Data storage method, device, system and storage medium
By generating hash values and signing and verifying stored secure data through terminal devices, the problem of high difficulty and low efficiency in joint debugging caused by encrypted transmission in existing technologies is solved, and efficient and reliable transmission and storage of secure data is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-22
- Publication Date
- 2026-03-17
AI Technical Summary
Existing technologies, when deploying secure data on terminal devices, especially SIMLOCK and IMEI data, involve encrypted data transmission, which leads to difficulties in joint debugging and low production efficiency.
After receiving secure data, the terminal device generates a hash value using a digest information processing algorithm and sends it to the deployment tool. The deployment tool then forwards the hash to the security device for signature processing. The terminal device verifies and stores the signature information, which simplifies the encryption process and improves data transmission efficiency and security.
It enables secure plaintext transmission of data, simplifies the data deployment process, improves production line efficiency, prevents data from being copied and tampered with, and reduces the difficulty of developing deployment tools.
Smart Images

Figure CN114547700B_ABST
Abstract
Description
Technical Field
[0001] This application relates to communication technology, and more particularly to a data storage method, apparatus, system and storage medium. Background Technology
[0002] To meet the needs of different operators, terminal devices are equipped with different security data before leaving the factory to enable different functions. For example, different Subscriber Identity Modules (SIMLOCKs) are deployed to restrict the country and network they can use. To meet the needs of different users, designers also deploy different International Mobile Equipment Identity (IMEI) codes on the terminal devices to support different standby modes.
[0003] Existing technologies encrypt all SIMLOCK and IMEI data when deploying secure data. The entire data transmission process is encrypted, and there are many interactions during the data transmission process. When a failure occurs during the data deployment process, the integration and debugging are difficult, resulting in low production efficiency of the production line corresponding to the terminal equipment. Summary of the Invention
[0004] This application provides a data storage method, apparatus, system, and storage medium that can simplify the secure data transmission process, improve data deployment efficiency, and enhance production line efficiency.
[0005] In a first aspect, this application provides a data storage method applied to a terminal device. The method includes: receiving security data sent by a deployment tool; determining a first hash value based on the security data and the unique identifier (UID) corresponding to the terminal device, and sending the first hash value to the deployment tool; receiving signature information sent by the security device through the deployment tool, wherein the signature information is determined by the security device based on the first hash value sent by the deployment tool; verifying the signature information based on the first hash value, and if the verification passes, storing the security data and the signature information.
[0006] Optionally, storing security data and signature information includes: performing operations on the security data and signature information to store them in a target storage area, reading the data already stored in the target storage area, comparing the read data with the security data and signature information respectively, and performing verification processing on the security data and signature information; if the verification is successful, it is determined that the security data and signature information have been successfully stored.
[0007] Optionally, it also includes: updating the first flag information, which is used to characterize the storage status of the security data and signature information.
[0008] Optionally, it also includes: sending a first notification message to the deployment tool, the first notification message being used to notify the deployment tool that the security data and signature information have been successfully stored.
[0009] Optionally, the security data includes user identification lock (SIMLOCK) data, which includes customer customized data (CCD). Based on the security data and the UID corresponding to the terminal device, a first hash value is determined, including: encrypting the control key (CK) sent by the deployment tool according to the UID to obtain first encrypted data; and determining the first hash value based on the first encrypted data, CCD, and UID.
[0010] Optionally, SIMLOCK data includes user data (URD); stores security data and signature information, including: determining the second hash value corresponding to the URD; and storing the security data, signature information, and second hash value.
[0011] Optionally, the security data includes at least two International Mobile Equipment Identity (IMEI) data; determining a first hash value based on the security data and the UID corresponding to the terminal device includes: receiving a first IMEI identifier sent by a deployment tool, the first IMEI identifier being used to identify the IMEI data applicable to the terminal device among the at least two IMEI data; determining a second IMEI identifier based on the at least two IMEI data and the configuration information of the terminal device; comparing whether the first IMEI identifier and the second IMEI identifier are consistent, and if they are consistent, determining the first hash value based on the at least two IMEI data, the second IMEI identifier, and the UID.
[0012] Optionally, receiving security data sent by the deployment tool includes: if an authentication request message is received from the deployment tool, generating a random number; encrypting the random number using a public key to obtain second encrypted data; sending the second encrypted data to the deployment tool; receiving third encrypted data sent by the security device through the deployment tool, the third encrypted data being data processed by the security device based on the second encrypted data and private key sent by the deployment tool, the private key corresponding to the public key; decrypting the third encrypted data using the public key to obtain a decryption result; comparing the decryption result with the random number for consistency, and if they are consistent, sending a second notification message to the deployment tool; and receiving security data sent by the deployment tool after receiving the second notification message.
[0013] Optionally, it also includes: setting a second flag bit, which is used to indicate that the decryption result is consistent with the random number.
[0014] Accordingly, receiving security data sent by the deployment tool includes: receiving security data sent by the deployment tool based on the second flag information.
[0015] Optionally, after storing the security data and signature information, the method also includes clearing the second flag information.
[0016] Secondly, this application provides a data storage device, the device comprising:
[0017] The receiving module is used to receive security data sent by the deployment tool.
[0018] The processing module is used to determine the first hash value based on the security data and the device unique identifier (UID) corresponding to the terminal device, and send the first hash value to the deployment tool.
[0019] The receiving module is also used to receive signature information sent by the security device through the deployment tool, wherein the signature information is determined by the security device based on the first hash value sent by the deployment tool.
[0020] The processing module is also used to verify the signature information based on the first hash value. If the verification passes, the security data and signature information are stored.
[0021] Optionally, the processing module is specifically used to perform operations on the security data and signature information to store them in the target storage area, and to read the data already stored in the target storage area, and compare the read data with the security data and signature information respectively to verify the security data and signature information; if the verification is successful, it is determined that the security data and signature information have been successfully stored.
[0022] Optionally, the processing module is also used to update the flag information corresponding to the security data, which is used to characterize the storage status of the security data and signature information.
[0023] Optionally, the processing module is also used to send a first notification message to the deployment tool, the first notification message being used to notify the deployment tool that the security data and signature information have been successfully stored.
[0024] Optionally, the security data includes user identification lock (SIMLOCK) data, which includes user-customized data (CCD); the processing module is specifically used to encrypt the control key (CK) sent by the deployment tool according to the UID to obtain first encrypted data; and to determine a first hash value based on the first encrypted data, CCD, and UID.
[0025] Optionally, SIMLOCK data includes user data URD; a processing module specifically used to determine the second hash value corresponding to the URD; and storage of security data, signature information, and the second hash value.
[0026] Optionally, the security data includes at least two International Mobile Equipment Identity (IMEI) data; the processing module is specifically configured to receive a first IMEI identifier sent by the deployment tool, the first IMEI identifier being used to identify the IMEI data applicable to the terminal device from the at least two IMEI data; determine a second IMEI identifier based on the at least two IMEI data and the configuration information of the terminal device; compare whether the first IMEI identifier and the second IMEI identifier are consistent, and if they are consistent, determine a first hash value based on the at least two IMEI data, the second IMEI identifier, and the UID.
[0027] Optionally, the receiving module is specifically configured to: generate a random number if it receives an authentication request message from the deployment tool; encrypt the random number using a public key to obtain second encrypted data; send the second encrypted data to the deployment tool; receive third encrypted data sent by the security device through the deployment tool, the third encrypted data being data processed by the security device based on the second encrypted data and private key sent by the deployment tool, the private key corresponding to the public key; decrypt the third encrypted data using the public key to obtain a decryption result; compare the decryption result with the random number for consistency, and if they are consistent, send a second notification message to the deployment tool; and receive security data sent by the deployment tool after receiving the second notification message.
[0028] Optionally, the processing module is also used to set a second flag bit, which is used to indicate that the decryption result is consistent with the random number; and to receive security data sent by the deployment tool based on the second flag bit.
[0029] Optionally, the processing module is also used to clear the second flag information.
[0030] Thirdly, this application provides a data storage system and a data processing system, including a terminal device, a security device, and a deployment tool, wherein the deployment tool is communicatively connected to the terminal device and the security device, respectively.
[0031] The terminal device is used to receive security data sent by the deployment tool, determine the first hash value based on the security data and the UID corresponding to the terminal device, and send the first hash value to the deployment tool.
[0032] Deployment tools are used to send the first received hash value to the security device.
[0033] The security device is used to determine the signature information based on the first hash value and send the signature information to the deployment tool.
[0034] The deployment tool is also used to send signature information to the terminal device.
[0035] The terminal device is also used to verify the signature information based on the first hash value. If the verification passes, it deploys the security data and signature information.
[0036] Fourthly, this application provides a terminal device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform a method as described in the first aspect or an alternative method of the first aspect.
[0037] Fifthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement a method as described in the first aspect or an alternative method of the first aspect.
[0038] In a sixth aspect, this application provides a computer program product including a computer program / instructions that, when executed by a processor, implement a method as described in the first aspect or an alternative method of the first aspect.
[0039] The data storage method, apparatus, system, and storage medium provided in this application receive secure data sent by a deployment tool; determine a first hash value based on the secure data and the UID corresponding to the terminal device, and send the first hash value to the deployment tool; receive signature information determined by the secure device based on the first hash value sent by the deployment tool; verify the signature information based on the first hash value; if the verification is successful, store the secure data and signature information. This enables the secure data to be transmitted to the terminal device in plaintext, simplifying the data encryption process and improving data transmission efficiency and production line efficiency. The terminal device generates a hash value by performing digest processing on the received secure data and its corresponding UID, which can bind the secure data and the mobile terminal to prevent the secure data from being copied and improve data security. Through the signature processing of the secure data by the secure device and the signature verification processing of the terminal device, it is possible to determine whether the secure data has been tampered with, thereby further improving data security and reliability. This method also simplifies the processing flow of the deployment tool, which mainly undertakes the data forwarding function, reducing the requirements for the deployment tool and reducing development difficulty. Attached Figure Description
[0040] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0041] Figure 1 A schematic diagram of the structure of a data storage system provided in this application;
[0042] Figure 2 A flowchart illustrating the data storage method provided in this application;
[0043] Figure 3 Another flowchart illustrating the data storage method provided in this application;
[0044] Figure 4 A signaling diagram for the data storage method provided in this application;
[0045] Figure 5 A signaling diagram for the data storage method provided in this application;
[0046] Figure 6 A schematic diagram of a data storage device provided in this application;
[0047] Figure 7 A schematic diagram of the structure of the terminal device provided in this application.
[0048] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0049] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0050] Deploying SIMLOCK and IMEI data in a terminal device, also known as personalization settings, allows for the restriction of the service providers it can use by storing relevant information. When the terminal device is powered on or a Subscriber Identity Module (SIM) or Universal Subscriber Identity Module (USIM) is inserted, the device checks this information against the SIM / USIM. If the check fails, the terminal device enters a limited service state, allowing only emergency calls.
[0051] Current technologies encrypt all SIMLOCK and IMEI data during deployment, and transmit encrypted data between the deployment tool and the terminal device. This necessitates encryption and decryption for both the deployment tool and the terminal device, resulting in extensive data interaction, a complex deployment process, and significant challenges in troubleshooting, ultimately leading to low production line efficiency. Furthermore, the interaction between the deployment tool and the terminal device requires obtaining the terminal device's UID, further complicating data processing. Reducing the amount of encrypted data could effectively improve the efficiency of secure data deployment and enhance production line efficiency.
[0052] To address the aforementioned issues, this application provides a data storage method applicable to terminal devices. The deployment tool does not need to encrypt the security data; instead, it directly sends the security data to the terminal device. Upon receiving the security data, the terminal device stores it and performs a digest processing algorithm on the received security data and its corresponding UID to generate a hash value, which it then sends to the deployment tool. The deployment tool, upon receiving the hash value, does not process it but forwards it to a security server, a High Secure Machine (HSM), or other security devices. The security device signs the received hash value to obtain signature information and sends it to the deployment tool. The deployment tool, upon receiving the signature information, does not process it but forwards it directly to the mobile terminal. Upon receiving the signature information, the mobile terminal verifies it against its previously stored security information. If the verification passes, it stores the security data and the signature information, thus completing the security data deployment. This method reduces the data encryption process, simplifies the deployment process, and streamlines the interaction and encryption / decryption logic between deployment tools, terminal devices, and security devices, thereby improving production line efficiency. Terminal devices generate a hash value by digesting the received security data and its corresponding UID, which binds the security data to the mobile terminal, preventing data copying and enhancing data security. Signature processing and corresponding verification processes further verify whether the security data has been tampered with, thus further improving data security and reliability.
[0053] Figure 1 A schematic diagram of a data storage system provided in this application is shown below. Figure 1 As shown, the system includes: a terminal device 11, a deployment tool 12, and a security device 13. The deployment tool 12 is communicatively connected to both the terminal device 11 and the security device 13.
[0054] Figure 1The system shown includes, but is not limited to, deployment tools, terminal devices, and security devices, and may also include other electronic devices. Figure 1 The number and form of the devices shown are for illustrative purposes and do not constitute a limitation on the embodiments of this application.
[0055] Terminal device 11 is used to receive security data sent by deployment tool 12, and determine a first hash value based on the security data and the UID corresponding to terminal device 11; and send the first hash value to deployment tool 12. Terminal device can be a mobile phone, tablet computer, or other device.
[0056] Deployment tool 12 is used to send the received first hash value to security device 13.
[0057] Security device 13 is used to determine signature information based on the first hash value and send the signature information to deployment tool 12. Security device 13 can be a security server or a high-security device.
[0058] Deployment tool 12 is also used to send signature information to terminal device 11.
[0059] Terminal device 11 is also used to verify the signature information based on the first hash value, and if the verification is successful, to store the security data and signature information.
[0060] This application also provides an alternative data storage system architecture, which includes a mobile terminal and a security device. The security device includes a deployment tool, and the security device and the mobile terminal communicate with each other through the deployment tool. The deployment tool can be a software interface deployed on the security device.
[0061] Figure 2 A flowchart illustrating the data storage method provided in this application, which is applied to a terminal device, such as... Figure 2 As shown, the method includes:
[0062] S201, Receive security data sent by the deployment tool.
[0063] Security data can be SIMLOCK-related data, such as CCD, URD, and / or IMEI-related data, such as one or more IMEIs.
[0064] Security data can be generated by the deployment tool or obtained by the deployment tool from other devices or storage media.
[0065] S202. Determine the first hash value based on the security data and the device unique identifier (UID) corresponding to the terminal device, and send the first hash value to the deployment tool.
[0066] The terminal device can perform message digest processing on the security data and the corresponding UID of the terminal device to obtain a first hash value. For example, the RSA-2048 algorithm can be used to perform message digest processing on the security data and the corresponding UID of the terminal device to obtain a first hash value.
[0067] S203. Receive signature information sent by the security device through the deployment tool.
[0068] The signature information is determined by the security device based on the first hash value sent by the deployment tool.
[0069] The signature information can be obtained by a security device signing the received first hash value using its private key. For example, the security device can encrypt the first hash value using the RSA-2048 algorithm and its private key to obtain the corresponding signature information.
[0070] S204. Verify the signature information based on the first hash value. If the verification passes, store the security data and signature information.
[0071] After receiving the signature information, the terminal device verifies the signature information using the public key corresponding to the private key used during the signature processing with the security device, along with the first hash value. If the verification passes, it indicates that the security data has not been tampered with, and the security data and signature information are then stored.
[0072] Optionally, for the sake of the security and reliability of the stored data, the security data and signature information can be stored in the non-volatile memory of the terminal device.
[0073] The data storage method provided in this application receives secure data sent by a deployment tool; determines a first hash value based on the secure data and the UID corresponding to the terminal device, and sends the first hash value to the deployment tool; receives signature information determined by the secure device based on the first hash value sent by the deployment tool; verifies the signature information based on the first hash value; if the verification is successful, stores the secure data and signature information. This method enables the secure data to be transmitted to the terminal device in plaintext, simplifying the data encryption process and improving data transmission efficiency and production line efficiency. The terminal device generates a hash value by performing digest processing on the received secure data and its corresponding UID, which can bind the secure data and the mobile terminal to prevent the secure data from being copied and improve data security. Through the signature processing of the secure data by the secure device and the signature verification processing of the terminal device, it is possible to determine whether the secure data has been tampered with, thereby further improving data security and reliability. This method also simplifies the processing flow of the deployment tool, which mainly undertakes the data forwarding function, reducing the requirements for the deployment tool and reducing development difficulty.
[0074] Figure 3 This is another flowchart illustrating the data storage method provided in this application, which is applied to a terminal device. Figure 3 The illustrated embodiment is in Figure 2 Based on the illustrated embodiment, further detailed explanations are provided on how to receive security data sent by the deployment tool, such as... Figure 3 As shown, the method includes:
[0075] S301. If an authentication request message is received from the deployment tool, a random number is generated.
[0076] S302. Encrypt the random number using the public key to obtain the second encrypted data.
[0077] S303. Send the second encrypted data to the deployment tool.
[0078] S304. Receive third encrypted data sent by the security device through the deployment tool.
[0079] The third encrypted data is the data processed by the security device based on the second encrypted data and the private key sent by the deployment tool, with the private key corresponding to the public key.
[0080] For example, after receiving the second encrypted data sent by the terminal device, the deployment tool forwards it to the security device. The security device decrypts the second encrypted data using its private key to obtain the decryption result, and then encrypts the decryption result using its private key to obtain the third encrypted data. The third encrypted data is then sent to the deployment tool, which then forwards the received third encrypted data to the terminal device.
[0081] S305. Using the public key, the third encrypted data is decrypted to obtain the decryption result.
[0082] S306. Compare the decryption result with the random number. If they match, send a second notification message to the deployment tool.
[0083] The second notification message is used to notify the deployment tool; the decryption result is consistent with the random number.
[0084] S307, Receive security data sent by the deployment tool.
[0085] The security data is sent by the deployment tool after receiving the second notification message.
[0086] Security data can be SIMLOCK-related data, such as Customer Customized Data (CCD), User Data (URD), and / or IMEI-related data, such as one or more IMEIs.
[0087] Security data can be generated by the deployment tool or obtained by the deployment tool from other devices or storage media.
[0088] Optionally, the method further includes setting a second flag information.
[0089] The second flag bit is used to indicate that the decryption result is consistent with the random number.
[0090] Accordingly, receiving security data sent by the deployment tool includes: receiving security data sent by the deployment tool based on the second flag information.
[0091] Once the second flag information of the terminal device is set correctly, the terminal device will be able to accept data sent by the deployment tool, or be able to successfully parse the data sent by the deployment tool.
[0092] Optionally, after storing the security data and signature information, the method further includes: clearing the second flag information.
[0093] For example, if the decryption result matches the random number, the second flag is set, for example, to 1. When the deployment tool sends data to the terminal device, if the terminal device's second flag is set, the terminal device can successfully receive the data sent by the security device, or can successfully parse the data sent by the deployment tool; if the terminal device's second flag is cleared, the terminal device cannot receive the data sent by the security device, or cannot parse the data sent by the deployment tool.
[0094] It should be noted that the above effect can also be achieved by setting different values for the second flag bit. For example, if the decryption result matches the random number, the second flag bit is set to 1; otherwise, it is set to 0. When the deployment tool sends data to the terminal device, if the terminal device's second flag bit is 1, the terminal device can successfully receive the data sent by the security device, or can successfully parse the data sent by the deployment tool; if the terminal device's second flag bit is 0, the terminal device cannot receive the data sent by the security device, or cannot parse the data sent by the deployment tool.
[0095] The communication between the terminal device and the deployment tool can be interrupted or resumed by changing the value of the second flag bit information of the terminal device.
[0096] S308. Determine the first hash value based on the security data and the device unique identifier (UID) corresponding to the terminal device, and send the first hash value to the deployment tool.
[0097] The terminal device can perform message digest processing on the security data and the corresponding UID of the terminal device to obtain a first hash value. For example, the RSA-2048 algorithm can be used to perform message digest processing on the security data and the corresponding UID of the terminal device to obtain a first hash value.
[0098] When the security data includes SIMLOCK data, and the SIMLOCK data includes user-customized data CCD, in one possible implementation, the first hash value is determined based on the security data and the UID corresponding to the terminal device, including: encrypting the control key CK sent by the deployment tool based on the UID to obtain the first encrypted data; and determining the first hash value based on the first encrypted data, the CCD, and the UID.
[0099] For example, the terminal device encrypts the received CK according to its corresponding UID, for example, by performing symmetric encryption to obtain an encryption result; then, it performs digest processing on the encryption result and the terminal device's configuration parameters, such as SIM card slot configuration parameters, using a message digest algorithm to obtain a hash value; then, it performs digest processing on the hash value, the received CCD, and the UID using a message digest algorithm to obtain a first hash value.
[0100] This method determines a hash value that is related to the UID of the terminal device, which can effectively prevent SIMLOCK data from being maliciously copied.
[0101] When the security data includes at least two IMEI data, in one possible implementation, determining a first hash value based on the security data and the UID corresponding to the terminal device includes: receiving a first IMEI identifier sent by a deployment tool, the first IMEI identifier being used to identify the IMEI data applicable to the terminal device among the at least two IMEI data; determining a second IMEI identifier based on the at least two IMEI data and the configuration information of the terminal device; comparing whether the first IMEI identifier and the second IMEI identifier are consistent, and if they are consistent, determining the first hash value based on the at least two IMEI data, the second IMEI identifier, and the UID.
[0102] For example, when the security data includes four IMEIs, namely IMEI1, IMEI2, IMEI3, and IMEI4, if the terminal device can support IMEI1 and IMEI3, then the first IMEI identifier can be 1010. It should be noted that this is merely an example and not a restrictive description.
[0103] This method determines a hash value that is related to the terminal device's UID, effectively preventing IMEI data from being maliciously copied.
[0104] S309. Receive signature information sent by the security device through the deployment tool.
[0105] The signature information is determined by the security device based on the first hash value sent by the deployment tool.
[0106] For example, after receiving the first hash value, the terminal device sends a signature request message to the security device, which includes the first hash value; after receiving the signature request message, the security device performs signature processing on the first hash value using a corresponding algorithm to obtain signature information, and sends the signature information to the deployment tool; after receiving the signature information, the deployment tool forwards it to the terminal device.
[0107] The signature information can be obtained by a security device signing the received first hash value using its private key. For example, a security device can obtain the corresponding signature information by signing the first hash value using the RSA-2048 algorithm and its private key.
[0108] S310. Verify the signature information based on the first hash value. If the verification passes, store the security data and signature information.
[0109] After receiving the signature information, the terminal device verifies the signature information using the public key corresponding to the private key used during the signature processing with the security device, along with the first hash value. If the verification passes, it indicates that the security data has not been tampered with, and the security data and signature information are then stored.
[0110] Optionally, for the sake of the security and reliability of the stored data, the security data and signature information can be stored in the non-volatile memory of the terminal device.
[0111] In one possible implementation, storing secure data and signature information includes: performing operations on the secure data and signature information to store them in a target storage area, reading the data already stored in the target storage area, comparing the read data with the secure data and signature information respectively to verify the secure data and signature information, and if the verification is successful, determining that the secure data and signature information have been successfully stored.
[0112] This method can determine whether security data and signature information have been successfully stored.
[0113] SIMLOCK data can be divided into static data and dynamic data. Static data will not be changed after successful SIMLOCK deployment. If static data is tampered with, the SIM / USIM personalized data check will fail, and the terminal device will enter a limited service state where only emergency calls can be made. Dynamic data, also known as User Data (URD), such as lock / unlock counts and SIMLOCK status, changes dynamically depending on the user's situation.
[0114] Optionally, when the security data is SIMLOCK data, and the SIMLOCK data also includes URD, storing the security data and signature information includes: determining the second hash value corresponding to the URD; storing the security data, signature information, and second hash value.
[0115] This method can reduce the difficulty of storing URD data and improve data storage efficiency.
[0116] Optionally, the method further includes: updating the flag information corresponding to the security data, the flag information being used to characterize the storage state of the security data and signature information; and sending a first notification message to the deployment tool, the first notification message including the updated flag information.
[0117] Accordingly, when the terminal device is powered on or a card is inserted, it will first read the flag information corresponding to the security data. If the flag information indicates that the terminal device stores security data and signature information, it will further read and check the corresponding data. If the check fails, the terminal device will enter a limited service state that can only make emergency calls; if successful, the terminal device will be able to be used normally.
[0118] The data storage method provided in this application, based on the above embodiments, further includes the following steps: Before receiving security data sent by the deployment tool, the terminal device can generate a random number if it receives an authentication request message from the deployment tool; encrypt the random number using a public key to obtain second encrypted data; send the second encrypted data to the deployment tool; receive third encrypted data from the security device, obtained by processing the second encrypted data and private key sent by the deployment tool; decrypt the third encrypted data using a public key to obtain a decryption result; and authenticate the deployment tool by comparing the decryption result with the random number to determine whether it has the authority to send security information to the terminal device. If the decryption result matches the random number, it indicates that the deployment tool's authentication is successful and it has the authority to send security data to the terminal device. The terminal device then sends a second notification message to the deployment tool, enabling the deployment tool to send security data to the terminal device according to the notification message. This more effectively ensures the security, effectiveness, and reliability of data transmission between the deployment tool and the terminal device.
[0119] Figure 4 A signaling diagram for the data storage method provided in this application, such as Figure 4 As shown, when the security data is SIMLOCK data, the method includes:
[0120] S401, The deployment tool sends an authentication request message to the terminal device.
[0121] S402, The terminal device generates a random number N.
[0122] S403. The terminal device encrypts the random number using the public key to obtain the decryption result M1.
[0123] S404, The terminal device sends M1 to the deployment tool.
[0124] S405, The deployment tool sends M1 to the security device.
[0125] S406. The security device decrypts M1 using its private key to obtain the decryption result N1.
[0126] S407. The security device encrypts N1 using its private key to obtain encrypted data M2.
[0127] S408, the security device sends M2 to the deployment tool.
[0128] S409, The deployment tool sends M2 to the terminal device.
[0129] S410, The terminal device decrypts M2 using the public key to obtain the decryption result N2.
[0130] S411. The terminal device compares whether N2 and N are consistent.
[0131] S412. If N2 and N are the same, the terminal device sends a second notification message to the deployment tool.
[0132] Optionally, the device may also set a second flag information, which is used to indicate that N2 and N are consistent.
[0133] S412, Deployment tool generates CK.
[0134] S413, Deployment tools obtain CCD and URD.
[0135] S415, The deployment tool sends CK, CCD, and URD to the terminal device.
[0136] S416. The terminal device encrypts CK using the terminal device's UID to obtain the encryption result M3.
[0137] S417. The terminal device obtains the hash value H1 based on M3.
[0138] S418. The terminal device obtains the hash value H2 based on H1, CCD, and URD.
[0139] S419. The terminal device sends H2 to the deployment tool.
[0140] S420: The deployment tool sends a signature request message to the security device. The signature request message includes H2.
[0141] S421. The security device performs signature processing on H2 to obtain signature information S1.
[0142] S422, The security device sends S1 to the deployment tool.
[0143] S423, The deployment tool sends S1 to the terminal device.
[0144] S424. The terminal device verifies S1 based on H2.
[0145] S425. If the verification is successful, the terminal device obtains H3 based on the URD.
[0146] S426. The terminal device performs the operation of storing M3, CCD, URD, S1 and H3 in the target storage area.
[0147] S427. The terminal device reads the data stored in the target storage area and verifies the read data through M3, CCD, URD, S1 and H3.
[0148] S428. If the verification is successful, the terminal device determines that M3, CCD, URD, S1 and H3 are successfully stored, and updates the first flag information, which is used to characterize the storage status of M3, CCD, URD, S1 and H3.
[0149] S429. The terminal device sends a first notification message to the deployment tool. The first notification message is used to notify the deployment tool that the security data and signature information have been successfully stored.
[0150] Optionally, it also includes: the terminal device clearing the second flag information.
[0151] Figure 5 A signaling diagram for the data storage method provided in this application, such as Figure 5 As shown, when the security data is IMEI data, the method includes:
[0152] S501, The deployment tool sends an authentication request message to the terminal device.
[0153] S502, The terminal device generates a random number N.
[0154] S503, The terminal device encrypts the random number using the public key to obtain the decryption result M1.
[0155] S504, The terminal device sends M1 to the deployment tool.
[0156] S505, the deployment tool sends M1 to the security device.
[0157] S506. The security device decrypts M1 using its private key to obtain the decryption result N1.
[0158] S507. The security device encrypts N1 using a private key to obtain encrypted data M2.
[0159] S508, the security device sends M2 to the deployment tool.
[0160] S509, the deployment tool sends M2 to the terminal device.
[0161] S510: The terminal device decrypts M2 using the public key to obtain the decryption result N2.
[0162] S511. The terminal device compares whether N2 and N are consistent.
[0163] S512. If N2 and N are the same, the terminal device sends a second notification message to the deployment tool.
[0164] Optionally, the device may also set a second flag information, which is used to indicate that N2 and N are consistent.
[0165] S513, the deployment tool generates at least two IMEI data.
[0166] S514. The deployment tool determines the IMEI identifier FLAG1 based on the configuration information of the terminal device and the at least two IMEIs.
[0167] S515, the deployment tool sends at least two IMEI data and FLAG1 to the terminal device.
[0168] S516. The terminal device determines the IMEI identifier FLAG2 based on its configuration information and the at least two IMEIs, and compares FLAG1 and FLAG2.
[0169] S517. If FLAG1 and FLAG2 are the same, the terminal device obtains the hash value H1 based on the at least two IMEIs, FLAG2 and the terminal device's UID.
[0170] S518, The terminal device sends H1 to the deployment tool.
[0171] S519. The deployment tool sends a signature request message to the security device. The signature request message includes H1.
[0172] S520. The security device performs signature processing on H1 to obtain signature information S2.
[0173] S521, The security device sends S2 to the deployment tool.
[0174] S522, the deployment tool sends S2 to the terminal device.
[0175] S523. The terminal device verifies S2 based on H1.
[0176] S524. If the verification is successful, the terminal device will perform the operation of storing at least two IMEIs and S2 in the target storage area.
[0177] S525, The terminal device reads the data stored in the target storage area and verifies the read data using at least two IMEIs and S2.
[0178] S526. If the verification is successful, the terminal device determines that the at least two IMEIs and S2 have been successfully stored, and updates the second flag information, which is used to characterize the storage status of the at least two IMEIs and S2.
[0179] S527. The terminal device sends a first notification message to the deployment tool. The first notification message is used to notify the deployment tool that the security data and signature information have been successfully stored.
[0180] Optionally, it also includes: the terminal device clearing the second flag information.
[0181] Figure 6 A schematic diagram of the data storage device provided in this application, such as Figure 6 As shown, the device includes:
[0182] The receiving module 61 is used to receive security data sent by the deployment tool.
[0183] The processing module 62 is used to determine the first hash value based on the security data and the device unique identifier (UID) corresponding to the terminal device, and send the first hash value to the deployment tool.
[0184] The receiving module 61 is also used to receive signature information sent by the security device through the deployment tool, wherein the signature information is determined by the security device based on the first hash value sent by the deployment tool.
[0185] The processing module 62 is also used to verify the signature information based on the first hash value. If the verification is successful, the security data and signature information are stored.
[0186] Optionally, the processing module 62 is specifically used to perform operations on the security data and signature information to store them in the target storage area, and to read the data already stored in the target storage area, and compare the read data with the security data and signature information respectively to verify the security data and signature information; if the verification is successful, it is determined that the security data and signature information have been successfully stored.
[0187] Optionally, the processing module 62 is also used to update the flag information corresponding to the security data, the flag information being used to characterize the storage status of the security data and signature information.
[0188] Optionally, the processing module 62 is also configured to send a first notification message to the deployment tool, the first notification message being used to notify the deployment tool that the security data and signature information have been successfully stored.
[0189] Optionally, the security data includes user identification lock (SIMLOCK) data, which includes user-customized data (CCD); the processing module 62 is specifically used to encrypt the control key (CK) sent by the deployment tool according to the UID to obtain first encrypted data; and to determine a first hash value based on the first encrypted data, the CCD, and the UID.
[0190] Optionally, the SIMLOCK data includes user data URD; the processing module 62 is specifically used to determine the second hash value corresponding to the URD; and to store security data, signature information, and the second hash value.
[0191] Optionally, the security data includes at least two International Mobile Equipment Identity (IMEI) data; the processing module 62 is specifically used to receive a first IMEI identifier sent by the deployment tool, the first IMEI identifier being used to identify the IMEI data applicable to the terminal device among the at least two IMEI data; determine a second IMEI identifier based on the at least two IMEI data and the configuration information of the terminal device; compare whether the first IMEI identifier and the second IMEI identifier are consistent, and if they are consistent, determine a first hash value based on the at least two IMEI data, the second IMEI identifier, and the UID.
[0192] Optionally, the receiving module 61 is specifically configured to: generate a random number if it receives an authentication request message sent by the deployment tool; encrypt the random number using a public key to obtain second encrypted data; send the second encrypted data to the deployment tool; receive third encrypted data sent by the security device through the deployment tool, the third encrypted data being data processed by the security device based on the second encrypted data and private key sent by the deployment tool, the private key corresponding to the public key; decrypt the third encrypted data using the public key to obtain a decryption result; compare the decryption result with the random number for consistency, and if they are consistent, send a second notification message to the deployment tool; and receive security data sent by the deployment tool after receiving the second notification message.
[0193] Optionally, the processing module 62 is also used to set a second flag bit information, which is used to indicate that the decryption result is consistent with the random number; and to receive security data sent by the deployment tool according to the second flag bit information.
[0194] Optionally, the processing module 62 is also used to clear the second flag information.
[0195] The data storage device provided in this application can execute the data storage method provided in the above embodiments. Its content and effects can be referred to the above method embodiment section, and will not be repeated here.
[0196] Figure 7 A schematic diagram of the structure of the terminal device provided in this application, such as... Figure 7 As shown, the terminal device includes a processor 71 and a memory 72; the processor 71 and the memory 72 are communicatively connected. The memory 72 is used to store computer programs. The processor 71 is used to call the computer programs stored in the memory 72 to implement the methods in the above-described method embodiments.
[0197] Optionally, the terminal device also includes a transceiver 73 for communicating with other devices.
[0198] The terminal device can execute the above-described data storage method. Its content and effects can be found in the method implementation section, and will not be repeated here.
[0199] This application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the aforementioned data storage method.
[0200] This application also provides a computer program product, including a computer program that, when executed by a processor, can implement the above-described data storage method.
[0201] All or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a readable memory. When the program is executed, it performs the steps of the above method embodiments; and the aforementioned memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disk, and any combination thereof.
[0202] This application describes embodiments with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processing unit of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processing unit of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0203] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0204] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0205] Obviously, those skilled in the art can make various modifications and variations to the embodiments of this application without departing from the spirit and scope of this application. Therefore, if these modifications and variations to the embodiments of this application fall within the scope of the claims of this application and their equivalents, this application also intends to include these modifications and variations.
[0206] In this application, the term "comprising" and its variations can refer to non-limiting inclusion; the term "or" and its variations can refer to "and / or". The terms "first", "second", etc., in this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. In this application, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0207] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0208] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A data storage method, characterized by, The method is applied to a terminal device, and comprises the following steps: receiving security data sent by a deployment tool; determining a first hash value according to the security data and a device unique identifier (UID) corresponding to the terminal device, and sending the first hash value to the deployment tool; receiving signature information sent by a security device through the deployment tool, the signature information being determined by the security device according to the first hash value sent by the deployment tool; verifying the signature information according to the first hash value, and storing the security data and the signature information if the verification is passed; the security data comprises subscriber identity module (SIM) lock data, and the SIM lock data comprises customised data (CCD); the step of determining the first hash value according to the security data and the UID corresponding to the terminal device comprises the following steps: encrypting a control key (CK) sent by the deployment tool according to the UID to obtain first encrypted data; determining the first hash value according to the first encrypted data, the CCD and the UID; or the security data comprises at least two international mobile equipment identity (IMEI) data; the step of determining the first hash value according to the security data and the UID corresponding to the terminal device comprises the following steps: receiving a first IMEI identifier sent by the deployment tool, the first IMEI identifier being used to identify IMEI data suitable for the terminal device among the at least two IMEI data; determining a second IMEI identifier according to the at least two IMEI data and configuration information of the terminal device; comparing whether the first IMEI identifier and the second IMEI identifier are consistent, and determining the first hash value according to the at least two IMEI data, the second IMEI identifier and the UID if the first IMEI identifier and the second IMEI identifier are consistent. the step of storing the security data and the signature information comprises the following steps:
2. The method of claim 1, wherein, performing an operation stored in a target storage area on the security data and the signature information, reading data stored in the target storage area, and comparing the read data with the security data and the signature information respectively to verify the security data and the signature information; if the verification is passed, determining that the security data and the signature information are stored successfully. the method further comprises the following steps:
3. The method of claim 2, wherein, updating first flag information, the first flag information being used to represent a storage state of the security data and the signature information. the method further comprises the following steps:
4. The method of claim 2, wherein, sending a first notification message to the deployment tool, the first notification message being used to notify the deployment tool that the security data and the signature information are stored successfully. the SIM lock data comprises user data (URD); 5. The method of claim 1, wherein, the step of storing the security data and the signature information comprises the following steps: determining a second hash value corresponding to the URD; storing the security data, the signature information and the second hash value. the step of receiving the security data sent by the deployment tool comprises the following steps:
6. The method according to any one of claims 1 to 3, characterized in that, generating a random number if an authentication request message sent by the deployment tool is received; encrypting the random number through a public key to obtain second encrypted data; sending the second encrypted data to the deployment tool; receiving third encrypted data sent by the security device through the deployment tool, the third encrypted data being data processed by the security device according to the second encrypted data sent by the deployment tool and a private key corresponding to the public key; decrypting the third encrypted data through the public key to obtain a decryption result; comparing the decryption result with the random number to determine whether they are consistent, and if so, sending a second notification message to the deployment tool; receiving security data sent by the deployment tool, the security data being sent by the deployment tool after receiving the second notification message.
7. The method of claim 6, wherein, The method further comprises: setting second flag information, the second flag information being used to represent that the decryption result and the random number are consistent; Correspondingly, the receiving security data sent by the deployment tool comprises: receiving security data sent by the deployment tool according to the second flag information.
8. The method of claim 7, wherein, After storing the security data and the signature information, the method further comprises: clearing the second flag information.
9. A data storage device, characterized by Comprise: a receiving module configured to receive security data sent by the deployment tool; a processing module configured to determine a first hash value according to the security data and a device unique identifier (UID) corresponding to a terminal device, and send the first hash value to the deployment tool; the receiving module is further configured to receive signature information sent by the security device through the deployment tool, the signature information being determined by the security device according to the first hash value sent by the deployment tool; the processing module is further configured to verify the signature information according to the first hash value, and if the verification is passed, store the security data and the signature information; the security data comprises subscriber identity module (SIM) lock (SIMLOCK) data, and the SIMLOCK data comprises customer custom data (CCD); the processing module is further configured to encrypt a control key (CK) sent by the deployment tool according to the UID to obtain first encrypted data, and determine a first hash value according to the first encrypted data, the CCD and the UID; Or, the security data comprises at least two international mobile equipment identity (IMEI) data; the processing module is further configured to receive a first IMEI identifier sent by the deployment tool, the first IMEI identifier being used to identify IMEI data suitable for the terminal device among the at least two IMEI data; determine a second IMEI identifier according to the at least two IMEI data and configuration information of the terminal device; compare the first IMEI identifier with the second IMEI identifier to determine whether they are consistent, and if so, determine a first hash value according to the at least two IMEI data, the second IMEI identifier and the UID.
10. A data processing system, characterized by Comprise a terminal device, a security device and a deployment tool, the deployment tool being in communication connection with the terminal device and the security device respectively; The terminal device is configured to receive the security data sent by the deployment tool, determine a first hash value according to the security data and a device unique identifier (UID) corresponding to the terminal device, and send the first hash value to the deployment tool. The deployment tool is configured to send the received first hash value to the security device. The security device is configured to determine signature information according to the first hash value, and send the signature information to the deployment tool. The deployment tool is further configured to send the signature information to the terminal device. The terminal device is further configured to verify the signature information according to the first hash value, and deploy the security data and the signature information if the verification is passed. The security data includes subscriber identity module (SIM) lock (SIMLOCK) data, and the SIMLOCK data includes customizing data (CCD) of a user. The terminal device is further configured to encrypt a control key (CK) sent by the deployment tool according to the UID to obtain first encrypted data, and determine a first hash value according to the first encrypted data, the CCD and the UID. Alternatively, The security data includes at least two international mobile equipment identity (IMEI) data.
11. A computer readable storage medium, characterized in that, The terminal device is further configured to receive a first IMEI identifier sent by the deployment tool, and the first IMEI identifier is used to identify the IMEI data suitable for the terminal device among the at least two IMEI data.
12. A computer program product comprising computer programs / instructions, characterized in that, A second IMEI identifier is determined according to the at least two IMEI data and configuration information of the terminal device. The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method in any one of claims 1 to 8. The computer program / instruction is executed by the processor to implement the method in any one of claims 1 to 8.
Citation Information
Patent Citations
Data transmission consistency verification method and device, computer equipment and storage medium
CN110289947A
Data processing method, communication device and storage medium
CN113918970A