eUICC card space management method, device, equipment and medium for multi-network access

By dividing the EEPROM space of the eUICC card into independent areas and dynamically allocating Profile indexes, the problem of the eUICC card being unable to support multiple network access is solved, and efficient management and storage of multiple Profile sessions are achieved, reducing user operations.

CN118400726BActive Publication Date: 2025-09-26EASTCOMPEACE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410415645.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-08
Publication Date
2025-09-26
Estimated Expiration
2044-04-08

AI Technical Summary

Technical Problem

Existing eUICC cards only support single Profile activation and cannot meet the requirements of multiple basebands connecting to different networks at the same time, resulting in users frequently logging out and changing numbers.

Method used

The EEPROM management space of the eUICC card is divided into independent first and second information areas, and a configuration area is set in each area. By dynamically allocating Profile indexes and addresses, it supports simultaneous downloading and management of multiple Profile sessions, reducing user operations.

Benefits of technology

It achieves efficient activation and operation of multiple Profile sessions, fully utilizes storage space, and reduces users' frequent logouts and number changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118400726B_ABST
    Figure CN118400726B_ABST
Patent Text Reader

Abstract

The present invention proposes a multi-network access eUICC card space management method, comprising dividing the EEPROM management space of the eUICC card into a first information area and a second information area, dividing the first information area into a first user information area and a first system information area, and dividing the second information area into a second user information area and a second system information area; obtaining first information and assigning it to the first information area, determining an execution area of ​​the first information area, obtaining a first profile index and first address information, assigning the first address information to the first information area, switching the first information area to the second information area according to a download instruction and adding a third system information area, obtaining second address information, and writing the second address information to the second profile index, until the profile session is downloaded. This method implements storage management of multiple profile sessions and application data, dynamically allocates multiple security interfaces to partition the profile session area, enables activation and simultaneous operation of multiple profile sessions, and fully utilizes storage space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of smart card technology, and in particular to a method, apparatus, device, and medium for managing eUICC card space for multi-network access. Background Art

[0002] The eUICC in the existing technology only supports single profile activation. When a device has multiple basebands that need to connect to different networks at the same time, the eUICC cannot activate multiple profiles, causing users to frequently log out and change numbers. Summary of the Invention

[0003] The present invention aims to solve at least one of the technical problems existing in the prior art. To this end, the present invention provides a multi-network access eUICC card space management method, apparatus, device, and medium, which can enable the eUICC to activate multiple profile scenarios and reduce the frequent operations such as user logout and number change.

[0004] In a first aspect, an embodiment of the present invention provides a method for managing eUICC card space for multi-network access, including:

[0005] Dividing the EEPROM management space of the eUICC card into a first information area and a second information area, dividing the first information area into a first user information area and a first system information area, and dividing the second information area into a second user information area and a second system information area, wherein the first information area and the second information area are independent of each other, and both the first information area and the second information area are provided with a configuration area;

[0006] When the eUICC card is powered on for the first time, obtaining first information from the EEPROM management space, allocating the first information only to the first user information area and the first system information area, initializing the first information allocated to the first user information area and the first system information area and the configuration area, and determining an execution area of ​​the first information area, wherein the first user information area and the first system information area are allocated in descending order of addresses;

[0007] When the Profile session starts downloading, the Profile session is provided with a first Profile index corresponding to the configuration area, first address information is obtained, a first address of the first information area is obtained according to the first address information, and the first address is written into the first Profile index;

[0008] When the profile session is downloading, the first information area receives a download instruction of the profile, switches the first information area to the second information area according to the download instruction, adds a third system information area and a third user information area to the second information area, both the third system information area and the third user information area are provided with a second profile index, obtains second address information, obtains a second address of the second information area according to the second address information, writes the second address information into the second profile index, and downloads multiple profile sessions into the second information area;

[0009] A third information area is newly added to the second information area, and multiple Profile sessions are allocated to the second information area and the third information area according to the first Profile index and the second Profile index, until all multiple Profile sessions are allocated to the second information area and the third information area.

[0010] In some embodiments of the present invention, after initializing the first information allocated to the first user information area and the first system information area, the method further includes:

[0011] When the eUICC card is powered on for the first time, all the Profile sessions allocated to the configuration area are initialized to an invalid state;

[0012] Executing the download instruction to obtain target index information of the configuration area, and marking the target index information as being downloaded through a first mark;

[0013] When the Profile session download is complete, marking the target index information as valid through a second mark;

[0014] Obtain deletion instruction information, mark the target index information as deleted, so that the Profile is deleted. After the Profile is deleted, mark the target index information as invalid through a third mark.

[0015] In some embodiments of the present invention, when the Profile is downloading, the first information area receives a download instruction from the Profile, and switches to the second information area according to the download instruction, including:

[0016] Obtaining switching mode information of the EU ICC card, distinguishing a command identifier and a target identifier of the Profile session according to the switching mode information, and constructing a first security interface in the first system information area according to the command identifier and the target identifier;

[0017] When the profile session is downloading, the second profile index is allocated to the profile session, the first target profile index is obtained, the first target profile index is allocated to the first security interface, and the second target profile index allocated to the first security interface is initialized, wherein the second profile index is an idle and valid profile index, wherein, when the profile session completes the download, the first profile index or the second profile index is allocated to the profile session;

[0018] Back up the second target Profile index assigned to the first security interface, and switch the second target Profile index in the first security interface to the second system information area and the second user information area, so that the second information area executes the second target Profile index.

[0019] In some embodiments of the present invention, when the eUICC card session is actively running within the second security interface, after interrupting the Profile session, the method further includes:

[0020] When the eUICC card session is not actively running in the second security interface, the eUICC card searches for a third profile index matching the profile session through the identity instruction and the application instruction;

[0021] Traversing the configuration area, determining whether the Profile session is in an invalid state, and detecting whether there is an activated Profile session in the second security interface;

[0022] When there is no activated Profile session in the security interface, obtaining refresh status information of the Profile session, and determining whether the Profile session is reset and activated according to the refresh status information;

[0023] When the network operator of the EU ICC card is acquired by the terminal, the Profile session in the configuration area to be activated in the second security interface is written into the third Profile index, wherein when the network operator is acquired for the terminal, the Profile session is the reset activation operation or the non-reset activation operation;

[0024] Alternatively, when the network operator of the EU ICC card is the EU ICC card itself, the third Profile index is written into the Profile session in the second security interface in the configuration area, and the Profile session of the second security interface is activated to make the Profile session an execution area, wherein, when the network operator is the EU ICC card itself, the Profile session can only be the non-reset activation operation;

[0025] The eu icc card sends a second instruction carrying a second security interface to the terminal, the terminal detects the second security interface, the eu icc card sends a reset command to the second security interface, the second security interface is reset according to the reset command, or is reset by the terminal.

[0026] In some embodiments of the present invention, obtaining the first instruction information and sending the first instruction information to the Profile session and the second security interface includes:

[0027] After the second security interface receives the first instruction, the second security interface determines the first instruction and the Profile session;

[0028] When the identity identification instruction and the application instruction are included in the first instruction, traverse the configuration area to determine whether the Profile session is in an invalid state;

[0029] When the Profile session is in an invalid state, obtaining a preset configuration file rule, and determining whether the Profile session in the invalid state is allowed to be deleted according to the configuration file specification;

[0030] When the Profile session allows deletion, marking the third Profile index of the Profile session as deleted;

[0031] According to the third Profiles index marked as deleted, the identity identification instruction and the application instruction are deleted, and the third Profiles index is marked as invalid.

[0032] In some embodiments of the present invention, when the second security interface is valid, determining whether the Profile session is actively running within the second security interface includes:

[0033] When the Profile session is not actively running in the second security interface, traverse the second security interface to obtain all activated Profile sessions and Profile execution areas generated according to the Profile sessions;

[0034] Obtaining configuration area information supporting the first security interface in all configuration areas, invalidating the Profile session at the second security interface based on the configuration area information, clearing the second target Profile index, and clearing the Profile execution area in the configuration area;

[0035] When the Profile execution area is cleared, or there is no activated Profile session in the second security interface, the second Profile index in the configuration area is marked as deleted;

[0036] According to the second Profile index marked as deleted, deleting all the Profile sessions in the configuration area, marking the second Profile index as invalid, and sending a reset instruction to the reset module of the EU ICC card;

[0037] The reset module performs a reset operation on the EU ICC card according to the reset instruction.

[0038] In a second aspect, an embodiment of the present invention provides a multi-network access EU ICC space management device, comprising at least one control processor and a memory for communicating with the at least one control processor; the memory stores instructions that can be executed by the at least one control processor, and the instructions are executed by the at least one control processor to enable the at least one control processor to execute the multi-network access EU ICC space management method as described in the first aspect above.

[0039] In a third aspect, an embodiment of the present invention provides an electronic device comprising the multi-network access EU ICC space management device as described in the second aspect above.

[0040] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the multi-network access EU ICC space management method as described in the first aspect above.

[0041] The multi-network access EU ICC space management method according to the embodiment of the present invention has at least the following beneficial effects:

[0042] The EEPROM management space of the eUICC card is divided into a first information area and a second information area, the first information area is divided into a first user information area and a first system information area, and the second information area is divided into a second user information area and a second system information area, wherein the first information area and the second information area are independent of each other, and both the first information area and the second information area are provided with a configuration area; when the eUICC card is powered on for the first time, first information of the EEPROM management space is obtained, the first information is allocated only to the first user information area and the first system information area, the first information allocated to the first user information area and the first system information area and the configuration area are initialized, and an execution area of ​​the first information area is determined, wherein the first user information area and the first system information area are allocated in descending order of address; when a profile session starts downloading, a first profile index corresponding to the configuration area is set for the profile session, first address information is obtained, a first address of the first information area is obtained based on the first address information, and the first address is written into the first profile index; when the profile session is downloading, the first information area receives the profile information; le download instruction, switching the first information area to the second information area according to the download instruction, adding a third system information area and a third user information area in the second information area, both the third system information area and the third user information area are provided with a second Profile index, obtaining second address information, obtaining a second address of the second information area according to the second address information, writing the second address information into the second Profile index, and downloading multiple Profile sessions into the second information area; adding a third information area in the second information area, and allocating multiple Profile sessions to the second information area and the third information area according to the first Profile index and the second Profile index, until all multiple Profile sessions are allocated to the second information area and the third information area. The solution provided by the embodiment of the present invention supports the EEPROM space management of the EU ICC card of the MEP, divides the EEPROM management space of the EU ICC card into a first information area and a second information area, divides the first information area into a first user area and a second system area, and divides the second storage area into a second user area and a second system area. The system area manages the use of the user area, thereby realizing the storage management of multiple profile sessions and application data. The profile session area is divided by a dynamic allocation method and multiple security interfaces, and multiple profile sessions are activated and operated simultaneously in a time-efficient manner, making full use of the storage space, so that users do not need to perform frequent operations such as logout and number change. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 This is a flowchart of a method for managing eUICC card space for multi-network access provided by an embodiment of the present invention;

[0044] Figure 2 This is a flow chart after initializing the first information allocated to the first user information area and the first system information area, provided by one embodiment of the present invention;

[0045] Figure 3 A flowchart of an embodiment of the present invention provides that when a profile is being downloaded, the first information area receives a profile download instruction and switches to the second information area according to the download instruction;

[0046] Figure 4 A flowchart of an embodiment of the present invention after initializing the target Profile index assigned to the first security interface;

[0047] Figure 5 A flowchart of interrupting a Profile session when the Profile session is actively running within a second security interface is provided in accordance with an embodiment of the present invention;

[0048] Figure 6 A flowchart of obtaining first instruction information and sending the first instruction information to a profile session and a second security interface provided by an embodiment of the present invention;

[0049] Figure 7 A flowchart of determining whether a Profile session is actively running within a second security interface when the second security interface is valid is provided as an embodiment of the present invention;

[0050] Figure 8 This is a structural diagram of an eUICC card space management device for multi-network access provided by another embodiment of the present invention. DETAILED DESCRIPTION

[0051] The following describes embodiments of the present invention in detail. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended only to explain the present invention and are not to be construed as limiting the present invention.

[0052] In the description of the present invention, it should be understood that descriptions involving orientations, such as up, down, front, back, left, right, etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings. They are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, they cannot be understood as limitations on the present invention.

[0053] In the description of the present invention, "several" means one or more, "many" means more than two, "greater than," "less than," and "exceed" are understood to exclude the number itself, while "above," "below," and "within" are understood to include the number itself. The use of "first" and "second" in the description is solely for the purpose of distinguishing technical features and should not be construed as indicating or implying relative importance, implicitly specifying the number of the indicated technical features, or implicitly specifying the order of the indicated technical features.

[0054] In the description of the present invention, unless otherwise clearly defined, terms such as setting, installing, and connecting should be understood in a broad sense, and technicians in the relevant technical field can reasonably determine the specific meanings of the above terms in the present invention based on the specific content of the technical solution.

[0055] An embodiment of the present invention provides a multi-network access EU ICC card space management method, comprising:

[0056] The EEPROM management space of the eUICC card is divided into a first information area and a second information area, the first information area is divided into a first user information area and a first system information area, and the second information area is divided into a second user information area and a second system information area, wherein the first information area and the second information area are independent of each other, and both the first information area and the second information area are provided with a configuration area; when the eUICC card is powered on for the first time, first information of the EEPROM management space is obtained, the first information is allocated only to the first user information area and the first system information area, the first information allocated to the first user information area and the first system information area and the configuration area are initialized, and an execution area of ​​the first information area is determined, wherein the first user information area and the first system information area are allocated in descending order of address; when a profile session starts downloading, a first profile index corresponding to the configuration area is set for the profile session, first address information is obtained, a first address of the first information area is obtained based on the first address information, and the first address is written into the first profile index; when the profile session is downloading, the first information area receives the profile information. le download instruction, switching the first information area to the second information area according to the download instruction, adding a third system information area and a third user information area in the second information area, both the third system information area and the third user information area are provided with a second Profile index, obtaining second address information, obtaining a second address of the second information area according to the second address information, writing the second address information into the second Profile index, and downloading multiple Profile sessions into the second information area; adding a third information area in the second information area, and allocating multiple Profile sessions to the second information area and the third information area according to the first Profile index and the second Profile index, until all multiple Profile sessions are allocated to the second information area and the third information area. According to the solution provided by the embodiment of the present invention, the EEPROM space management of the EU ICC card of the MEP is supported, the EEPROM management space of the EU ICC card is divided into a first information area and a second information area, the first information area is divided into a first user area and a first system area, and the second storage area is divided into a second user area and a second system area. The system area manages the use of the user area, thereby realizing the storage management of multiple profile sessions and application data, using a dynamic allocation method and multiple security interfaces to divide the profile session area, time-efficient activation and simultaneous operation of multiple profile sessions, fully utilizing the storage space, and eliminating the need for users to frequently perform operations such as logout and number change.

[0057] The control method of the embodiment of the present invention is further described below based on the accompanying drawings.

[0058] Reference Figure 1 , Figure 1 A flowchart of a method for managing eUICC card space for multi-network access provided by an embodiment of the present invention includes but is not limited to the following steps:

[0059] Step S11: Divide the EEPROM management space of the eUICC card into a first information area and a second information area, divide the first information area into a first user information area and a first system information area, and divide the second storage area into a second user information area and a second system information area, wherein the first information area and the second information area are independent of each other, and both the first information area and the second information area are provided with a system configuration area and a user configuration area;

[0060] It should be noted that by dividing the EEPROM management space into a first information area and a second information area, and dividing each into a user information area and a system information area, EEPROM space management, user storage of profiles and application data, etc. are facilitated. The first information area and the second information area respectively establish a first user information area and a second user information area, and the user information area is respectively constructed into a user configuration area; the usage of the user area information area corresponds to the first system information area and the second system information area, thereby managing the first user information area and the second user information area. The first information area and the second information area are independent of each other, thereby reducing mutual influence. The user configuration area includes a profile validity configuration area that supports the maximum number of profile sessions by default and a security interface status configuration area that supports the maximum number of security interfaces by default;

[0061] Step S12: When the eUICC card is powered on for the first time, first information of the EEPROM management space is obtained, the first information is allocated only to the first user information area and the first system information area, the first information allocated to the first user information area and the first system information area and the configuration area are initialized, and an execution area of ​​the first information area is determined, wherein the first user information area and the first system information area are allocated in descending order of address.

[0062] It should be noted that the first information is only allocated to the first user information area and the first system information area of ​​the first information area. When the first information is allocated to the first user information area, it is allocated starting from the high address area of ​​the first user information area. When the space status information is allocated to the first system information area, the size of the space status information is fixed. After the space status information is allocated, the space status information and configuration area are initialized. At this time, the first information area is the execution area.

[0063] Step S13: When the Profile session starts downloading, the Profile session is provided with a first Profile index corresponding to the configuration area, first address information is obtained, a first address of the first information area is obtained according to the first address information, and the first address is written into the first Profile index;

[0064] It should be noted that, in order to save card space of the EU ICC card, a dynamic allocation method is adopted. When the Profile session download starts, the first Profile index is obtained, wherein the first Profile index is an idle valid index; after the Profile session download is completed, the size of the first user information area is allocated according to the size of the space occupied by the Profile after the download is completed;

[0065] If the Profile session download fails, the data in the first system information area is rolled back, and the information recorded in the system configuration area continues to be retained and can be directly used for downloading the next Profile session.

[0066] In step S14, when the Profile session is downloaded, the first information area receives the Profile download instruction, switches the first information area to the second information area according to the download instruction, adds a third system information area and a third user information area to the second information area, and both the third system information area and the third user information area are provided with a second Profile index. The second address information is obtained, and the second address of the second information area is obtained according to the second address information. The second address information is written into the second Profile index, and multiple Profile sessions are downloaded into the second information area.

[0067] When downloading a profile session, a third system information area and a third user information area are added to the second system information area, and the second address information is written into a second profile index corresponding to the third system information area and the third user information area. The sizes of the first system information area, the second system information area, and the third system information area are fixed, and information in the first system information area, the second system information area, and the third system information area is recorded in the system configuration area; the sizes of the first user information area, the second user information area, and the third user information area are not fixed, and the user information area is recorded in the user configuration area.

[0068] If the Profile session download fails, the data in the first user information area is rolled back, and the information recorded in the user configuration area continues to be retained and can be directly used for the next Profile session download;

[0069] Regarding the sizes of the first user information area, the second user information area, and the third user information area, after the Profile session is successfully downloaded, a certain amount of space is reserved for the downloaded Profile session. The size of the reserved space is converted according to the corresponding rules of the first user information area, the second user information area, and the third user information area actually consumed when the Profile session is successfully downloaded. The sizes of the first user information area, the second user information area, and the third user information area are set to size1, size2, and size3, respectively. When the size of the user area is 0, it indicates that the Profile session download has failed, that is, the end address of the user area is the high address of the system area in the first information area corresponding to the first user information area, the second user information area, and the third user information area.

[0070] Step S15: A third information area is added to the second information area, and multiple profile sessions are allocated to the second information area and the third information area according to the first profile index and the second profile index, until all the profile sessions are allocated to the second information area and the third information area;

[0071] It should be noted that multiple Profile sessions are allocated to the first information area and the second information area according to the first Profile index and the second Profile index, which better utilizes the EEPROM space of the EUICC card and improves the compatibility of the EUICC card.

[0072] It should be noted that, according to the solution provided in this embodiment, the EEPROM space management of the EU ICC card of the MEP is supported, the EEPROM management space of the EU ICC card is divided into a first information area and a second information area, the first information area is divided into a first user area and a first system area, the second storage area is divided into a second user area and a second system area, and the system area manages the use of the user area, thereby realizing the storage management of multiple Profile sessions and application data, using a dynamic allocation method and multiple security interfaces to divide the Profile session area, realizing efficient activation and simultaneous operation of multiple Profile sessions, making full use of the EEPROM space, and eliminating the need for users to perform frequent operations such as logout and number change.

[0073] In addition, in one embodiment, referring to Figure 2 ,exist Figure 1 After step S15 in the embodiment shown, the following steps are also included but not limited to:

[0074] S21, when the eUICC card is powered on for the first time, initializing all the Profile sessions allocated to the configuration area to an invalid state;

[0075] S22, executing the download instruction, obtaining target index information of the configuration area, and marking the target index information as being downloaded using a first mark;

[0076] S23, when the Profile session download is completed, the target index information is marked as valid through a second mark;

[0077] S24, obtaining deletion instruction information, marking the target index information as deleted, so that the Profile is deleted. After the Profile is deleted, the target index information is marked as invalid through a third mark;

[0078] It should be noted that when the EU ICC card is powered on for the first time, the first information area is selected by default, wherein there is no preset Profile session in the first information area. Therefore, all Profile sessions allocated to the configuration area are initialized to an invalid state; the download instruction is executed, and the Profile validity configuration area is marked as downloading during downloading. If the download is not completed and the EU ICC card is powered off, the Profile session whose download is not completed is deleted when the EU ICC is powered on again; when the Profile session is downloaded, the Profile validity configuration area is marked as valid; when the Profile session is to be deleted, deletion instruction information is obtained and the deletion instruction is executed. After the Profile session is deleted, the target index information of the Profile validity configuration area is obtained, and the Profile session is marked as deleted according to the target index information. After the Profile is deleted, the Profile validity configuration area is marked as invalid according to the third mark. If the EU ICC card is powered off during the deletion process, the Profile session whose download is not completed is deleted when the EU ICC card is powered on again.

[0079] When the eu icc card is powered on for the first time, the first information area is selected by default, and the profile validity configuration area for downloading the profile session is initialized to an illegal profile index, that is, the target index information is obtained, and the profile session activation, invalidation, deletion and eu icc memory rest are executed to change the status of the profile session.

[0080] In addition, in one embodiment, referring to Figure 3 ,exist Figure 1 Step S14 of the illustrated embodiment further includes but is not limited to the following steps:

[0081] S31, obtaining switching mode information of the EU ICC card, distinguishing the command identifier and target identifier of the Profile session according to the switching mode information, and constructing a first security interface in the first system information area according to the command identifier and the target identifier;

[0082] S32, when the profile session is downloading, assigning the second profile index to the profile session, obtaining the first target profile index, assigning the first target profile index to the first security interface, and initializing the second target profile index assigned to the first security interface, wherein the second profile index is an idle and valid profile index, wherein, when the profile session completes the download, the first profile index or the second profile index is assigned to the profile session;

[0083] S33: back up the second target Profile index allocated to the first security interface, switch the second target Profile index in the first security interface to the second system information area and the second user information area, so that the second information area executes the second target Profile index.

[0084] It should be noted that, during the process of downloading the Profile session, the switching mode information of the EU ICC card in the MEP mode is obtained, and the command identifier and the target identifier are distinguished according to the switching mode information. The download instruction of the Profile session is received in the first information area, but the relevant data information created by downloading the Profile session belongs to the second information area. Therefore, it is necessary to switch the execution area during the Profile session download process, that is, it is necessary to switch the first information area to the second information area when activating the Profile session, deactivating the Profile session, and deleting the Profile session. When the Profile session is downloaded, the second Profile index is allocated to the Profile session to obtain the first target Profile index, and the first target Profile index is allocated to the first security interface. The second target Profile index allocated to the first security interface is initialized. After the initialization operation is completed, the first security interface still uses the first information area as the execution area, backs up the first user information area and the first system area of ​​the first information area, switches the first information area to the second information area through the first security interface, and constructs the Profile in the second information area. le session execution area. When a Profile session is downloading, there can only be one Profile download session. When a Profile session is downloaded, it can be downloaded again.

[0085] It should be noted that, when downloading a Profile session, the first download is switched to the second information area, the second download is switched to the third information area, the third download is switched to the fourth information area, and so on.

[0086] Install ISD-P and Profile session. If the installation fails, delete the Profile session execution area and restore the first information area as the execution area on the first security interface. If the installation is successful, set the Profile user area size in the first user configuration area and the second user configuration area, and restore the first information area as the execution area on the first security interface.

[0087] In addition, in one embodiment, referring to Figure 4 ,exist Figure 3 Step S32 of the illustrated embodiment further includes but is not limited to the following steps:

[0088] S41, the second information area receives the first instruction information, and sends the first instruction information to the Profile session and the second security interface, so that the EU ICC card determines the type of network operator, wherein the first instruction information carries the EU ICC card identity identification instruction and application instruction;

[0089] S42: Determine whether the second security interface is valid based on the network operator type, the identity identification instruction, and the application instruction. If the second security interface is valid, determine whether the eUICC card session is actively running within the second security interface. If the eUICC card session is actively running within the second security interface, terminate the Profile session.

[0090] It should be noted that the eu icc card sends the first instruction information to the profile session and the second security interface. The eu icc card determines the type of network operator based on the first instruction information. When the network operator type is MEP-A1, the second security interface is used as the target security interface to detect the validity of the network operator. When the network operator type is MEP-A2, the eu icc card selects any valid network security interface for detection. The eu icc card determines whether there is an active session in the target security interface, and determines whether the second security interface is valid based on the identification instruction and application instruction carried in the first instruction information and the type of network operator.

[0091] The eU ICC card can determine the validity of the second security interface based on the relevant parameters and operator type in the first instruction information, combined with the detection of the target security interface and active session. This ensures that the selected network operator is legitimate and has the necessary configuration and authorization, thereby providing more secure and reliable services.

[0092] In addition, in one embodiment, referring to Figure 5 ,exist Figure 4 Step S42 of the illustrated embodiment further includes but is not limited to the following steps:

[0093] S51, when the eUICC card session is not actively running in the second security interface, the eUICC card searches for a third profile index that matches the profile session through the identity instruction and the application instruction;

[0094] S52, traversing the first configuration area, determining whether the Profile session is in an invalid state, and detecting whether there is an activated Profile session in the second security interface;

[0095] S53, when there is no activated Profile session in the security interface, obtain the refresh status information of the Profile session, and determine whether the Profile session is reset and activated according to the refresh status information;

[0096] S54, when the network operator of the EU ICC card is acquired by the terminal, the Profile session in the configuration area to be activated in the second security interface is written into the third Profile index, wherein when the network operator is acquired for the terminal, the Profile session is a reset activation operation or a non-reset activation operation;

[0097] S55, or, when the network operator of the EU ICC card is the EU ICC card itself, write the third Profile index into the Profile session in the second security interface in the configuration area, activate the Profile session of the second security interface, so that the Profile session is the execution area, wherein, when the network operator is the EU ICC card itself, the Profile session can only be activated without resetting;

[0098] S56, the eu icc card sends a second instruction carrying the second security interface to the terminal, the terminal detects the second security interface, the eu icc card sends a reset command to the second security interface, the second security interface is reset according to the reset command, or the terminal resets it.

[0099] It should be noted that when the Profile session is reset and activated, the network operator type cannot be MEP-A2; when the Profile session is successfully activated, the Profile session is switched to the second user information area and the second system information area on the second network security interface, that is, the second information area is the execution area. Through the second network security interface, it can be ensured that when the Profile session is activated, a secure communication connection is established between the terminal and the EU ICC card, and the reset operation is used to eliminate potential security risks during the Profile session download process, ensure the stability of communication, ensure normal communication and error correction between the terminal and the EU ICC card, and avoid the EEPROM management space containing too many unusable Profile sessions due to multiple Profile session downloads.

[0100] In addition, in one embodiment, referring to Figure 6 ,exist Figure 4 Step S41 of the illustrated embodiment further includes but is not limited to the following steps:

[0101] S61, after the second security interface receives the first instruction, the second security interface determines the first instruction and the Profile session;

[0102] S62, when the first instruction contains the identity identification instruction and the application instruction, traverse the configuration area to determine whether the Profile session is in an invalid state;

[0103] S63, when the Profile session is in an invalid state, obtaining a preset configuration file rule and determining whether the Profile session in the invalid state is allowed to be deleted according to the configuration file specification;

[0104] S64, when the profile session allows deletion, marking the third profile index of the profile session as deleted;

[0105] S65: Delete the identity recognition instruction and the application instruction according to the third Profile index marked as deleted, and mark the third Profile index as invalid.

[0106] It should be noted that, after the second security interface receives the first instruction, the EU ICC card searches for a matching Profile session according to the identity instruction and application instruction carried by the first instruction, obtains the fourth Profile index, traverses the configuration area, checks the status of the Profile session input to the second security interface, and if the Profile session is in an active state, obtains the second security interface with the Profile session, detects whether there is an active session running in the second security interface, verifies whether the Profile complies with the relevant Profile policy rules through the second security interface, and determines whether it is necessary to mark the Profile session as invalid; according to whether refreshFlag is reset invalid, if it is not reset invalid, invalidates the second security interface in the configuration area and clears the third Profile index, clears the Profile execution area in the second security interface, and if it is reset invalid, writes the Profile session to be invalidated in the second security interface into the third Profile index in the configuration area, and the EU ICC card sends an active instruction to enable the terminal to check the second security interface. The icc card sends a refresh command on the second security interface, waiting for the second security interface to be reset or the device to be reset; traverses the configuration area, and clears the third Profile index in the configuration area to clear the third Profile index in the Profile session to be invalidated in the second security interface.

[0107] In addition, in one embodiment, referring to Figure 7 ,exist Figure 4 Step S42 of the illustrated embodiment further includes but is not limited to the following steps:

[0108] S71: When the eUICC card session is not actively running within the second security interface, traverse the second security interface to obtain all activated Profile sessions and Profile execution areas generated based on the Profile sessions.

[0109] S72, obtaining configuration area information supporting the first security interface in all second configuration areas, invalidating the Profile session in the second security interface according to the configuration area information, clearing the second target Profile index, and clearing the Profile execution area in the second configuration area;

[0110] S73: When the Profile execution area is cleared, or when there is no activated Profile session in the second security interface, the second Profile index in the second configuration area is marked as deleted.

[0111] S74, according to the second profile index marked as deleted, delete all profile sessions in the second configuration area, mark the second profile index as invalid, and send a reset instruction to the reset module of the EU ICC card;

[0112] S75: The reset module resets the EU ICC card according to the reset instruction.

[0113] It should be noted that the second profile index in the configuration area is marked as deleted; after the profile session is deleted, the configuration area is marked as invalid. At this time, the second user information area and the second system information area where the profile session is located are idle, and the fifth profile index is set to mark this section as idle and available for download next time.

[0114] The system checks whether there is an active session on the first security interface. It then traverses the configuration area to retrieve all active profile indexes. If an active profile session exists, it clears the second profile index from the profile area in the second security interface activation area in the configuration area. It then clears the target profile execution area on the target security interface and marks the second profile index as deleted in the configuration area. After the profile session is deleted, the configuration area for the profile session is marked invalid. It then sends a UICC PLATFORM RESET active command (reset instruction) to cause the reset module to reset the UICC card.

[0115] Furthermore, the EU ICC card supports secure interface management, including configuring the secure interface as the first command after power-up, and setting MEP-related configurations: the maximum supported secure interfaces, MEP mode, and the maximum number of active profile sessions. The Select Secure Interface command selects the corresponding secure interface after powering up the card, and other secure interfaces can be selected using the Select Secure Interface command.

[0116] Preferably, in this embodiment, resetting the target profile area on the second security interface includes: initializing the execution content of the target profile area; marking the profile session as a to-be-activated profile session and the to-be-deactivated profile session as activated and disabled, respectively, in the configuration area within the second security interface; resetting the target profile area, the first user information area, and the second user information area. The device is powered on and a profile area configuration command is sent; the initialized first information area is used as the execution area; the configuration area is traversed to obtain activated profile sessions and profile areas, and the activated profile session is restored in each profile area as the execution area.

[0117] like Figure 8 As shown, Figure 8 This is a structural diagram of a multi-network access EU ICC space management device provided by an embodiment of the present invention. The present invention also provides a multi-network access EU ICC space management device, including:

[0118] The processor 801 may be implemented using a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.

[0119] The memory 802 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 802 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 802 and is called by the processor 801 to execute the multi-network access EU ICC space management method of the embodiment of the present application;

[0120] Input / output interface 803, used to implement information input and output;

[0121] Communication interface 804, used to implement communication interaction between the apparatus and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, Wi-Fi, Bluetooth, etc.);

[0122] Bus 805 , which transmits information between various components of the device (e.g., processor 801 , memory 802 , input / output interface 803 , and communication interface 804 );

[0123] The processor 801 , the memory 802 , the input / output interface 803 and the communication interface 804 are connected to each other in communication within the device via a bus 805 .

[0124] An embodiment of the present application further provides an electronic device, including the multi-network access EU ICC space management device as described above.

[0125] The embodiment of the present application further provides a storage medium, which is a computer-readable storage medium and stores a computer program. When the computer program is executed by a processor, the above-mentioned multi-network access EU ICC space management method is implemented.

[0126] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory optionally includes a memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of the above-mentioned networks include but are not limited to the Internet, an intranet, a local area network, a mobile communication network and a combination thereof. The device embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and are located in one place, or may be distributed to multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment.

[0127] Those skilled in the art will appreciate that all or some of the steps and systems in the method disclosed above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, and the computer-readable medium can include computer storage media (or non-transitory media) and communication media (or temporary media). As known to those skilled in the art, the term computer storage media is included in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data) and is volatile and non-volatile, removable, and non-removable. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory, or other memory technology, CD-ROM, digital versatile disks (DVD), or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage, or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0128] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the above implementation. Those skilled in the art can also make various equivalent modifications or substitutions under the shared conditions that do not violate the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present invention.

Claims

1. A method for managing eUICC card space for multi-network access, characterized in that: include: Dividing the EEPROM management space of the eUICC card into a first information area and a second information area, dividing the first information area into a first user information area and a first system information area, and dividing the second information area into a second user information area and a second system information area, wherein the first information area and the second information area are independent of each other, and both the first information area and the second information area are provided with a configuration area; When the eUICC card is powered on for the first time, obtaining first information from the EEPROM management space, allocating the first information only to the first user information area and the first system information area, initializing the first information allocated to the first user information area and the first system information area and the configuration area, and determining an execution area of ​​the first information area, wherein the first user information area and the first system information area are allocated in descending order of addresses; When the Profile session starts downloading, the Profile session is set with a first Profile index corresponding to the configuration area, first address information is obtained, a first address of the first information area is obtained according to the first address information, and the first address is written into the first Profile index; When the Profile session is downloaded, the first information area receives a download instruction of the Profile, switches the first information area to the second information area according to the download instruction, adds a third system information area and a third user information area to the second information area, and both the third system information area and the third user information area are provided with a second Profile index. Second address information is obtained, and a second address of the second information area is obtained according to the second address information. The second address information is written into the second Profile index, and multiple Profile sessions are downloaded into the second information area. A third information area is added to the second information area, and multiple Profile sessions are allocated to the second information area and the third information area according to the first Profile index and the second Profile index until all the Profile sessions are allocated to the second information area and the third information area.

2. The eUICC card space management method for multi-network access according to claim 1, characterized in that: After performing the initialization operation on the first information allocated to the first user information area and the first system information area, the method further includes: When the eUICC card is powered on for the first time, all the Profile sessions allocated to the configuration area are initialized to an invalid state; Executing the download instruction to obtain target index information of the configuration area, and marking the target index information as being downloaded through a first mark; When the Profile session download is complete, marking the target index information as valid through a second mark; Obtain deletion instruction information, mark the target index information as deleted, so that the Profile is deleted. After the Profile is deleted, mark the target index information as invalid through a third mark.

3. The eUICC card space management method for multi-network access according to claim 1, characterized in that: When the profile is being downloaded, the first information area receives a download instruction of the profile, and switches to the second information area according to the download instruction, including: Obtaining switching mode information of the eUICC card, distinguishing a command identifier and a target identifier of the profile session according to the switching mode information, and establishing a first security interface in the first system information area according to the command identifier and the target identifier; When the Profile session is downloading, the second Profile index is assigned to the Profile session, the first target Profile index is obtained, the first target Profile index is assigned to the first security interface, and the second target Profile index assigned to the first security interface is initialized, wherein the second Profile index is an idle and valid Profile index, wherein when the Profile session completes the download, the first Profile index or the second Profile index is assigned to the Profile session; Back up the second target Profile index allocated to the first security interface, and switch the second target Profile index in the first security interface to the second system information area and the second user information area, so that the second information area executes the second target Profile index.

4. The eUICC card space management method for multi-network access according to claim 3, characterized in that: After initializing the target Profile index assigned to the first security interface, the method further includes: The second information area receives first instruction information, and sends the first instruction information to the profile session and the second security interface, so that the eUICC card determines the type of network operator, wherein the first instruction information carries the identity identification instruction and application instruction of the eUICC card; Determining whether the second security interface is valid based on the type of the network operator, the identity identification instruction, and the application instruction; when the second security interface is valid, determining whether the eUICC card session is actively running within the second security interface; and when the eUICC card session is actively running within the second security interface, terminating the profile session.

5. The eUICC card space management method for multi-network access according to claim 4, characterized in that: When the eUICC card session is actively running in the second security interface, after interrupting the Profile session, the method further includes: When the eUICC card session is not actively running in the second security interface, the eUICC card searches for a third profile index matching the profile session through the identity instruction and the application instruction; Traversing the configuration area, determining whether the Profile session is in an invalid state, and detecting whether there is an activated Profile session in the second security interface; When there is no activated Profile session in the security interface, obtaining refresh status information of the Profile session, and determining whether the Profile session is reset and activated according to the refresh status information; When the network operator of the eUICC card is acquired by the terminal, the profile session in the configuration area to be activated in the second security interface is written into the third profile index, wherein when the network operator is acquired for the terminal, the profile session is the reset activation operation or the non-reset activation operation; Alternatively, when the network operator of the eUICC card is the eUICC card itself, the third profile index is written to the profile session in the second security interface in the configuration area, and the profile session of the second security interface is activated to make the profile session an execution area, wherein when the network operator is the eUICC card itself, the profile session can only be the non-reset activation operation; The eUICC card sends a second instruction carrying a second security interface to the terminal, the terminal detects the second security interface, the eUICC card sends a reset command to the second security interface, and the second security interface is reset according to the reset command, or is reset by the terminal.

6. The method for managing eUICC card space for multi-network access according to claim 4, wherein: The obtaining of the first instruction information and sending the first instruction information to the Profile session and the second security interface includes: After the second security interface receives the first instruction, the second security interface determines the first instruction and the profile session; When the identity identification instruction and the application instruction are included in the first instruction, traverse the configuration area to determine whether the profile session is in an invalid state; When the Profile session is in an invalid state, obtaining a preset configuration file rule, and determining whether the Profile session in the invalid state is allowed to be deleted according to the configuration file specification; When the Profile session allows deletion, mark the third Profiles index of the Profile session as deleted; According to the third Profiles index marked as deleted, the identity identification instruction and the application instruction are deleted, and the third Profiles index is marked as invalid.

7. The method for managing eUICC card space for multi-network access according to claim 4, wherein: When the second security interface is valid, determining whether the eUICC card session is actively running within the second security interface includes: When the eUICC card session is not actively running in the second security interface, traverse the second security interface to obtain all activated Profile sessions and Profile execution areas generated according to the Profile sessions; Obtaining configuration area information supporting the first security interface in all configuration areas, invalidating the profile session at the second security interface based on the configuration area information, clearing the second target profile index, and clearing the profile execution area in the configuration area; When the Profile execution area is cleared, or when there is no activated Profile session in the second security interface, the second Profile index in the configuration area is marked as deleted; deleting all the Profile sessions in the configuration area according to the second Profile index marked as deleted, marking the second Profile index as invalid, and sending a reset instruction to the reset module of the eUICC card; The reset module performs a reset operation on the eUICC card according to the reset instruction.

8. A multi-network access eUICC card space management device, characterized in that: The invention comprises at least one control processor and a memory for communicating with the at least one control processor; the memory stores instructions executable by the at least one control processor, and the instructions are executed by the at least one control processor to enable the at least one control processor to perform the eUICC card space management method for multi-network access according to any one of claims 1 to 7.

9. An electronic device, characterized in that: The eUICC card space management device for multi-network access includes the device described in claim 8.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the eUICC card space management method for multi-network access according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and system for intelligently downloading Profile

    CN109688576A

  • Method and Device for Switching Between Networks

    US20150237551A1