A method for automatically switching priority of multiple sources based on eSIM

By employing an eSIM-based multi-source priority automatic handover method, which utilizes historical release performance data and a comprehensive scoring formula to select the optimal source, caches identity credentials, and maintains network consistency, the network handover problem for critical services in eSIM technology is solved, achieving efficient service continuity and security.

CN120935535BActive Publication Date: 2025-12-23GUANGDONG LEGEND COMM CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511453528.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-13
Publication Date
2025-12-23
Estimated Expiration
2045-10-13

AI Technical Summary

Technical Problem

In eSIM technology, how can we quickly select the most suitable information source without disclosing business content to ensure the network continuity and security of critical businesses such as financial payments, online banking, or government services, and avoid transaction failures and authentication link interruptions caused by network switching?

Method used

By collecting and analyzing historical release performance data from multiple information sources, candidate information sources are ranked using the comprehensive scoring formula U=PLK. When a critical business is initiated, the system switches to the information source with the highest score. At the same time, identity credentials and external network identifiers are cached to maintain consistency, and a session context transfer mechanism is used to ensure transaction continuity.

Benefits of technology

It significantly improves the success rate and reliability of critical business operations, reduces CAPTCHA loss and authentication interruptions, enhances user experience and business continuity, and is suitable for scenarios with high security requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120935535B_ABST
    Figure CN120935535B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on eSIM's multi-source priority automatic switching method, it is related to eSIM network switching field, including in terminal side identification user is about to initiate service whether belong to preset key service, key service includes financial payment or bank online banking or government service;Collect the historical release performance data of multiple different candidate sources in eSIM under key service, release performance data includes transaction one-time pass rate, SMS or voice verification code receiving rate and source network consistency rate;Based on the release success ability of candidate source in target service in historical release performance data is sorted;When detecting key service initiation, priority is sorted according to sorting.The application first uses the historical release performance data of key service as the core basis of network switching and priority sorting, so as to solve the problem that the traditional only depends on signal strength or time delay causes verification code receiving failure, identity discontinuity, transaction is rejected by background in key service.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of eSIM network switching, and more particularly to an eSIM-based multi-source priority automatic switching method. BACKGROUND

[0002] In eSIM technology, the eUICC (embedded universal integrated circuit card) of a terminal device supports the storage of multiple operator profiles at the same time, each profile being equivalent to a virtual SIM card and being able to independently provide network access capability. Unlike a traditional SIM card, which can only be fixedly bound to a single operator, the multi-profile feature of eSIM enables the terminal to flexibly switch to the most suitable source according to business needs, network environment or compliance requirements. More importantly, such switching does not require physical card replacement, but can be completed through software instructions, thereby far exceeding traditional SIM cards in terms of switching speed, manageability and automation.

[0003] As mentioned above, a mobile terminal can manage multiple operator sources simultaneously under the condition of eSIM, and can obtain continuous mobile data services between different networks through access and switching. Unlike daily entertainment or information access, financial payment, bank online banking and government services belong to key businesses that are extremely sensitive to security compliance and authentication links: background risk control usually determines risk based on source IP / ASN and regional information, and transaction processes are highly dependent on SMS or voice verification code reception and timeliness, and require network sources to remain consistent within a transaction window. If only general indicators such as throughput and latency are used to select or switch networks, the transaction pass rate may decrease, the SMS or voice verification code reception rate may fluctuate, and even the session may be interrupted and re-verified due to switching. At the same time, the terminal cannot accurately determine the release pass ability of each candidate source at the moment of initiating a key business, and lacks a mechanism for structuring historical release performance data for real-time sorting and access priority adjustment. How to build an executable evaluation system around observable quantities such as transaction pass rate, SMS or voice verification code reception rate without revealing the content of the business, and quickly select a candidate source that is more conducive to release at the initiation of a key business, while avoiding authentication link interruption caused by switching, is a problem that needs to be solved in this field. SUMMARY

[0004] The technical problem to be solved by the present application is to provide an eSIM-based multi-source priority automatic switching method to solve the problems mentioned in the background.

[0005] In order to achieve the above-mentioned purpose, the present application adopts the following technical scheme:

[0006] An eSIM-based multi-source priority automatic switching method, comprising the following steps:

[0007] identifying whether a service to be initiated by a user belongs to a preset critical service including financial payment or bank online banking or government service at a terminal side;

[0008] collecting historical release performance data of a plurality of different candidate sources in the eSIM under the critical service, the historical release performance data including transaction one-time pass rate, SMS or voice verification code receiving rate, and source network consistency rate;

[0009] sorting release success ability of the candidate sources in the target service based on the historical release performance data;

[0010] when detecting initiation of the critical service, performing priority sorting according to the sorting.

[0011] In some embodiments, the process of sorting the candidate sources includes:

[0012] collecting transaction one-time pass rate P, source network consistency rate L, and SMS or voice verification code receiving rate K of the candidate sources under each critical service; the source network consistency rate is used to represent the probability of maintaining the same IP address in a one-time critical service transaction;

[0013] and calculating the comprehensive score based on the following formula U :

[0014] U = PLK;

[0015] sorting the candidate sources according to the comprehensive score, and selecting the source with the highest score as the optimal source.

[0016] In some embodiments, the method further includes: selecting the candidate source with the smallest average transaction completion delay from the top N candidate sources as the final accessed source.

[0017] In some embodiments, the terminal caches identity credential information of the current session before switching, and replays the identity credential to restore the authentication link of the service session after switching to a new source.

[0018] In some embodiments, the identity credential information includes Cookie, Token, and TLS session ticket.

[0019] In some embodiments, before switching, the external network identifier of the terminal is mapped to a preset compliant egress address or an encrypted tunnel identifier recorded by the operator; after switching, the compliant egress address or tunnel identifier is continued to be used for external communication, so that consistent source identity is maintained in the background system of financial payment or government service.

[0020] In some embodiments, when a source switch occurs during execution of a critical service, the terminal maintains transaction continuity through a session context transfer mechanism, which includes:

[0021] exporting a context snapshot of the current transaction before the switch, the context snapshot including a transaction identifier, authentication progress, verification code status, and a session sequence number;

[0022] resuming the transaction state in a new session based on the context snapshot after switching to the new source.

[0023] In some embodiments, the candidate sources correspond to multiple operator profiles in the eUICC, and a critical service compliance label is set in the profiles, the label being used to identify a compliant source suitable for financial payment or government service, and when a critical service is detected, the profile with the label is activated preferentially.

[0024] In some embodiments, collecting historical release performance data of different candidate sources under the critical service includes:

[0025] recording access logs of each candidate source in a critical service transaction in the terminal or a background system;

[0026] statistically analyzing transaction one-time pass rate, SMS or voice verification code reception results, and source network consistency rate based on the logs;

[0027] storing the historical release performance data in a time series manner.

[0028] In some embodiments, the method further includes pre-screening candidate sources based on rules, the rules including whether the network protocol required by the target service is supported; and collecting historical release performance data only for candidate sources that meet the rules.

[0029] The advantages of the present application over the prior art are that by introducing historical release performance data as the core evaluation basis for network switching, the limitations of traditional network selection relying only on general indicators such as delay are effectively solved, the transaction success rate and reliability in key business such as financial payment are significantly improved, for example, the loss of verification code or interruption of identity verification caused by network mismatch is reduced, ensuring smooth user operation and reducing security risks. At the same time, further through the comprehensive scoring formula combined with the transaction one-time pass rate, source network consistency rate and SMS or voice verification code receiving rate for sorting, the optimal source is selected, thereby optimizing the release capability in multiple dimensions and avoiding the amplification of single weak point to the overall failure probability. In addition, in the switching process, identity credentials such as Cookie or Token are cached and the session is recovered, and the external network identifier is mapped to the compliant export address, maintaining the consistency of the source identity, preventing the background system from misjudging as abnormal behavior, and improving the business continuity; the session context transfer mechanism derives the transaction snapshot including the authentication progress and the verification code state, and restores the state in the new source, further reducing the reset demand caused by interruption and improving the user experience; the pre-screening rules and compliance labels ensure the applicability of the source, combined with the historical data statistics stored in time sequence, the decision is more accurate and dynamically adapts to changes. These improvements collectively enhance the robustness of the eSIM multi-source environment, suitable for scenarios with high security requirements. BRIEF DESCRIPTION OF DRAWINGS

[0030] Figure 1 is the overall structure diagram of the present application;

[0031] Figure 2 is the sorting and selection structure diagram of the present application;

[0032] Figure 3 is the session continuity schematic diagram of the present application;

[0033] Figure 4 is the data collection schematic diagram of the present application. DETAILED DESCRIPTION

[0034] The specific embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0035] The present application provides a multi-source priority automatic switching method based on eSIM, which aims to optimize the network access strategy of terminal equipment when processing key business, and ensure smooth business and maintain identity consistency.

[0036] Traditional network switching often only focuses on general indicators such as latency or signal strength, however, when it comes to key businesses such as financial payment, bank online banking or government service, these indicators may not be sufficient to ensure transaction success, because such businesses have higher requirements for release efficiency and identity continuity. For example, in the process of financial payment, if the verification code receiving fails or the source identity changes due to network source or network switching, the background system may regard it as an exception and refuse the transaction, thereby affecting user experience and security.

[0037] To solve the above problems, as shown in the present application includes terminal side business identification, historical release performance data collection and processing, candidate source sorting and priority adjustment and other steps. Figure 1

[0038] More specifically, the method of the present application solves this problem by introducing historical release performance data as the core evaluation basis. Specifically, the method of the present application first identifies at the terminal side whether the business to be initiated by the user belongs to the pre-set key business, which specifically refers to sensitive operations such as financial payment, bank online banking or government service. The identification process can be achieved by monitoring the starting behavior or API call of the application program, for example, when the user opens the bank application and navigates to the transfer interface, the operating system or embedded software module of the terminal will analyze the application's intent label or URL pattern to determine whether it matches the pre-set key business list. This list can be pre-stored in the local database of the terminal and updated from the server regularly to obtain the latest definition to adapt to business changes.

[0039] ​Once the critical transaction is confirmed to be initiated, or in the preparatory stage before the critical transaction occurs, the method of the present application collects historical release performance data of different candidate sources under the critical transaction. These candidate sources usually correspond to multiple operator profiles in the eUICC, each of which represents an activatable SIM card configuration supporting network access of different operators. The historical release performance data includes transaction one-time pass rate, SMS or voice verification code reception rate, and source network consistency rate. Among them, the transaction one-time pass rate reflects the success rate of completing the transaction in the first attempt, for example, in financial payment, whether the complete process from submitting an order to confirming the receipt is uninterrupted; the SMS or voice verification code reception rate measures the reliability of the verification code from the server to the terminal, which is crucial in two-factor authentication; the source network consistency rate is used to represent the probability of maintaining the same IP address in a critical transaction, avoiding identity verification failure due to IP changes. The reason why IP may jump is that operators usually use large-scale NAT technology in the core network to save public IPv4 addresses, and the user's session may be allocated to a new external IP address due to NAT port multiplexing or gateway migration, thus presenting different source information at different stages of a transaction. On the other hand, the network may temporarily change the export gateway when load balancing, link redundancy or regional switching, causing the user's public network address to jump. For IPv6 scenarios, the terminal address may be automatically updated in a short time due to privacy extension mechanisms, further exacerbating the instability of external source identification.

[0040] The collection of these data requires recording the access log of each candidate source in the critical transaction in the terminal or background system, as shown in FIG. 4. In specific implementation, the terminal can maintain a log database, and record the transaction start time, end time, used source, one-time pass, verification code reception, and IP address change record after each critical transaction is executed.

[0041] Based on these logs, the system can calculate the transaction one-time pass rate, such as the number of successful transactions in the past 30 days divided by the total number of transactions; the SMS or voice verification code reception rate is obtained by recording the ratio of sending requests and successful reception; the source network consistency rate can be calculated by the proportion of unique IP addresses within the transaction period. These statistical results are stored in time series, for example, using SQLite database to save locally in the terminal, grouped by date and source, facilitating subsequent query and analysis. This time series storage allows the system to capture trend changes, for example, if a certain source performs poorly during peak hours, recent data can be considered in the sorting.

[0042] Further, as shown in FIG. 2, after collecting data, the application ranks the candidate sources on the success of releasing in the target service based on historical release performance data. The specific ranking process involves collecting the transaction one-time pass rate P, the source network consistency rate L, and the short message or voice verification code receiving rate K of the candidate source under each key service. These indicators can be extracted from the above-mentioned logs, for example, P is equal to the number of successful transactions divided by the total number of transactions, L is equal to the number of transactions maintaining the same IP divided by the total number of transactions, and K is equal to the number of transactions successfully receiving the verification code divided by the number of transactions involving the verification code.

[0043] Then, a comprehensive score is calculated using the formula U = PLK, which multiplies the three indicators to emphasize that any weakness in a single indicator will significantly reduce the overall score, thus prioritizing sources that perform well in all aspects. After calculation, the candidate sources are ranked from high to low according to the comprehensive score, and the source with the highest score is selected as the optimal source. For example, if there are three candidate sources A, B, and C with scores of 0.9, 0.85, and 0.7 respectively, A is selected as the optimal source. This multiplication formula is more suitable than addition because it amplifies multidimensional risks and avoids overall collapse due to a single failure point in key services.

[0044] Upon detecting the initiation of a key service, such as a user clicking a payment button, the system prioritizes according to this ranking and automatically switches to the optimal source. The switching here utilizes the dynamic activation function of eSIM, activating the corresponding profile through eUICC manager API call to ensure seamless access.

[0045] In addition, the method of the application also includes selecting the candidate source with the smallest average transaction completion time from the top N candidate sources as the final access source. Here, N can be set to 3 or 5 and dynamically adjusted according to terminal configuration. The motivation is that although release performance data is the primary consideration, latency also affects user experience at the same performance level. For example, when the top three scores are similar after ranking, the system further queries the average latency data of each source, which can be statistically obtained from historical logs such as the average completion time of past transactions. Then, the source with the smallest latency is selected as the final source, achieving a balance between release capability and efficiency.

[0046] To further improve reliability, the method of the application performs pre-screening on candidate sources based on rules before collecting historical release performance data. These rules include whether they meet the network protocol requirements of the target service, such as financial payment which may require support for TLS 1.3 or specific encryption standards. Pre-screening is achieved by checking the metadata in the eUICC profile, and only collecting historical data for candidate sources that meet the rules to avoid invalid calculations and improve efficiency. For example, if a source does not support IPv6 but the service requires it, it is directly excluded.

[0047] Further, as shown in FIG. 3, during the execution of critical services, if source switching occurs, for example due to signal attenuation or load balancing, the method of the present application provides multiple mechanisms to ensure identity consistency and transaction continuity.

[0048] First, when switching occurs, the terminal caches the identity credential information of the current session before switching, and replays the identity credentials after switching to the new source to restore the authentication link of the service session. Identity credential information includes Cookie, Token or TLS session ticket. These credentials are exported before switching through the session management module of the browser or application, for example, saving Cookie using WebStorage API, or extracting Token from HTTP response header. After switching, the terminal injects these credentials when establishing a new connection, for example, attaching Cookie header or Authorization header carrying Token when sending a request, so that the background server considers that the session is not interrupted. The motivation of this mechanism is to prevent the need for re-authentication caused by switching, especially in financial payments, repeated authentication may trigger risk control alarms.

[0049] Second, when source switching occurs during the execution of critical services, before switching, the external network identifier of the terminal is mapped to a preset compliant egress address or an encrypted tunnel identifier recorded by the operator; after switching, the external communication continues to use the compliant egress address or tunnel identifier, thereby maintaining consistent source identity in the background system of financial payment or government service. External network identifier usually refers to IP address or NAT egress. The mapping process can be implemented through VPN or proxy service, for example, the terminal is preconfigured with a compliant egress address, such as a fixed IP pool provided by the operator, and the current traffic is routed to this address before switching. After switching, the traffic of the new source is also forced to pass through the same egress, ensuring that the background sees the same source IP. This way solves the identity consistency problem, because many critical business backends rely on IP as an auxiliary identity verification, if the IP changes, it may be considered as a fraud attempt. The encrypted tunnel identifier involves the use of tunnels such as IPsec or WireGuard, the terminal establishes a tunnel before switching, and records the tunnel ID to the operator, and after switching, the same tunnel ID is reused.

[0050] In addition, the terminal maintains transaction continuity through a session context transfer mechanism when a source switch occurs during the execution of a critical service. This mechanism includes exporting a context snapshot of the current transaction before the switch, which includes the transaction identifier, authentication progress, verification code status, and session sequence number. For example, the transaction identifier can be a unique UUID, the authentication progress record is like "password verification passed, verification code not passed", the verification code status includes the received verification code value and the validity period, and the session sequence number is used to prevent replay attacks. The export process serializes these data into JSON format and temporarily stores them in the terminal memory or an encrypted file. After switching to a new source, the transaction state is restored in the new session based on the context snapshot, such as carrying these data when sending a recovery request to let the server rebuild the session. This mechanism ensures that the transaction does not start from scratch, especially in government services such as online application switching in the middle, avoiding repeated user input of information.

[0051] Further, the method of the present application corresponds to multiple operator profiles in the eUICC, and sets a critical service compliance label in the profile, which is used to identify a compliant source suitable for financial payment or government service, such as a label value of "financial_compliant" indicating that the relevant compliance certification is passed. When detecting the initiation of a critical service, the profile with the compliance label is activated preferentially. In specific implementation, the eUICC management software filters the profiles before sorting, only the labeled ones are scored, if there is no label source with higher score, it can also be used as an alternative, but the priority is reduced. This label setting can be embedded by the operator when issuing the profile, and the terminal can query the label value through API to ensure compliance priority.

[0052] The implementation of the method of the present application depends on the software framework of the terminal, such as integrating the eSIM management module and the log recording service in the Android or iOS system. The data storage uses a local database to protect privacy, and a background system can be selected to aggregate multi-terminal data, but it needs to comply with data protection regulations. The update of historical data can be performed periodically, such as once a day, to reflect network changes. Through these detailed steps, the method not only improves the success rate of critical services, but also maintains identity continuity in switching scenarios, avoiding the failure risk caused by ignoring the release performance in traditional methods. In actual deployment, the terminal can further integrate a user feedback mechanism, such as allowing the user to manually mark if the transaction fails after switching, to optimize future data collection and sorting logic, thereby forming a closed-loop improvement.

[0053] To make the collection process more accurate, the records of the access log can be subdivided into multiple fields: transaction type such as payment or login, source ID, start timestamp, end timestamp, pass flag 0 or 1, verification code reception flag, IP change count, etc. When counting, a weighted average is used, for example, recent data is given a higher weight, such as 0.6 for the past 7 days and 0.4 for the past 30 days, to capture dynamic changes. The pre-screening rule can also be extended to check the compliance history of the source, for example, if a certain source has been blacklisted in the past, it is excluded. The sorting algorithm can introduce a threshold, if the highest score is lower than 0.5, prompt the user to check the network or delay the service initiation.

[0054] In terms of identity credential caching, the specific replay process needs to consider security, such as using encrypted storage credentials to avoid plaintext leakage. The replay of the TLS session ticket can be achieved by restoring the TLS context, using libraries such as OpenSSL to simulate session recovery on the terminal side. For context snapshots, sequence number consistency needs to be verified when restoring to prevent man-in-the-middle attacks. The mapping of compliant egress addresses can be combined with SD-WAN technology to achieve intelligent routing and ensure that all critical traffic passes through a fixed path.

[0055] In addition, in the eUICC profile management, the compliance label can be dynamically updated by pushing new labels through a remote management platform, and timely adjustments can be made when new regulations are introduced. The priority activation process involves fast switching of eSIM, usually completed within a few seconds, avoiding service interruption. The overall method is highly scalable, for example, in the future, 5G slicing technology can be integrated to extend the source to a dedicated network slice, further optimizing the performance of critical services.

[0056] The method of the present application can significantly improve the success rate of payment in practical scenarios such as mobile banking applications, while maintaining seamless session switching and reducing user frustration. The time series method of log storage allows for advanced analysis, such as using a simple trend prediction model to calculate future performance on the terminal, but without the need for complex machine learning, based only on linear regression.

[0057] In summary, the present application provides a new type of priority switching method specifically for financial payment, bank online banking or government services, effectively filling the gap in this field.

[0058] The above is only the preferred embodiment of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can make equivalent substitutions or changes within the scope of the technical disclosure of the present application according to the technical solution and inventive concept of the present application, which should be covered within the protection scope of the present application.

Claims

1. A method for automatic handover of multiple information source priorities based on eSIM, characterized in that, Includes the following steps: On the terminal side, it is possible to identify whether the service that a user is about to initiate belongs to a preset key service, which includes financial payment, online banking, or government services. Collect historical release performance data of multiple different candidate information sources in eSIM under the key service. The historical release performance data includes transaction first pass rate, SMS or voice verification code reception rate and source network consistency rate. The candidate information sources are ranked based on their historical release performance data to assess their success rate in releasing information in the target service. When a critical business activity is detected, it is prioritized according to the aforementioned sorting.

2. The method for automatic handover of multiple information source priorities based on eSIM according to claim 1, characterized in that, The process of ranking candidate information sources includes: The candidate information sources are collected for the transaction first-pass rate P, the source network consistency rate L, and the SMS or voice verification code reception rate K under each key business; the source network consistency rate is used to characterize the probability of maintaining the same IP address in a key business transaction; The comprehensive score is calculated based on the following formula. U : U=PLK; The candidate sources are ranked according to the comprehensive score, and the source with the highest score is selected as the optimal source.

3. The method for automatic handover of multiple information source priorities based on eSIM according to claim 1, characterized in that, The method further includes: selecting the candidate source with the smallest average transaction completion latency from the top N candidate sources as the final access source.

4. The method according to claim 1, characterized in that, When a source switch occurs during the execution of critical business operations, the terminal caches the identity credential information of the current session before the switch and replays the identity credential after switching to the new source to restore the authentication link of the business session.

5. The method for automatic handover of multiple information source priorities based on eSIM according to claim 4, characterized in that, The identity credentials include cookies, tokens, and TLS session tickets.

6. The method according to claim 1, characterized in that, When a source switch occurs during the execution of critical business operations, the external network identifier of the terminal is mapped to a preset compliant exit address or an encrypted tunnel identifier registered with the operator before the switch. After the switch, continue to use the compliant exit address or tunnel identifier for external communication, thereby maintaining a consistent source identity in the back-end systems of financial payments or government services.

7. The method according to claim 1, characterized in that, When a source switch occurs during the execution of critical business operations, the terminal maintains transaction continuity through a session context transfer mechanism, which includes: Before switching, export a context snapshot of the current transaction, which includes the transaction identifier, authentication progress, verification code status, and session sequence number; After switching to the new information source, the transaction state is restored in the new session based on the context snapshot.

8. The method according to claim 1, characterized in that, The candidate information sources correspond to multiple operator profiles in eUICC, and key business compliance tags are set in the profiles. The key business compliance tags are used to identify compliant information sources suitable for financial payments or government services. When a key business is detected, the profile with the compliance tag is activated first.

9. The method according to claim 1, characterized in that, The historical release performance data of different candidate information sources under the aforementioned critical service includes: Record the access logs of each candidate information source in critical business transactions in the terminal or back-end system; Based on the log statistics, the transaction first-pass rate, SMS or voice verification code reception results, and source network consistency rate are analyzed. The historical release performance data is stored in a time-series format.

10. The method according to claim 9, characterized in that, The method also includes pre-screening candidate information sources based on rules, including whether they meet the network protocol support requirements of the target service; and collecting historical release performance data only for candidate information sources that meet the rules.

Citation Information

Patent Citations

  • Vehicle adaptive network switching and traffic sharing method based on multi-source cooperation

    CN120224321A

  • Subscriber tag-based shunting method and system in 5g network

    WO2017004858A1