Method and system for forming trusted sovereign network by expanding SIM (Subscriber Identity Module) cards in multi-identification network system

The integration of SIM cards into a multi-identifier network framework addresses the challenge of cross-platform and cross-network identity authentication, ensuring secure and unified identity verification and data sharing.

CN120321655AActive Publication Date: 2025-07-15PEKING UNIV SHENZHEN GRADUATE SCHOOL +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510797331.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-07-15
Estimated Expiration
2045-06-16

AI Technical Summary

Technical Problem

Existing SIM cards have problems with difficult identity consistency and security in cross-platform and cross-network identity authentication, especially when they are attacked, it is difficult to achieve real-time traceability and behavioral locking.

Method used

Through the multi-identification network system, SIM cards are expanded to realize authentication, identity signature and network packet addressing of SIM cards, combined with multilateral co-management and decentralized management, and adopted the National Secret Security Chip and PKI asymmetric encryption technology to generate a unique master key and perform identity authentication and data encryption.

Benefits of technology

It realizes unified identity authentication across platforms and networks of SIM cards, improves identity consistency and security, ensures the uniqueness of user identities and confidentiality of communication, and supports identity authentication and data interoperability across physical and virtual spaces.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321655A_ABST
    Figure CN120321655A_ABST
Patent Text Reader

Abstract

The invention provides a method and system for forming a trusted sovereignty network by expanding SIM cards in a multi-identification network system, and the method comprises the following steps: S1, achieving the authentication of the SIM cards through a client of the multi-identification network system, and enabling the SIM cards to be connected to the multi-identification network system; s2, performing identity signature and signature verification in the multi-identifier network system; s3, network grouping addressing is carried out in the multi-identification network system through the SIM card; the step S1 is used for realizing rapid authentication and login of the SIM card. According to the invention, the SIM card can be used as an effective network identifier to be accessed into the multi-identifier network system, identity authentication and communication of the SIM card in the multi-identifier network system are realized, a trusted sovereign network is constructed, the advantages of multilateral co-management, decentralized management and multiple identifiers of the multi-identifier network system are combined, and the reliability of the system is improved. The cross-platform and cross-network unified identity authentication of the SIM card is realized, and the cross-platform and cross-network identity consistency and security requirements of the SIM card are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for constructing a trusted sovereign network, in particular to a method for constructing a trusted sovereign network by extending a SIM card with a multi-identifier network system, and also relates to a system adopting the method for constructing a trusted sovereign network by extending a SIM card with a multi-identifier network system. Background Art

[0002] With the accelerating trend of the social "digitization" and "intelligence" transformation, secure connection and identity authentication have become basic rigid demands. Against this background, as a natural security authentication carrier, the SIM card has gradually realized the transformation from the communication field to the identity authentication field through technological upgrades, and has become an important pillar of security services in the digital age. However, the existing application of the SIM card uses a single communication identifier, and the identity authentication of the traditional IP network it applies to mainly relies on centralized services. It is difficult to achieve unified identity authentication of the SIM card across platforms and networks, and it is impossible to guarantee the identity consistency and security across platforms and networks. Moreover, in the event of an attack, it is also difficult to achieve real-time traceability and behavior locking.

[0003] Therefore, whether as an Internet identity or a communication network identity, there is an urgent need to provide a digital identity definition and mechanism that can penetrate various industries and has certain inherent attributes of global interoperability to meet the unified identity authentication of the SIM card across platforms and networks, and to meet its cross-platform and cross-network identity consistency and security requirements. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a method for constructing a trusted sovereign network by extending a SIM card with a multi-identifier network system, aiming to connect the SIM card as an effective network identifier to the multi-identifier network system to achieve identity authentication and communication of the SIM card in the multi-identifier network system, construct a trusted sovereign network, and further achieve unified identity authentication of the SIM card across platforms and networks, and meet its cross-platform and cross-network identity consistency and security requirements. On this basis, a system adopting the method for constructing a trusted sovereign network by extending a SIM card with a multi-identifier network system is further provided.

[0005] To this end, the present invention provides a method for constructing a trusted sovereign network by extending a SIM card with a multi-identifier network system, including the following steps: Step S1, authenticate the SIM card through the client of the multi-identifier network system and connect the SIM card to the multi-identifier network system; Step S2, perform identity signature and signature verification in the multi-identifier network system; Step S3, perform network packet addressing in the multi-identifier network system through the SIM card; Wherein, the step S1 includes the following sub-steps: Step S101: Initiate a registration and login request by inputting the mobile phone number corresponding to the SIM card. Step S102: The client of the multi-identifier network system carries the mobile phone number and its local account information and sends a registration and login request to the multi-identifier router MIR. Step S103: Input the mobile phone number, request SIM card authentication, return and cache the transaction ID, and set the operation result to be pending. Step S104: Asynchronously notify the user to confirm authorization and modify the cached operation result according to the transaction ID. Step S105: Input the transaction ID, poll to judge the user authorization result, and complete registration and login. Step S106: Return the queried operation result. Until the operation result is determined, maintain the login state; otherwise, return to Step S105 and repeat the loop process until the operation result is determined.

[0006] A further improvement of the present invention is that the step S104 includes the following sub-steps: Step S1041: Asynchronously notify the user to confirm authorization to determine the account for registering the multi-identifier network system. Step S1042: Wait for the user operation, where the user operation includes confirm, cancel, and timeout. Step S1043: According to the user operation, asynchronously notify the multi-identifier management system MIS through a callback and input the transaction ID. Step S1044: Modify the cached operation result according to the transaction ID. Step S1045: Respond to the user operation.

[0007] A further improvement of the present invention is that the step S105 includes the following sub-steps: Step S1051: Input the transaction ID and request to query the registration and login results through the multi-identifier router MIR. Step S1052: Query the cached operation result according to the transaction ID. If the operation result is determined, register and log in through the multi-identifier management system MIS. Step S1053: Return the queried operation result.

[0008] A further improvement of the present invention is that the step S2 includes the following sub-steps: Step S201: Implement signature based on the user's private key. After confirming that the private key is not empty, first select the corresponding signature method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the private key to the private key type of the SM2 algorithm, and call the p.Sign digital signature method to perform signature. Step S202: Implement signature verification based on the user's public key. After verifying that the public key is not empty, first select the corresponding verification method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the public key to the public key type of the SM2 algorithm, and call the p.Sign verification method for verification.

[0009] A further improvement of the present invention is that the step S3 includes the following sub-steps: Step S301: When a multi-identifier network packet flows in, send the International Mobile Subscriber Identity (IMSI) corresponding to the SIM card to the multi-identifier network system. Step S302: Read the data link layer data segment and decode the multi-identifier network packet through TLV encoding. Among them, the multi-identifier network packet includes four regions, namely the identifier region, the signature region, the read-only region, and the variable region. Each region consists of one or more TLV-encoded triples. TLV encoding divides the binary data block into three intervals. The outermost interval is the Type field, indicating the type of the current data block. The middle interval is the Length field, indicating the length of the Value field. The last interval is the Value field, used to store the data block. Step S303: Determine whether the decoding of the multi-identifier network packet is successful. If not, discard the multi-identifier network packet and end the processing flow. If so, jump to step S304. Step S304: Check the destination identifier region field of the multi-identifier network packet and determine whether there is a next unprocessed identifier in the destination identifier region. If there is no identifier or the identifier has been processed in the destination identifier region, discard the multi-identifier network packet and end the processing flow. If there is a next unprocessed identifier in the destination identifier, jump to step S305. Step S305: Read the next unprocessed identifier and determine whether the current multi-identifier router can resolve and process the identifier based on the identifier type number of the identifier. If not, that is, it cannot resolve and process the identifier, return to step S304 to continue determining whether there is a next unprocessed identifier in the destination identifier region. If so, jump to step S306. Step S306: Call the processing flow, read and parse the value of the identifier, and call the corresponding processing function to process the multi-identifier network packet according to the value of the identifier and the identifier type number, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet from the specified port. Step S307: Determine whether the processing of the multi-identifier network packet is successful. If not, return to step S304 to continue determining whether there is a next unprocessed identifier in the destination identifier region. If so, end the processing flow.

[0010] A further improvement of the present invention is that in step S3, when a multi-identity network packet carrying multiple identifiers enters the multi-identity router MIR, the multi-identity router MIR processes the multiple identifiers concurrently.

[0011] A further improvement of the present invention is that the process of the multi-identity router MIR processing multiple identifiers concurrently includes: Step A1, extracting all the identifiers in the multi-identity network group, and determining the identifier types supported by the multi-identity router MIR through the identifier filter; Step A2: duplicating the data according to the number of supported identifiers and sending them to different identifier processing units for processing. After receiving the processing tasks, different identifier processing units independently complete the processing of multi-identifier network groups and then summarize the processing results to the decision-making unit. Step A3: the decision unit selects a processing result to be adopted according to the sequence of the identifiers in the multi-identifier network group.

[0012] A further improvement of the present invention is that it also includes an identity authentication step, and the identity authentication step includes: Step B1, generate a random seed , combined with the SIM card's phone number, device ID and timestamp , through the hash function Formula Generate a master key , represents a hash function, The unique identifier of the SIM card; Step B2: The multi-identity network uses the SIM card multi-identity binding mechanism to calculate the value of Calculating the success rate of identity forgery ,in, Indicates the success rate of identity forgery in IP networks, represents the identification dimension enhancement coefficient, Indicates the number of identification dimensions; Step B3: When a malicious attack occurs, the blockchain log in the multi-identity network automatically records the attacker's identity and operation path through the log chain to form an unalterable evidence chain. The log chain adopts a chain hash structure, recorded as ,in, Indicates i The content of the operation, Indicates i −1 operation log hash value.

[0013] A further improvement of the present invention is that it also includes a signature encryption step, and the signature encryption step includes: Step C1, during the data transmission process, each network interaction generates a unique signature through the formula Generate a unique signature , where Indicates using the private key To perform digital signature, Indicates the original data; Step C2, during the data transmission process, the data is encrypted and protected through an asymmetric encryption mechanism. The encryption process is , Indicates the ciphertext after asymmetric encryption, Indicates using the public key To perform asymmetric encryption, Indicates the original data to be encrypted.

[0014] The present invention also provides a system for a multi-identifier network system extended SIM card to form a trusted sovereign network. It adopts the method for a multi-identifier network system extended SIM card to form a trusted sovereign network as described above, and includes: SIM card authentication module, which authenticates the SIM card through the client of the multi-identifier network system and connects the SIM card to the multi-identifier network system; Identity signature and verification module, which performs identity signature and signature verification in the multi-identifier network system; Multi-identifier network packet addressing module, which performs network packet addressing in the multi-identifier network system through the SIM card.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: First, the SIM card is authenticated through the client of the multi-identifier network system, and the SIM card is connected to the multi-identifier network system. Then, the multi-identifier network system performs identity signature and signature verification on the SIM card. Finally, the SIM card performs network packet addressing in the multi-identifier network system. Thus, the SIM card can be used as an effective network identifier to be connected to the multi-identifier network system, realizing the identity authentication and communication of the SIM card in the multi-identifier network system to construct a trusted sovereign network. Furthermore, by combining the advantages of multi-party co-governance, decentralized management, and multi-identifiers of the multi-identifier network system, the unified identity authentication of the SIM card across platforms and networks is achieved, meeting its cross-platform and cross-network identity consistency and security requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 Is a schematic diagram of the working process of an embodiment of the present invention; Figure 2 Is a schematic diagram of the process for implementing SIM card authentication through the multi-identifier network system in an embodiment of the present invention; Figure 3 Is a schematic diagram of the multi-identifier network packet in an embodiment of the present invention; Figure 4 It is a flowchart of multi-identifier network packet processing in an embodiment of the present invention; Figure 5 It is a schematic diagram of concurrent processing of a multi-identifier router in an embodiment of the present invention. Specific embodiments

[0017] Before introducing the specific embodiments of the present invention in detail, the key terms of the present invention and related technologies will be described first.

[0018] CT refers to Communication Technology, representing communication technology; IT refers to Internet Technology, representing Internet technology; ESN refers to Equipment Serial Number, representing the equipment serial number; SIM refers to Subscriber Identity Model, representing the customer identification module; IMEI refers to International Mobile equipment Identity, representing the international mobile equipment identity; TMSI refers to Temporary Mobile Subscriber Identity, representing the temporary mobile subscriber identity; URI refers to Uniform Resource Identifier, representing the uniform resource identifier; SUPI refers to subscription permanent identifier, representing the user permanent identifier; SUCI refers to Subscription Concealed Identifier, representing the user hidden identifier; PEI refers to Permanent Equipment Identifier, representing the permanent equipment identifier; NSSAI refers to Single Network Slice Selection Assistance Information, representing the single network slice selection support information; IMSI refers to International Mobile Subscriber Identification Number, representing the international mobile subscriber identification number.

[0019] The concept of network digital identity has naturally formed with the popularization of the Internet and communication network processes. So far, there is no unified concept and accurate definition of network digital identity globally. There are different definitions of digital identity on the Internet side and the communication network side, and the differences mainly come from different observation perspectives, development needs, and construction ideas of digital identity.

[0020] From the perspective of the Internet, the International Organization for Standardization and the International Electrotechnical Commission believe that digital identity is to solve the identification and trust of objects in the digital space, use network information systems for secure transmission, storage, use and management, and assign a unique corresponding digital identifier to the object and the associated attribute declarations, etc. From the perspective of the communication network, the Telecommunication Standardization Sector of the International Telecommunication Union believes that digital identity is an identifier of an individual or entity in the digital communication and network environment, allowing it to be authenticated and accessed in various online services and applications.

[0021] With the rapid development of the Internet and the communication network, the integration speed of the two has accelerated, and they have jointly become the key core components and important infrastructure supporting the digital world. Especially after the network digital identity enters the "digital identity application period", whether in the definition of digital identity or in actual applications, network digital identity has become a key link in the construction of the trust system in the digital world and supporting the governance of the digital ecosystem.

[0022] Regarding the connotation of network digital identity: In the wave of the digital economy, digital identity is gradually becoming the bridge and link connecting the physical world and the digital world. With the innovation of technology and the expansion of application scenarios, the scope, capabilities and concepts of digital identity have undergone a comprehensive upgrade, and its importance has become increasingly prominent. Digital identity is not only a mapping of the entity's behavior in the digital space, but also the basis for all activities in the digital world.

[0023] The upgrade of the scope, capabilities and concepts of digital identity has led to the expansion of the connotations and extensions of the digital identity subject, carrier and function. First, in terms of the connotation of the digital identity subject, it has expanded from the narrow sense of "natural person" to the broad sense of "human, machine, and object", and from physical entities such as "human, machine, and object" to virtual entities such as "data elements, digital humans", etc., with the coverage gradually expanding and the entities involved gradually increasing. Second, in terms of the connotation of the digital identity carrier, in addition to including "digitalized" legal identity documents such as electronic ID cards, electronic passports and electronic social security cards, it also includes "digitalized" identity credentials such as phone numbers, email addresses, various account vouchers, biometric features and QR codes, etc., and the types of identity carriers are more abundant. Third, in terms of the connotation of the digital identity function, in addition to the function of "proving who I am", it has also expanded the function of "proving the rights and attributes I possess". Through the three core modules of identity identification, identity attributes and identity credentials, the digital identity function is expanded, that is, the entity is uniquely determined through identification, the entity characteristics are described through attributes, and evidence for verifying the entity's identity attributes is provided through credentials. The three together constitute the basis of digital identity, ensuring the correct registration, issuance, verification and management of identity.

[0024] Therefore, whether it is an Internet identity or a communication network identity, there is an urgent need for a digital identity definition and mechanism that can penetrate various industries and has certain inherent attributes of global interoperability to meet the identity and data interoperability needs across physical and virtual spaces, while ensuring the trustworthiness, interoperability, security, and privacy protection of digital identities, providing a foundation for building a more secure, open, and interconnected digital world.

[0025] Regarding the multi-identifier network system, a multi-identifier management mechanism that integrates future networks and existing IP networks is adopted, which is innovative and cutting-edge. The multi-identifier network system, abbreviated as MIN or MIN network, where MIN is the abbreviation of Multi-Identifier Network, is the world's first system that supports the construction of a multilateral co-governed sovereign Internet, aiming to solve the security, governance, and evolution problems faced by the current Internet architecture. The core concept of the MIN network is to achieve the sovereignty independence and interoperability of the cyberspace by supporting multi-identifiers (such as identity identifiers, content identifiers, geographical location identifiers, etc.) and decentralized management.

[0026] The MIN network mainly consists of a multi-identifier management system (MIS) and a multi-identifier router (MIR): Among them, in the multi-identifier management system (MIS, that is, Multi-Identifier System), the identity management system of the MIN network is governed by a multilateral co-governed consortium chain mechanism, and a voting method based on one country, one vote is used to manage the top-level identifier domain names; within each country, it is independently managed through an extensible hierarchical consortium chain. The multi-identifier router (MIR, that is, Multi-Identifier Router) supports multiple identifiers, including identity, content, service, and IP, etc., to achieve a network layer of parallel coexistence. MIN adopts the HPT algorithm of hash table and prefix tree, supporting multi-identifier mutual translation and addressing of tens of billions of entries.

[0027] The MIN network has the following prominent advantages: First, multi-identifier support. MIN supports the parallel existence of multiple identifiers (such as identity, content, IP, etc.), and can flexibly use different identifiers for addressing and routing according to the application scenario. This enables MIN to not only meet the needs of the traditional Internet but also adapt to emerging fields such as the Internet of Things, industrial Internet, and vehicle Internet.

[0028] Second, decentralized governance. MIN adopts blockchain technology and a consortium chain voting mechanism to ensure the fairness and transparency of global network management, avoiding the unilateral monopoly problem brought by the current centralized DNS management; III. High security and data traceability. The MIN network achieves data traceability by using asymmetric encryption technology, ensuring the security of data transmission and privacy protection. The design of MIN gives it inherent security features, enabling it to defend against various network attacks. MIN integrates multiple security technologies such as signature cryptography, authentication, and behavior detection, etc., to build a dynamic security protection model, effectively resisting various network attacks.

[0029] IV. Scalability and flexibility. The multi-identifier routing mechanism and the hierarchical management structure based on the consortium blockchain of MIN endow it with high scalability. Whether in a small-scale enterprise private network or a global sovereign Internet scenario, MIN can provide flexible solutions.

[0030] V. Compatibility with the existing network system. MIN is compatible with existing network architectures such as IPv4 and IPv6, supports gradual evolution and transition, and does not require a complete replacement of existing network devices, reducing the migration cost.

[0031] VI. Identity-driven. MIN takes identity as the core identifier, supports the registration and verification of users' real identities, enhancing the security and transparency of the network. The binding of identity identifiers to devices ensures the traceability of network behaviors.

[0032] Therefore, MIN (abbreviation for Multi-Identifier Network System or Multi-Identifier Network) has broad application prospects, especially in the fields of global Internet governance, security, and emerging technologies. Its core advantages are multilateral co-governance and decentralized management. Combining the support of multiple identifiers and a powerful security mechanism, it can adapt to the development needs of future networks.

[0033] Generally speaking, the MIN network system provides a secure, flexible, and cost-effective network solution through features such as multi-identifier management, decentralized governance, identity-driven, and data traceability. It not only enhances the security and transparency of the network but also promotes international cooperation and technological innovation, adapting to the diverse needs of modern networks. With the continuous change of the network environment, the application prospects of MIN will be even broader.

[0034] Regarding the development of digital identities in communication networks, CT communication network technology and digital identity technology are integrated and developed. Digital identity technology began to be used to identify entities in the first-generation mobile communication technology 1G, but there were relatively large security vulnerabilities. The first-generation mobile communication network technology 1G, represented by AMPS, although belonging to an analog cellular mobile communication system, users and terminal devices still used digital identifiers within the system.

[0035] The second-generation mobile communication technology 2G implemented a solution for separating the identity identification of the "mobile phone and SIM card", effectively reducing security risks. The second-generation mobile communication network technology 2G, represented by GSM, pioneered the "mobile phone and SIM card separation" method, and the mobile phone and the SIM card together constitute the mobile communication terminal device.

[0036] While the third-generation mobile communication technology 3G provides two-way authentication capabilities, it further enriches the types of service identifiers. The third-generation mobile communication network technology 3G, represented by WCDMA, upgraded the SIM card to the Universal Subscriber Identity Module USIM and further supported two-way authentication between the terminal and the network. The 3G mobile communication network enriched and expanded two types of services, namely circuit switching CS and packet switching PS, for users, so that the service identifiers not only cover the MSISDN in the CS domain but also include the access point name APN in the PS domain.

[0037] The fourth-generation mobile communication technology 4G introduced a new IP multimedia identity, enabling IP-based unified communication and identity management. The fourth-generation mobile communication network technology 4G, represented by LTE, stopped the development and evolution of the CS domain, and the IP multimedia subsystem IMS domain took over the audio and video services.

[0038] The fifth-generation mobile communication technology 5G introduced new service identifiers, enabling secure and flexible network slicing services and unified user identity management. In the fifth-generation mobile communication network technology 5G, the subscriber permanent identifier SUPI is equivalent to the IMSI in LTE, with the same format as the IMSI, but the SUPI will never be transmitted over the air interface to prevent tracking users by eavesdropping on wireless signals. The subscriber concealed identifier SUCI is a privacy protection identifier that contains the concealed SUPI and can be transmitted over the air interface. Each terminal device accessing the 5G mobile communication network should have a permanent equipment identifier PEI, corresponding to the IMEI in the LTE network.

[0039] Generally speaking, during the evolution from 1G to 5G, the integration of digital identity technology and mobile communication networks has been continuously deepened, effectively realizing the separation and independent development of device identifiers, user identifiers, and service identifiers. Although the system centered on user identifiers is expected to continue to exist, with the diversification of network terminals and the continuous expansion of service types, the specific form of user identifiers, the types of device identifiers, and service identifiers will all experience more innovations and changes accordingly. Correspondingly, the digital identity technology in mobile networks will also follow this development trend and continue to evolve to adapt to new challenges and requirements.

[0040] Regarding the promotion of digital transformation by the super SIM card, the super SIM card has core advantages of low cost, high popularity, and financial-level security, profoundly changing the traditional identity authentication mode. Compared with traditional U shield devices, the cost of the super SIM card is only one-tenth of theirs, and it also has the convenience of being carried around. In terms of popularity, relying on a user scale of billions and the existing stock of SIM cards, the super SIM card has the ability to cover the globe.

[0041] From a technical architecture perspective, the super SIM card is essentially a micro security computer with powerful hardware, operating system, and application capabilities. Its hardware layer is based on an EAL4+ certified chip, supporting national cryptographic algorithms such as SM2, SM3, and SM4, providing 40KB RAM, a 36MHz CPU, and 1.25M Flash storage space, providing a basic guarantee for efficient operation and secure storage. At the operating system layer, the super SIM card supports multiple encrypted communication protocols, including the card-to-card encrypted channel (7816 protocol), the SMS encrypted channel, the NFC channel (SWP protocol), and the BIP encrypted channel (TCP / IP protocol), enabling secure communication in multiple scenarios. At the application layer, supported by Java Applet and paired with the TSM platform, the super SIM card ensures security domain isolation and card space openness, meeting the requirements of complex multi-application scenarios. This layered architecture gives the super SIM card significant advantages in terms of security, compatibility, and scalability.

[0042] The super SIM card has built a complete application ecosystem in the digital age. Its functions not only cover traditional communication authentication but also extend to identity authentication scenarios such as electronic certificates and digital signatures, as well as support diverse applications such as NFC payment and OTA remote management. As a natural secure hardware carrier, through features such as open APIs, the super SIM card has become an important security infrastructure in the digital age, promoting the digital security transformation of the whole society. In the future, the super SIM card will further strengthen its core position in the digital society with higher technical standards and broader application scenarios, providing a solid guarantee for digital security and identity authentication.

[0043] In an existing technology related to the present invention, the internet protocol (IP), also known as the Internet Protocol, is the network layer communication protocol in the Internet Protocol packet, used for packet switching across network boundaries. Its routing function enables interconnection and essentially establishes the Internet.

[0044] IP is the main protocol in the network layer of the TCP / IP protocol family. Its task is to transfer data packets from the source host to the destination host based only on the IP address in the data packet header. For this purpose, the IP protocol defines the data packet structure for encapsulating the data to be transferred. It also defines the addressing method for labeling datagrams with source and destination information.

[0045] The characteristic of the IP address method is to assign a network address to each terminal, and each packet carries this address as the basis for the network node to forward the packet. The packet structure of the currently widely used IPv4 uses 32 bits as the address field, which is roughly equivalent to only 9 decimal digits. Now, almost all the telephone numbers in big cities in China have adopted 8-digit numbers. It is certain that using a 32-bit address field to identify terminals worldwide is insufficient. Therefore, the problem of this address crisis was realized in the early 1990s, and the IETF began the standardization work of IPv6. IPv6 uses 128 bits as the address field. It seems that this numbering resource will meet the actual needs for a quite long time. The work of expanding the address field seems very natural, but the other two issues associated with the expansion of the address field are quite interesting. One is the popularization of IPv6, and the other is the difficulty brought by the IP network address method to high-speed packet forwarding. The popularization speed of IPv6 is extremely slow. On the one hand, this reflects that through the address segmentation of CIDR, the address reuse through proxy servers, and the dynamic address allocation through ISPs, IPv4 can still cope with the current actual needs. But more importantly, it reflects that the IP address method is too involved with the operation mode of the network. It requires replacing the communication programs of users and changing the packet forwarding modules of routers, almost affecting all devices on the network. The number upgrade work that can be completed overnight on the traditional telephone network may take more than ten years to be possible to complete on the IP network.

[0046] On the traditional telecommunication network, the number for identifying the transceiver terminal and the channel identifier for guiding information forwarding are relatively separated. This makes sense. The potential transceiver terminals may number in the tens of millions or even hundreds of millions, while the operations of a switch or router related to information forwarding are just the selection of dozens, at most hundreds of output ports. Like in the IP network, to find a suitable port among no more than a thousand output ports, it is necessary to search tens of millions of records.

[0047] The existing related technologies have the following disadvantages: The security issues of the IP network include two levels: network security and information security. Network security refers to the attack or damage of the public facilities providing network services, such as the settings of domain name servers or routers being damaged, or their services being maliciously blocked, etc. Information security refers to the leakage or rewriting of the information transmitted on the Internet or stored on the server, etc. How to encrypt information and how to set up a secure and effective information access method are issues related to the network, but they themselves are not network problems. Since information is exposed on the network in electronic form, it is more difficult to maintain its security on the network.

[0048] Moreover, the introduction of the TCP / IP protocol seemingly solved the problem of the basic rules for data transmission in the vast Internet, establishing a set of basic rules for data transmission. To facilitate the determination of the location of each computer and find an identifiable destination for data transmission, the IP protocol labels each node on the network with an address, and this label is the IP address. The IP address adopts the four-segment dotted decimal as the writing rule, such as "211.214.1.XXX". However, based on the principle of non-repetition, the disordered and complex IP combinations impose a burden on computer operators and it is difficult to easily handle a series of disordered numbers. In this way, the disordered and complex IP addresses indirectly raise the threshold for using the Internet and become one of the limiting factors for Internet applications.

[0049] In another prior art related to the present invention, the Named Data Networking (NDN) is adopted. It was proposed in 2010 and its predecessor is the Content-Centric Networking (CCN). It uses the receiver-driven pull-based communication semantics to replace the sender-driven push-based communication semantics in the IP network. In NDN, content consumers obtain content by sending interest packets (Interest) into the network. Any intermediate router or content producer (Producer) that caches the corresponding content will respond with a data packet (Data) when it receives an Interest. Each Interest can pull one Data, and there is a one-to-one correspondence between Interest and Data. NDN designs a Pending Interest Table (PIT) to support the stateful forwarding plane. Each PIT entry records from which network interface the Interest is received. All PIT entry records on the Interest forwarding path construct a reverse path, and the corresponding Data only needs to return along the reverse path constructed by the PIT. Through this pull-based interaction, NDN realizes the decoupling of content and producers and can better support the business scenario of content distribution. To protect the security of content, NDN requires the Producer to sign each sent Data, which enables consumers to trust the content itself without caring about how and from where the content is obtained. Since NDN adopts a subversive architecture design, its compatibility with the existing network architecture remains to be studied.

[0050] This existing technology has the following drawbacks: Although NDN enhances data integrity, source authentication, and correctness through a content signature mechanism, it still faces many privacy and security risks: name privacy, the hierarchical names in interest packets can disclose content information. Especially when the name structure is very intuitive, it may lead to the leakage of user privacy; cache privacy, attackers can obtain access information about the content in the cache through timing analysis; content privacy, although data packets are signed, the content itself is not encrypted, so data leakage cannot be prevented; signature privacy, the signature can expose the identity of the producer, thus infringing on the privacy of individuals or organizations.

[0051] In addition, NDN may face various forms of attacks, including denial-of-service (DoS) attacks, protocol attacks, and timing attacks. Among them, for the denial-of-service (DoS) attack, the DoS attack floods the router's PIT table with a large number of interest packets, thereby blocking legitimate requests. Since the interest packets in NDN do not contain source addresses, it is difficult to trace the attacker. Attackers can generate a large number of invalid interest packets through a botnet, resulting in cache pollution, bandwidth consumption, and exhaustion of network resources. For protocol and timing attacks, protocol attacks utilize the prefix matching mechanism of NDN to infer the content requested by consumers, thereby infringing on name privacy. Timing attacks infer whether the content is cached by measuring the response time, thus obtaining cache privacy.

[0052] Therefore, the present invention aims to combine the operator's SIM card with a multi-identifier network system based on the multi-identifier network system MIN under multilateral co-governance to realize the construction of a sovereign Internet. Furthermore, the traditional SIM card is used as an effective network identifier to access the MIN network, and identity authentication and communication are realized. Moreover, unified identity authentication of the SIM card across platforms and networks is achieved to meet its cross-platform and cross-network identity consistency and security requirements, providing a basis for realizing identity authentication and data intercommunication across physical and virtual spaces.

[0053] The present invention proposes a method and system for an extended SIM card of a multi-identifier network system to form a trusted sovereign network, enabling users to directly use the mobile phone number assigned by their operator as the only identifier to achieve identity authentication and communication in the MIN network. The SIM card will be registered as the only identifier in the identity management system of the MIN network. The identity management system in the MIN network will be connected to the operator's database in real time to verify the legality of the mobile phone number and ensure the uniqueness and accuracy of the user identity.

[0054] During this process, the SIM card not only serves as a traditional communication identifier but can also be associated with other network identifiers of the user (such as device identifier, IP address, etc.) to achieve cross-domain unified identity authentication. Therefore, with just one mobile phone number, users can achieve identity authentication and access globally, across platforms and networks. No matter where the user is, as long as there is a network connection, they can log in to the MIN network through the mobile phone number for secure communication and data interaction.

[0055] The present invention further builds on the national secret security chip and key storage capabilities of the super SIM card, combines PKI asymmetric encryption technology and domestic cryptographic algorithms to create a new type of mobile intelligent password key, which can provide high-security identity authentication and data encryption transmission capabilities in application scenarios such as the human network and the Internet of Things.

[0056] The following will further elaborate on the preferred embodiments of the present invention in conjunction with the accompanying drawings.

[0057] As Figures 1 to 5 shown, this embodiment provides a method for expanding the SIM card of a multi-identifier network system to form a trusted sovereign network, including the following steps: Step S1, authenticate the SIM card through the client of the multi-identifier network system and connect the SIM card to the multi-identifier network system; Step S2, perform identity signature and signature verification in the multi-identifier network system; Step S3, perform network packet addressing in the multi-identifier network system through the SIM card.

[0058] In this embodiment, first, SIM card authentication is implemented on the MIN client, and then the SIM card can be upgraded to the addressing identifier of the MIN network, which is equivalent to newly defining the SIM card as the MIN network identifier. Then, the functions of the MIN client are encapsulated into SDKs (Software Development Kits) applicable to different operating systems, including operating systems such as Android, iOS, and HarmonyOS. Since the encapsulation of the SDK is not within the protection scope and essential technical features of this application, it will not be described in detail herein.

[0059] Step S1 in this embodiment is used to achieve quick authentication and login of the SIM card. Specifically, as Figure 2 shown, Step S1 includes the following sub-steps: Step S101, input the mobile phone number corresponding to the SIM card through the MIN client (i.e., the client of the multi-identifier network system, also known as the multi-identifier network client) to initiate a registration and login request; the login described in this embodiment refers to the quick login of the SIM card; Step S102, the client of the multi-identifier network system carries the mobile phone number and its local account information and sends a registration and login request to the multi-identifier router MIR; Step S103: Query user information from the multi-identity management system (MIS), pass the mobile phone number to the SIM card authentication server, request SIM card quick authentication, return and cache the transaction ID, and set the operation result to be pending. Step S104: Asynchronously notify the user to confirm authorization, and modify the cached operation result according to the transaction ID. Step S105: Pass in the transaction ID, poll to determine the user authorization result, and complete registration and login. Step S106: Return the queried operation result. Keep the login status until the operation result is determined; otherwise, return to Step S105 and repeat the loop until the operation result is determined.

[0060] Preferably, in Step S101 of this embodiment, the C-end customer (i.e., the terminal customer) first opens the MIN client, enters the mobile phone number corresponding to the SIM card, and realizes SIM card quick login by obtaining a verification code or other means. Then, in Step S102, carry the local account information such as the mobile phone number and terminal identifier, obtain user information, and send a registration and login request to the multi-identity router (MIR). Next, in Step S103, query user information from the multi-identity management system (MIS), pass the mobile phone number to the SIM card authentication server to initiate a real-name authentication request, and return user information including the real-name authentication result for SIM card quick authentication. In Step S104, asynchronously send the user information bound to the SIM card to confirm whether to continue registering the main identifier. After the user confirms authorization, verify whether it has been authenticated. If so, respond, that is, modify the cached operation result according to the transaction ID; and complete registration and login through Step S105. During the registration process, preferably, first create a chain account and return the chain account registration result; then query the chain account status and return the registration result. When the returned result is that the transaction is in progress, set the fallback logic to timeout and return a processing prompt. When the returned result is successful registration, callback through the MIN client and maintain the login status.

[0061] Preferably, Step S104 of this embodiment includes the following sub-steps: Step S1041: Asynchronously notify the user to confirm authorization to determine the account for registering the multi-identity network system. Step S1042: Wait for the user operation. The user operations include confirm, cancel, and timeout. Step S1043: According to the user operation, asynchronously callback and notify the multi-identity management system (MIS) and pass in the transaction ID. Step S1044: Modify the cached operation result according to the transaction ID. Step S1045: Respond to the user operation.

[0062] Preferably, step S105 in this embodiment includes the following sub-steps: Step S1051, input the transaction ID, and request to query the registration and login results through the multi-identifier router MIR; Step S1052, query the cached operation result according to the transaction ID. If the operation result is determined, register and log in through the multi-identifier management system MIS; Step S1053, return the queried operation result.

[0063] Step S2 in this embodiment is used to implement MIN network identity signature and verification, and preferably includes the following sub-steps: Step S201, implement signature based on the user's private key. After confirming that the private key is not empty, first select the corresponding signature method according to the public key generation algorithm in the KeyParam key parameter, and then convert the private key (such as id.Prikey) to the private key type of the SM2 algorithm, such as the parameter p of the sm2.Sm2PrivateKey type, and call the p.Sign digital signature method for signature; among them, KeyParam is the key parameter used to specify the public key generation algorithm; the SM2 algorithm is a public key cryptography algorithm based on elliptic curves, used for digital signature and encryption; the signature in this embodiment defaults to the SM2WithSM3 algorithm; Step S202, implement verification based on the user's public key. After verifying that the public key is not empty, first select the corresponding verification method according to the public key generation algorithm in the KeyParam key parameter, and then convert the public key (such as id.Pubkey) to the public key type of the SM2 algorithm, such as the parameter p of the sm2.Sm2PublicKey type, and call the p.Sign verification method for verification. The verification in this embodiment defaults to the SM2WithSM3 algorithm.

[0064] Step S3 in this embodiment is used to implement the network packet addressing process of the SIM card in the MIN, as Figure 4 shown, and preferably includes the following sub-steps: Step S301, when the multi-identifier network packet flows in, send the international mobile subscriber identification number IMSI corresponding to the SIM card to the multi-identifier network system; Step S302, read a data link layer data segment from the network and decode the multi-identifier network packet through TLV encoding; among them, the multi-identifier network packet includes four regions, such as Figure 3As shown, the four regions are the identification region, the signature region, the read-only region, and the variable region; each region consists of one or more TLV-encoded triples (i.e., Type / Length / Value). The TLV encoding divides the binary data block into three intervals. The frontmost interval is the Type field, representing the type of the current data block; the middle interval is the Length field, representing the length of the Value field; and the last interval is the Value field, used to store the data block. Step S303: Determine whether the decoding of the multi-identifier network packet is successful. If not, discard the multi-identifier network packet and end the processing flow; if so, jump to step S304. Step S304: Check the destination identifier area field of the multi-identifier network packet and determine whether there is a next unprocessed identifier in the destination identifier area. If there is no identifier in the destination identifier area or the identifier has been processed, discard the multi-identifier network packet and end the processing flow; if there is a next unprocessed identifier in the destination identifier, jump to step S305. Step S305: Read the next unprocessed identifier and determine whether the current multi-identifier router can resolve and process this identifier based on the identifier type number of this identifier. If not, that is, it cannot resolve and process this identifier, return to step S304 to continue determining whether there is a next unprocessed identifier in the destination identifier area; if so, jump to step S306. Step S306: Process the multi-identifier network packet according to the identifier semantics, that is, call the processing flow, read and parse the value of this identifier, and call the corresponding processing function to process the multi-identifier network packet according to the value of this identifier and the identifier type number, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet from the specified port. Step S307: Determine whether the processing of the multi-identifier network packet is successful. If not, return to step S304 to continue determining whether there is a next unprocessed identifier in the destination identifier area; if so, end the processing flow.

[0065] In this embodiment, IMSI (International Mobile Subscriber Identification Number) is used as the identity identifier of the SIM card. IMSI, that is, the International Mobile Subscriber Identification Code, is the globally unique identification code of the SIM card, consisting of a string of numbers not exceeding 15 digits, and is the credential for the user to access the mobile communication network.

[0066] When a user tries to access a mobile communication network, the mobile phone will send the IMSI code to the network. The network identifies the user's identity and the operator it belongs to by identifying the IMSI code, and thus provides the corresponding services. In addition, the IMSI code can also be used to track and identify mobile device users, playing an important role in cybercrime investigations.

[0067] This embodiment provides a single-thread (single-processor) network packet processing process through steps S301 to S307, and provides a flow chart of a network packet forwarder processing a network packet, such as Figure 4 The figure shows the complete process of a single-core router processing a network packet.

[0068] Since the support of multiple identifiers by the multi-identity router MIR can be completely isolated from each other, in the software-implemented forwarder, a multi-core processor can be used to forward network packets carrying different identifiers. Therefore, in step S3 of this embodiment, when a multi-identity network packet carrying multiple identifiers enters the multi-identity router MIR, the multi-identity router MIR processes the multiple identifiers concurrently, such as Figure 5 The FIB table refers to the Forwarding Information Base, i.e., the query forwarding table, which is used to implement query and forwarding processing in the identification processing unit.

[0069] In this embodiment, the process of the multi-identity router MIR concurrently processing multiple identifiers includes: Step A1, extracting all the identifiers in the multi-identity network group, and determining the identifier types supported by the multi-identity router MIR through the identifier filter; Step A2: duplicating the data according to the number of supported identifiers and sending them to different identifier processing units for processing. After receiving the processing tasks, different identifier processing units independently complete the processing of multi-identifier network groups and then summarize the processing results to the decision-making unit. Step A3: the decision unit selects a processing result to be adopted according to the sequence of the identifiers in the multi-identifier network group.

[0070] For example, in Figure 5 In the example, the identifiers 101 and 103 carried in the multi-identifier network packet are both identifier types supported by the current router, so the incoming network packet is copied into two copies and distributed to two different identifier processing units for processing, and different identifier processing units can independently run on different CPUs or different CPU cores. After receiving the multi-identifier network packet processing task, different identifier processing units independently complete the processing of the multi-identifier network packet, and each identifier processing unit summarizes the processing results to the decision unit.

[0071] likeFigure 5 As shown, the priority of identifier 103 in the network packet is higher than that of identifier 101. Therefore, if the processing result of identifier 103 is normal, that is, the result of the identifier processing unit is not to discard the multi-identifier network packet, the decision unit adopts the processing result of the identifier processing unit corresponding to identifier 103, and ignores the result of the identifier processing unit corresponding to identifier 101. Only when the processing result corresponding to identifier 103 is to discard the multi-identifier network packet, the decision unit adopts the processing result of the identifier processing unit corresponding to identifier 101.

[0072] Therefore, in the parallel multi-identity router MIR of this embodiment, all the identifiers in the multi-identity network group are first extracted, and different identifier processing units independently complete the processing of the multi-identity network group after receiving the processing task of the multi-identity network group, and then each identifier processing unit summarizes the processing results to the decision unit. The decision unit decides which identifier processing unit's processing result to use according to the order of each identifier in the multi-identity network group.

[0073] To summarize, this embodiment first implements the authentication of the SIM card through the client of the multi-identity network system, connects the SIM card to the multi-identity network system, and then signs and verifies the identity of the SIM card through the multi-identity network system. Finally, network group addressing is performed in the multi-identity network system through the SIM card, and then the SIM card can be connected to the multi-identity network system as a valid network identifier to realize the identity authentication and communication of the SIM card in the multi-identity network system, so as to build a trusted sovereign network, and then combine the advantages of multilateral co-management, decentralized management and multiple identifiers of the multi-identity network system to realize unified identity authentication of the SIM card across platforms and networks, meet its identity consistency and security requirements across platforms and networks, and provide a basis for identity authentication and data interoperability across physical spaces and virtual spaces.

[0074] This embodiment proposes a method and system for building a trusted sovereign network by extending the SIM card based on MIN (Multi-Identifier Network). By connecting the traditional SIM card to the MIN network, it is upgraded from a single communication identifier to a multi-identifier network identity identifier, and identity authentication, data encryption and cross-domain access are realized, thus building a sovereign Internet architecture with both decentralized management and global interconnection capabilities. It solves the technical problems that identity authentication in traditional IP networks mainly relies on centralized services, it is difficult to ensure identity consistency and security across platforms and networks, and it is difficult to achieve real-time traceability and behavior locking when attacked. This embodiment significantly improves the security of identity authentication and the trust of cyberspace through the MIN network architecture.

[0075] In the MIN network, the top-level identifier is jointly managed by multiple countries, ensuring multilateral co-governance of the cyberspace and global connectivity; the lower-level identifiers are independently managed by each country, ensuring sovereignty and autonomy. By embedding a national cryptographic security chip and PKI asymmetric encryption technology in the SIM card, the SIM card can generate a unique master key , and construct a unique identity mapping of the SIM card in the MIN network.

[0076] Specifically, this embodiment preferably further includes an identity authentication step, and the identity authentication step includes: Step B1, first generate a random seed , and combine the mobile phone number, device ID and timestamp of the SIM card , and generate a master key through the formula of the hash function , represents the hash function, represents the unique identity identifier of the SIM card; the master key is used to uniquely identify the SIM card in the MIN network, and all subsequent identity-related operations (such as registering the main identifier, generating sub-identifiers, and verifying identities) are based on this master key for binding and verification, ensuring a one-to-one correspondence between the SIM card identity and device behavior, and preventing forgery; Step B2, the multi-identifier network calculates the identity forgery success rate through the SIM card multi-identifier binding mechanism by the formula , where represents the success rate of identity forgery in the IP network; represents the identifier dimension enhancement coefficient, and this identifier dimension enhancement coefficient is set by the system according to the security policy, and the default value is in the range of 0.01 - 0.1; represents the number of identifier dimensions, including SIM card ID, device ID, and IP address, etc.; Step B3, when a malicious attack behavior occurs, the blockchain log in the multi-identifier network automatically records the identity and operation path of the attacker through the log chain, forming an immutable evidence chain. The log chain adopts a chained hash structure, denoted as , where represents the content of the i th operation, represents the log hash value of the i −1th operation.

[0077] In step B1 of this embodiment, the random seed The generation process can call the secure entropy source in the SIM card chip through a standardized interface (such as the PKCS#11 interface) and be completed inside the SIM card. This process is completed inside the SIM card without being exported, which can avoid the risks of man-in-the-middle attacks and seed leakage.

[0078] Due to the collaborative verification of multiple independent identifiers, it is difficult for attackers to break through all security mechanisms in a short time, and the security is significantly enhanced. When malicious attack behaviors occur, the blockchain logs in the multi-identifier network automatically record the identities and operation paths of the attackers through the log chain, forming an immutable evidence chain. This log chain adopts a chained hash structure . Therefore, even in the event of malicious tampering, the data on the chain can be completely preserved and traced.

[0079] That is to say, the main technical problem to be solved in this embodiment is how to realize the expansion and authentication of SIM cards based on the multi-identifier network system, upgrade the traditional SIM card from a single communication access tool to a trusted network identity identifier, and achieve cross-domain identity authentication and high-security communication globally. In the traditional Internet system, SIM cards are mainly used for mobile communication access and cannot meet the high-security requirements of multi-identifier and multi-domain identity authentication in the future sovereign Internet. This embodiment introduces the MIN system to build a trusted sovereign network with the SIM card as the core, improving the network space governance ability and user identity protection level.

[0080] In this embodiment, by connecting the SIM card to the MIN network, the multi-dimensional expansion of the SIM card identity identifier is realized, making the mobile phone number not only a communication identifier but also a unified authentication entry for multiple identifiers such as the identity identifier (ID), geographical location identifier (LID), and device identifier (DID). This unified identity management mechanism effectively guarantees the sovereignty independence and decentralized interconnection of the network space. During the identity authentication process, the SIM card uses the built-in national cryptography security chip to generate the master key , encrypts the authentication information and uploads it to the MIN network identity management system to ensure the uniqueness and credibility of the user's identity in cross-platform, cross-network, and cross-region scenarios.

[0081] Preferably, this embodiment also realizes the end-to-end encrypted communication of the SIM card through the PKI asymmetric encryption technology. That is, this embodiment preferably further includes a signature encryption step, and the signature encryption step includes: Step C1, during the data transmission process, each network interaction generates a unique signature through the formula , where represents digital signature using the private key , and represents the original data; a unique signature is adopted during the data transmission process , which can not only verify the authenticity of data, but also be verified when the data reaches the destination to prevent data from being tampered with or forged; Step C2, during the data transmission process, encrypt and protect the data through an asymmetric encryption mechanism. The encryption process is , represents the ciphertext after asymmetric encryption, represents using the public key to perform asymmetric encryption, represents the original data to be encrypted.

[0082] The above signature and encryption steps adopted in this embodiment belong to a dual mechanism, which can ensure the confidentiality and integrity of data during transmission and prevent man-in-the-middle attacks or data tampering. Even if the communication path is eavesdropped, the attacker cannot decrypt the data content or forge data packets.

[0083] On this basis, through steps B1 to B3, the multi-party co-governed log system of the MIN network records each authentication and data interaction on the chain, forming an immutable behavior log based on blockchain technology, realizing fast traceability and evidence collection of attack behaviors. Once the attacker's behavior trajectory is recorded on the chain, it will be permanently archived, providing a good basis for the evidence storage mechanism.

[0084] In summary, this embodiment can expand the identity authentication function of the SIM card through the multi-identifier network system, and construct a trusted sovereign network with the SIM card as the core. This embodiment upgrades the SIM card from a traditional communication tool to the core carrier of network identity authentication, and can further utilize national cryptography algorithms and PKI encryption means to ensure the uniqueness of user identities, the accuracy of authentication, and the security of communications, comprehensively improving the security governance ability of future cyberspace and the level of user privacy protection.

[0085] This embodiment also provides a system for expanding the SIM card by the multi-identifier network system to form a trusted sovereign network, which adopts the method of expanding the SIM card by the multi-identifier network system as described above, and includes: The SIM card authentication module realizes the authentication of the SIM card through the client of the multi-identifier network system and connects the SIM card to the multi-identifier network system; The identity signature and verification module is used for identity signature and signature verification in the multi-identifier network system; The multi-identifier network packet addressing module performs network packet addressing in the multi-identifier network system through the SIM card.

[0086] The above content is a further detailed description of the present invention in combination with specific preferred embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. A method for a multi - identification network system to expand a SIM card to form a trusted sovereign network, characterized in that It includes the following steps: Step S1, authenticate the SIM card through the client of the multi-identity network system and connect the SIM card to the multi-identity network system; Step S2, perform identity signature and verification in the multi-identity network system; Step S3, perform network packet addressing in the multi-identity network system through the SIM card; Among them, step S1 includes the following sub-steps: Step S101, initiate a registration and login request by inputting the mobile phone number corresponding to the SIM card; Step S102, the client of the multi-identity network system carries the mobile phone number and its local account information and sends a registration and login request to the multi-identity router MIR; Step S103, input the mobile phone number, request to perform SIM card authentication, return and cache the transaction ID, and set the operation result to be pending; Step S104, asynchronously notify the user to confirm authorization and modify the cached operation result according to the transaction ID; Step S105, input the transaction ID, poll to judge the user authorization result, and complete registration and login; Step S106, return the queried operation result. Until the operation result is determined, maintain the login state; otherwise, return to step S105 and repeat the loop process until the operation result is determined.

2. The method for the multi-identifier network system to expand the SIM card to form a trusted sovereign network according to claim 1, characterized in that, Step S104 includes the following sub-steps: Step S1041, asynchronously notify the user to confirm authorization to determine the account for registering the multi-identity network system; Step S1042, wait for the user operation. The user operation includes confirm, cancel, and timeout; Step S1043, according to the user operation, asynchronously notify the multi-identity management system MIS through a callback and input the transaction ID; Step S1044, modify the cached operation result according to the transaction ID; Step S1045, respond to the user operation.

3. The method for expanding a SIM card with multiple identifiers in the network system according to claim 1 to form a trusted sovereign network, characterized in that, Step S105 includes the following sub-steps: Step S1051, input the transaction ID, and request to query the registration and login results through the multi-identity router MIR; Step S1052, query the cached operation result according to the transaction ID. If the operation result is determined, register and log in through the multi-identity management system MIS; Step S1053, return the queried operation result.

4. The method for a multi-identifier network system to expand a SIM card to form a trusted sovereign network according to any one of claims 1 to 3, characterized in that, Step S2 includes the following sub-steps: Step S201, implement signature based on the user's private key. After confirming that the private key is not empty, first select the corresponding signature method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the private key to the private key type of the SM2 algorithm, and call the p.Sign digital signature method to perform signature; Step S202, implement verification based on the user's public key. After verifying that the public key is not empty, first select the corresponding verification method according to the public key generation algorithm in the KeyParam key parameter, then convert the type of the public key to the public key type of the SM2 algorithm, and call the p.Sign verification method to perform verification.

5. The method for the multi-identifier network system to expand the SIM card to form a trusted sovereign network according to any one of claims 1 to 3, characterized in that, Step S3 includes the following sub-steps: Step S301, when the multi-identity network packet flows in, send the international mobile subscriber identification number IMSI corresponding to the SIM card to the multi-identity network system; Step S302, read the data link layer data segment, and decode the multi-identifier network group through TLV encoding; wherein the multi-identifier network group includes four areas, namely, the identification area, the signature area, the read-only area and the variable area; each area is composed of one or more TLV-encoded triplets, and the TLV encoding divides the binary data block into three intervals, the front-end interval is the Type field, indicating the type of the current data block; the middle interval is the Length field, indicating the length of the Value field; the last interval is the Value field, which is used to store the data block; Step S303, determining whether the decoding of the multi-identifier network packet is successful, if not, discarding the multi-identifier network packet and ending the processing flow; if yes, jumping to step S304; Step S304, check the destination identifier field of the multi-identifier network packet to determine whether there is a next unprocessed identifier in the destination identifier field; if there is no identifier in the destination identifier field or the identifier has been processed, discard the multi-identifier network packet and the processing flow ends; if there is a next unprocessed identifier in the destination identifier, jump to step S305; Step S305, read the next unprocessed identifier, and determine whether the current multi-identity router can parse and process the identifier by the identifier type number of the identifier. If not, that is, the identifier cannot be parsed and processed, return to step S304 to continue to determine whether there is a next unprocessed identifier in the destination identifier area; if so, jump to step S306; Step S306, calling the processing flow, reading and parsing the value of the identifier, and calling the corresponding processing function to process the multi-identifier network packet according to the value of the identifier and the identifier type number, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet from the specified port; Step S307, determine whether the processing of the multi-identifier network group is successful. If not, return to step S304 to continue to determine whether there is a next unprocessed identifier in the destination identifier area; if so, the processing flow ends.

6. The method for a multi-identifier network system to expand a SIM card to form a trusted sovereign network according to any one of claims 1 to 3, characterized in that, In step S3, when a multi-identity network packet carrying multiple identifiers enters the multi-identity router MIR, the multi-identity router MIR processes the multiple identifiers concurrently.

7. The method for the multi-identifier network system extended SIM card to form a trusted sovereign network according to claim 6, wherein The process of the multi-identity router MIR processing multiple identifiers concurrently includes: Step A1, extracting all the identifiers in the multi-identity network group, and determining the identifier types supported by the multi-identity router MIR through the identifier filter; Step A2: duplicating the data according to the number of supported identifiers and sending them to different identifier processing units for processing. After receiving the processing tasks, different identifier processing units independently complete the processing of multi-identifier network groups and then summarize the processing results to the decision-making unit. Step A3: the decision unit selects a processing result to be adopted according to the sequence of the identifiers in the multi-identifier network group.

8. The method for a multi-identifier network system extended SIM card to form a trusted sovereign network according to any one of claims 1 to 3, characterized in that, The identity authentication step is also included, and the identity authentication step includes: Step B1, first generate a random seed , and combine the mobile phone number of the SIM card, the device ID, and the timestamp , and generate the master key through the formula of the hash function . Generate the master key , represents the hash function, represents the unique identity identifier of the SIM card; Step B2, the multi-identity network calculates the identity forgery success rate through the SIM card multi-identity binding mechanism using the formula to calculate the identity forgery success rate , where represents the success rate of identity forgery in the IP network, represents the identity dimension enhancement coefficient, represents the number of identity dimensions; Step B3, when a malicious attack occurs, the blockchain logs in the multi-identity network automatically record the identity and operation path of the attacker through the log chain, forming an immutable evidence chain. The log chain adopts a chained hash structure, denoted as , where represents the content of the i th operation, and represents the log hash value of the i −1th operation.

9. The method for the multi - identity network system to expand the SIM card to form a trusted sovereign network according to any one of claims 1 to 3, characterized in that, The step of signature encryption is also included, and the step of signature encryption includes: Step C1, during data transmission, each network interaction generates a unique signature through the formula Generate a unique signature , where Indicates the use of the private key For digital signature Indicates the original data; Step C2, during the data transmission process, the data is encrypted and protected through an asymmetric encryption mechanism. The encryption process is , represents the ciphertext after asymmetric encryption, represents using the public key to perform asymmetric encryption, represents the original data to be encrypted.

10. A system for a multi - identity network system to expand a SIM card to form a trusted sovereign network, characterized in that, A method for constructing a trusted sovereign network using a multi-identity network system extended SIM card as described in any one of claims 1 to 9, and includes: A SIM card authentication module, which authenticates the SIM card through the client of the multi-identity network system and connects the SIM card to the multi-identity network system; An identity signature and verification module, which is used for identity signature and signature verification in the multi-identity network system; A multi-identity network packet addressing module, which performs network packet addressing in the multi-identity network system through the SIM card.

Citation Information

Patent Citations

  • High-security mobile office network based on multi-identification network system

    CN112291295A

  • Multi-side co-management multi-identification space-ground integrated intelligent network connection automobile high-safety private network system

    CN115296826A

  • Method and system for ensuring credibility and security of network space

    CN119155055A

  • Method for secure ATM transactions using a portable device

    US20140358777A1