Profile data writing method and device
By introducing a Profile data writing method in the eSIM manufacturing system, using the data preparation server and the Profile installation assistant, the problem of eSIM terminal equipment manufacturers need to pre-install the operator's Profile data during the stocking stage is solved, and secure writing of Profile data and flexible order scheduling are realized.
Patent Information
- Application Number
- CN202411880562.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-19
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, eSIM terminal equipment manufacturers need to pre-install operator profile data during the stocking stage, which affects the production and manufacturing order schedule and increases the complexity of managing eSIM materials.
Profile data writing method and device are proposed. Through the data preparation server and the Profile installation assistant in the eSIM manufacturing system, the operator's Profile data is safely written into the eSIM chip. The specific steps include importing the basic information and Profile data of the eSIM, generating candidate Profile files, building an EID list, determining the Profile file to be installed, generating an encryption package, and writing the Profile data to the eSIM terminal.
Ensure the security of the operator's Profile data, so that the timing of the Profile data being written to the eSIM chip is before the eSIM terminal equipment leaves the factory, thereby reducing the complexity of eSIM terminal equipment manufacturers in managing eSIM materials and improving the flexibility of order schedules.
Smart Images

Figure CN119937940A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Things, and in particular to a Profile data writing method and a device thereof. Background Art
[0002] Since operator profile data is highly sensitive data, to ensure the security of operator profile data, operators require eSIM manufacturers to pre-set operator profile data in eSIM chips before shipment. This will cause eSIM terminal equipment manufacturers to incur data package fees during the stocking stage, which not only affects the production and manufacturing order scheduling plans of eSIM terminal equipment manufacturers, but also increases the complexity of eSIM terminal equipment manufacturers in managing eSIM materials. Summary of the invention
[0003] The present invention aims to solve at least one of the technical problems existing in the prior art. To this end, the present invention proposes a method and device for writing profile data, which can ensure the security of operator profile data and enable the operator profile data to be written into the eSIM chip before the eSIM terminal device leaves the factory, thereby reducing the complexity of eSIM terminal device manufacturers in managing eSIM materials and improving the flexibility of order scheduling for eSIM terminal manufacturers.
[0004] In a first aspect, an embodiment of the present invention provides a method for writing Profile data, which is applied to an eSIM manufacturing system, wherein the eSIM manufacturing system includes a data preparation server and a terminal production line device, wherein the terminal production line device is provided with a plurality of eSIM terminals to be shipped, wherein the terminal production line device is pre-installed with a Profile installation assistant, wherein the data preparation server is communicatively connected with the Profile installation assistant, wherein the eSIM terminal is installed with an eSIM chip, wherein the eSIM chip is not pre-installed with Profile data, and wherein the method includes: Importing a plurality of eSIM basic information and a plurality of Profile data on the data preparation server, and generating a candidate Profile file based on each pair of the eSIM basic information and the Profile data, wherein the eSIM basic information includes a first EID; Building an EID list based on the second EID of each of the eSIM chips through the Profile installation assistant, and sending the EID list to the data preparation server; The data preparation server determines a plurality of profile files to be installed from the candidate profile files based on the EID list, generates an encrypted package based on all the profile files to be installed, and sends the encrypted package to the profile installation assistant, wherein the profile file to be installed is the candidate profile file whose first EID is recorded in the EID list; The Profile installation assistant obtains the Profile file to be installed based on the encrypted package, determines a corresponding target Profile file from the multiple Profile files to be installed based on the second EID of any of the eSIM terminals, and writes the Profile data of the target Profile file into the corresponding eSIM terminal.
[0005] According to some embodiments of the present invention, the eSIM basic information includes a public key value, and generating a candidate Profile file based on each pair of the eSIM basic information and the Profile data includes: Generate a temporary session key based on the first EID, encrypt the Profile data into Profile encrypted data, and generate a MAC value based on the Profile encrypted data; Encrypting the temporary session key based on the public key value and a preset asymmetric algorithm to obtain temporary session key ciphertext data; The first EID, the temporary session key ciphertext data, the Profile encryption data and the MAC value are serially concatenated into the candidate Profile file.
[0006] According to some embodiments of the present invention, the data preparation server includes an API interface, and sending the EID list to the data preparation server includes: The Profile installation assistant calls the API interface to send the EID list and the preset authorization credential code to the data preparation server; After verification based on the authorization credential code is passed, the data preparation server matches the first EID based on the EID list; When each of the second EIDs recorded in the EID list matches the corresponding first EID, a data preparation transaction is created through the API interface and a transaction ID is generated, and the transaction ID and a normal status word are returned to the Profile installation assistant.
[0007] According to some embodiments of the present invention, the data preparation server determines a plurality of profile files to be installed from the candidate profile files based on the EID list, and generates an encrypted package based on all the profile files to be installed, including: Determining the candidate Profile file of the first EID that matches the second EID as the Profile file to be installed; The data preparation server serially concatenates and encodes the plurality of Profile files to be installed into the encrypted package.
[0008] According to some embodiments of the present invention, sending the encrypted package to the Profile installation assistant includes: The Profile installation assistant calls the API interface and sends the transaction ID to the data preparation server; The data preparation server sends the corresponding encrypted package to the Profile installation assistant based on the transaction ID.
[0009] According to some embodiments of the present invention, the Profile installation assistant obtains the Profile file to be installed based on the encrypted package, determines a corresponding target Profile file from a plurality of Profile files to be installed based on the second EID of any of the eSIM terminals, and writes the Profile data of the target Profile file into the corresponding eSIM terminal, including: The Profile installation assistant decodes the encrypted package to obtain a plurality of Profile files to be installed; The Profile installation assistant determines the second EID of any of the eSIM terminals as a target EID, and determines the Profile file to be installed of the target EID as the target Profile file; The Profile installation assistant sends the target Profile file to the eSIM chip of the corresponding eSIM terminal, and installs the Profile data of the target Profile file through the eSIM chip.
[0010] According to some embodiments of the present invention, the eSIM chip is pre-installed with a Profile template, the Profile data includes network access authentication data, and the Profile data of the target Profile file is installed through the eSIM chip, including: The Profile installation assistant converts the target Profile file into an APDU instruction and sends the APDU instruction to the eSIM terminal; The eSIM terminal obtains the target Profile file based on the APDU instruction; The eSIM terminal decrypts the temporary session key ciphertext data of the target Profile file based on the asymmetric algorithm to obtain the temporary session key, and decrypts the Profile encrypted data of the target Profile file based on the temporary session key to obtain the target Profile data; Based on the Profile template, the network access authentication data of the target Profile data is written into the eSIM chip.
[0011] In a second aspect, an embodiment of the present invention provides a profile data writing device, comprising at least one control processor and a memory for communicating with the at least one control processor; the memory stores instructions executable by the at least one control processor, and the instructions are executed by the at least one control processor so that the at least one control processor can execute the profile data writing method as described in the first aspect above.
[0012] The Profile data writing method according to an embodiment of the present invention has at least the following beneficial effects: applied to an eSIM manufacturing system, the eSIM manufacturing system comprising a data preparation server and a terminal production line device, the terminal production line device being provided with a plurality of eSIM terminals to be shipped, the terminal production line device being pre-installed with a Profile installation assistant, the data preparation server being communicatively connected with the Profile installation assistant, the eSIM terminal being installed with an eSIM chip, the eSIM chip being not pre-installed with Profile data, the method comprising: importing a plurality of eSIM basic information and a plurality of Profile data on the data preparation server, generating a candidate Profile file based on each pair of the eSIM basic information and the Profile data, wherein the eSIM basic information comprises a first EID; generating a candidate Profile file based on each pair of the eSIM basic information and the Profile data through the Profile installation assistant; The second EID of the M chip constructs an EID list, and sends the EID list to the data preparation server; the data preparation server determines multiple profile files to be installed from the candidate profile files based on the EID list, generates an encrypted package based on all the profile files to be installed, and sends the encrypted package to the profile installation assistant, wherein the profile file to be installed is the candidate profile file recorded in the EID list by the first EID; the profile installation assistant obtains the profile file to be installed based on the encrypted package, determines the corresponding target profile file from the multiple profile files to be installed based on the second EID of any of the eSIM terminals, and writes the profile data of the target profile file into the corresponding eSIM terminal. According to the technical solution of the embodiment of the present invention, the security of the operator profile data can be guaranteed, and the timing of writing the operator profile data into the eSIM chip is before the eSIM terminal device leaves the factory, thereby reducing the complexity of the eSIM terminal device manufacturer in managing eSIM materials and improving the flexibility of the order scheduling of the eSIM terminal manufacturer. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 is a schematic diagram of an eSIM manufacturing system provided by an embodiment of the present invention; Figure 2 is a flow chart of a method for writing Profile data provided by another embodiment of the present invention; Figure 3 is a flowchart of a specific example of a method for writing Profile data provided by another embodiment of the present invention; Figure 4It is a structural diagram of a Profile data writing device provided by another embodiment of the present invention. DETAILED DESCRIPTION
[0014] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be understood as limiting the present invention.
[0015] In the description of the present invention, it should be understood that descriptions involving orientations, such as up, down, front, back, left, right, etc., and orientations or positional relationships indicated are based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present invention.
[0016] In the description of the present invention, "several" means one or more, "more" means more than two, "greater than", "less than", "exceed" etc. are understood as not including the number itself, and "above", "below", "within" etc. are understood as including the number itself. If there is a description of "first" or "second", it is only used for the purpose of distinguishing the technical features, and cannot be understood as indicating or implying the relative importance or implicitly indicating the number of the indicated technical features or implicitly indicating the order of the indicated technical features.
[0017] In the description of the present invention, unless otherwise clearly defined, terms such as setting, installing, connecting, etc. should be understood in a broad sense, and technicians in the relevant technical field can reasonably determine the specific meanings of the above terms in the present invention based on the specific content of the technical solution.
[0018] An embodiment of the present invention provides a method for writing Profile data and a device thereof, wherein the method for writing Profile data is applied to an eSIM manufacturing system, wherein the eSIM manufacturing system includes a data preparation server and a terminal production line device, wherein the terminal production line device is provided with a plurality of eSIM terminals to be shipped out of the factory, wherein the terminal production line device is pre-installed with a Profile installation assistant, the data preparation server is in communication connection with the Profile installation assistant, the eSIM terminal is installed with an eSIM chip, and the eSIM chip is not pre-installed with Profile data, and the method comprises: importing a plurality of eSIM basic information and a plurality of Profile data on the data preparation server, generating a candidate Profile file based on each pair of the eSIM basic information and the Profile data, wherein the eSIM basic information includes a first EID; using the Profile installation assistant to generate a candidate Profile file based on each The second EID of the eSIM chip constructs an EID list, and sends the EID list to the data preparation server; the data preparation server determines multiple profile files to be installed from the candidate profile files based on the EID list, generates an encrypted package based on all the profile files to be installed, and sends the encrypted package to the profile installation assistant, wherein the profile file to be installed is the candidate profile file recorded in the EID list by the first EID; the profile installation assistant obtains the profile file to be installed based on the encrypted package, determines the corresponding target profile file from the multiple profile files to be installed based on the second EID of any of the eSIM terminals, and writes the profile data of the target profile file into the corresponding eSIM terminal. According to the technical solution of the embodiment of the present invention, the security of the operator profile data can be guaranteed, and the timing of writing the operator profile data into the eSIM chip is before the eSIM terminal device leaves the factory, thereby reducing the complexity of the eSIM terminal device manufacturer in managing eSIM materials and improving the flexibility of the order scheduling of the eSIM terminal manufacturer.
[0019] First, refer to Figure 1 , Figure 1 A schematic diagram of an eSIM manufacturing system provided for an embodiment of the present invention is applied to the eSIM manufacturing system, the eSIM manufacturing system includes a data preparation server and terminal production line equipment, the terminal production line equipment is provided with multiple eSIM terminals to be shipped, the terminal production line equipment is pre-installed with a Profile installation assistant, the data preparation server is communicatively connected with the Profile installation assistant, the eSIM terminal is installed with an eSIM chip, and the eSIM chip is not pre-installed with Profile data.
[0020] It should be noted that the data preparation server is located in a secure physical environment deployed by the operator. The data preparation server is authorized by the operator, and only the Profile installation assistant that meets the request conditions of the data preparation server can access and obtain the encryption package. The data preparation server can support operators to upload Profile data, support eSIM chip manufacturers to upload eSIM basic information, support batch encryption of Profile encrypted data, and support eSIM terminal manufacturers to remotely request Profile encrypted data from operators through the Internet or dedicated lines.
[0021] It should be noted that the eSIM terminal can be any terminal device equipped with an eSIM chip, such as a smart bracelet or tablet computer.
[0022] It should be noted that terminal production line equipment is production line equipment for producing eSIM terminals, such as production line equipment for producing smart bracelets and tablet computers. The terminal production line equipment is connected to multiple eSIM terminals with installed eSIM chips. The eSIM chips installed in the eSIM terminals are not pre-set with Profile data. The terminal production line equipment can read the basic information of the eSIM chip through the connection relationship with the eSIM terminal.
[0023] It should be noted that the Profile Installation Assistant is Profile data-related software installed on terminal production line equipment. The Profile Installation Assistant obtains the basic information of the eSIM chip through the terminal production line equipment, supports requesting encrypted packages from the data preparation server, extracts multiple target Profile files from the encrypted packages, and writes the Profile data corresponding to the specified eSIM chip to the specified eSIM chip through the terminal production line equipment.
[0024] It should be noted that the data preparation server and the Profile installation assistant are connected through VPN or dedicated line communication, and the Profile installation assistant requests access and establishes an HTTP secure connection with the data preparation server. However, the encrypted package can only be transmitted between the data preparation server and the Profile installation assistant after the data preparation server successfully verifies the request conditions of the Profile installation assistant.
[0025] The following is combined with Figure 1 The eSIM manufacturing system shown is used to further illustrate the Profile data writing method of the embodiment of the present invention.
[0026] Reference Figure 2 , Figure 2 A flowchart of a method for writing profile data provided by an embodiment of the present invention. The method for writing profile data includes but is not limited to the following steps: S110, importing multiple eSIM basic information and multiple Profile data on the data preparation server, and generating a candidate Profile file based on each pair of eSIM basic information and Profile data, wherein the eSIM basic information includes the first EID; S120, constructing an EID list based on the second EID of each eSIM chip through the Profile installation assistant, and sending the EID list to the data preparation server; S130, the data preparation server determines multiple profile files to be installed from the candidate profile files based on the EID list, generates an encrypted package based on all the profile files to be installed, and sends the encrypted package to the profile installation assistant, wherein the profile file to be installed is the candidate profile file whose first EID is recorded in the EID list; S140, the Profile installation assistant obtains the Profile file to be installed based on the encrypted package, determines a corresponding target Profile file from multiple Profile files to be installed based on the second EID of any eSIM terminal, and writes Profile data of the target Profile file into the corresponding eSIM terminal.
[0027] It should be noted that eSIM terminal manufacturers order eSIM chips without pre-installed Profile data from eSIM chip manufacturers, and the eSIM chip manufacturers import the basic information of the eSIM chips into the data preparation server; eSIM terminal manufacturers order Profile data from operators, and the operators import the Profile data into the data preparation server.
[0028] It should be noted that the basic information of the eSIM chip is the basic information of the eSIM chip, and the basic information of each eSIM chip is different. The basic information of the eSIM chip includes EID, authorization certificate code, public key value and private key value.
[0029] It should be noted that the association between the first EID and the Profile data has been completed before the candidate Profile file is generated, and there is a one-to-one correspondence between the first EID and the Profile data.
[0030] It should be noted that the eSIM terminal manufacturer orders eSIM chips from the eSIM chip manufacturer. After the eSIM terminal manufacturer receives the order, the eSIM chip is put into eSIM terminal production. After the eSIM terminal is completed and ready to leave the factory, the Profile data is written to the eSIM terminal. The Profile Installation Assistant reads the EID, i.e., the second EID, of the eSIM chip installed in the eSIM terminal connected to the terminal production line equipment through the terminal production line equipment. One second EID corresponds to only one eSIM terminal. After the Profile Installation Assistant reads all the second EIDs, an EID list is generated for all second EID sets.
[0031] It should be noted that the Profile Installation Assistant generates an EID list and sends it to the data preparation server. It only needs to obtain the Profile data corresponding to the second EID in the EID list, thereby reducing the total time of the eSIM terminal writing Profile data, reducing the traffic costs that eSIM terminal manufacturers need to bear, and improving the production efficiency of eSIM terminals.
[0032] It should be noted that, since the eSIM terminal manufacturer puts the ordered eSIM chip into the eSIM terminal production process, the first EID includes the second EID. A candidate Profile file includes a first EID, and based on the second EID in the EID list, the candidate Profile file including the first EID with the same characters as the second EID is the Profile file to be installed.
[0033] It should be noted that since eSIM terminal manufacturers have reserves of eSIM chips and unused candidate Profile files, and eSIM terminal manufacturers can only produce eSIM terminals based on order requirements, they cannot determine when and which eSIM chip will be used in eSIM terminal production. Therefore, the Profile file to be installed is matched from the candidate Profile files saved in the data preparation server through the EID list.
[0034] It should be noted that because Profile data is highly sensitive data, each manufacturer must ensure the security of Profile data. The timing of writing Profile data is now moved back to before the eSIM terminal leaves the factory. Profile data needs to be remotely transmitted across devices, operators, and eSIM terminal manufacturers to obtain Profile data. In this process, in order to ensure the security and integrity of Profile data, Profile data is protected by encryption. The encryption method of Profile data can select any encryption algorithm and its combination.
[0035] It should be noted that the data preparation server can complete the encryption of the Profile data during the candidate Profile file generation process. That is, after the data preparation server determines all the Profile files to be installed, it only needs to package the Profile files to be installed to generate an encrypted package and send it to the Profile installation assistant, thereby reducing the total time of the eSIM terminal writing Profile data and reducing the traffic costs generated by the eSIM chip after the Profile data is written, which the eSIM terminal manufacturer needs to bear.
[0036] It should be noted that the process from the Profile Installation Assistant obtaining the encrypted package to writing the Profile data to the eSIM chip must include decrypting the encrypted Profile data. To ensure the security of the Profile data, the encrypted Profile data can only be decrypted by the designated eSIM chip. The Profile data is encrypted based on the EID of the eSIM chip.
[0037] It should be noted that after the Profile Installation Assistant obtains the encrypted package, it obtains all the Profile files to be installed based on the encrypted package, and the Profile files to be installed include the first EID. The Profile Installation Assistant can obtain the target Profile files one by one. For example, the terminal production line equipment includes eSIM terminal No. 1, eSIM terminal No. 2, and eSIM terminal No. 3. The Profile Installation Assistant reads the EID of eSIM terminal No. 1 through the terminal production line equipment, that is, the second EID, which is 123. According to the character 123 of the second EID, it matches the first EID in the Profile file to be installed. The characters of the first EID in the Profile file to be installed are 123. The matched Profile file to be installed is the target Profile file, and the Profile data of the target Profile file is written to eSIM terminal No. 1. The Profile Installation Assistant can also obtain target Profile files in batches. For example, the Profile Installation Assistant reads eSIM Terminal No. 1, eSIM Terminal No. 2, and eSIM Terminal No. 3 located in the terminal production line equipment through the terminal production line equipment, and according to the second EID No. 1 of eSIM Terminal No. 1: 123, the second EID No. 2 of eSIM Terminal No. 2: 456, and the second EID No. 3 of eSIM Terminal No. 3: 789, the Profile files to be installed that include the same characters as the second EID No. 1, the second EID No. 2, and the second EID No. 3 are determined from all Profile files to be installed, namely, the target Profile file No. 1, the target Profile file No. 2, and the target Profile file No. 3, and send them to eSIM Terminal No. 1, eSIM Terminal No. 2, and eSIM Terminal No. 3.
[0038] It should be noted that the eSIM terminal manufacturer orders eSIM chips without pre-installed Profile data from the eSIM chip manufacturer, and the eSIM chip manufacturer imports the basic information of the eSIM chip into the data preparation server; the eSIM terminal manufacturer orders Profile data from the operator, and the operator imports the Profile data into the data preparation server; before generating the candidate Profile file, the first EID and the Profile data are made to correspond one to one, and a candidate Profile file only includes one first EID. Generate an EID list for the EIDs of the eSIM chips of all eSIM terminals, that is, all second EIDs, and send it to the data preparation server. The data preparation server selects the candidate Profile file corresponding to the first EID recorded in the EID list, and determines it as the Profile file to be installed; encode multiple Profile files to be installed to generate an encrypted package and send it to the Profile installation assistant. The Profile Installation Assistant decodes the encrypted package to obtain multiple Profile files to be installed, selects any second EID, determines a target Profile file including the same characters as the second EID among the multiple Profile files to be installed, the target Profile file includes a first EID with the same characters as the second EID and Profile data, sends the target Profile file to the eSIM terminal corresponding to the second EID, and writes the Profile data to the internal secure storage area of the eSIM chip.
[0039] It should be noted that traffic charges will be incurred as soon as the Profile data is written into the eSIM chip. In the technical solution of this embodiment, the eSIM chip produced by the eSIM manufacturer does not pre-set the Profile data, so it is not activated when delivered to the terminal manufacturer, so no traffic charges will be incurred. After the terminal manufacturer determines multiple eSIM terminals according to production needs, it requests Profile data from the data preparation server through the Profile installation assistant. Through the technical solution of this embodiment, the Profile data is written into the eSIM terminal on the eSIM manufacturer side, so that the eSIM traffic is reactivated when the eSIM terminal leaves the factory, reducing traffic charges. Therefore, the eSIM terminal manufacturer orders an eSIM chip that is not pre-set with Profile data, and through the data interaction between the data preparation server and the Profile installation assistant, the eSIM terminal manufacturer can write the Profile data into the eSIM terminal to be shipped in a secure manner, reducing the traffic charges generated by the eSIM chip that the eSIM terminal manufacturer needs to bear, thereby reducing the complexity of the eSIM terminal manufacturer's management of the eSIM chip and improving the flexibility of order scheduling.
[0040] In addition, in one embodiment, the eSIM basic information includes a public key value, and a candidate Profile file is generated based on each pair of the eSIM basic information and the Profile data. Figure 2 S110 of the illustrated embodiment further includes but is not limited to the following steps: S210, generating a temporary session key based on the first EID, encrypting the Profile data into Profile encrypted data, and generating a MAC value based on the Profile encrypted data; S220, encrypting the temporary session key based on the public key value and a preset asymmetric algorithm to obtain ciphertext data of the temporary session key; S230, serially concatenate the first EID, the temporary session key ciphertext data, the Profile encryption data and the MAC value into a candidate Profile file.
[0041] It should be noted that the encryption algorithm of this embodiment may be a symmetric algorithm or an asymmetric algorithm. The symmetric algorithm of this application may be a symmetric algorithm such as AES and SM4, and the asymmetric algorithm of this application may be an asymmetric algorithm such as ECC or SM2. This application does not make any improvements to the encryption algorithm, symmetric algorithm, and asymmetric algorithm, and will not be elaborated here.
[0042] It should be noted that the temporary session key is generated based on the first EID through the key algorithm, the generated temporary session key is unique, the key algorithm adopts symmetric algorithms such as AES and SM4, and the key algorithm does not exclude the use of asymmetric algorithms to generate temporary session keys.
[0043] It should be noted that a message authentication code (MAC value) is generated based on the Profile encrypted data, and the MAC value is used to determine whether the Profile encrypted data has been encrypted and tampered with; this application does not make any improvements to the method of generating the MAC value, and will not be elaborated here.
[0044] It should be noted that the obtained candidate Profile file is a standard DER-TLV structure, thereby ensuring the security and integrity of the candidate Profile file during the subsequent transmission of the candidate Profile file from the data preparation server to the Profile security assistant.
[0045] It should be noted that the temporary session key generated in this embodiment is unique and corresponds to the first EID. The Profile data is encrypted using the temporary session key, and the temporary session key is encrypted using the public key value, thereby ensuring the confidentiality and integrity of the operator's Profile data.
[0046] In addition, in one embodiment, the data preparation server includes an API interface. Figure 2 S120 in the illustrated embodiment further includes but is not limited to the following steps: S310, the Profile installation assistant calls the API interface to send the EID list and the preset authorization credential code to the data preparation server; S320, after the data preparation server passes the verification based on the authorization credential code, matches the first EID based on the EID list; S330: When each second EID recorded in the EID list matches the corresponding first EID, a data preparation transaction is created through the API interface and a transaction ID is generated, and the transaction ID and a normal status word are returned to the Profile installation assistant.
[0047] It should be noted that one authorization credential code corresponds to multiple EIDs. The data preparation server includes the authorization credential codes of all first EIDs. The authorization credential code of the second EID sent by the Profile installation assistant is compared with the authorization credential code of the first EID. If the authorization credential code of the second EID can be found in the authorization credential code of the first EID, the verification passes, indicating that the data preparation server has the Profile data required by the second EID in the EID list, and the Profile installation assistant meets the request conditions of the data preparation server.
[0048] It should be noted that, given that the authorization credential code verification has passed, the first EID must include the second EID; the first EID is matched based on the EID list, that is, the second EID based on the EID list, to find out whether there are characters in the first EID that are the same as those in the second EID. If they are the same, it is regarded as the first EID matched by the second EID; after matching all the first EIDs, a data preparation transaction is created and a transaction ID is generated. The transaction ID is associated with the data preparation transaction generated together and the EID list on which it is based.
[0049] It should be noted that the Profile installation assistant receives the transaction ID and the normal status word, and obtains the result: the data preparation server has the Profile data required for the EID list sent this time, and the transaction ID corresponding to the EID list sent.
[0050] In addition, in one embodiment, Figure 2 S130 in the illustrated embodiment further includes but is not limited to the following steps: S410, the candidate Profile file of the first EID matching the second EID is determined as the Profile file to be installed; S420, the data preparation server serially concatenates and encodes multiple Profile files to be installed into an encrypted package.
[0051] It should be noted that the eSIM terminal manufacturer puts the ordered eSIM chips into production according to the order requirements, that is, the first EID must include the second EID, and the Profile file to be installed includes only one first EID; a second EID is selected, and a Profile file to be installed that includes the same first EID as the selected second EID is determined among multiple Profile files to be installed, and the selected Profile file to be installed is the target Profile file.
[0052] It should be noted that the data preparation server serially concatenates multiple Profile files and then performs standard Base64 encoding to obtain an encrypted package.
[0053] In addition, in one embodiment, Figure 2 S130 in the illustrated embodiment further includes but is not limited to the following steps: S510, the Profile installation assistant calls the API interface and sends the transaction ID to the data preparation server; S520: The data preparation server sends the corresponding encrypted package to the Profile installation assistant based on the transaction ID.
[0054] It should be noted that the data preparation server can receive multiple EID lists sent by the Profile installation assistant and generate multiple corresponding encryption packages, data preparation tasks and transaction IDs. The eSIM terminal to be shipped is connected to the Profile installation assistant. The Profile assistant obtains the EID list of the second EID of multiple eSIM terminals, obtains the corresponding transaction ID according to the EID list, and sends it to the data preparation server. Based on the received transaction ID, the data preparation server obtains the data preparation task and the corresponding encryption package corresponding to the transaction ID, and sends the encrypted package to the Profile installation assistant.
[0055] It should be noted that through the transaction ID, the data preparation server does not need to complete two-way authentication with the eSIM chip again, which improves the production efficiency of eSIM terminal manufacturers.
[0056] In addition, in one embodiment, Figure 2 S140 in the illustrated embodiment further includes but is not limited to the following steps: S610, the Profile installation assistant decodes the encrypted package to obtain multiple Profile files to be installed; S620, the Profile installation assistant determines the second EID of any eSIM terminal as the target EID, and determines the profile file to be installed of the target EID as the target profile file; S630: The Profile installation assistant sends the target Profile file to the eSIM chip of the corresponding eSIM terminal, and installs Profile data of the target Profile file through the eSIM chip.
[0057] It should be noted that after the Profile installation assistant obtains the encrypted package, it caches the encrypted package locally, decodes the encrypted package, and divides the serially spliced files to be installed to obtain multiple single files to be installed; the files to be installed include the first EID and the Profile encrypted data corresponding to the first EID; obtain any second EID, search in the file to be installed, the first EID that is the same as the second EID is the target EID, and the file to be installed containing the target EID is the target Profile file; send the target Profile file to the eSIM chip corresponding to the selected second EID, the eSIM chip decrypts the target Profile file, obtains and installs the Profile data.
[0058] It should be noted that although the Profile Installation Assistant can obtain the Profile file to be installed based on the encrypted package, it cannot decrypt the target Profile file. Only the eSIM chip that includes the same characters as the first EID has the same basic information as the first EID. The basic information of the first EID includes a private key value paired with a public key value. Only the eSIM chip that includes the same characters as the first EID can decrypt the target Profile file, thereby ensuring the security and confidentiality of the Profile data.
[0059] In addition, in one embodiment, the eSIM chip is pre-installed with a Profile template, and the Profile data includes network access authentication data. Figure 2 S140 in the illustrated embodiment further includes but is not limited to the following steps: S710, the Profile installation assistant converts the target Profile file into an APDU command, and sends the APDU command to the eSIM terminal; S720, the eSIM terminal obtains the target Profile file based on the APDU instruction; S730, the eSIM terminal decrypts the temporary session key ciphertext data of the target Profile file based on the asymmetric algorithm to obtain the temporary session key, and decrypts the Profile encrypted data of the target Profile file based on the temporary session key to obtain the target Profile data; S740: Write the network access authentication data of the target Profile data into the eSIM chip based on the Profile template.
[0060] It should be noted that before decryption, the MAC value of the Profile encrypted data of the target Profile file is calculated based on the same algorithm, and the MAC value of the candidate Profile file is compared with the MAC value of the target Profile file. If the two MAC values are the same, the Profile encrypted data has not been tampered with during the transmission process.
[0061] It should be noted that the temporary session key ciphertext data is obtained by encrypting the temporary session key based on the public key value and the asymmetric algorithm. The eSIM basic information includes a pair of public key values and private key values. In this embodiment, the temporary session key ciphertext data of the target Profile file is decrypted by the asymmetric algorithm and the private key value to obtain the temporary session key; if the Profile data is encrypted by a symmetric algorithm and a temporary session key, the Profile encrypted data is decrypted based on the same symmetric algorithm and the temporary session key to obtain the Profile data, and the obtained Profile data is written into the internal secure storage area of the eSIM chip.
[0062] It should be noted that, knowing the specific symmetric algorithm or asymmetric algorithm and having the decryption key, technical personnel in this field are familiar with how to decrypt temporary session key ciphertext data based on the asymmetric algorithm and the private key value, and are familiar with decrypting Profile encrypted data based on the symmetric algorithm and the temporary session key; this application does not make any improvements to the encryption algorithm or the decryption process, and will not go into details here.
[0063] It should be noted that this application only writes the network access authentication data of the Profile data into the eSIM chip, thereby shortening the time for writing the Profile data into the eSIM chip and improving the production efficiency of the eSIM terminal.
[0064] It should be noted that when the eSIM chip leaves the factory, the eSIM chip manufacturer has preset the Profile template for the eSIM chip. The Profile template defines the operator's file system. The format of the Profile data of this application complies with the "eUICC Profile Package: Interoperable Format Technical Specification" standard issued by the international TCA organization. However, the present invention does not exclude the use of Profile data in other formats, such as Profile data in a custom format. The Profile template preset in this embodiment makes adaptive changes according to the Profile data format.
[0065] It should be noted that after the Profile data is written into the eSIM chips of all eSIM terminals, the Profile Installation Assistant deletes the temporarily stored encrypted package.
[0066] In addition, in order to better illustrate the technical solution of this embodiment, the following specific examples are provided. Figure 3 , including but not limited to the following steps: S810, the eSIM terminal manufacturer orders an eSIM chip without pre-set Profile data from the eSIM chip manufacturer, and the eSIM chip manufacturer imports the basic information of the eSIM chip ordered by the eSIM terminal manufacturer into the data preparation server; the eSIM terminal manufacturer orders Profile data from the operator, and the operator imports the Profile data into the data preparation server; the data preparation server associates the eSIM basic information with the Profile data one by one, and generates a candidate Profile file based on the first EID and public key value in the eSIM basic information and the key algorithm; S820, the Profile installation assistant reads the basic information of the eSIM terminal through the terminal production line equipment, and generates an EID list and an authorization certificate code and sends them to the data preparation server; after the data preparation server verifies the authorization certificate code, it matches the first EID corresponding to the second EID based on the second EID in the EID list, and generates a data preparation transaction and a transaction ID, and the data preparation server sends the transaction ID to the Profile installation assistant; S830, the data preparation server determines the profile file to be installed in the candidate profile files based on the matched first EID, and generates an encrypted package after serial splicing and encoding multiple profile files to be installed. The Profile installation assistant sends the transaction ID to the data preparation server, and the data preparation server obtains the corresponding data preparation transaction and encrypted package based on the transaction ID, and sends the encrypted package to the Profile installation assistant; S840, the Profile installation assistant decodes and splits the obtained encrypted package to obtain multiple Profile files to be installed. The Profile installation assistant reads the EID of any eSIM terminal through the terminal production line equipment, that is, the target EID, and determines the Profile file to be installed including the target EID as the target Profile file. The Profile installation assistant sends the target Profile file to the eSIM terminal corresponding to the target EID. The eSIM chip of the eSIM terminal verifies the MAC value of the target Profile file. After the verification passes, the Profile encrypted data is decrypted based on the EID and private key value in the basic information of the eSIM chip to obtain the Profile data, and the network access authentication data of the Profile data is written into the internal security area of the eSIM chip. After the Profile installation assistant sends all the Profile files to be installed in the encrypted package to the corresponding eSIM terminal, the Profile installation assistant deletes the encrypted package.
[0067] As shown in the figure, Figure 4 As shown, Figure 4 : is a structural diagram of a Profile data writing device provided by an embodiment of the present invention. The present invention also provides a Profile data writing device, comprising: The processor 901 may be implemented by a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application; The memory 902 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store an operating system and other application programs. When the technical solution provided in the embodiment of this specification is implemented by software or firmware, the relevant program code is stored in the memory 902, and the processor 901 calls and executes the Profile data writing method of the embodiment of this application; Input / output interface 903, used to implement information input and output; Communication interface 904, used to realize communication interaction between the device and other devices, which can be realized through wired mode (such as USB, network cable, etc.) or wireless mode (such as mobile network, WIFI, Bluetooth, etc.); A bus 905 that transmits information between various components of the device (e.g., the processor 901, the memory 902, the input / output interface 903, and the communication interface 904); The processor 901 , the memory 902 , the input / output interface 903 and the communication interface 904 are connected to each other in communication within the device via a bus 905 .
[0068] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the above-mentioned implementation mode. Technical personnel familiar with the field can also make various equivalent deformations or substitutions under the shared conditions without violating the spirit of the present invention. These equivalent deformations or substitutions are all included in the scope defined by the claims of the present invention.
Claims
1. A method for writing Profile data of an eSIM terminal, characterized in that: Applied to an eSIM manufacturing system, the eSIM manufacturing system includes a data preparation server and a terminal production line device, the terminal production line device is provided with a plurality of eSIM terminals to be shipped, the terminal production line device is pre-installed with a Profile installation assistant, the data preparation server is in communication connection with the Profile installation assistant, the eSIM terminal is installed with an eSIM chip, and the eSIM chip is not pre-installed with Profile data, the method includes: Importing a plurality of eSIM basic information and a plurality of Profile data on the data preparation server, and generating a candidate Profile file based on each pair of the eSIM basic information and the Profile data, wherein the eSIM basic information includes a first EID; Building an EID list based on the second EID of each of the eSIM chips through the Profile installation assistant, and sending the EID list to the data preparation server; The data preparation server determines a plurality of profile files to be installed from the candidate profile files based on the EID list, generates an encrypted package based on all the profile files to be installed, and sends the encrypted package to the profile installation assistant, wherein the profile file to be installed is the candidate profile file whose first EID is recorded in the EID list; The Profile installation assistant obtains the Profile file to be installed based on the encrypted package, determines a corresponding target Profile file from the multiple Profile files to be installed based on the second EID of any of the eSIM terminals, and writes the Profile data of the target Profile file into the corresponding eSIM terminal.
2. The method for writing Profile data of an eSIM terminal according to claim 1, characterized in that: The eSIM basic information includes a public key value, and a candidate Profile file is generated based on each pair of the eSIM basic information and the Profile data. include, Generate a temporary session key based on the first EID, encrypt the Profile data into Profile encrypted data, and generate a MAC value based on the Profile encrypted data; Encrypting the temporary session key based on the public key value and a preset asymmetric algorithm to obtain temporary session key ciphertext data; The first EID, the temporary session key ciphertext data, the Profile encryption data and the MAC value are serially concatenated into the candidate Profile file.
3. The method for writing Profile data of an eSIM terminal according to claim 2, characterized in that: The data preparation server includes an API interface, and sending the EID list to the data preparation server includes: The Profile installation assistant calls the API interface to send the EID list and the preset authorization credential code to the data preparation server; After verification based on the authorization credential code is passed, the data preparation server matches the first EID based on the EID list; When each of the second EIDs recorded in the EID list matches the corresponding first EID, a data preparation transaction is created through the API interface and a transaction ID is generated, and the transaction ID and a normal status word are returned to the Profile installation assistant.
4. The method for writing profile data of an eSIM terminal according to claim 3, characterized in that: The data preparation server determines a plurality of profile files to be installed from the candidate profile files based on the EID list, and generates an encrypted package based on all the profile files to be installed, including: Determining the candidate Profile file of the first EID that matches the second EID as the Profile file to be installed; The data preparation server serially concatenates and encodes the plurality of Profile files to be installed into the encrypted package.
5. The method for writing Profile data of an eSIM terminal according to claim 4, characterized in that: Send the encrypted package to the Profile installation assistant, include, The Profile installation assistant calls the API interface and sends the transaction ID to the data preparation server; The data preparation server sends the corresponding encrypted package to the Profile installation assistant based on the transaction ID.
6. The method for writing Profile data of an eSIM terminal according to claim 4, characterized in that: The Profile installation assistant obtains the Profile file to be installed based on the encrypted package, determines a corresponding target Profile file from a plurality of Profile files to be installed based on the second EID of any of the eSIM terminals, and writes the Profile data of the target Profile file into the corresponding eSIM terminal, including: The Profile installation assistant decodes the encrypted package to obtain a plurality of Profile files to be installed; The Profile installation assistant determines the second EID of any of the eSIM terminals as a target EID, and determines the Profile file to be installed of the target EID as the target Profile file; The Profile installation assistant sends the target Profile file to the eSIM chip of the corresponding eSIM terminal, and installs the Profile data of the target Profile file through the eSIM chip.
7. The method for writing Profile data of an eSIM terminal according to claim 6, characterized in that: The eSIM chip is pre-installed with a Profile template, the Profile data includes network access authentication data, and the Profile data of the target Profile file installed through the eSIM chip includes: The Profile installation assistant converts the target Profile file into an APDU instruction and sends the APDU instruction to the eSIM terminal; The eSIM terminal obtains the target Profile file based on the APDU instruction; The eSIM terminal decrypts the temporary session key ciphertext data of the target Profile file based on the asymmetric algorithm to obtain the temporary session key, and decrypts the Profile encrypted data of the target Profile file based on the temporary session key to obtain the target Profile data; Based on the Profile template, the network access authentication data of the target Profile data is written into the eSIM chip.
8. A profile data writing device, characterized in that: It includes at least one control processor and a memory for communicating with the at least one control processor; the memory stores instructions that can be executed by the at least one control processor, and the instructions are executed by the at least one control processor so that the at least one control processor can execute the Profile data writing method as described in any one of claims 1 to 7.