Method and system for extending SIM card in multi-identity network system to form trusted sovereign network

Through the multi-identification network system, SIM cards are expanded to realize authentication, signature and addressing, solving the identity consistency and security issues across platforms and cross-networks, and providing high security and cross-space interoperability with identity authentication.

CN120321655BActive Publication Date: 2025-08-29PEKING UNIV SHENZHEN GRADUATE SCHOOL +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510797331.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-08-29
Estimated Expiration
2045-06-16

AI Technical Summary

Technical Problem

Existing SIM cards have problems with difficult identity consistency and security in cross-platform and cross-network identity authentication, especially when they are attacked, it is difficult to achieve real-time traceability and behavioral locking.

Method used

Through the multi-identification network system, SIM cards are expanded to realize SIM cards authentication, identity signature and signature verification, and network packet addressing. Combined with multilateral co-management and decentralized management, SM2 algorithm is used for digital signature and asymmetric encryption, and a hash function is used to generate unique identity identifiers, and attack behavior is recorded through blockchain.

Benefits of technology

It realizes cross-platform and cross-network unified identity authentication of SIM cards in the multi-identity network system, meets the needs of identity consistency and security, provides the advantages and high security of multiple identifiers, and supports identity authentication and data interoperability across physical and virtual spaces.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321655B_ABST
    Figure CN120321655B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for extending a multi-identity network system with a SIM card to form a trusted sovereign network, comprising the following steps: Step S1, authenticating the SIM card through a client of the multi-identity network system, and connecting the SIM card to the multi-identity network system; Step S2, performing identity signing and signature verification in the multi-identity network system; Step S3, performing network group addressing in the multi-identity network system through the SIM card; Step S1 is used to implement quick authentication and login of the SIM card. The present invention can connect the SIM card to the multi-identity network system as a valid network identifier, implement identity authentication and communication of the SIM card in the multi-identity network system, and build a trusted sovereign network. Furthermore, by combining the advantages of multilateral co-management, decentralized management, and multiple identifiers of the multi-identity network system, unified identity authentication of the SIM card across platforms and networks is implemented, meeting its identity consistency and security requirements across platforms and networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for forming a trusted sovereign network, in particular to a method for forming a trusted sovereign network by extending a SIM card through a multi-identification network system, and to a system adopting the method for forming a trusted sovereign network by extending a SIM card through a multi-identification network system. Background Art

[0002] With the accelerating transformation of society toward digitalization and intelligence, secure connectivity and identity authentication have become fundamental and rigid requirements. Against this backdrop, SIM cards, as a natural carrier of security authentication, have gradually transitioned from the communications sector to the identity authentication sector through technological upgrades, becoming a key pillar of security services in the digital age. However, existing SIM card applications utilize a single communication identifier, and their traditional IP network authentication relies primarily on centralized services. This makes it difficult to achieve unified SIM card authentication across platforms and networks, ensuring identity consistency and security across platforms and networks. Furthermore, real-time traceability and behavior targeting are difficult in the event of an attack.

[0003] Therefore, whether it is an Internet identity or a communication network identity, there is an urgent need to provide a digital identity definition and mechanism that can connect various industries and has certain global interoperability inherent properties to meet the unified identity authentication of SIM cards across platforms and networks, and meet its identity consistency and security requirements across platforms and networks. Summary of the Invention

[0004] The technical problem to be solved by this invention is to provide a method for extending a multi-identity network system with a SIM card to form a trusted sovereign network. This method aims to connect a SIM card as a valid network identifier to the multi-identity network system, enabling identity authentication and communication for the SIM card within the multi-identity network system, building a trusted sovereign network, and further achieving unified identity authentication for SIM cards across platforms and networks, thereby meeting the requirements for identity consistency and security across platforms and networks. Furthermore, a system that utilizes this method for extending a multi-identity network system with a SIM card to form a trusted sovereign network is also provided.

[0005] To this end, the present invention provides a method for extending a SIM card in a multi-identity network system to form a trusted sovereign network, comprising the following steps:

[0006] Step S1: authenticating the SIM card through the client of the multi-identity network system and connecting the SIM card to the multi-identity network system;

[0007] Step S2: identity signing and signature verification in the multi-identity network system;

[0008] Step S3, performing network group addressing in a multi-identity network system through the SIM card;

[0009] Wherein, the step S1 includes the following sub-steps:

[0010] Step S101, initiating a registration and login request by inputting the mobile phone number corresponding to the SIM card;

[0011] Step S102: The client of the multi-identity network system sends a registration and login request to the multi-identity router MIR with the mobile phone number and its local account information;

[0012] Step S103: input the mobile phone number, request SIM card authentication, return and cache the transaction ID, and set the operation result to pending operation;

[0013] Step S104: asynchronously notifying the user to confirm the authorization and modifying the cached operation result according to the transaction ID;

[0014] Step S105: Pass in the transaction ID, poll to determine the user authorization result, and complete the registration and login;

[0015] Step S106, returns the query operation result, and maintains the login status until the operation result is confirmed; otherwise, returns to step S105 and repeats the loop process until the operation result is confirmed.

[0016] A further improvement of the present invention is that step S104 includes the following sub-steps:

[0017] Step S1041, asynchronously notifying the user to confirm authorization to confirm the account number for registering the multi-identity network system;

[0018] Step S1042, waiting for user operation, which includes confirmation, cancellation and timeout;

[0019] Step S1043: Notify the multi-identity management system MIS through asynchronous callback according to the user operation, and pass in the transaction ID;

[0020] Step S1044, modifying the cached operation result according to the transaction ID;

[0021] Step S1045, responding to user operations.

[0022] A further improvement of the present invention is that step S105 includes the following sub-steps:

[0023] Step S1051: The transaction ID is passed in and the registration and login results are queried through the multi-identity router (MIR).

[0024] Step S1052: query the cached operation result according to the transaction ID. If the operation result is positive, register and log in through the multi-identity management system MIS;

[0025] Step S1053: Return the query operation result.

[0026] A further improvement of the present invention is that step S2 includes the following sub-steps:

[0027] Step S201: Signing based on the user's private key. After confirming that the private key is not empty, the corresponding signature method is selected according to the public key generation algorithm in the KeyParam key parameter. The private key is then converted to the private key type of the SM2 algorithm, and the p.Sign digital signature method is called to sign.

[0028] Step S202: Verify the signature based on the user's public key. After verifying that the public key is not empty, first select the corresponding verification method based on the public key generation algorithm in the KeyParam key parameter, then convert the public key to the public key type of the SM2 algorithm, and call the p.Sign verification method for verification.

[0029] A further improvement of the present invention is that step S3 includes the following sub-steps:

[0030] Step S301, when a multi-identity network packet flows in, the International Mobile Subscriber Identity (IMSI) corresponding to the SIM card is sent to the multi-identity network system;

[0031] Step S302: Read the data link layer data segment and decode the multi-identifier network packet using TLV encoding. The multi-identifier network packet includes four areas: an identification area, a signature area, a read-only area, and a variable area. Each area consists of one or more TLV-encoded triplets. The TLV encoding divides the binary data block into three intervals: the first interval is the Type field, indicating the type of the current data block; the middle interval is the Length field, indicating the length of the Value field; and the last interval is the Value field, which is used to store the data block.

[0032] Step S303, determining whether the decoding of the multi-identifier network packet is successful. If not, the multi-identifier network packet is discarded and the processing flow ends; if yes, jump to step S304;

[0033] Step S304: Check the destination identifier field of the multi-identifier network packet to determine whether there is an unprocessed identifier in the destination identifier field. If there is no identifier in the destination identifier field or the identifier has been processed, the multi-identifier network packet is discarded and the processing flow ends. If there is an unprocessed identifier in the destination identifier field, jump to step S305.

[0034] Step S305: Read the next unprocessed identifier and determine whether the current multi-identity router can parse and process the identifier based on the identifier type number of the identifier. If not, that is, it cannot parse and process the identifier, then return to step S304 to continue to determine whether there is another unprocessed identifier in the destination identifier area; if so, jump to step S306;

[0035] Step S306: Invoke the processing flow, read and parse the value of the identifier, and call the corresponding processing function based on the identifier value and the identifier type number to process the multi-identifier network packet, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet out of the specified port;

[0036] Step S307, determine whether the processing of the multi-identifier network group is successful. If not, return to step S304 to continue to determine whether there is an unprocessed identifier in the destination identifier area; if so, the processing flow ends.

[0037] A further improvement of the present invention is that in step S3, when a multi-identity network packet carrying multiple identifiers enters the multi-identity router MIR, the multi-identity router MIR processes the multiple identifiers concurrently.

[0038] A further improvement of the present invention is that the process of the multi-identity router MIR concurrently processing multiple identifiers includes:

[0039] Step A1, extracting all identifiers in the multi-identity network group, and determining the identifier types supported by the multi-identity router MIR through an identifier filter;

[0040] Step A2: Duplicate the data according to the number of supported identifiers and send them to different identifier processing units for processing. After receiving the processing task, different identifier processing units independently complete the processing of the multi-identifier network group and then summarize the processing results to the decision unit;

[0041] In step A3, the decision unit selects a processing result to be adopted according to the order of the identifiers in the multi-identifier network group.

[0042] A further improvement of the present invention is that it further includes an identity authentication step, which includes:

[0043] Step B1: Generate a random seed , combined with the SIM card's phone number, device ID, and timestamp , through the hash function Formula Generate a master key , represents a hash function, Indicates the unique identifier of the SIM card;

[0044] Step B2: The multi-identity network uses the SIM card multi-identity binding mechanism to calculate the value of the multi-identity network. Calculating the identity forgery success rate ,in, Indicates the success rate of identity forgery in IP networks, represents the identification dimension enhancement coefficient, Indicates the number of identification dimensions;

[0045] Step B3: When a malicious attack occurs, the blockchain log in the multi-identity network automatically records the attacker's identity and operation path through the log chain, forming an unalterable evidence chain. The log chain adopts a chain hash structure, which is recorded as ,in, Indicates the i The content of the operation, Indicates the i −1 operation log hash value.

[0046] A further improvement of the present invention is that it further includes a signature encryption step, which includes:

[0047] Step C1: During data transmission, each network interaction is performed by formula Generate a unique signature ,in, Indicates the use of private key Digitally sign, Represents the original data;

[0048] Step C2: During the data transmission process, the data is encrypted and protected by an asymmetric encryption mechanism. The encryption process is: , Represents the ciphertext after asymmetric encryption, Indicates the use of public key Perform asymmetric encryption, Indicates the original encrypted data.

[0049] The present invention also provides a system for forming a trusted sovereign network by extending a SIM card in a multi-identification network system, which adopts the method for forming a trusted sovereign network by extending a SIM card in a multi-identification network system as described above, and includes:

[0050] SIM card authentication module, which realizes SIM card authentication through the client of the multi-identity network system and connects the SIM card to the multi-identity network system;

[0051] Identity signing and verification module, which performs identity signing and verification in a multi-identity network system;

[0052] The multi-identity network group addressing module performs network group addressing in a multi-identity network system through a SIM card.

[0053] Compared with the prior art, the beneficial effects of the present invention are: first, the SIM card authentication is realized through the client of the multi-identity network system, the SIM card is connected to the multi-identity network system, and then the identity signature and signature of the SIM card are performed through the multi-identity network system. Finally, the network group addressing is performed in the multi-identity network system through the SIM card, and then the SIM card can be connected to the multi-identity network system as a valid network identifier, realizing the identity authentication and communication of the SIM card in the multi-identity network system, so as to build a trusted sovereign network, and then combining the advantages of multilateral co-management, decentralized management and multiple identifiers of the multi-identity network system, realizing unified identity authentication of the SIM card across platforms and networks, and meeting its identity consistency and security requirements across platforms and networks. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 This is a schematic diagram of the workflow of an embodiment of the present invention;

[0055] Figure 2 This is a flow chart of implementing SIM card authentication through a multi-identity network system according to an embodiment of the present invention;

[0056] Figure 3 This is a schematic diagram of a multi-identity network grouping according to an embodiment of the present invention;

[0057] Figure 4 This is a flowchart of multi-identifier network grouping processing according to an embodiment of the present invention;

[0058] Figure 5 This is a schematic diagram of concurrent processing of a multi-identity router according to an embodiment of the present invention. DETAILED DESCRIPTION

[0059] Before describing the specific embodiments of the present invention in detail, the key terms and related technologies of the present invention are first explained.

[0060] CT stands for Communication Technology; IT stands for Internet Technology; ESN stands for Equipment Serial Number; SIM stands for Subscriber Identity Model; IMEI stands for International Mobile Equipment Identity; TMSI stands for Temporary Mobile Subscriber Identity; URI stands for Uniform Resource Identifier; SUPI stands for Subscription Permanent Identifier; SUCI stands for Subscription Concealed Identifier; PEI stands for Permanent Equipment Identifier; NSSAI stands for Single Network Slice Selection Assistance Information; IMSI stands for International Mobile Subscriber Identification Number.

[0061] The concept of network digital identity (NDI) naturally emerged with the popularization of the Internet and communication networks. To date, there is no unified concept and accurate definition of NDI globally. The Internet and communication networks have different definitions of digital identity. The differences mainly stem from different perspectives on digital identity, development needs, and construction ideas.

[0062] From the perspective of the internet, the International Organization for Standardization and the International Electrotechnical Commission (IEC) believe that digital identity addresses the identification and trust of objects in digital spaces, using network information systems for secure transmission, storage, use, and management, assigning unique digital identifiers and associated attribute declarations to objects. From the perspective of communications networks, the International Telecommunication Union's Standardization Bureau (ITU-S) defines digital identity as the identification of an individual or entity in digital communications and network environments, enabling authentication and access to various online services and applications.

[0063] With the rapid development of the Internet and communication networks, the integration of the two has accelerated, and they have become key core components and important infrastructure supporting the digital world. Especially after network digital identity entered the "digital identity application period", whether from the definition of digital identity or in actual application, network digital identity has become a key link in the construction of the trust system in the digital world and supporting digital ecological governance.

[0064] Regarding the connotation of online digital identity: Amidst the digital economy, digital identity is increasingly becoming the bridge and link between the physical and digital worlds. With technological innovation and the expansion of application scenarios, the scope, capabilities, and concepts of digital identity have undergone a comprehensive upgrade, and its importance has become increasingly prominent. Digital identity is not only a reflection of physical behavior in the digital space; it is also the foundation of all activities in the digital world.

[0065] The expansion of the scope, capabilities, and concepts of digital identity has led to an expansion in the meaning and extension of digital identity subjects, carriers, and functions. First, the definition of digital identity subjects has expanded from the narrow definition of "natural persons" to the broader definition of "humans, machines, and objects," and from physical entities such as "humans, machines, and objects" to virtual entities such as "data elements and digital humans." This has led to a gradual expansion in coverage and the number of entities involved. Second, the definition of digital identity carriers has expanded beyond "digital" legal ID documents such as electronic ID cards, e-passports, and e-social security cards to include "digital" identity credentials such as phone numbers, email addresses, various account credentials, biometrics, and QR codes, enriching the types of identity carriers. Third, the functional connotation of digital identity has expanded beyond "proving who I am" to "proving my rights and attributes." This expansion is achieved through three core modules: identity identification, identity attributes, and identity credentials. These modules uniquely identify entities through identification, describe entity characteristics through attributes, and provide evidence verifying the identity attributes of entities through credentials. Together, these three modules form the foundation of digital identity, ensuring the proper registration, issuance, verification, and management of identities.

[0066] Therefore, whether it is Internet identity or communication network identity, there is an urgent need for a digital identity definition and mechanism that can connect various industries and has certain global interoperability inherent properties to meet the identity and data interoperability needs across physical and virtual spaces, while ensuring the trustworthiness, interoperability, security and privacy protection of digital identity, providing a foundation for building a more secure, open and interconnected digital world.

[0067] The Multi-Identifier Network system utilizes an innovative and cutting-edge multi-identifier management mechanism that integrates future networks with existing IP networks. The Multi-Identifier Network system, abbreviated as MIN or MIN Network (MIN stands for Multi-Identifier Network), is the world's first system to support the construction of a multilaterally managed sovereign internet. It aims to address the security, governance, and evolution challenges facing the current internet architecture. The core concept of the MIN Network is to achieve sovereign independence and interoperability in cyberspace by supporting multiple identifiers (such as identity, content, and geolocation) and decentralized management.

[0068] The MIN network primarily consists of a Multi-Identifier Management System (MIS) and a Multi-Identifier Router (MIR). Within the Multi-Identifier Management System (MIS), the MIN network's identity management system is governed through a multilaterally managed consortium chain mechanism, using a one-country-one-vote voting system to manage top-level identifier domain names. Each country manages its own internal operations through a scalable, hierarchical consortium chain. The Multi-Identifier Router (MIR) supports multiple identifiers, including identity, content, services, and IP addresses, enabling parallel coexistence in the network layer. MIN utilizes the HPT algorithm, a hash table and prefix tree, to support multi-identifier translation and addressing for tens of billions of entries.

[0069] The MIN network has the following outstanding advantages:

[0070] MIN supports multiple identifiers (such as identity, content, and IP) and can flexibly use different identifiers for addressing and routing based on the application scenario. This allows MIN to not only meet the needs of the traditional Internet, but also adapt to emerging fields such as the Internet of Things, Industrial Internet, and Internet of Vehicles.

[0071] Second, decentralized governance: MIN uses blockchain technology and a consortium chain voting mechanism to ensure fairness and transparency in global network management, avoiding the unilateral monopoly problem brought about by the current centralized DNS management.

[0072] 3. High security and data traceability. The MIN network uses asymmetric encryption technology to achieve data traceability, ensuring the security and privacy of data transmission. MIN's design provides inherent security features and can defend against various network attacks. MIN integrates multiple security technologies, such as signature cryptography, identity verification, and behavior detection, to build a dynamic security protection model to effectively resist various network attacks.

[0073] MIN's multi-identity routing mechanism and hierarchical management structure based on the alliance chain make it highly scalable. Whether in small-scale enterprise private networks or global sovereign Internet scenarios, MIN can provide flexible solutions.

[0074] 5. Compatible with existing network systems. MIN is compatible with existing IPv4 and IPv6 network architectures, supports gradual evolution and transition, and does not require complete replacement of existing network equipment, reducing migration costs.

[0075] 6. Identity-driven: MIN uses identity as its core identifier, supports the registration and verification of users' real identities, and enhances network security and transparency. The binding of identity identifiers to devices ensures the traceability of network behavior.

[0076] Therefore, MIN (short for Multi-Identifier Network System or Multi-Identifier Network) has broad application prospects, particularly in global internet governance, security, and emerging technologies. Its core advantages are multilateral co-management and decentralized management, combined with the support of multiple identifiers and strong security mechanisms, making it adaptable to the development needs of future networks.

[0077] Overall, the MIN network system, through its multi-identity management, decentralized governance, identity-driven, and data traceability, provides a secure, flexible, and cost-effective network solution. It not only enhances network security and transparency, but also promotes international cooperation and technological innovation, adapting to the diverse needs of modern networks. As the network environment continues to evolve, the application prospects of MIN will become even broader.

[0078] Regarding the development of digital identity in communication networks, CT communication network technology and digital identity technology are being integrated. The first generation of mobile communication technology, 1G, began using digital identity technology to identify entities, but this presented significant security vulnerabilities. Although 1G, the first generation of mobile communication network technology represented by AMPS, was an analog cellular mobile communication system, users and terminal devices still used digital identification within the system.

[0079] The second generation of mobile communication technology (2G) has achieved a solution to separate the "device" and "SIM" identity, effectively reducing security risks. The second generation of mobile communication network technology, represented by GSM, pioneered the use of a "device-SIM" separation method, with the mobile phone and SIM card together forming the mobile communication terminal device.

[0080] Third-generation mobile communication technology (3G) provides two-way authentication capabilities and further enriches service identification types. 3G, represented by WCDMA, upgrades the SIM card to the Universal Subscriber Identity Module (USIM) and further supports two-way authentication between the terminal and the network. 3G mobile communication networks offer users a richer and expanded range of services, including circuit-switched (CS) and packet-switched (PS). Service identification now includes not only the MSISDN in the CS domain but also the access point name (APN) in the PS domain.

[0081] Fourth-generation mobile communication technology (4G) introduced new IP multimedia identities, enabling IP-based unified communications and identity management. 4G, represented by LTE, halted the evolution of the CS domain, with the IP Multimedia Subsystem (IMS) domain taking over audio and video services.

[0082] 5G, the fifth generation of mobile communications technology, introduces new service identifiers to enable secure and flexible network slicing services and unified user identity management. In 5G, the User Permanent Identifier (SUPI) is equivalent to the IMSI in LTE. While its format is identical to the IMSI, the SUPI is never transmitted over the air interface to prevent user tracking through wireless signal monitoring. The User Hidden Identifier (SUCI) is a privacy-preserving identifier that includes the hidden SUPI and can be transmitted over the air interface. Every terminal device accessing the 5G mobile communications network must have a Permanent Equipment Identifier (PEI), which corresponds to the IMEI in LTE networks.

[0083] Overall, the evolution from 1G to 5G has seen the continuous deepening of the integration of digital identity technology and mobile communication networks, effectively achieving the separation and independent development of device, user, and service identification. While the user-centric system is expected to persist, the increasing diversification of network terminals and the continued expansion of service types will lead to further innovation and change in the specific forms of user, device, and service identification. Accordingly, digital identity technology in mobile networks will also follow this trend, evolving to meet new challenges and demands.

[0084] Regarding Super SIM cards driving digital transformation, they offer key advantages: low cost, widespread adoption, and financial-grade security, profoundly transforming traditional identity authentication models. Compared to traditional USB-shield devices, Super SIM cards cost only one-tenth as much and offer the convenience of portability. In terms of ubiquity, Super SIM cards, leveraging billions of users and the existing SIM card base, offer global reach.

[0085] From a technical perspective, the Super SIM card is essentially a miniature secure computer, boasting powerful hardware, operating system, and application capabilities. Its hardware layer is based on an EAL4+-certified chip, supporting national encryption algorithms such as SM2, SM3, and SM4. It offers 40KB of RAM, a 36MHz CPU, and 1.25MB of Flash storage, providing the foundation for efficient computing and secure storage. At the operating system level, the Super SIM card supports multiple encrypted communication protocols, including device-to-card encrypted channels (7816 protocol), SMS encrypted channels, NFC channels (SWP protocol), and BIP encrypted channels (TCP / IP protocol), enabling secure communication in multiple scenarios. At the application layer, the Super SIM card, through Java Applet support, complements the TSM platform, ensuring security domain isolation and open card space, meeting the needs of complex multi-application scenarios. This layered architecture gives the Super SIM card significant advantages in security, compatibility, and scalability.

[0086] The Super SIM card has built a complete application ecosystem for the digital age. Its functions extend beyond traditional communication authentication to identity authentication scenarios such as electronic certificates and digital signatures, and support diverse applications such as NFC payments and OTA remote management. As a natural secure hardware carrier, the Super SIM card, through features such as open APIs, has become a vital security infrastructure in the digital age, driving the digital security transformation of society as a whole. In the future, the Super SIM card will further strengthen its core position in the digital society with higher technical standards and a wider range of application scenarios, providing a solid foundation for digital security and identity authentication.

[0087] One prior art technique related to the present invention utilizes the Internet Protocol (IP), also known as the Internet Protocol. This is the network layer communication protocol within the Internet Protocol package, used for packet switching across network boundaries. Its routing function enables interconnection and essentially establishes the Internet.

[0088] IP is the primary protocol at the network layer of the TCP / IP protocol suite. Its mission is to deliver data packets from a source host to a destination host based solely on the IP address in the packet header. To accomplish this, the IP protocol defines the packet structure that encapsulates the data to be delivered. It also defines the addressing method used to label datagrams with source and destination information.

[0089] The characteristic of the IP address system is that each terminal is assigned a network address. Each packet carries this address, which serves as the basis for network nodes to forward packets. The currently widely used IPv4 packet structure uses a 32-bit address field, which is roughly equivalent to a 9-digit decimal number. With telephone numbers in major Chinese cities now almost all using 8-bit numbers, a 32-bit address field is undoubtedly insufficient for terminal identification worldwide. Consequently, recognizing this address crisis in the early 1990s, the IETF began work on IPv6 specifications. IPv6 uses a 128-bit address field, and it appears that this numbering resource will meet practical needs for a considerable period of time. While expanding the address field seems natural, two other issues related to this expansion are of particular interest: the promotion of IPv6 and the difficulties that the IP network's addressing scheme presents for high-speed packet forwarding. The promotion of IPv6 is extremely slow. On the one hand, this reflects that IPv4 can still cope with current practical needs through CIDR address segmentation, address reuse of proxy servers, and dynamic address allocation by ISPs. But on a larger scale, it reflects that the IP address method is too closely related to the way the network operates. It requires changing the user's communication program and the packet forwarding module of the router, which affects almost all devices on the network. The number upgrade work that can be completed overnight on the traditional telephone network may take more than ten years to complete on the IP network.

[0090] In traditional telecommunications networks, the numbers that identify transceiver terminals and the channel identifiers that guide information forwarding are relatively separate. This makes sense, as the potential number of transceiver terminals may be in the tens or even hundreds of millions, while the information forwarding operations involved in a switch or router are merely selecting from dozens, or at most hundreds, of output ports. On IP networks, finding a suitable output port among no more than a thousand requires searching through tens of millions of records.

[0091] This related prior art suffers from the following shortcomings: IP network security issues encompass both network security and information security. Network security refers to the ability of public infrastructure providing network services to be attacked or damaged, such as compromised domain name servers or routers, or maliciously blocked. Information security, on the other hand, refers to the ability of information transmitted online or stored on servers to be leaked or overwritten. Information encryption and secure, effective access methods are network-related issues, not inherently network-related ones. Because information is exposed electronically on the network, maintaining its security is more difficult.

[0092] The introduction of the TCP / IP protocol seemingly solved the fundamental problem of data transmission across the vast internet, establishing a set of basic rules for data transmission. To facilitate the identification of each computer's location and find a recognizable destination for data transmission, the IP protocol assigned each node on the network an address, known as an IP address. IP addresses are written using a four-segment dotted decimal format, such as "211.214.1.XXX." However, due to the principle of non-repetition, unordered and complex IP combinations placed a burden on computer operators, who found it difficult to easily process a series of unordered numbers. Consequently, the unordered and complex IP addresses indirectly raised the barrier to internet use and became a limiting factor in its application.

[0093] Another prior art related to the present invention uses Named Data Networking (NDN), proposed in 2010. Its predecessor is Content-Centric Networking (CCN). It uses receiver-driven pull-based communication semantics to replace the sender-driven push-based communication semantics of IP networks. In NDN, content consumers obtain content by sending interest packets to the network. Any intermediate router or content producer that caches the corresponding content responds with a data packet upon receiving the interest. Each interest can pull a piece of data, and there is a one-to-one correspondence between interests and data. NDN designs a pending interest table (PIT) to support a stateful forwarding plane. Each PIT entry records the network interface from which the interest was received. All PIT entries on the interest forwarding path construct a reverse path. The corresponding data only needs to be returned along the reverse path constructed by the PIT. Through this pull-based interaction, NDN decouples content from producers, better supporting content distribution. To protect content security, NDN requires producers to sign each data they send. This allows consumers to trust the content itself, regardless of how or where it was obtained. Due to NDN's disruptive architectural design, its compatibility with existing network architectures remains to be determined.

[0094] This existing technology has the following shortcomings: Although NDN enhances data integrity, source authentication, and correctness through a content signing mechanism, it still faces many privacy and security risks: Name privacy, hierarchical names in interest packets can leak content information, especially when the name structure is very intuitive, which may lead to user privacy leakage; cache privacy, attackers can obtain access information about cached content through timing analysis; content privacy, although the data packet is signed, the content itself is not encrypted, so it cannot prevent data leakage; signature privacy, the signature can reveal the identity of the producer, thereby infringing the privacy of individuals or organizations.

[0095] Furthermore, NDN may be vulnerable to various attacks, including denial of service (DoS) attacks, protocol attacks, and timing attacks. Denial of service (DoS) attacks involve sending a large number of Interest packets, overflowing the router's PIT table and thereby blocking legitimate requests. Because NDN Interest packets do not contain source addresses, attackers are difficult to track. Attackers can generate large numbers of invalid Interest packets through botnets, leading to cache contamination, bandwidth consumption, and network resource exhaustion. Protocol and timing attacks exploit NDN's prefix matching mechanism to infer the content requested by consumers, thereby violating name privacy. Timing attacks, on the other hand, measure response times to infer whether content is cached, thereby gaining cache privacy.

[0096] Therefore, the present invention aims to combine the operator's SIM card with the multi-identity network system MIN based on the multilateral co-management, realize the construction of a sovereign Internet, and then connect the traditional SIM card to the MIN network as an effective network identifier, and realize identity authentication and communication, thereby realizing unified identity authentication of SIM cards across platforms and networks, meeting its identity consistency and security requirements across platforms and networks, and providing a basis for realizing identity authentication and data interoperability across physical and virtual spaces.

[0097] The present invention proposes a method and system for expanding a multi-identity network system into a SIM card to form a trusted sovereign network, enabling users to directly use the mobile phone number assigned by their operator as a unique identifier to achieve identity authentication and communication in the MIN network. The SIM card will be registered as a unique identifier in the identity management system of the MIN network. The identity management system in the MIN network will connect with the operator database in real time to verify the legitimacy of the mobile phone number and ensure the uniqueness and accuracy of the user's identity.

[0098] In this process, the SIM card not only serves as a traditional communication identifier but can also be associated with the user's other network identifiers (such as device identifiers and IP addresses) to achieve unified cross-domain identity authentication. Therefore, users only need a mobile phone number to achieve identity authentication and access globally, across platforms, and across networks. No matter where the user is, as long as there is an Internet connection, they can log in to the MIN network through their mobile phone number and conduct secure communication and data exchange.

[0099] The present invention is further based on the national secret security chip and key storage capabilities of the super SIM card, combined with PKI asymmetric encryption technology and domestic cryptographic algorithms, to create a new type of mobile smart password key that can provide high-security identity authentication and data encryption transmission capabilities in application scenarios such as the Internet of People and the Internet of Things.

[0100] The preferred embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.

[0101] like Figures 1 to 5 As shown, this embodiment provides a method for extending a SIM card in a multi-identity network system to form a trusted sovereign network, including the following steps:

[0102] Step S1: authenticating the SIM card through the client of the multi-identity network system and connecting the SIM card to the multi-identity network system;

[0103] Step S2: identity signing and signature verification in the multi-identity network system;

[0104] Step S3: performing network group addressing in a multi-identity network system through the SIM card.

[0105] In this embodiment, SIM card authentication is first implemented on the MIN client, which then upgrades the SIM card to the MIN network's addressing identifier, effectively defining the SIM card as a MIN network identifier. The MIN client's functionality is then packaged into SDKs (software development kits) for various operating systems, including Android, iOS, and Hongmeng. Because the SDK package falls outside the scope of this application and is not a necessary technical feature, it is not described in detail herein.

[0106] Step S1 in this embodiment is used to implement quick authentication and login of SIM card. Figure 2 As shown, step S1 includes the following sub-steps:

[0107] Step S101: Enter the mobile phone number corresponding to the SIM card through the MIN client (i.e., the client of the multi-identity network system, also known as the multi-identity network client) to initiate a registration and login request; the login described in this embodiment refers to the SIM card quick login;

[0108] Step S102: The client of the multi-identity network system sends a registration and login request to the multi-identity router MIR with the mobile phone number and its local account information;

[0109] Step S103: query the multi-identity management system MIS for user information, pass the mobile phone number to the number card authentication server, request SIM card quick authentication, return and cache the transaction ID, and set the operation result to pending operation;

[0110] Step S104: asynchronously notifying the user to confirm the authorization and modifying the cached operation result according to the transaction ID;

[0111] Step S105: Pass in the transaction ID, poll to determine the user authorization result, and complete the registration and login;

[0112] Step S106, returns the query operation result, and maintains the login status until the operation result is confirmed; otherwise, returns to step S105 and repeats the loop process until the operation result is confirmed.

[0113] Preferably, in step S101 of this embodiment, the C-end client (i.e., the end user) first opens the MIN client and enters the mobile phone number associated with the SIM card, achieving quick SIM card login by obtaining a verification code or other means. Then, in step S102, the client obtains user information, carries local account information such as the mobile phone number and terminal ID, and sends a registration and login request to the multi-identity router (MIR). Next, in step S103, the client queries the multi-identity management system (MIS) for user information, transmits the mobile phone number to the number card authentication server, initiates a real-name authentication request, and returns user information including the real-name authentication result, facilitating quick SIM card authentication. In step S104, the client's SIM card-bound user information is asynchronously transmitted to confirm whether to continue registering the primary ID. After the user confirms authorization, the client verifies whether authentication has been completed. If so, a response is issued, i.e., the cached operation result is modified based on the transaction ID. Registration and login are then completed in step S105. During the registration process, preferably, a chain account is first created, and the chain account registration result is returned. The chain account status is then queried and the registration result is returned. If the response indicates that the transaction is in progress, the fallback logic sets a timeout and returns a processing prompt. When the return value is a successful registration, the MIN client will call back and maintain the login status.

[0114] Preferably, step S104 in this embodiment includes the following sub-steps:

[0115] Step S1041, asynchronously notifying the user to confirm authorization to confirm the account number for registering the multi-identity network system;

[0116] Step S1042, waiting for user operation, which includes confirmation, cancellation and timeout;

[0117] Step S1043: Notify the multi-identity management system MIS through asynchronous callback according to the user operation, and pass in the transaction ID;

[0118] Step S1044, modifying the cached operation result according to the transaction ID;

[0119] Step S1045, responding to user operations.

[0120] Preferably, step S105 in this embodiment includes the following sub-steps:

[0121] Step S1051: The transaction ID is passed in and the registration and login results are queried through the multi-identity router (MIR).

[0122] Step S1052: query the cached operation result according to the transaction ID. If the operation result is positive, register and log in through the multi-identity management system MIS;

[0123] Step S1053: Return the query operation result.

[0124] Step S2 in this embodiment is used to implement the MIN network identity signature and verification, and preferably includes the following sub-steps:

[0125] Step S201: Signing is performed based on the user's private key. After confirming that the private key is not empty, the corresponding signature method is first selected according to the public key generation algorithm in the KeyParam key parameter. Then, the private key (such as id.Prikey) is type-converted to the private key type of the SM2 algorithm, such as the parameter p of the sm2.Sm2PrivateKey type, and the p.Sign digital signature method is called to sign. Among them, KeyParam is a key parameter used to specify the public key generation algorithm. The SM2 algorithm is a public key cryptography algorithm based on elliptic curves and is used for digital signatures and encryption. The signature of this embodiment uses the SM2WithSM3 algorithm by default.

[0126] Step S202 verifies the signature based on the user's public key. After verifying that the public key is not null, the corresponding verification method is selected based on the public key generation algorithm in the KeyParam key parameter. The public key (such as id.Pubkey) is then converted to the SM2 algorithm's public key type, such as parameter p of the sm2.Sm2PublicKey type. The p.Sign verification method is then called for verification. This embodiment uses the SM2WithSM3 algorithm by default.

[0127] Step S3 of this embodiment is used to implement the network group addressing process of the SIM card in the MIN, such as Figure 4 As shown, it preferably includes the following sub-steps:

[0128] Step S301, when a multi-identity network packet flows in, the International Mobile Subscriber Identity (IMSI) corresponding to the SIM card is sent to the multi-identity network system;

[0129] Step S302, read a data link layer data segment from the network, and decode the multi-identifier network packet through TLV encoding; wherein the multi-identifier network packet includes four areas, such as Figure 3 As shown in the figure, the four areas are the identification area, signature area, read-only area, and variable area. Each area consists of one or more TLV-encoded triplets (i.e., Type / Length / Value). TLV encoding divides the binary data block into three intervals. The first interval is the Type field, which indicates the type of the current data block; the middle interval is the Length field, which indicates the length of the Value field; and the last interval is the Value field, which is used to store the data block.

[0130] Step S303, determining whether the decoding of the multi-identifier network packet is successful. If not, the multi-identifier network packet is discarded and the processing flow ends; if yes, jump to step S304;

[0131] Step S304: Check the destination identifier field of the multi-identifier network packet to determine whether there is an unprocessed identifier in the destination identifier field. If there is no identifier in the destination identifier field or the identifier has been processed, the multi-identifier network packet is discarded and the processing flow ends. If there is an unprocessed identifier in the destination identifier field, jump to step S305.

[0132] Step S305: Read the next unprocessed identifier and determine whether the current multi-identity router can parse and process the identifier based on the identifier type number of the identifier. If not, that is, it cannot parse and process the identifier, then return to step S304 to continue to determine whether there is another unprocessed identifier in the destination identifier area; if so, jump to step S306;

[0133] Step S306: Process the multi-identifier network packet according to the identifier semantics, i.e., call the processing flow, read and parse the identifier value, and call the corresponding processing function based on the identifier value and the identifier type number to process the multi-identifier network packet, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet out the designated port;

[0134] Step S307, determine whether the processing of the multi-identifier network group is successful. If not, return to step S304 to continue to determine whether there is an unprocessed identifier in the destination identifier area; if so, the processing flow ends.

[0135] This embodiment uses the International Mobile Subscriber Identification Number (IMSI) as the SIM card's identity. The IMSI, or International Mobile Subscriber Identity, is a globally unique identifier for a SIM card. It consists of a string of numbers up to 15 digits and serves as a user's credential for accessing a mobile communications network.

[0136] When a user attempts to access a mobile communications network, the phone sends the IMSI number to the network. The network uses this IMSI number to determine the user's identity and carrier, allowing it to provide appropriate services. Furthermore, the IMSI number can be used to track and identify mobile device users, playing a vital role in cybercrime investigations.

[0137] This embodiment provides a single-thread (single-processor) network packet processing process through steps S301 to S307, and provides a flow chart of a network packet forwarder processing a network packet. Figure 4 The figure shows the complete process of a single-core router processing a network packet.

[0138] Since the support of multiple identifiers by the multi-identity router MIR can be completely isolated from each other, in the software-implemented forwarder, a multi-core processor can be used to forward network packets carrying different identifiers. Therefore, in step S3 of this embodiment, when a multi-identity network packet carrying multiple identifiers enters the multi-identity router MIR, the multi-identity router MIR processes the multiple identifiers concurrently, such as Figure 5 The FIB table refers to the Forwarding Information Base, which is a query forwarding table used to implement query and forwarding processing in the identification processing unit.

[0139] In this embodiment, the process of concurrently processing multiple identifiers by the multi-identity router MIR includes:

[0140] Step A1, extracting all identifiers in the multi-identity network group, and determining the identifier types supported by the multi-identity router MIR through an identifier filter;

[0141] Step A2: Duplicate the data according to the number of supported identifiers and send them to different identifier processing units for processing. After receiving the processing task, different identifier processing units independently complete the processing of the multi-identifier network group and then summarize the processing results to the decision unit;

[0142] In step A3, the decision unit selects a processing result to be adopted according to the order of the identifiers in the multi-identifier network group.

[0143] For example, in Figure 5In this example, identifiers 101 and 103 carried in the multi-identifier network packet are both identifier types supported by the current router. Therefore, the incoming network packet is duplicated and distributed to two different identifier processing units for processing. These different identifier processing units can independently run on different CPUs or CPU cores. After receiving the multi-identifier network packet processing task, each identifier processing unit independently completes processing of the multi-identifier network packet and aggregates the processing results to the decision unit.

[0144] like Figure 5 As shown, identifier 103 has a higher priority in the network packet than identifier 101. Therefore, if the processing result of identifier 103 is normal, that is, the result of the identifier processing unit is not to discard the multi-identifier network packet, the decision unit adopts the processing result of the identifier processing unit corresponding to identifier 103 and ignores the result of the identifier processing unit corresponding to identifier 101. Only when the processing result corresponding to identifier 103 is to discard the multi-identifier network packet does the decision unit adopt the processing result of the identifier processing unit corresponding to identifier 101.

[0145] Therefore, in the parallel multi-identity router (MIR) of this embodiment, all identifiers in the multi-identity network group are first extracted. After receiving the processing task for the multi-identity network group, different identifier processing units independently complete the processing of the multi-identity network group. Subsequently, each identifier processing unit summarizes the processing results to the decision unit. The decision unit determines which identifier processing unit's processing result to use based on the order of the identifiers in the multi-identity network group.

[0146] To summarize, this embodiment first implements SIM card authentication through the client of the multi-identity network system, connects the SIM card to the multi-identity network system, then signs and verifies the identity of the SIM card through the multi-identity network system. Finally, network group addressing is performed in the multi-identity network system through the SIM card, and the SIM card can be connected to the multi-identity network system as a valid network identifier to realize identity authentication and communication of the SIM card in the multi-identity network system, so as to build a trusted sovereign network. Combining the advantages of multilateral co-management, decentralized management and multiple identifiers of the multi-identity network system, unified identity authentication of the SIM card across platforms and networks is realized, meeting its identity consistency and security requirements across platforms and networks, and providing a basis for identity authentication and data interoperability across physical and virtual spaces.

[0147] This embodiment proposes a method and system for building a trusted sovereign network by extending SIM cards based on the MIN (Multi-Identifier Network). By connecting a traditional SIM card to the MIN network, it is upgraded from a single communication identifier to a multi-identity network identifier, enabling identity authentication, data encryption, and cross-domain access. This creates a sovereign internet architecture that combines decentralized management with global interoperability. This addresses the technical issues in traditional IP networks, where identity authentication primarily relies on centralized services, making it difficult to ensure identity consistency and security across platforms and networks, and achieving real-time traceability and behavior locking in the event of an attack. This embodiment significantly improves the security of identity authentication and the trust in cyberspace through the MIN network architecture.

[0148] In the MIN network, the top-level identifier is jointly managed by multiple countries, ensuring the multilateral co-management and global interconnection of cyberspace; the lower-level identifiers are independently managed by each country, ensuring sovereignty and autonomy. By embedding the national security chip and PKI asymmetric encryption technology in the SIM card, the SIM card can generate a unique master key. , build the unique identity mapping of the SIM card in the MIN network.

[0149] Specifically, this embodiment preferably further includes an identity authentication step, which includes:

[0150] Step B1: Generate a random seed , combined with the SIM card's phone number, device ID, and timestamp , through the hash function Formula Generate a master key , represents a hash function, Indicates the unique identifier of the SIM card; master key Used to uniquely identify the SIM card in the MIN network. All subsequent identity-related operations (such as registering the main identity, generating sub-identities, and verifying identities) are based on this master key. Perform binding and verification to ensure one-to-one correspondence between SIM card identity and device behavior to prevent forgery;

[0151] Step B2: The multi-identity network uses the SIM card multi-identity binding mechanism to calculate the value of the multi-identity network. Calculating the identity forgery success rate ,in, Indicates the success rate of identity forgery in IP networks; Indicates the identification dimension enhancement coefficient, which It is set by the system according to the security policy, and the default value is in the range of 0.01–0.1; Indicates the number of identification dimensions, including SIM card ID, device ID, and IP address;

[0152] Step B3: When a malicious attack occurs, the blockchain log in the multi-identity network automatically records the attacker's identity and operation path through the log chain, forming an unalterable evidence chain. The log chain adopts a chain hash structure, which is recorded as ,in, Indicates the i The content of the operation, Indicates the i −1 operation log hash value.

[0153] In step B1 of this embodiment, the random seed The generation process can call the secure entropy source in the SIM card chip through a standardized interface (such as the PKCS#11 interface) and be completed inside the SIM card. This process is completed in the SIM card and is not exported, which can avoid the risks of man-in-the-middle attacks and seed leakage.

[0154] Due to the collaborative verification of multiple independent identities, it is difficult for attackers to break through all security mechanisms in a short period of time, and security is significantly enhanced. When a malicious attack occurs, the blockchain log in the multi-identity network automatically records the attacker's identity and operation path through the log chain, forming an unalterable chain of evidence. The log chain adopts a chain hash structure. Therefore, even in the event of malicious tampering, the on-chain data can be fully preserved and traceable.

[0155] In other words, the primary technical problem addressed by this embodiment is how to expand and authenticate SIM cards based on a multi-identity network system, upgrading the traditional SIM card from a single communication access tool to a trusted network identity identifier, enabling global cross-domain identity authentication and highly secure communications. In the traditional internet system, SIM cards are primarily used for mobile communication access and cannot meet the high security requirements of the future sovereign internet for multi-identity, multi-domain identity authentication. This embodiment introduces the MIN system to build a trusted sovereign network with the SIM card at its core, enhancing cyberspace governance capabilities and user identity protection.

[0156] This embodiment achieves multi-dimensional expansion of SIM card identity identification by connecting the SIM card to the MIN network, making the mobile phone number not only a communication identifier, but also a unified authentication entry for multiple identifiers such as identity identification (ID), location identification (LID) and device identification (DID). This unified identity management mechanism effectively guarantees the sovereignty and independence of cyberspace and decentralized interoperability. During the identity authentication process, the SIM card uses the built-in national security chip to generate the master key. , encrypt the authentication information and upload it to the MIN network identification management system to ensure the uniqueness and credibility of the user's identity in cross-platform, cross-network, and cross-regional scenarios.

[0157] Preferably, this embodiment also implements end-to-end encrypted communication of the SIM card through PKI asymmetric encryption technology. That is, this embodiment also preferably includes a signature encryption step, which includes:

[0158] Step C1: During data transmission, each network interaction is performed by formula Generate a unique signature ,in, Indicates the use of private key Digitally sign, Represents the original data; a unique signature is used during data transmission , which can not only verify the authenticity of the data, but also can be verified when the data reaches the destination to prevent the data from being tampered with or forged;

[0159] Step C2: During the data transmission process, the data is encrypted and protected by an asymmetric encryption mechanism. The encryption process is: , Represents the ciphertext after asymmetric encryption, Indicates the use of public key Perform asymmetric encryption, Indicates the original encrypted data.

[0160] The signature encryption step used in this embodiment is a dual mechanism that ensures the confidentiality and integrity of data during transmission and prevents man-in-the-middle attacks or data tampering. Even if the communication path is eavesdropped, the attacker cannot decrypt the data content or forge data packets.

[0161] On this basis, through steps B1 to B3, the MIN network's multilaterally managed log system records each identity verification and data interaction on-chain, forming an immutable behavior log based on blockchain technology, enabling rapid tracing and evidence collection of attack behaviors. Once the attacker's behavior trajectory is recorded on-chain, it will be permanently archived, providing a good foundation for the evidence storage mechanism.

[0162] In summary, this embodiment expands the SIM card's identity authentication capabilities through a multi-identity network system, building a trusted sovereign network centered around the SIM card. This embodiment elevates the SIM card from a traditional communication tool to a core carrier for network identity authentication. Furthermore, it leverages national secret algorithms and PKI encryption to ensure user identity uniqueness, authentication accuracy, and communication security, comprehensively enhancing future cybersecurity governance capabilities and user privacy protection.

[0163] This embodiment further provides a system for forming a trusted sovereign network by extending a SIM card in a multi-identity network system, which adopts the method for forming a trusted sovereign network by extending a SIM card in a multi-identity network system as described above, and includes:

[0164] SIM card authentication module, which realizes SIM card authentication through the client of the multi-identity network system and connects the SIM card to the multi-identity network system;

[0165] Identity signing and verification module, used for identity signing and verification in a multi-identity network system;

[0166] The multi-identity network group addressing module performs network group addressing in a multi-identity network system through a SIM card.

[0167] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A method for extending a SIM card in a multi-identity network system to form a trusted sovereign network, characterized in that: The following steps are involved: Step S1: authenticating the SIM card through the client of the multi-identity network system and connecting the SIM card to the multi-identity network system; Step S2: identity signing and signature verification in the multi-identity network system; Step S3, performing network group addressing in a multi-identity network system through the SIM card; Wherein, the step S1 includes the following sub-steps: Step S101, initiating a registration and login request by inputting the mobile phone number corresponding to the SIM card; Step S102: The client of the multi-identity network system sends a registration and login request to the multi-identity router MIR with the mobile phone number and its local account information; Step S103: input the mobile phone number, request SIM card authentication, return and cache the transaction ID, and set the operation result to pending operation; Step S104: asynchronously notifying the user to confirm the authorization and modifying the cached operation result according to the transaction ID; Step S105: Pass in the transaction ID, poll to determine the user authorization result, and complete the registration and login; Step S106, returns the query operation result, and maintains the login status until the operation result is confirmed; otherwise, returns to step S105 and repeats the loop process until the operation result is confirmed.

2. The method for forming a trusted sovereign network by extending a SIM card in a multi-identity network system according to claim 1, characterized in that: The step S104 includes the following sub-steps: Step S1041, asynchronously notifying the user to confirm authorization to confirm the account number for registering the multi-identity network system; Step S1042, waiting for user operation, which includes confirmation, cancellation and timeout; Step S1043: Notify the multi-identity management system MIS through asynchronous callback according to the user operation, and pass in the transaction ID; Step S1044, modifying the cached operation result according to the transaction ID; Step S1045, responding to user operations.

3. The method for forming a trusted sovereign network by expanding a SIM card in a multi-identity network system according to claim 1, characterized in that: The step S105 includes the following sub-steps: Step S1051: The transaction ID is passed in and the registration and login results are queried through the multi-identity router (MIR). Step S1052: query the cached operation result according to the transaction ID. If the operation result is positive, register and log in through the multi-identity management system MIS; Step S1053: Return the query operation result.

4. The method for forming a trusted sovereign network by extending a SIM card in a multi-identity network system according to any one of claims 1 to 3, characterized in that: The step S2 includes the following sub-steps: Step S201: Signing based on the user's private key. After confirming that the private key is not empty, the corresponding signature method is selected according to the public key generation algorithm in the KeyParam key parameter. The private key is then converted to the private key type of the SM2 algorithm, and the p.Sign digital signature method is called to sign. Step S202: Verify the signature based on the user's public key. After verifying that the public key is not empty, first select the corresponding verification method based on the public key generation algorithm in the KeyParam key parameter, then convert the public key to the public key type of the SM2 algorithm, and call the p.Sign verification method for verification.

5. The method for forming a trusted sovereign network by extending a SIM card in a multi-identity network system according to any one of claims 1 to 3, characterized in that: The step S3 includes the following sub-steps: Step S301, when a multi-identity network packet flows in, the International Mobile Subscriber Identity (IMSI) corresponding to the SIM card is sent to the multi-identity network system; Step S302: Read the data link layer data segment and decode the multi-identifier network packet using TLV encoding. The multi-identifier network packet includes four areas: an identification area, a signature area, a read-only area, and a variable area. Each area consists of one or more TLV-encoded triplets. The TLV encoding divides the binary data block into three intervals: the first interval is the Type field, indicating the type of the current data block; the middle interval is the Length field, indicating the length of the Value field; and the last interval is the Value field, which is used to store the data block. Step S303, determining whether the decoding of the multi-identifier network packet is successful. If not, the multi-identifier network packet is discarded and the processing flow ends; if yes, jump to step S304; Step S304: Check the destination identifier field of the multi-identifier network packet to determine whether there is an unprocessed identifier in the destination identifier field. If there is no identifier in the destination identifier field or the identifier has been processed, the multi-identifier network packet is discarded and the processing flow ends. If there is an unprocessed identifier in the destination identifier field, jump to step S305. Step S305: Read the next unprocessed identifier and determine whether the current multi-identity router can parse and process the identifier based on the identifier type number of the identifier. If not, that is, it cannot parse and process the identifier, then return to step S304 to continue to determine whether there is another unprocessed identifier in the destination identifier area; if so, jump to step S306; Step S306: Invoke the processing flow, read and parse the value of the identifier, and call the corresponding processing function based on the identifier value and the identifier type number to process the multi-identifier network packet, including checking the cache, recording the return path, checking the forwarding information table, and forwarding the network packet out of the specified port; Step S307, determine whether the processing of the multi-identifier network group is successful. If not, return to step S304 to continue to determine whether there is an unprocessed identifier in the destination identifier area; if so, the processing flow ends.

6. The method for forming a trusted sovereign network by extending a SIM card in a multi-identity network system according to any one of claims 1 to 3, characterized in that: In step S3, when a multi-identity network packet carrying multiple identifiers enters the multi-identity router MIR, the multi-identity router MIR processes the multiple identifiers concurrently.

7. The method for forming a trusted sovereign network by extending a SIM card in a multi-identity network system according to claim 6, characterized in that: The process of concurrently processing multiple identifiers by the Multi-Identity Router (MIR) includes the following: Step A1, extracting all identifiers in the multi-identity network group, and determining the identifier types supported by the multi-identity router MIR through an identifier filter; Step A2: Duplicate the data according to the number of supported identifiers and send them to different identifier processing units for processing. After receiving the processing task, different identifier processing units independently complete the processing of the multi-identifier network group and then summarize the processing results to the decision unit; In step A3, the decision unit selects a processing result to be adopted according to the order of the identifiers in the multi-identifier network group.

8. The method for forming a trusted sovereign network by extending a SIM card in a multi-identity network system according to any one of claims 1 to 3, characterized in that: The identity authentication step is further included, and the identity authentication step includes: Step B1: Generate a random seed , combined with the SIM card's phone number, device ID, and timestamp , through the hash function Formula Generate a master key , represents a hash function, Indicates the unique identifier of the SIM card; Step B2: The multi-identity network uses the SIM card multi-identity binding mechanism to calculate the value of the multi-identity network. Calculating the identity forgery success rate ,in, Indicates the success rate of identity forgery in IP networks, represents the identification dimension enhancement coefficient, Indicates the number of identification dimensions; Step B3: When a malicious attack occurs, the blockchain log in the multi-identity network automatically records the attacker's identity and operation path through the log chain, forming an unalterable evidence chain. The log chain adopts a chain hash structure, which is recorded as ,in, Indicates the i The content of the operation, Indicates the i −1 operation log hash value.

9. The method for forming a trusted sovereign network by extending a SIM card in a multi-identity network system according to any one of claims 1 to 3, characterized in that: The method further includes a signature encryption step, wherein the signature encryption step includes: Step C1: During data transmission, each network interaction is performed by formula Generate a unique signature ,in, Indicates the use of private key Digitally sign, Represents the original data; Step C2: During the data transmission process, the data is encrypted and protected by an asymmetric encryption mechanism. The encryption process is: , Represents the ciphertext after asymmetric encryption, Indicates the use of public key Perform asymmetric encryption, Indicates the original encrypted data.

10. A system for extending a SIM card to form a trusted sovereign network using a multi-identity network system, characterized in that: A method for forming a trusted sovereign network by extending a SIM card in a multi-identity network system according to any one of claims 1 to 9 is adopted, and includes: SIM card authentication module, which realizes SIM card authentication through the client of the multi-identity network system and connects the SIM card to the multi-identity network system; Identity signing and verification module, used for identity signing and verification in a multi-identity network system; The multi-identity network group addressing module performs network group addressing in a multi-identity network system through a SIM card.

Citation Information

Patent Citations

  • High-security mobile office network based on multi-identification network system

    CN112291295A

  • Multi-side co-management multi-identification space-ground integrated intelligent network connection automobile high-safety private network system

    CN115296826A