A working environment safety detection alarm system based on a special SIM card for an internet of things terminal device and an operation method thereof

By integrating security sensors and processing modules into the SIM card of IoT terminal devices, and combining this with data verification from the backend cloud service platform, the problem of false alarms caused by SIM cards in abnormal environments is solved. This enables rapid location and preventative measures, ensuring stable device operation and data security.

CN118890628BActive Publication Date: 2025-11-11CHINA ELECTRONICS STANDARDIZATION INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410923278.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-10
Publication Date
2025-11-11
Estimated Expiration
2044-07-10

AI Technical Summary

Technical Problem

SIM cards in IoT terminal devices are prone to generating false security alarms under abnormal operating environments, causing the devices to go offline. Existing technologies lack effective preventive measures.

Method used

Design a working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices. The system detects abnormal environments through security sensors, executes security processing procedures, and encrypts and records alarm information in ATR historical bytes. The system then uses a backend cloud service platform for data verification and analysis to quickly locate the cause of the problem and formulate preventive measures.

Benefits of technology

It reduces the cost of locating problems, improves the reliability of equipment in abnormal environments, prevents equipment from going offline due to false alarms, and ensures data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118890628B_ABST
    Figure CN118890628B_ABST
Patent Text Reader

Abstract

This invention discloses a working environment security detection and alarm system and its operation method based on a dedicated SIM card for IoT terminal devices. The system includes triggering a security alarm and executing security processing and auditing procedures when the dedicated SIM card detects an abnormal working environment. The encrypted information of the working environment security alarm is synchronously recorded in the historical bytes of the card's ATR (Automatic Transfer Record). The IoT terminal device obtains the ATR information by resetting the chip and reports the encrypted information to a background cloud server monitoring platform in either active or passive mode. The system decrypts and verifies the reported encrypted information to verify its validity, thereby analyzing the type and frequency of false alarms and quickly locating the cause of the problem. This invention shortens the problem location cycle, reduces manpower and material costs, and allows for the development of preventative measures based on the cause of the problem, ensuring the safe, stable, and reliable operation of IoT terminal devices based on dedicated SIM cards.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of smart card technology, specifically to a working environment security detection and alarm system and operating method based on a dedicated SIM card for Internet of Things terminal devices. Background Technology

[0002] IoT terminals are key devices in the IoT architecture, connecting the sensor network layer and the transmission network layer. They are responsible for collecting data and sending it to the network layer. They possess multiple functions, including data acquisition, preliminary processing, encryption, and transmission. IoT terminals can sense environmental changes and, through front-end devices such as RF modules or sensor modules, collect information such as sound, light, heat, electricity, mechanics, chemistry, biology, and location. Utilizing various possible network access methods, they achieve ubiquitous connectivity between things and between things and people, enabling intelligent sensing, identification, and management of objects and processes. Simultaneously, IoT terminals possess reliable security mechanisms to ensure the confidentiality and integrity of data.

[0003] The networking methods for IoT devices mainly include wired connections, wireless connections, and mobile network connections. With the continuous development of IoT technology, IoT terminal devices are becoming increasingly widespread, and mobile network connections have become an important transmission method for these devices. Utilizing mobile network connections, IoT terminal devices can leverage their advantages to achieve more convenient, efficient, and real-time communication and data transmission. The application areas of mobile network connections for IoT devices are very broad, including smart homes, smart cities, smart manufacturing, smart healthcare, smart agriculture, and smart logistics.

[0004] As a crucial medium for IoT terminals to access 2G / 3G / 4G / 5G and NB-IoT mobile networks, the IoT-dedicated SIM card offers both efficient and flexible network connectivity, comprehensively meeting the needs of various devices and application scenarios. Simultaneously, its built-in encryption algorithms and security authentication mechanisms protect the confidentiality and integrity of data. Furthermore, the IoT-dedicated SIM card features hardware-level security protection mechanisms. Upon detecting abnormal operating environments such as voltage, current, temperature, laser, or electromagnetic interference, the IoT-dedicated SIM card operating system will execute security procedures, such as entering a security interrupt routine or directly resetting the chip, to prevent data tampering or leakage. For security reasons, the IoT-dedicated SIM card operating system is typically designed to support security auditing functions. When a security anomaly is detected, the system audits the event. When the number of audits reaches a preset threshold, the IoT-dedicated SIM card operating system will execute a self-destruct procedure, erasing user privacy data from the card and entering a dead card state. In the dead card state, the card typically only returns ATR information and does not respond to any APDU commands, ensuring that user privacy data is not leaked.

[0005] Currently, due to the diverse application scenarios and needs of the Internet of Things (IoT), IoT terminals are characterized by massive heterogeneity, severe fragmentation, and inconsistent device quality. Often, non-standard design of the SIM card electrical interface in IoT terminal devices leads to low-probability anomalies such as high voltage, strong current, glitches, and interference, causing false security alarms in the dedicated IoT SIM card operating system. Furthermore, some IoT devices may be deployed in remote locations such as deep mountains or lakesides, causing the dedicated IoT SIM cards to frequently operate in harsh environments such as high temperature, low temperature, and high humidity, further increasing the probability of false security alarms. Once the security audit reaches a threshold, the operating system will execute a self-destruct program, causing the card to enter a dead state and no longer respond to any APDU commands. This results in the IoT terminal being unable to access the mobile network, causing the device to malfunction offline.

[0006] To address the aforementioned problems, this invention provides a working environment security detection and alarm system and operating method based on a dedicated SIM card for IoT terminal devices, which allows for the formulation of preventative measures in advance based on the causes of the problems. Summary of the Invention

[0007] This invention provides a working environment security detection and alarm system and its operation method based on a dedicated SIM card for Internet of Things terminal devices, which can formulate preventive measures in advance according to the cause of the problem.

[0008] The purpose of this invention is to provide a working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices. The system includes a dedicated IoT SIM card, an IoT terminal device, and a backend cloud service monitoring platform. The dedicated IoT SIM card includes an IoT SIM card electrical interface communication module, a security processing module, and a security sensor module. The IoT terminal device includes an IoT terminal electrical interface communication module, a policy processing module, and an IoT terminal mobile network communication module. The backend cloud service monitoring platform includes a backend cloud service network communication module, a data processing module, and a data verification module. The security sensor module is connected to the security processing module. The security processing module is connected to the IoT SIM card electrical interface communication module. The IoT SIM card electrical interface module is connected to the IoT terminal electrical interface communication module. The IoT terminal electrical interface communication module is connected to the policy processing module. The policy processing module is connected to the IoT terminal mobile network communication module. The IoT terminal mobile network communication module is connected to the backend cloud service network communication module. The backend cloud service network communication module is connected to the data processing module. The data processing module is connected to the data verification module.

[0009] An operation method for a working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices, the operation method steps are as follows:

[0010] Step 1: Detect abnormal operating environments such as voltage, current, temperature, and laser through the safety sensor module, and notify the internal safety processing module of the safety alarm information;

[0011] Step 2: Upon receiving a security alarm, the security processing module executes the security processing procedure. Due to differences in chip architecture, operating system design, and the type of security triggered, the security processing procedure can be categorized into real-time security auditing via a security processing interrupt function and delayed security auditing after directly executing a security reset operation.

[0012] Step 3: After completing the security processing procedure, the security audit procedure is executed. Based on the type of security anomaly triggered, the corresponding security counter is updated (e.g., incremented or decremented). The updated counter result is checked. If the threshold is reached, a self-destruct procedure is initiated. If the threshold is not reached, plaintext security alarm data for the working environment is generated. A checksum is calculated and concatenated on the plaintext data. Then, the information is encrypted using the agreed encryption algorithm and key to form ciphertext data. Finally, the relevant ciphertext information is updated in the ATR's historical bytes, and a security reset operation is performed on the chip.

[0013] Step 4: Whenever the security sensor module of the IoT dedicated SIM card detects an abnormal working environment, it will sequentially follow Steps 1 to 3. The security processing module will execute the security processing procedure and the security audit procedure, record the working environment security alarm encrypted information into the historical bytes of ATR, and perform a security reset operation on the chip.

[0014] Step 5: IoT terminal devices monitor and report data, mainly in active and passive working modes. The policy processing module is mainly responsible for processing the functional policies in active and passive working modes, such as obtaining ATR messages through the IoT terminal electrical interface module and packaging and reporting security alarm encrypted information to the background cloud server monitoring platform through the IoT terminal mobile network communication module.

[0015] Step Six: After receiving the encrypted security alarm information, the backend cloud service network communication module transmits the data to the internal data processing module. The data processing module, according to the policy, transmits the encrypted data to the data verification module for decryption and verification. The data verification module uses the negotiated key or a pre-stored pairing key to decrypt the reported encrypted security alarm information of the working environment, performs integrity verification on the decrypted data, and finally returns the verification result to the data processing module.

[0016] Step 7: The data processing module verifies the verification results. If the verification passes, the reported data is considered authentic and reliable. This allows the module to obtain the cumulative number of alarms triggered by various security anomalies in the current IoT-dedicated SIM card. By retrieving and comparing the previously reported data stored on the server, the module can analyze the types of new security anomaly alarms and their corresponding alarm counts for the SIM card in recent times. The data processing module can also decide, based on functional policies, whether to send the verification results to the IoT terminal devices via the backend cloud service network communication module.

[0017] Step 8: If the background cloud server monitoring platform actively initiates a business process to obtain encrypted information of security alarms in the work environment, it will execute the passive working mode in step 5, step 6, and step 7 in sequence.

[0018] Furthermore, in step two, the real-time security audit of the security interrupt handling function is called and executed by the security handler, and the security audit program is executed in the function.

[0019] Furthermore, in step two, the delayed security audit following the direct execution of the security reset operation is a security processing procedure that directly executes the security reset operation. After the card is powered on again, the specific security anomaly type that caused the previous reset is obtained by reading the chip's security alarm register, and the security audit procedure is then executed.

[0020] Furthermore, in the active working mode of step five, at regular intervals, the policy processing module of the IoT terminal device controls the IoT terminal electrical interface module to reset the IoT SIM card electrical interface module in order to obtain the ATR information returned by the card, and packages the working environment security alarm encrypted information in the ATR historical bytes and reports it to the background cloud server monitoring platform through the IoT terminal mobile network communication module.

[0021] Furthermore, in the passive working mode of step five, before starting the relevant business process, the policy processing module of the IoT terminal device first resets the IoT SIM card electrical interface communication module by controlling the IoT terminal electrical interface communication module, and obtains the working environment security alarm encrypted information from the ATR historical bytes. After packaging the encrypted information through the IoT terminal mobile network communication module, it reports it to the background cloud server monitoring platform, and waits for the data processing module of the monitoring platform to return the data verification result. If the monitoring platform returns a verification success, the policy processing module continues to execute the subsequent business process; if the verification fails, the policy processing module terminates the current business process.

[0022] This invention has the following advantages:

[0023] This invention monitors the encrypted information of working environment security alarms in the historical ATR bytes of IoT-dedicated SIM cards in real time and feeds this information back to the R&D center's cloud server monitoring platform. If a false security alarm occurs during operation, the monitoring platform can decrypt and analyze the encrypted information to determine the type of security anomaly causing the alarm and the number of times the alarm has been triggered, thus quickly pinpointing the cause of the problem. This reduces the manpower and material costs required to locate the problem and allows for the development of preventative measures based on the cause. Attached Figure Description

[0024] Figure 1 System framework diagram of the present invention;

[0025] Figure 2 This is a flowchart of the process of the present invention. Detailed Implementation

[0026] This invention provides a working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices. The system includes a dedicated IoT SIM card, an IoT terminal device, and a backend cloud service monitoring platform. The dedicated IoT SIM card includes an IoT SIM card electrical interface communication module, a security processing module, and a security sensor module. The IoT terminal device includes an IoT terminal electrical interface communication module, a policy processing module, and an IoT terminal mobile network communication module. The backend cloud service monitoring platform includes a backend cloud service network communication module, a data processing module, and a data verification module. The security sensor module is connected to the security processing module. The security processing module is connected to the IoT SIM card electrical interface communication module. The IoT SIM card electrical interface communication module is connected to the IoT terminal electrical interface communication module. The IoT terminal electrical interface communication module is connected to the policy processing module. The policy processing module is connected to the IoT terminal mobile network communication module. The IoT terminal mobile network communication module is connected to the backend cloud service network communication module. The backend cloud service network communication module is connected to the data processing module. The data processing module is connected to the data verification module.

[0027] An operation method for a working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices, the operation method steps are as follows:

[0028] Step 1: Detect abnormal operating environments such as voltage, current, temperature, and laser through the safety sensor module, and notify the internal safety processing module of the safety alarm information;

[0029] Step 2: Upon receiving a security alarm, the security processing module executes the security processing procedure. Due to differences in chip architecture, operating system design, and the type of security triggered, the security processing procedure can be categorized into real-time security auditing via a security processing interrupt function and delayed security auditing after directly executing a security reset operation.

[0030] Step 3: After completing the security processing procedure, the security audit procedure is executed. Based on the type of security anomaly triggered, the corresponding security counter is updated (e.g., incremented or decremented). The updated counter result is checked. If the threshold is reached, a self-destruct procedure is initiated. If the threshold is not reached, plaintext security alarm data for the working environment is generated. A checksum is calculated and concatenated on the plaintext data. Then, the information is encrypted using the agreed encryption algorithm and key to form ciphertext data. Finally, the relevant ciphertext information is updated in the ATR's historical bytes, and a security reset operation is performed on the chip.

[0031] Step 4: Whenever the security sensor module of the IoT dedicated SIM card detects an abnormal working environment, it will sequentially follow Steps 1 to 3. The security processing module will execute the security processing procedure and the security audit procedure, record the working environment security alarm encrypted information into the historical bytes of ATR, and perform a security reset operation on the chip.

[0032] Step 5: IoT terminal devices monitor and report data, mainly in active and passive working modes. The policy processing module is mainly responsible for processing the functional policies in active and passive working modes, such as obtaining ATR messages through the IoT terminal electrical interface module and packaging and reporting security alarm encrypted information to the background cloud server monitoring platform through the IoT terminal mobile network communication module.

[0033] Step Six: After receiving the encrypted security alarm information, the backend cloud service network communication module transmits the data to the internal data processing module. The data processing module, according to the policy, transmits the encrypted data to the data verification module for decryption and verification. The data verification module uses the negotiated key or a pre-stored pairing key to decrypt the reported encrypted security alarm information of the working environment, performs integrity verification on the decrypted data, and finally returns the verification result to the data processing module.

[0034] Step 7: The data processing module verifies the verification results. If the verification passes, the reported data is considered authentic and reliable. This allows the module to obtain the cumulative number of alarms triggered by various security anomalies in the current IoT-dedicated SIM card. By retrieving and comparing the previously reported data stored on the server, the module can analyze the types of new security anomaly alarms and their corresponding alarm counts for the SIM card in recent times. The data processing module can also decide, based on functional policies, whether to send the verification results to the IoT terminal devices via the backend cloud service network communication module.

[0035] Step 8: If the background cloud server monitoring platform actively initiates a business process to obtain encrypted information of security alarms in the work environment, it will execute the passive working mode in step 5, step 6, and step 7 in sequence.

[0036] In this embodiment, the real-time security audit of the security interrupt handling function in step two is that the security handling program calls and executes the security interrupt handling function, and the security audit program is executed in the function.

[0037] In this embodiment, the delayed security audit after directly executing the security reset operation in step two is that the security processing program directly executes the security reset operation. After the card is powered on again, the specific security anomaly type that caused the previous reset is obtained by reading the chip's security alarm register, and the security audit program is executed.

[0038] In this embodiment, the active working mode in step five is that at regular intervals, the policy processing module of the IoT terminal device controls the IoT terminal electrical interface communication module to reset the IoT SIM card electrical interface communication module in order to obtain the ATR information returned by the card, and packages the working environment security alarm encrypted information in the ATR historical bytes and reports it to the background cloud server monitoring platform through the IoT terminal mobile network communication module.

[0039] In this embodiment, the passive working mode in step five involves the IoT terminal device's policy processing module resetting the IoT SIM card's electrical interface communication module by controlling the IoT terminal's electrical interface communication module before initiating the relevant business process. It then obtains the encrypted information of the working environment security alarm from the ATR historical bytes, packages the encrypted information through the IoT terminal's mobile network communication module, and reports it to the backend cloud server monitoring platform. The module then waits for the monitoring platform's data processing module to return the data verification result. If the monitoring platform returns a successful verification, the policy processing module continues to execute the subsequent business process; if the verification fails, the policy processing module terminates the current business process.

[0040] This embodiment is not limited to IoT-specific SIM cards, but also applies to security chips with security attributes based on the ISO 7816-3 contact communication method. Examples include traditional contact smart cards, embedded SIM cards (eSIM), security element chips (SE), embedded security elements (eSE), and converged chips (e.g., NFC+eSE). All of these can record and report security alarm information of the working environment according to the method described in this patent, enabling rapid identification of false security alarms.

[0041] In this embodiment, APDU command interaction can also be used to obtain work environment security alarm information. The reason why this patent uses the method of recording in ATR and obtaining through reset is that even if the card is in a dead or broken state, or if the internal memory of the operating system is disordered due to certain factors and the operating system cannot respond to APDU commands, the ATR information (i.e., work environment security alarm information) can still be obtained through reset.

[0042] In this embodiment, extending its application, because the ATR information of the card contains encrypted and checksum information, the backend server can use decryption and verification to verify the validity of the ATR information. If the encrypted plaintext information incorporates the card's serial number, this patent may also be applied to device binding between the SIM card and the IoT terminal device. Since some terminals are unattended for extended periods, attackers can use brute-force methods to replace the original IoT-specific SIM card in the device. The replaced SIM card, lacking knowledge of the valid encryption key, data format, and checksum generation method, generates an incorrect encrypted ATR. Whenever a business process is initiated, the IoT terminal device reports the encrypted information in the ATR. When the backend server detects that the uploaded encrypted information fails decryption verification, it determines that the current SIM card may have been replaced. Therefore, the backend server will terminate the current business process of the IoT terminal device, as well as subsequent new business process requests initiated by the IoT terminal device. This ensures that user privacy is not compromised.

[0043] Although specific embodiments of the present invention have been described in detail with reference to the accompanying drawings, this should not be construed as limiting the scope of protection of this patent. Various modifications and variations that can be made by those skilled in the art without inventive effort within the scope described in the claims still fall within the scope of protection of this patent.

Claims

1. An operation method for a working environment security detection and alarm system based on a dedicated SIM card for Internet of Things terminal devices, characterized in that: The operation method steps are as follows: Step 1: Detect abnormal operating environments such as voltage, current, temperature, and laser through the safety sensor module, and notify the internal safety processing module of the safety alarm information; Step 2: After receiving the security alarm information, the security processing module executes the security processing program. The security processing program is divided into real-time security auditing of the security processing interrupt function and delayed security auditing after directly executing the security reset operation, depending on the chip architecture, operating system design and the type of security triggered. Step 3: After completing the security processing procedure, the security audit procedure is executed. Based on the type of security anomaly triggered, the corresponding security counter is updated by incrementing or decrementing by one. The updated security counter result is checked. If the threshold is reached, a self-destruct procedure is initiated. If the threshold is not reached, plaintext information data of the working environment security alarm is organized, and a checksum is calculated and concatenated on the plaintext information data. Then, the above information is encrypted according to the agreed encryption algorithm and key to form ciphertext information data. Finally, the ciphertext information data is updated to the historical bytes of the ATR, and a security reset operation is performed on the chip. Step 4: Whenever the security sensor module of the IoT dedicated SIM card detects an abnormal working environment, the security processing module will execute the security processing procedure and security audit procedure in sequence according to Step 1 to Step 3, record the working environment security alarm encrypted information data into the historical bytes of ATR, and perform a security reset operation on the chip. Step 5: IoT terminal devices monitor and report data in two modes: active and passive. The policy processing module is responsible for processing the functional policies in both active and passive modes. The system obtains ATR messages through the electrical interface module of the IoT terminal and packages and reports the encrypted security alarm information data to the back-end cloud server monitoring platform through the mobile network communication module of the IoT terminal. Step Six: After receiving the encrypted security alarm information data, the background cloud service network communication module transmits the data to the internal data processing module. The data processing module transmits the encrypted data to the data verification module for decryption and verification according to the policy. The data verification module uses the negotiated key or the pre-loaded pairing key to decrypt the reported encrypted security alarm information data of the working environment, performs integrity verification on the decrypted data, and finally returns the verification result to the data processing module. Step 7: The data processing module verifies the verification results. If the verification passes, the reported data is considered to be true and reliable. The module then obtains the cumulative number of alarms triggered by various security anomalies in the current IoT dedicated SIM card. By retrieving and comparing the previously reported data stored in the server, the module analyzes the types of security anomaly alarms and the number of alarms that have been added to the SIM card recently. The data processing module decides whether to send the verification results to the IoT terminal device through the background cloud service network communication module based on the functional strategy. Step 8: If the background cloud server monitoring platform actively initiates a business process to obtain encrypted information data of security alarms in the work environment, it will execute the passive working mode in step 5, step 6, and step 7 in sequence.

2. The operating method of the working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices as described in claim 1, characterized in that: The real-time security audit in step two involves the security interrupt handling function being called and executed by the security handler, within which the security audit program is executed.

3. The operating method of the working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices as described in claim 1, characterized in that: The delayed security audit following the direct execution of the security reset operation in step two is that the security processing program directly executes the security reset operation. After the card is powered on again, the specific security anomaly type that caused the previous reset is obtained by reading the chip's security alarm register, and the security audit program is executed.

4. The operating method of the working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices as described in claim 1, characterized in that: In the active working mode of step five, at regular intervals, the policy processing module of the IoT terminal device controls the IoT terminal electrical interface module to reset the IoT SIM card electrical interface module, obtains the ATR information returned by the card, and packages and reports the working environment security alarm encrypted information data in the ATR historical bytes to the background cloud server monitoring platform through the IoT terminal mobile network communication module.

5. The operating method of the working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices as described in claim 1, characterized in that: In the passive working mode of step five, before starting the relevant business process, the policy processing module of the IoT terminal device first resets the IoT SIM card electrical interface communication module by controlling the IoT terminal electrical interface communication module, and obtains the encrypted information data of the working environment security alarm in the ATR historical bytes. After packaging the encrypted information data through the IoT terminal mobile network communication module, it reports it to the background cloud server monitoring platform, and waits for the data processing module of the monitoring platform to return the data verification result. If the monitoring platform returns that the verification is successful, the policy processing module continues to execute the subsequent business process. If the verification fails, the policy processing module terminates the current business process.

6. A working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices, used to implement the operating method of the working environment security detection and alarm system based on a dedicated SIM card for IoT terminal devices as described in any one of claims 1-5, comprising a dedicated IoT SIM card, an IoT terminal device, and a backend cloud service monitoring platform, characterized in that: The IoT-dedicated SIM card includes an IoT SIM card electrical interface communication module, a security processing module, and a security sensor module. The IoT terminal device includes an IoT terminal electrical interface communication module, a policy processing module, and an IoT terminal mobile network communication module. The background cloud service monitoring platform includes a background cloud service network communication module, a data processing module, and a data verification module. The security sensor module is connected to the security processing module. The security processing module is connected to the IoT SIM card electrical interface communication module. The IoT SIM card electrical interface module is connected to the IoT terminal electrical interface communication module. The IoT terminal electrical interface communication module is connected to the policy processing module. The policy processing module is connected to the IoT terminal mobile network communication module. The IoT terminal mobile network communication module is connected to the background cloud service network communication module. The background cloud service network communication module is connected to the data processing module. The data processing module is connected to the data verification module.

Citation Information

Patent Citations

  • Smart card and method for storing security detectioninformation

    KR1020040106075A

  • Fault detection method

    US20020124179A1