A method, system, device and storage medium for controlling access to a SIM card
By requesting authentication data from the authorized access platform and writing it to the SIM card through the industry application client, the problem of SIM card access control rule update failure was solved, and dynamic updates and efficient access control rule management were achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2023-07-05
- Publication Date
- 2026-07-24
AI Technical Summary
In existing technologies, updating access control rules within a SIM card relies on data SMS interaction between the authorized access platform and the SIM card. This is prone to errors, leading to update failures and a low success rate. As a result, it cannot be applied to production environments and requires card replacement for updates, causing inconvenience to users.
The industry application client sends a SIM card access authorization request to the authorization access platform, receives and verifies the authentication data, and uses the authorization writing application to write authorization information to the SIM card, thereby realizing dynamic updates of access control rules.
It enables dynamic updates of access control rules within the SIM card, meeting business needs, enriching usage scenarios, and avoiding errors and update failures in data SMS interaction.
Smart Images

Figure CN116828462B_ABST
Abstract
Description
Technical Field
[0001] This application relates to communication technology, and more particularly to a control method, system, device, and storage medium for SIM card access. Background Technology
[0002] The digital currency and digital identity promoted by the state both use SIM cards as the security module carrier. They are accessed via apps to achieve functions such as storing critical business data, processing keys, and verifying signatures. Apps need to authorize access when accessing SIM card applications. Access control rules are stored in the SIM card, and the mobile terminal's operating system uses these rules to allow or deny access to which client applications can access which SIM card applications.
[0003] Currently, updating access control rules within a SIM card requires extensive data and SMS interactions between the authorized access platform and the SIM card. Besides this method, another approach is to streamline the access control rules for the application client accessing the SIM card and then pre-install these rules into the card at the factory.
[0004] The above-mentioned method of updating access control rules via SMS is prone to errors. Once the SMS interaction fails, the rule update will also fail, resulting in a low success rate and making it unsuitable for production environments. Therefore, currently, the only way to update access control rules for application clients is by replacing the card, which causes inconvenience to users. Summary of the Invention
[0005] This application provides a SIM card access control method system, device, and storage medium to solve the problem of updating access control rules within a SIM card.
[0006] Firstly, this application provides a SIM card access control method, applied to an industry application client on a terminal device, comprising:
[0007] Send a SIM card access authorization request to the authorized access platform;
[0008] Receive authentication data returned by the authorized access platform, which is generated by the authorized access platform after the industry application client passes the access verification on the general terminal access control management platform;
[0009] The authentication data is sent to the authorization writing application on the terminal device to invoke the authorization writing application to write authorization information to the SIM card of the terminal device.
[0010] Secondly, this application provides a SIM card access control method, applied to an authorized access platform, including:
[0011] Receive SIM card access authorization requests sent by industry application clients on terminal devices;
[0012] The access information of the industry application client is sent to the general terminal access control management platform for access verification.
[0013] The system receives authentication data generated by the general terminal access control management platform after successful access verification, and sends the authentication data to the industry application client.
[0014] Thirdly, this application provides a method for controlling SIM card access, applied to an authorized writing application on a terminal device, including:
[0015] Receive authentication data security verification data sent by the industry application client of the terminal device; send the authentication data security verification data to the general terminal access control management platform for verification;
[0016] After receiving the authorization information returned by the control and management platform after successful verification, the authorization information is written into the SIM card of the terminal device.
[0017] Fourthly, this application provides a control device for SIM card access, including: a processor, and a memory communicatively connected to the processor;
[0018] The memory stores computer-executed instructions;
[0019] The processor executes computer execution instructions stored in the memory to implement the SIM card access control method as described in any of the preceding claims.
[0020] Fifthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the SIM card access control method as described in any of the preceding claims.
[0021] This application provides a SIM card access control method, system, device, and storage medium. The method involves an industry application client sending a SIM card access authorization request to an authorization access platform; receiving authentication data returned by the authorization access platform, which is generated by the authorization access platform after the industry application client passes access verification on a general terminal access control management platform; and sending the authentication data to an authorization writing application on the terminal device to write authorization information to the SIM card of the terminal device. Because this application initiates the access authorization request through the industry application client and the authorization writing program writes the authorization information to the SIM card of the terminal device, the industry application client can initiate an access authorization request independently when it does not have permission to access the SIM card, thus updating the access control rules. This application achieves dynamic updating of access control rules, meets business needs, and enriches usage scenarios. Attached Figure Description
[0022] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0023] Figure 1 A flowchart illustrating an embodiment of a SIM card access control method provided in this application;
[0024] Figure 2 A flowchart illustrating an embodiment of a SIM card access control method provided in this application for industry application clients accessing SIM cards;
[0025] Figure 3 A flowchart illustrating an embodiment of a SIM card access control method provided in this application;
[0026] Figure 4 A flowchart illustrating an embodiment of a SIM card access control method provided in this application;
[0027] Figure 5 A flowchart illustrating an embodiment of a SIM card access control method for writing authorization information to a SIM card, as provided in this application;
[0028] Figure 6 This is a schematic diagram of a SIM card access control device provided in an embodiment of this application.
[0029] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concepts of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0030] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0031] First, let me explain the terms used in this application:
[0032] Application Protocol Data Unit (APDU): refers to the information unit transmitted between the smart card and the smart card reader;
[0033] Application Identifier (AID): A string of numeric characters, usually enclosed in parentheses and located at the beginning of the barcode, is a unique code used to identify different applications;
[0034] SIM (Subscriber Identity Module) card: refers to the IC card held by mobile users in the GSM system, also known as a user identification card, used to store the access control master file, access control rule file, and access control condition file.
[0035] Access control rules refer to the rules that application clients need to follow when accessing the SIM card. Specifically, they include the Access Control Master File (ACMF), the Access Control Rule File (ACRF), and the Access Control Condition File (ACCF).
[0036] Public Key Infrastructure (PKI) refers to a universal infrastructure based on public key cryptography technology that can be used to provide security services such as confidentiality of information, authenticity of information sources, integrity of data, and non-repudiation of actions.
[0037] IP Service Device (ISD): refers to IP service equipment, which includes functions such as IP address allocation and revocation, online IP statistics, historical IP statistics, and IP access control. It also integrates services such as DNS / TFTP / NTP, and is a highly reliable and high-performance core service system that integrates service and management.
[0038] SCP02: refers to a secure channel protocol between the card and an external entity used to ensure entity authentication, data integrity, and confidentiality;
[0039] Application (APP): refers to third-party applications for smartphones;
[0040] Software Development Kit (SDK): refers to a collection of development tools used by software engineers to create application software for specific software packages, software frameworks, hardware platforms, operating systems, etc.
[0041] In existing technologies, updating access control rules within a SIM card requires extensive data and SMS interactions between the authorized access platform and the SIM card. Besides this method, current approaches require streamlining access control rules for application clients accessing the SIM card and then pre-writing these rules to the card at the factory. The data and SMS interaction methods described above are prone to errors; if the data and SMS interaction fails, the rule update will also fail, resulting in a low success rate and making it unsuitable for production environments. Therefore, currently, updating access control rules for application clients can only be achieved by replacing the SIM card, causing inconvenience to users.
[0042] To address the aforementioned problems, this application provides a SIM card access control method system that can read and dynamically update access control rules within the SIM card. The specific technical concept is as follows:
[0043] The industry application client sends a SIM card access authorization request to the authorization access platform and receives the authentication data returned by the authorization access platform. The authentication data is sent to the authorization writing application on the terminal device, which then writes the authorization information to the SIM card of the terminal device.
[0044] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0045] Figure 1 A flowchart of an embodiment of a SIM card access control method provided in this application is shown below. Figure 1 As shown, the executing entity of this method can be a terminal device implementing a SIM card access control method. This terminal device can execute the following steps via hardware, software, or a combination of both. The method includes:
[0046] S101. Send a SIM card access authorization request to the authorized access platform;
[0047] The industry application client submits an access authorization request to the business provider platform, which then requests information verification from the authorized access platform.
[0048] Industry application clients refer to application clients within a specific field. For example, in the fintech industry, industry application clients could be cryptocurrency clients or mobile wallet clients.
[0049] S102. Receive authentication data returned by the authorized access platform. The authentication data is generated by the authorized access platform after the industry application client passes the access verification on the general terminal access control management platform.
[0050] The authorized access platform verifies the access information from the previous business provider platform, generates SDK authentication data, and returns the authentication data to the industry application client.
[0051] The access information for the service provider's platform is set in advance by the service provider on the access control platform.
[0052] S103. Authentication data is sent to the authorization writing application on the terminal device to call the authorization writing application to write authorization information to the SIM card of the terminal device.
[0053] The authorization access platform returns authentication data to the industry application client. The industry application client calls the authorization writing application to verify the authentication data, and the authorization writing application writes the access control rules to the SIM card.
[0054] This application sends a SIM card access authorization request to the authorization access platform via an industry application client. The industry application client receives authentication data returned by the authorization access platform. This authentication data is generated by the authorization access platform after the industry application client passes access verification on the general terminal access control management platform. The authentication data is then sent to the authorization writing application on the terminal device to write authorization information to the SIM card of the terminal device. Since this application initiates the access authorization request through the industry application client and the authorization writing program writes the authorization information to the SIM card of the terminal device, the industry application client can initiate an access authorization request independently when it does not have permission to access the SIM card, and update the access control rules. This application realizes dynamic updates of access control rules, meets business needs, and enriches the use cases.
[0055] like Figure 2 The diagram shown is a flowchart of an embodiment of a SIM card access control method provided in this application, where an industry application client accesses a SIM card. Figure 2As shown, the method includes:
[0056] S201, Send an access request to the SIM card;
[0057] Step S201 provides a further detailed method for sending a SIM card access authorization request to the authorized access platform, prior to step S101:
[0058] The industry application client sends an access request to the SIM card to access the card applications within the SIM card.
[0059] The SIM card serves as a security module, divided into multiple security domains. Within each security domain is a card application, which stores security information, such as digital currency strings, digital identity information, PKI key pairs, and CA certificates.
[0060] S202. If the access request does not have access rights to the SIM, then send a SIM card access authorization application to the authorized access platform.
[0061] If the industry application client does not have permission to access the SIM card, the industry application client submits an access authorization request to the service provider platform, and the service provider platform then requests authorization information verification from the authorized access platform.
[0062] Among them, the authorized access platform is a general terminal access control management platform that can perform security authentication on the information accessed by industry application clients, and perform data management, file information recording, updating, and querying of access control rule files in SIM cards.
[0063] S203, Receive the authorization information writing result of the authorization writing application on the SIM;
[0064] Step S203, following step S104, provides a further detailed method for industry application clients to access the SIM card:
[0065] The industry application client receives the updated results of the access control rules file for the SIM card, which are authorized to be written into the application.
[0066] The authorized writing application updates the access control rules in the SIM card, sends the writing result to the industry application client on the terminal device, and returns a status to the industry application client after the writing is complete.
[0067] S204. Access the application data in the SIM card based on the authorization information writing result.
[0068] The industry application client accesses the application data in the SIM card based on the authorization information written results, and the industry application client can access the card application normally.
[0069] Figure 3 A flowchart of an embodiment of a SIM card access control method provided in this application is shown below. Figure 3 As shown, the executing entity of this method can be a control device / management platform for a SIM card access control method. This device / platform can execute the following steps through hardware, software, or a combination of hardware and software. The method includes:
[0070] S301, Receive SIM card access authorization request sent by the industry application client on the terminal device;
[0071] If the industry application client does not have permission to access the SIM card, the authorization access platform receives the SIM card access authorization request sent from the industry application client on the terminal device.
[0072] In this process, the service provider platform directly receives access authorization requests sent by industry application clients, while the authorization access platform receives and verifies industry authorization information from the service provider platform.
[0073] Among them, the authorized access platform is a general terminal access control management platform that can perform security authentication on the information accessed by industry application clients, and perform data management, file information recording, updating, and querying of access control rule files in SIM cards.
[0074] S302. Send the access information of the industry application client to the general terminal access control management platform for access verification;
[0075] The service provider platform receives access authorization requests from industry application clients, and the general terminal access control management platform then verifies the authorization information of the service provider platform.
[0076] S303: Receive the authentication data generated by the general terminal access control management platform after the access verification is passed, and send the authentication data to the industry application client.
[0077] The universal terminal access control management platform verifies the access information of the service provider and generates authentication data.
[0078] The access information of the service provider is set in advance by the service provider in the general terminal access control management platform.
[0079] Figure 4 A flowchart of an embodiment of a SIM card access control method provided in this application is shown below. Figure 4As shown, the executing entity of this method can be an operating device / execution platform for a SIM card access control method. This device / platform can execute the following steps via hardware, software, or a combination of both. The method includes:
[0080] S401, Receive authentication data and security verification data sent by the industry application client of the terminal device;
[0081] The authorization write application receives authentication and security verification data from industry application clients.
[0082] Among them, the authentication data security verification data is the authentication data security verification data returned by the authorization access platform to the industry application client after the industry application client submits an access authorization request to the authorization access platform.
[0083] S402. Send the authentication data security verification data to the general terminal access control management platform for verification;
[0084] The authorization write application sends the authentication data security verification data from the industry application client to the universal terminal access control management platform, which then verifies the authentication data security verification data.
[0085] S403. Receive the authorization information returned by the control and management platform after successful verification, and write the authorization information into the SIM card of the terminal device.
[0086] After verifying the authentication data security verification data sent by the authorized writing application, the general terminal access control management platform returns an authorization instruction. The authorized writing application receives the authorization instruction, authenticates through the SCP02 channel, reads and stores the access control rules, and incrementally writes new rules, writing the authorization information into the SIM card.
[0087] like Figure 5 The diagram shown is a flowchart of an embodiment of the SIM card access control method provided in this application, which involves writing authorization information into the SIM card. Figure 5 As shown, the method includes:
[0088] S501, Authorized writing application obtains the write card application protocol data unit data stream by authorizing access to the platform authentication;
[0089] The authorized writing application sends a request to the authorized access platform to obtain the APDU data stream, and the authorized access platform returns the APDU data stream to the authorized writing application.
[0090] S502: Authorize the application to establish an SCP02 secure channel with the SIM card;
[0091] The authorized writing application initiates an SCP02 channel request to the SIM card. After SCP02 channel authentication, an SCP02 secure channel is established between the authorized writing application and the SIM card.
[0092] S503, Authorized Writing Application stores the access control rules of the current SIM card into the authorized access platform;
[0093] The authorization write application reads the current access control rule file in the SIM card and stores the current access control rule file in the authorization access platform.
[0094] S504, the authorized writing application writes the new access control rules into the SIM card. The authorized writing application receives the authorization information writing result returned by the SIM card and returns the authorization information writing result to the industry application client.
[0095] The Authorized Write application receives the write results of the access control file from the SIM card and returns the write results to the industry application client on the terminal device.
[0096] S505: Authorized writing of the application synchronizes access control rules to the authorized access platform;
[0097] The authorized writing application synchronizes the written access control rules to the authorized access platform, and the authorized access platform returns the processing results to the authorized writing application.
[0098] One possible embodiment of this application provides a control device for SIM card access. Figure 6 This is a schematic diagram of a SIM card access control device provided in an embodiment of this application, such as... Figure 6 As shown, a SIM card access control device includes: a processor 601, a memory 602, and a communication interface 603, wherein the processor 601, the memory 602, and the communication interface 603 are connected via a bus 604.
[0099] Memory 602 stores computer-executed instructions;
[0100] The processor 601 executes computer execution instructions stored in memory to implement any of the above-mentioned SIM card access control methods.
[0101] The specific implementation process of processor 601 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0102] In the above Figure 6In the illustrated embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0103] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0104] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0105] In one possible embodiment of this application, a computer-readable storage medium is also provided, which stores computer-executable instructions that, when executed by a processor, are used to implement the control method for SIM card access as described above.
[0106] The aforementioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The computer-readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0107] An exemplary computer-readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the computer-readable storage medium can also be a component of the processor. The processor and the computer-readable storage medium can reside in application-specific integrated circuits (ASICs). Alternatively, the processor and the computer-readable storage medium can exist as discrete components in the device.
[0108] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0109] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0110] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0111] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0112] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0113] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0114] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for controlling SIM card access, characterized in that, Industry application clients used on terminal devices include: Send an access request to the SIM card; If the access request does not have access rights to the SIM card, a SIM card access authorization application is sent to the authorized access platform; Receive authentication data returned by the authorized access platform, which is generated by the authorized access platform after the industry application client passes the access verification on the general terminal access control management platform; The authentication data is sent to the authorization writing application on the terminal device to invoke the authorization writing application to write authorization information to the SIM card of the terminal device; Receive the authorization information writing result of the authorization writing application on the SIM; Access the application data in the SIM card based on the authorization information writing result; Specifically, the authorization writing application receives authentication data security verification data sent by the industry application client of the terminal device, and sends the authentication data security verification data to the general terminal access control management platform for verification. After the verification is successful, the authorization writing application receives the authorization information returned by the general terminal access control management platform and writes the authorization information into the SIM card of the terminal device.
2. A method for controlling SIM card access, characterized in that, Applied to authorized access platforms, including: Receive SIM card access authorization requests sent by industry application clients on terminal devices; The access information of the industry application client is sent to the general terminal access control management platform for access verification. The system receives authentication data generated by the general terminal access control management platform after successful access verification, and sends the authentication data to the industry application client, which is used to execute the method described in claim 1.
3. The method according to claim 2, characterized in that, The method further includes: The system receives the authorization information writing result returned by the SIM and returns the authorization information writing result to the industry application client.
4. The method according to claim 2, characterized in that, Before writing the authorization information into the SIM card of the terminal device, the method further includes: The authorized writing application obtains the card writing application protocol data unit data stream through the authorized access platform authentication; The authorized writing application establishes an SCP02 secure channel with the SIM card; The authorization writing application stores the current access control rules of the SIM card into the authorization access platform.
5. The method according to claim 2, characterized in that, After writing the authorization information into the SIM card of the terminal device, the method further includes: The authorization writing application synchronizes access control rules to the authorization access platform.
6. A control device for SIM card access, comprising: The processor, memory, and communication interface are connected via a bus. The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the SIM card access control method as described in any one of claims 1 to 5.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the SIM card access control method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
CN103812649A
CN110519753A