WO2019024031A1 - 一种基于cn39码认证手机号码的系统及方法 - Google Patents

一种基于cn39码认证手机号码的系统及方法 Download PDF

Info

Publication number
WO2019024031A1
WO2019024031A1 PCT/CN2017/095759 CN2017095759W WO2019024031A1 WO 2019024031 A1 WO2019024031 A1 WO 2019024031A1 CN 2017095759 W CN2017095759 W CN 2017095759W WO 2019024031 A1 WO2019024031 A1 WO 2019024031A1
Authority
WO
WIPO (PCT)
Prior art keywords
mobile phone
data
code
base station
control unit
Prior art date
Application number
PCT/CN2017/095759
Other languages
English (en)
French (fr)
Inventor
于志
Original Assignee
于志
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 于志 filed Critical 于志
Priority to PCT/CN2017/095759 priority Critical patent/WO2019024031A1/zh
Publication of WO2019024031A1 publication Critical patent/WO2019024031A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/02Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]

Definitions

  • the invention relates to the application of the commercial cryptography technology in securing the security of the mobile phone number communication, and is a digital password authentication method capable of ensuring the security of the mobile phone number communication, which can effectively block the spam message sent by the pseudo base station and intercept the scam call dialed by the rebranding software. .
  • Cryptography is one of the important means to protect network information security. Cryptography has been around since ancient times and has moved from the civil and military fields to the present. It not only has the information encryption function to ensure the confidentiality of information, but also has the functions of digital signature, identity verification, system security and so on. Therefore, the use of cryptography not only guarantees the confidentiality of the mobile number, but also ensures the integrity and determination of the mobile number. Sex, to prevent mobile phone numbers from being tampered with, forged and counterfeited.
  • the object of the present invention is to provide a method for encrypting, identifying, and authenticating a mobile phone number according to the above deficiencies of the prior art; both an explicit part and a password part are easy to dialectify for both the visitor and the interviewee; It is not easy to fake.
  • a system and method for authenticating a mobile phone number based on a CN39 code comprising:
  • Mobile phone control unit used for generating, encrypting, and storing access signals sent by the visitor's mobile phone to generate a CN39 code
  • a communication base station control unit configured to receive a signal sent by a visitor mobile phone
  • Communication base station program fragmentation processing unit for extracting CN39 from the received data packet, and dividing it into three segments, 13 segments of decimal numbers;
  • Communication base station authentication unit used for decrypting the fragment data
  • the communication base station data processing unit converts the CN39 code passed by the authentication unit into the original visitor mobile phone number and generates a token, and outputs an access signal.
  • the mobile phone control unit of the interviewee is used to receive the mobile phone signal of the visitor, decrypt the "token", and perform an incoming call or short message prompt.
  • the mobile phone control unit and the accessed mobile phone control unit are stored in the same mobile phone to complete the signal dialing and receiving.
  • a system and method for authenticating a mobile phone number based on a CN39 code comprising the following steps:
  • the visitor's mobile phone sends an access signal, that is, the mobile phone number of the interviewee.
  • the mobile phone number of the visitor is 11 digits
  • the mobile phone number of the visitor is preceded by a two-digit decimal country code, if the visitor's mobile phone
  • the mobile phone control unit adds zero to the visitor's mobile phone number, making it 11 digits. Decimal number, and then the first two digits of the mobile phone number plus the decimal country code as the first group of data;
  • the mobile phone control unit automatically generates a 13-digit decimal number that conforms to the serial number coding principle as the second group of data;
  • the mobile phone control unit acquires the first group of data and the second group of data each of which is 13 decimal digits to be processed;
  • the mobile phone control unit determines whether the second group of data conforms to the serial number coding principle, and if yes, proceeds to the next step, and if not, performs an error prompt;
  • the mobile phone control unit encrypts the first group of data and the second group of data conforming to the serial number coding principle by a commercial cryptographic algorithm to generate a 13-digit decimal verification code, that is, a third group of data, the three groups
  • the data constitutes the CN39 code
  • the mobile phone control unit sends the CN39 code and the mobile phone number of the visited party to the communication base station together;
  • the program fragment processing unit of the communication base station that is, CN39-313, extracts the 39-digit decimal number that constitutes the CN39 code from the received data packet according to the encoding rule of the CN39 code, and divides it into three segments, which are divided into three segments.
  • 13-digit decimal number that is, 52-bit binary number (52 bits), that is, three sets of data codes;
  • the program fragment processing unit of the communication base station transmits three sets of data to the authentication unit of the communication base station, and the authentication unit decrypts the three sets of data, and the decryption result is "0", and the data is transmitted to the data processing unit of the communication base station; otherwise, Do not transmit data;
  • the communication base station data processing unit converts the CN39 code after the authentication unit authentication into the original visitor mobile phone number, and generates a signal for transmitting the license, that is, "token", and then the "token” and the visitor's mobile phone number. Output an access signal to the mobile phone number of the interviewee;
  • the accessed mobile phone receives the access signal, and the mobile phone control unit of the interviewee decrypts the “token”, and returns to zero, then performs an incoming call or short message prompt, otherwise it does not prompt.
  • the system and method for authenticating a mobile phone number based on the CN39 code, and the editing of the second group of data The code principle, that is, the coding principle of the serial number is a category code with the 1-2 digits being 2 digits, wherein the mobile phone number has a category number of 00, the 3rd to 6th digits are 4 digits of the year code, and the 7th and 8th digits are 2 digits.
  • the month code of the digit, the 9th-10th digit is the 2-digit date code, the 11th-13th digit is the 3-digit serial number code of the day, and 1000 CN39 codes are provided for each mobile phone number every day, and each mobile phone sends out An access signal corresponds one by one in order. If the access requirement exceeds 1000, it is re-circulated from the beginning.
  • the system and method for authenticating a mobile phone number based on the CN39 code after receiving the three sets of data codes transmitted by the communication base station program fragment processing unit, the communication base station authentication unit decrypts the verification code by using a commercial cryptographic algorithm.
  • the first and second sets of data of 13 decimal digits can be obtained.
  • a system and method for authenticating a mobile phone number based on a CN39 code wherein the mobile phone control unit divides the first group of data, the second group of data, and the third group of data into three lines and stores the data in the first group of data, The second group data and the third group data are stored in three lines.
  • the technical advantage of the present invention is that the method for authenticating the mobile phone number has both an explicit part and a password part, which is easy to distinguish between the visitor and the interviewee; is not easy to tamper, is not easy to counterfeit, has high security, and can be completely shielded. The transmission of irrelevant information.
  • the invention adds a serial number code and a verification code on the basis of the user's mobile phone number.
  • the serial number code uniquely identifies the second set of data, expanding the number of mobile phones available to the user from one to 1,000.
  • the verification code is generated by the first group of data and the second group of data, and is encrypted by a commercial cryptographic algorithm. After the cryptographic algorithm encrypts and obtains the verification code, the first group of data and the second group of data can be obtained by the commercial cryptographic algorithm to obtain the verification.
  • the CN39 code can identify each outgoing access signal in the world. The probability that the CN39 code is guessed is one in ten trillion, so the probability that the user's mobile phone number has been tampered and counterfeited is also one in ten trillion.
  • Figure 1 is a schematic diagram of the CN39 code
  • FIG. 2 is a schematic block diagram showing a flow of generating a CN39 code
  • Figure 3 is a schematic block diagram of the authentication process of the CN39 code
  • Figure 5 is a schematic block diagram of the data flow of the CN39 code
  • Figure 6 is a schematic diagram of program fragmentation
  • FIG. 7 is a schematic diagram of the authentication unit
  • Figure 8 is a system architecture diagram
  • Figure 9 is a schematic diagram of "token"
  • the verification code is a 13-bit decimal number generated by encrypting the first set of data and the second set of data by a commercial cryptographic algorithm, which is unique and random.
  • the above three groups of data are divided, middle and upper to obtain the CN39 code.
  • the CN39 code identifies the access signal sent by the mobile phone number in the world, and can be verified and verified by the commercial cryptographic algorithm to identify and protect the mobile phone. The purpose of number communication security.
  • CN39 code 0-9 ten digits are used as the data carrier of the CN39 code, and the CN39 code is divided into three lines for identification and authentication of the mobile phone number.
  • the CN39 code manufactured according to the above steps has the following advantages:
  • the CN39 code is composed of two sets of plaintext and a set of ciphertext.
  • the security reliability of the CN39 code is based on the confidentiality and secret key of the cryptographic algorithm. Therefore, the disclosure of ciphertext does not affect the security of the cryptographic algorithm. The possibility of deciphering the cryptographic algorithm is considered to be absent here.
  • the CN39 code consists of 39 decimal digits, and its variation is 10 39 ; the CN39 code consists of three sets of 13-digit decimal numbers, of which the first group and the second group are plaintext, and the third group is the verification code, that is, the ciphertext. . Therefore, the probability that the CN39 code is guessed is one in ten trillion, which is obviously a small probability event, and even if the guess is successful, it will not pose a threat to the CN39 code corresponding to other access signals of the user.
  • the CN39 code becomes a reality for establishing a third-party authentication; the communication base station authentication unit has a cryptographic algorithm and a key, transmits a CN39 code to the communication base station authentication unit, and verifies the authenticity by the communication base station authentication unit, and if the verification passes, the information is transmitted, otherwise give up.
  • the communication base station authentication unit monitors the mobile phone number of the visitor in real time. If an IP continues to send a large number of CN39 codes, even if the authentication is passed, the communication base station authentication unit blocks the mobile phone number and blocks the transmission of the information.
  • the security of the CN39 code lies in the fact that there are both plain text and ciphertext, and the probability of being guessed is one in ten trillion.
  • a basic principle of information secrecy is that the details of the public algorithm do not fundamentally affect the security of the algorithm, that is, the security depends on the key. In this scheme, even if the ciphertext is disclosed, the security of the CN39 code will not be affected. .
  • CN39 code is applied to user mobile internet security management, providing a digital platform that meets international standards for users to digitally manage network information.
  • the CN39 code is in one-to-one correspondence with the user.
  • the communication base station authentication unit helps the user to filter out malicious harassment calls and short messages, thereby ensuring the security of the user's personal information and reducing unnecessary losses.
  • the mobile phone control unit collects the user's mobile phone number, serial number coded data, and initializes the database.
  • the database data is encrypted by a commercial cryptographic algorithm, and a 13-digit decimal number verification code is generated and stored in the corresponding three sets of data code databases.
  • the above three sets of data are stored in the order of upper, middle and lower, that is, "CN39 code”.
  • the communication base station authentication unit has functions of encryption, decryption, encoding, decoding, network transmission, data query, data comparison, etc., and has a mobile phone number database, a CN39 code database, a commercial password database, etc., and a commercial password database for managing keys and commercial A cryptographic algorithm that ensures the security of keys and algorithms.
  • the communication base station program fragment processing unit performs program fragmentation processing on the received CN39 code, divides it into three groups of data codes, and transmits the data to the communication base station authentication unit, and the authentication unit decrypts it by using a commercial cryptographic algorithm to verify the legality of the CN39 code.
  • the communication base station data processing unit converts the CN39 code after the communication base station authentication unit authentication into the original visitor mobile phone number, and generates a transmission permission signal, that is, a "token", and then the "token" and the visitor mobile phone number are The visitor's mobile phone number outputs an access signal.
  • CN39 code used to authenticate mobile phone numbers can be divided into:
  • the CN39 code is composed of the first group data, the second group data and the verification code of the user, and is composed of upper, middle and lower groups of codes.
  • the mobile phone control unit collects the user's mobile phone number, serial number code, and initializes the database.
  • Reading code The CN39 code is transmitted to the communication base station via the mobile network.
  • the communication base station program fragmentation processing unit decodes the CN39 code into three sets of 13-bit decimal numbers. Store the verification code in the password database.
  • the communication base station authentication unit decrypts the verification code by using a commercial cryptographic algorithm, and generates two sets of 13-digit decimal numbers, that is, digital authentication clear codes.
  • the communication base station authentication unit compares the digital authentication clear code with the first group data and the serial number of the user in the initial database.
  • the mobile phone control unit collects the mobile phone number and serial number code of the user, generates two sets of 13-digit decimal data, generates a set of 13-digit decimal data by encryption, and stores the three sets of data into the CN39 code database.
  • the CN39 code is transmitted to the communication base station program fragment processing unit, and performs program fragmentation processing, and is divided into three groups of data codes and then transmitted to the communication base station authentication unit, and the authentication unit decrypts the verification code to generate the first group data and the second group data group.
  • the decimal data is stored in the digital certificate clear code database.
  • the digital certificate clear code database is compared with the initialization database, and the information is determined according to the result.
  • the handset control unit transmits the CN39 code to the communication base station program fragmentation processing unit.
  • CN39-313 performs program fragmentation on the data and divides it into 3 segments, each segment of 13 decimal digits, 52 bits.
  • the communication base station authentication unit performs a decryption operation on the three sets of data.
  • a system architecture diagram of a system and method for authenticating a mobile phone number based on a CN39 code comprising a visitor mobile phone control unit, a communication base station program fragment processing unit, a communication base station authentication unit, a communication base station data processing unit, and a visited mobile phone control unit
  • the whole operation process is basically as follows: First, the visitor's mobile phone sends an access signal, that is, the mobile phone number of the interviewee, and the mobile phone control unit generates and stores three sets of data codes, that is, the CN39 code and transmits the CN39 code to the communication base station program fragment processing unit.
  • the program fragment processing unit performs program fragmentation processing on the data, divides it into three groups of data codes, and finally verifies the authenticity of the CN39 code through the communication base station authentication unit. If the verification passes, the data is transmitted to the communication base station data processing unit, otherwise the data is discarded.
  • the communication base station data processing unit converts the CN39 code passed by the communication base station authentication unit into the original visitor mobile number, and outputs an access signal.
  • the mobile phone control unit of the interviewee receives the signal of the visitor's mobile phone, decrypts the "token", and returns to zero, then performs an incoming call or short message prompt.
  • the corresponding data flow chart is: visitor mobile phone control unit (generating CN39 code) ⁇ communication base station program fragment processing unit ⁇ communication base station authentication unit (authentication transmission, decrypting operation of CN39 code, and verifying result is “0”, then transmitting, "1" will abandon) ⁇ Communication base station data processing unit (convert CN39 code to original visitor mobile phone number + token) ⁇ Visited mobile phone control unit (execute the incoming call prompt according to the "token” decryption operation result) .
  • the "token” is encrypted by the communication base station data processing unit to encrypt the CN39 code passed by the authentication unit. Generated, is a 13-digit decimal random number.
  • the last three digits of the second set of data represent the serial number code, which means that the first access signal sent out every day, the maximum number of access signals sent out in one day is 1000. If the access demand exceeds 1000, the sequence is restarted from the beginning. cycle.
  • the CN39 code corresponding to the 1000th phone is:
  • the mobile phone control unit sends the data packet including the CN39 code (002017071700058177969361426913612202293) and the accessed mobile phone number (18818653209) to the communication base station;
  • the program fragment processing unit of the communication base station extracts the 39-digit decimal number CN39 code (002017071700058177969361426913612202293), which is divided into three segments: 0020170717000
  • the three sets of data codes are transmitted to the communication base station authentication unit, and the authentication unit decrypts the operation. Decryption result is "0" to continue transmitting data to the communication base station data processing unit;
  • the communication base station data processing unit converts the CN39 code into the original visitor mobile phone number (13612202293), and generates a signal for transmitting the license, that is, "token", the "token” and the visitor's mobile phone number to the mobile phone of the interviewee. Number output access signal;
  • the mobile phone control unit of the interviewee decrypts the “token” and returns to zero, and then performs an incoming call or short message prompt.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

一种基于CN39码认证手机号码的系统及方法,系统包括:手机控制单元、通信基站控制单元、通信基站程序碎片处理单元、通信基站认证单元、通信基站数据处理单元及被访问者手机控制单元。所述方法步骤为:访问者手机发出访问信号,生成第一组数据;手机控制单元生成第二组数据;手机控制单元产生第三组数据;手机控制单元传送CN39码及被访问者手机号至通信基站;通信基站的程序碎片处理单元处理信号,通信基站的认证单元对三组数据解密,通过,传送到数据处理单元;通信基站的数据处理单元将CN39码转换成原来的访问者手机号,并产生传输许可的信号,向被访问者手机号输出访问信号;被访问者手机控制单元解密运算,归零,则提示。

Description

一种基于CN39码认证手机号码的系统及方法 技术领域:
本发明涉及商用密码技术在保障手机号码通信安全中的应用,是一种能保障手机号码通信安全的数字密码认证方法,可以有效屏蔽伪基站发送的垃圾短信、拦截通过改号软件拨打的诈骗电话。
背景技术:
中国互联网络信息中心(CNNIC)发布第39次《中国互联网络发展状况统计报告》。报告显示,截止到2016年12月,中国网民规模达7.31亿,相当于欧洲人口总量,互联网普及率达到53.2%;其中,手机网民占比达95.1%,线下手机支付习惯已经形成。此外,报告还显示手机诈骗及骚扰类电话、短信令用户烦不胜烦。2016年360安全中心和腾讯安全共同监测到安卓手机用户标记骚扰诈骗类电话391.2亿次,其中诈骗电话48.9亿次;安卓手机用户标记骚扰诈骗类短信183.8亿条,其中诈骗短信6.1亿条。
网络时代,伴随公民个人信息泄露而来的恶果令人瞠目。中国互联网协会《中国网民权益保护调查报告2016》显示,近一年的时间,国内6.88亿网民因垃圾短信、诈骗信息、个人信息泄露等造成的经济损失估算达915亿元。手机诈骗及骚扰类电话、短信令用户烦不胜烦,现在手机用户一般下载软件用来屏蔽骚扰电话和短信,但是效果甚微,特别是改号软件、伪基站的出现,可以将普通的手机号码变成“诈骗号码”,骚扰电话一直变换,软件不能有效进行控制。
密码技术是保护网络信息安全的重要手段之一。密码技术自古有之,到目前为止,已经从外交和军事领域走向公开。它不仅具有保证信息机密性的信息加密功能,而且具有数字签名、身份验证、系统安全等功能。因此,使用密码技术不仅可以保证手机号码的机密性,而且可以保证手机号码的完整性和确定 性,防止手机号码被篡改、伪造和假冒。
发明内容:
本发明目的是针对以上现有技术的不足,提供一种对手机号码进行加密、识别以及认证的方法;既有明示部分,又有密码部分,对于访问者及被访问者都易辨证;不易篡改,不易假冒。
本发明目的可通过以下技术方案实现:
一种基于CN39码认证手机号码的系统及方法,包括:
手机控制单元:用于对访问者手机发出的访问信号进行生成、加密运算、存储处理,生成CN39码;
通信基站控制单元:用于接收访问者手机发出的信号;
通信基站程序碎片处理单元:用于从接收到的数据包中提取CN39,并将其分为三段,毎段13位十进制数;
通信基站认证单元:用于对碎片数据进行解密运算;
通信基站数据处理单元:用于将认证单元认证通过的CN39码转化成原来的访问者手机号码并产生令牌,输出访问信号。
被访问者手机控制单元:用于接收访问者手机信号,并将“令牌”进行解密运算,执行来电或短信提示。
所述的手机控制单元与被访问者手机控制单元存储在同一手机中,用以完成信号的拨出及接收。
一种基于CN39码认证手机号码的系统及方法,包括以下步骤:
(1)、访问者手机发出访问信号,即被访问者手机号,手机控制单元在访问者手机号为11位时,在访问者手机号前加两位十进制的国别代码,若访问者手机号不足11位时,手机控制单元在该访问者手机号后加零,使其变成11位 十进制数,再在该手机号前两位加十进制的国别代码,作为第一组数据;
(2)、手机控制单元自动生成符合流水号编码原则的13位十进制数,作为第二组数据;
(3)、手机控制单元获取待处理的各为13位十进制的第一组数据及第二组数据;
(4)、手机控制单元判断第二组数据是否符合流水号编码原则,若符合则进行下一步,若不符合则进行错误提示;
(5)、手机控制单元将上述第一组数据和符合流水号编码原则的第二组数据,通过商用密码算法加密运算,产生一个13位的十进制验证码,即第三组数据,该三组数据组成了CN39码;
(6)、手机控制单元将CN39码及被访问者手机号一同发送至通信基站;
(7)、通信基站的程序碎片处理单元,即CN39-313,依据CN39码的编码规则从接收到的数据包中提取组成CN39码的39位十进制数,并将其分为三段,毎段13位十进制数,即52位二进制数(52bit),即得三组数据码;
(8)、通信基站的程序碎片处理单元将三组数据传输到通信基站的认证单元,认证单元对三组数据解密,解密结果为"0"则将数据传送到通信基站数据处理单元,否则,不传送数据;
(9)、通信基站数据处理单元将认证单元认证之后的CN39码转换成原来的访问者手机号,并产生传输许可的信号,即"令牌",再将"令牌"及访问者手机号向被访问者手机号输出访问信号;
(10)、被访问者手机收到访问信号,被访问者手机控制单元将“令牌”进行解密运算,归零,则执行来电或短信提示,否则则不提示。
所述的一种基于CN39码认证手机号码的系统及方法,其第2组数据的编 码原则,即流水号的编码原则是第1-2位为2位的类别代码,其中手机号码的类别号为00,第3-6位为4位的年份代码,第7-8位为2位的月份代码,第9-10位为2位的日期代码,第11-13位为3位的该日的流水号代码,每天针对每个手机号码提供1000个CN39码,和手机发出的每一个访问信号按照顺序一一对应,如果访问需求超过1000个,则从头开始重新循环。
所述的一种基于CN39码认证手机号码的系统及方法,通信基站认证单元在收到通信基站程序碎片处理单元传输过来的三组数据码后,通过商用密码算法对其中的验证码解密运算,可得到13位十进制的第1组及第2组两组数据。
一种基于CN39码认证手机号码的系统及方法,其手机控制单元将第1组数据、第2组数据及第3组数据分为三行后给予存储,其存储方式为,第1组数据、第2组数据及第3组数据分三行存储。
本发明的技术优点在于,所设计的认证手机号码的方法既有明示部分,又有密码部分,对于访问者及被访问者都易辨证;不易篡改、不易假冒,安全性高,且可完全屏蔽不相关的信息的传递。
本发明是在用户手机号码的基础上,又增加了流水号编码和验证码。流水号编码唯一标识第二组数据,将用户每日可用的手机号码由1个扩大到了1000个。同时,验证码是由第一组数据和第二组数据,通过商用密码算法加密产生,密码算法加密得到验证码后,通过商用密码算法解密可得到第一组数据和第二组数据,达到验证之目的。CN39码可在世界范围内,标识每个发出去的访问信号,CN39码被猜测到的概率是十万亿分之一,故用户手机号码被篡改和假冒的概率也是十万亿分之一。
附图说明:
图1为CN39码示意图;
图2为CN39码的产生流程示意框图;
图3为CN39码的认证流程示意框图;
图4为CN39码的比对流程示意框图;
图5为CN39码的数据流程示意框图;
图6为程序碎片示意图;
图7认证单元示意图;
图8为系统体系架构图;
图9为“令牌”示意图;
具体实施方式:
结合附图和实施方法对本发明做进一步的详细说明:
一、验证码
验证码是通过商用密码算法将第一组数据和第二组数据加密产生的13位的十进制数,是唯一的,随机的。
将上述三组数据分下、中、上排列即得CN39码,CN39码在世界范围内标识手机号码发出去的访问信号,且可通过商用密码算法加、解密验证真伪,达到识别和保护手机号码通信安全的目的。
0-9十个数字作为CN39码的数据载体,将CN39码分成三行存储,用于手机号码的识别认证。
二、按上述步骤制造成的CN39码具有以下优点:
CN39码是由两组明文和一组密文组成,CN39码的安全可靠性建立在密码算法的保密性和保密的密钥基础之上,所以,公开密文不会影响密码算法的安全性。破译密码算法的可能性在此视为不存在。
CN39码由39位十进制数组成,它的变化量是1039个;CN39码有三组13位的 十进制数组成,其中第1组及第2组是明文,第3组是验证码,即密文。所以,CN39码被猜测到的概率是十万亿分之一,很显然这是一个小概率事件,且即使猜测成功,它不会对用户其他访问信号对应的CN39码构成威胁。
三、CN39码的应用
CN39码为建立第三方认证成为现实;通信基站认证单元拥有密码算法和密钥,向通信基站认证单元传递CN39码,通过通信基站认证单元验证真伪,如验证通过,则将该信息传递,否则放弃。通信基站认证单元实时监控访问者的手机号码,若某个IP持续大量发送CN39码,即使认证通过,通信基站认证单元也会屏蔽该手机号码,阻断信息的发送。
1、CN39码安全性在于,既有明文,又有密文,被猜到的概率为十万亿分之一。信息保密的一个基本原则是公开算法的细节不会从根本上影响算法的安全性,即保密依赖于密钥,在这种方案中,即使公开了密文,也不会影响CN39码的安全性。
2、CN39码应用于用户移动互联网安全管理,为用户对网络信息的数字化管理提供了符合国际标准的数字平台。CN39码与用户是一一对应的,通信基站认证单元帮助用户过滤掉恶意的骚扰类电话、短信,保障用户个人信息的安全性,减少不必要的损失。
四、建立CN39码体系,需建立手机控制单元、通信基站程序碎片处理单元、通信基站认证单元、通信基站数据处理单元。
手机控制单元收集用户的手机号码、流水号编码数据,初始化数据库。通过商用密码算法对该数据库数据进行加密,产生13位十进制数的验证码,存入相应三组数据码数据库。将上述三组数据按照上、中、下顺序存储,即“CN39码”。
通信基站认证单元有加密、解密、编码、解码、网络传输、数据查询、数据比对等功能,建有手机号码数据库、CN39码数据库、商用密码数据库等,商用密码数据库用于管理密钥和商用密码算法,确保密钥和算法的安全。通信基站程序碎片处理单元对接收到的CN39码进行程序碎片处理,将其分为3组数据码,传输给通信基站认证单元,认证单元用商用密码算法对其解密,验证该CN39码的合法性,如合法,产生第一组数据、流水号码,将此第一组数据、流水号码与初始数据库中的第一组数据和第二组数据比对,比对通过则将验证通过,将该信息传输,否则则放弃。通信基站数据处理单元将通信基站认证单元认证之后的CN39码转换成原来的访问者手机号,并产生传输许可的信号,即"令牌",再将"令牌"及访问者手机号向被访问者手机号输出访问信号。
CN39码用于认证手机号码可分为:
1、申请密码算法:
按照《商用密码管理条例》规定审批所需要的商用密码算法,如杂凑算法、随机数生成算法。
2、CN39码,如图1所示:
CN39码由用户的第一组数据、第二组数据、验证码组成,由上、中、下三组编码组成。
3、CN39码的产生,如图2所示:
(1)初始化:手机控制单元收集用户的手机号码、流水号编码,初始化数据库。
(2)加密:用密码算法对该数据库数据进行加密,生成13位十进制数的验证码,存入相应的密码数据库。
(3)编码:将用户的第一组数据、第二组数据、验证码分成三组13位十进制 数,存入CN39码数据库。
4、CN39码的识别,如图3所示:
(1)读码:CN39码经过移动网络传输至通信基站。
(2)解码:通信基站程序碎片处理单元将CN39码解码,转换为三组13位十进制数。将验证码存入密码数据库。
(3)解密:通信基站认证单元用商用密码算法对验证码解密,产生二组13位十进制数,即数字认证明码。
5、CN39码的比对,如图4所示:
(1)通信基站认证单元将该数字认证明码与初始数据库中该用户的第一组数据、流水号码比对。
(2)比对结果反馈,一致则验证通过,信息被传输,不一致则放弃传输。
6、CN39码的数据流程图,如图5所示:
(1)建立通信基站,该基站具有加密、解密、编码、解码、网络传输、数据查询、数据比对等功能。
(2)手机控制单元收集用户的手机号码、流水号编码,产生二组13位十进制的数据,通过加密产生一组13位十进制的数据,三组数据存入CN39码数据库。CN39码传至通信基站程序碎片处理单元,进行程序碎片处理,将其分为3组数据码再传送给通信基站认证单元,认证单元对验证码解密产生第一组数据和第二组数据二组十进制数据,存入数字认证明码数据库。数字认证明码数据库与初始化数据库比对,根据结果决定信息是否传输。
7、程序碎片,如图6所示:
(1)手机控制单元将CN39码发送至通信基站程序碎片处理单元。
(2)CN39-313对数据进行程序碎片处理,将其分为3段,每段13位十进制数、52bit。
8、先认证后传输,如图7所示:
(1)通信基站认证单元对三组数据进行解密运算。
(2)验算结果为“0”则传输;为“1”则放弃。
9.系统架构图如图8所示:
一种基于CN39码认证手机号码的系统及方法的系统架构图,由访问者手机控制单元、通信基站程序碎片处理单元、通信基站认证单元、通信基站数据处理单元以及被访问者手机控制单元等构成,整个运作流程基本如下:首先,访问者手机发出访问信号,即被访问者手机号,手机控制单元产生并存储三组数据码,即CN39码并将CN39码传送给通信基站程序碎片处理单元,程序碎片处理单元对数据进行程序碎片处理,将其分为3组数据码,最后通过通信基站认证单元验证CN39码真伪,如验证通过,则将数据传送到通信基站数据处理单元,否则则放弃,通信基站数据处理单元将通信基站认证单元认证通过的CN39码转化成原来的访问者手机号码,并输出访问信号。被访问者手机控制单元,接收到访问者手机信号,将“令牌”进行解密运算,归零,则执行来电或短信提示。
相对应的数据流程图为:访问者手机控制单元(产生CN39码)→通信基站程序碎片处理单元→通信基站认证单元(认证传输,对CN39码进行解密运算,验算结果为“0”则传输,为“1”则放弃)→通信基站数据处理单元(将CN39码转化成原来的访问者手机号码+令牌)→被访问者手机控制单元(根据“令牌”解密运算结果,执行来电提示)。
10.“令牌”如图9所示:
“令牌”由通信基站数据处理单元将认证单元认证通过的CN39码再次加密 产生,是13位十进制随机数。
具体案例:
2017年7月17日,手机号码为13612202293的访问者发出去第一个访问信号,被访问者手机号码18818653209.同时,访问者的手机控制单元会依据自己的手机号码13612202293生成该电话对应的CN39码:
第二组数据0020170717000
验证码5817796936142
第一组数据6913612202293
第二组数据中后三位代表的是流水号编码,表示每天发出去的第几个访问信号,一天发出去的访问信号最多为1000个,如果访问需求超过1000个,则从头开始按照顺序重新循环。第1000个电话对应的CN39码为:
第二组数据0020170717999
验证码7539514823942
第一组数据6913612202293
首先,手机控制单元将包含CN39码(002017071700058177969361426913612202293)及被访问者手机号码(18818653209)的数据包一同发送给通信基站;
其次,通信基站的程序碎片处理单元接受到收据包后,会相应的提取其中39位十进制数的CN39码(002017071700058177969361426913612202293),分为三段:0020170717000
5817796936142
6913612202293,
即各为13位十进制数的三组数据码;
再次,三组数据码传送给通信基站认证单元,认证单元对其进行解密运算, 解密结果为"0"继续将数据传送到通信基站数据处理单元;
然后,通信基站数据处理单元将CN39码转换成原来的访问者手机号(13612202293),并产生传输许可的信号,即"令牌",将"令牌"及访问者手机号向被访问者手机号输出访问信号;
最后,被访问者手机收到访问信号后,被访问者手机控制单元将“令牌”进行解密运算,归零,则执行来电或短信提示。

Claims (6)

  1. 一种基于CN39码认证手机号码的系统,其特征在于,所述系统包括:
    手机控制单元:用于对访问者手机发出的访问信号进行生成、加密运算、存储处理,生成CN39码;
    通信基站控制单元:用于接收访问者手机发出的信号;
    通信基站程序碎片处理单元:用于从接收到的数据包中提取CN39,并将其分为三段,毎段13位十进制数;
    通信基站认证单元:用于对碎片数据进行解密运算;
    通信基站数据处理单元:用于将认证单元认证通过的CN39码转化成原来的访问者手机号码并产生令牌,输出访问信号;
    被访问者手机控制单元:用于接收访问者手机信号,并将“令牌”进行解密运算,执行来电提示。
  2. 根据权利要求1所述的手机控制单元与被访问者手机控制单元存储在同一手机中,用以完成信号的拨出及接收。
  3. 一种基于CN39码认证手机号码的方法,包括以下步骤:
    (1)、访问者手机发出访问信号,即被访问者手机号,手机控制单元在访问者手机号为11位时,在访问者手机号前加两位十进制的国别代码,若访问者手机号不足11位时,手机控制单元在该访问者手机号后加零,使其变成11位十进制数,再在该手机号前两位加十进制的国别代码,作为第一组数据;
    (2)、手机控制单元自动生成符合流水号编码原则的13位十进制 数,作为第二组数据;
    (3)、手机控制单元获取待处理的各为13位十进制的第一组数据及第二组数据;
    (4)、手机控制单元判断第二组数据是否符合流水号编码原则,若符合则进行下一步,若不符合则进行错误提示;
    (5)、手机控制单元将上述第一组数据和符合流水号编码原则的第二组数据,通过商用密码算法加密运算,产生一个13位的十进制验证码,即第三组数据,该三组数据组成了CN39码;
    (6)、手机控制单元将CN39码及被访问者手机号一同发送至通信基站;
    (7)、通信基站的程序碎片处理单元,即CN39-313,依据CN39码的编码规则从接收到的数据包中提取组成CN39码的39位十进制数,并将其分为三段,毎段13位十进制数,即52位二进制数(52bit),即得三组数据码;
    (8)、通信基站的程序碎片处理单元将三组数据传输到通信基站的认证单元,认证单元对三组数据解密,解密结果为"0"则将数据传送到数据处理单元,否则,不传送数据;
    (9)、通信基站的数据处理单元将认证单元认证之后的CN39码转换成原来的访问者手机号,并产生传输许可的信号,即"令牌",再将"令牌"及访问者手机号向被访问者手机号输出访问信号;
    (10)、被访问者手机收到访问信号,被访问者手机控制单元将“令牌”进行解密运算,归零,则执行来电或短信提示,否则则不提示。
  4. 根据权利要求3所示的一种基于CN39码认证手机号码的方法,其特征在于,所述第2组数据的编码原则,即流水号的编码原则是第1-2位为2位的类别代码,其中手机号码的类别号为00,第3-6位为4位的年份代码,第7-8位为2位的月份代码,第9-10位为2位的日期代码,第11-13位为3位的该日的流水号代码,每天针对每个手机号码提供1000个CN39码,和手机发出的每一个访问信号按照顺序一一对应,如果访问需求超过1000个,则从头开始重新循环。
  5. 根据权利要求3所示的一种基于CN39码认证手机号码的方法,其特征在于,认证单元在收到程序碎片单元传输过来的三组数据码后,通过商用密码算法对其中的验证码解密运算,可得到13位十进制的第1组及第2组两组数据。
  6. 根据权利要求3所示的一种基于CN39码认证手机号码的方法,其特征在于,手机控制单元将第1组数据、第2组数据及第3组数据分为三行后给予存储,其存储方式为,第1组数据、第2组数据及第3组数据分三行存储。
PCT/CN2017/095759 2017-08-03 2017-08-03 一种基于cn39码认证手机号码的系统及方法 WO2019024031A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/CN2017/095759 WO2019024031A1 (zh) 2017-08-03 2017-08-03 一种基于cn39码认证手机号码的系统及方法

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2017/095759 WO2019024031A1 (zh) 2017-08-03 2017-08-03 一种基于cn39码认证手机号码的系统及方法

Publications (1)

Publication Number Publication Date
WO2019024031A1 true WO2019024031A1 (zh) 2019-02-07

Family

ID=65233219

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/095759 WO2019024031A1 (zh) 2017-08-03 2017-08-03 一种基于cn39码认证手机号码的系统及方法

Country Status (1)

Country Link
WO (1) WO2019024031A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101552668A (zh) * 2008-03-31 2009-10-07 展讯通信(上海)有限公司 用户设备接入网络时的认证方法、用户设备及基站
CN103906039A (zh) * 2012-12-27 2014-07-02 中国移动通信集团福建有限公司 一种防止手机号码泄露的方法和装置
CN104836817A (zh) * 2015-06-04 2015-08-12 于志 一种保障网络信息安全的体系架构及方法
CN107333262A (zh) * 2017-08-03 2017-11-07 于志 一种基于cn39码认证手机号码的系统及方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101552668A (zh) * 2008-03-31 2009-10-07 展讯通信(上海)有限公司 用户设备接入网络时的认证方法、用户设备及基站
CN103906039A (zh) * 2012-12-27 2014-07-02 中国移动通信集团福建有限公司 一种防止手机号码泄露的方法和装置
CN104836817A (zh) * 2015-06-04 2015-08-12 于志 一种保障网络信息安全的体系架构及方法
CN107333262A (zh) * 2017-08-03 2017-11-07 于志 一种基于cn39码认证手机号码的系统及方法

Similar Documents

Publication Publication Date Title
US7095851B1 (en) Voice and data encryption method using a cryptographic key split combiner
CN102572817B (zh) 实现移动通信保密的方法和智能存储卡
US8688996B2 (en) Multipad encryption
KR20000012131A (ko) 공중 전파 통신과 패스워드 프로토콜을 사용하여 키를 확립하는 방법 및 패스워드 프로토콜
CN107294964B (zh) 一种信息传输的方法
US8230218B2 (en) Mobile station authentication in tetra networks
CN107277059A (zh) 一种基于二维码的一次性口令身份认证方法及系统
CN107333262A (zh) 一种基于cn39码认证手机号码的系统及方法
CN103179514B (zh) 一种敏感信息的手机安全群分发方法和装置
CN103781064A (zh) 短信验证系统及验证方法
CN109728896A (zh) 一种基于区块链的来电认证和溯源方法及流程
JPH06504626A (ja) アクセスコントロールおよび/または識別方法および装置
CN112020038A (zh) 一种适用于轨道交通移动应用的国产加密终端
CN104821883A (zh) 一种基于非对称密码算法的保护隐私征信方法
CN108401494B (zh) 一种传输数据的方法及系统
CN108696508A (zh) 基于cn39码认证居民身份证号码的系统及方法
CN110691359A (zh) 一种电力营销专业的蓝牙通信的安全防护方法
CN105162592B (zh) 一种认证可穿戴设备的方法及系统
CN105490814A (zh) 一种基于三维码的票务实名认证方法及系统
CN101174945B (zh) 一种用于验证push消息及其发送方身份的方法
CN1783777B (zh) 固定通信安全、数据加密方法和系统及固定终端鉴权方法
US20230070408A1 (en) Secure communication device equipped with quantum encryption chip based quantum random number and method of providing secure communication service using the same
CN112054905B (zh) 一种移动终端的安全通信方法及系统
WO2019024031A1 (zh) 一种基于cn39码认证手机号码的系统及方法
EP3185504A1 (en) Security management system for securing a communication between a remote server and an electronic device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17920000

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17920000

Country of ref document: EP

Kind code of ref document: A1