CN112637855B - Machine-card binding method and server based on block chain - Google Patents

Machine-card binding method and server based on block chain Download PDF

Info

Publication number
CN112637855B
CN112637855B CN202011482006.9A CN202011482006A CN112637855B CN 112637855 B CN112637855 B CN 112637855B CN 202011482006 A CN202011482006 A CN 202011482006A CN 112637855 B CN112637855 B CN 112637855B
Authority
CN
China
Prior art keywords
terminal
sim card
signature message
verified
block
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN202011482006.9A
Other languages
Chinese (zh)
Other versions
CN112637855A (en
Inventor
李张铮
陈海
连慧
洪林梦涵
陈锋
潘晓宇
张雪平
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China United Network Communications Group Co Ltd
Original Assignee
China United Network Communications Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China United Network Communications Group Co Ltd filed Critical China United Network Communications Group Co Ltd
Priority to CN202011482006.9A priority Critical patent/CN112637855B/en
Publication of CN112637855A publication Critical patent/CN112637855A/en
Application granted granted Critical
Publication of CN112637855B publication Critical patent/CN112637855B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Telephone Function (AREA)

Abstract

The application provides a machine-card binding method and a server based on a block chain. The method comprises the following steps: after acquiring a binding request sent by a terminal, a server determines a first signature message of an SIM card and a first identity public key of the terminal corresponding to the binding request according to the binding request. The first signature message of the SIM card may be generated according to the SIM card information and a first preset hash algorithm. The first identity public key of the terminal can be generated by the terminal feature code through an asymmetric encryption algorithm. And the server generates a new SIM card block by taking the first signature message of the SIM card as the data block identifier and the first identity public key of the terminal as the data block identifier. The server inserts the new SIM card block into the SIM card block chain. The method improves the safety of the machine-card binding information and avoids the problem that the machine-card binding information is tampered.

Description

基于区块链的机卡绑定方法和服务器Machine-card binding method and server based on block chain

技术领域technical field

本申请涉及通信技术领域,尤其涉及一种基于区块链的机卡绑定方法和服务器。The present application relates to the field of communication technology, and in particular to a blockchain-based machine-card binding method and server.

背景技术Background technique

在终端与SIM卡的使用中,其连接通常是不稳定的,终端可以更换SIM卡,SIM卡也可以更换终端。因此,在一些需要SIM卡与终端唯一绑定的场景中,例如客户前置设备(Customer Premise Equipment,CPE)的使用中,该SIM卡与终端的连接方式是不安全的。In the use of the terminal and the SIM card, the connection is usually unstable, the terminal can replace the SIM card, and the SIM card can also replace the terminal. Therefore, in some scenarios that require a unique binding between the SIM card and the terminal, such as the use of customer premise equipment (Customer Premise Equipment, CPE), the connection mode between the SIM card and the terminal is not safe.

针对这一情况,现有技术可以通过机卡绑定方式实现SIM卡和终端的绑定。目前,常用的机卡绑定方法通常由SIM卡发送主动式命令到终端实现。终端在接收到SIM卡发送的主动式命令后,向SIM卡发送绑定信息,进而实现SIM卡与终端的绑定。In view of this situation, in the prior art, the binding of the SIM card and the terminal can be realized by means of machine-card binding. At present, the commonly used machine-card binding method is usually realized by sending active commands from the SIM card to the terminal. After receiving the proactive command sent by the SIM card, the terminal sends binding information to the SIM card, thereby realizing the binding of the SIM card and the terminal.

然而,该绑定方式存在容易被篡改,安全性低的问题。However, this binding method has the problems of being easily tampered and having low security.

发明内容Contents of the invention

本申请提供一种基于区块链的机卡绑定方法和服务器,用以解决现有技术的绑定方式容易被篡改,安全性低的问题。The present application provides a block chain-based machine-card binding method and server to solve the problems that the binding methods in the prior art are easy to be tampered with and have low security.

第一方面,本申请提供一种基于区块链的机卡绑定方法,包括:In the first aspect, the present application provides a blockchain-based machine-card binding method, including:

获取SIM卡第一签名消息和终端第一身份公钥;Obtain the first signature message of the SIM card and the first identity public key of the terminal;

根据所述SIM卡第一签名消息和所述终端第一身份公钥,生成SIM卡新区块,所述SIM卡新区块包括数据块标识和数据块数据,所述SIM卡第一签名消息为所述数据块标识,所述终端第一身份公钥为所述数据块数据;According to the first signature message of the SIM card and the first identity public key of the terminal, a new block of the SIM card is generated, the new block of the SIM card includes a data block identifier and data block data, and the first signature message of the SIM card is the The data block identifier, the terminal first identity public key is the data block data;

将所述SIM卡新区块插入SIM卡区块链中。Insert the new block of the SIM card into the SIM card block chain.

可选地,所述方法,还包括:Optionally, the method also includes:

获取终端第一签名消息和SIM卡第一身份公钥;Obtain the first signature message of the terminal and the first identity public key of the SIM card;

根据所述终端第一签名消息和所述SIM卡第一身份公钥,生成终端新区块,所述终端新区块包括数据块标识和数据块数据,所述终端第一签名消息为所述数据块标识,所述SIM卡第一身份公钥为所述数据块数据;According to the first signature message of the terminal and the first identity public key of the SIM card, a new block of the terminal is generated, the new block of the terminal includes a data block identifier and data block data, and the first signature message of the terminal is the data block Identification, the first identity public key of the SIM card is the data block data;

将所述终端新区块插入终端区块链中;inserting said terminal new block into the terminal blockchain;

可选地,所述方法,包括:Optionally, the method includes:

根据SIM卡特征编码,生成SIM卡第一身份私钥和SIM卡第一身份公钥;Generate the private key of the first identity of the SIM card and the public key of the first identity of the SIM card according to the characteristic code of the SIM card;

根据SIM卡信息和第一预设哈希算法,生成SIM卡第一签名消息,所述SIM卡第一签名消息为所述SIM卡信息通过所述第一预设哈希算法加密得到。According to the SIM card information and the first preset hash algorithm, generate a first SIM card signature message, where the SIM card first signature message is obtained by encrypting the SIM card information through the first preset hash algorithm.

可选地,所述方法,包括:Optionally, the method includes:

根据终端特征编码,生成终端第一身份私钥和终端第一身份公钥;Generate terminal first identity private key and terminal first identity public key according to terminal characteristic code;

根据终端信息和第二预设哈希算法,生成终端第一签名消息,所述终端第一签名消息为所述终端信息通过所述第二预设哈希算法加密得到。According to the terminal information and the second preset hash algorithm, a first terminal signature message is generated, where the terminal first signature message is obtained by encrypting the terminal information through the second preset hash algorithm.

可选地,完成机卡绑定后,所述方法,包括:Optionally, after the machine-card binding is completed, the method includes:

获取待验证SIM卡的SIM卡第二签名消息、待验证终端的终端第二身份私钥和终端第二签名消息,所述SIM卡第二签名消息为所述待验证SIM卡的SIM卡信息通过所述第一预设哈希算法加密得到,所述终端第二签名消息为所述待验证终端的终端信息通过所述第二预设哈希算法加密得到,所述终端第二身份私钥根据所述待验证终端的终端特征编码生成;Obtain the SIM card second signature message of the SIM card to be verified, the terminal second identity private key of the terminal to be verified, and the terminal second signature message, the second SIM card signature message is the SIM card information of the SIM card to be verified through The first preset hash algorithm is encrypted, the terminal second signature message is obtained by encrypting the terminal information of the terminal to be verified through the second preset hash algorithm, and the terminal second identity private key is obtained according to generating a terminal characteristic code of the terminal to be verified;

将所述待验证终端的终端数字签名、所述终端第二签名消息和所述SIM卡第二签名消息上报SIM卡区块链,所述终端数字签名通过所述终端第二身份私钥对终端第二签名消息进行数字签名得到;Report the terminal digital signature of the terminal to be verified, the second signature message of the terminal, and the second signature message of the SIM card to the SIM card block chain, and the digital signature of the terminal is registered to the terminal through the second identity private key of the terminal. The second signature message is digitally signed to obtain;

将所有SIM卡区块链的数据块标识与所述SIM卡第二签名消息进行匹配,确定所述待验证SIM卡的SIM卡区块;The data block identification of all SIM card block chains is matched with the second signature message of the SIM card to determine the SIM card block of the SIM card to be verified;

根据所述待验证SIM卡的所述SIM卡区块中的终端第一身份公钥和所述终端第二签名消息验证所述终端数字签名,并确定验证结果。Verifying the digital signature of the terminal according to the first identity public key of the terminal in the SIM card block of the SIM card to be verified and the second signature message of the terminal, and determining a verification result.

可选地,完成机卡绑定后,所述方法,包括:Optionally, after the machine-card binding is completed, the method includes:

获取待验证SIM卡的SIM卡第二签名消息、SIM卡第二身份私钥和待验证终端的终端第二签名消息,所述SIM卡第二签名消息为所述待验证SIM卡的所述SIM卡信息通过所述第一预设哈希算法加密得到,所述SIM卡第二身份私钥根据所述待验证终端的所述终端特征编码生成,所述终端第二签名消息为所述终端信息通过所述第二预设哈希算法加密得到;Obtain the second signature message of the SIM card of the SIM card to be verified, the second identity private key of the SIM card, and the second signature message of the terminal of the terminal to be verified, and the second signature message of the SIM card is the SIM card of the SIM card to be verified. The card information is encrypted by the first preset hash algorithm, the second identity private key of the SIM card is generated according to the terminal feature code of the terminal to be verified, and the second signature message of the terminal is the terminal information Encrypted by the second preset hash algorithm;

将待验证SIM卡的SIM卡数字签名、所述SIM卡第二签名消息和所述终端第二签名消息上报终端区块链,所述SIM卡数字签名通过所述SIM卡第二身份私钥对SIM卡第二签名消息进行数字签名得到;Report the SIM card digital signature of the SIM card to be verified, the second signature message of the SIM card, and the second signature message of the terminal to the terminal block chain, and the digital signature of the SIM card passes the second identity private key pair of the SIM card The second signature message of the SIM card is digitally signed to obtain;

将所有终端区块链的数据块标识与所述终端第二签名消息进行匹配,确定所述待验证终端的终端区块;Matching the data block identifiers of all terminal block chains with the second signature message of the terminal to determine the terminal block of the terminal to be verified;

根据所述待验证终端的所述终端区块中的SIM卡第一身份公钥和所述SIM卡第二签名消息验证所述SIM卡数字签名,并确定验证结果;Verify the SIM card digital signature according to the SIM card first identity public key in the terminal block of the terminal to be verified and the SIM card second signature message, and determine the verification result;

可选地,所述方法,还包括:Optionally, the method also includes:

根据所述验证结果,判断是否出现机卡分离;According to the verification result, it is judged whether machine-card separation occurs;

当所述机卡分离时,对所述待验证终端或者所述待验证SIM卡进行限制入网。When the device-card is separated, restrict network access to the terminal to be verified or the SIM card to be verified.

第二方面,本申请提供一种基于区块链的机卡绑定装置,包括:In a second aspect, the present application provides a blockchain-based machine-card binding device, including:

第一获取模块,用于获取SIM卡第一签名消息和终端第一身份公钥;The first obtaining module is used to obtain the first signature message of the SIM card and the first identity public key of the terminal;

第一生成模块,用于根据所述SIM卡第一签名消息和所述终端第一身份公钥,生成SIM卡新区块,所述SIM卡新区块包括数据块标识和数据块数据,所述SIM卡第一签名消息为所述数据块标识,所述终端第一身份公钥为所述数据块数据;The first generation module is used to generate a new block of the SIM card according to the first signature message of the SIM card and the first identity public key of the terminal, and the new block of the SIM card includes a data block identifier and a data block data, and the SIM card The card's first signature message is the data block identifier, and the terminal's first identity public key is the data block data;

第一插入模块,用于将所述SIM卡新区块插入SIM卡区块链中。The first inserting module is used for inserting the new block of the SIM card into the block chain of the SIM card.

可选地,所述装置,还包括:Optionally, the device also includes:

第二获取模块,用于获取终端第一签名消息和SIM卡第一身份公钥;The second obtaining module is used to obtain the first signature message of the terminal and the first identity public key of the SIM card;

第二生成模块,用于根据所述终端第一签名消息和所述SIM卡第一身份公钥,生成终端新区块,所述终端新区块包括数据块标识和数据块数据,所述终端第一签名消息为所述数据块标识,所述SIM卡第一身份公钥为所述数据块数据;The second generating module is configured to generate a new terminal block according to the first signature message of the terminal and the first identity public key of the SIM card, the new block of the terminal includes a data block identifier and data block data, and the terminal first The signature message is the data block identifier, and the SIM card first identity public key is the data block data;

第二插入模块,用于将所述终端新区块插入终端区块链中;The second inserting module is used to insert the terminal new block into the terminal block chain;

可选地,SIM卡数据的生成过程可以包括:根据SIM卡特征编码,生成SIM卡第一身份私钥和SIM卡第一身份公钥;根据SIM卡信息和第一预设哈希算法,生成SIM卡第一签名消息,所述SIM卡第一签名消息为所述SIM卡信息通过所述第一预设哈希算法加密得到。Optionally, the generating process of the SIM card data may include: according to the SIM card feature code, generating the SIM card first identity private key and the SIM card first identity public key; according to the SIM card information and the first preset hash algorithm, generating A first SIM card signature message, where the SIM card first signature message is obtained by encrypting the SIM card information through the first preset hash algorithm.

可选地,终端数据的生成过程可以包括:根据终端特征编码,生成终端第一身份私钥和终端第一身份公钥;根据终端信息和第二预设哈希算法,生成终端第一签名消息,所述终端第一签名消息为所述终端信息通过所述第二预设哈希算法加密得到。Optionally, the generating process of the terminal data may include: generating the terminal first identity private key and the terminal first identity public key according to the terminal characteristic code; generating the terminal first signature message according to the terminal information and the second preset hash algorithm , the terminal first signature message is obtained by encrypting the terminal information through the second preset hash algorithm.

可选地,完成机卡绑定后,所述装置,包括:Optionally, after the machine-card binding is completed, the device includes:

第三获取模块,用于获取待验证SIM卡的SIM卡第二签名消息、待验证终端的终端第二身份私钥和终端第二签名消息,所述SIM卡第二签名消息为所述待验证SIM卡的SIM卡信息通过所述第一预设哈希算法加密得到,所述终端第二签名消息为所述待验证终端的终端信息通过所述第二预设哈希算法加密得到,所述终端第二身份私钥根据所述待验证终端的终端特征编码生成;The third obtaining module is used to obtain the SIM card second signature message of the SIM card to be verified, the terminal second identity private key of the terminal to be verified and the terminal second signature message, and the second signature message of the SIM card is the second signature message of the SIM card to be verified The SIM card information of the SIM card is obtained by encrypting the first preset hash algorithm, and the second signature message of the terminal is obtained by encrypting the terminal information of the terminal to be verified by the second preset hash algorithm, and the The terminal second identity private key is generated according to the terminal feature code of the terminal to be verified;

第一上报模块,用于将所述待验证终端的终端数字签名、所述终端第二签名消息和所述SIM卡第二签名消息上报SIM卡区块链,所述终端数字签名通过所述终端第二身份私钥对终端第二签名消息进行数字签名得到;The first reporting module is used to report the terminal digital signature of the terminal to be verified, the terminal second signature message and the SIM card second signature message to the SIM card block chain, and the terminal digital signature is passed through the terminal The second identity private key is obtained by digitally signing the second signature message of the terminal;

第一确定模块,用于将所有SIM卡区块链的数据块标识与所述SIM卡第二签名消息进行匹配,确定所述待验证SIM卡的SIM卡区块;The first determining module is used to match the data block identifiers of all SIM card block chains with the second signature message of the SIM card, and determine the SIM card block of the SIM card to be verified;

第一验证模块,用于根据所述待验证SIM卡的所述SIM卡区块中的终端第一身份公钥和所述终端第二签名消息验证所述终端数字签名,并确定验证结果。The first verification module is configured to verify the terminal digital signature according to the terminal first identity public key in the SIM card block of the SIM card to be verified and the terminal second signature message, and determine a verification result.

可选地,完成机卡绑定后,所述装置,包括:Optionally, after the machine-card binding is completed, the device includes:

第四获取模块,用于获取待验证SIM卡的SIM卡第二签名消息、SIM卡第二身份私钥和待验证终端的终端第二签名消息,所述SIM卡第二签名消息为所述待验证SIM卡的所述SIM卡信息通过所述第一预设哈希算法加密得到,所述SIM卡第二身份私钥根据所述待验证终端的所述终端特征编码生成,所述终端第二签名消息为所述终端信息通过所述第二预设哈希算法加密得到;The fourth obtaining module is used to obtain the second signed message of the SIM card of the SIM card to be verified, the second identity private key of the SIM card and the second signed message of the terminal of the terminal to be verified, and the second signed message of the SIM card is the second signed message of the terminal to be verified. The SIM card information for verifying the SIM card is obtained by encrypting the first preset hash algorithm, the second identity private key of the SIM card is generated according to the terminal feature code of the terminal to be verified, and the terminal second The signature message is obtained by encrypting the terminal information through the second preset hash algorithm;

第二上报模块,用于将待验证SIM卡的SIM卡数字签名、所述SIM卡第二签名消息和所述终端第二签名消息上报终端区块链,所述SIM卡数字签名通过所述SIM卡第二身份私钥对SIM卡第二签名消息进行数字签名得到;The second reporting module is used to report the SIM card digital signature of the SIM card to be verified, the second signature message of the SIM card and the second signature message of the terminal to the terminal block chain, and the digital signature of the SIM card is passed through the SIM The private key of the second identity of the card is obtained by digitally signing the second signature message of the SIM card;

第二确定模块,用于将所有终端区块链的数据块标识与所述终端第二签名消息进行匹配,确定所述待验证终端的终端区块;The second determination module is used to match the data block identifiers of all terminal block chains with the second signature message of the terminal, and determine the terminal block of the terminal to be verified;

第二验证模块,用于根据所述待验证终端的所述终端区块中的SIM卡第一身份公钥和所述SIM卡第二签名消息验证所述SIM卡数字签名,并确定验证结果;The second verification module is used to verify the digital signature of the SIM card according to the first identity public key of the SIM card in the terminal block of the terminal to be verified and the second signature message of the SIM card, and determine the verification result;

可选地,所述装置,还包括:Optionally, the device also includes:

判断模块,用于根据所述验证结果,判断是否出现机卡分离;A judging module, configured to judge whether machine-card separation occurs according to the verification result;

限制模块,用于当所述机卡分离时,对所述待验证终端或者所述待验证SIM卡进行限制入网。A restriction module, configured to restrict network access of the terminal to be verified or the SIM card to be verified when the machine card is separated.

第三方面,本申请提供一种服务器,包括:存储器,处理器,所述存储器,用于存储计算机程序,所述处理器,用于根据所述存储器存储的计算机程,实现第一方面及第一方面任一种可能的设计中的基于区块链的机卡绑定方法。In a third aspect, the present application provides a server, including: a memory, a processor, the memory is used to store computer programs, and the processor is used to realize the first aspect and the second aspect according to the computer program stored in the memory. On the one hand, any possible design of the machine-card binding method based on blockchain.

第四方面,本申请提供一种可读存储介质,可读存储介质中存储有执行指令,当服务器的至少一个处理器执行该执行指令时,服务器执行第一方面及第一方面任一种可能的设计中的基于区块链的机卡绑定方法。In a fourth aspect, the present application provides a readable storage medium in which an execution instruction is stored. When at least one processor of the server executes the execution instruction, the server executes any one of the first aspect and the first aspect. The blockchain-based machine-card binding method in the design of .

第五方面,本申请提供一种计算机程序产品,计算机程序产品包括计算机程序,该计算机程序被处理器执行时实现第一方面及第一方面任一种可能的设计中的基于区块链的机卡绑定方法。In the fifth aspect, the present application provides a computer program product. The computer program product includes a computer program. When the computer program is executed by a processor, it realizes the first aspect and the blockchain-based machine in any possible design of the first aspect. Card binding method.

本申请提供的基于区块链的机卡绑定方法和服务器,通过在获取终端发送的绑定请求后,根据该绑定请求确定其对应的SIM卡第一签名消息和终端第一身份公钥;其中,SIM卡第一签名消息可以根据SIM卡信息和第一预设哈希算法生成;其中,终端第一身份公钥可以由终端特征编码通过非对称加密算法生成;以SIM卡第一签名消息为数据块标识,以终端第一身份公钥为数据块数据,生成一个SIM卡新区块;将该SIM卡新区块插入SIM卡区块链中的手段,实现提高该机卡绑定信息的安全性,避免该机卡绑定信息出现被篡改的问题。The block chain-based machine-card binding method and server provided by this application determine the corresponding SIM card first signature message and terminal first identity public key according to the binding request after obtaining the binding request sent by the terminal ; Wherein, the first signature message of the SIM card can be generated according to the SIM card information and the first preset hash algorithm; wherein, the first identity public key of the terminal can be generated by the terminal feature code through an asymmetric encryption algorithm; the first signature of the SIM card The message is the data block identification, and the first identity public key of the terminal is used as the data block data to generate a new block of the SIM card; the method of inserting the new block of the SIM card into the block chain of the SIM card realizes the improvement of the binding information of the machine card Security, to avoid the problem of tampering with the card binding information of the machine.

附图说明Description of drawings

为了更清楚地说明本申请或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作一简单地介绍,显而易见地,下面描述中的附图是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。In order to more clearly illustrate the technical solutions in this application or the prior art, the accompanying drawings that need to be used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the accompanying drawings in the following description are the present For some embodiments of the application, those of ordinary skill in the art can also obtain other drawings based on these drawings without any creative effort.

图1为本申请一实施例提供的一种基于区块链的机卡绑定场景示意图;FIG. 1 is a schematic diagram of a blockchain-based machine-card binding scenario provided by an embodiment of the present application;

图2为本申请一实施例提供的一种基于区块链的机卡绑定方法的流程图;Fig. 2 is a flow chart of a blockchain-based machine-card binding method provided by an embodiment of the present application;

图3为本申请一实施例提供的一种SIM卡新区块的结构示意图;Fig. 3 is a schematic structural diagram of a new block of a SIM card provided by an embodiment of the present application;

图4为本申请一实施例提供的一种区块链的的结构示意图;FIG. 4 is a schematic structural diagram of a block chain provided by an embodiment of the present application;

图5为本申请一实施例提供的另一种基于区块链的机卡绑定方法的流程图;Fig. 5 is a flow chart of another blockchain-based machine-card binding method provided by an embodiment of the present application;

图6为本申请一实施例提供的一种终端新区块的结构示意图;FIG. 6 is a schematic structural diagram of a terminal new block provided by an embodiment of the present application;

图7为本申请一实施例提供的再一种基于区块链的机卡绑定方法的流程图;Fig. 7 is a flow chart of another block chain-based machine-card binding method provided by an embodiment of the present application;

图8为本申请一实施例提供的一种基于区块链的机卡绑定装置的结构示意图;FIG. 8 is a schematic structural diagram of a blockchain-based machine-card binding device provided by an embodiment of the present application;

图9为本申请一实施例提供的另一种基于区块链的机卡绑定装置的结构示意图;FIG. 9 is a schematic structural diagram of another blockchain-based machine-card binding device provided by an embodiment of the present application;

图10为本申请一实施例提供的一种基于区块链的机卡绑定系统的结构示意图;FIG. 10 is a schematic structural diagram of a blockchain-based machine-card binding system provided by an embodiment of the present application;

图11为本申请一实施例提供的一种服务器的硬件结构示意图。FIG. 11 is a schematic diagram of a hardware structure of a server provided by an embodiment of the present application.

具体实施方式Detailed ways

为使本申请的目的、技术方案和优点更加清楚,下面将结合本申请中的附图,对本申请中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。In order to make the purpose, technical solutions and advantages of this application clearer, the technical solutions in this application will be clearly and completely described below in conjunction with the accompanying drawings in this application. Obviously, the described embodiments are part of the embodiments of this application , but not all examples. Based on the embodiments in this application, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the scope of protection of this application.

在终端与SIM卡的使用中,其连接通常是不稳定的,终端可以更换SIM卡,SIM卡也可以更换终端。因此,在一些需要SIM卡与终端唯一绑定的场景中,该SIM卡与终端的连接方式是不安全的。例如,随着5G时代的到来,政企行业专网蓬勃发展,越来越多的政企行业产品选择5G无线接入。客户前置设备(Customer Premise Equipment,CPE)是其中的重要接入设备之一。CPE正是一种需要保证SIM卡与终端唯一绑定设备。由于5G政企专网套餐资费相对传统套餐更便宜,因此,容易出现用户将CPE中的SIM卡拔出来,放在手机中继续使用的情况。同时,由于5G政企专网签约长期合约后,CPE通常可以免费使用,但在使用期间,用户可能出现中途更换其它运营商SIM卡的情况。因此,为了保证CPE与其SIM的唯一绑定,需要使用机卡绑定方法来保证CPE使用的是其绑定的SIM卡,或者SIM卡是在其绑定的CPE中被使用。In the use of the terminal and the SIM card, the connection is usually unstable, the terminal can replace the SIM card, and the SIM card can also replace the terminal. Therefore, in some scenarios where the unique binding between the SIM card and the terminal is required, the connection mode between the SIM card and the terminal is not safe. For example, with the advent of the 5G era, private networks for government and enterprise industries are booming, and more and more government and enterprise industry products choose 5G wireless access. Customer Premise Equipment (CPE) is one of the important access devices. CPE is a device that needs to ensure that the SIM card is uniquely bound to the terminal. Since the 5G government-enterprise private network package is cheaper than the traditional package, it is easy for the user to pull out the SIM card in the CPE and continue to use it in the mobile phone. At the same time, since the 5G government-enterprise private network signs a long-term contract, CPE can usually be used for free, but during the use period, users may change SIM cards of other operators midway. Therefore, in order to ensure the unique binding between the CPE and its SIM, it is necessary to use a machine-card binding method to ensure that the CPE uses its bound SIM card, or that the SIM card is used in its bound CPE.

目前,常用的机卡绑定方法通常由SIM卡发送主动式命令到终端实现。终端在接收到SIM卡发送的主动式命令后,向SIM卡发送绑定信息,进而实现SIM卡与终端的绑定。然而,该机卡绑定方法需要通过SIM卡发送主动式命令。要实现SIM卡发送主动式命令,就需要在SIM卡芯片上设计移动终端的机卡绑定装置。该机卡绑定装置的设置存在对SIM卡系统制作和开发要求高的问题。其次,基于主动式命令的机卡绑定方法通常需要设计专门的机卡交互协议信令流程,以保证机卡的正确交互和绑定。该机卡交互协议信令流程的设置容易导致额外的信令开销。再次,该机卡绑定方法中绑定方向是单向的,只能在SIM卡中绑定终端。即,SIM卡在绑定后只能在该终端中使用,但是当终端更换SIM卡时,终端可以使用新的SIM卡。At present, the commonly used machine-card binding method is usually realized by sending active commands from the SIM card to the terminal. After receiving the proactive command sent by the SIM card, the terminal sends binding information to the SIM card, thereby realizing the binding of the SIM card and the terminal. However, this machine-card binding method needs to send active commands through the SIM card. To realize that the SIM card sends active commands, it is necessary to design a machine-card binding device of the mobile terminal on the SIM card chip. The setting of the machine card binding device has the problem of high requirements for the production and development of the SIM card system. Secondly, the machine-card binding method based on active commands usually needs to design a special machine-card interaction protocol signaling process to ensure the correct interaction and binding of the machine-card. The setting of the signaling process of the machine-card interaction protocol easily leads to additional signaling overhead. Again, the binding direction in this phone-card binding method is one-way, and the terminal can only be bound to the SIM card. That is, the SIM card can only be used in the terminal after binding, but when the terminal replaces the SIM card, the terminal can use a new SIM card.

针对上述问题,本申请提出了一种基于区块链的机卡绑定方法。出于对绑定安全性和稳定性的考虑,本申请使用了区块链作为机卡绑定信息的存储方式。本申请通过基于区块链的公钥存储,使公钥具有不可篡改性,提高公钥的安全性,同时提高验证的合法性。为了保证终端与SIM卡的唯一绑定,避免SIM卡绑定了终端,但是终端没有绑定SIM卡的情况出现,本申请提出了一种机卡的双向绑定方法。本申请中,服务器以SIM卡第一签名消息为数据块标识,终端第一身份公钥为数据块数据生成一个SIM卡新区块,插入SIM卡区块链。服务器还以终端第一签名消息为数据块标识,SIM卡第一身份公钥为数据块数据生成一个终端新区块,插入终端区块链。进而,在后续开机时,终端和SIM卡可以通过该SIM卡区块链或者终端区块链实现双向验证。并且,由于在本申请中,该注册和验证的过程均在服务器实现,因此对SIM卡系统要求不高,且不需要额外的机卡信令交互流程。In view of the above problems, this application proposes a block chain-based machine-card binding method. In consideration of binding security and stability, this application uses blockchain as the storage method of machine-card binding information. This application uses blockchain-based public key storage to make the public key non-tamperable, improve the security of the public key, and improve the legitimacy of verification at the same time. In order to ensure the unique binding between the terminal and the SIM card and avoid the situation that the SIM card is bound to the terminal but the terminal is not bound to the SIM card, this application proposes a two-way binding method of the machine card. In this application, the server uses the first signature message of the SIM card as the data block identifier, and the terminal's first identity public key generates a new block of the SIM card for the data block data, and inserts it into the SIM card block chain. The server also uses the terminal's first signature message as the data block identifier, and the SIM card's first identity public key generates a new terminal block for the data block data, and inserts it into the terminal block chain. Furthermore, when starting up later, the terminal and the SIM card can realize two-way verification through the SIM card blockchain or the terminal blockchain. Moreover, since in this application, the registration and verification processes are all implemented on the server, the requirements for the SIM card system are not high, and no additional machine-card signaling interaction process is required.

此外,本申请所使用的基于区块链的的机卡绑定方法不仅可用于机卡绑定及其验证,还可以用于机卡分离检测。In addition, the block chain-based machine-card binding method used in this application can not only be used for machine-card binding and its verification, but also can be used for machine-card separation detection.

下面以具体地实施例对本申请的技术方案进行详细说明。下面这几个具体的实施例可以相互结合,对于相同或相似的概念或过程可能在某些实施例不再赘述。The technical solution of the present application will be described in detail below with specific embodiments. The following specific embodiments may be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

图1示出了本申请一实施例提供的一种基于区块链的机卡绑定场景示意图。如图1所示,该机卡绑定场景中包括插入了SIM卡的终端和服务器。当终端插入新的SIM卡,或SIM卡插入新的终端后,终端开机,并向服务器发送绑定请求。服务器根据该终端与SIM卡的绑定请求生成终端第一身份私钥、终端第一身份公钥和终端第一签名消息,以及SIM卡第一身份私钥、SIM卡第一身份公钥和SIM卡第一签名消息。服务器根据以上信息生成SIM卡区块和终端区块。服务器分别将SIM卡区块和终端区块上传至SIM卡区块链和终端区块链。当该终端再次开机时,该终端响服务器发送验证请求。服务器根据该终端与SIM卡的验证请求生成终端第二身份私钥、终端第二签名消息和终端数字签名,以及SIM卡第二身份私钥、SIM卡第二签名消息和SIM卡数字签名。服务器根据SIM卡第二签名消息从SIM卡区块链中匹配SIM卡区块。当匹配到SIM卡区块后,服务器根据终端第一身份公钥和终端第二签名消息对终端数字签名进行验证。若数字签名通过验证,则说明该SIM卡当前插入的终端为原始的终端。或者,服务器根据终端第二签名消息从终端区块链中匹配终端区块。当匹配到终端区块后,服务器根据SIM卡第一身份公钥和SIM卡第二签名消息对SIM卡数字签名进行验证。若数字签名通过验证,则表明该终端使用的SIM卡为原始的SIM卡。Fig. 1 shows a schematic diagram of a blockchain-based machine-card binding scenario provided by an embodiment of the present application. As shown in FIG. 1 , the machine-card binding scenario includes a terminal and a server in which a SIM card is inserted. When a new SIM card is inserted into the terminal, or after the SIM card is inserted into a new terminal, the terminal starts up and sends a binding request to the server. According to the binding request between the terminal and the SIM card, the server generates the terminal first identity private key, the terminal first identity public key and the terminal first signature message, as well as the SIM card first identity private key, the SIM card first identity public key and the SIM Card first signature message. The server generates the SIM card block and the terminal block according to the above information. The server uploads the SIM card block and the terminal block to the SIM card block chain and the terminal block chain respectively. When the terminal is turned on again, the terminal sends a verification request to the server. According to the verification request of the terminal and the SIM card, the server generates the terminal second identity private key, the terminal second signature message and the terminal digital signature, and the SIM card second identity private key, the SIM card second signature message and the SIM card digital signature. The server matches the SIM card block from the SIM card blockchain according to the second signature message of the SIM card. After the SIM card block is matched, the server verifies the digital signature of the terminal according to the terminal's first identity public key and the terminal's second signature message. If the digital signature is verified, it means that the terminal where the SIM card is currently inserted is the original terminal. Alternatively, the server matches the terminal block from the terminal block chain according to the second signature message of the terminal. When the terminal block is matched, the server verifies the digital signature of the SIM card according to the first identity public key of the SIM card and the second signature message of the SIM card. If the digital signature is verified, it indicates that the SIM card used by the terminal is the original SIM card.

本申请中,以服务器为执行主体,执行如下实施例的句式编辑方法。具体地,该执行主体可以为服务器的硬件装置,或者为服务器中实现下述实施例的软件应用,或者为安装有实现下述实施例的软件应用的计算机可读存储介质。In this application, the server is used as the execution subject to execute the sentence pattern editing method in the following embodiments. Specifically, the execution subject may be a hardware device of a server, or a software application implementing the following embodiments in the server, or a computer-readable storage medium installed with a software application implementing the following embodiments.

图2示出了本申请一实施例提供的一种基于区块链的机卡绑定方法的流程图。在图1所示实施例的基础上,如图2所示,以服务器为执行主体,本实施例的方法可以包括如下步骤:Fig. 2 shows a flow chart of a blockchain-based machine-card binding method provided by an embodiment of the present application. On the basis of the embodiment shown in Figure 1, as shown in Figure 2, with the server as the execution subject, the method of this embodiment may include the following steps:

S101、获取SIM卡第一签名消息和终端第一身份公钥。S101. Obtain the first signature message of the SIM card and the first identity public key of the terminal.

本实施例中,服务器在获取终端发送的绑定请求后,根据该绑定请求确定其对应的SIM卡第一签名消息和终端第一身份公钥。In this embodiment, after obtaining the binding request sent by the terminal, the server determines the corresponding first signature message of the SIM card and the first identity public key of the terminal according to the binding request.

其中,该绑定请求可以在该终端第一次开机时或者该SIM卡第一次申请入网时,由该终端向服务器发送。Wherein, the binding request may be sent by the terminal to the server when the terminal is turned on for the first time or when the SIM card applies for network access for the first time.

其中,该SIM卡第一签名消息和终端第一身份公钥可以为服务器从该绑定请求中获取。Wherein, the first signature message of the SIM card and the first identity public key of the terminal may be acquired by the server from the binding request.

或者,该SIM卡第一签名消息和终端第一身份公钥还可以为服务器从内存中获取。当该SIM卡第一签名消息和终端第一身份公钥为服务器从内存中获取时,服务器可以根据绑定请求确定SIM卡特征编码和终端特征编码。服务器根据该SIM卡特征编码和终端特征编码,从服务器的存储设备中获取预先存储的SIM卡第一签名消息和终端第一身份公钥。其中,SIM卡特征编码和终端特征编码用于唯一标识该SIM卡和该终端。其中,SIM卡特征编码包括但不限于IMSI、MSISDN、ICCID、序列号SN等。其中,终端特征编码包括但不限于IMEI、MEID、ESN等。Alternatively, the first signature message of the SIM card and the first identity public key of the terminal may also be obtained by the server from memory. When the first signature message of the SIM card and the first terminal identity public key are obtained by the server from the memory, the server may determine the SIM card feature code and the terminal feature code according to the binding request. According to the SIM card feature code and the terminal feature code, the server obtains the pre-stored first signature message of the SIM card and the first terminal identity public key from the storage device of the server. Wherein, the SIM card feature code and the terminal feature code are used to uniquely identify the SIM card and the terminal. Wherein, the characteristic code of the SIM card includes but not limited to IMSI, MSISDN, ICCID, serial number SN and so on. Wherein, the terminal characteristic encoding includes but not limited to IMEI, MEID, ESN and so on.

或者,该SIM卡第一签名消息和终端第一身份公钥还可以为服务器根据SIM卡特征编码和SIM卡信息以及终端特征编码和终端信息生成。其中,SIM卡特征编码和SIM卡信息以及终端特征编码和终端信息可以为服务器根据绑定请求获取。或者服务器在根据绑定请求确定SIM卡特征编码和终端特征编码后,从存储设备中获取。其中,服务器根据SIM卡特征编码和SIM卡信息以及终端特征编码和终端信息生成SIM卡第一签名消息和终端第一身份公钥可以通过如下示例实现。Alternatively, the first signature message of the SIM card and the first terminal identity public key may also be generated by the server according to the SIM card feature code and SIM card information as well as the terminal feature code and terminal information. Wherein, the SIM card feature code and SIM card information as well as the terminal feature code and terminal information can be acquired by the server according to the binding request. Or the server acquires it from the storage device after determining the SIM card feature code and the terminal feature code according to the binding request. Wherein, the server generates the SIM card first signature message and the terminal first identity public key according to the SIM card feature code and SIM card information and the terminal feature code and terminal information, which can be implemented through the following example.

一种示例中,该SIM卡参数的生成过程可以包括:In an example, the generation process of the SIM card parameters may include:

步骤1、服务器在获取SIM卡特征编码后,可以根据SIM卡特征编码,生成SIM卡第一身份私钥和SIM卡第一身份公钥。Step 1. After obtaining the SIM card feature code, the server can generate the SIM card first identity private key and the SIM card first identity public key according to the SIM card feature code.

本步骤中,服务器可以基于非对称加密算法,根据SIM卡特征编码生成SIM卡第一身份私钥。进而,服务器基于该非对称加密算法,根据SIM卡第一身份私钥生成SIM卡第一身份公钥。其中,非对称加密算法可以包括RSA、Elgamal、背包算法、Rabin、D-H、ECC(椭圆曲线加密算法)等现有算法,该非对称加密算法还可以为改进后的算发。In this step, the server can generate the private key of the first identity of the SIM card according to the feature code of the SIM card based on the asymmetric encryption algorithm. Furthermore, based on the asymmetric encryption algorithm, the server generates the first public key of the SIM card identity according to the private key of the first identity of the SIM card. Wherein, the asymmetric encryption algorithm may include existing algorithms such as RSA, Elgamal, knapsack algorithm, Rabin, D-H, ECC (elliptic curve encryption algorithm), and the asymmetric encryption algorithm may also be an improved algorithm.

步骤2、服务器在获取SIM卡信息后,可以根据SIM卡信息和第一预设哈希算法,生成SIM卡第一签名消息,SIM卡第一签名消息为SIM卡信息通过第一预设哈希算法加密得到。Step 2. After obtaining the SIM card information, the server can generate the first signature message of the SIM card according to the SIM card information and the first preset hash algorithm. The first signature message of the SIM card is that the SIM card information passes the first preset hash algorithm. Algorithm encrypted.

本步骤中,该SIM卡信息包括但不限于IMSI、MSISDN、ICCID、序列号SN等。该第一预设哈希算法可以为MD5,HMAC,SHA1,SHA256等现有算法,该Hash算法还可以为改进后的算法。In this step, the SIM card information includes but not limited to IMSI, MSISDN, ICCID, serial number SN and so on. The first preset hash algorithm may be an existing algorithm such as MD5, HMAC, SHA1, SHA256, etc., and the Hash algorithm may also be an improved algorithm.

另一种示例中,该终端参数的生成步骤可以包括:In another example, the step of generating the terminal parameters may include:

步骤1、服务器在获取终端特征编码后,可以根据终端特征编码,生成终端第一身份私钥和终端第一身份公钥。Step 1. After obtaining the terminal characteristic code, the server can generate a terminal first identity private key and a terminal first identity public key according to the terminal characteristic code.

本步骤中,服务器可以基于非对称加密算法,根据终端特征编码,生成终端第一身份私钥。进而,服务器基于该非对称加密算法,根据终端第一身份私钥,生成终端第一身份公钥。其中,非对称加密算法可以包括RSA、Elgamal、背包算法、Rabin、D-H、ECC(椭圆曲线加密算法)等现有算法,该非对称加密算法还可以为改进后的算发。In this step, the server may generate the terminal first identity private key based on the asymmetric encryption algorithm and the terminal characteristic code. Furthermore, based on the asymmetric encryption algorithm, the server generates the terminal first identity public key according to the terminal first identity private key. Wherein, the asymmetric encryption algorithm may include existing algorithms such as RSA, Elgamal, knapsack algorithm, Rabin, D-H, ECC (elliptic curve encryption algorithm), and the asymmetric encryption algorithm may also be an improved algorithm.

步骤2、根据终端信息和第二预设哈希算法,生成终端第一签名消息,终端第一签名消息为终端信息通过第二预设哈希算法加密得到。Step 2: Generate a first terminal signature message according to the terminal information and the second preset hash algorithm, where the terminal first signature message is obtained by encrypting the terminal information through the second preset hash algorithm.

本步骤中,该终端信息包括但不限于IMEI、MEID、ESN等。该第二预设哈希算法可以为MD5,HMAC,SHA1,SHA256等现有算法,该Hash算法还可以为改进后的算法。其中,第二预设哈希算法与第一预设哈希算法可以为相同的哈希算法,或者,第二预设哈希算法与第一预设哈希算法可以为不同的哈希算法,本申请对此不作限制。In this step, the terminal information includes but not limited to IMEI, MEID, ESN and so on. The second preset hash algorithm may be existing algorithms such as MD5, HMAC, SHA1, SHA256, etc., and the Hash algorithm may also be an improved algorithm. Wherein, the second preset hash algorithm and the first preset hash algorithm may be the same hash algorithm, or the second preset hash algorithm and the first preset hash algorithm may be different hash algorithms, This application is not limited to this.

S102、根据SIM卡第一签名消息和终端第一身份公钥,生成SIM卡新区块,SIM卡新区块包括数据块标识和数据块数据,SIM卡第一签名消息为数据块标识,终端第一身份公钥为数据块数据。S102. Generate a new block of the SIM card according to the first signature message of the SIM card and the first identity public key of the terminal. The new block of the SIM card includes the data block identifier and the data block data. The first signature message of the SIM card is the data block identifier, and the terminal first The identity public key is data block data.

本实施例中,服务器生成一个SIM卡新区块,该SIM卡新区块可以如图3所示。该SIM卡新区块中包括数据块标识和数据块数据。其中,数据块标识内容为SIM卡第一签名消息。其中,数据块数据内容为终端第一身份公钥。In this embodiment, the server generates a new block of the SIM card, and the new block of the SIM card may be as shown in FIG. 3 . The new block of the SIM card includes the data block identifier and the data block data. Wherein, the content of the data block identification is the first signature message of the SIM card. Wherein, the data content of the data block is the terminal first identity public key.

S103、将SIM卡区块插入SIM卡区块链中。S103. Insert the SIM card block into the SIM card block chain.

本实施例中,该SIM卡区块链可以如图4所示,每一区块中包括索引、时间戳、数据块、哈希值和上一区块哈希值五个部分。其中,索引用于在该SIM卡区块链中唯一标识其中的区块。其中,该时间戳为该区块插入到该区块链的时间。其中,数据块中存储的内容为S102中SIM卡区块的内容,即以SIM卡第一签名消息为数据块标识,以终端第一身份公钥为数据块数据的数据块内容。其中,上一区块哈希值为该SIM卡区块链中,该区块的上一区块的哈希值,第一区块的上一区块哈希值为0。In this embodiment, the SIM card block chain can be shown in FIG. 4 , and each block includes five parts: index, time stamp, data block, hash value and previous block hash value. Wherein, the index is used to uniquely identify the blocks in the SIM card blockchain. Wherein, the timestamp is the time when the block is inserted into the blockchain. Wherein, the content stored in the data block is the content of the SIM card block in S102, that is, the content of the data block with the first signature message of the SIM card as the data block identifier and the terminal first identity public key as the data block data. Wherein, the hash value of the previous block is the hash value of the previous block of the block in the SIM card blockchain, and the hash value of the previous block of the first block is 0.

当SIM卡新区块插入SIM卡区块链时,SIM卡新区块使用尾插法插入到该SIM卡区块链的末尾。服务器将该SIM卡新区块的时间戳确定为该SIM卡新区块的插入时间。服务器根据SIM卡区块链的索引,确定该SIM卡新区块的索引。服务器根据该SIM卡区块链中该SIM卡新区块的上一区块,确定上一区块哈希值。When a new block of the SIM card is inserted into the block chain of the SIM card, the new block of the SIM card is inserted into the end of the block chain of the SIM card using the tail insertion method. The server determines the time stamp of the new block of the SIM card as the insertion time of the new block of the SIM card. The server determines the index of the new block of the SIM card according to the index of the SIM card blockchain. The server determines the hash value of the previous block according to the previous block of the new block of the SIM card in the SIM card blockchain.

其中,该SIM卡区块链可以存储在该服务器上,或者该SIM卡区块链还可以存储在区块链服务器中。当SIM卡区块链存储在区块链服务器中时,该区块链的操作通过区块链系统实现。Wherein, the SIM card blockchain can be stored on the server, or the SIM card blockchain can also be stored in the blockchain server. When the SIM card blockchain is stored in the blockchain server, the operation of the blockchain is realized through the blockchain system.

本申请提供的基于区块链的机卡绑定方法,服务器在获取终端发送的绑定请求后,根据该绑定请求确定其对应的SIM卡第一签名消息和终端第一身份公钥。其中,SIM卡第一签名消息可以根据SIM卡信息和第一预设哈希算法生成。其中,终端第一身份公钥可以由终端特征编码通过非对称加密算法生成。服务器以SIM卡第一签名消息为数据块标识,以终端第一身份公钥为数据块数据,生成一个SIM卡新区块。服务器将该SIM卡新区块插入SIM卡区块链中。本申请中,通过生成SIM卡区块,实现该SIM卡与终端的绑定,还通过将该SIM卡区块插入SIM卡区块链,提高该机卡绑定信息的安全性,避免该机卡绑定信息出现被篡改的问题。In the blockchain-based machine-card binding method provided by this application, after obtaining the binding request sent by the terminal, the server determines the corresponding first signature message of the SIM card and the first identity public key of the terminal according to the binding request. Wherein, the first signature message of the SIM card may be generated according to the information of the SIM card and the first preset hash algorithm. Wherein, the terminal first identity public key may be generated from the terminal feature code through an asymmetric encryption algorithm. The server uses the first signature message of the SIM card as the data block identifier, and uses the terminal's first identity public key as the data block data to generate a new block of the SIM card. The server inserts the new block of the SIM card into the SIM card blockchain. In this application, by generating the SIM card block, the binding of the SIM card and the terminal is realized, and by inserting the SIM card block into the SIM card block chain, the security of the card binding information of the machine is improved, and the terminal is prevented from The card binding information has been tampered with.

图5示出了本申请一实施例提供的另一种基于区块链的机卡绑定方法的流程图。在图1至图4所示实施例的基础上,本实施例除了可以实现SIM卡绑定终端,还可以实现终端绑定SIM卡,从而实现双向绑定的效果。如图5所示,以服务器为执行主体,本实施例的方法可以包括如下步骤:Fig. 5 shows a flow chart of another blockchain-based machine-card binding method provided by an embodiment of the present application. On the basis of the embodiments shown in FIG. 1 to FIG. 4 , in this embodiment, not only the SIM card can be bound to the terminal, but also the terminal can be bound to the SIM card, so as to achieve the effect of two-way binding. As shown in Figure 5, with the server as the execution subject, the method of this embodiment may include the following steps:

S201、获取终端第一签名消息和SIM卡第一身份公钥。S201. Obtain a first signature message of a terminal and a first identity public key of a SIM card.

本实施例中,服务器在获取终端发送的绑定请求后,根据该绑定请求确定其对应的SIM卡第一签名消息和终端第一身份公钥。In this embodiment, after obtaining the binding request sent by the terminal, the server determines the corresponding first signature message of the SIM card and the first identity public key of the terminal according to the binding request.

其中,该绑定请求可以在该终端第一次开机时或者该SIM卡第一次申请入网时,由该终端向服务器发送。Wherein, the binding request may be sent by the terminal to the server when the terminal is turned on for the first time or when the SIM card applies for network access for the first time.

其中,该终端第一签名消息和SIM卡第一身份公钥可以为服务器从该绑定请求中获取。Wherein, the first signature message of the terminal and the first identity public key of the SIM card may be acquired by the server from the binding request.

或者,该终端第一签名消息和SIM卡第一身份公钥还可以为服务器从内存中获取。Alternatively, the first signed message of the terminal and the first identity public key of the SIM card may also be acquired by the server from memory.

或者,该终端第一签名消息和SIM卡第一身份公钥还可以为服务器根据SIM卡特征编码和SIM卡信息以及终端特征编码和终端信息生成。其中,该终端第一签名消息和SIM卡第一身份公钥的生成过程与图2实施例中的步骤S101实现方式类似,本实施例此处不再赘述。Alternatively, the first signature message of the terminal and the first identity public key of the SIM card may also be generated by the server according to the SIM card feature code and SIM card information as well as the terminal feature code and terminal information. Wherein, the generation process of the first signature message of the terminal and the first identity public key of the SIM card is similar to that of step S101 in the embodiment of FIG. 2 , and will not be repeated here in this embodiment.

S202、根据终端第一签名消息和SIM卡第一身份公钥,生成终端新区块,终端新区块包括数据块标识和数据块数据,终端第一签名消息为数据块标识,SIM卡第一身份公钥为数据块数据。S202. Generate a new block for the terminal according to the first signature message of the terminal and the first identity public key of the SIM card. The new block of the terminal includes a data block identifier and data block data. The first signature message of the terminal is the data block identifier, and the first identity public key of the SIM card The key is the block data.

本实施例中,服务器生成一个终端新区块,该终端新区块可以如图6所示。该终端新区块中包括数据块标识和数据块数据。其中,数据块标识内容为终端第一签名消息。其中,数据块数据内容为SIM卡第一身份公钥。In this embodiment, the server generates a new terminal block, and the new terminal block may be as shown in FIG. 6 . The terminal new block includes a data block identifier and data block data. Wherein, the content of the data block identification is the terminal's first signature message. Wherein, the data content of the data block is the first identity public key of the SIM card.

S203、将终端新区块插入终端区块链中。S203. Insert the terminal new block into the terminal blockchain.

该终端区块链可以如图4所示。当终端新区块插入终端区块链时,终端新区块使用尾插法插入到该终端区块链的末尾。服务器将该终端新区块的时间戳确定为该终端新区块的插入时间。服务器根据终端区块链的索引,确定该终端新区块的索引。服务器根据该终端区块链中该终端新区块的上一区块,确定上一区块哈希值。The terminal blockchain can be shown in Figure 4. When a terminal new block is inserted into the terminal blockchain, the terminal new block is inserted at the end of the terminal blockchain using the tail insertion method. The server determines the time stamp of the new block of the terminal as the insertion time of the new block of the terminal. The server determines the index of the new block of the terminal according to the index of the terminal blockchain. The server determines the hash value of the previous block according to the previous block of the new block of the terminal in the terminal blockchain.

本申请提供的基于区块链的机卡绑定方法,服务器在获取终端发送的绑定请求后,根据该绑定请求确定其对应的终端第一签名消息和SIM卡第一身份公钥。其中,终端第一签名消息可以根据终端信息和第二预设哈希算法生成。其中,SIM卡第一身份公钥可以由SIM卡特征编码通过非对称加密算法生成。服务器以终端第一签名消息为数据块标识,以SIM卡第一身份公钥为数据块数据,生成一个终端新区块。服务器将该终端新区块插入终端区块链中。本申请中,生成SIM卡区块,实现该SIM卡与终端的绑定,还通过将该SIM卡区块插入SIM卡区块链,提高该机卡绑定信息的安全性,避免该机卡绑定信息出现被篡改的问题。同时,本申请还通过SIM卡区块链和终端区块链实现了双向绑定,可以更好的保证SIM卡与终端的唯一绑定效果。In the blockchain-based machine-card binding method provided by this application, after the server obtains the binding request sent by the terminal, it determines the corresponding first signature message of the terminal and the first identity public key of the SIM card according to the binding request. Wherein, the terminal first signature message may be generated according to terminal information and a second preset hash algorithm. Wherein, the first identity public key of the SIM card can be generated from the feature code of the SIM card through an asymmetric encryption algorithm. The server uses the terminal's first signature message as the data block identifier and the SIM card's first identity public key as the data block data to generate a new terminal block. The server inserts the terminal new block into the terminal blockchain. In this application, the SIM card block is generated to realize the binding of the SIM card and the terminal, and by inserting the SIM card block into the SIM card block chain, the security of the machine card binding information is improved, and the machine card is avoided. The binding information has been tampered with. At the same time, this application also realizes two-way binding through the SIM card blockchain and the terminal blockchain, which can better ensure the unique binding effect between the SIM card and the terminal.

例如,在5G CPE的使用中,由于5G政企专网套餐资费相对传统套餐更便宜,因此,在实际使用中容易出现用户将CPE中的SIM卡拔出来,放在手机中继续使用的情况。为了避免这一情况,本申请通过图2的实施例实现了SIM卡与终端的绑定。服务器可以在后续使用中,通过查询与该SIM卡绑定的终端,并比较当前终端是否与绑定终端一致,确定SIM卡是否被挪用。同时,由于5G政企专网签约长期合约后CPE是免费使用,因此,在实际使用中容易出现用户将该CPE中的SIM卡更换为其它运营商的SIM卡。为了避免这一情况,本申请通过图5的实施例实现了终端与SIM卡的绑定。服务器可以在后续使用中,通过查询与该终端绑定的SIM卡,并比较当前SIM卡是否与绑定SIM卡一致,确定SIM卡是否被更换。For example, in the use of 5G CPE, since the 5G government-enterprise private network package is cheaper than the traditional package, in actual use, it is easy for the user to pull out the SIM card in the CPE and continue to use it in the mobile phone. In order to avoid this situation, the present application realizes the binding of the SIM card and the terminal through the embodiment shown in FIG. 2 . In subsequent use, the server can determine whether the SIM card has been embezzled by querying the terminal bound to the SIM card and comparing whether the current terminal is consistent with the bound terminal. At the same time, since the CPE is free to use after signing a long-term contract for the 5G government-enterprise private network, it is easy for users to replace the SIM card in the CPE with a SIM card of another operator in actual use. In order to avoid this situation, the present application realizes the binding of the terminal and the SIM card through the embodiment shown in FIG. 5 . In subsequent use, the server may determine whether the SIM card has been replaced by querying the SIM card bound to the terminal and comparing whether the current SIM card is consistent with the bound SIM card.

图7示出了本申请一实施例提供的再一种基于区块链的机卡绑定方法的流程图。在图1至图6所示实施例的基础上,本实施例除了可以实现机卡绑定,还可以实现机卡验证,从而确定SIM卡是否为终端的初始绑定SIM卡,或者终端是否为SIM卡的初始绑定终端。如图7所示,以服务器为执行主体,本实施例的方法可以包括如下步骤:Fig. 7 shows a flow chart of another block chain-based machine-card binding method provided by an embodiment of the present application. On the basis of the embodiments shown in Figures 1 to 6, in addition to machine-card binding, this embodiment can also implement machine-card verification, so as to determine whether the SIM card is the initial bound SIM card of the terminal, or whether the terminal is The initial binding terminal of the SIM card. As shown in Figure 7, with the server as the execution subject, the method of this embodiment may include the following steps:

S301、获取SIM卡第一签名消息和终端第一身份公钥。S301. Obtain the first signature message of the SIM card and the first identity public key of the terminal.

S302、根据SIM卡第一签名消息和终端第一身份公钥,生成SIM卡新区块,SIM卡新区块包括数据块标识和数据块数据,SIM卡第一签名消息为数据块标识,终端第一身份公钥为数据块数据。S302. Generate a new block of the SIM card according to the first signature message of the SIM card and the first identity public key of the terminal. The new block of the SIM card includes the data block identifier and the data block data. The first signature message of the SIM card is the data block identifier, and the terminal first The identity public key is data block data.

S303、将SIM卡新区块插入SIM卡区块链中。S303. Insert the new block of the SIM card into the block chain of the SIM card.

其中,步骤S301至S303与图2实施例中的步骤S101至S103实现方式类似,本实施例此处不再赘述。Wherein, steps S301 to S303 are implemented in a manner similar to that of steps S101 to S103 in the embodiment of FIG. 2 , which will not be repeated here in this embodiment.

S304、获取待验证SIM卡的SIM卡第二签名消息、待验证终端的终端第二身份私钥和终端第二签名消息,SIM卡第二签名消息为待验证SIM卡的SIM卡信息通过第一预设哈希算法加密得到,终端第二签名消息为待验证终端的终端信息通过第二预设哈希算法加密得到,终端第二身份私钥根据待验证终端的终端特征编码生成。S304. Obtain the SIM card second signature message of the SIM card to be verified, the terminal second identity private key of the terminal to be verified, and the terminal second signature message. The SIM card second signature message is the SIM card information of the SIM card to be verified through the first The second signature message of the terminal is obtained by encrypting the terminal information of the terminal to be verified through the second preset hash algorithm, and the second identity private key of the terminal is generated according to the terminal characteristic code of the terminal to be verified.

本实施例中,服务器在获取待验证终端发送的验证请求后,根据该验证请求确定其对应的SIM卡第二签名消息、终端第二身份私钥和终端第二签名消息。In this embodiment, after obtaining the verification request sent by the terminal to be verified, the server determines the corresponding SIM card second signature message, terminal second identity private key, and terminal second signature message according to the verification request.

其中,该验证请求可以在该终端再次开机时或者再次申请入网时,由该待验证终端向服务器发送。Wherein, the verification request may be sent by the terminal to be verified to the server when the terminal is turned on again or when applying for network access again.

其中,该待验证终端的SIM卡第二签名消息、终端第二身份私钥和终端第二签名消息可以为服务器从该验证请求中获取。Wherein, the second signature message of the SIM card of the terminal to be verified, the second identity private key of the terminal, and the second signature message of the terminal may be acquired by the server from the verification request.

或者,该SIM卡第二签名消息、终端第二身份私钥和终端第二签名消息还可以为服务器从内存中获取。此时,该验证请求中包括待验证SIM卡的SIM卡特征编码和待验证终端的终端特征编码。服务器根据该SIM卡特征编码和终端特征编码直接从服务器的内存中获取。Alternatively, the second signature message of the SIM card, the second identity private key of the terminal, and the second signature message of the terminal may also be obtained by the server from memory. At this time, the verification request includes the SIM card feature code of the SIM card to be verified and the terminal feature code of the terminal to be verified. The server obtains directly from the memory of the server according to the SIM card feature code and the terminal feature code.

或者,该SIM卡第二签名消息、终端第二身份私钥和终端第二签名消息还可以为服务器根据待验证SIM卡的SIM卡特征编码和SIM卡信息以及待验证终端的终端特征编码和终端信息生成。其中,该生成过程与图2实施例中的步骤S101实现方式类似,本实施例此处不再赘述。Or, the second SIM card signature message, the terminal second identity private key, and the terminal second signature message can also be the server's SIM card feature code and SIM card information of the SIM card to be verified and the terminal feature code and terminal feature code of the terminal to be verified. Information generation. Wherein, the generation process is similar to the implementation of step S101 in the embodiment of FIG. 2 , and will not be repeated here in this embodiment.

S305、将待验证终端的终端数字签名、终端第二签名消息和SIM卡第二签名消息上报SIM卡区块链,终端数字签名通过终端第二身份私钥对终端第二签名消息进行数字签名得到。S305. Report the terminal digital signature of the terminal to be verified, the terminal second signature message and the SIM card second signature message to the SIM card blockchain, and the terminal digital signature is obtained by digitally signing the terminal second signature message with the terminal second identity private key .

本实施例中,服务器在获取终端第二身份私钥和终端第二签名消息后,使用终端第二身份私钥对终端第二签名消息进行数字签名,得到终端数字签名。服务器将该终端数字签名、终端第二签名消息和SIM卡第二签名消息一起上报到SIM卡区块链。In this embodiment, after obtaining the terminal's second identity private key and the terminal's second signature message, the server uses the terminal's second identity private key to digitally sign the terminal's second signature message to obtain the terminal's digital signature. The server reports the terminal digital signature, the terminal second signature message and the SIM card second signature message to the SIM card block chain together.

S306、将所有SIM卡区块链的数据块标识与SIM卡第二签名消息进行匹配,确定待验证SIM卡的SIM卡区块。S306. Match the data block identifiers of all SIM card block chains with the second signature message of the SIM card, and determine the SIM card block of the SIM card to be verified.

本实施例中,区块链根据服务器上报的SIM卡第二签名消息,在SIM卡区块链中匹配与之对应的待验证SIM卡的SIM卡区块。具体的,服务器获取该SIM卡区块链中每一SIM卡区块的数据块标识。服务器通过匹配该数据块标识与SIM卡第二签名消息,确定该SIM卡区块链中与数据块标识与SIM卡第二签名消息相同的SIM卡区块。服务器确定该SIM卡区块为待验证SIM卡的SIM卡区块。In this embodiment, the blockchain matches the corresponding SIM card block of the SIM card to be verified in the SIM card blockchain according to the second signature message of the SIM card reported by the server. Specifically, the server obtains the data block identifier of each SIM card block in the SIM card blockchain. By matching the data block identifier and the second SIM card signature message, the server determines the SIM card block in the SIM card blockchain that is identical to the data block identifier and the SIM card second signature message. The server determines that the SIM card block is the SIM card block of the SIM card to be verified.

S307、根据待验证SIM卡的SIM卡区块中的终端第一身份公钥和终端第二签名消息验证终端数字签名,并确定验证结果。S307. Verify the terminal digital signature according to the terminal's first identity public key in the SIM card block of the SIM card to be verified and the terminal's second signature message, and determine a verification result.

本实施例中,服务器在确定该待验证SIM卡的SIM卡区块后,获取该SIM卡区块的数据块数据。该数据块数据为该待验证的SIM卡的原始匹配终端的终端第一身份公钥。服务器根据原始匹配终端的终端第一身份公钥和终端第二签名消息,对终端数字签名进行验证。如果验证成功则说明待验证终端与该原始匹配终端为同一个终端。如果验证失败则说明待验证终端与该原始匹配终端为不同终端。In this embodiment, after determining the SIM card block of the SIM card to be verified, the server obtains the data block data of the SIM card block. The data block data is the terminal first identity public key of the original matching terminal of the SIM card to be verified. The server verifies the digital signature of the terminal according to the terminal's first identity public key of the originally matched terminal and the terminal's second signature message. If the verification is successful, it means that the terminal to be verified is the same terminal as the original matching terminal. If the verification fails, it means that the terminal to be verified is different from the original matching terminal.

S308、获取终端第一签名消息和SIM卡第一身份公钥。S308. Obtain the first signature message of the terminal and the first identity public key of the SIM card.

S309、根据终端第一签名消息和SIM卡第一身份公钥,生成终端新区块,终端新区块包括数据块标识和数据块数据,终端第一签名消息为数据块标识,SIM卡第一身份公钥为数据块数据。S309. Generate a new block for the terminal according to the first signature message of the terminal and the first identity public key of the SIM card. The new block of the terminal includes the data block identifier and the data block data. The first signature message of the terminal is the data block identifier, and the first identity public key of the SIM card The key is the block data.

S310、将终端新区块插入终端区块链中。S310. Insert the terminal new block into the terminal blockchain.

其中,步骤S308至S310与图5实施例中的步骤S201至S203实现方式类似,本实施例此处不再赘述。Wherein, steps S308 to S310 are implemented in a manner similar to steps S201 to S203 in the embodiment of FIG. 5 , and details are not repeated here in this embodiment.

S311、获取待验证SIM卡的SIM卡第二签名消息、SIM卡第二身份私钥和待验证终端的终端第二签名消息,SIM卡第二签名消息为待验证SIM卡的SIM卡信息通过第一预设哈希算法加密得到,SIM卡第二身份私钥根据待验证终端的终端特征编码生成,终端第二签名消息为终端信息通过第二预设哈希算法加密得到。S311. Obtain the second signature message of the SIM card of the SIM card to be verified, the second identity private key of the SIM card, and the second signature message of the terminal of the terminal to be verified. The second signature message of the SIM card is the SIM card information of the SIM card to be verified through the second It is encrypted by a preset hash algorithm, the second identity private key of the SIM card is generated according to the terminal feature code of the terminal to be verified, and the second signature message of the terminal is terminal information encrypted by the second preset hash algorithm.

本实施例中,服务器在获取待验证终端发送的验证请求后,根据该验证请求确定其对应的SIM卡第二签名消息、SIM卡第二身份私钥和终端第二签名消息。In this embodiment, after obtaining the verification request sent by the terminal to be verified, the server determines the corresponding SIM card second signature message, SIM card second identity private key, and terminal second signature message according to the verification request.

其中,该验证请求可以在该终端再次开机时或者再次申请入网时,由该待验证终端向服务器发送。Wherein, the verification request may be sent by the terminal to be verified to the server when the terminal is turned on again or when applying for network access again.

其中,该待验证终端的SIM卡第二签名消息、SIM卡第二身份私钥和终端第二签名消息可以为服务器从该验证请求中获取。Wherein, the second signature message of the SIM card of the terminal to be verified, the second identity private key of the SIM card, and the second signature message of the terminal may be acquired by the server from the verification request.

或者,该SIM卡第二签名消息、SIM卡第二身份私钥和终端第二签名消息还可以为服务器从内存中获取。此时,该验证请求中包括待验证SIM卡的SIM卡特征编码和待验证终端的终端特征编码。服务器根据该SIM卡特征编码和终端特征编码直接从服务器的内存中获取。Alternatively, the second signature message of the SIM card, the second identity private key of the SIM card, and the second signature message of the terminal may also be acquired by the server from memory. At this time, the verification request includes the SIM card feature code of the SIM card to be verified and the terminal feature code of the terminal to be verified. The server obtains directly from the memory of the server according to the SIM card feature code and the terminal feature code.

或者,该SIM卡第二签名消息、SIM卡第二身份私钥和终端第二签名消息还可以为服务器根据待验证SIM卡的SIM卡特征编码和SIM卡信息以及待验证终端的终端特征编码和终端信息生成。其中,该生成过程与图2实施例中的步骤S101实现方式类似,本实施例此处不再赘述。Or, the second signature message of the SIM card, the second identity private key of the SIM card, and the second signature message of the terminal can also be used by the server according to the SIM card feature code and SIM card information of the SIM card to be verified and the terminal feature code and the terminal feature code of the terminal to be verified. Generate terminal information. Wherein, the generation process is similar to the implementation of step S101 in the embodiment of FIG. 2 , and will not be repeated here in this embodiment.

S312、将待验证SIM卡的SIM卡数字签名、SIM卡第二签名消息和终端第二签名消息上报终端区块链,SIM卡数字签名通过SIM卡第二身份私钥对SIM卡第二签名消息进行数字签名得到。S312. Report the SIM card digital signature of the SIM card to be verified, the second SIM card signature message and the terminal second signature message to the terminal block chain, and the SIM card digital signature uses the SIM card second identity private key to the SIM card second signature message Get digitally signed.

本实施例中,服务器在获取SIM卡第二身份私钥和SIM卡第二签名消息后,使用SIM卡第二身份私钥对SIM卡第二签名消息进行数字签名,得到SIM卡数字签名。服务器将该SIM卡数字签名、SIM卡第二签名消息和终端第二签名消息一起上报到终端区块链。In this embodiment, after obtaining the private key of the second identity of the SIM card and the second signature message of the SIM card, the server uses the private key of the second identity of the SIM card to digitally sign the second signature message of the SIM card to obtain the digital signature of the SIM card. The server reports the digital signature of the SIM card, the second signature message of the SIM card and the second signature message of the terminal to the terminal block chain together.

S313、将所有终端区块链的数据块标识与终端第二签名消息进行匹配,确定待验证终端的终端区块。S313. Match the data block identifiers of all terminal block chains with the second signature message of the terminal to determine the terminal block of the terminal to be verified.

本实施例中,区块链根据服务器上报的终端第二签名消息,在终端区块链中匹配与之对应的待验证终端的终端区块。具体的,服务器获取该终端区块链中每一终端区块的数据块标识。服务器通过匹配该数据块标识与终端第二签名消息,确定该终端区块链中与数据块标识与终端第二签名消息相同的终端区块。服务器确定该终端区块为待验证终端的终端区块。In this embodiment, the block chain matches the corresponding terminal block of the terminal to be verified in the terminal block chain according to the second signature message of the terminal reported by the server. Specifically, the server obtains the data block identifier of each terminal block in the terminal blockchain. By matching the data block identifier and the terminal second signature message, the server determines the terminal block in the terminal block chain that is identical to the data block identifier and the terminal second signature message. The server determines that the terminal block is the terminal block of the terminal to be verified.

S314、根据待验证终端的终端区块中的SIM卡第一身份公钥和SIM卡第二签名消息验证SIM卡数字签名,并确定验证结果。S314. Verify the digital signature of the SIM card according to the first identity public key of the SIM card and the second signature message of the SIM card in the terminal block of the terminal to be verified, and determine the verification result.

本实施例中,服务器在确定该待验证终端的终端区块后,获取该终端区块的数据块数据。该数据块数据为该待验证的终端的原始匹配SIM卡的SIM卡第一身份公钥。服务器根据原始匹配SIM卡的SIM卡第一身份公钥和SIM卡第二签名消息,对SIM卡数字签名进行验证。如果验证成功则说明待验证SIM卡与该原始匹配SIM卡为同一SIM卡。如果验证失败则说明待验证SIM卡与该原始匹配SIM卡为不同SIM卡。In this embodiment, after determining the terminal block of the terminal to be verified, the server obtains the data block data of the terminal block. The data block data is the first identity public key of the SIM card that originally matches the SIM card of the terminal to be verified. The server verifies the digital signature of the SIM card according to the first public key of the SIM card identity and the second signature message of the SIM card originally matched with the SIM card. If the verification is successful, it means that the SIM card to be verified and the original matching SIM card are the same SIM card. If the verification fails, it means that the SIM card to be verified is different from the original matched SIM card.

S315、根据验证结果,判断是否出现机卡分离。S315. According to the verification result, it is judged whether the machine-card separation occurs.

本实施例中,服务器获取S307或者S308确定的验证结果。服务器根据该验证结果,确定该待验证SIM卡与该待验证终端是否为原始匹配的SIM卡与终端。如果该待验证SIM卡与该待验证终端为原始匹配的SIM卡与终端,则未出现机卡分离。如果该待验证SIM卡与该待验证终端与原始匹配的SIM卡与终端不一致,则出现机卡分离。In this embodiment, the server acquires the verification result determined in S307 or S308. The server determines whether the SIM card to be verified and the terminal to be verified are the original matching SIM card and terminal according to the verification result. If the SIM card to be verified and the terminal to be verified are the original matching SIM card and terminal, there is no machine-card separation. If the SIM card to be verified and the terminal to be verified are not consistent with the original matching SIM card and terminal, the device-card separation occurs.

S316、当机卡分离时,对待验证终端或者待验证SIM卡进行限制入网。S316. When the device card is separated, restrict network access of the terminal to be verified or the SIM card to be verified.

本实施例中,当出现机卡分离情况时,服务器对待验证终端或者待验证SIM卡进行限制入网,以确保机卡绑定的有效性。In this embodiment, when the device-card separation occurs, the server restricts the terminal to be verified or the SIM card to be verified from accessing the network, so as to ensure the validity of the device-card binding.

本申请提供的基于区块链的机卡绑定方法,服务器通过将SIM卡与终端的绑定信息分别保存到SIM卡区块链和终端区块链,实现SIM卡和终端的双向绑定。同时,服务器通过验证待验证SIM的绑定终端与待验证终端是否一致,以及待验证终端的绑定SIM卡是否与待验证SIM卡一致,确定是否出现机卡分离。当服务器确定出现机卡分离时,服务器对该待验证终端或者待验证SIM卡进行限制入网。本申请中,通过对待验证终端或者待验证SIM卡进行双向验证,确保了SIM卡与终端绑定的唯一性,提高了绑定的可靠性,并且在要求SIM卡与终端唯一绑定的场景下,实现了机卡绑定的有效性。In the block chain-based machine-card binding method provided by this application, the server realizes the two-way binding between the SIM card and the terminal by saving the binding information of the SIM card and the terminal to the SIM card block chain and the terminal block chain respectively. At the same time, the server determines whether the machine-card separation occurs by verifying whether the bound terminal of the SIM to be verified is consistent with the terminal to be verified, and whether the bound SIM card of the terminal to be verified is consistent with the SIM card to be verified. When the server determines that the device-card separation occurs, the server restricts the terminal to be verified or the SIM card to be verified from accessing the network. In this application, through two-way verification of the terminal to be verified or the SIM card to be verified, the uniqueness of the binding between the SIM card and the terminal is ensured, the reliability of the binding is improved, and in the scenario where the unique binding between the SIM card and the terminal is required , realizing the effectiveness of machine-card binding.

在上述实施例的基础上,需要说明的是,本申请使用的基于数字签名机制的机卡绑定方法不仅限于生成SIM卡区块和终端区块,并将之存储到对应的区块链中。该机卡绑定方法还可以生成SIM卡数据表和终端数据表,并将该数据表存储到对应的大数据表中,或者存储到对应的数据库中。On the basis of the above embodiments, it should be noted that the machine-card binding method based on the digital signature mechanism used in this application is not limited to generating SIM card blocks and terminal blocks, and storing them in the corresponding block chain . The machine-card binding method can also generate a SIM card data table and a terminal data table, and store the data table in a corresponding large data table or in a corresponding database.

图8示出了本申请一实施例提供的一种基于区块链的机卡绑定装置的结构示意图,如图8所示,本实施例的基于区块链的机卡绑定装置10用于实现上述任一方法实施例中对应于服务器的操作,本实施例的基于区块链的机卡绑定装置400还包括:Fig. 8 shows a schematic structural diagram of a blockchain-based machine-card binding device provided by an embodiment of the present application. As shown in Fig. 8, the blockchain-based machine-card binding device 10 of this embodiment uses In order to realize the operation corresponding to the server in any of the above method embodiments, the blockchain-based machine-card binding device 400 of this embodiment also includes:

第一获取模块401,用于获取SIM卡第一签名消息和终端第一身份公钥。The first acquiring module 401 is configured to acquire the first signature message of the SIM card and the first identity public key of the terminal.

第一生成模块402,用于根据SIM卡第一签名消息和终端第一身份公钥,生成SIM卡新区块,SIM卡新区块包括数据块标识和数据块数据,SIM卡第一签名消息为数据块标识,终端第一身份公钥为数据块数据。The first generation module 402 is used to generate a new block of the SIM card according to the first signature message of the SIM card and the first identity public key of the terminal, the new block of the SIM card includes a data block identifier and data block data, and the first signature message of the SIM card is data The block identifier, the terminal first identity public key is the data block data.

第一插入模块403,用于将SIM卡新区块插入SIM卡区块链中。The first insertion module 403 is configured to insert the new block of the SIM card into the block chain of the SIM card.

一种示例中,SIM卡数据的生成过程可以包括:根据SIM卡特征编码,生成SIM卡第一身份私钥和SIM卡第一身份公钥。根据SIM卡信息和第一预设哈希算法,生成SIM卡第一签名消息,SIM卡第一签名消息为SIM卡信息通过第一预设哈希算法加密得到。In an example, the generating process of the SIM card data may include: generating the private key of the first identity of the SIM card and the public key of the first identity of the SIM card according to the characteristic code of the SIM card. According to the SIM card information and the first preset hash algorithm, a first signature message of the SIM card is generated, and the first signature message of the SIM card is obtained by encrypting the SIM card information through the first preset hash algorithm.

另一种示例中,终端数据的生成过程可以包括:根据终端特征编码,生成终端第一身份私钥和终端第一身份公钥。根据终端信息和第二预设哈希算法,生成终端第一签名消息,终端第一签名消息为终端信息通过第二预设哈希算法加密得到。In another example, the generating process of the terminal data may include: generating the terminal first identity private key and the terminal first identity public key according to the terminal characteristic code. According to the terminal information and the second preset hash algorithm, a first terminal signature message is generated, and the terminal first signature message is obtained by encrypting the terminal information through the second preset hash algorithm.

本申请实施例提供的基于区块链的机卡绑定装置10,可执行上述方法实施例,其具体实现原理和技术效果,可参见上述方法实施例,本实施例此处不再赘述。The block chain-based machine-card binding device 10 provided in the embodiment of the present application can execute the above-mentioned method embodiment. For its specific implementation principles and technical effects, please refer to the above-mentioned method embodiment, and this embodiment will not repeat it here.

图9示出了本申请一实施例提供的另一种基于区块链的机卡绑定装置的结构示意图,如图9所示,本实施例的基于区块链的机卡绑定装置10用于实现上述任一方法实施例中对应于服务器的操作,本实施例的基于区块链的机卡绑定装置10还包括:Fig. 9 shows a schematic structural diagram of another blockchain-based machine-card binding device provided by an embodiment of the present application. As shown in Fig. 9, the blockchain-based machine-card binding device 10 of this embodiment To implement the operation corresponding to the server in any of the above method embodiments, the blockchain-based machine-card binding device 10 of this embodiment also includes:

第二获取模块404,用于获取终端第一签名消息和SIM卡第一身份公钥。The second acquiring module 404 is configured to acquire the first signed message of the terminal and the first identity public key of the SIM card.

第二生成模块405,用于根据终端第一签名消息和SIM卡第一身份公钥,生成终端新区块,终端新区块包括数据块标识和数据块数据,终端第一签名消息为数据块标识,SIM卡第一身份公钥为数据块数据。The second generation module 405 is used to generate a new terminal block according to the first signature message of the terminal and the first identity public key of the SIM card, the new block of the terminal includes a data block identifier and data block data, and the first signature message of the terminal is a data block identifier, The first identity public key of the SIM card is data block data.

第二插入模块406,用于将终端新区块插入终端区块链中。The second insertion module 406 is used for inserting the terminal new block into the terminal block chain.

第三获取模块407,用于获取待验证SIM卡的SIM卡第二签名消息、待验证终端的终端第二身份私钥和终端第二签名消息,SIM卡第二签名消息为待验证SIM卡的SIM卡信息通过第一预设哈希算法加密得到,终端第二签名消息为待验证终端的终端信息通过第二预设哈希算法加密得到,终端第二身份私钥根据待验证终端的终端特征编码生成。The third obtaining module 407 is used to obtain the SIM card second signature message of the SIM card to be verified, the terminal second identity private key of the terminal to be verified and the terminal second signature message, the second signature message of the SIM card is the SIM card to be verified The SIM card information is obtained by encrypting the first preset hash algorithm, the second signature message of the terminal is obtained by encrypting the terminal information of the terminal to be verified by the second preset hash algorithm, and the second identity private key of the terminal is obtained according to the terminal characteristics of the terminal to be verified code generation.

第一上报模块408,用于将待验证终端的终端数字签名、终端第二签名消息和SIM卡第二签名消息上报SIM卡区块链,终端数字签名通过终端第二身份私钥对终端第二签名消息进行数字签名得到。The first reporting module 408 is used to report the terminal digital signature of the terminal to be verified, the terminal second signature message, and the SIM card second signature message to the SIM card block chain, and the terminal digital signature is used for the terminal second identity through the terminal second identity private key. The signed message is digitally signed.

第一确定模块409,用于将所有SIM卡区块链的数据块标识与SIM卡第二签名消息进行匹配,确定待验证SIM卡的SIM卡区块。The first determining module 409 is configured to match the data block identifiers of all SIM card block chains with the second signature message of the SIM card, and determine the SIM card block of the SIM card to be verified.

第一验证模块410,用于根据待验证SIM卡的SIM卡区块中的终端第一身份公钥和终端第二签名消息验证终端数字签名,并确定验证结果。The first verification module 410 is configured to verify the digital signature of the terminal according to the terminal's first identity public key in the SIM card block of the SIM card to be verified and the terminal's second signature message, and determine the verification result.

第四获取模块411,用于获取待验证SIM卡的SIM卡第二签名消息、SIM卡第二身份私钥和待验证终端的终端第二签名消息,SIM卡第二签名消息为待验证SIM卡的SIM卡信息通过第一预设哈希算法加密得到,SIM卡第二身份私钥根据待验证终端的终端特征编码生成,终端第二签名消息为终端信息通过第二预设哈希算法加密得到。The fourth obtaining module 411 is used to obtain the second signature message of the SIM card of the SIM card to be verified, the second identity private key of the SIM card and the second signature message of the terminal of the terminal to be verified, and the second signature message of the SIM card is the SIM card to be verified The SIM card information is encrypted by the first preset hash algorithm, the second identity private key of the SIM card is generated according to the terminal feature code of the terminal to be verified, and the second signature message of the terminal is obtained by encrypting the terminal information by the second preset hash algorithm .

第二上报模块412,用于将待验证SIM卡的SIM卡数字签名、SIM卡第二签名消息和终端第二签名消息上报终端区块链,SIM卡数字签名通过SIM卡第二身份私钥对SIM卡第二签名消息进行数字签名得到。The second reporting module 412 is used to report the SIM card digital signature of the SIM card to be verified, the second signature message of the SIM card and the second signature message of the terminal to the terminal block chain, and the digital signature of the SIM card passes through the second identity private key pair of the SIM card The second signature message of the SIM card is obtained by performing a digital signature.

第二确定模块413,用于将所有终端区块链的数据块标识与终端第二签名消息进行匹配,确定待验证终端的终端区块。The second determining module 413 is configured to match the data block identifiers of all terminal block chains with the second signature message of the terminal, and determine the terminal block of the terminal to be verified.

第二验证模块414,用于根据待验证终端的终端区块中的SIM卡第一身份公钥和SIM卡第二签名消息验证SIM卡数字签名,并确定验证结果。The second verification module 414 is configured to verify the digital signature of the SIM card according to the first identity public key of the SIM card and the second signature message of the SIM card in the terminal block of the terminal to be verified, and determine the verification result.

判断模块415,用于根据验证结果,判断是否出现机卡分离。The judging module 415 is configured to judge whether the machine-card separation occurs according to the verification result.

限制模块416,用于当机卡分离时,对待验证终端或者待验证SIM卡进行限制入网。The restriction module 416 is configured to restrict network access of the terminal to be verified or the SIM card to be verified when the device card is separated.

本申请实施例提供的基于区块链的机卡绑定装置10,可执行上述方法实施例,其具体实现原理和技术效果,可参见上述方法实施例,本实施例此处不再赘述。The block chain-based machine-card binding device 10 provided in the embodiment of the present application can execute the above-mentioned method embodiment. For its specific implementation principles and technical effects, please refer to the above-mentioned method embodiment, and this embodiment will not repeat it here.

图10示出了本申请实施例提供的一种基于区块链的机卡绑定系统的结构示意图。如图10所示,该基于区块链的机卡绑定系统20,用于实现上述基于区块链的机卡绑定方法,本实施例的基于区块链的机卡绑定系统20可以包括:注册单元21、验证单元22和执行单元23。Fig. 10 shows a schematic structural diagram of a blockchain-based machine-card binding system provided by an embodiment of the present application. As shown in FIG. 10 , the blockchain-based machine-card binding system 20 is used to implement the above-mentioned blockchain-based machine-card binding method, and the blockchain-based machine-card binding system 20 of this embodiment can It includes: a registration unit 21 , a verification unit 22 and an execution unit 23 .

注册单元21,用于在终端第一次开机或者SIM卡第一绑定时,生成SIM卡区块或者终端区块。其中,SIM卡区块以SIM卡第一签名消息为数据块标识,以终端第一身份公钥为数据块数据。其中,终端区块以终端第一签名消息为数据块标识,SIM卡第一身份公钥为数据块数据。服务器将SIM卡区块插入SIM卡区块链,将终端区块插入终端区块链。The registration unit 21 is configured to generate a SIM card block or a terminal block when the terminal is turned on for the first time or the SIM card is bound for the first time. Wherein, the SIM card block uses the first signature message of the SIM card as the data block identifier, and uses the terminal first identity public key as the data block data. Wherein, the terminal block uses the terminal's first signature message as the data block identifier, and the SIM card's first identity public key is the data block data. The server inserts the SIM block into the SIM blockchain and the terminal block into the terminal blockchain.

验证单元22,用于在终端再次开机或者再次请求入网时,向服务器发送该待验证终端及插入该待验证终端的待验证SIM卡是否匹配。服务器根据SIM卡第二签名消息,在SIM卡区块链中检索数据块标识与SIM卡第二签名消息相同的区块,并确定该SIM卡区块为待验证SIM卡对应的SIM卡区块。服务器获取该SIM卡区块中的终端第一身份公钥,并结合上报的终端第二签名消息对终端数字签名进行验证。服务器还可以根据中断第二签名消息,在终端区块链中检索数据块标识与该终端第二签名消息相同的区块,并确定该终端区块为待验证终端的终端区块。服务器获取该终端区块中的SIM卡第一身份公钥,并结合上报的SIM卡第二签名消息对SIM卡数字签名进行验证。验证单元将该验证结果发送到执行单元。The verification unit 22 is configured to send the terminal to be verified and whether the SIM card to be verified inserted into the terminal to be verified matches to the server when the terminal is powered on again or requests network access again. According to the second signature message of the SIM card, the server retrieves the same block of the data block identification and the second signature message of the SIM card in the SIM card block chain, and determines that the SIM card block is the SIM card block corresponding to the SIM card to be verified . The server acquires the terminal's first identity public key in the SIM card block, and verifies the terminal's digital signature in combination with the reported terminal's second signature message. The server can also retrieve the block whose data block identifier is the same as the terminal's second signature message in the terminal block chain according to the interrupted second signature message, and determine that the terminal block is the terminal block of the terminal to be verified. The server acquires the first identity public key of the SIM card in the terminal block, and verifies the digital signature of the SIM card in combination with the reported second signature message of the SIM card. The verification unit sends the verification result to the execution unit.

执行单元23,当该待验证终端与待验证SIM卡出现机卡分离时,服务器对该待验证终端或者该待验证SIM卡执行限制入网操作。Executing unit 23, when the terminal to be verified is separated from the SIM card to be verified, the server performs a network access restriction operation on the terminal to be verified or the SIM card to be verified.

单元可以集成在一起,也可以分开在不同的设备中。例如,注册单元21、验证单元22和执行单元23均为服务器中的功能单元。或者,注册单元21、验证单元22集成于服务器,执行单元23为网络设备中的单元,网络设备例如路由器。Units can be integrated together or separated in different devices. For example, the registration unit 21, the verification unit 22 and the execution unit 23 are all functional units in the server. Alternatively, the registration unit 21 and the verification unit 22 are integrated in the server, and the execution unit 23 is a unit in a network device, such as a router.

本申请实施例提供的基于区块链的机卡绑定装置10,可执行上述方法实施例,其具体实现原理和技术效果,可参见上述方法实施例,本实施例此处不再赘述。The block chain-based machine-card binding device 10 provided in the embodiment of the present application can execute the above-mentioned method embodiment. For its specific implementation principles and technical effects, please refer to the above-mentioned method embodiment, and this embodiment will not repeat it here.

图11示出了本申请实施例提供的一种服务器的硬件结构示意图。如图11所示,该服务器30,用于实现上述任一方法实施例中对应于服务器的操作,本实施例的服务器30可以包括:存储器31,处理器32。FIG. 11 shows a schematic diagram of a hardware structure of a server provided by an embodiment of the present application. As shown in FIG. 11 , the server 30 is configured to implement operations corresponding to the server in any of the above method embodiments, and the server 30 in this embodiment may include: a memory 31 and a processor 32 .

存储器31,用于存储计算机程序。该存储器31可能包含高速随机存取存储器(Random Access Memory,RAM),也可能还包括非易失性存储(Non-Volatile Memory,NVM),例如至少一个磁盘存储器,还可以为U盘、移动硬盘、只读存储器、磁盘或光盘等。The memory 31 is used for storing computer programs. The memory 31 may include a high-speed random access memory (Random Access Memory, RAM), and may also include a non-volatile storage (Non-Volatile Memory, NVM), such as at least one disk storage, and may also be a U disk or a mobile hard disk. , read-only memory, disk or CD-ROM, etc.

处理器32用于根据存储器存储的计算机程,以实现上述实施例中的基于区块链的机卡绑定方法。具体可以参见前述方法实施例中的相关描述。The processor 32 is used to implement the block chain-based machine-card binding method in the above-mentioned embodiment according to the computer program stored in the memory. For details, refer to the related descriptions in the foregoing method embodiments.

可选地,存储器31既可以是独立的,也可以跟处理器32集成在一起。Optionally, the memory 31 can be independent or integrated with the processor 32 .

当存储器31是独立于处理器32之外的器件时,服务器30还可以包括:When the memory 31 is a device independent of the processor 32, the server 30 may also include:

总线33,用于连接存储器31和处理器32。其中,总线33可以是工业标准体系结构(Industry Standard Architecture,ISA)总线、外部设备互连(Peripheral ComponentInterconnect,PCI)总线或扩展工业标准体系结构(Extended Industry StandardArchitecture,EISA)总线等。总线可以分为地址总线、数据总线、控制总线等。为便于表示,本申请附图中的总线并不限定仅有一根总线或一种类型的总线。The bus 33 is used to connect the memory 31 and the processor 32 . Wherein, the bus 33 may be an Industry Standard Architecture (Industry Standard Architecture, ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (Extended Industry Standard Architecture, EISA) bus, etc. The bus can be divided into address bus, data bus, control bus and so on. For ease of representation, the buses in the drawings of the present application are not limited to only one bus or one type of bus.

可选的,该服务器30还可以包括通信接口34。该通信接口34可以通过总线33与处理器32连接。处理器32可以控制通信接口34来实现服务器30与终端的信息交互。Optionally, the server 30 may also include a communication interface 34 . The communication interface 34 can be connected with the processor 32 through the bus 33 . The processor 32 can control the communication interface 34 to implement information interaction between the server 30 and the terminal.

本实施例提供的服务器可用于执行上述的基于区块链的机卡绑定方法,其实现方式和技术效果类似,本实施例此处不再赘述。The server provided in this embodiment can be used to execute the above-mentioned block chain-based machine-card binding method, and its implementation method and technical effect are similar, so this embodiment will not repeat them here.

本申请还提供一种计算机可读存储介质,计算机可读存储介质中存储有计算机程序,计算机程序被处理器执行时用于实现上述的各种实施方式提供的方法。The present application also provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, the computer program is used to implement the methods provided by the above-mentioned various implementations.

本申请还提供一种程序产品,该程序产品包括执行指令,该执行指令存储在计算机可读存储介质中。设备的至少一个处理器可以从计算机可读存储介质读取该执行指令,至少一个处理器执行该执行指令使得设备实施上述的各种实施方式提供的方法。The present application also provides a program product, the program product includes execution instructions, and the execution instructions are stored in a computer-readable storage medium. At least one processor of the device may read the execution instruction from the computer-readable storage medium, and the at least one processor executes the execution instruction so that the device implements the methods provided in the foregoing various implementations.

在本申请所提供的几个实施例中,应该理解到,所揭露的装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅是示意性的,例如,模块的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个模块可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或模块的间接耦合或通信连接,可以是电性,机械或其它的形式。In the several embodiments provided in this application, it should be understood that the disclosed devices and methods may be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules can be combined or integrated into another A system, or some feature, can be ignored, or not implemented. In another point, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of devices or modules may be in electrical, mechanical or other forms.

作为分离部件说明的模块可以是或者也可以不是物理上分开的,作为模块显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的。A module described as a separate component may or may not be physically separated, and a component shown as a module may or may not be a physical unit, that is, it may be located in one place, or may also be distributed to multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

另外,在本申请各个实施例中的各功能模块可以集成在一个处理单元中,也可以是各个模块单独物理存在,也可以两个或两个以上模块集成在一个单元中。上述模块成的单元既可以采用硬件的形式实现,也可以采用硬件加软件功能单元的形式实现。In addition, each functional module in each embodiment of the present application may be integrated into one processing unit, each module may exist separately physically, or two or more modules may be integrated into one unit. The units formed by the above modules can be implemented in the form of hardware, or in the form of hardware plus software functional units.

上述以软件功能模块的形式实现的集成的模块,可以存储在一个计算机可读取存储介质中。上述软件功能模块存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)或处理器执行本申请各个实施例方法的部分步骤。The above-mentioned integrated modules implemented in the form of software function modules can be stored in a computer-readable storage medium. The above-mentioned software function modules are stored in a storage medium, and include several instructions to enable a computer device (which may be a personal computer, server, or network device, etc.) or a processor to execute some steps of the methods in various embodiments of the present application.

本领域普通技术人员可以理解:实现上述各方法实施例的全部或部分步骤可以通过程序指令相关的硬件来完成。前述的程序可以存储于一计算机可读取存储介质中。该程序在执行时,执行包括上述各方法实施例的步骤。而前述的存储介质包括:ROM、RAM、磁碟或者光盘等各种可以存储程序代码的介质。Those of ordinary skill in the art can understand that all or part of the steps for implementing the above method embodiments can be completed by program instructions and related hardware. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps including the above-mentioned method embodiments are executed. The aforementioned storage medium includes various media capable of storing program codes such as ROM, RAM, magnetic disk or optical disk.

最后应说明的是:以上各实施例仅用以说明本申请的技术方案,而非对其限制。尽管参照前述各实施例对本申请进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分或者全部技术特征进行等同替换。而这些修改或者替换,并不使相应技术方案的本质脱离本申请各实施例技术方案的范围。Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present application, rather than to limit it. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features . However, these modifications or replacements do not make the essence of the corresponding technical solutions depart from the scope of the technical solutions of the embodiments of the present application.

Claims (9)

1.一种基于区块链的机卡绑定方法,其特征在于,所述方法,包括:1. A block chain-based machine-card binding method, characterized in that, the method includes: 获取SIM卡第一签名消息和终端第一身份公钥;Obtain the first signature message of the SIM card and the first identity public key of the terminal; 根据所述SIM卡第一签名消息和所述终端第一身份公钥,生成SIM卡新区块,所述SIM卡新区块包括数据块标识和数据块数据,所述SIM卡第一签名消息为所述数据块标识,所述终端第一身份公钥为所述数据块数据;According to the first signature message of the SIM card and the first identity public key of the terminal, a new block of the SIM card is generated, the new block of the SIM card includes a data block identifier and data block data, and the first signature message of the SIM card is the The data block identifier, the terminal first identity public key is the data block data; 将所述SIM卡新区块插入SIM卡区块链中;Insert the new block of the SIM card into the SIM card block chain; 完成机卡绑定后,所述方法,还包括:After the machine-card binding is completed, the method further includes: 获取待验证SIM卡的SIM卡第二签名消息、待验证终端的终端第二身份私钥和终端第二签名消息,所述SIM卡第二签名消息为所述待验证SIM卡的SIM卡信息通过第一预设哈希算法加密得到,所述终端第二签名消息为所述待验证终端的终端信息通过第二预设哈希算法加密得到,所述终端第二身份私钥根据所述待验证终端的终端特征编码生成;Obtain the SIM card second signature message of the SIM card to be verified, the terminal second identity private key of the terminal to be verified, and the terminal second signature message, the second SIM card signature message is the SIM card information of the SIM card to be verified through The second signature message of the terminal is obtained by encrypting the terminal information of the terminal to be verified through the second preset hash algorithm, and the second identity private key of the terminal is obtained according to the Terminal characteristic code generation of the terminal; 将所述待验证终端的终端数字签名、所述终端第二签名消息和所述SIM卡第二签名消息上报SIM卡区块链,所述终端数字签名通过所述终端第二身份私钥对所述终端第二签名消息进行数字签名得到;Report the terminal digital signature of the terminal to be verified, the second signature message of the terminal and the second signature message of the SIM card to the SIM card block chain, and the digital signature of the terminal is paired with the second identity private key of the terminal. The second signature message of the terminal is digitally signed to obtain; 将所有SIM卡区块链的数据块标识与所述SIM卡第二签名消息进行匹配,确定所述待验证SIM卡的SIM卡区块;The data block identification of all SIM card block chains is matched with the second signature message of the SIM card to determine the SIM card block of the SIM card to be verified; 根据所述待验证SIM卡的所述SIM卡区块中的终端第一身份公钥和所述终端第二签名消息验证所述终端数字签名,并确定验证结果。Verifying the digital signature of the terminal according to the first identity public key of the terminal in the SIM card block of the SIM card to be verified and the second signature message of the terminal, and determining a verification result. 2.根据权利要求1所述的方法,其特征在于,所述方法,还包括:2. The method according to claim 1, characterized in that, the method further comprises: 获取终端第一签名消息和SIM卡第一身份公钥;Obtain the first signature message of the terminal and the first identity public key of the SIM card; 根据所述终端第一签名消息和所述SIM卡第一身份公钥,生成终端新区块,所述终端新区块包括数据块标识和数据块数据,所述终端第一签名消息为所述数据块标识,所述SIM卡第一身份公钥为所述数据块数据;According to the first signature message of the terminal and the first identity public key of the SIM card, a new block of the terminal is generated, the new block of the terminal includes a data block identifier and data block data, and the first signature message of the terminal is the data block Identification, the first identity public key of the SIM card is the data block data; 将所述终端新区块插入终端区块链中。Inserting said terminal new block into the terminal blockchain. 3.根据权利要求1或2所述的方法,其特征在于,所述方法,包括:3. The method according to claim 1 or 2, characterized in that, the method comprises: 根据SIM卡特征编码,生成SIM卡第一身份私钥和SIM卡第一身份公钥;Generate the private key of the first identity of the SIM card and the public key of the first identity of the SIM card according to the characteristic code of the SIM card; 根据SIM卡信息和第一预设哈希算法,生成SIM卡第一签名消息,所述SIM卡第一签名消息为所述SIM卡信息通过所述第一预设哈希算法加密得到。According to the SIM card information and the first preset hash algorithm, generate a first SIM card signature message, where the SIM card first signature message is obtained by encrypting the SIM card information through the first preset hash algorithm. 4.根据权利要求1或2所述的方法,其特征在于,所述方法,包括:4. The method according to claim 1 or 2, characterized in that, the method comprises: 根据终端特征编码,生成终端第一身份私钥和终端第一身份公钥;Generate terminal first identity private key and terminal first identity public key according to terminal characteristic code; 根据终端信息和第二预设哈希算法,生成终端第一签名消息,所述终端第一签名消息为所述终端信息通过所述第二预设哈希算法加密得到。According to the terminal information and the second preset hash algorithm, a first terminal signature message is generated, where the terminal first signature message is obtained by encrypting the terminal information through the second preset hash algorithm. 5.根据权利要求2所述的方法,其特征在于,完成机卡绑定后,所述方法,包括:5. The method according to claim 2, characterized in that, after the machine-card binding is completed, the method comprises: 获取待验证SIM卡的SIM卡第二签名消息、SIM卡第二身份私钥和待验证终端的终端第二签名消息,所述SIM卡第二签名消息为所述待验证SIM卡的SIM卡信息通过第一预设哈希算法加密得到,所述SIM卡第二身份私钥根据所述待验证终端的终端特征编码生成,所述终端第二签名消息为终端信息通过第二预设哈希算法加密得到;Obtain the second signature message of the SIM card of the SIM card to be verified, the second identity private key of the SIM card and the second signature message of the terminal of the terminal to be verified, and the second signature message of the SIM card is the SIM card information of the SIM card to be verified Encrypted by the first preset hash algorithm, the second identity private key of the SIM card is generated according to the terminal feature code of the terminal to be verified, and the second signature message of the terminal is terminal information through the second preset hash algorithm Encrypted to get; 将待验证SIM卡的SIM卡数字签名、所述SIM卡第二签名消息和所述终端第二签名消息上报终端区块链,所述SIM卡数字签名通过所述SIM卡第二身份私钥对SIM卡第二签名消息进行数字签名得到;Report the SIM card digital signature of the SIM card to be verified, the second signature message of the SIM card, and the second signature message of the terminal to the terminal block chain, and the digital signature of the SIM card passes the second identity private key pair of the SIM card The second signature message of the SIM card is digitally signed to obtain; 将所有终端区块链的数据块标识与所述终端第二签名消息进行匹配,确定所述待验证终端的终端区块;Matching the data block identifiers of all terminal block chains with the second signature message of the terminal to determine the terminal block of the terminal to be verified; 根据所述待验证终端的所述终端区块中的SIM卡第一身份公钥和所述SIM卡第二签名消息验证所述SIM卡数字签名,并确定验证结果。Verifying the digital signature of the SIM card according to the first identity public key of the SIM card in the terminal block of the terminal to be verified and the second signature message of the SIM card, and determining a verification result. 6.根据权利要求1或5所述的方法,其特征在于,所述方法,还包括:6. The method according to claim 1 or 5, wherein the method further comprises: 根据所述验证结果,判断是否出现机卡分离;According to the verification result, it is judged whether machine-card separation occurs; 当所述机卡分离时,对所述待验证终端或者所述待验证SIM卡进行限制入网。When the device-card is separated, restrict network access to the terminal to be verified or the SIM card to be verified. 7.一种基于区块链的机卡绑定装置,其特征在于,所述装置,包括:7. A blockchain-based machine-card binding device, characterized in that the device includes: 第一获取模块,用于获取SIM卡第一签名消息和终端第一身份公钥;The first obtaining module is used to obtain the first signature message of the SIM card and the first identity public key of the terminal; 第一生成模块,用于根据所述SIM卡第一签名消息和所述终端第一身份公钥,生成SIM卡新区块,所述SIM卡新区块包括数据块标识和数据块数据,所述SIM卡第一签名消息为所述数据块标识,所述终端第一身份公钥为所述数据块数据;The first generation module is used to generate a new block of the SIM card according to the first signature message of the SIM card and the first identity public key of the terminal, and the new block of the SIM card includes a data block identifier and a data block data, and the SIM card The card's first signature message is the data block identifier, and the terminal's first identity public key is the data block data; 第一插入模块,用于将所述SIM卡新区块插入SIM卡区块链中;The first insertion module is used to insert the new block of the SIM card into the SIM card block chain; 第二获取模块,用于获取待验证SIM卡的SIM卡第二签名消息、待验证终端的终端第二身份私钥和终端第二签名消息,所述SIM卡第二签名消息为所述待验证SIM卡的SIM卡信息通过第一预设哈希算法加密得到,所述终端第二签名消息为所述待验证终端的终端信息通过第二预设哈希算法加密得到,所述终端第二身份私钥根据所述待验证终端的终端特征编码生成;The second obtaining module is used to obtain the SIM card second signature message of the SIM card to be verified, the terminal second identity private key of the terminal to be verified and the terminal second signature message, and the second signature message of the SIM card is the second signature message of the SIM card to be verified The SIM card information of the SIM card is obtained by encrypting through a first preset hash algorithm, and the second signature message of the terminal is obtained by encrypting the terminal information of the terminal to be verified through a second preset hash algorithm, and the second identity of the terminal The private key is generated according to the terminal feature code of the terminal to be verified; 第一上报模块,用于将所述待验证终端的终端数字签名、所述终端第二签名消息和所述SIM卡第二签名消息上报SIM卡区块链,所述终端数字签名通过所述终端第二身份私钥对所述终端第二签名消息进行数字签名得到;The first reporting module is used to report the terminal digital signature of the terminal to be verified, the terminal second signature message and the SIM card second signature message to the SIM card block chain, and the terminal digital signature is passed through the terminal The second identity private key is obtained by digitally signing the second signature message of the terminal; 第一确定模块,用于将所有SIM卡区块链的数据块标识与所述SIM卡第二签名消息进行匹配,确定所述待验证SIM卡的SIM卡区块;The first determining module is used to match the data block identifiers of all SIM card block chains with the second signature message of the SIM card, and determine the SIM card block of the SIM card to be verified; 第一验证模块,用于根据所述待验证SIM卡的所述SIM卡区块中的终端第一身份公钥和所述终端第二签名消息验证终端数字签名,并确定验证结果。The first verification module is configured to verify the digital signature of the terminal according to the terminal's first identity public key in the SIM card block of the SIM card to be verified and the terminal's second signature message, and determine a verification result. 8.一种服务器,其特征在于,所述服务器,包括:存储器,处理器,所述存储器,用于存储计算机程序,所述处理器,用于根据所述存储器存储的计算机程序 ,实现如权利要求1至6中任意一项所述的基于区块链的机卡绑定方法。8. A server, characterized in that, the server includes: a memory, a processor, the memory is used to store computer programs, and the processor is used to implement the computer program according to the claim according to the computer program stored in the memory The blockchain-based machine-card binding method described in any one of requirements 1 to 6. 9.一种计算机可读存储介质,其特征在于,所述计算机可读存储介质中存储有计算机执行指令,所述计算机执行指令被处理器执行时用于实现如权利要求1至5任一项所述的基于区块链的机卡绑定方法。9. A computer-readable storage medium, characterized in that, computer-executable instructions are stored in the computer-readable storage medium, and the computer-executable instructions are used to implement any one of claims 1 to 5 when executed by a processor The block chain-based machine-card binding method.
CN202011482006.9A 2020-12-15 2020-12-15 Machine-card binding method and server based on block chain Active CN112637855B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202011482006.9A CN112637855B (en) 2020-12-15 2020-12-15 Machine-card binding method and server based on block chain

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202011482006.9A CN112637855B (en) 2020-12-15 2020-12-15 Machine-card binding method and server based on block chain

Publications (2)

Publication Number Publication Date
CN112637855A CN112637855A (en) 2021-04-09
CN112637855B true CN112637855B (en) 2022-11-29

Family

ID=75313563

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202011482006.9A Active CN112637855B (en) 2020-12-15 2020-12-15 Machine-card binding method and server based on block chain

Country Status (1)

Country Link
CN (1) CN112637855B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113014676B (en) * 2021-04-21 2023-11-03 联通雄安产业互联网有限公司 System and method for storing data of Internet of things into blockchain based on SIM card

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111787530A (en) * 2020-08-06 2020-10-16 联通雄安产业互联网有限公司 Block chain digital identity management method based on SIM card

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104754552B (en) * 2013-12-25 2018-07-24 中国移动通信集团公司 A kind of credible performing environment TEE initial methods and equipment
CN109168156B (en) * 2018-11-01 2021-06-29 中国联合网络通信集团有限公司 A method, system, medium, computer program product and server for implementing a virtual SIM card
CN111356121B (en) * 2018-12-21 2024-01-26 西安佰才邦网络技术有限公司 Method and equipment for binding subscription data based on blockchain

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111787530A (en) * 2020-08-06 2020-10-16 联通雄安产业互联网有限公司 Block chain digital identity management method based on SIM card

Also Published As

Publication number Publication date
CN112637855A (en) 2021-04-09

Similar Documents

Publication Publication Date Title
EP3800909B1 (en) Remote management method, and device
EP3726804A2 (en) Device authentication method, service access control method, device, and non-transitory computer-readable recording medium
US11070542B2 (en) Systems and methods for certificate chain validation of secure elements
US12273721B2 (en) Method for securely connecting vehicle and Bluetooth key, and Bluetooth module and Bluetooth key
CN111262701A (en) Replay attack detection method, system, equipment and storage medium
CN110177124A (en) Identity identifying method and relevant device based on block chain
CN113872932B (en) SGX-based micro-service interface authentication method, system, terminal and storage medium
CN112632573B (en) Intelligent contract execution method, device, system, storage medium and electronic equipment
CN110856170B (en) Data transmission method, device and Internet of things communication system
CN109391473B (en) Electronic signature method, device and storage medium
CN112637855B (en) Machine-card binding method and server based on block chain
CN114040401B (en) Terminal authentication method and system
CN111970122B (en) Official APP identification method, mobile terminal and application server
CN114143198A (en) Firmware upgrading method
WO2021147433A1 (en) Mobile phone key state management method, tsm platform server, and storage medium
CN105825247B (en) A kind of card reader and data transmission method
CN115828223A (en) Operating system login method, electronic device and storage medium
CN114268466B (en) Encoding processing method, device, equipment and storage medium
WO2021102753A1 (en) Flash packet encryption method and apparatus, electronic device, and computer storage medium
CN112422292A (en) Network security protection method, system, equipment and storage medium
CN113194090A (en) Authentication method, authentication device, terminal device and computer readable storage medium
CN113497779A (en) Method and communication device for network key exchange protocol authentication using certificate
CN114650175B (en) A verification method and device
CN108737377A (en) Data guard method, server and computer readable storage medium
CN118972353A (en) A data synchronization method, device, equipment, chip and storage medium

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant