SIM (Subscriber Identity Module) card activation method, activation equipment, key management system and related equipment

By using quantum key distribution technology to encrypt and decrypt user identity information during the SIM card activation process, the problem of information security threats in SIM card activation is solved, and data privacy and security are improved.

CN121056859APending Publication Date: 2025-12-02CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511217502.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-12-02

AI Technical Summary

Technical Problem

During the SIM card activation process, user information is vulnerable to attacks, leading to information leakage, tampering, or identity theft. Existing technologies are insufficient to effectively protect data privacy and security.

Method used

Quantum key distribution technology is used to generate quantum keys, which are then used to encrypt user identity information. The key management system is then used to decrypt and activate the SIM card, leveraging the non-cloning and non-measurability of quantum keys to ensure secure information transmission.

Benefits of technology

It effectively prevents eavesdropping and tampering of identity information during transmission, improves data privacy and security during SIM card activation, and ensures information integrity and uniqueness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121056859A_ABST
    Figure CN121056859A_ABST
Patent Text Reader

Abstract

The invention provides an SIM (Subscriber Identity Module) card activation method, activation equipment, a key management system and related equipment, and relates to the technical field of communication. The method comprises the steps of collecting identity information submitted by a user; the key management system generates a quantum key through quantum key division; encrypting the identity information by using the quantum key to obtain encrypted data; and sending the encrypted data to a key management system to activate a subscriber identity module (SIM) card of the subscriber. Through the technical means, the problem that security threats exist in activation of the user identity information in the SIM card in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a SIM card activation method, activation device, key management system and related devices. Background Technology

[0002] When activating a SIM card, users often need to upload sensitive information to the operator's server via the network to complete identity authentication and activation. However, during data transmission, user information is vulnerable to attacks, which may lead to information leakage, tampering, or even identity theft. Summary of the Invention

[0003] This disclosure provides a SIM card activation method, activation device, key management system, and related devices to improve data privacy and security.

[0004] According to one aspect of this disclosure, a SIM card activation method is provided for use in an activation device, comprising: collecting identity information submitted by a user; generating a quantum key with a key management system via quantum key distribution; encrypting the identity information using the quantum key to obtain encrypted data; and sending the encrypted data to the key management system to activate the user's identity module SIM card.

[0005] In some embodiments, generating a quantum key with a key management system via quantum key distribution includes: generating a random bit stream and randomly selecting a measurement basis for each bit in the random bit stream to obtain a first measurement basis set; determining the quantum state of each bit based on each bit and the measurement basis of each bit; sending the first measurement basis set and the quantum state of each bit to the key management system; receiving a second measurement basis set sent by the key management system, wherein the second measurement basis set includes measurement bases randomly selected by the key management system for measuring each quantum state; determining the same measurement bases in the same order from the first and second measurement basis sets to obtain a third measurement basis set; and generating a quantum key based on the bits corresponding to the measurement bases in the third measurement basis set.

[0006] In some embodiments, the method further includes: sending a portion of the bits in the random bit stream to the key management system; receiving the quantum error rate fed back by the key management system, wherein the key management system determines the quantum error rate by comparing the received portion of the bits with the measurement results of each quantum state; when the quantum error rate is greater than a preset threshold, destroying the quantum key and regenerating the quantum key with the key management system through quantum key distribution.

[0007] In some embodiments, the method further includes: when the number of measurement bases in the third measurement base set is less than a preset number, after initialization, regenerating a quantum key with the key management system through quantum key distribution.

[0008] In some embodiments, the method further includes: performing the following loop: determining whether the number of measurement bases in the third measurement base set is less than a preset number; if it is greater than or equal to, generating a quantum key based on the bits corresponding to the measurement bases in the third measurement base set and ending the loop; if it is less than, performing initialization and then re-determining the third measurement base set with the key management system through quantum key distribution.

[0009] In some embodiments, the method further includes: processing the identity information using a hash algorithm to obtain a first hash value representing the length of the identity information; and sending the encrypted data and the first hash value to a key management system to activate the SIM card.

[0010] In some embodiments, the quantum key is destroyed after the SIM card is activated.

[0011] According to another aspect of this disclosure, a SIM card activation method is provided, applied to a key management system, comprising: generating a quantum key with an activation device via quantum key distribution; receiving encrypted data sent by the activation device; decrypting the encrypted data using the quantum key to obtain the user's identity information; and activating the user's SIM card based on the identity information.

[0012] In some embodiments, generating a quantum key with an activation device via quantum key distribution includes: receiving a first set of measurement bases and the quantum states of each bit sent by the activation device; randomly selecting a measurement base for each bit to obtain a second set of measurement bases, and sequentially measuring the quantum states of each bit using the measurement bases in the second set of measurement bases to obtain the measurement results of the quantum states of each bit; sending the second set of measurement bases to the activation device; determining the same measurement bases in the same order from the first set of measurement bases and the second set of measurement bases to obtain a third set of measurement bases; and generating a quantum key based on the measurement results of the quantum states of the bits corresponding to the measurement bases in the third set of measurement bases.

[0013] In some embodiments, the method further includes: receiving a portion of bits from a random bit stream sent by an activation device; determining a quantum error rate by comparing the received portion of bits with the measurement results of each quantum state; sending the quantum error rate to the activation device; and when the quantum error rate is greater than a preset threshold, destroying the quantum key and regenerating a quantum key with the activation device via quantum key distribution.

[0014] In some embodiments, the method further includes: if the number of measurement bases in the third measurement base set is less than a preset number, then after initialization, re-determine the third measurement base set with the activation device through quantum key distribution.

[0015] In some embodiments, the method further includes: performing the following loop: determining whether the number of measurement bases in the third measurement base set is less than a preset number; if it is greater than or equal to, generating a quantum key based on the bits corresponding to the measurement bases in the third measurement base set and ending the loop; if it is less than, performing initialization and then re-determining the third measurement base set with the activation device through quantum key distribution.

[0016] In some embodiments, the method further includes: receiving a first hash value sent by an activation device; processing the identity information using a hash algorithm to obtain a second hash value representing the length of the identity information; and activating the SIM card based on the identity information when the first hash value and the second hash value are equal.

[0017] In some embodiments, the quantum key is destroyed after the SIM card is activated.

[0018] According to another aspect of this disclosure, an activation device is provided, comprising: a collection unit configured to collect identity information submitted by a user; a first generation unit configured to generate a quantum key with a key management system via quantum key distribution; an encryption unit configured to encrypt the identity information using the quantum key to obtain encrypted data; and a sending unit configured to send the encrypted data to the key management system to activate the user's identity module SIM card.

[0019] According to another aspect of this disclosure, a key management system is provided, comprising: a second generation unit configured to generate a quantum key with an activation device via quantum key distribution; a receiving unit configured to receive encrypted data sent by the activation device; a decryption unit configured to decrypt the encrypted data using the quantum key to obtain user identity information; and an activation unit configured to activate the user's SIM card based on the identity information.

[0020] According to another aspect of this disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform any of the methods described above by executing the executable instructions.

[0021] According to another aspect of this disclosure, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements any of the methods described above.

[0022] According to another aspect of this disclosure, a computer program product is provided, including computer instructions stored in a computer-readable storage medium, which, when executed by a processor, implement operation instructions for any of the methods described above.

[0023] In the embodiments of this disclosure, a quantum key is generated by a key management system through quantum key distribution, and the quantum key is used to encrypt identity information. The encrypted data is then used to activate the user's identity module SIM card, thereby solving the security threat problem of activating user identity information in the SIM card using related technologies, thus ensuring data privacy and improving security.

[0024] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0025] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0026] Figure 1 A schematic diagram of a SIM card activation system according to an embodiment of this disclosure is shown.

[0027] Figure 2 A flowchart of a SIM card activation method according to an embodiment of this disclosure is shown.

[0028] Figure 3 A flowchart of a quantum key generation method according to an embodiment of this disclosure is shown.

[0029] Figure 4 A flowchart of another quantum key generation method in an embodiment of this disclosure is shown.

[0030] Figure 5 A flowchart illustrating a method for determining a set of measurement bases according to an embodiment of this disclosure is shown.

[0031] Figure 6 A flowchart illustrating another SIM card activation method in an embodiment of this disclosure is shown.

[0032] Figure 7 A flowchart of yet another quantum key generation method according to an embodiment of this disclosure is shown.

[0033] Figure 8 A flowchart of yet another quantum key generation method according to an embodiment of this disclosure is shown.

[0034] Figure 9 A flowchart illustrating another method for determining a set of measurement bases in an embodiment of this disclosure is shown.

[0035] Figure 10 An activation device is shown in an embodiment of this disclosure.

[0036] Figure 11 An embodiment of a key management system is shown in this disclosure.

[0037] Figure 12 This diagram illustrates an electronic device provided in an embodiment of the present disclosure. Detailed Implementation

[0038] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that this disclosure will be more comprehensive and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0039] Furthermore, the accompanying drawings are merely illustrative of this disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0040] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0041] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0042] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0043] It should be noted that, unless otherwise specified, the embodiments of this disclosure and the technical features thereof can be combined with each other.

[0044] To facilitate understanding, the following is an explanation of several terms used in this disclosure:

[0045] QKD (quantum key distribution) is a secure key generation and distribution technology based on the principles of quantum mechanics. QKD utilizes the unmeasurability and uncopyability of quantum states to ensure the security of key transmission, making any eavesdropping attempt detectable.

[0046] OTP (One-Time Pad) is an encryption method that uses a unique random key for each encryption. During encryption, OTP XORs the plaintext with the key bit by bit, resulting in a completely random and unbreakable encryption. This is provided the key is used only once and is the same length as the plaintext. With keys generated by quantum key distribution, OTP offers unconditional security.

[0047] KMS (Key Management Service): A system responsible for the generation, storage, distribution, updating, and destruction of keys. In this invention, the operator's KMS is used to receive the quantum key from the quantum SIM card and collaborate with the activation device to complete data decryption and user authentication, ensuring the security of data transmission.

[0048] ECC (Elliptic Curve Cryptography) is a public-key cryptography system based on elliptic curve mathematical theory. With its shorter key length, higher security, and faster computation speed, it has become an important technology in modern cryptography, especially in resource-constrained environments (such as the Internet of Things and mobile devices) and privacy protection scenarios.

[0049] SHA-256 (Secure Hash Algorithm 256-bit) is a widely used cryptographic hash function belonging to the SHA-2 family (designed by the NSA and standardized by NIST). It can convert input data of arbitrary length into a fixed-length (256 bits / 32 bytes) hash value (also known as a "digest"), possessing properties such as collision resistance, irreversibility, and avalanche effect. It is a core algorithm in fields such as blockchain, digital signatures, and document integrity verification.

[0050] The SIM card (Subscriber Identity Module) is a core component of a mobile communication system, used to uniquely identify a user, store critical information, and perform secure authentication. It is not only the "key" for mobile phone network access but also carries functions related to user privacy, communication security, and some value-added services.

[0051] Figure 1 This diagram illustrates a SIM card activation system according to an embodiment of the present disclosure. The SIM card activation system includes:

[0052] Terminal 101, activation device 102 and key management system 103.

[0053] The activation device 102 is a terminal device for activating the SIM card for the user. The key management system is located on the operator's side and is responsible for distributing quantum keys with the activation device, generating, storing and managing quantum keys.

[0054] An application can be installed in the activation device to perform the following actions: collecting the identity information submitted by the user; generating a quantum key with the key management system through quantum key distribution; encrypting the identity information using the quantum key to obtain encrypted data; and sending the encrypted data to the key management system to activate the user's identity module SIM card.

[0055] An application can be installed in the key management system to perform the following actions: generating a quantum key with the activation device via quantum key distribution; receiving encrypted data sent by the activation device; decrypting the encrypted data using the quantum key to obtain the user's identity information; and activating the user's SIM card based on the identity information.

[0056] Figure 2 This diagram illustrates a flowchart of a SIM card activation method according to an embodiment of the present disclosure. This method can be applied to an activation device. The method is as follows: Figure 2 As shown, it includes the following steps:

[0057] S201, Collect the identity information submitted by the user.

[0058] Identity information includes at least one of the following: a photo of the user's ID card, a live photo, a signature, basic personal information, and mobile phone number information.

[0059] S202, together with the key management system, generates quantum keys through quantum key distribution.

[0060] In quantum key distribution, the activation device and the key management system generate quantum keys independently based on their own random selection of measurement bases and the information exchanged. The two parties do not exchange quantum keys, so quantum key leakage can be avoided. Moreover, based on quantum principles, if an attack occurs, the activation device and the key management system will detect it, and the two parties can discard the information exchanged in this instance and redistribute the quantum key.

[0061] S203 uses quantum keys to encrypt identity information to obtain encrypted data.

[0062] As an example, a bitwise XOR operation is performed on the quantum key and identity information to obtain encrypted data.

[0063] As an example, the ECC algorithm is used to encrypt identity information using quantum keys to obtain encrypted data.

[0064] S204, send encrypted data to the key management system to activate the user's identity module SIM card.

[0065] After receiving the encrypted data, the key management system uses a quantum key to decrypt the identity information, obtains the identity information, and then uses the identity information to activate the SIM card.

[0066] This disclosure embodiment uses the above-described technical means to encrypt the user-submitted identity information using quantum keys before transmission, preventing the identity information from being eavesdropped on or tampered with during transmission. This solves the security threat to user identity information in SIM card activation by related technologies, thereby protecting data privacy and improving security.

[0067] Figure 3 This diagram illustrates a flowchart of a quantum key generation method according to an embodiment of the present disclosure. The method is as follows: Figure 3 As shown, it includes the following steps:

[0068] S301, Generate a random bit stream, and randomly select a measurement basis for each bit in the random bit stream to obtain the first measurement basis set;

[0069] S302, based on each bit and the measurement basis of each bit, determines the quantum state of each bit;

[0070] S303, send the first set of measurement bases and the quantum states of each bit to the key management system;

[0071] S304, Receive a second set of measurement bases sent by the key management system, wherein the second set of measurement bases includes measurement bases randomly selected by the key management system for measuring each quantum state;

[0072] S305, determine the same measurement basis in the same order from the first measurement basis set and the second measurement basis set to obtain the third measurement basis set;

[0073] S306 generates a quantum key based on the bits corresponding to the measurement basis in the third measurement basis set.

[0074] An exemplary random bit stream is a binary sequence of 0s and 1s generated by an activated device; the term includes the raw data stream that serves as a candidate bit for quantum key distribution.

[0075] As an example, a measurement basis is a quantum mechanical basis vector used to represent the encoding or measurement of a quantum state. This term includes two types: rectangular basis and diagonal basis, which affect the preparation and detection of quantum states.

[0076] As an example, the first set of measurement bases includes a measurement base that corresponds one-to-one with each bit in the random bit stream.

[0077] Exemplary, a quantum state is a quantum state determined based on bit values ​​and measurement basis, including physical representations realized as single-photon polarization states or phase states. The quantum state corresponding to a bit and measurement basis can be determined through methods such as mapping; this process can be understood as encoding.

[0078] As an example, the second set of measurement bases is a set of measurement bases randomly selected by the key management system when measuring the received quantum state. The number of measurement bases in the first set of measurement bases and the second set of measurement bases is the same, which is equal to the number of quantum states or bits.

[0079] As an example, the third measurement basis set is a subset selected from the first and second measurement basis sets that have the same measurement basis at the same position. For example, if the measurement basis at the first position of the first and second measurement basis sets is the same, then the measurement basis is put into the third measurement basis set; if the measurement basis at the second position of the first and second measurement basis sets is different, then the measurement basis is discarded.

[0080] In this embodiment, the activation device generates a random bit stream and randomly selects a measurement basis for each bit to form a first measurement basis set. Based on the bit value and the measurement basis, it determines the corresponding quantum state and sends the first measurement basis set and the quantum state to the key management system. The key management system measures the received quantum state, uses its independently selected second measurement basis set, and feeds this set back to the activation device. The activation device compares the first and second measurement basis sets, extracts the portions where the measurement basis is consistent at the same position, and forms a third measurement basis set. Then, the bits corresponding to the measurement basis in the third measurement basis set are used to generate the final quantum key. Through the above technical means, the activation device and the key management system generate the quantum key by publicly comparing measurement basis and filtering out matching portions, ensuring that bits are retained only when both parties use the same basis. This utilizes quantum mechanics principles to introduce detectable errors into eavesdropping, thereby ensuring the security of the quantum key distribution process.

[0081] In one optional embodiment, generating a quantum key with a key management system via quantum key distribution includes: activating a device to generate a random bit stream and randomly selecting a phase modulation scheme for each bit in the random bit stream to obtain a first phase-coded sequence; generating a weakly coherent optical pulse sequence as a quantum state signal based on each bit and its corresponding phase modulation scheme; sending the weakly coherent optical pulse sequence to the key management system; receiving a second phase-coded sequence sent by the key management system, wherein the second phase-coded sequence includes the phase modulation selection used by the key management system at the receiving end for demodulating each pulse; comparing the first phase-coded sequence and the second phase-coded sequence to determine the positions where the modulation schemes are consistent, forming a matching phase set; and extracting the bits at the corresponding positions of the matching phase set to generate a quantum key. Through the above technical means, quantum state preparation and measurement are achieved using a phase encoding method, enhancing the compatibility and stability of quantum key distribution in practical communication infrastructures.

[0082] Figure 4 This invention discloses a flowchart of another quantum key generation method according to an embodiment of the present disclosure. The method is as follows: Figure 4 As shown, it includes the following steps:

[0083] S401 sends a portion of the bits in the random bit stream to the key management system;

[0084] S402, Receive the quantum error rate fed back by the key management system, wherein the key management system determines the quantum error rate by comparing the received partial bits with the measurement results of each quantum state;

[0085] S403: When the quantum error rate exceeds a preset threshold, destroy the quantum key and regenerate a quantum key with the key management system via quantum key distribution.

[0086] As an example, the quantum error rate is the proportion of errors calculated by a key management system by comparing the difference between the received partial random bit stream and the actual measurement result. For instance, if the key management system receives the first 20% of bits (partial bits) of the random bit stream, it compares the received bits with the first 20% of bits in the actual measurement result, and then calculates the error proportion to obtain the quantum error rate.

[0087] In this embodiment, the activation device sends a portion of the bits from the random bit stream used to generate the quantum key to the key management system. The key management system compares its measurement results with the received portion of the bits, calculates the quantum error rate (BER), and feeds it back to the activation device. The activation device then determines whether the received BER exceeds a preset threshold. If it does, the generated quantum key is immediately destroyed, and a new round of quantum key distribution is initiated. Through these technical means, by publicly comparing a portion of the bits to calculate the BER, and utilizing quantum mechanics principles to detect any illegal measurement of the quantum channel, the use of the key is terminated promptly when there is a risk of eavesdropping, thereby ensuring the verifiable security of the key distribution process.

[0088] In some embodiments, the method further includes: when the number of measurement bases in the third measurement base set is less than a preset number, after initialization, regenerating a quantum key with the key management system through quantum key distribution.

[0089] In this embodiment, after determining the third measurement base set, the activation device counts the number of measurement bases included in it. If this number is less than a preset number, it is determined that the effective key bits generated in this quantum key distribution are insufficient to support subsequent encryption operations. Therefore, initialization is performed to clear all current intermediate data (including the generated random bit stream, the first measurement base set, the quantum states of each bit, and the received second measurement base set), and the quantum key distribution process is restarted. This includes regenerating the random bit stream, reselecting measurement bases, re-encoding and transmitting the quantum states until a third measurement base set meeting the length requirement is obtained. Through the above technical means, by determining whether the number of matching measurement bases reaches a security threshold, it ensures that the generated quantum key has a sufficient length to support high-strength encryption, avoiding security risks caused by an excessively short key.

[0090] Figure 5 This invention discloses a flowchart illustrating a method for determining a set of measurement bases according to an embodiment of the present disclosure. The method is as follows: Figure 5 As shown, it includes the following steps:

[0091] Execute the following loop:

[0092] S501, Determine whether the number of measurement bases in the third measurement base set is less than the preset number;

[0093] S502, if it is greater than or equal to, then generate a quantum key based on the bit corresponding to the measurement basis in the third measurement basis set, and end the loop;

[0094] If S503 is less than 1, then after initialization, the third measurement basis set is determined again with the key management system through quantum key distribution.

[0095] If the number of measurement bases in the third measurement base set is less than a preset number, initialization is performed to clear all current intermediate data. Then, the third measurement base set is re-determined with the key management system via quantum key distribution, including: generating a random bit stream and randomly selecting a measurement base for each bit in the random bit stream to obtain a first measurement base set; determining the quantum state of each bit based on each bit and the measurement base of each bit; sending the first measurement base set and the quantum states of each bit to the key management system; receiving the second measurement base set sent by the key management system, wherein the second measurement base set includes measurement bases randomly selected by the key management system for measuring each quantum state; and determining the same measurement bases in the same order from the first and second measurement base sets to obtain the third measurement base set.

[0096] The embodiments disclosed herein utilize the aforementioned technical means to cyclically perform quantum key distribution until a valid key bit that meets the length requirement is obtained, ensuring that the final generated quantum key has a sufficient bit length, thereby avoiding security risks caused by insufficient key length.

[0097] In an optional embodiment, the method further includes: performing the following first loop: determining whether the number of measurement bases in the third measurement base set is less than a preset number; if less, then after initialization, re-determining the third measurement base set with the key management system via quantum key distribution; if greater than or equal to, then generating a quantum key based on the bits corresponding to the measurement bases in the third measurement base set, and ending the first loop; performing the following second loop: sending a portion of the bits in the random bit stream to the key management system; receiving the quantum error rate fed back by the key management system; when the quantum error rate is greater than a preset threshold, destroying the quantum key and re-generating a quantum key with the key management system via quantum key distribution; when the quantum error rate is less than or equal to the preset threshold, encrypting the identity information using the quantum key to obtain encrypted data; sending the encrypted data to the key management system, and ending the second loop.

[0098] In some embodiments, the method further includes: processing the identity information using a hash algorithm to obtain a first hash value representing the length of the identity information; and sending the encrypted data and the first hash value to a key management system to activate the SIM card.

[0099] As an example, the first hash value is a fixed length calculated from the identity information using a hash algorithm to verify data integrity; the hash algorithm could be the SHA-256 algorithm.

[0100] In this embodiment, after generating encrypted data, the activation device further processes the original identity information using a hash algorithm to obtain a first hash value, and sends this hash value along with the encrypted data to the key management system. The key management system decrypts the received encrypted data to obtain the decrypted identity information, and performs the same hash algorithm calculation on this information to obtain a corresponding hash value. This hash value is then compared with the received first hash value. If they match, it confirms that the identity information has not been tampered with during transmission, and the SIM card activation process continues. Through the above technical means, by calculating and attaching a hash value of the identity information at the sending end, the receiving end can verify the integrity of the decrypted data.

[0101] In some embodiments, the quantum key is destroyed after the SIM card is activated.

[0102] Once activation is complete, the quantum SIM card and key management system of the activated device automatically destroys the quantum key used for this activation, ensuring the uniqueness and non-reusability of the key and eliminating the possibility of it being stolen and misused in the future.

[0103] Figure 6 This invention discloses a flowchart of another SIM card activation method according to an embodiment of the present disclosure. This method is applied to a key management system, and the method is as follows: Figure 6 As shown, it includes the following steps:

[0104] S601 generates a quantum key with the activation device via quantum key distribution;

[0105] S602, receives encrypted data sent by the activated device;

[0106] S603 uses quantum key distribution to decrypt encrypted data and obtain the user's identity information;

[0107] S604, activates the user's SIM card based on identity information.

[0108] In this embodiment, the key management system and the activation device negotiate and generate a quantum key through a quantum key distribution protocol. The system receives encrypted data sent by the activation device, decrypts the encrypted data using the quantum key to recover the original identity information, and performs verification and registration operations based on this identity information, thereby completing the activation of the user's SIM card. By employing the above technical means, the system addresses the security threat posed by related technologies in activating user identity information on SIM cards, thereby protecting data privacy and improving security.

[0109] Figure 7 This invention discloses a flowchart of another quantum key generation method according to an embodiment of the present disclosure. The method is as follows: Figure 7 As shown, it includes the following steps:

[0110] S701 receives the first set of measurement bases and the quantum states of each bit sent by the activation device;

[0111] S702, randomly select a measurement basis for each bit to obtain a second measurement basis set, and use the measurement basis in the second measurement basis set to measure the quantum state of each bit in turn to obtain the measurement result of the quantum state of each bit;

[0112] S703, the second measurement base set is sent to the activation device;

[0113] S704, determine the same measurement basis in the same order from the first measurement basis set and the second measurement basis set to obtain the third measurement basis set;

[0114] S705 generates a quantum key based on the measurement results of the quantum states of the bits corresponding to the measurement basis in the third measurement basis set.

[0115] In this embodiment, the key management system independently and randomly selects a measurement basis for each quantum state to form a second measurement basis set. Measurements are then performed on each quantum state according to this set to obtain measurement results. The second measurement basis set is compared with the first measurement basis set to determine the measurement basis that matches in the same order, forming a third measurement basis set. The measurement results corresponding to the measurement basis in this set are then extracted as valid bits to generate a quantum key for decryption. Through these techniques, the key management system generates a quantum key based on a matching measurement basis shared with the activation device. Utilizing the basis dependency and non-cloning property of quantum state measurements, it ensures that any eavesdropping will introduce detectable errors, thereby guaranteeing the security of the key distribution process.

[0116] In one optional embodiment, generating a quantum key with an activation device via quantum key distribution includes: a key management system receiving a weakly coherent optical pulse sequence and a corresponding first phase encoding sequence sent by the activation device; randomly selecting a demodulation phase for each pulse to form a second phase encoding sequence, and measuring each pulse using an interferometer to obtain the measurement result; sending the second phase encoding sequence to the activation device; comparing the first and second phase encoding sequences to determine the positions where the phase modulation methods are consistent, forming a matching phase set; and generating a quantum key based on the measurement results at the corresponding positions of the matching phase set. By employing the above techniques, quantum key distribution is achieved through a combination of phase encoding and interferometry, improving the stability and compatibility of the system in practical deployments.

[0117] Figure 8 This invention discloses a flowchart of yet another quantum key generation method according to an embodiment of the present disclosure. The method is as follows: Figure 8 As shown, it includes the following steps:

[0118] S801, Receive a portion of bits from the random bit stream sent by the activating device;

[0119] S802 determines the quantum error rate by comparing the received partial bits with the measurement results of each quantum state;

[0120] S803 sends the quantum bit error rate to the activation device;

[0121] S804: When the quantum error rate exceeds a preset threshold, the quantum key is destroyed, and a new quantum key is generated by quantum key distribution with the activation device.

[0122] In this embodiment, the key management system receives a portion of the bits from the random bit stream sent by the activation device, compares it with its own measurement results at the corresponding positions, calculates the quantum error rate, and feeds back the error rate to the activation device. If the activation device determines that the error rate is greater than a preset threshold, both parties stop using the currently generated quantum key and initiate a new round of quantum key distribution. Through the above technical means, the key management system detects abnormal disturbances in the quantum channel by publicly comparing a portion of the bits, identifies potential eavesdropping behavior using quantum mechanics principles, and ensures the verifiable security of the key distribution process.

[0123] In some embodiments, the method further includes: if the number of measurement bases in the third measurement base set is less than a preset number, then after initialization, re-determine the third measurement base set with the activation device through quantum key distribution.

[0124] In this embodiment, after generating the third measurement basis set, the key management system determines whether the number of measurement basis units contained therein is less than a preset number. If it is less than this threshold, it is considered that there are insufficient valid key bits to support the security encryption requirements. Therefore, it initializes to clear all intermediate data and responds to the re-key distribution process initiated by the activation device, re-participating in the measurement basis selection, quantum state measurement, and basis vector comparison processes to generate a new third measurement basis set. Through the above technical means, by determining whether the number of matching measurement basis units meets the security requirements, it ensures that the generated quantum key has a sufficient length.

[0125] Figure 9 A flowchart illustrating another method for determining a measurement basis set in an embodiment of this disclosure is shown, the method as follows: Figure 9 As shown, it includes the following steps:

[0126] Execute the following loop:

[0127] S901, determine whether the number of measurement bases in the third measurement base set is less than the preset number;

[0128] S902, if it is greater than or equal to, then generate a quantum key based on the bit corresponding to the measurement basis in the third measurement basis set, and end the loop;

[0129] If S903 is less than 1, then after initialization, the third measurement basis set is determined again with the activation device through quantum key distribution.

[0130] If the number of measurement bases in the third measurement base set is less than a preset number, initialization is performed to clear all current intermediate data. Then, the third measurement base set is re-determined with the activating device via quantum key distribution, including: receiving the first measurement base set and the quantum state of each bit sent by the activating device; randomly selecting a measurement base for each bit to obtain the second measurement base set, and using the measurement bases in the second measurement base set to sequentially measure the quantum state of each bit to obtain the measurement result of the quantum state of each bit; sending the second measurement base set to the activating device; and determining the same measurement bases in the same order from the first and second measurement base sets to obtain the third measurement base set.

[0131] The embodiments disclosed herein utilize the aforementioned technical means to cyclically perform quantum key distribution until a valid key bit that meets the length requirement is obtained, ensuring that the final generated quantum key has a sufficient bit length, thereby avoiding security risks caused by insufficient key length.

[0132] In an optional embodiment, the method further includes: performing the following third loop: determining whether the number of measurement bases in the third measurement base set is less than a preset number; if less, after initialization, re-determining the third measurement base set with the activation device via quantum key distribution; if greater than or equal to, generating a quantum key based on the bits corresponding to the measurement bases in the third measurement base set, and ending the third loop; performing the following fourth loop: receiving a portion of the bits in the random bit stream sent by the activation device; determining the quantum error rate by comparing the received portion of the bits with the measurement results of each quantum state; sending the quantum error rate to the activation device; when the quantum error rate is greater than a preset threshold, destroying the quantum key and re-generating a quantum key with the activation device via quantum key distribution; when the quantum error rate is less than or equal to the preset threshold, receiving encrypted data, decrypting the encrypted data using the quantum key to obtain identity information, activating the user's SIM card based on the identity information, and ending the fourth loop.

[0133] In some embodiments, the method further includes: receiving a first hash value sent by an activation device; processing the identity information using a hash algorithm to obtain a second hash value representing the length of the identity information; and activating the SIM card based on the identity information when the first hash value and the second hash value are equal.

[0134] In this embodiment, the key management system receives a first hash value sent by the activation device. After decrypting the encrypted data using a quantum key to obtain the identity information, it processes the identity information using the same hash algorithm to generate a second hash value. The first hash value is then compared with the second hash value. If they are equal, it is determined that the identity information has not been tampered with during transmission, and the SIM card activation operation is then performed based on this identity information. By comparing the hash value of the decrypted identity information with the received original hash value, the integrity of the data during transmission is verified, preventing malicious modification of the identity information and thus ensuring the authenticity and security of the data during the SIM card activation process.

[0135] In some embodiments, the quantum key is destroyed after the SIM card is activated.

[0136] Once activation is complete, the quantum SIM card and key management system of the activated device automatically destroys the quantum key used for this activation, ensuring the uniqueness and non-reusability of the key and eliminating the possibility of it being stolen and misused in the future.

[0137] In one exemplary embodiment, when a user activates a SIM card, the activation device needs to collect and transmit the user's identity information (such as a photo of their ID card, a live photo, signature, etc.) to the operator for identity verification. To prevent this sensitive information from being stolen or tampered with during transmission, quantum encryption technology is used to encrypt the information during transmission, ensuring user privacy and data security. Implementation process:

[0138] Users submit identity information on the activation device, including a photo of their ID card, a live photo, a signature, basic personal information, and mobile phone number information. The app activating the device integrates the collected user information into a data package D.

[0139] The quantum SIM card in the activation device and the operator's key management system generate a one-time quantum key through quantum key distribution (QKD). Specifically, the activation device generates a random bit stream B = {b_1, b_2, ..., b_n} and randomly selects a ground state θ = {θ_1, θ_2, ..., θ_n}, encoding the bit stream into quantum states based on these two states. After receiving these quantum states, the key management system randomly selects a ground state to measure each quantum bit, obtaining a measurement result M = {m_1, m_2, ..., m_n}. The activation device and the key management system publicly compare the ground state selections and retain only the data matching the ground state to generate a shared key S = {s_1, s_2, ..., s_x}.

[0140] The activation device uses a quantum key S to encrypt the user information data packet D bit by bit, generating an encrypted data packet C.

[0141] To ensure the integrity of data transmission, the activating device uses the SHA-256 algorithm to generate a hash value H for the encrypted data packet C. This hash value will be used by the receiver to verify the integrity of the data packet C.

[0142] The encrypted data packet C and its hash value H are transmitted together to the key management system via the mobile communication network.

[0143] After receiving data packet C and hash value H, the key management system decrypts the data packet using the same quantum key as the activated device to recover the original data. The key management system recalculates the hash value of the decrypted data packet and compares it with the received hash value H. If they match, the data integrity verification passes, indicating that the data has not been tampered with during transmission; if they do not match, the data integrity verification fails, and the operator can request a retransmission of the data packet.

[0144] After the data integrity verification is passed, the operator will transfer the user information to the identity verification system for real-name verification, complete the user identity authentication process, and activate the SIM card.

[0145] Upon activation, the quantum SIM card and key management system of the activated device automatically destroys the quantum key used for this activation. The destruction operation completely removes the key from the quantum SIM card and key management system, ensuring the uniqueness and non-reusability of the key and eliminating the possibility of subsequent theft and misuse.

[0146] This disclosure embodiment generates a one-time key through quantum key distribution and uses it to encrypt user information to prevent eavesdropping and tampering during transmission. By using the above-mentioned technical means, the non-measurability and non-copyability of quantum mechanics are utilized to ensure the security of the key during the generation and distribution process. Even if there is eavesdropping, the eavesdropper cannot obtain the real key, thereby protecting the user's privacy information from being leaked.

[0147] This embodiment of the disclosure incorporates a quantum encryption component and a key storage medium within the quantum SIM card, enabling the generation and management of quantum keys. This achieves both convenience and security in information encryption. Through the aforementioned technical means, the quantum SIM card and the application on the activation device work together to complete key generation, storage, and encryption operations, ensuring absolute key security at the hardware level and preventing unauthorized access or copying of the key during storage or use.

[0148] This embodiment of the disclosure uses quantum key encryption to encrypt user information item by item and generates a hash value based on the SHA-256 algorithm to achieve integrity protection during data transmission. By using the above technical means, hash value verification information is added to the encrypted data packet, enabling the receiver to verify the integrity of the decrypted data, effectively detecting and preventing data from being tampered with during transmission, and improving the integrity and anti-attack capability of user information transmission.

[0149] Based on the same inventive concept, this disclosure also provides an activation device and a key management system, as shown in the following embodiments. Since the principle by which the activation device and key management system solves the problem is similar to that of the above method embodiments, the implementation of the activation device and key management system can refer to the implementation of the above method embodiments, and repeated details will not be elaborated further.

[0150] Figure 10 An activation device is shown in an embodiment of this disclosure, such as Figure 10 As shown, the activation device may include:

[0151] The data collection unit 1001 is configured to collect the identity information submitted by the user.

[0152] The first generation unit 1002 is configured to generate quantum keys with the key management system through quantum key distribution.

[0153] The encryption unit 1003 is configured to encrypt identity information using a quantum key to obtain encrypted data;

[0154] The sending unit 1004 is configured to send encrypted data to the key management system to activate the user's identity module SIM card.

[0155] In some embodiments, the first generation unit 1002 is further configured to generate a random bit stream and randomly select a measurement basis for each bit in the random bit stream to obtain a first measurement basis set; determine the quantum state of each bit based on each bit and the measurement basis of each bit; send the first measurement basis set and the quantum state of each bit to the key management system; receive a second measurement basis set sent by the key management system, wherein the second measurement basis set includes measurement basis randomly selected by the key management system for measuring each quantum state; determine the same measurement basis in the same order from the first measurement basis set and the second measurement basis set to obtain a third measurement basis set; and generate a quantum key based on the bits corresponding to the measurement basis in the third measurement basis set.

[0156] In some embodiments, the first generation unit 1002 is further configured to send a portion of the bits in the random bit stream to the key management system; receive the quantum error rate fed back by the key management system, wherein the key management system determines the quantum error rate by comparing the received portion of the bits with the measurement results of each quantum state; when the quantum error rate is greater than a preset threshold, destroy the quantum key and regenerate the quantum key with the key management system through quantum key distribution.

[0157] In some embodiments, the first generation unit 1002 is further configured to, after initialization, regenerate a quantum key with the key management system via quantum key distribution when the number of measurement bases in the third measurement base set is less than a preset number.

[0158] In some embodiments, the first generation unit 1002 is further configured to perform the following loop: determine whether the number of measurement bases in the third measurement base set is less than a preset number; if it is greater than or equal to, generate a quantum key based on the bits corresponding to the measurement bases in the third measurement base set and end the loop; if it is less than, perform initialization and then re-determine the third measurement base set with the key management system through quantum key distribution.

[0159] In some embodiments, the sending unit 1004 is further configured to process the identity information using a hash algorithm to obtain a first hash value representing the length of the identity information; and send the encrypted data and the first hash value to the key management system to activate the SIM card.

[0160] In some embodiments, the transmitting unit 1004 is further configured to destroy the quantum key after activating the SIM card.

[0161] Figure 11 This disclosure illustrates a key management system, such as... Figure 11 As shown, the key management system may include:

[0162] The second generation unit 1101 is configured to generate a quantum key with the activation device via quantum key distribution.

[0163] The receiving unit 1102 is configured to receive encrypted data sent by the activating device;

[0164] The decryption unit 1103 is configured to use a quantum key to decrypt encrypted data and obtain the user's identity information;

[0165] Activation unit 1104 is configured to activate a user's SIM card based on identity information.

[0166] In some embodiments, the second generation unit 1101 is further configured to receive a first measurement basis set and the quantum state of each bit sent by the activation device; randomly select a measurement basis for each bit to obtain a second measurement basis set, and use the measurement basis in the second measurement basis set to measure the quantum state of each bit in sequence to obtain the measurement result of the quantum state of each bit; send the second measurement basis set to the activation device; determine the same measurement basis in the same order from the first measurement basis set and the second measurement basis set to obtain a third measurement basis set; and generate a quantum key based on the measurement result of the quantum state of the bit corresponding to the measurement basis in the third measurement basis set.

[0167] In some embodiments, the second generation unit 1101 is further configured to receive a portion of bits from a random bit stream sent by the activation device; determine the quantum error rate by comparing the received portion of bits with the measurement results of each quantum state; send the quantum error rate to the activation device; and when the quantum error rate is greater than a preset threshold, destroy the quantum key and regenerate the quantum key with the activation device through quantum key distribution.

[0168] In some embodiments, the second generation unit 1101 is further configured to, after initialization, re-determine the third measurement base set with the activation device via quantum key distribution when the number of measurement bases in the third measurement base set is less than a preset number.

[0169] In some embodiments, the second generation unit 1101 is further configured to perform the following loop: determine whether the number of measurement bases in the third measurement base set is less than a preset number; if it is greater than or equal to, generate a quantum key based on the bits corresponding to the measurement bases in the third measurement base set and end the loop; if it is less than, perform initialization and then re-determine the third measurement base set with the activation device through quantum key distribution.

[0170] In some embodiments, the activation unit 1104 is further configured to receive a first hash value sent by the activation device; process the identity information using a hash algorithm to obtain a second hash value representing the length of the identity information; and activate the SIM card based on the identity information when the first hash value and the second hash value are equal.

[0171] In some embodiments, the activation unit 1104 is further configured to destroy the quantum key after activating the SIM card.

[0172] Those skilled in the art will understand that various aspects of this disclosure can be implemented as a system, method, or program product. Therefore, various aspects of this disclosure can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, collectively referred to herein as a "circuit," "module," or "system."

[0173] The following reference Figure 12 To describe an electronic device 1200 according to such an embodiment of the present disclosure. Figure 12 The electronic device 1200 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.

[0174] like Figure 12As shown, the electronic device 1200 is presented in the form of a general-purpose computing device. The components of the electronic device 1200 may include, but are not limited to: at least one processor 1210, at least one memory 1220, and a bus 1230 connecting different system components (including memory 1220 and processor 1210).

[0175] The memory stores program code that can be executed by the processor 1210, causing the processor 1210 to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of this disclosure. For example, the processor 1210 can perform the following steps of the above method embodiments: collecting identity information submitted by the user; generating a quantum key with the key management system through quantum key distribution; encrypting the identity information using the quantum key to obtain encrypted data; and sending the encrypted data to the key management system to activate the user's SIM card.

[0176] The processor 1210 can perform the following steps in the above method embodiment: generating a quantum key with the activation device through quantum key distribution; receiving encrypted data sent by the activation device; decrypting the encrypted data using the quantum key to obtain the user's identity information; and activating the user's SIM card based on the identity information.

[0177] The memory 1220 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 12201 and / or cache memory 12202, and may further include read-only memory (ROM) 12203.

[0178] The memory 1220 may also include a program / utility 12204 having a set (at least one) of program modules 12205, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.

[0179] Bus 1230 can represent one or more of several types of bus structures, including a memory bus or memory controller, peripheral bus, graphics acceleration port, processor, or a local bus using any of the various bus structures.

[0180] Electronic device 1200 can also communicate with one or more external devices 1240 (e.g., keyboard, pointing device, Bluetooth device, etc.), activate with one or more first SIM cards enabling user interaction with electronic device 1200, and / or communicate with any device enabling electronic device 1200 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 1250. Furthermore, electronic device 1200 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 1260. As shown, network adapter 1260 communicates with other modules of electronic device 1200 via bus 1230. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 1200, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0181] In the disclosed exemplary embodiments, a computer-readable storage medium is also provided, which may be a readable signal medium or a readable storage medium.

[0182] In some possible implementations, various aspects of this disclosure may also be implemented as a program product comprising program code that, when run on a terminal device, causes the terminal device to perform the steps described in the foregoing “Detailed Description” section of this specification according to various exemplary embodiments of this disclosure.

[0183] More specific examples of computer-readable storage media in this disclosure may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0184] In this disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of transmitting, propagating, or transmitting a program for use by or in connection with an instruction execution system, apparatus, or device.

[0185] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0186] In practice, program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on a terminal device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0187] This disclosure provides a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform a SIM card activation method provided in various alternative embodiments of this disclosure.

[0188] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0189] Furthermore, although the steps of the method in this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additional or alternative steps may be omitted, multiple steps may be combined into one step, and / or a step may be broken down into multiple steps.

[0190] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of this disclosure.

[0191] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope of this disclosure is indicated by the appended claims.

Claims

1. A SIM card activation method, applied to an activation device, characterized in that, include: Collect user-submitted identity information; Quantum keys are generated through quantum key distribution in conjunction with a key management system; The identity information is encrypted using the quantum key to obtain encrypted data; The encrypted data is sent to the key management system to activate the user's SIM card.

2. The method according to claim 1, characterized in that, The key management system generates quantum keys through quantum key distribution, including: A random bit stream is generated, and a measurement basis is randomly selected for each bit in the random bit stream to obtain a first set of measurement bases; The quantum state of each bit is determined based on each bit and the measurement basis of each bit. The first set of measurement bases and the quantum states of each bit are sent to the key management system; The system receives a second set of measurement bases sent by the key management system, wherein the second set of measurement bases includes measurement bases randomly selected by the key management system for measuring each quantum state; A third set of measurement bases is obtained by identifying the same measurement bases in the same order from the first set of measurement bases and the second set of measurement bases. The quantum key is generated based on the bits corresponding to the measurement bases in the third set of measurement bases.

3. The method according to claim 2, characterized in that, The method further includes: Send a portion of the bits from the random bit stream to the key management system; The quantum error rate is received from the key management system, wherein the key management system determines the quantum error rate by comparing the received partial bits with the measurement results of each quantum state; When the quantum error rate exceeds a preset threshold, the quantum key is destroyed, and a new quantum key is generated by quantum key distribution with the key management system.

4. The method according to claim 2, characterized in that, The method further includes: If the number of measurement bases in the third measurement base set is less than the preset number, then after initialization, a quantum key is generated again through quantum key distribution with the key management system.

5. The method according to claim 2, characterized in that, The method further includes: Execute the following loop: Determine whether the number of measurement bases in the third measurement base set is less than a preset number; If it is greater than or equal to, then the quantum key is generated based on the bit corresponding to the measurement basis in the third measurement basis set, and the loop ends; If it is less than, then after initialization, the third measurement basis set is re-determined with the key management system through quantum key distribution.

6. The method according to claim 1, characterized in that, The method further includes: The identity information is processed using a hash algorithm to obtain a first hash value representing the length of the identity information; The encrypted data and the first hash value are sent to the key management system to activate the SIM card.

7. The method according to claim 1, characterized in that, After activating the SIM card, the quantum key is destroyed.

8. A SIM card activation method, applied to a key management system, characterized in that, include: The activation device generates a quantum key through quantum key distribution; Receive encrypted data sent by the activation device; The encrypted data is decrypted using the quantum key to obtain the user's identity information; The user's SIM card is activated based on the identity information.

9. The method according to claim 8, characterized in that, The activation device generates a quantum key via quantum key distribution, including: Receive the first set of measurement bases and the quantum states of each bit sent by the activation device; For each bit, a measurement basis is randomly selected to obtain a second measurement basis set. The quantum state of each bit is measured sequentially using the measurement basis in the second measurement basis set to obtain the measurement result of the quantum state of each bit. The second set of measurement bases is sent to the activation device; A third set of measurement bases is obtained by identifying the same measurement bases in the same order from the first set of measurement bases and the second set of measurement bases. The quantum key is generated based on the measurement results of the quantum states of the bits corresponding to the measurement basis in the third set of measurement basis.

10. The method according to claim 9, characterized in that, The method further includes: Receive a portion of bits from the random bit stream sent by the activation device; The quantum error rate is determined by comparing the received partial bits with the measurement results of each quantum state. The quantum error rate is sent to the activation device; When the quantum error rate exceeds a preset threshold, the quantum key is destroyed, and a new quantum key is generated by quantum key distribution with the activation device.

11. The method according to claim 9, characterized in that, The method further includes: If the number of measurement bases in the third measurement base set is less than the preset number, then after initialization, the third measurement base set is re-determined with the activation device through quantum key distribution.

12. The method according to claim 9, characterized in that, The method further includes: Execute the following loop: Determine whether the number of measurement bases in the third measurement base set is less than a preset number; If it is greater than or equal to, then the quantum key is generated based on the bit corresponding to the measurement basis in the third measurement basis set, and the loop ends; If it is less than, then after initialization, the third measurement basis set is determined again with the activation device via quantum key distribution.

13. The method according to claim 8, characterized in that, The method further includes: Receive the first hash value sent by the activation device; The identity information is processed using a hash algorithm to obtain a second hash value representing the length of the identity information; If the first hash value and the second hash value are equal, the SIM card is activated based on the identity information.

14. The method according to claim 8, characterized in that, After activating the SIM card, the quantum key is destroyed.

15. An activation device, characterized in that, include: The data collection unit is configured to collect identity information submitted by the user. The first generation unit is configured to generate quantum keys with the key management system via quantum key distribution. An encryption unit is configured to encrypt the identity information using the quantum key to obtain encrypted data; The sending unit is configured to send the encrypted data to the key management system to activate the user's SIM card.

16. A key management system, characterized in that, include: The second generation unit is configured to generate quantum keys with the activation device via quantum key distribution. The receiving unit is configured to receive encrypted data sent by the activation device; The decryption unit is configured to decrypt the encrypted data using the quantum key to obtain the user's identity information; The activation unit is configured to activate the user's SIM card based on the identity information.

17. An electronic device, characterized in that, include: processor; as well as Memory for storing the executable instructions of the processor; The processor is configured to execute the method of any one of claims 1-7 or 8-14 by executing the executable instructions.

18. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 1-7 or 8-14.

19. A computer program product comprising computer instructions stored in a computer-readable storage medium, wherein the computer instructions, when executed by a processor, implement the operation instructions of the method according to any one of claims 1-7 or 8-14.