Chip circuit and access control method

By setting up a dual interface architecture between the baseband chip and the application chip, the application chip allows the application chip to access ordinary card applications and security card applications through different interfaces under different operating environments, the access blocking problem is solved and the effect of access control is improved.

CN114386111BActive Publication Date: 2025-08-22CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011122418.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-20
Publication Date
2025-08-22
Estimated Expiration
2040-10-20

AI Technical Summary

Technical Problem

In the existing access control scheme, the application chip cannot access the ordinary card application of the user identification card when accessing the security card application of the user identification card, resulting in access blockage and poor access control effect.

Method used

By setting a dual interface architecture between the baseband chip and the application chip, the first and second interfaces are provided for the application chip respectively, allowing the application chip to access the ordinary card application and the security card application of the user identification card through different interfaces under different operating environments (such as rich execution environment and trusted execution environment).

Benefits of technology

It realizes that the application chip accesses the user identification card in parallel under different operating environments, avoids access blockage, and improves the effect of access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114386111B_ABST
    Figure CN114386111B_ABST
Patent Text Reader

Abstract

The present invention provides a chip circuit and access control method, relating to the field of communications technology. The chip circuit includes: a baseband chip, an application chip, and a user identification card, wherein: a first end of the baseband chip is connected to a first end of the application chip to form a first interface between the baseband chip and the application chip; a second end of the baseband chip is connected to a second end of the application chip to form a second interface between the baseband chip and the application chip; and a third end of the baseband chip is connected to the user identification card. In an embodiment of the present invention, a first interface and a second interface are provided between the baseband chip and the application chip, so that the application chip can access the user identification card's ordinary card application and security card application through the first interface and the second interface, respectively, thereby avoiding access blockage and improving access control effectiveness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a chip circuit and an access control method. Background Art

[0002] In the prior art, a terminal usually includes an application chip, a baseband chip, and a user identification card. The application chip accesses the user identification card through the baseband chip. The user identification card can carry ordinary card applications and security card applications. Ordinary card applications can be accessed without the authorization of trusted applications, while security card applications can be accessed only with the authorization of trusted applications. Generally, security card applications are applications involving identity security information such as identity cards or bank cards. When the application chip accesses the security card application of the user identification card, the communication interface between the application chip and the baseband chip needs to work in a secure mode, so that the application chip cannot access the ordinary card application of the user identification card when accessing the security card application of the user identification card. It can be seen that the existing access control scheme will lead to access blocking and the access control effect is poor. Summary of the Invention

[0003] The embodiment of the present invention provides a chip circuit and access control method to solve the problem in existing access control solutions that an application chip cannot access a common card application of a user identification card when accessing a security card application of a user identification card, resulting in access blockage and poor access control effect.

[0004] To solve the above-mentioned technical problems, the present invention is achieved as follows:

[0005] In a first aspect, an embodiment of the present invention provides a chip circuit, including: a baseband chip, an application chip, and a user identification card, wherein:

[0006] The first end of the baseband chip is connected to the first end of the application chip to form a first interface between the baseband chip and the application chip;

[0007] The second end of the baseband chip is connected to the second end of the application chip to form a second interface between the baseband chip and the application chip;

[0008] The third end of the baseband chip is connected to the user identification card.

[0009] Optionally, when the application chip runs the first operating environment and the second operating environment simultaneously:

[0010] The application chip is used to send a first subscriber identification card access request to the baseband chip through the first interface under the first operating environment, and the baseband chip is used to access the subscriber identification card based on the first subscriber identification card access request;

[0011] The application chip is used to send a second subscriber identification card access request to the baseband chip through the second interface under the second operating environment, and the baseband chip is used to access the subscriber identification card based on the second subscriber identification card access request.

[0012] Optionally, the application chip runs a trusted application, and the application chip is configured to send a second subscriber identification card access request to the baseband chip through the second interface in the second operating environment based on the trusted application.

[0013] Optionally, when the application chip runs the first operating environment:

[0014] The application chip is used to send a third user identification card access request to the baseband chip through the first interface under the first operating environment, and the baseband chip is used to access the user identification card based on the third user identification card access request;

[0015] or

[0016] The application chip is used to send a fourth subscriber identification card access request to the baseband chip through the second interface under the first operating environment, and the baseband chip is used to access the subscriber identification card based on the fourth subscriber identification card access request.

[0017] Optionally, the first operating environment is a rich execution environment, and / or the second operating environment is a trusted execution environment.

[0018] In a second aspect, an embodiment of the present invention provides an access control method, the method comprising:

[0019] Performing user identification card access of the first operating environment through the first interface;

[0020] Performing user identification card access to the second operating environment through the second interface;

[0021] The first operating environment and the second operating environment are two operating environments in which the application chip runs simultaneously, and the first interface and the second interface are two interfaces between the application chip and the baseband chip.

[0022] Optionally, the step of accessing the first operating environment through the first interface using a user identification card includes:

[0023] The application chip sends a first user identification card access request to the baseband chip through the first interface in the first operating environment;

[0024] The baseband chip accesses the subscriber identification card based on the first subscriber identification card access request.

[0025] Optionally, the step of accessing the second operating environment through the second interface using a user identification card includes:

[0026] The application chip sends a second user identification card access request to the baseband chip through the second interface in the second operating environment;

[0027] The baseband chip accesses the subscriber identification card based on the second subscriber identification card access request.

[0028] Optionally, the application chip runs a trusted application program, and the application chip sends a second subscriber identity card access request to the baseband chip through the second interface in the second operating environment, including:

[0029] The application chip sends a second subscriber identification card access request to the baseband chip through the second interface in the second operating environment based on the trusted application program.

[0030] Optionally, the first operating environment is a rich execution environment, and / or the second operating environment is a trusted execution environment.

[0031] In an embodiment of the present invention, the first end of the baseband chip is connected to the first end of the application chip to form a first interface between the baseband chip and the application chip, and the second end of the baseband chip is connected to the second end of the application chip to form a second interface between the baseband chip and the application chip. Therefore, the baseband chip and the application chip include a first interface and a second interface, so that the application chip can access the ordinary card application and the security card application of the user identification card through the first interface and the second interface respectively, which can avoid access blocking and thus improve the access control effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in describing the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0033] Figure 1 This is a schematic structural diagram of a chip circuit provided by an embodiment of the present invention;

[0034] Figure 2 This is one of the flow charts of an access control method provided by an embodiment of the present invention;

[0035] Figure 3 This is the second flowchart of an access control method provided by an embodiment of the present invention;

[0036] Figure 4 This is the third flow chart of an access control method provided by an embodiment of the present invention;

[0037] Figure 5 This is the fourth flowchart of an access control method provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0038] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort shall fall within the scope of protection of the present invention.

[0039] In an embodiment of the present invention, a chip circuit and an access control method are proposed to solve the problem in existing access control schemes that an application chip cannot access the ordinary card application of a user identification card when accessing the security card application of a user identification card, resulting in access blockage and poor access control effect.

[0040] See also Figure 1 , Figure 1 FIG. 1 is a schematic diagram of a chip circuit provided by an embodiment of the present invention. Figure 1 As shown, the chip circuit includes: a baseband chip 11, an application chip 12 and a user identification card 13, wherein:

[0041] The first end of the baseband chip 11 is connected to the first end of the application chip 12 to form a first interface 14 between the baseband chip 11 and the application chip 12;

[0042] The second end of the baseband chip 11 is connected to the second end of the application chip 12 to form a second interface 15 between the baseband chip 11 and the application chip 12;

[0043] The third terminal of the baseband chip 11 is connected to the subscriber identification card 13 .

[0044] The first interface 14 and the second interface 15 can be physical interfaces. The first interface 14 can be used for the application chip 12 to access the ordinary card application of the user identification card 13, and the second interface 15 can be used for the application chip 12 to access the security card application of the user identification card 13. The user identification card 13 can be a subscriber identity module (SIM) card; or, the second interface 15 can be used for the application chip 12 to access the ordinary card application of the user identification card 13, and the first interface 14 can be used for the application chip 12 to access the security card application of the user identification card 13. This embodiment does not limit this. By setting the first interface 14 and the second interface 15, a dual-interface architecture of the baseband chip 11 can be implemented.

[0045] Taking the first interface 14 as an example, in which the application chip 12 is used to access the ordinary card application of the user identification card 13, and the second interface 15 is used to access the security card application of the user identification card 13, when the application chip 12 does not access the security card application of the user identification card 13, the second interface 15 can serve as a redundancy of the first interface 14, and the application chip 12 can access the ordinary card application of the user identification card 13 through the second interface 15.

[0046] It should be noted that an application (APP) can run on the application chip 12, and the APP can access the security card application of the user identification card 13 through the second interface 15. Specifically, the APP can access the security card application of the user identification card 13 through the second interface 15 in a trusted execution environment (TEE), or the APP can access the security card application of the user identification card 13 through the second interface 15 in a rich execution environment (REE).

[0047] Take the security card application where APP can access the user identification card through the second interface under REE as an example. Figure 2 As shown, the following steps may be included:

[0048] Step 101: The APP may send a SIM card security access request to the SIM card software development kit (SDK);

[0049] Step 102: After receiving the SIM card security access request, the SIM card SDK sends the SIM card security access request to the SIM authorization TA;

[0050] Step 103: After receiving the SIM card security request, the SIM authorization TA generates a SIM card security instruction request carrying an authorization code;

[0051] Step 104: The SIM authorizes the TA to send the SIM card security instruction request carrying the authorization code to the second interface;

[0052] Step 105: The second interface sends the received SIM card security instruction request to the security card application of the SIM card;

[0053] Among them, when the SIM authorization TA and the security card application of the SIM card are initialized, a shared key can be preset through the security solution. The communication data between the SIM authorization TA and the security card application of the SIM card is encrypted by the shared key, thereby establishing a secure channel and ensuring the security of the data of the second interface.

[0054] Step 106: After receiving the SIM card security instruction request, the security card application of the SIM card verifies the authorization code and performs security calculations;

[0055] Step 107: After successful verification, the security card application of the SIM card sends a SIM card security instruction response to the second interface;

[0056] Step 108: The second interface sends a SIM card security instruction response to the SIM authorization TA;

[0057] Step 109: After receiving the SIM card security command response, the SIM authorization TA sends a SIM card security response to the SIM card SDK;

[0058] Step 110: After receiving the SIM card security response, the SIM card SDK sends a SIM card security access response to the APP.

[0059] It should be noted that the SIM card SDK can be an agent for accessing the SIM card. For example, the SIM card SDK can be an agent for accessing the SIM card under the REE. The SIM authorization TA can be a trusted application in the TEE, used to implement the authorization capability of the user to access the security card application of the SIM card.

[0060] Through the chip circuit in the embodiment of the present invention, the application chip can access the common card application and the security card application of the user identification card through the first interface and the second interface respectively, which can avoid access blocking and thus improve the access control effect.

[0061] Optionally, when the application chip runs the first operating environment and the second operating environment simultaneously:

[0062] The application chip is used to send a first subscriber identification card access request to the baseband chip through the first interface under the first operating environment, and the baseband chip is used to access the subscriber identification card based on the first subscriber identification card access request;

[0063] The application chip is used to send a second subscriber identification card access request to the baseband chip through the second interface under the second operating environment, and the baseband chip is used to access the subscriber identification card based on the second subscriber identification card access request.

[0064] The first interface may be used by the application chip to access a common card application of the user identification card, and the second interface may be used by the application chip to access a security card application of the user identification card. The first operating environment may be an operating environment for accessing a common card application of the user identification card, and the second operating environment may be an operating environment for accessing a security card application of the user identification card.

[0065] For example, if the first operating environment is REE and the second operating environment is TEE, applications under the REE can access the user identity card's standard card application through the first interface. At the same time, the second interface can run in secure mode, allowing trusted applications under the TEE to access the user identity card's secure card application. Access from the REE side and access from the TEE side can be achieved through the first interface and the second interface respectively, without interfering with each other.

[0066] In actual applications, the user identification card is used as the basic security medium on the electronic device and can be used to carry high-security applications. In some application scenarios, it is necessary to access the user identification card simultaneously in the first operating environment and the second operating environment. Taking the first operating environment as REE and the second operating environment as TEE as an example, in some application scenarios, it is necessary to access the user identification card simultaneously under REE and TEE. In the related art, since there is only one interface between the application chip and the baseband chip, when the application chip accesses the user identification card under TEE, the application chip will switch to the Secure state through mode conversion. In the Secure state, the application chip cannot access the user identification card under REE. The application chip will load the operating system (OS) in the TEE, and the OS in the TEE will call the corresponding trusted application (TA) to realize interaction with the user identification card. After completing the access to the user identification card under TEE, the application chip will switch the access rights of the baseband chip to REE through mode conversion and reload the OS in REE. As a result, when the application chip runs under TEE, it will not be able to access the user identification card normally under REE, and TEE will block REE from accessing the user identification card.

[0067] In the embodiment of the present invention, through the first interface and the second interface, the application chip can access the user identification card under the TEE, and at the same time, the application chip can access the user identification card under the REE, thereby achieving concurrent access to the user identification card. The baseband chip may also include a SIM card concurrent access control module. When the SIM card is accessed simultaneously under the TEE and the REE, concurrent access control of the SIM card can be achieved through the SIM card concurrent access control module.

[0068] In this way, through the first interface and the second interface, the application chip can access the user identification card in parallel in the first operating environment and the second operating environment, thereby avoiding access to the user identification card only in the first operating environment or only in the second operating environment, avoiding access congestion.

[0069] Optionally, the application chip runs a trusted application, and the application chip is configured to send a second subscriber identification card access request to the baseband chip through the second interface in the second operating environment based on the trusted application.

[0070] An APP may be run on the application chip, and the APP may access the security card application of the user identification card through the second interface based on the trusted application (TA).

[0071] For example, Figure 3 As shown, the access control method for accessing the security card application of the user identification card through the second interface may include the following steps:

[0072] Step 201: The APP may send a TA request to the SIM card SDK;

[0073] Step 202: After receiving the TA request, the SIM card SDK sends a TA security request to the trusted application;

[0074] Step 203: After receiving the TA security request, the trusted application sends a SIM card authorization request to the SIM authorization TA;

[0075] Step 204: After receiving the SIM card authorization request, the TA generates an authorization code;

[0076] Step 205: The SIM authorization TA sends a SIM card authorization response corresponding to the SIM card authorization request to the TA, wherein the SIM card authorization response carries an authorization code;

[0077] Step 206: The TA sends a SIM card security instruction request carrying an authorization code to the second interface;

[0078] Step 207: After receiving the SIM card security instruction request, the second interface sends the SIM card security instruction request to the security card application of the SIM card;

[0079] Step 208: After receiving the SIM card security instruction request, the security card application of the SIM card verifies the authorization code and performs security calculations;

[0080] Step 209: After successful verification, the security card application of the SIM card sends a SIM card security instruction response to the second interface;

[0081] Step 210: The second interface sends a SIM card security instruction response to the TA;

[0082] In addition, after receiving the SIM card security instruction response, the TA sends a verification request to the SIM authorized TA, and receives a verification response to the verification request from the SIM authorized TA.

[0083] Step 211: After the TA passes the verification, the TA performs a TA security operation and generates a TA security operation result.

[0084] Step 212: The TA sends a TA security response to the SIM card SDK. The TA security response carries the TA security calculation result.

[0085] Step 213: The SIM card SDK sends a TA response to the APP.

[0086] It should be noted that the SIM card SDK may be an agent for accessing the SIM card. For example, the SIM card SDK may be an agent for accessing the SIM card under REE.

[0087] In this embodiment, the application chip sends a second subscriber identity card access request to the baseband chip via the second interface based on the trusted application in the second operating environment. The baseband chip is configured to access the subscriber identity card based on the second subscriber identity card access request. In this way, the dual-interface architecture of the baseband chip provides an additional interface for trusted applications to access the subscriber identity card, enabling secure card applications that access the subscriber identity card in secure mode.

[0088] Optionally, when the application chip runs the first operating environment:

[0089] The application chip is used to send a third user identification card access request to the baseband chip through the first interface under the first operating environment, and the baseband chip is used to access the user identification card based on the third user identification card access request;

[0090] or

[0091] The application chip is used to send a fourth subscriber identification card access request to the baseband chip through the second interface under the first operating environment, and the baseband chip is used to access the subscriber identification card based on the fourth subscriber identification card access request.

[0092] An APP may be run on the application chip, and the APP may access a common card application of the user identification card through the first interface or the second interface.

[0093] For example, Figure 4 As shown, the access control method for a common card application accessing a user identification card through the first interface or the second interface may include the following steps:

[0094] Step 301: The APP may send a SIM card access request to the SIM card SDK;

[0095] Step 302: After receiving the SIM card access request, the SIM card SDK sends the SIM card access request to the first interface or the second interface;

[0096] Step 303: The first interface or the second interface sends the SIM card access request to the common card application of the SIM card;

[0097] Step 304: The common card application of the SIM card responds to the SIM card access request and obtains an encrypted SIM card access response through a shared key calculation with the APP service platform;

[0098] Step 305: The common card application of the SIM card sends a SIM card access response to the first interface or the second interface;

[0099] Step 307: The first interface or the second interface sends the SIM card access response to the SIM card SDK;

[0100] Step 308: After receiving the SIM card access response, the SIM card SDK sends the SIM card access response to the APP.

[0101] It should be noted that the SIM card's standard card application and the app service platform can share a key through a security process. The SIM card access response is information encrypted using the shared key, ensuring the security of data on the first and second interfaces. After receiving the SIM card access response, the app can use it for login verification on the app service platform. Upon successful verification, the app can log in to the app service platform.

[0102] In this embodiment, the second interface can serve as redundancy for the first interface, and the application chip can access the ordinary card application of the user identification card through the second interface. When the first interface is busy or fails, the ordinary card application of the user identification card can be accessed through the second interface, thereby improving the reliability of the baseband chip.

[0103] Optionally, the first operating environment is a rich execution environment, and / or the second operating environment is a trusted execution environment.

[0104] Among them, the trusted execution environment is an operating environment that corresponds to the rich execution environment in logical terms. By providing an isolated trusted execution environment in the secure area of ​​the processor of the electronic device, the security, confidentiality and integrity of various sensitive data loaded into the trusted execution environment can be guaranteed, thereby providing services such as secure encryption and decryption, secure storage and trusted identity authentication. The application chip can send a first user identification card access request to the baseband chip through the first interface under REE, and the baseband chip can access the user identification card based on the first user identification card access request; the application chip can send a second user identification card access request to the baseband chip through the second interface under TEE, and the baseband chip can access the user identification card based on the second user identification card access request.

[0105] In this way, the application chip can access the secure card application of the SIM card under TEE without affecting the application chip's access to the ordinary card application of the SIM card under REE; and the application chip can achieve the ability to access the SIM card application under TEE and REE at the same time without switching states.

[0106] See also Figure 5 , Figure 5 This is a flow chart of an access control method provided by an embodiment of the present invention. Figure 5 As shown, the method includes the following steps:

[0107] Step 401: Accessing a first operating environment through a user identification card via a first interface.

[0108] Step 402: Access the second operating environment through the second interface using a user identification card.

[0109] The first operating environment and the second operating environment are two operating environments in which the application chip runs simultaneously, and the first interface and the second interface are two interfaces between the application chip and the baseband chip.

[0110] The first interface and the second interface can be physical interfaces. The first interface can be used for the application chip to access the ordinary card application of the user identification card, the second interface can be used for the application chip to access the security card application of the user identification card, the first operating environment can be the operating environment for accessing the ordinary card application of the user identification card, and the second operating environment can be the operating environment for accessing the security card application of the user identification card; or, the second interface can be used for the application chip to access the ordinary card application of the user identification card, the first interface can be used for the application chip to access the security card application of the user identification card, the second operating environment can be the operating environment for accessing the ordinary card application of the user identification card, and the first operating environment can be the operating environment for accessing the security card application of the user identification card. This embodiment does not limit this. By setting the first interface and the second interface, the dual-interface architecture of the baseband chip can be realized.

[0111] In an embodiment of the present invention, user identification card access of a first operating environment is performed through a first interface, and user identification card access of a second operating environment is performed through a second interface. Therefore, a first interface and a second interface are included between the baseband chip and the application chip, so that the application chip can access the ordinary card application and the security card application of the user identification card through the first interface and the second interface respectively, which can avoid access blocking and thus improve the access control effect.

[0112] Optionally, the step of accessing the first operating environment through the first interface using a user identification card includes:

[0113] The application chip sends a first user identification card access request to the baseband chip through the first interface in the first operating environment;

[0114] The baseband chip accesses the subscriber identification card based on the first subscriber identification card access request.

[0115] Optionally, the step of accessing the second operating environment through the second interface using a user identification card includes:

[0116] The application chip sends a second user identification card access request to the baseband chip through the second interface in the second operating environment;

[0117] The baseband chip accesses the subscriber identification card based on the second subscriber identification card access request.

[0118] Optionally, the application chip runs a trusted application program, and the application chip sends a second subscriber identity card access request to the baseband chip through the second interface in the second operating environment, including:

[0119] The application chip sends a second subscriber identification card access request to the baseband chip through the second interface in the second operating environment based on the trusted application program.

[0120] Optionally, the first operating environment is a rich execution environment, and / or the second operating environment is a trusted execution environment.

[0121] It should be noted that the access control method in the embodiment of the present invention can be applied to the chip circuit described in the above embodiment and can achieve the same technical effect. To avoid repetition, it will not be described here.

[0122] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0123] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present invention.

[0124] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the present invention and the claims, all of which are protected by the present invention.

Claims

1. A chip circuit, characterized in that: include: Baseband chip, application chip and user identification card, including: The first end of the baseband chip is connected to the first end of the application chip to form a first interface between the baseband chip and the application chip; The second end of the baseband chip is connected to the second end of the application chip to form a second interface between the baseband chip and the application chip; The third end of the baseband chip is connected to the user identification card; When the application chip runs the first operating environment and the second operating environment at the same time: The application chip is used to send a first subscriber identification card access request to the baseband chip through the first interface under the first operating environment, and the baseband chip is used to access the subscriber identification card based on the first subscriber identification card access request; The application chip is used to send a second subscriber identification card access request to the baseband chip through the second interface under the second operating environment, and the baseband chip is used to access the subscriber identification card based on the second subscriber identification card access request.

2. The chip circuit according to claim 1, characterized in that: The application chip runs a trusted application program, and the application chip is configured to send a second subscriber identification card access request to the baseband chip through the second interface in the second operating environment based on the trusted application program.

3. The chip circuit according to claim 1, characterized in that: When the application chip runs the first operating environment: The application chip is used to send a third user identification card access request to the baseband chip through the first interface under the first operating environment, and the baseband chip is used to access the user identification card based on the third user identification card access request; or The application chip is used to send a fourth subscriber identification card access request to the baseband chip through the second interface under the first operating environment, and the baseband chip is used to access the subscriber identification card based on the fourth subscriber identification card access request.

4. The chip circuit according to claim 1 or 2, characterized in that: The first operating environment is a rich execution environment, and / or the second operating environment is a trusted execution environment.

5. An access control method, characterized in that: The method comprises: Performing user identification card access of the first operating environment through the first interface; Performing user identification card access to the second operating environment through the second interface; The first operating environment and the second operating environment are two operating environments in which the application chip runs simultaneously, and the first interface and the second interface are two interfaces between the application chip and the baseband chip; The first end of the baseband chip is connected to the first end of the application chip to form the first interface between the baseband chip and the application chip; The second end of the baseband chip is connected to the second end of the application chip to form the second interface between the baseband chip and the application chip.

6. The access control method according to claim 5, characterized in that: The step of executing the user identification card access to the first operating environment through the first interface includes: The application chip sends a first user identification card access request to the baseband chip through the first interface in the first operating environment; The baseband chip accesses the subscriber identification card based on the first subscriber identification card access request.

7. The access control method according to claim 5, characterized in that: The step of executing the user identification card access to the second operating environment through the second interface includes: The application chip sends a second user identification card access request to the baseband chip through the second interface in the second operating environment; The baseband chip accesses the subscriber identification card based on the second subscriber identification card access request.

8. The access control method according to claim 7, characterized in that: The application chip runs a trusted application program, and the application chip sends a second user identification card access request to the baseband chip through the second interface in the second operating environment, including: The application chip sends a second subscriber identification card access request to the baseband chip through the second interface in the second operating environment based on the trusted application program.

9. The access control method according to any one of claims 5 to 8, characterized in that: The first operating environment is a rich execution environment, and / or the second operating environment is a trusted execution environment.

Citation Information

Patent Citations

  • Processor, baseband chip and SIM card information transmission method

    CN109831775A