Download link processing method and device, electronic equipment and storage medium

By using public key encryption and private key decryption in LPA, the problem of insufficient security of the Profile download link provided by the operator is solved, and the secure transmission and decryption of the Profile download address is realized, which improves the overall security and reliability.

CN120018111APending Publication Date: 2025-05-16BEIJING TSINGTENG MICROSYSTEM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510202401.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the prior art, the QR code provided by operators to users lacks effective protection means, resulting in the download link of the Profile that can be attacked and stolen, posing a greater security risk.

Method used

The Profile download address plaintext is encrypted by using the public key of the local configuration assistant LPA, and the Profile download address ciphertext is generated, and then it is securely sent to the LPA, decrypted in a secure environment through the LPA's private key, and then download the Profile from the download server.

Benefits of technology

It realizes encrypted transmission of the Profile download address, improves the security and reliability of the download link, and eliminates the risk of private key leakage in transmission and storage by storing the LPA private key in a secure environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120018111A_ABST
    Figure CN120018111A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a downloading link processing method and device, electronic equipment and a storage medium, and the method comprises the steps: responding to a received operator Profile downloading instruction, obtaining a target coding graph, the target coding graph carries a Profile downloading address ciphertext, and the Profile downloading address ciphertext is obtained by encrypting a Profile downloading address plaintext through an LPA public key provided based on LPA; scanning the target coding graph to obtain a Profile downloading address ciphertext; the Profile downloading address ciphertext is sent to a security environment of the electronic equipment for decryption so as to obtain a Profile downloading address plaintext, an LPA key pair is stored in the security environment, and the LPA key pair comprises an LPA public key and a corresponding LPA private key; and initiating a Profile downloading request to a downloading server of the target operator based on the Profile downloading address plaintext so as to download the Profile. By adopting the technical scheme, encrypted transmission of the Profile downloading address is realized, and the security and reliability of the Profile downloading address are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of embedded Subscriber Identity Module (eSIM), and in particular to a download link processing method, device, electronic device and storage medium. Background Art

[0002] eSIM technology has gradually been widely used in mobile communication devices. eSIM allows users to directly download and switch operator profiles through remote configuration without having to replace the physical SIM card.

[0003] In the related art, the operator provides the user with a QR code for downloading the Profile. The user scans the QR code to obtain the download link of the Profile, and uses the download link to obtain the Profile. After the Profile is downloaded and activated, the user's eSIM can use the services provided by the operator.

[0004] However, the QR codes provided by operators to users lack effective protection measures, resulting in the download link of the Profile being attacked and stolen, posing a major security risk. Summary of the invention

[0005] In order to solve the above technical problem or at least partially solve the above technical problem, the present disclosure provides a download link processing method, device, electronic device and storage medium.

[0006] In a first aspect, an embodiment of the present disclosure provides a method for processing a download link, which is applied to a local configuration assistant (LPA) of an electronic device, including:

[0007] In response to receiving the operator Profile download instruction, obtaining a target code map, the target code map carrying a Profile download address ciphertext, the Profile download address ciphertext being obtained by encrypting the Profile download address plaintext based on the LPA public key provided by the LPA;

[0008] Scan the target code map to obtain the Profile download address ciphertext;

[0009] Sending the Profile download address ciphertext to the security environment of the electronic device for decryption to obtain the Profile download address plaintext, wherein the security environment stores an LPA key pair, the LPA key pair including the LPA public key and the corresponding LPA private key;

[0010] A Profile download request is initiated to the download server of the target operator based on the Profile download address in plain text to download the Profile.

[0011] In a second aspect, an embodiment of the present disclosure provides a download link processing device, which is applied to a local configuration assistant LPA of an electronic device, including:

[0012] A first acquisition module, configured to acquire a target code map in response to receiving an operator Profile download instruction, wherein the target code map carries a Profile download address ciphertext, and the Profile download address ciphertext is obtained by encrypting the Profile download address plaintext based on an LPA public key provided by the LPA;

[0013] A scanning module, used for scanning the target code map to obtain the ciphertext of the Profile download address;

[0014] A second acquisition module is used to send the Profile download address ciphertext to the security environment of the electronic device for decryption to obtain the Profile download address plaintext, wherein the security environment stores an LPA key pair, and the LPA key pair includes the LPA public key and a corresponding LPA private key;

[0015] The download module is used to initiate a Profile download request to a download server of a target operator based on the Profile download address in plain text to download the Profile.

[0016] In a third aspect, an embodiment of the present disclosure provides an electronic device, comprising: a processor; a memory for storing executable instructions of the processor; the processor is used to read the executable instructions from the memory and execute the executable instructions to implement the download link processing method as described in the first aspect.

[0017] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program is used to implement the download link processing method as described in the first aspect.

[0018] In a fifth aspect, an embodiment of the present disclosure provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the method for processing a download link as described in the first aspect.

[0019] Compared with the prior art, the technical solution provided by the embodiments of the present disclosure has the following advantages:

[0020] The processing scheme for download links provided by the embodiments of the present disclosure is, in response to receiving an operator Profile download instruction, obtaining a target code map, the target code map carrying a Profile download address ciphertext, the Profile download address ciphertext being obtained by encrypting the Profile download address plaintext based on the LPA public key provided by the LPA; scanning the target code map to obtain the Profile download address ciphertext; sending the Profile download address ciphertext to a secure environment of an electronic device for decryption to obtain the Profile download address plaintext, wherein the secure environment stores an LPA key pair, the LPA key pair including an LPA public key and a corresponding LPA private key; initiating a Profile download request to a download server of a target operator based on the Profile download address plaintext to download the Profile. By adopting the scheme disclosed in the present invention, the plain text of the Profile download address is encrypted by using the LPA public key to obtain the ciphertext of the Profile download address. The ciphertext of the Profile download address obtained by the LPA is then decrypted in a secure environment to obtain the plain text of the Profile download address, and then the Profile is downloaded from the download server based on the plain text of the Profile download address, thereby realizing the encrypted transmission of the Profile download address, ensuring the security and reliability of the Profile download address, and ensuring the security of the LPA private key by storing the LPA private key in a secure environment of the electronic device, thereby eliminating the risk of leakage of the LPA private key during transmission and storage. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and the originals and elements are not necessarily drawn to scale.

[0022] Figure 1 A flowchart of a method for processing a download link provided by an exemplary embodiment of the present disclosure;

[0023] Figure 2 A flowchart of a method for processing a download link provided by another exemplary embodiment of the present disclosure;

[0024] Figure 3 A schematic diagram showing the structure of LPA and other interactive objects according to an exemplary embodiment of the present disclosure is shown;

[0025] Figure 4 A schematic diagram showing an interactive process of a method for processing a download link according to a specific embodiment of the present disclosure is shown;

[0026] Figure 5A schematic diagram of the structure of a download link processing device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0027] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein, which are instead provided for a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.

[0028] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.

[0029] The term "including" and its variations used herein are open inclusions, i.e., "including but not limited to". The term "based on" means "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0030] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0031] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0032] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0033] eSIM technology has gradually been widely used in mobile communication devices. The core components of this technology include:

[0034] (1) Local Profile Assistant (LPA)

[0035] LPA is an application or service running on the user's electronic device, responsible for communicating with the operator's download server to download, install and manage the eSIM Profile.

[0036] (2)DP+ Server

[0037] That is, the operator's download server provides eSIM Profile data and sends it to the user's electronic device through the network.

[0038] (3) eSIM

[0039] Embedded SIM replaces the traditional physical SIM card and can access different operator services by changing the profile.

[0040] (4) Profile QR code

[0041] The operator releases a QR code for LPA to download the Profile to the user. LPA requests the Profile from the DP+ server based on the plain text data of the QR code (the download address of the Profile).

[0042] (5) Profile

[0043] The configuration file in the eSIM contains some necessary files and information, such as identity information, network information, service configuration, etc., so that electronic devices can connect to the mobile network.

[0044] The process of users downloading and switching operator profiles includes: users provide personal information to operators and select appropriate services; operators generate a profile download link based on the information provided by users and provide it to users for download in the form of a QR code; users use the camera of their electronic device to scan the QR code to obtain the profile download information, initiate a profile download request to the DP+ server through the LPA in the electronic device, and start downloading the profile. After the profile is downloaded and activated, the user's eSIM can use the services provided by the operator.

[0045] From the above description, it can be seen that in the existing solution, the Profile QR code provided by the operator to the user does not provide effective protection means, resulting in the Profile download link being attacked and stolen, posing a great security risk.

[0046] In response to the above problems, the present disclosure provides a download link processing solution, which aims to solve the security and reliability problems faced by LPA in the prior art when receiving eSIM Profile download link data issued by the operator. In this solution, before the operator sends the Profile download link data, the Profile download link data is first encrypted using the public key of the LPA, and then the encrypted data is securely sent to the LPA. Through encrypted data transmission, the high security of data encryption and decryption is guaranteed. At the same time, the consumption of computing resources on the device side is small, and the original user habits can be retained. After receiving the data, the user does not need to download it immediately. When downloading, LPA will automatically decrypt it, which provides a good user experience.

[0047] The download link processing method, device, electronic device and storage medium provided by the present disclosure are explained in detail below with reference to the accompanying drawings.

[0048] Figure 1 A flow chart of a method for processing a download link provided for an exemplary embodiment of the present disclosure. The method may be executed by a device for processing a download link provided for an embodiment of the present disclosure. The device may be implemented by software and / or hardware and may be integrated in an electronic device. The electronic device is a device that supports eSIM, including but not limited to mobile phones, smart watches, etc.

[0049] like Figure 1 As shown, the download link processing method may include the following steps:

[0050] Step 101, in response to receiving an operator Profile download instruction, a target code map is obtained, the target code map carries a Profile download address ciphertext, and the Profile download address ciphertext is obtained by encrypting the Profile download address plaintext based on the LPA public key provided by the LPA.

[0051] In this embodiment, when the user wants to download or switch the operator's profile, the operator profile download instruction can be initiated through the electronic device. For example, the user can trigger the operator profile download instruction through the LPA in the electronic device. After receiving the operator profile download instruction, the LPA can obtain the target coding map.

[0052] The target code map may be a QR code, a barcode, etc. The target code map carries the encrypted ciphertext of the Profile download address. For example, the operator may use the LPA public key provided by the LPA to encrypt the Profile download address plaintext to obtain the Profile download address ciphertext, encode the Profile download address ciphertext to obtain the code map, and then return it to the LPA for the LPA to download the Profile.

[0053] Step 102, scan the target code map to obtain the Profile download address ciphertext.

[0054] In this embodiment, after the LPA obtains the target code map, it can call the camera of the electronic device to scan the target code map. By scanning the target code map, the ciphertext of the Profile download address carried in the target code map can be extracted.

[0055] Step 103: Send the ciphertext of the Profile download address to the security environment of the electronic device for decryption to obtain the plaintext of the Profile download address, wherein the LPA key pair is stored in the security environment, and the LPA key pair includes an LPA public key and a corresponding LPA private key.

[0056] In this embodiment, after the LPA scans and obtains the Profile download address ciphertext from the target coding map, the Profile download address ciphertext can be sent to the security environment in the electronic device, requesting the security environment to decrypt the Profile download address ciphertext, and returning the decrypted Profile download address plaintext to the LPA.

[0057] Among them, the secure environment stores an LPA key pair generated according to a preset encryption algorithm. The LPA key pair includes an LPA public key and an LPA private key. The LPA public key is used by the operator to encrypt the plain text of the Profile download address, and the LPA private key is stored in the secure environment and used in the secure environment to decrypt the ciphertext of the Profile download address. The secure environment can be, but is not limited to, a Trusted Execution Environment (TEE), an embedded Secure Element (eSE), an embedded Universal Integrated Circuit Card (eUICC), etc.

[0058] In this embodiment, an LPA key pair exclusive to LPA is generated by utilizing the security environment in the electronic device, and the LPA private key is securely stored in the secure environment and will not be exported to the outside, thereby ensuring the invisibility and non-extractability of the key during transmission. Data is encrypted using the LPA public key to ensure that the sent data cannot be decrypted even if it is intercepted.

[0059] Step 104: Initiate a Profile download request to the download server of the target operator based on the Profile download address in plain text to download the Profile.

[0060] In this embodiment, after the LPA obtains the plain text of the Profile download address returned by the security environment, it can use the plain text of the Profile download address to initiate a Profile download request to the download server of the target operator to download the Profile. After the Profile download is completed and activated, the user's eSIM can use the services provided by the operator.

[0061] The method for processing a download link provided by an embodiment of the present disclosure obtains a target code map in response to receiving a Profile download instruction from an operator, the target code map carries a Profile download address ciphertext, and the Profile download address ciphertext is obtained by encrypting the Profile download address plaintext based on the LPA public key provided by the LPA; the target code map is scanned to obtain the Profile download address ciphertext; the Profile download address ciphertext is sent to a secure environment of an electronic device for decryption to obtain the Profile download address plaintext, wherein an LPA key pair is stored in the secure environment, the LPA key pair including an LPA public key and a corresponding LPA private key; a Profile download request is initiated to a download server of a target operator based on the Profile download address plaintext to download the Profile. By adopting the scheme disclosed in the present invention, the plain text of the Profile download address is encrypted by using the LPA public key to obtain the ciphertext of the Profile download address. The ciphertext of the Profile download address obtained by the LPA is then decrypted in a secure environment to obtain the plain text of the Profile download address, and then the Profile is downloaded from the download server based on the plain text of the Profile download address, thereby realizing the encrypted transmission of the Profile download address, ensuring the security and reliability of the Profile download address, and ensuring the security of the LPA private key by storing the LPA private key in a secure environment of the electronic device, thereby eliminating the risk of leakage of the LPA private key during transmission and storage.

[0062] In an optional implementation of the present disclosure, in response to receiving the operator Profile download instruction, the LPA may first detect whether there is a coding map under the target storage path of the local storage space, and then perform corresponding subsequent operations according to whether there is a coding map. Figure 2 As shown, based on the above embodiment, step 102 may include the following sub-steps:

[0063] Step 201, in response to receiving an operator Profile download instruction, detecting whether there is a coding map under a target storage path of a local storage space.

[0064] Step 202: In response to the existence of a coding map under the target storage path, obtain the coding map as the target coding map.

[0065] The target storage path of the local storage space is only used to store the encoding map carrying the ciphertext of the Profile download address requested from the operator.

[0066] In this embodiment, when LPA receives an operator Profile download instruction, it can first detect whether there is a coding map under the target storage path of the local storage space. If it exists, it means that the Profile download address previously requested from the operator has not been used to download the Profile, and the coding map is used as the target coding map.

[0067] Optionally, in this embodiment, in order to ensure that the downloaded Profile meets the user's current needs, each time the coding map is obtained from the target storage path and the Profile is successfully downloaded, the coding map in the target storage path can be deleted, so that only the coding maps for which the Profile has not been downloaded are stored in the target storage path.

[0068] Step 203: In response to the absence of the encoding map under the target storage path, obtain the LPA public key from the secure environment.

[0069] In this embodiment, if the encoding map is not detected from the target storage path, the LPA obtains the LPA public key from the security environment of the electronic device.

[0070] In an optional implementation of the present disclosure, when LPA obtains the LPA public key from the secure environment, it may initiate an LPA public key request to the secure environment, wherein the secure environment responds to the LPA public key request, detects whether there is an LPA key pair, and if so, sends the LPA public key in the LPA key pair to LPA, and if not, generates an LPA key pair according to a preset encryption algorithm, and sends the LPA public key in the LPA key pair to LPA. Then, LPA can obtain the LPA public key sent by the secure environment.

[0071] The preset encryption algorithm may be, but is not limited to, an asymmetric encryption algorithm such as an RSA algorithm, an elliptic curve cryptography (ECC) algorithm, an Elgamal algorithm, a backpack algorithm, or the like.

[0072] That is to say, in this embodiment, the security environment only needs to generate and store the LPA key pair once. The LPA key pair is generated only when the LPA requests the LPA public key from it for the first time (at this time, the LPA key pair does not exist in the security environment). The LPA key pair is stored locally in the security environment. When the LPA requests the LPA public key each time subsequently, the LPA public key in the LPA key pair is obtained locally and sent to the LPA.

[0073] Step 204: Initiate a Profile download address request to the target operator based on the LPA public key, wherein the target operator responds to the Profile download address request, encrypts the Profile download address plaintext using the LPA public key, generates a code map carrying the Profile download address ciphertext, and sends it to the LPA.

[0074] In this embodiment, after LPA obtains the LPA public key from the secure environment, it can initiate a Profile download address request to the target operator based on the LPA public key. Among them, the target operator is the operator from which the user hopes to apply for services. The Profile download address request can carry the LPA public key and some other necessary information specified by the operator. After the target operator receives the Profile download address request, it can perform a legality check on the information submitted by LPA, and then generate the corresponding Profile and its download address (plain text), and use the LPA public key provided by LPA to encrypt the Profile download address plain text to obtain the Profile download address ciphertext, and then generate a coding map carrying the Profile download address ciphertext and send it to LPA.

[0075] Step 205: In response to receiving the codemap sent by the target operator, determine the codemap as the target codemap.

[0076] In this embodiment, after receiving the code map sent by the target operator, the LPA may determine the code map as the target code map.

[0077] In an optional implementation of the present disclosure, after receiving the coding map sent by the target operator, the LPA may also store the coding map in the target storage path.

[0078] It should be noted that, in this embodiment, after the LPA receives the coding map sent by the target operator, it can store the coding map in the target storage path while determining the coding map as the target coding map, and delete the coding map in the target storage path after successfully downloading the Profile; alternatively, the coding map can be first stored in the target storage path, and then the coding map can be obtained from the target storage path as the target coding map, and the coding map in the target storage path can be deleted after successfully downloading the Profile; alternatively, the coding map can be first determined as the target coding map, and then the coding map can be saved in the target storage path, and the coding map in the target storage path can be deleted after successfully downloading the Profile.

[0079] That is to say, in this embodiment, after LPA receives the coding map sent by the operator, it can directly obtain the Profile download address ciphertext from the target coding map and send it to the security environment of the electronic device for decryption to obtain the Profile download address plaintext, and use the Profile download address plaintext to apply for the Profile from the operator's download server. It can also temporarily not download it, only save the coding map to the target storage path, and download it when needed.

[0080] The processing method of the download link disclosed in the present invention detects whether there is a coding map under the target storage path of the local storage space in response to receiving the operator's Profile download instruction, and if so, obtains the coding map as the target coding map; if not, obtains the LPA public key from the security environment, and initiates a Profile download address request to the target operator based on the LPA public key. The target operator uses the LPA public key to encrypt the Profile download address plaintext and generates a coding map carrying the Profile download address ciphertext and sends it to the LPA. As a result, the LPA requests the security environment to generate an LPA key pair, and stores the LPA private key in the security environment, thereby ensuring the invisibility and non-extractability of the key during transmission. Data encryption is performed through the LPA public key, ensuring that the sent data cannot be decrypted even if it is intercepted.

[0081] Since there is more than one operator, the user can request the corresponding service from each operator. In order to ensure that the Profile is accurately requested from the operator, the operator Profile download instruction can carry the operator identifier of the requested operator, and the corresponding target operator is uniquely determined according to the operator identifier. Thus, in an optional implementation of the present disclosure, when the LPA detects whether there is a coding map under the target storage path of the local storage space in response to receiving the operator Profile download instruction, in response to receiving the operator Profile download instruction, the operator identifier carried by the operator Profile download instruction can be obtained, and whether there is a coding map matching the operator identifier under the target storage path of the local storage space, if there is, the coding map matching the operator identifier is obtained as the target coding map, and subsequent steps are performed. If not, the LPA obtains the LPA public key from the security environment of the electronic device, and based on the LPA public key, initiates a Profile download address request to the target operator corresponding to the operator identifier, and the target operator uses the LPA public key to encrypt the Profile download address plaintext, and generates a coding map carrying the Profile download address ciphertext and sends it to the LPA.

[0082] Figure 3 FIG. 4 shows a schematic diagram of the structure of LPA and other interactive objects according to an exemplary embodiment of the present disclosure. Figure 3As shown, the electronic device includes LPA and a secure environment, wherein the interaction security between LPA and the secure environment is guaranteed by the industry-disclosed Open Mobile Alliance (OMA) standard or the Client Application (CA)-Trusted Application (TA) method. The interaction between LPA and the operator and the download server (DP+ server, referred to as DP+) is protected by Hypertext Transfer Protocol Secure (HTTPS) and other methods.

[0083] Figure 4 A schematic diagram of an interactive process of a method for processing a download link according to a specific embodiment of the present disclosure is shown. Figure 4 As shown, the interaction process includes the following steps:

[0084] 1. Before applying to download the Profile, LPA first requests a secure environment to generate an LPA key pair;

[0085] 2. The security environment generates an asymmetric LPA key pair based on the RSA algorithm and stores it;

[0086] 3. LPA requests the LPA public key from the secure environment;

[0087] 4. The security environment returns the LPA public key to LPA;

[0088] 5. LPA applies to the operator to download the Profile, that is, requests the Profile download link, and submits the LPA public key and other necessary information specified by the operator;

[0089] 6. After the operator conducts a legality check on the information submitted by the LPA, it generates a Profile and its download link;

[0090] 7. The operator uses the LPA public key and the same RSA algorithm used in the previous security environment to encrypt the Profile download link data;

[0091] 8. The operator returns the encrypted Profile download link data to LPA;

[0092] 9. LPA sends the encrypted Profile download link data to the secure environment and requests decryption;

[0093] 10. The secure environment decrypts the encrypted Profile download link data and returns it to the LPA;

[0094] 11. After LPA obtains the decrypted Profile download link data, it uses the Profile download link to request Profile data from the DP+ server.

[0095] This solution uses the LPA's public key to encrypt the Profile download link before the operator sends the Profile download link data, and then securely sends the encrypted data to the LPA, which can improve the security of Profile download link transmission.

[0096] In order to implement the above embodiment, the present disclosure further provides a download link processing device, which is applied to a local configuration assistant LPA of an electronic device.

[0097] Figure 5 This is a schematic diagram of the structure of a download link processing device provided in an embodiment of the present disclosure. The device is implemented in software and / or hardware and can be integrated in an electronic device.

[0098] like Figure 5 As shown, the download link processing device 30 may include: a first acquisition module 310 , a scanning module 320 , a second acquisition module 330 and a download module 340 .

[0099] The first acquisition module 310 is used to obtain a target code map in response to receiving an operator profile download instruction, the target code map carries a ciphertext of a profile download address, and the ciphertext of the profile download address is obtained by encrypting the plaintext of the profile download address based on the LPA public key provided by the LPA;

[0100] Scanning module 320, used to scan the target code map to obtain the Profile download address ciphertext;

[0101] The second acquisition module 330 is used to send the Profile download address ciphertext to the security environment of the electronic device for decryption to obtain the Profile download address plaintext, wherein the security environment stores the LPA key pair, and the LPA key pair includes an LPA public key and a corresponding LPA private key;

[0102] The download module 340 is used to initiate a Profile download request to the download server of the target operator based on the Profile download address in plain text to download the Profile.

[0103] Optionally, the first acquisition module 310 includes:

[0104] A detection unit, configured to detect whether a coding map exists under a target storage path of a local storage space in response to receiving an operator Profile download instruction;

[0105] The first acquisition unit is used to acquire the encoding map as the target encoding map in response to the existence of the encoding map under the target storage path.

[0106] Further optionally, the first acquisition module 310 further includes:

[0107] A second acquisition unit, configured to acquire an LPA public key from a secure environment in response to the absence of a coding map under the target storage path;

[0108] A request unit, configured to initiate a Profile download address request to a target operator based on an LPA public key, wherein the target operator responds to the Profile download address request by encrypting the Profile download address plaintext using the LPA public key, generating a code map carrying the Profile download address ciphertext and sending it to the LPA;

[0109] The determining unit is configured to determine the code map as a target code map in response to receiving the code map sent by the target operator.

[0110] Optionally, the download link processing device 30 further includes:

[0111] The storage module is used for storing the coding map in a target storage path in response to receiving the coding map sent by the target operator.

[0112] Optionally, the second acquisition unit is further used for:

[0113] Initiate an LPA public key request to the security environment, wherein the security environment responds to the LPA public key request, detects whether there is an LPA key pair, and if so, sends the LPA public key in the LPA key pair to the LPA; if not, generates an LPA key pair according to a preset encryption algorithm, and sends the LPA public key in the LPA key pair to the LPA;

[0114] Get the LPA public key sent by the security environment.

[0115] Optionally, the detection unit is further used for:

[0116] In response to receiving the operator Profile download instruction, obtaining the operator identifier carried in the operator Profile download instruction;

[0117] Check whether there is a coding map matching the operator identifier under the target storage path of the local storage space;

[0118] The request unit is also used to:

[0119] Based on the LPA public key, a Profile download address request is initiated to the target operator corresponding to the operator identifier.

[0120] The processing device for processing the download link of the LPA applied to the electronic device provided in the embodiment of the present disclosure can execute the processing method for the download link provided in the embodiment of the present disclosure, and has the functional modules and beneficial effects corresponding to the execution method. The contents not fully described in the embodiment of the device of the present disclosure can refer to the description in any method embodiment of the present disclosure.

[0121] The embodiments of the present disclosure further provide a computer program product, including a computer program / instruction, which, when executed by a processor, implements the download link processing method provided by any embodiment of the present disclosure.

[0122] According to one or more embodiments of the present disclosure, the present disclosure provides an electronic device, including:

[0123] processor;

[0124] a memory for storing instructions executable by the processor;

[0125] The processor is used to read the executable instructions from the memory and execute the executable instructions to implement the download link processing method provided in any embodiment of the present disclosure.

[0126] According to one or more embodiments of the present disclosure, the present disclosure provides a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program is used to implement the download link processing method provided by any embodiment of the present disclosure.

[0127] It should be noted that the computer-readable medium disclosed above may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, device or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. This propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The computer readable signal medium may also be any computer readable medium other than a computer readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0128] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.

[0129] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0130] The units involved in the embodiments described in the present disclosure may be implemented by software or hardware, wherein the name of a unit does not, in some cases, limit the unit itself.

[0131] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.

[0132] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0133] The above description is only a preferred embodiment of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosed concept. For example, the above features are replaced with the technical features with similar functions disclosed in the present disclosure (but not limited to) by each other to form a technical solution.

[0134] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.

[0135] Although the subject matter has been described in language specific to structural features and / or methodological logical actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. On the contrary, the specific features and actions described above are merely example forms of implementing the claims.

Claims

1. A method for processing a download link, characterized in that: A local configuration assistant LPA is applied to an electronic device, the method comprising: In response to receiving the operator Profile download instruction, obtaining a target code map, the target code map carrying a Profile download address ciphertext, the Profile download address ciphertext being obtained by encrypting the Profile download address plaintext based on the LPA public key provided by the LPA; Scan the target code map to obtain the Profile download address ciphertext; Sending the Profile download address ciphertext to the security environment of the electronic device for decryption to obtain the Profile download address plaintext, wherein the security environment stores an LPA key pair, the LPA key pair including the LPA public key and the corresponding LPA private key; A Profile download request is initiated to the download server of the target operator based on the Profile download address in plain text to download the Profile.

2. The method according to claim 1, characterized in that The step of obtaining a target coding map in response to receiving an operator Profile download instruction includes: In response to receiving the operator Profile download instruction, detecting whether there is a coding map under the target storage path of the local storage space; In response to the existence of a coding map under the target storage path, the coding map is obtained as a target coding map.

3. The method according to claim 2, characterized in that The method further comprises: In response to the absence of a coding map under the target storage path, obtaining the LPA public key from the secure environment; Initiating a Profile download address request to the target operator based on the LPA public key, wherein the target operator, in response to the Profile download address request, encrypts the Profile download address plaintext using the LPA public key, generates a coding map carrying the Profile download address ciphertext, and sends it to the LPA; In response to receiving the codemap sent by the target operator, determining the codemap as the target codemap.

4. The method according to claim 3, characterized in that The method further comprises: In response to receiving the coding map sent by the target operator, the coding map is stored in the target storage path.

5. The method according to claim 3, characterized in that: The obtaining the LPA public key from the secure environment includes: Initiate an LPA public key request to the security environment, wherein the security environment detects whether the LPA key pair exists in response to the LPA public key request, and if so, sends the LPA public key in the LPA key pair to the LPA; if not, generate an LPA key pair according to a preset encryption algorithm, and send the LPA public key in the LPA key pair to the LPA; Obtain the LPA public key sent by the security environment.

6. The method according to claim 3, characterized in that In response to receiving the operator Profile download instruction, detecting whether there is a coding map under the target storage path of the local storage space includes: In response to receiving the operator Profile download instruction, obtaining the operator identifier carried in the operator Profile download instruction; Detecting whether there is a coding map matching the operator identifier under the target storage path of the local storage space; The initiating a Profile download address request to the target operator based on the LPA public key includes: Based on the LPA public key, a Profile download address request is initiated to the target operator corresponding to the operator identifier.

7. A download link processing device, characterized in that: A local configuration assistant LPA applied to an electronic device, the device comprising: A first acquisition module, configured to acquire a target code map in response to receiving an operator profile download instruction, wherein the target code map carries a profile download address ciphertext, and the profile download address ciphertext is obtained by encrypting the profile download address plaintext based on an LPA public key provided by the LPA; A scanning module, used for scanning the target code map to obtain the ciphertext of the Profile download address; A second acquisition module is used to send the Profile download address ciphertext to the security environment of the electronic device for decryption to obtain the Profile download address plaintext, wherein the security environment stores an LPA key pair, and the LPA key pair includes the LPA public key and a corresponding LPA private key; The download module is used to initiate a Profile download request to a download server of a target operator based on the Profile download address in plain text to download the Profile.

8. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is used to read the executable instructions from the memory and execute the executable instructions to implement the download link processing method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and the computer program is used to implement the download link processing method according to any one of claims 1 to 6.

10. A computer program product, characterized in that It comprises a computer program / instruction, and when the computer program / instruction is executed by a processor, it implements the download link processing method as described in any one of claims 1-6.