Security authentication method and device for eSIM network access, electronic equipment and storage medium

Through a multi-dimensional binding authentication method that hashes and fuses user identity and eSIM data, combined with double verification of the cloud and device security chips, the security issues of eSIM network access are resolved, and highly secure network access authentication is achieved.

CN120676357APending Publication Date: 2025-09-19BEIJING TSINGTENG MICROSYSTEM CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511103265.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

The existing eSIM network access authentication method is easily used by attackers to forge device IDs or steal profile data to bypass security mechanisms, resulting in reduced network access security. In addition, the user identity is not deeply bound, so the SIM card can still be used by others after it is stolen.

Method used

By hashing and fusing user identity, terminal hardware, and eSIM data, an irreversible multi-dimensional binding credential is formed, and double verification is performed on the cloud server and device security chip to achieve dynamic authentication.

Benefits of technology

It improves the security of network access, prevents cloning attacks and man-in-the-middle attacks, and realizes full-link security protection of "one machine, one card, one person" through multi-dimensional data binding, enhancing the security of equipment and user identity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120676357A_ABST
    Figure CN120676357A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a security authentication method and device for eSIM network access, electronic equipment and a storage medium, and the method comprises the steps: obtaining first eSIM identification information, first equipment identification information and first user identification information in response to a received network access request; determining a verification hash value based on the first eSIM identification information, the first device identification information and the first user identification information; the verification hash value is sent to the cloud server and the equipment security chip for verification, the cloud server activates the network under the condition that the verification hash value passes verification, and the equipment security chip accesses the network under the condition that the verification hash value passes verification. According to the scheme, data of multiple dimensions of eSIM identification information, equipment identification information and user identification information are fused through Hash, deep association of different data is achieved, an irreversible multi-dimensional binding certificate is formed, multiple pieces of data need to be stolen at the same time for cracking, clone attacks can be effectively prevented, and the purpose of resisting man-in-the-middle attacks is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of mobile communication security technology, and in particular to a security authentication method, device, electronic device, and storage medium for eSIM network access. Background Art

[0002] In order to ensure the network access security of the embedded subscriber identity module (eSIM), it is usually necessary to perform security authentication on the device requesting to access the network before activating the network.

[0003] Currently, the main security authentication method used in related technologies is to verify the device identity through the Integrated Circuit Card Identity (ICCID) or International Mobile Subscriber Identity (IMSI). However, using this authentication method, attackers can bypass security mechanisms by forging device IDs or stealing profile data, thereby reducing network access security. Summary of the Invention

[0004] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides a security authentication method, device, electronic device and storage medium for eSIM network access.

[0005] In a first aspect, an embodiment of the present disclosure provides a security authentication method for eSIM network access, which is applied to a local number assistant (LPA), including:

[0006] In response to receiving the network access request, obtaining first eSIM identification information, first device identification information, and first user identification information;

[0007] Determining a verification hash value based on the first eSIM identification information, the first device identification information, and the first user identification information;

[0008] The verification hash value is sent to the cloud server and the device security chip for verification. The cloud server activates the network if the verification hash value passes the verification, and the device security chip accesses the network if the verification hash value passes the verification.

[0009] In a second aspect, an embodiment of the present disclosure provides a secure authentication device for eSIM network access, which is applied to a local number assistant (LPA), including:

[0010] an information acquisition module, configured to acquire, in response to receiving a network access request, first eSIM identification information, first device identification information, and first user identification information;

[0011] a determination module, configured to determine a verification hash value based on the first eSIM identification information, the first device identification information, and the first user identification information;

[0012] The sending module is used to send the verification hash value to the cloud server and the device security chip for verification. The cloud server activates the network if the verification hash value passes the verification, and the device security chip accesses the network if the verification hash value passes the verification.

[0013] In a third aspect, an embodiment of the present disclosure provides an electronic device, comprising: a processor; a memory for storing executable instructions of the processor; and the processor for reading the executable instructions from the memory and executing the executable instructions to implement the secure authentication method for eSIM network access as described in the first aspect.

[0014] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program is used to implement the security authentication method for eSIM network access as described in the first aspect.

[0015] The technical solution provided by the embodiments of the present disclosure has the following advantages over the prior art:

[0016] The security authentication scheme for eSIM network access provided by the embodiment of the present disclosure obtains the first eSIM identification information, the first device identification information, and the first user identification information in response to receiving a network access request; determines a verification hash value based on the first eSIM identification information, the first device identification information, and the first user identification information; sends the verification hash value to the cloud server and the device security chip for verification; the cloud server activates the network if the verification hash value passes, and the device security chip accesses the network if the verification hash value passes. Using the scheme of the present disclosure, data of multiple dimensions of eSIM identification information, device identification information, and user identification information are fused through hashing, achieving deep association of different data and forming irreversible multi-dimensional binding credentials. Cracking requires stealing multiple data at the same time, which can effectively prevent cloning attacks, achieve the purpose of resisting man-in-the-middle attacks, and improve the security of network access. In addition, through double verification by the cloud server and the local device security chip, the security of network access is further improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale.

[0018] Figure 1 A flowchart of a secure authentication method for eSIM network access provided by an exemplary embodiment of the present disclosure;

[0019] Figure 2 A flowchart of a security authentication method for eSIM network access provided by another exemplary embodiment of the present disclosure;

[0020] Figure 3 A flowchart of a security authentication method for eSIM network access provided by another exemplary embodiment of the present disclosure;

[0021] Figure 4 A schematic diagram of a system architecture for implementing a secure authentication method for eSIM network access according to an exemplary embodiment of the present disclosure is shown;

[0022] Figure 5 A schematic diagram of the structure of a secure authentication device for eSIM network access provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0023] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0024] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.

[0025] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment," the term "another embodiment" means "at least one additional embodiment," and the term "some embodiments" means "at least some embodiments." Other terms are defined in the following description.

[0026] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0027] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0028] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0029] Before explaining the specific embodiments of the present disclosure, the Chinese and English terms that may be involved in the present disclosure are explained as follows:

[0030] Profile: The core component of eSIM, which refers to the configuration file stored in the eSIM, including the operator's network information and the user's subscription data;

[0031] EID: The unique identifier of the eSIM embedded chip is a 32-bit number integrated into electronic devices that support the eSIM chip;

[0032] SE: Secure Element, a core component of the eSIM, is used to store sensitive data (such as keys and certificates) and perform security operations. It has functions such as user authentication and data encryption and decryption.

[0033] eUICC: Embedded Universal Integrated Circuit Card, a chip built into a device that can store multiple operator configuration files and switch or update these configurations through remote management technology;

[0034] IMEI: International Mobile Equipment Identity, a unique identifier for Global System for Mobile Communications (GSM) and Universal Mobile Telecommunications System (UMTS) devices (such as mobile phones).

[0035] MEID: Mobile Equipment Identifier, a unique identifier for Code Division Multiple Access (CDMA) devices such as some mobile phones and tablets.

[0036] TEE: Trusted Execution Environment (TEE) is a combination of hardware and software security technology that creates a secure area on the device's main processor that is isolated from the normal operating system, ensuring the security of sensitive data and operations.

[0037] API: The full name of the application programming interface is application programming interface, which is a set of rules and mechanisms that define the interaction between software components, allowing different software systems to exchange data or call functions in a standardized way.

[0038] Currently, in related technologies, the binding of eSIMs to electronic devices (such as smartphones, smart wearable devices, etc.) and Internet security verification have certain defects, such as:

[0039] (1) Physical binding limitations: Existing eSIM and electronic device binding relies only on physical layer association (such as ICCID binding), but the core data of the profile (such as IMSI, EID) still has the risk of cloud storage leakage or man-in-the-middle attack;

[0040] (2) Single-factor authentication vulnerabilities: Traditional security authentication schemes only verify device identity through ICCID or IMSI. Attackers can bypass security mechanisms by forging device IDs or stealing profile data.

[0041] (3) User identity is out of control: Existing solutions do not deeply bind user identity (such as ID number) with eSIM data, resulting in the SIM card being able to be used by others even if it is stolen.

[0042] Therefore, there is an urgent need for a dynamic authentication mechanism based on multi-dimensional data binding to deeply associate user identity, terminal device and eSIM data (Profile) to achieve full-link security protection of "one device, one card and one person" to ensure the security of network access.

[0043] Therefore, this disclosure provides a secure authentication method for eSIM network access. By fusing the user identity (document number), terminal hardware (SE chip ID / device ID), and eSIM data (IMSI / EID) through hashing, it forms an irreversible multi-dimensional binding credential. Cracking requires the simultaneous theft of various types of data, increasing the difficulty of attack and improving network access security. This solution, driven by the dual-wheel "data fusion + dynamic verification", builds a high-security protection system for the eSIM era and has significant practicality.

[0044] The following describes in detail the eSIM network access security authentication method, device, electronic device, and storage medium provided by the present disclosure with reference to the accompanying drawings.

[0045] Figure 1 This is a flow chart of a security authentication method for eSIM network access provided in an exemplary embodiment of the present disclosure. The method can be performed by a security authentication device for eSIM network access provided in an embodiment of the present disclosure. The device can be implemented in software and / or hardware and can be integrated into an electronic device, specifically a local profile assistant (LPA) of the electronic device.

[0046] like Figure 1 As shown, the security authentication method for eSIM network access may include the following steps:

[0047] Step 101: In response to receiving a network access request, obtain first eSIM identification information, first device identification information, and first user identification information.

[0048] The network access request is used to request access to the eSIM network and initiate security authentication for the device requesting network access. Different scenarios can be set to trigger the network access request, as shown below.

[0049] For example, when an electronic device is powered on, it may initiate a network access request. After receiving the network access request from the electronic device, the LPA obtains eSIM identification information (referred to as first eSIM identification information for ease of description and distinction), device identification information (referred to as first device identification information for ease of description and distinction), and user identification information (referred to as first user identification information for ease of description and distinction).

[0050] For example, when a user unlocks an electronic device using a security password (such as a fingerprint, face, or digital password), the electronic device may initiate a network access request.

[0051] Exemplarily, when the duration of this network access reaches a preset duration (eg, one hour), the electronic device may initiate a network access request.

[0052] In an optional embodiment of the present disclosure, the first eSIM identification information may include but is not limited to at least one of IMSI and eSIM embedded chip unique identifier (EID), and the first device identification information may include but is not limited to at least one of device security chip identifier (SE chip ID) and device unique identifier, wherein the device unique identifier may be but is not limited to IMEI and MEID. For different users, the first user identification information is different. For example, if the user refers to an individual, the first user identification information may be the user's real-name authentication document number, such as ID card number, passport number, etc. If the user is an enterprise, the first user identification information may be the enterprise's unified document number. It should be noted that the first user identification information is obtained with the user's authorization.

[0053] As an example, the first eSIM identification information includes IMSI and EID, the first device identification information includes SE chip ID and device unique identifier, and the first user identification information includes user ID number. Thus, the eSIMProfile is bound to the terminal device through the five-tuple data to generate a unique binding credential. If you want to crack it, you need to obtain these five types of data at the same time. For example, even if the IMSI / EID is stolen, due to the lack of device ID and user ID number, a valid binding hash cannot be generated, which increases the difficulty of cracking and helps to improve the security of network access.

[0054] Step 102: Determine a verification hash value based on the first eSIM identification information, the first device identification information, and the first user identification information.

[0055] In this embodiment, after the first eSIM identification information, the first device identification information, and the first user identification information are obtained, a verification hash value may be determined based on the first eSIM identification information, the first device identification information, and the first user identification information.

[0056] As an example, a hash calculation may be performed on the first eSIM identification information, the first device identification information, and the first user identification information, and the obtained hash value may be directly used as the verification hash value.

[0057] As another example, in order to ensure data security, the first eSIM identification information, the first device identification information and the first user identification information can be hashed to obtain a hash value, and then the obtained hash value can be encrypted according to a preset encryption algorithm. The obtained ciphertext data is used as the verification hash value, so that when the verification hash value is uploaded to the cloud server, the verification hash value can be prevented from being attacked during the transmission process, thereby ensuring transmission security.

[0058] Step 103: Send the verification hash value to the cloud server and the device security chip for verification. The cloud server activates the network if the verification hash value passes the verification, and the device security chip accesses the network if the verification hash value passes the verification.

[0059] In this embodiment, after obtaining the verification hash value, the verification hash value can be sent to the cloud server and the device security chip respectively for double verification. If the verification hash value is verified successfully, the cloud server activates the network so that the device security chip can access the corresponding network; if the verification hash value is verified successfully, the device security chip accesses the network, allowing the electronic device to access the Internet through the eSIM network.

[0060] For example, the cloud server and the device security chip store an authentication hash value for verifying the verification hash value. The authentication hash value is calculated in the same way as the verification hash value. The authentication hash value can be determined during the user registration phase and stored in the cloud server and the SE security chip of the eSIM for verification when needed. In addition, the authentication hash value stored in the cloud server is bound to the EID and IMSI of the profile corresponding to the eSIM, so that after the cloud server verifies the verification hash value, it determines the profile that needs to be activated based on the EID and IMSI bound to the authentication hash value that matches the verification hash value, and activates the corresponding network.

[0061] In the embodiment of the present disclosure, by obtaining the current eSIM identification information, device identification information and user identification information for calculating the verification hash value for identity verification when receiving the network access request, and dynamically verifying the five-tuple data when accessing the network, it can effectively prevent man-in-the-middle attacks caused by forged profiles or device hijacking, and ensure network access security.

[0062] The security authentication method for eSIM network access provided by the embodiment of the present disclosure obtains the first eSIM identification information, the first device identification information, and the first user identification information in response to receiving a network access request; determines a verification hash value based on the first eSIM identification information, the first device identification information, and the first user identification information; sends the verification hash value to the cloud server and the device security chip for verification; the cloud server activates the network if the verification hash value passes, and the device security chip accesses the network if the verification hash value passes. Using the solution of the present disclosure, data of multiple dimensions of eSIM identification information, device identification information, and user identification information are fused through hashing, achieving deep association of different data and forming irreversible multi-dimensional binding credentials. Cracking requires stealing multiple data at the same time, which can effectively prevent cloning attacks, achieve the purpose of resisting man-in-the-middle attacks, and improve the security of network access. In addition, through double verification by the cloud server and the local device security chip, the security of network access is further improved.

[0063] In an optional embodiment of the present disclosure, Figure 2 As shown, based on the above embodiment, step 102 may include the following sub-steps:

[0064] Step 201: Perform a hash operation on the first eSIM identification information, the first device identification information, and the first user identification information based on a preset hash function to obtain a target hash value.

[0065] A target hash value may be obtained by performing a hash operation on the first eSIM identification information, the first device identification information, and the first user identification information using a currently used hash function. For example, the hash function may be Message-Digest Algorithm 5 (MD5), a Secure Hash Algorithm (SHA-1) algorithm, a SHA-256 algorithm, an SM3 algorithm, or the like.

[0066] Step 202: Call the trusted execution environment to encrypt the target hash value, wherein the trusted execution environment encrypts the target hash value based on the locally stored initial counter value and initialization vector, obtains a verification hash value and returns it.

[0067] In this embodiment, for the calculated target hash value, a trusted execution environment can be called to encrypt the target hash value to obtain a verification hash value. The encryption algorithm for encrypting the target hash value can use the CTR mode of SM4. The initial counter value and initialization vector required for encryption can be pre-stored in the trusted execution environment. The specific encryption process includes: concatenating the initialization vector and the initial counter value to form a counter, encrypting the counter using the SM4 algorithm, generating a pseudo-random block, performing a bitwise exclusive OR (XOR) operation on the pseudo-random block and the target hash value to generate ciphertext, incrementing the counter, and repeating the above process until all data has been processed, encryption is completed, and a verification hash value is obtained. The trusted execution environment returns the obtained verification hash value to the LPA.

[0068] Taking the five-tuple data [IMSI, EID, SE chip ID, device ID, user ID number] composed of the first eSIM identification information, the first device identification information and the first user identification information as an example, the verification hash value (denoted as FiveTuple Hash) can be determined as follows: FiveTuple Hash = SM4_CTR(HASH_SM3(IMSI||EID||SE chip ID||device ID||user ID number), IV, Ksalt), where IV represents the initialization vector and Ksalt represents the initial counter value.

[0069] The secure authentication method for eSIM network access in the disclosed embodiment performs a hash operation on the first eSIM identification information, the first device identification information, and the first user identification information based on a preset hash function to obtain a target hash value, and then calls a trusted execution environment to encrypt the target hash value. The trusted execution environment encrypts the target hash value based on a locally stored initial counter value and initialization vector to obtain and return a verification hash value. Thus, by pre-storing the initial counter value and initialization vector in the trusted execution environment for encrypting the target hash value to obtain the verification hash value, the security of the verification hash value acquisition process is ensured due to the security of the trusted execution environment.

[0070] In an optional embodiment of the present disclosure, Figure 3 As shown, based on the above embodiment, the security authentication method for eSIM network access disclosed in the present invention may further include the following steps:

[0071] Step 301: During the user registration phase, obtain second eSIM identification information, second device identification information, and second user identification information.

[0072] It should be noted that in the embodiments of the present disclosure, "first" and "second" are only used to distinguish the same type of data obtained at different times and do not have specific meanings. For example, the first eSIM identification information and the second eSIM identification information both represent unique identification information of the eSIM. In the absence of an attack, the identification information of the same eSIM is identical, that is, the first eSIM identification information and the second eSIM identification information are exactly the same. If an attack occurs, the first eSIM identification information and the second eSIM identification information will differ, resulting in a calculated verification hash value that differs from the pre-stored authentication hash value, and the verification will fail. As a result, the cloud server will not activate the network, ensuring that attackers cannot access the eSIM network and ensuring network access security.

[0073] Step 302: Determine an authentication hash value based on the second eSIM identification information, the second device identification information, and the second user identification information.

[0074] In the embodiment of the present disclosure, during the user registration stage, the user files his or her own identification information (such as user ID number, enterprise unified certificate number) and passes biometric identification (such as fingerprint, face, etc.), and then scans the QR code provided by the operator through the mobile phone APP to download the eSIM Profile to the electronic device. The LPA in the electronic device obtains the EID and IMSI of the Profile and uploads it to the cloud server. The user enters his or her own biometric features and submits valid identification information. The LPA obtains the eSIM identification information (for the convenience of description and distinction, referred to as the second eSIM identification information), device identification information (for the convenience of description and distinction, referred to as the second device identification information) and user identification information (for the convenience of description and distinction, referred to as the second user identification information), and performs hash calculation based on this information to generate a hash value, and encrypts the obtained hash value according to a preset encryption algorithm to obtain an authentication hash value.

[0075] It should be noted that, in this embodiment, the hash function and encryption algorithm used to generate the authentication hash value are the same as the hash function and encryption algorithm used to generate the verification hash value in the aforementioned embodiment, and are not described in detail here.

[0076] Step 303: Invoke the trusted execution environment to encrypt the second user identification information to generate a user identification ciphertext.

[0077] In this embodiment, in order to ensure the security of the user identification information, the second user identification information may be encrypted and stored. Specifically, the trusted execution environment may be called to encrypt the second user identification information to generate a user identification ciphertext.

[0078] As an example, a trusted execution environment (TEE) can generate a pair of public and private keys within its secure environment. The private key can only be used within the TEE, while the public key can be used both inside and outside the TEE. When the LPA calls the trusted execution environment to encrypt the second user identification information, the TEE uses the public key to encrypt the second user identification information to obtain a user identification ciphertext and returns the user identification ciphertext to the LPA. By encrypting the second user identification information within the TEE, it can ensure that the data will not be tampered with or stolen during transmission. Based on this, when the LPA obtains the first user identification information, it needs to obtain the user identification ciphertext from the cloud server, and then call the trusted execution environment to decrypt the user identification ciphertext to obtain the second user identification information. For example, the TEE uses the private key to decrypt the user identification ciphertext to obtain the plaintext second user identification information and return it to the LPA. The LPA determines the obtained second user identification information as the first user identification information.

[0079] As an example, in order to better ensure the security of user identification and ensure the legitimacy of user identity, user identification information can be bound to the user's biometric features, so that when performing network user identity verification, network security can be further guaranteed through dual authorization of user identification information and biometric features. Therefore, in an optional embodiment of the present disclosure, when generating a user identification ciphertext, the user's biometric features can be obtained, and the obtained biometric features can be hashed to obtain a first hash value, and then the trusted execution environment is called, and the first hash value is used as an encryption key to encrypt the second user identification information to generate a user identification ciphertext. Among them, the currently commonly used encryption algorithm can be used for encryption, and the present disclosure does not impose any restrictions on this. Therefore, in the user registration stage, the authenticity of the user is verified by the biometric features, and the user identification information is encrypted based on the biometric features to obtain the user identification ciphertext and filed in the cloud server, thereby ensuring the security of the user identification information.

[0080] Based on this, during the device network verification phase, it is necessary to obtain the user identification ciphertext filed during registration from the cloud server and decrypt it based on the biometric feature currently input by the user. Only after successful decryption can the second user identification information in plain text be obtained. Thus, in an optional embodiment of the present disclosure, when the electronic device detects that the user unlocks the device through a biometric feature (referred to as a target biometric feature for ease of description and distinction), the target biometric feature currently input by the user can be obtained, and a network access request can be generated based on the target biometric feature. The network access request carries the target biometric feature. After the LPA receives the network access request, it can obtain the target biometric feature from the network access request and perform a hash calculation on the target biometric feature to obtain a second hash value. It should be noted that the hash function used for the hash calculation of the target biometric feature is the same as the hash function used to generate the first hash value during the user registration phase described above. Then, the trusted execution environment is called, and the second hash value is used as the decryption key to decrypt the user identification ciphertext obtained from the cloud server. If the decryption is successful, the second user identification information obtained by decryption is used as the first user identification information. If the decryption fails, it can be determined that the user currently unlocking the electronic device is not a registered user of the eSIM network and cannot obtain the second user identification information filed during registration, so the Internet authentication process will not be initiated. Even if Internet authentication is initiated, since the second user identification information filed cannot be obtained, the calculated verification hash value cannot match the authentication hash value filed during the user registration phase, and the verification cannot pass, so the electronic device cannot access the eSIM network. Therefore, only the user who filed during user registration can decrypt and obtain the user identification information stored on the cloud server, and then generate a verification hash value to complete the Internet access through verification. For unfiled users, even if they can successfully unlock the electronic device, they cannot access the Internet. This is very practical in some scenarios, such as when children use their parents' mobile phones, it can prevent children from engaging in some inappropriate online activities.

[0081] Step 304: Upload the authentication hash value and the user identification ciphertext to the cloud server, and send the authentication hash value to the device security chip, wherein the authentication hash value is used to verify the verification hash value.

[0082] In this embodiment, the LPA uploads the obtained authentication hash value and user identification ciphertext to the cloud server and sends the authentication hash value to the device security chip so that the cloud server and the device security chip can respectively use the authentication hash value to verify the subsequently received verification hash value.

[0083] In addition, after receiving the authentication hash value, the cloud server binds it to the EID and IMSI of the profile uploaded by the LPA. The cloud server verifies the authentication hash value by matching it with the received verification hash value. If the authentication hash value matches the verification hash value, the verification hash value is determined to have passed. Based on the EID and IMSI bound to the matching authentication hash value, the corresponding profile is activated to activate the network. If the verification hash value fails, a lock is triggered and an alarm is issued.

[0084] The security authentication method for eSIM network access of the disclosed embodiment obtains the second eSIM identification information, the second device identification information and the second user identification information during the user registration stage, determines the authentication hash value based on the second eSIM identification information, the second device identification information and the second user identification information, calls the trusted execution environment to encrypt the second user identification information to generate a user identification ciphertext, and then uploads the authentication hash value and the user identification ciphertext to the cloud server, and sends the authentication hash value to the device security chip, wherein the authentication hash value is used to verify the verification hash value, thereby laying the foundation for verifying the verification hash value in the subsequent network access verification stage, and by calling the trusted execution environment to encrypt the second user identification information to generate a user identification ciphertext and then upload it to the cloud server for filing, the security of the user identification information is guaranteed, and the network access security can also be further guaranteed.

[0085] Figure 4 A schematic diagram of the system architecture of a method for implementing secure authentication of eSIM network access according to an exemplary embodiment of the present disclosure is shown. Figure 4 As shown, during the user registration phase, an authentication hash value is generated and stored locally in the device's security chip and on the cloud server, and the encrypted user identification information (i.e., user identification ciphertext) is filed with the cloud server. During the network access verification phase, the LPA obtains the eSIM identification information of the eUICC module, the device identification information of the SE module (e.g., chip ID, device ID), and the decrypted user identification information. Based on this information, a verification hash value is calculated and sent to the network (cloud server) and the device's security chip for verification. Only after both sides pass verification can the device access the Internet.

[0086] This disclosed solution is applicable not only to individual smartphone users but also to IoT devices. In the IoT device scenario, during the device binding phase, industrial sensors upload their SE chip ID and device ID via the carrier's API, binding the eSIM profile's EID / IMSI and the company's unified ID number to prevent unauthorized devices from accessing the monitoring network. During the network access phase, devices are only allowed to access the monitoring network after successful verification. If verification fails three times in a row, the cloud server automatically revokes the profile and notifies the administrator.

[0087] Furthermore, this solution complies with the 3GPP TS 33.201 security specification and supports the SM3 algorithm extension. Carrier servers can regularly push hash algorithm upgrades, allowing SM3 to replace SHA256. If a user loses their device, they can remotely revoke the five-tuple binding data and disable the profile through the app.

[0088] In order to implement the above embodiments, the present disclosure also provides a security authentication device for eSIM network access.

[0089] Figure 5 This is a schematic diagram of the structure of a secure authentication device for eSIM network access provided by an embodiment of the present disclosure. The device is implemented in software and / or hardware and can be integrated into an electronic device, specifically, the LPA of the electronic device.

[0090] like Figure 5 As shown, the security authentication device 50 for eSIM network access may include: an information acquisition module 510 , a determination module 520 and a sending module 530 .

[0091] The information acquisition module 510 is configured to acquire the first eSIM identification information, the first device identification information, and the first user identification information in response to receiving the network access request;

[0092] A determination module 520 is configured to determine a verification hash value based on the first eSIM identification information, the first device identification information, and the first user identification information;

[0093] The sending module 530 is used to send the verification hash value to the cloud server and the device security chip for verification. The cloud server activates the network when the verification hash value passes the verification, and the device security chip accesses the network when the verification hash value passes the verification.

[0094] Optionally, the eSIM network access security authentication device 50 further includes an information filing module for:

[0095] During the user registration phase, obtaining the second eSIM identification information, the second device identification information, and the second user identification information;

[0096] Determining an authentication hash value based on the second eSIM identification information, the second device identification information, and the second user identification information;

[0097] Invoking the trusted execution environment to encrypt the second user identification information to generate a user identification ciphertext;

[0098] The authentication hash value and user identification ciphertext are uploaded to the cloud server, and the authentication hash value is sent to the device security chip, where the authentication hash value is used to verify the verification hash value.

[0099] Further optionally, the information acquisition module 510 is further configured to:

[0100] Obtain the user identification ciphertext from the cloud server;

[0101] Calling the trusted execution environment to decrypt the user identification ciphertext to obtain second user identification information;

[0102] The second user identification information is determined as the first user identification information.

[0103] Optionally, the information filing module is further used to:

[0104] Obtaining the user's biometric characteristics;

[0105] Performing a hash calculation on the biometric feature to obtain a first hash value;

[0106] The trusted execution environment is called, and the second user identification information is encrypting by using the first hash value as an encryption key to generate a user identification ciphertext.

[0107] Further optionally, the network access request carries a target biometric feature, which is obtained when the electronic device detects that a user unlocks the device using the target biometric feature, and generates the network access request based on the target biometric feature; the information acquisition module 510 is further configured to:

[0108] Obtain target biometric features from the network access request;

[0109] Performing a hash calculation on the target biometric feature to obtain a second hash value;

[0110] Invoke the trusted execution environment and use the second hash value as a decryption key to decrypt the user identification ciphertext obtained from the cloud server;

[0111] If the decryption is successful, the second user identification information obtained by decryption is used as the first user identification information.

[0112] Optionally, the determining module 520 is further configured to:

[0113] Performing a hash operation on the first eSIM identification information, the first device identification information, and the first user identification information based on a preset hash function to obtain a target hash value;

[0114] The trusted execution environment is called to encrypt the target hash value, wherein the trusted execution environment encrypts the target hash value based on the locally stored initial counter value and initialization vector, obtains a verification hash value and returns it.

[0115] Optionally, the eSIM identification information includes at least one of an international mobile subscriber identity code and an eSIM embedded chip unique identifier, and the device identification information includes at least one of a device security chip identifier and a device unique identifier.

[0116] The security authentication device for eSIM network access of an electronic device provided in the embodiments of the present disclosure can execute the security authentication method for eSIM network access provided in the embodiments of the present disclosure, and has the corresponding functional modules and beneficial effects of executing the method. For matters not fully described in the embodiments of the present disclosure, reference can be made to the description of any method embodiment of the present disclosure.

[0117] An embodiment of the present disclosure further provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the secure authentication method for eSIM network access provided by any embodiment of the present disclosure.

[0118] According to one or more embodiments of the present disclosure, the present disclosure provides an electronic device, including:

[0119] processor;

[0120] a memory for storing instructions executable by the processor;

[0121] The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the secure authentication method for eSIM network access as provided in any embodiment of the present disclosure.

[0122] According to one or more embodiments of the present disclosure, the present disclosure provides a computer-readable storage medium storing a computer program for implementing the secure authentication method for eSIM network access provided in any embodiment of the present disclosure.

[0123] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0124] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.

[0125] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0126] The units involved in the embodiments described in this disclosure may be implemented in software or hardware, wherein the name of a unit does not necessarily limit the unit itself.

[0127] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0128] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0129] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also includes other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the above-mentioned disclosed concepts. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.

[0130] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details have been included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.

[0131] Although the subject matter has been described in language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims.

Claims

1. A security authentication method for eSIM network access, characterized in that: Applied to a local number assistant (LPA), the method includes: In response to receiving the network access request, obtaining first eSIM identification information, first device identification information, and first user identification information; Determining a verification hash value based on the first eSIM identification information, the first device identification information, and the first user identification information; The verification hash value is sent to the cloud server and the device security chip for verification. The cloud server activates the network if the verification hash value passes the verification, and the device security chip accesses the network if the verification hash value passes the verification.

2. The method for secure authentication of eSIM network access according to claim 1, wherein: The method further comprises: During the user registration phase, obtaining the second eSIM identification information, the second device identification information, and the second user identification information; Determining an authentication hash value based on the second eSIM identification information, the second device identification information, and the second user identification information; Invoking a trusted execution environment to encrypt the second user identification information to generate a user identification ciphertext; The authentication hash value and the user identification ciphertext are uploaded to the cloud server, and the authentication hash value is sent to the device security chip, wherein the authentication hash value is used to verify the verification hash value.

3. The method for secure authentication of eSIM network access according to claim 2, wherein: Obtaining first user identification information includes: Obtain the user identification ciphertext from the cloud server; Invoking the trusted execution environment to decrypt the user identification ciphertext to obtain the second user identification information; The second user identification information is determined as the first user identification information.

4. The method for secure authentication of eSIM network access according to claim 2, wherein: The calling of the trusted execution environment to encrypt the second user identification information to generate a user identification ciphertext includes: Obtaining the user's biometric characteristics; Performing a hash calculation on the biometric feature to obtain a first hash value; The trusted execution environment is called, and the second user identification information is encrypting by using the first hash value as an encryption key to generate the user identification ciphertext.

5. The method for secure authentication of eSIM network access according to claim 4, wherein: The network access request carries a target biometric feature, which is obtained when the electronic device detects that a user unlocks the device using the target biometric feature, and the network access request is generated based on the target biometric feature; The obtaining of the first user identification information includes: Obtaining the target biometric feature from the network access request; Performing a hash calculation on the target biometric feature to obtain a second hash value; Invoking the trusted execution environment and using the second hash value as a decryption key to decrypt the user identification ciphertext obtained from the cloud server; If the decryption is successful, the second user identification information obtained by decryption is used as the first user identification information.

6. The method for secure authentication of eSIM network access according to claim 1, wherein: The determining a verification hash value based on the first eSIM identification information, the first device identification information, and the first user identification information includes: Performing a hash operation on the first eSIM identification information, the first device identification information, and the first user identification information based on a preset hash function to obtain a target hash value; A trusted execution environment is called to encrypt the target hash value, wherein the trusted execution environment encrypts the target hash value based on a locally stored initial counter value and an initialization vector to obtain and return the verification hash value.

7. The method for secure authentication of eSIM network access according to any one of claims 1 to 6, wherein: The eSIM identification information includes at least one of the international mobile subscriber identity code and the unique identifier of the eSIM embedded chip, and the device identification information includes at least one of the device security chip identifier and the device unique identifier.

8. A security authentication device for eSIM network access, characterized in that: Applied to a local number assistant (LPA), the device includes: an information acquisition module, configured to acquire, in response to receiving a network access request, first eSIM identification information, first device identification information, and first user identification information; a determination module, configured to determine a verification hash value based on the first eSIM identification information, the first device identification information, and the first user identification information; The sending module is used to send the verification hash value to the cloud server and the device security chip for verification. The cloud server activates the network if the verification hash value passes the verification, and the device security chip accesses the network if the verification hash value passes the verification.

9. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the secure authentication method for eSIM network access according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and the computer program is used to implement the security authentication method for eSIM network access according to any one of claims 1 to 7.

Citation Information

Cited By

  • Security authentication method, device and equipment of eSIM (Embedded Subscriber Identity Module) and storage medium

    CN121692167A