Anonymous subscription service providing method and device, equipment, storage medium and product
By generating and sharing anonymous identifiers through an anonymous subscription service platform, the problems of insufficient stability and poor cross-system compatibility of anonymous identifiers are solved, and stable identifier user services and privacy protection are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-25
- Publication Date
- 2026-03-13
AI Technical Summary
Existing anonymous login technologies suffer from insufficient stability of anonymous identifiers and poor cross-system compatibility, making it difficult for businesses to provide services to users based on stable identifiers.
Anonymous identifiers are generated through an anonymous subscription service platform. Key identification information (such as the target mobile phone number and International Mobile Equipment Identity) obtained by the gateway is used to establish a mapping relationship between the anonymous identifier and the mobile phone number. The anonymous identifier is then shared with the business party. When the business party responds to the service provision instruction, it sends service-related information carrying the identifier to the anonymous subscription service platform. The anonymous subscription service platform determines the target mobile phone number based on the mapping relationship and provides the service.
It protects user privacy, improves cross-system compatibility, supports business units in providing services to users based on stable identifiers, and protects user privacy.
Smart Images

Figure CN121665225A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of anonymous login technology, and in particular to a method, apparatus, device, storage medium and product for providing anonymous subscription services. Background Technology
[0002] With increasing emphasis on personal privacy protection, anonymous login technology is being used more and more widely. Its core objective is to provide a privacy-preserving device identifier, supporting business units in achieving core business functions such as device identification and service adaptation while protecting user privacy, thereby providing stable services to users. Currently, the China Advertising ID (CAID) and the Open Advertising ID (OAID) are two typical device identification technologies for anonymous login in the industry, but both have significant drawbacks.
[0003] The technical solutions for CAID mainly fall into two categories: one is where the user device automatically collects hardware parameters and random numbers, generates a CAID through an algorithm, and synchronously uploads the mapping relationship between the device and the CAID to the server; the other is where the client collects non-user privacy data with a certain degree of identification capability, uploads it to the server, and the server combines this data with random numbers to generate a CAID and distributes it to the client for application use. This solution has significant shortcomings: firstly, after a device undergoes a system upgrade or factory reset, the core parameters for generating the CAID will change, causing the CAID to change accordingly and making it impossible to maintain long-term unique identification capabilities; secondly, its design violates Apple's App Tracking Transparency (ATT) framework, making it unusable on Apple's mobile operating system (iOS). Ultimately, due to a lack of practical implementation cases, updates and iterations ceased, making it difficult to achieve large-scale application.
[0004] OAID, introduced by the China Mobile Internet Industry Alliance, is generated during application installation. However, this solution also has drawbacks: firstly, there are scenarios where OAID acquisition fails, affecting the identifier's usability; secondly, it lacks stability, as a factory reset triggers an OAID reset, making it impossible to guarantee its long-term uniqueness.
[0005] Therefore, there is an urgent need for a stable and iOS-compatible anonymous subscription service solution to support businesses in providing services to users. Summary of the Invention
[0006] This invention provides a method, apparatus, device, storage medium, and product for providing anonymous subscription services, in order to address the shortcomings of existing technologies where insufficient stability of anonymous identifiers and poor cross-system compatibility make it difficult for business operators to provide services to users based on stable identifiers.
[0007] In a first aspect, embodiments of the present invention provide a method for providing anonymous subscription services, applied to a business entity, including: In response to a service provision instruction, the system sends service-related information carrying a target anonymous identifier to an anonymous subscription service platform, so that the anonymous subscription service platform performs a service provision operation. The service provision operation includes: determining a target mobile phone number based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, and providing services to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation.
[0008] Secondly, embodiments of the present invention also provide a method for providing anonymous subscription services, applied to an anonymous subscription service platform, comprising: Receive service-related information carrying the target anonymous identifier sent by the service provider; Based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, the target mobile phone number is determined according to the target anonymous identifier, and services are provided to the user terminal currently bound to the target mobile phone number; The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation.
[0009] Thirdly, embodiments of the present invention also provide a method for providing anonymous subscription services, applied to an anonymous identifier management server, including: Receive anonymous identifier retrieval requests initiated by business parties; The gateway obtains key identification information associated with the anonymous identification request; wherein, the key identification information includes the target mobile phone number and / or International Mobile Equipment Identity (IMSI). And generate a target anonymous identifier based on the key identification information; The target anonymous identifier is returned to the business party for use by the business party when performing the anonymous subscription service provision method applied to the business party as described above.
[0010] Fourthly, embodiments of the present invention also provide a method for providing an anonymous subscription service, applied to a user identification card, including: The system receives a signature request initiated by a business party, carrying a business identifier and a temporary credential. The temporary credential of the business party is generated by the business party in the following manner: by sending an anonymous identifier acquisition request to the anonymous identifier management server, carrying the business identifier, so that the anonymous identifier management server can obtain key identifier information associated with the anonymous identifier acquisition request through the gateway and generate the temporary credential. The key identifier information includes the target mobile phone number and / or International Mobile Equipment Identity (IMEI). The temporary credential is signed using a pre-generated SIM card signing private key to generate the signature value of the temporary credential; The signature value of the temporary credential is returned to the business party, so that the business party sends the business identifier and the signature value of the temporary credential to the anonymous identifier management server, and obtains the target anonymous identifier for requesting the anonymous subscription service from the anonymous identifier management server. The target anonymous identifier is generated by the anonymous identifier management server based on the key identifier information after the signature value of the temporary credential has been verified. The signature value of the temporary credential is verified according to the SIM card signature public key provided in advance by the user identification card.
[0011] Fifthly, embodiments of the present invention also provide an anonymous subscription service providing apparatus, comprising: An anonymous subscription module is used to respond to a service provision instruction by sending service-related information carrying a target anonymous identifier to an anonymous subscription service platform, so that the anonymous subscription service platform can perform a service provision operation. The service provision operation includes: determining a target mobile phone number based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, and providing services to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation.
[0012] Sixthly, embodiments of the present invention also provide an anonymous subscription service providing apparatus, comprising: The information receiving module is used to receive service-related information carrying a target anonymous identifier sent by the service provider; An anonymous subscription service provides services to determine a target mobile phone number based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, and to provide services to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number, and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound at the time of generation.
[0013] In a seventh aspect, embodiments of the present invention also provide an anonymous subscription service providing apparatus, comprising: The identifier acquisition request receiving module is used to receive anonymous identifier acquisition requests initiated by the business party; The key identifier acquisition module is used to acquire key identifier information associated with the anonymous identifier acquisition request through the gateway; wherein, the key identifier information includes the target mobile phone number and / or International Mobile Equipment Identity (IMEI); An anonymous identifier generation module is used to generate a target anonymous identifier based on the key identifier information; The target anonymous identifier is returned to the business party for use by the business party when performing any of the above-described methods for providing anonymous subscription services to the business party.
[0014] Eighthly, embodiments of the present invention also provide an anonymous subscription service providing apparatus, comprising: The signature request receiving module is used to receive a signature request initiated by a business party, carrying a business identifier and a temporary credential. The temporary credential is generated by the business party by sending an anonymous identifier acquisition request to an anonymous identifier management server, carrying the business identifier. This allows the anonymous identifier management server to obtain key identifier information associated with the anonymous identifier acquisition request through a gateway and generate the temporary credential. The key identifier information includes a target mobile phone number and / or an International Mobile Equipment Identity (IMEI). The signature module is used to sign the temporary credential using a pre-generated SIM card signature private key, and generate the signature value of the temporary credential. The signature value return module is used to return the signature value of the temporary credential to the business party, so that the business party can send the business identifier and the signature value of the temporary credential to the anonymous identifier management server, and obtain the target anonymous identifier for requesting the anonymous subscription service from the anonymous identifier management server; The target anonymous identifier is generated by the anonymous identifier management server based on the key identifier information after the signature value of the temporary credential has been verified. The signature value of the temporary credential is verified according to the SIM card signature public key provided in advance by the user identification card.
[0015] In a ninth aspect, embodiments of the present invention also provide an anonymous subscription service providing device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the anonymous subscription service providing method as described in any of the above embodiments.
[0016] In a tenth aspect, embodiments of the present invention also provide a computer-readable storage medium comprising a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the anonymous subscription service provision method as described in any of the above embodiments.
[0017] Eleventhly, embodiments of the present invention also provide a computer program product, including a computer program / instructions, which, when executed by a processor, implement the anonymous subscription service provision method as described in any of the above embodiments.
[0018] Compared with existing technologies, the anonymous subscription service provision method, apparatus, device, storage medium, and product provided in this embodiment of the invention firstly involve the service provider responding to a service provision instruction by sending service-related information carrying a target anonymous identifier to the anonymous subscription service platform. Then, the anonymous subscription service platform, based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, determines the target mobile phone number according to the target anonymous identifier and provides the corresponding service to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is pre-generated by the anonymous subscription service platform based on key identification information obtained from a gateway, establishing a mapping relationship between the anonymous identifier and the target mobile phone number, and sharing the target anonymous identifier with the service provider. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation. Therefore, this embodiment of the invention generates an anonymous identifier based on key identification information (target mobile phone number and / or International Mobile Equipment Identity) obtained from the gateway through an anonymous subscription service platform, establishes a mapping between the identifier and the mobile phone number, and then shares the anonymous identifier with the business party. When the business party responds to the service provision instruction, it sends service-related information carrying the identifier to the anonymous subscription service platform. The anonymous subscription service platform determines the target mobile phone number based on the mapping relationship and provides services to the user. This not only protects user privacy but also improves cross-system compatibility, supports business parties in providing services to users based on stable identifiers, and protects user privacy. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of an anonymous ID request and acquisition process provided by an embodiment of the present invention; Figure 2 This is a schematic diagram of a PIN code initialization process provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of a certificate initialization process provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of a key pair initialization process provided in an embodiment of the present invention; Figure 5 This is a flowchart illustrating an anonymous subscription service provision method according to an embodiment of the present invention; Figure 6 This is a flowchart illustrating an anonymous subscription service provision method according to an embodiment of the present invention; Figure 7 This is a schematic diagram of the structure of an anonymous subscription service providing device according to an embodiment of the present invention; Figure 8 This is a schematic diagram of the structure of an anonymous subscription service providing device according to an embodiment of the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] With the strengthening of national and policy protection for personal privacy, the application of anonymous login technology is increasing. Its core advantages are: strengthening user privacy protection and reducing the risk of personal information leakage; simplifying the user access process, avoiding users from being harassed by targeted advertising and spam, supporting service trials and quick switching of user identities; enhancing users' control over their own data; and adapting to global privacy compliance requirements.
[0022] Furthermore, anonymous login can alleviate the compliance pressure on service providers under data protection regulations, providing convenience for emergency scenarios or one-off service use. It is important to note that when providing anonymous login functionality, service providers must balance service security and service quality, addressing the dual needs of user privacy protection and service management.
[0023] Currently, anonymous login on the market primarily identifies users or devices through anonymous identifiers (IDs). Sensitive information such as the user's mobile phone number and International Mobile Equipment Identity (IMEI) is not output in plaintext. The main anonymous ID technologies include the following: 1. Identifier for Advertisers (IDFA) Introduced by Apple, IDFA is only available for iOS devices. Its core purpose is to uniquely identify devices and support personalized advertising and statistical analysis. Starting with iOS 14.5, Apple officially implemented the App Tracking Transparency (ATT) framework without additional extensions. Apps must obtain explicit user authorization via a pop-up window before they can access and use IDFA.
[0024] As a result of this policy, some developers predict that over two-thirds of users will refuse to authorize tracking, making it difficult to achieve cross-application (APP) full-scenario intelligent marketing and exacerbating the data silo phenomenon. This identifier is only compatible with iOS and does not support Android or other platforms.
[0025] 2. Open Advertising ID (OAID) Launched under the leadership of the China Mobile Internet Industry Alliance (CAIA) and the Mobile Security Alliance (MSA), this system is primarily designed for Android devices and aims to balance ad tracking needs with user privacy protection. Its core features, technical details, and limitations are as follows: Generation and Uniqueness: The OAID is generated when the device is first started. The OAID of the same device is consistent across all applications (supports sharing among multiple applications); the OAID will change synchronously when the device is restored to factory settings, manually reset by the user, or when the tracking switch is turned off.
[0026] Composition and Format: OAID is composed of an Android Identifier (AID) and an Android Version Code. The standard format is "AID:Android Version Code". After generation, it needs to be encrypted and compressed using the SHA-256 algorithm to ensure the uniqueness of the identifier, data security, and long-term validity. Among them: 1) The AID is generated by Google, and each Android device is assigned a unique AID, which only changes after a factory reset; 2) The Android version number is based on the official Android OS version definition from Google and is used to identify the current system version running on the device.
[0027] Generation rules and compatibility: MSA only standardizes the technical framework and basic requirements for OAID. The specific generation logic (such as encoding length and character format) is defined by each mobile phone manufacturer, resulting in differences in OAID format between different brands of devices (such as Huawei using a 14-digit number combination and Xiaomi using a 32-digit string), which limits compatibility to a certain extent.
[0028] Key limitations: In practical applications, there are scenarios where OAID acquisition fails; at the same time, the identifier lacks a dedicated security protection mechanism and anti-fraud capability, making it easy to be maliciously tampered with; in addition, the platform grants users the permission to disable or manually reset the OAID, and the identifier value will change directly after the reset, affecting the stability of the identifier.
[0029] 3. China Advertising ID (CAID) Introduced by the Chinese advertising industry, its initial purpose was to address the limitations of Apple's ATT framework on IDFA, providing advertisers with an alternative for precise targeting and performance tracking. Its core mechanism and current status are as follows: There are two main generation methods: one is client-side generation (collecting device hardware parameters and random numbers, generating and uploading mapping relationships through algorithms, which has the problems of frequent interaction and inconvenience in rule adjustment); the other is server-side generation (the client collects non-privacy data and sends it to the centralized ID management center, which generates and distributes it after using multi-parameter and random number algorithms to ensure the uniqueness of the single device identifier).
[0030] Current status: Due to violations of Apple's ATT framework privacy rules, CAID has been banned from use in iOS applications by Apple, and there have been no further updates due to a lack of practical application cases.
[0031] 4. International Mobile Equipment Identity (IMEI) It is a globally unique hardware identifier for mobile devices, burned into the device during manufacturing. Its core purpose is for device tracking and management in mobile communication networks. However, due to privacy protection requirements, starting with Android 10, applications cannot obtain unique device identifiers such as IMEI and MAC address.
[0032] To address the shortcomings of existing technologies, such as insufficient stability and poor cross-system compatibility of anonymous identifiers, which make it difficult for business users to provide services to users based on stable identifiers, an embodiment of the present invention provides a method for providing anonymous subscription services, applied to business users. The method includes: In response to a service provision instruction, the system sends service-related information carrying a target anonymous identifier to an anonymous subscription service platform, so that the anonymous subscription service platform performs a service provision operation. The service provision operation includes: determining a target mobile phone number based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, and providing services to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation.
[0033] Specifically, service provision instructions are generally triggered by users. For example, when a user clicks on an application or webpage that requires a service from the business provider, such as "Use Membership Service" or "Receive Push Notifications," the user sends service-related information to the anonymous subscription service platform. This information must include the target anonymous identifier. Upon receiving the request from the business provider, the anonymous subscription service platform executes the service provision operation. The core of this operation is to locate the real user terminal using the anonymous identifier. The platform pre-stores the mapping relationship between anonymous identifiers and mobile phone numbers; The platform uses the anonymous identifier sent by the business party to find the corresponding target mobile phone number in the mapping relationship; Finally, the service is provided to the user terminal currently bound to this target mobile number (such as the user's current mobile phone; even if the device is changed, as long as the mobile phone number is not changed, it can be located).
[0034] The services provided by the business provider include sending text messages, images, or making phone calls to user terminals, etc., which are not limited here.
[0035] It is worth noting that the method has a key premise: the target anonymous identifier is not generated by the business party itself, but is prepared in advance by the platform and shared with the business party, and the generation logic ensures its stability. Generating entity: Anonymous subscription service platform; Generation Basis: The platform obtains key identification information through the gateway (either the user's target mobile phone number, the IMEI of the device bound to that mobile phone number, or both). Understandably, when the user is not logged in, the platform uses the user's device IMEI and mobile phone number obtained through the operator's gateway capabilities to generate an anonymous identifier (anonymous ID, or UAID). This anonymous ID is mapped to the corresponding IMEI and mobile phone number, ensuring the stability of the anonymous ID and preventing it from being limited by device and system-level parameters. Furthermore, the mobile phone number is invisible to the enterprise, and the number remains within the operator's domain throughout the number conversion process, ensuring high security. Core action: The platform generates a unique target anonymous identifier based on these key identification information, and establishes a mapping relationship between the anonymous identifier and the target mobile phone number; Shared action: The platform synchronizes this target anonymous identifier with the business party, which can then use it directly when requesting services in the future.
[0036] Preferably, the service provision operation is performed by the anonymous identifier management server in the anonymous subscription service platform.
[0037] Compared with existing technologies, the embodiments of the present invention generate anonymous identifiers based on key identification information (target mobile phone number and / or International Mobile Equipment Identity) obtained by the gateway through an anonymous subscription service platform, establish a mapping between the anonymous identifier and the mobile phone number, and then share the anonymous identifier with the business party. When the business party responds to the service provision instruction, it sends service-related information carrying the identifier to the anonymous subscription service platform. The anonymous subscription service platform determines the target mobile phone number based on the mapping relationship and provides services to the user. This not only protects user privacy but also improves cross-system compatibility, supports business parties in providing services to users based on stable identifiers, and protects user privacy.
[0038] In a preferred embodiment, the step of sending service-related information carrying a target anonymous identifier to the anonymous subscription service platform in response to a service provision instruction, so that the anonymous subscription service platform performs a service provision operation, includes: In response to a service provision instruction, the system obtains the basic information of the business party, performs signature processing on the basic information, and generates signature information. The target anonymous identifier is encrypted using the generated symmetric key to generate anonymous identifier ciphertext; The symmetric key is encrypted using a preset private key from the business party to generate an encryption key; Submit the obtained business identifier, the signature information, the anonymous identifier ciphertext, and the encryption key to the anonymous subscription service platform so that the anonymous subscription service platform can perform service provision operations; The service provision operations include: The corresponding basic information is retrieved from the pre-stored information based on the business identifier, and the signature information is verified based on the retrieved basic information. The encryption key is decrypted using a preset public key from the business party; The ciphertext of the anonymous identifier is processed using the symmetric key obtained from decryption to restore the target anonymous identifier; Based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, the target mobile phone number is determined according to the target anonymous identifier, and services are provided to the user terminal currently bound to the target mobile phone number.
[0039] Specifically, after responding to the service provision instruction, the business party submits key information to the anonymous subscription service platform through a secure method of "signature + double encryption". After identity verification and decryption to restore the anonymous identifier, the platform associates the user's mobile phone number and provides services.
[0040] Furthermore, the basic information also includes the authorization period, and the symmetric key is generated based on the authorization period; The step of decrypting the encryption key using a preset business party public key includes: After the signature information is verified, the validity of the retrieved authorization validity period is checked; a reference key is generated based on the retrieved authorization validity period. If the authorization period is valid and the reference key is equal to the decrypted symmetric key, the encryption key is decrypted using the preset business party public key.
[0041] For example, the business party first completes the access configuration (such as system integration and function debugging), determines its unique business identifier (APPID) and application key appkeySK (i.e., the business party's private key), and can selectively report the business party's server IP to the anonymous subscription service platform (the platform will add these IPs to a trust list (i.e., a whitelist), and only requests initiated from IPs within this whitelist will be accepted and processed by the platform; requests from IPs outside the whitelist will be directly blocked). The process of the business party initiating a service request and the platform providing the service is as follows: 1. The business side's server sends a service request (related to batch anonymous identification UAID). When the business server (i.e., the service server) needs to initiate a service request, follow these steps: (1) Generate verification signature: First, collect basic information and merge it into a string. Then, use the SM3 cryptographic hash function (SM3 algorithm) to calculate a signature. This signature is used by the platform to verify whether the request comes from a legitimate business party. The basic information may include the application identifier APPID, IP whitelist, appkeySK (application key), authorization validity period, etc. The authorization validity period is related to the UAID and can be the UAID generation time or the UAID validity period.
[0042] The formula is as follows: Sign = SM3(APPID + IP whitelist + appkeySK + authorization time) (Note: the "+" sign means merging and is not included in the encrypted string). The APPID (application identifier), IP whitelist (list of allowed IP addresses), appkeySK (application key), and authorization time are used by the anonymous subscription service platform to verify the signature after receiving the information, confirming that the information comes from a previously applied-for service and not from an unknown requester.
[0043] (2) Encrypt batch UAIDs (or encrypt a single UAID): Obtain the authorization validity period and use the SHA256 algorithm to generate a random number R (as the key for subsequent encryption). The system filters the stored UAID information in the local database, concatenates the batch of UAIDs (UAID1, UAID2, ..., UAIDi) to be sent into a whole, and uses the national cryptographic SM4 block cipher algorithm (SM4 algorithm) to perform an XOR operation with a random number R to generate an anonymous identifier ciphertext MAC. The random number R is encrypted using the RSA asymmetric encryption algorithm (Rivest-Shamir-Adleman, RSA) with the business party's own private key (appkeySK) to obtain the encryption key (i.e., ciphertext MAC1).
[0044] The formula is as follows: R = SHA256(Author_TIME); MAC=SM4((UAID1||UAID2||UAID2||…||UAIDi) R); MAC1=Enc(RSA(R,appkeySK)).
[0045] (3) Submit request: Send the four types of information, namely APPID, Sign, MAC and MAC1 generated earlier, to the anonymous subscription service platform via HTTPS protocol. Specifically, send them to the anonymous identifier management server in the anonymous subscription service platform.
[0046] 2. The platform verifies the identity of business parties and executes services. Upon receiving a request, the anonymous subscription service platform verifies and processes it according to the following procedure: (1) Verify signature + confirm legality: First, use the APPID in the request to query the information of the business party that is stored on the platform (such as the reported IP whitelist and the business party's public key appkeyPK). Using the same method as the business party (SM3 algorithm), a new digest is generated based on the queried information and compared with the received signature information. If the two match, it means that the request has not been tampered with and the source is legitimate; if they do not match, the request is rejected directly.
[0047] (2) Verify the validity of the time: Check whether the authorization time in the request is within the valid range stored in the platform. If it exceeds the range, discard the request.
[0048] (3) Decryption to obtain batch UAIDs: Use the business party's public key appkeyPK to decrypt MAC1 using the RSA algorithm to obtain a random number R: R=Dec(RSA(MAC1,appkeyPK)); Then, using the authorization validity period of the business party stored on the platform, a random number R* is generated using the SHA256 algorithm. The R and R* are compared to see if they match. If they match, the process continues; otherwise, the request is discarded. Finally, the SM4 algorithm, combined with a random number R, is used to decrypt the MAC, restoring the original batch UAIDs: UAID1||UAID2||UAID2||.....||UAIDi=SM4(MAC) R).
[0049] (4) Match UAID and provide services: The platform matches the restored UAID with the UAID stored in the platform's local database (LOG_UAID_INFO table). If they do not match, the request is discarded. Once a match is successful, the corresponding phone number in Advanced Encryption Standard (AES) encryption format is retrieved, and decryption is performed to obtain the real phone number. The system queries the mobile number's current operator through the portability interface, and then sends an SMS message or makes a phone call to the user via the SMS gateway or the operator's outbound call line.
[0050] It is worth noting that the encryption methods involved in this implementation method are not limited to the specific algorithm types mentioned above. Appropriate algorithms can be selected according to the actual situation, and no limitation is made here.
[0051] In a preferred embodiment, before sending service-related information carrying a target anonymous identifier to the anonymous subscription service platform in response to a service provision instruction, so that the anonymous subscription service platform performs the service provision operation, the method further includes: An anonymous identifier acquisition request is initiated to the anonymous subscription service platform, so that the anonymous subscription service platform can obtain the key identifier information through the gateway and generate the target anonymous identifier based on the key identifier information; Receive the target anonymous identifier returned by the anonymous subscription service platform.
[0052] Specifically, the user selects anonymous subscription on the service provider's app and completes the authorization (e.g., entering the previously set PIN code). The service provider's app sends an anonymous identifier acquisition request to the anonymous subscription service platform by carrying its valid credential APPID. The core components of the anonymous subscription service platform (such as the anonymous identifier management server) obtain key identifier information through the operator's internal dedicated gateway interface (the key identifier information only circulates within the operator, and the service provider cannot see the plaintext, completely isolating external access). Based on the key identifier information, a target anonymous identifier is generated and returned to the service provider. The service provider only needs to send a request to the platform with the target anonymous identifier, and the platform internally maps it to a mobile phone number through UAID and performs the service provision operation.
[0053] In a preferred embodiment, the target anonymity identifier is generated by the anonymity subscription service platform in the following manner: After data preprocessing and standardization, the key identification information is subjected to feature extraction to obtain a feature vector; The preset quantum-secure key is combined with the feature vector and processed by a quantum-secure hash function to generate preliminary anonymity information; The initial anonymization information is encrypted to generate a target anonymization identifier.
[0054] Specifically, anonymous ID generation employs Quantum Key Distribution (QKD) technology and quantum-secure symmetric encryption algorithm authentication. As an example, the following is a brief introduction to the anonymous identifier generation algorithm: The phone number and IMEI data are preprocessed and standardized, and feature extraction is performed using a deep neural network model (other models can also be used). A quantum-secure key is generated using quantum key distribution technology, combined with a quantum-secure hash function to generate an encrypted ID, and then a quantum-secure symmetric encryption algorithm is used to generate the final anonymous ID (UAID). Specific generation rules: 1. Data preprocessing: Verify the validity of the input mobile phone number and IMEI-A, and standardize the data to unify the data format, expanding it to 128 bits, using x=[x1,x2,x3,…xn], where n is 128, to eliminate differences between different devices and users.
[0055] Mobile phone number and IMEI converted into a numerical sequence: Mobile phone number sequence: [1, 9, 8, 0, 2, 0, 2, 1, 0, 1, 9, 0, 0, 0, 0, 0, 0, ……]; IMEI sequence: [8, 6, 9, 4, 1, 5, 0, 6, 9, 5, 2, 4, 8, 5, 8, 0, 0, 0, ...].
[0056] 2. Feature Extraction: A deep neural network model is used to extract features from the numerical sequences of the mobile phone number and IMEI, generating two 128-dimensional feature vectors.
[0057] Mobile phone number feature vector: [0.1, 0.2, ..., 0.8, 0.9, 1.0]; IMEI feature vector: [1.0, 0.9, ..., 0.3, 0.2, 0.1].
[0058] 3. Using quantum key distribution (QKD) technology, a 256-bit quantum secure key is generated. This key is randomized, and its value is known only to the legitimate communicating parties. The key will be used in the encryption process.
[0059] 4. Quantum-safe hash function: Each 128-dimensional feature vector is combined with a 256-bit quantum-safe key and processed using a quantum-safe hash function to generate two 128-bit hash values, which serve as the initial encrypted ID. The feature vector and quantum key are combined in the following way: Mobile phone number combined with data: mobile phone number feature vector + the first 128 bits of the quantum key; IMEI combined with data: IMEI feature vector + the last 128 bits of the quantum key.
[0060] 5. Encrypted ID generation: The two 128-bit hash values are further encrypted using a quantum-safe symmetric encryption algorithm to generate the final encrypted IDs (uuid1 and uuid2).
[0061] Mobile phone number hash value (uuid1): Hash function (mobile phone number combined with data); IMEI hash value (uuid2): Hash function (IMEI combined with data).
[0062] 6. Anonymous ID concatenation: The encrypted ID (uuid1) of the mobile phone number and the encrypted ID (uuid2) of the IMEI are concatenated into a unique 256-bit anonymous ID (UAID).
[0063] 7. The anonymous subscription service platform returns an anonymous ID (UAID) to the business party and concatenates it with the authorization validity period (i.e., authorization duration) to form a data set. As shown in the following formula: ={UAID||Author_TIME}; The relationship between anonymous IDs and phone numbers is stored in the database table LOG_UAID_INFO, as shown in the table below:
[0064] In a preferred embodiment, the step of initiating an anonymous identifier acquisition request to the anonymous subscription service platform, so that the anonymous subscription service platform obtains the key identifier information through the gateway and generates the target anonymous identifier based on the key identifier information, includes: The system sends an anonymous identifier retrieval request to the anonymous subscription service platform, carrying a business identifier, so that the anonymous subscription service platform can obtain the key identifier information through the gateway. The system receives a PIN code to be verified from the user and sends it along with the business identifier to the anonymous subscription service platform to request identity verification. The anonymous subscription service platform then verifies the PIN code to be verified based on a pre-stored reference PIN code. After the PIN code to be verified is successfully verified, the system generates the target anonymous identifier based on the key identification information and shares it with the business party.
[0065] Specifically, the business requires user authorization to obtain the target anonymous identifier. The user accesses the business's service through the application, selects anonymous subscription, enters a PIN code, and after verification by the anonymous subscription service platform, authorizes the application to obtain the target anonymous identifier. If the user submits an authorization cancellation request through the client interface, the anonymous subscription service platform verifies the validity of the target anonymous identifier and updates the authorization certificate status to "invalid".
[0066] It's worth noting that users must actively choose anonymous subscription and enter a PIN code to trigger the generation of an anonymous identifier. This prevents business entities from forcibly obtaining user identifiers and making unauthorized calls, thus eliminating unauthorized SMS / call harassment at the source. The platform supports submitting cancellation requests through the customer interface, and the platform immediately updates the corresponding authorization certificate status to invalid, avoiding the risk of "once authorized, always being contacted."
[0067] Furthermore, the anonymous subscription service platform includes a user identification card and an anonymous identifier management server; The step of sending an anonymous identifier retrieval request to the anonymous subscription service platform, carrying a business identifier, so that the anonymous subscription service platform can obtain the key identifier information through the gateway, includes: The application installed on the user terminal sends an anonymous identifier acquisition request to the anonymous identifier management server, carrying a business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway. The process of receiving a user-inputted PIN code to be verified, and requesting identity verification from the anonymous subscription service platform along with the PIN code and the business identifier, allows the anonymous subscription service platform to verify the PIN code based on a pre-stored reference PIN code. Upon successful verification of the PIN code, the platform generates the target anonymous identifier based on the key identification information and shares it with the business party. This includes: The application receives a PIN code to be verified input by the user, and sends the PIN code and the business identifier to the user identification card to request authentication, so that the user identification card verifies the PIN code to be verified according to the pre-stored reference PIN code, and sends a PIN code verification success message to the application after successful verification. The application receives the PIN code verification success information and triggers the anonymous identifier management server to generate and return the target anonymous identifier; wherein, the target anonymous identifier is generated by the anonymous identifier management server based on the key identifier information.
[0068] Specifically, the business party includes the application programs of the business party. The anonymous subscription service platform includes a user identification card and an anonymous identification management server. The user identification card and the application programs are deployed on the user terminal. The user identification card is used to store the reference PIN code and perform PIN code verification (hardware-level security verification). The anonymous identification management server is used to receive requests from the business party, obtain key identification information through the operator gateway, and generate a target anonymous identifier. The user identification card can be a super SIM card, an embedded SIM card (Embedded SIM, eSIM), or a Universal Subscriber Identity Module (USIM), etc. The Chinese name of SIM is user identification card, and its English full name is Subscriber Identity Module.
[0069] Among them, the business party includes the APP and the server. The core operation process for the business party to obtain the target anonymous identifier is as follows: 1. The APP of the business party carries the business identifier APPID and发起 an anonymous identifier acquisition request to the anonymous identification management server; 2. After receiving the request, the anonymous identification management server obtains the key identification information through the internal operator gateway interface (only accessible to the platform); 3. The APP renders the PIN code input page, and the user inputs the PIN code to be verified (the reference PIN code set by the user before); 4. The APP carries the PIN code to be verified and the business identifier APPID and发起 an authentication request to the user identification card (such as a super SIM card); 5. The user identification card retrieves the pre-stored reference PIN code from its own hardware storage and compares it with the PIN code to be verified. Only when the two are consistent is the verification determined to be successful; 6. The user identification card returns the PIN code verification success information to the APP; 7. After receiving the success information, the APP triggers the anonymous identification management server to execute the "UAID generation" operation; 8. The anonymous identification management server generates the target anonymous identifier UAID based on the key identification information (such as the mobile phone number and IMEI) obtained from the gateway before; 9. The anonymous identification management server returns the UAID to the APP. It can be understood that the APP can share the UAID with the server of the business party.
[0070] This embodiment clarifies the standardized and secure process for obtaining the anonymous ID and has the following advantages: The division of labor among components is clear: the user identification card is responsible for "authentication" (PIN code verification), and the anonymous identification management server is responsible for "data acquisition + UAID generation". The powers and responsibilities are separated, reducing security risks; Authorization closed-loop: Only when the user actively inputs the PIN code and the verification is passed can the UAID be generated, ensuring the user's autonomous control over personal information and conforming to privacy protection regulations; Secure and controllable: The phone number and IMEI only circulate within the operator's domain, and the PIN code is stored in hardware and internally verified, blocking the risk of privacy leakage throughout the process.
[0071] In a preferred embodiment, the anonymous subscription service platform includes a user identification card, an anonymous identifier management server, and a CA certificate platform; The step of initiating an anonymous identifier acquisition request to the anonymous subscription service platform, so that the anonymous subscription service platform can obtain the key identifier information through the gateway and generate the target anonymous identifier based on the key identifier information, includes: The application installed on the user terminal sends an anonymous identifier acquisition request to the anonymous identifier management server, carrying the business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, obtain the pre-generated certificate serial number corresponding to the key identifier information and the business identifier, and generate a temporary credential. The application receives the temporary credential and certificate serial number returned by the anonymous identifier management server, initiates a signature request to the user identification card carrying the service identifier, the temporary credential, and the certificate serial number, so that the user identification card signs the temporary credential based on the pre-stored SIM card signature private key corresponding to the certificate serial number, generates the signature value of the temporary credential, and returns the certificate serial number and the signature value of the temporary credential to the service party; Carrying the business identifier, the certificate serial number, and the signature value of the temporary credential, the anonymous identifier management server initiates a signature verification request to the CA certificate platform. This allows the CA certificate platform to verify the signature value of the temporary credential based on a pre-stored SIM card signature public key corresponding to the certificate serial number and return the signature verification result to the anonymous identifier management server. After determining that the signature value of the temporary credential has passed verification based on the signature verification result, the anonymous identifier management server generates the target anonymous identifier based on the key identifier information.
[0072] Specifically, the business side includes the business application, and the anonymous subscription service platform includes a user identification card, an anonymous identity management server, and a CA certificate platform. The user identification card and application are deployed on the user terminal. The user identification card is used to store the SIM card signing private key (pre-generated) and perform hardware-level signing on temporary credentials (the private key is not leaked). The anonymous identity management server is used to perform the following operations: 1. Receive requests and obtain key identification information through the gateway; 2. Obtain the certificate serial number and generate temporary credentials; 3. Forward signature verification requests; 4. Generate UAID after successful signature verification.
[0073] The enhanced anonymous ID acquisition process in this embodiment is as follows: 1. Initiate a request → Obtain temporary credentials and certificate serial number (1) The APP carries the business identifier APPID and sends an anonymous identifier acquisition request to the anonymous identifier management server; (2) After receiving the request, the anonymous identifier management server obtains the key identifier information through the operator's internal gateway; (3) The management server queries the pre-generated corresponding certificate serial number from the CA certificate platform based on the key identification information and business identifier; (4) The management server generates a temporary credential (such as a random number accessToken, which is only used for this signature verification to prevent sensitive information from being directly involved in the signature). (5) The management server returns the temporary credential and certificate serial number to the APP.
[0074] 2. User identification card signature → Generate signature value (1) After receiving the temporary credential and certificate serial number, the APP initiates a signature request to the user identification card, carrying three key pieces of information: APPID, temporary credential, and certificate serial number; (2) The user identification card retrieves the corresponding SIM card signature private key from its own hardware storage based on the certificate serial number (the private key is always stored in the card, is not transmitted to the outside world, and cannot be cracked). (3) The user identification card uses the private key to encrypt and sign the "temporary credential" to generate the "signature value of the temporary credential" (only the corresponding public key can verify the validity of the signature); (4) The user identification card returns the certificate serial number and the signature value of the temporary credential to the APP.
[0075] 3. CA verification → UAID generated upon successful verification (1) The APP carries the APPID, certificate serial number and the signature value of the temporary certificate, and sends a signature verification request to the CA certificate platform through the anonymous identifier management server; (2) The CA certificate platform retrieves the pre-stored SIM card signature public key (which is a pair of asymmetric keys with the user identification card's private key) based on the certificate serial number. (3) The CA certificate platform uses the public key to verify the signature value of the temporary certificate: If the signature verification passes: it proves that the signature was generated by the corresponding private key (i.e., the request comes from a legitimate user device and has not been tampered with); if the signature verification fails: the request is rejected directly and the process is terminated. (4) The CA certificate platform returns the signature verification result to the anonymous identifier management server; (5) After the management server confirms that the signature verification is successful, it generates a UAID based on the key identification information obtained in step 1; (6) The management server returns the UAID to the APP.
[0076] In this implementation, illegal requests are blocked by using hardware-level private key signing and third-party CA verification.
[0077] Furthermore, receiving the target anonymous identifier returned by the anonymous subscription service platform includes: receiving the target anonymous identifier returned by the anonymous identifier management server through the application.
[0078] In a preferred embodiment, the anonymous subscription service platform includes a user identification card, an anonymous identifier management server, and a CA certificate platform; The step of initiating an anonymous identifier acquisition request to the anonymous subscription service platform, so that the anonymous subscription service platform can obtain the key identifier information through the gateway and generate the target anonymous identifier based on the key identifier information, includes: The application installed on the user terminal sends an anonymous identifier acquisition request to the anonymous identifier management server, carrying the business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, obtain the pre-generated certificate serial number corresponding to the key identifier information and the business identifier, and generate a temporary credential. The application receives the temporary credential and certificate serial number returned by the anonymous identifier management server. The application receives a PIN code to be verified input by the user, and sends the PIN code and the business identifier to the user identification card to request authentication, so that the user identification card verifies the PIN code to be verified according to the pre-stored reference PIN code, and sends a PIN code verification success message to the application after successful verification. After receiving the PIN code verification success information through the application, a signature request carrying the service identifier, the temporary credential, and the certificate serial number is initiated to the user identification card, so that the user identification card signs the temporary credential based on the pre-stored SIM card signature private key corresponding to the certificate serial number, generates the signature value of the temporary credential, and returns the certificate serial number and the signature value of the temporary credential to the service party. Carrying the business identifier, the certificate serial number, and the signature value of the temporary credential, the anonymous identifier management server initiates a signature verification request to the CA certificate platform. This allows the CA certificate platform to verify the signature value of the temporary credential based on a pre-stored SIM card signature public key corresponding to the certificate serial number and return the signature verification result to the anonymous identifier management server. After determining that the signature value of the temporary credential has passed verification based on the signature verification result, the anonymous identifier management server generates the target anonymous identifier based on the key identifier information.
[0079] Specifically, the business side includes the application and server, while the anonymous subscription service platform includes a user identification card, an anonymous identifier management server, and a CA certificate platform. The user identification card and application are deployed on the user terminal. The user identification card stores the SIM card signature private key (pre-generated), performs hardware-level signing on temporary credentials (private key not leaked), and also stores a reference PIN code and performs PIN code verification. The anonymous identifier management server performs the following operations: 1. Receives requests and obtains key identifier information through the gateway; 2. Obtains the certificate serial number and generates temporary credentials; 3. Forwards signature verification requests; 4. Generates a UAID after successful signature verification. The CA certificate platform stores the SIM card signature public key and performs third-party authoritative verification of the signature value of the temporary credentials (confirming signature validity).
[0080] The key prerequisites for this implementation include: 1. PIN code initialization completed: The user has previously set a reference PIN code in the APP, which is stored in the user identification card; 2. Key pair + certificate initialization completed: The user identification card pre-stores the SIM card signing private key, the CA certificate platform pre-stores the corresponding SIM card signing public key, and a unique certificate serial number binding the user and the business party has been generated. The anonymous ID acquisition process is as follows: 1. Initiate a request → Platform retrieves number + generates basic signature data (1) The APP sends an anonymous identifier retrieval request to the anonymous identifier management server, carrying the APPID; (2) The anonymous identifier management server obtains key identifier information through the operator's internal gateway. This is the core raw data for generating UAID and is not disclosed to the outside world throughout the process. (3) The anonymous identifier management server queries the pre-generated certificate serial number from the CA certificate platform based on the key identifier information (for subsequent matching of public and private keys). (4) The anonymous identifier management server generates a temporary credential (such as a random accessToken) – which is only used for this signature verification to avoid sensitive information (phone number / IMEI) from directly participating in the signature and reduce the risk of leakage; (5) The anonymous identifier management server returns the temporary credential and certificate serial number to the APP.
[0081] 2. Receiving data → APP waits for user authorization The app receives the temporary credential and certificate serial number returned by the anonymous identifier management server, renders the PIN code input page, and waits for the user to enter authorization.
[0082] 3. User Authorization → PIN Code Verification (Confirms user's consent) (1) The user enters the PIN code to be verified in the APP (the reference PIN code that they set beforehand); (2) The APP sends an identity verification request to the user identification card, carrying the PIN code and APPID to be verified; (3) The user identification card retrieves the pre-stored reference PIN code from its own hardware storage and compares it with the PIN code to be verified: Verification successful: A message indicating successful PIN code verification is returned to the app. Verification failed: The process terminates immediately, and no further operations are allowed; 4. Hardware Signature → User Identification Card Generates "Signature Value" (Identity Verification) (1) After receiving the PIN code verification success message, the APP initiates a signature request to the user identification card, carrying three key data: business identifier, temporary credential, and certificate serial number; (2) The user identification card retrieves the SIM card signature private key stored in its own memory based on the certificate serial number (the private key is always locked in the hardware and is not transmitted to the outside world, so it cannot be cracked). (3) The user identification card uses the private key to encrypt and sign the temporary certificate, generating a signature value for the temporary certificate. Only the corresponding public key (stored on the CA certificate platform) can verify the validity of the signature. (4) The user identification card returns the certificate serial number and the signature value of the temporary credential to the APP.
[0083] 5. Authoritative verification → UAID generated after CA confirms legitimacy. (1) The business party sends a "signature verification request" to the CA certificate platform through the anonymous identifier management server, carrying the APPID, certificate serial number and the signature value of the temporary certificate; (2) The CA certificate platform retrieves the pre-stored SIM card signature public key (which is a pair of asymmetric keys with the user identification card's private key) based on the certificate serial number. (3) The CA certificate platform uses the public key to verify the signature value of the temporary credential: Signature verification passed: This proves that the signature was generated with a legitimate private key (the device is genuine and the data has not been tampered with). Verification failed: The process was terminated and UAID generation was refused. The CA platform will return the signature verification result to the management server. (5) The anonymous identifier management server generates the target anonymous identifier UAID based on the key identifier information obtained in step 1; (6) The server returns the UAID to the APP.
[0084] In a preferred embodiment, the data interaction between the application and the user identification card is implemented through an anonymous identifier authentication SDK; the data interaction between the anonymous identifier authentication SDK and the user identification card is implemented through a machine-card channel; wherein, the Chinese name of SDK is Software Development Kit.
[0085] The anonymous identifier acquisition request is initiated by the application to the anonymous identifier management server through the anonymous identifier authentication SDK; the certificate serial number is obtained by the anonymous identifier management server from the CA certificate platform based on the key identifier information and the business identifier; The temporary credential and the certificate serial number are returned to the application by the anonymous identifier management server through the anonymous identifier authentication SDK; The signature verification request is initiated by the application sequentially through the business server and the anonymous identifier management server to the CA certificate platform; The target anonymous identifier returned by the anonymous identifier management server is sent to the application by the anonymous identifier management server through the business server.
[0086] For example, see Figure 1 After completing key pair initialization, certificate initialization, and PIN initialization, the anonymous ID request and retrieval process begins: 1. The business party sends an APP with parameters such as APPID to the anonymous identifier authentication SDK to request identity authentication. The anonymous identifier authentication SDK sends an APPID with parameters such as APPID to the anonymous identifier management server to request identity authentication. 2. The anonymous identifier management server retrieves the number from the gateway. After successfully retrieving the number, it sends a request to the CA certificate platform to query the certificate serial number, carrying parameters such as APPID, mobile phone number, and IMEI. 3. The CA certificate platform uses information such as mobile phone number and APPID to query the corresponding certificate serial number and returns it to the anonymous identifier management server; 4. The anonymous identifier management server generates a temporary access token, caches information such as the mobile phone number, IMEI, and APPID, and returns the certificate serial number and temporary access token to the anonymous identifier authentication SDK. The anonymous identifier authentication SDK then forwards the certificate serial number and temporary access token information to the business APP. 5. The business app renders the PIN code authentication authorization page. The user enters the PIN code, and the business app sends the APPID, PIN code, and other parameters to the anonymous identifier authentication SDK to request identity authentication. 6. The Anonymous Identifier Authentication SDK requests PIN code verification from the Super SIM card with parameters such as APPID and PIN code. After the Super SIM card completes the PIN code verification, it returns the PIN code verification result to the Anonymous Identifier Authentication SDK. The Anonymous Identifier Authentication SDK then transmits the verification result to the business APP. 7. The business app requests a signature from the anonymous identifier authentication SDK, carrying parameters such as the APPID. 8. The anonymous authentication SDK carries the APPID, accessToken, and certificate serial number to request the Super SIM card to sign. 9. After receiving the request, the Super SIM card uses the SIM card signing private key corresponding to the certificate serial number to sign the random number accessToken. After successful processing, it returns the certificate serial number and the signature value of the random number accessToken to the Anonymous Identifier Authentication SDK. The Anonymous Identifier Authentication SDK then transmits the response result to the business APP. 10. The business app sends a signature authentication request to the business server, carrying the APPID, certificate serial number, and the signature value of the random accessToken. 11. The business server requests signature authentication from the anonymous identifier management server, carrying the APPID, certificate serial number, and the signature value of the random accessToken. 12. The anonymous identifier management server requests signature authentication from the CA certificate platform by carrying the APPID, certificate serial number, and the signature value of the random accessToken. 13. The CA certificate platform uses the SIM card signature public key corresponding to the certificate serial number to verify the signature. After successful verification, it returns the signature verification result to the anonymous identifier management server. 14. The anonymous identifier management server retrieves the mobile phone number and IMEI from the accessToken cache and generates an anonymous ID, which is then returned to the business server. 15. The business server returns the authentication result and anonymous ID to the APP to complete the anonymous ID acquisition.
[0087] In a preferred embodiment, before the step of initiating an anonymous identifier acquisition request to the anonymous identifier management server via an application installed on the user terminal, carrying a business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, the method further includes: The application renders a PIN code initialization page for the user to enter a reference PIN code; The application sends a PIN code initialization request to the user identification card, carrying the reference PIN code and the service identifier, so that the user identification card sets the reference PIN code for the service identifier.
[0088] For example, see Figure 2 The diagram shown illustrates the PIN code initialization process. The PIN code initialization steps are as follows: 1. The business app on the client side renders a PIN code initialization page, where the user enters their PIN code; 2. The business app sends a PIN code initialization request to the anonymous identity authentication SDK, carrying parameters such as the APPID and PIN code; 3. The anonymous identity authentication SDK sends a PIN code initialization request to the Super SIM card, carrying parameters such as the APPID and PIN code; 4. The Super SIM card initializes the PIN code through the SIM card channel, stores the user's PIN in the Super SIM card, and returns the processing result to the anonymous identity authentication SDK; 5. The anonymous identity authentication SDK transmits the Super SIM card result to the business app, completing the PIN code initialization.
[0089] In a preferred embodiment, before the step of initiating an anonymous identifier acquisition request to the anonymous identifier management server via an application installed on the user terminal, carrying a business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, obtain the pre-generated certificate serial number corresponding to the key identifier information and the business identifier, and generate a temporary credential, the method further includes: The application renders an identity information entry page for users to fill in their real-name information; Through the application, a certificate request is initiated to the Anonymous Identifier Authentication SDK, carrying the service identifier and the real-name information, so that the Anonymous Identifier Authentication SDK obtains the SIM card signature public key from the signature key pair corresponding to the service identifier from the user identification card, and initiates a certificate acquisition request to the Anonymous Identifier Management Server, carrying the real-name information, the service identifier and the SIM card signature public key. The system receives a certificate installation success message returned by the user identification card. The certificate installation success message is generated by the user identification card after verifying the certificate returned by the CA certificate platform through the anonymous identifier management server and the anonymous identifier authentication SDK in sequence using the private key in the signature key pair, and binding the signature key pair and the certificate.
[0090] For example, see Figure 3 The diagram illustrates the certificate initialization process. The user fills out a certificate application form in the business app, and the anonymous identifier authentication SDK requests a certificate key pair from the Super SIM card. The user's private key is stored in the Super SIM card, and the user's public key is used to apply for the user certificate. The specific steps are as follows: 1. The business app on the client side renders the identity information filling page, where users enter their real-name information (such as the three user elements: name, ID card number, and mobile phone number). 2. The business app requests a certificate from the anonymous identifier authentication SDK by sending parameters such as APPID and real-name information; 3. The anonymous identifier authentication SDK generates random numbers and caches the user's three key information elements; 4. The anonymous identifier authentication SDK sends an APPID and other information to the Super SIM card to query whether a signature key pair exists; 5. The Super SIM card checks if a key pair exists. If it does not exist, it will directly report an error and remind the user to perform the key initialization process and PIN code initialization process. If it exists, it will return the Super SIM card signing public key to the anonymous identifier authentication SDK. 6. The anonymous identifier authentication SDK requests a certificate from the anonymous identifier management server, carrying cached user three elements, SIM card signature public key, APPID and other parameters. 7. After verifying the local phone number, the anonymous identifier management server requests the CA certificate platform to obtain a certificate, carrying the user's three key elements, the SIM card signature public key, and the APPID. 8. The CA certificate platform generates a certificate and certificate serial number using the user's three key elements, SIM card signature public key, APPID, and other information, and returns them to the anonymous identifier management server. 9. The anonymous identifier management server binds the mobile phone number and certificate serial number, and returns the certificate to the anonymous identifier authentication SDK; 10. The Anonymous Identifier Authentication SDK requests the Super SIM card to install a certificate (the certificate contains the SIM card's signature public key) through the SIM card channel. The Super SIM card determines whether the public key has been tampered with. If it has not been tampered with, it binds the SIM card's signature public and private key pair with the certificate. The Super SIM card returns the binding success and certificate installation success results to the Anonymous Identifier Authentication SDK. The Anonymous Identifier Authentication SDK then transmits the results to the business APP. 11. Complete certificate initialization.
[0091] Furthermore, the signature key pair is generated by the application sending a key pair initialization request to the user identification card, carrying the service identifier, so that the user identification card generates the signature key pair for the service identifier.
[0092] Further, the step of initiating a key pair initialization request to the user identification card via the application carrying the service identifier, so that the user identification card generates the signature key pair for the service identifier, includes: The application sends a key pair initialization request to the anonymous identifier authentication SDK by carrying the business identifier, so that the anonymous identifier authentication SDK sends an identity authentication request to the anonymous identifier management server by carrying the business identifier, and after receiving the identity authentication success identifier returned by the anonymous identifier management server, requests the user identification card to generate the signature key pair, so that the user identification card generates the signature key pair for the business identifier.
[0093] For example, see Figure 4 The diagram shown illustrates the key pair initialization process. The specific steps for key pair initialization are as follows: 1. The business application on the client side requests a key initialization from the anonymous identifier authentication SDK by sending parameters such as the APPID; 2. The anonymous identifier authentication SDK requests identity authentication from the anonymous identifier management server by sending parameters such as APPID; 3. The anonymous identifier management server requests the authentication number retrieval interface with the APPID, obtains the mobile phone number and IMEI from the gateway, and returns the identity authentication identifier upon successful number retrieval; 4. The anonymous identifier authentication SDK requests and generates a signature key pair through the machine-card channel; 5. The Super SIM card generates a Super SIM card signature key pair through the SIM card algorithm logic and returns the SIM card signature public key to the anonymous identifier authentication SDK; 6. The Anonymous Identifier Authentication SDK sends the identity authentication identifier and SIM card signature public key to the Anonymous Identifier Management Server to request the generation of a public-private key pair for the cloud cryptography service platform; 7. The anonymous identifier management server requests the public and private key pair of the cloud cryptography service platform by sending parameters such as APPID to the cloud cryptography service platform; 8. The cloud cryptography service platform generates a public-private key pair using parameters such as APPID and random number. The private key is stored on the cloud cryptography service platform server, and the public key is returned to the anonymous identifier management server. 9. After receiving the public key returned by the cloud password service platform server, the anonymous identifier management server first exchanges the number and IMEI according to the identity authentication identifier, then binds the public key of the cloud password service platform server with the user number and IMEI, and then uses the SIM card signing public key to encrypt the platform public key. After processing, it returns the encrypted platform public key to the anonymous identifier authentication SDK. 10. The Anonymous Identifier Authentication SDK requests the Super SIM card to bind the platform public key, carrying the APPID and the encrypted platform public key returned by the Anonymous Identifier Management Server; 11. After receiving the encrypted platform public key and the business party's APPID provided by the anonymous identifier authentication SDK, the Super SIM card first decrypts the platform public key and then writes the platform public key into the Super SIM card. Complete the key initialization process.
[0094] In a preferred embodiment, the business party has a data interaction relationship with a pre-built trusted blockchain authorization and evidence storage platform, and the business party will store key interaction information with the anonymous subscription service platform on the blockchain for evidence storage; the on-chain nodes of the trusted blockchain authorization and evidence storage platform include regulatory department nodes and operator nodes, which are used to support the evidence storage, verification, evidence collection and modification operations of the anonymous subscription service platform.
[0095] Specifically, a trusted blockchain-based authorization and evidence storage platform is constructed to support the storage, verification, retrieval, and modification of evidence for the anonymous subscription service platform. Regulatory authorities and telecom operators both connect as on-chain nodes. After obtaining user authorization, the enterprise stores the authorization information on the blockchain as evidence, serving as the basis for investigation and evidence collection for anonymous subscription SMS and anonymous call services. For example: 1. After obtaining relevant user authorization, enterprises will store key user authorization information on the blockchain for evidence. Subsequent access, retrieval, and changes to this evidence will be traceable and tamper-proof. 2. When sending messages, operators and associations can verify user authorization. 3. After SMS messages are sent, key communication records will be encrypted and stored on the blockchain for evidence. 4. After a call is completed, recordings and call details will be encrypted and stored on the blockchain for evidence. 5. In the event of a customer complaint, a convenient user authorization evidence collection service can be provided, facilitating evidence collection and review by regulatory authorities.
[0096] See Figure 5 To make the anonymous subscription service provision method clearer, the basic process is briefly introduced below with an example (for specific details, please refer to the above embodiments): I. Anonymous ID Generation Process The user accesses the business's app; the business initiates an authorization and notarization request and requests an anonymous ID; the anonymous subscription service platform first initializes the key, PIN code, and certificate, and then obtains the user's mobile phone number and IMEI through the gateway; next, it verifies the PIN code entered by the user. After successful PIN code verification, it uses SIM card-based certificate authentication technology to perform signature verification during the transmission of the user's mobile phone number and IMEI; if all verification processes are successful, it uses quantum key distribution technology and quantum-secure symmetric encryption algorithms to generate a unique anonymous ID, stores the anonymous ID, mobile phone number, authorization time, and other information on the blockchain authorization and notarization platform, and returns the anonymous ID and authorization time to the business.
[0097] II. Anonymous ID Application Process 1. The business party applies for an anonymous subscription service based on an anonymous ID: Generate verification signature: Combine basic information such as APPID, IP whitelist, application key, and authorization validity period, and generate a signature using the SM3 algorithm (for platform verification). Encrypting Anonymous IDs: Generate a random number R based on the authorization time limit, encrypt the batch UAIDs using the SM4 algorithm to obtain the ciphertext MAC, and then encrypt R using the RSA algorithm (business private key) to obtain the ciphertext MAC1; Submit a request: Send the APPID, signature, MAC, and MAC1 to the anonymous identifier management server via HTTPS.
[0098] 2. Anonymous subscription service platform processing: Signature verification and legality confirmation: Query the business party information through APPID, verify the signature using SM3, and confirm the legitimacy of the request; Decrypt Anonymous IDs: Decrypt MAC1 using the business party's public key to obtain R. After verifying the validity of R, decrypt the MAC to restore the batch of anonymous IDs. Matching and service: The anonymous ID is matched with the database to determine the corresponding mobile phone number. After querying the carrier, the SMS / call service is triggered. Finally, the key information of the communication record is encrypted and stored on the blockchain.
[0099] Compared with existing technologies, the method provided in this invention addresses situations where users do not actively provide personal information. It uses an anonymous ID to replace the user's real mobile phone number to complete the process, achieving encrypted protection of personal information. Furthermore, the mobile phone number circulates only within the operator's domain and is not output externally. Its core implementation logic is as follows: based on the user's unique device identifier (IMEI) and mobile phone number obtained from the operator's gateway, a unified anonymous ID is generated using quantum key distribution technology and a quantum-secure symmetric encryption algorithm. This ID serves as the user's virtual identifier, completing the entire service process. It has the following advantages: 1. Anonymous IDs have strong stability In scenarios where users are not logged in, anonymous IDs are directly mapped and associated with IMEI and mobile phone numbers, without relying on device or system parameters, and can remain stable and effective in the long term.
[0100] 2. Cross-platform and device interoperability Leveraging the acquisition capabilities of carrier gateways, it does not restrict device systems and supports iOS, Android systems, as well as the interoperability of anonymous IDs between different devices.
[0101] 3. End-to-end data security protection Anonymous ID generation stage: A multi-factor signature verification mechanism, including SIM card channel, key encryption, PIN code verification, and CA certificate authentication, ensures the security of data flow; Business service application stage: The anonymous subscription service platform uses multiple encryption algorithms such as SHA256, SM4, and RSA to authenticate the identity of enterprises. At the same time, it uses asymmetric and symmetric encryption to process relevant information to ensure the security and reliability of the requester and reduce the enterprise's management risks.
[0102] See Figure 6 An embodiment of the present invention also provides a method for providing anonymous subscription services, applied to an anonymous subscription service platform, including steps S11-S12: S11. Receive service-related information carrying the target anonymous identifier sent by the service provider; S12. Based on the preset mapping relationship between anonymous identifiers and mobile phone numbers, determine the target mobile phone number according to the target anonymous identifier, and provide services to the user terminal currently bound to the target mobile phone number; The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation.
[0103] It is worth noting that the specific working process of the anonymous subscription service provision method described in the embodiments of the present invention can refer to the working process of the anonymous subscription service provision method regarding the anonymous subscription service platform in any of the above embodiments, and will not be repeated here.
[0104] An embodiment of the present invention also provides a method for providing anonymous subscription services, applied to an anonymous identifier management server, comprising the following steps: Receive anonymous identifier retrieval requests initiated by business parties; The gateway obtains key identification information associated with the anonymous identification request; wherein, the key identification information includes the target mobile phone number and / or International Mobile Equipment Identity (IMSI). Generate a target anonymous identifier based on the key identification information; The target anonymous identifier is returned to the business party for use by the business party when performing the anonymous subscription service provision method as described in any of the embodiments applied to the business party above.
[0105] It is worth noting that the specific working process of the anonymous subscription service provision method described in the embodiments of the present invention can refer to the working process of the anonymous identifier management server in any of the above embodiments, and will not be repeated here.
[0106] An embodiment of the present invention also provides a method for providing anonymous subscription services, applied to a user identification card, comprising the following steps: The system receives a signature request initiated by a business party, carrying a business identifier and a temporary credential. The temporary credential of the business party is generated by the business party in the following manner: by sending an anonymous identifier acquisition request to the anonymous identifier management server, carrying the business identifier, so that the anonymous identifier management server can obtain key identifier information associated with the anonymous identifier acquisition request through the gateway and generate the temporary credential. The key identifier information includes the target mobile phone number and / or International Mobile Equipment Identity (IMEI). The temporary credential is signed using a pre-generated SIM card signing private key to generate the signature value of the temporary credential; The signature value of the temporary credential is returned to the business party, so that the business party sends the business identifier and the signature value of the temporary credential to the anonymous identifier management server, and obtains the target anonymous identifier for requesting the anonymous subscription service from the anonymous identifier management server. The target anonymous identifier is generated by the anonymous identifier management server based on the key identifier information after the signature value of the temporary credential has been verified. The signature value of the temporary credential is verified according to the SIM card signature public key provided in advance by the user identification card.
[0107] It is worth noting that the specific working process of the anonymous subscription service provision method described in the embodiments of the present invention can refer to the working process of the anonymous subscription service provision method with respect to the user identification card in any of the above embodiments, and will not be repeated here.
[0108] An embodiment of the present invention also provides an anonymous subscription service providing apparatus, comprising: An anonymous subscription module is used to respond to a service provision instruction by sending service-related information carrying a target anonymous identifier to an anonymous subscription service platform, so that the anonymous subscription service platform can perform a service provision operation. The service provision operation includes: determining a target mobile phone number based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, and providing services to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation.
[0109] In one implementation, the anonymous subscription module includes: The signature unit is used to respond to the service provision instruction, obtain the basic information of the business party, perform signature processing on the basic information, and generate signature information; An anonymous identifier encryption unit is used to encrypt the target anonymous identifier using a generated symmetric key to generate anonymous identifier ciphertext. The key encryption unit is used to encrypt the symmetric key using a preset business party private key to generate an encryption key; The data sending unit is used to submit the obtained business identifier, the signature information, the anonymous identifier ciphertext, and the encryption key to the anonymous subscription service platform, so that the anonymous subscription service platform can perform service provision operations. The service provision operations include: The corresponding basic information is retrieved from the pre-stored information based on the business identifier, and the signature information is verified based on the retrieved basic information. The encryption key is decrypted using a preset public key from the business party; The ciphertext of the anonymous identifier is processed using the symmetric key obtained from decryption to restore the target anonymous identifier; Based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, the target mobile phone number is determined according to the target anonymous identifier, and services are provided to the user terminal currently bound to the target mobile phone number.
[0110] In one implementation, the basic information further includes an authorization period, and the symmetric key is generated based on the authorization period; The step of decrypting the encryption key using a preset business party public key includes: After the signature information is verified, the validity of the retrieved authorization validity period is checked; a reference key is generated based on the retrieved authorization validity period. If the authorization period is valid and the reference key is equal to the decrypted symmetric key, the encryption key is decrypted using the preset business party public key.
[0111] In one implementation, the service provision operation is performed by the anonymous identifier management server in the anonymous subscription service platform.
[0112] In one implementation, an anonymous identifier acquisition module is also included, comprising: An anonymous identifier request unit is used to initiate an anonymous identifier acquisition request to the anonymous subscription service platform, so that the anonymous subscription service platform can obtain the key identifier information through the gateway and generate the target anonymous identifier based on the key identifier information; An anonymous identifier acquisition unit is used to receive the target anonymous identifier returned by the anonymous subscription service platform.
[0113] In one implementation, the target anonymity identifier is generated by the anonymity subscription service platform in the following manner: After data preprocessing and standardization, the key identification information is subjected to feature extraction to obtain a feature vector; The preset quantum-secure key is combined with the feature vector and processed by a quantum-secure hash function to generate preliminary anonymity information; The initial anonymization information is encrypted to generate a target anonymization identifier.
[0114] In one implementation, the anonymous identifier request unit is configured to: The system sends an anonymous identifier retrieval request to the anonymous subscription service platform, carrying a business identifier, so that the anonymous subscription service platform can obtain the key identifier information through the gateway. The system receives a PIN code to be verified from the user and sends it along with the business identifier to the anonymous subscription service platform to request identity verification. The anonymous subscription service platform then verifies the PIN code to be verified based on a pre-stored reference PIN code. After the PIN code to be verified is successfully verified, the system generates the target anonymous identifier based on the key identification information and shares it with the business party.
[0115] In one implementation, the anonymous subscription service platform includes a user identification card and an anonymous identifier management server; The anonymous identifier request unit is specifically used for: The application installed on the user terminal sends an anonymous identifier acquisition request to the anonymous identifier management server, carrying a business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway. The application receives a PIN code to be verified input by the user, and sends the PIN code and the business identifier to the user identification card to request authentication, so that the user identification card verifies the PIN code to be verified according to the pre-stored reference PIN code, and sends a PIN code verification success message to the application after successful verification. The application receives the PIN code verification success information and triggers the anonymous identifier management server to generate and return the target anonymous identifier; wherein, the target anonymous identifier is generated by the anonymous identifier management server based on the key identifier information.
[0116] In one implementation, the anonymous subscription service platform includes a user identification card, an anonymous identifier management server, and a CA certificate platform; The anonymous identifier request unit is specifically used for: The application installed on the user terminal sends an anonymous identifier acquisition request to the anonymous identifier management server, carrying the business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, obtain the pre-generated certificate serial number corresponding to the key identifier information and the business identifier, and generate a temporary credential. The application receives the temporary credential and certificate serial number returned by the anonymous identifier management server, initiates a signature request to the user identification card carrying the service identifier, the temporary credential, and the certificate serial number, so that the user identification card signs the temporary credential based on the pre-stored SIM card signature private key corresponding to the certificate serial number, generates the signature value of the temporary credential, and returns the certificate serial number and the signature value of the temporary credential to the service party; Carrying the business identifier, the certificate serial number, and the signature value of the temporary credential, the anonymous identifier management server initiates a signature verification request to the CA certificate platform. This allows the CA certificate platform to verify the signature value of the temporary credential based on a pre-stored SIM card signature public key corresponding to the certificate serial number and return the signature verification result to the anonymous identifier management server. After determining that the signature value of the temporary credential has passed verification based on the signature verification result, the anonymous identifier management server generates the target anonymous identifier based on the key identifier information.
[0117] In one implementation, the anonymous identifier acquisition unit is specifically used to: receive the target anonymous identifier returned by the anonymous identifier management server through the application.
[0118] In one implementation, the anonymous subscription service platform includes a user identification card, an anonymous identifier management server, and a CA certificate platform; The anonymous identifier request unit is specifically used for: The application installed on the user terminal sends an anonymous identifier acquisition request to the anonymous identifier management server, carrying the business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, obtain the pre-generated certificate serial number corresponding to the key identifier information and the business identifier, and generate a temporary credential. The application receives the temporary credential and certificate serial number returned by the anonymous identifier management server. The application receives a PIN code to be verified input by the user, and sends the PIN code and the business identifier to the user identification card to request authentication, so that the user identification card verifies the PIN code to be verified according to the pre-stored reference PIN code, and sends a PIN code verification success message to the application after successful verification. After receiving the PIN code verification success information through the application, a signature request carrying the service identifier, the temporary credential, and the certificate serial number is initiated to the user identification card, so that the user identification card signs the temporary credential based on the pre-stored SIM card signature private key corresponding to the certificate serial number, generates the signature value of the temporary credential, and returns the certificate serial number and the signature value of the temporary credential to the service party. Carrying the business identifier, the certificate serial number, and the signature value of the temporary credential, the anonymous identifier management server initiates a signature verification request to the CA certificate platform. This allows the CA certificate platform to verify the signature value of the temporary credential based on a pre-stored SIM card signature public key corresponding to the certificate serial number and return the signature verification result to the anonymous identifier management server. After determining that the signature value of the temporary credential has passed verification based on the signature verification result, the anonymous identifier management server generates the target anonymous identifier based on the key identifier information.
[0119] In one implementation, the data interaction between the application and the user identification card is achieved through an anonymous identity authentication SDK; the data interaction between the anonymous identity authentication SDK and the user identification card is achieved through a machine-card channel. The anonymous identifier acquisition request is initiated by the application to the anonymous identifier management server through the anonymous identifier authentication SDK; the certificate serial number is obtained by the anonymous identifier management server from the CA certificate platform based on the key identifier information and the business identifier; The temporary credential and the certificate serial number are returned to the application by the anonymous identifier management server through the anonymous identifier authentication SDK; The signature verification request is initiated by the application sequentially through the business server and the anonymous identifier management server to the CA certificate platform; The target anonymous identifier returned by the anonymous identifier management server is sent to the application by the anonymous identifier management server through the business server.
[0120] In one embodiment, the device further includes a PIN code initialization module for: The application renders a PIN code initialization page for the user to enter a reference PIN code; The application sends a PIN code initialization request to the user identification card, carrying the reference PIN code and the service identifier, so that the user identification card sets the reference PIN code for the service identifier.
[0121] In one embodiment, the apparatus further includes a certificate initialization module for: The application renders an identity information entry page for users to fill in their real-name information; Through the application, a certificate request is initiated to the Anonymous Identifier Authentication SDK, carrying the service identifier and the real-name information, so that the Anonymous Identifier Authentication SDK obtains the SIM card signature public key from the signature key pair corresponding to the service identifier from the user identification card, and initiates a certificate acquisition request to the Anonymous Identifier Management Server, carrying the real-name information, the service identifier and the SIM card signature public key. The system receives a certificate installation success message returned by the user identification card. The certificate installation success message is generated by the user identification card after verifying the certificate returned by the CA certificate platform through the anonymous identifier management server and the anonymous identifier authentication SDK in sequence using the private key in the signature key pair, and binding the signature key pair and the certificate.
[0122] In one embodiment, the apparatus further includes a key initialization module for: The application sends a key pair initialization request to the user identification card, carrying the service identifier, so that the user identification card generates the signature key pair for the service identifier.
[0123] In one implementation, the key initialization module is specifically used for: The application sends a key pair initialization request to the anonymous identifier authentication SDK by carrying the business identifier, so that the anonymous identifier authentication SDK sends an identity authentication request to the anonymous identifier management server by carrying the business identifier, and after receiving the identity authentication success identifier returned by the anonymous identifier management server, requests the user identification card to generate the signature key pair, so that the user identification card generates the signature key pair for the business identifier.
[0124] In one implementation, the device interacts with a pre-built trusted blockchain authorization and evidence storage platform, and stores key interaction information with the anonymous subscription service platform on the blockchain for evidence storage. The on-chain nodes of the trusted blockchain authorization and evidence storage platform include regulatory nodes and operator nodes, used to support the evidence storage, verification, evidence retrieval, and modification operations of the anonymous subscription service platform. It is worth noting that the specific working process of the anonymous subscription service providing device described in this embodiment can refer to the working process of the anonymous subscription service providing method regarding the business side in any of the above embodiments, and will not be repeated here.
[0125] See Figure 7 An embodiment of the present invention also provides an anonymous subscription service providing apparatus, comprising: Information receiving module 21 is used to receive service-related information carrying a target anonymous identifier sent by the service provider; An anonymous subscription service provider module 22 is used to determine the target mobile phone number based on the target anonymous identifier according to the preset mapping relationship between anonymous identifiers and mobile phone numbers, and provide services to the user terminal currently bound to the target mobile phone number; The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number, and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound at the time of generation.
[0126] It is worth noting that the specific working process of the anonymous subscription service providing device described in the embodiments of the present invention can refer to the working process of the anonymous subscription service providing method regarding the anonymous subscription service platform in any of the above embodiments, and will not be repeated here.
[0127] An embodiment of the present invention also provides an anonymous subscription service providing apparatus, comprising: The identifier acquisition request receiving module is used to receive anonymous identifier acquisition requests initiated by the business party; The key identifier acquisition module is used to acquire key identifier information associated with the anonymous identifier acquisition request through the gateway; wherein, the key identifier information includes the target mobile phone number and / or International Mobile Equipment Identity (IMEI); An anonymous identifier generation module is used to generate a target anonymous identifier based on the key identifier information; The target anonymous identifier is returned to the business party for use by the business party when performing the anonymous subscription service provision method applied to the business party as in any of the above embodiments.
[0128] It is worth noting that the specific working process of the anonymous subscription service providing device described in the embodiments of the present invention can refer to the working process of the anonymous subscription service providing method regarding the anonymous identifier management server in any of the above embodiments, and will not be repeated here.
[0129] An embodiment of the present invention also provides an anonymous subscription service providing apparatus, comprising: The signature request receiving module is used to receive a signature request initiated by a business party, carrying a business identifier and a temporary credential. The temporary credential is generated by the business party by sending an anonymous identifier acquisition request to an anonymous identifier management server, carrying the business identifier. This allows the anonymous identifier management server to obtain key identifier information associated with the anonymous identifier acquisition request through a gateway and generate the temporary credential. The key identifier information includes a target mobile phone number and / or an International Mobile Equipment Identity (IMEI). The signature module is used to sign the temporary credential using a pre-generated SIM card signature private key, and generate the signature value of the temporary credential. The signature value return module is used to return the signature value of the temporary credential to the business party, so that the business party can send the business identifier and the signature value of the temporary credential to the anonymous identifier management server, and obtain the target anonymous identifier for requesting the anonymous subscription service from the anonymous identifier management server; The target anonymous identifier is generated by the anonymous identifier management server based on the key identifier information after the signature value of the temporary credential has been verified. The signature value of the temporary credential is verified according to the SIM card signature public key provided in advance by the user identification card.
[0130] It is worth noting that the specific working process of the anonymous subscription service providing device described in the embodiments of the present invention can refer to the working process of the anonymous subscription service providing method with respect to the user identification card in any of the above embodiments, and will not be repeated here.
[0131] See Figure 8This invention also provides an anonymous subscription service providing device, including a processor 31, a memory 32, and a computer program stored in the memory 32 and configured to be executed by the processor 31. When the processor 31 executes the computer program, it implements the steps described in the above-described anonymous subscription service providing method embodiments, for example... Figure 1 The steps S11-S12 described above; or, when the processor 31 executes the computer program, it implements the functions of each module in the above-described device embodiments.
[0132] For example, the computer program can be divided into one or more modules, which are stored in the memory 32 and executed by the processor 31 to complete the present invention. The one or more modules can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the anonymous subscription service providing device. For example, the computer program can be divided into multiple modules. The specific working process of each module can be referred to the working process of the anonymous subscription service providing model described in the above embodiments, and will not be repeated here.
[0133] The anonymous subscription service providing device can be a desktop computer, laptop, handheld computer, or cloud server, etc. The anonymous subscription service providing device may include, but is not limited to, a processor 31 and a memory 32. Those skilled in the art will understand that the anonymous subscription service providing device may also include input / output devices, network access devices, buses, etc.
[0134] The processor 31 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor 31 is the control center of the anonymous subscription service providing device, connecting various parts of the device via various interfaces and lines.
[0135] The memory 32 can be used to store the computer programs and / or modules. The processor 31 implements various functions of the anonymous subscription service providing device by running or executing the computer programs and / or modules stored in the memory 32 and calling the data stored in the memory 32. The memory 32 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as image playback function), etc.; the data storage area may store data created based on the use of the mobile phone, etc. In addition, the memory 32 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0136] Wherein, if the anonymous subscription service provides a device integration module that is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by the processor 31, it can implement the steps of the above method embodiments. Wherein, the computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0137] This invention also provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the anonymous subscription service provision method as described in any of the above embodiments.
[0138] Compared with existing technologies, the anonymous subscription service provision method, apparatus, device, storage medium, and product provided in this embodiment of the invention firstly involve the service provider responding to a service provision instruction by sending service-related information carrying a target anonymous identifier to the anonymous subscription service platform. Then, the anonymous subscription service platform, based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, determines the target mobile phone number according to the target anonymous identifier and provides the corresponding service to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is pre-generated by the anonymous subscription service platform based on key identification information obtained from a gateway, establishing a mapping relationship between the anonymous identifier and the target mobile phone number, and sharing the target anonymous identifier with the service provider. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation. Therefore, this embodiment of the invention generates an anonymous identifier based on key identification information (target mobile phone number and / or International Mobile Equipment Identity) obtained from the gateway through an anonymous subscription service platform, establishes a mapping between the identifier and the mobile phone number, and then shares the anonymous identifier with the business party. When the business party responds to the service provision instruction, it sends service-related information carrying the identifier to the anonymous subscription service platform. The anonymous subscription service platform determines the target mobile phone number based on the mapping relationship and provides services to the user. This not only protects user privacy but also improves cross-system compatibility, supports business parties in providing services to users based on stable identifiers, and protects user privacy.
[0139] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method for providing an anonymous subscription service, characterized in that, Applied to business users, including: In response to a service provision instruction, the system sends service-related information carrying a target anonymous identifier to an anonymous subscription service platform, so that the anonymous subscription service platform performs a service provision operation. The service provision operation includes: determining a target mobile phone number based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, and providing services to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation.
2. The method for providing anonymous subscription services as described in claim 1, characterized in that, The step of responding to a service provision instruction by sending service-related information carrying a target anonymous identifier to an anonymous subscription service platform, so that the anonymous subscription service platform performs a service provision operation, includes: In response to a service provision instruction, the system obtains the basic information of the business party, performs signature processing on the basic information, and generates signature information. The target anonymous identifier is encrypted using the generated symmetric key to generate anonymous identifier ciphertext; The symmetric key is encrypted using a preset private key from the business party to generate an encryption key; Submit the obtained business identifier, the signature information, the anonymous identifier ciphertext, and the encryption key to the anonymous subscription service platform so that the anonymous subscription service platform can perform service provision operations; The service provision operations include: The corresponding basic information is retrieved from the pre-stored information based on the business identifier, and the signature information is verified based on the retrieved basic information. The encryption key is decrypted using a preset public key from the business party; The ciphertext of the anonymous identifier is processed using the symmetric key obtained from decryption to restore the target anonymous identifier; Based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, the target mobile phone number is determined according to the target anonymous identifier, and services are provided to the user terminal currently bound to the target mobile phone number.
3. The method for providing anonymous subscription services as described in claim 2, characterized in that, The basic information also includes the authorization period, and the symmetric key is generated based on the authorization period. The step of decrypting the encryption key using a preset business party public key includes: After the signature information is verified, the validity of the retrieved authorization validity period is checked; a reference key is generated based on the retrieved authorization validity period. If the authorization period is valid and the reference key is equal to the decrypted symmetric key, the encryption key is decrypted using the preset business party public key.
4. The method for providing anonymous subscription services as described in claim 1, characterized in that, The service provision operation is performed by the anonymous identifier management server in the anonymous subscription service platform.
5. The method for providing anonymous subscription services as described in any one of claims 1 to 4, characterized in that, Before the step of sending service-related information carrying a target anonymous identifier to the anonymous subscription service platform in response to a service provision instruction, so that the anonymous subscription service platform performs the service provision operation, the method further includes: An anonymous identifier acquisition request is initiated to the anonymous subscription service platform, so that the anonymous subscription service platform can obtain the key identifier information through the gateway and generate the target anonymous identifier based on the key identifier information; Receive the target anonymous identifier returned by the anonymous subscription service platform.
6. The method for providing anonymous subscription services as described in claim 5, characterized in that, The target anonymity identifier is generated by the anonymity subscription service platform in the following way: After data preprocessing and standardization, the key identification information is subjected to feature extraction to obtain a feature vector; The preset quantum-secure key is combined with the feature vector and processed by a quantum-secure hash function to generate preliminary anonymity information; The initial anonymization information is encrypted to generate a target anonymization identifier.
7. The method for providing anonymous subscription services as described in claim 5, characterized in that, The step of initiating an anonymous identifier acquisition request to the anonymous subscription service platform, so that the anonymous subscription service platform can obtain the key identifier information through the gateway and generate the target anonymous identifier based on the key identifier information, includes: The system sends an anonymous identifier retrieval request to the anonymous subscription service platform, carrying a business identifier, so that the anonymous subscription service platform can obtain the key identifier information through the gateway. The system receives a PIN code to be verified from the user and sends it along with the business identifier to the anonymous subscription service platform to request identity verification. The anonymous subscription service platform then verifies the PIN code to be verified based on a pre-stored reference PIN code. After the PIN code to be verified is successfully verified, the system generates the target anonymous identifier based on the key identification information and shares it with the business party.
8. The method for providing anonymous subscription services as described in claim 7, characterized in that, The anonymous subscription service platform includes a user identification card and an anonymous identifier management server. The step of sending an anonymous identifier retrieval request to the anonymous subscription service platform, carrying a business identifier, so that the anonymous subscription service platform can obtain the key identifier information through the gateway, includes: The application installed on the user terminal sends an anonymous identifier acquisition request to the anonymous identifier management server, carrying a business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway. The process of receiving a user-inputted PIN code to be verified, and requesting identity verification from the anonymous subscription service platform along with the PIN code and the business identifier, allows the anonymous subscription service platform to verify the PIN code based on a pre-stored reference PIN code. Upon successful verification of the PIN code, the platform generates the target anonymous identifier based on the key identification information and shares it with the business party. This includes: The application receives a PIN code to be verified input by the user, and sends the PIN code and the business identifier to the user identification card to request authentication, so that the user identification card verifies the PIN code to be verified according to the pre-stored reference PIN code, and sends a PIN code verification success message to the application after successful verification. The application receives the PIN code verification success information and triggers the anonymous identifier management server to generate and return the target anonymous identifier; wherein, the target anonymous identifier is generated by the anonymous identifier management server based on the key identifier information.
9. The method for providing anonymous subscription services as described in claim 5, characterized in that, The anonymous subscription service platform includes a user identification card, an anonymous identifier management server, and a CA certificate platform. The step of initiating an anonymous identifier acquisition request to the anonymous subscription service platform, so that the anonymous subscription service platform can obtain the key identifier information through the gateway and generate the target anonymous identifier based on the key identifier information, includes: The application installed on the user terminal sends an anonymous identifier acquisition request to the anonymous identifier management server, carrying the business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, obtain the pre-generated certificate serial number corresponding to the key identifier information and the business identifier, and generate a temporary credential. The application receives the temporary credential and certificate serial number returned by the anonymous identifier management server, initiates a signature request to the user identification card carrying the service identifier, the temporary credential, and the certificate serial number, so that the user identification card signs the temporary credential based on the pre-stored SIM card signature private key corresponding to the certificate serial number, generates the signature value of the temporary credential, and returns the certificate serial number and the signature value of the temporary credential to the service party; Carrying the business identifier, the certificate serial number, and the signature value of the temporary credential, the anonymous identifier management server initiates a signature verification request to the CA certificate platform. This allows the CA certificate platform to verify the signature value of the temporary credential based on a pre-stored SIM card signature public key corresponding to the certificate serial number and return the signature verification result to the anonymous identifier management server. After determining that the signature value of the temporary credential has passed verification based on the signature verification result, the anonymous identifier management server generates the target anonymous identifier based on the key identifier information.
10. The method for providing anonymous subscription services as described in claim 9, characterized in that, Receiving the target anonymous identifier returned by the anonymous subscription service platform includes: receiving the target anonymous identifier returned by the anonymous identifier management server through the application.
11. The method for providing anonymous subscription services as described in claim 5, characterized in that, The anonymous subscription service platform includes a user identification card, an anonymous identifier management server, and a CA certificate platform. The step of initiating an anonymous identifier acquisition request to the anonymous subscription service platform, so that the anonymous subscription service platform can obtain the key identifier information through the gateway and generate the target anonymous identifier based on the key identifier information, includes: The application installed on the user terminal sends an anonymous identifier acquisition request to the anonymous identifier management server, carrying the business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, obtain the pre-generated certificate serial number corresponding to the key identifier information and the business identifier, and generate a temporary credential. The application receives the temporary credential and certificate serial number returned by the anonymous identifier management server. The application receives a PIN code to be verified input by the user, and sends the PIN code and the business identifier to the user identification card to request authentication, so that the user identification card verifies the PIN code to be verified according to the pre-stored reference PIN code, and sends a PIN code verification success message to the application after successful verification. After receiving the PIN code verification success information through the application, a signature request carrying the service identifier, the temporary credential, and the certificate serial number is initiated to the user identification card, so that the user identification card signs the temporary credential based on the pre-stored SIM card signature private key corresponding to the certificate serial number, generates the signature value of the temporary credential, and returns the certificate serial number and the signature value of the temporary credential to the service party. Carrying the business identifier, the certificate serial number, and the signature value of the temporary credential, the anonymous identifier management server initiates a signature verification request to the CA certificate platform. This allows the CA certificate platform to verify the signature value of the temporary credential based on a pre-stored SIM card signature public key corresponding to the certificate serial number and return the signature verification result to the anonymous identifier management server. After determining that the signature value of the temporary credential has passed verification based on the signature verification result, the anonymous identifier management server generates the target anonymous identifier based on the key identifier information.
12. The method for providing anonymous subscription services as described in claim 11, characterized in that, The data interaction between the application and the user identification card is implemented through the anonymous identifier authentication SDK; the data interaction between the anonymous identifier authentication SDK and the user identification card is implemented through the machine-card channel; The anonymous identifier acquisition request is initiated by the application to the anonymous identifier management server through the anonymous identifier authentication SDK; the certificate serial number is obtained by the anonymous identifier management server from the CA certificate platform based on the key identifier information and the business identifier; The temporary credential and the certificate serial number are returned to the application by the anonymous identifier management server through the anonymous identifier authentication SDK; The signature verification request is initiated by the application sequentially through the business server and the anonymous identifier management server to the CA certificate platform; The target anonymous identifier returned by the anonymous identifier management server is sent to the application by the anonymous identifier management server through the business server.
13. The method for providing anonymous subscription services as described in claim 9 or 11, characterized in that, Before the step of initiating an anonymous identifier retrieval request to the anonymous identifier management server via an application installed on the user terminal, carrying a business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, the process further includes: The application renders a PIN code initialization page for the user to enter a reference PIN code; The application sends a PIN code initialization request to the user identification card, carrying the reference PIN code and the service identifier, so that the user identification card sets the reference PIN code for the service identifier.
14. The method for providing an anonymous subscription service as described in any one of claims 9 to 11, characterized in that, Before the step of initiating an anonymous identifier retrieval request to the anonymous identifier management server via an application installed on the user terminal, carrying a business identifier, so that the anonymous identifier management server can obtain the key identifier information through the gateway, obtain the pre-generated certificate serial number corresponding to the key identifier information and the business identifier, and generate a temporary credential, the process further includes: The application renders an identity information entry page for users to fill in their real-name information; Through the application, a certificate request is initiated to the Anonymous Identifier Authentication SDK, carrying the service identifier and the real-name information, so that the Anonymous Identifier Authentication SDK obtains the SIM card signature public key from the signature key pair corresponding to the service identifier from the user identification card, and initiates a certificate acquisition request to the Anonymous Identifier Management Server, carrying the real-name information, the service identifier and the SIM card signature public key. The system receives a certificate installation success message returned by the user identification card. The certificate installation success message is generated by the user identification card after verifying the certificate returned by the CA certificate platform through the anonymous identifier management server and the anonymous identifier authentication SDK in sequence using the private key in the signature key pair, and binding the signature key pair and the certificate.
15. The method for providing an anonymous subscription service as described in claim 14, characterized in that, The signature key pair is generated in the following manner: The application sends a key pair initialization request to the user identification card, carrying the service identifier, so that the user identification card generates the signature key pair for the service identifier.
16. The method for providing an anonymous subscription service as described in claim 15, characterized in that, The step of initiating a key pair initialization request to the user identification card via the application carrying the service identifier, so that the user identification card generates the signature key pair for the service identifier, includes: The application sends a key pair initialization request to the anonymous identifier authentication SDK by carrying the business identifier, so that the anonymous identifier authentication SDK sends an identity authentication request to the anonymous identifier management server by carrying the business identifier, and after receiving the identity authentication success identifier returned by the anonymous identifier management server, requests the user identification card to generate the signature key pair, so that the user identification card generates the signature key pair for the business identifier.
17. The method for providing anonymous subscription services as described in claim 1, characterized in that, The business party has a data interaction relationship with the pre-built trusted blockchain authorization and evidence storage platform. The business party will put the key interaction information with the anonymous subscription service platform on the blockchain for evidence storage. The on-chain nodes of the trusted blockchain authorization and evidence storage platform include regulatory department nodes and operator nodes, which are used to support the evidence storage, verification, evidence collection and modification operations of the anonymous subscription service platform.
18. A method for providing an anonymous subscription service, characterized in that, Applied to anonymous subscription service platforms, including: Receive service-related information carrying the target anonymous identifier sent by the service provider; Based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, the target mobile phone number is determined according to the target anonymous identifier, and services are provided to the user terminal currently bound to the target mobile phone number; The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation.
19. A method for providing an anonymous subscription service, characterized in that, Applications to anonymous identifier management servers include: Receive anonymous identifier retrieval requests initiated by business parties; The gateway obtains key identification information associated with the anonymous identification request; wherein, the key identification information includes the target mobile phone number and / or International Mobile Equipment Identity (IMSI). And generate a target anonymous identifier based on the key identification information; The target anonymous identifier is returned to the business party for use by the business party when performing the anonymous subscription service provision method as described in any one of claims 1 to 17.
20. A method for providing an anonymous subscription service, characterized in that, Applied to user identification cards, including: The system receives a signature request initiated by a business party, carrying a business identifier and a temporary credential. The temporary credential of the business party is generated by the business party in the following manner: by sending an anonymous identifier acquisition request to the anonymous identifier management server, carrying the business identifier, so that the anonymous identifier management server can obtain key identifier information associated with the anonymous identifier acquisition request through the gateway and generate the temporary credential. The key identifier information includes the target mobile phone number and / or International Mobile Equipment Identity (IMEI). The temporary credential is signed using a pre-generated SIM card signing private key to generate the signature value of the temporary credential; The signature value of the temporary credential is returned to the business party, so that the business party sends the business identifier and the signature value of the temporary credential to the anonymous identifier management server, and obtains the target anonymous identifier for requesting the anonymous subscription service from the anonymous identifier management server. The target anonymous identifier is generated by the anonymous identifier management server based on the key identifier information after the signature value of the temporary credential has been verified. The signature value of the temporary credential is verified according to the SIM card signature public key provided in advance by the user identification card.
21. An anonymous subscription service provider, characterized in that, include: An anonymous subscription module is used to respond to a service provision instruction by sending service-related information carrying a target anonymous identifier to an anonymous subscription service platform, so that the anonymous subscription service platform can perform a service provision operation. The service provision operation includes: determining a target mobile phone number based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, and providing services to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound to the target mobile phone number at the time of generation.
22. An apparatus for providing an anonymous subscription service, characterized in that, include: The information receiving module is used to receive service-related information carrying a target anonymous identifier sent by the service provider; An anonymous subscription service provides services to determine a target mobile phone number based on a preset mapping relationship between anonymous identifiers and mobile phone numbers, and to provide services to the user terminal currently bound to the target mobile phone number. The target anonymous identifier is generated in advance by the anonymous subscription service platform based on key identification information obtained from the gateway. The platform establishes a mapping relationship between the anonymous identifier and the target mobile phone number, and shares the target anonymous identifier with the business party. The key identification information includes the target mobile phone number and / or the International Mobile Equipment Identity (IMEI) of the user terminal bound at the time of generation.
23. An anonymous subscription service providing device, characterized in that, include: The identifier acquisition request receiving module is used to receive anonymous identifier acquisition requests initiated by the business party; The key identifier acquisition module is used to acquire key identifier information associated with the anonymous identifier acquisition request through the gateway; wherein, the key identifier information includes the target mobile phone number and / or International Mobile Equipment Identity (IMEI); An anonymous identifier generation module is used to generate a target anonymous identifier based on the key identifier information; The target anonymous identifier is returned to the business party for use by the business party when performing the anonymous subscription service provision method as described in any one of claims 1 to 17.
24. An apparatus for providing an anonymous subscription service, characterized in that, include: The signature request receiving module is used to receive a signature request initiated by a business party, carrying a business identifier and a temporary credential. The temporary credential is generated by the business party by sending an anonymous identifier acquisition request to an anonymous identifier management server, carrying the business identifier. This allows the anonymous identifier management server to obtain key identifier information associated with the anonymous identifier acquisition request through a gateway and generate the temporary credential. The key identifier information includes a target mobile phone number and / or an International Mobile Equipment Identity (IMEI). The signature module is used to sign the temporary credential using a pre-generated SIM card signature private key, and generate the signature value of the temporary credential. The signature value return module is used to return the signature value of the temporary credential to the business party, so that the business party can send the business identifier and the signature value of the temporary credential to the anonymous identifier management server, and obtain the target anonymous identifier for requesting the anonymous subscription service from the anonymous identifier management server; The target anonymous identifier is generated by the anonymous identifier management server based on the key identifier information after the signature value of the temporary credential has been verified. The signature value of the temporary credential is verified according to the SIM card signature public key provided in advance by the user identification card.
25. An anonymous subscription service providing device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the anonymous subscription service provision method as described in any one of claims 1 to 20.
26. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device on which the computer-readable storage medium is located to perform the anonymous subscription service provision method as described in any one of claims 1 to 20.
27. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the anonymous subscription service provision method as described in any one of claims 1 to 20.