in the MIN network through mobile phone numbers.

Citation Information

Patent Citations

  • Method and system for supporting continuous evolution of packet communication network addressing routing identifier

    CN112804152A

  • Method for multi-identifier login of an instant messaging system

    US20060059240A1