Communication method and apparatus, electronic device, storage medium and product

CN119420470BActive Publication Date: 2026-09-18CHINA MOBILE COMM LTD RES INST +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411092989.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-09
Publication Date
2026-09-18
Estimated Expiration
2044-08-09

AI Technical Summary

Technical Problem

然而,在离线状态下,SIM卡无法验证应用所提供的密钥的合法性,从而导致SIM卡和应用之间通信的安全性降低

Benefits of technology

[0011] As will be described in detail below, a communication method, apparatus, electronic device, storage medium, and product according to embodiments of the present disclosure are disclosed. The present disclosure sends first information to a SIM card via a first application. The first information is obtained by encrypting a temporary key and a first PIN using the SIM card's public key. After the SIM card successfully verifies the first PIN, it can communicate with the first application using the temporary key. Thus, the present disclosure uses the first PIN to verify the legitimacy of the temporary key generated by the first application. When the verification is successful, it means that the legitimacy of the temporary key is confirmed and can be used for encryption of sensitive information in subsequent interactions between the first application and the SIM card. In this way, secure communication between the first application and the SIM card can be achieved offline without the need for a pre-set key. Furthermore, the temporary key is only valid within the validity period of this verification, allowing for flexible adaptation to dynamically changing environments and avoiding security risks caused by long-term unchanging keys, further improving the security of the interaction process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420470B_ABST
    Figure CN119420470B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of communication, and particularly provides a communication method and device, electronic equipment, storage medium and product. The present disclosure receives first information from a first application, the first information being encrypted by using a SIM card public key on a temporary key and a first PIN; decrypts the first information by using a SIM card private key to obtain the temporary key and the first PIN; and when the identity verification of the first PIN is passed, communicates with the first application by using the temporary key. The present disclosure can realize the secure communication between the first application and the SIM card in an offline state without pre-setting a key. Meanwhile, the temporary key is only valid within the validity period of this verification, can flexibly adapt to the dynamically changing environment, avoids the security risks caused by the long-term unchanged key, and further improves the security of the interactive process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a communication method and apparatus, electronic device, storage medium and product. Background Technology

[0002] Currently, the transmission between the SIM card and the application within the same terminal is encrypted using a negotiated key or a key provided by the application. However, in offline mode, the SIM card cannot verify the legitimacy of the key provided by the application, thus reducing the security of communication between the SIM card and the application. Summary of the Invention

[0003] This disclosure is made in view of the above-mentioned problems. This disclosure provides a communication method and apparatus, an electronic device, a storage medium, and a product.

[0004] According to one aspect of this disclosure, a communication method is provided, comprising: receiving first information from a first application, the first information being obtained by encrypting a temporary key and a first PIN using a SIM card public key; decrypting the first information using a SIM card private key to obtain the temporary key and the first PIN; and communicating with the first application using the temporary key when the authentication of the first PIN is successful; wherein the first application and the SIM card are located on the same terminal.

[0005] According to another aspect of this disclosure, a communication method is provided, comprising: encrypting a temporary key and a first PIN using a SIM card public key to obtain first information; wherein the first PIN is used for SIM card authentication of a first application; sending the first information to the SIM card; and communicating with the SIM card using the temporary key; wherein the first application and the SIM card are located on the same terminal.

[0006] According to another aspect of this disclosure, a communication device is provided, comprising: a receiving module for receiving first information from a first application, the first information being obtained by encrypting a temporary key and a first PIN using a SIM card public key; a decryption module for decrypting the first information using a SIM card key to obtain the temporary key and the first PIN; and an authentication module for communicating with the first application using the temporary key when the authentication of the first PIN is successful; wherein the first application and the SIM card are located on the same terminal.

[0007] According to another aspect of this disclosure, a communication device is provided, comprising: an encryption module that encrypts a temporary key and a first PIN using a SIM card public key to obtain first information; wherein the first PIN is used for authentication of the first application by the SIM card; a sending module that sends the first information to the SIM card; and a communication module that communicates with the SIM card using the temporary key; wherein the first application and the SIM card are located on the same terminal.

[0008] According to another aspect of this disclosure, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the method described in any of the above embodiments.

[0009] According to another aspect of this disclosure, a computer-readable storage medium is provided that stores a computer program / instructions thereon, which, when executed by a processor, implement the methods described in any of the above embodiments.

[0010] According to another aspect of this disclosure, a computer program product is provided, including a computer program / instructions that, when executed by a processor, implement the methods described in any of the above embodiments.

[0011] As will be described in detail below, a communication method, apparatus, electronic device, storage medium, and product according to embodiments of the present disclosure are disclosed. The present disclosure sends first information to a SIM card via a first application. The first information is obtained by encrypting a temporary key and a first PIN using the SIM card's public key. After the SIM card successfully verifies the first PIN, it can communicate with the first application using the temporary key. Thus, the present disclosure uses the first PIN to verify the legitimacy of the temporary key generated by the first application. When the verification is successful, it means that the legitimacy of the temporary key is confirmed and can be used for encryption of sensitive information in subsequent interactions between the first application and the SIM card. In this way, secure communication between the first application and the SIM card can be achieved offline without the need for a pre-set key. Furthermore, the temporary key is only valid within the validity period of this verification, allowing for flexible adaptation to dynamically changing environments and avoiding security risks caused by long-term unchanging keys, further improving the security of the interaction process.

[0012] It should be understood that both the foregoing general description and the following detailed description are exemplary and intended to provide further illustration of the claimed technology. Attached Figure Description

[0013] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of the embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the disclosure and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0014] Figure 1 This is a schematic diagram illustrating a communication system according to an embodiment of the present disclosure.

[0015] Figure 2 This is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.

[0016] Figure 3 This is an interactive diagram illustrating a signature method according to an embodiment of the present disclosure.

[0017] Figure 4 This is an interactive diagram illustrating PIN acquisition according to an embodiment of the present disclosure.

[0018] Figure 5 This is an interactive diagram illustrating data transmission in an embodiment of the present disclosure.

[0019] Figure 6 This is an interactive diagram illustrating the verification status cancellation in an embodiment of this disclosure.

[0020] Figure 7 This is a block diagram illustrating a communication device according to an embodiment of the present disclosure.

[0021] Figure 8 This is a block diagram illustrating another communication device according to an embodiment of the present disclosure.

[0022] Figure 9 This is a hardware block diagram illustrating an electronic device according to an embodiment of the present disclosure.

[0023] Figure 10 This is a schematic diagram illustrating a computer program product according to an embodiment of the present disclosure. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of this disclosure more apparent, exemplary embodiments according to this disclosure will now be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this disclosure, and not all embodiments of this disclosure. It should be understood that this disclosure is not limited to the exemplary embodiments described herein.

[0025] Currently, in existing technologies, the main secure communication methods between the SIM card and the application within the same terminal are as follows:

[0026] 1. Data transmitted between the SIM card and the application is not encrypted and is transmitted directly in plaintext.

[0027] 2. During the interaction, use the key provided by the application to encrypt the transmitted sensitive data directly.

[0028] 3. The SIM card negotiates a key with the application to obtain a session key, and then uses the session key to encrypt sensitive data.

[0029] However, in Option 1, the lack of encryption may lead to the leakage of sensitive user information, thereby causing serious business risks.

[0030] Schemes 2 and 3 require online verification of the key. Therefore, for some offline applications, it's impossible to obtain a reliable key online to encrypt sensitive data, nor can a key signature be obtained for verification and encryption of sensitive information. If a pre-defined key agreed upon between the SIM card and the application is used, updating this key typically requires physical access to the device or complex configuration changes, making timely updates difficult in practice. This increases the risk of data leakage and associated costs.

[0031] To address the aforementioned problems, this disclosure provides a communication method applicable to a communication system, which includes at least: a first application and a SIM card. Further, it may also include a communication module and a security management platform. For example, see [link to relevant documentation]. Figure 1 , Figure 1 This is a schematic diagram illustrating a communication system according to an embodiment of the present disclosure, such as... Figure 1 As shown, the first application, SIM card, and security management platform can interact through the communication module.

[0032] This disclosure performs PIN verification on the first application before communication, and then uses the key provided by the first application for encryption after successful verification. Figure 2 This is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure, such as... Figure 2 As shown, the method may include:

[0033] S201, the first application uses the SIM card public key to encrypt the temporary key and the first PIN to obtain the first information.

[0034] S202, the first application sends the first information to the SIM card.

[0035] S203, the SIM card receives the first information from the first application.

[0036] S204, the SIM card uses the SIM card private key to decrypt the first information to obtain the temporary key and the first PIN.

[0037] S205, when the authentication of the first PIN is successful, the SIM card uses the temporary key to communicate with the first application.

[0038] In this embodiment, the first application may include, but is not limited to, at least one of the following: mobile application (e.g., terminal APP), desktop application, and browser application.

[0039] The first application and the SIM card are located on the same terminal.

[0040] Before communication, the SIM card can generate a public key and a private key for encryption, send the public key to the first application, and store the private key locally on the SIM card.

[0041] After verifying the integrity and security of the SIM card public key, the first application can generate at least one temporary key for further encrypting information. This temporary key can further encrypt subsequent interaction processes based on the preset SIM card public and private keys, thereby ensuring the security of the interaction information to a certain extent.

[0042] The temporary key is only valid within the validity period of this verification. This reduces the exposure of sensitive information and thus lowers the risk of malicious exploitation.

[0043] The number and type of temporary keys are not specifically limited here; you can decide based on the actual situation. The types of temporary keys include, but are not limited to, at least one of the following: symmetric key, MAC key, asymmetric key, and session key.

[0044] For example, a temporary key may include an encryption key and a MAC key. The encryption key is used to encrypt sensitive information to obtain ciphertext, and the MAC key is used to determine the MAC value of the ciphertext, thereby realizing the integrity verification of the sensitive information.

[0045] When the first application generates a temporary key and sends it to the SIM card, it also needs to send the first PIN to the SIM card to verify the validity of the temporary key. Furthermore, the SIM card's public key can be used to encrypt the information carrying the temporary key and the first PIN to obtain the initial information, thereby preventing the leakage of the temporary key and the first PIN to a certain extent and improving the security of subsequent interactions.

[0046] The first information can be presented in any form, including but not limited to: instructions (such as APDU instructions) and messages.

[0047] The first PIN is used to verify the user's identity and must be re-entered for each verification.

[0048] After receiving the first message, the SIM card can use the locally stored SIM card private key to decrypt the first message and obtain the temporary key and the first PIN.

[0049] Next, the SIM card can authenticate the first PIN. When the authentication is successful, it confirms that the incoming temporary key was generated by the legitimate first application. The SIM card can store the temporary key for subsequent encrypted interactions.

[0050] In summary, this disclosure utilizes a first PIN to verify the legitimacy of the temporary key generated by the first application. When the verification passes, the legitimacy of the temporary key is confirmed, and it can be used for encryption of sensitive information in subsequent interactions between the first application and the SIM card. Thus, secure communication between the first application and the SIM card can be achieved offline without the need for a pre-set key. Furthermore, the temporary key is only valid within the validity period of this verification, allowing for flexible adaptation to dynamically changing environments and avoiding security risks arising from long-term unchanging keys, further enhancing the security of the interaction process.

[0051] Before step S201, to ensure the security of the SIM card public key during transmission, a signing key can be used to sign the SIM card public key, thereby obtaining signature information. The first application can then use the signing key to decrypt the signature information, thus obtaining a secure and reliable SIM card public key. The signature information includes at least a signature and the SIM card public key.

[0052] For example, the signature key can be generated by the security management platform or by the SIM card itself.

[0053] The signature key can be a preset key or generated offline, and you can decide based on the actual situation.

[0054] The following will be explained in conjunction with specific embodiments.

[0055] In one illustrative embodiment, the security management platform can generate a signing public key and a signing private key. The signing private key can be used to sign the SIM card public key, and the signing public key is used for verification. The security management platform can send the signing public key to a first application and store it locally in the first application. After receiving the signing information, the first application can use the locally stored signing public key to verify it. If the verification passes, the first application saves the SIM card public key locally.

[0056] The step of signing the SIM card's public key can be completed by the security management platform or by the SIM card itself.

[0057] When this step is completed by the security management platform, the SIM card needs to send its public key to the security management platform. The security management platform then uses its private key to sign the SIM card's public key to obtain the signature information. In response to receiving a signature acquisition request from the first application, the platform sends the signature information to the first application, thereby enabling the security management platform to comprehensively monitor and manage the terminal and improving management efficiency to a certain extent.

[0058] When this step is completed by the SIM card, the security management platform needs to send a signing private key to the SIM card. The SIM card then uses the signing private key to self-sign its public key, obtaining the signature information. In response to a signature retrieval request received from the first application, the platform sends the signature information to the first application. This can, to some extent, prevent the SIM card's public key from being leaked during the interaction between the security management platform and the SIM card, thereby improving the security of subsequent communication processes. For details, please refer to [reference needed]. Figure 3 , Figure 3 This is an interactive diagram illustrating a signature method according to an embodiment of the present disclosure.

[0059] When the first application interacts with the SIM card for the first time, the SIM card does not have a known PIN. Having obtained the SIM card's public key, the first application can use the public key to encrypt the obtained second PIN, obtain fourth information, and send the fourth information to the SIM card. The SIM card decrypts the fourth information to obtain the second PIN and stores it locally.

[0060] The second PIN is the PIN code initially set by the user, and the first PIN is the PIN code entered by the user when logging in. If the two are the same, the verification is successful; if they are different, the verification is unsuccessful.

[0061] Optionally, after obtaining the second PIN, the SIM card can also send response information to the first application. The response information is used to indicate the reception status of the third information. The form of the response information is not limited, and includes, but is not limited to, at least one of the following: a pop-up window, a text message, or a status code.

[0062] For example, please refer to Figure 4 , Figure 4 This is an interactive diagram illustrating PIN acquisition according to an embodiment of the present disclosure, such as... Figure 4 As shown, in the initial stage, the second PIN is set by the user. The first application obtains the second PIN, encrypts it using the SIM card's public key, and encapsulates it into an APDU (i.e., the fourth piece of information). Next, the APDU is sent to the SIM card, which decrypts it using its private key to obtain the second PIN and stores it locally. Finally, the SIM card sends a response message to the first application.

[0063] When the SIM card already has a locally stored second PIN, and the user has not logged in to verify the PIN, or the current PIN verification fails, in step S205, the verification process for the first PIN can be as follows: After receiving the first PIN, the SIM card can use the second PIN to authenticate the first PIN. When the second PIN is the same as the first PIN, it means that the authentication of the first PIN is successful. The SIM card can store a temporary key and use the temporary key to communicate with the first application.

[0064] Optionally, after the first PIN verification is successful, the SIM card can mark the first application with a verification success identifier. The specific form of the identifier is not limited, and includes, but is not limited to, text, numbers, and characters.

[0065] The SIM card needs to update the temporary key every time it obtains one. This prevents the key from remaining unchanged for an extended period, which could increase the risk of it being compromised. Furthermore, compared to pre-set keys, updating temporary keys is more convenient, faster, and less costly.

[0066] The SIM card can store temporary keys in a preset location, making it easy to trace operations within a certain time period.

[0067] or,

[0068] Replacing the stored location with a temporary key in the preset location saves storage space and reduces the possibility of historical temporary key leakage to a certain extent, thereby improving security.

[0069] Once the first PIN is verified and within the verification period, the first application and the SIM card can communicate using the temporary key.

[0070] The temporary key can encrypt all information or only sensitive information.

[0071] The sensitive information here may include, but is not limited to, at least one of the following: name, gender, age, ID number, phone number, email address, home address, and account information.

[0072] The sender of sensitive information can be either the primary application or the SIM card.

[0073] In one illustrative embodiment, when the sender of the sensitive information is a first application, the specific steps may include: when the first application obtains the first sensitive information, it can encrypt the first sensitive information using a temporary key to obtain second information, and then send the second information to the SIM card. After receiving the second information, the SIM card can decrypt the second information using the temporary key to obtain the first sensitive information.

[0074] Please refer to the details. Figure 5 , Figure 5 This is an interactive diagram illustrating data transmission in an embodiment of the present disclosure, such as... Figure 5 As shown in Figure 501, after obtaining sensitive information (i.e., the first sensitive information), the first application sequentially encrypts and encapsulates the sensitive information using a symmetric key and a MAC key (i.e., a temporary key) to obtain an APDU instruction (i.e., the second information). At this time, the APDU instruction carries at least the encrypted first sensitive information and the MAC value of the first sensitive information. After the SIM card verifies the MAC, it is decrypted using the symmetric key to obtain the first sensitive information.

[0075] And / or,

[0076] In another illustrative embodiment, when the sender of the sensitive information is a SIM card, the specific steps may include: after obtaining the initial information, the SIM card may optionally process the initial information according to the actual situation. The SIM card may use the temporary key to encrypt the second sensitive information to obtain the third information; and send the third information to the first application. After receiving the third information, the first application may use the temporary key to decrypt the third information to obtain the second sensitive information.

[0077] For example, such as Figure 5 As shown in Figure 502, after the SIM card performs calculations and stores the data (i.e., the second sensitive information) (i.e., the data processing described above), it encrypts the data using a symmetric key, calculates the ciphertext MAC using a MAC key, and encapsulates it into an APDU (i.e., the third information). At this time, the APDU instruction carries at least the encrypted second sensitive information and the MAC value of the second sensitive information. After the first application verifies the MAC, it decrypts the data using the symmetric key to obtain the first sensitive information.

[0078] When the first application meets the preset conditions, the first application can send a cancellation command to the SIM card.

[0079] The preset conditions include, but are not limited to, at least one of the following: reaching a first preset duration, switching screens, or reaching a second preset duration of inactivity. The first and second preset durations can be determined based on actual circumstances and are not subject to further restrictions here.

[0080] Upon receiving a cancellation command, the SIM card can cancel the identifier that enabled the first application verification. Furthermore, it can delete the locally stored temporary key, thereby preventing its leakage and improving security.

[0081] Optionally, after cancellation is complete, the SIM card can send a feedback command to the first application to indicate the completion status of the cancellation command. Furthermore, the feedback command can also instruct the first application to delete the temporary key stored locally, thereby preventing the leakage of the temporary key and improving security.

[0082] For easier understanding, please refer to Figure 6 , Figure 6 This is an interactive diagram illustrating the verification status cancellation of an embodiment of this disclosure, such as... Figure 6 As shown, when the first application detects screen switching or prolonged inactivity, it can send a deregistration verification status APDU (i.e., deregistration command) to the SIM card. The SIM card then verifies the deregistration as successful and deletes the MAC key and symmetric key (i.e., temporary key). After completing the operation, the SIM card can inform the first application whether the deregistration was successful or failed (i.e., feedback command). When the feedback indicates successful deregistration, the first application can delete the MAC key and symmetric key stored locally.

[0083] The above is a communication method provided by this disclosure. The above embodiments can be combined according to actual conditions, and no specific limitations are made here.

[0084] In addition, this disclosure also provides a communication device. Figure 7 A structural block diagram of a communication device provided in an embodiment of this disclosure, such as... Figure 7 As shown, the communication device 700 includes:

[0085] The receiving module 701 is used to receive first information from the first application, wherein the first information is obtained by encrypting a temporary key and a first PIN using the SIM card public key.

[0086] The decryption module 702 is used to decrypt the first information using the SIM card key to obtain the temporary key and the first PIN.

[0087] The verification module 703 is used to communicate with the first application using the temporary key when the authentication of the first PIN is successful; wherein the first application and the SIM card are set on the same terminal.

[0088] In one exemplary embodiment, the communication device 700 is further configured to authenticate the first PIN using a pre-stored second PIN; store the temporary key when the second PIN is the same as the first PIN; and communicate with the first application using the temporary key.

[0089] In one exemplary embodiment, the communication device 700 is further configured to receive fourth information from the first application, the fourth information being obtained by encrypting the second PIN using the SIM card public key; and to store the second PIN.

[0090] In one exemplary embodiment, the communication device 700 is further configured to store the temporary key in a preset location, or to replace data already stored in the preset location with the temporary key.

[0091] In one exemplary embodiment, the communication device 700 is further configured to receive second information from the first application, the second information being obtained by encrypting first sensitive information using the temporary key; and to decrypt the second information using the temporary key to obtain the first sensitive information.

[0092] And / or,

[0093] The temporary key is used to encrypt the second sensitive information to obtain the third information; and the third information is sent to the first application.

[0094] In one exemplary embodiment, the communication device 700 is further configured such that the temporary key includes: an encryption key and a MAC key; wherein the encryption key is used to encrypt sensitive information to obtain ciphertext; and the MAC key is used to determine the MAC value of the ciphertext.

[0095] In one exemplary embodiment, the communication device 700 is further configured to receive a logout command from the first application; the logout verification passes an identifier, and the temporary key is deleted.

[0096] In one exemplary embodiment, the communication device 700 is further configured to generate a key pair, the key pair including: a SIM card public key and a SIM card private key; to sign the SIM card public key using a signing private key to obtain signature information; and to send the signature information to the first application in response to receiving a signature acquisition request from the first application.

[0097] In addition, this disclosure also provides a communication device. Figure 8 A structural block diagram of a communication device provided in an embodiment of this disclosure, such as... Figure 8 As shown, the communication device 800 includes:

[0098] The encryption module 801 is used to encrypt the temporary key and the first PIN using the SIM card public key to obtain the first information; wherein the first PIN is used for the SIM card to authenticate the first application.

[0099] The sending module 802 is used to send the first information to the SIM card.

[0100] The communication module 803 is used to communicate with the SIM card using the temporary key; wherein the first application and the SIM card are located on the same terminal.

[0101] In one exemplary embodiment, the communication device 800 is further configured to encrypt the first sensitive information using the temporary key to obtain the second information; and to send the second information to the SIM card;

[0102] And / or,

[0103] Receive third information, which is obtained by encrypting the second sensitive information using the temporary key.

[0104] In one exemplary embodiment, the communication device 800 is further configured such that the temporary key includes: an encryption key and a MAC key; wherein the encryption key is used to encrypt sensitive information to obtain ciphertext; and the MAC key is used to determine the MAC value of the ciphertext.

[0105] In one exemplary embodiment, the communication device 800 is further configured to send a cancellation instruction to the SIM card; the cancellation instruction is used to instruct the SIM card to cancel the verification pass identifier and delete the temporary key.

[0106] In one exemplary embodiment, the communication device 800 is further configured to send a signature acquisition request to the SIM card and receive the signature information from the SIM card.

[0107] In one exemplary embodiment, the communication device 800 is further configured to encrypt the second PIN using the SIM card public key to obtain fourth information; and to send the fourth information to the SIM card.

[0108] Figure 9 This is a hardware block diagram of an electronic device provided according to an embodiment of the present disclosure. The electronic device 900 according to an embodiment of the present disclosure includes at least a memory, a processor, and a computer program stored in the memory. The processor executes the computer program to implement the signal transmission method described in any of the above embodiments.

[0109] Figure 9The illustrated electronic device 900 specifically includes a central processing unit (CPU) 901, a graphics processing unit (GPU) 902, and a memory 903. These units are interconnected via a bus 904. The CPU 901 and / or GPU 902 can function as the aforementioned processor, and the memory 903 can function as the aforementioned memory storing computer-readable instructions. Furthermore, the electronic device 900 may also include a communication unit 905, a storage unit 906, an output unit 907, an input unit 908, and an external device 909, all of which are also connected to the bus 904.

[0110] Figure 10 This is a schematic diagram of a computer-readable storage medium provided in an embodiment of this disclosure. (As shown...) Figure 10 As shown, a computer-readable storage medium 1000 according to an embodiment of the present disclosure stores a computer-readable program / instructions 1001 thereon. When executed by a processor, the computer-readable program / instructions 1001 implements the signal transmission method described in any of the preceding embodiments of the present disclosure. The computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, optical disk, magnetic disk, etc.

[0111] This disclosure further provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the communication method described in any of the preceding embodiments of this disclosure.

[0112] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0113] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0114] Additionally, as used herein, the “or” used in a list of items beginning with “at least one” indicates a separate list, such that a list of, for example, “at least one of A, B, or C” means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word “exemplary” does not imply that the described example is preferred or better than other examples.

[0115] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0116] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.

[0117] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0118] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

Claims

1. A communication method characterized by comprising: Applied to a SIM card, the method includes: Receive first information from the first application, the first information being obtained by encrypting a temporary key and a first PIN using the SIM card public key; The first information is decrypted using the SIM card private key to obtain the temporary key and the first PIN; When the authentication of the first PIN is successful, the temporary key is used to communicate with the first application; The first application and the SIM card are located on the same terminal.

2. The method of claim 1, wherein, When the PIN authentication is successful, communicating with the first application using the temporary key includes: The first PIN is authenticated using a pre-stored second PIN; When the second PIN is the same as the first PIN, the temporary key is stored; The temporary key is used to communicate with the first application.

3. The method of claim 2, wherein, Before authenticating the first PIN using a pre-stored second PIN, the method further includes: Receive fourth information from the first application, wherein the fourth information is obtained by encrypting the second PIN using the SIM card public key; Store the second PIN.

4. The method according to claim 2, characterized in that, The storage of the temporary key includes: The temporary key can be stored in a preset location, or the temporary key can be used to replace the data already stored in the preset location.

5. The method according to claim 1, characterized in that, The step of communicating with the first application using the temporary key includes: Receive second information from the first application, the second information being obtained by encrypting first sensitive information using the temporary key; and decrypt the second information using the temporary key to obtain the first sensitive information. And / or, The temporary key is used to encrypt the second sensitive information to obtain the third information; and the third information is sent to the first application.

6. The method according to claim 1, characterized in that, The temporary key includes: an encryption key and a MAC key; The encryption key is used to encrypt sensitive information to obtain ciphertext; The MAC key is used to determine the MAC value of the ciphertext.

7. The method according to claim 1, characterized in that, The method further includes: Receive a logout command from the first application; The verification pass is cancelled, and the temporary key is deleted.

8. The method according to claim 1, characterized in that, The method further includes: Generate a key pair, which includes: a SIM card public key and a SIM card private key; The public key of the SIM card is signed using the signing private key to obtain signature information; In response to receiving a signature acquisition request from the first application, the signature information is sent to the first application.

9. A communication method, characterized in that, Applied to a first application, the method includes: The temporary key and the first PIN are encrypted using the SIM card's public key to obtain the first information; wherein, the first PIN is used for the SIM card to authenticate the first application. Send the first information to the SIM card; The temporary key is used to communicate with the SIM card; The first application and the SIM card are located on the same terminal.

10. The method according to claim 9, characterized in that, The step of communicating with the SIM card using the temporary key includes: The first sensitive information is encrypted using the temporary key to obtain the second information; and the second information is sent to the SIM card. And / or, Receive third information, which is obtained by encrypting the second sensitive information using the temporary key.

11. The method according to claim 9, characterized in that, The temporary key includes: an encryption key and a MAC key; The encryption key is used to encrypt sensitive information to obtain ciphertext; The MAC key is used to determine the MAC value of the ciphertext.

12. The method according to claim 9, characterized in that, The method further includes: Send a cancellation command to the SIM card; The cancellation command is used to instruct the SIM card to cancel the verification pass flag and delete the temporary key.

13. The method according to claim 12, characterized in that, The method further includes: Send a signature acquisition request to the SIM card; Receive the signature information from the SIM card; the signature information is obtained by signing the SIM card's public key using a signature private key; The signature information is decrypted using the signature public key to obtain the SIM card public key.

14. The method according to claim 9, characterized in that, The method further includes: The second PIN is encrypted using the SIM card public key to obtain the fourth information; The fourth information is sent to the SIM card.

15. A communication device, characterized in that, The device includes: The receiving module is used to receive first information from the first application, wherein the first information is obtained by encrypting a temporary key and a first PIN using the SIM card public key; The decryption module is used to decrypt the first information using the SIM card key to obtain the temporary key and the first PIN; The verification module is used to communicate with the first application using the temporary key when the authentication of the first PIN is successful. The first application and the SIM card are located on the same terminal.

16. A communication device, characterized in that, The device includes: An encryption module is used to encrypt a temporary key and a first PIN using the SIM card's public key to obtain first information; wherein, the first PIN is used for the SIM card to authenticate the first application. The sending module is used to send the first information to the SIM card; A communication module is used to communicate with the SIM card using the temporary key; The first application and the SIM card are located on the same terminal.

17. A computer device / equipment / system, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the method according to any one of claims 1-14.

18. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instructions are executed by the processor, they implement the method described in any one of claims 1-14.

19. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the method described in any one of claims 1-14.

Citation Information

Patent Citations

  • Mobile terminal intelligent card based data transmission method and mobile terminal

    CN104184892A

  • Scheme for generating, storing and using private key

    CN107453862A

  • Information processing method, device and equipment

    CN108564361A

  • Key storage method, device and server

    CN110430051A