Method and related device for authenticating and updating eUICC firmware version

By introducing a group event identification mechanism and a single communication connection, efficient firmware version updates and two-way authentication for multiple eUICCs are achieved, solving the problems of cumbersome event registration and low efficiency in existing technologies, and improving the efficiency of eUICC management.

CN113407204BActive Publication Date: 2025-10-21HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110530603.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2017-06-07
Publication Date
2025-10-21
Estimated Expiration
2037-06-07

AI Technical Summary

Technical Problem

In the eUICC remote management system, the event registration and two-way authentication processes in the existing technology are cumbersome and inefficient. Especially when multiple eUICCs are connected at the same time, it is impossible to efficiently manage and update the firmware version.

Method used

A group event identification mechanism is introduced to find the target event record by receiving information from the terminal device and send it to multiple eUICCs, simplifying the event registration process; at the same time, the remote server establishes a communication connection with the terminal device to realize bidirectional authentication between two eUICCs.

Benefits of technology

It improves the efficiency of eUICC firmware version updates, simplifies the event registration process, and saves time during two-way authentication, thereby improving operational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113407204B_ABST
    Figure CN113407204B_ABST
Patent Text Reader

Abstract

A method for authenticating updating of eUICC firmware version and related device. The method comprises the following steps: receiving first information sent by a terminal device, wherein the first information comprises a target identifier (S101); searching for a target event record in a currently saved event record, wherein a group event identifier in the target event record matches the target identifier in the first information (S102); sending the target event record to the terminal device (S103), wherein the target event record is used to make the terminal device download an eUICC firmware version update package (S104), and update a firmware version of an eUICC of the terminal device according to the eUICC firmware version update package (S105). By using the method, the event registration process and the two-way authentication process when providing the eUICC firmware version update service can be simplified, and the efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of telecommunication smart cards, and in particular to a method and related apparatus for authenticating and updating an eUICC firmware version. Background Art

[0002] The embedded Universal Integrated Circuit Card (eUICC) is a third-generation telecom smart card that can securely perform remote profile management or local profile management (for example, profile activation, deactivation, or deletion triggered by the terminal device user). The term eUICC originates from the term embedded UICC. It can be a single chip embedded in a terminal device or part of another single chip in the terminal device. However, this does not necessarily mean that it must be embedded in the terminal device and cannot be removed. It can also be a removable card, such as a Subscriber Identification Module (SIM), Micro SIM, or Nano SIM card.

[0003] In the architecture of the eUICC remote management / configuration system, remote servers include the Subscription Manager Data Preparation+ (SM-DP+) server, the Subscription Manager Discovery Service (SM-DS) server, the Operation System Patch Server (OPS), and other servers that provide services to or interact with terminal devices. The SM-DS, also known as the Event Management Server, is used to register events based on event registration requests from other remote servers and, upon receiving a query from a terminal device, send corresponding event records to the terminal device. This allows the terminal device to establish a connection with the corresponding remote server using the remote server address in the event record and perform the corresponding operation. Events include, but are not limited to, Profile download events and Remote Profile Management (RPM) events. Currently, event registration and distribution by the SM-DS server are one-to-one, meaning that one event record corresponds to only one eUICC. In scenarios where a service corresponds to multiple eUICCs, such as an eUICC firmware update service, the remote server providing the eUICC firmware update service needs to initiate multiple event registration requests to the SM-DS, causing the SM-DS to register multiple event records corresponding to the multiple eUICCs, which is cumbersome. Furthermore, if a terminal device has two or more eUICCs and both of them establish connections to the same remote server at the same time, the two or more eUICCs need to perform bidirectional eUICC authentication with the remote server separately, which is inefficient. Summary of the Invention

[0004] The present application provides a method and related apparatus for authenticating and updating the eUICC firmware version, which can simplify the event registration process and the two-way authentication process when providing the eUICC firmware version update service, thereby improving efficiency.

[0005] A first aspect of an embodiment of the present application provides a method for updating an eUICC firmware version, including:

[0006] receiving first information sent by a terminal device, where the first information includes a target identifier;

[0007] Searching for a target event record in currently saved event records, wherein a group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0008] The target event record is sent to the terminal device, where the target event record is used to enable the terminal device to download the eUICC firmware version update package.

[0009] In a first aspect of an embodiment of the present application, a target event record stores a group event identifier. One group event identifier can correspond to multiple eUICCs. That is, the target event record can be sent to multiple eUICCs corresponding to the group event identifier, so that the eUICC corresponding to the group event identifier downloads the eUICC firmware version update package. The eUICC firmware version update service is provided to multiple eUICCs. The group event identifier solves the problem of needing to register multiple events when registering an event.

[0010] In a first possible implementation of the first aspect, the receiving terminal device also includes: receiving an event registration request sent by an update server, wherein the event registration request carries the group event identifier; and saving the group event identifier in an event record according to the event registration request.

[0011] In a second possible implementation manner of the first aspect, the group event identifier further includes a customized identifier or a country code.

[0012] In a third possible implementation manner of the first aspect, the target identifier includes at least one of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

[0013] In a fourth possible implementation manner of the first aspect, the customized identifier includes additional issuer information or a personal identification code in a preset customized position.

[0014] In a fifth possible implementation manner of the first aspect, the target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC;

[0015] Searching for a target event record in the currently saved event records includes: searching for a first event record and a second event record in the currently saved event records, respectively, wherein a group event identifier in the first event record matches the first target identifier, and a group event identifier in the second event record matches the second target identifier; and sending the target event record to the terminal device includes: sending the first event record and the second event record to the terminal device, the first event record being used to enable the terminal device to download a first eUICC firmware version update package for the first eUICC, and the second event record being used to enable the terminal device to download a second eUICC firmware version update package for the second eUICC.

[0016] A second aspect of an embodiment of the present application provides another method for updating an eUICC firmware version, including:

[0017] Sending first information to an event management server, where the first information includes a target identifier;

[0018] receiving a target event record obtained by the search and sent by the event management server, wherein a group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0019] Download the eUICC firmware version update package according to the target event record;

[0020] Update the eUICC firmware version according to the eUICC firmware version update package.

[0021] In a second aspect of the embodiment of the present application, an eUICC firmware version update package is downloaded according to the target event record and the firmware version of the eUICC is updated to implement the update of the firmware version of the eUICC.

[0022] In a first possible implementation manner of the second aspect, the group event identifier may further include a customized identifier or a country code.

[0023] In a second possible implementation manner of the second aspect, the target identifier includes at least one of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

[0024] In a third possible implementation manner of the second aspect, the customized identifier includes additional issuer information or a personal identification code in a preset customized position.

[0025] In a fourth possible implementation of the second aspect, the target identifier includes a first target identifier of a first eUICC and a second target identifier of a second eUICC; receiving the target event record obtained by the search and sent by the event management server includes: receiving the first event record and the second event record obtained by the search and sent by the event management server, wherein a group event identifier in the first event record matches the first target identifier, and a group event identifier in the second event record matches the second target identifier; downloading the eUICC firmware version update package according to the target event record includes: downloading a first eUICC firmware version update package for the first eUICC according to the first event record; and downloading a second eUICC firmware version update package for the second eUICC according to the second event record; and updating the firmware version of the eUICC according to the eUICC firmware version update package includes: updating the firmware version of the first eUICC according to the first eUICC firmware version update package; and updating the firmware version of the second eUICC according to the second eUICC firmware version update package.

[0026] In a fifth possible implementation of the second aspect, downloading the eUICC firmware version update package according to the target event record includes: extracting an update server address from the target event record; sending the current eUICC firmware version to the update server; and receiving the eUICC firmware version update package sent by the update server based on the current eUICC firmware version.

[0027] In a sixth possible implementation of the second aspect, before the receiving the eUICC firmware version update package sent by the update server based on the current eUICC firmware version, the method further includes: sending second information to the update server, where the second information includes a target identifier; and the receiving the eUICC firmware version update package sent by the update server based on the current eUICC firmware version includes: receiving the eUICC firmware version update package sent by the update server based on the current eUICC firmware version when the target identifier in the second information matches a group event identifier stored in the update server.

[0028] In a seventh possible implementation manner of the second aspect, after updating the eUICC firmware version according to the eUICC firmware version update package, the method further includes: updating the eUICC firmware version in the eUICC information.

[0029] In an eighth possible implementation manner of the second aspect, updating the eUICC firmware version in the eUICC information includes: updating the eUICC firmware version in the eUICC information according to first data in the eUICC firmware version update package, where the first data includes a target firmware version.

[0030] In a ninth possible implementation of the second aspect, after sending the current firmware version to the update server, the method further includes: receiving second data sent by the update server, where the second data includes a target firmware version; and updating the eUICC firmware version in the eUICC information includes: updating the eUICC firmware version in the eUICC information according to the second data.

[0031] A third aspect of the embodiments of the present application provides another method for updating the eUICC firmware version, including:

[0032] Sending first information to an event management server, where the first information includes a target identifier;

[0033] receiving a target event record obtained by the search and sent by the event management server, wherein a group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0034] Download the eUICC firmware version update package according to the target event record;

[0035] The eUICC firmware version update package is sent to the eUICC, where the eUICC firmware version update package is used by the eUICC to update the firmware version of the eUICC.

[0036] In a third aspect of the embodiment of the present application, an eUICC firmware version update package is downloaded according to the target event record and the eUICC firmware version update package is sent to the eUICC, so that the eUICC completes the update of its own firmware version.

[0037] In a first possible implementation of the third aspect, the target identifier includes a first target identifier of a first eUICC and a second target identifier of a second eUICC; the receiving the target event record obtained by the search and sent by the event management server includes: receiving the first event record and the second event record obtained by the search and sent by the event management server, wherein a group event identifier in the first event record matches the first target identifier, and a group event identifier in the second event record matches the second target identifier; the downloading the eUICC firmware version update package according to the target event record includes: downloading a first eUICC firmware version update package for the first eUICC according to the first event record; and downloading a second eUICC firmware version update package for the second eUICC according to the second event record; and the sending the eUICC firmware version update package to the eUICC includes: sending the first eUICC firmware version update package to the first eUICC, where the first eUICC firmware version update package is used by the first eUICC to update the eUICC firmware version of the first eUICC; and sending the second eUICC firmware version update package to the second eUICC, where the second eUICC is used by the second eUICC to update the eUICC firmware version of the second eUICC.

[0038] In a second possible implementation of the third aspect, before downloading the first eUICC firmware version update package of the first eUICC according to the first event record, the method further includes: sending the first event record to the first eUICC according to the first eUICC identifier; and before downloading the second eUICC firmware version update package of the second eUICC according to the second event record, the method further includes: obtaining a second eUICC identifier of the second eUICC; and sending the second event record to the second eUICC according to the second eUICC identifier.

[0039] In a third possible implementation of the third aspect, the downloading, according to the first event record, the first eUICC firmware version update package for the first eUICC includes: while downloading the first eUICC firmware version update package for the first eUICC according to the first event record, further receiving a first eUICC identifier sent by an update server corresponding to the first eUICC; the downloading, according to the second event record, the second eUICC firmware version update package for the second eUICC includes: while downloading the second eUICC firmware version update package for the second eUICC according to the second event record, further receiving a second eUICC identifier sent by the update server corresponding to the second eUICC; the sending, according to the first eUICC firmware version update package for the first eUICC includes: sending, according to the first eUICC identifier, the first eUICC firmware version update package for the first eUICC; and the sending, according to the second eUICC firmware version update package for the second eUICC includes: sending, according to the second eUICC identifier, the second eUICC firmware version update package for the second eUICC.

[0040] A fourth aspect of the embodiments of the present application provides another method for updating the eUICC firmware version, including:

[0041] Sending an event registration request to an event management server, wherein the event registration request carries a group event identifier, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0042] The event registration request is used to enable the event management server to save the group event identifier in an event record, and send the event record to the terminal device when receiving first information sent by a terminal device matching the group event identifier.

[0043] In a fourth aspect of the embodiments of the present application, an event registration request carries a group event identifier, which includes at least one eUICC firmware version and at least one issuer identifier. Both the eUICC firmware version and the issuer identifier can correspond to multiple eUICCs. Registering only one event can correspond to multiple eUICCs, thus resolving the problem of needing to register multiple events in order to provide services to multiple terminal devices.

[0044] In a first possible implementation manner of the fourth aspect, after sending the event registration request to the event management server, the further step includes: receiving a current eUICC firmware version of the terminal device sent by the terminal device; determining, based on the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device to a target firmware version; and sending the eUICC firmware version update package to the terminal device, where the eUICC firmware version update package is used by the terminal device to update the firmware version of the eUICC of the terminal device.

[0045] In a second possible implementation of the fourth aspect, determining, based on the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device to a target firmware version includes: receiving second information sent by the terminal device, the second information including eUICC performance and an eUICC firmware version; and, if it is determined that the eUICC performance and the eUICC firmware version meet performance and firmware version requirements of the target firmware version, determining, based on the current eUICC firmware version, the eUICC firmware version update package required for updating the eUICC of the terminal device to the target firmware version.

[0046] In a third possible implementation of the fourth aspect, the second information further includes a target identifier; and determining, based on the current eUICC firmware version, an eUICC firmware version update package required to update the eUICC of the terminal device to a target firmware version includes: determining whether the eUICC performance and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version when the target identifier in the second information matches the locally stored group event identifier.

[0047] A fifth aspect of the embodiments of the present application provides a bidirectional authentication method, including:

[0048] Receiving first eUICC information of a first eUICC of a terminal device and second eUICC information of a second eUICC of the terminal device;

[0049] determining target verification information according to the first eUICC information and the second eUICC information;

[0050] Sending first authentication information to the terminal device, wherein the first authentication information includes the target verification information;

[0051] receiving second authentication information sent by the terminal device after the first eUICC and the second eUICC successfully verify the first authentication information;

[0052] The second authentication information is verified according to the target verification information.

[0053] In a fifth aspect of the embodiment of the present application, the remote server and the terminal device only need to establish a communication connection once to achieve bidirectional authentication between the two eUICCs of the terminal device and the remote server in parallel, so that after the bidirectional authentication is completed, each can complete operations on the eUICC, thereby improving operational efficiency.

[0054] In a first possible implementation of the fifth aspect, the target verification information includes a target signing public key identifier, the first eUICC information includes a first signing public key identifier list of the first eUICC, and the second eUICC information includes a second signing public key identifier list of the second eUICC; determining the target verification information based on the first eUICC information and the second eUICC information includes: selecting a first target signing public key identifier from the first signing public key identifier list, where the first target signing public key identifier also exists in a local certificate issuer public key identifier list; selecting a second target signing public key identifier from the second signing public key identifier list, where the second target signing public key identifier also exists in the local certificate issuer public key identifier list; and determining the first target signing public key identifier and the second target signing public key identifier as the target signing public key identifiers.

[0055] In a second possible implementation of the fifth aspect, when the same signature public key identifier exists in the first signature public key identifier list and the second signature public key identifier list, the same signature public key identifier is determined as the target signature public key identifier, and the same signature public key identifier also exists in the local certificate issuer public key identifier list.

[0056] In a third possible implementation of the fifth aspect, the target verification information includes a target verification certificate, the first eUICC information includes a first verification public key identifier list of the first eUICC, and the second eUICC information includes a second verification public key identifier list of the second eUICC; determining the target verification information based on the first eUICC information and the second eUICC information includes: selecting a first target verification public key identifier from the first verification public key identifier list, where the first target verification public key identifier also exists in a local certificate issuer public key identifier list; selecting a second target verification public key identifier from the second verification public key identifier list, where the second target verification public key identifier also exists in the local certificate issuer public key identifier list; and determining a first target verification certificate corresponding to the first target verification public key identifier and a second target verification certificate corresponding to the second target verification public key identifier as the target verification certificate.

[0057] In a fourth possible implementation of the fifth aspect, when the same verification public key identifier exists in the first verification public key identifier list and the second verification public key identifier list, the verification certificate corresponding to the same verification public key identifier is determined as the target verification certificate, and the same verification signature public key identifier also exists in the local certificate issuer public key identifier list.

[0058] A sixth aspect of the embodiments of the present application provides another bidirectional authentication method, including:

[0059] Sending first eUICC information of the first eUICC and second eUICC information of the second eUICC to a remote server;

[0060] Receiving first authentication information sent by the remote server, wherein the first authentication information includes target verification information;

[0061] If the first authentication information is successfully verified by the first eUICC and the second eUICC, second authentication information is sent to the remote server, where the second authentication information includes the first authentication sub-information sent by the first eUICC and the second authentication sub-information sent by the second eUICC.

[0062] In a fifth aspect of the embodiment of the present application, two eUICCs can be bidirectionally authenticated with a remote server at the same time, saving time and improving the efficiency of bidirectional authentication.

[0063] In a first possible implementation manner of the sixth aspect, before sending the first eUICC information of the first eUICC and the second eUICC information of the second eUICC to the remote server, the method further includes: acquiring the first eUICC information from the first eUICC; and acquiring the second eUICC information from the second eUICC.

[0064] In a second possible implementation of the sixth aspect, before sending the second authentication information to the remote server, the method further includes: obtaining third authentication sub-information corresponding to the first eUICC from the first authentication information and sending the third authentication sub-information to the first eUICC; receiving first authentication sub-information sent by the first eUICC after successful verification of the third authentication sub-information; obtaining fourth authentication sub-information corresponding to the second eUICC from the first authentication information and sending the fourth authentication sub-information to the second eUICC; and receiving second authentication sub-information sent by the second eUICC after successful verification of the fourth authentication sub-information.

[0065] In a third possible implementation of the sixth aspect, the target verification information includes a first target signing public key identifier and a second target signing public key identifier, wherein the first target signing public key identifier is selected by the remote server from a first signing public key identifier list of the first eUICC, and the first target signing public key identifier is also present in a local certificate issuer public key identifier list of the remote server; the second target signing public key identifier is selected by the remote server from a second signing public key identifier list of the second eUICC, and the second target signing public key identifier is also present in the local certificate issuer public key identifier list; the third authentication sub-information carries the first target signing public key identifier, and the fourth authentication sub-information carries the second target signing public key identifier.

[0066] In a fourth possible implementation of the sixth aspect, the target verification information includes a target signature public key identifier, where the target signature public key identifier exists in a first signature public key identifier list of the first eUICC, a second signature public key identifier list of the second eUICC, and a local certificate issuer public key identifier list of the remote server; and both the third authentication sub-information and the fourth authentication sub-information carry the target signature public key identifier.

[0067] In a fifth possible implementation of the sixth aspect, the target verification information includes a first target verification certificate corresponding to a first target verification public key identifier and a second target verification certificate corresponding to a second target verification public key identifier, wherein the first target verification public key identifier is selected by the remote server from a list of first verification public key identifiers of the first eUICC, and the first target verification public key identifier is also present in a list of local certificate issuer public key identifiers of the remote server; the second target verification public key identifier is selected by the remote server from a list of second verification public key identifiers of the second eUICC, and the second target verification public key identifier is also present in the list of local certificate issuer public key identifiers; the third authentication sub-information carries the first target verification certificate, and the fourth authentication sub-information carries the second target verification certificate.

[0068] In a sixth possible implementation of the sixth aspect, the target verification information includes a target verification certificate, where the target verification certificate is a verification certificate corresponding to a target verification public key identifier that exists in a first verification public key identifier list of the first eUICC, a second verification public key identifier list of the second eUICC, and a local certificate issuer public key identifier list of the remote server; and both the third authentication sub-information and the fourth authentication sub-information carry the target verification certificate.

[0069] In a seventh aspect, an embodiment of the present application provides an event management server, wherein the event management server is capable of implementing the method described in the first aspect. The functions may be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0070] In one possible design, the event management server includes a receiving module, a processing module, and a sending module. The receiving module is configured to receive first information sent by a terminal device, the first information including a target identifier; the processing module is configured to search for a target event record in currently saved event records, wherein a group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier; and the sending module is configured to send the target event record to the terminal device, the target event record being used to enable the terminal device to download an eUICC firmware version update package.

[0071] In a possible implementation, the receiving module is further configured to receive an event registration request sent by an update server, wherein the event registration request carries the group event identifier; and the processing module is further configured to save the group event identifier in an event record according to the event registration request.

[0072] In a possible implementation, the group event identifier further includes a customized identifier or a country code.

[0073] In a possible implementation manner, the target identifier includes at least one of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

[0074] In one possible implementation, the target identifier includes a first target identifier of a first eUICC and a second target identifier of a second eUICC; the processing module is specifically configured to search for the first event record and the second event record in currently stored event records, respectively, wherein a group event identifier in the first event record matches the first target identifier, and a group event identifier in the second event record matches the second target identifier; and send the first event record and the second event record to the terminal device, the first event record being used to enable the terminal device to download a first eUICC firmware version update package for the first eUICC, and the second event record being used to enable the terminal device to download a second eUICC firmware version update package for the second eUICC.

[0075] In one possible design, the event management server includes a processor and a transceiver, the transceiver being configured to receive first information sent by a terminal device, the first information including a target identifier; the processor being configured to search for a target event record in currently stored event records, wherein a group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier; the transceiver being further configured to send the target event record to the terminal device, the target event record being used to enable the terminal device to download an eUICC firmware version update package.

[0076] Based on the same inventive concept, the principle and beneficial effects of the event management server in solving the problem can be referred to the method described in the first aspect and the beneficial effects brought about. The implementation of the event management server can be referred to the implementation of the method described in the first aspect, and the repetitive parts will not be repeated.

[0077] In an eighth aspect of the present application, a terminal device is provided, wherein the terminal device has the function of implementing the method described in the second aspect, wherein the function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0078] In one possible design, the terminal device includes a sending module, a receiving module, and a processing module. The sending module is used to send first information to an event management server, where the first information includes a target identifier; the receiving module is used to receive a target event record obtained by a search and sent by the event management server, wherein the group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier; the processing module is used to download an eUICC firmware version update package according to the target event record; and the processing module is further used to update the eUICC firmware version according to the eUICC firmware version update package.

[0079] In a possible implementation, the group event identifier further includes a customized identifier or a country code.

[0080] In a possible implementation manner, the target identifier includes at least one of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

[0081] In a possible implementation, the customized identifier includes additional issuer information or a personal identification code in a preset customized position.

[0082] In one possible implementation, the target identifier includes a first target identifier of a first eUICC and a second target identifier of a second eUICC; the receiving module is specifically configured to receive a first event record and a second event record sent by the event management server 90, wherein a group event identifier in the first event record matches the first target identifier, and a group event identifier in the second event record matches the second target identifier; the processing module is specifically configured to: download a first eUICC firmware version update package for the first eUICC according to the first event record; download a second eUICC firmware version update package for the second eUICC according to the second event record; update the firmware version of the first eUICC according to the first eUICC firmware version update package; and update the firmware version of the second eUICC according to the second eUICC firmware version update package.

[0083] In one possible implementation, the processing module is specifically configured to extract an address of an update server from the target event record; the sending module is further configured to send the current eUICC firmware version to the update server; and the receiving module is further configured to receive an eUICC firmware version update package sent by the update server based on the current eUICC firmware version.

[0084] In one possible implementation, the sending module is further configured to: send second information to the update server, where the second information includes a target identifier; and the receiving module is specifically configured to: receive an eUICC firmware version update package sent by the update server according to the current eUICC firmware version when the target identifier in the second information matches the group event identifier stored in the update server.

[0085] In a possible implementation manner, the processing module is specifically configured to update the eUICC firmware version in the eUICC information according to first data in the eUICC firmware version update package, where the first data includes a target firmware version.

[0086] In a possible implementation, the receiving module is further configured to: receive second data sent by the update server, where the second data includes a target firmware version; and the processing module is further configured to: update the eUICC firmware version in the eUICC information according to the second data.

[0087] In one possible design, the terminal device includes a processor and a transceiver, the transceiver being configured to send first information to an event management server, the first information including a target identifier; the transceiver being further configured to receive a target event record obtained by a search and sent by the event management server, wherein the group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier; the processor being configured to download an eUICC firmware version update package according to the target event record; and the processor being further configured to update the eUICC firmware version according to the eUICC firmware version update package.

[0088] Based on the same inventive concept, the principle and beneficial effects of the terminal device in solving the problem can be referred to the method described in the second aspect and the beneficial effects brought about. The implementation of the terminal device can be referred to the implementation of the method described in the second aspect. The repetitive parts will not be repeated.

[0089] A ninth aspect of an embodiment of the present application provides a local file assistant, including:

[0090] A sending module, configured to send first information to an event management server, wherein the first information includes a target identifier;

[0091] a receiving module, configured to receive a target event record obtained by searching and sent by the event management server, wherein the group event identifier in the target event record matches the target identifier in the first information;

[0092] a processing module, configured to download an eUICC firmware version update package according to the target event record;

[0093] The sending module is further configured to send the eUICC firmware version update package to the eUICC, where the eUICC firmware version update package is used by the eUICC to update the eUICC firmware version.

[0094] The local file assistant provided in the ninth aspect of the embodiment of the present application is used to execute the method for updating the eUICC firmware version provided in the third aspect of the present application. For details, please refer to the description of the third aspect of the embodiment of the present application, which will not be repeated here.

[0095] In one possible design, the local file assistant can exist as one or more software modules on the hardware module of the terminal device, and the application code corresponding to the local file assistant is stored in the memory of the terminal device. The application code can be executed by the processor of the terminal device to implement the function of the local file assistant.

[0096] In a tenth aspect, an embodiment of the present application provides an update server, wherein the update server has the function of implementing the method described in the fourth aspect, wherein the function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0097] In one possible design, the update server includes a sending module, which is used to send an event registration request to an event management server, wherein the event registration request carries a group event identifier, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier; the event registration request is used to enable the event management server to save the group event identifier in an event record, and upon receiving the first information sent by a terminal device that matches the group event identifier, send the event record to the terminal device.

[0098] In one possible implementation, the update server further includes: a receiving module configured to receive a current eUICC firmware version of the terminal device sent by the terminal device; a processing module configured to determine, based on the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device to a target firmware version; and the sending module further configured to send the eUICC firmware version update package to the terminal device, where the eUICC firmware version update package is used by the terminal device 100 to update the firmware version of the eUICC of the terminal device.

[0099] In one possible implementation, the receiving module is further configured to: receive second information sent by the terminal device 100, where the second information includes eUICC capabilities and an eUICC firmware version; and the processing module is specifically configured to: upon determining that the eUICC capabilities and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version, determine, based on the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device 100 to the target firmware version.

[0100] In one possible implementation, the second information further includes a target identifier; and the processing module is further configured to: when the target identifier in the second information matches the locally stored group event identifier, determine whether the eUICC performance and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version.

[0101] In one possible design, the structure of the update server includes a processor and a transceiver, and the transceiver is used to send an event registration request to an event management server, wherein the event registration request carries a group event identifier, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier; the event registration request is used to enable the event management server to save the group event identifier in an event record, and upon receiving the first information sent by the terminal device that matches the group event identifier, send the event record to the terminal device.

[0102] Based on the same inventive concept, the principle and beneficial effects of the update server in solving the problem can be referred to the method described in the fourth aspect and the beneficial effects brought about. The implementation of the event management server can be referred to the implementation of the method described in the fourth aspect. The repetitive parts will not be repeated here.

[0103] In an eleventh aspect of the present application, a remote server is provided, wherein the remote server has the function of implementing the method described in the fifth aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0104] In one possible design, the remote server includes a receiving module, a processing module, and a sending module. The receiving module is configured to receive first eUICC information of a first eUICC of a terminal device and second eUICC information of a second eUICC of the terminal device; the processing module is configured to determine target verification information based on the first eUICC information and the second eUICC information; the sending module is configured to send first authentication information to the terminal device, wherein the first authentication information includes the target verification information; the receiving module is further configured to receive second authentication information sent by the terminal device after the first eUICC and the second eUICC successfully verify the first authentication information; and the processing module is further configured to verify the second authentication information based on the target verification information.

[0105] In one possible implementation, the target verification information includes a target signing public key identifier, the first eUICC information includes a first signing public key identifier list of the first eUICC, and the second eUICC information includes a second signing public key identifier list of the second eUICC; the processing module is specifically configured to: select a first target signing public key identifier from the first signing public key identifier list, where the first target signing public key identifier also exists in a local certificate issuer public key identifier list; select a second target signing public key identifier from the second signing public key identifier list, where the second target signing public key identifier also exists in the local certificate issuer public key identifier list; and determine the first target signing public key identifier and the second target signing public key identifier as the target signing public key identifiers.

[0106] In one possible implementation, the processing module is also used to: when the same signature public key identifier exists in the first signature public key identifier list and the second signature public key identifier list, determine the same signature public key identifier as the target signature public key identifier, and the same signature public key identifier also exists in the local certificate issuer public key identifier list.

[0107] In one possible implementation, the target verification information includes a target verification certificate, the first eUICC information includes a first verification public key identifier list of the first eUICC, and the second eUICC information includes a second verification public key identifier list of the second eUICC; the processing module is specifically configured to: select a first target verification public key identifier from the first verification public key identifier list, where the first target verification public key identifier also exists in a local certificate issuer public key identifier list; select a second target verification public key identifier from the second verification public key identifier list, where the second target verification public key identifier also exists in the local certificate issuer public key identifier list; and determine a first target verification certificate corresponding to the first target verification public key identifier and a second target verification certificate corresponding to the second target verification public key identifier as the target verification certificates.

[0108] In one possible implementation, the processing module is also used to: when the same verification public key identifier exists in the first verification public key identifier list and the second verification public key identifier list, determine the verification certificate corresponding to the same verification public key identifier as the target verification certificate, and the same verification signature public key identifier also exists in the local certificate issuer public key identifier list.

[0109] In one possible design, the remote server includes a processor and a transceiver, the transceiver configured to receive first eUICC information of a first eUICC of a terminal device and second eUICC information of a second eUICC of the terminal device; the processor configured to determine target verification information based on the first eUICC information and the second eUICC information; the transceiver further configured to send first authentication information to the terminal device, wherein the first authentication information includes the target verification information; the transceiver further configured to receive second authentication information sent by the terminal device after the first eUICC and the second eUICC successfully verify the first authentication information; and the processor further configured to verify the second authentication information based on the target verification information.

[0110] Based on the same inventive concept, the principle and beneficial effects of the remote server in solving the problem can be referred to the method described in the fifth aspect and the beneficial effects brought about. The implementation of the event management server can be referred to the implementation of the method described in the fifth aspect. The repetitive parts will not be repeated.

[0111] A twelfth aspect of an embodiment of the present application provides a local file assistant, including:

[0112] A sending module, configured to send first eUICC information of the first eUICC and second eUICC information of the second eUICC to a remote server;

[0113] A receiving module, configured to receive first authentication information sent by the remote server, wherein the first authentication information includes target verification information;

[0114] The sending module is further configured to send second authentication information to the remote server if the first eUICC and the second eUICC successfully verify the first authentication information, where the second authentication information includes the first authentication sub-information sent by the first eUICC and the second authentication sub-information sent by the second eUICC.

[0115] The local file assistant provided in the twelfth aspect of the embodiment of the present application is used to execute the two-way authentication method provided in the sixth aspect of the present application. For details, please refer to the description of the sixth aspect of the embodiment of the present application, which will not be repeated here.

[0116] In one possible design, the local file assistant can exist as one or more software modules on the hardware module of the terminal device, and the application code corresponding to the local file assistant is stored in the memory of the terminal device. The application code can be executed by the processor of the terminal device to implement the function of the local file assistant.

[0117] A thirteenth aspect of the embodiments of the present application provides a computer storage medium for storing computer program instructions for use by a computer, which includes instructions for executing the program involved in the above-mentioned first aspect.

[0118] A fourteenth aspect of an embodiment of the present application provides a computer storage medium for storing computer program instructions for use by a computer, which includes instructions for executing the program involved in the above-mentioned second aspect.

[0119] A fifteenth aspect of an embodiment of the present application provides a computer storage medium for storing computer program instructions for use by a computer, which includes instructions for executing the program involved in the third aspect above.

[0120] A sixteenth aspect of an embodiment of the present application provides a computer storage medium for storing computer program instructions for use by a computer, which includes instructions for executing the program involved in the fourth aspect above.

[0121] A seventeenth aspect of an embodiment of the present application provides a computer storage medium for storing computer program instructions for use by a computer, which includes instructions for executing the program involved in the fifth aspect above.

[0122] An eighteenth aspect of an embodiment of the present application provides a computer storage medium for storing computer program instructions for use by a computer, which includes instructions for executing the program involved in the sixth aspect above.

[0123] A nineteenth aspect of the embodiments of the present application provides a computer program for executing the various methods provided in the first aspect above.

[0124] The twentieth aspect of the embodiment of the present application provides a computer program for executing the various methods provided in the second aspect above.

[0125] In the twenty-first aspect of the embodiment of the present application, a computer program is provided for executing the various methods provided in the third aspect above.

[0126] The twenty-second aspect of the embodiment of the present application provides a computer program for executing the various methods provided in the fourth aspect above.

[0127] The twenty-third aspect of the embodiment of the present application provides a computer program for executing the various methods provided in the fifth aspect above.

[0128] The twenty-fourth aspect of the embodiment of the present application provides a computer program for executing the various methods provided in the sixth aspect above. BRIEF DESCRIPTION OF THE DRAWINGS

[0129] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments.

[0130] Figure 1 This is a schematic diagram of the architecture of an eUICC remote configuration / management system provided by an embodiment of the present application;

[0131] Figure 2 This is a flowchart of a method for updating a firmware version provided by an embodiment of the present application;

[0132] Figure 3 This is a flowchart of a method for a terminal device to download an eUICC firmware version update package provided in an embodiment of the present application;

[0133] Figure 4 This is a flowchart of another method for updating the firmware version provided by an embodiment of the present application;

[0134] Figure 5 This is a flowchart of another method for updating the eUICC firmware version provided by an embodiment of the present application;

[0135] Figure 6 This is a flowchart of another method for updating the eUICC firmware version provided by an embodiment of the present application;

[0136] Figure 7 This is a flow chart of a two-way authentication method provided in an embodiment of the present application;

[0137] Figure 8 This is a flowchart of another two-way authentication method provided by an embodiment of the present application;

[0138] Figure 9 This is a schematic diagram of the structure of a system consisting of a terminal device, an event management server, and an update server provided in an embodiment of the present application;

[0139] Figure 10 This is a schematic diagram of the hardware structure of an event management server provided in an embodiment of the present application;

[0140] Figure 11 This is a schematic diagram of the structure of a local file assistant provided in an embodiment of the present application;

[0141] Figure 12 This is a hardware structure diagram of an update server provided by the present application;

[0142] Figure 13 This is a schematic diagram of the structure of a system consisting of a remote server and a terminal device provided in an embodiment of the present application;

[0143] Figure 14 This is a schematic diagram of the hardware structure of a remote server provided in an embodiment of the present application;

[0144] Figure 15This is a structural diagram of another local file assistant provided in an embodiment of the present application;

[0145] Figure 16 This is a structural block diagram of an implementation method of the terminal device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0146] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application.

[0147] The technical solution of the embodiment of the present application is applicable to the eUICC remote management / configuration system. The architecture of the eUICC remote management / configuration system of the embodiment of the present application can be as follows: Figure 1 As shown, Figure 1This is a schematic diagram of an eUICC remote configuration / management system architecture provided by an embodiment of the present application. The SM-DP+ is responsible for preparing a configuration file package and encrypting the configuration file package with a configuration file protection key. The SM-DP+ binds the configuration file package encrypted with the protection key to the EID of the specified eUICC and securely downloads the bound configuration file package to the terminal. In addition, the SM-DP+ can also perform remote profile management (RPM) and remote eUICC management (ReM). The SM-DP+ can be deployed on the server of an operator, eUICC manufacturer, original equipment manufacturer (OEM), or other party. The OPS is used to prepare an eUICC firmware version update package and send the prepared eUICC firmware version update package (e.g., an eUICC firmware version incremental package or full package) to the terminal device. The eUICC firmware version can refer to the Remote SIM Provisioning (RSP) version supported by the eUICC, the eUICC platform version, the eUICC operating system version, or the eUICC platform and operating system versions. In addition, the eUICC firmware version can also include the JAVA platform version, or the eUICC operating system version that includes a new feature (ie, a new algorithm). The eUICC firmware version can also include the TS102241 version and the global platform version. The SM-DS is used to provide one or more SM-DP+ addresses or OPS addresses to terminal devices. Terminal devices can establish a connection with SM-DP+ through this SM-DP+ address, or the terminal device can establish a connection with OPS through this OPS address. The terminal device includes a Local Profile Assistant (LPA) for establishing a connection with SM-DP+ to perform related management operations on Profiles and eUICCs, such as downloading and installation, remote Profile management and remote eUICC management, and eUICC firmware version updates. The terminal device also includes an eUICC for implementing various SIM card functions and Profile and eUICC configuration and management functions. The Operator is the operator's business support system, which is responsible for ordering Profiles from SM-DP+ and requesting Profile management on the eUICC. The End User is the user / subscriber of the terminal device. The eUICC Manufacturer (EUM) is the manufacturer of the eUICC.SM-DP+, SM-DS and OPS can all be referred to as eUICC remote servers (or remote SIM configuration servers). In one possible approach, SM-DP+ and OPS can be deployed on the same server.

[0148] The terminal devices involved in the embodiments of the present application may be devices that provide voice and / or data connectivity to users, handheld devices with wireless connection capabilities, or other processing devices connected to wireless modems. The terminal device can communicate with one or more core networks via a radio access network (RAN). The terminal device may be a mobile terminal, such as a mobile phone (or "cellular" phone) and a computer with a mobile terminal. For example, it may be a portable, pocket-sized, handheld, computer-built-in, or vehicle-mounted mobile device that exchanges language and / or data with the radio access network. For example, it may be a Personal Communication Service (PCS) phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), and other devices. The terminal device may also refer to an Internet of Things device that connects the sensor network layer and the transmission network layer, collects data, and sends data to the network layer. For example, it may be a refrigerator, air conditioner, washing machine, and other devices in a smart home system. The terminal device may also be referred to as a system, subscriber unit, subscriber station, mobile station, mobile, remote station, access point, remote terminal, access terminal, user terminal, user agent, user device, or user equipment.

[0149] See also Figure 2 , Figure 2 FIG. 1 is a flow chart of a method for updating a firmware version provided in an embodiment of the present application. As shown in the figure, the method includes:

[0150] S101. A terminal device sends first information to an event management server, where the first information includes a target identifier. The event management server receives the first information.

[0151] Specifically, if Figure 1As shown, a terminal device may include an LPA and an eUICC. The LPA and eUICC may be two separate modules that are physically or logically connected. For example, the LPA resides on a baseband chip, an application processor, or other hardware modules of the terminal device. The LPA may also reside directly on the eUICC. Specifically, the LPA may be a single software module or multiple distributed and interconnected software modules.

[0152] Specifically, the event management server can be SM-DS, or other servers with event management functions such as event registration, event deletion, event sending, event modification, etc., or a server that provides one or more SM-DP+ addresses or OPS addresses to the terminal device so that the terminal device can establish a communication connection with SM-DS+ or OPS.

[0153] S102. The event management server searches for a target event record in currently stored event records, where the group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier.

[0154] Optionally, there may be multiple event records stored in the event management server, for example, an event record corresponding to eUICC1, an event record corresponding to eUICC2, an event record corresponding to eUICC3, and so on.

[0155] Optionally, the event record and the eUICC may correspond via an eUICC Identity (EID) or a group event ID.

[0156] For example, when there is a one-to-one correspondence between an event record and an eUICC, the correspondence can be achieved through the EID, that is, the EID is saved in the event record, and the eUICC that matches the EID in the event record is the eUICC corresponding to the event record; when there is a one-to-many correspondence between an event record and an eUICC, the correspondence can be achieved through the group event identifier, that is, the group event identifier is saved in the event record, and the eUICC that matches the group event identifier in the event record is the eUICC corresponding to the event record.

[0157] Specifically, the group event identifier may be an identifier shared by multiple eUICCs, used to identify that the target event record may correspond to multiple terminal devices or multiple eUICCs, and that the service provided by the remote server corresponding to the target event record may correspond to multiple terminal devices or multiple eUICCs.

[0158] Optionally, the matching of the group event identifier and the target identifier may mean that the group event identifier is the same as the target identifier or the target identifier belongs to the group event identifier.

[0159] Specifically, the target event record can be registered by the event management server before the terminal device sends the first information to the event management server, that is, before the event management server receives the first information sent by the terminal device, it also includes: the event management server receives the event registration request sent by the update server, wherein the registration request carries the group event identifier; the event management server saves the group event identifier in the target event record according to the registration request.

[0160] In an optional embodiment, the terminal device may also perform the operation of matching the group event identifier with an identifier stored locally on the terminal device, i.e., the terminal device receives an event record sent by the event management server, and the terminal device selects a target event record from the event record that matches the locally stored identifier. For example, the target identifier in the first information includes a partial group event identifier, the event management server searches for an event record matching the target identifier in the currently stored event records, and the event management server sends the event record matching the target identifier to the terminal device. The terminal device extracts the complete group event identifier from the event record and matches the group event identifier with the locally stored identifier information one by one, thereby determining the target event record. In this embodiment, the target identifier only includes a partial group event identifier, and there may be one or more event records matching the target identifier. The terminal device determines the target event record based on the one or more received event records. In this embodiment, the event server may perform an initial screening of the event records to select some event records that meet the conditions, and then the terminal device may perform a final screening of the event records to select the target event record whose group event identifier best matches the identifier information of the terminal device.

[0161] S103: The event management server sends the target event record to the terminal device, and the terminal device receives the target event record.

[0162] Optionally, the target event record may further include the address of the update server.

[0163] S104. The terminal device downloads the eUICC firmware version update package.

[0164] Specifically, the process of the terminal device downloading the eUICC firmware version update package can be as follows: Figure 3 As shown, Figure 3 This is a flow chart of a method for a terminal device to download an eUICC firmware version update package provided in an embodiment of the present application. As shown in the figure, the method at least includes:

[0165] S201. The terminal device extracts the address of the update server from the target event record.

[0166] Specifically, the update server may be an OPS, or other server that provides eUICC firmware update package download services for terminal devices, for example, the update server may also be an SM-DP+, and so on.

[0167] S202: The terminal device sends the current eUICC firmware version to the update server, and the update server receives the current eUICC firmware version.

[0168] In an optional embodiment, the terminal device may carry the current eUICC firmware version in the first command (e.g., AuthenticateClient) and send it to the update server during the two-way authentication process with the update server. The terminal device may also carry the current eUICC firmware version in the second command (e.g., InitiateAuthentication) and send it to the update server during the two-way authentication process with the update server.

[0169] S203: The update server determines, based on the current eUICC firmware version, the eUICC firmware version update package required for the terminal device to update to the target firmware version.

[0170] Specifically, an eUICC firmware version update can include an eUICC firmware version update incremental package, a full eUICC firmware version update package, or an eUICC firmware version bug fix package. A firmware version update incremental package contains a module portion of the eUICC firmware version. A firmware version update incremental package can also exist as a differential package, meaning that the firmware version update incremental package only includes the differences between the old and new firmware versions. Therefore, an eUICC firmware version update incremental package can be used to complete the update operation by patching the eUICC firmware version. A full eUICC firmware version update package includes a complete firmware version installation package, requiring the eUICC to enter recovery mode beforehand to install the full eUICC firmware version update package. An eUICC firmware version bug fix package can be an update package generated to address bug fix issues in the eUICC platform, the eUICC system, or both the eUICC platform and the system.

[0171] S204: The update server sends an eUICC firmware version update package to the terminal device, and the terminal device receives the eUICC firmware version update package.

[0172] S105. The terminal device updates the eUICC firmware version according to the eUICC firmware version update package.

[0173] To more clearly describe the technical solutions of the embodiments of the present application, the following describes the specific implementation process of the method for updating the eUICC firmware version by the terminal device, using the LPA and eUICC of the terminal device as independent execution entities. It should be understood that after omitting the interaction steps between the LPA and eUICC (i.e., the internal interaction process of the terminal device), the operation steps performed by the LPA and eUICC are the operation steps performed by the terminal device. The above embodiment is described in detail below using SM-DS to represent the event management server and OPS to represent the update server.

[0174] See also Figure 4 , Figure 4 This is a flowchart of another method for updating the eUICC firmware version provided by an embodiment of the present application. As shown in the figure, the method includes:

[0175] S301. The OPS sends an event registration request (e.g., RegisterEvent) to the SM-DS. The event registration request carries a group event identifier. The SM-DS receives the event registration request. The group event identifier includes at least one eUICC firmware version and at least one issuer identifier.

[0176] Optionally, the OPS may also perform two-way authentication with the SM-DS before sending the event registration request to the SM-DS.

[0177] Optionally, the event registration request may also carry the address of the OPS and an event identifier (Event Identity, EventID).

[0178] Optionally, the group event identifier may further include a custom identifier or a country code.

[0179] Specifically, when the group event identifier is an eUICC firmware version, the event registration request may carry at least one eUICC firmware version, indicating that the OPS can currently provide an eUICC firmware version update service for the eUICC corresponding to the at least one eUICC firmware version.

[0180] For example, if OPS can currently provide eUICC firmware version update services for multiple versions of eUICCs, and the target firmware version is 50000, OPS can provide eUICC firmware version update services for eUICCs with eUICC firmware versions of 49999, 49998, or 49997, then OPS will carry 49999, 49998, and 49997 in the Event Registration Request and send it to SM-DS.

[0181] Optionally, the customized identifier may include additional issuer information or an individual identification number in a preset customized position.

[0182] Optionally, the preset customized digits may be one or more digits. For example, the customized identifier may be characters within a range of digits of the personal identification code, such as 100100110111 to 101110110101. The customized identifier can also be a character in the nth position (n is 1 to 12) of the personal identification code. The customized identifier can also be a character in the odd-numbered positions of the personal identification code, that is, the characters in the 1st, 3rd, 5th, 7th, 9th and 11th positions of the personal identification code; the customized identifier can also be a character in the even-numbered positions of the personal identification code, that is, the numbers in the 2nd, 4th, 6th, 8th, 10th and 12th positions of the personal identification code; the customized identifier can also be a character in the 1st to 5th positions of the personal identification code; the customized identifier can also be a character in the 3rd to 8th positions of the personal identification code, and so on. The personal identification code has a total of 12 digits, and there can be multiple setting rules for the preset customized positions. Accordingly, different preset customized positions have different customized identifiers, which are not listed here.

[0183] S302. SM-DS saves the event record.

[0184] Specifically, the SM-DS saves the group event identifier in the event registration request in the event record.

[0185] Optionally, the SM-DS may also save the address and event identifier of the OPS in the event record.

[0186] At this point, the SM-DS stores an event record including a group event identifier, where the group event identifier corresponds to at least one eUICC, waiting for the LPA to query.

[0187] S303. The LPA establishes a secure Hypertext Transfer Protocol Secure (HTTPS) connection with the SM-DS.

[0188] Specifically, under conditions such as user operation, timer triggering or eUICC triggering, the LPA initiates a connection request to the SM-DS to query whether there is an event record corresponding to the eUICC.

[0189] Optionally, the LPA can obtain a default SM-DS address from the eUICC. For example, if the terminal device is customized and produced by operator A, operator A specifies to preset an SM-DS address in the eUICC, or the terminal manufacturer presets an SM-DS address shared by multiple operators in the eUICC.

[0190] Optionally, HTTPS can be run over a Transport Layer Security (TLS) connection. For example, the LPA performs one-way certificate authentication on the SM-DS and establishes a TLS connection after successful authentication.

[0191] S304: The eUICC sends first information to the LPA. The LPA receives the first information, where the first information includes a target identifier.

[0192] Optionally, the first information may be the second authentication information sent by the terminal device to the SM-DS during the two-way authentication process between the terminal device and the SM-DS.

[0193] Optionally, the first information may include eUICC data to be signed (e.g., euiccSigned1), the signature value of the eUICC data to be signed (e.g., euiccSignature1), the eUICC certificate (e.g., CERT.EUICC.ECDSA), the eUICC manufacturer certificate (e.g., CERT.EUM.ECDSA), and the like.

[0194] Specifically, the eUICC data to be signed (e.g., euiccSigned1) may include eUICC information, wherein the eUICC information in the eUICC data to be signed (e.g., euiccSigned1) is additional eUICC information (e.g., euiccInfo2); and the eUICC certificate (e.g., CERT.EUICC.ECDSA) includes an eUICC identity (eUICC Identity, EID).

[0195] Specifically, the additional eUICC information (eg, euiccInfo2) includes the eUICC firmware version (euiccFirmwareVersion) and the eUICC capability (UICCCapability).

[0196] Optionally, the first information may also be information sent by the terminal device to the SM-DS after the two-way authentication process between the terminal device and the SM-DS is completed. For example, the first information may include additional eUICC information (e.g., euiccInfo2), EID, etc.

[0197] Optionally, the target identifier may include at least one of an eUICC firmware version, an issuer identifier, a customized identifier, or a country code.

[0198] Specifically, the eUICC firmware version in the first information is the current firmware version of the eUICC. For example, if the current firmware version of the eUICC is 49997, then the eUICC firmware version in the first information is 49997.

[0199] S305. The LPA sends first information to the SM-DS, and the SM-DS receives the first information.

[0200] Optionally, the LPA may carry the first information in a first command (eg, AuthenticateClient) and send it to the SM-DS.

[0201] S306. The SM-DS searches for a target event record in the currently saved event records, where the group event identifier in the target event record matches the target identifier in the first information.

[0202] Specifically, the SM-DS can obtain the target identifier from the first information, obtain the group event identifier from the currently saved event record, compare the target identifier with the group event identifier, and if the target identifier is the same as the group event identifier or the target identifier belongs to the group event identifier, determine that the group event identifier in the target event record matches the target identifier in the first information.

[0203] Optionally, if the group event identifier is the eUICC firmware version, the SM-DS may obtain the eUICC firmware version from the additional eUICC information (e.g., euiccInfo2) in the first information as the target identifier in the first information; the SM-DS may also obtain the EID from the eUICC certificate (e.g., CERT.EUICC.ECDSA) in the first information, extract the eUICC firmware version from the EID as the target identifier in the first information, and compare the target identifier with the group event identifier in the at least one event record, thereby determining a target event record whose target identifier matches the group event identifier from the at least one event record.

[0204] Specifically, the SM-DS may extract characters from 9th to 13th positions of the EID and determine them as the eUICC firmware version, that is, the target identifier in the first information.

[0205] For example, the group event identifier is the eUICC firmware version, the eUICC firmware versions in event record 1 are 49999, 49998, and 49997, and the eUICC firmware version in the first information obtained by the SM-DS is 49997. 49997 belongs to the group event identifier, so the group event identifier matches the target identifier, and event record 1 is determined as the target event record.

[0206] Optionally, if the group event identifier is an issuer identifier, the SM-DS can obtain the EID from the eUICC certificate (e.g., CERT.EUICC.ECDSA) in the first information, extract the issuer identifier from the EID as the target identifier in the first information, and compare the target identifier with the group event identifier in at least one event record, thereby determining the target event record whose target identifier matches the group event identifier from the at least one event record.

[0207] Specifically, the SM-DS may extract the 6th to 8th characters of the EID and determine them as the issuer identifier, that is, the target identifier in the first information.

[0208] For example, if the group event identifier is the issuer identifier and the issuer identifier in event record 2 is 1111, then if the characters from bits 5 to 8 extracted by the SM-DS from the EID are 1111, it is determined that the group event identifier matches the target identifier, and event record 2 is determined as the target event record.

[0209] Optionally, if the group event identifier is a customized identifier and the customized identifier is additional issuer information, the SM-DS can obtain the EID from the eUICC certificate (e.g., CERT.EUICC.ECDSA) in the first information, extract the additional issuer information from the EID as the target identifier in the first information, and compare the target identifier with the group event identifier in at least one event record, thereby determining the target event record whose target identifier matches the group event identifier from the at least one event record.

[0210] Specifically, the SM-DS may extract characters from the 14th to 18th positions of the EID and determine them as additional issuer information, that is, the target identifier in the first information.

[0211] For example, if the group event identifier is a customized identifier and the customized identifier is additional issuer information, and the additional issuer information in event record 3 is 22222, then if the characters from bits 14 to 18 extracted by the SM-DS from the EID are 22222, then it is determined that the group event identifier matches the target identifier, and event record 3 is determined to be the target event record.

[0212] Optionally, if the group event identifier is a customized identifier and the customized identifier is a personal identification code in a preset customized position, the SM-DS can obtain the EID from the eUICC certificate (e.g., CERT.EUICC.ECDSA) in the first information, extract the personal identification code in the preset customized position from the EID as the target identifier in the first information, and compare the target identifier with the group event identifier in the at least one event record, thereby determining the target event record whose target identifier matches the group event identifier from the at least one event record.

[0213] Specifically, the SM-DS may extract characters from the 19th to 30th positions of the EID, and extract characters in preset customized positions from the extracted characters from the 19th to 30th positions as the target identifier in the first information.

[0214] For example, the group event identifier is a customized identifier and the customized identifier is a personal identification code in a preset customized position, the preset customized position is the 2nd to 4th positions of the personal identification code, and the personal identification code in the preset customized position in event record 4 is 333. If the characters from positions 20 to 22 of the EID of the SM-DS are 333, then it is determined that the group event matches the target identifier, and event record 4 is determined as the target event record.

[0215] Optionally, if the group event identifier is an issuer identifier, the SM-DS can obtain the EID from the eUICC certificate (e.g., CERT.EUICC.ECDSA) in the first information, extract the country code from the EID as the target identifier in the first information, and compare the target identifier with the group event identifier in at least one event record, thereby determining the target event record whose target identifier matches the group event identifier from the at least one event record.

[0216] Specifically, the SM-DS may extract the 3rd to 5th characters of the EID and determine them as the country code, that is, the target identifier in the first information.

[0217] Optionally, if the group event identifier is two or three of the following information: the eUICC firmware version, the issuer identifier, the customized identifier, or the country code, the corresponding information can be obtained according to the above-mentioned method for obtaining the eUICC firmware version, the issuer identifier, or the customized identifier, and used as the target identifier in the first information. The target identifier is compared with the group event identifier in the event record to determine the target event record whose event identifier matches the target identifier.

[0218] S307. The SM-DS sends the target event record to the LPA, and the LPA receives the target event record.

[0219] At this point, the interaction between the LPA and the SM-DS is completed, and the LPA obtains the target event record. The LPA can process the target event to obtain the information in the target event record, and then perform corresponding operations based on the information in the event record, such as executing the operations corresponding to step S308 and subsequent steps.

[0220] Optionally, when there are multiple target event records, the LPA may process the target event records in sequence.

[0221] S308. The LPA extracts the address of the OPS from the target event record.

[0222] S309. The LPA establishes an HTTPS connection with the OPS.

[0223] S310 : The LPA sends the current eUICC firmware version of the terminal device to the OPS, and the OPS receives the current eUICC firmware version of the terminal device.

[0224] Optionally, the LPA may carry the current eUICC firmware version of the terminal device in a second command (eg, InitiateAuthentication) and send it to the OPS.

[0225] Optionally, the second command (eg, InitiateAuthentication) may further carry an eUICC random number (eg, eUICCChallenge1), eUICC information, and an OPS address, etc., wherein the eUICC information in the second command is initial eUICC information (eg, euiccInfo1).

[0226] S311 . The OPS sends the third information to the LPA, and the LPA receives the third information.

[0227] Optionally, the third information may be the first authentication information sent by the OPS to the terminal device during the two-way authentication process between the terminal device and the OPS.

[0228] Optionally, the third information may include a session identifier (TransactionIdentity, TransactionID), authentication and verification data to be signed (e.g., OPSSigned1), authentication and verification signature value of data to be signed (e.g., OPSSignature1), target public key identifier (e.g., euiccCiPKIdToBeUsed), and an authentication certificate of the update server (e.g., CERT.OPSauth.ECDSA).

[0229] Optionally, the authentication verification data to be signed (e.g., OPSSigned1) may include a session identifier, the current eUICC firmware version of the terminal device, an eUICC random number (e.g., euiccChange1), an update server random number (e.g., OPSChanllenge), and an OPS address.

[0230] S312: The LPA sends the third information to the eUICC, and the eUICC receives the third information.

[0231] Optionally, the LPA may carry the third information in a third command (eg, AuthenticateServer) and send it to the eUICC.

[0232] S313: The eUICC sends second information to the LPA. The LPA receives the second information, where the second information includes a target identifier, eUICC capabilities, and an eUICC firmware version.

[0233] Optionally, the second information may be second authentication information sent by the terminal device to the OPS during a two-way authentication process between the terminal device and the OPS.

[0234] Optionally, the second information may include eUICC data to be signed (e.g., euiccSigned1), a signature value of the eUICC data to be signed (e.g., euiccSignature1), an eUICC certificate (e.g., CERT.EUICC.ECDSA), an eUICC manufacturer certificate (e.g., CERT.EUM.ECDSA), and the like.

[0235] Optionally, the second information may also be information sent by the terminal device to the OPS after the two-way authentication between the terminal device and the OPS is completed. For example, the second information may include additional eUICC information (eg, euiccInfo2) and EID.

[0236] S314. The LPA sends the second information to the OPS, and the OPS receives the second information.

[0237] Optionally, the LPA may carry the second information in the first command (eg, AuthenticateClient) and send it to the OPS.

[0238] S315 : The OPS determines whether the target identifier matches the locally stored group event identifier.

[0239] Optionally, the specific implementation of determining whether the target identifier matches the group event identifier may refer to the description in step S306 and will not be repeated here.

[0240] Specifically, when the target identifier matches the locally stored group event identifier, the OPS executes step S316.

[0241] S316. The OPS checks whether the eUICC performance and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version.

[0242] Specifically, the OPS may check whether the eUICC performance can support updating to the target firmware version; the OPS may check whether the eUICC firmware version belongs to the firmware version range that can be updated to the target firmware version.

[0243] For example, the OPS currently provides an eUICC firmware version update server for eUICCs with eUICC firmware versions 49997, 49998, and 49999. If the eUICC firmware version of the eUICC is one of 49997, 49998, and 49999, the eUICC firmware version requirement of the target firmware version is met.

[0244] Optionally, after checking whether the eUICC performance and firmware version can be updated to the target firmware version, the OPS further includes: generating third data (e.g., patch metadata); generating first data to be signed (e.g., OPSSigned2); generating a signature value of the first data to be signed (e.g., OPSSignature2); and sending second data to the LPA.

[0245] Optionally, the third data (eg, patch metadata) may include the target firmware version.

[0246] Optionally, the second data may include a session identifier, third data (eg, patch metadata), first data to be signed (eg, OPSSigned2), a signature value of the first data to be signed (eg, OPSSignature2), and the like.

[0247] Specifically, the first data to be signed (eg, OPSSigned2) may include a session identifier, a target firmware version, a confirmation code required flag (Confirmation Code Required Flag), a temporary key pair public key (eg, bppEuiccOtpk), and the like.

[0248] Optionally, after receiving the second data sent by the OPS, the LPA may carry the second data in a prepare download command (eg, PrepareDownload) and send it to the eUICC.

[0249] S317. The OPS determines, based on the current eUICC firmware version of the terminal device, the eUICC firmware version update package required for the terminal device to update to the target firmware version.

[0250] In one embodiment, the OPS may obtain the current eUICC firmware version of the terminal device through step S310; in another embodiment, the OPS may also obtain the current eUICC firmware version of the terminal device from the second information.

[0251] In one possible implementation, different eUICC firmware version update packages may be designed for different eUICC firmware versions, where different eUICC firmware version update packages may contain different numbers of system patches, function codes, etc. The OPS may search for the eUICC firmware version update package corresponding to the current eUICC firmware version of the terminal device and determine it as the eUICC firmware version update package required for the terminal device to update to the target firmware version.

[0252] For example, if the target firmware version is 50000, there are currently three types of eUICC firmware version update packages in OPS, namely, update package [49997-50000], update package [49998-50000], and update package [49999-50000]. Among them, update package [49997-50000] is the eUICC firmware version update package prepared for eUICC firmware version 49997, update package [49998-50000] is the eUICC firmware version update package prepared for eUICC firmware version 49998, and update package [49999-50000] is the eUICC firmware version update package prepared for eUICC firmware version 49999. If the current eUICC firmware version of the terminal device is 49997, the OPS determines that the eUICC firmware version update package required for updating to the target firmware version is the update package [49997-50000]. If the current eUICC firmware version of the terminal device is 49998, the OPS determines that the eUICC firmware version update package required for updating to the target firmware version is the update package [49998-50000]. If the current eUICC firmware version of the terminal device is 49999, the OPS determines that the eUICC firmware version update package required for updating to the target firmware version is the update package [49999-50000].

[0253] S318. The OPS sends the eUICC firmware version update package to the LPA, and the LPA receives the eUICC firmware version update package.

[0254] S319. The LPA sends the eUICC firmware version update package to the eUICC, and the eUICC receives the eUICC firmware version update package.

[0255] Optionally, the LPA may carry the eUICC firmware version update package in a fourth command (eg, LoadBoundPackage) and send it to the eUICC.

[0256] S320: The eUICC updates the eUICC firmware version according to the eUICC firmware version update package.

[0257] Specifically, the eUICC updates the eUICC platform according to the firmware version update data in the eUICC firmware version update package, or the eUICC updates the eUICC operating system according to the firmware version update data in the eUICC firmware version update package, or the eUICC updates both the eUICC platform and the eUICC operating system according to the firmware version update data in the eUICC firmware version update package, or the eUICC updates the RSP version according to the firmware version update data in the eUICC firmware version update package, or the eUICC updates the TS102241 version or the global platform version according to the firmware version update data in the eUICC firmware version update package.

[0258] Specifically, the eUICC may upgrade the eUICC platform version to the target version, or the eUICC may upgrade the eUICC operating system version to the target version, or the eUICC may upgrade the eUICC platform version and the eUICC operating system version to the target version, or the eUICC may upgrade the RSP version to the target version.

[0259] S321. The eUICC updates the eUICC firmware version in the eUICC information.

[0260] Optionally, the eUICC may update the eUICC firmware version in the eUICC information according to first data (eg, StoreMetadata) in the eUICC firmware version update package, where the first data includes the target firmware version.

[0261] Optionally, the eUICC may update the eUICC firmware version in the eUICC information according to first data (eg, encrypted data) in the eUICC firmware version update package, where the first data includes the target firmware version.

[0262] Optionally, the eUICC may also update the eUICC firmware version in the eUICC information based on the second data. For example, the eUICC may update the eUICC firmware version in the eUICC information based on the third data (e.g., patch metadata) in the second data. The eUICC may also update the eUICC firmware version in the eUICC information based on the first data to be signed (e.g., OPSSigned2) in the second data. Optionally, updating the eUICC firmware version in the eUICC information may also occur before the eUICC firmware version is updated.

[0263] Specifically, the eUICC may update / replace the firmware version in the eUICC information with the target firmware version.

[0264] For example, before the eUICC firmware version is updated, the eUICC firmware version in the eUICC information is 49997, and the target firmware version is 50000. After the firmware version is updated, the eUICC updates the eUICC firmware version in the eUICC information to 50000.

[0265] Optionally, after the eUICC updates the eUICC firmware version in the eUICC information, the eUICC may send a notification message to the LPA. The notification message may be carried by an Application Protocol Data Unit (APDU). The notification message may include the firmware version upgrade result of the current eUICC. The firmware version upgrade result may also include the target firmware version. The notification message may include one or more of notification metadata, session identifier, final result, SM-DP+ object identifier, and eUICC signature; the notification metadata may include a sequence number and a recipient address; and the final result may carry the latest firmware version update status.

[0266] exist Figure 4 In the method described above, the group event identifier can correspond to multiple eUICCs, which is applicable to the scenario of eUICC firmware version update. The eUICC firmware version update corresponds to multiple eUICCs. The OPS sends an event registration request carrying the group event identifier to the SM-DS to enable the SM-DS to complete the event registration. One event record can correspond to multiple eUICCs or terminal devices, avoiding the registration of multiple events when providing the eUICC firmware version update service, thereby improving efficiency.

[0267] In an optional solution, when there are two eUICCs in the terminal device and the eUICC firmware versions of both eUICCs need to be updated, the eUICC firmware version update of the two eUICCs can be implemented in parallel. Assuming that the two eUICCs are a first eUICC, i.e., eUICC1, and a second eUICC, i.e., eUICC2, the following describes the implementation process of implementing the eUICC firmware version update of the two eUICCs in parallel when eUICC1 and eUICC2 are from the same manufacturer and different manufacturers, respectively.

[0268] First, let's introduce the case where eUICC1 and eUICC2 belong to different manufacturers. Assuming that the update server corresponding to eUICC1 is OPS1 and the update server corresponding to eUICC2 is OPS2, the implementation process can be as follows: Figure 5 shown. Figure 5 This is a flowchart of another method for updating the eUICC firmware version provided by an embodiment of the present application. As shown in the figure, the method includes:

[0269] S401. OPS1 sends an event registration request to the SM-DS. The event registration request carries a first group of event identifiers. The SM-DS receives the event registration request. The first group of event identifiers includes at least one eUICC firmware version and at least one issuer identifier.

[0270] S402. The SM-DS saves a first event record, where the first event record includes a first group of event identifiers.

[0271] S403. OPS2 sends an event registration request to the SM-DS. The event registration request carries a second group of event identifiers. The SM-DS receives the event registration request. The second group of event identifiers includes at least one eUICC firmware version and at least one issuer identifier.

[0272] S404. The SM-DS saves a second event record, where the second event record includes a second group of event identifiers.

[0273] Specifically, the specific implementation of steps S401-S402 and steps S403-S404 can refer to Figure 3 The description of steps S301 to S302 in the corresponding embodiments will not be repeated. It should be understood that the type / composition / definition / structure of the first group of event identifiers in step S401 and the second group of event identifiers in step S403 can be the same as the group event identifier in step S301, and the group event identifier in step S301 can include the first group of event identifiers and / or the second group of event identifiers; the type / composition / definition / structure of the first event record in step S402 and the second event record in step S404 can be the same as the target event record in step S302, and the target event record in step S302 can include the first event record and / or the second event record.

[0274] It should be noted that steps S401-S402 and steps S403-S404 may be independent and parallel steps. In an optional embodiment, steps S401-S402 and steps S403-S404 may be executed simultaneously, or steps S401-S402 may be executed after steps S403-S404 are executed.

[0275] At this point, the SM-DS has saved the first event record corresponding to eUICC1 and the second event record corresponding to eUICC2, waiting for the LPA to query.

[0276] S405. The LPA establishes an HTTPS connection with the SM-DS.

[0277] Specifically, the specific implementation of step S405 can refer to the description of step S303, which will not be repeated here.

[0278] S406. eUICC1 sends first sub-information to the LPA. The LPA receives the first sub-information, where the first sub-information includes the first target identifier.

[0279] Optionally, the first sub-information may be the first authentication sub-information in the second authentication information sent by the terminal device to the SM-DS during the two-way authentication process between the terminal device and the SM-DS.

[0280] Optionally, the first sub-information may include the first eUICC data to be signed (e.g., euicc1Signed1), the signature value of the first eUICC data to be signed (e.g., euicc1Signature1), the first eUICC certificate (e.g., CERT.EUICC1.ECDSA), the first eUICC manufacturer certificate (e.g., CERT.EUM1.ECDSA), and the like.

[0281] The first eUICC data to be signed (e.g., euicc1Signed1) is eUICC data to be signed, and may specifically include first eUICC information. The first eUICC information in the first eUICC data to be signed (e.g., euicc1Signed1) is first additional eUICC information (e.g., euicc1Info2). The first eUICC certificate (e.g., CERT.EUICC1.ECDSA) is an eUICC certificate, and may specifically include a first eUICC identifier (e.g., EID1).

[0282] The first target identifier is a target identifier, which may specifically include at least one of the following information: the eUICC firmware version of the eUICC1, the issuer identifier of the eUICC1, the customized identifier of the eUICC1, or the country code of the eUICC1.

[0283] S407. eUICC2 sends the second sub-information to the LPA. The LPA receives the second sub-information, where the second sub-information includes the second target identifier.

[0284] Optionally, the second sub-information may be the second authentication sub-information in the second authentication information sent by the terminal device to the SM-DS during the two-way authentication process between the terminal device and the SM-DS.

[0285] Optionally, the second sub-information may include the second eUICC to-be-signed data (e.g., euicc2Signed1), the signature value of the second eUICC to-be-signed data (e.g., euicc2Signature1), the second eUICC certificate (e.g., CERT.EUICC2.ECDSA), the second eUICC manufacturer certificate (e.g., CERT.EUM2.ECDSA), and the like.

[0286] The second eUICC data to be signed (e.g., euicc2Signed1) is eUICC data to be signed, and may specifically include second eUICC information. The second eUICC information in the second eUICC data to be signed (e.g., euicc2Signed1) is second additional eUICC information (e.g., euicc2Info2). The second eUICC certificate (e.g., CERT.EUICC2.ECDSA) is an eUICC certificate, and may specifically include a second eUICC identifier (e.g., EID2).

[0287] The second target identifier is a target identifier, which may specifically include at least one of the following information: the eUICC firmware version of the eUICC2, the issuer identifier of the eUICC2, the customized identifier of the eUICC2, or the country code of the eUICC2.

[0288] It should be noted that step S406 and step S407 may be independent and parallel steps. In an optional embodiment, step S406 and step S407 may be executed simultaneously, or step S406 may be executed after step S407 is executed.

[0289] It should be understood that the type / composition / definition / structure of the first sub-information and the second sub-information may be the same as the first information in step S304, that is, the first information in step S304 may include the first sub-information and / or the second sub-information.

[0290] S408. The LPA sends first information to the SM-DS. The first information includes first sub-information and second sub-information. The SM-DS receives the first information.

[0291] S409. The SM-DS searches for the first event record and the second event record in the currently saved event records, respectively, where the first group of event identifiers in the first event record matches the first target identifier, and the second group of event identifiers in the second event record matches the second target identifier.

[0292] Specifically, the SM-DS can obtain the first target identifier and the second target identifier from the first information; obtain the first group event identifier and the second group event identifier from the currently saved event record, match the first target identifier with the first group event identifier, and if the first target identifier is the same as the first group event identifier or the first target identifier belongs to the first group event identifier, then determine that the first target identifier matches the first group event identifier; match the second target identifier with the second group event, and if the second target identifier is the same as the second group event identifier or the second target identifier belongs to the second group event identifier, then determine that the second target identifier matches the second group event identifier.

[0293] Optionally, the specific implementation of the SM-DS obtaining the first target identifier and the second target identifier and determining that the first target identifier matches the first group of event identifiers and determining that the second target identifier matches the second group of event identifiers can be referred to the description in step S306 and will not be repeated here.

[0294] S410. The SM-DS sends the first event record and the second event record to the LPA, and the LPA receives the first event record and the second event record.

[0295] At this point, the interaction between the LPA and the SM-DS is completed, and the LPA obtains the first event record corresponding to eUICC1 and the second event record corresponding to eUICC2.

[0296] Optionally, the LPA may process the first event record and the second event record in sequence.

[0297] S411. The LPA obtains a first eUICC identifier of eUICC1.

[0298] In an optional implementation, the LPA may also obtain the first eUICC identifier of eUICC1 by obtaining the certificate of eUICC1 during the mutual authentication process with the SM-DS; the LPA may also obtain the first eUICC identifier of eUICC1 by obtaining an EID instruction (e.g., GetEID) after the mutual authentication process with the SM-DS is completed.

[0299] S412: The LPA sends a first event record to eUICC1 according to the first eUICC identifier, and eUICC1 receives the first event record.

[0300] Optionally, the LPA may obtain the first target identifier from the first eUICC identifier, and determine to send the first event record to eUICC1 if the first target identifier matches the first group of event identifiers in the first event record.

[0301] S413. LPA establishes an HTTPS connection with OPS1.

[0302] S414. The LPA downloads the first eUICC firmware version update package from OPS1.

[0303] Specifically, the specific implementation process of the LPA downloading the first eUICC firmware version update package from the OPS1 can refer to steps S310 to S318, which will not be repeated here.

[0304] S415 : The LPA sends the first eUICC firmware version update package to eUICC1 , and eUICC1 receives the first eUICC firmware version update package.

[0305] S416 : The eUICC1 updates the firmware version of the eUICC1 according to the first eUICC firmware version update package.

[0306] S417. eUICC1 updates the eUICC firmware version in the first eUICC information.

[0307] Specifically, the specific implementation of steps S415 to S417 can refer to the description of steps S319 to S321 and will not be repeated here.

[0308] S418. The LPA obtains the second eUICC identifier of eUICC2.

[0309] In an optional embodiment, the LPA may also obtain the second eUICC identifier of eUICC2 by obtaining the certificate of eUICC2 during the mutual authentication process with the SM-DS; the LPA may also obtain the second eUICC identifier of eUICC2 by obtaining an EID instruction (e.g., GetEID) after the mutual authentication process with the SM-DS is completed.

[0310] S419: The LPA sends a second event record to eUICC2 according to the second eUICC identifier, and eUICC2 receives the second event record.

[0311] Optionally, the LPA may obtain a second target identifier from the second eUICC identifier, and determine to send the second event record to eUICC1 if the second target identifier matches the second group of event identifiers in the second event record.

[0312] S420. LPA establishes an HTTPS connection with OPS2.

[0313] S421. The LPA downloads the second eUICC firmware version update package from the OPS2.

[0314] Specifically, the specific implementation process of the LPA downloading the second eUICC firmware version update package from the OPS2 may refer to steps S310 to S318, which will not be repeated here.

[0315] S422. The LPA sends the second eUICC firmware version update package to eUICC2. eUICC2 receives the second eUICC firmware version update package.

[0316] S423: eUICC2 updates its firmware version according to the second eUICC firmware version update package.

[0317] S424. eUICC2 updates the eUICC firmware version information in the second eUICC information.

[0318] Specifically, the specific implementation of steps S422 to S424 can refer to steps S319 to S321 and will not be repeated here.

[0319] It should be noted that steps S411 to S417 and steps S418 to S424 can be independent and parallel steps. In an optional embodiment, steps S411 to S417 and steps S418 to S424 can be executed simultaneously, or steps S411 to S417 can be executed after steps S418 to S424 are executed.

[0320] It should be understood that the definitions of the first eUICC firmware version update package and the second eUICC firmware version update package may be the same as the definition of the eUICC firmware version update package in step S318, that is, the eUICC firmware version update package in step S318 may include the first eUICC firmware version update and / or the second eUICC firmware version update package.

[0321] exist Figure 5 In the described method, eUICC1 and eUICC2 belong to different manufacturers. When the eUICC firmware versions of both eUICC1 and eUICC2 need to be updated, the eUICC firmware versions of eUICC1 and eUICC2 can be updated in parallel. The LPA can send different event records and eUICC firmware version update packages to the corresponding eUICCs based on the EID of eUICC1 and the EID of eUICC2, thereby improving the efficiency of the eUICC firmware version update.

[0322] The following describes the case where eUICC1 and eUICC2 are from the same manufacturer. Assuming that the update servers corresponding to eUICC1 and eUICC2 are both OPS, the implementation process can be as follows: Figure 6 shown. Figure 6 This is a flowchart of another method for updating the eUICC firmware version provided by an embodiment of the present application. As shown in the figure, the method includes:

[0323] S501. The OPS sends an event registration request to the SM-DS. The event registration request carries a group event identifier. The SM-DS receives the event registration request. The group event identifier includes at least one eUICC firmware version and at least one issuer identifier.

[0324] S502. The SM-DS saves an event record, where the event record includes a group event identifier.

[0325] S503. The LPA establishes an HTTPS connection with the SM-DS.

[0326] Specifically, the specific implementation of steps S501 to S503 can refer to the description of steps S301 to S303 and will not be repeated here.

[0327] S504. eUICC1 sends first sub-information to the LPA. The LPA receives the first sub-information, where the first sub-information includes a first target identifier.

[0328] S505. eUICC2 sends the second sub-information to the LPA. The LPA receives the second sub-information, where the second sub-information includes the second target identifier.

[0329] S506. The LPA sends first information to the SM-DS. The first information includes first sub-information and second sub-information. The SM-DS receives the first information.

[0330] Specifically, the specific implementation of steps S504 to S506 can refer to the description of steps S406 to S408 and will not be repeated here.

[0331] S507. The SM-DS searches for a target event record in the currently saved event record, where the group event identifier in the target event record matches the first target identifier and the second target identifier respectively.

[0332] In the embodiment of the present application, eUICC1 and eUCC2 belong to the same manufacturer, and the group event identifier in the target event record can match the first target identifier and the second target identifier at the same time.

[0333] Specifically, the SM-DS can obtain the first target identifier and the second target identifier from the first information; obtain the group event identifier from the currently saved event record, and match the first target identifier and the second target identifier with the group event identifier respectively. If they are the same as the group event identifier or belong to the group event identifier, it is determined that the first target identifier and the second target identifier match the group event identifier.

[0334] Optionally, the specific implementation manner in which the SM-DS obtains the first target identifier and the second target identifier and determines that the first target identifier and the second target identifier match the group event respectively can be referred to the description in step S306 and will not be repeated here.

[0335] S508. The SM-DS sends the target event record to the LPA, and the LPA receives the target event record.

[0336] S509. The LPA obtains the first eUICC identifier of eUICC1.

[0337] S510 : The LPA sends a target event record to eUICC1 according to the first eUICC identifier, and eUICC1 receives the target event record.

[0338] Specifically, the specific implementation of steps S509 to S510 can refer to the description of steps S411 to S412 and will not be repeated here.

[0339] S511. The LPA obtains the current eUICC firmware version of eUICC1.

[0340] Optionally, the LPA may further obtain a first eUICC random number of eUICC1 (eg, eUICC1Challenge1), first eUICC information of eUICC1, etc., wherein the first eUICC information is first initial eUICC information (eg, euicc1Info1).

[0341] S512. The LPA obtains a second eUICC identifier of eUICC2.

[0342] S513: The LPA sends the target event record to eUICC1 according to the second eUICC identifier, and eUICC2 receives the target event record.

[0343] Specifically, the specific implementation of steps S512 to S513 can refer to the description of steps S418 to S419 and will not be repeated here.

[0344] S514. The LPA obtains the current eUICC firmware version of eUICC2.

[0345] Optionally, the LPA may further obtain a second eUICC random number of eUICC2 (eg, eUICC2Challenge1), second eUICC information of eUICC2, and the like, wherein the second eUICC information is second initial eUICC information (eg, euicc2Info1).

[0346] S515. The LPA establishes an HTTPS connection with the OPS.

[0347] S516 . The LPA sends the current eUICC firmware version of eUICC1 and the current eUICC firmware version of eUICC2 to the OPS. The OPS receives the current eUICC firmware version of eUICC1 and the current eUICC firmware version of eUICC2.

[0348] Optionally, the LPA may carry the current eUICC firmware version of eUICC1 and the current eUICC firmware version of eUICC2 in a second command (eg, InitiateAuthentication) and send it to the OPS.

[0349] Optionally, the second command (e.g., InitiateAuthentication) may further carry a first eUICC random number (e.g., eUICC1Challenge1), first initial eUICC information (e.g., euicc1Info1), a second eUICC random number (e.g., eUICC2Challenge1), second initial eUICC information (e.g., euicc2Info1), and an OPS address.

[0350] S517 . The OPS sends the third information to the LPA. The LPA receives the third information. The third information includes the third sub-information and the fourth sub-information.

[0351] Optionally, the type / composition / definition / structure of the third sub-information and the fourth sub-information may be the same as the third information in step S311, that is, the third information in step S311 may include third sub-information and / or fourth sub-information, the third sub-information includes the current eUICC firmware version of eUICC1, and the fourth sub-information includes the current eUICC firmware version of eUICC2.

[0352] Optionally, the third sub-information may be the third authentication sub-information in the first authentication information sent by OPS to the terminal device during the two-way authentication process between the terminal device and OPS; the fourth sub-information may be the fourth authentication sub-information in the first authentication information sent by OPS to the terminal device during the two-way authentication process between the terminal device and OPS.

[0353] S518. The LPA sends the third sub-information to the eUICC1.

[0354] S519. eUICC1 sends the fifth sub-information to the LPA. The LPA receives the fifth sub-information. The fifth sub-information includes the first target identifier.

[0355] Optionally, the fifth sub-information may be the first authentication sub-information in the second authentication information sent by the eUICC1 to the LPA during the two-way authentication process between the terminal device and the OPS.

[0356] Optionally, the fifth sub-information may include the first eUICC to-be-signed data (e.g., euicc1Signed1), the signature value of the first eUICC to-be-signed data (e.g., euicc1Signature1), the first eUICC certificate (e.g., CERT.EUICC1.ECDSA), the first eUICC manufacturer certificate (e.g., CERT.EUM1.ECDSA), and the like.

[0357] S520. The LPA sends the fourth sub-information to eUICC2.

[0358] S521. eUICC2 sends sixth sub-information to the LPA. The LPA receives the sixth sub-information, where the sixth sub-information includes a second target identifier.

[0359] Optionally, the sixth sub-information may be the second authentication sub-information in the second authentication information sent by eUICC1 to LPA during the two-way authentication process between the terminal device and the SM-DS.

[0360] Optionally, the sixth sub-information may include the second eUICC to-be-signed data (e.g., euicc2Signed1), the signature value of the second eUICC to-be-signed data (e.g., euicc2Signature1), the second eUICC certificate (e.g., CERT.EUICC2.ECDSA), the second eUICC manufacturer certificate (e.g., CERT.EUM2.ECDSA), and the like.

[0361] The specific implementation of step S518 and step S520 can refer to the description of step S312 and will not be repeated here.

[0362] It should be noted that steps S518 to S519 and steps S520 to S521 can be independent and parallel steps. In an optional embodiment, steps S518 to S519 and steps S520 to S521 can be executed simultaneously, or steps S518 to S519 can be executed after steps S520 to S521 are executed.

[0363] S522. The LPA sends second information to the OPS. The second information includes the fifth sub-information and the sixth sub-information. The OPS receives the second information.

[0364] S523 , the OPS respectively determines whether the first target identifier and the second target identifier match the locally stored group event identifier.

[0365] S524. The OPS checks whether the eUICC performance and the eUICC firmware version of eUICC1 meet the performance and firmware version requirements of the target firmware version, and checks whether the eUICC performance and the eUICC firmware version of eUICC2 meet the performance and firmware version requirements of the target firmware version.

[0366] Specifically, the specific implementation of steps S522 to S524 can refer to steps S314 to S316 and will not be repeated here.

[0367] S525 . The OPS determines, based on the current eUICC firmware version of eUICC1 , a first eUICC firmware version update package required for the terminal device to update to the target firmware version.

[0368] S526. The OPS determines, based on the current eUICC firmware version of eUICC2, a second eUICC firmware version update package required for the terminal device to update to the target firmware version.

[0369] Specifically, the specific implementation of step S525 and step S526 can refer to the description of step 317 and will not be repeated here.

[0370] It should be noted that step S525 and step S526 may be independent and parallel steps. In an optional embodiment, step S525 and step S526 may be executed simultaneously, or step S525 may be executed after step S526 is executed.

[0371] S527 . The OPS sends the first eUICC firmware version update package and the first eUICC identifier to the LPA. The LPA receives the first eUICC firmware version update package and the first eUICC identifier.

[0372] S528 : The LPA sends the first eUICC firmware version update package to eUICC1 according to the first eUICC identifier, and eUICC1 receives the first eUICC firmware version update package.

[0373] S529 : The eUICC1 updates the eUICC firmware version of the eUICC1 according to the first eUICC firmware version update package.

[0374] S530 : eUICC1 updates the eUICC firmware version in the first eUICC information.

[0375] Specifically, the specific implementation of steps S528 to S529 can refer to the description of steps S320 to S321 and will not be repeated here.

[0376] S531 : The OPS sends a second eUICC firmware version update package and a second eUICC identifier to the LPA. The LPA receives the second eUICC firmware version update package and the second eUICC identifier.

[0377] S532: The LPA sends the second eUICC firmware version update package to eUICC2 according to the second eUICC identifier, and eUICC2 receives the second eUICC firmware version update package.

[0378] S533 : eUICC2 updates its eUICC firmware version according to the second eUICC firmware version update package.

[0379] S534. eUICC2 updates the eUICC firmware version in the second eUICC information.

[0380] Specifically, the specific implementation of steps S533 to S534 can refer to the description of steps S320 to S321 and will not be repeated here.

[0381] It should be noted that steps S527 to S530 and steps S531 to S34 can be independent and parallel steps. In an optional embodiment, steps S527 to S530 and steps S531 to S34 can be executed simultaneously, or steps S527 to S530 can be executed after steps S531 to S534 are executed.

[0382] In an optional embodiment, if steps S527 to S530 and steps S531 to S534 are performed in a certain order, that is, if the eUICC firmware version of eUICC1 needs to be updated before the eUICC firmware version of eUICC2, or if the eUICC firmware version of eUICC2 needs to be updated before the eUICC firmware version of eUICC1, a notification message may be set after the previous eUICC update is completed. The notification message may include the firmware version upgrade result of the current eUICC, indicating the result of the current eUICC update. The notification message may be sent by the eUICC to the OPS via the LPA. After receiving the notification message, the OPS may send the eUICC firmware version update package of the next eUICC to the LPA.

[0383] For example, after receiving a notification message (e.g., HandleNotification) sent by eUICC1 through LPA, OPS may send the second eUICC firmware version update package and the second eUICC identifier to the second LPA; or, after receiving a notification message (e.g., HandleNotification) sent by eUICC2 through LPA, OPS may send the first eUICC firmware version update package and the first eUICC identifier to LPA.

[0384] In an optional embodiment, the notification message may include one or more of notification metadata, session identifier, final result, SM-DP+ object identifier, and eUICC signature; the notification metadata may include a sequence number and a receiving address; the final result may carry the final firmware version update status.

[0385] exist Figure 6In the method described above, eUICC1 and eUICC2 belong to the same manufacturer. When the eUICC firmware versions of both eUICC1 and eUICC2 need to be updated, the eUICC firmware versions of eUICC1 and eUICC2 are updated in parallel. The LPA obtains the target event record corresponding to both eUICC1 and eUICC from the SM-DS, and authenticates the two eUICCs simultaneously with the OPS. The LPA can send the eUICC firmware version update package to the corresponding eUICC based on the EID of eUICC1 and the EID of eUICC2, improving the efficiency of the eUICC firmware version update.

[0386] In the above embodiment, when there are two eUICCs in the terminal device, if the two eUICCs need to interact with the same remote server, the terminal device can implement two-way authentication between the two eUICCs and the remote server in parallel. The process of two-way authentication between the two eUICCs and the remote server in parallel can be as follows: Figure 7 shown. Figure 7 This is a flow chart of a two-way authentication method provided in an embodiment of the present application. As shown in the figure, the method at least includes:

[0387] S601: A terminal device sends first eUICC information of a first eUICC and second eUICC information of a second eUICC to a remote server. The remote server receives the first eUICC information of the first eUICC and the second eUICC information of the second eUICC.

[0388] Specifically, the remote server may be a server such as OPS, SM-DS, SM-DP, etc. that can perform two-way authentication with the terminal device.

[0389] S602: The remote server determines target verification information according to the first eUICC information and the second eUICC information.

[0390] Optionally, the target verification information may include a target public key identifier and a target verification certificate.

[0391] Specifically, there may be one or two target public key identifiers; there may be one or two target verification certificates.

[0392] S603: The remote server sends first authentication information to the terminal device, where the first authentication information includes target verification information, and the terminal device receives the first authentication information.

[0393] S604: The terminal device sends second authentication information to the remote server, and the remote server receives the second authentication information.

[0394] S605: The remote server verifies the second authentication information according to the target verification information.

[0395] The two-way authentication between the terminal device and the remote server is completed by the LPA and eUICC of the terminal device in cooperation with each other. The following describes the specific implementation process of the two-way authentication method of the terminal device as independent execution entities. It should be understood that after omitting the interaction steps between the LPA and the eUICC (i.e., the internal interaction process of the terminal device), the operation steps performed by the LPA and the eUICC are the operation steps performed by the terminal device. The eUICC includes a first eUICC, i.e., eUICC1, and a second eUICC, i.e., eUICC2. Figure 8 , Figure 8 This is a flowchart of another two-way authentication method provided in an embodiment of the present application.

[0396] S701. The LPA obtains first eUICC information from eUICC1.

[0397] The first eUICC information is the first initial eUICC information (eg, euicc1Info1).

[0398] Specifically, the first initial eUICC information may include a first verification public key identifier list (eg, euiccCiPKIdListForVerification1) and a first signing public key identifier list (eg, euiccCiPKIdListForSigning1).

[0399] Optionally, the first verification public key identifier list (eg, euiccCiPKIdListForVerification1) and the first signature public key identifier list (eg, euiccCiPKIdListForSigning1) may be the same as or different from each other.

[0400] Optionally, the LPA may also obtain a first eUICC random number (eg, eUICC1Challenge1) from eUICC1.

[0401] Optionally, before the LPA obtains the first eUICC random number from the eUICC1, the method further includes: the eUICC1 generates the first eUICC random number (for example, eUICC1Challenge1).

[0402] S702: The LPA obtains second eUICC information from eUICC2.

[0403] The second eUICC information is the second initial eUICC information (eg, euicc2Info1).

[0404] Specifically, the second initial eUICC information may include a second verification public key identifier list (eg, euiccCiPKIdListForVerification2) and a second signing public key identifier list (eg, euiccCiPKIdListForSigning2).

[0405] Optionally, the second verification public key identifier list (eg, euiccCiPKIdListForVerification2) and the second signing public key identifier list (eg, euiccCiPKIdListForSigning2) may be the same or different.

[0406] Optionally, the LPA may also obtain a second eUICC random number (eg, eUICC2Challenge1) from eUICC2.

[0407] Optionally, before the LPA obtains the second eUICC random number from the eUICC2, the method further includes: the eUICC2 generates a second eUICC random number (eg, eUICC2Challenge1).

[0408] It should be noted that step S701 and step S702 may be independent and parallel steps. In an optional embodiment, step S701 and step S702 may be performed simultaneously, or step S701 may be performed after step 702 is performed.

[0409] S703: The LPA establishes an HTTPS connection with the remote server.

[0410] S704 : The LPA sends the first eUICC information and the second eUICC information to the remote server, and the remote server receives the first eUICC information and the second eUICC information.

[0411] Optionally, the LPA may carry the first eUICC information and the second eUICC information in a second command (eg, InitiateAuthentication) and send it to the remote server.

[0412] Optionally, the second command (eg, InitiateAuthentication) may further carry the first eUICC random number (eg, eUICC2Challenge1), the second eUICC random number (eg, eUICC2Challenge1), and the address of the remote server.

[0413] S705: The remote server determines target verification information according to the first eUICC information and the second eUICC information.

[0414] Optionally, the target verification information may include a target signature public key identifier and a target verification certificate.

[0415] Optionally, before the remote server determines the target authentication information, the process further includes: the remote server checking an address of the remote server in a second command (eg, InitiateAuthentication); and the remote server checking the first eUICC information and the second eUICC information.

[0416] Optionally, the remote server may determine the target signing public key identifier based on a first signing public key identifier list (e.g., euiccCiPKIdListForSigning1) in the first eUICC information and a second signing public key identifier list (e.g., euiccCiPKIdListForSigning2) in the second eUICC information.

[0417] Optionally, there can be one or two target signature public key identifiers: in the first signature public key identifier list (e.g., euiccCiPKIdListForSigning1), the second signature public key identifier list (e.g., euiccCiPKIdListForSigning2), and the local certificate issuer (Certificate When the same signature public key identifier exists in the public key identifier list of the local certificate issuer (CI), the remote server can determine the signature public key identifier that exists in all three lists as the target signature public key identifier (for example, euiccCiPKIdToBeUsed); when the same signature public key identifier does not exist in the first signature public key identifier list and the second signature public key identifier list, the remote server can select the first signature public key identifier (for example, euiccCiPKIdToBeUsed1) that exists in both the first signature public key identifier list and the local certificate issuer public key identifier list, and the second signature public key identifier (for example, euiccCiPKIdToBeUsed2) that exists in both the second signature public key identifier and the local certificate issuer public key identifier list as the target signature public key identifier; that is, the target signature public key identifier can be euiccCiPKIdToBeUsed, or it can be euiccCiPKIdToBeUsed1 and euiccCiPKIdToBeUsed2.

[0418] In an optional implementation manner, the local CI public key identifier list may further include a local CI public key identifier set.

[0419] Specifically, when there are multiple identical signature public key identifiers in the first signature public key identifier list (for example, euiccCiPKIdListForSigning1), the second signature public key identifier list (for example, euiccCiPKIdListForSigning2) and the local CI public key identifier list, the CI public key identifier corresponding to the highest priority CI public key can be selected as the target signature public key identifier (for example, euiccCiPKIdToBeUsed) according to the priority order of the multiple signature public keys corresponding to the multiple identical signature public key identifiers.

[0420] Specifically, when there are multiple identical CI public key identifiers in the first signature public key identifier list (for example, euiccCiPKIdListForSigning1) and the local CI public key identifier list, the CI public key identifier corresponding to the CI public key with the highest priority can be selected as the first signature public key identifier (for example, euiccCiPKIdToBeUsed1) according to the priority order of the multiple CI public keys corresponding to the multiple identical CI public key identifiers.

[0421] Specifically, when there are multiple identical signature public key identifiers in the second signature public key identifier list (for example, euiccCiPKIdListForSigning2) and the local signature public key identifier list, the signature public key identifier corresponding to the signature public key with the highest priority can be selected as the second signature public key identifier (for example, euiccCiPKIdToBeUsed2) according to the priority order of the multiple signature public keys corresponding to the multiple identical signature public key identifiers.

[0422] Optionally, the remote server may determine the target verification certificate according to the first verification public key identifier list in the first eUICC information and the second verification public key identifier list in the second eUICC information.

[0423] Optionally, there may be one or two target verification certificates: if the same verification public key identifier exists in the first verification public key identifier list (e.g., euiccCiPKIdListForVerification1), the second verification public key identifier list (e.g., euiccCiPKIdListForVerification2), and the local certificate issuer public key identifier list, the remote server may determine the certificate corresponding to the CI public key identifier that exists in all three lists (e.g., CERT.DSauth.ECDSA) as the target verification certificate; if the same CI does not exist in the first verification public key identifier list and the second verification public key identifier list, the remote server may determine the certificate corresponding to the CI public key identifier that exists in all three lists (e.g., CERT.DSauth.ECDSA) as the target verification certificate. In the case of public key identification, the remote server can select the first target verification certificate (for example, CERT.DSauth1.ECDSA) corresponding to the first CI public key identifier that exists in both the first verification public key identification list and the local certificate issuer public key identification list, and the second target verification certificate (for example, CERT.DSauth2.ECDSA) corresponding to the second CI public key identifier that exists in both the second verification public key identification list and the local certificate issuer public key identification list as the target verification certificate; that is, the target certificate can be CERT.DSauth.ECDSA, or it can be CERT.DSauth1.ECDSA and CERT.DSauth2.ECDSA.

[0424] Specifically, when there are multiple identical CI public key identifiers in the first verification public key identifier list (for example, euiccCiPKIdListForVerification1), the second verification public key identifier list (for example, euiccCiPKIdListForVerification2), and the local certificate issuer public key identifier list, the CI public key identifier corresponding to the highest priority CI public key can be selected as the target verification public key identifier according to the priority order of the multiple CI public keys corresponding to the multiple identical CI public key identifiers, and the verification certificate corresponding to the target verification public key identifier can be determined as the target verification certificate (for example, CERT.DSauth.ECDSA).

[0425] Specifically, when there are multiple identical CI public key identifiers in the first verification public key identifier list (for example, euiccCiPKIdListForVerification1) and the local CI public key identifier list, the CI public key identifier corresponding to the highest priority CI public key can be selected as the first verification public key identifier according to the priority order of the multiple CI public keys corresponding to the multiple identical CI public key identifiers, and the verification certificate corresponding to the first verification public key identifier is the first target verification certificate (for example, CERT.DSauth1.ECDSA).

[0426] Specifically, when there are multiple identical CI public key identifiers in the second verification public key identifier list (for example, euiccCiPKIdListForVerification2) and the local verification public key identifier list, the CI public key identifier corresponding to the highest priority CI public key can be selected as the second verification public key identifier according to the priority order of the multiple CI public keys corresponding to the multiple identical CI public key identifiers, and the verification certificate corresponding to the second verification public key identifier is the second target verification certificate (for example, CERT.DSauth2.ECDSA).

[0427] Optionally, after the remote server determines the target verification information, it also includes: generating a session identifier; generating a remote server random number (for example, serverChallenge), serverChallenge includes but is not limited to OPSChallenge, DSChallenge, DPChallenge; generating first authentication verification data to be signed (for example, serverSigned11), wherein serverSigned11 includes but is not limited to DSSigned11, DPSigned11, OPSSigned11; generating second authentication verification data to be signed (for example, serverSigned12), wherein serverSigned12 includes but is not limited to DSSigned12, DPSigned12, OPSSigned12; generating a signature value of the first authentication verification data to be signed (for example, serverSignature11), serverSignature11 includes but is not limited to DSSignature11, DPSignature11, OPSSignature11; generating a signature value of the second authentication verification data to be signed (for example, serverSignature12), serverSignature12 includes but is not limited to DSSignature12, DPSignature12, OPSSignature12.

[0428] Specifically, the remote server uses the private key of the target verification certificate to sign the first authentication verification data to be signed (for example, serverSigned11) and calculates the signature value of the first authentication verification data to be signed (for example, serverSignature11); wherein, when the same CI public key identifier exists in the first verification public key identifier list, the second verification public key identifier list, and the local certificate issuer public key identifier list, the target verification certificate is CERT.DSauth.ECDSA, and when the same CI public key identifier does not exist in the first verification public key identifier list and the second verification public key identifier list, the target verification certificate is CERT.DSauth1.ECDSA.

[0429] Specifically, the remote server uses the private key of the target verification certificate to sign the second authentication verification data to be signed (for example, serverSigned12) and calculates the signature value of the second authentication verification data to be signed (for example, serverSignature12); wherein, when the same CI public key identifier exists in the first verification public key identifier list, the second verification public key identifier list, and the local certificate issuer public key identifier list, the target verification certificate is CERT.DSauth.ECDSA, and when the same CI public key identifier does not exist in the first verification public key identifier list and the second verification public key identifier list, the target verification certificate is CERT.DSauth2.ECDSA.

[0430] S706: The remote server sends first authentication information to the LPA, where the first authentication information includes target verification information. The LPA receives the first authentication information.

[0431] Optionally, the first authentication information may also include a session identifier, first authentication verification data to be signed (e.g., serverSignature11), a signature value of the first authentication verification data to be signed (e.g., serverSignature11), second authentication verification data to be signed (e.g., serverSigned12), and a signature value of the second authentication verification data to be signed (e.g., serverSignature12).

[0432] S707: The LPA obtains third authentication sub-information corresponding to the eUICC1 from the first authentication information and sends the third authentication sub-information to the eUICC1. The eUICC1 receives the third authentication sub-information.

[0433] Optionally, before the LPA sends the third authentication sub-information to the eUICC1, the LPA may further include: checking the address of the remote server.

[0434] Specifically, the third authentication sub-information may include a session identifier, the first authentication verification data to be signed (for example, serverSigned11), the signature value of the first authentication verification data to be signed (for example, serverSignature11), the target signature public key identifier, and the target verification certificate, wherein the target signature public key identifier is euiccCiPKIdToBeUsed or euiccCiPKIdToBeUsed1, and the target verification certificate is CERT.DSauth.ECDSA or CERT.DSauth1.ECDSA.

[0435] Optionally, the LPA may carry the third authentication sub-information in a third command (eg, AuthentiateServer) and send it to the eUICC1.

[0436] S708. eUICC1 verifies the third authentication sub-information.

[0437] Specifically, eUICC1 can verify the target verification certificate; use the first authentication verification data to be signed (e.g., serverSigned11) to verify the signature value of the first authentication verification data to be signed (e.g., serverSignature11); and verify the first authentication verification data to be signed (e.g., serverSigned11).

[0438] S709 : eUICC1 sends the first authentication sub-information to the LPA, and the LPA receives the first authentication sub-information.

[0439] Optionally, before the eUICC1 sends the first authentication sub-information to the LPA, the process further includes: the eUICC1 generates first eUICC data to be signed (for example, euicc1Signed1); and the eUICC1 generates a signature value of the first eUICC data to be signed (for example, euicc1Signature).

[0440] Optionally, the first authentication sub-information may include the first eUICC to-be-signed data (e.g., euicc1Signed1), the signature value of the first eUICC to-be-signed data (e.g., euicc1Signature), the first eUICC certificate (e.g., CERT.EUICC1.ECDSA), the first eUICC manufacturer certificate (e.g., CERT.EUM1.ECDSA), and the like.

[0441] S710. The LPA obtains fourth authentication sub-information corresponding to eUICC2 from the first authentication information and sends the fourth authentication sub-information to eUICC2. eUICC2 receives the fourth authentication sub-information.

[0442] Specifically, the fourth authentication sub-information may include a session identifier, the second authentication verification data to be signed (for example, serverSigned12), the signature value of the second authentication verification data to be signed (for example, serverSignature12), the target signature public key identifier, and the target verification certificate, wherein the target signature public key identifier is euiccCiPKIdToBeUsed or euiccCiPKIdToBeUsed2, and the target verification certificate is CERT.DSauth.ECDSA or CERT.DSauth2.ECDSA.

[0443] Optionally, the LPA may carry the fourth authentication sub-information in a fourth command (eg, AuthentiateServer) and send it to the eUICC2.

[0444] S711. eUICC2 verifies the fourth authentication sub-information.

[0445] Specifically, eUICC1 can verify the target verification certificate; use the second authentication verification data to be signed (e.g., serverSigned12) to verify the signature value of the second authentication verification data to be signed (e.g., serverSignature12); and verify the second authentication verification data to be signed (e.g., serverSigned12).

[0446] S712. eUICC2 sends the second authentication sub-information to the LPA, and the LPA receives the second authentication sub-information.

[0447] Optionally, before the eUICC2 sends the second authentication sub-information to the LPA, the process further includes: the eUICC2 generating second eUICC data to be signed (for example, euicc2Signed1); and the eUICC2 generating a signature value (euicc2Signature1) of the second eUICC data to be signed.

[0448] Optionally, the second authentication sub-information may include the second eUICC to-be-signed data (e.g., euicc2Signed1), the signature value of the second eUICC to-be-signed data (e.g., euicc2Signature1), the second eUICC certificate (e.g., CERT.EUICC2.ECDSA), and the second eUICC manufacturer certificate (e.g., CERT.EUM2.ECDSA).

[0449] S713: The LPA sends second authentication information to the remote server. The second authentication information includes the first authentication sub-information and the second authentication sub-information. The remote server receives the second authentication information.

[0450] Optionally, the LPA may carry the second authentication information in the first command (eg, AuthenticateClient) and send it to the remote server.

[0451] S714. The remote server verifies the second authentication information according to the target verification information.

[0452] Optionally, the remote server verifies the first eUICC certificate (e.g., CERT.EUICC1.ECDSA), the second eUICC certificate (e.g., CERT.EUICC2.ECDSA), the first eUICC manufacturer certificate (e.g., CERT.EUM1.ECDSA), and the second eUICC manufacturer certificate (e.g., CERT.EUM2.ECDSA) based on the target verification information; verifies the signature value (e.g., euicc1Signature1) of the first eUICC data to be signed using the first eUICC data to be signed (e.g., euicc1Signed1); verifies the signature value (e.g., euicc2Signature1) of the second eUICC data to be signed using the second eUICC data to be signed (e.g., euicc2Signed1); verifies the first eUICC data to be signed (e.g., euicc1Signed1); and verifies the second eUICC data to be signed (e.g., euicc2Signed1).

[0453] Optionally, after the remote server verifies the second authentication information, the remote server and the terminal device can perform other subsequent operations so that the remote server can continue to provide various services for the terminal device. For example, SM-DP+ can provide Profile download service and Profile remote management service for the terminal device; SM-DS can provide event query service for the terminal device; OPS can provide eUICC firmware version update service for the terminal device, and so on.

[0454] For example, during the eUICC firmware version update process:

[0455] In the case where the remote server is OPS, the first authentication information can be Figure 6 The third information in step S516 of the corresponding embodiment; the third authentication sub-information can be Figure 6 The third sub-information in step S516 of the corresponding embodiment; the fourth authentication sub-information can be Figure 6 The fourth sub-information in step S516 of the corresponding embodiment; the second authentication information can be Figure 6 The second information in step S521 of the corresponding embodiment; the first authentication sub-information can be Figure 6 The fifth sub-information in step S521 of the corresponding embodiment; the second authentication sub-information can be Figure 6 This corresponds to the sixth sub-information in step S521 of the embodiment.

[0456] In the case where the remote server is SM-DS, the second authentication information may be Figure 5 The corresponding embodiment steps S408 and Figure 6 The first information in step S506 of the corresponding embodiment, the first authentication sub-information can be Figure 5 The corresponding embodiment steps S408 and Figure 6 The first sub-information in step S506 of the corresponding embodiment; the second authentication sub-information can be Figure 5 The corresponding embodiment steps S408 and Figure 6 The second sub-information in step S506 of the corresponding embodiment.

[0457] exist Figure 8 In the method described, LPA can achieve bidirectional authentication between the two eUICCs of the terminal device and the remote server in parallel by establishing HTTPS once, so that after the bidirectional authentication is completed, each can complete operations on the eUICC, thereby improving operational efficiency.

[0458] The above describes in detail the method of the embodiment of the present application, and the following provides an apparatus of the embodiment of the present application.

[0459] See also Figure 9 , Figure 9 FIG is a structural diagram of a system consisting of a terminal device, an event management server, and an update server provided in an embodiment of the present application. Figure 9 The event management server 90, the terminal device 100, and the update server 120 are connected to each other by communication, such as a wifi connection, a mobile data connection, etc., so that data communication between the three can be achieved. The modules of the terminal device, the event management server, and the update server can be implemented by hardware, software, or a combination of hardware and software to implement the present application scheme. It should be understood by those skilled in the art that Figure 9 The modules described in the above can be combined or separated into several sub-blocks to implement the solution of the present application. Therefore, the content described above in the present application can support any possible combination or separation or further definition of the following modules.

[0460] like Figure 9 As shown, the event management server 90 may include:

[0461] The receiving module 901 is configured to receive first information sent by the terminal device 100, where the first information includes a target identifier;

[0462] a processing module 902 configured to search for a target event record in currently saved event records, wherein a group event identifier in the target event record matches a target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0463] The sending module 903 is configured to send the target event record to the terminal device 100 , where the target event record is used to enable the terminal device 100 to download the eUICC firmware version update package.

[0464] Optionally, the receiving module 901 is further configured to:

[0465] receiving an event registration request sent by the update server 110, wherein the event registration request carries the group event identifier;

[0466] The processing module 902 is further configured to:

[0467] The group event identifier is stored in an event record according to the event registration request.

[0468] Optionally, the group event identifier further includes a customized identifier or a country code.

[0469] Optionally, the target identifier includes at least one of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

[0470] Optionally, the customized identification includes additional issuer information or a personal identification code in a preset customized position.

[0471] Optionally, the target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC;

[0472] The processing module 902 is specifically configured to:

[0473] Searching for a first event record and a second event record in currently saved event records, respectively, wherein the group event identifier in the first event record matches the first target identifier, and the group event identifier in the second event record matches the second target identifier;

[0474] The first event record and the second event record are sent to the terminal device 100, where the first event record is used to enable the terminal device 100 to download a first eUICC firmware version update package of the first eUICC, and the second event record is used to enable the terminal device 100 to download a second eUICC firmware version update package of the second eUICC.

[0475] like Figure 9 As shown, the terminal device 100 may include:

[0476] A sending module 1001 is configured to send first information to the event management server 90, where the first information includes a target identifier;

[0477] a receiving module 1002 configured to receive a target event record obtained by the search and sent by the event management server 90, wherein a group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0478] The processing module 1003 is configured to download an eUICC firmware version update package according to the target event record;

[0479] The processing module 1003 is further configured to update the firmware version of the eUICC according to the eUICC firmware version update package.

[0480] Optionally, the group event identifier further includes a customized identifier or a country code.

[0481] Optionally, the target identifier includes at least one of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

[0482] Optionally, the customized identification includes additional issuer information or a personal identification code in a preset customized position.

[0483] Optionally, the target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC;

[0484] The receiving module 1002 is specifically configured to:

[0485] receiving a first event record and a second event record obtained by searching and sent by the event management server 90, wherein the group event identifier in the first event record matches the first target identifier, and the group event identifier in the second event record matches the second target identifier;

[0486] The processing module 1003 is specifically configured to:

[0487] downloading a first eUICC firmware version update package of the first eUICC according to the first event record;

[0488] Downloading a second eUICC firmware version update package of the second eUICC according to the second event record;

[0489] Updating the firmware version of the first eUICC according to the first eUICC firmware version update package;

[0490] Updating the firmware version of the second eUICC according to the second eUICC firmware version update package.

[0491] Optionally, the processing module 1003 is specifically configured to:

[0492] Extracting the address of the update server 110 from the target event record;

[0493] The sending module 1001 is further configured to:

[0494] Sending the current eUICC firmware version to the update server 110;

[0495] The receiving module 1002 is further configured to:

[0496] Receive an eUICC firmware version update package sent by the update server 110 according to the current eUICC firmware version.

[0497] Optionally, the sending module 1001 is further configured to:

[0498] Sending second information to the update server 110, where the second information includes a target identifier;

[0499] The receiving module 1002 is specifically configured to:

[0500] and receiving an eUICC firmware version update package sent by the update server 110 according to the current eUICC firmware version when the target identifier in the second information matches the group event identifier stored in the update server 110 .

[0501] Optionally, the processing module 1003 is specifically configured to:

[0502] The eUICC firmware version in the eUICC information is updated according to first data in the eUICC firmware version update package, wherein the first data includes a target firmware version.

[0503] Optionally, the receiving module 1002 is further configured to:

[0504] receiving second data sent by the update server 110, wherein the second data includes a target firmware version;

[0505] The processing module 1003 is further configured to:

[0506] The eUICC firmware version in the eUICC information is updated according to the second data.

[0507] like Figure 9 As shown, the update server 110 may include:

[0508] A sending module 1101 is configured to send an event registration request to the event management server 90, wherein the event registration request carries a group event identifier, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0509] The event registration request is used to enable the event management server 90 to save the group event identifier in the event record, and send the event record to the terminal device 100 when receiving the first information sent by the terminal device matching the group event identifier.

[0510] Optionally, the update server 110 further includes:

[0511] The receiving module 1102 is configured to receive the current eUICC firmware version of the terminal device sent by the terminal device 100;

[0512] The processing module 1103 is configured to determine, based on the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device 100 to a target firmware version;

[0513] The sending module 1101 is further configured to send the eUICC firmware version update package to the terminal device 100 , where the eUICC firmware version update package is used by the terminal device 100 to update the firmware version of the eUICC of the terminal device.

[0514] Optionally, the receiving module 1102 is further configured to:

[0515] receiving second information sent by the terminal device 100, where the second information includes eUICC capabilities and an eUICC firmware version;

[0516] The processing module 1103 is specifically configured to:

[0517] If it is determined that the eUICC performance and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device 100 to the target firmware version is determined according to the current eUICC firmware version.

[0518] Optionally, the second information further includes a target identifier;

[0519] The processing module 1103 is further configured to:

[0520] When the target identifier in the second information matches the locally stored group event identifier, determining whether the eUICC performance and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version.

[0521] Need to explain, Figure 9 For details not mentioned in the corresponding embodiments and the specific implementation of each module, please refer to Figure 2 、 Figure 3 、 Figure 4 、 Figure 5 or Figure 6 The embodiments of the method shown are not described in detail here.

[0522] exist Figure 9In the described system, the event management server, the terminal device, and the update server cooperate with each other to complete the update of the firmware version of the eUICC of the terminal device. By matching the group event identifier, it is possible to avoid registering multiple events, thereby improving the efficiency of event registration and eUICC firmware version update.

[0523] In a possible implementation, the processing module 902 may be a processor or a processing chip, the receiving module 901 and the sending module 903 may be transceivers, and the event management server may further include a memory for storing event records and computer instructions. Figure 9 For an implementation of the event management server involved in the corresponding embodiment, see Figure 10 , Figure 10 1 is a schematic diagram of the hardware structure of an event management server provided in an embodiment of the present application. The event management server 120 includes a processor 1201, a memory 1202, and a transceiver 1203, wherein the processor 1201, the memory 1202, and the transceiver 1203 are connected via one or more communication buses.

[0524] The processor 1201 is configured to support the event management server to execute Figure 2 、 Figure 4 、 Figure 5 or Figure 6 The corresponding functions in the method for updating the eUICC firmware version. The processor 1201 can be a central processing unit (CPU), a network processor (NP), a hardware chip, or any combination thereof. The above-mentioned hardware chip can be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above-mentioned PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0525] Memory 1202 is used to store program code, etc. Memory 1202 may include volatile memory, such as random access memory (RAM); non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or a combination of the aforementioned types of memory.

[0526] The transceiver 1203 is used to receive and send data.

[0527] The processor 1201 may call the program code to perform the following operations:

[0528] receiving, through the transceiver 1203, first information sent by the terminal device, where the first information includes a target identifier;

[0529] Searching for a target event record in currently saved event records, wherein a group event identifier in the target event record matches an event identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0530] The target event record is sent to the terminal device through the transceiver 1203, where the target event record is used to enable the terminal device to download the eUICC firmware version update package.

[0531] It should be noted that the processor 1201 can also execute reference Figure 2 、 Figure 4 、 Figure 5 or Figure 6 The methods shown are the actions performed by the event management server.

[0532] The embodiment of the present application further provides a computer storage medium storing a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer executes the following Figure 2 、 Figure 4 、 Figure 5 or Figure 6 In the method described in the corresponding embodiment, the computer may be a part of the event management server mentioned above.

[0533] The present application also provides a computer program including program instructions, which are used to execute the following when executed by a computer: Figure 2 、 Figure 4 、 Figure 5 or Figure 6 In the method described in the corresponding embodiment, the computer program may be a part of the program stored in the memory 1202 mentioned above.

[0534] In one possible implementation, the terminal device may include at least one eUICC and a local file assistant (LPA). The local file assistant (LPA) may exist as one or more software modules on a hardware module of the terminal device, such as a baseband chip, an application processor, or other hardware. The local file assistant (LPA) may also exist directly on the eUICC. The local file assistant (LPA) has the function of enabling interaction between the eUICC and the terminal device and servers outside the terminal device. Figure 11 , Figure 11 FIG. 1 is a structural diagram of a local file assistant provided in an embodiment of the present application. As shown in the figure, the local file assistant 130 includes:

[0535] A sending module 1301 is configured to send first information to an event management server, where the first information includes a target identifier;

[0536] a receiving module 1302 configured to receive a target event record obtained by the search and sent by the event management server, wherein a group event identifier in the target event record matches the target identifier in the first information, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0537] The processing module 1303 is configured to download an eUICC firmware version update package according to the target event record;

[0538] The sending module 1301 is further configured to send the eUICC firmware version update package to the eUICC, where the eUICC firmware version update package is used by the eUICC to update the eUICC firmware version.

[0539] Optionally, the target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC;

[0540] The receiving module 1302 is specifically configured to:

[0541] Receiving a first event record and a second event record obtained by searching and sent by the event management server, wherein the group event identifier in the first event record matches the first target identifier, and the group event identifier in the second event record matches the second target identifier;

[0542] The processing module 1303 is specifically configured to:

[0543] downloading a first eUICC firmware version update package of the first eUICC according to the first event record;

[0544] Downloading a second eUICC firmware version update package of the second eUICC according to the second event record;

[0545] The sending module 1301 is specifically configured to:

[0546] Sending the first eUICC firmware version update package to the first eUICC, where the first eUICC uses the first eUICC to update the eUICC firmware version of the first eUICC;

[0547] The second eUICC firmware version update package is sent to the second eUICC, where the second eUICC firmware version update package is used by the second eUICC to update the eUICC firmware version of the second eUICC.

[0548] Optionally, the sending module 1301 is further configured to:

[0549] sending the first event record to the first eUICC according to the first eUICC identifier;

[0550] The sending module 1301 is further configured to:

[0551] sending the second event record to the second eUICC according to the second eUICC identifier.

[0552] Optionally, while the processing module 1303 downloads the first eUICC firmware version update package of the first eUICC according to the first event record, the receiving module 1302 further receives a first eUICC identifier sent by an update server corresponding to the first eUICC;

[0553] While the processing module 1303 downloads the second eUICC firmware version update package of the second eUICC according to the second event record, the receiving module 1302 also receives a second eUICC identifier sent by the update server corresponding to the second eUICC;

[0554] The sending module 1301 is specifically configured to:

[0555] Sending the first eUICC firmware version update package to the first eUICC according to the first eUICC identifier;

[0556] Sending the second eUICC firmware version update package to the second eUICC according to the second eUICC identifier.

[0557] The present application also provides a computer program including program instructions, which are used to execute the following when executed by a computer: Figure 4 、 Figure 5 or Figure 6 In the method described in the corresponding embodiment, the computer program may be a part of the program corresponding to the local file assistant 130.

[0558] In a possible implementation, the processing module 1103 may be a processor or a processing chip, the sending module 1101 and the receiving module 1102 may be transceivers, and the update server may further include a memory for storing event records and computer instructions. Figure 9 For an implementation of the update server involved in the corresponding embodiment, see Figure 12 , Figure 12 This is a hardware structure diagram of an update server provided by the implementation of this application. The update server 140 includes a processor 1401, a memory 1402, and a transceiver 1402. The processor 1401, the memory 1402, and the transceiver 1402 are connected via one or more communication buses 1404.

[0559] The processor 1401 is configured to support the update server to execute Figure 2 、 Figure 3 、 Figure 5 or Figure 6 The corresponding functions in the method for updating the eUICC firmware version. The processor 1401 can be a central processing unit (CPU), a network processor (NP), a hardware chip, or any combination thereof. The above-mentioned hardware chip can be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above-mentioned PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0560] Memory 1402 is used to store program code, etc. Memory 1402 may include volatile memory, such as random access memory (RAM); non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or a combination of the aforementioned types of memory.

[0561] The transceiver 1403 is used to receive and send data.

[0562] The processor 1401 may call the program code to perform the following operations:

[0563] Sending an event registration request to an event management server, wherein the event registration request carries a group event identifier, and the group event identifier includes at least one eUICC firmware version and at least one issuer identifier;

[0564] The event registration request is used to enable the event management server to save the group event identifier in an event record, and send the event record to the terminal device when receiving first information sent by a terminal device matching the group event identifier.

[0565] It should be noted that the processor 1401 can also execute reference Figure 3 、 Figure 4 、 Figure 5 or Figure 6 The methods shown update the actions performed by the server.

[0566] The embodiment of the present application further provides a computer storage medium storing a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer executes the following Figure 3 、 Figure 4 、 Figure 5 or Figure 6 In the method described in the corresponding embodiment, the computer may be a part of the update server mentioned above.

[0567] The present application also provides a computer program including program instructions, which are used to execute the following when executed by a computer: Figure 3 、 Figure 4 、 Figure 5 or Figure 6In the method described in the corresponding embodiment, the computer program may be a part of the program stored in the memory 1402 mentioned above.

[0568] See also Figure 13 , Figure 13 This is a structural diagram of a system consisting of a remote server and a terminal device provided in an embodiment of the present application. As shown in the figure, there is a communication connection between the remote server 150 and the terminal device 160, such as a wifi connection, a mobile data connection, etc., which can realize data communication between the remote server 150 and the terminal device 160. The modules of the terminal device and the remote server can be implemented by hardware, software, or a combination of hardware and software to implement the present application scheme. It should be understood by those skilled in the art that Figure 13 The modules described in the above can be combined or separated into several sub-blocks to implement the solution of the present application. Therefore, the content described above in the present application can support any possible combination or separation or further definition of the following modules.

[0569] like Figure 13 As shown, the remote server 150 may include:

[0570] The receiving module 1501 is configured to receive first eUICC information of a first eUICC of a terminal device 160 and second eUICC information of a second eUICC of the terminal device 160;

[0571] The processing module 1502 is configured to determine target verification information based on the first eUICC information and the second eUICC information;

[0572] A sending module 1503 is configured to send first authentication information to the terminal device 160, wherein the first authentication information includes the target verification information;

[0573] The receiving module 1501 is further configured to receive second authentication information sent by the terminal device 160 after the first eUICC and the second eUICC successfully verify the first authentication information;

[0574] The processing module 1502 is further configured to verify the second authentication information according to the target verification information.

[0575] Optionally, the target verification information includes a target signature public key identifier, the first eUICC information includes a first signature public key identifier list of the first eUICC, and the second eUICC information includes a second signature public key identifier list of the second eUICC;

[0576] The processing module 1502 is specifically configured to:

[0577] Selecting a first target signature public key identifier from the first signature public key identifier list, where the first target signature public key identifier also exists in the local certificate issuer public key identifier list;

[0578] Selecting a second target signature public key identifier from the second signature public key identifier list, where the second target signature public key identifier also exists in the local certificate issuer public key identifier list;

[0579] The first target signature public key identifier and the second target signature public key identifier are determined as target signature public key identifiers.

[0580] Optionally, the processing module 1502 is further configured to:

[0581] When the same signature public key identifier exists in the first signature public key identifier list and the second signature public key identifier list, the same signature public key identifier is determined as the target signature public key identifier, and the same signature public key identifier also exists in the local certificate issuer public key identifier list.

[0582] Optionally, the target verification information includes a target verification certificate, the first eUICC information includes a first verification public key identifier list of the first eUICC, and the second eUICC information includes a second verification public key identifier list of the second eUICC;

[0583] The processing module 1502 is specifically configured to:

[0584] Selecting a first target verification public key identifier from the first verification public key identifier list, where the first target verification public key identifier also exists in the local certificate issuer public key identifier list;

[0585] Selecting a second target verification public key identifier from the second verification public key identifier list, where the second target verification public key identifier also exists in the local certificate issuer public key identifier list;

[0586] A first target verification certificate corresponding to the first target verification public key identifier and a second target verification certificate corresponding to the second target verification public key identifier are determined as target verification certificates.

[0587] Optionally, the processing module 1502 is further configured to:

[0588] When the same verification public key identifier exists in the first verification public key identifier list and the second verification public key identifier list, the verification certificate corresponding to the same verification public key identifier is determined as the target verification certificate, and the same verification signature public key identifier also exists in the local certificate issuer public key identifier list.

[0589] like Figure 13As shown, the terminal device 160 may include:

[0590] The sending module 1601 is configured to send first eUICC information of a first eUICC and second eUICC information of a second eUICC to a remote server;

[0591] A receiving module 1602 is configured to receive first authentication information sent by the remote server, wherein the first authentication information includes target verification information;

[0592] The sending module 1601 is further configured to send second authentication information to the remote server if the first eUICC and the second eUICC successfully verify the first authentication information.

[0593] Optionally, the terminal device further includes a processing module 1603, configured to instruct the sending module 1601 to send data, the receiving module 1602 to receive data, and the first eUICC and the second eUICC to verify the first authentication information.

[0594] Optionally, the target verification information includes a first target signing public key identifier and a second target signing public key identifier, wherein the first target signing public key identifier is selected by the remote server from a first signing public key identifier list of the first eUICC, and the first target signing public key identifier is also present in a local certificate issuer public key identifier list of the remote server, and the second target signing public key identifier is selected by the remote server from a second signing public key identifier list of the second eUICC, and the second target signing public key identifier is also present in the local certificate issuer public key identifier list.

[0595] Optionally, the target verification information includes a target signature public key identifier, wherein the target signature public key identifier exists in the first signature public key identifier list of the first eUICC, the second signature public key identifier list of the second eUICC, and the local certificate issuer public key identifier list of the remote server.

[0596] Optionally, the target verification information includes a first target verification certificate corresponding to a first target verification public key identifier and a second target verification certificate corresponding to a second target verification public key identifier, wherein the first target verification public key identifier is selected by the remote server from a first verification public key identifier list of the first eUICC, and the first target verification public key identifier is also present in a local certificate issuer public key identifier list of the remote server, and the second target verification public key identifier is selected by the remote server from a second verification public key identifier list of the second eUICC, and the second target verification public key identifier is also present in the local certificate issuer public key identifier list.

[0597] Optionally, the target verification information includes a target verification certificate, wherein the target verification certificate is a verification certificate corresponding to a target verification public key identifier that exists in the first verification public key identifier list of the first eUICC, the second verification public key identifier list of the second eUICC, and the local certificate issuer public key identifier list of the remote server.

[0598] Need to explain, Figure 13 For details not mentioned in the corresponding embodiments and the specific implementation of each module, please refer to Figure 7 or Figure 8 The embodiments of the method shown are not described in detail here.

[0599] exist Figure 13 In the described system, simultaneous bidirectional authentication of two eUICCs can be achieved between the remote server and the terminal device, which helps to improve the efficiency of bidirectional authentication.

[0600] In a possible implementation, the processing module 1502 may be a processor or a processing chip, the receiving module 1501 and the sending module 1503 may be transceivers, and the remote server may further include a memory. Figure 13 An implementation of the remote server involved in the system, see Figure 14 , Figure 14 170 is a schematic diagram of the hardware structure of a remote server provided in an embodiment of the present application. The remote server 170 includes a processor 1701, a memory 1702, and a transceiver 1703, wherein the processor 1701, the memory 1702, and the transceiver 1703 are connected via one or more communication buses 1704.

[0601] The processor 1701 is configured to support the remote server to execute Figure 7 or Figure 8The corresponding function in the described two-way authentication method. The processor 1701 can be a central processing unit (CPU), a network processor (NP), a hardware chip, or any combination thereof. The above-mentioned hardware chip can be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above-mentioned PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0602] Memory 1702 is used to store program code, etc. Memory 1702 may include volatile memory, such as random access memory (RAM); non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or a combination of the aforementioned types of memory.

[0603] The transceiver 1703 is used to receive and send data.

[0604] The processor 1701 may call the program code to perform the following operations:

[0605] Receiving first eUICC information of a first eUICC of a terminal device and second eUICC information of a second eUICC of the terminal device;

[0606] determining target verification information according to the first eUICC information and the second eUICC information;

[0607] Sending first authentication information to the terminal device, wherein the first authentication information includes the target verification information;

[0608] receiving second authentication information sent by the terminal device after the first eUICC and the second eUICC successfully verify the first authentication information;

[0609] The second authentication information is verified according to the target verification information.

[0610] It should be noted that the processor 1701 can also execute reference Figure 7 or Figure 8 The actions performed by the remote server in the method shown.

[0611] The embodiment of the present application further provides a computer storage medium storing a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer executes the following Figure 7 or Figure 8 In the method described in the corresponding embodiment, the computer may be a part of the remote server mentioned above.

[0612] The present application also provides a computer program including program instructions, which are used to execute the following when executed by a computer: Figure 7 or Figure 8 In the method described in the corresponding embodiment, the computer program may be a part of the program stored in the memory 1702 mentioned above.

[0613] In one possible implementation, the terminal device may include two eUICCs and a local file assistant (LPA). The local file assistant (LPA) may exist as one or more software modules on a hardware module of the terminal device, such as a baseband chip, an application processor, or other hardware. The local file assistant may also exist directly on the eUICC. The local file assistant (LPA) has the function of enabling interaction between the eUICC and the terminal device and the remote server. Figure 15 , Figure 15 FIG1 is a structural diagram of a local file assistant provided in an embodiment of the present application. As shown in the figure, the local file assistant 180 includes:

[0614] The sending module 1801 is configured to send first eUICC information of a first eUICC and second eUICC information of a second eUICC to a remote server;

[0615] A receiving module 1802 is configured to receive first authentication information sent by the remote server, wherein the first authentication information includes target verification information;

[0616] The sending module 1801 is further configured to send second authentication information to the remote server if the first eUICC and the second eUICC successfully verify the first authentication information, where the second authentication information includes the first authentication sub-information sent by the first eUICC and the second authentication sub-information sent by the second eUICC.

[0617] Optionally, the receiving module 1802 is further configured to:

[0618] acquiring the first eUICC information from the first eUICC;

[0619] Acquire the second eUICC information from the second eUICC.

[0620] Optionally, the local file assistant 180 further includes a processing module 1803;

[0621] The processing module 1803 is configured to obtain third authentication sub-information corresponding to the first eUICC from the first authentication information, and the sending module is further configured to send the third authentication sub-information to the first eUICC;

[0622] The receiving module 1802 is further configured to receive the first authentication sub-information sent by the first eUICC after successfully verifying the third authentication sub-information;

[0623] The processing module 1803 is further configured to obtain fourth authentication sub-information corresponding to the second eUICC from the first authentication information, and the sending module 1801 is further configured to send the fourth authentication sub-information to the second eUICC;

[0624] The receiving module 1802 is further configured to receive the second authentication sub-information sent by the second eUICC after the second eUICC successfully verifies the fourth authentication sub-information.

[0625] Optionally, the target verification information includes a first target signing public key identifier and a second target signing public key identifier, wherein the first target signing public key identifier is selected by the remote server from a first signing public key identifier list of the first eUICC, and the first target signing public key identifier is also present in a local certificate issuer public key identifier list of the remote server, and the second target signing public key identifier is selected by the remote server from a second signing public key identifier list of the second eUICC, and the second target signing public key identifier is also present in the local certificate issuer public key identifier list;

[0626] The third authentication sub-information carries the first target signature public key identifier, and the fourth authentication sub-information carries the second target signature public key identifier.

[0627] Optionally, the target verification information includes a target signature public key identifier, wherein the target signature public key identifier exists in a first signature public key identifier list of the first eUICC, a second signature public key identifier list of the second eUICC, and a local certificate issuer public key identifier list of the remote server.

[0628] The third authentication sub-information and the fourth authentication sub-information both carry the target signature public key identifier.

[0629] Optionally, the target verification information includes a first target verification certificate corresponding to a first target verification public key identifier and a second target verification certificate corresponding to a second target verification public key identifier, wherein the first target verification public key identifier is selected by the remote server from a first verification public key identifier list of the first eUICC, and the first target verification public key identifier is also present in a local certificate issuer public key identifier list of the remote server, and the second target verification public key identifier is selected by the remote server from a second verification public key identifier list of the second eUICC, and the second target verification public key identifier is also present in the local certificate issuer public key identifier list.

[0630] The third authentication sub-information carries the first target verification certificate, and the fourth authentication sub-information carries the second target verification certificate.

[0631] Optionally, the target verification information includes a target verification certificate, wherein the target verification certificate is a verification certificate corresponding to a target verification public key identifier that exists in a first verification public key identifier list of the first eUICC, a second verification public key identifier list of the second eUICC, and a local certificate issuer public key identifier list of the remote server.

[0632] The third authentication sub-information and the fourth authentication sub-information both carry the target verification certificate.

[0633] The present application also provides a computer program including program instructions, which are used to execute the following when executed by a computer: Figure 7 or Figure 8 In the method described in the corresponding embodiment, the computer program may be a part of the program corresponding to the local file assistant 180.

[0634] The following introduces Figure 9 or an implementation of the terminal device involved in the system of 13, see Figure 16 , Figure 16 This is a structural diagram of an implementation method of terminal equipment, such as Figure 16As shown, the terminal device 190 may include a baseband chip 1910 , a memory 1915 (one or more computer-readable storage media), a radio frequency (RF) module 1916 , and a peripheral system 1917 . These components may communicate over one or more communication buses 1919 .

[0635] The peripheral system 1917 is primarily used to implement interactive functions between the terminal device 190 and the user / external environment, and primarily includes the input and output devices of the terminal device 190. Specifically, the peripheral system 1917 may include a camera controller 1918, an audio controller 1919, and a sensor management module 1920. Each controller may be coupled to a corresponding peripheral device (such as a camera 1921, an audio circuit 1922, and a sensor 1923). In some embodiments, the camera 1921 may be a 3D camera. In some embodiments, the sensor 1923 may be an infrared sensor, a fingerprint sensor, a displacement sensor, an energy consumption sensor, a temperature sensor, a humidity sensor, a light sensor, and the like. It should be noted that the peripheral system 1917 may also include other I / O peripherals. For example, the peripheral system 1917 may also include a radio frequency identification (RFID) read / write controller 1924, wherein the RFID read / write controller is coupled to an RFID reader / writer 1925.

[0636] The baseband chip 1910 may include a processor 1911, a clock module 1912, and a power management module 1913. The clock module 1912 integrated into the baseband chip 1910 is primarily used to generate the clock required for data transmission and timing control for the processor 1911. The power management module 1913 integrated into the baseband chip 1910 is primarily used to provide stable, high-precision voltages for the processor 1911, the radio frequency module 1916, and the peripheral system 1917. In some embodiments, the processor may be a central processing unit (CPU), an embedded microcontroller unit (MCU), an embedded microprocessor unit (MPU), an embedded system on chip (SoC), and the like.

[0637] The RF module 1916 is used to receive and transmit RF signals and primarily integrates the receiver and transmitter of the terminal device 190. The RF module 1916 communicates with the communication network and other communication devices via RF signals. In a specific implementation, the RF module 1916 may include, but is not limited to, at least one eUICC, an antenna system, an RF transceiver, one or more amplifiers, a tuner, one or more oscillators, a digital signal processor, a CODEC chip, and storage media. In some embodiments, the RF module 1916 may be implemented on a separate chip.

[0638] The memory 1915 is coupled to the processor 1911 and is used to store various software programs and / or multiple groups of commands. In a specific implementation, the memory 1915 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more disk storage devices, flash memory devices or other non-volatile solid-state storage devices. The memory 1915 can store an operating system (hereinafter referred to as the system), such as an embedded operating system such as ANDROID, IOS, WINDOWS or LINUX. The memory 1915 can also store a network communication program, which can be used to communicate with one or more additional devices, one or more terminal devices, and one or more network devices. The memory 1915 can also store a user interface program, which can display the content of the application program vividly through a graphical operating interface, and receive user control operations on the application program through input controls such as menus, dialog boxes and buttons. The memory 1915 can also store one or more applications including a local file assistant LPA.

[0639] The embodiment of the present application further provides a computer storage medium storing a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer executes the following Figures 2 to 4 、 Figures 5 to 8 In the method described in the corresponding embodiment, the computer may be a part of the terminal device mentioned above.

[0640] The present application also provides a computer program including program instructions, which are used to execute the following when executed by a computer: Figures 2 to 4 、 Figures 5 to 8 In the method described in the corresponding embodiment, the computer program may be a part of the program stored in the memory 1915 mentioned above.

[0641] During implementation, each step of the above method can be completed by an integrated logic circuit of hardware in a processor or by instructions in the form of software. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in a memory, and the processor executes the instructions in the memory, and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it will not be described in detail here.

[0642] It should be understood that the term "and / or" in this document simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the related objects are in an "or" relationship.

[0643] Those skilled in the art will appreciate that the various method steps and modules described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0644] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and modules described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0645] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the modules is merely a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules, or can be electrical, mechanical or other forms of connection.

[0646] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the embodiments of the present application.

[0647] In addition, the functional modules in the various embodiments of the present application may be integrated into a processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The above-mentioned integrated modules may be implemented in the form of hardware or software functional modules.

[0648] If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0649] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A method for updating the eUICC firmware version, characterized in that: include: receiving first information sent by a terminal device, where the first information includes a target identifier; searching for a target event record in currently saved event records, wherein at least one eUICC firmware version and at least one issuer identifier in the target event record match the target identifier in the first information, and the at least one eUICC firmware version and the at least one issuer identifier correspond to multiple eUICCs; The target event record is sent to the terminal device, where the target event record is used to enable the terminal device to download the eUICC firmware version update package based on the at least one eUICC firmware version and the at least one issuer identifier in the target event record.

2. The method according to claim 1, wherein The receiving of the first information sent by the terminal device also includes: Receive an event registration request sent by the update server, wherein the event registration request carries the at least one eUICC firmware version and at least one issuer identifier and saving the at least one eUICC firmware version and the at least one issuer identifier in an event record according to the event registration request.

3. The method according to any one of claims 1 to 2, characterized in that The target identifier includes at least one of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

4. The method according to claim 3, wherein The customized identification includes additional issuer information or a personal identification code in a preset customized position.

5. The method according to any one of claims 1 to 2, characterized in that The target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC; The step of searching for a target event record in the currently saved event records includes: searching for a first event record and a second event record in currently saved event records, respectively, wherein at least one eUICC firmware version and at least one issuer identifier in the first event record match the first target identifier, and at least one eUICC firmware version and at least one issuer identifier in the second event record match the second target identifier; The sending the target event record to the terminal device includes: The first event record and the second event record are sent to the terminal device, where the first event record is used to enable the terminal device to download a first eUICC firmware version update package of the first eUICC, and the second event record is used to enable the terminal device to download a second eUICC firmware version update package of the second eUICC.

6. A method for updating the eUICC firmware version, characterized in that: include: Sending first information to an event management server, where the first information includes a target identifier; receiving a target event record obtained by the search and sent by the event management server, wherein at least one eUICC firmware version and at least one issuer identifier in the target event record match the target identifier in the first information, and the at least one eUICC firmware version and the at least one issuer identifier correspond to multiple eUICCs; Downloading an eUICC firmware version update package according to the at least one eUICC firmware version and the at least one issuer identifier in the target event record; Update the eUICC firmware version according to the eUICC firmware version update package.

7. The method according to claim 6, wherein The target identifier includes at least one of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

8. The method according to claim 7, wherein The customized identification includes additional issuer information or a personal identification code in a preset customized position.

9. The method according to any one of claims 6 to 7, wherein: The target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC; The receiving of the searched target event record sent by the event management server includes: receiving a first event record and a second event record obtained by the search and sent by the event management server, wherein at least one eUICC firmware version and at least one issuer identifier in the first event record match the first target identifier, and at least one eUICC firmware version and at least one issuer identifier in the second event record match the second target identifier; Downloading the eUICC firmware version update package according to the target event record includes: downloading a first eUICC firmware version update package of the first eUICC according to the first event record; Downloading a second eUICC firmware version update package of the second eUICC according to the second event record; Updating the eUICC firmware version according to the eUICC firmware version update package includes: Updating the firmware version of the first eUICC according to the first eUICC firmware version update package; Updating the firmware version of the second eUICC according to the second eUICC firmware version update package.

10. The method according to claim 6, wherein Downloading the eUICC firmware version update package according to the target event record includes: Extracting an address of an update server from the target event record; Sending the current eUICC firmware version to the update server; Receive an eUICC firmware version update package sent by the update server according to the current eUICC firmware version.

11. The method according to claim 10, wherein Before receiving the eUICC firmware version update package sent by the update server according to the current eUICC firmware version, the method further includes: Sending second information to the update server, where the second information includes a target identifier; The receiving the eUICC firmware version update package sent by the update server according to the current eUICC firmware version includes: and receiving an eUICC firmware version update package sent by the update server according to the current eUICC firmware version when a target identifier in the second information matches at least one eUICC firmware version and at least one issuer identifier stored in the update server.

12. The method according to claim 10, wherein After updating the eUICC firmware version according to the eUICC firmware version update package, the method further includes: Update the eUICC firmware version in the eUICC information.

13. The method according to claim 12, wherein: The eUICC firmware version in the eUICC update information includes: The eUICC firmware version in the eUICC information is updated according to first data in the eUICC firmware version update package, wherein the first data includes a target firmware version.

14. The method according to claim 12, wherein: After sending the current firmware version to the update server, the method further includes: receiving second data sent by the update server, wherein the second data includes a target firmware version; The eUICC firmware version in the eUICC update information includes: The eUICC firmware version in the eUICC information is updated according to the second data.

15. A method for updating the eUICC firmware version, characterized in that: include: Sending first information to an event management server, where the first information includes a target identifier; receiving a target event record obtained by the search and sent by the event management server, wherein at least one eUICC firmware version and at least one issuer identifier in the target event record match the target identifier in the first information, and the at least one eUICC firmware version and the at least one issuer identifier correspond to multiple eUICCs; Downloading an eUICC firmware version update package according to the at least one eUICC firmware version and the at least one issuer identifier in the target event record; The eUICC firmware version update package is sent to the eUICC, where the eUICC firmware version update package is used by the eUICC to update the firmware version of the eUICC.

16. The method according to claim 15, wherein The target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC; The receiving of the searched target event record sent by the event management server includes: receiving a first event record and a second event record obtained by the search and sent by the event management server, wherein at least one eUICC firmware version and at least one issuer identifier in the first event record match the first target identifier, and at least one eUICC firmware version and at least one issuer identifier in the second event record match the second target identifier; Downloading the eUICC firmware version update package according to the target event record includes: downloading a first eUICC firmware version update package of the first eUICC according to the first event record; Downloading a second eUICC firmware version update package of the second eUICC according to the second event record; The sending the eUICC firmware version update package to the eUICC includes: Sending the first eUICC firmware version update package to the first eUICC, where the first eUICC uses the first eUICC to update the eUICC firmware version of the first eUICC; The second eUICC firmware version update package is sent to the second eUICC, where the second eUICC firmware version update package is used by the second eUICC to update the eUICC firmware version of the second eUICC.

17. The method according to claim 16, wherein Before downloading the first eUICC firmware version update package of the first eUICC according to the first event record, the method further includes: sending the first event record to the first eUICC according to the first eUICC identifier; Before downloading the second eUICC firmware version update package of the second eUICC according to the second event record, the method further includes: sending the second event record to the second eUICC according to the second eUICC identifier.

18. The method according to claim 17, wherein The downloading the first eUICC firmware version update package of the first eUICC according to the first event record includes: while downloading the first eUICC firmware version update package of the first eUICC according to the first event record, also receiving a first eUICC identifier sent by an update server corresponding to the first eUICC; The downloading the second eUICC firmware version update package of the second eUICC according to the second event record includes: while downloading the second eUICC firmware version update package of the second eUICC according to the second event record, also receiving a second eUICC identifier sent by an update server corresponding to the second eUICC; The sending the first eUICC firmware version update package to the first eUICC includes: Sending the first eUICC firmware version update package to the first eUICC according to the first eUICC identifier; The sending the second eUICC firmware version update package to the second eUICC includes: Sending the second eUICC firmware version update package to the second eUICC according to the second eUICC identifier.

19. A method for updating the eUICC firmware version, characterized in that: include: Sending an event registration request to an event management server, wherein the event registration request carries at least one eUICC firmware version and at least one issuer identifier, where the at least one eUICC firmware version and the at least one issuer identifier correspond to multiple eUICCs; The event registration request is used to cause the event management server to save the at least one eUICC firmware version and the at least one issuer identifier in an event record, and to send the event record to the terminal device upon receiving first information sent by a terminal device that matches the at least one eUICC firmware version and the at least one issuer identifier.

20. The method according to claim 19, wherein After sending the event registration request to the event management server, the method further includes: Receiving a current eUICC firmware version of the terminal device sent by the terminal device; Determining, according to the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device to a target firmware version; The eUICC firmware version update package is sent to the terminal device, where the eUICC firmware version update package is used by the terminal device to update the firmware version of the eUICC of the terminal device.

21. The method according to claim 19, wherein The determining, according to the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device to a target firmware version includes: receiving second information sent by the terminal device, where the second information includes eUICC capabilities and an eUICC firmware version; If it is determined that the eUICC performance and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version, determine, based on the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device to the target firmware version.

22. The method according to claim 21, wherein The second information also includes a target identifier; The step of determining, according to the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device to a target firmware version includes: When the target identifier in the second information matches the at least one locally stored eUICC firmware version and the at least one issuer identifier, determining whether the eUICC performance and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version.

23. An event management server, characterized in that: Including processor and transceiver, The transceiver is configured to receive first information sent by a terminal device, where the first information includes a target identifier; the processor being configured to search for a target event record in currently stored event records, wherein at least one eUICC firmware version and at least one issuer identifier in the target event record match the target identifier in the first information, and the at least one eUICC firmware version and the at least one issuer identifier correspond to multiple eUICCs; The transceiver is further configured to send the target event record to the terminal device, where the target event record is used to enable the terminal device to download an eUICC firmware version update package based on the at least one eUICC firmware version and at least one issuer identifier in the target event record.

24. The event management server according to claim 23, wherein The transceiver is further configured to: receiving an event registration request sent by the update server, wherein the event registration request carries the at least one eUICC firmware version and at least one issuer identifier; The processor is further configured to: and saving the at least one eUICC firmware version and the at least one issuer identifier in an event record according to the event registration request.

25. The event management server according to any one of claims 23 to 24, characterized in that: The target identifier includes at least one of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

26. The event management server according to claim 25, wherein The customized identification includes additional issuer information or a personal identification code in a preset customized position.

27. The event management server according to any one of claims 23 to 24, characterized in that: The target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC; The processor is specifically configured to: Searching for a first event record and a second event record in currently saved event records, respectively, wherein the group event identifier in the first event record matches the first target identifier, and the group event identifier in the second event record matches the second target identifier; The transceiver is specifically used for: The first event record and the second event record are sent to the terminal device, where the first event record is used to enable the terminal device to download a first eUICC firmware version update package of the first eUICC, and the second event record is used to enable the terminal device to download a second eUICC firmware version update package of the second eUICC.

28. A terminal device, characterized in that: Including processor and transceiver, The transceiver is configured to send first information to the event management server, wherein the first information includes a target identifier; the transceiver is further configured to receive a target event record obtained by the search and sent by the event management server, wherein at least one eUICC firmware version and at least one issuer identifier in the target event record match the target identifier in the first information, and the at least one eUICC firmware version and the at least one issuer identifier correspond to multiple eUICCs; the processor being configured to download an eUICC firmware version update package according to the at least one eUICC firmware version and the at least one issuer identifier in the target event record; The processor is further configured to update the firmware version of the eUICC according to the eUICC firmware version update package.

29. The terminal device according to claim 28, wherein: The target identifier includes at least one piece of information of an eUICC firmware version, an issuer identifier, a customization identifier, or a country code.

30. The terminal device according to claim 29, wherein: The customized identification includes additional issuer information or a personal identification code in a preset customized position.

31. The terminal device according to any one of claims 28 to 30, characterized in that: The target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC; The transceiver is specifically used for: receiving a first event record and a second event record obtained by the search and sent by the event management server, wherein at least one eUICC firmware version and at least one issuer identifier in the first event record match the first target identifier, and at least one eUICC firmware version and at least one issuer identifier in the second event record match the second target identifier; The processor is specifically configured to: downloading a first eUICC firmware version update package of the first eUICC according to the first event record; Downloading a second eUICC firmware version update package of the second eUICC according to the second event record; Updating the firmware version of the first eUICC according to the first eUICC firmware version update package; Updating the firmware version of the second eUICC according to the second eUICC firmware version update package.

32. The terminal device according to claim 28, wherein: The processor is specifically configured to: Extracting an address of an update server from the target event record; The transceiver is further configured to: Sending the current eUICC firmware version to the update server; The transceiver is further configured to: Receive an eUICC firmware version update package sent by the update server according to the current eUICC firmware version.

33. The terminal device according to claim 32, wherein: The transceiver is further configured to: Sending second information to the update server, where the second information includes a target identifier; The transceiver is specifically used for: and receiving an eUICC firmware version update package sent by the update server according to the current eUICC firmware version when the target identifier in the second information matches the group event identifier stored in the update server.

34. The terminal device according to claim 32 or 33, characterized in that: The processor is further configured to: Update the eUICC firmware version in the eUICC information.

35. The terminal device according to claim 34, wherein: The processor is specifically configured to: The eUICC firmware version in the eUICC information is updated according to first data in the eUICC firmware version update package, wherein the first data includes a target firmware version.

36. The terminal device according to claim 34, wherein: The transceiver is further configured to: receiving second data sent by the update server, wherein the second data includes a target firmware version; The processor is further configured to: The eUICC firmware version in the eUICC information is updated according to the second data.

37. A local file assistant, characterized in that include: A sending module, configured to send first information to an event management server, wherein the first information includes a target identifier; a receiving module, configured to receive a target event record obtained by the search and sent by the event management server, wherein at least one eUICC firmware version and at least one issuer identifier in the target event record match the target identifier in the first information, and the at least one eUICC firmware version and the at least one issuer identifier correspond to multiple eUICCs; a processing module, configured to download an eUICC firmware version update package according to the at least one eUICC firmware version and the at least one issuer identifier in the target event record; The sending module is further configured to send the eUICC firmware version update package to the eUICC, where the eUICC firmware version update package is used by the eUICC to update the eUICC firmware version.

38. The local file assistant of claim 37, wherein: The target identifier includes a first target identifier of the first eUICC and a second target identifier of the second eUICC; The receiving module is specifically used for: receiving a first event record and a second event record obtained by the search and sent by the event management server, wherein at least one eUICC firmware version and at least one issuer identifier in the first event record match the first target identifier, and at least one eUICC firmware version and at least one issuer identifier in the second event record match the second target identifier; The processing module is specifically used for: downloading a first eUICC firmware version update package of the first eUICC according to the first event record; Downloading a second eUICC firmware version update package of the second eUICC according to the second event record; The sending module is specifically used for: Sending the first eUICC firmware version update package to the first eUICC, where the first eUICC uses the first eUICC to update the eUICC firmware version of the first eUICC; The second eUICC firmware version update package is sent to the second eUICC, where the second eUICC firmware version update package is used by the second eUICC to update the eUICC firmware version of the second eUICC.

39. The local file assistant of claim 38, wherein: The sending module is further used for: sending the first event record to the first eUICC according to the first eUICC identifier; sending the second event record to the second eUICC according to the second eUICC identifier.

40. The local file assistant of claim 38, wherein: While the processing module downloads the first eUICC firmware version update package of the first eUICC according to the first event record, the receiving module further receives a first eUICC identifier sent by an update server corresponding to the first eUICC; While the processing module downloads the second eUICC firmware version update package of the second eUICC according to the second event record, the receiving module further receives a second eUICC identifier sent by an update server corresponding to the second eUICC; The sending module is specifically used for: Sending the first eUICC firmware version update package to the first eUICC according to the first eUICC identifier; Sending the second eUICC firmware version update package to the second eUICC according to the second eUICC identifier.

41. An update server, characterized in that Including transceiver, the transceiver is configured to send an event registration request to an event management server, wherein the event registration request carries at least one eUICC firmware version and at least one issuer identifier, and the at least one eUICC firmware version and the at least one issuer identifier correspond to multiple eUICCs; The event registration request is used to cause the event management server to save the at least one eUICC firmware version and the at least one issuer identifier in an event record, and to send the event record to the terminal device upon receiving first information sent by a terminal device that matches the at least one eUICC firmware version and the at least one issuer identifier.

42. The update server according to claim 41, wherein The update server also includes a processor, The transceiver is further configured to receive a current eUICC firmware version of the terminal device sent by the terminal device; The processor is configured to determine, based on the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device to a target firmware version; The transceiver is further configured to send the eUICC firmware version update package to the terminal device, where the eUICC firmware version update package is used by the terminal device to update the firmware version of the eUICC of the terminal device.

43. The update server according to claim 42, wherein The transceiver is further configured to: receiving second information sent by the terminal device, where the second information includes eUICC capabilities and an eUICC firmware version; The processor is specifically configured to: If it is determined that the eUICC performance and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version, determine, based on the current eUICC firmware version, an eUICC firmware version update package required for updating the eUICC of the terminal device to the target firmware version.

44. The update server according to claim 43, wherein The second information also includes a target identifier; The processor is further configured to: When the target identifier in the second information matches the locally stored group event identifier, determining whether the eUICC performance and the eUICC firmware version meet the performance and firmware version requirements of the target firmware version.

45. A computer storage medium, characterized in that The computer storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer is caused to perform the method according to any one of claims 1 to 5.

46. ​​A computer storage medium, characterized in that The computer storage medium stores a computer program, wherein the computer program includes program instructions. When the program instructions are executed by a computer, the computer is caused to perform the method according to any one of claims 6 to 14.

47. A computer storage medium, characterized in that The computer storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer is caused to perform the method according to any one of claims 15 to 18.

48. A computer storage medium, characterized in that The computer storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer is caused to perform the method according to any one of claims 19 to 22.

Citation Information

Patent Citations

  • FOTA update method, device and server

    CN106708564A