Access control initiation method, terminal, usim, and medium

By negotiating access control initiation devices and exchanging access control data with the USIM through the terminal, the problem of secure access when the USIM cannot provide access control rules is solved, enabling secure access to the USIM by the terminal, expanding the applicability of the USIM access control mechanism, and enhancing its versatility and security.

CN116684882BActive Publication Date: 2026-05-19CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA UNITED NETWORK COMM GRP CO LTD
Filing Date
2023-07-21
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

How can we securely initiate terminal access control to USIM when USIM cannot provide access control rules, in order to ensure the security of terminal access?

Method used

The terminal sends a remote access control initiation request to USIM, receives the initiating device specified by USIM, and exchanges access control access information and platform address, so that the initiating device can initiate remote access control based on the platform address and access information.

Benefits of technology

The scope of application of the USIM access control mechanism has been expanded, its versatility has been enhanced, and secure access to the USIM by the terminal in different scenarios has been ensured. The interaction capability of the card-machine interface has been enhanced, and the security of the USIM card and terminal applications has been comprehensively guaranteed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116684882B_ABST
    Figure CN116684882B_ABST
Patent Text Reader

Abstract

The application provides an access control initiation method, a terminal, a USIM and a medium, and relates to the technical field of communication, and is used for solving the problem of how to initiate access control to guarantee the security of terminal access to the USIM in the case that the USIM cannot provide access control rules, and the method comprises the following steps: sending a remote access control initiation request to a universal subscriber identity module (USIM); receiving a first response from the USIM, wherein the first response is used for specifying an initiation device of remote access control according to the remote access control initiation request; and providing access information of the remote access control to the initiation device, so that the initiation device initiates the remote access control according to the address and the access information after the address of a remote access control platform provided by the USIM is acquired. The application provides a new access control initiation method, and the method can ensure the security of terminal access to the USIM.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to an access control initiation method, a terminal, a USIM, and a computer-readable storage medium. Background Technology

[0002] In existing technologies, access control mechanisms for USIM cards typically rely on the USIM itself.

[0003] Access control rules are stored in the configuration file provided by the USIM. Sometimes, it's necessary to control terminal access to the USIM even when USIM doesn't provide access control rules, minimizing the impact of the configuration file's presence or absence on the access control mechanism. In such cases, how to initiate access control to ensure the security of terminal access to the USIM becomes a pressing issue. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing an access control initiation method, a terminal, a USIM, and a computer-readable storage medium, so as to solve the problem of how to initiate access control to ensure the security of terminal access to USIM when USIM cannot provide access control rules.

[0005] In a first aspect, the present invention provides an access control initiation method, applied to a terminal, the method comprising:

[0006] Send a remote access control initiation request to the Universal User Identification Module (USIM);

[0007] Receive the first response from USIM, which is specified by USIM as the initiating device of the remote access control request;

[0008] Provide the initiating device with access information for remote access control, so that the initiating device, after also obtaining the address of the remote access control platform provided by USIM, can initiate remote access control based on the address and access information.

[0009] Optionally, a remote access control initiation request may be sent to the USIM, specifically including:

[0010] In response to the terminal application's access request to the USIM application, check whether the USIM has the corresponding access control rules;

[0011] If not, generate a remote access control initiation request that includes information on whether the terminal has the capability to initiate remote access control, and send it to USIM.

[0012] Optionally, access information for remote access control is provided to the initiating device, so that after obtaining the address of the remote access control platform provided by USIM, the initiating device initiates remote access control based on the address and access information, specifically including:

[0013] After parsing the first response and confirming that the initiating device for remote access control specified in the first response is USIM, a second response is sent to USIM. The second response includes the terminal application identifier with access request, the USIM application identifier, and the digest certificate for remote access control. This enables USIM to obtain the address of the remote access control platform based on the terminal application identifier and the USIM application identifier, and then initiate remote access control to the corresponding remote access control platform based on the address, the terminal application identifier, the USIM application identifier, and the digest certificate.

[0014] Optionally, access information for remote access control is provided to the initiating device, so that after obtaining the address of the remote access control platform provided by USIM, the initiating device initiates remote access control based on the address and access information, specifically including:

[0015] After parsing the first response and confirming that the initiating device for the remote access control specified in the first response is a terminal, a third response is sent to the USIM. The third response includes the terminal application identifier with access request and the USIM application identifier.

[0016] Receive the remote access control entity command sent by USIM. The remote access control entity command includes the address of the remote access control platform obtained based on the terminal application identifier and the USIM application identifier.

[0017] It obtains the terminal application identifier and USIM application identifier that require access, as well as the digest certificate for remote access control, and initiates remote access control to the corresponding remote access control platform based on the address, terminal application identifier, USIM application identifier, and digest certificate.

[0018] Optionally, a second / third response may be sent to the USIM, specifically including:

[0019] Receive the Access Provide Data command sent by USIM, and send a second / third response to USIM according to the Access Provide Data command.

[0020] Secondly, the present invention provides an access control initiation method applied to a Universal User Identification Module (USIM), the method comprising:

[0021] Receive a remote access control request from the terminal;

[0022] The first response is sent to the terminal. The first response is initiated by the device that initiated the remote access control, as specified by USIM in the remote access control request.

[0023] The address of the remote access control platform is provided to the initiating device so that the initiating device can initiate remote access control based on the address and access information after obtaining the remote access control access information provided by the terminal.

[0024] Optionally, USIM does not have access control rules corresponding to the access requirements of terminal applications to USIM applications;

[0025] The remote access control request includes information on whether the terminal has the capability to initiate remote access control.

[0026] Optionally, the address of the remote access control platform is provided to the initiating device, so that after obtaining the remote access control access information provided by the terminal, the initiating device initiates remote access control based on the address and access information, specifically including:

[0027] If the initiating device for remote access control specified in the first response is USIM, then a second response is received from the terminal, which includes the terminal application identifier with access request, the USIM application identifier, and the digest certificate of the remote access control.

[0028] The system parses the second response, obtains the address of the remote access control platform based on the terminal application identifier and the USIM application identifier, and initiates remote access control to the corresponding remote access control platform based on the address, the terminal application identifier, the USIM application identifier, and the digest certificate.

[0029] Optionally, the address of the remote access control platform is provided to the initiating device, so that after obtaining the remote access control access information provided by the terminal, the initiating device initiates remote access control based on the address and access information, specifically including:

[0030] If the device initiating the remote access control specified in the first response is a terminal, then a third response from the terminal is received, which includes the terminal application identifier and the USIM application identifier that have the access request.

[0031] According to the third response, a remote access control entity command is sent to the terminal. The remote access control entity command includes the address of the remote access control platform obtained based on the terminal application identifier and the USIM application identifier. This enables the terminal to initiate remote access control to the corresponding remote access control platform after it has obtained the terminal application identifier and USIM application identifier that require access, as well as the digest certificate of the remote access control, based on the address, the terminal application identifier and the USIM application identifier and the digest certificate.

[0032] Optionally, after sending the first response to the terminal, the method further includes:

[0033] Send an access data command to the terminal so that the terminal sends a second / third response in response to the access data command.

[0034] Thirdly, the present invention provides a terminal, the terminal comprising:

[0035] The first sending module is used to send a remote access control initiation request to the Universal User Identification Module (USIM).

[0036] The first receiving module, connected to the first sending module, is used to receive a first response from the USIM. The first response is initiated by the USIM based on the remote access control request, specifying the initiating device of the remote access control.

[0037] The first execution module, connected to the first receiving module, is used to provide access information for remote access control to the initiating device, so that the initiating device, after obtaining the address of the remote access control platform provided by USIM, can initiate remote access control based on the address and access information.

[0038] Fourthly, the present invention provides a Universal User Identification Module (USIM), the USIM comprising:

[0039] The second receiving module is used to receive remote access control initiation requests from the terminal;

[0040] The second sending module, connected to the second receiving module, is used to send a first response to the terminal. The first response is initiated by the USIM according to the remote access control initiation request, specifying the initiating device of the remote access control.

[0041] The second execution module, connected to the second sending module, is used to provide the address of the remote access control platform to the initiating device, so that the initiating device, after obtaining the remote access control access information provided by the terminal, can initiate remote access control based on the address and access information.

[0042] Fifthly, the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the access control initiation method as described above.

[0043] This invention provides an access control initiation method, a terminal, a USIM (United States Information Modeling System), and a computer-readable storage medium. The terminal sends a remote access control initiation request to the USIM, which then designates the initiating device for the remote access control. Both the terminal and the USIM provide the designated initiating device with the necessary access information and platform address for the remote access control, enabling the initiating device to initiate remote access control based on the platform address and access information. This method determines the initiation conditions for remote access control through data exchange between the terminal and the USIM. It proposes a novel access control initiation method that ensures the security of subsequent terminal access to the USIM, expands the applicability of the USIM access control mechanism, enhances its versatility, and better adapts to the needs of secure terminal access to the USIM in different scenarios. Attached Figure Description

[0044] Figure 1 This is a flowchart of an access control initiation method according to an embodiment of the present invention;

[0045] Figure 2 This is a flowchart of another access control initiation method according to an embodiment of the present invention;

[0046] Figure 3 This is a flowchart of another access control initiation method according to an embodiment of the present invention;

[0047] Figure 4 This is a schematic diagram of the structure of a terminal according to an embodiment of the present invention;

[0048] Figure 5 This is a schematic diagram of the structure of a USIM according to an embodiment of the present invention. Detailed Implementation

[0049] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0050] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.

[0051] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.

[0052] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.

[0053] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.

[0054] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.

[0055] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of the invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.

[0056] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.

[0057] To facilitate understanding of this invention, the USIM access control mechanism and a possible application scenario of this invention will be introduced first.

[0058] USIM (Universal Subscriber Identity Module) is one of the basic devices used by mobile users. It is used to store user identity information and personal data, ensure the security of access to mobile network services, and can use necessary functions and data to perform user identification and authorization when users access mobile network services, so as to enable the mobile network to represent and identify user applications.

[0059] As a user terminal device used in conjunction with mobile terminals, the interaction requirements between USIM and terminals are constantly increasing, including the interaction between terminal applications and USIM. As a device that stores sensitive information, USIM has relatively high security requirements. Terminal applications cannot easily access USIM, especially non-system applications, whose access to USIM requires even more security mechanisms.

[0060] Therefore, to support secure access to USIM by end applications, international standards have established a common access control mechanism, GPAC (Global Platform Access Control), for devices such as USIM. This allows USIM to provide unified management access control rules, which can be stored in USIM's rule file or rule application. The terminal has an access control module that manages secure access by end applications. This module can read the rules through a file / application interface and determine whether access is allowed based on the rules when the end application accesses USIM through the interface. Because access control rules reflect the will of the USIM data owner, in the traditional model, the file / application storing the rules is part of the USIM configuration file.

[0061] In traditional USIM cards, the USIM card and configuration file are inseparable; the configuration file is present from the moment the USIM card is manufactured and issued. However, with the emergence of new USIM card forms in recent years, this situation has changed. For example, for eSIM (Embedded-SIM), which supports remote download and management of configuration files, the configuration file is only downloaded to the eSIM card via the network when the user selects an operator to activate their account. Before that, for a considerable period, the eSIM does not have an operator configuration file, which affects the implementation prerequisites of some existing solutions, including the SIM (Subscriber Identity Module) card access control mechanism. In most cases, the original solution is applicable; that is, the eSIM only enters the formal application stage after the user activates the network and downloads the configuration file. The downloaded configuration file contains access control rules / applications, and the application on the user's terminal can access the eSIM under the control of the rules. However, in some scenarios, such as when the operator needs to perform the network activation operation through the terminal application, the configuration file has not yet been downloaded, but the terminal application still needs to access the eSIM. In this case, how to securely access the eSIM without access control rules becomes a significant problem.

[0062] Therefore, this invention proposes a method for initiating remote access control from a terminal or USIM. This requires the terminal to exchange data with the USIM and determine the preconditions for initiating remote access control. This method can initiate access control even when the USIM cannot provide access control rules, thereby ensuring the security of the terminal's access to the USIM. This expands the applicability of the USIM access control mechanism, enhances its versatility, better adapts to the needs of terminal applications for secure access to the USIM in different scenarios, enhances the interaction capabilities of the card-machine interface in this regard, provides a feasible solution for the implementation of more services, and more comprehensively ensures the security of the USIM card and terminal applications.

[0063] Example 1:

[0064] like Figure 1 As shown, Embodiment 1 of the present invention provides an access control initiation method applied to a terminal, the method comprising:

[0065] S11. Send a remote access control initiation request to the Universal User Identification Module (USIM).

[0066] S12. Receive the first response from USIM, the first response being specified by USIM as the initiating device of the remote access control based on the remote access control initiation request;

[0067] S13. Provide the initiating device with access information for remote access control, so that the initiating device, after obtaining the address of the remote access control platform provided by USIM, can initiate remote access control based on the address and access information.

[0068] Specifically, in this embodiment, as Figure 1 The method described primarily involves negotiating the initiating device for access control and exchanging access control data (i.e., access information and platform address) between the terminal and USIM. This method can be applied to terminals, specifically mobile terminals. The terminal sends a remote access control initiation request to USIM, which then designates the initiating device. Both the terminal and USIM provide the required access information and platform address to the designated initiating device, enabling the initiating device to initiate remote access control based on the platform address and access information. Specifically, the initiating device sends a remote access control request containing access information to the corresponding remote access control platform to initiate remote access control. This method determines the initiation conditions for remote access control through data exchange between the terminal and USIM, proposing a novel access control initiation method. This method ensures the security of subsequent terminal access to USIM, expands the applicability of the USIM access control mechanism, enhances its versatility, and better adapts to the needs of secure terminal access to USIM in different scenarios. It should be noted that after the method in this embodiment, the remote access control platform will determine whether to allow the corresponding access process based on the access information. If allowed, the terminal's access requirements for USIM can be met. However, the main purpose of this embodiment is the negotiation and data exchange before the remote access control is initiated. How the remote access control process and the access process are implemented does not affect the implementation of this invention.

[0069] Optionally, a remote access control initiation request may be sent to the USIM, specifically including:

[0070] In response to the terminal application's access request to the USIM application, check whether the USIM has the corresponding access control rules;

[0071] If not, generate a remote access control initiation request that includes information on whether the terminal has the capability to initiate remote access control, and send it to USIM.

[0072] Specifically, in this embodiment, when a terminal application initiates a request to access the USIM application, the terminal access control module first determines whether the current USIM has access control rules in the configuration file. If no access control rules are available, the terminal access control module can propose to the USIM that a request for remote access control of the terminal application's access to the USIM application needs to be initiated with the remote access control platform, and provide information on whether the terminal supports remote access control. After receiving the terminal's proposal, the USIM determines the device initiating the remote access control and synchronizes this information to the terminal via a first response message. Subsequently, the USIM requests the basic data that the terminal needs to access from the USIM via an active command. Based on the USIM's determination of the device initiating the remote access control, the terminal determines the data content that needs to be provided. After receiving the data content provided by the terminal, the USIM analyzes and obtains the remote access control platform information. If the remote access control is initiated by the access control module to the remote access control platform, the platform information is provided to the access control module, and then the terminal initiates the remote access control. If the remote access control is initiated by the USIM, the platform information does not need to be provided to the terminal, and then the USIM initiates the remote access control. To implement this solution, it is necessary to extend the commands for the terminal's access control module and USIM. These commands can be implemented based on the USAT (USIM Application Toolkit) protocol. The first extended command is a remote access control request, which proposes to the USIM system that a remote access control request be initiated to the remote access control platform. This first command can be named Remote Access Control Request, and its specific definition is shown in Table 1 below.

[0073] Table 1 Example of Remote Access Control Request Structure

[0074]

[0075]

[0076] In Table 1, the remote access control device capability is a data object added according to the USAT mechanism. It is mandatory in this command. When using this command in this application, only b2 can be used, which indicates whether the terminal supports initiating remote access control.

[0077] Optionally, the first response specifies that the initiating device for remote access control is a terminal or a USIM.

[0078] Specifically, in this embodiment, after receiving the Remote Access Control Request, the USIM will generate a corresponding response, which we will call the first response. The specific definitions are shown in Table 2 below:

[0079] Table 2 Example of First Response Structure

[0080]

[0081] In Table 2, the Remote Access Control Device is a newly added data object and is required in the first response. It represents the device that the USIM requires to initiate the remote access control task, including two possibilities: the Terminal Access Control Module and the USIM.

[0082] Optionally, access information for remote access control is provided to the initiating device, so that after obtaining the address of the remote access control platform provided by USIM, the initiating device initiates remote access control based on the address and access information, specifically including:

[0083] After parsing the first response and confirming that the initiating device for remote access control specified in the first response is USIM, a second response is sent to USIM. The second response includes the terminal application identifier with access request, the USIM application identifier, and the digest certificate for remote access control. This enables USIM to obtain the address of the remote access control platform based on the terminal application identifier and the USIM application identifier, and then initiate remote access control to the corresponding remote access control platform based on the address, the terminal application identifier, the USIM application identifier, and the digest certificate.

[0084] Specifically, in this embodiment, the access information includes the terminal application identifier and the USIM application identifier, and may also include a digest certificate. Based on the result of the USIM determining the initiating remote access control device in the previous step, the terminal returns different access USIM data through a Terminal Response (for Provide Access Data) message. Let's refer to the Terminal Response (for Provide Access Data) when the initiating device is USIM as the second response, and the Terminal Response (for Provide Access Data) when the initiating device is the terminal as the third response. The specific definitions are shown in Table 3 below:

[0085] Table 3 Examples of Second / Third Response Structures

[0086]

[0087] In Table 3, the USIM application identifier is a mandatory data object in both the second and third responses. It represents the identifier of the USIM application that the terminal application requests access to, and is represented in the form of AID (Application Identity). USIM obtains access control platform information by querying the USIM application with the specified AID. The terminal application identifier is also a mandatory data object, representing the identifier of the terminal application that requests access to the USIM application. It can also be one of the base information for the USIM application to determine the access control platform. The certificate digest is a conditionally mandatory data object. It must exist when the initiating remote access control device is determined to be USIM in the previous step (i.e., it must exist in the second response). The access control platform determines whether the identity of the terminal application that needs to access USIM is legitimate by comparing and verifying the certificate digest. It does not exist when the initiating remote access control device is a terminal (i.e., it does not exist in the third response).

[0088] Optionally, access information for remote access control is provided to the initiating device, so that after obtaining the address of the remote access control platform provided by USIM, the initiating device initiates remote access control based on the address and access information, specifically including:

[0089] After parsing the first response and confirming that the initiating device for the remote access control specified in the first response is a terminal, a third response is sent to the USIM. The third response includes the terminal application identifier with access request and the USIM application identifier.

[0090] Receive the remote access control entity command sent by USIM. The remote access control entity command includes the address of the remote access control platform obtained based on the terminal application identifier and the USIM application identifier.

[0091] It obtains the terminal application identifier and USIM application identifier that require access, as well as the digest certificate for remote access control, and initiates remote access control to the corresponding remote access control platform based on the address, terminal application identifier, USIM application identifier, and digest certificate.

[0092] Specifically, in this embodiment, after receiving the data, the USIM queries the address information of the access control platform from the designated USIM application based on the AID, and provides the platform address to the terminal by adding a new proactive command, Remote Access Control Entity. The specific definition of this command is shown in Table 4 below:

[0093] Table 4 Example of Remote Access Control Entity Command Structure

[0094]

[0095]

[0096] In Table 4, the Access Control Platform URL is a required data object, representing the URL of the remote access control platform provided to the terminal to initiate remote access control.

[0097] Optionally, a second / third response may be sent to the USIM, specifically including:

[0098] Receive the Access Provide Data command sent by USIM, and send a second / third response to USIM according to the Access Provide Data command.

[0099] Specifically, in this embodiment, USIM needs to obtain the data required for this USIM access from the terminal access control module through a newly added proactive command. USIM requests the terminal to provide the data required for this USIM access. The command type indicates the function of this command. The reasons for setting this command are twofold: first, the scenario of this embodiment is for terminal application accessing USIM application, in which USIM plays a control role, and it is more suitable for USIM to proactively initiate the data exchange process; second, the current USAT mechanism completes each process with a pair of command responses. This command can be named Provide Access Data, and its specific definition is shown in Table 5 below.

[0100] Table 5 provides an example of the access data command structure.

[0101]

[0102] This embodiment primarily aims to enable remote access control interaction between the terminal and USIM when the USIM cannot provide access control rules and the terminal application needs to access the USIM. This provides more comprehensive security for both the USIM card and the terminal application. An example of a complete access control initiation process is shown below. Figure 2 As shown:

[0103] S001: Generates a terminal application's access request to the USIM application. Specifically, on the terminal, the terminal application generates a request to access the USIM application and submits the request to the terminal access control module.

[0104] S002: The terminal detected that the USIM does not have access control rules. Specifically, the terminal access control module requested to read the USIM access control rules and found that the USIM does not have access control rules due to reasons such as the lack of a configuration file.

[0105] S003: The terminal sends a remote access control initiation request to the USIM. Specifically, the terminal generates a Remote Access Control Request command to request the access control platform to access the USIM. The command includes a description of whether the terminal supports the ability to initiate remote access control, i.e. whether the terminal access control module supports initiating remote access control. The command is then sent to the USIM. The specific structure of the command is shown in Table 1 above.

[0106] S004: The USIM specifies whether the initiating device for this remote access control is a terminal or the USIM. Specifically, after receiving the Remote Access Control Request command, the USIM parses the command to obtain its content. Based on the terminal's capabilities and its own capabilities and circumstances, it determines whether the initiating device for this remote access control is a terminal or the USIM.

[0107] If the remote access control capability b2 = 0, meaning the terminal does not support initiating remote access control, then the device initiating this remote access control is the USIM.

[0108] If the remote access control capability b2=1 and the USIM policy is configured to initiate remote access control, then the device initiating this remote access control is the USIM.

[0109] If the remote access control capability b2=1, and the accessed USIM application policy is configured to initiate remote access control, then the device initiating this remote access control is the USIM.

[0110] If the remote access control capability b2=1, the USIM determines that the current situation is not suitable for initiating remote access control, and the device that initiates this remote access control is a terminal, etc.

[0111] S005: USIM sends a first response to the terminal. Specifically, based on the result of determining whether the device initiating this remote access control is the terminal or USIM, USIM generates a response message and sends it to the terminal. After receiving the response message, the terminal learns about the device requirements of USIM for this remote access control. The specific structure of the response message is shown in Table 2 above.

[0112] S006: USIM sends a command to the terminal to provide access data. Specifically, USIM generates a command to provide access data, which requests the terminal to provide basic data for the terminal application to access USIM, and sends the command to the terminal. The specific structure of the command is shown in Table 5 above.

[0113] S007: The terminal determines whether the initiating device is a USIM. Specifically, after receiving the Provide Access Data command, the terminal parses the command and the first response, and determines whether the initiating device identified in the first response is a USIM. If it is, proceed to step S008; otherwise, proceed to step S009.

[0114] S008: The terminal sends a second response to the USIM, which includes the application identifier and digest certificate. Specifically, if the initiating device is the USIM, the terminal generates a second response which includes the application identifier (AID and terminal application name) and digest certificate, and sends it to the USIM.

[0115] S009: The terminal sends a third response to the USIM, which includes the application identifier. Specifically, if the initiating device is not the USIM but the terminal access control module, the terminal generates a third response containing only the application identifier (AID and terminal application name) and sends it to the USIM.

[0116] S010: USIM obtains the remote access control platform address based on the application identifier. Specifically, when USIM receives the terminal response message, it obtains the access control platform address information corresponding to the USIM application from the USIM application with the specified AID. Since different terminal applications that request access to the same USIM application may correspond to accessing different control platform addresses, the name of the terminal application accessing USIM may also be one of the bases for USIM application to determine the access control platform.

[0117] S011: USIM determines whether the initiating device is a USIM. Specifically, USIM determines whether the initiating device determined in step S004 is a USIM. If it is, continue to the subsequent step S012; otherwise, proceed to step S013.

[0118] S012: USIM initiates remote access control based on the address and access information. Specifically, USIM retains the access control platform address information obtained, and combines it with the application identifier (AID and terminal application name) and digest certificate sent in step S008 to initiate remote access control to the remote access control platform corresponding to the platform address.

[0119] S013: USIM sends a remote access control entity command to the terminal, which includes the platform address. Specifically, USIM generates the remote access control entity command Remote Access Control Entity and sends it to the terminal, providing the terminal with access control platform address information. The specific structure of the command is shown in Table 4 above.

[0120] S014: The terminal initiates remote access control based on the address and access information. Specifically, after receiving the RemoteAccess Control Entity command, the terminal parses the command to obtain the access control platform address information, and can subsequently initiate remote access control by combining the application identifier (AID and terminal application name) and digest certificate.

[0121] This embodiment 1 addresses the problem that access control for terminal applications accessing USIM applications is difficult to achieve due to the lack of access control rules in USIM caused by the absence of configuration files and other reasons. It proposes a method for the terminal or USIM to initiate remote access control, exchange data, and determine necessary information. It proposes the idea of ​​using remote access control as a supplement to USIM local control, while retaining the USIM's dominant role. It expands a series of commands for remote access control requests, providing access data, and informing remote access control entities, and adds definitions for its functional requirements, command structure, and parameter definitions. It also specifies the steps, procedures, and rules for interaction between the terminal and USIM.

[0122] Example 2:

[0123] like Figure 3 As shown, Embodiment 2 of the present invention provides an access control initiation method applied to a Universal User Identification Module (USIM), the method comprising:

[0124] S21. Receive a remote access control initiation request from the terminal;

[0125] S22. Send a first response to the terminal. The first response is initiated by the USIM based on the remote access control request, specifying the initiating device of the remote access control.

[0126] S23. Provide the initiating device with the address of the remote access control platform, so that the initiating device, after obtaining the remote access control access information provided by the terminal, can initiate remote access control based on the address and access information.

[0127] Optionally, USIM does not have access control rules corresponding to the access requirements of terminal applications to USIM applications;

[0128] The remote access control request includes information on whether the terminal has the capability to initiate remote access control.

[0129] Optionally, the address of the remote access control platform is provided to the initiating device, so that after obtaining the remote access control access information provided by the terminal, the initiating device initiates remote access control based on the address and access information, specifically including:

[0130] If the initiating device for remote access control specified in the first response is USIM, then a second response is received from the terminal, which includes the terminal application identifier with access request, the USIM application identifier, and the digest certificate of the remote access control.

[0131] The system parses the second response, obtains the address of the remote access control platform based on the terminal application identifier and the USIM application identifier, and initiates remote access control to the corresponding remote access control platform based on the address, the terminal application identifier, the USIM application identifier, and the digest certificate.

[0132] Optionally, the address of the remote access control platform is provided to the initiating device, so that after obtaining the remote access control access information provided by the terminal, the initiating device initiates remote access control based on the address and access information, specifically including:

[0133] If the device initiating the remote access control specified in the first response is a terminal, then a third response from the terminal is received, which includes the terminal application identifier and the USIM application identifier that have the access request.

[0134] According to the third response, a remote access control entity command is sent to the terminal. The remote access control entity command includes the address of the remote access control platform obtained based on the terminal application identifier and the USIM application identifier. This enables the terminal to initiate remote access control to the corresponding remote access control platform after it has obtained the terminal application identifier and USIM application identifier that require access, as well as the digest certificate of the remote access control, based on the address, the terminal application identifier and the USIM application identifier and the digest certificate.

[0135] Optionally, after sending the first response to the terminal, the method further includes:

[0136] Send an access data command to the terminal so that the terminal sends a second / third response in response to the access data command.

[0137] The method described in Example 2 can be specifically applied to USIM, and the detailed interaction process is as follows: Figure 2 As shown, for Figure 2 The explanations and details of the information exchanged, as well as the specific structure of the information, have been described in detail in Example 1.

[0138] Example 3:

[0139] like Figure 4 As shown, Embodiment 3 of the present invention provides a terminal, the terminal comprising:

[0140] The first sending module 11 is used to send a remote access control initiation request to the Universal User Identification Module (USIM);

[0141] The first receiving module 12 is connected to the first sending module 11 and is used to receive a first response from the USIM. The first response is provided by the USIM, which specifies the initiating device of the remote access control based on the remote access control initiation request.

[0142] The first execution module 13, connected to the first receiving module 12, is used to provide access information for remote access control to the initiating device, so that the initiating device, after obtaining the address of the remote access control platform provided by USIM, can initiate remote access control based on the address and access information.

[0143] Optionally, the first transmitting module 11 specifically includes:

[0144] The first detection unit is used to detect whether the USIM has the corresponding access control rules in response to the terminal application's access request to the USIM application.

[0145] The first sending unit is used to generate a remote access control initiation request, including information on whether the terminal has the ability to initiate remote access control, and send it to the USIM if the USIM does not have access control rules.

[0146] Optionally, the first execution module 13 is specifically used for:

[0147] After parsing the first response and confirming that the initiating device for remote access control specified in the first response is USIM, a second response is sent to USIM. The second response includes the terminal application identifier with access request, the USIM application identifier, and the digest certificate for remote access control. This enables USIM to obtain the address of the remote access control platform based on the terminal application identifier and the USIM application identifier, and then initiate remote access control to the corresponding remote access control platform based on the address, the terminal application identifier, the USIM application identifier, and the digest certificate.

[0148] Optionally, the first execution module 13 is specifically used for:

[0149] After parsing the first response and confirming that the initiating device for the remote access control specified in the first response is a terminal, a third response is sent to the USIM. The third response includes the terminal application identifier with access request and the USIM application identifier.

[0150] Receive the remote access control entity command sent by USIM. The remote access control entity command includes the address of the remote access control platform obtained based on the terminal application identifier and the USIM application identifier.

[0151] It obtains the terminal application identifier and USIM application identifier that require access, as well as the digest certificate for remote access control, and initiates remote access control to the corresponding remote access control platform based on the address, terminal application identifier, USIM application identifier, and digest certificate.

[0152] Optionally, a second / third response may be sent to the USIM, specifically including:

[0153] Receive the Access Provide Data command sent by USIM, and send a second / third response to USIM according to the Access Provide Data command.

[0154] Example 4:

[0155] like Figure 5 As shown, Embodiment 4 of the present invention provides a Universal User Identification Module (USIM), the USIM comprising:

[0156] The second receiving module 21 is used to receive remote access control initiation requests from the terminal;

[0157] The second sending module 22, connected to the second receiving module 21, is used to send a first response to the terminal. The first response is initiated by the USIM according to the remote access control initiation request, specifying the initiating device of the remote access control.

[0158] The second execution module 23, connected to the second sending module 22, is used to provide the address of the remote access control platform to the initiating device, so that the initiating device can initiate remote access control based on the address and access information after obtaining the remote access control access information provided by the terminal.

[0159] Optionally, USIM does not have access control rules corresponding to the access requirements of terminal applications to USIM applications;

[0160] The remote access control request includes information on whether the terminal has the capability to initiate remote access control.

[0161] Optionally, the second execution module 23 is specifically used for:

[0162] If the initiating device for remote access control specified in the first response is USIM, then a second response is received from the terminal, which includes the terminal application identifier with access request, the USIM application identifier, and the digest certificate of the remote access control.

[0163] The system parses the second response, obtains the address of the remote access control platform based on the terminal application identifier and the USIM application identifier, and initiates remote access control to the corresponding remote access control platform based on the address, the terminal application identifier, the USIM application identifier, and the digest certificate.

[0164] Optionally, the second execution module 23 is specifically used for:

[0165] If the device initiating the remote access control specified in the first response is a terminal, then a third response from the terminal is received, which includes the terminal application identifier and the USIM application identifier that have the access request.

[0166] According to the third response, a remote access control entity command is sent to the terminal. The remote access control entity command includes the address of the remote access control platform obtained based on the terminal application identifier and the USIM application identifier. This enables the terminal to initiate remote access control to the corresponding remote access control platform after it has obtained the terminal application identifier and USIM application identifier that require access, as well as the digest certificate of the remote access control, based on the address, the terminal application identifier and the USIM application identifier and the digest certificate.

[0167] Optionally, the second transmitting module 22 is also used for:

[0168] Send an access data command to the terminal so that the terminal sends a second / third response in response to the access data command.

[0169] Example 5:

[0170] Embodiment 5 of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the access control initiation method as described in Embodiment 1 or 2.

[0171] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.

[0172] In addition, the present invention may also provide a computer device including a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the access control initiation method as described in Embodiment 1 or 2.

[0173] The memory is connected to the processor. The memory can be flash memory, read-only memory or other types of memory. The processor can be a central processing unit or a microcontroller.

[0174] Furthermore, the present invention may also provide an access control initiation system, including a terminal for implementing the access control initiation method as described in Embodiment 1, a USIM for implementing the access control initiation method as described in Embodiment 2, and a remote access control platform for storing access control rules for terminal applications to access USIM applications and providing remote access control according to the access control rules.

[0175] Embodiments 1-5 of this invention provide an access control initiation method, a terminal, a USIM, and a computer-readable storage medium. The terminal sends a remote access control initiation request to the USIM, which designates the initiating device for the remote access control. Then, the terminal and USIM respectively provide the designated initiating device with the access information and platform address required for remote access control, enabling the initiating device to initiate remote access control based on the platform address and access information. This method determines the initiation conditions for remote access control through data exchange between the terminal and the USIM, proposing a novel access control initiation method. This method ensures the security of subsequent terminal access to the USIM, expands the applicability of the USIM access control mechanism, enhances its versatility, and better adapts to the needs of secure terminal access to the USIM in different scenarios.

[0176] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.

Claims

1. An access control initiation method, characterized in that, Applied to a terminal, the method includes: Send a remote access control initiation request to the Universal User Identification Module (USIM), specifically including: In response to the terminal application's access request to the USIM application, it checks whether the USIM has the corresponding access control rules. If not, generate a Remote Access Control Initiation Request (RAI) including information on whether the terminal has the capability to initiate remote access control, and send it to USIM. USIM is an eSIM that supports remote download and management of configuration files. Before a user joins the network and downloads the configuration file, USIM does not have corresponding access control rules. Receive the first response from USIM. The first response is initiated by USIM based on the remote access control request, specifying the initiating device of the remote access control. The initiating device is either USIM or a terminal. The system provides the initiating device with access information for remote access control. This access information includes the terminal application identifier with access requirements, the USIM application identifier, and the digest certificate for remote access control. This enables the initiating device to initiate remote access control based on the address and access information after obtaining the address of the remote access control platform provided by USIM.

2. The method according to claim 1, characterized in that, Provide the initiating device with access information for remote access control, so that after obtaining the address of the remote access control platform provided by USIM, the initiating device can initiate remote access control based on the address and access information, specifically including: After parsing the first response and confirming that the initiating device for remote access control specified in the first response is USIM, a second response is sent to USIM. The second response includes the terminal application identifier with access request, the USIM application identifier, and the digest certificate for remote access control. This enables USIM to obtain the address of the remote access control platform based on the terminal application identifier and the USIM application identifier, and then initiate remote access control to the corresponding remote access control platform based on the address, the terminal application identifier, the USIM application identifier, and the digest certificate.

3. The method according to claim 1, characterized in that, Provide the initiating device with access information for remote access control, so that after obtaining the address of the remote access control platform provided by USIM, the initiating device can initiate remote access control based on the address and access information, specifically including: After parsing the first response and confirming that the initiating device for the remote access control specified in the first response is a terminal, a third response is sent to the USIM. The third response includes the terminal application identifier with access request and the USIM application identifier. Receive the remote access control entity command sent by USIM. The remote access control entity command includes the address of the remote access control platform obtained based on the terminal application identifier and the USIM application identifier. It obtains the terminal application identifier and USIM application identifier that require access, as well as the digest certificate for remote access control, and initiates remote access control to the corresponding remote access control platform based on the address, terminal application identifier, USIM application identifier, and digest certificate.

4. The method according to claim 2 or 3, characterized in that, Send a second / third response to USIM, specifically including: Receive the Access Provide Data command sent by USIM, and send a second / third response to USIM according to the Access Provide Data command.

5. An access control initiation method, characterized in that, The method, applied to the Universal User Identification Module (USIM), includes: Receive a remote access control initiation request from the terminal. The remote access control initiation request includes information on whether the terminal has the capability to initiate remote access control. USIM does not have access control rules corresponding to the access requirements of terminal applications to USIM applications. USIM is an eSIM that supports remote download and management of configuration files. Before the user joins the network and downloads the configuration file, USIM does not have corresponding access control rules. The first response is sent to the terminal. The first response is initiated by the USIM based on the remote access control request, which specifies the initiating device of the remote access control. The initiating device is either the USIM or the terminal. The address of the remote access control platform is provided to the initiating device so that, after obtaining the remote access control access information provided by the terminal, the initiating device can initiate remote access control based on the address and access information. The access information includes the terminal application identifier and USIM application identifier with access requirements, as well as the digest certificate of the remote access control.

6. The method according to claim 5, characterized in that, The address of the remote access control platform is provided to the initiating device so that, after obtaining the remote access control access information provided by the terminal, the initiating device can initiate remote access control based on the address and access information. Specifically, this includes: If the initiating device for remote access control specified in the first response is USIM, then a second response is received from the terminal, which includes the terminal application identifier with access request, the USIM application identifier, and the digest certificate of the remote access control. The system parses the second response, obtains the address of the remote access control platform based on the terminal application identifier and the USIM application identifier, and initiates remote access control to the corresponding remote access control platform based on the address, the terminal application identifier, the USIM application identifier, and the digest certificate.

7. The method according to claim 5, characterized in that, The address of the remote access control platform is provided to the initiating device so that, after obtaining the remote access control access information provided by the terminal, the initiating device can initiate remote access control based on the address and access information. Specifically, this includes: If the device initiating the remote access control specified in the first response is a terminal, then a third response from the terminal is received, which includes the terminal application identifier and the USIM application identifier that have the access request. According to the third response, a remote access control entity command is sent to the terminal. The remote access control entity command includes the address of the remote access control platform obtained based on the terminal application identifier and the USIM application identifier. This enables the terminal to initiate remote access control to the corresponding remote access control platform after it has obtained the terminal application identifier and USIM application identifier that require access, as well as the digest certificate of the remote access control, based on the address, the terminal application identifier and the USIM application identifier and the digest certificate.

8. The method according to claim 6 or 7, characterized in that, After sending the first response to the terminal, the method further includes: Send an access data command to the terminal so that the terminal sends a second / third response in response to the access data command.

9. A terminal, characterized in that, The terminal includes: The first sending module is used to send a remote access control initiation request to the Universal User Identification Module (USIM), specifically including: In response to the terminal application's access request to the USIM application, it checks whether the USIM has the corresponding access control rules. If not, generate a Remote Access Control Initiation Request (RAI) including information on whether the terminal has the capability to initiate remote access control, and send it to USIM. USIM is an eSIM that supports remote download and management of configuration files. Before a user joins the network and downloads the configuration file, USIM does not have corresponding access control rules. The first receiving module, connected to the first sending module, is used to receive a first response from the USIM. The first response is initiated by the USIM according to the remote access control request, specifying the initiating device of the remote access control. The initiating device is the USIM or a terminal. The first execution module, connected to the first receiving module, is used to provide the initiating device with access information for remote access control. The access information includes the terminal application identifier with access requirements, the USIM application identifier, and the digest certificate for remote access control, so that the initiating device, after obtaining the address of the remote access control platform provided by USIM, can initiate remote access control based on the address and access information.

10. A universal user identification module (USIM), characterized in that, The USIM includes: The second receiving module is used to receive remote access control initiation requests from the terminal. The remote access control initiation request includes information on whether the terminal has the capability to initiate remote access control. USIM does not have access control rules corresponding to the access requirements of terminal applications to USIM applications. USIM is an eSIM that supports remote download and management of configuration files. Before the user joins the network and downloads the configuration file, USIM does not have corresponding access control rules. The second sending module, connected to the second receiving module, is used to send a first response to the terminal. The first response is initiated by the USIM according to the remote access control initiation request, specifying the initiating device of the remote access control. The initiating device is either the USIM or the terminal. The second execution module, connected to the second sending module, is used to provide the address of the remote access control platform to the initiating device, so that after the initiating device has also obtained the remote access control access information provided by the terminal, it can initiate remote access control based on the address and access information. The access information includes the terminal application identifier and USIM application identifier with access requirements, as well as the digest certificate of the remote access control.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the access control initiation method as described in any one of claims 1-4 or 5-8.