SIM card data management methods, devices, equipment, storage media, and products

By combining the national cryptographic algorithms SM4 and SM2 with a PKI system, and utilizing distributed encryption and a certificate system, the security risk of key leakage in SIM card data management is solved, realizing full-process secure management of SIM card data and improving the security and reliability of data transmission.

CN119521173BActive Publication Date: 2025-10-31中移信息技术有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411629075.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-13
Publication Date
2025-10-31
Estimated Expiration
2044-11-13

AI Technical Summary

Technical Problem

In existing technologies, the generation, storage, and transmission of SIM card data mainly rely on encryption using a unified symmetric key, which poses significant security risks. Once the key is leaked, all card-making data will be at risk, and the data transmission process is not secure enough.

Method used

Using the national cryptographic algorithms SM4 and SM2, combined with the PKI system, a unique card production batch number is generated. Distributed encryption technology is used to independently encrypt and store each SIM card data, and a certificate system is used to ensure the security of data transmission, allowing only authorized card vendors to decrypt it.

Benefits of technology

It ensures the security of SIM card data during generation, storage, and transmission, prevents data leakage, and improves the security and availability of card production data management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119521173B_ABST
    Figure CN119521173B_ABST
Patent Text Reader

Abstract

This application discloses a SIM card data management method, apparatus, device, storage medium, and product, relating to the field of data management technology. The method involves a card manufacturing system responding to a SIM card manufacturing request and generating a card manufacturing batch number; generating encrypted card manufacturing data based on the batch number and a corresponding algorithm; generating a card vendor's card manufacturing file package based on the batch number and the encrypted data; sending the card vendor's card manufacturing file package to the target card vendor's production system to read the card vendor's signature file and card manufacturing file from the package for production verification; after successful verification, decrypting the random encryption key and the operator variant key using the card vendor's encrypted random encryption key and encrypted operator variant key, respectively; and writing the keys and card manufacturing configuration information into a pre-connected blank SIM card. This scheme ensures the security of the entire process of SIM card manufacturing data generation, storage, and transmission, improving the security and usability of the card manufacturing data management method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data management technology, and in particular to a SIM card data management method, apparatus, device, storage medium, and product. Background Technology

[0002] In the field of communications, especially in mobile communication technology, the SIM card (Subscriber Identity Module) is a key component for user identification and network access, and the security of its data is of paramount importance. With the rapid development of the Internet of Things and information technology, security issues in the generation, storage, and transmission of SIM card data are becoming increasingly prominent.

[0003] SIM card data includes sensitive information such as ICCID (Integrated Circuit Card ID), IMSI (International Mobile Subscriber Identity), K (Ciphering Key), OPC (Operator Variant Key), SMSP (SIM Service Provider), PIN (Personal Identification Number), and PUK (Personal Unblocking Key). Among these, IMSI, K, and OPC are crucial authentication data that play a core role in SIM card login on a user's mobile phone. The security of this data is directly related to user privacy protection and communication security.

[0004] In existing technologies, the generation, storage, and transmission of SIM card data primarily rely on the card manufacturing system storing the data after generation and transmitting it to the card manufacturer for SIM card production when needed. During this process, core data such as K and OPC are encrypted using a symmetric key after generation and transmitted directly to the card manufacturer. The card manufacturer then decrypts the data using the symmetric key before producing the card. However, this unified symmetric key storage method presents significant security risks. If the key is leaked, the card manufacturing data will be leaked, creating a major security vulnerability. Furthermore, since all card manufacturing data is encrypted with the same key, if the key is cracked, all data stored in the system will be at risk.

[0005] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention

[0006] The main objective of this application is to provide a SIM card data management method, apparatus, device, storage medium, and computer program product, which aims to reduce the risk of data leakage during the SIM card manufacturing data transmission process and improve the security and usability of the card manufacturing data management method.

[0007] To achieve the above objectives, this application proposes a SIM card data management method, which is applied to a card manufacturing system and includes:

[0008] In response to a SIM card production request, a production batch number corresponding to the SIM card production request is generated;

[0009] Based on the card production batch number and the preset card production data generation algorithm, generate SIM card production encryption data;

[0010] A card manufacturer's card production file package is generated based on the card production batch number and the SIM card production encryption data.

[0011] The card manufacturer's card production file package is sent to the target card manufacturer's production system, so that the target card manufacturer's production system receives the card manufacturer's card production file package, and decrypts it according to the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key in the card manufacturer's card production file package to obtain the random encryption key and the operator variant key respectively. The random encryption key, the operator variant key, and the SIM card production configuration information in the card manufacturer's card production file are written into a pre-connected blank SIM card.

[0012] In one embodiment, the SIM card production encryption data includes an encrypted random encryption key and an encrypted carrier variant key. The step of generating the SIM card production encryption data based on the production batch number and a preset production data generation algorithm includes:

[0013] Obtain several integrated circuit card identification codes corresponding to the card production batch number;

[0014] Random encryption keys and carrier variant keys are generated based on a preset system encryption machine;

[0015] The hybrid distributed key is obtained by performing secondary distributed encryption based on the pre-generated storage root key, the batch number of the card production batch number, and the integrated circuit card identification code;

[0016] Based on the hybrid distributed key, the random encryption key and the operator variant key are encrypted using the first national cryptographic algorithm to obtain the encrypted random encryption key and the encrypted operator variant key.

[0017] In one embodiment, the step of generating a card manufacturer's card production file package based on the card production batch number and the SIM card production encryption data includes:

[0018] Based on the card production batch number and the pre-acquired card manufacturer code, the target card production data and the card manufacturer certificate index are determined respectively. The target card production data includes several integrated circuit card identification codes and the SIM card production encryption data.

[0019] Based on the pre-generated storage root key, the card production batch number, and the integrated circuit card identification code, a secondary distributed encryption is performed to obtain a hybrid distributed key;

[0020] Based on the hybrid distributed key, the SIM card manufacturing encryption data is decrypted using the national cryptographic algorithm to obtain a random encryption key and an operator variant key;

[0021] Based on the card manufacturer certificate corresponding to the card manufacturer certificate index, the random encryption key and the operator variant key are encrypted using the second national cryptographic algorithm to obtain the card manufacturer ciphertext random encryption key and the card manufacturer ciphertext operator variant key.

[0022] The card manufacturer's card production file package is generated based on the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key.

[0023] In one embodiment, the card vendor card production file package includes a card vendor signature file and a card vendor card production file. The step of generating the card vendor card production file package based on the card vendor's encrypted random encryption key and the card vendor's encrypted operator variant key includes:

[0024] Generate the original card manufacturing files and the original card signature files for the card vendor;

[0025] The integrated circuit card identification code, the card vendor's encrypted random encryption key, the card vendor's encrypted operator variant key, and the pre-acquired SIM card manufacturing configuration information are written into the card vendor's original card manufacturing file to obtain the card vendor's card manufacturing file;

[0026] Based on the file attributes of the card manufacturer's card production file, the card production batch number, and the pre-acquired card production system private key, a signature string and a string signature value are assembled and signed.

[0027] The signature string and the string signature value are written into the card seller's original signature file to obtain the card seller's signature file.

[0028] Furthermore, to achieve the above objectives, this application also proposes a SIM card data management method, which is applied to a target card manufacturer's production system, comprising:

[0029] The system receives a card manufacturer's card production file package sent by the card manufacturing system. The card manufacturer's card production file package is generated by the card manufacturing system in response to the SIM card production request. The system generates a card production batch number corresponding to the SIM card production request. Based on the card production batch number and a preset card production data generation algorithm, the system generates encrypted SIM card production data. The system generates encrypted SIM card production data based on the card production batch number and the encrypted SIM card production data.

[0030] Based on the card vendor's encrypted random encryption key and the card vendor's encrypted operator variant key in the card vendor's card production file package, the random encryption key and the operator variant key are decrypted respectively.

[0031] The random encryption key, the operator variant key, and the SIM card configuration information from the card manufacturer's card production file package are written into a pre-connected blank SIM card.

[0032] In one embodiment, the card vendor signature file and card vendor card production file in the card vendor production file package, before the step of decrypting the random encryption key and the operator variant key respectively based on the card vendor encrypted random encryption key and the card vendor encrypted operator variant key in the card vendor production file package, further includes:

[0033] Obtain the signature string and string signature value from the card vendor's signature file;

[0034] Verify the validity of the signature value of the string based on the pre-obtained card-making system certificate and the signature string;

[0035] Parse the signature string to obtain the file attributes of the card manufacturer's card production file;

[0036] If the file attributes of the card manufacturer's card production file match the preset file attribute values, and the string signature value is correct, then the following steps are executed: based on the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key in the card manufacturer's card production file, the random encryption key and the operator variant key are decrypted respectively.

[0037] Furthermore, to achieve the above objectives, this application also proposes a SIM card data management device, which includes:

[0038] The first generation module is used to generate a card production batch number corresponding to the SIM card production request in response to the SIM card production request.

[0039] The second generation module is used to generate SIM card production encryption data based on the card production batch number and the preset card production data generation algorithm.

[0040] The third generation module is used to generate a card manufacturer's card production file package based on the card production batch number and the SIM card production encryption data.

[0041] The sending module is used to send the card manufacturer's card production file package to the target card manufacturer's production system, so that the target card manufacturer's production system receives the card manufacturer's card production file package, decrypts it according to the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key in the card manufacturer's card production file package to obtain the random encryption key and the operator variant key respectively, and writes the random encryption key, the operator variant key, and the SIM card production configuration information in the card manufacturer's card production file into a pre-connected blank SIM card.

[0042] In addition, to achieve the above objectives, this application also proposes a SIM card data management device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the SIM card data management method as described above.

[0043] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the SIM card data management method described above.

[0044] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the SIM card data management method described above.

[0045] One or more technical solutions proposed in this application involve a card manufacturing system responding to a SIM card manufacturing request and generating a corresponding card manufacturing batch number; generating encrypted SIM card manufacturing data based on the batch number and a card manufacturing data generation algorithm; generating a card vendor manufacturing file package based on the batch number and the encrypted SIM card manufacturing data; sending the card vendor manufacturing file package to the target card vendor's production system, enabling the target card vendor's production system to read the card vendor's signature file and card vendor manufacturing file in the card vendor manufacturing file package, and performing SIM card production verification. If the production verification is successful, the system decrypts the random encryption key and the operator variant key in the card vendor's manufacturing file to obtain the random encryption key and operator variant key, respectively. These keys, along with SIM card manufacturing configuration information, are then written into a pre-connected blank SIM card. This solution ensures the security of the entire process of generating, storing, and transmitting SIM card manufacturing data, improving the security and usability of the card manufacturing data management method. Attached Figure Description

[0046] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0047] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 A flowchart illustrating one embodiment of the SIM card data management method provided in this application;

[0049] Figure 2 This application provides a schematic diagram of a SIM card data management system architecture.

[0050] Figure 3 This application provides a schematic diagram of a card manufacturing data encryption process.

[0051] Figure 4 This application provides a schematic diagram of a card production data generation and storage process.

[0052] Figure 5 This application provides a schematic diagram of a card manufacturer's process for encrypted transmission of card manufacturing data, as exemplified in this application.

[0053] Figure 6 A flowchart illustrating yet another embodiment of the SIM card data management method provided in this application;

[0054] Figure 7 This application provides a schematic diagram of a card vendor's decryption and card production process.

[0055] Figure 8 This is a schematic diagram of the module structure of the SIM card data management device according to an embodiment of this application;

[0056] Figure 9 This is a schematic diagram of the device structure of the hardware operating environment involved in the SIM card data management method in the embodiments of this application.

[0057] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0058] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0059] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0060] The main solution of this application embodiment is to propose an encryption method and system for SIM card data generation, storage, and transmission based on national cryptographic algorithms. This solution aims to address the security issues of symmetric key management in existing technologies, particularly its shortcomings in key leakage risk and data transmission security. Specifically, this solution is implemented through the following steps:

[0061] First, during the SIM card data generation and storage phase, the card manufacturing system uses a dedicated encryption machine to generate key data K and OPC, and directly outputs the encrypted data. The system uses the national cryptographic algorithm SM4 as the root key, distributing the root key across each SIM card data entry to generate independent subkeys, and then encrypting and storing each data entry separately. In this way, each data entry has a unique encryption key, ensuring that even if one data entry is compromised, the security of other data remains unaffected.

[0062] Secondly, during the data transmission phase, the solution employs a PKI system and the national cryptographic algorithm SM2 to encrypt and transmit card data. The card manufacturing system and the card manufacturer use certificates for authentication and data encryption, ensuring that only the corresponding card manufacturer can decrypt and obtain the plaintext data. The card manufacturing system issues an independent certificate to each card manufacturer, achieving access control and data non-repudiation.

[0063] Finally, during the process of receiving data and producing the SIM card, the card manufacturer uses its own private key to decrypt the received encrypted data and writes the decrypted plaintext data into a blank SIM card, completing the SIM card production. The card manufacturer's production system is completely closed, leaving no log data, and ensures data security through regular checks.

[0064] In summary, the solution proposed in the technical disclosure combines symmetric and asymmetric national cryptographic algorithms to achieve secure protection of SIM card data throughout its entire lifecycle, including data generation, storage, and transmission, thereby improving the security of SIM card data.

[0065] This application provides a solution that, in response to a SIM card manufacturing request, generates a corresponding manufacturing batch number; generates encrypted SIM card manufacturing data based on the batch number and a manufacturing data generation algorithm; generates a card vendor manufacturing file package based on the batch number and the encrypted SIM card manufacturing data; and sends the card vendor manufacturing file package to the target card vendor's production system, enabling the target card vendor's production system to read the card vendor's signature file and manufacturing file within the file and perform SIM card production verification. If the verification passes, the system decrypts the random encryption key and operator variant key from the card vendor's encrypted text in the manufacturing file to obtain the random encryption key and operator variant key, respectively. These keys, along with SIM card manufacturing configuration information, are then written into a pre-connected blank SIM card. This solution ensures the security of the entire process of SIM card manufacturing data generation, storage, and transmission, improving the security and usability of the card manufacturing data management method.

[0066] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or SIM card data management system capable of performing the above functions. The following description uses a SIM card data management system as an example to illustrate this embodiment and the subsequent embodiments.

[0067] Based on this, embodiments of this application provide a SIM card data management method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the SIM card data management method of this application.

[0068] In this embodiment, the SIM card data management method includes steps S1000~S4000:

[0069] Step S1000: In response to the SIM card production request, generate the production batch number corresponding to the SIM card production request;

[0070] It should be noted that, referring to Figure 2 , Figure 2 This is a schematic diagram of a SIM card data management system architecture provided in an embodiment of this application. In this embodiment, a SIM card data management system is provided, which specifically includes: a SIM card manufacturing system, which is mainly responsible for generating SIM card data. The manufacturing data is stored internally within the system and sent to the corresponding card manufacturer. The manufacturing system has a dedicated encryption machine that stores all SIM card manufacturer certificates, data storage master keys, and its own public and private key pairs. The manufacturing system is a system deployed on the internal network of a telecommunications operator.

[0071] SIM card manufacturers primarily receive card production data and produce SIM cards based on this data. Their dedicated encryption machines store the SIM card production system's certificate and its own public / private key pair. The CA (Certificate Authority) is the certificate center (CI) provider, a standard PKI certificate authority that issues trusted digital certificates to all parties within the system. The CI issues certificates to the SIM card manufacturers. During production, the manufacturers decrypt and verify the received card production data. Once verified, they proceed with SIM card production. The CI can also issue certificates to the SIM card production system, which are used to sign subsequent card production documents. These certificates are stored in the encryption machine.

[0072] Specifically, during the certificate application and usage process, the certificate applicant (card vendor or card manufacturing system) can generate a public-private key pair in the encryption machine and generate a certificate issuance application (the application contains the certificate applicant's public key and applicant information). After receiving the application, CI generates a certificate file and returns the certificate file to the certificate applicant (the certificate contains the certificate applicant's public key, applicant information, and CI information).

[0073] After receiving the certificate file, the applicant can pass it on to other parties (such as card vendors submitting their certificates to the card manufacturing system). The recipient can verify the applicant information and CI information in the certificate. If they are correct, the recipient can confirm that it is a trusted certificate and import it into the encryption machine. The encryption machine can then use the certificate's public key for encryption and other operations.

[0074] In this embodiment, considering that the existing card manufacturing system stores the K (Ciphering Key) and OPc (Operator Variant Key) in the card manufacturing data as card manufacturing data within the system after generation, it is necessary to encrypt and store them to ensure data security. To ensure the security of the stored data, each piece of data needs to be encrypted and stored using a separate key. In this embodiment, the national cryptographic standard SM4 can be used as the root key. Each piece of card manufacturing data is distributed using the root key and then encrypted and stored separately. The SM4 root key is randomly generated in the encryption machine. After being randomly generated by the encryption machine, it is only stored in the encryption machine and is not visible elsewhere.

[0075] Specifically, you can refer to Figure 3 , Figure 3This is a schematic diagram of a card manufacturing data encryption process provided in an embodiment of this application. When the card manufacturing data is transmitted to the card vendor system, a PKI system (using the national cryptographic SM2 key) is used to encrypt the card data during transmission. The PKI certificate system is divided into two layers: root certificate and card vendor certificate / card manufacturing system platform certificate. The root certificate is a self-signed certificate and is the starting point of the trust chain. The card vendor certificate is issued by the root certificate. The card vendor submits the issued certificate offline to the card manufacturing system and imports it into the encryption machine of the card manufacturing system. The card manufacturing system certificate is also issued by the root certificate. After issuance, it is submitted to each card vendor, and the card vendor verifies the validity of the certificate.

[0076] It should be noted that, in this embodiment, the step of generating a card production batch number corresponding to the SIM card production request in response to the SIM card production request is to ensure the uniqueness and traceability of each production request. The production batch number is a unique identifier, corresponding one-to-one with the SIM card production request, used to identify and manage each batch of cards throughout the entire production process. The batch number not only helps monitor and manage the production process but also allows for tracing the specific production batch in case of problems, thereby improving the security and efficiency of the production process. Furthermore, it should be noted that the process of generating the production batch number involves the identification and processing of the production request, as well as the generation and recording of the batch number. This process can be accomplished by a dedicated module in the card production system. This module is responsible for receiving the production request signal and automatically or semi-automatically generating a unique batch number. This batch number typically includes a timestamp, serial number, or other identifying information to ensure its uniqueness.

[0077] For example, in one specific implementation, when the card-making system receives a card-making request, the system triggers an event that activates the batch number generation module. This module creates a unique batch number based on the current date and time, as well as an internal serial number generator. This batch number is then used to identify and manage all subsequent operations related to the request.

[0078] Step S2000: Generate SIM card encryption data based on the card production batch number and the preset card production data generation algorithm;

[0079] It should be noted that the step of generating SIM card encrypted data based on the card production batch number and the preset card production data generation algorithm is to ensure the security of SIM card data. The system will generate encrypted SIM card data according to the batch number and the preset algorithm, including an encrypted random encryption key (K) and an encrypted carrier variant key (OPc). The process of generating SIM card encrypted data includes obtaining the Integrated Circuit Card Identifier (ICCID), generating the random encryption key and the carrier variant key, and using the stored root key and the national cryptographic algorithm for secondary distributed encryption. This process ensures that even if the data is intercepted during transmission, it cannot be decrypted and used by unauthorized parties.

[0080] In one specific implementation, the card-making system retrieves the corresponding ICCID from the database based on the card production batch number. Then, the system's encryption module generates random K and OPC. Subsequently, it performs secondary distributed encryption using a pre-set storage root key, the batch number, and the ICCID to obtain a hybrid distributed key. Finally, it uses the hybrid distributed key to encrypt K and OPC using the national cryptographic SM4 algorithm, resulting in encrypted K and OPC.

[0081] Step S3000: Generate a card manufacturer's card production file package based on the card production batch number and the SIM card production encryption data;

[0082] It should be noted that, in this embodiment of the application, the step of generating a card manufacturer's card production file package based on the card production batch number and the encrypted SIM card production data is to securely package the encrypted SIM card data for transmission to the card manufacturer. In this step, the card production system generates a file package containing all necessary information based on the batch number and the encrypted data. This file package is then sent to the card manufacturer for SIM card production.

[0083] Additionally, it should be noted that the process of generating the card manufacturer's card production file package involves determining the target card production data and the card manufacturer's certificate index, decrypting the SIM card production encrypted data using a hybrid distributed key, and re-encrypting the decrypted data using the card manufacturer's certificate. For example, in one specific implementation, the card production system determines the target card production data and the card manufacturer's certificate index based on the batch number and a pre-acquired card manufacturer code. Then, it decrypts the SIM card production encrypted data using a hybrid distributed key to obtain a random encryption key and an operator variant key. Next, the system uses the card manufacturer's certificate to encrypt these keys using the national cryptographic SM2 algorithm to obtain the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key. Finally, the system generates the card manufacturer's card production file package based on these keys.

[0084] Step S4000: Send the card manufacturer's card production file package to the target card manufacturer's production system, so that the target card manufacturer's production system receives the card manufacturer's card production file package, and decrypts the random encryption key and the operator variant key in the card manufacturer's encrypted text in the card manufacturer's card production file package to obtain the random encryption key and the operator variant key respectively, and writes the random encryption key, the operator variant key, and the SIM card production configuration information in the card manufacturer's card production file into the pre-connected blank SIM card.

[0085] It should be noted that in order to complete the transmission of SIM card data, the system sends the card manufacturer's card production file package to the target card manufacturer's production system, so that the card manufacturer can receive all the necessary information to produce SIM cards. In this step, the card manufacturing system will send the file package to the card manufacturer through a secure communication channel to ensure the security and integrity of the data during the transmission process.

[0086] Additionally, it should be noted that the process of sending the card manufacturer's card production file package involves the packaging, encryption, and transmission of files. This file package contains the card manufacturer's card production file and the card manufacturer's signature file. The card manufacturer's card production file contains SIM card production configuration information, while the card manufacturer's signature file is used to verify the integrity and authenticity of the file package.

[0087] For example, in one specific implementation, the card manufacturing system transmits the card manufacturer's card manufacturing file package to the card manufacturer offline, point-to-point. Upon receiving the file package, the card manufacturer's production system first reads the signature value and signature string from the card manufacturer's signature file and verifies the correctness of the signature value using the card manufacturing system's certificate. If the signature verification passes, the card manufacturer's production system further verifies file attributes, such as whether the file name and size match expectations. If all checks pass, the card manufacturer's production system uses the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key to decrypt and obtain the random encryption key and operator variant key, and writes these keys, along with the SIM card manufacturing configuration information, into a pre-connected blank SIM card, completing the SIM card production.

[0088] In one feasible implementation, the SIM card encryption data includes an encrypted random encryption key and an encrypted carrier variant key, and step S2000 may include steps S2100~S2400:

[0089] Step S2100: Obtain several integrated circuit card identification codes corresponding to the card production batch number;

[0090] Step S2200: Generate a random encryption key and a carrier variant key based on a preset system encryption machine;

[0091] Step S2300: Perform secondary distributed encryption based on the pre-generated storage root key, the batch number of the card production batch number, and the integrated circuit card identification code to obtain a hybrid distributed key;

[0092] Step S2400: Based on the hybrid distributed key, encrypt the random encryption key and the operator variant key using the first national cryptographic algorithm to obtain the encrypted random encryption key and the encrypted operator variant key.

[0093] It should be noted that in this embodiment, firstly, several Integrated Circuit Card Identifiers (ICCIDs) corresponding to the card production batch number are obtained. The ICCID is a unique identifier for the SIM card, assigned and burned by the operator during SIM card manufacturing. It is a globally unique identifier for the SIM card and is crucial for SIM card identification and management. Next, a random encryption key (K) and an operator variant key (OPc) are generated based on a preset system encryption machine. These two keys are core data in the SIM card authentication process, ensuring data security during SIM card login. The random encryption key (K) is used to encrypt sensitive information in the SIM card, while the operator variant key (OPc) is used for authentication between the SIM card and the network.

[0094] Subsequently, a second round of distributed encryption is performed based on the pre-generated storage root key, card production batch number, and ICCID to obtain a hybrid distributed key. This step utilizes the national cryptographic algorithm SM4, enhancing key security through distributed key methods. This ensures that even if the key is leaked, the encrypted data cannot be easily cracked. Finally, based on the hybrid distributed key, the random encryption key and the operator variant key are encrypted using the first national cryptographic algorithm to obtain an encrypted random encryption key and an encrypted operator variant key. This step encrypts K and OPC, ensuring the security of this sensitive data during storage and transmission. Throughout the entire process from SIM card data generation to transmission, sensitive information remains encrypted, preventing the risk of data interception and cracking during transmission, thereby greatly improving the security of SIM card data.

[0095] In one feasible implementation, the card manufacturing system first generates a unique card manufacturing batch number based on the received card manufacturing request and retrieves the corresponding ICCID. Then, the system's encryption machine generates random K and OPC, and performs secondary distributed encryption using the stored root key and ICCID to obtain a hybrid distributed key. Next, the hybrid distributed key is used to encrypt K and OPC using the national cryptographic SM4 algorithm, resulting in encrypted K and OPC. Finally, this encrypted data is used to generate the card manufacturer's card manufacturing file package and sent to the target card manufacturer's production system. At the card manufacturer's production system, the encrypted K and OPC in the received file package are decrypted and written into a blank SIM card along with the SIM card manufacturing configuration information, completing the SIM card production. The entire process follows strict security standards, ensuring data security and reliability.

[0096] For example, in another feasible implementation, please refer to Figure 4 , Figure 4 This is a schematic diagram of a card production data generation and storage process provided in an embodiment of this application. The card production data includes ICCID, IMSI, K, OPC, SMSP, PIN, and PUK. Among them, ICCID and IMSI are serial numbers, which are managed by the system itself according to the serial number. SMSP is distinguished according to the city where the card belongs, and is generally a fixed value for a city. PIN and PUK are fixed values ​​according to the batch number. K and OPC are the key considerations. This data is used for SIM card login authentication and is a core parameter. It is necessary to ensure that this data is not stored in plaintext during generation, storage, and transmission.

[0097] The card manufacturing system receives a card manufacturing request, including the quantity, SIM card manufacturer, city, and number segment. It then generates a serial number and determines the ICCID, IMSI, SMSP, PIN, and PUK based on the user's selected data. The card manufacturing system sends the ICCID and serial number to the encryption machine. The encryption machine first generates a random key (32 bytes). It then uses the stored root key (SM4 type) to distribute the last 8 bytes of the serial number, obtaining distribution key one. The last 8 bytes of the ICCID are used again to distribute distribution key one, obtaining distribution key two. Distribution key two is then used to encrypt the key using SM4. The encrypted key is returned to the card manufacturing system. (This operation is atomic within the encryption machine; the encryption machine does not retain any data, and intermediate data is not stored.) The card manufacturing system receives the encrypted key and saves it.

[0098] The card-making system sends the ICCID and serial number to the encryption machine. The encryption machine first generates a random OPC (32 bytes). The encryption machine uses the stored root key (SM4 type) to distribute the last 8 bytes of the serial number to obtain the first distribution key. The last 8 bytes of the ICCID are then used to distribute the first distribution key to obtain the second distribution key. The OPC is then encrypted using the second distribution key with SM4. The encrypted data is returned to the card-making system. (This operation is atomic within the encryption machine; the encryption machine does not retain any data, and intermediate data is not retained.) The card-making system receives the encrypted OPC and saves it. After the card-making data is generated, the card-making system retains the card serial number, ICCID, IMSI, encrypted K, encrypted OPC, SMSP, PIN, and PUK. Throughout the process, the K and OPC are stored without plaintext. The encryption keys for all K and OPC are also different. If one piece of data is decrypted, it will not affect the security of other data.

[0099] In one feasible implementation, step S3000 may include steps S3100~S3500:

[0100] Step S3100: Based on the card production batch number and the pre-acquired card manufacturer code, determine the target card production data and the card manufacturer certificate index respectively. The target card production data includes several integrated circuit card identification codes and the SIM card production encryption data.

[0101] Step S3200: Based on the pre-generated storage root key, the card production batch number, and the integrated circuit card identification code, perform secondary distributed encryption to obtain a hybrid distributed key;

[0102] Step S3300: Based on the hybrid distributed key, decrypt the SIM card manufacturing encryption data using the national cryptographic algorithm to obtain a random encryption key and an operator variant key;

[0103] Step S3400: Based on the card manufacturer certificate corresponding to the card manufacturer certificate index, encrypt the random encryption key and the operator variant key using the second national cryptographic algorithm to obtain the card manufacturer ciphertext random encryption key and the card manufacturer ciphertext operator variant key;

[0104] Step S3500: Generate the card manufacturer's card production file package based on the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key.

[0105] It should be noted that, in order to ensure the security of data during transmission from the card manufacturing system to the card manufacturer, in this embodiment of the application, the target card manufacturing data and the card manufacturer certificate index can be determined based on the card manufacturing batch number and the pre-acquired card manufacturer code. The target card manufacturing data includes several integrated circuit card identification codes (ICCID) and SIM card manufacturing encryption data. Among them, the ICCID is the unique identifier of the SIM card, which is crucial for the identification and management of the SIM card. Next, based on the pre-generated storage root key, the card manufacturing batch number and the ICCID, a second-stage distributed encryption is performed to obtain a hybrid distributed key. Using the national cryptographic SM4 algorithm, the security of the key is enhanced by the distributed key method, ensuring that even if the key is leaked, the encrypted data cannot be easily cracked.

[0106] Subsequently, the encrypted data from SIM card manufacturing is decrypted using a national cryptographic algorithm using a hybrid distributed key, yielding a random encryption key and a carrier variant key. These two keys are core data in the SIM card authentication process, ensuring data security during SIM card login. Based on the card manufacturer's certificate corresponding to the card manufacturer's certificate index, the random encryption key and the carrier variant key are respectively encrypted using a second national cryptographic algorithm, resulting in the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted carrier variant key. This step ensures that only card manufacturers with the correct certificates can decrypt and access SIM card data.

[0107] Finally, a card manufacturer's card production file package is generated based on the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key. This file package includes a card manufacturer's signature file and a card manufacturer's card production file. The card manufacturer's card production file contains SIM card production configuration information, while the card manufacturer's signature file is used to verify the integrity and authenticity of the file package.

[0108] Additionally, it's important to note that the card manufacturer's card production file package generation process involves multiple security measures, including encryption, decryption, and signing using national cryptographic algorithms, and leveraging a PKI certificate system to ensure data transmission security. These measures collectively ensure the security of SIM card data during generation, storage, and transmission, preventing the risks of data leakage and unauthorized access.

[0109] In one feasible implementation, the card manufacturing system first generates a card production batch number based on the card production request and retrieves the corresponding ICCID and SIM card production encryption data. Then, the system performs secondary distributed encryption using the stored root key and ICCID to obtain a hybrid distributed key. Using this key, the system decrypts the SIM card production encryption data to obtain a random encryption key and a carrier variant key. Next, the system re-encrypts these keys based on the card manufacturer's certificate to obtain the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted carrier variant key. Finally, the system packages these keys and SIM card production configuration information into a card manufacturer production file package and securely transmits it to the card manufacturer offline. Upon receiving the file package, the card manufacturer decrypts it using their private key to obtain the plaintext keys and writes these keys and configuration information into a blank SIM card, completing SIM card production. The entire process adheres to strict security standards, ensuring data security and reliability.

[0110] For example, refer to Figure 5 , Figure 5 This application provides a schematic diagram of a card manufacturing data encryption and transmission process for card vendors. In another feasible implementation, in order to transmit card manufacturing data to card vendors, it is necessary to ensure that the K and OPC are transmitted in encrypted form, and that only the corresponding card vendor can decrypt them. Other parties, even if they obtain the card manufacturing data, will not be able to decrypt it. First, the card manufacturing file is transmitted to the card vendor, and the K and OPC need to be encrypted. After the user selects the card manufacturing serial number and the card vendor, they submit a card manufacturing file production request. After receiving the request, the card manufacturing system obtains the corresponding data through the card manufacturing serial number, including ICCID, IMSI, encrypted K (stored encrypted), encrypted OPC (stored encrypted), SMSP, PIN, and PUK. The card manufacturing system searches for the corresponding card vendor configuration in the system according to the card vendor code, determines the certificate index of the card vendor certificate stored in the encryption machine, and sends the serial number, ICCID, encrypted K, and the certificate index corresponding to the card vendor to the encryption machine.

[0111] The encryption machine uses the stored root key (SM4 type) to disperse the last 8 bytes of the serial number to obtain dispersed key one. It then uses the last 8 bytes of the ICCID to disperse dispersed key one again to obtain dispersed key two. Dispersed key two is then used to decrypt the ciphertext K using SM4. The card vendor's certificate is used again to encrypt K, resulting in the card vendor's ciphertext K (key type SM2). The card vendor's ciphertext K is then returned to the card production system (this operation is atomic within the encryption machine; the encryption machine does not retain any data, and intermediate data is not retained). The card production system sends the serial number, ICCID, ciphertext OPC, and the certificate index corresponding to the card vendor to the encryption machine. Simultaneously, the encryption machine uses the stored root key (SM4 type) to scatter the last 8 bytes of the serial number, resulting in scatter key one. The last 8 bytes of the ICCID are then used to scatter scatter key one, resulting in scatter key two. Scatter key two is used to decrypt the ciphertext OPC using SM4. The card vendor's certificate is used again to encrypt OPC, resulting in the card vendor's ciphertext OPC (key type SM2). The card vendor's ciphertext OPC is then returned to the card production system (this operation is atomic within the encryption machine; the encryption machine does not retain any data, and intermediate data is not retained).

[0112] In one feasible implementation, the card vendor card production file package includes a card vendor signature file and a card vendor card production file, and step S3500 may include steps S3510~3540:

[0113] Step S3510: Generate the original card manufacturing file and the original card signature file for the card vendor;

[0114] Step S3520: Write the integrated circuit card identification code, the card vendor's encrypted random encryption key, the card vendor's encrypted operator variant key, and the pre-acquired SIM card manufacturing configuration information into the card vendor's original manufacturing file to obtain the card vendor's manufacturing file;

[0115] Step S3530: Based on the file attributes of the card manufacturer's card production file, the card production batch number, and the pre-acquired card production system private key, assemble the signature to obtain the signature string and the string signature value;

[0116] Step S3540: Write the signature string and the string signature value into the card vendor signature original file to obtain the card vendor signature file.

[0117] It should be noted that the card manufacturer's card production file package includes a card manufacturer's signature file and a card manufacturer's card production file. The signature file is used to verify the integrity and authenticity of the file package, while the card production file contains all the sensitive data required for SIM card production. The card manufacturer's original card production file and original signature file are generated as the basis for subsequent operations. The card production system writes the Integrated Circuit Card Identifier (ICCID), the card manufacturer's encrypted random encryption key, the card manufacturer's encrypted operator variant key, and the pre-acquired SIM card production configuration information into the card manufacturer's original card production file to obtain the card manufacturer's card production file. Next, the card production system assembles the signature string based on the file attributes and production batch number of the card manufacturer's card production file, and signs the signature string according to the pre-acquired card production system private key to obtain the string signature value. This step ensures the traceability of the file package's origin and the integrity of its content, preventing the file from being tampered with during transmission.

[0118] Finally, the card manufacturing system writes the signature string and string signature value into the card vendor's original signature file, resulting in the card vendor's signature file. This signature file, together with the card manufacturing file, constitutes the complete card vendor card manufacturing file package, used to verify the integrity and authenticity of the file package.

[0119] In one feasible implementation, the card manufacturing system first generates a card manufacturer's original card manufacturing file and a card manufacturer's original signature file. Then, the system writes the ICCID, encrypted K and OPC, and SIM card manufacturing configuration information into the original card manufacturing file, forming the card manufacturer's card manufacturing file. Next, the card manufacturing system assembles a signature string based on the file attributes and batch number of the card manufacturer's card manufacturing file. It then signs the signature string using a pre-acquired private key to obtain a signature value, and writes the signature string and signature value into the original signature file, forming the card manufacturer's signature file. Finally, these two files are packaged into a card manufacturer's card manufacturing file package and securely sent to the card manufacturer. Upon receiving the package, the card manufacturer first verifies the validity of the signature file, then decrypts it using its private key to obtain the plaintext key, and writes these keys and configuration information into a blank SIM card, completing the SIM card production. The entire process follows strict security standards, ensuring data security and reliability.

[0120] For example, please refer to again Figure 5Based on the card manufacturer certificate corresponding to the card manufacturer certificate index, the random encryption key and the operator variant key are encrypted using the second national cryptographic algorithm to obtain the card manufacturer ciphertext random encryption key (card manufacturer ciphertext K) and the card manufacturer ciphertext operator variant key (card manufacturer ciphertext OPC). The card manufacturing system then generates a card manufacturer card manufacturing file, which includes ICCID, IMSI, the card manufacturer certificate encrypted K, the card manufacturer certificate encrypted OPC, SMSP, PIN, and PUK. The generated card manufacturer card manufacturing file name, size (bytes), and card manufacturing serial number are assembled to generate a signature string. The signature string and the card manufacturing system's private key index are sent to the encryption machine. The encryption machine signs the signature string using its private key and returns a signature value. The card manufacturing system writes the signature string and signature value together into a card manufacturer signature file. The card manufacturing system packages the card manufacturer signature file and the card manufacturer card manufacturing file together and transmits the packaged file to the card manufacturer offline, point-to-point.

[0121] This application provides a SIM card data management method. The method involves a card manufacturing system responding to a SIM card manufacturing request by generating a corresponding manufacturing batch number; generating encrypted SIM card manufacturing data based on the batch number and a data generation algorithm; generating a card vendor manufacturing file package based on the batch number and the encrypted data; and sending the card vendor manufacturing file package to a target card vendor's production system. The target card vendor's production system reads the card vendor's signature file and manufacturing file from the file and performs SIM card production verification. If the verification passes, the system decrypts the random encryption key and operator variant key from the card vendor's manufacturing file to obtain the random encryption key and operator variant key, respectively. These keys, along with SIM card manufacturing configuration information, are then written into a pre-connected blank SIM card. This method ensures the security of the entire process of SIM card manufacturing data generation, storage, and transmission, improving the security and usability of the card manufacturing data management method.

[0122] Based on the above embodiments of this application, another embodiment of this application is proposed. For content that is the same as or similar to the above embodiments, please refer to the above description; further details will not be repeated hereafter. Based on this, please refer to... Figure 6 The SIM card data management method is applied to the target card vendor's production system, including steps A1000~A3000:

[0123] Step A1000: Receive the card manufacturer's card production file package sent by the card manufacturing system. The card manufacturer's card production file package is generated by the card manufacturing system in response to the SIM card production request. The card manufacturing system generates a card production batch number corresponding to the SIM card production request. Based on the card production batch number and a preset card production data generation algorithm, it generates encrypted SIM card production data.

[0124] Step A2000: Based on the card vendor's encrypted random encryption key and the card vendor's encrypted operator variant key in the card vendor's card production file package, decrypt to obtain the random encryption key and the operator variant key respectively;

[0125] Step A3000: Write the random encryption key, the operator variant key, and the SIM card manufacturing configuration information from the card manufacturer's card manufacturing file package into the pre-connected blank SIM card.

[0126] It should be noted that, in this embodiment of the application, the target card manufacturer's production system of the SIM card data management method involves a series of operations to receive, decrypt, and write SIM card data, ensuring the secure transmission and accurate writing of SIM card production data. This process begins with the card manufacturing system responding to the SIM card production request and generating a production batch number corresponding to the SIM card production request. This is a unique number used to identify each batch of SIM cards, which helps to track and manage the SIM card production process. Based on this batch number and a preset card production data generation algorithm, the system generates encrypted SIM card production data, including an encrypted random encryption key and an operator variant key. These data are crucial for SIM card authentication and secure communication.

[0127] Additionally, it should be noted that the process of generating the SIM card manufacturing file package involves combining the encrypted SIM card manufacturing data with the batch number of the manufacturing sequence to generate a file package containing sensitive information. This file package ensures data integrity and confidentiality when transmitted to the target SIM card manufacturer's production system, preventing data leakage during transmission.

[0128] On the target card manufacturer's production system side, the first operation is to receive the card manufacturer's card production file package sent by the card manufacturing system. This file package contains encrypted SIM card production data. This data is encrypted using national cryptographic algorithms during transmission to ensure that only authorized card manufacturers can decrypt and access this data.

[0129] Next, the card manufacturer's production system needs to decrypt the card manufacturer's encrypted random encryption key and the card manufacturer's key carrier variant key in the card manufacturing file package to obtain the random encryption key and the carrier variant key. This step is crucial because it involves converting the encrypted data back into a readable format so that this critical information can be written to the SIM card.

[0130] Finally, the card manufacturer's production system writes the random encryption key, the operator variant key, and the SIM card manufacturing configuration information into the pre-connected blank SIM card. This step completes the data programming process of the SIM card, enabling the SIM card to be used by the user and ensuring a secure connection between the SIM card and the mobile network.

[0131] For example, in one feasible implementation, the card manufacturing system first responds to the SIM card manufacturing request, generates a card manufacturing batch number, and generates encrypted SIM card manufacturing data based on this batch number. Then, the card manufacturing system packages this encrypted data into a card vendor manufacturing file package and sends it to the target card vendor's production system. Upon receiving the file package, the card vendor's production system first verifies its validity, then uses its private key to decrypt it to obtain a random encryption key and an operator variant key. Finally, the card vendor's production system writes these keys and SIM card manufacturing configuration information into a blank SIM card, completing the SIM card production. This entire process ensures the security and integrity of the SIM card data, prevents unauthorized access and data leakage, and protects the interests of both operators and users.

[0132] In one feasible implementation, the card vendor signature file and card vendor card production file in the card vendor production file package further include steps A1100 to A1400 before step A2000:

[0133] Step A1100: Obtain the signature string and string signature value from the card vendor's signature file;

[0134] Step A1200: Verify whether the signature value of the string is correct based on the pre-acquired card-making system certificate and the signature string;

[0135] Step A1300: Parse the signature string to obtain the file attributes of the card manufacturer's card production file;

[0136] Step A1400: If the file attributes of the card manufacturer's card production file match the preset file attribute values, and the string signature value is correct, then execute the following steps: Decrypt the random encryption key and the operator variant key respectively based on the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key in the card manufacturer's card production file.

[0137] It should be noted that the SIM card data management method implemented in the target card manufacturer's production system involves a series of security measures to ensure the integrity, authenticity, and security of the SIM card manufacturing file package. This process begins when the card manufacturing system responds to the SIM card manufacturing request and generates a manufacturing batch number corresponding to the SIM card manufacturing request. This unique identifier is used to track and manage the SIM card manufacturing process. Based on this batch number and a preset manufacturing data generation algorithm, the system generates encrypted SIM card manufacturing data, including an encrypted random encryption key and an operator variant key. This data is crucial for SIM card authentication.

[0138] During the process of receiving card manufacturing file packages from card vendors, the first step is to verify the validity of the package's signature. This includes obtaining the signature string and string signature value from the card vendor's signature file, and using a pre-obtained card manufacturing system certificate to verify the correctness of the signature value. Signature verification is a crucial step in ensuring that the file package has not been tampered with; it utilizes Public Key Infrastructure (PKI) and digital certificates to confirm the source and integrity of the file.

[0139] After successful verification, the system parses the signature string to obtain the file attributes of the card manufacturer's card production file. This step ensures that the received file matches the expected file attributes, thereby guaranteeing data consistency and correctness. If the file attributes match the preset values ​​and the signature value is correct, the system will perform a decryption operation, using the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key to decrypt and obtain the random encryption key and operator variant key.

[0140] Additionally, it's important to note that the decryption process for these keys is a prerequisite for securely writing them to the SIM card. The random encryption key and the carrier variant key are core data in the SIM card authentication process; their secure transmission and decryption are crucial for ensuring the SIM card can correctly log in and use the mobile network. After the verification and decryption steps, the system writes these keys, along with the SIM card manufacturing configuration information, into a pre-connected blank SIM card, completing the SIM card production.

[0141] In one feasible implementation, the card manufacturing system first generates a card manufacturing batch number and then generates encrypted SIM card manufacturing data based on this batch number. The system then packages this data into a card vendor manufacturing file package and sends it to the target card vendor's production system. Upon receiving the file package, the card vendor's production system first reads the signature value and signature string from the card vendor's signature file and verifies the signature's correctness using the card manufacturing system's public key. Once the signature verification is successful, the system parses the signature string to confirm the file attributes, and upon successful matching, decrypts it using the card vendor's private key to obtain a random encryption key and an operator variant key. Finally, these keys and configuration information are securely written into a blank SIM card, completing the SIM card production. The entire process ensures the security and integrity of the SIM card data, prevents unauthorized access and data leakage, and protects the interests of operators and users.

[0142] For example, refer to Figure 7 , Figure 7 This is a schematic diagram of a card merchant's decryption and card production process provided in an embodiment of this application. In another feasible implementation, the card production system packages the card merchant's signature file and card merchant's card production file together, and transmits the packaged file to the card merchant offline point-to-point.

[0143] The card manufacturer's system first reads the signature file to obtain the signature value and signature string. It then retrieves the index of the card manufacturer's certificate in the encryption machine and sends this data to the encryption machine for signature verification. The encryption machine uses the card manufacturer's certificate to verify the signature value against the signature string and sends the verification result back to the card manufacturer's production system. If the signature is abnormal, the SIM card production is paused, and all files and card production data are discarded. If the signature is correct, the system retrieves the card production file name and size from the signature string and verifies their correctness. If correct, all data in the card production file is read; otherwise, all files and card production data are discarded.

[0144] After both verifications pass, the card vendor's encrypted K and the key index of the card vendor's private key are sent to the encryption machine. The encryption machine decrypts the K and returns plaintext K. The card vendor's encrypted OPC and the key index of the card vendor's private key are then sent to the encryption machine, which decrypts the OPC and returns plaintext OPC. The card vendor's production system writes the ICCID, IMSI, plaintext K, plaintext OPC, SMSP, PIN, and PUK into the blank SIM card, completing the SIM card production. The card vendor's production system is completely closed and does not leave any logs or other data. It is checked regularly to ensure data security.

[0145] This application provides a SIM card data management method. The method involves receiving a card manufacturer's production file package from a card manufacturing system via a target card manufacturer's production system. The card manufacturer's production file package is generated by the card manufacturing system in response to a SIM card manufacturing request. A card manufacturing batch number corresponding to the SIM card manufacturing request is generated. Based on the batch number and a preset card manufacturing data generation algorithm, encrypted SIM card manufacturing data is generated. The method further involves decrypting the card manufacturer's encrypted random encryption key and carrier variant key from the card manufacturer's production file package to obtain a random encryption key and a carrier variant key, respectively. Finally, the random encryption key, the carrier variant key, and the SIM card manufacturing configuration information from the card manufacturer's production file package are written into a pre-connected blank SIM card. This scheme ensures the security of the entire process of SIM card manufacturing data generation, storage, and transmission, improving the security and usability of the card manufacturing data management method.

[0146] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the SIM card data management method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0147] Please refer to Figure 8 This application also provides a SIM card data management device, the SIM card data management device comprising:

[0148] The first generation module 81 is used to generate a card production batch number corresponding to the SIM card production request in response to the SIM card production request.

[0149] The second generation module 82 is used to generate SIM card production encryption data based on the card production batch number and the preset card production data generation algorithm.

[0150] The third generation module 83 is used to generate a card manufacturer's card production file package based on the card production batch number and the SIM card production encryption data.

[0151] The sending module 84 is used to send the card manufacturer's card production file package to the target card manufacturer's production system, so that the target card manufacturer's production system receives the card manufacturer's card production file package, decrypts it according to the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key in the card manufacturer's card production file package to obtain the random encryption key and the operator variant key respectively, and writes the random encryption key, the operator variant key, and the SIM card production configuration information in the card manufacturer's card production file into a pre-connected blank SIM card.

[0152] The SIM card data management device provided in this application, employing the SIM card data management method in the above embodiments, can solve the technical problems of SIM card data management. Compared with the prior art, the beneficial effects of the SIM card data management device provided in this application are the same as those of the SIM card data management method provided in the above embodiments, and other technical features in the SIM card data management device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0153] This application provides a SIM card data management device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the SIM card data management method in Embodiment 1 above.

[0154] The following is for reference. Figure 9The diagram illustrates a structural schematic of a SIM card data management device suitable for implementing embodiments of this application. The SIM card data management device in these embodiments may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital radio receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 9 The SIM card data management device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0155] like Figure 9 As shown, the SIM card data management device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the SIM card data management device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. The communication device 1009 allows the SIM card data management device to communicate wirelessly or wiredly with other devices to exchange data. Although the figures show SIM card data management devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.

[0156] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0157] The SIM card data management device provided in this application adopts the SIM card data management method in the above embodiments. Compared with the prior art, the beneficial effects of the SIM card data management device provided in this application are the same as the beneficial effects of the SIM card data management method provided in the above embodiments. In addition, other technical features in the SIM card data management device are the same as the features disclosed in the method of the previous embodiment, and will not be described in detail here.

[0158] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0159] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0160] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, which are used to execute the SIM card data management method in the above embodiments.

[0161] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0162] The aforementioned computer-readable storage medium may be included in the SIM card data management device; or it may exist independently and not be assembled into the SIM card data management device.

[0163] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0164] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0165] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0166] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described SIM card data management method, thereby solving the technical problem of SIM card data management. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the SIM card data management method provided in the above embodiments, and will not be repeated here.

[0167] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the SIM card data management method described above.

[0168] The computer program product provided in this application can solve the technical problem of SIM card data management. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as the beneficial effects of the SIM card data management method provided in the above embodiments, and will not be repeated here.

[0169] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A SIM card data management method, characterized in that, The method is applied to a card-making system, including: In response to a SIM card production request, a production batch number corresponding to the SIM card production request is generated; Based on the card production batch number and a preset card production data generation algorithm, SIM card production encrypted data is generated, including: obtaining several integrated circuit card identification codes corresponding to the card production batch number; generating a random encryption key and an operator variant key based on a preset system encryption machine; performing secondary distributed encryption according to a pre-generated storage root key, the batch number of the card production batch number, and the integrated circuit card identification codes to obtain a hybrid distributed key; and encrypting the random encryption key and the operator variant key using a first national cryptographic algorithm according to the hybrid distributed key to obtain an encrypted random encryption key and an encrypted operator variant key. Generating a card manufacturer's card production file package based on the card production batch number and the SIM card production encryption data includes: determining target card production data and a card manufacturer certificate index based on the card production batch number and a pre-acquired card manufacturer code, wherein the target card production data includes several integrated circuit card identification codes and the SIM card production encryption data; performing secondary distributed encryption based on a pre-generated storage root key, the card production batch number, and the integrated circuit card identification codes to obtain a hybrid distributed key; decrypting the SIM card production encryption data using a national cryptographic algorithm based on the hybrid distributed key to obtain a random encryption key and an operator variant key; encrypting the random encryption key and the operator variant key using a second national cryptographic algorithm based on the card manufacturer certificate corresponding to the card manufacturer certificate index to obtain a card manufacturer ciphertext random encryption key and a card manufacturer ciphertext operator variant key; and generating the card manufacturer's card production file package based on the card manufacturer ciphertext random encryption key and the card manufacturer ciphertext operator variant key. The card manufacturer's card production file package is sent to the target card manufacturer's production system, so that the target card manufacturer's production system receives the card manufacturer's card production file package, and decrypts it according to the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key in the card manufacturer's card production file package to obtain the random encryption key and the operator variant key respectively. The random encryption key, the operator variant key, and the SIM card production configuration information in the card manufacturer's card production file are written into a pre-connected blank SIM card.

2. The method as described in claim 1, characterized in that, The card vendor card production file package includes a card vendor signature file and a card vendor card production file. The step of generating the card vendor card production file package based on the card vendor's encrypted random encryption key and the card vendor's encrypted operator variant key includes: Generate the original card manufacturing files and the original card signature files for the card vendor; The integrated circuit card identification code, the card vendor's encrypted random encryption key, the card vendor's encrypted operator variant key, and the pre-acquired SIM card manufacturing configuration information are written into the card vendor's original card manufacturing file to obtain the card vendor's card manufacturing file; Based on the file attributes of the card manufacturer's card production file, the card production batch number, and the pre-acquired card production system private key, a signature string and a string signature value are assembled and signed. The signature string and the string signature value are written into the card seller's original signature file to obtain the card seller's signature file.

3. A SIM card data management method, characterized in that, The method is applied to the target card manufacturer's production system, including: The system receives a card manufacturer's card production file package sent by the card manufacturing system. The card manufacturer's card production file package is generated by the card manufacturing system in response to the SIM card production request. The system generates a card production batch number corresponding to the SIM card production request. Based on the card production batch number and a preset card production data generation algorithm, the system generates encrypted SIM card production data. The system generates encrypted SIM card production data based on the card production batch number and the encrypted SIM card production data. The step of generating SIM card encrypted data based on the card production batch number and a preset card production data generation algorithm includes: obtaining several integrated circuit card identification codes corresponding to the card production batch number; generating a random encryption key and an operator variant key based on a preset system encryption machine; performing secondary distributed encryption according to the pre-generated storage root key, the batch number of the card production batch number, and the integrated circuit card identification code to obtain a hybrid distributed key; and encrypting the random encryption key and the operator variant key using a first national cryptographic algorithm according to the hybrid distributed key to obtain an encrypted random encryption key and an encrypted operator variant key. The step of generating a card manufacturer's card production file package based on the card production batch number and the SIM card production encryption data includes: determining the target card production data and the card manufacturer's certificate index according to the card production batch number and the pre-acquired card manufacturer code, wherein the target card production data includes several integrated circuit card identification codes and the SIM card production encryption data; performing secondary distributed encryption based on the pre-generated storage root key, the card production batch number, and the integrated circuit card identification codes to obtain a hybrid distributed key; decrypting the SIM card production encryption data using a national cryptographic algorithm according to the hybrid distributed key to obtain a random encryption key and an operator variant key; encrypting the random encryption key and the operator variant key using a second national cryptographic algorithm according to the card manufacturer certificate corresponding to the card manufacturer's certificate index to obtain a card manufacturer's encrypted random encryption key and a card manufacturer's encrypted operator variant key; and generating the card manufacturer's card production file package based on the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key. Based on the card vendor's encrypted random encryption key and the card vendor's encrypted operator variant key in the card vendor's card production file package, the random encryption key and the operator variant key are decrypted respectively. The random encryption key, the operator variant key, and the SIM card configuration information from the card manufacturer's card production file package are written into a pre-connected blank SIM card.

4. The method as described in claim 3, characterized in that, The card vendor card production file package includes a card vendor signature file and a card vendor card production file. Before the step of decrypting the card vendor encrypted random encryption key and the card vendor encrypted operator variant key respectively based on the card vendor encrypted random encryption key and the card vendor encrypted operator variant key in the card vendor card production file package, the following further step is included: Obtain the signature string and string signature value from the card vendor's signature file; Verify the validity of the signature value of the string based on the pre-obtained card-making system certificate and the signature string; Parse the signature string to obtain the file attributes of the card manufacturer's card production file; If the file attributes of the card manufacturer's card production file match the preset file attribute values, and the string signature value is correct, then the following steps are executed: based on the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key in the card manufacturer's card production file, the random encryption key and the operator variant key are decrypted respectively.

5. A SIM card data management device, characterized in that, The device includes: The first generation module is used to generate a card production batch number corresponding to the SIM card production request in response to the SIM card production request. The second generation module is used to generate SIM card production encryption data based on the card production batch number and a preset card production data generation algorithm. This includes: obtaining several integrated circuit card identification codes corresponding to the card production batch number; generating a random encryption key and a carrier variant key based on a preset system encryption machine; performing secondary distributed encryption based on a pre-generated storage root key, the batch number of the card production batch number, and the integrated circuit card identification codes to obtain a hybrid distributed key; and encrypting the random encryption key and the carrier variant key using a first national cryptographic algorithm based on the hybrid distributed key to obtain an encrypted random encryption key and an encrypted carrier variant key. The third generation module is used to generate a card manufacturer's card production file package based on the card production batch number and the SIM card production encryption data. This includes: determining target card production data and a card manufacturer's certificate index based on the card production batch number and a pre-acquired card manufacturer code, wherein the target card production data includes several integrated circuit card identification codes and the SIM card production encryption data; performing secondary distributed encryption based on a pre-generated storage root key, the card production batch number, and the integrated circuit card identification codes to obtain a hybrid distributed key; decrypting the SIM card production encryption data using a national cryptographic algorithm based on the hybrid distributed key to obtain a random encryption key and an operator variant key; encrypting the random encryption key and the operator variant key using a second national cryptographic algorithm based on the card manufacturer certificate corresponding to the card manufacturer's certificate index to obtain a card manufacturer's encrypted random encryption key and a card manufacturer's encrypted operator variant key; and generating the card manufacturer's card production file package based on the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key. The sending module is used to send the card manufacturer's card production file package to the target card manufacturer's production system, so that the target card manufacturer's production system receives the card manufacturer's card production file package, decrypts it according to the card manufacturer's encrypted random encryption key and the card manufacturer's encrypted operator variant key in the card manufacturer's card production file package to obtain the random encryption key and the operator variant key respectively, and writes the random encryption key, the operator variant key, and the SIM card production configuration information in the card manufacturer's card production file into a pre-connected blank SIM card.

6. A SIM card data management device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the SIM card data management method as described in any one of claims 1 to 4.

7. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the SIM card data management method as described in any one of claims 1 to 4.

8. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the SIM card data management method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Card key management method and system

    CN113726514A

  • Network access authentication data protection method and device, storage medium and electronic equipment

    CN117750360A