A data download system for an eSIM module

By using an eSIM module on IoT devices, combined with the collaborative work of mobile terminals, network analyzers, and servers, the problems of cumbersome SIM card replacement and poor communication performance in traditional SIM cards are solved, enabling remote card writing that simplifies operations and improves security.

CN115567914BActive Publication Date: 2026-01-02BEIJING SHUMI NETWORK TECH CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211175783.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-26
Publication Date
2026-01-02
Estimated Expiration
2042-09-26

AI Technical Summary

Technical Problem

Replacing SIM cards for traditional IoT devices is cumbersome and can easily cause wear and tear on the devices. Furthermore, existing technologies cannot effectively solve the problem of poor communication performance for operators.

Method used

By replacing the traditional SIM card slot with an eSIM module, and through the collaborative work of a mobile terminal, network analyzer, first server, and second server, signal strength analysis and operator available resource analysis are provided, enabling remote card writing and improving data security.

Benefits of technology

It simplifies card replacement operations, reduces equipment wear and tear, ensures better communication performance, and improves the security of card writing data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115567914B_ABST
    Figure CN115567914B_ABST
Patent Text Reader

Abstract

Embodiments of the present application relate to a data download system of an eSIM module, the system comprising a mobile terminal, a network analyzer, an Internet of Things device, a first server and a second server, the Internet of Things device being built-in with an eSIM module. The system solves the hot plug problem when changing cards, and provides signal strength and operator available resource analysis to the staff through the network analyzer and the first server each time the card is changed, assisting the staff to perform network optimization. The system also provides an eSIM module data download mechanism based on an asymmetric key system through the second server, which realizes remote card writing and improves the security of card writing data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, in particular to a data download system of an eSIM module. BACKGROUND

[0002] The traditional Internet of Things device uses a physical SIM card as an operator identity module. During the working process of the Internet of Things device, if the communication effect of the SIM card of a certain device is not good, a worker needs to carry a new card of another operator to replace the old card; the worker needs to apply for the physical card before replacing the card and return the old card after replacing the card, and the device card slot needs to be hot-plugged each time the card is replaced. Obviously, the traditional method has some problems: it is complicated and easy to cause device wear and tear. SUMMARY

[0003] The present application is aimed at the defects of the prior art and provides a data download system of an eSIM module, which comprises a mobile terminal, a network analyzer, an Internet of Things device, a first server and a second server, and the Internet of Things device is built-in with an eSIM (Embedded-SIM) module. The system uses a pre-installed eSIM module to replace the traditional SIM card slot on each Internet of Things device, which can solve the problem of hot-plugging when replacing the card; the system provides a mobile terminal for the worker to replace the card, which is simple to operate and does not need to apply for / return the physical card; the system provides signal strength analysis and operator available resource analysis to the worker through the network analyzer and the first server each time the card is replaced, which assists the worker in network optimization and ensures better communication effect after replacing the card; and the system provides an eSIM module data download mechanism based on an asymmetric key system through the second server, which can realize remote card writing and improve the security of the written data.

[0004] To achieve the above-mentioned purpose, the embodiments of the present application provide a data download system of an eSIM module, which comprises a mobile terminal, a network analyzer, an Internet of Things device, a first server and a second server, and the Internet of Things device is built-in with an eSIM module.

[0005] The mobile terminal is connected with the network analyzer, the Internet of Things device, the first server and the second server respectively; the mobile terminal is used to provide a user operation interface with a data download button for the staff; and when the staff clicks the data download button, the network analyzer is called to generate a corresponding first network analysis list; the Internet of Things device is called to generate corresponding first device identification and first IMEI data; the first server is called to analyze and process the available resources of the operator according to the first device identification and the first IMEI data to generate a corresponding first operator resource list; the first network analysis list and the first operator resource list are integrated to generate a corresponding first integrated list; when the preferred network mode is an interactive confirmation mode, the first integrated list is sorted according to the network signal strength from high to low to generate a corresponding first integrated record sequence, which is displayed to the staff, and the first integrated record selected by the staff in the first integrated record sequence is taken as a corresponding preferred record; the first server is called to allocate telecom card resources according to the preferred record to generate a corresponding first activation code; the second server and the eSIM module of the Internet of Things device are bidirectionally authenticated; and when the bidirectional authentication is successful, the second server is called to load card data into the eSIM module according to the first activation code.

[0006] Preferably, the first network analysis list includes a plurality of first network analysis records; the first network analysis record includes a first operator network standard field and a first signal strength field; the first operator network standard field includes a first operator identification and a first network standard, and the first network standard includes a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard;

[0007] The first operator resource list includes a plurality of first operator resource records; the first operator resource record includes a second operator network standard field and a first available card number field; the second operator network standard field includes a second operator identification and a second network standard, and the second network standard includes a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard;

[0008] The first integrated list includes a plurality of first integrated records; the first integrated record includes a third operator network standard field, a second signal strength field and a second available card number field; the third operator network standard field includes a third operator identification and a third network standard, and the third network standard includes a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard;

[0009] The first integrated record in the first integrated record sequence is ordered in descending order of the second signal strength field;

[0010] The first activation code includes a second server address and a first token;

[0011] The eSIM module is locally pre-stored with a plurality of sets of first module public-private key pairs, a first manufacturer public key certificate, and a first certificate authority public key certificate; each of the first module public-private key pairs corresponds to a first module identifier; the first module public-private key pair includes a first module public key certificate and a first module private key; the first module public key certificate includes a first module public key, first module key information, and a first module certificate signature; the first manufacturer public key certificate includes a first manufacturer public key, first manufacturer public key information, and a first manufacturer certificate signature; and the first certificate authority public key certificate includes a certificate authority public key, certificate authority public key information, and a certificate authority certificate signature;

[0012] The second server is locally pre-stored with a first server public-private key pair, a second server public-private key pair, the first certificate authority public key certificate, and a script encryption and decryption key; the first server public-private key pair includes a first server public key certificate and a first server private key; the first server public key certificate includes a first server public key, first server key information, and a first server certificate signature; the second server public-private key pair includes a second server public key certificate and a second server private key; the second server public key certificate includes a second server public key, second server key information, and a second server certificate signature; and the first certificate authority public key certificate includes a certificate authority public key, certificate authority public key information, and a certificate authority certificate signature.

[0013] Preferably, the mobile terminal is specifically used for sending a network analysis instruction to the network analyzer when the network analyzer is called to perform network analysis processing; and receiving the first network analysis list sent back by the network analyzer.

[0014] Further, the network analyzer is configured to traverse each first network signal frequency band record of a preset network signal frequency band list when receiving the network analysis instruction sent by the mobile terminal; and during the traversal, take the first network signal frequency band record currently traversed as a corresponding current frequency band record, and extract the fourth operator network standard field, the first signal frequency band field and the first signal frequency range field of the current frequency band record as a corresponding current operator network standard, a current signal frequency band and a current signal frequency range; analyze the signal strength of the wireless signal with the signal frequency band being the current signal frequency band, the signal frequency satisfying the current signal frequency range, and the signal standard satisfying the current operator network standard to generate a corresponding current signal strength; and take the current operator network standard and the current signal strength obtained as the first operator network standard field and the first signal strength field to form a corresponding first network analysis record; and when the traversal ends, send all the first network analysis records obtained to the data download terminal as a corresponding first network analysis list.

[0015] Preferably, the network signal frequency band list includes a plurality of first network signal frequency band records; the first network signal frequency band record includes the fourth operator network standard field, the first signal frequency band field and the first signal frequency range field; the fourth operator network standard field includes a fourth operator identifier and a fourth network standard, and the fourth network standard includes a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard.

[0016] Preferably, the mobile terminal is specifically configured to send a device basic data acquisition instruction to the Internet of Things device when calling the Internet of Things device to perform device identification and device IMEI data acquisition processing; and receive the first device identifier and the first IMEI data sent back by the Internet of Things device.

[0017] Further, the Internet of Things device is configured to extract the locally stored unique device code and unique IMEI data as the first device identifier and the first IMEI data to send back to the mobile terminal when receiving the device basic data acquisition instruction sent by the mobile terminal.

[0018] Preferably, the mobile terminal is specifically configured to send an available resource query instruction carrying the first device identifier and the first IMEI data to the first server when calling the first server to perform operator available resource analysis processing according to the first device identifier and the first IMEI data; and receive the first operator resource list sent back by the first server.

[0019] Further, the first server is configured to extract the first device identifier and the first IMEI data from the available resource query instruction sent by the mobile terminal when receiving the available resource query instruction; extract the first deployment area of the first device deployment record in the preset device deployment list, in which the first device identifier field matches the first device identifier and the first IMEI field matches the first IMEI data, as the corresponding first deployment area; mark all first regional resource statistical records in the preset regional resource statistical list, in which the first area field matches the first deployment area, as matching statistical records; extract the fifth operator network mode field and the third available card quantity field of each matching statistical record as the corresponding second operator network mode field and the first available card quantity field to form the corresponding first operator resource record; and send the corresponding first operator resource list composed of all the first operator resource records to the mobile terminal;

[0020] The device deployment list includes a plurality of first device deployment records, and each first device deployment record includes the first device identifier field, the first IMEI field, and the first deployment area field.

[0021] The regional resource statistical list includes a plurality of first regional resource statistical records, and each first regional resource statistical record includes the first area field, the fifth operator network mode field, and the third available card quantity field. The fifth operator network mode field includes a fifth operator identifier and a fifth network mode, and the fifth network mode includes a 2G mode, a 3G mode, a 4G mode, a 5G mode, and an NB-IOT mode.

[0022] Preferably, the mobile terminal is specifically configured to initialize the first integrated list as an empty list when performing content integration processing on the first network analysis list and the first operator resource list; count the number of first network analysis records in the first network analysis list to generate a corresponding first number N; add N first integrated records with empty record content to the first integrated list, the first integrated records corresponding one-to-one to the first network analysis records; and set the second available card quantity field of each first integrated record to 0.

[0023] According to the first operator network mode field and the first signal strength field of each first network analysis record in the first network analysis list, the third operator network mode field and the second signal strength field of the corresponding first integrated record are set.

[0024] and the first operator resource record of the first operator resource list is traversed; and in the traversal, the first operator resource record currently traversed is taken as a corresponding current resource record, the second operator network mode field and the first available card number field of the current resource record are taken as a corresponding current operator network mode and a current available card number, and the second available card number field of the first integrated record in the first integrated list, which has the third operator network mode field matching the current operator network mode, is set as the current available card number.

[0025] Preferably, the mobile terminal is specifically used for extracting the third operator network mode field from the preferred record as a corresponding preferred operator network mode when the first server is called to perform the telecommunication card resource allocation processing according to the preferred record; and sending a resource application instruction carrying the first device identifier, the first IMEI data and the preferred operator network mode to the first server; and receiving the first activation code sent back by the first server.

[0026] Further, the first server is further used for extracting the first device identifier, the first IMEI data and the preferred operator network mode from the resource application instruction sent by the mobile terminal when the resource application instruction is received; extracting the first deployment area field of the first device deployment record in the preset device deployment list, which has the first device identifier matching the first device identifier and the first IMEI field matching the first IMEI data, as a corresponding second deployment area; marking all first card number resource records in the preset card number resource list, which have the second area field matching the second deployment area, the sixth operator network mode field matching the preferred operator network mode and the first state field being in the unoccupied state, as matching card number resource records; selecting one of the obtained multiple matching card number resource records as a corresponding preferred card number resource record; extracting the first ICCID field and the first card issuing script field of the preferred card number resource record as corresponding first ICCID data and first card issuing script data, and changing the first state field of the preferred card number resource record to the occupied state; sending an activation code application instruction carrying the first device identifier, the first IMEI data, the first ICCID data and the first card issuing script data to the second server; and sending the first activation code sent back by the second server to the mobile terminal;

[0027] The device deployment list includes multiple first device deployment records; the first device deployment record includes the first device identifier field, the first IMEI field and the first deployment area field.

[0028] The card number resource list includes a plurality of first card number resource records; the first card number resource record includes the first ICCID field, the second region field, the sixth operator network mode field, the first card issuing script field, and the first state field; the sixth operator network mode field includes a sixth operator identifier and a sixth network mode, and the sixth network mode includes a 2G mode, a 3G mode, a 4G mode, a 5G mode, and an NB-IOT mode; the first card issuing script field is used to store card issuing script data; and the first state field includes an occupied state and an unoccupied state.

[0029] Further preferably, the second server is configured to extract the first device identifier, the first IMEI data, the first ICCID data, and the first card issuing script data from the activation code application instruction sent by the first server when receiving the activation code application instruction, add a first device card number binding record to a preset device card number binding list, set the second device identifier field, the second IMEI field, the second ICCID field, and the second card issuing script field of the added record to the first device identifier, the first IMEI data, the first ICCID data, and the first card issuing script data, respectively, generate a token data as the first token corresponding to the added record, set the first token field of the added record to the first token, and send the first activation code composed of the second server address and the first token to the first server.

[0030] The device card number binding list includes a plurality of first device card number binding records; and each first device card number binding record includes the second device identifier field, the second IMEI field, the second ICCID field, the second card issuing script field, and the first token field.

[0031] Preferably, the mobile terminal is specifically configured to extract the second server address from the first activation code when performing the bidirectional authentication processing on the second server and the eSIM module of the Internet of Things device.

[0032] The mobile terminal is further configured to send a module information acquisition instruction to the eSIM module through the Internet of Things device, and receive first module data returned by the eSIM module through the Internet of Things device; the first module data includes first version data and a first public key identifier sequence, and the first public key identifier sequence includes a plurality of first public key identifiers.

[0033] The mobile terminal is further configured to send a module random number acquisition instruction to the eSIM module through the Internet of Things device, and receive a first module random number returned by the eSIM module through the Internet of Things device.

[0034] and sending the first module random number, the first module data and the second server address to the second server; and receiving the first session identification, the first server plaintext, the first server signature, the second module public key identification and the first server public key certificate sent back by the second server; wherein the first server plaintext comprises the first session identification, second module random number, first server random number and third server address;

[0035] and comparing the third server address with the second server address; if both are the same, sending the first session identification, the first server plaintext, the first server signature, the second module public key identification and the first server public key certificate to the eSIM module through the Internet of Things device; and receiving the first session identification, first module plaintext, first module signature, second module public key certificate and the first manufacturer public key certificate sent back by the eSIM module through the Internet of Things device; wherein the first module plaintext comprises the first session identification, second server random number and second module data, the second module data comprises second version data and second public key identification sequence, and the second public key identification sequence comprises a plurality of second public key identifications;

[0036] and sending the first session identification, the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate to the second server; and receiving the verification return data sent back by the second server; and confirming that the two-way authentication processing is successful when the verification return data is verification success.

[0037] Further, the eSIM module is configured to, when receiving the module information acquisition instruction sent by the mobile terminal through the Internet of Things device, take the locally stored module version information as the corresponding first version data; take the first module identification of each first module public and private key pair pre-stored locally as the corresponding first public key identification, and form the corresponding first public key identification sequence by all the first public key identifications; form the corresponding first module data by the first version data and the first public key identification sequence; and send the first module data back to the mobile terminal through the Internet of Things device.

[0038] The eSIM module is further configured to, when receiving the module random number acquisition instruction sent by the mobile terminal through the Internet of Things device, call a local random number generator to generate a random number as the corresponding first module random number and save it; and send the first module random number back to the mobile terminal through the Internet of Things device.

[0039] Further, the second server is further configured to identify whether the second server address matches the server address when receiving the first module random number, the first module data and the second server address sent by the mobile terminal; if yes, save the first version data of the first module data; select one first public key identifier from the first public key identifier sequence of the first module data as the corresponding second module public key identifier; generate a unique session identifier code as the corresponding first session identifier according to a preset session identifier coding rule; take the first module random number as the corresponding second module random number; call a local random number generation interface to generate a random number as the corresponding first server random number and save it; take the second server address as the corresponding third server address; compose the corresponding first server plaintext from the first session identifier, the second module random number, the first server random number and the third server address; generate the corresponding first hash code based on a preset hash algorithm; use the first server private key of the first server public-private key pair to sign and calculate the first hash code to generate the corresponding first server signature; and send the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate to the mobile terminal.

[0040] Further, the eSIM module is further configured to extract the first server public key and the first server key information from the first server public key certificate to compose the corresponding first plaintext when receiving the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate sent by the mobile terminal through the Internet of Things device, and generate the corresponding second hash code based on a preset hash algorithm; use the issuing center public key of the first issuing center public key certificate to verify and calculate the first server certificate signature of the first server public key certificate to obtain the corresponding third hash code; and confirm that the server public key certificate is a valid certificate when the second and third hash codes match.

[0041] When it is confirmed that the server public key certificate is a valid certificate, generate the corresponding fourth hash code based on a preset hash algorithm, and use the first server public key of the first server public key certificate to verify and calculate the first server signature to obtain the corresponding fifth hash code; and confirm that the server signature is correct when the fourth and fifth hash codes match.

[0042] and when it is confirmed that the server signature is correct, the second module random number is extracted from the first server plaintext and compared with the locally saved first module random number; if they match, the locally stored module version information is taken as the corresponding second version data; and the locally preset first module identifier of each first module public-private key pair is taken as the corresponding second public key identifier, and the obtained all second public key identifiers form the corresponding second public key identifier sequence; and the second version data and the second public key identifier sequence form the corresponding second module data; and the first server random number of the first server plaintext is taken as the corresponding second server random number; and the first session identifier of the first server plaintext, the second server random number and the second module data form the corresponding first module plaintext;

[0043] and the first module identifier that matches the second module public key identifier of the locally preset first module public-private key pair is taken as the corresponding current module public-private key pair; and the first module private key of the current module public-private key pair is taken as the corresponding current module private key;

[0044] and the first module plaintext is hashed based on a preset hash algorithm to generate the corresponding sixth hash code; and the sixth hash code is signed using the current module private key to generate the corresponding first module signature;

[0045] and the first module public key certificate of the current module public-private key pair is extracted as the corresponding second module public key certificate;

[0046] and the first session identifier, the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate are sent back to the mobile terminal through the Internet of Things device.

[0047] Further, the second server is further configured to, when the first session identifier, the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate sent by the mobile terminal are received, extract the second server random number from the first module plaintext and compare it with the saved first server random number;

[0048] if the first and second server random numbers match, the second version data is extracted from the second module data of the first module plaintext and compared with the saved first version data;

[0049] if the first and second version data match, the first module public key and the first module key information are extracted from the second module public key certificate to form a corresponding second plaintext, a corresponding seventh hash code is generated by performing hash calculation on the second plaintext based on a preset hash algorithm, a corresponding eighth hash code is obtained by performing signature verification calculation on the first module certificate signature of the second module public key certificate using the first issuing center public key of the first issuing center public key certificate pre-stored locally, and when the seventh and eighth hash codes match, it is confirmed that the eSIM module public key certificate is a valid certificate;

[0050] When it is confirmed that the eSIM module public key certificate is a valid certificate, the first manufacturer public key and the first manufacturer public key information are extracted from the first manufacturer public key certificate to form a corresponding third plaintext, a corresponding ninth hash code is generated by performing hash calculation on the third plaintext based on a preset hash algorithm, a corresponding tenth hash code is obtained by performing signature verification calculation on the first manufacturer certificate signature of the first manufacturer public key certificate using the first issuing center public key of the first issuing center public key certificate pre-stored locally, and when the ninth and tenth hash codes match, it is confirmed that the manufacturer public key certificate is a valid certificate;

[0051] When it is confirmed that the manufacturer public key certificate is a valid certificate, a corresponding eleventh hash code is generated by performing hash calculation on the first module plaintext based on a preset hash algorithm, a corresponding twelfth hash code is obtained by performing signature verification calculation on the first module signature using the first module public key of the second module public key certificate, and when the eleventh and twelfth hash codes match, it is confirmed that the eSIM module signature is correct;

[0052] When it is confirmed that the eSIM module signature is correct, the corresponding verification return data is set to verification success; and the verification return data is sent back to the mobile terminal.

[0053] Preferably, the mobile terminal is specifically used for sending the first session identifier and the first activation code to the second server when the second server is called to perform card data loading processing on the eSIM module according to the first activation code; and receiving the first session identifier, the second server signature and the second server public key certificate sent back by the second server;

[0054] The first session identifier, the second server signature and the second server public key certificate are sent to the eSIM module through the Internet of Things device; and the first session identifier, the second module signature and the first module temporary public key sent back by the eSIM module through the Internet of Things device are received;

[0055] and send the first session identifier, the second module signature, and the first module temporary public key to the second server; and receive the first session identifier, first ciphertext, second ciphertext, and first server temporary public key sent back by the second server;

[0056] and send the first session identifier, the first ciphertext, the second ciphertext, and the first server temporary public key to the eSIM module through the Internet of Things device; and receive loading status data sent back by the eSIM module through the Internet of Things device; and confirm that the card data loading process is successful when the loading status data is loading success.

[0057] Further, the second server is further configured to, when receiving the first session identifier and the first activation code sent by the mobile terminal, check the second server address of the first activation code; when the check is passed, extract the second card issuing script field of the first device card number binding record in which the first token field in the preset device card number binding list matches the first token of the first activation code as corresponding second card issuing script data and store the second card issuing script data locally; wherein the device card number binding list includes a plurality of first device card number binding records; and the first device card number binding record includes a second device identifier field, a second IMEI field, a second ICCID field, the second card issuing script field, and the first token field.

[0058] and generate a corresponding thirteenth hash code by performing hash calculation on the first session identifier based on a preset hash algorithm; and generate a corresponding second server signature by performing signature calculation on the thirteenth hash code using the second server private key of the second server public-private key pair;

[0059] and send the first session identifier, the second server signature, and the second server public key certificate of the second server public-private key pair back to the mobile terminal.

[0060] Further, the eSIM module is further configured to, when receiving the first session identifier, the second server signature, and the second server public key certificate sent by the mobile terminal through the Internet of Things device, extract the second server public key and the second server key information from the second server public key certificate to form a corresponding fourth plaintext, generate a corresponding fourteenth hash code by performing hash calculation on the fourth plaintext based on a preset hash algorithm, perform signature verification calculation on the second server certificate signature of the second server public key certificate using the first issuing center public key of the first issuing center public key certificate pre-stored locally to obtain a corresponding fifteenth hash code, and confirm that the server public key certificate is a valid certificate when the fourteenth hash code and the fifteenth hash code match.

[0061] and when it is confirmed that the server public key certificate is a valid certificate, a corresponding sixteenth hash code is generated by performing hash calculation on the first session identifier based on a preset hash algorithm, and a corresponding seventeenth hash code is obtained by performing signature verification calculation on the second server signature using the second server public key of the second server public key certificate, and when the sixteenth and seventeenth hash codes match, it is confirmed that the server signature is correct;

[0062] and when it is confirmed that the server signature is correct, a pair of temporary public and private key pairs are generated by performing a public and private key pair generation process, which are recorded as a corresponding first module temporary public key and a first module temporary private key; and an eighteenth hash code is generated by performing hash calculation on the first session identifier based on a preset hash algorithm; and a corresponding second module signature is generated by performing signature calculation on the eighteenth hash code using the first module temporary private key;

[0063] and the first session identifier, the second module signature and the first module temporary public key are sent back to the mobile terminal through the Internet of Things device.

[0064] Further, the second server is further configured to, when the first session identifier, the second module signature and the first module temporary public key sent by the mobile terminal are received, generate a corresponding nineteenth hash code by performing hash calculation on the first session identifier based on a preset hash algorithm, and obtain a corresponding twentieth hash code by performing signature verification calculation on the second module signature using the first module temporary public key, and when the nineteenth and twentieth hash codes match, it is confirmed that the eSIM module signature is correct.

[0065] and when it is confirmed that the eSIM module signature is correct, a pair of temporary public and private key pairs are generated by performing a public and private key pair generation process, which are recorded as a corresponding first server temporary public key and a first server temporary private key;

[0066] and the second card issuing script data saved based on the script encryption and decryption key is encrypted to generate a corresponding first ciphertext;

[0067] and the script encryption and decryption key is signed using the first server temporary private key to generate a corresponding first key signature; and the script encryption and decryption key and the first key signature form a corresponding first key data; and the first key data is encrypted using the first module temporary public key to generate a corresponding second ciphertext;

[0068] and the first session identifier, the first ciphertext, the second ciphertext and the first server temporary public key are sent back to the mobile terminal.

[0069] Further, the eSIM module is further used for, when the first session identifier, the first cipher text, the second cipher text and the first server temporary public key sent by the mobile terminal are received through the Internet of Things device, using the first module temporary private key to decrypt the second cipher text to obtain a corresponding fifth plaintext; and extracting the script encryption and decryption key and a corresponding first key signature from the fifth plaintext;

[0070] and based on a preset hash algorithm, a corresponding second hash code is generated by performing hash calculation on the script encryption and decryption key, and a corresponding second hash code is obtained by performing signature verification calculation on the first key signature using the first server temporary public key, and when the second hash code and the second hash code match, it is confirmed that the key signature is correct;

[0071] and when it is confirmed that the key signature is correct, the first cipher text is decrypted using the script encryption and decryption key to generate a corresponding sixth plaintext; and the sixth plaintext is used as corresponding third card issuing script data;

[0072] and according to the third card issuing script data, card issuing data loading processing is performed; and when the card issuing data loading processing is successful, the corresponding loading state data is set to loading success; and the loading state data is sent to the mobile terminal through the Internet of Things device.

[0073] The embodiment of the application provides a data download system of an eSIM module, which comprises a mobile terminal, a network analyzer, an Internet of Things device, a first server and a second server, and the Internet of Things device is built-in with an eSIM module. The system uses a pre-installed eSIM module to replace a traditional SIM card slot on each Internet of Things device, solves the hot plug problem during card replacement, provides a mobile terminal for a worker to perform card replacement operation, and is simple to operate and does not need to perform entity card application / return operation; the system provides signal strength analysis and operator available resource analysis to the worker through the network analyzer and the first server during each card replacement, assists the worker to perform network optimization, and ensures that better communication effect can be achieved after card replacement; the system further provides an eSIM module data download mechanism based on an asymmetric key system through the second server, which realizes remote card writing and improves the security of card writing data. BRIEF DESCRIPTION OF DRAWINGS

[0074] Figure 1 A structural schematic diagram of the data download system of the eSIM module is provided for the embodiment of the application. DETAILED DESCRIPTION

[0075] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0076] Figure 1 This is a schematic diagram of the structure of a data download system for an eSIM module provided in an embodiment of the present invention, as shown below. Figure 1 As shown, the system of this embodiment includes: a mobile terminal 1, a network analyzer 2, an Internet of Things (IoT) device 3, a first server 4, and a second server 5. The IoT device 3 has a built-in eSIM module 31. The mobile terminal 1 is connected to the network analyzer 2, the IoT device 3, the first server 4, and the second server 5 respectively; the first server 4 and the second server 5 are also connected.

[0077] The mobile terminal 1 in this embodiment of the invention is a mobile phone, PC, tablet computer or mobile terminal. The mobile terminal 1 supports Bluetooth communication, WiFi communication, serial communication, wired network communication and USB communication, and also supports 2G / 3G / 4G / 5G / NB-IoT and other network communication methods.

[0078] The network analyzer 2 in this embodiment of the invention is an external device of the mobile terminal 1; the network analyzer 2 in this embodiment of the invention can scan the wireless signal strength of different network standards under different signal frequency ranges in different frequency bands; the network analyzer 2 supports Bluetooth communication, WiFi communication, serial communication, wired network communication and USB communication; the network analyzer 2 can be connected to the mobile terminal 1 through any of the following connection methods: Bluetooth, WiFi, serial port, network cable and USB data cable.

[0079] The Internet of Things device 3 of the embodiment of the application is any device, terminal, equipment, computer or server applied to an Internet of Things scene, for example, a smart meter device in a smart energy network, such as a smart electricity meter, a smart gas meter, a smart water meter, etc., for example, a vending machine in a vending system, for example, a front-end acquisition device for observing environmental and meteorological data in an environmental and meteorological monitoring system, etc.; each Internet of Things device 3 is pre-installed with an eSIM module 31; the Internet of Things device 3 supports Bluetooth communication mode, WiFi communication mode, serial port communication mode, wired network communication mode and USB communication mode, and also supports communication modes of 2G / 3G / 4G / 5G / NB-IOT mobile communication networks; the Internet of Things device 3 can be connected with the mobile terminal 1 through any one of Bluetooth, WiFi, serial port, network cable and USB data line, and can realize network registration on a corresponding 2G, 3G, 4G, 5G or NB-IOT mobile communication network based on card data in the eSIM module 31; each Internet of Things device 3 locally stores a unique device code, and because it can register in the mobile communication network, each device locally also stores a unique International Mobile Equipment Identity (IMEI).

[0080] The first server 4 and the second server 5 of the embodiment of the application are remote servers, systems or cloud platforms.

[0081] The mobile terminal 1 is used to provide a user operation interface with a data download button for a worker; when the worker clicks the data download button, the network analyzer 2 is called to perform network analysis processing to generate a corresponding first network analysis list; the Internet of Things device 3 is called to perform device identification and device IMEI data acquisition processing to generate corresponding first device identification and first IMEI data; the first server 4 is called to perform operator available resource analysis processing according to the first device identification and the first IMEI data to generate a corresponding first operator resource list; content integration processing is performed on the first network analysis list and the first operator resource list to generate a corresponding first integration list; when a local preset preferred network mode is an interactive confirmation mode, integration record sorting processing is performed on the first integration list in order of network signal strength from high to low to generate a corresponding first integration record sequence, which is displayed to the worker, and a first integration record selected by the worker in the first integration record sequence is taken as a corresponding preferred record; the first server 4 is called to perform telecommunication card resource allocation processing according to the preferred record to generate a corresponding first activation code; bidirectional authentication processing is performed on the second server 5 and the eSIM module 31 of the Internet of Things device 3; and when the bidirectional authentication processing is successful, the second server 5 is called to perform card data loading processing on the eSIM module 31 according to the first activation code.

[0082] In a specific implementation of the embodiment of the present application, the mobile terminal 1 is specifically configured to send a network analysis instruction to the network analyzer 2 when calling the network analyzer 2 to perform network analysis processing, and receive a first network analysis list returned by the network analyzer 2.

[0083] The first network analysis list includes a plurality of first network analysis records, and each first network analysis record includes a first operator network standard field and a first signal strength field. The first operator network standard field includes a first operator identifier and a first network standard, and the first network standard includes a 2G standard, a 3G standard, a 4G standard, a 5G standard, and an NB-IOT standard.

[0084] Here, the mobile terminal 1 of the embodiment of the present application activates the network analyzer 2 to perform network analysis processing by sending a network analysis instruction to the network analyzer 2. Each first network analysis record of the obtained first network analysis list corresponds to an operator network standard. For example, there are two first network analysis records in the first network analysis list, which are first network analysis record 1 and 2. The first network analysis record 1 is (the first operator network standard field is operator 1 + 2G standard, and the first signal strength field is strength 1), and the first network analysis record 2 is (the first operator network standard field is operator 2 + 4G standard, and the first signal strength field is strength 2). That is, the 2G network signal strength of operator 1 is strength 1, and the 4G network signal strength of operator 2 is strength 2.

[0085] The network analyzer 2 is configured to traverse each first network signal frequency band record of a preset network signal frequency band list when receiving the network analysis instruction sent by the mobile terminal 1, and when traversing, take the currently traversed first network signal frequency band record as a corresponding current frequency band record, and extract the fourth operator network standard field, the first signal frequency band field and the first signal frequency range field of the current frequency band record as the corresponding current operator network standard, the current signal frequency band and the current signal frequency range. The signal strength of the wireless signal with the signal frequency band being the current signal frequency band, the signal frequency satisfying the current signal frequency range, and the signal standard satisfying the current operator network standard is analyzed to generate a corresponding current signal strength. The obtained current operator network standard and current signal strength are taken as the corresponding first operator network standard field and first signal strength field to form the corresponding first network analysis record. When the traversal is completed, all the obtained first network analysis records are combined to form a corresponding first network analysis list to return to the data download terminal.

[0086] The network signal frequency band list includes a plurality of first network signal frequency band records; the first network signal frequency band record includes a fourth operator network standard field, a first signal frequency band field and a first signal frequency range field; the fourth operator network standard field includes a fourth operator identifier and a fourth network standard, and the fourth network standard includes a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard.

[0087] Here, the network analyzer 2 performs network analysis processing, that is, scans and analyzes the signal strength of each first network signal frequency band record corresponding to the operator network standard based on the network signal frequency band list to obtain the first network analysis list and send it back to the mobile terminal 1.

[0088] In another specific implementation manner of the embodiment of the application, the mobile terminal 1 is specifically configured to send a device basic data acquisition instruction to the Internet of Things device 3 when calling the Internet of Things device 3 to perform device identification and device IMEI data acquisition processing; and receive the first device identification and the first IMEI data sent back by the Internet of Things device 3.

[0089] The Internet of Things device 3 is configured to extract the locally stored unique device code and unique IMEI data as the corresponding first device identification and first IMEI data when receiving the device basic data acquisition instruction sent by the mobile terminal 1, and send them back to the mobile terminal 1.

[0090] In another specific implementation manner of the embodiment of the application, the mobile terminal 1 is specifically configured to send an available resource query instruction carrying the first device identification and the first IMEI data to the first server 4 when calling the first server 4 to perform operator available resource analysis processing according to the first device identification and the first IMEI data; and receive the first operator resource list sent back by the first server 4.

[0091] The first operator resource list includes a plurality of first operator resource records; the first operator resource record includes a second operator network standard field and a first available card number field; the second operator network standard field includes a second operator identifier and a second network standard, and the second network standard includes a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard.

[0092] Here, the embodiment of the application moves terminal 1 to activate the first server 4 to analyze the available resources by sending the available resource query instruction to the first server 4; the first operator resource list obtained by each first operator resource record corresponds to an operator network mode. For example, there are 2 first operator resource records in the first operator resource list, which are first operator resource records 1 and 2, the first operator resource record 1 is (the second operator network mode field is the operator 1+2G mode, and the first available card number field is 100), and the first network analysis record 2 is (the second operator network mode field is the operator 2+4G mode, and the first available card number field is 120), that is, the number of available telecom cards of the 2G network of operator 1 is 100, and the number of available telecom cards of the 4G network of operator 2 is 120.

[0093] The first server 4 is used to extract the first device identifier and the first IMEI data from the available resource query instruction sent by the mobile terminal 1 when receiving the available resource query instruction; and extract the first deployment area field of the first device deployment record in the preset device deployment list, which matches the first device identifier and the first IMEI data, as the corresponding first deployment area; and mark all first regional resource statistical records in the preset regional resource statistical list, which match the first deployment area, as matching statistical records; and extract the fifth operator network mode field and the third available card number field of each matching statistical record as the corresponding second operator network mode field and the first available card number field to form the corresponding first operator resource record; and form the corresponding first operator resource list by all the first operator resource records obtained to send back to the mobile terminal 1;

[0094] The device deployment list includes a plurality of first device deployment records; the first device deployment record includes a first device identifier field, a first IMEI field, and a first deployment area field;

[0095] The regional resource statistical list includes a plurality of first regional resource statistical records; the first regional resource statistical record includes a first regional field, a fifth operator network mode field, and a third available card number field; the fifth operator network mode field includes a fifth operator identifier and a fifth network mode, and the fifth network mode includes a 2G mode, a 3G mode, a 4G mode, a 5G mode, and an NB-IOT mode.

[0096] Here, the device deployment list of the embodiment of the application is used for recording the deployment region of each Internet of Things device 3; the first device identifier field and the first IMEI field are the unique device code and the unique IMEI data of the corresponding Internet of Things device; the first deployment region field is the deployment region data of the corresponding Internet of Things device, and the coding format of the deployment region data is a four-level region coding format such as country / province (state) / city / district (county), or a three-level region coding format such as country / province (state) / city, or a two-level region coding format such as country / province (state), or other types of region coding formats defined according to specific implementation requirements; the first server 4 can obtain the deployment region data of the current Internet of Things device, that is, the first deployment region, according to the first device identifier and the first IMEI data query device deployment list;

[0097] The region resource statistics list of the embodiment of the application is used for recording the real-time available telecommunication card number of each region under each operator network mode; each first region resource statistics record corresponds to one region of one operator network mode, the first region field and the fifth operator network mode field in the record are used for marking the corresponding region coding data and the corresponding operator network mode, and the third available card number field in the record is used for marking the corresponding available telecommunication card number; the first server 4 obtains the first operator resource list according to the first deployment region query region resource statistics list, and the first operator resource list records the available telecommunication card number of all operator network modes in the first deployment region.

[0098] In another specific implementation manner of the embodiment of the application, the mobile terminal 1 is specifically used for initializing the first integrated list as an empty list when performing content integration processing on the first network analysis list and the first operator resource list; and generating the corresponding first number N by counting the number of the first network analysis records of the first network analysis list; and adding N first integrated records with empty record contents to the first integrated list, the first integrated records correspond to the first network analysis records one by one; and setting the second available card number field of each first integrated record as 0; and setting the third operator network mode field and the second signal strength field of the corresponding first integrated record according to the first operator network mode field and the first signal strength field of each first network analysis record of the first network analysis list; and traversing the first operator resource records of the first operator resource list; and when traversing, taking the currently traversed first operator resource record as the corresponding current resource record, taking the second operator network mode field and the first available card number field of the current resource record as the corresponding current operator network mode and the current available card number, and setting the second available card number field of the first integrated record with the third operator network mode field matched with the first integrated list as the corresponding current available card number;

[0099] The first integrated list includes a plurality of first integrated records; the first integrated record includes a third operator network mode field, a second signal strength field and a second available card number field; the third operator network mode field includes a third operator identifier and a third network mode, and the third network mode includes a 2G mode, a 3G mode, a 4G mode, a 5G mode and an NB-IOT mode.

[0100] Here, the mobile terminal 1 of the embodiment of the application can obtain the signal strength and the number of available telecom cards of all the operator network modes in the region where the Internet of Things device 3 is located by performing content integration processing on the first network analysis list and the first operator resource list; each first integrated record of the obtained first integrated list corresponds to an operator network mode, the third operator network mode field in the record is the corresponding operator network mode, the second signal strength field is the corresponding signal strength, and the second available card number field is the corresponding number of available telecom cards.

[0101] For example, it is known that there are two first network analysis records in the first network analysis list, namely, first network analysis records 1 and 2, the first network analysis record 1 is (the first operator network mode field is operator 1+2G mode, and the first signal strength field is strength 1), and the first network analysis record 2 is (the first operator network mode field is operator 2+4G mode, and the first signal strength field is strength 2); there are two first operator resource records in the first operator resource list, namely, first operator resource records 1 and 2, the first operator resource record 1 is (the second operator network mode field is operator 1+2G mode, and the first available card number field is 100), and the first network analysis record 2 is (the second operator network mode field is operator 2+4G mode, and the first available card number field is 120);

[0102] Then, when the mobile terminal 1 performs content integration processing, it first initializes the first integrated list, and then counts the number of first network analysis records in the first network analysis list to obtain a first number N=2; then, N=2 first integrated records with empty record contents are added to the first integrated list, namely, first integrated records 1 and 2, wherein the first integrated record 1 corresponds to the first network analysis record 1, the first integrated record 2 corresponds to the first network analysis record 2, and the second available card number fields of the two first integrated records are both set to 0; at this time, the first integrated list is {first integrated record 1 (the third operator network mode field is empty, the second signal strength field is empty, and the second available card number field is 0), first integrated record 2 (the third operator network mode field is empty, the second signal strength field is empty, and the second available card number field is 0)};

[0103] Then, the mobile terminal 1 sets the third operator network mode field and the second signal strength field of the corresponding first integrated record 1, 2 according to the first operator network mode field and the first signal strength field of the first network analysis record 1, 2 of the first network analysis list, and the first integrated list obtained is {first integrated record 1 (the third operator network mode field is the operator 1+2G mode, the second signal strength field is strength 1, and the second available card number field is 0), first integrated record 2 (the third operator network mode field is the operator 2+4G mode, the second signal strength field is strength 2, and the second available card number field is 0)};

[0104] Then, the mobile terminal 1 traverses the 2 first operator resource records of the first operator resource list; in the traversal process:

[0105] When the current resource record is the first operator resource record 1, the current operator network mode is the operator 1+2G mode, the current available card number is 100, the first integrated record in the first integrated list whose third operator network mode field matches the current operator network mode (the operator 1+2G mode) is the first integrated record 1, and then the second available card number field of the first integrated record 1 is set to 100;

[0106] When the current resource record is the first operator resource record 2, the current operator network mode is the operator 2+4G mode, the current available card number is 120, the first integrated record in the first integrated list whose third operator network mode field matches the current operator network mode (the operator 2+4G mode) is the first integrated record 2, and then the second available card number field of the first integrated record 2 is set to 120;

[0107] At this time, the first integrated list obtained is {first integrated record 1 (the third operator network mode field is the operator 1+2G mode, the second signal strength field is strength 1, and the second available card number field is 100), first integrated record 2 (the third operator network mode field is the operator 2+4G mode, the second signal strength field is strength 2, and the second available card number field is 120)}.

[0108] After the mobile terminal 1 of the embodiment of the application obtains the first integrated list, the preferred record is selected from the first integrated list according to the locally preset preferred network mode; the preferred network mode includes an interactive confirmation mode and an automatic preferred confirmation mode.

[0109] In the preferred network mode is the interactive confirmation mode, means need to show the relevant information to the staff and the staff's choice results as the preferred record. In another specific implementation of the embodiment of the application, the mobile terminal 1 is specifically used for generating the corresponding first integrated record sequence in the order of sorting the integrated records in the first integrated list according to the network signal strength from high to low, displaying to the staff and taking the first integrated record selected by the staff in the first integrated record sequence as the corresponding preferred record; and extracting all the first integrated records with the second available card number field being 0 from the first integrated list to form the corresponding first integrated record set; and generating the corresponding first integrated record sequence in the order of sorting the first integrated records in the first integrated record set according to the second signal strength field from high to low; and displaying the first integrated record sequence to the staff; and taking the first integrated record corresponding to the staff's selection result in the first integrated record sequence as the corresponding preferred record; wherein the first integrated records in the first integrated record sequence are sorted in the order of the second signal strength field from high to low.

[0110] Here, the mobile terminal 1 can display the first integrated record sequence through various ways such as text, table or statistical chart when displaying the first integrated record sequence, so that the staff can clearly see the signal strength and the number of available telecom cards of all the operator network modes in the area where the internet of things device 3 is located, thereby helping the staff to quickly select the operator network mode with the best communication effect; after the staff completes the selection on the display interface provided by the mobile terminal 1, the mobile terminal 1 will take the first integrated record corresponding to the staff's selection result in the first integrated record sequence as the corresponding preferred record.

[0111] It should be noted that the mobile terminal 1 of the embodiment of the application also provides a preferred record automatic confirmation mode without human-computer interaction when the preferred network mode is the automatic preferred confirmation mode, and specifically, the mobile terminal 1 of the embodiment of the application extracts all the first integrated records with the second available card number field being 0 from the first integrated list to form a corresponding first integrated record set when the preferred network mode is the automatic preferred confirmation mode, and sorts the first integrated records of the first integrated record set in descending order of the second signal strength field to generate a corresponding first integrated record sequence, and extracts the first two first integrated records of the first integrated record sequence to form a corresponding first candidate record set, and filters the two first integrated records of the first candidate record set according to the second available card number field and the second signal strength field, and if the second available card number field and the second signal strength field of the two first integrated records are equal, selects one of the first integrated records as the corresponding preferred record, if the second available card number field of the two first integrated records is equal but the second signal strength field is not equal, selects the first integrated record with the larger second signal strength field as the corresponding preferred record, and if the second available card number field of the two first integrated records is not equal, selects the first integrated record with the larger second available card number field as the corresponding preferred record.

[0112] Here, the mobile terminal 1 of the embodiment of the application provides a preferred record automatic confirmation mode that first selects the first integrated records corresponding to the two strongest signal strength operator network modes to form a first candidate record set, and then filters the two candidate records according to the available card number and the signal strength: if the available card number and the signal strength are equal, selects one of the two as the preferred record; if the available card number is equal but the signal strength is not equal, selects the one with the stronger signal strength as the preferred record; and if the available card number is not equal, selects the one with the larger available card number as the preferred record. The preferred mode of the embodiment of the application can not only consider the network signal strength preference, but also balance the available cards under each operator network mode.

[0113] In one specific implementation of the embodiment of the application, the mobile terminal 1 is specifically used for extracting the third operator network mode field from the preferred record as the corresponding preferred operator network mode when calling the first server 4 to perform the telecommunication card resource allocation processing according to the preferred record; and sending a resource application instruction carrying the first device identifier, the first IMEI data and the preferred operator network mode to the first server 4; and receiving the first activation code sent back by the first server 4;

[0114] The first activation code includes the second server address and the first token.

[0115] Here, the mobile terminal 1 of the embodiment of the application can confirm the preferred operator network mode according to the preferred record after obtaining the preferred record. After obtaining the preferred operator network mode, the mobile terminal 1 should apply for the telecom card data corresponding to the preferred operator network mode from the remote server and download and install the eSIM module 31 of the Internet of Things device 3. The first step of this application-download installation is to send a resource application instruction to the first server 4 to obtain the activation code data, i.e., the first activation code, with the card data download address, i.e., the second server address, and the authorized download token, i.e., the first token.

[0116] The first server 4 is further configured to extract the first device identifier, the first IMEI data, and the preferred operator network mode from the resource application instruction sent by the mobile terminal 1 when receiving the resource application instruction; extract the first deployment area field of the first device deployment record in the preset device deployment list, which matches the first device identifier field and the first device identifier, and the first IMEI field and the first IMEI data, as the corresponding second deployment area; mark all the first card number resource records in the preset card number resource list as matching card number resource records, which match the second area field and the second deployment area, the sixth operator network mode field and the preferred operator network mode, and the first state field is in the unoccupied state; select one of the obtained multiple matching card number resource records as the corresponding preferred card number resource record; extract the first ICCID field and the first card issuing script field of the preferred card number resource record as the corresponding first ICCID data and first card issuing script data, and change the first state field of the preferred card number resource record to the occupied state; send the activation code application instruction carrying the first device identifier, the first IMEI data, the first ICCID data, and the first card issuing script data to the second server 5; and send the first activation code returned by the second server 5 to the mobile terminal 1;

[0117] The device deployment list includes a plurality of first device deployment records as described above; the first device deployment record includes a first device identifier field, a first IMEI field, and a first deployment area field;

[0118] The card number resource list includes a plurality of first card number resource records; the first card number resource record includes a first ICCID field, a second area field, a sixth operator network mode field, a first card issuing script field, and a first state field; the sixth operator network mode field includes a sixth operator identifier and a sixth network mode, and the sixth network mode includes a 2G mode, a 3G mode, a 4G mode, a 5G mode, and an NB-IOT mode; the first card issuing script field is used to store card issuing script data; and the first state field includes an occupied state and an unoccupied state.

[0119] The first server 4 of the embodiment of the present application, in addition to the aforementioned management of the device deployment information of all the Internet of Things devices 3 based on the device deployment list, also manages all the telecom card data under all the operator network modes based on the preset card number resource list. Each first card number resource record in the card number resource list corresponds to a telecom card and its related data; the first ICCID field is the unique integrated circuit card identity (ICCID) of the corresponding telecom card; the second region field is the region information of the regional telecom operator to which the corresponding telecom card belongs, and its coding format is consistent with the region coding format of the first deployment region field of the first device deployment record in the device deployment list; the sixth operator network mode field is the operator network mode of the corresponding telecom card; the first card issuing script field is the card issuing script data of the corresponding telecom card, and its data format is the data format of the card issuing script recognizable by the eSIM module 31, which can be run by the eSIM module 31 after being downloaded to the eSIM module 31; the first state field includes at least two states: occupied state and unoccupied state, and if it is the occupied state, it means that the corresponding telecom card has been used and its card issuing script data cannot be downloaded, and if it is the unoccupied state, it means that the corresponding telecom card has not been used and its card issuing script data can be downloaded. When the first server 4 of the embodiment of the present application receives the resource application instruction sent by the mobile terminal 1, it first queries the device deployment list according to the first device identifier and the first IMEI data to obtain the deployment region data of the corresponding Internet of Things device, i.e., the second deployment region; then, based on the second deployment region and the preferred operator network mode, it queries the preset card number resource list to obtain a plurality of unoccupied matching card number resource records; then, it randomly selects one from the plurality of matching card number resource records as the card number resource allocated at this time, i.e., the preferred card number resource record; after obtaining the preferred card number resource record, the first server 4 of the embodiment of the present application needs to switch the first state field of the record to the occupied state on the one hand, and extract the first ICCID data and the first card issuing script data from the record and combine them with the first device identifier and the first IMEI data to form an activation code application instruction to the second server 5 so as to obtain the corresponding first activation code and send it back to the mobile terminal 1.

[0120] The second server 5 is configured to extract the first device identifier, the first IMEI data, the first ICCID data and the first card issuing script data from the activation code application instruction sent by the first server 4 when receiving the activation code application instruction, add a first device card number binding record in a preset device card number binding list, set the second device identifier field, the second IMEI field, the second ICCID field and the second card issuing script field of the added record to the corresponding first device identifier, the first IMEI data, the first ICCID data and the first card issuing script data, generate a token data as the corresponding first token for the added record, set the first token field of the added record to the first token, and send the corresponding first activation code composed of the preset second server address and the first token to the first server 4.

[0121] The device card number binding list includes a plurality of first device card number binding records, and each first device card number binding record includes a second device identifier field, a second IMEI field, a second ICCID field, a second card issuing script field and a first token field.

[0122] Here, the second server 5 of the embodiment of the present application manages the telecom card binding relationship of all the Internet of Things devices 3 based on the preset device card number binding list. Each first device card number binding record of the device card number binding list corresponds to one Internet of Things device 3; the second device identifier field and the second IMEI field are the unique device code and the unique IMEI data of the corresponding Internet of Things device; the second ICCID field and the second card issuing script field are the ICCID data and the card issuing script data of the telecom card bound with the corresponding Internet of Things device; and the first token field is the authorization download token allocated to the corresponding Internet of Things device for starting the card issuing data download. When the second server 5 receives the activation code application instruction sent by the first server 4, it first adds a first device card number binding record in the device card number binding list, and sets the second device identifier field, the second IMEI field, the second ICCID field and the second card issuing script field of the added first device card number binding record based on the first device identifier, the first IMEI data, the first ICCID data and the first card issuing script data; then generates a token data as the corresponding first token based on a conventional token allocation mechanism and saves it into the first token field; and finally sends the first activation code composed of the second server address, which is the URL address for processing the download application and is set in the second server 5 in advance, and the first token back to the first server 4. The conventional token allocation mechanism mentioned here has multiple implementation manners, one of which is to generate a plaintext composed of the first device identifier + the first IMEI data + the first ICCID data + the server real-time timestamp, and to obtain the corresponding first token by performing hash calculation on the plaintext; another of which is to generate a plaintext composed of the first device identifier + the first IMEI data + the first ICCID data + the first card issuing script data + the server real-time timestamp, and to obtain the corresponding first token by performing hash calculation on the plaintext, and there are multiple other implementation manners, which are not specifically limited by the embodiment of the present application.

[0123] The second server 5 sends the first activation code back to the first server 4, and the first server 4 sends the first activation code back to the mobile terminal 1. After the mobile terminal 1 of the embodiment of the present application obtains the first activation code, it will perform the subsequent download and installation processing step of the application-download and installation process of the telecom card data. The download and installation processing step of the telecom card data in the embodiment of the present application consists of two processing procedures: the two-way authentication processing procedure between the second server 5 and the eSIM module 31 mediated by the mobile terminal 1, and the card data loading processing procedure from the second server 5 to the eSIM module 31 mediated by the mobile terminal 1 after the two-way authentication processing succeeds, and both of the two processing procedures are protected by an asymmetric key system provided by the embodiment of the present application. Before the two-way authentication processing procedure and the card data loading processing procedure are described, the various keys pre-stored in the eSIM module 31 and the second server 5 by the asymmetric key system provided by the embodiment of the present application are described first.

[0124] The eSIM module 31 is pre-stored with multiple sets of first module public-private key pairs, a first manufacturer public key certificate and a first issuing center public key certificate; each first module public-private key pair corresponds to a first module identifier; the first module public-private key pair includes a first module public key certificate and a first module private key; the first module public key certificate includes a first module public key, first module key information and a first module certificate signature; the first manufacturer public key certificate includes a first manufacturer public key, first manufacturer public key information and a first manufacturer certificate signature; and the first issuing center public key certificate includes an issuing center public key, issuing center public key information and an issuing center certificate signature.

[0125] Here, the keys on the eSIM module 31 side of the embodiments of the present application are all asymmetric keys, and the corresponding algorithms are asymmetric key algorithms. The asymmetric key algorithms of the asymmetric keys on the eSIM module 31 of the embodiments of the present application include internationally common asymmetric key algorithms (such as RSA algorithms, ECC algorithms, etc.) and the SM2 algorithm of the national asymmetric key algorithm system. Each group of first module public-private key pairs, first module public-private key pairs, first manufacturer public key certificates, and first issuing center public key certificates are called by a two-way authentication process. All module public keys of the embodiments of the present application are encapsulated in a corresponding module public key certificate, and each module public key certificate includes a corresponding module public key, module key information (such as common certificate key information such as an issuing authority and an issuing time), and a module certificate signature. The first manufacturer public key certificate is the public key certificate of the module manufacturer of the eSIM module 31, which, like the module public key certificate, also encapsulates the corresponding manufacturer public key, manufacturer public key information, and manufacturer certificate signature. The first issuing center public key certificate is the public key certificate of the third-party trusted certificate issuing authority, which, like the module public key certificate, also encapsulates the corresponding issuing center public key, issuing center public key information, and issuing center certificate signature. It should be noted that the certificate signatures of all public key certificates on the eSIM module 31 of the embodiments of the present application, except for the first issuing center public key certificate, can be verified by the issuing center public key of the first issuing center public key certificate.

[0126] The second server 5 is locally preset with a first server public-private key pair, a second server public-private key pair, a first issuing center public key certificate, and a script encryption and decryption key; the first server public-private key pair includes a first server public key certificate and a first server private key; the first server public key certificate includes a first server public key, first server key information, and a first server certificate signature; the second server public-private key pair includes a second server public key certificate and a second server private key; the second server public key certificate includes a second server public key, second server key information, and a second server certificate signature; and the first issuing center public key certificate includes an issuing center public key, issuing center public key information, and an issuing center certificate signature.

[0127] Here, the second server 5 side key of the embodiment of the application includes an asymmetric key and a symmetric key. The asymmetric key corresponds to an asymmetric key algorithm, and the asymmetric key algorithm of the asymmetric key on the second server 5 of the embodiment of the application includes a plurality of internationally common asymmetric key algorithms (such as RSA algorithm, ECC algorithm, etc.) and SM2 algorithm of the national asymmetric key algorithm system. The symmetric key corresponds to a symmetric key algorithm, and the symmetric key algorithm of the symmetric key on the second server 5 of the embodiment of the application includes a plurality of internationally common symmetric key algorithms (such as DES algorithm, 3DES algorithm, AES algorithm, etc.) and SM1 algorithm, SM4 algorithm, SM7 algorithm and ZUC algorithm of the national symmetric key algorithm system. The first server public-private key pair, the second server public-private key pair and the first issuing center public key certificate on the second server 5 side of the embodiment of the application are all asymmetric keys, and the script encryption and decryption key is a symmetric key.

[0128] The first server public-private key pair and the first issuing center public key certificate on the second server 5 side of the embodiment of the application are called by the two-way authentication process, and the second server public-private key pair, the first issuing center public key certificate and the script encryption and decryption key are called by the card data loading process. The script encryption and decryption key on the second server 5 side of the embodiment of the application is a symmetric key, and the script encryption and decryption key is used to encrypt the plaintext of the card issuing script data. All server public keys on the second server 5 side of the embodiment of the application are packaged in a corresponding server public key certificate, and each server public key certificate includes a corresponding server public key, server key information (such as common certificate key information such as issuing authority and issuing time) and server certificate signature. The first issuing center public key certificate is the public key certificate of the third party trusted certificate issuing authority, which is similar to the server public key certificate and also encapsulates the corresponding issuing center public key, issuing center public key information and issuing center certificate signature. It should be noted that the certificate signature of all public key certificates on the second server 5 side of the embodiment of the application except the first issuing center public key certificate can be verified by the issuing center public key of the first issuing center public key certificate, and the first issuing center public key certificate on the eSIM module 31 and the second server 5 of the embodiment of the application are consistent, which are the public key certificates of the same third party trusted certificate issuing authority.

[0129] Through the above, the various keys preloaded on the eSIM module 31 and the second server 5 of the embodiment of the application can be understood, and the two-way authentication process between the second server 5 and the eSIM module 31 mediated by the mobile terminal 1 based on the above various keys will be described below.

[0130] In another specific implementation manner of the application, the mobile terminal 1 is specifically used for, when performing the two-way authentication process on the eSIM module 31 of the second server 5 and the Internet of Things device 3,

[0131] Step A1, extracting the second server address from the first activation code;

[0132] Here, the mobile terminal 1 of the embodiment of the application extracts the second server address from the first activation code when performing the bidirectional authentication processing;

[0133] Step A2, sending a module information acquisition instruction to the eSIM module 31 through the Internet of Things device 3, and receiving the first module data returned by the eSIM module 31 through the Internet of Things device 3;

[0134] The first module data includes first version data and a first public key identification sequence, and the first public key identification sequence includes a plurality of first public key identifications.

[0135] Here, the mobile terminal 1 of the embodiment of the application obtains the corresponding module basic data, i.e., the first module data, by sending the module information acquisition instruction to the eSIM module 31; the first version data in the first module data is module version information used to identify the software and hardware system version of the eSIM module 31; and each first public key identification of the first public key identification sequence is a first module identification of a first module public and private key pair available for authentication on the eSIM module 31.

[0136] Here, the corresponding processing flow on the eSIM module 31 side of the embodiment of the application is as follows:

[0137] When the eSIM module 31 receives the module information acquisition instruction sent by the mobile terminal 1 through the Internet of Things device 3, it takes the locally stored module version information as the corresponding first version data; takes the first module identifications of each first module public and private key pair pre-stored locally as the corresponding first public key identifications, and forms a corresponding first public key identification sequence from all the obtained first public key identifications; forms the corresponding first module data from the first version data and the first public key identification sequence; and returns the first module data to the mobile terminal 1 through the Internet of Things device 3.

[0138] Step A3, sending a module random number acquisition instruction to the eSIM module 31 through the Internet of Things device 3, and receiving the first module random number returned by the eSIM module 31 through the Internet of Things device 3;

[0139] Here, the mobile terminal 1 of the embodiment of the application obtains the corresponding module random number, i.e., the first module random number, by sending the module random number acquisition instruction to the eSIM module 31;

[0140] Here, the corresponding processing flow on the eSIM module 31 side of the embodiment of the application is as follows:

[0141] The eSIM module 31 is further configured to, when receiving the module random number acquisition instruction sent by the mobile terminal 1 through the IoT device 3, call a local random number generator to generate a random number as a corresponding first module random number and save the first module random number; and send the first module random number, the first module data and the second server address to the second server 5 through the IoT device 3, and receive the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate sent back by the second server 5.

[0142] The step A4, and the first module random number, the first module data and the second server address are sent to the second server 5; and the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate sent back by the second server address are received;

[0143] The first server plaintext includes the first session identifier, the second module random number, the first server random number and the third server address; here, the first session identifier is a unique session identifier for the second server 5 for this two-way authentication processing and subsequent card data loading processing, respectively, and the first session identifier should not change during the entire two-way authentication processing and card data loading processing;

[0144] Here, the mobile terminal 1 of the embodiment of the application starts the server verification data preparation process on the second server 5 side by sending the first module random number, the first module data and the second server address to the second server 5;

[0145] Here, the corresponding processing flow on the second server 5 side of the embodiment of the application is as follows:

[0146] The second server 5 is further configured to, when receiving the first module random number, the first module data and the second server address sent by the mobile terminal 1, identify whether the second server address matches the server address; if yes, save the first version data of the first module data; select a first public key identifier as a corresponding second module public key identifier from the first public key identifier sequence of the first module data; generate a unique session identifier code as a corresponding first session identifier according to a preset session identifier coding rule; take the first module random number as a corresponding second module random number; call a local random number generation interface to generate a random number as a corresponding first server random number and save the first server random number; take the second server address as a corresponding third server address; compose a corresponding first server plaintext from the first session identifier, the second module random number, the first server random number and the third server address; perform a hash calculation on the first server plaintext based on a preset hash algorithm to generate a corresponding first hash code; use the first server private key of the first server public-private key pair to perform a signature calculation on the first hash code to generate a corresponding first server signature; and send the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate back to the mobile terminal 1;

[0147] Here, the second server 5 side of the embodiment of the application includes international commonly used multiple hash algorithms (such as SHA family series algorithms, MD family series algorithms, etc.) and SM3 algorithm of the national cryptographic hash algorithm system in the preset hash algorithm in the bidirectional authentication process;

[0148] Step A5, and comparing the third server address with the second server address; if they are the same, sending the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate to the eSIM module 31 through the Internet of Things device 3; and receiving the first session identifier, the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate sent back by the eSIM module 31 through the Internet of Things device 3;

[0149] The first module plaintext includes the first session identifier, the second server random number and the second module data, the second module data includes the second version data and the second public key identifier sequence, and the second public key identifier sequence includes multiple second public key identifiers.

[0150] Here, after the mobile terminal 1 receives the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate sent back by the second server address, the mobile terminal 1 first compares the server address in the first server plaintext with the server address of the activation code, and if they match, the server verification data (the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate) sent by the server is forwarded to the eSIM module 31 to start the verification process of the second server 5 on the eSIM module 31 side and the module verification data preparation process on the module side.

[0151] Here, the corresponding processing flow of the eSIM module 31 side of the embodiment of the application is as follows:

[0152] The eSIM module 31 is further configured to, when receiving the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate sent by the mobile terminal 1 through the Internet of Things device 3, extract the first server public key and the first server key information from the first server public key certificate to form a corresponding first plaintext, perform hash calculation on the first plaintext based on the preset hash algorithm to generate a corresponding second hash code, use the signing center public key of the first signing center public key certificate pre-stored locally to perform signature verification calculation on the first server certificate signature of the first server public key certificate to obtain a corresponding third hash code, and confirm that the server public key certificate is a valid certificate when the second and third hash codes match.

[0153] and when it is confirmed that the server public key certificate is a valid certificate, a fourth hash code corresponding to the first server plaintext is generated by performing hash calculation based on a preset hash algorithm, and a fifth hash code corresponding to the first server signature is obtained by performing signature verification calculation using the first server public key of the first server public key certificate, and when the fourth and fifth hash codes match, it is confirmed that the server signature is correct;

[0154] and when it is confirmed that the server signature is correct, the second module random number is extracted from the first server plaintext and compared with the first module random number stored locally; if the two match, the module version information stored locally is taken as the corresponding second version data; and the first module identifier of each first module public-private key pair pre-stored locally is taken as the corresponding second public key identifier, and all the second public key identifiers obtained are taken as the corresponding second public key identifier sequence; and the second version data and the second public key identifier sequence are taken as the corresponding second module data; the first server random number of the first server plaintext is taken as the corresponding second server random number; and the first session identifier, the second server random number and the second module data of the first server plaintext are taken as the corresponding first module plaintext;

[0155] and the first module identifier of the first module public-private key pair pre-stored locally and matched with the second module public key identifier is taken as the corresponding current module public-private key pair; the first module private key of the current module public-private key pair is taken as the corresponding current module private key; the first module plaintext is taken as the corresponding sixth hash code by performing hash calculation based on a preset hash algorithm; the sixth hash code is taken as the corresponding first module signature by performing signature calculation using the current module private key; the first module public key certificate of the current module public-private key pair is extracted as the corresponding second module public key certificate; and the first session identifier, the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate are sent back to the mobile terminal 1 through the Internet of Things device 3;

[0156] Here, the eSIM module 31 of the embodiment of the application first confirms the validity of the first server public key certificate after receiving the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate sent by the mobile terminal 1 through the Internet of Things device 3, confirms the first server signature after confirming the validity of the first server public key certificate, compares the module random number in the first server plaintext with the locally saved module random number after the signature verification is successful, and confirms that the server verification is passed on the eSIM module 31 side after the comparison matches. At this time, the eSIM module 31 will prepare a plurality of data used for subsequent server verification to obtain the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate and send them back to the mobile terminal 1. It should be noted that the preset hash algorithm of the eSIM module 31 side of the embodiment of the application in the two-way authentication process includes a plurality of internationally common hash algorithms (such as SHA family series algorithms, MD family series algorithms, etc.) and the SM3 algorithm of the national secret hash algorithm system. The hash algorithm used by the eSIM module 31 of the embodiment of the application when confirming the validity of the first server public key certificate should be consistent with the hash algorithm used by the third-party trusted certificate issuing agency corresponding to the first issuing center public key certificate when processing the certificate signature. The hash algorithm used by the eSIM module 31 of the embodiment of the application when verifying the first server signature should be consistent with the hash algorithm used when the first server signature is generated on the second server 5.

[0157] Step A6, and send the first session identifier, the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate to the second server 5; receive the verification return data sent back by the second server 5; and confirm that the two-way authentication processing is successful when the verification return data is verification success.

[0158] Here, the mobile terminal 1 of the embodiment of the application forwards the module verification data (the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate) sent back by the eSIM module 31 to the second server 5 after receiving it to start the verification process of the eSIM module 31 on the second server 5 side. If the return data sent back by the second server 5 is verification success, it means that the two-way authentication processing is successful.

[0159] Here, the corresponding processing flow of the second server 5 side of the embodiment of the application is as follows:

[0160] The second server 5 is further configured to, upon receiving the first session identification, the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate sent by the mobile terminal 1, extract the second server random number from the first module plaintext and compare the second server random number with the saved first server random number; if the first and second server random numbers match, extract the second version data from the second module data of the first module plaintext and compare the second version data with the saved first version data;

[0161] If the first and second version data match, extract the first module public key and the first module key information from the second module public key certificate to form a corresponding second plaintext, perform hash calculation on the second plaintext based on a preset hash algorithm to generate a corresponding seventh hash code, perform signature verification calculation on the first module certificate signature of the second module public key certificate using the signing center public key of the locally preset first signing center public key certificate to obtain a corresponding eighth hash code, and confirm that the eSIM module public key certificate is a valid certificate when the seventh and eighth hash codes match;

[0162] If the first and second version data match, extract the first module public key and the first module key information from the second module public key certificate to form a corresponding second plaintext, perform hash calculation on the second plaintext based on a preset hash algorithm to generate a corresponding seventh hash code, perform signature verification calculation on the first module certificate signature of the second module public key certificate using the signing center public key of the locally preset first signing center public key certificate to obtain a corresponding eighth hash code, and confirm that the eSIM module public key certificate is a valid certificate when the seventh and eighth hash codes match;

[0163] If the first and second version data match, extract the first module public key and the first module key information from the second module public key certificate to form a corresponding second plaintext, perform hash calculation on the second plaintext based on a preset hash algorithm to generate a corresponding seventh hash code, perform signature verification calculation on the first module certificate signature of the second module public key certificate using the signing center public key of the locally preset first signing center public key certificate to obtain a corresponding eighth hash code, and confirm that the eSIM module public key certificate is a valid certificate when the seventh and eighth hash codes match;

[0164] If the first and second version data match, extract the first module public key and the first module key information from the second module public key certificate to form a corresponding second plaintext, perform hash calculation on the second plaintext based on a preset hash algorithm to generate a corresponding seventh hash code, perform signature verification calculation on the first module certificate signature of the second module public key certificate using the signing center public key of the locally preset first signing center public key certificate to obtain a corresponding eighth hash code, and confirm that the eSIM module public key certificate is a valid certificate when the seventh and eighth hash codes match;

[0165] Here, the second server 5 of the embodiment of the application first compares the server random number in the first module plaintext with the locally saved server random number after receiving the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate sent by the mobile terminal 1, and then compares the version data in the first module plaintext with the locally saved version data if the comparison matches, and then confirms the validity of the second module public key certificate, and then confirms the validity of the first manufacturer public key certificate after confirming the validity, and then verifies the first module signature, and then confirms the verification of the eSIM module on the second server 5 side to be passed after the verification is successful, at this time, the second server 5 returns the verification return data to the mobile terminal 1, which is the verification success to indicate that the two-way authentication processing is successful; it should be noted that the hash algorithm used by the second server 5 of the embodiment of the application when confirming the validity of the second module public key certificate and the first manufacturer public key certificate should be consistent with the hash algorithm used by the third-party trusted certificate issuing agency corresponding to the first issuing center public key certificate when processing the certificate signature, and the hash algorithm used by the second server 5 of the embodiment of the application when verifying the first module signature should be consistent with the hash algorithm used when the first module signature is generated on the eSIM module 31.

[0166] From the above, the two-way authentication processing process of the second server 5 and the eSIM module 31 mediated by the mobile terminal 1 can be understood, and the card data loading processing process from the second server 5 to the eSIM module 31 mediated by the mobile terminal 1 after the two-way authentication processing succeeds will be described below.

[0167] In another specific implementation manner of the embodiment of the application, the mobile terminal 1 is specifically used for calling the second server 5 to perform card data loading processing on the eSIM module 31 according to the first activation code,

[0168] Step B1, sending the first session identifier and the first activation code to the second server 5; and receiving the first session identifier, the second server signature and the second server public key certificate returned by the second server 5;

[0169] Here, the embodiment of the application will send the first session identifier and the first activation code to the second server 5 to start the preparation processing flow of the card data download on the second server 5 side after the two-way authentication processing succeeds;

[0170] Here, the corresponding processing flow on the second server 5 side of the embodiment of the application is as follows:

[0171] The second server 5 is further configured to, upon receiving the first session identifier and the first activation code sent by the mobile terminal 1, check the second server address of the first activation code; if the check is passed, extract the second card issuing script data corresponding to the first token field in the first device card number binding record in the preset device card number binding list that matches the first token of the first activation code, and store the second card issuing script data in the local as the corresponding second card issuing script; based on a preset hash algorithm, generate a thirteenth hash code corresponding to the first session identifier by performing hash calculation on the first session identifier; use the second server private key of the second server public-private key pair to perform signature calculation on the thirteenth hash code to generate a second server signature corresponding to the thirteenth hash code; and send the first session identifier, the second server signature and the second server public key certificate of the second server public-private key pair to the mobile terminal 1.

[0172] The device card number binding list includes a plurality of first device card number binding records, and each first device card number binding record includes a second device identifier field, a second IMEI field, a second ICCID field, a second card issuing script field and a first token field.

[0173] Here, the second server 5 of the embodiment of the present application checks the second server address of the first activation code after receiving the first activation code sent by the mobile terminal 1, that is, compares the URL address for processing the download application pre-set in the local of the second server 5 with the second server address of the first activation code, and if the comparison is matched, the check is passed, otherwise the check fails; when the check is passed, the second server 5 queries the device card number binding list according to the first token of the first activation code to obtain the matched first device card number binding record, and extracts the corresponding card issuing script plaintext, i.e., the second card issuing script data, as the prepared to-be-downloaded data; after saving the second card issuing script data, the second server 5 signs the first session identifier using the second server public-private key pair, and sends the second server signature and the second server public key certificate to the mobile terminal 1; it should be noted that the preset hash algorithms on the second server 5 side in the card data loading process of the embodiment of the present application include a plurality of international hash algorithms (such as SHA family series algorithms, MD family series algorithms, etc.) and the SM3 algorithm of the national encryption hash algorithm system.

[0174] Step B2, sending the first session identifier, the second server signature and the second server public key certificate to the eSIM module 31 through the Internet of Things device 3; and receiving the first session identifier, the second module signature and the first module temporary public key sent by the eSIM module 31 through the Internet of Things device 3.

[0175] Here, the embodiment of the application is that the mobile terminal 1 directly forwards the second server signature and the second server public key certificate to the eSIM module 31 after receiving them to start the temporary public-private key pair generation process on the eSIM module 31 side for this card data download;

[0176] Here, the corresponding process flow of the eSIM module 31 side of the embodiment of the application is as follows:

[0177] The eSIM module 31 is also used to extract the second server public key and the second server key information from the second server public key certificate to form a corresponding fourth plaintext when receiving the first session identifier, the second server signature, and the second server public key certificate sent by the mobile terminal 1 through the Internet of Things device 3, perform hash calculation on the fourth plaintext based on a preset hash algorithm to generate a corresponding fourteenth hash code, use the pre-installed first issuing center public key certificate of the issuing center public key to perform signature verification calculation on the second server certificate signature of the second server public key certificate to obtain a corresponding fifteenth hash code, and confirm that the server public key certificate is a valid certificate when the fourteenth and fifteenth hash codes match;

[0178] And when it is confirmed that the server public key certificate is a valid certificate, perform hash calculation on the first session identifier based on a preset hash algorithm to generate a corresponding sixteenth hash code, use the second server public key of the second server public key certificate to perform signature verification calculation on the second server signature to obtain a corresponding seventeenth hash code, and confirm that the server signature is correct when the sixteenth and seventeenth hash codes match;

[0179] And when it is confirmed that the server signature is correct, perform a public-private key pair generation process to obtain a pair of temporary public-private key pairs, which are corresponding first module temporary public key and first module temporary private key; perform hash calculation on the first session identifier based on a preset hash algorithm to generate a corresponding eighteenth hash code; and use the first module temporary private key to perform signature calculation on the eighteenth hash code to generate a corresponding second module signature;

[0180] And send the first session identifier, the second module signature, and the first module temporary public key back to the mobile terminal 1 through the Internet of Things device 3;

[0181] Here, the eSIM module 31 of the embodiment of the application first confirms the validity of the second server public key certificate after receiving the second server signature and the second server public key certificate sent by the mobile terminal 1 through the Internet of Things device 3, confirms the validity of the second server signature after confirming the validity of the second server public key certificate, generates a pair of temporary public and private keys (a first module temporary public key and a first module temporary private key) for this card data loading, signs the first session identifier using the first module temporary private key to generate a corresponding second module signature, and sends the second module signature and the first module temporary public key back to the mobile terminal 1; It should be noted that the preset hash algorithm of the eSIM module 31 side of the embodiment of the application in the card data loading process includes international commonly used hash algorithms (such as SHA family series algorithms, MD family series algorithms, etc.) and SM3 algorithm of the national secret hash algorithm system; The hash algorithm used by the eSIM module 31 of the embodiment of the application when confirming the validity of the second server public key certificate should be consistent with the hash algorithm used by the third-party trusted certificate issuing agency corresponding to the first issuing center public key certificate when processing the certificate signature, and the hash algorithm used by the eSIM module 31 of the embodiment of the application when verifying the second server signature should be consistent with the hash algorithm used by the second server 5 when generating the second server signature;

[0182] Step B3, and send the first session identifier, the second module signature, and the first module temporary public key to the second server 5; and receive the first session identifier, the first ciphertext, the second ciphertext, and the first server temporary public key sent back by the second server 5;

[0183] Here, after receiving the second module signature and the first module temporary public key, the mobile terminal 1 directly forwards it to the second server 5 to start the card issuing script data encryption processing, temporary public and private key pair generation processing, signature and encryption processing of the script encryption and decryption key for this card data download on the second server 5 side;

[0184] Here, the corresponding processing flow of the second server 5 side of the embodiment of the application is as follows:

[0185] The second server 5 is also used for, when receiving the first session identifier, the second module signature, and the first module temporary public key sent by the mobile terminal 1, generating a corresponding nineteenth hash code by performing hash calculation on the first session identifier based on the preset hash algorithm, verifying the second module signature using the first module temporary public key to obtain a corresponding twentieth hash code, and confirming that the eSIM module signature is correct when the nineteenth and twentieth hash codes match;

[0186] And when confirming that the eSIM module signature is correct, performing a public and private key pair generation processing to obtain a pair of temporary public and private keys, denoted as a corresponding first server temporary public key and a first server temporary private key.

[0187] and the second server 5 uses the first server temporary private key to sign the script encryption and decryption key to generate a corresponding first key signature; and the first key data is composed of the script encryption and decryption key and the first key signature; and the first key data is encrypted using the first module temporary public key to generate a corresponding second ciphertext;

[0188] and sends the first session identifier, the first ciphertext, the second ciphertext and the first server temporary public key back to the mobile terminal 1;

[0189] Here, the second server 5 of the embodiment of the application first verifies the second module signature after receiving the second module signature and the first module temporary public key sent by the mobile terminal 1; a pair of temporary public and private keys (the first server temporary public key and the first server temporary private key) is generated for this card data loading after the verification is successful; the card script plaintext, i.e., the second card script data, is encrypted using the script encryption and decryption key pre-stored on the second server 5 side to obtain the corresponding card script ciphertext, i.e., the first ciphertext; the first key signature is obtained by signing the script encryption and decryption key using the first server temporary private key, and the second ciphertext is obtained by encrypting the first key data (the script encryption and decryption key + the first key signature) using the first module temporary public key; the first ciphertext, the second ciphertext and the first server temporary public key are sent back to the mobile terminal 1; It should be noted that the hash algorithm used by the second server 5 of the embodiment of the application when verifying the second module signature should be consistent with the hash algorithm used when generating the second module signature on the eSIM module 31;

[0190] Step B4, and the first session identifier, the first ciphertext, the second ciphertext and the first server temporary public key are sent to the eSIM module 31 through the Internet of Things device 3; and the loading state data sent back by the eSIM module 31 through the Internet of Things device 3 is received; and the card data loading process is confirmed to be successful when the loading state data is loading success.

[0191] Here, the embodiment of the application will directly forward the encrypted ciphertext of the card script data, i.e., the first ciphertext, the encrypted ciphertext of (the script encryption and decryption key + the first key signature), i.e., the second ciphertext, and the temporary public key of the server, i.e., the first server temporary public key, to the eSIM module 31 after receiving them, so as to start the key analysis, script decryption and script running process on the eSIM module 31 side;

[0192] Here, the corresponding processing flow on the eSIM module 31 side of the embodiment of the application is as follows:

[0193] The eSIM module 31 is further configured to, when the first session identifier, the first ciphertext, the second ciphertext and the first server temporary public key sent by the mobile terminal 1 are received by the Internet of Things device 3, decrypt the second ciphertext using the first module temporary private key to obtain a corresponding fifth plaintext; and extract the script encryption and decryption key and the corresponding first key signature from the fifth plaintext;

[0194] and generate a corresponding second hash code by performing hash calculation on the script encryption and decryption key based on a preset hash algorithm, and obtain a corresponding second hash code by performing signature verification calculation on the first key signature using the first server temporary public key, and confirm that the key signature is correct when the first hash code and the second hash code match;

[0195] and, when it is confirmed that the key signature is correct, decrypt the first ciphertext using the script encryption and decryption key to generate a corresponding sixth plaintext; and use the sixth plaintext as corresponding third card issuance script data;

[0196] and perform card issuance data loading processing according to the third card issuance script data; and set corresponding loading state data to loading success when the card issuance data loading processing is successful; and send the loading state data to the mobile terminal 1 through the Internet of Things device 3.

[0197] Here, the eSIM module 31 of the embodiment of the application first decrypts the second ciphertext using the first module temporary private key to obtain (script encryption and decryption key + first key signature) after receiving the first ciphertext, the second ciphertext and the first server temporary public key sent by the mobile terminal 1, then performs signature verification on the first key signature based on the first server temporary public key, and then decrypts the first ciphertext based on the script encryption and decryption key to obtain card issuance script plaintext, i.e. third card issuance script data, after the signature verification is successful, at this time, the third card issuance script data is run to complete card issuance data loading, and the loading state data of loading success is sent to the mobile terminal 1 when the card issuance data loading processing is successful; It should be noted that the hash algorithm used by the eSIM module 31 of the embodiment of the application when performing signature verification on the first key signature should be consistent with the hash algorithm used when the first key signature is generated on the second server 5.

[0198] The embodiment of the present application provides a data download system of an eSIM module, the system comprises: a mobile terminal, a network analyzer, an Internet of Things device, a first server and a second server, and the Internet of Things device is internally provided with an eSIM module. The system uses a pre-installed eSIM module to replace a traditional SIM card slot on each Internet of Things device, and solves the hot plug problem when replacing a card; the system provides a mobile terminal for a staff to replace a card, and the operation is simple, and the staff does not need to perform entity card application / return operation; the system provides signal strength analysis and operator available resource analysis to the staff through the network analyzer and the first server each time when replacing a card, assists the staff to perform network optimization, and ensures that better communication effect can be achieved after replacing a card; and the system further provides an eSIM module data download mechanism based on an asymmetric key system through the second server, so that remote card writing is realized, and the security of card writing data is improved.

[0199] Those skilled in the art should further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both, and in order to clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been described in the above description in general terms. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0200] The steps of the method or algorithm described in combination with the embodiments disclosed herein can be implemented by hardware, a software module executed by a processor, or a combination of both. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0201] The above specific embodiments further specifically describe the purpose, technical solution and beneficial effects of the present application, and it should be understood that the above description is only a specific embodiment of the present application, and is not used to limit the protection scope of the present application, and any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the protection scope of the present application.

Claims

1. A data download system for an eSIM module, characterized by, The system comprises a mobile terminal, a network analyzer, an Internet of Things device, a first server and a second server, and the Internet of Things device is internally provided with an eSIM module; The mobile terminal is connected with the network analyzer, the Internet of Things device, the first server and the second server respectively; the mobile terminal is used to provide a user operation interface with a data download button for a staff; when the staff clicks the data download button, the network analyzer is called to perform network analysis processing to generate a corresponding first network analysis list; the Internet of Things device is called to perform device identification and device IMEI data acquisition processing to generate corresponding first device identification and first IMEI data; the first server is called to perform operator available resource analysis processing according to the first device identification and the first IMEI data to generate a corresponding first operator resource list; the first network analysis list and the first operator resource list are subjected to content integration processing to generate a corresponding first integration list; when a local preset preferred network mode is an interactive confirmation mode, the first integration list is subjected to integration record sorting processing in order of network signal strength from high to low to generate a corresponding first integration record sequence, which is displayed to the staff, and a first integration record selected by the staff in the first integration record sequence is taken as a corresponding preferred record; the first server is called to perform telecom card resource allocation processing according to the preferred record to generate a corresponding first activation code; the second server and the eSIM module of the Internet of Things device are subjected to bidirectional authentication processing; and when the bidirectional authentication processing is successful, the second server is called to perform card data loading processing on the eSIM module according to the first activation code.

2. The data download system of the eSIM module according to claim 1, wherein the first network analysis list comprises a plurality of first network analysis records; the first network analysis record comprises a first operator network standard field and a first signal strength field; the first operator network standard field comprises a first operator identifier and a first network standard, and the first network standard comprises a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard; the first operator resource list comprises a plurality of first operator resource records; the first operator resource record comprises a second operator network standard field and a first available card quantity field; the second operator network standard field comprises a second operator identifier and a second network standard, and the second network standard comprises a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard; the first integration list comprises a plurality of first integration records; the first integration record comprises a third operator network standard field, a second signal strength field and a second available card quantity field; the third operator network standard field comprises a third operator identifier and a third network standard, and the third network standard comprises a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard; The first integrated records in the first integrated record sequence are sorted in descending order of the second signal strength field; The first activation code includes a second server address and a first token; The eSIM module is locally preset with a plurality of groups of first module public-private key pairs, a first manufacturer public key certificate and a first certificate authority public key certificate; each of the first module public-private key pairs corresponds to a first module identifier; the first module public-private key pair includes a first module public key certificate and a first module private key; the first module public key certificate includes a first module public key, first module key information and a first module certificate signature; the first manufacturer public key certificate includes a first manufacturer public key, first manufacturer public key information and a first manufacturer certificate signature; and the first certificate authority public key certificate includes a certificate authority public key, certificate authority public key information and a certificate authority certificate signature; The second server is locally preset with a first server public-private key pair, a second server public-private key pair, the first certificate authority public key certificate and a script encryption and decryption key; the first server public-private key pair includes a first server public key certificate and a first server private key; the first server public key certificate includes a first server public key, first server key information and a first server certificate signature; the second server public-private key pair includes a second server public key certificate and a second server private key; the second server public key certificate includes a second server public key, second server key information and a second server certificate signature; and the first certificate authority public key certificate includes a certificate authority public key, certificate authority public key information and a certificate authority certificate signature.

3. The data download system of the eSIM module according to claim 2, wherein The mobile terminal is specifically configured to send a network analysis instruction to the network analyzer when the network analyzer is called to perform network analysis processing, and receive the first network analysis list returned by the network analyzer.

4. The data download system of the eSIM module according to claim 3, wherein ​ The network analyzer is used to traverse each first network signal frequency band record of a preset network signal frequency band list when receiving the network analysis instruction sent by the mobile terminal; and when traversing, the first network signal frequency band record currently traversed is taken as a corresponding current frequency band record, and the fourth operator network standard field, the first signal frequency band field and the first signal frequency range field of the current frequency band record are extracted as a corresponding current operator network standard, a current signal frequency band and a current signal frequency range; and the signal strength of a wireless signal with a signal frequency band of the current signal frequency band, a signal frequency satisfying the current signal frequency range and a signal standard satisfying the current operator network standard is analyzed to generate a corresponding current signal strength; and the obtained current operator network standard and the current signal strength are taken as the corresponding first operator network standard field and the first signal strength field to form a corresponding first network analysis record; when the traversal ends, all the obtained first network analysis records are taken to form a corresponding first network analysis list to send back to the mobile terminal; The network signal frequency band list includes a plurality of first network signal frequency band records; the first network signal frequency band record includes the fourth operator network standard field, the first signal frequency band field and the first signal frequency range field; the fourth operator network standard field includes a fourth operator identifier and a fourth network standard, and the fourth network standard includes a 2G standard, a 3G standard, a 4G standard, a 5G standard and an NB-IOT standard.

5. The data download system of the eSIM module according to claim 1, wherein The mobile terminal is specifically configured to send a device basic data acquisition instruction to the Internet of Things device when the Internet of Things device is called to perform device identification and device IMEI data acquisition processing, and receive the first device identification and the first IMEI data sent back by the Internet of Things device.

6. The data download system of the eSIM module according to claim 5, wherein The Internet of Things device is configured to extract locally stored unique device codes and unique IMEI data as the first device identification and the first IMEI data to send back to the mobile terminal when receiving the device basic data acquisition instruction sent by the mobile terminal.

7. The data download system of the eSIM module according to claim 2, wherein The mobile terminal is specifically configured to send an available resource query instruction carrying the first device identification and the first IMEI data to the first server when the first server is called to perform operator available resource analysis processing according to the first device identification and the first IMEI data, and receive the first operator resource list sent back by the first server.

8. The data download system of the eSIM module according to claim 7, wherein The first server is configured to extract the first device identifier and the first IMEI data from the available resource query instruction sent by the mobile terminal when receiving the available resource query instruction; extract the first deployment area field of the first device deployment record in the preset device deployment list, in which the first device identifier field matches the first device identifier and the first IMEI field matches the first IMEI data, as the corresponding first deployment area; mark all first region resource statistical records in the preset region resource statistical list, in which the first region field matches the first deployment area, as matching statistical records; extract the fifth operator network mode field and the third available card quantity field of each matching statistical record as the corresponding second operator network mode field and the first available card quantity field to form the corresponding first operator resource record; and send the corresponding first operator resource list composed of all the first operator resource records to the mobile terminal; The device deployment list includes a plurality of first device deployment records, and each first device deployment record includes the first device identifier field, the first IMEI field, and the first deployment area field. The region resource statistical list includes a plurality of first region resource statistical records, and each first region resource statistical record includes the first region field, the fifth operator network mode field, and the third available card quantity field. The fifth operator network mode field includes a fifth operator identifier and a fifth network mode, and the fifth network mode includes a 2G mode, a 3G mode, a 4G mode, a 5G mode, and an NB-IOT mode.

9. The data download system of the eSIM module according to claim 2, wherein The mobile terminal is specifically configured to initialize the first integrated list as an empty list when performing the content integration processing on the first network analysis list and the first operator resource list; count the number of first network analysis records in the first network analysis list to generate a corresponding first number N; add N first integrated records with empty record content to the first integrated list, the first integrated records correspond to the first network analysis records one by one; and set the second available card quantity field of each first integrated record to 0; and set the third operator network mode field and the second signal strength field of each first integrated record according to the first operator network mode field and the first signal strength field of each first network analysis record in the first network analysis list. ​ ​ and the first operator resource list is traversed; and in the traversal, the first operator resource record currently traversed is taken as a corresponding current resource record, the second operator network mode field and the first available card number field of the current resource record are taken as a corresponding current operator network mode and a current available card number, and the second available card number field of the first integrated record in the first integrated list that matches the third operator network mode field with the current operator network mode is set as the current available card number.

10. The data download system of the eSIM module according to claim 2, characterized in that, the mobile terminal is specifically configured to extract the third operator network mode field from the preferred record as a corresponding preferred operator network mode when the first server is called to perform the telecom card resource allocation processing according to the preferred record; and send a resource application instruction carrying the first device identifier, the first IMEI data and the preferred operator network mode to the first server; and receive the first activation code sent back by the first server.

11. The data download system of the eSIM module according to claim 10, characterized in that, the first server is further configured to extract the first device identifier, the first IMEI data and the preferred operator network mode from the resource application instruction sent by the mobile terminal when the resource application instruction is received; extract the first deployment area field of the first device deployment record in the preset device deployment list that matches the first device identifier in the first device identifier field and the first IMEI data in the first IMEI field as a corresponding second deployment area; mark all first card number resource records in the preset card number resource list that match the second deployment area in the second area field and the preferred operator network mode in the sixth operator network mode field and have the first state field in the unoccupied state as matching card number resource records; select one of the obtained multiple matching card number resource records as a corresponding preferred card number resource record; extract the first ICCID field and the first card issuing script field of the preferred card number resource record as the first ICCID data and the first card issuing script data, and change the first state field of the preferred card number resource record to the occupied state; send an activation code application instruction carrying the first device identifier, the first IMEI data, the first ICCID data and the first card issuing script data to the second server; and send the first activation code sent back by the second server to the mobile terminal; wherein the device deployment list includes multiple first device deployment records; and the first device deployment record includes the first device identifier field, the first IMEI field and the first deployment area field. The card number resource list includes a plurality of first card number resource records; the first card number resource record includes the first ICCID field, the second region field, the sixth operator network mode field, the first card issuing script field and the first state field; the sixth operator network mode field includes a sixth operator identifier and a sixth network mode, and the sixth network mode includes a 2G mode, a 3G mode, a 4G mode, a 5G mode and an NB-IOT mode; the first card issuing script field is used for storing card issuing script data; and the first state field includes an occupied state and an unoccupied state.

12. The data download system of the eSIM module according to claim 11, wherein, the second server is configured to extract the first device identifier, the first IMEI data, the first ICCID data and the first card issuing script data from the activation code application instruction sent by the first server when receiving the activation code application instruction; add a first device card number binding record to a preset device card number binding list as a corresponding new record, and set the second device identifier field, the second IMEI field, the second ICCID field and the second card issuing script field of the new record to the first device identifier, the first IMEI data, the first ICCID data and the first card issuing script data respectively; generate a token data for the new record as the first token corresponding to the new record; set the first token field of the new record to the first token; compose the first activation code corresponding to the first token from the preset second server address and the first token, and send the first activation code to the first server; wherein the device card number binding list includes a plurality of first device card number binding records; and each first device card number binding record includes the second device identifier field, the second IMEI field, the second ICCID field, the second card issuing script field and the first token field.

13. The data download system of the eSIM module according to claim 2, wherein, the mobile terminal is specifically configured to extract the second server address from the first activation code when performing the bidirectional authentication processing on the second server and the eSIM module of the Internet of Things device; send a module information acquisition instruction to the eSIM module through the Internet of Things device, and receive first module data returned by the eSIM module through the Internet of Things device; wherein the first module data includes first version data and a first public key identifier sequence, and the first public key identifier sequence includes a plurality of first public key identifiers; send a module random number acquisition instruction to the eSIM module through the Internet of Things device, and receive a first module random number returned by the eSIM module through the Internet of Things device; and send the first module random number, the first module data and the second server address to the second server; and receive the first session identification, the first server plaintext, the first server signature, the second module public key identification and the first server public key certificate sent back by the second server; wherein the first server plaintext comprises the first session identification, second module random number, first server random number and third server address; and compare the third server address with the second server address; if they are the same, send the first session identification, the first server plaintext, the first server signature, the second module public key identification and the first server public key certificate to the eSIM module through the Internet of Things device; and receive the first session identification, first module plaintext, first module signature, second module public key certificate and the first manufacturer public key certificate sent back by the eSIM module through the Internet of Things device; wherein the first module plaintext comprises the first session identification, second server random number and second module data, the second module data comprises second version data and second public key identification sequence, and the second public key identification sequence comprises a plurality of second public key identifications; and send the first session identification, the first module plaintext, the first module signature, the second module public key certificate and the first manufacturer public key certificate to the second server; and receive the verification return data sent back by the second server; and confirm that the two-way authentication processing is successful when the verification return data is verification success.

14. The eSIM module data download system of claim 13, wherein when the eSIM module receives the module information acquisition instruction sent by the mobile terminal through the Internet of Things device, the eSIM module uses the locally stored module version information as the corresponding first version data; and uses the first module identification of each first module public and private key pair pre-stored locally as the corresponding first public key identification, and uses all the first public key identifications obtained to form the corresponding first public key identification sequence; and uses the first version data and the first public key identification sequence to form the corresponding first module data; and sends the first module data back to the mobile terminal through the Internet of Things device; when the eSIM module receives the module random number acquisition instruction sent by the mobile terminal through the Internet of Things device, the eSIM module calls a local random number generator to generate a random number as the corresponding first module random number and saves it; and sends the first module random number back to the mobile terminal through the Internet of Things device.

15. The eSIM module data download system of claim 13, wherein The second server is further configured to identify whether the second server address matches the server address when receiving the first module random number, the first module data and the second server address sent by the mobile terminal; if yes, save the first version data of the first module data; and select one first public key identifier from the first public key identifier sequence of the first module data as the corresponding second module public key identifier; generate a unique session identifier code as the corresponding first session identifier according to a preset session identifier coding rule; use the first module random number as the corresponding second module random number; call a local random number generation interface to generate a random number as the corresponding first server random number and save the random number; use the second server address as the corresponding third server address; compose the corresponding first server plaintext from the first session identifier, the second module random number, the first server random number and the third server address; and perform hash calculation on the first server plaintext based on a preset hash algorithm to generate a corresponding first hash code; perform signature calculation on the first hash code using the first server private key of the first server public-private key pair to generate the corresponding first server signature; send the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate to the mobile terminal.

16. The data download system of the eSIM module of claim 14, wherein the eSIM module is further configured to extract the first server public key and the first server key information from the first server public key certificate to compose a corresponding first plaintext when receiving the first session identifier, the first server plaintext, the first server signature, the second module public key identifier and the first server public key certificate sent by the mobile terminal through the Internet of Things device, perform hash calculation on the first plaintext based on a preset hash algorithm to generate a corresponding second hash code, perform signature verification calculation on the first server certificate signature of the first server public key certificate using the issuing center public key of the first issuing center public key certificate to obtain a corresponding third hash code, and confirm that the server public key certificate is a valid certificate when the second and third hash codes match; perform hash calculation on the first server plaintext based on a preset hash algorithm to generate a corresponding fourth hash code when confirming that the server public key certificate is a valid certificate, perform signature verification calculation on the first server signature using the first server public key of the first server public key certificate to obtain a corresponding fifth hash code, and confirm that the server signature is correct when the fourth and fifth hash codes match; extract the second module random number from the first server plaintext and compare the second module random number with the first module random number saved locally when confirming that the server signature is correct; If the two match, the locally stored module version information is taken as the corresponding second version data, and the locally preset first module private key of each first module public-private key pair is taken as the corresponding second public key identifier, and all the second public key identifiers are taken to form the corresponding second public key identifier sequence, and the second version data and the second public key identifier sequence are taken to form the corresponding second module data, and the first server random number of the first server plaintext is taken as the corresponding second server random number, and the first session identifier, the second server random number, and the second module data of the first server plaintext are taken to form the corresponding first module plaintext; and the first module identifier that matches the second module public key identifier is taken as the corresponding current module public key. and a sixth hash code is generated by performing hash calculation on the first module plaintext based on a preset hash algorithm; and the first module signature is generated by performing signature calculation on the sixth hash code using the current module private key; and the first module public key certificate of the current module public-private key pair is extracted as the corresponding second module public key certificate; and the first session identifier, the first module plaintext, the first module signature, the second module public key certificate, and the first manufacturer public key certificate are sent back to the mobile terminal through the IoT device.

17. The eSIM module data download system of claim 15, wherein the second server is further configured to, when receiving the first session identifier, the first module plaintext, the first module signature, the second module public key certificate, and the first manufacturer public key certificate sent by the mobile terminal, extract the second server random number from the first module plaintext and compare the second server random number with the saved first server random number; if the first and second server random numbers match, extract the second version data from the second module data of the first module plaintext and compare the second version data with the saved first version data; if the first and second version data match, extract the first module public key and the first module key information from the second module public key certificate to form a second plaintext, generate a seventh hash code by performing hash calculation on the second plaintext based on a preset hash algorithm, perform signature verification calculation on the first module certificate signature of the second module public key certificate using the signing center public key of the locally preset first signing center public key certificate to obtain an eighth hash code, and confirm that the eSIM module public key certificate is a valid certificate when the seventh and eighth hash codes match. and when it is confirmed that the eSIM module public key certificate is a valid certificate, the first manufacturer public key and the first manufacturer public key information are extracted from the first manufacturer public key certificate to form a corresponding third plaintext, a ninth hash code corresponding to the third plaintext is generated based on a preset hash algorithm, and a tenth hash code corresponding to the first manufacturer certificate signature of the first manufacturer public key certificate is obtained by performing a signature verification calculation on the first manufacturer certificate signature using the manufacturer center public key of the first issuer center public key certificate pre-stored locally, and when the ninth and tenth hash codes match, it is confirmed that the manufacturer public key certificate is a valid certificate; and when it is confirmed that the manufacturer public key certificate is a valid certificate, an eleventh hash code corresponding to the first module plaintext is generated based on a preset hash algorithm, and a twelfth hash code corresponding to the first module signature is obtained by performing a signature verification calculation on the first module signature using the first module public key of the second module public key certificate, and when the eleventh and twelfth hash codes match, it is confirmed that the eSIM module signature is correct; and when it is confirmed that the eSIM module signature is correct, the corresponding verification return data is set to verification success; and the verification return data is sent back to the mobile terminal.

18. The eSIM module data download system of claim 13, wherein the mobile terminal is specifically configured to send the first session identifier and the first activation code to the second server when the second server is called to perform card data loading processing on the eSIM module according to the first activation code, and receive the first session identifier, the second server signature, and the second server public key certificate sent back by the second server; the first session identifier, the second server signature, and the second server public key certificate are sent to the eSIM module through the Internet of Things device, and the first session identifier, the second module signature, and the first module temporary public key sent back by the eSIM module through the Internet of Things device are received; the first session identifier, the second module signature, and the first module temporary public key are sent to the second server, and the first session identifier, the first ciphertext, the second ciphertext, and the first server temporary public key sent back by the second server are received; the first session identifier, the first ciphertext, the second ciphertext, and the first server temporary public key are sent to the eSIM module through the Internet of Things device, and the loading state data sent back by the eSIM module through the Internet of Things device is received; and when the loading state data is loading success, it is confirmed that the card data loading processing is successful.

19. The eSIM module data download system of claim 18, wherein The second server is further configured to check the second server address of the first activation code when receiving the first session identifier and the first activation code sent by the mobile terminal; when the check is passed, extract the second card issuing script field of the first device card number binding record in which the first token field matches the first token of the first activation code from a preset device card number binding list as corresponding second card issuing script data and store the second card issuing script data in the local; the device card number binding list includes a plurality of first device card number binding records; the first device card number binding record includes a second device identifier field, a second IMEI field, a second ICCID field, the second card issuing script field, and the first token field; and generate a corresponding thirteenth hash code by performing hash calculation on the first session identifier based on a preset hash algorithm; and generate a corresponding second server signature by performing signature calculation on the thirteenth hash code using the second server private key of the second server public-private key pair; and send the first session identifier, the second server signature, and the second server public key certificate of the second server public-private key pair to the mobile terminal.

20. The data download system of the eSIM module according to claim 18, wherein when the eSIM module receives the first session identifier, the second server signature, and the second server public key certificate sent by the mobile terminal through the Internet of Things device, the eSIM module extracts the second server public key and the second server key information from the second server public key certificate to form a corresponding fourth plaintext, generates a corresponding fourteenth hash code by performing hash calculation on the fourth plaintext based on a preset hash algorithm, performs signature verification calculation on the second server certificate signature of the second server public key certificate using the issuing center public key of the first issuing center public key certificate pre-stored in the local to obtain a corresponding fifteenth hash code, and confirms that the server public key certificate is a valid certificate when the fourteenth hash code matches the fifteenth hash code; when it is confirmed that the server public key certificate is a valid certificate, the eSIM module generates a corresponding sixteenth hash code by performing hash calculation on the first session identifier based on a preset hash algorithm, performs signature verification calculation on the second server signature using the second server public key of the second server public key certificate to obtain a corresponding seventeenth hash code, and confirms that the server signature is correct when the sixteenth hash code matches the seventeenth hash code; when it is confirmed that the server signature is correct, the eSIM module performs a public-private key pair generation process to obtain a pair of temporary public-private key pairs, which are denoted as a corresponding first module temporary public key and a first module temporary private key; generates a corresponding eighteenth hash code by performing hash calculation on the first session identifier based on a preset hash algorithm; generates a corresponding second module signature by performing signature calculation on the eighteenth hash code using the first module temporary private key; and sends the first session identifier, the second module signature, and the first module temporary public key to the mobile terminal through the Internet of Things device. 21.The data download system of eSIM module of claim 19, wherein, the second server is further configured to, upon receiving the first session identifier, the second module signature and the first module temporary public key sent by the mobile terminal, generate a corresponding nineteenth hash code by performing hash calculation on the first session identifier based on a preset hash algorithm, and generate a corresponding twentieth hash code by performing signature verification calculation on the second module signature using the first module temporary public key, and confirm that the eSIM module signature is correct when the nineteenth and twentieth hash codes match; generate a pair of temporary public and private keys, denoted as a corresponding first server temporary public key and first server temporary private key, by performing a one-time public and private key pair generation process when the eSIM module signature is confirmed to be correct; encrypt the saved second card issuing script data based on the script encryption and decryption key to generate a corresponding first ciphertext; sign the script encryption and decryption key using the first server temporary private key to generate a corresponding first key signature; and compose a corresponding first key data from the script encryption and decryption key and the first key signature; encrypt the first key data using the first module temporary public key to generate a corresponding second ciphertext; send the first session identifier, the first ciphertext, the second ciphertext and the first server temporary public key back to the mobile terminal. 22.The data download system of eSIM module of claim 20, wherein, the eSIM module is further configured to, upon receiving the first session identifier, the first ciphertext, the second ciphertext and the first server temporary public key sent by the mobile terminal through the Internet of Things device, decrypt the second ciphertext using the first module temporary private key to obtain a corresponding fifth plaintext; extract the script encryption and decryption key and a corresponding first key signature from the fifth plaintext; generate a corresponding second hash code by performing hash calculation on the script encryption and decryption key based on a preset hash algorithm, and generate a corresponding second hash code by performing signature verification calculation on the first key signature using the first server temporary public key, and confirm that the key signature is correct when the second hash code matches the second hash code; decrypt the first ciphertext using the script encryption and decryption key to generate a corresponding sixth plaintext when the key signature is confirmed to be correct; use the sixth plaintext as a corresponding third card issuing script data; perform card data loading processing according to the third card issuing script data; set a corresponding loading state data to loading success when the card data loading processing is successful; send the loading state data to the mobile terminal through the Internet of Things device.

Citation Information

Patent Citations

  • ESIM (emulation subscriber identity module) card and method for operating same

    CN107613487A

  • SIM card-to-eSIM card data migration method and device

    CN107734498A