SIM card-based identity authentication method, platform, SIM card and terminal

CN116419212BActive Publication Date: 2026-08-21CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111679786.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-31
Publication Date
2026-08-21
Estimated Expiration
2041-12-31

AI Technical Summary

Technical Problem

[0005]本申请提供一种基于SIM卡的身份认证方法、平台、SIM卡及终端,用以解决现有技术中终端直接获取SIM卡存储信息的方式存在一定安全隐患,用户信息泄露风险较大的问题

Benefits of technology

[0068] In a tenth aspect, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in any one of the first, second, or third aspects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116419212B_ABST
    Figure CN116419212B_ABST
Patent Text Reader

Abstract

The application provides a SIM card-based identity authentication method, platform, SIM card and terminal. A login request sent by a terminal application program is received by a trusted service management platform, and request data is generated according to the login request, wherein the request data comprises the login request and network certificate data stored by the trusted service management platform. The trusted service management platform sends the request data to the SIM card, and the SIM card sends the network certificate data in the request data back to the trusted service management platform after encryption. The trusted service management platform decrypts the encrypted network certificate data by using a symmetric encryption algorithm, and if the network certificate data is decrypted, the user identity authentication is passed, and the decrypted network certificate data is sent to the application program, and the application program logs in by using the network certificate data. According to the method, the network certificate data used for identity authentication is encrypted, the security in the process of obtaining the network certificate data is improved, and the risk of user information leakage stored in the terminal SIM card is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to an identity authentication method, platform, SIM card, and terminal based on a SIM card. Background Technology

[0002] Identity authentication technology is a technology developed to verify the identity of users in computer networks. Among them, authenticating user identity through a smart identification card (Subscriber Identity Module, SIM) is one of the main methods of authentication technology.

[0003] When authenticating user identity based on a SIM card, the existing technology collects the user's facial biometric information on-site through the terminal and compares it with the biometric information of the ID card photo stored on the SIM card. If the biometric information collected by the terminal matches the biometric information stored on the SIM card, the user identity authentication is successful.

[0004] However, the current technology of directly accessing SIM card stored information by terminals poses certain security risks and increases the risk of user information leakage. Summary of the Invention

[0005] This application provides a SIM card-based identity authentication method, platform, SIM card, and terminal to address the security risks and significant user information leakage risks associated with existing technologies where terminals directly access information stored in SIM cards.

[0006] Firstly, this application provides a SIM card-based identity authentication method applied to a trusted service management platform, including:

[0007] Receive login requests sent by terminal applications;

[0008] Based on the login request, request data is generated, which includes the login request and the network certificate data stored in the trusted service management platform. The network certificate data contains user identity authentication information.

[0009] The request data is sent to the SIM card of the terminal;

[0010] Receive the encrypted network certificate data returned by the SIM card;

[0011] The encrypted online ID data is decrypted using a symmetric encryption algorithm. If the online ID data is successfully decrypted, the user's identity authentication is successful.

[0012] The decrypted e-ID data is sent to the terminal application so that the terminal application can log in using the decrypted e-ID data.

[0013] Optionally, before receiving the login request sent by the terminal, the following steps are also included:

[0014] Receive the network license download request sent by the terminal application;

[0015] The network certificate data is obtained from the network certificate platform according to the network certificate download request;

[0016] The network certificate data is encrypted using the symmetric encryption algorithm to generate encrypted network certificate data, which is then stored in the trusted service management platform.

[0017] The encrypted network certificate data is sent to the terminal via an encrypted SMS transmission link.

[0018] Optionally, the network certificate data is encrypted using the symmetric encryption algorithm to generate encrypted network certificate data, including:

[0019] The network certificate data is grouped into first network certificate data, second network certificate data, and third network certificate data;

[0020] The key is fused with the first, second, and third network certificate data respectively through a key generation algorithm to generate a first subkey, a second subkey, and a third subkey.

[0021] The first input, the second input, and the third input are input into a symmetric encryption function to generate the encrypted network certificate data. The first input is a set consisting of the first network certificate data and the first subkey, the second input is a set consisting of the second network certificate data and the second subkey, and the third input is a set consisting of the third network certificate data and the third subkey.

[0022] Optionally, the fusion processing of the key with the first, second, and third network certificate data includes one or more of the following:

[0023] The key is fused with the first, second, and third network certificate data respectively through specific positioning permutations, inverse permutations, or shifts.

[0024] Secondly, this application provides a SIM card-based authentication method, applied to the SIM card of a user terminal, comprising:

[0025] Receive request data generated based on a login request from a trusted service management platform. The request data includes the login request and the network certificate data stored by the trusted service management platform. The network certificate data contains user identity authentication information.

[0026] The network license data included in the request data is compared with the network license data stored in the SIM card of the terminal;

[0027] If the comparison results are the same, the network certificate data included in the request data is encrypted using a symmetric encryption algorithm to generate encrypted network certificate data;

[0028] The encrypted network certificate data is sent to the trusted service management platform.

[0029] Optionally, before receiving the request data generated based on the login request sent by the trusted service management platform, the following steps are also included:

[0030] Receive network certificate data encrypted by the Trusted Service Management Platform, which is sent by the Trusted Service Management Platform through an encrypted SMS transmission link;

[0031] The encrypted network ID data is decrypted using the symmetric encryption algorithm, and the decrypted network ID data is stored in the SIM card of the terminal.

[0032] Thirdly, this application provides a SIM card-based authentication method, which is applied to a user terminal application, including:

[0033] Receive login requests entered by users in the interactive interface;

[0034] Send the login request to the trusted service management platform;

[0035] Receive the decrypted network certificate data from the trusted service management platform and log in using the network certificate data.

[0036] Optionally, after receiving the decrypted network certificate data from the trusted service management platform, the method further includes:

[0037] Send a QR code acquisition request to the trusted service management platform;

[0038] Receive the QR code sent by the trusted service management platform;

[0039] The QR code is displayed to the user through the terminal interface and is used by the user to log in to other terminals.

[0040] Fourthly, this application provides a trusted service management platform, including:

[0041] The receiving module is used to receive login requests sent by the terminal application;

[0042] The generation module is used to generate request data based on the login request. The request data includes the login request and the network certificate data stored in the trusted service management platform. The network certificate data contains user identity authentication information.

[0043] A sending module is used to send the request data to the SIM card of the terminal;

[0044] The receiving module is also used to receive the encrypted network certificate data returned by the SIM card;

[0045] The decryption module is used to decrypt the encrypted online certificate data using a symmetric encryption algorithm. If the online certificate data is decrypted, the user's identity authentication is successful.

[0046] The sending module is also used to send the decrypted network certificate data to the terminal application, so that the terminal application can log in using the decrypted network certificate data.

[0047] Fifthly, this application provides a SIM card for a user terminal, comprising:

[0048] The receiving module is used to receive request data generated based on the login request sent by the trusted service management platform. The request data includes the login request and the network certificate data stored by the trusted service management platform. The network certificate data contains user identity authentication information.

[0049] The comparison module is used to compare the network certificate data included in the request data with the network certificate data stored in the SIM card of the terminal;

[0050] The encryption module is used to encrypt the network certificate data included in the request data using a symmetric encryption algorithm if the comparison results are the same, thereby generating encrypted network certificate data.

[0051] The sending module is used to send the encrypted network certificate data to the trusted service management platform through the terminal application.

[0052] Sixthly, this application provides a terminal, including:

[0053] The receiving module is used to receive login requests entered by the user in the interactive interface;

[0054] The sending module is used to send the login request to the trusted service management platform;

[0055] The receiving module is also used to receive the decrypted network certificate data from the trusted service management platform and to log in using the network certificate data.

[0056] In a seventh aspect, this application provides a trusted service management platform, including: a processor, and a memory and a transceiver communicatively connected to the processor;

[0057] The processor controls the receiving and transmitting actions of the transceiver;

[0058] The memory stores computer-executed instructions;

[0059] The processor executes computer execution instructions stored in the memory to implement the method described in any of the first aspects.

[0060] Eighthly, this application provides a SIM card for a user terminal, comprising: a processor, and a memory and a transceiver communicatively connected to the processor;

[0061] The processor controls the receiving and transmitting actions of the transceiver;

[0062] The memory stores computer-executed instructions;

[0063] The processor executes computer execution instructions stored in the memory to implement the method described in any of the second aspects.

[0064] Ninthly, this application provides a user terminal, including: a processor, and a memory and a transceiver communicatively connected to the processor;

[0065] The processor controls the receiving and transmitting actions of the transceiver;

[0066] The memory stores computer-executed instructions;

[0067] The processor executes computer execution instructions stored in the memory to implement the method described in any of the third aspects.

[0068] In a tenth aspect, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in any one of the first, second, or third aspects.

[0069] In one aspect, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method described in any one of the first, second, or third aspects.

[0070] This application provides a SIM card-based identity authentication method, platform, SIM card, and terminal. The method involves a trusted service management platform receiving login requests from a terminal application and generating request data based on these requests. This request data includes the login request and e-certificate data stored on the trusted service management platform. The trusted service management platform sends the request data to the terminal's SIM card. The SIM card encrypts the e-certificate data included in the request data using a symmetric encryption algorithm and sends the encrypted e-certificate data back to the trusted service management platform. The trusted service management platform decrypts the encrypted e-certificate data using the same symmetric encryption algorithm. If the e-certificate data is successfully decrypted, user authentication is successful. Finally, the trusted service management platform sends the decrypted e-certificate data to the terminal application, which then uses the decrypted e-certificate data to log in. This method improves the security of obtaining e-certificate data by encrypting the e-certificate data used for user authentication, thereby reducing the risk of leakage of user information stored on the terminal's SIM card. Attached Figure Description

[0071] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0072] Figure 1 This is a schematic diagram of a communication scenario to which this application applies;

[0073] Figure 2 This is a flowchart illustrating a SIM card-based identity authentication method provided in Embodiment 1 of this application.

[0074] Figure 3 A flowchart illustrating a method for pre-storing network certificate data in a trusted service management platform, as provided in Embodiment 2 of this application;

[0075] Figure 4 A flowchart illustrating another SIM card-based identity authentication method provided in Embodiment 3 of this application;

[0076] Figure 5 This is a flowchart illustrating a method for pre-storing network license data on a terminal SIM card, as provided in Embodiment 4 of this application.

[0077] Figure 6 A flowchart illustrating another SIM card-based identity authentication method provided in Embodiment 5 of this application;

[0078] Figure 7 This is a signaling flowchart of a SIM card-based identity authentication method provided in Embodiment Six of this application;

[0079] Figure 8A schematic diagram of the device structure of a trusted service management platform provided in Embodiment 7 of this application;

[0080] Figure 9 This is a schematic diagram of a SIM card device structure for a user terminal provided in Embodiment 8 of this application;

[0081] Figure 10 A schematic diagram of the device structure of a user terminal provided in Embodiment 9 of this application;

[0082] Figure 11 This is a schematic diagram of the structure of a trusted service management platform provided in Embodiment 10 of this application;

[0083] Figure 12 This is a schematic diagram of a SIM card structure for a user terminal provided in Embodiment Eleven of this application;

[0084] Figure 13 This is a schematic diagram of the structure of a user terminal provided in Embodiment Twelve of this application.

[0085] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0086] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0087] First, let me explain the terms used in this application:

[0088] Trusted Service Management (TSM) is a platform through which application information and data from service providers such as telecommunications operators, urban integrated service providers, financial institutions, and other smart card issuers can be interconnected in e-commerce.

[0089] Identity authentication is the process of verifying the identity of an operator in a computer network, that is, determining whether a user is a legitimate user. Authentication of user identity through a smart identification card (Subscriber Identity Module, SIM) is one of the main methods of authentication technology.

[0090] Current technologies for user authentication via SIM cards typically rely on biometric information. This involves collecting the user's facial biometrics on-site using a terminal and comparing it to the biometrics of the ID photo stored on the SIM card. If the biometrics collected by the terminal match the biometrics stored on the SIM card, the user's identity is authenticated. This biometric information can include iris data, facial features, etc.

[0091] However, when existing terminals obtain user authentication information, i.e. biometric information, stored on the SIM card, they can directly read the content stored on the SIM card without any security encryption methods, which poses certain security risks and increases the risk of user information leakage.

[0092] Therefore, to address the aforementioned problems in the prior art, this application proposes a SIM card-based identity authentication method, platform, SIM card, and terminal. After receiving a login request from the terminal application, the Trusted Service Management Platform sends the network certificate data used for user authentication to the terminal's SIM card. The SIM card compares the network certificate data sent by the Trusted Service Management Platform with the network certificate data stored in the terminal's SIM card. If they match, the network certificate data sent by the Trusted Service Management Platform is encrypted using a symmetric encryption algorithm and sent back to the Trusted Service Management Platform. If the Trusted Service Management Platform can decrypt the encrypted network certificate data sent by the terminal, user authentication is successful. Finally, the terminal application logs in using the decrypted network certificate data. By encrypting the network certificate data used for user authentication, the security of obtaining network certificate data is improved, thereby reducing the risk of leakage of user information stored in the terminal's SIM card.

[0093] The Trusted Service Management Platform is primarily used for interoperability between various terminals or business platforms. It consists of a business processing module and a business management module. The business processing module enables the connection between terminals and various business platforms, and selects and processes interaction channels according to the business processing flow. The business management module allows for the querying and statistics of internal data within each terminal or business platform. This internal data can include various configuration data or business data.

[0094] The e-certificate platform is mainly used to store e-certificate data, which includes user identity authentication information, such as identity authentication infrastructure platforms.

[0095] This application can be applied to various SIM card-based identity authentication scenarios, such as communication scenarios, etc. Figure 1 As shown, Figure 1This diagram illustrates a communication scenario to which this application applies. The SIM card 101, as a telecommunications smart card, is installed on the terminal 102. User authentication is performed by receiving network certificate data sent by the Trusted Service Manager (TSM) platform 103, whereby the network certificate data is generated by the network certificate platform 104. It is understood that the SIM card-based authentication method provided in this application includes, but is not limited to, the above communication scenario, and is not intended to limit this application.

[0096] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0097] Figure 2 This is a flowchart illustrating a SIM card-based identity authentication method provided in Embodiment 1 of this application. This method can be executed by a trusted service management platform, such as... Figure 2 As shown, the method may include the following steps:

[0098] S201, Receive login request sent by terminal application.

[0099] In this application, the terminal can be a user's mobile phone, tablet computer, etc. The user selects the application they want to log in to on the terminal. The application to log in to can be an application that requires user authentication. After the user selects the login option on the application's onboarding interface, the terminal will receive the login request sent by the user clicking on the application. The terminal application will send the login request to the Trusted Service Manager (TSM) platform, and the TSM platform will then receive the login request sent by the terminal application.

[0100] S202. Based on the login request, generate request data. The request data includes the login request and the network certificate data stored in the trusted service management platform. The network certificate data contains user identity authentication information.

[0101] After receiving a login request from a terminal, the TSM platform encapsulates the login request with the e-certificate data pre-stored in the TSM platform to generate request data, which includes user identity authentication information.

[0102] S203. Send the request data to the SIM card of the terminal.

[0103] The TSM platform will send request data, including login requests and e-certificate data, to the terminal's SIM card via methods such as encrypted SMS transmission links, or through other signaling channels. Sending the request data via encrypted SMS transmission links further protects the e-certificate data, preventing tampering and attacks during transmission, and ensuring the integrity and originality of the e-certificate data.

[0104] S204. Receive the network certificate data returned after encryption by the SIM card.

[0105] After the terminal's SIM card receives the request data sent by the TSM platform, if the network certificate data contained in the request data sent by the TSM platform matches the network certificate data pre-stored in the terminal's SIM card, then the SIM card authenticates the network certificate data sent by the TSM platform. The SIM card further encrypts the network certificate data sent by the TSM platform using a symmetric encryption algorithm and sends the encrypted network certificate data to the TSM platform. The encrypted network certificate data can be sent via, for example, an encrypted SMS transmission link, or it can be sent through other signaling channels.

[0106] S205. Decrypt the encrypted online ID data using a symmetric encryption algorithm. If the online ID data is decrypted, the user's identity authentication is successful.

[0107] After receiving the encrypted e-ID data from the terminal, the TSM platform decrypts it using a symmetric encryption algorithm. The decryption process is the reverse of the encryption process. If the e-ID data is successfully decrypted, the TSM platform has authenticated the e-ID data sent by the terminal's SIM card, meaning the user's identity has been successfully authenticated.

[0108] S206. Send the decrypted e-certificate data to the terminal application so that the terminal application can log in using the decrypted e-certificate data.

[0109] After successful user authentication, the authentication result will be sent to the terminal application. Upon receiving the authentication result, the terminal application will send a request to the TSM platform to retrieve the decrypted e-certificate data stored in the TSM platform.

[0110] The TSM platform sends the decrypted e-ID data to the terminal application, enabling the terminal application to log in using the decrypted e-ID data.

[0111] It should be noted that after user authentication is successful, the terminal application can also request a QR code from the TSM platform based on the decrypted e-certificate data. This QR code includes information that displays the user's identity. The TSM platform, upon receiving the QR code request from the terminal application, retrieves the QR code from the e-certificate platform. The e-certificate platform generates the QR code and sends it back to the TSM platform, which then sends it back to the terminal application. Other terminals can then log in by scanning this QR code.

[0112] In the first embodiment of this application, a trusted service management platform receives a login request from a terminal application, generates request data based on the login request, and sends it to the terminal's SIM card. The request data includes network ID information used for user authentication. Then, the trusted service management platform decrypts the received network ID data, which has been encrypted by the terminal, using a symmetric encryption algorithm. If decryption is successful, user authentication is successful, and the decrypted network ID data is sent to the terminal application so that the terminal application can log in using the decrypted network ID data. By encrypting and decrypting the network ID data, the security of obtaining the network ID data is improved, thereby reducing the risk of leakage of user information stored on the terminal's SIM card.

[0113] Based on the above embodiment one, before the TSM platform receives the login request sent by the terminal application, the TSM platform also needs to obtain and store the network certificate data, wherein the stored network certificate data is used in step S202 of embodiment one. Figure 3 As shown, Figure 3 A flowchart illustrating a method for pre-storing network certificate data in a trusted service management platform, as provided in Embodiment 2 of this application, may include the following steps:

[0114] S301, Receive network license download request sent by terminal application.

[0115] After the user selects the application they want to use on the terminal, they select the e-certificate download option on the application's introductory interface. The terminal application receives the e-certificate download request sent by the user by clicking the application and sends it to the TSM platform. The TSM platform then receives the e-certificate download request sent by the terminal application.

[0116] S302. Obtain the e-certificate data from the e-certificate platform according to the e-certificate download request.

[0117] After receiving the network certificate download request from the terminal application, the TSM platform obtains the network certificate data from the network certificate platform. After generating the network certificate data, the network certificate platform sends the network certificate data to the TSM platform.

[0118] S303. Encrypt the online certificate data using a symmetric encryption algorithm to generate encrypted online certificate data and store it on the trusted service management platform.

[0119] After receiving the e-certificate data sent by the e-certificate platform, the TSM platform encrypts it using a symmetric encryption algorithm and stores both the encrypted and unencrypted e-certificate data in the TSM platform.

[0120] In addition, the TSM platform also sends the encrypted e-certificate data to the terminal's SIM card via an encrypted SMS transmission link. This encrypted SMS transmission link can also be other signaling channels. It's important to note that when the TSM platform sends the encrypted e-certificate data to the terminal's SIM card, it also sends the e-certificate information used for user authentication to the SIM card, which then stores this authentication information. Environmental information related to user authentication, such as time and location information, is not sent to the SIM card by the TSM platform, thus saving SIM card storage space without affecting the user authentication result.

[0121] Furthermore, the following describes the specific process of the TSM platform encrypting the network certificate data using a symmetric encryption algorithm in step S303:

[0122] After receiving the e-certificate data sent by the e-certificate platform, the TSM platform groups the e-certificate data into first e-certificate data, second e-certificate data, and third e-certificate data.

[0123] The key is fused with the first, second, and third network certificate data through a key generation algorithm to generate the first subkey, the second subkey, and the third subkey.

[0124] The first input, the second input, and the third input are input into the symmetric encryption function to generate encrypted network certificate data. The first input is a set consisting of the first network certificate data and the first subkey, the second input is a set consisting of the second network certificate data and the second subkey, and the third input is a set consisting of the third network certificate data and the third subkey.

[0125] The fusion process includes one or more of the following: fusing the key with the first, second, and third network certificate data respectively through specific positioning permutations, inverse permutations, or shifts.

[0126] For example, the TSM platform divides the plaintext e-certificate data into three parts: first e-certificate data L, second e-certificate data M, and third e-certificate data R. A key generation algorithm then merges key K with each of these parts to generate a first subkey KL, a second subkey KM, and a third subkey KR. Key K is divided into three identical parts, each 90 bits long. Key K is then merged with the first e-certificate data L, the second e-certificate data M, and the third e-certificate data R using specific permutations, inverse permutations, or shifts. The first network certificate data L and the first subkey KL form the first input quantity (L, KL), the second network certificate data M and the second subkey KM form the second input quantity (M, KM), and the third network certificate data R and the third subkey KR form the second input quantity (R, KR). These are input into the encryption function Fn. After encryption by the encryption function Fn, RTL, RTM, and RTR are output. Finally, the three are combined into RTLRTRTRTR to obtain the encrypted network certificate data.

[0127] The symmetric encryption algorithm used in this application selects a total key length of 256 bits. The first subkey KL, the second subkey KM, and the third subkey KR generated by the key generation algorithm can also reach 256 bits. The number of keys can be generated from one key and then distributed into three. The length of the output result after encryption by the encryption function will be three times that of the original data. Therefore, the security of the network certificate data can be better guaranteed in terms of key length, number of keys, and length of result data.

[0128] In the above Embodiment 1 and Embodiment 2, a SIM card-based identity authentication method applied to a trusted service management platform was described. Below, Embodiment 3 will be used to describe a SIM card-based identity authentication method applied to a user terminal SIM card. Figure 4 This is a flowchart illustrating another SIM card-based authentication method provided in Embodiment 3 of this application. This method can be executed by the SIM card of a user terminal, such as... Figure 4 As shown, the method may include the following steps:

[0129] S401. Receive request data generated based on the login request sent by the Trusted Service Management Platform. The request data includes the login request and the network certificate data stored by the Trusted Service Management Platform. The network certificate data contains user identity authentication information.

[0130] After receiving a login request from the terminal application, the TSM platform generates request data based on the login request and sends it to the terminal's SIM card. This request data can be sent to the terminal's SIM card via, for example, an encrypted SMS transmission link, or through other signaling channels. The terminal's SIM card can then receive this request data.

[0131] S402. Compare the network license data included in the request data with the network license data stored in the terminal's SIM card.

[0132] S403. If the comparison results are the same, the network certificate data included in the request data will be encrypted using a symmetric encryption algorithm to generate encrypted network certificate data.

[0133] After receiving the request data from the TSM platform, the terminal's SIM card compares the network license data included in the request data with the network license data stored in the terminal's SIM card. If the network license data included in the request data sent by the TSM platform matches the network license data pre-stored in the terminal's SIM card, then the SIM card successfully authenticates the network license data sent by the TSM platform.

[0134] S404. Send the encrypted network certificate data to the trusted service management platform.

[0135] The terminal's SIM card further encrypts the network certificate data sent by the TSM platform using a symmetric encryption algorithm, and sends the encrypted network certificate data to the TSM platform through methods such as encrypted SMS transmission links, or through other signaling channels.

[0136] In the above-described embodiment three of this application, the terminal's SIM card receives request data generated by the Trusted Service Management Platform based on a login request. This request data includes network certificate information used for user authentication. Then, the network certificate data included in the request data is compared with the network certificate data stored in the terminal's SIM card. If the comparison results are the same, the network certificate data included in the request data is encrypted using a symmetric encryption algorithm, and finally, the generated encrypted network certificate data is sent to the TSM platform. If the TSM platform successfully decrypts the data, user authentication is successful, thus preparing for the user to log in to the terminal application.

[0137] Based on the above embodiment three, before the SIM card receives the request data generated based on the login request sent by the trusted service management platform, the SIM card first needs to obtain and store the network certificate data, wherein the stored network certificate data is used in step S402 of embodiment three. Figure 5 As shown, Figure 5 This is a flowchart illustrating a method for pre-storing network license data on a terminal SIM card, as provided in Embodiment 4 of this application. The executing entity is the terminal's SIM card, and the method may specifically include the following steps:

[0138] After selecting the desired application on the terminal, the user selects the e-certificate download option in the application's boot menu. The terminal application then sends the e-certificate download request to the TSM platform.

[0139] S501. Receive network certificate data encrypted by the Trusted Service Management Platform, sent by the Trusted Service Management Platform through an encrypted SMS transmission link.

[0140] After receiving the e-certificate data sent by the e-certificate platform, the TSM platform encrypts it using a symmetric encryption algorithm and sends the encrypted e-certificate data to the terminal's SIM card. The SIM card then receives the e-certificate data encrypted by the Trusted Service Management Platform.

[0141] S502. The encrypted network certificate data is decrypted using a symmetric encryption algorithm, and the decrypted network certificate data is stored in the SIM card of the terminal.

[0142] After receiving the encrypted network certificate data sent by the trusted service management platform, the terminal's SIM card decrypts it using a symmetric encryption algorithm and stores the decrypted network certificate data in the terminal's SIM card.

[0143] In summary, the SIM card receives encrypted network certificate data from the trusted service management platform and decrypts the encrypted network certificate data using a symmetric encryption algorithm, thereby storing the decrypted network certificate data in the card in advance.

[0144] Furthermore,

[0145] The above embodiments three and four illustrate a SIM card-based authentication method from the perspective of the SIM card as the execution subject. Below, through embodiment five, we will illustrate another SIM card-based authentication method from the perspective of the user terminal application as the execution subject.

[0146] like Figure 6 As shown, Figure 6 This is a flowchart illustrating another SIM card-based identity authentication method provided in Embodiment 5 of this application. The method may include the following steps:

[0147] S601, Receive login request entered by user in the interactive interface.

[0148] Users select the application they want to log in to on the terminal. The application to log in to is one that requires user authentication. After the user selects the login option on the application's onboarding screen, the terminal application will receive the login request entered by the user on the interactive interface.

[0149] S602. Send the login request to the trusted service management platform.

[0150] The terminal application sends a login request to the Trusted Service Management Platform (TSM), which then generates request data based on the login request.

[0151] S603: Receive the decrypted network certificate data from the trusted service management platform and log in using the network certificate data.

[0152] In step S404 of Embodiment 3, the SIM card sends the encrypted network certificate data to the Trusted Service Management Platform. After receiving the encrypted network certificate data, the TSM platform decrypts it using a symmetric encryption algorithm. If the network certificate data can be successfully decrypted, it means that the TSM platform has successfully authenticated the network certificate data sent by the terminal, i.e., the user's identity authentication has been successful.

[0153] The TSM platform sends the authentication result after successful user identity verification to the terminal application. Upon receiving the authentication result, the terminal application retrieves the e-certificate data stored in the TSM platform. The TSM platform then sends the e-certificate data back to the terminal application, which finally logs in using the decrypted e-certificate data.

[0154] In addition, after receiving the result of successful user authentication, the terminal application can also send a QR code acquisition request to the Trusted Service Management Platform. The TSM platform obtains the QR code from the online certificate platform based on the QR code acquisition request sent by the terminal application. After generating the QR code, the online certificate platform sends it back to the TSM platform, and the TSM platform finally sends the QR code back to the terminal application.

[0155] The terminal application receives a QR code sent by the trusted service management platform and displays the QR code to the user through the terminal's interface. The QR code is used by the user to log in to other terminals, and other terminals can then log in by scanning the QR code.

[0156] In the above embodiments one to five of this application, the SIM card-based identity authentication method was described from the perspective of different implementing entities. Below, embodiment six, based on embodiments one to five, describes in detail the interaction process between the various devices, such as... Figure 7 As shown, Figure 7 This is a signaling flowchart of a SIM card-based identity authentication method provided in Embodiment Six of this application. The method provided in this embodiment may include the following steps:

[0157] The S701 and TSM platforms receive network license download requests sent by terminal applications.

[0158] S702 and TSM platforms send a request to the e-certificate platform to obtain e-certificate data based on the e-certificate download request.

[0159] S703, the online certificate platform generates online certificate data.

[0160] S704, the e-certificate platform sends the generated e-certificate data to the TSM platform.

[0161] The S705 and TSM platforms encrypt and store online certificate data using a symmetric encryption algorithm.

[0162] The S706 and TSM platforms send the encrypted network certificate data to the terminal's SIM card via the encrypted SMS transmission link of the SMS gateway.

[0163] S707: The terminal's SIM card decrypts the encrypted network certificate data and stores the decrypted network certificate data in the SIM card.

[0164] S708, the SIM card returns the successful storage processing result and sends it to the SMS gateway.

[0165] S709, the SMS gateway sends the successfully stored processing results to the TSM platform.

[0166] The S710 and TSM platforms send the successfully stored processing results to the terminal application.

[0167] Steps S701 to S710 can be understood as the process of downloading network certificate data. Through this process, the network certificate data downloaded from the network certificate platform is stored in the TSM platform and the terminal SIM card.

[0168] The S711 and TSM platforms receive login requests sent by terminal applications.

[0169] The S712 and TSM platforms encapsulate login requests and stored network certificate data to generate request data.

[0170] The S713 and TSM platforms send the request data to the terminal's SIM card via the encrypted SMS transmission link of the SMS gateway.

[0171] S714: The SIM card compares the network certificate data contained in the request data sent by the TSM platform with the network certificate data stored in the SIM card.

[0172] If the S715 and SIM card match, the network certificate data contained in the request data sent by the TSM platform will be encrypted using a symmetric encryption algorithm, and the encrypted network certificate data will be sent to the TSM platform through the encrypted SMS transmission link of the SMS gateway.

[0173] The S716 and TSM platforms decrypt and store the encrypted online certificate data.

[0174] The S717 and TSM platforms send the successful authentication result to the terminal application.

[0175] S718, The terminal application sends a request to the TSM platform to obtain network certificate data.

[0176] The S719 and TSM platforms receive requests for obtaining network certificate data and send the network certificate data back to the terminal application.

[0177] S720 and terminal applications log in using network certificate data.

[0178] The S721 and TSM platforms receive QR code acquisition requests sent by terminal applications.

[0179] The S722 and TSM platforms send a request to the online certificate platform to apply for a QR code based on the QR code acquisition request.

[0180] S723, QR code generated by the online certificate platform.

[0181] S724, the online certificate platform sends the generated QR code to the TSM platform.

[0182] After receiving the QR code, the S725 and TSM platforms send it to the terminal application.

[0183] Other terminals can scan the QR code, and after successful scanning, log in to those terminals. Steps S711 to S725 can be understood as the process of using the network ID data, through which user authentication is completed. Specifically, S711 to S720 involves logging into the terminal application after user authentication. Furthermore, steps S721 to S725 explain that after user authentication, a QR code can also be generated to log in to other terminals.

[0184] The process of this embodiment can be used to execute a SIM card-based identity authentication method according to Embodiments 1 to 6. The specific implementation and technical effects are similar, and will not be described again here.

[0185] Figure 8 This is a schematic diagram of the device structure of a trusted service management platform provided in Embodiment 7 of this application. Figure 8 As shown, the device 80 includes: a receiving module 801, a generating module 802, a sending module 803, and a decryption module 804.

[0186] The receiving module 801 is used to receive login requests sent by the terminal application.

[0187] The generation module 802 is used to generate request data based on the login request. The request data includes the login request and the network certificate data stored in the trusted service management platform. The network certificate data contains user identity authentication information.

[0188] The sending module 803 is used to send request data to the SIM card of the terminal.

[0189] The receiving module 801 is also used to receive the network certificate data returned after encryption by the SIM card.

[0190] The decryption module 804 is used to decrypt the encrypted online certificate data using a symmetric encryption algorithm. If the online certificate data is decrypted, the user's identity authentication is successful.

[0191] The sending module 803 is also used to send the decrypted network certificate data to the terminal application so that the terminal application can log in using the decrypted network certificate data.

[0192] Figure 9 This is a schematic diagram of a SIM card device structure for a user terminal provided in Embodiment 8 of this application. Figure 9 As shown, the device 90 includes: a receiving module 901, a comparison module 902, an encryption module 903, and a sending module 904.

[0193] The receiving module 901 is used to receive request data generated based on the login request sent by the trusted service management platform. The request data includes the login request and the network certificate data stored by the trusted service management platform. The network certificate data contains user identity authentication information.

[0194] The comparison module 902 is used to compare the network license data included in the request data with the network license data stored in the terminal's SIM card;

[0195] The encryption module 903 is used to encrypt the network certificate data included in the request data using a symmetric encryption algorithm if the comparison results are the same, so as to generate encrypted network certificate data.

[0196] The sending module 904 is used to send the encrypted network certificate data to the trusted service management platform.

[0197] Figure 10 This is a schematic diagram of a user terminal device structure provided in Embodiment 9 of this application. Figure 10 As shown, the device 100 includes: a receiving module 1001 and a transmitting module 1002.

[0198] The receiving module 1001 is used to receive the login request entered by the user in the interactive interface.

[0199] The sending module 1002 is used to send login requests to the trusted service management platform.

[0200] The receiving module 1001 is also used to receive the decrypted network certificate data from the trusted service management platform and to log in using the network certificate data.

[0201] Figure 11 This is a schematic diagram of the structure of a trusted service management platform provided in Embodiment 10 of this application. Figure 11 As shown, it includes: at least one transceiver 1101, a processor 1102, and a memory 1103.

[0202] The memory 1103 is used to store programs. Specifically, the program may include program code, which includes computer operation instructions.

[0203] The memory 1103 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.

[0204] The processor 1102 is used to execute computer execution instructions stored in the memory 1103 and control the receiving and sending actions of the transceiver 1101 to implement a SIM card-based authentication method.

[0205] The processor 1102 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application. The processor 1102 implements the SIM card-based identity authentication method by running instructions stored in the memory 1103.

[0206] Optionally, in specific implementations, if the transceiver 1101, processor 1102, and memory 1103 are implemented independently, they can be interconnected via a bus to complete communication. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc., but are not limited to a single bus or a single type of bus.

[0207] Optionally, in a specific implementation, if the transceiver 1101, processor 1102, and memory 1103 are integrated on a single chip, then the transceiver 1101, processor 1102, and memory 1103 can communicate through an internal interface.

[0208] Figure 12 This is a schematic diagram of a SIM card structure for a user terminal provided in Embodiment Eleven of this application. Figure 12 As shown, it includes: at least one transceiver 1201, a processor 1202, and a memory 1203.

[0209] The memory 1203 is used to store programs. Specifically, the program may include program code, which includes computer operation instructions.

[0210] The memory 1203 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.

[0211] The processor 1202 is used to execute computer execution instructions stored in the memory 1203 and control the receiving and sending actions of the transceiver 1201 to implement a SIM card-based authentication method.

[0212] The processor 1202 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application. The processor 1202 implements the SIM card-based identity authentication method by running instructions stored in the memory 1203.

[0213] Optionally, in specific implementations, if the transceiver 1201, processor 1202, and memory 1203 are implemented independently, they can be interconnected via a bus to complete communication. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc., but are not limited to a single bus or a single type of bus.

[0214] Optionally, in a specific implementation, if the transceiver 1201, processor 1202, and memory 1203 are integrated on a single chip, then the transceiver 1201, processor 1202, and memory 1203 can communicate through an internal interface.

[0215] Figure 13 This is a schematic diagram of a user terminal structure provided in Embodiment Twelve of this application. Figure 13 As shown, it includes: at least one transceiver 1301, a processor 1302, and a memory 1303.

[0216] The memory 1303 is used to store programs. Specifically, the program may include program code, which includes computer operation instructions.

[0217] The memory 1303 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.

[0218] The processor 1302 is used to execute computer execution instructions stored in the memory 1303 and control the receiving and sending actions of the transceiver 1301 to implement a SIM card-based authentication method.

[0219] The processor 1302 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application. The processor 1302 implements the SIM card-based authentication method by running instructions stored in the memory 1303.

[0220] Optionally, in specific implementations, if the transceiver 1301, processor 1302, and memory 1303 are implemented independently, they can be interconnected via a bus to complete communication. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc., but are not limited to a single bus or a single type of bus.

[0221] Optionally, in a specific implementation, if the transceiver 1301, processor 1302, and memory 1303 are integrated on a single chip, then the transceiver 1301, processor 1302, and memory 1303 can communicate through an internal interface.

[0222] Embodiment 13 of this application also provides a computer-readable storage medium, which may include various media capable of storing program code and user authentication data, such as SIM cards, USB flash drives, mobile hard drives, read-only memory (ROM), random access memory (RAM), disks, or optical discs. Specifically, the computer-readable storage medium stores program information, which is used for authentication.

[0223] This application also provides a program product, such as a computer-readable storage medium, which stores instructions that, when run on a computer, cause the computer to execute the SIM card-based authentication method provided in the above embodiments.

[0224] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0225] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A SIM card-based identity authentication method, characterized in that, Applied to trusted service management platforms, including: receiving login requests sent by terminal applications; Based on the login request, request data is generated, which includes the login request and the network certificate data stored in the trusted service management platform. The network certificate data contains user identity authentication information. The request data is sent to the SIM card of the terminal, so that the SIM card compares the network certificate data included in the request data with the network certificate data stored in the SIM card. If the comparison results are the same, the network certificate data included in the request data is encrypted using a symmetric encryption algorithm to generate encrypted network certificate data. Receive the encrypted network certificate data returned by the SIM card; The encrypted online ID data is decrypted using a symmetric encryption algorithm. If the online ID data is successfully decrypted, the user's identity authentication is successful. The decrypted e-ID data is sent to the terminal application so that the terminal application can log in using the decrypted e-ID data; Before receiving the login request sent by the terminal application, the method further includes: Receive the network license download request sent by the terminal application; The network certificate data is obtained from the network certificate platform according to the network certificate download request; The network certificate data is encrypted using the symmetric encryption algorithm to generate encrypted network certificate data, which is then stored in the trusted service management platform. The encrypted network certificate data is sent to the terminal via an encrypted SMS transmission link; The symmetric encryption algorithm is implemented by: grouping the network certificate data into first network certificate data, second network certificate data, and third network certificate data; using a key generation algorithm, fusing the key with the first network certificate data, second network certificate data, and third network certificate data respectively to generate a first subkey, a second subkey, and a third subkey; and inputting a first input, a second input, and a third input into a symmetric encryption function to generate the encrypted network certificate data, wherein the first input is a set composed of the first network certificate data and the first subkey, the second input is a set composed of the second network certificate data and the second subkey, and the third input is a set composed of the third network certificate data and the third subkey.

2. The method according to claim 1, characterized in that, The process of fusing the key with the first, second, and third online certificate data respectively includes one or more of the following: The key is fused with the first, second, and third network certificate data respectively through specific positioning permutations, inverse permutations, or shifts.

3. A SIM card-based identity authentication method, characterized in that, SIM cards used in user terminals include: Receive request data generated based on a login request from a trusted service management platform. The request data includes the login request and the network certificate data stored by the trusted service management platform. The network certificate data contains user identity authentication information. The network license data included in the request data is compared with the network license data stored in the SIM card of the terminal; If the comparison results are the same, the network certificate data included in the request data is encrypted using a symmetric encryption algorithm to generate encrypted network certificate data; The encrypted network certificate data is sent to the trusted service management platform; Before receiving the request data generated based on the login request sent by the trusted service management platform, the process also includes: Receive network certificate data encrypted by the Trusted Service Management Platform, which is sent by the Trusted Service Management Platform through an encrypted SMS transmission link; The encrypted network certificate data is decrypted using the symmetric encryption algorithm, and the decrypted network certificate data is stored in the SIM card of the terminal. The symmetric encryption algorithm is implemented by: grouping the network certificate data into first network certificate data, second network certificate data, and third network certificate data; using a key generation algorithm, fusing the key with the first network certificate data, second network certificate data, and third network certificate data respectively to generate a first subkey, a second subkey, and a third subkey; and inputting a first input, a second input, and a third input into a symmetric encryption function to generate the encrypted network certificate data, wherein the first input is a set composed of the first network certificate data and the first subkey, the second input is a set composed of the second network certificate data and the second subkey, and the third input is a set composed of the third network certificate data and the third subkey.

4. A SIM card-based identity authentication method, characterized in that, Applications used on user terminals include: Receive login requests entered by users in the interactive interface; The login request is sent to the Trusted Service Management Platform, which generates request data based on the login request and sends the request data to the SIM card of the terminal. The SIM card compares the network certificate data included in the request data with the network certificate data stored locally. If the comparison results are the same, the network certificate data is encrypted using a symmetric encryption algorithm and the encrypted network certificate data is returned. The Trusted Service Management Platform decrypts the encrypted network certificate data and determines that the user's identity authentication is successful when the decryption is successful. Receive the decrypted network certificate data from the trusted service management platform and log in using the network certificate data; The symmetric encryption algorithm is implemented by: grouping the network certificate data into first network certificate data, second network certificate data, and third network certificate data; using a key generation algorithm, fusing the key with the first network certificate data, second network certificate data, and third network certificate data respectively to generate a first subkey, a second subkey, and a third subkey; and inputting a first input, a second input, and a third input into a symmetric encryption function to generate the encrypted network certificate data, wherein the first input is a set composed of the first network certificate data and the first subkey, the second input is a set composed of the second network certificate data and the second subkey, and the third input is a set composed of the third network certificate data and the third subkey.

5. The method according to claim 4, characterized in that, After receiving the decrypted network certificate data from the trusted service management platform, the process further includes: Send a QR code acquisition request to the trusted service management platform; Receive the QR code sent by the trusted service management platform; The QR code is displayed to the user through the terminal interface and is used by the user to log in to other terminals.

6. A trusted service management platform, characterized in that, include: The receiving module is used to receive login requests sent by the terminal application; The generation module is used to generate request data based on the login request. The request data includes the login request and the network certificate data stored in the trusted service management platform. The network certificate data contains user identity authentication information. The sending module is used to send the request data to the SIM card of the terminal, so that the SIM card compares the network certificate data included in the request data with the network certificate data stored in the SIM card, and encrypts the network certificate data included in the request data using a symmetric encryption algorithm to generate encrypted network certificate data; The receiving module is also used to receive the network certificate data returned by the SIM card after encryption; The receiving module is also used to receive the network license download request sent by the terminal application; The network certificate data is obtained from the network certificate platform according to the network certificate download request; The network certificate data is encrypted using the symmetric encryption algorithm to generate encrypted network certificate data, which is then stored in the trusted service management platform. The encrypted network certificate data is sent to the terminal via an encrypted SMS transmission link; The decryption module is used to decrypt the encrypted network certificate data using a symmetric encryption algorithm. If the network certificate data is decrypted, the user's identity authentication is successful. The symmetric encryption algorithm is implemented by grouping the network certificate data into first network certificate data, second network certificate data, and third network certificate data; using a key generation algorithm, the keys are fused with the first network certificate data, second network certificate data, and third network certificate data respectively to generate a first subkey, a second subkey, and a third subkey; the first input, second input, and third input are input into a symmetric encryption function to generate the encrypted network certificate data. The first input is a set consisting of the first network certificate data and the first subkey; the second input is a set consisting of the second network certificate data and the second subkey; and the third input is a set consisting of the third network certificate data and the third subkey. The sending module is also used to send the decrypted network certificate data to the terminal application, so that the terminal application can log in using the decrypted network certificate data.

7. A SIM card for a user terminal, characterized in that, include: The receiving module is used to receive request data generated based on the login request sent by the trusted service management platform. The request data includes the login request and the network certificate data stored by the trusted service management platform. The network certificate data contains user identity authentication information. The comparison module is used to compare the network certificate data included in the request data with the network certificate data stored in the SIM card of the terminal; An encryption module is used to encrypt the network certificate data included in the request data using a symmetric encryption algorithm if the comparison results are the same, generating encrypted network certificate data. The symmetric encryption algorithm is implemented by grouping the network certificate data into first network certificate data, second network certificate data, and third network certificate data; using a key generation algorithm, fusing the keys with the first network certificate data, second network certificate data, and third network certificate data respectively to generate a first subkey, a second subkey, and a third subkey; and inputting a first input, a second input, and a third input into a symmetric encryption function to generate the encrypted network certificate data. The first input is a set composed of the first network certificate data and the first subkey; the second input is a set composed of the second network certificate data and the second subkey; and the third input is a set composed of the third network certificate data and the third subkey. The sending module is used to send the encrypted network certificate data to the trusted service management platform through a terminal application. The receiving module is also used to receive network certificate data encrypted by the Trusted Service Management Platform and sent by the Trusted Service Management Platform through the encrypted SMS transmission link; The encrypted network ID data is decrypted using the symmetric encryption algorithm, and the decrypted network ID data is stored in the SIM card of the terminal.

8. A user terminal, characterized in that, include: The receiving module is used to receive login requests entered by the user in the interactive interface; The sending module is used to send the login request to the trusted service management platform, so that the trusted service management platform generates request data according to the login request and sends the request data to the SIM card of the terminal. The SIM card compares the network certificate data included in the request data with the network certificate data stored locally. If the comparison results are the same, the network certificate data is encrypted using a symmetric encryption algorithm and the encrypted network certificate data is returned. The trusted service management platform decrypts the encrypted network certificate data and determines that the user's identity authentication is successful when the decryption is successful. The symmetric encryption algorithm is implemented by grouping the network certificate data into first network certificate data, second network certificate data, and third network certificate data; using a key generation algorithm, the key is fused with the first network certificate data, second network certificate data, and third network certificate data respectively to generate a first subkey, a second subkey, and a third subkey; the first input, the second input, and the third input are input into a symmetric encryption function to generate the encrypted network certificate data, wherein the first input is a set composed of the first network certificate data and the first subkey, the second input is a set composed of the second network certificate data and the second subkey, and the third input is a set composed of the third network certificate data and the third subkey. The receiving module is also used to receive the decrypted network certificate data from the trusted service management platform and to log in using the network certificate data.

9. A trusted service management platform, characterized in that, include: A processor, and a memory and a transceiver communicatively connected to the processor; The processor controls the receiving and transmitting actions of the transceiver; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in claim 1 or 2.

10. A SIM card for a user terminal, characterized in that, include: A processor, and a memory and a transceiver communicatively connected to the processor; The processor controls the receiving and transmitting actions of the transceiver; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in claim 3.

11. A user terminal, characterized in that, include: A processor, and a memory and a transceiver communicatively connected to the processor; The processor controls the receiving and transmitting actions of the transceiver; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in claim 4 or 5.

Citation Information

Patent Citations

  • Client security login method, device and system

    CN103312678A

  • Method for implementing trusted identity authentication by loading PKI based on SIM card

    CN109361697A