Profile information management method and device, electronic equipment and storage medium
By obtaining the LPA certificate carrying device information from eSIM and launching a Profile download request to the operator based on the certificate, the problem that the operator cannot direct the management of the Profile download link is solved, and the directional transmission and information management of the Profile download address are realized.
Patent Information
- Application Number
- CN202510202325.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-16
AI Technical Summary
In the prior art, operators cannot issue a directional link to users, resulting in difficulty in managing the Profile because it is impossible to determine the user and device that actually downloads the Profile.
By obtaining the LPA certificate from the embedded user identity card eSIM, the certificate carries the device information of the electronic device, initiates a Profile download request to the target operator based on the LPA certificate, and after the operator passes verification, it generates the Profile download address corresponding to the device information and returns.
Ensure that the electronic devices requesting Profile are trustworthy. Only electronic devices that provide legal LPA certificates can obtain the corresponding Profile download address, realizing the directional transmission of the Profile download address, and facilitates operators' management of Profile information.
Smart Images

Figure CN120018108A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of embedded Subscriber Identity Module (eSIM), and in particular to a Profile information management method, device, electronic device and storage medium. Background Art
[0002] eSIM technology has gradually been widely used in mobile communication devices. eSIM allows users to directly download and switch operator profiles through remote configuration without having to replace the physical SIM card.
[0003] In the related art, the operator provides the user with a QR code for downloading the Profile. The user scans the QR code to obtain the download link of the Profile, and uses the download link to obtain the Profile. After the Profile is downloaded and activated, the user's eSIM can use the services provided by the operator.
[0004] However, the QR code provided by the operator to the user can be spread freely, and any eSIM can download the QR code at will, resulting in the operator being unable to issue Profile download links to users in a targeted manner. This will lead to the problem of difficult Profile management because the operator cannot determine the users and devices that actually download the Profile. Summary of the invention
[0005] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides a Profile information management method, device, electronic device and storage medium.
[0006] In a first aspect, an embodiment of the present disclosure provides a profile information management method, which is applied to a local configuration assistant (LPA) of an electronic device, including:
[0007] Obtaining an LPA certificate from an embedded user identity card eSIM, where the LPA certificate carries device information of the electronic device;
[0008] Initiating a Profile download request to a target operator based on the LPA certificate, wherein the target operator, in response to the Profile download request, verifies the LPA certificate, generates a Profile download address corresponding to the device information, and returns the address to the LPA;
[0009] In response to receiving the Profile download address, a request is made to download the Profile from a download server of the target operator based on the Profile download address.
[0010] In a second aspect, an embodiment of the present disclosure provides a profile information management device, which is applied to a local configuration assistant LPA of an electronic device, including:
[0011] A certificate acquisition module, used to obtain an LPA certificate from an embedded user identity card eSIM, wherein the LPA certificate carries device information of the electronic device;
[0012] A first request module, configured to initiate a Profile download request to a target operator based on the LPA certificate, wherein the target operator, in response to the Profile download request, verifies the LPA certificate, generates a Profile download address corresponding to the device information, and returns the address to the LPA;
[0013] The second request module is configured to, in response to receiving the Profile download address, request the download server of the target operator to download the Profile based on the Profile download address.
[0014] In a third aspect, an embodiment of the present disclosure provides an electronic device, comprising: a processor; a memory for storing executable instructions of the processor; the processor is used to read the executable instructions from the memory and execute the executable instructions to implement the Profile information management method as described in the first aspect.
[0015] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program is used to implement the Profile information management method as described in the first aspect.
[0016] In a fifth aspect, an embodiment of the present disclosure provides a computer program product, including a computer program / instructions, which, when executed by a processor, implements the Profile information management method as described in the first aspect.
[0017] Compared with the prior art, the technical solution provided by the embodiments of the present disclosure has the following advantages:
[0018] The profile information management scheme provided by the embodiment of the present disclosure obtains the LPA certificate from the embedded user identity card eSIM, and the LPA certificate carries the device information of the electronic device; based on the LPA certificate, a profile download request is initiated to the target operator, wherein the target operator responds to the profile download request, verifies the LPA certificate, generates a profile download address corresponding to the device information, and returns it to the LPA; in response to receiving the profile download address, a profile download is requested from the download server of the target operator based on the profile download address. Using the scheme of the present disclosure, the LPA obtains the LPA certificate carrying the device information of the electronic device from the eSIM through the LPA, and initiates a profile download request to the target operator based on the LPA certificate. The target operator verifies the LPA certificate, generates a profile download address corresponding to the device information, and returns it to the LPA, thereby ensuring that the electronic device requesting the profile is credible, so that only the electronic device that provides a legitimate LPA certificate can obtain the corresponding profile download address, realizing the directional transmission of the profile download address, and facilitating the operator's management of the profile information. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and the originals and elements are not necessarily drawn to scale.
[0020] Figure 1 A flowchart of a Profile information management method provided by an exemplary embodiment of the present disclosure;
[0021] Figure 2 A flowchart of a Profile information management method provided by another exemplary embodiment of the present disclosure;
[0022] Figure 3 A schematic diagram showing the structure of LPA and other interactive objects according to an exemplary embodiment of the present disclosure is shown;
[0023] Figure 4 A schematic diagram showing an interaction process of a Profile information management method according to a specific embodiment of the present disclosure is shown;
[0024] Figure 5 A schematic diagram of the structure of a Profile information management device provided in one embodiment of the present disclosure. DETAILED DESCRIPTION
[0025] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein, which are instead provided for a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.
[0026] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0027] The term "including" and its variations used herein are open inclusions, i.e., "including but not limited to". The term "based on" means "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.
[0028] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0029] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".
[0030] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0031] eSIM technology has gradually been widely used in mobile communication devices. The core components of this technology include:
[0032] (1) Local Profile Assistant (LPA)
[0033] LPA is an application or service running on the user's electronic device, responsible for communicating with the operator's download server to download, install and manage the eSIM Profile.
[0034] (2)DP+ Server
[0035] That is, the operator's download server provides eSIM Profile data and sends it to the user's electronic device through the network.
[0036] (3) eSIM
[0037] Embedded SIM replaces the traditional physical SIM card and can access different operator services by changing the profile.
[0038] (4) Profile QR code
[0039] The operator releases a QR code for LPA to download the Profile to the user. LPA requests the Profile from the DP+ server based on the plain text data of the QR code (the download address of the Profile).
[0040] (5) Profile
[0041] The configuration file in the eSIM contains some necessary files and information, such as identity information, network information, service configuration, etc., so that electronic devices can connect to the mobile network.
[0042] (6) Embedded Universal Integrated Circuit Card (eUICC) certificate
[0043] The eUICC certificate is issued by the eSIM manufacturer (EUM), and the private key of the eUICC certificate is stored in the security domain of the eUICC (i.e., eSIM). Certificate chain: The Global System for Mobile communications Association (GSMA) company registration certificate (Certificate of Incorporation, CI) issues the EUM certificate, and the private key of the EUM certificate issues the eUICC certificate. The certificate chain ensures that the eUICC certificate is trustworthy.
[0044] The process of users downloading and switching operator profiles includes: users provide personal information to operators and select appropriate services; operators generate a profile download link based on the information provided by users and provide it to users for download in the form of a QR code; users use the camera of their electronic device to scan the QR code to obtain the profile download information, initiate a profile download request to the DP+ server through the LPA in the electronic device, and start downloading the profile. After the profile is downloaded and activated, the user's eSIM can use the services provided by the operator.
[0045] From the above description, it can be seen that in the existing scheme, when operators issue QR codes, they do not go through any protection, and they do not check the device information of the electronic device requesting to download the Profile. As long as the QR code is obtained, it can be scanned and downloaded on other legitimate devices immediately, resulting in the QR code obtained by the user being stolen and downloaded, and the user cannot download it, causing losses to the user. On the other hand, this situation will also lead to the problem of irregular information management, and personal information and Profile information will not match, leading to the rampant telecommunications fraud.
[0046] In response to the above problems, the present disclosure provides a Profile information management solution, which aims to solve the problem of lack of information management and information authentication mechanism faced by LPA in the prior art when receiving eSIM Profile download link data issued by the operator. In this solution, the LPA in the electronic device requests the LPA certificate from the eSIM. The LPA certificate carries the device information of the electronic device. The private key of the LPA certificate is generated and securely stored by the eUICC security domain and will not be exported to the outside, ensuring security; the public key of the LPA certificate is included in the certificate and returned to the LPA as the key material for subsequent information authentication; the LPA submits the LPA certificate and other service information through the network or other transmission means, and initiates a Profile download link application to the operator. The operator records the LPA certificate, generates a Profile bound to the device information, and returns the Profile download link to the LPA, so that the LPA can download its own Profile based on the Profile download link. Therefore, the LPA certificate is issued by the eUICC certificate in the eSIM through the device information of the electronic device, thereby ensuring that the electronic device is trustworthy, manageable, and one-to-one corresponding to the electronic device, optimizing information authentication and management; the LPA certificate is securely issued in the eUICC of the device, eliminating the risk of leakage of the private key during transmission and storage.
[0047] The following is a detailed explanation of the Profile information management method, device, electronic device and storage medium provided by the present disclosure in conjunction with the accompanying drawings.
[0048] Figure 1 This is a flow chart of a Profile information management method provided for an exemplary embodiment of the present disclosure. The method can be executed by a Profile information management device provided for an embodiment of the present disclosure. The device can be implemented by software and / or hardware and can be integrated in an electronic device. The electronic device is a device that supports eSIM, including but not limited to mobile phones, smart watches, etc.
[0049] like Figure 1 As shown, the Profile information management method may include the following steps:
[0050] Step 101: Obtain an LPA certificate from an embedded user identity card eSIM, where the LPA certificate carries device information of the electronic device.
[0051] Among them, the device information of the electronic device can uniquely identify the electronic device. For example, the device information of the electronic device can be but is not limited to at least one of the unique identity information such as the International Mobile Equipment Identity (IMEI) and the electronic identity (eID).
[0052] When a user wants to download or switch the operator's profile, he needs to initiate a profile download application to the operator to be downloaded or switched through LPA. In this embodiment, before initiating the profile download application, LPA first obtains the LPA certificate from eSIM. The LPA certificate is a digital certificate issued by eSIM for LPA, which is used to ensure that LPA is credible. The LPA certificate is generated by eSIM by digitally signing the device information of the electronic device and carries the device information of the electronic device.
[0053] As an example, when a user wants to download or switch the operator's profile, the user can trigger the operator profile download instruction through the LPA in the electronic device. In response to the operator profile download instruction, the LPA applies for an LPA certificate from the eSIM in the electronic device and receives the LPA certificate returned by the eSIM.
[0054] In an optional implementation of the present disclosure, when LPA obtains LPA certificate from eSIM, it may send LPA certificate acquisition request to eSIM, wherein the LPA certificate acquisition request carries the device information of the electronic device. After receiving the LPA certificate acquisition request sent by LPA, eSIM responds to the LPA certificate acquisition request to detect whether there is LPA certificate in the security domain, wherein the security domain of eSIM is the most critical security element in eSIM, and the management of card content by entities outside the card is controlled by setting security domain permissions, and the identity of entities outside the card is authenticated by setting security domain keys. If LPA certificate already exists in the security domain, the LPA certificate is obtained from the security domain and sent to LPA; if LPA certificate does not exist in the security domain of eSIM, the device information is digitally signed using the eUICC certificate to generate LPA certificate and sent to LPA, the private key of LPA certificate is stored in the security domain, and the public key of LPA certificate and the public key of eUICC certificate are transmitted with LPA certificate for subsequent signature verification. For example, based on the eUICC certificate, the eSIM can use the private key of the eUICC certificate to digitally sign the device information of the electronic device and generate an LPA certificate. Specifically, the eSIM can use the private key of the eUICC certificate to encrypt the device information, the public key of the eUICC certificate, and the summary of the LPA public key to obtain the signature data, thereby obtaining the LPA certificate. The eSIM returns the issued LPA certificate to the LPA, and then the LPA can obtain the LPA certificate returned by the eSIM. In addition, the LPA certificate issued by the eSIM is also stored in its own security domain. When the LPA of the electronic device requests the LPA certificate from the eSIM in the future, the eSIM can directly obtain the LPA certificate from the security domain and send it to the LPA, without the need to issue a new LPA certificate again.
[0055] Step 102: Initiate a Profile download request to the target operator based on the LPA certificate, wherein the target operator responds to the Profile download request, verifies the LPA certificate, generates a Profile download address corresponding to the device information, and returns it to the LPA.
[0056] In this embodiment, after the LPA obtains the LPA certificate, it can initiate a Profile download request to the target operator based on the LPA certificate. For example, the LPA can submit the LPA certificate and other service information through the network or other transmission means, and initiate a Profile download request to the target operator to initiate a Profile download link application.
[0057] The target operator is the operator from which the user wishes to apply for services. After receiving the Profile download request sent by the LPA, the target operator verifies the LPA certificate in response to the Profile download request, generates a Profile download address corresponding to the device information after the verification is passed, and then returns the Profile download address to the LPA. The Profile download address is used by the LPA to download the corresponding Profile.
[0058] It can be understood that the LPA certificate carries the public key of the eUICC certificate, and the public key is used to verify the LPA certificate. Specifically, assuming that the LPA certificate is the signature data obtained by encrypting the device information, the public key of the eUICC certificate, and the summary information of the LPA public key using the private key of the eUICC certificate, the signature data is decrypted using the public key of the eUICC certificate to obtain decrypted data, and the decrypted data includes the device information, the public key of the eUICC certificate, and the summary of the LPA public key. The summary generated by the hash algorithm is compared with the decrypted summary. If they are consistent, it is determined that the LPA certificate is issued by the eSIM, and the LPA certificate verification is successful.
[0059] Step 103: In response to receiving the Profile download address, a request is made to download the Profile from a download server of the target operator based on the Profile download address.
[0060] In this embodiment, after receiving the Profile download address from the target operator, the LPA can request to download the Profile from the download server of the target operator based on the Profile download address, thereby obtaining the required Profile. After the Profile is downloaded and activated, the user's eSIM can use the services provided by the target operator.
[0061] In addition, in an optional implementation of the present disclosure, after receiving the Profile download address sent by the target operator, the LPA may not download the Profile temporarily, but save the received Profile download address in a local storage space first, and then download it when needed.
[0062] It can be understood that in this embodiment, the Profile download address returned by the target operator can exist in the form of a code map (such as a QR code, barcode, etc.), or in the form of a web link, or in other forms, and the present disclosure does not limit this. In the scenario where the Profile download address exists in the form of a code map, when the LPA needs to download the Profile, it can call the camera of the electronic device to scan the code map to obtain the Profile download address, and then use the Profile download address to request the Profile from the download server.
[0063] The profile information management method provided by the embodiment of the present disclosure obtains the LPA certificate from the embedded user identity card eSIM, and the LPA certificate carries the device information of the electronic device; based on the LPA certificate, a profile download request is initiated to the target operator, wherein the target operator responds to the profile download request, verifies the LPA certificate, generates a profile download address corresponding to the device information, and returns it to the LPA; in response to receiving the profile download address, based on the profile download address, a download server of the target operator is requested to download the profile. Using the scheme of the present disclosure, the LPA obtains the LPA certificate carrying the device information of the electronic device from the eSIM through the LPA, and initiates a profile download request to the target operator based on the LPA certificate. The target operator verifies the LPA certificate, generates a profile download address corresponding to the device information, and returns it to the LPA, thereby ensuring that the electronic device requesting the profile download address is credible, so that only the electronic device that provides a legitimate LPA certificate can obtain the corresponding profile download address, realizing the directional transmission of the profile download address, and facilitating the operator's management of profile information.
[0064] In an optional implementation of the present disclosure, after the target operator generates the Profile download address corresponding to the device information, the received LPA certificate can also be associated with the generated Profile download address and stored in the download server, so that after the LPA requests the download server to download the Profile, the download server can determine the associated LPA certificate based on the Profile download address, and then use the LPA certificate to verify the signature before providing the Profile to the LPA, thereby ensuring that the electronic device downloading the Profile is trustworthy and ensuring the security of the Profile download.
[0065] Currently, in the related technology, there is a lack of effective protection measures for the Profile download address sent by the operator to the LPA. If the Profile download address is monitored during the transmission process, there is a risk of the Profile being stolen and downloaded. Based on this, in an optional implementation of the present disclosure, before the LPA triggers the download of the Profile, the Profile download address and download timestamp are first transmitted to the eSIM. The eSIM uses the private key of the LPA certificate to digitally sign the Profile download address and download timestamp, and returns the signature data to the LPA. The LPA generates a real download link based on the Profile download address, download timestamp, and signature data, and requests the download server to perform the Profile download process. After the download server verifies the validity of the information, it starts the real Profile download process. Specifically, if Figure 2 As shown, based on the above embodiment, step 103 may include the following sub-steps:
[0066] Step 201, in response to receiving the Profile download address, obtain the current time as the download timestamp.
[0067] In this embodiment, after the LPA receives the Profile download address, if the Profile needs to be downloaded immediately, the current time may be obtained as the download timestamp.
[0068] It is understandable that if the LPA receives the Profile download address and saves it first without downloading the Profile temporarily, it does not need to obtain the current time, and only needs to obtain the current time as the download timestamp when the Profile download is triggered later. The current time is the system time of the electronic device when the Profile download is triggered.
[0069] Step 202: Request a digital signature from the eSIM based on the Profile download address and download timestamp, and obtain the target signature data returned by the eSIM.
[0070] In this embodiment, after LPA obtains the download timestamp, it sends the download timestamp and Profile download address to eSIM to request a digital signature. After eSIM receives the download timestamp and Profile download address sent by LPA, it uses the private key of the LPA certificate stored in the security domain to digitally sign the Profile download address and download timestamp. The data generated by the signature is the target signature data, and the target signature data is returned to LPA. LPA can obtain the target signature data returned by eSIM.
[0071] Step 203: Generate a target download request based on the Profile download address, download timestamp and target signature data.
[0072] In this embodiment, after the LPA receives the target signature data returned by the eSIM, it can generate a target download request based on the target signature data, download timestamp and Profile download address, and the target download request carries the target signature data, download timestamp and Profile download address.
[0073] As an example, LPA can sequentially concatenate the Profile download address, download timestamp, and target signature data to obtain a target download request. For example, the target download request can be expressed as (Profile download address, download timestamp, target signature data).
[0074] Step 204: Request the download server of the target operator to download the Profile based on the target download request.
[0075] In this embodiment, after the LPA generates a target download request, it can request the download server of the target operator to download the Profile based on the target download request. After receiving the target download request, the download server can obtain the Profile download address, download timestamp and target signature data from the target download request, and determine the associated target LPA certificate based on the Profile download address, wherein the association relationship between the LPA certificate and the Profile download address is associated and stored by the operator to the download server when generating the Profile download address. After the download server determines the target LPA certificate, it obtains the public key of the LPA certificate (i.e., the target LPA certificate) from the target LPA certificate (including the public key of the eUICC certificate that issued the target LPA certificate and the public key of the target LPA certificate itself), and uses the public key to verify the target signature data. When the target signature data is verified by the public key and the download timestamp is determined to be valid (for example, the time interval between the download timestamp and the current time of the download server is less than the preset duration), the Profile download process is started to start downloading the Profile under the Profile download address.
[0076] The Profile information management method of this embodiment, in response to receiving the Profile download address, obtains the current time as the download timestamp, requests a digital signature from the eSIM based on the Profile download address and the download timestamp, obtains the target signature data returned by the eSIM, generates a target download request based on the Profile download address, the download timestamp and the target signature data, and then requests to download the Profile from the download server of the target operator based on the target download request, thereby realizing identity authentication when the LPA requests the Profile from the download server, thereby realizing dual authentication when requesting the Profile download address from the operator and when requesting the Profile from the download server, protecting the security of the Profile information, and realizing standardized management of the Profile information, so that even if the Profile download address is monitored, other devices cannot obtain the Profile through the Profile download address, reducing the probability of the Profile being stolen and downloaded.
[0077] Figure 3 FIG. 4 shows a schematic diagram of the structure of LPA and other interactive objects according to an exemplary embodiment of the present disclosure. Figure 3 As shown, the electronic device includes LPA and eSIM, wherein the secure authentication interaction between LPA and eSIM is guaranteed by the industry-disclosed Open Mobile Alliance (OMA) standard or Telephony method to ensure that LPA is not forged by a third party. The interaction between LPA and the operator and the download server (DP+ server, referred to as DP+) is protected by Hypertext Transfer Protocol Secure (HTTPS) and other methods.
[0078] Figure 4 A schematic diagram of the interaction process of a Profile information management method according to a specific embodiment of the present disclosure is shown. Figure 4 As shown, the interaction process includes the following steps:
[0079] 1. Before applying to download the Profile, LPA transmits IMEI and other device information to eSIM and requests to generate an LPA certificate;
[0080] 2. eSIM uses the eUICC certificate to digitally sign the device information and issue the LPA certificate. The private key of the LPA certificate is stored in the security domain.
[0081] 3. LPA requests LPA certificate from eSIM;
[0082] 4. eSIM returns the LPA certificate to LPA;
[0083] 5. LPA applies to the operator to download the Profile, submits the LPA certificate and other necessary information specified by the operator, and requests the Profile download address;
[0084] 6. After the operator conducts a legality check on the LPA certificate and other information submitted by the LPA, it generates a Profile and Profile download address corresponding to the device information;
[0085] 7. The operator puts the LPA certificate and its corresponding Profile download address at DP+, so that DP+ can obtain the LPA certificate through the Profile download address;
[0086] 8. The operator returns the Profile download address (denoted as L) to the LPA;
[0087] 9. LPA sends L and download timestamp (represented as T) to eSIM and requests signature data;
[0088] 10. The eSIM signs L and T using the private key of the LPA certificate and returns the signature data (denoted as S) to the LPA.
[0089] 11. After LPA obtains S, it concatenates L, T, and S to obtain the real download link (denoted as M);
[0090] 12. LPA uses M to request the DP+ server to download the Profile;
[0091] 13. DP+ obtains L, T, and S from M, uses L to find its corresponding LPA certificate, uses the found LPA certificate to verify the signature of S, checks the validity of S, and uses T to check the timeliness;
[0092] 14. When DP+ verifies that both S and T are valid, it responds to LPA's request and starts the Profile download process.
[0093] This solution verifies the validity of the LPA certificate before the operator sends the Profile download link data, and the download server verifies the validity of the Profile download address and download timestamp before starting the Profile download process. This achieves dual authentication and can improve the security of Profile information.
[0094] In order to implement the above embodiment, the present disclosure also provides a Profile information management device, which is applied to a local configuration assistant LPA of an electronic device.
[0095] Figure 5This is a schematic diagram of the structure of a Profile information management device provided in an embodiment of the present disclosure. The device is implemented in software and / or hardware and can be integrated in an electronic device.
[0096] like Figure 5 As shown, the Profile information management device 30 may include: a certificate acquisition module 310 , a first request module 320 and a second request module 330 .
[0097] The certificate acquisition module 310 is used to obtain an LPA certificate from an embedded user identity card eSIM, where the LPA certificate carries device information of the electronic device;
[0098] The first request module 320 is used to initiate a Profile download request to the target operator based on the LPA certificate, wherein the target operator responds to the Profile download request, verifies the LPA certificate, generates a Profile download address corresponding to the device information, and returns it to the LPA;
[0099] The second request module 330 is configured to, in response to receiving the Profile download address, request the download server of the target operator to download the Profile based on the Profile download address.
[0100] Optionally, the certificate acquisition module 310 is further configured to:
[0101] Send an LPA certificate acquisition request to the eSIM, where the LPA certificate acquisition request carries the device information of the electronic device. In response to the LPA certificate acquisition request, the eSIM detects whether there is an LPA certificate in the security domain. If so, the LPA certificate is sent to the LPA. If not, the device information is digitally signed using the eUICC certificate to generate an LPA certificate and the LPA certificate is sent to the LPA. The private key of the LPA certificate is stored in the security domain.
[0102] Get the LPA certificate returned by the eSIM.
[0103] Optionally, after generating the Profile download address, the target operator further associates the LPA certificate with the Profile download address and stores it in the download server.
[0104] Further optionally, the second request module 330 includes:
[0105] A time acquisition unit, configured to acquire the current time as a download timestamp in response to receiving the Profile download address;
[0106] A signature acquisition unit, used to request a digital signature from the eSIM based on the Profile download address and download timestamp, and obtain the target signature data returned by the eSIM;
[0107] A generating unit, used for generating a target download request based on the Profile download address, the download timestamp and the target signature data;
[0108] The download request unit is used to request the download server of the target operator to download the Profile based on the target download request.
[0109] Optionally, the eSIM uses the private key of the LPA certificate stored in the security domain to digitally sign the Profile download address and download timestamp to generate target signature data;
[0110] After receiving the target download request, the download server obtains the Profile download address, download timestamp and target signature data from the target download request, and determines the associated target LPA certificate based on the Profile download address. When the target signature data is verified using the public key of the LPA certificate in the target LPA certificate and the download timestamp is determined to be valid, the Profile download process is started.
[0111] Optionally, the generating unit is further configured to:
[0112] The Profile download address, download timestamp and target signature data are concatenated in sequence to obtain the target download request.
[0113] The profile information management device for LPA applied to electronic devices provided in the embodiments of the present disclosure can execute the profile information management method provided in the embodiments of the present disclosure, and has the corresponding functional modules and beneficial effects of the execution method. The contents not described in detail in the embodiments of the present disclosure device can refer to the description in any method embodiment of the present disclosure.
[0114] The embodiments of the present disclosure also provide a computer program product, including a computer program / instruction, which, when executed by a processor, implements the Profile information management method provided by any embodiment of the present disclosure.
[0115] According to one or more embodiments of the present disclosure, the present disclosure provides an electronic device, including:
[0116] processor;
[0117] a memory for storing instructions executable by the processor;
[0118] The processor is used to read the executable instructions from the memory and execute the executable instructions to implement the Profile information management method provided in any embodiment of the present disclosure.
[0119] According to one or more embodiments of the present disclosure, the present disclosure provides a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program is used to implement the Profile information management method provided by any embodiment of the present disclosure.
[0120] It should be noted that the computer-readable medium disclosed above may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, device or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. This propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The computer readable signal medium may also be any computer readable medium other than a computer readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0121] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0122] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0123] The units involved in the embodiments described in the present disclosure may be implemented by software or hardware, wherein the name of a unit does not, in some cases, limit the unit itself.
[0124] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0125] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0126] The above description is only a preferred embodiment of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosed concept. For example, the above features are replaced with the technical features with similar functions disclosed in the present disclosure (but not limited to) by each other to form a technical solution.
[0127] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0128] Although the subject matter has been described in language specific to structural features and / or methodological logical actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. On the contrary, the specific features and actions described above are merely example forms of implementing the claims.
Claims
1. A Profile information management method, characterized in that: A local configuration assistant LPA is applied to an electronic device, the method comprising: Obtaining an LPA certificate from an embedded user identity card eSIM, where the LPA certificate carries device information of the electronic device; Initiating a Profile download request to a target operator based on the LPA certificate, wherein the target operator, in response to the Profile download request, verifies the LPA certificate, generates a Profile download address corresponding to the device information, and returns the address to the LPA; In response to receiving the Profile download address, a request is made to download the Profile from a download server of the target operator based on the Profile download address.
2. The method according to claim 1, characterized in that The obtaining of the LPA certificate from the embedded user identity card eSIM includes: Sending an LPA certificate acquisition request to the eSIM, wherein the LPA certificate acquisition request carries the device information of the electronic device, and the eSIM responds to the LPA certificate acquisition request, detecting whether there is an LPA certificate in the security domain, and if so, sending the LPA certificate to the LPA; if not, using the eUICC certificate to digitally sign the device information to generate an LPA certificate and sending it to the LPA, and the private key of the LPA certificate is stored in the security domain; Obtain the LPA certificate returned by the eSIM.
3. The method according to claim 1, characterized in that After generating the Profile download address, the target operator also associates the LPA certificate with the Profile download address and stores them in the download server.
4. The method according to claim 3, characterized in that In response to receiving the Profile download address, requesting the download server of the target operator to download the Profile based on the Profile download address, comprises: In response to receiving the Profile download address, obtaining a current time as a download timestamp; Requesting a digital signature from the eSIM based on the Profile download address and the download timestamp, and obtaining target signature data returned by the eSIM; Generate a target download request based on the Profile download address, the download timestamp and the target signature data; Based on the target download request, a download server of the target operator is requested to download the Profile.
5. The method according to claim 4, characterized in that The eSIM uses the private key of the LPA certificate stored in the security domain to digitally sign the Profile download address and the download timestamp to generate target signature data; After receiving the target download request, the download server obtains the Profile download address, the download timestamp and the target signature data from the target download request, and determines the associated target LPA certificate based on the Profile download address. When the target signature data is verified using the public key of the LPA certificate in the target LPA certificate and it is determined that the download timestamp is valid, the Profile download process is started.
6. The method according to claim 4, characterized in that The generating a target download request based on the Profile download address, the download timestamp and the target signature data includes: The Profile download address, the download timestamp and the target signature data are sequentially concatenated to obtain the target download request.
7. A Profile information management device, characterized in that: A local configuration assistant LPA applied to an electronic device, the device comprising: A certificate acquisition module, used to obtain an LPA certificate from an embedded user identity card eSIM, wherein the LPA certificate carries device information of the electronic device; A first request module, configured to initiate a Profile download request to a target operator based on the LPA certificate, wherein the target operator, in response to the Profile download request, verifies the LPA certificate, generates a Profile download address corresponding to the device information, and returns the address to the LPA; The second request module is configured to, in response to receiving the Profile download address, request the download server of the target operator to download the Profile based on the Profile download address.
8. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is used to read the executable instructions from the memory and execute the executable instructions to implement the Profile information management method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and the computer program is used to implement the Profile information management method according to any one of claims 1 to 6.
10. A computer program product, characterized in that It includes a computer program / instruction, which, when executed by a processor, implements the Profile information management method as described in any one of claims 1 to 6.