ESIM authentication method and related device
By implementing the authentication method in the eSIM module, the matching of the device identifier is detected, and the problem of the eSIM module illegally accessing the mobile communication network after being disassembled is solved, thereby improving security.
Patent Information
- Application Number
- CN202410173927.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-14
- Filing Date
- 2024-02-06
- Publication Date
- 2025-05-16
AI Technical Summary
After the eSIM module is disassembled, if inserted into other devices, it will affect the security of the mobile communication network and make it impossible to effectively prevent illegal access.
By implementing the authentication method in the eSIM module, the matching of device identification is detected, ensuring that only devices bound to the eSIM module can carry out mobile communication services normally. The specific steps include: the first processing module negotiates and shares the security key with the eSIM module, generates device binding information, and the eSIM module stores the device identification. Before powering on again or performing mobile communication services, the eSIM module verifies the matching of the device identification through the device verification information.
Effectively prevent the eSIM module from being inserted into other devices after being disassembled, improving the security of the eSIM module when it is connected to the mobile communication network.
Smart Images

Figure CN120018143A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to an eSIM authentication method and related devices. Background Art
[0002] In the field of mobile communications, one of the common mobile communication access solutions is a user identity authentication access solution based on a subscriber identity module (SIM). Its common implementation method is that the user inserts a SIM card into a SIM card slot of a mobile communication device such as a mobile phone or tablet computer, and the mobile communication device performs a legitimacy authentication at the communication service provider through the inserted SIM card. After the authentication is passed, the mobile communication device is allowed to access the mobile communication network.
[0003] With the development of mobile communication technology, the embedded SIM (eSIM) solution has been proposed in the prior art based on the SIM card solution. The eSIM solution is to embed the traditional SIM card directly into the chip of the electronic device, rather than adding it to the device as an independent removable component, and the user does not need to insert a physical SIM card. This solution will allow users to choose operators more flexibly and rewrite new numbers into the eSIM module of the electronic device.
[0004] Currently, users can write new numbers into the eSIM modules of devices such as watches on their mobile phones, so that users can use watches and other devices to make calls and access the Internet based on the eSIM modules. However, if the eSIM module is disassembled and inserted into other devices to access the mobile communication network, it will affect the security of the mobile communication network. Summary of the invention
[0005] The present application provides an eSIM authentication method and related devices, which can prevent the eSIM module in an electronic device from being inserted into other devices and accessing a mobile communication network after being disassembled, thereby improving the security of the eSIM module when accessing a mobile communication network.
[0006] In a first aspect, the present application provides an eSIM authentication method, which is applied to an eSIM module, the method comprising: the eSIM module stores a first device identifier sent by a first processing module; after the eSIM module detects a power outage and then powers on, the eSIM module receives device verification information sent by the second processing module; the eSIM module decrypts a second device identifier from the device verification information; if the first device identifier is the same as the second device identifier, the eSIM module performs mobile communication services normally; if the first device identifier is different from the second device identifier or the eSIM module does not receive the device verification information sent by the second processing module after detecting a power outage and then powers on, the eSIM module is prohibited from performing mobile communication services.
[0007] Through an eSIM authentication method provided in an embodiment of the present application, the first processing module and the eSIM module in the electronic device can be implemented to first negotiate a shared security key, and then the first processing module encrypts the device identifier through the shared security key, generates device binding information, and sends the device binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the device binding information through the shared security key pair and store the first device identifier. When the eSIM module is powered on again or before a mobile communication service is to be performed, the eSIM module can allow the second processing module that communicates with the eSIM module at this time to obtain the second device identifier, and encrypt the second device identifier through the shared security key to generate device verification information. The eSIM module can decrypt the second device identification from the device verification information through the shared security key. If the second device identification is the same as the first device identification stored in the eSIM module, it indicates that the second processing module and the first processing module bound to the eSIM module are the same processing module. Therefore, the eSIM module can normally perform mobile communication services. If the second device identification is different from the first device identification stored in the eSIM module or the eSIM module does not receive the device verification information sent by the second processing module after detecting power failure and power on, it indicates that the second processing module and the first processing module bound to the eSIM module are not the same processing module. Therefore, the eSIM module can be prohibited from performing mobile communication services. In this way, the eSIM module in the electronic device can be prevented from being inserted into other devices to access the mobile communication network after being disassembled, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0008] In a possible implementation, before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: the eSIM module receives device binding information sent by the first processing module; after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information and stores the first device identifier.
[0009] In a possible implementation, after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information, specifically including: after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information using a shared security key generated by the eSIM module.
[0010] In a possible implementation, after receiving the device verification information, the eSIM module decrypts the second device identifier from the device verification information, specifically including: after receiving the device verification information, the eSIM module decrypts the second device identifier from the verification information using a shared security key generated by the eSIM module.
[0011] In a possible implementation, before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: generating, by the eSIM module, an eUICC temporary working public key and an eUICC temporary working private key; receiving, by the eSIM module, a TEE temporary working public key generated by the first processing module; and generating, by the eSIM module, a shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
[0012] In a possible implementation, before the eSIM module receives the TEE temporary working public key sent by the first processing module, the method also includes: the eSIM module receives the TEE signature data sent by the first processing module; the eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; the eSIM module receives the TEE temporary working public key sent by the first processing module, specifically including: after the eSIM module verifies the legitimacy of the TEE signature data, obtaining the TEE temporary working public key from the TEE signature data.
[0013] In a possible implementation, before the eSIM module receives the TEE signature data sent by the first processing module, the method further includes: the eSIM module verifies the legitimacy of the TEE certificate; after the eSIM module verifies the legitimacy of the TEE certificate, obtains the TEE public key from the TEE certificate.
[0014] In one possible implementation, the TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
[0015] In one possible implementation, the TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; before the eSIM module verifies the legitimacy of the TEE certificate, the method also includes: the eSIM module receives the TEE certificate sent by the first processing module; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module uses the terminal manufacturer's root public key in the terminal manufacturer's root certificate to verify the legitimacy of the device certificate; after the eSIM module verifies the legitimacy of the device certificate, it uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
[0016] In one possible implementation, the TEE certificate is a terminal manufacturer's root certificate, which is pre-set in the eSIM module; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal manufacturer's root certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
[0017] In a possible implementation manner, the method further includes: the eSIM module generating the eUICC temporary working private key and the eUICC temporary working public key, the eUICC temporary working private key and the eUICC temporary working public key being a pair of public-private keys; the eSIM module signing the eUICC temporary working public key by using the eUICC private key to obtain eUICC signature data; the eSIM module sending the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key, and generate a shared security key based on the eUICC temporary working public key and the TEE temporary working private key, the TEE temporary working private key and the TEE temporary working public key being a pair of public-private keys.
[0018] In a possible implementation, the method further includes: the eSIM module sending the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by an EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes an eUICC public key, the eUICC public key and the eUICC private key are a pair of public-private keys, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
[0019] In one possible implementation, the first device identifier is the chip identifier of the first processing module, and the second device identifier is the chip identifier of the second processing module; or, the first device identifier is the international mobile equipment identity code IMEI of the first processing module, and the second device identifier is the IMEI of the second processing module; or, the first device identifier is the chip identifier of the first processing module and the IMEI of the first processing module, and the second device identifier is the chip identifier of the second processing module and the IMEI of the second processing module.
[0020] In a possible implementation, after the eSIM module detects power failure and power on, it receives the device verification information sent by the second processing module, which specifically includes: after the eSIM module detects power failure and power on, it sends a first request to the second processing module, and the first request is used to request the second processing module to send a device identification to the eSIM module.
[0021] In a possible implementation manner, the first request includes a first eUICC random number, and the first eUICC random number is used to be encrypted by the second processing module together with the second device identifier to form the device verification information.
[0022] In a possible implementation manner, the method further includes: decrypting, by the eSIM module, a second eUICC random number from the device verification information; if the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally, specifically including: if the first device identifier is the same as the second device identifier and the second eUICC random number is the same as the first eUIC random number, the eSIM module performs the mobile communication service normally.
[0023] In a possible implementation, the first request is a Get Input command.
[0024] In a possible implementation manner, the eSIM module receives the device binding information sent by the first processing module, specifically including: the eSIM module receives the device binding information sent by the first processing module through a store data Storedata command.
[0025] In a second aspect, the present application provides an eSIM authentication method, which is applied to an electronic device including an eSIM module and a second processing module, the method comprising: the eSIM module stores a first device identification sent by the first processing module; after the eSIM module detects a power outage and then powers on, the eSIM module sends a first request to the second processing module, the first request being used to request the second processing module to send a device identification to the eSIM module; the second processing module obtains a second device identification; the second processing module encrypts the second device identification to obtain device verification information; the second processing module sends the device verification information to the eSIM module; the eSIM module decrypts the second device identification from the device verification information; if the first device identification is the same as the second device identification, the eSIM module performs mobile communication services normally; if the first device identification is different from the second device identification or the eSIM module does not receive the device verification information sent by the second processing module after detecting a power outage and then powers on, the eSIM module is prohibited from performing mobile communication services.
[0026] Through an eSIM authentication method provided in an embodiment of the present application, the first processing module and the eSIM module in the electronic device can be implemented to first negotiate a shared security key, and then the first processing module encrypts the device identifier through the shared security key, generates device binding information, and sends the device binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the device binding information through the shared security key pair and store the first device identifier. When the eSIM module is powered on again or before a mobile communication service is to be performed, the eSIM module can allow the second processing module that communicates with the eSIM module at this time to obtain the second device identifier, and encrypt the second device identifier through the shared security key to generate device verification information. The eSIM module can decrypt the second device identification from the device verification information through the shared security key. If the second device identification is the same as the first device identification stored in the eSIM module, it indicates that the second processing module and the first processing module bound to the eSIM module are the same processing module. Therefore, the eSIM module can normally perform mobile communication services. If the second device identification is different from the first device identification stored in the eSIM module or the eSIM module does not receive the device verification information sent by the second processing module after detecting power failure and power on, it indicates that the second processing module and the first processing module bound to the eSIM module are not the same processing module. Therefore, the eSIM module can be prohibited from performing mobile communication services. In this way, the eSIM module in the electronic device can be prevented from being inserted into other devices to access the mobile communication network after being disassembled, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0027] In a possible implementation, before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: the eSIM module receives device binding information sent by the first processing module; after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information and stores the first device identifier.
[0028] In a possible implementation, after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information, specifically including: after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information using a shared security key.
[0029] In a possible implementation, after receiving the verification information, the eSIM module decrypts the second device identifier from the device verification information, specifically including: after receiving the device verification information, the eSIM module decrypts the second device identifier from the verification information using a shared security key.
[0030] In a possible implementation, before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: generating, by the eSIM module, an eUICC temporary working public key and an eUICC temporary working private key; receiving, by the eSIM module, a TEE temporary working public key generated by the first processing module; and generating, by the eSIM module, the shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
[0031] In a possible implementation, before the eSIM module receives the TEE temporary working public key generated by the first processing module, the method also includes: the eSIM module receives the TEE signature data sent by the first processing module; the eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; the eSIM module receives the TEE temporary working public key generated by the first processing module, specifically including: after the eSIM module verifies the legitimacy of the TEE signature data, obtaining the TEE temporary working public key from the TEE signature data.
[0032] In a possible implementation, before the eSIM module receives the TEE signature data sent by the first processing module, the method further includes: the eSIM module verifies the legitimacy of the TEE certificate; after the eSIM module verifies the legitimacy of the TEE certificate, obtains the TEE public key from the TEE certificate.
[0033] In one possible implementation, the TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
[0034] In one possible implementation, the TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
[0035] In one possible implementation, the TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; before the eSIM module verifies the legitimacy of the TEE certificate, the method also includes: the eSIM module receives the TEE certificate sent by the first processing module; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module uses the terminal manufacturer's root public key in the terminal manufacturer's root certificate to verify the legitimacy of the device certificate; after the eSIM module verifies the legitimacy of the device certificate, it uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
[0036] In one possible implementation, the TEE certificate is a terminal manufacturer's root certificate, which is pre-set in the eSIM module; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal manufacturer's root certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
[0037] In a possible implementation, the method further includes: the eSIM module generates the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key are a pair of public-private keys; the eSIM module signs the eUICC temporary working public key by using the eUICC private key to obtain eUICC signature data; the eSIM module sends the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key, and generate the shared security key based on the eUICC temporary working public key and the TEE temporary working private key, where the TEE temporary working private key and the TEE temporary working public key are a pair of public-private keys.
[0038] In a possible implementation, the method further includes: the eSIM module sending the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by an EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes an eUICC public key, the eUICC public key and the eUICC private key are a pair of public-private keys, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
[0039] In one possible implementation, the first device identifier is the chip identifier of the first processing module, and the second device identifier is the chip identifier of the second processing module; or, the first device identifier is the international mobile equipment identity code IMEI of the first processing module, and the second device identifier is the IMEI of the second processing module; or, the first device identifier is the chip identifier of the first processing module and the IMEI of the first processing module, and the second device identifier is the chip identifier of the second processing module and the IMEI of the second processing module.
[0040] In a possible implementation manner, the first request includes a first eUICC random number; and the second processing module encrypts the second device identifier to obtain device verification information, specifically including: the second processing module encrypts the first eUICC random number and the second device identifier to obtain the device verification information.
[0041] In a possible implementation manner, the method further includes: decrypting, by the eSIM module, a second eUICC random number from the device verification information; if the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally, specifically including: if the first device identifier is the same as the second device identifier and the second eUICC random number is the same as the first eUICC random number, the eSIM module performs the mobile communication service normally.
[0042] In a possible implementation, the first request is a Get Input command.
[0043] In a possible implementation manner, the eSIM module receives the device binding information sent by the first processing module, specifically including: the eSIM module receives the device binding information sent by the first processing module through a Storedata command.
[0044] In the third aspect, the present application provides an eSIM authentication method, which is applied to a processing module, the method comprising: a first eSIM identifier sent by a first eSIM module is stored in the TEE of the processing module; the processing module receives eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on; the processing module decrypts the second eSIM identifier from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, the processing module prohibits the use of the second eSIM module for mobile communication services.
[0045] Through an eSIM authentication method provided in an embodiment of the present application, a processing module and a first eSIM module in an electronic device can be implemented to first negotiate a shared key, and then the first eSIM module encrypts the eSIM identifier through the shared security key to generate eSIM binding information, and sends the eSIM binding information to the processing module. The processing module can decrypt the first eSIM identifier from the eSIM binding information through the shared security key pair and store the first eSIM identifier. When the eSIM module is powered on again or before a mobile communication service is to be performed, the processing module can allow the second eSIM module that is communicating with the processing module at this time to obtain the second eSIM identifier, and encrypt the second eSIM identifier through the shared security key to generate eSIM verification information. The processing module can decrypt the second eSIM identifier from the eSIM verification information through the shared security key. If the second eSIM identifier is the same as the first eSIM identifier stored in the TEE of the processing module, it indicates that the second eSIM module and the first eSIM module bound to the processing module are the same eSIM module, so the processing module can perform mobile communication services normally. If the second eSIM identifier is different from the first device identifier stored in the TEE of the processing module or the processing module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, it indicates that the second eSIM module is not the same as the first eSIM module bound to the processing module. Therefore, the processing module can prohibit the use of the second eSIM for mobile communication services. In this way, the eSIM module in the electronic device can be prevented from being disassembled or obtained through other means, and then inserted into the current device to access the mobile communication network, thereby improving the security of the current device when it simultaneously includes an eSIM module to access the mobile communication network.
[0046] In a possible implementation, before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: the processing module receives eSIM binding information sent by the first eSIM module; after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
[0047] In a possible implementation, after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information by using the shared security key generated by the TEE in the processing module.
[0048] In a possible implementation, after receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: after receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
[0049] In a possible implementation, before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: the processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; the processing module receives the eUICC temporary working public key generated by the first processing module; and the processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
[0050] In a possible implementation, before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: the processing module receives TEE signature data sent by the first processing module;
[0051] The processing module verifies the legitimacy of the eUICC signature data through the eUICC public key in the eUICC certificate; the processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: after the processing module verifies the legitimacy of the eUICC signature data, the processing module obtains the eUICC temporary working public key from the eUICC signature data.
[0052] In a possible implementation, before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: the processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; the processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; after the processing module verifies the legitimacy of the EUM certificate, the processing module verifies the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate; after the processing module verifies the legitimacy of the eUICC certificate, the processing module obtains the eUICC public key from the eUICC certificate.
[0053] In a possible implementation, the method further includes: the processing module generating the TEE temporary working private key and the TEE temporary working public key in the TEE, the TEE temporary working private key and the TEE temporary working public key being a pair of public-private keys; the processing module signing the TEE temporary working public key by using the TEE private key to obtain TEE signature data; the processing module sending the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, the eUICC temporary working private key and the eUICC temporary working public key being a pair of public-private keys.
[0054] In a possible implementation, before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: after detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier into the eSIM verification information.
[0055] In a possible implementation, the method also includes: the processing module decrypts a second device random number from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module to perform mobile communication services, specifically including: if the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally uses the second eSIM module to perform mobile communication services.
[0056] In a fourth aspect, the present application provides an eSIM authentication method, which is applied to an electronic device including a processing module and a second eSIM module, the method comprising: a first eSIM identifier sent by a first eSIM module is stored in the TEE of the processing module; after the second eSIM module is powered off and then powered on, the second eSIM module obtains the second eSIM identifier of the second eSIM module; the second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; the second eSIM module sends the eSIM verification information to the processing module; the processing module decrypts the second eSIM identifier from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, the processing module prohibits the use of the second eSIM module for mobile communication services.
[0057] Through an eSIM authentication method provided in an embodiment of the present application, a processing module and a first eSIM module in an electronic device can be implemented to first negotiate a shared key, and then the first eSIM module encrypts the eSIM identifier through the shared security key to generate eSIM binding information, and sends the eSIM binding information to the processing module. The processing module can decrypt the first eSIM identifier from the eSIM binding information through the shared security key pair and store the first eSIM identifier. When the eSIM module is powered on again or before a mobile communication service is to be performed, the processing module can allow the second eSIM module that is communicating with the processing module at this time to obtain the second eSIM identifier, and encrypt the second eSIM identifier through the shared security key to generate eSIM verification information. The processing module can decrypt the second eSIM identifier from the eSIM verification information through the shared security key. If the second eSIM identifier is the same as the first eSIM identifier stored in the TEE of the processing module, it indicates that the second eSIM module and the first eSIM module bound to the processing module are the same eSIM module, so the processing module can perform mobile communication services normally. If the second eSIM identifier is different from the first eSIM identifier stored in the TEE of the processing module, it indicates that the second eSIM module is not the same as the first eSIM module bound to the processing module. Therefore, the processing module can prohibit the use of the second eSIM for mobile communication services. In this way, the eSIM module in the electronic device can be prevented from being disassembled or obtained through other means, and then inserted into the current device to access the mobile communication network, thereby improving the security of the current device when it simultaneously includes an eSIM module to access the mobile communication network.
[0058] In a possible implementation, before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: the processing module receives eSIM binding information sent by the first eSIM module; after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
[0059] In a possible implementation, after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information by using the shared security key generated by the TEE in the processing module.
[0060] In a possible implementation, after receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: after receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
[0061] In a possible implementation, before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: the processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; the processing module receives the eUICC temporary working public key generated by the first processing module; and the processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
[0062] In a possible implementation manner, before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: the processing module receives TEE signature data sent by the first processing module; the processing module verifies the legitimacy of the eUICC signature data by the eUICC public key in the eUICC certificate; the processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: after the processing module verifies the legitimacy of the eUICC signature data, obtaining the eUICC temporary working public key from the eUICC signature data.
[0063] In a possible implementation, before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: the processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; the processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; after the processing module verifies the legitimacy of the EUM certificate, the processing module verifies the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate; after the processing module verifies the legitimacy of the eUICC certificate, the processing module obtains the eUICC public key from the eUICC certificate.
[0064] In a possible implementation, the method further includes: the processing module generating the TEE temporary working private key and the TEE temporary working public key in the TEE, the TEE temporary working private key and the TEE temporary working public key being a pair of public-private keys; the processing module signing the TEE temporary working public key by using the TEE private key to obtain TEE signature data; the processing module sending the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, the eUICC temporary working private key and the eUICC temporary working public key being a pair of public-private keys.
[0065] In a possible implementation, before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: after detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier into the eSIM verification information.
[0066] In a possible implementation, the method also includes: the processing module decrypts a second device random number from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module to perform mobile communication services, specifically including: if the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally uses the second eSIM module to perform mobile communication services.
[0067] In a fifth aspect, the present application provides an eSIM authentication method, which is applied to an electronic device including a second processing module and a second eSIM module, the method comprising: a first eSIM identifier sent by the first eSIM module is stored in the TEE of the second processing module; a first device identifier sent by the first processing module is stored in the second eSIM module; after the second eSIM module is powered off and then powered on again, the second eSIM module obtains the second eSIM identifier of the second eSIM module; the second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; the second eSIM module sends the eSIM verification information to the second processing module; the second processing module obtains the second device identifier, encrypts the second device identifier, obtains the device verification information, and sends the device verification information to the second eSIM module; The second processing module decrypts the second eSIM identifier from the eSIM verification information; the second eSIM module decrypts the second device identifier from the device verification information; if the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier, the electronic device normally uses the second eSIM module for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the second device identifier is different from the first device identifier or the second processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, the electronic device is prohibited from using the second eSIM module for mobile communication services.
[0068] Through an eSIM authentication method provided in an embodiment of the present application, the second processing module is legally bound to the first eSIM module, so the TEE of the second processing module stores the first eSIM identifier of the first eSIM module and the shared security key negotiated with the first eSIM module. The second eSIM module is legally bound to the first processing module, so the second eSIM module stores the first device identifier of the first processing module and the shared security key negotiated with the first processing module. When the second processing module cooperates with the second eSIM module, if the second eSIM module is powered on or before performing mobile communication services, the second processing module can obtain the second device identifier of the second processing module, and use the shared security key to encrypt the second device identifier into device verification information and send it to the second eSIM module. The second eSIM module can also obtain the second eSIM identifier of the second eSIM module, and encrypt the second eSIM identifier into eSIM verification information through the shared security key and send it to the second processing module. The second processing module can decrypt the second eSIM identifier from the eSIM verification information through the shared security key, and the second eSIM module can decrypt the second device identifier from the device verification information through the shared security key. If the second eSIM identifier is the same as the first eSIM identifier stored in the TEE of the processing module and the second device identifier is the same as the first device identifier, it indicates that the second eSIM module and the second processing module are bound to each other, so the second processing module can normally use the second eSIM module for mobile communication services. If the second eSIM identifier is different from the first eSIM identifier stored in the TEE of the processing module or the second device identifier is different from the first device identifier or the second processing module does not receive the eSIM verification information after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information after the second eSIM module is powered off and then powered on, it indicates that the second eSIM module and the second processing module are not bound to each other, so the second processing module can prohibit the use of the second eSIM for mobile communication services. In this way, it can prevent the eSIM module in the electronic device from being disassembled and inserted into other devices to access the mobile communication network, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0069] In a possible implementation, before the second eSIM module stores the first device identifier sent by the first processing module, the method further includes: the second eSIM module receives device binding information sent by the first processing module; after receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information and stores the first device identifier.
[0070] In a possible implementation, after receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information, specifically including: after receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information using a shared security key generated by the second eSIM module.
[0071] In a possible implementation, after receiving the device verification information, the second eSIM module decrypts the second device identifier from the device verification information, specifically including: after receiving the device verification information, the second eSIM module decrypts the second device identifier from the verification information using a shared security key generated by the second eSIM module.
[0072] In a possible implementation, before the second eSIM module stores the first device identifier sent by the first processing module, the method further includes: generating, by the second eSIM module, an eUICC temporary working public key and an eUICC temporary working private key; receiving, by the second eSIM module, a TEE temporary working public key generated by the first processing module; and generating, by the second eSIM module, a shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
[0073] In a possible implementation, before the second eSIM module receives the TEE temporary working public key sent by the first processing module, the method also includes: the second eSIM module receives the TEE signature data sent by the first processing module; the second eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; the second eSIM module receives the TEE temporary working public key sent by the first processing module, specifically including: after the second eSIM module verifies the legitimacy of the TEE signature data, obtaining the TEE temporary working public key from the TEE signature data.
[0074] In a possible implementation, before the second eSIM module receives the TEE signature data sent by the first processing module, the method further includes: the second eSIM module verifies the legitimacy of the TEE certificate; after the second eSIM module verifies the legitimacy of the TEE certificate, obtains the TEE public key from the TEE certificate.
[0075] In one possible implementation, the TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; the second eSIM module verifies the legitimacy of the TEE certificate, specifically including: the second eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
[0076] In one possible implementation, the TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; before the eSIM module verifies the legitimacy of the TEE certificate, the method also includes: the second eSIM module receives the TEE certificate sent by the first processing module; the second eSIM module verifies the legitimacy of the TEE certificate, specifically including: the second eSIM module uses the terminal manufacturer's root public key in the terminal manufacturer's root certificate to verify the legitimacy of the device certificate; after the second eSIM module verifies the legitimacy of the device certificate, it uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
[0077] In one possible implementation, the TEE certificate is a terminal manufacturer's root certificate, which is pre-set in the second eSIM module; the second eSIM module verifies the legitimacy of the TEE certificate, specifically including: the second eSIM module verifies the legitimacy of the terminal manufacturer's root certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
[0078] In a possible implementation, the method further includes: the second eSIM module generating the eUICC temporary working private key and the eUICC temporary working public key, the eUICC temporary working private key and the eUICC temporary working public key being a pair of public-private keys; the second eSIM module signing the eUICC temporary working public key by using the eUICC private key to obtain eUICC signature data; the second eSIM module sending the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key, and generate a shared security key based on the eUICC temporary working public key and the TEE temporary working private key, the TEE temporary working private key and the TEE temporary working public key being a pair of public-private keys.
[0079] In a possible implementation, the method further includes: the second eSIM module sending the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by an EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes an eUICC public key, the eUICC public key and the eUICC private key are a pair of public-private keys, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
[0080] In one possible implementation, the first device identifier is the chip identifier of the first processing module, and the second device identifier is the chip identifier of the second processing module; or, the first device identifier is the international mobile equipment identity code IMEI of the first processing module, and the second device identifier is the IMEI of the second processing module; or, the first device identifier is the chip identifier of the first processing module and the IMEI of the first processing module, and the second device identifier is the chip identifier of the second processing module and the IMEI of the second processing module.
[0081] In a possible implementation, before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the second processing module, the method further includes: the second processing module receives eSIM binding information sent by the first eSIM module; after receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
[0082] In a possible implementation, after receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: after receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information by using the shared security key generated by the TEE in the second processing module.
[0083] In a possible implementation, after receiving the eSIM verification information, the second processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: after receiving the eSIM verification information, the second processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
[0084] In a possible implementation, before the second processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: the second processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; the second processing module receives the eUICC temporary working public key generated by the first processing module; and the second processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
[0085] In a possible implementation manner, before the second processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: the second processing module receives TEE signature data sent by the first processing module; the second processing module verifies the legitimacy of the eUICC signature data by the eUICC public key in the eUICC certificate; the second processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: after the second processing module verifies the legitimacy of the eUICC signature data, obtaining the eUICC temporary working public key from the eUICC signature data.
[0086] In a possible implementation, before the second processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: the second processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; the second processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; after the second processing module verifies the legitimacy of the EUM certificate, the second processing module verifies the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate; after the second processing module verifies the legitimacy of the eUICC certificate, the second processing module obtains the eUICC public key from the eUICC certificate.
[0087] In a possible implementation, the method further includes: the second processing module generates the TEE temporary working private key and the TEE temporary working public key in the TEE, the TEE temporary working private key and the TEE temporary working public key are a pair of public-private keys; the second processing module signs the TEE temporary working public key by using the TEE private key to obtain TEE signature data; the second processing module sends the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, the eUICC temporary working private key and the eUICC temporary working public key are a pair of public-private keys.
[0088] In a possible implementation, the method further includes: after detecting that the second eSIM module is powered off and then powered on, the second processing module sends an eUICC random number acquisition command to the second processing module, the eUICC random number acquisition command being used to request the second processing module to send the eUICC random number to the second processing module; after receiving the eUICC random number acquisition command, the second eSIM module generates a first eUICC random number and sends the first eUICC random number to the second processing module; the second processing module generates a first device random number; the second processing module acquires the second device identifier, encrypts the second device identifier, and obtains device verification information, specifically including: the second processing module acquires the second device identifier, encrypts the second device identifier, the first device random number, and the first eUICC random number, and obtains device verification information.
[0089] In a possible implementation manner, the method further includes: after receiving the device verification information, the second eSIM module decrypts the second eUICC random number and the third device random number from the device verification information; the second eSIM module encrypts the second eSIM identifier to obtain the eSIM verification information, specifically including: the second eSIM module encrypts the second eSIM identifier and the third device random number to obtain the eSIM verification information.
[0090] In a possible implementation manner, the method further includes: the second processing module decrypting a second device random number from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier, the electronic device normally uses the second eSIM module to perform mobile communication services, specifically including: if the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier and the second device random number is the same as the first device random number and the second eUICC random number is the same as the first eUICC random number, the electronic device normally uses the second eSIM module to perform mobile communication services.
[0091] In a sixth aspect, the present application provides an eSIM module, comprising: a processing circuit, a storage circuit and an interface circuit, the storage circuit being used to store data and code instructions, the interface circuit being used to send commands to the processing module through a modem or to receive commands sent by the processing module through the modem; the processing circuit being used to run the code instructions to execute the method in the above-mentioned first aspect and any possible implementation of the first aspect.
[0092] In the seventh aspect, the present application provides a processing module, characterized in that it includes: a processing circuit, a storage circuit and an interface circuit, the storage circuit is used to store data and code instructions, the interface circuit is used to send commands to the eSIM module through a modem or receive commands sent by the eSIM module through the modem; the processing circuit is used to run the code instructions to execute the method in the above-mentioned third aspect and any possible implementation method of the third aspect.
[0093] In an eighth aspect, the present application provides an electronic device comprising: an eSIM module, a second processing module and one or more memories, wherein the one or more memories are coupled to the second processing module, and the one or more memories are used to store a computer program, and when the second processing module executes the computer program, the first electronic device executes the method in the above-mentioned second aspect and any possible implementation method of the second aspect.
[0094] In the ninth aspect, the present application provides an electronic device, comprising: a second eSIM module, a processing module and one or more memories, wherein the one or more memories are coupled to the processing module, and the one or more memories are used to store a computer program, and when the processing module executes the computer program, the second electronic device executes the method in the above-mentioned fourth aspect and any possible implementation of the fourth aspect.
[0095] In the tenth aspect, the present application provides an electronic device, comprising: a second eSIM module, a second processing module and one or more memories, wherein the one or more memories are coupled to the second processing module, and the one or more memories are used to store a computer program, and when the second processing module executes the computer program, the electronic device executes the method in the above-mentioned fifth aspect and any possible implementation method of the fifth aspect.
[0096] In the eleventh aspect, an embodiment of the present application provides a computer storage medium, including computer instructions. When the computer instructions are executed on a processor of an electronic device, the electronic device executes a method in any possible implementation of the second aspect described above.
[0097] In the twelfth aspect, an embodiment of the present application provides a computer storage medium, including computer instructions. When the computer instructions are executed on a processor of an electronic device, the electronic device executes the method in the above-mentioned fourth aspect and any possible implementation of the fourth aspect.
[0098] In the thirteenth aspect, an embodiment of the present application provides a computer storage medium, including computer instructions. When the computer instructions are executed on a processor of an electronic device, the electronic device executes the method in the above-mentioned fifth aspect and any possible implementation of the fifth aspect.
[0099] The beneficial effects of the second to thirteenth aspects mentioned above can refer to the beneficial effects of the first aspect mentioned above and any possible implementation method of the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0100] Figure 1 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application;
[0101] Figure 2 A schematic diagram of the structure of a trusted execution environment of an electronic device provided in an embodiment of the present application;
[0102] Figure 3 A schematic diagram of a certificate chain in a TEE and an eSIM module of an electronic device provided in an embodiment of the present application;
[0103] Figure 4 A schematic diagram of a certificate signing process provided for an embodiment of the present application;
[0104] Figure 5 A schematic diagram of a process of binding a device to an eSIM card in an eSIM authentication method provided in an embodiment of the present application;
[0105] Figure 6 A schematic diagram of a process of machine-card verification in an eSIM authentication method provided in an embodiment of the present application;
[0106] Figure 7 A schematic diagram of the signaling interaction process for machine-card binding in an eSIM authentication method provided in an embodiment of the present application;
[0107] Fig. 8A A schematic diagram of the encryption process of command plaintext data in a Storedata command provided in an embodiment of the present application;
[0108] Figure 8B A schematic diagram of an encryption process of response plaintext data in a Response command provided in an embodiment of the present application;
[0109] Fig. 9 A schematic diagram of the signaling interaction process of machine-card verification in an eSIM authentication method provided in an embodiment of the present application;
[0110] Fig.10 A command format diagram of a Get Input command provided in an embodiment of the present application;
[0111] Fig.11 A schematic diagram of the structure of an execution environment of an electronic device provided in an embodiment of the present application;
[0112] Fig.12A schematic diagram of a certificate chain in a TEE and an eSIM module of an electronic device provided in an embodiment of the present application;
[0113] Fig.13 A schematic diagram of a process of one-way binding of a machine and a card in an eSIM authentication method provided in an embodiment of the present application;
[0114] Fig.14 A schematic diagram of a process of bidirectional binding of a machine and a card in an eSIM authentication method provided in an embodiment of the present application;
[0115] Fig.15 A schematic diagram of a process of bidirectional binding of a machine and a card in an eSIM authentication method provided in an embodiment of the present application;
[0116] Fig.16 A schematic diagram of a process of two-way verification of a machine and a card in an eSIM authentication method provided in an embodiment of the present application;
[0117] Fig.17 A schematic diagram of the signaling interaction flow of one-way binding of a machine and a card in an eSIM authentication method provided in an embodiment of the present application;
[0118] Fig.18 A schematic diagram of the signaling interaction flow of bidirectional binding of machine and card in an eSIM authentication method provided in an embodiment of the present application;
[0119] Fig.19 A schematic diagram of a signaling interaction flow for bidirectional binding of a machine and a card in an eSIM authentication method provided in another embodiment of the present application;
[0120] Fig. 20 The present invention is a flowchart of a two-way verification of a machine and a card in an eSIM authentication method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0121] The technical solutions in the embodiments of the present application will be described clearly and in detail below in conjunction with the accompanying drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in the text is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.
[0122] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as suggesting or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features, and in the description of the embodiments of the present application, unless otherwise specified, "plurality" means two or more.
[0123] Figure 1 A schematic structural diagram of an electronic device 100 is shown.
[0124] The following is a detailed description of the embodiment using the electronic device 100 as an example. It should be understood that: Figure 1 The electronic device 100 shown is only an example, and the electronic device 100 may have more Figure 1 The more or less components shown in the figure can be combined with two or more components, or can have different component configurations. The various components shown in the figure can be implemented in hardware, software, or a combination of hardware and software including one or more signal processing and / or application specific integrated circuits.
[0125] The electronic device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and an embedded SIM (eSIM) module 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0126] It is to be understood that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown in the figure, or combine some components, or separate some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0127] The processor 110 may include one or more processing units, for example, the processor 110 may include an application processor (AP), a modem processor, a graphics processor (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.
[0128] The controller may be the nerve center and command center of the electronic device 100. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0129] The processor 110 may also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory may store instructions or data that the processor 110 has just used or cyclically used. If the processor 110 needs to use the instruction or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0130] In some embodiments, the processor 110 may include one or more interfaces. The interface may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0131] The I2C interface is a bidirectional synchronous serial bus, including a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 may include multiple groups of I2C buses. The processor 110 may be coupled to the touch sensor 180K, the charger, the flash, the camera 193, etc. through different I2C bus interfaces. For example: the processor 110 may be coupled to the touch sensor 180K through the I2C interface, so that the processor 110 communicates with the touch sensor 180K through the I2C bus interface, thereby realizing the touch function of the electronic device 100.
[0132] The I2S interface can be used for audio communication. In some embodiments, the processor 110 can include multiple I2S buses. The processor 110 can be coupled to the audio module 170 via the I2S bus to achieve communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit an audio signal to the wireless communication module 160 via the I2S interface to achieve the function of answering a call through a Bluetooth headset.
[0133] The PCM interface can also be used for audio communication, sampling, quantizing and encoding analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled via a PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 via the PCM interface to realize the function of answering calls via a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.
[0134] The UART interface is a universal serial data bus for asynchronous communication. The bus can be a bidirectional communication bus. It converts the data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is generally used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 through the UART interface to implement the Bluetooth function. In some embodiments, the audio module 170 can transmit an audio signal to the wireless communication module 160 through the UART interface to implement the function of playing music through a Bluetooth headset.
[0135] The MIPI interface can be used to connect the processor 110 with peripheral devices such as the display screen 194 and the camera 193. The MIPI interface includes a camera serial interface (CSI), a display serial interface (DSI), etc. In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to implement the shooting function of the electronic device 100. The processor 110 and the display screen 194 communicate via the DSI interface to implement the display function of the electronic device 100.
[0136] The GPIO interface can be configured by software. The GPIO interface can be configured as a control signal or as a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 with the camera 193, the display 194, the wireless communication module 160, the audio module 170, the sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.
[0137] The USB interface 130 is an interface that complies with the USB standard specification, and specifically can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 can be used to connect a charger to charge the electronic device 100, and can also be used to transfer data between the electronic device 100 and a peripheral device. It can also be used to connect headphones to play audio through the headphones. The interface can also be used to connect other electronic devices, such as AR devices, etc.
[0138] It is understandable that the interface connection relationship between the modules illustrated in the embodiment of the present invention is only a schematic illustration and does not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods in the above embodiments, or a combination of multiple interface connection methods.
[0139] The charging management module 140 is used to receive charging input from a charger. The charger may be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 may receive charging input from a wired charger through the USB interface 130. In some wireless charging embodiments, the charging management module 140 may receive wireless charging input through a wireless charging coil of the electronic device 100. While the charging management module 140 is charging the battery 142, it may also power the electronic device through the power management module 141.
[0140] The power management module 141 is used to connect the battery 142, the charging management module 140 and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, and supplies power to the processor 110, the internal memory 121, the external memory, the display screen 194, the camera 193, and the wireless communication module 160. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle number, battery health status (leakage, impedance), etc. In some other embodiments, the power management module 141 can also be set in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be set in the same device.
[0141] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor.
[0142] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve the utilization of antennas. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0143] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G, etc., applied to the electronic device 100. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.
[0144] The modem processor may include a modulator and a demodulator. Among them, the modulator is used to modulate the low-frequency baseband signal to be sent into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After the low-frequency baseband signal is processed by the baseband processor, it is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to a speaker 170A, a receiver 170B, etc.), or displays an image or video through a display screen 194. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be set in the same device as the mobile communication module 150 or other functional modules.
[0145] The wireless communication module 160 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., which are applied to the electronic device 100. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, modulates the frequency of the electromagnetic wave signal and performs filtering, and sends the processed signal to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, modulate the frequency of it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.
[0146] In some embodiments, the antenna 1 of the electronic device 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the electronic device 100 can communicate with the network and other devices through wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).
[0147] The electronic device 100 implements the display function through a GPU, a display screen 194, and an application processor. The GPU is a microprocessor for image processing, which connects the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 may include one or more GPUs that execute program instructions to generate or change display information.
[0148] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD). The display screen panel can also be made of an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), miniled, microled, micro-oled, a quantum dot light emitting diode (QLED), etc. In some embodiments, the electronic device 100 may include 1 or N display screens 194, where N is a positive integer greater than 1.
[0149] The electronic device 100 can realize the shooting function through ISP, camera 193, video codec, GPU, display screen 194 and application processor.
[0150] ISP is used to process the data fed back by camera 193. For example, when taking a photo, the shutter is opened, and the light is transmitted to the camera photosensitive element through the lens. The light signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to ISP for processing and converts it into an image visible to the naked eye. ISP can also perform algorithm optimization on the noise, brightness, etc. of the image. ISP can also optimize the exposure, color temperature and other parameters of the shooting scene. In some embodiments, ISP can be set in camera 193.
[0151] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, and then passes the electrical signal to the ISP to be converted into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the electronic device 100 may include 1 or N cameras 193, where N is a positive integer greater than 1.
[0152] The digital signal processor is used to process digital signals, and can process not only digital image signals but also other digital signals. For example, when the electronic device 100 is selecting a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy.
[0153] Video codecs are used to compress or decompress digital videos. The electronic device 100 may support one or more video codecs. Thus, the electronic device 100 may play or record videos in a variety of coding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.
[0154] NPU is a neural network (NN) computing processor. By drawing on the structure of biological neural networks, such as the transmission mode between neurons in the human brain, it can quickly process input information and can also continuously self-learn. Through NPU, applications such as intelligent cognition of electronic device 100 can be realized, such as image recognition, face recognition, voice recognition, text understanding, etc.
[0155] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to implement a data storage function, such as storing music, video and other files in the external memory card.
[0156] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area may store data created during the use of the electronic device 100 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0157] The electronic device 100 can implement audio functions through an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, and an application processor. For example, music playback, recording, etc. The pressure sensor 180A is used to sense the pressure signal and can convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A can be set on the display screen 194. The gyroscope sensor 180B can be used to determine the motion posture of the electronic device 100. The air pressure sensor 180C is used to measure the air pressure. The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can use the magnetic sensor 180D to detect the opening and closing of the flip leather case. The acceleration sensor 180E can detect the magnitude of the acceleration of the electronic device 100 in all directions (generally three axes). The distance sensor 180F is used to measure the distance. The proximity light sensor 180G may include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The ambient light sensor 180L is used to sense the ambient light brightness. The fingerprint sensor 180H is used to collect fingerprints. The temperature sensor 180J is used to detect the temperature. The touch sensor 180K is also called a "touch panel". The touch sensor 180K can be set on the display screen 194, and the touch sensor 180K and the display screen 194 form a touch screen, also called a "touch screen". The touch sensor 180K is used to detect touch operations acting on or near it. The touch sensor can pass the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through the display screen 194. In other embodiments, the touch sensor 180K can also be set on the surface of the electronic device 100, which is different from the position of the display screen 194. The bone conduction sensor 180M can obtain a vibration signal. The button 190 includes a power button, a volume button, etc. The motor 191 can generate a vibration prompt. The indicator 192 can be an indicator light, which can be used to indicate the charging status, power changes, messages, missed calls, notifications, etc.
[0158] The eSIM module 195 can be embedded in the electronic device 100. The eSIM module is usually embedded inside the motherboard of the electronic device. It can replace the physical SIM card, but the size of the eSIM is much smaller. Unlike the SIM card, the eSIM card can switch numbers or change operators at will because the information on the eSIM can be rewritten. The eSIM card is remotely configured through over-the-air technology (OTA) writing card, and the operator configuration file can be downloaded, installed, activated, deactivated and deleted through the network and installed in the terminal.
[0159] In an embodiment of the present application, the device type of the electronic device 100 may include any one of a smart phone, a smart watch, a smart speaker, a personal computer, a smart TV, a tablet computer, a smart socket, an air purifier, a smart desk lamp, a smart air conditioner, a smart curtain, a smart water heater, a smart door lock, a smart camera, and the like.
[0160] Figure 2 A schematic diagram of the structure of a trusted execution environment of an electronic device provided in an embodiment of the present application.
[0161] like Figure 2 As shown, the electronic device 100 may include a central processor unit (CPU), a modem (Modem) and an eSIM module. Among them, the CPU can run two application environments: a rich execution environment (REE) and a trusted execution environment (TEE).
[0162] The applications running in REE can be called client applications, and the client applications in REE can include encryption and decryption client applications (CA). REE can also run local profile assistants (LPA), card application tool services (Catservice), and telephone management modules (TelephonyManager).
[0163] Applications running in TEE can be called trusted applications (TA). Among them, trusted applications in TEE can include encryption and decryption TA, and TEE can also manage some digital certificates issued by digital certificate certification authorities (CertificatiuonAuthority). For example, digital certificates in TEE can include authentication root certificates (CERT.CI.ECDSA), device certificates (CERT.DEVICE.ECDSA) and terminal certificates (CERT.OEM.ECDSA), etc.
[0164] The operating system running in REE can be called a rich execution environment operating system (REE OS), and the operating system running in TEE can be called a trusted execution environment operating system (TEE OS). Among them, TEE is a secure operating environment running in the CPU. The secure boot process of TEE needs to be verified, and its secure boot process is separated from REE. The various applications running under TEE are independent of each other, and the various applications cannot access each other without authorization, ensuring that the processing of resources and data of applications under TEE is executed in a trusted environment, thereby providing security services for the REE operating system. TEE has its own execution space, which has a higher security level than the REE operating system. It is a security architecture that overlaps with the hardware architecture of the currently used CPU. The software and hardware resources that TEE can access are separated from the REE operating system, providing hardware-supported isolation. Among them, the encryption and decryption CA and the encryption and decryption TA share memory. If the encryption and decryption CA needs to communicate with the encryption and decryption TA, the encryption and decryption CA can apply to the TEE OS to establish a session with the requested encryption and decryption TA. After the session between the encryption and decryption CA and the encryption and decryption TA is established, the encryption and decryption CA can send a processing request and the data to be processed to the encryption and decryption TA through the shared memory. After the encryption and decryption TA obtains the processing request of the encryption and decryption CA and the data to be processed from the shared memory, it can execute the processing request in the TEE environment, and the obtained processing result is stored in the shared memory. The encryption and decryption CA can obtain the processing result of the encryption and decryption TA through the shared memory. After obtaining the processing result, if the encryption and decryption TA does not need to continue processing, the encryption and decryption CA can initiate a request to close the session (close session) to the TEE OS. After receiving the request to close the session (close session), TEEOS can reclaim the relevant resources of the encryption and decryption TA.
[0165] LPA can call the machine-card binding logic and send machine-card binding instructions to the eSIM module. LPA can interact with the eSIM module for machine-card binding through Telephony Manage and Modem. LPA can communicate with the encryption and decryption TA in TEE by calling the encryption and decryption CA, thereby calling the encryption and decryption TA to provide encryption and decryption, certificate verification, and key negotiation services during the machine-card binding interaction.
[0166] The eSIM module can manage the card binding logic, digital certificates, security status and transmitter card verification commands. Among them, the digital certificates managed in the eSIM module can include authentication root certificates, terminal manufacturer root certificates (CERT.OEMCI.ECDSA), etc.
[0167] The eSIM module can call the machine-card binding logic and send a machine-card verification instruction to the Cat Service through the Modem, thereby triggering the machine-card verification interaction between the eSIM module and the Cat Service. Among them, the Cat Service can communicate with the encryption and decryption TA in the TEE by calling the encryption and decryption CA, thereby calling the encryption and decryption TA to provide encryption and decryption services during the machine-card verification interaction.
[0168] 1. In the machine-card binding logic:
[0169] LPA can first request the certificate chain of the eSIM module, and verify the certificate chain of the eSIM module by calling the encryption and decryption TA through the encryption and decryption CA. After verifying the legitimacy of the certificate chain of the eSIM module, the encryption and decryption TA can obtain the embedded universal integrated circuit card (eUICC) public key from the certificate chain of the eSIM module. LPA can call the encryption and decryption TA through the encryption and decryption CA to generate the TEE temporary working public key and the TEE temporary working private key, and call the encryption and decryption TA to sign the TEE temporary working public key using the TEE private key (for example, the OEM private key), and send the signature data including the TEE temporary working public key to the eSIM module.
[0170] LPA can send the TEE certificate chain to the eSIM module. The eSIM module can verify the TEE certificate chain. After verifying the legitimacy of the TEE certificate chain, the eSIM module can obtain the TEE public key (e.g., OEM public key) from the TEE certificate chain. The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key, and signs the eUICC temporary working public key with the eUICC private key, and sends the signature data including the eUICC temporary working public key to the LPA.
[0171] LPA can verify the signature data including the temporary working public key of eUICC by calling the encryption and decryption TA and using the eUICC public key, and obtain the temporary working public key of eUICC after the verification. The encryption and decryption TA can generate a shared security key based on the temporary working public key of eUICC and the temporary working private key of TEE.
[0172] The eSIM module can use the TEE public key (e.g., OEM public key) to verify the signature data including the TEE temporary working public key, and obtain the TEE temporary working public key after the verification is passed. The eSIM module can generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key.
[0173] Among them, the eSIM module and the encryption and decryption TA can use the other party's temporary working public key and their own temporary working private key to generate the same shared security key.
[0174] The LPA may obtain the device identification 1 (eg, the CPU identification and / or IMEI), and call the encryption and decryption TA to encrypt the device identification 1 with a shared security key to obtain the binding information. The LPA may send the binding information to the eSIM module.
[0175] The eSIM module can decrypt the device identification from the binding information by using the shared security key and store the device identification 1 .
[0176] 2. In the machine card verification logic:
[0177] After the aforementioned machine-card binding logic, the eSIM module has been bound to device identification 1. When the eSIM module is powered on again or before initiating network registration, it can actively send a device identification acquisition request to Cat Service. After obtaining the device identification acquisition request, Cat Service can obtain device identification 2 in the CPU, and call the encryption and decryption TA to encrypt device identification 2 through the shared security key to obtain verification information. Cat Service can send the verification information to the eSIM module. The eSIM module can decrypt the device identification 2 from the verification information through the shared security key. The eSIM module can determine whether the device identification 2 decrypted from the verification information is the same as the stored device identification 1. If the device identification 2 is the same as the device identification 1, the machine-card verification is passed, and the eSIM module can perform communication services normally. If the device identification 2 is different from the device identification 1, the machine-card verification fails, and the eSIM module is prohibited from performing communication services.
[0178] In one possible implementation, a random number may be carried in a device identification acquisition request. Encryption and Decryption TA can encrypt the device identification 2 and the random number together through a shared security key to obtain verification information. The eSIM module can decrypt the device identification 2 and the random number from the verification information through a shared security key. If the decrypted random number is the same as the random number carried in the device identification acquisition request, and the device identification 2 is the same as the device identification 1, the machine card verification is successful. If the decrypted random number is different from the random number carried in the device identification acquisition request, or the device identification 2 is different from the device identification 1, the machine card verification is unsuccessful.
[0179] In the embodiment of the present application, the above-mentioned central processor is only an exemplary explanation of the present application, and is not limited thereto. The central processor may also be other processing modules, and the processing modules may include the above-mentioned REE and TEE. For the functional description of REE and TEE and the architecture of the internal modules, reference may be made to the above-mentioned Figure 2 The embodiments shown will not be described in detail here.
[0180] In the embodiments of the present application, the CPU may be referred to as a processing module, the first CPU may be referred to as a first processing module, the second CPU may be referred to as a second processing module, the first CPU may be understood as an example of the first processing module, and the second CPU may be understood as an example of the second processing module. In some possible embodiments of the present application, the first processing module and the second processing module may be the same processing module or different processing modules.
[0181] In the embodiment of the present application, the electronic device 100 may be referred to as a terminal, and the processing module and the modem in the electronic device 100 may be collectively referred to as a terminal device. Therefore, the terminal may include a terminal device and an eSIM module.
[0182] Figure 3 A schematic diagram of a certificate chain in a TEE and an eSIM module of an electronic device 100 provided in an embodiment of the present application is shown.
[0183] like Figure 3 As shown, the TEE can manage authentication root certificates (CERT.CI.ECDSA), device certificates, and terminal certificates (CERT.OEM.ECDSA). Among them, the authentication root certificate is the root certificate of the card manufacturer (embedded UICCmanufacture, EUM) certificate in the eSIM module, and the EUM certificate is the root certificate of the eUICC certificate. That is, the EUM certificate is signed by the private key corresponding to the authentication root certificate, and the eUICC certificate is signed by the private key corresponding to the EUM certificate.
[0184] Among them, the authentication root certificate (CERT.CI.ECDSA) can be imported into the TEE of the electronic device 100 through the authentication root certificate authorization public key infrastructure (PKI) device through the OTA method.
[0185] TEE can generate a pair of OEM public and private keys, which include OEM public key (PK.OEM.ECDSA) and OEM private key (SK.OEM.ECDSA). The OEM public and private keys can be public and private keys under the elliptic curve cryptography (ECC) standard of NIST P256 standard. The signature algorithm of the OEM public and private keys can be the elliptic curve digital signature algorithm (ECDSA).
[0186] Among them, TEE can import the TEE certificate into TEE offline through the device manufacturer certificate authorization PKI device. For example, the TEE certificate may include a device certificate, a terminal certificate, etc. Among them, TEE can send an offline certificate signing request to the device manufacturer certificate authorization PKI device. Among them, the offline certificate signing request includes the OEM public key (PK.OEM.ECDSA). The offline certificate signing request is used to request the device manufacturer certificate authorization PKI device to issue a digital certificate for the OEM public key. After receiving the offline certificate signing request, the device manufacturer certificate authorization PKI device can first issue a device certificate through the private key corresponding to the terminal manufacturer's root certificate, and then use the private key corresponding to the device certificate to issue a terminal certificate including the OEM public key. Among them, the terminal certificate includes the OEM public key (PK.OEM.ECDSA), and the private key corresponding to the terminal certificate is the OEM private key (SK.OEM.ECDSA).
[0187] For example, see Figure 4 The certificate signing process shown:
[0188] 1. The device manufacturer's root certificate authorization PKI device can store the terminal manufacturer's root certificate and the private key (SK.OEMCI.ECDSA) corresponding to the terminal manufacturer's root certificate. The device manufacturer's certificate authorization PKI device can sign the certificate content of the device certificate with the private key (SK.OEMCI.ECDSA) corresponding to the terminal manufacturer's root certificate to generate a device certificate. Among them, the device certificate includes the device public key (PK.DEVICE.ECDSA), and the terminal manufacturer's root authorization PKI device stores the device private key (SK.DEVICE.ECDSA) paired with the device public key (PK.DEVICE.ECDSA).
[0189] 2. After receiving the offline certificate signing request sent by the TEE of the electronic device 100, the PKI device can obtain the OEM public key (PK.OEM.ECDSA) from the offline certificate signing request and generate the certificate content of the terminal certificate. The certificate content of the terminal certificate may include the OEM public key (PK.OEM.ECDSA), the specified signature algorithm (for example, ECDSA), the certificate validity period, the user, and so on.
[0190] 3. The terminal manufacturer's root authorized PKI device can perform a hash operation on the certificate content of the terminal certificate to generate a digital summary of the terminal certificate. The terminal manufacturer's root authorized PKI device can encrypt the digital summary of the terminal certificate into the certificate signature of the terminal certificate through the device private key (SK.DEVICE.ECDSA) and the specified signature algorithm. The terminal manufacturer's root authorized PKI device can combine the digital summary of the terminal certificate and the certificate signature of the business root certificate to generate a terminal certificate.
[0191] The eSIM module can be pre-installed with the terminal manufacturer root certificate, authentication root certificate (CERT.CI.ECDSA), EUM certificate, eUICC certificate, EUM private key corresponding to the EUM certificate, and eUICC private key (SK.eUICC.ECDSA) corresponding to the eUICC certificate. Among them, the terminal manufacturer root certificate includes the terminal manufacturer root public key, the authentication root certificate (CERT.CI.ECDSA) includes the authentication root public key (PK.CI.ECDSA), the EUM certificate includes the EUM public key, and the eUICC certificate includes the eUICC public key (PK.eUICC.ECDSA). The authentication root private key corresponding to the authentication root certificate (CERT.CI.ECDSA) has signed the EUM certificate. The EUM private key corresponding to the EUM certificate has signed the EUM certificate.
[0192] TEE and the eSIM module can verify each other's certificate chain and exchange temporary working public keys.
[0193] in:
[0194] (1) The encryption and decryption TA in TEE can verify the certificate chain of the eSIM module.
[0195] Among them, the certificate chain of the eSIM module includes the authentication root certificate, EUM certificate and eUICC certificate. The eSIM module can send the EUM certificate and eUICC certificate to the encryption and decryption TA. The encryption and decryption TA can verify the legitimacy of the EUM certificate through the authentication root public key in the authentication root certificate preset in the TEE. If the verification of the legitimacy of the EUM certificate passes, the encryption and decryption TA can verify the legitimacy of the eUICC certificate through the EUM public key in the EUM certificate. If the verification of the legitimacy of the eUICC certificate passes, the encryption and decryption TA can determine that the verification of the legitimacy of the certificate chain of the eSIM module passes.
[0196] (2) The eSIM module can verify the TEE certificate chain.
[0197] Among them, the TEE certificate chain includes the device certificate and the terminal certificate. The encrypted TA can send the device certificate and the terminal certificate to the eSIM module. The eSIM module can verify the legitimacy of the device certificate through the public key in the terminal manufacturer's root certificate preset in the eSIM module. If the legitimacy of the device certificate is verified, the eSIM module can verify the legitimacy of the terminal certificate through the device public key in the device certificate. If the legitimacy of the terminal certificate is verified, the eSIM module can determine that the legitimacy of the certificate chain of the TEE is verified.
[0198] In one possible implementation, the TEE certificate may include the terminal manufacturer's root certificate. The terminal manufacturer's root certificate is self-signed by the terminal manufacturer's root private key corresponding to the terminal manufacturer's root certificate. In this case, the eSIM module can store the terminal manufacturer's root certificate after the OTA upgrade is completed. Since the device certificate managed by TEE only includes the terminal manufacturer's root certificate, LPA does not need to send the terminal manufacturer's root certificate to the eSIM module for verification. The eSIM module can directly verify it by signing after receiving the subsequent TEE temporary working public key.
[0199] (3) The encryption and decryption TA in TEE exchanges a temporary working public key with the eSIM module.
[0200] Among them, the encryption and decryption TA can generate TEE temporary working public and private keys, wherein the TEE temporary working public and private keys include TEE temporary working public key (otPK.TEE.ECKA) and TEE temporary working private key (otSK.TEE.ECKA). After the encryption and decryption TA and the eSIM module have verified each other's certificate chain, the encryption and decryption TA can sign the TEE temporary working public key (otPK.TEE.ECDSA) with the OEM private key (SK.OEM.ECDSA), and send the TEE signature data including the TEE temporary working public key (otPK.TEE.ECKA) to the eSIM module.
[0201] After verifying the TEE certificate chain, the eSIM module can obtain the OEM public key in the TEE terminal certificate. The eSIM module can verify the TEE signature data including the TEE temporary working public key (otPK.TEE.ECKA) through the OEM public key, and obtain the TEE temporary working public key (otPK.TEE.ECKA) after successful verification.
[0202] The eSIM module can generate the eUICC temporary working public and private keys, wherein the eUICC temporary working public and private keys include the eUICC temporary working public key (otPK.eUICC.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA). The eSIM module can sign the eUICC temporary working public key (otPK.eUICC.ECKA) by the eUICC private key (SK.eUICC.ECDSA), and send the eUICC signature data including the eUICC temporary working public key (otPK.eUICC.ECKA) to the encryption and decryption TA.
[0203] After verifying the certificate chain of the eSIM module, the encryption and decryption TA can obtain the eUICC public key (PK.eUICC.ECDSA) in the eUICC certificate. The encryption and decryption TA can verify the eUICC signature data including the eUICC temporary work public key (otPK.eUICC.ECKA) through the eUICC public key (PK.eUICC.ECDSA), and after successful verification, obtain the eUICC temporary work public key (otPK.TEE.ECKA).
[0204] The eSIM module can generate a shared security key (shared secret key, ShS) based on the TEE temporary working public key (otPK.TEE.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA).
[0205] The encryption and decryption TA can generate a shared security key (sharedsecretkey, ShS) based on the eUICC temporary working public key (otPK.eUICC.ECKA) and the TEE temporary working private key (otSK.TEE.ECKA).
[0206] Among them, since the TEE temporary working public key (otPK.TEE.ECKA) and the TEE temporary working private key (otSK.TEE.ECKA) are a pair of public and private keys, and the eUICC temporary working public key (otPK.eUICC.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA) are a pair of public and private keys, the eSIM module and the encryption and decryption TA can use each other's temporary working public key and their own temporary working private key to generate the same shared security key (ShS).
[0207] In one possible implementation, the authentication root certificate (CERT.CI.ECDSA) can be a root certificate issued by an operator, a root certificate issued by a third-party organization, a root certificate issued by a terminal manufacturer, a root certificate issued by an EUM manufacturer, and so on.
[0208] In a possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be issued directly by the terminal manufacturer's root certificate or by an intermediate certificate issued by the terminal manufacturer's root certificate, or may be issued by an authentication root certificate.
[0209] In one possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be self-signed.
[0210] In a possible implementation, the device manufacturer root certificate (CERT.OEMCI.ECDSA) may be preset in the eSIM module before the electronic device 100 leaves the factory.
[0211] In a possible implementation, the device manufacturer root certificate (CERT.OEMCI.ECDSA) may also be issued by the server to the electronic device 100 during OTA upgrade after the electronic device 100 leaves the factory. The processing module (eg, CPU) in the electronic device 100 is pre-installed in the eSIM module.
[0212] The following is a unified description of the abbreviations of the certificates involved in the embodiments of this application.
[0213] (1) The abbreviation of the authentication root certificate may be CERT.CI.ECDSA or CERT.CI.SIG or CERT.CNCI.SIG. The abbreviation of the authentication root public key of the authentication root certificate may be PK.CI.ECKA or PK.CNCI.ECKA or PK.CNCI.SIG, etc. The abbreviation of the authentication root private key corresponding to the authentication root certificate may be SK.CI.ECKA or SK.CNCI.ECKA or SK.CNCI.SIG, etc.
[0214] (2) The abbreviation of the EUM certificate can be CERT.EUM.ECDSA or CERT.EUM.SIG. The abbreviation of the EUM public key of the EUM certificate can be PK.EUM.ECKA or PK.EUM.ECKA or PK.EUM.SIG, etc. The abbreviation of the EUM private key corresponding to the EUM certificate can be SK.EUM.ECKA or SK.EUM.ECKA or SK.EUM.SIG, etc.
[0215] (3) The eUICC certificate may also be referred to as the eSIM certificate. The abbreviation of the eUICC certificate (also known as the eSIM certificate) may be CERT.eUICC.ECDSA or CERT.eUICC.SIG or CERT.eSIM.ECDSA or CERT.eSIM.SIG. Among them, the abbreviation of the eUICC public key (also known as the eSIM public key) of the eUICC certificate (also known as the eSIM certificate) may be PK.eUICC.ECKA or PK.eUICC.ECKA or PK.eUICC.SIG or PK.eSIM.ECKA or PK.eSIM.ECKA or PK.eSIM.SIG, etc. The abbreviation of the eUICC private key (also known as the eSIM private key) corresponding to the eUICC certificate (also known as the eSIM certificate) may be SK.eUICC.ECKA or SK.eUICC.ECKA or SK.eUICC.SIG or SK.eSIM.ECKA or SK.eSIM.ECKA or SK.eSIM.SIG, etc.
[0216] (4) The abbreviation of the terminal manufacturer root certificate may be CERT.OEMCI.ECDSA or CERT.OEMCI.SIG. The abbreviation of the terminal manufacturer root public key of the terminal manufacturer root certificate may be PK.OEMCI.ECKA or PK.OEMCI.SIG. The abbreviation of the terminal manufacturer root private key corresponding to the terminal manufacturer root certificate may be SK.OEMCI.ECKA or SK.OEMCI.SIG.
[0217] (5) The abbreviation of the device certificate may be CERT.DEVICE.ECDSA or CERT.DEVICE.SIG. The abbreviation of the device public key of the device certificate may be PK.DEVICE.ECKA or PK.DEVICE.SIG. The abbreviation of the device private key corresponding to the device certificate may be SK.DEVICE.ECKA or SK.DEVICE.SIG.
[0218] (6) The abbreviation of the terminal certificate can be CERT.OEM.ECDSA or CERT.OEM.SIG. The abbreviation of the terminal public key of the terminal certificate can be PK.OEM.ECKA or PK.OEM.SIG. The abbreviation of the device private key corresponding to the device certificate can be SK.OEM.ECKA or SK.OEM.SIG.
[0219] In order to facilitate the description of the certificate in the embodiment of the present application, the certificate is described in a uniform format ending with ".ECDSA".
[0220] The following describes an eSIM authentication method provided in an embodiment of the present application.
[0221] Figure 5 A schematic diagram of the process of machine-card binding in an eSIM authentication method provided in an embodiment of the present application is shown.
[0222] The eSIM authentication method can be applied to a first electronic device including a first CPU and an eSIM module. The first CPU can run REE and TEE. LPA and encryption and decryption CA can be run in REE, and encryption and decryption TA can be run in TEE. For a detailed description of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The illustrated embodiments will not be described in detail here.
[0223] like Figure 5 As shown, the process of machine card binding may include the following steps:
[0224] S501. The first CPU can detect the first startup after leaving the factory, or the first startup after the system upgrades the machine card binding verification function.
[0225] The first CPU can detect the first boot after leaving the factory, or the first boot after the system upgrades the machine card binding verification function, and trigger the subsequent machine card binding process. The machine card binding process may include the following three stages: mutual certificate verification, mutual exchange of temporary working public keys, and device identification binding.
[0226] The first electronic device may be pre-installed with a machine-card binding function and a machine-card verification function before leaving the factory. In this way, the first CPU and the eSIM module in the first electronic device can be bound when the first electronic device is turned on for the first time after leaving the factory, so as to avoid the eSIM module of the first electronic device being disassembled and used normally on other devices.
[0227] In a possible implementation, the first electronic device can obtain the device-card binding function and the device-card verification function when performing a system upgrade via OTA after leaving the factory. In this way, the first CPU and the eSIM module in the electronic device that has been sold are bound through a system upgrade, thereby preventing the eSIM module of the first electronic device that has been sold from being disassembled and used normally on other devices.
[0228] Phase 1: Certificate verification between both parties.
[0229] S502. The first CPU may send the TEE certificate to the eSIM module.
[0230] Among them, TEE certificates can include device certificates and terminal certificates. TEE certificates can be managed by TEE. TEE can also manage authentication root certificates.
[0231] In a possible implementation, the TEE certificate may be a terminal manufacturer root certificate, and the terminal manufacturer root certificate is signed by the terminal manufacturer root public key in the terminal manufacturer root certificate.
[0232] S503. The eSIM module may use the terminal manufacturer's root public key in the terminal manufacturer's root certificate to verify the legitimacy of the device certificate.
[0233] Among them, the eSIM module can be pre-installed with the terminal manufacturer root certificate, the authentication root certificate (CERT.CI.ECDSA), the EUM certificate, the eUICC certificate, the EUM private key corresponding to the EUM certificate, and the eUICC private key (SK.eUICC.ECDSA) corresponding to the eUICC certificate. Among them, the terminal manufacturer root certificate includes the terminal manufacturer root public key, the authentication root certificate (CERT.CI.ECDSA) includes the authentication root public key (PK.CI.ECDSA), the EUM certificate includes the EUM public key, and the eUICC certificate includes the eUICC public key (PK.eUICC.ECDSA). The authentication root private key corresponding to the authentication root certificate (CERT.CI.ECDSA) has signed the EUM certificate. The EUM private key corresponding to the EUM certificate has signed the eUICC certificate.
[0234] Specifically, the eSIM module can decrypt the summary information 1 of the device certificate from the certificate signature of the device certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate. Then, the eSIM module can perform a hash operation on the certificate content in the device certificate to obtain summary information 2. If summary information 2 is the same as summary information 1, the eSIM module can determine that the legitimacy of the device certificate is passed; if summary information 2 is different from summary information 1, the eSIM module can determine that the legitimacy of the device certificate is not passed.
[0235] S504. After verifying the legitimacy of the device certificate, the eSIM module may use the device public key in the device certificate to verify the legitimacy of the terminal certificate.
[0236] Specifically, the eSIM module can decrypt the summary information 3 of the terminal certificate from the certificate signature of the terminal certificate through the device public key in the device certificate. Then, the eSIM module can perform a hash operation on the certificate content in the terminal certificate to obtain summary information 4. If the summary information 3 is the same as the summary information 4, the eSIM module can determine that the legitimacy of the terminal certificate is passed; if the summary information 3 is different from the summary information 4, the eSIM module can determine that the legitimacy of the terminal certificate is not passed.
[0237] S505. The eSIM module may send the EUM certificate and the eUICC certificate to the first CPU after the legitimacy verification of the TEE certificate is passed.
[0238] S506. After receiving the EUM certificate and the eUICC certificate, the first CPU may use the authentication root public key in the authentication root certificate to verify the legitimacy of the EUM certificate.
[0239] Among them, the TEE run by the first CPU can manage the authentication root certificate (CERT.CI.ECDSA), device certificate, and terminal certificate (CERT.OEM.ECDSA). Among them, the authentication root certificate is the root certificate of the card manufacturer (embedded UICCmanufacture, EUM) certificate in the eSIM module, and the EUM certificate is the root certificate of the eUICC certificate. That is, the EUM certificate is signed by the authentication root private key corresponding to the authentication root certificate, and the eUICC certificate is signed by the EUM private key corresponding to the EUM certificate. Among them, the terminal certificate is signed by the device private key corresponding to the device certificate, and the device certificate is signed by the terminal manufacturer root private key corresponding to the terminal manufacturer root certificate.
[0240] Specifically, after receiving the EUM certificate and the eUICC certificate, the first CPU may first decrypt the summary information 5 of the EUM certificate from the certificate signature of the EUM certificate using the authentication root public key in the authentication root certificate. Then, the first CPU may obtain the summary information 6 by performing a hash operation on the certificate content of the EUM certificate. If the summary information 5 is the same as the summary information 6, the first CPU may determine that the legitimacy of the EUM certificate is passed; if the summary information 5 is different from the summary information 6, the first CPU may determine that the legitimacy of the EUM certificate is not passed.
[0241] S507. After the first CPU verifies the legitimacy of the EUM certificate, it can use the EUM public key in the EUM certificate to verify the legitimacy of the eUICC certificate.
[0242] Specifically, the first CPU may first decrypt the summary information 7 of the eUICC certificate from the certificate signature of the eUICC certificate using the EUM public key in the EUM certificate. Then, the first CPU may obtain the summary information 8 by performing a hash operation on the certificate content of the eUICC certificate. If the summary information 7 is the same as the summary information 8, the first CPU may determine that the legitimacy of the eUICC certificate is passed; if the summary information 7 is different from the summary information 8, the first CPU may determine that the legitimacy of the eUICC certificate is not passed.
[0243] S508. After the legitimacy verification of the eUICC certificate passes, the first CPU sends a verification completion notification to the eSIM module.
[0244] The verification completion notification is used to indicate that the eUICC certificate verification has passed.
[0245] Phase 2: Both parties exchange temporary working public keys.
[0246] S509. After sending the verification completion notification to the eSIM module, the first CPU may generate a TEE temporary working public key and a TEE temporary working private key.
[0247] Among them, the TEE temporary working public key and the TEE temporary working private key are a pair of paired public and private keys.
[0248] S510. The first CPU can use the OEM private key to sign the TEE temporary working public key to obtain TEE signature data.
[0249] The OEM private key and the OEM public key are a pair of paired public and private keys. The TEE signature data may include the TEE temporary working public key and the TEE signature value.
[0250] S511. After receiving the verification completion notification, the eSIM module may generate an eUICC temporary working public key and an eUICC temporary working private key.
[0251] The eUICC temporary working public key and the eUICC temporary working private key are a pair of paired public and private keys.
[0252] S512. The eSIM module may use the eUICC private key to sign the eUICC temporary working public key to obtain eUICC signature data.
[0253] The eUICC signature data includes the eUICC temporary working public key and the eUICC signature value.
[0254] S513: The first CPU may send the TEE signature data to the eSIM module.
[0255] S514. The eSIM module may send the eUICC signature data to the first CPU.
[0256] S515. The first CPU may verify the legitimacy of the eUICC signature data through the eUICC public key in the eUICC certificate, and obtain the eUICC temporary working public key after the legitimacy of the eUICC signature data is verified.
[0257] The first CPU may decrypt summary information 9 from the eUICC signature value in the eUICC signature data using the eUICC public key in the eUICC certificate. Then, the first CPU may perform a hash operation on the eUICC temporary working public key in the eUICC signature data to obtain summary information 10. If summary information 10 is the same as summary information 9, the first CPU may determine that the legitimacy verification of the eUICC signature data has passed, and the first CPU may save the eUICC temporary working public key in the eUICC signature data through TEE.
[0258] S516. The eSIM module can verify the legitimacy of the TEE signature data through the OEM public key in the terminal certificate, and obtain the TEE temporary working public key after the legitimacy of the TEE signature data is verified.
[0259] Among them, the eSIM module can decrypt summary information 11 from the TEE signature value in the TEE signature data through the OEM public key in the terminal certificate. Then, the eSIM module can sign the TEE temporary working public key in the TEE signature data to obtain summary information 12. If summary information 12 is the same as summary information 11, the eSIM module can determine that the legitimacy verification of the TEE signature data has passed, and the eSIM module can save the TEE temporary working public key in the TEE signature data.
[0260] Phase 3: Device identification binding.
[0261] S517. The first CPU may generate a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0262] S518. The eSIM module may generate a shared security key (ShS) based on the eUICC temporary working private key and the TEE temporary working public key.
[0263] Since the TEE temporary working public key and TEE temporary working private key are a pair of public-private keys, and the eUICC temporary working public key and eUICC temporary working private key are a pair of public-private keys, the eSIM module and the encryption and decryption TA can use each other's temporary working public key and their own temporary working private key to generate the same shared security key (ShS).
[0264] S519. The first CPU may obtain a device identification.
[0265] The device identification may include a chip identification (chipID) of the first CPU and / or an international mobile equipment identity (IMEI), and the like.
[0266] S520. The first CPU may encrypt the device identification by using the shared security key to obtain binding information.
[0267] S521. The first CPU may send binding information to the eSIM module.
[0268] S522. The eSIM module may decrypt the device identifier from the binding information using the shared security key, and store the device identifier.
[0269] Among them, after the eSIM module stores the device identification, the machine-card binding process is completed.
[0270] In some embodiments, the above step S501 is optional, and the above steps S502 to S522 may be performed on the production line before the electronic device leaves the factory.
[0271] In this application Figure 5 In the illustrated embodiment, the steps executed by the first CPU may be specifically executed by the LPA in the first CPU or by the LPA triggering the encryption and decryption TA in the TEE through the encryption and decryption CA. For example, in steps: S501 and S502, after the LPA detects the first boot after leaving the factory or the first boot after the system upgrade and card binding function, it can obtain the TEE certificate from the TEE and send the TEE certificate to the eSIM module. Steps: S506, S507, S509, S510, S515, S517, S519 and S520 are executed by the LPA triggering the encryption and decryption TA through the encryption and decryption CA. Steps: S509, S513 and S521 are executed by the LPA.
[0272] Figure 6 A schematic diagram of the process of machine-card verification in an eSIM authentication method provided in an embodiment of the present application is shown.
[0273] The eSIM authentication method can be applied to an electronic device including a second CPU and an eSIM module. The second CPU can run REE and TEE. REE can run Cat Service and encryption and decryption CA, and TEE can run encryption and decryption TA. For detailed descriptions of REE and TEE, please refer to the above Figure 2-Figure 4 The embodiments shown will not be described in detail here.
[0274] like Figure 6 As shown, the process of machine card verification may include the following steps:
[0275] S601. When the eSIM module detects that it is powered on again, it can determine whether the eSIM module is bound to a device identifier based on the security status internally.
[0276] In a possible implementation, the eSIM module may also determine whether the eSIM module is bound to a device identifier when receiving a request for performing a communication service.
[0277] S602. If the eSIM module is bound with a device identifier (device identifier 1), a random number A is generated.
[0278] S603. The eSIM module sends a device identification acquisition request to the second CPU, wherein the device identification acquisition request carries a random number A.
[0279] S604. The second CPU may obtain the device identification of the electronic device (device identification 2).
[0280] The device identification of the electronic device may include a chip identification (chipID) and / or IMEI, etc.
[0281] S605. The second CPU may use the shared security key to encrypt the device identification 2 and the random number A to obtain verification information.
[0282] S606. The second CPU sends verification information to the eSIM module.
[0283] S607. The eSIM module may use the shared security key to decrypt the device identification 2 and the random number B from the verification information.
[0284] S608. The eSIM module may determine whether the device identification 2 is the same as the device identification 1 and the random number B is the same as the random number A.
[0285] S609. If the device identification 2 is the same as the device identification 1 and the random number B is the same as the random number A, the machine card verification is passed and the eSIM module can perform mobile communication services normally.
[0286] S610. If the device identification 2 is different from the device identification 1 or the random number B is different from the random number A, the machine card verification fails and the eSIM module is prohibited from performing mobile communication services.
[0287] In the embodiment of the present application, if the machine card verification is passed, it means that the second CPU is connected to the above Figure 5 In the illustrated embodiment, the first CPU is the same CPU, and the first electronic device is the same as the second electronic device.
[0288] If the card verification fails, it means that the second CPU is Figure 5 The first CPU in the illustrated embodiment is not the same CPU, and the second electronic device is not bound to the first electronic device as far as the eSIM module is concerned.
[0289] In a possible implementation, if the eSIM module detects that the machine card authentication fails for more than a specified number of times (for example, 3 times), it is permanently locked.
[0290] In this application Figure 6 In the illustrated embodiment, the steps executed by the second CPU may be specifically executed by Catservice in the second CPU or by Catservice triggering encryption and decryption TA in TEE through encryption and decryption CA. For example, the recipient of the device identification acquisition request in step S603 may be Catsevice, step S604 may be executed by Catservice, step S605 may be executed by Catservice triggering encryption and decryption TA through encryption and decryption CA, and step S606 may be executed by Catservice.
[0291] In a possible implementation, if the eSIM module does not receive verification information sent by the second CPU after sending a device identification acquisition request to the second CPU, the machine card verification fails, and the eSIM module is prohibited from performing mobile communication services.
[0292] Through an eSIM authentication method provided in an embodiment of the present application, a first CPU and an eSIM module in a first electronic device can be implemented. After a system upgrade or the first factory startup, a shared key is first negotiated, and then the first CPU encrypts the device identifier through the shared security key to generate binding information, and sends the binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the binding information through the shared security key pair and store the first device identifier. When the eSIM module is powered on again or before a mobile communication service is to be performed, the eSIM module can allow the second CPU that communicates with the eSIM module at this time to obtain the second device identifier, and encrypt the second device identifier through the shared security key to generate verification information. The eSIM module can decrypt the second device identifier from the verification information through the shared key. If the second device identifier is the same as the first device identifier stored in the eSIM module, the eSIM module can perform mobile communication services normally. If the second device identifier is different from the first device identifier stored in the eSIM module or the eSIM module does not receive the device verification information sent by the second CPU after power off and then on, the eSIM module can prohibit mobile communication services. In this way, the eSIM module in the first electronic device can be prevented from being inserted into other devices and accessing the mobile communication network after being disassembled, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0293] The following specifically describes the process of machine-card binding in the eSIM authentication method provided in an embodiment of the present application in conjunction with signaling.
[0294] Figure 7 A schematic diagram of the signaling interaction process for machine-card binding in an eSIM authentication method provided in an embodiment of the present application is shown.
[0295] The eSIM authentication method can be applied to a first electronic device including a first CPU, a first Modem and an eSIM module. The first CPU can run REE and TEE. LPA and encryption and decryption CA can be run in REE, and encryption and decryption TA can be run in TEE. For specific descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiments shown will not be described in detail here.
[0296] like Figure 7 As shown, the signaling interaction process of machine-card binding in the eSIM authentication method may include the following steps:
[0297] S701. The first CPU detects that the ROM upgrade is completed.
[0298] Among them, after detecting that the ROM upgrade is completed, LPA can call the system upgrade management (OsUpdateManager) module to complete the patch (Patch) upgrade of the eSIM module.
[0299] S702. The eSIM module detects that the patch upgrade is complete.
[0300] After the ROM upgrade is completed, the TEE running on the first CPU can manage the TEE certificate and the authentication root certificate (CERT.CI.ECDSA). Among them, the authentication root certificate is the root certificate of the EUM certificate in the eSIM module, and the EUM certificate is the root certificate of the eUICC certificate. That is, the EUM certificate is signed by the private key corresponding to the authentication root certificate, and the eUICC certificate is signed by the private key corresponding to the EUM certificate.
[0301] In one possible implementation, the TEE certificate may include a device certificate and a terminal certificate (CERT.OEM.ECDSA). The terminal certificate is signed by the device private key corresponding to the device certificate, the device certificate is signed by the terminal manufacturer root private key corresponding to the terminal manufacturer root certificate, and the terminal manufacturer root certificate is self-signed by the terminal manufacturer root private key corresponding to the terminal manufacturer root certificate. In this case, the eSIM module may store the terminal manufacturer root certificate after the Patch upgrade is completed. The eSIM module can use the terminal manufacturer root certificate to verify the TEE certificate.
[0302] In one possible implementation, the TEE certificate may include the terminal manufacturer's root certificate. The terminal manufacturer's root certificate is self-signed by the terminal manufacturer's root private key corresponding to the terminal manufacturer's root certificate. In this case, the eSIM module can store the terminal manufacturer's root certificate after the Patch upgrade is completed. Since the TEE certificate managed by the TEE only includes the terminal manufacturer's root certificate, the LPA does not need to send the terminal manufacturer's root certificate to the eSIM module for verification, and the eSIM module can directly self-verify the stored terminal manufacturer's root certificate.
[0303] In the subsequent embodiments of this application, an example is used to illustrate that the device certificate includes the terminal manufacturer's root certificate, and the LPA does not need to send the terminal manufacturer's root certificate to the eSIM module for verification.
[0304] After the eSIM module patch upgrade is completed, the terminal manufacturer root certificate, authentication root certificate (CERT.CI.ECDSA), EUM certificate, eUICC certificate, EUM private key corresponding to the EUM certificate, and eUICC private key (SK.eUICC.ECDSA) corresponding to the eUICC certificate can be stored. Among them, the terminal manufacturer root certificate includes the terminal manufacturer root public key, the authentication root certificate (CERT.CI.ECDSA) includes the authentication root public key (PK.CI.ECDSA), the EUM certificate includes the EUM public key, and the eUICC certificate includes the eUICC public key (PK.eUICC.ECDSA). The authentication root private key corresponding to the authentication root certificate (CERT.CI.ECDSA) has signed the EUM certificate. The EUM private key corresponding to the EUM certificate has signed the EUM certificate.
[0305] In a possible implementation, the above steps S701 and S702 are optional, and the first CPU may complete subsequent steps S703 to S735 when the first electronic device is turned on for the first time after leaving the factory.
[0306] S703. The eSIM module may send a refresh command to the first Modem.
[0307] The refresh command may be a proactive command.
[0308] S704. The first modem powers on the eSIM module.
[0309] The first modem may re-power on the eSIM module after receiving the eSIM module.
[0310] S705. After powering on the eSIM module, the first modem sends a reset command to the eSIM module.
[0311] After the patch upgrade is completed, the eSIM module can set the value of the bound device identification bit to the initial value. For example, the value of the bound device identification bit can be set to "0x00".
[0312] The bound device identification bit is used to indicate the device binding state of the eSIM module. When the value of the bound device identification bit is the initial value, it indicates that the eSIM module is in an unbound state.
[0313] S706. The eSIM module may detect that the eSIM module has not completed the machine-card binding.
[0314] After resetting, the eSIM module can detect through the binding device identification bit that the eSIM module has not completed the machine-card binding.
[0315] S707. The eSIM module may send a reset response (answer to reset, ATR) to the first Modem.
[0316] The ATR is used to indicate that the eSIM module reset is complete.
[0317] S708. The first CPU may open a logical channel (open channel) with the eSIM module.
[0318] After the first modem receives the ATR, the first modem can complete the necessary machine-card interaction process with the eSIM module.
[0319] Among them, the first modem can trigger LPA to call the machine-card binding logic and open the logical channel between LPA and the eSIM module.
[0320] S709. The first CPU may send an electronic identity acquisition (GetEID) command to the eSIM module.
[0321] Among them, LPA can determine whether the electronic identity (EID) of the eSIM module has been obtained. If the EID of the eSIM module has not been obtained, LPA can send a GetEID command to the eSIM module to obtain the EID of the eSIM module. If the EID of the eSIM module has been obtained, LPA does not need to send a GetEID command to the eSIM module.
[0322] S710. After receiving the electronic identity acquisition command, the eSIM module may return a response command 1 to the first CPU, wherein the response command 1 carries the EID.
[0323] For example, the response command 1 may be “BF3312 5A10 12345634202200001234512345112233”, where the EID is “12345634202200001234512345112233”.
[0324] S711. The first CPU may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0325] Among them, the LPA can send an eUICC random number acquisition command to the eSIM module to obtain the eUICC random number (eUICCChallenge).
[0326] S712. After receiving the eUICC random number acquisition command, the eSIM module may return a response command 2 to the first CPU. The response command 2 may carry the eUICC random number (eUICCChallenge).
[0327] For example, the response command 2 may be “BF2312 8010 76543212BE97D30B2D1FBECA7B7A9668”, where the eUICC random number may be “76543212BE97D30B2D1FBECA7B7A9668”.
[0328] S713. The first CPU may generate a TEE temporary working public key (otPK.TEE.ECKA), a TEE temporary working private key (otSK.TEE.ECKA), a device random number (deviceChallenge), and a host identifier (HostID).
[0329] Among them, LPA can call the encryption and decryption CA, and call the encryption and decryption TA through the encryption and decryption CA to generate a temporary TEE temporary working public key, a TEE temporary working private key and a device random number (deviceChallenge). Among them, the TEE temporary working public key and the TEE temporary working private key can meet the public and private key standard "ECC-256".
[0330] The host identifier (HostID) can be used to indicate the initiator identifier of the session currently established on the logical channel between the LPA and the eSIM module.
[0331] S714. The first CPU may generate TEE package data, wherein the TEE package data includes a TEE temporary working public key, a device random number, an eUICC random number, and a host identifier.
[0332] Among them, LPA can call the encryption and decryption CA, and call the encryption and decryption TA through the encryption and decryption CA to generate the TEE package data.
[0333] S715. The first CPU can use the TEE private key (SK.TEE.ECKA) to sign the TEE package data and obtain the TEE signature value (serverSignature).
[0334] LPA can call the encryption and decryption CA, and through the encryption and decryption CA, call the encryption and decryption TA to sign the TEE package data with the TEE private key (SK.TEE.ECDSA) to obtain the TEE signature value (serverSignature).
[0335] For example, the TEE package data may include, from front to back, the eUICC random number, the device random number, the host identifier, and the TEE temporary working public key.
[0336] Specifically, the encryption and decryption TA can first perform a hash operation on the TEE package data to obtain the summary information of the TEE package data. Then, the encryption and decryption TA can use the TEE private key (SK.TEE.ECDSA) to use the specified signature algorithm (for example, the ECDSA signature algorithm) to encrypt the summary information of the TEE package data into a TEE signature value (serverSignature).
[0337] In one possible implementation, the TEE private key (SK.TEE.ECDSA) may be the OEM private key (SK.OEM.ECDSA) corresponding to the terminal certificate (CERT.OEM.ECDSA) in the aforementioned embodiment, and the TEE public key (PK.TEE.ECDSA) paired with the TEE private key (SK.TEE.ECDSA) may be the OEM public key (PK.OEM.ECDSA) in the terminal certificate (CERT.OEM.ECDSA) in the aforementioned embodiment.
[0338] In one possible implementation, the TEE private key (SK.TEE.ECDSA) may be the terminal manufacturer root private key (SK.OEMCI.ECDSA) corresponding to the terminal manufacturer root certificate in the aforementioned embodiment. The TEE public key (PK.TEE.ECDSA) paired with the TEE private key (SK.TEE.ECDSA) may be the terminal manufacturer root public key (PK.OEMCI.ECDSA) in the terminal manufacturer root certificate in the aforementioned embodiment.
[0339] S716. The first CPU may send a store data command 1 to the eSIM module, wherein the store data command 1 carries TEE signature data, and the TEE signature data may include TEE package data and TEE signature value.
[0340] For example, the storage data command 1 may be:
[0341] "80E29211XX
[0342] 6F800281XX
[0343] 30XX
[0344] 8210
eUICCChallenge
[0345] 8211
deviceChallenge
[0346] 8330
HostID
[0347] 3F4333
otPK.TEE.ECKA
[0348] 3F2444
serverSignature
[0349] S717. After receiving the store data command 1, the eSIM module can verify the TEE signature value and the eUICC random number in the TEE signature data through the TEE public key (PK.TEE.ECDSA) stored in the TEE certificate.
[0350] Among them, the eSIM module can first decrypt summary information A from the TEE signature value through the TEE public key. Then, the eSIM module can perform a hash operation on the TEE package data to generate summary information B. The eSIM module can determine whether summary information A is the same as summary information B. If summary information A is the same as summary information B, the TEE signature value verification is passed. If summary information A is different from summary information B, the TEE signature value verification fails.
[0351] After the TEE signature verification is passed, the eSIM module can determine whether the eUICC random number in the TEE package data is the same as the eUICC random number previously generated by the eSIM module. If the eUICC random number in the TEE package data is the same as the eUICC random number previously generated by the eSIM module, the eUICC random number verification is passed. If the eUICC random number in the TEE package data is different from the eUICC random number previously generated by the eSIM module, the eUICC random number verification fails.
[0352] When the TEE signature value verification fails and / or the eUICC random number verification fails, the eSIM module terminates subsequent steps.
[0353] S718. After the TEE signature value and the eUICC random number are verified, the eSIM module can generate an eUICC temporary working public key (ot.PK.EUICC.ECKA) and an eUICC temporary working private key (ot.SK.EUICC.ECKA).
[0354] S719. The eSIM module may generate eUICC package data, wherein the eUICC package data may include an eUICC temporary working public key and a device random number (deviceChallenge).
[0355] S720. The eSIM module may sign the eUICC package data using the eUICC private key (SK.eUICC.ECDSA) to obtain an eUICC signature value.
[0356] For example, the eUICC package data may be, from front to back, a device random number and an eUICC temporary working public key.
[0357] The eSIM module may first perform a hash operation on the eUICC package data to obtain summary information of the eUICC package data. Then, the eSIM module may use the eUICC private key (SK.eUICC.ECDSA) to encrypt the summary information of the eUICC package data into an eUICC signature value (eUICCSignature) using a specified signature algorithm (e.g., ECDSA signature algorithm).
[0358] S721. The eSIM module may send a response command 3 to the first CPU, wherein the response command 3 carries the eUICC signature data, the EUM certificate (CERT.EUM.ECDSA) and the eUICC certificate (CERT.eUICC.ECDSA).
[0359] The eUICC signature data may include eUICC package data and eUICC signature value.
[0360] For example, response command 3 may be:
[0361] "6F8002 82XXX
[0362] A0 82XXXX
[0363] 30 XX
[0364] 8211
deviceChallenge
[0365] 3F5031
ot.PK.EUICC.ECKA
[0366] 3F5032
eUICCSignature
[0367] 1082XXXX
CERT.eUICC.ECDSA
[0368] 1082YYYY
CERT.EUM.ECDSA
[0369] ”
[0370] Among them, since the content carried in the response command 3 is large and exceeds a certain number (for example, 255 bytes), the first modem can continue to send the Get Response command based on the state word (SW) returned by the eSIM module to obtain the entire response command 3. The first modem can send the entire content of the response command 3 to the LPA.
[0371] S722. After receiving the response command 3, the first CPU may verify the legitimacy of the EUM certificate and the eUICC certificate through the authentication root public key (PK.CI.ECDSA) in the stored authentication root certificate.
[0372] Specifically, LPA can call the encryption and decryption CA, and call the encryption and decryption TA through the encryption and decryption CA to verify the EUM certificate and eUICC certificate through the authentication root public key (PK.CI.ECDSA) in the stored authentication root certificate. Among them, the encryption and decryption TA can first decrypt the summary information 5 of the EUM certificate from the certificate signature of the EUM certificate through the authentication root public key in the authentication root certificate. Then, the encryption and decryption TA can obtain the summary information 6 by performing a hash operation on the certificate content of the EUM certificate. If the summary information 5 is the same as the summary information 6, the encryption and decryption TA can determine that the legitimacy of the EUM certificate is passed. If the summary information 5 is different from the summary information 6, the encryption and decryption TA can determine that the legitimacy of the EUM certificate is not passed.
[0373] After verifying the legitimacy of the EUM certificate, the encryption and decryption TA can decrypt the summary information 7 of the eUICC certificate from the certificate signature of the eUICC certificate by using the EUM public key in the EUM certificate. Then, the encryption and decryption TA can obtain summary information 8 by performing a hash operation on the certificate content of the eUICC certificate. If summary information 7 is the same as summary information 8, the encryption and decryption TA can determine that the legitimacy of the eUICC certificate is passed; if summary information 7 is different from summary information 8, the encryption and decryption TA can determine that the legitimacy of the eUICC certificate is not passed.
[0374] S723. After verifying the legitimacy of the EUM certificate and the eUICC certificate, the first CPU may verify the device random number and the eUICC signature value through the eUICC public key in the eUICC certificate.
[0375] Among them, the encryption and decryption TA can use the eUICC public key (PK.EUICC.ECDSA) to decrypt the summary information C from the eUICC signature value. Then, the encryption and decryption TA can perform a hash operation on the eUICC package data to generate summary information D. The encryption and decryption TA can determine whether the summary information C is the same as the summary information D. If the summary information C is the same as the summary information D, the eUICC signature value verification is passed. If the summary information C is different from the summary information D, the eUICC signature value verification fails.
[0376] After the eUICC signature verification is passed, the encryption and decryption TA can determine whether the device random number in the eUICC package data is the same as the device random number generated before the encryption and decryption TA. If the device random number in the eUICC package data is the same as the device random number generated before the encryption and decryption TA, the device random number verification is passed. If the device random number in the eUICC package data is different from the device random number generated before the encryption and decryption TA, the device random number verification fails.
[0377] When the eUICC signature value verification fails and / or the device random number verification fails, the encryption and decryption TA terminates the subsequent steps.
[0378] S724. After the device random number and the eUICC signature value are verified, the first CPU generates a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key.
[0379] Among them, LPA can call the encryption and decryption TA, and the encryption and decryption TA can generate ShS based on the eUICC temporary working public key and the TEE temporary working private key through the "TEE DeriveKey" interface.
[0380] S725. The first CPU may obtain a device identification, where the device identification may include a chip identification (ChipID) and / or an equipment identification code (IMEI) of the first CPU, etc.
[0381] For example, the LPA may call the file stream “read” interface to read the “ / sys / devices / soc0 / serialnumber” storage path to obtain the chip ID (chipID) of the first CPU.
[0382] S726. The first CPU may encrypt the device identifier and the eUICC random number into binding information through the ShS, the host identifier and the EID, and generate a command message authentication code (C-MAC).
[0383] S727. The first CPU may send a store data command 2 to the eSIM module, wherein the store data command 2 may carry binding information and C-MAC.
[0384] Among them, the encryption and decryption TA can derive the initial message authentication code chaining value (Initial MAC chaining value), session encryption key (S-ENC), and session message authentication code (S-MAC) based on ShS, host identification and EID according to the "BSI TR-03111X9.63 KeyDerivation Function" standard rules.
[0385] like Fig. 8A As shown, the encryption process of the plain text data in the Storedata command can be as follows:
[0386] 1. Encryption and Decryption TA can generate command plaintext data based on the device identity and eUICC random number.
[0387] For example, the command plain text data can be:
[0388] "6F8002 XX
[0389]
Device identification in TLV format
[0390] [eUICC random number in TLV format]".
[0391] 2. Encryption and decryption TA can add padding data after the command plaintext data, so that the total length of the command plaintext data and the padding data is an integer number of bytes. The padding data can start with "80".
[0392] 3. Encryption and decryption TA can determine the integrity check value (ICV) 1 based on the count value 1 and S-ENC through the AES-CBC encryption algorithm. The length of the count value 1 can be 16 bytes.
[0393] 4. Encryption and Decryption TA can determine the command ciphertext data (ciphered command data field, CCDF) based on the command plaintext data after adding padding data, integrity check value 1 and S-ENC through the AEC-CBC encryption algorithm. The command ciphertext data is also the above-mentioned binding information.
[0394] 5. For encryption and decryption, TA can add a data length (Lcc) field before the command ciphertext data, add a flag bit (Tag) before the data length field, and add the Initial MAC chaining value before the flag bit to obtain the C-MAC data to be generated.
[0395] 6. The encryption and decryption TA can determine the C-MAC signature data based on the C-MAC data to be generated and S-MAC through the C-MAC calculation algorithm, and use the highest 8 bytes of data and the lowest 8 bytes of data in the C-MAC signature data as the new message authentication code chaining value (New MAC chaining value). Among them, the C-MAC calculation algorithm can be the "NIST SP 800-38B" standard algorithm.
[0396] 7. Encryption and decryption TA can extract the highest 8 bytes of data from the C-MAC signature data as C-MAC.
[0397] 8. Encryption and decryption TA can return C-MAC and command ciphertext data (CCDF) to LPA through encryption and decryption CA.
[0398] 9. After receiving C-MAC and command ciphertext data (CCDF), LPA can assemble the above-mentioned Storedata command 2. Among them, Storedata command 2 may include a flag bit, a data length field and a data field. Among them, the value of the flag bit can be "86". When the value of the flag bit can be "86", it can be used to indicate that the data structure of the Storedata command 2 located after the flag bit is a TLV data grid structure that complies with the GSMA specification requirements. The data length field is used to indicate the length of the data field. The data field of Storedata command 2 may include command ciphertext data (CCDF) and C-MAC. Among them, the command ciphertext data (CCDF) of Storedata command 2 is the above-mentioned binding information.
[0399] S728. After sending the response command 3 to the first CPU, the eSIM module may generate an ShS based on the TEE temporary working public key and the eUICC temporary working private key.
[0400] S729. After obtaining the Storedata command 2, the eSIM module can verify the C-MAC through the ShS, host identifier and EID, decrypt the binding information, obtain the device identifier and eUICC random number, and verify the decrypted eUICC random number.
[0401] Among them, the eSIM module can derive the Initial MAC chaining value, S-ENC, and S-MAC based on ShS, host identification and EID according to the "BSI TR-03111X9.63 KeyDerivation Function" standard rules.
[0402] Then, the eSIM module adds the flag bit, data length field and command ciphertext in the stored data command 2 after the Initial MAC chaining value to form the MAC verification information, and re-determines the C-MAC based on the MAC verification information and S-MAC and the C-MAC calculation algorithm. The eSIM module can determine whether the re-determined C-MAC is the same as the C-MAC carried in the Storedata command 2. If they are the same, the C-MAC verification passes. The eSIM module can decrypt the device identification and eUICC random number from the command ciphertext data (i.e., binding information) of the Storedata command 2 based on S-ENC and S-MAC.
[0403] The eSIM module can determine whether the eUICC random number decrypted from the Storedata command 2 is the same as the eUICC random number previously generated by the eSIM module. If they are the same, the eUICC random number verification is successful; if they are not the same, the eUICC random number verification is successful.
[0404] S730. After the eSIM module verifies the eUICC random number decrypted from the binding information, it encrypts the device random number into eUICC encrypted data through the shared security key, host identifier and EID, and generates a response message authentication code (R-MAC).
[0405] S731. The eSIM module may send a response command 4 to the first CPU, wherein the response command 4 carries the eUICC encrypted data and R-MAC.
[0406] like Figure 8B As shown, the encryption process of the response plaintext data of Response command 4 can be as follows:
[0407] 1. The eSIM module can assemble the response plaintext data of Response command 4 based on the device random number.
[0408] For example, the response plaintext data can be:
[0409] "6F8002 XX
[0410]
Device random number in TLV format
[0411] ”
[0412] 2. The eSIM module can add padding data after the plain text data response, so that the total length of the plain text data response and the padding data is an integer number of bytes. The padding data can start with "80".
[0413] 3. The eSIM module may determine an integrity check value (ICV) 2 based on the count value 2 and S-ENC by using an AES-CBC encryption algorithm. The length of the count value 2 may be 16 bytes.
[0414] 4. The eSIM module can determine the response ciphertext data (cipheredresponsedatafield, CRDF) based on the response plaintext data after adding the padding data, the integrity check value 2 and S-ENC through the AEC-CBC encryption algorithm. The response ciphertext data is also the above-mentioned eUICC encrypted data.
[0415] 5. The eSIM module can add a data length (Lcc) field before the response ciphertext data, add a flag bit (Tag) before the data length field, and add a New MAC chaining value before the flag bit to obtain the R-MAC data to be generated.
[0416] 6. The eSIM module can determine the R-MAC signature data through the R-MAC calculation algorithm based on the R-MAC data to be generated and S-MAC, and use the highest 8 bytes of data in the R-MAC signature data as the R-MAC. The R-MAC calculation algorithm can be the "NIST SP 800-38B" standard algorithm.
[0417] 7. The eSIM module may assemble a Response command 4. The Response command 4 may include a flag bit, a data length field, and a data field. The data field in the Response command 4 may include a response ciphertext data (CRDF) and an R-MAC. The data length field is used to indicate the length of the data field. The response ciphertext data (CRDF) in the Response command 4 is the eUICC encrypted data.
[0418] S732. The first CPU verifies the R-MAC through the ShS, the host identifier and the EID, decrypts the device random number from the eUICC encrypted data, and verifies the decrypted device random number.
[0419] LPA can call the encryption and decryption TA to verify the R-MAC, decrypt the device random number from the eUICC encrypted data, and verify the decrypted device random number.
[0420] Among them, the process of encrypting and decrypting TA to verify R-MAC can refer to the process of eSIM module verifying C-MAC, which will not be repeated here.
[0421] S733. After the first CPU verifies the decrypted device random number, it sends a store data command 3 to the eSIM module, wherein the store data command 3 is used to indicate the end of the device-card binding interaction.
[0422] The Storedata command 3 includes a flag bit, a data length field and a data field. The data field in the Storedata command 3 includes the encrypted end indication ciphertext and C-MAC after the end indication plaintext (eg, "0F6001 03 03") is encrypted.
[0423] Among them, the encryption process of the end indication ciphertext and the generation process of C-MAC in Storedata command 3 can refer to the above Fig. 8A The encryption process of the command ciphertext data and the generation process of C-MAC in the embodiment shown in the figure. Fig. 8A The count value shown is incremented by 1.
[0424] S734. After receiving the Storedata command 3, the eSIM module sets the device binding state to the bound state and stores the device identification.
[0425] Among them, after receiving the Storedata command 3, the eSIM module can verify the C-MAC in the Storedata command 3, and after verifying that the C-MAC in the Storedata command 3 passes, decrypt the end indication ciphertext in the Storedata command 3 to obtain the end indication plaintext (for example, "0F6001 03 03").
[0426] After obtaining the end indication plain text, the eSIM module can set the value of the bound device identification bit to the first value (for example, "0x12"). When the value of the bound device identification bit is the first value, it indicates that the eSIM module is in a bound state.
[0427] When the eSIM module completes the machine-card binding, in order to improve compatibility, the machine-card verification can be assumed to be successful. The eSIM module can also reset the binding information verification flag to a second value (for example, "0x44"). When the value of the binding information verification flag is the second value, it indicates that the eSIM module binding information verification is completed.
[0428] S735. The eSIM module returns a binding completion status code to the first CPU. The binding completion status code is used to indicate that the machine-card binding is completed.
[0429] The eSIM module may return a binding completion status code to the LPA through status words SW1 and SW2. For example, the values of SW1 and SW2 may be 9000.
[0430] In some embodiments, the above steps S701 and S702 are optional, and the above steps S703 to S735 may be performed on the production line before the electronic device leaves the factory.
[0431] The following specifically introduces the machine-card verification process in the eSIM authentication method provided in the embodiment of the present application in combination with signaling.
[0432] Fig. 9 A schematic diagram of the signaling interaction process of machine-card verification in an eSIM authentication method provided in an embodiment of the present application is shown.
[0433] The eSIM authentication method can be applied to a second electronic device including a second CPU, a second Modem and an eSIM module. The second CPU can run REE and TEE. REE can run Catservice and encryption and decryption CA, and TEE can run encryption and decryption TA. For detailed descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiments shown will not be described in detail here.
[0434] like Fig. 9 As shown, the signaling interaction process of machine card verification in the eSIM authentication method may include the following steps:
[0435] S901. The eSIM module sends a refresh command to the second Modem.
[0436] The refresh command may be a proactive command.
[0437] S902. The second modem powers on the eSIM module.
[0438] The second modem may re-power on the eSIM module after receiving the eSIM module.
[0439] S903. After powering on the eSIM module, the second modem sends a reset command to the eSIM module.
[0440] S904. The eSIM module can detect that the eSIM module has completed the machine-card binding.
[0441] After receiving the reset command, the eSIM module can complete the reset operation and detect that the machine-card binding has been completed through the binding device mark.
[0442] S905. The eSIM module may send an ATR to the second modem.
[0443] The ATR is used to indicate that the eSIM module reset is complete.
[0444] S906. The second modem may send a terminal profile command to the eSIM module.
[0445] S907. The eSIM module may send a setup menu command to the second modem.
[0446] S908. The second modem may send a terminal response (Terminalresponse) command 1 to the eSIM module.
[0447] S909. The eSIM module sends status code 1 (eg, “91xx”) to the second modem.
[0448] Among them, the status code 1 can be used to request Momdem to send a Fetch command to the eSIM module, so as to obtain a Get Input command from the eSIM module.
[0449] S910. The second modem may send a Fetch command to the eSIM module.
[0450] S911. The eSIM module may generate a random number A and generate a message authentication code 1 (MAC1) for the random number A.
[0451] Among them, the eSIM module can perform MAC calculation on the random number A based on the S-MAC and C-MAC calculation algorithms derived from the above ShS (for example, the NISTSP 800-38B standard algorithm), and use the highest 8 bytes of data in the calculation result as MAC1.
[0452] S912. The eSIM module may send a GetInput command to the second Modem, wherein the GetInput command may carry a random number A and MAC1.
[0453] like Fig.10As shown, the Get Input command may include a proactive SIM command tag, a data length field, and a data domain. The proactive SIM command tag may be used for the type of the Get Input command. For example, the proactive SIM command tag in the Get Input command may be "D0". The data length field may be used to indicate the data length of the data domain. The data domain may include a command details field, a device identities field, a text string field, a response length field, and a default text field.
[0454] The text string field may include a text string tag, a text string length field, a text string encoding scheme field, and a text string data field. The text string tag may be used to mark the starting position of the text string field. The text string length field may be used to indicate the total length of data in the data encoding scheme field and the text string data field. The text string encoding scheme field may be used to indicate the encoding scheme of the text string data field.
[0455] The default text (textdefault) field may include a default text tag, a default text length field, a data encoding scheme field, and a default text data domain. The default text tag may be used to mark the starting position of the default text field. The default text length field may be used to indicate the total length of data in the default text encoding scheme field and the default text data domain. The default text encoding scheme field may be used to indicate the encoding scheme of the default text data domain.
[0456] The random number A and MAC1 may be carried in the default text data field of the default text field of the Get Input command, and the text string data field of the text string field may include a specified string (e.g., the ASCII code of "Verify"). The ASCII code of the string "Verify" may be "566572696679".
[0457] For example, the values of the fields in the Get Input command may be as follows:
[0458] The active command SIM card command mark can be "D0";
[0459] The value of the data length field can be "XX";
[0460] The value of the command details field can be "8103012311";
[0461] The value of the device identification field can be "82028122";
[0462] The value of the text string field can be "0D0E01 566572696679";
[0463] The value of the response length field can be "6102FFFF";
[0464] The value of the default text field can be "970901[Random number A][MAC1]".
[0465] In a possible implementation, the random number A and MAC1 may also be carried in the text string data domain in the text string field of the Get Input command, which is not limited here.
[0466] S913. The second modem sends a GetInput command to the second CPU, wherein the GetInput command carries a random number A and MAC1.
[0467] After receiving the Get Input command, the Catservice running in the second CPU parses the data structure of the Get Input command through the command parameter proxy class (CommandParamsFactory). After the command parameter proxy class parses the specified string (for example, the ASCII code of "VerifyBinding") from the text string data field of the Get Input command, the Catservice can parse the default text field in the Get Input command.
[0468] S914. The second CPU verifies MAC1 and obtains device identification 2 after MAC1 passes verification.
[0469] Catservice can call the encryption and decryption CA, and then complete the verification of MAC1 through encryption and decryption TA. The verification of MAC1 can refer to the above Figure 7 The verification process of C-MAC or R-MAC in the illustrated embodiment will not be described in detail here.
[0470] After MAC1 is verified, Catservice can obtain the random number A from the default text field and provide the random number A to the encryption and decryption TA.
[0471] S915. The second CPU encrypts the device identification 2 and the random number A into verification information through ShS, and generates MAC2.
[0472] Among them, Catservice can call the encryption and decryption TA to use ShS to derive S-ENC, S-MAC and initial MACchaining value to encrypt the device identifier 2 and random number A into verification information and generate MAC2. The process of encrypting the device identifier 2 and random number A and generating MAC2 can refer to the above Fig. 8A The process of encrypting and generating C-MAC in the illustrated embodiment will not be described in detail here.
[0473] S916. The second CPU sends a terminal response (Terminalresponse) command 2 to the second modem, wherein the Terminalresponse command 2 carries verification information and MAC2.
[0474] S917. The second modem sends a Terminalresponse command 2 to the eSIM module.
[0475] S918. After receiving the Terminalresponse command 2, the eSIM module verifies MAC2, and after MAC2 verification passes, decrypts the device identification 2 and the random number B from the verification information through ShS.
[0476] The process of eSIM module verifying MAC2 can refer to the above Figure 7 The process of the eSIM module verifying the C-MAC in step S729 in the illustrated embodiment will not be repeated here.
[0477] S919. The eSIM module determines whether the device identification 2 is the same as the device identification 1 bound to the eSIM module and whether the random number B is the same as the random number A.
[0478] S920. If the device identification 2 is the same as the device identification 1 bound to the eSIM module and the random number B is the same as the random number A, the machine-card verification is passed and the eSIM module performs mobile communication services normally.
[0479] If the machine card verification is passed, the eSIM module can set the value of the binding information verification flag to the second value (for example, "0x44"). When the value of the binding information verification flag is set to the second value (for example, "0x44"), it is used to indicate that the eSIM module has completed the machine card verification.
[0480] If the machine card verification passes, the eSIM module can set the value of the binding information verification flag to a third value (e.g., "0x66"). When the value of the binding information verification flag is set to the third value (e.g., "0x66"), it indicates that the eSIM module machine card verification has failed.
[0481] S921. If the device identification 2 is different from the device identification 1 bound to the eSIM module or the random number B is different from the random number A, the machine-card authentication fails and the eSIM module is prohibited from performing mobile communication services.
[0482] For example, when the eSIM module triggers the on-line authentication process, the eSIM module can determine whether the above-mentioned binding information check bit flag indicates that the machine-card verification has been completed and passed the machine-card verification. If the above-mentioned binding information check bit flag indicates that the machine-card verification has been completed and passed the machine-card verification (for example, the value of the binding information check bit flag is "0x44"), the eSIM module completes the on-line authentication process. If the above-mentioned binding information check bit flag indicates that the machine-card verification has not passed the machine-card verification, the eSIM module returns a verification failure response to the second Modem. The verification failure response is used to indicate that the eSIM module is not the eSIM bound to the second CPU.
[0483] In the embodiment of the present application, if the machine card verification is passed, it means that the second CPU is connected to the above Figure 7 In the illustrated embodiment, the first CPU is the same CPU, and the first electronic device is the same as the second electronic device.
[0484] If the card verification fails, it means that the second CPU is Figure 7 The first CPU in the illustrated embodiment is not the same CPU, and the second electronic device is not bound to the first electronic device as far as the eSIM module is concerned.
[0485] In a possible implementation, if the eSIM module does not receive verification information sent by the second CPU after sending a device identification acquisition request to the second CPU, the machine card verification fails, and the eSIM module is prohibited from performing mobile communication services.
[0486] In a possible implementation, if the eSIM module detects that the machine card authentication fails for more than a specified number of times (for example, 3 times), it is permanently locked.
[0487] Through an eSIM authentication method provided in an embodiment of the present application, a first CPU and an eSIM module in a first electronic device can be implemented. After a system upgrade or the first factory startup, a shared key is first negotiated, and then the first CPU encrypts the device identifier through the shared security key to generate binding information, and sends the binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the binding information through the shared security key pair and store the first device identifier. When the eSIM module is powered on again or before a mobile communication service is to be performed, the eSIM module can allow the second CPU that communicates with the eSIM module at this time to obtain the second device identifier, and encrypt the second device identifier through the shared security key to generate verification information. The eSIM module can decrypt the second device identifier from the verification information through the shared key. If the second device identifier is the same as the first device identifier stored in the eSIM module, the eSIM module can perform mobile communication services normally. If the second device identifier is different from the first device identifier stored in the eSIM module or the eSIM module does not receive the device verification information sent by the second CPU after power off and then on, the eSIM module can prohibit mobile communication services. In this way, the eSIM module in the first electronic device can be prevented from being inserted into other devices and accessing the mobile communication network after being disassembled, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0488] The structure of an execution environment of another electronic device provided in an embodiment of the present application is introduced below.
[0489] Fig.11 A schematic diagram of the structure of an execution environment of another electronic device provided in an embodiment of the present application.
[0490] like Fig.11 As shown, the electronic device 100 may include a processing module, a modem, and an eSIM module. Among them, two application environments can be run in the processing module: a common execution environment (REE) and a trusted execution environment (TEE). The processing module can be a CPU or other modules with processing functions, which are not limited here.
[0491] Among them, the application running in REE can be called client application, wherein the client application in REE can include encryption and decryption client application (client application, CA). REE can also run local profile assistant (local profile assistant, LPA), machine card verification module and telephone management module (Telephony Manager), etc. Among them, the machine card verification module can include card application tool service (Catservice) and verification module. Among them, for example, the verification module can be a radio interface layer (radio interface layer, RiL). For the convenience of description, the embodiment of the present application takes the verification module as RiL as an example to illustrate the embodiment of the present application.
[0492] Applications running in TEE can be called trusted applications (TA). Among them, trusted applications in TEE can include encryption and decryption TA, and TEE can also manage some digital certificates issued by digital certificate certification authorities (CertificatiuonAuthority). For example, digital certificates in TEE can include authentication root certificates (CERT.CI.ECDSA), device certificates (CERT.DEVICE.ECDSA) and terminal certificates (CERT.OEM.ECDSA), etc.
[0493] LPA can call the machine-card binding logic and send machine-card binding instructions to the eSIM module. LPA can interact with the eSIM module for machine-card binding through Telephony Manage and Modem. LPA can communicate with the encryption and decryption TA in TEE by calling the encryption and decryption CA, thereby calling the encryption and decryption TA to provide encryption and decryption, certificate verification, and key negotiation services during the machine-card binding interaction.
[0494] The eSIM module can call the machine-card binding logic and send a machine-card verification instruction to the machine-card verification module through the Modem, thereby triggering the machine-card verification interaction between the eSIM module and the machine-card verification module. Among them, the machine-card verification module can communicate with the encryption and decryption TA in the TEE by calling the encryption and decryption CA, thereby calling the encryption and decryption TA to provide encryption and decryption services during the machine-card verification interaction.
[0495] Specifically, the eSIM module can call the machine-card binding logic and interact with the Cat Service through the Modem to verify the legitimacy of the device, thereby triggering the eSIM module to verify the legitimacy of the device (which can also be understood as verifying the legitimacy of the processing module). Among them, the Cat Service can communicate with the encryption and decryption TA in the TEE by calling the encryption and decryption CA, thereby calling the encryption and decryption TA to provide encryption and decryption services in the process of verifying the legitimacy of the device.
[0496] The verification module can call the machine-card binding logic, and interact with the eSIM module through the Modem to verify the legitimacy of the eSIM module, thereby triggering the verification module to verify the legitimacy of the eSIM module. Possibly, the verification module can also trigger the eSIM module to verify the legitimacy of the device (which can also be understood as verifying the legitimacy of the processing module). Among them, the verification module can communicate with the encryption and decryption TA in the TEE by calling the encryption and decryption CA, thereby calling the encryption and decryption TA to provide encryption and decryption services in the process of verifying the legitimacy of the eSIM module.
[0497] For the functional description of other modules, please refer to the above Figure 2 The embodiments shown will not be described in detail here.
[0498] Fig.12 A schematic diagram of a certificate chain in a TEE and an eSIM module of an electronic device provided in an embodiment of the present application is shown.
[0499] like Fig.12 As shown, the TEE can manage the authentication root certificate (CERT.CI.ECDSA) and the terminal certificate (CERT.OEM.ECDSA). Among them, the authentication root certificate is the root certificate of the card manufacturer (embedded UICC manufacture, EUM) certificate in the eSIM module, and the EUM certificate is the root certificate of the eUICC certificate. That is, the EUM certificate is signed by the private key corresponding to the authentication root certificate, and the eUICC certificate is signed by the private key corresponding to the EUM certificate.
[0500] In one possible implementation, the authentication root certificate (CERT.CI.ECDSA) can be a root certificate issued by an operator, a root certificate issued by a third-party organization, a root certificate issued by a terminal manufacturer, a root certificate issued by an EUM manufacturer, and so on.
[0501] The terminal certificate (CERT.OEM.ECDSA) can be self-signed by the OEM private key corresponding to the terminal certificate (CERT.OEM.ECDSA).
[0502] In a possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be issued directly or indirectly by a terminal manufacturer root certificate, or may be issued by an authentication root certificate.
[0503] The eSIM module may be pre-installed with an authentication root certificate (CERT.CI.ECDSA), an EUM certificate and an eUICC certificate, an EUM private key corresponding to the EUM certificate, and an eUICC private key (SK.eUICC.ECDSA) corresponding to the eUICC certificate. The authentication root certificate (CERT.CI.ECDSA) includes an authentication root public key (PK.CI.ECDSA), the EUM certificate includes an EUM public key, and the eUICC certificate includes an eUICC public key (PK.eUICC.ECDSA). The authentication root private key corresponding to the authentication root certificate (CERT.CI.ECDSA) has signed the EUM certificate. The EUM private key corresponding to the EUM certificate has signed the EUM certificate. Optionally, a terminal certificate (CERT.OEM.ECDSA) may also be pre-installed in the eSIM module. In one possible implementation, the eSIM module can obtain the terminal certificate (CERT.OEM.ECDSA) through the server during an OTA upgrade after leaving the factory.
[0504] The LPA can exchange temporary working public keys with the eSIM module.
[0505] in:
[0506] (1) LPA calls TEE to verify the certificate chain of the eSIM module.
[0507] Among them, the certificate chain of the eSIM module includes the authentication root certificate, EUM certificate and eUICC certificate. The eSIM module can send the EUM certificate and eUICC certificate to the LPA. The LPA can call the encryption and decryption CA to further call the encryption and decryption TA, and verify the legitimacy of the EUM certificate through the authentication root public key in the authentication root certificate preset in the TEE. If the verification of the legitimacy of the EUM certificate passes, the encryption and decryption TA can verify the legitimacy of the eUICC certificate through the EUM public key in the EUM certificate. If the verification of the legitimacy of the eUICC certificate passes, the encryption and decryption TA can determine that the verification of the legitimacy of the certificate chain of the eSIM module passes.
[0508] (2) The eSIM module can verify the terminal certificate (CERT.OEM.ECDSA).
[0509] In a possible implementation, if the terminal certificate (CERT.OEM.ECDSA) is self-signed, the eSIM module may use the OEM public key in the terminal certificate (CERT.OEM.ECDSA) to verify the legitimacy of the terminal certificate (CERT.OEM.ECDSA).
[0510] In a possible implementation, if the terminal certificate (CERT.OEM.ECDSA) is passed by the device certificate, the eSIM module can verify the legitimacy of the device certificate through the public key in the root certificate preset in the eSIM module. If the legitimacy of the device certificate is verified, the eSIM module can verify the legitimacy of the terminal certificate (CERT.OEM.ECDSA) through the device public key in the device certificate.
[0511] (3) LPA calls TEE to exchange temporary working public keys with the eSIM module.
[0512] Among them, LPA calls the encryption and decryption TA in TEE to generate TEE temporary working public and private keys, among which the TEE temporary working public and private keys include TEE temporary working public key (otPK.TEE.ECKA) and TEE temporary working private key (otSK.TEE.ECKA).
[0513] LPA calls encryption and decryption TA to sign the TEE temporary working public key (otPK.TEE.ECDSA) through the OEM private key (SK.OEM.ECDSA), and sends the TEE signature data including the TEE temporary working public key (otPK.TEE.ECKA) to the eSIM module.
[0514] The eSIM module can verify the TEE signature data including the TEE temporary working public key (otPK.TEE.ECKA) through the OEM public key, and obtain the TEE temporary working public key (otPK.TEE.ECKA) after successful verification.
[0515] The eSIM module may generate an eUICC temporary working public and private key, wherein the eUICC temporary working public and private key includes an eUICC temporary working public key (otPK.eUICC.ECKA) and an eUICC temporary working private key (otSK.eUICC.ECKA). The eSIM module may sign the eUICC temporary working public key (otPK.eUICC.ECKA) by using the eUICC private key (SK.eUICC.ECDSA), and send the eUICC signature data including the eUICC temporary working public key (otPK.eUICC.ECKA) to the LPA.
[0516] LPA calls encryption and decryption TA to verify the eUICC signature data including the eUICC temporary work public key (otPK.eUICC.ECKA) through the eUICC public key (PK.eUICC.ECDSA), and after successful verification, obtains the eUICC temporary work public key (otPK.TEE.ECKA).
[0517] The eSIM module can generate a shared security key (shared secret key, ShS) based on the TEE temporary working public key (otPK.TEE.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA).
[0518] LPA calls the encryption and decryption TA to generate a shared security key (sharedsecretkey, ShS) based on the eUICC temporary working public key (otPK.eUICC.ECKA) and the TEE temporary working private key (otSK.TEE.ECKA).
[0519] Among them, since the TEE temporary working public key (otPK.TEE.ECKA) and the TEE temporary working private key (otSK.TEE.ECKA) are a pair of public and private keys, and the eUICC temporary working public key (otPK.eUICC.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA) are a pair of public and private keys, the eSIM module and the encryption and decryption TA can use each other's temporary working public key and their own temporary working private key to generate the same shared security key (ShS).
[0520] In one possible implementation, for example, on a production line of an electronic device, after LPA calls the encryption and decryption TA in the TEE to generate TEE temporary working public and private keys, the TEE temporary working public key can be sent directly to the other party.
[0521] In one possible implementation, the authentication root certificate (CERT.CI.ECDSA) can be a root certificate issued by an operator, a root certificate issued by a third-party organization, a root certificate issued by a terminal manufacturer, a root certificate issued by an EUM manufacturer, and so on.
[0522] In a possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be issued directly by the terminal manufacturer's root certificate or by an intermediate certificate issued by the terminal manufacturer's root certificate, or may be issued by an authentication root certificate.
[0523] In one possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be self-signed.
[0524] In a possible implementation, the device manufacturer root certificate (CERT.OEMCI.ECDSA) may be preset in the eSIM module before the electronic device 100 leaves the factory.
[0525] In a possible implementation, the device manufacturer root certificate (CERT.OEMCI.ECDSA) may also be issued by the server to the electronic device 100 during OTA upgrade after the electronic device 100 leaves the factory. The processing module (eg, CPU) in the electronic device 100 is pre-installed in the eSIM module.
[0526] Fig.13 A schematic diagram of the process of one-way binding of machine and card in an eSIM authentication method provided in an embodiment of the present application is shown.
[0527] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. REE and TEE can be run in the first processing module. LPA and encryption and decryption CA can be run in REE, and encryption and decryption TA can be run in TEE. For specific descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiment shown or Fig.11 , Fig.12 The illustrated embodiments will not be described in detail here.
[0528] like Fig.13 As shown, the process of machine-card binding can include two stages: both parties exchange temporary working private keys and device identification binding.
[0529] Phase A1: Both parties exchange temporary working private keys.
[0530] S1301. The first processing module generates a TEE temporary working public key and a TEE temporary working private key.
[0531] The encryption and decryption TA in the TEE of the first processing module can generate a TEE temporary working public key and a TEE temporary working private key, and store the TEE temporary working public key and the TEE temporary working private key in the TEE. The TEE temporary working public key and the TEE temporary working private key are a pair of paired public and private keys.
[0532] S1302. The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key.
[0533] The eUICC temporary working public key and the eUICC temporary working private key are a pair of paired public and private keys.
[0534] S1303. The first processing module sends the TEE temporary working public key to the eSIM module.
[0535] The LPA in the first processing module can obtain the TEE temporary working public key from the TEE by encrypting and decrypting the CA and encrypting and decrypting the TA, and send the TEE temporary working public key to the eSIM module.
[0536] S1304. The eSIM module sends the eUICC temporary working public key to the first processing module.
[0537] The eSIM module can send the temporary working public key of the eUICC to the LPA. The LPA can send the temporary working public key of the eUICC to the encryption and decryption TA through the encryption and decryption CA.
[0538] Phase A2: Device Identity Binding
[0539] S1305. The first processing module generates a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0540] Among them, the encryption and decryption TA can generate a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0541] S1306. The eSIM module generates a shared security key (ShS) based on the eUICC temporary working private key and the TEE temporary working public key.
[0542] Since the TEE temporary working public key and TEE temporary working private key are a pair of public-private keys, and the eUICC temporary working public key and eUICC temporary working private key are a pair of public-private keys, the eSIM module and the encryption and decryption TA can use each other's temporary working public key and their own temporary working private key to generate the same shared security key (ShS).
[0543] S1307: The first processing module obtains a device identification, where the device identification may include a chip identification and / or IMEI of the first processing module.
[0544] Among them, LPA can obtain the device identification.
[0545] S1308. The first processing module encrypts the device identification using the shared security key generated in the TEE to obtain device binding information.
[0546] Among them, LPA can pass the device identity to the encryption and decryption TA through the encryption and decryption CA, and call the encryption and decryption TA to encrypt the device identity through the shared security key to obtain the device binding information. The encryption and decryption TA can return the device binding information to LPA through the encryption and decryption CA.
[0547] S1309. The first processing module sends the device binding information to the eSIM module.
[0548] Among them, LPA can send the encrypted and decrypted CA to the eSIM module.
[0549] S1310. The eSIM module decrypts the device identifier from the device binding information using the shared security key generated by the eSIM module, and stores the device identifier.
[0550] The eSIM authentication method provided by the present application is safe and controllable on the production line, and does not need to consider security issues such as man-in-the-middle attacks. Therefore, when exchanging temporary working public keys between the first processing module and the eSIM module, certificate verification and signature are not required. Thus, the binding of the eSIM module and the device identification is completed.
[0551] Fig.14 A schematic diagram of the process of bidirectional binding of machine and card in an eSIM authentication method provided in an embodiment of the present application is shown.
[0552] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. REE and TEE can be run in the first processing module. LPA and encryption and decryption CA can be run in REE, and encryption and decryption TA can be run in TEE. For specific descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiment shown or Fig.11 , Fig.12 The illustrated embodiments will not be described in detail here.
[0553] like Fig.14 As shown, the process of machine-card binding can include two stages: both parties exchange temporary working private keys and device identification binding.
[0554] Phase B1: Both parties exchange temporary working private keys.
[0555] S1401. The first processing module generates a TEE temporary working public key and a TEE temporary working private key.
[0556] S1402. The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key.
[0557] S1403. The first processing module sends the TEE temporary working public key to the eSIM module.
[0558] S1404. The eSIM module sends the eUICC temporary working public key to the first processing module.
[0559] Phase B2: Device Identity Binding
[0560] S1405. The first processing module generates a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0561] S1406. The eSIM module generates a shared security key (ShS) based on the eUICC temporary working private key and the TEE temporary working public key.
[0562] S1407. The first processing module obtains a device identification, where the device identification may include a CPU chip identification and / or an IMEI.
[0563] S1408. The first processing module encrypts the device identifier using the shared security key generated in the TEE to obtain device binding information.
[0564] S1409. The first processing module sends the device binding information to the eSIM module.
[0565] S1410. The eSIM module decrypts the device identifier from the device binding information using the shared security key generated by the eSIM module, and stores the device identifier.
[0566] Among them, step S1401 to step S1410 can refer to the above Fig.13 Steps S1301 to S1310 in the illustrated embodiment.
[0567] S1411. The eSIM module obtains the eSIM identifier.
[0568] The eSIM identifier may be an embedded universal integrated circuit card identifier (eUICC ID) and / or other identifiers.
[0569] S1412. The eSIM module encrypts the eSIM identifier using the shared security key generated by the eSIM module to obtain the eSIM binding information.
[0570] S1413. The eSIM module sends the eSIM binding information to the first processing module.
[0571] The eSIM module may send the eSIM binding information to the LPA of the first processing module.
[0572] S1414. The first processing module decrypts the eSIM identifier from the eSIM binding information using the shared security key generated in the TEE, and stores the eSIM identifier.
[0573] LPA can pass the eSIM binding information to the encryption and decryption TA through the encryption and decryption CA, and call the encryption and decryption TA to decrypt the eSIM identifier from the eSIM binding information through the shared security key generated in the TEE, and store the eSIM identifier in the TEE.
[0574] The eSIM authentication method provided by the present application is safe and controllable on the production line, and there is no need to consider security issues such as man-in-the-middle attacks. Therefore, when exchanging temporary working public keys between the first processing module and the eSIM module, there is no need to perform certificate verification and signature. Thus, the two-way binding between the eSIM module and the device (specifically, the first processing module) is completed.
[0575] In some embodiments, the above Fig.14 Steps S1401 to S1414 in the embodiment can also be triggered to execute the first processing module and the eSIM module through OTA upgrade after the electronic device leaves the factory, thereby completing the binding of the processing module and the eSIM module in the electronic device even after the electronic device has been sold out of the factory.
[0576] Fig.15 A schematic diagram of the process of bidirectional binding of machine and card in an eSIM authentication method provided in an embodiment of the present application is shown.
[0577] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. REE and TEE can be run in the first processing module. LPA and encryption and decryption CA can be run in REE, and encryption and decryption TA can be run in TEE. For specific descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiment shown or Fig.11 , Fig.12 The illustrated embodiments will not be described in detail here.
[0578] like Fig.15 As shown, the process of machine-card binding can include two stages: both parties exchange temporary working private keys and device identification binding.
[0579] S1501. The first processing module can detect the first startup after leaving the factory, or the first startup after the system upgrades the machine card binding verification function.
[0580] The first processing module can detect the first boot after leaving the factory, or the first boot after the system upgrades the machine-card binding verification function, and trigger the subsequent machine-card binding process. The machine-card binding process may include the following three stages: mutual certificate chain verification, mutual exchange of temporary working public keys, and machine-card two-way binding.
[0581] The first electronic device may be pre-installed with a machine-card binding function and a machine-card verification function before leaving the factory. In this way, the first processing module in the first electronic device can be bound to the eSIM module when the first electronic device is turned on for the first time after leaving the factory, which can prevent the eSIM module of the first electronic device from being disassembled and used normally on other devices, and also prevent the first electronic device from being used normally with the eSIM module of other devices.
[0582] In a possible implementation, the first electronic device can obtain the machine-card binding function and the machine-card verification function when the system is upgraded through the first processing module after leaving the factory. In this way, the first processing module and the eSIM module in the electronic device that has been sold are bidirectionally bound through the system upgrade, thereby preventing the eSIM module of the first electronic device that has been sold from being disassembled and used normally on other devices, and also preventing the first electronic device from being equipped with the eSIM module of other devices for normal use.
[0583] S1502. The eSIM module stores the authentication root certificate, EUM certificate, eUICC certificate and terminal certificate.
[0584] Phase C1: Certificate chain verification phase for both parties
[0585] S1503. The eSIM module verifies the legitimacy of the terminal certificate.
[0586] For details, please refer to the above Fig.12 The embodiments shown will not be described in detail here.
[0587] S1504. The eSIM sends the EUM certificate and the eUICC certificate to the first processing module.
[0588] S1505. After receiving the EUM certificate and the eUICC certificate, the first processing module may use the authentication root public key in the authentication root certificate to verify the legitimacy of the EUM certificate.
[0589] S1506. After the first processing module verifies the legitimacy of the EUM certificate, the EUM public key in the EUM certificate can be used to verify the legitimacy of the eUICC certificate.
[0590] S1507. After the legitimacy verification of the eUICC certificate passes, the first processing module sends a verification completion notification to the eSIM module.
[0591] Phase C2: Both parties exchange temporary working public keys.
[0592] S1508. After sending the verification completion notification to the eSIM module, the first processing module may generate a TEE temporary working public key and a TEE temporary working private key.
[0593] S1509. The first processing module can use the OEM private key to sign the TEE temporary working public key to obtain TEE signature data.
[0594] S1510. After receiving the verification completion notification, the eSIM module may generate an eUICC temporary working public key and an eUICC temporary working private key.
[0595] S1511. The eSIM module may use the eUICC private key to sign the eUICC temporary working public key to obtain eUICC signature data.
[0596] S1512. The first processing module can send the TEE signature data to the eSIM module.
[0597] S1513. The eSIM module may send the eUICC signature data to the first processing module.
[0598] S1514. The first processing module may verify the legitimacy of the eUICC signature data through the eUICC public key in the eUICC certificate, and obtain the eUICC temporary working public key after the legitimacy of the eUICC signature data is verified.
[0599] S1515. The eSIM module can verify the legitimacy of the TEE signature data through the OEM public key in the terminal certificate, and obtain the TEE temporary working public key after the legitimacy of the TEE signature data is verified.
[0600] Phase C3: Two-way binding of machine and card.
[0601] S1516. The first processing module may generate a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0602] S1517. The eSIM module may generate a shared security key (ShS) based on the eUICC temporary working private key and the TEE temporary working public key.
[0603] S1518. The first processing module may obtain a device identification.
[0604] S1519. The first processing module may encrypt the device identification by using a shared security key to obtain device binding information.
[0605] S1520. The first processing module may send the device binding information to the eSIM module.
[0606] S1521. The eSIM module may decrypt the device identification from the device binding information using the shared security key generated by the eSIM module, and store the device identification.
[0607] The above steps S1505 to S1521 can refer to the above Figure 5 Steps S506 to S522 in the illustrated embodiment.
[0608] S1522. The eSIM module obtains the eSIM identifier.
[0609] S1523. The eSIM module encrypts the eSIM identifier using the shared security key to obtain the eSIM binding information.
[0610] S1524. The eSIM module sends the eSIM binding information to the first processing module.
[0611] S1525. The eSIM module decrypts the eSIM identifier from the eSIM binding information using the shared security key generated in the TEE, and stores the eSIM identifier.
[0612] The above steps S1522 to S1525 can refer to the above Fig.14 Steps S1411 to S1414 in the illustrated embodiment are not described in detail here.
[0613] Through the implementation of an eSIM authentication method provided by the present application, the first processing module and the eSIM module in the first electronic device can be implemented. After the system is upgraded or the first time it is turned on after leaving the factory, the temporary public keys of both parties are first verified by the certificate exchange, and then the shared security key is negotiated based on its own temporary private key and the temporary public key of the other party. The first processing module encrypts the device identifier by the shared security key, generates device binding information, and sends the device binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the device binding information through the shared security key pair and store the first device identifier. The eSIM module can also encrypt the first eSIM identifier by the shared security key to generate eSIM binding information. The eSIM module can send the eSIM binding information to the first processing module. The first processing module can use the shared security key to decrypt the first eSIM identifier from the eSIM binding information and store the first device identifier in the TEE. In this way, the two-way binding of the eSIM module and the first processing module can be completed.
[0614] Fig.16 A schematic diagram of the process of two-way verification of machine and card in an eSIM authentication method provided in an embodiment of the present application is shown.
[0615] The eSIM authentication method can be applied to an electronic device including a second CPU and an eSIM module. The second CPU can run REE and TEE. REE can run RiL and encryption and decryption CA, and TEE can run encryption and decryption TA. For detailed descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiment shown or Fig.11 , Fig.12 It should be noted that RiL is only an example for explaining the present application and is not intended to be limiting. When implemented, the function of RiL can also be used in other modules integrated in other REEs.
[0616] like Fig.16 As shown, the process of machine card verification may include the following steps:
[0617] S1601. The TEE of the second processing module stores the eSIM identifier (eSIM identifier 1) of the eSIM module.
[0618] S1602. When the eSIM module detects that it is powered on again, it can determine whether the eSIM module is bound to a device identifier based on the security status internally.
[0619] S1603. If the eSIM module is bound to a device identifier (device identifier 1), execute the subsequent device card verification process.
[0620] Among them, the subsequent machine-card verification process performed by the eSIM module includes subsequent steps S1604 to S1618.
[0621] S1604. The second processing module sends an eUICC random number acquisition command to the eSIM module.
[0622] Among them, the RiL in the REE can send an eUICC random number acquisition command to the eSIM module.
[0623] S1605. The eSIM module sends the eUICC random number A to the second processing module.
[0624] The eSIM module sends the eUICC random number A to RiL in REE.
[0625] S1606. The second processing module obtains the device identification of the electronic device and generates a device random number C.
[0626] The RiL in the REE can obtain the device identification of the electronic device and generate a device random number C.
[0627] S1607. The second processing module may use the shared security key generated by the TEE to encrypt the device identification, the eUICC random number A and the device random number C to obtain verification information.
[0628] RiL in REE can call the encryption and decryption TA in TEE through the encryption and decryption CA, and use the shared security key generated by TEE to encrypt the device identity, eUICC random number A and device random number C to obtain verification information
[0629] S1608. The second processing module sends the device verification information to the eSIM module.
[0630] S1609. The eSIM module may use the shared security key generated by the eSIM module to decrypt the device identification 2, the eUICC random number B, and the device random number D from the device verification information.
[0631] S1610. The eSIM module may determine whether the device identity 2 is the same as the device identity 1 and the eUICC random number B is the same as the eUICC random number A.
[0632] S1611. If the device identification 2 is different from the device identification 1 or the eUICC random number B is different from the eUICC random number A, the device card authentication fails and the eSIM module is prohibited from performing mobile communication services.
[0633] S1612. If the device identification 2 is the same as the device identification 1 and the eUICC random number B is the same as the eUICC random number A, the eSIM module obtains the eSIM identification.
[0634] S1613. The eSIM module uses the shared security key generated by the eSIM module to encrypt the eSIM identifier and the device random number D to obtain the eSIM verification information.
[0635] S1614. The eSIM module sends the eSIM verification information to the second processing module.
[0636] S1615. The second processing module uses the shared security key generated in the TEE to decrypt the eSIM identifier 2 and the device random number E from the eSIM verification information.
[0637] RiL in REE can call encryption and decryption TA in TEE through encryption and decryption CA to decrypt the eSIM identification 2 and device random number E from the eSIM verification information.
[0638] S1616. The second processing module determines whether the eSIM identifier 2 is the same as the eSIM identifier 1 and the device random number E is the same as the device random number C.
[0639] Among them, RiL in REE can determine whether eSIM identifier 2 is the same as eSIM identifier 1 and whether the device random number E is the same as the device random number C.
[0640] S1617. If the eSIM identifier 2 is different from the eSIM identifier 1 or the device random number E is different from the device random number C, the machine card verification fails and the use of the eSIM module for mobile communication services is prohibited.
[0641] In a possible implementation, the eSIM identifier 2 is different from the eSIM identifier 1 or the device random number E is different from the device random number C, and the RiL in the REE can notify the modem to prohibit the use of the eSIM module for mobile communication services.
[0642] S1618. If the eSIM identifier 2 is the same as the eSIM identifier 1 and the device random number E is the same as the device random number C, the machine card verification is passed and the eSIM module can be used normally for mobile communication services.
[0643] If the machine-card verification fails, it indicates that the second processing module is not bound to the eSIM module.
[0644] In a possible implementation, if the second processing module does not receive the eSIM verification information sent by the eSIM module after the eSIM module is powered off and then powered on, or if the eSIM module does not receive the device verification information sent by the second processing module after the eSIM module is powered off and then powered on, the machine-card verification fails.
[0645] In one possible implementation, if the second processing module fails the machine-card verification with the eSIM module, the second processing module may perform the machine-card verification with the eSIM module again. If the machine-card verification fails for more than a specified number of times (for example, 3 times), the second processing module and the eSIM module are permanently locked.
[0646] By implementing an eSIM authentication method provided by the present application, it can be achieved that when the eSIM module is powered on again or before a mobile communication service is to be carried out, the eSIM module can allow the second processing module communicating with the eSIM module to mutually verify the legitimacy of each other. In this way, it can prevent the eSIM module in the electronic device from being disassembled and inserted into other devices to access the mobile communication network, and also prevent the electronic device from being used by the disassembled eSIM module of other devices to access the mobile communication network, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0647] In the embodiment of the present application, the device identifier 1 may be referred to as a first device identifier, the device identifier 2 may be referred to as a second device identifier, the eSIM identifier 1 may be referred to as a first eSIM identifier, the eSIM identifier 2 may be referred to as a second eSIM identifier, the eUICC random number A may be referred to as a first eUICC random number, the eUICC random number B may be referred to as a second eUICC random number, the device random number C may be referred to as a first device random number, the device random number E may be referred to as a second device random number, and the device random number D may be referred to as a third device random number.
[0648] In the embodiment of the present application, the eUICC random number may also be referred to as the eSIM random number. Therefore, the eUICC random number A may be referred to as the first eUICC random number or the first eSIM random number, and the eUICC random number B may be referred to as the second eSIM random number. The eUICC temporary working public key may also be referred to as the eSIM temporary working public key. The eUICC temporary working private key may also be referred to as the eSIM temporary working private key.
[0649] The following specifically describes the process of one-way binding of the machine and the card in the eSIM authentication method provided in the embodiment of the present application in combination with signaling.
[0650] Fig.17 A schematic diagram of the signaling interaction process for one-way binding of a machine and a card in an eSIM authentication method provided in an embodiment of the present application is shown.
[0651] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. REE and TEE can be run in the first processing module. LPA and encryption and decryption CA can be run in REE, and encryption and decryption TA can be run in TEE. For specific descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiment shown or Fig.11 , Fig.12 The illustrated embodiments will not be described in detail here.
[0652] like Fig.17 As shown, the signaling interaction process of machine-card binding in the eSIM authentication method may include the following steps:
[0653] S1701. The first processing module may open a logical channel (open channel) with the eSIM module.
[0654] Among them, the LPA in the first processing module can open a logical channel with the eSIM module.
[0655] S1702. The first processing module may send an electronic identity acquisition (GetEID) command to the eSIM module.
[0656] Among them, the LPA in the first processing module can send an electronic identity acquisition command to the eSIM module.
[0657] S1703. After receiving the electronic identity acquisition command, the eSIM module may return a response command 1 to the first processing module, wherein the response command 1 carries the EID.
[0658] The eSIM module may send the response command 1 to the LPA in the first processing module.
[0659] S1704. The first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0660] The LPA in the first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0661] S1705. After receiving the eUICC random number acquisition command, the eSIM module may return a response command 2 to the first processing module. The response command 2 may carry the eUICC random number (eUICCChallenge).
[0662] The eSIM module may return a response (Response) command 2 to the LPA in the first processing module.
[0663] S1706. The first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA), a TEE temporary working private key (otSK.TEE.ECKA), a device random number (deviceChallenge) and a host identifier (HostID).
[0664] Among them, the LPA in the first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA) and a TEE temporary working private key (otSK.TEE.ECKA) by calling the encryption and decryption TA through the encryption and decryption CA.
[0665] LPA can generate a device random number (deviceChallenge) and obtain a host identifier (HostID).
[0666] S1707. The first processing module sends a store data command 3 to the eSIM module, wherein the store data command 3 carries a device random number, a host identifier, and a TEE temporary working public key.
[0667] Among them, the LPA in the first processing module can send a store data (Storedata) command 3 to the eSIM module.
[0668] S1708. The eSIM module generates an eUICC temporary working public key (ot.PK.EUICC.ECKA) and an eUICC temporary working private key (ot.SK.EUICC.ECKA).
[0669] S1709. The eSIM module sends a response command 5 to the first processing module, wherein the response command 5 carries the eUICC temporary working public key.
[0670] The eSIM module sends a response command 5 to the LPA in the first processing module.
[0671] S1710. The first processing module generates a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key.
[0672] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA, generate a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key, and store the shared security key in the TEE.
[0673] S1711. The first processing module obtains a device identification, wherein the device identification may include a chip identification of the first processing module.
[0674] Among them, the LPA in the first processing module can obtain the device identification.
[0675] S1712. The first processing module encrypts the device identifier and the eUICC random number into device binding information through the ShS, the host identifier and the EID, and generates a command message authentication code (C-MAC).
[0676] Among them, the LPA in the first processing module calls the encryption and decryption TA using ShS, host identifier and EID through the encryption and decryption CA, encrypts the device identifier and eUICC random number into device binding information, and generates a command message authentication code (C-MAC).
[0677] For details, please refer to the above process of encrypting the device identifier and eUICC random number into device binding information. Figure 7 Step S726 in the illustrated embodiment will not be described in detail here.
[0678] S1713. The first processing module sends a store data command 2 to the eSIM module, wherein the store data command 2 carries device binding information and C-MAC.
[0679] The LPA in the first processing module may send a storage data (Storedata) command 2 to the eSIM module. For a detailed description of the storage data (Storedata) command 2, please refer to the above Figure 7 Step S727 in the illustrated embodiment.
[0680] S1714. The eSIM module generates a shared security key (ShS) based on the TEE temporary working public key and the eUICC temporary working private key.
[0681] S1715. After receiving the Storedata command 2, the eSIM module can verify the C-MAC through the ShS, host identifier and EID, decrypt the binding information, obtain the device identifier and eUICC random number, and verify the decrypted eUICC random number.
[0682] S1716. After the eSIM module verifies the eUICC random number decrypted from the binding information, it encrypts the device random number into eUICC encrypted data using the shared security key, host identifier and EID, and generates a response message authentication code (R-MAC).
[0683] S1717. The eSIM module may send a response command 4 to the first processing module, wherein the response command 4 carries the eUICC encrypted data and R-MAC.
[0684] S1718. The first processing module verifies the R-MAC through the ShS, the host identifier and the EID, decrypts the device random number from the eUICC encrypted data, and verifies the decrypted device random number.
[0685] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA, use ShS, host identification and EID to verify R-MAC, and decrypt the device random number from the eUICC encrypted data, and verify the decrypted device random number
[0686] S1719. After the first processing module verifies the decrypted device random number, it sends a store data command 3 to the eSIM module. The store data command 3 is used to indicate the end of the device-card binding interaction.
[0687] S1720. After receiving the Storedata command 3, the eSIM module sets the device binding state to the bound state and stores the device identification.
[0688] S1721. The eSIM module returns a binding completion status code to the first CPU. The binding completion status code is used to indicate that the machine-card binding is completed.
[0689] For detailed description of steps S1714 to S1721, please refer to the aforementioned Figure 7 Steps S728 to S735 in the illustrated embodiment are not described in detail here.
[0690] The eSIM authentication method provided by the present application is safe and controllable on the production line, and does not need to consider security issues such as man-in-the-middle attacks. Therefore, when exchanging temporary working public keys between the first processing module and the eSIM module, certificate verification and signature are not required. Thus, the binding of the eSIM module and the device identification is completed.
[0691] Fig.18 A schematic diagram of the signaling interaction process for bidirectional binding of machine and card in an eSIM authentication method provided in an embodiment of the present application is shown.
[0692] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. REE and TEE can be run in the first processing module. LPA and encryption and decryption CA can be run in REE, and encryption and decryption TA can be run in TEE. For specific descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiment shown or Fig.11 , Fig.12 The embodiments shown will not be described in detail here.
[0693] like Fig.18 As shown, the signaling interaction process of machine-card binding in the eSIM authentication method may include the following steps:
[0694] S1801. The first processing module may open a logical channel (open channel) with the eSIM module.
[0695] Among them, the LPA in the first processing module can open a logical channel with the eSIM module.
[0696] S1802. The first processing module may send an electronic identity acquisition (GetEID) command to the eSIM module.
[0697] Among them, the LPA in the first processing module can send an electronic identity acquisition command to the eSIM module.
[0698] S1803. After receiving the electronic identity acquisition command, the eSIM module may return a response command 1 to the first processing module, wherein the response command 1 carries the EID.
[0699] The eSIM module may send the response command 1 to the LPA in the first processing module.
[0700] S1804. The first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0701] The LPA in the first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0702] S1805. After receiving the eUICC random number acquisition command, the eSIM module may return a response command 2 to the first processing module. The response command 2 may carry the eUICC random number (eUICCChallenge).
[0703] The eSIM module may return a response (Response) command 2 to the LPA in the first processing module.
[0704] S1806. The first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA), a TEE temporary working private key (otSK.TEE.ECKA), a device random number (deviceChallenge) and a host identifier (HostID).
[0705] Among them, the LPA in the first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA) and a TEE temporary working private key (otSK.TEE.ECKA) by calling the encryption and decryption TA through the encryption and decryption CA.
[0706] LPA can generate a device random number (deviceChallenge) and obtain a host identifier (HostID).
[0707] S1807. The first processing module sends a store data command 3 to the eSIM module, wherein the store data command 3 carries a device random number, a host identifier, and a TEE temporary working public key.
[0708] Among them, the LPA in the first processing module can send a store data (Storedata) command 3 to the eSIM module.
[0709] S1808. The eSIM module generates an eUICC temporary working public key (ot.PK.EUICC.ECKA) and an eUICC temporary working private key (ot.SK.EUICC.ECKA).
[0710] S1809. The eSIM module sends a response command 5 to the first processing module, wherein the response command 5 carries the eUICC temporary working public key.
[0711] The eSIM module sends a response command 5 to the LPA in the first processing module.
[0712] S1810. The first processing module generates a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key.
[0713] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA, generate a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key, and store the shared security key in the TEE.
[0714] S1811. The first processing module obtains a device identification, wherein the device identification may include a chip identification of the first processing module.
[0715] Among them, the LPA in the first processing module can obtain the device identification.
[0716] S1812. The first processing module encrypts the device identifier and the eUICC random number into device binding information through the ShS, the host identifier and the EID, and generates a command message authentication code (C-MAC).
[0717] Among them, the LPA in the first processing module calls the encryption and decryption TA using ShS, host identifier and EID through the encryption and decryption CA, encrypts the device identifier and eUICC random number into device binding information, and generates a command message authentication code (C-MAC).
[0718] For details, please refer to the above process of encrypting the device identifier and eUICC random number into device binding information. Figure 7 Step S726 in the illustrated embodiment will not be described in detail here.
[0719] S1813. The first processing module sends a store data command 2 to the eSIM module, wherein the store data command 2 carries device binding information and C-MAC.
[0720] The LPA in the first processing module may send a storage data (Storedata) command 2 to the eSIM module. For a detailed description of the storage data (Storedata) command 2, please refer to the above Figure 7 Step S727 in the illustrated embodiment.
[0721] S1814. The eSIM module generates a shared security key (ShS) based on the TEE temporary working public key and the eUICC temporary working private key.
[0722] S1815. After receiving the Storedata command 2, the eSIM module can verify the C-MAC through the ShS, host identifier and EID, decrypt the binding information, obtain the device identifier and eUICC random number, and verify the decrypted eUICC random number.
[0723] S1816. After the eSIM module verifies the eUICC random number decrypted from the binding information, it encrypts the device random number and the eSIM identity into the eSIM binding information through the shared security key, host identity and EID, and generates a response message authentication code (R-MAC).
[0724] S1817. The eSIM module may send a response command 4 to the first processing module, wherein the response command 4 carries the eSIM binding information and R-MAC.
[0725] For specific steps on the encryption process of eSIM binding information, please refer to the above Figure 7 The encryption process of the eUICC encrypted data in the above embodiment will not be described in detail here.
[0726] S1818. The first processing module verifies the R-MAC through the ShS, the host identifier and the EID, decrypts the device random number and the eSIM identifier from the eSIM binding information, and verifies the decrypted device random number.
[0727] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA, use ShS, host identifier and EID to verify R-MAC, and decrypt the device random number and eSIM identifier from the eSIM binding information, and verify the decrypted device random number.
[0728] Among them, the decryption process of eSIM binding information can refer to the above Figure 7 The process of eUICC decryption in the illustrated embodiment will not be described in detail here.
[0729] S1819. After the first processing module verifies the decrypted device random number, it stores the eSIM identifier in the TEE.
[0730] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA, and store the eSIM identity in the TEE.
[0731] S1820. The first processing module sends a store data command 3 to the eSIM module, wherein the store data command 3 is used to indicate that the machine-card binding interaction is finished.
[0732] S1821. After receiving the Storedata command 3, the eSIM module sets the device binding state to the bound state and stores the device identification.
[0733] S1822. The eSIM module returns a binding completion status code to the first CPU. The binding completion status code is used to indicate that the machine-card binding is completed.
[0734] For detailed description of steps S1820 to S1822, please refer to the aforementioned Figure 7 Steps S733 to S735 in the illustrated embodiment are not described in detail here.
[0735] The eSIM authentication method provided by the present application is safe and controllable on the production line, and there is no need to consider security issues such as man-in-the-middle attacks. Therefore, when exchanging temporary working public keys between the first processing module and the eSIM module, there is no need to perform certificate verification and signature. Thus, the two-way binding between the eSIM module and the device (specifically, the first processing module) is completed.
[0736] Fig.19 A schematic diagram of the signaling interaction process for bidirectional binding of machine and card in an eSIM authentication method provided in another embodiment of the present application is shown.
[0737] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. REE and TEE can be run in the first processing module. LPA and encryption and decryption CA can be run in REE, and encryption and decryption TA can be run in TEE. For specific descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiment shown or Fig.11 , Fig.12 The embodiments shown will not be described in detail here.
[0738] like Fig.19 As shown, the signaling interaction process of machine-card binding in the eSIM authentication method may include the following steps:
[0739] S1901. The first processing module detects that the ROM upgrade is completed.
[0740] S1902. The eSIM module detects that the patch upgrade is complete.
[0741] S1903. The eSIM module may send a refresh command to the first Modem.
[0742] S1904. The first modem powers on the eSIM module.
[0743] S1905. After powering on the eSIM module, the first modem sends a reset command to the eSIM module.
[0744] S1906. The eSIM module can detect that the eSIM module has not completed the machine-card binding.
[0745] S1907. The eSIM module may send an answer to reset (ATR) to the first Modem.
[0746] S1908. The first processing module may open a logical channel (open channel) with the eSIM module.
[0747] S1909. The first processing module may send an electronic identity acquisition (GetEID) command to the eSIM module.
[0748] S1910. After receiving the electronic identity acquisition command, the eSIM module may return a response command 1 to the first processing module, wherein the response command 1 carries the EID.
[0749] S1911. The first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0750] S1912. After receiving the eUICC random number acquisition command, the eSIM module may return a response command 2 to the first processing module. The response command 2 may carry the eUICC random number (eUICCChallenge).
[0751] S1913. The first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA), a TEE temporary working private key (otSK.TEE.ECKA), a device random number (deviceChallenge) and a host identifier (HostID).
[0752] S1914. The first processing module may generate TEE package data, wherein the TEE package data includes a TEE temporary working public key, a device random number, an eUICC random number, and a host identifier.
[0753] S1915. The first processing module can use the TEE private key (SK.TEE.ECKA) to sign the TEE package data and obtain the TEE signature value (serverSignature).
[0754] LPA can call the encryption and decryption CA, and through the encryption and decryption CA, call the encryption and decryption TA to sign the TEE package data with the TEE private key (SK.TEE.ECDSA) to obtain the TEE signature value (serverSignature).
[0755] In one possible implementation, the TEE private key (SK.TEE.ECDSA) may be the OEM private key (SK.OEM.ECDSA) corresponding to the terminal certificate (CERT.OEM.ECDSA) in the aforementioned embodiment, and the TEE public key (PK.TEE.ECDSA) paired with the TEE private key (SK.TEE.ECDSA) may be the OEM public key (PK.OEM.ECDSA) in the terminal certificate (CERT.OEM.ECDSA) in the aforementioned embodiment.
[0756] S1916. The first processing module may send a store data command 1 to the eSIM module, wherein the store data command 1 carries TEE signature data, and the TEE signature data may include TEE package data and TEE signature value.
[0757] S1917. After receiving the store data command 1, the eSIM module can verify the TEE signature value and eUICC random number in the TEE signature data through the TEE public key (PK.TEE.ECDSA) in the stored TEE certificate.
[0758] S1918. After the TEE signature value and eUICC random number are verified, the eSIM module can generate an eUICC temporary working public key (ot.PK.EUICC.ECKA) and an eUICC temporary working private key (ot.SK.EUICC.ECKA).
[0759] S1919. The eSIM module may generate eUICC package data, wherein the eUICC package data may include an eUICC temporary working public key and a device random number (deviceChallenge).
[0760] S1920. The eSIM module can use the eUICC private key (SK.eUICC.ECDSA) to sign the eUICC package data to obtain the eUICC signature value.
[0761] S1921. The eSIM module may send a response command 3 to the first CPU, wherein the response command 3 carries the eUICC signature data, the EUM certificate (CERT.EUM.ECDSA) and the eUICC certificate (CERT.eUICC.ECDSA).
[0762] S1922. After receiving the response command 3, the first processing module can verify the legitimacy of the EUM certificate and the eUICC certificate through the authentication root public key (PK.CI.ECDSA) in the stored authentication root certificate.
[0763] S1923. After verifying the legitimacy of the EUM certificate and the eUICC certificate, the first processing module may verify the device random number and the eUICC signature value through the eUICC public key in the eUICC certificate.
[0764] S1924. After the device random number and the eUICC signature value are verified, the first processing module generates a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key.
[0765] For detailed description of steps S1901 to S1924, please refer to the above Figure 7 Steps S701 to S724 in the illustrated embodiment.
[0766] S1925. The first processing module may obtain a device identifier, wherein the device identifier may include a chip identifier (ChipID) and / or an equipment identification code (IMEI) of the first processing module, etc.
[0767] S1926. The first processing module may encrypt the device identifier and the eUICC random number into device binding information through the ShS, the host identifier and the EID, and generate a command message authentication code (C-MAC).
[0768] S1927. The first processing module may send a store data command 2 to the eSIM module, wherein the store data command 2 may carry device binding information and C-MAC.
[0769] S1928. After sending the response command 3 to the first processing module, the eSIM module may generate ShS based on the TEE temporary working public key and the eUICC temporary working private key.
[0770] S1929. After receiving the Storedata command 2, the eSIM module can verify the C-MAC through ShS, host identification and EID, decrypt the device binding information, obtain the device identification and eUICC random number, and verify the decrypted eUICC random number.
[0771] S1930. After the eSIM module verifies the eUICC random number decrypted from the binding information, it encrypts the device random number and the eSIM identity into the eSIM binding information through the shared security key, the host identity and the EID, and generates a response message authentication code (R-MAC).
[0772] S1931. The eSIM module may send a response command 4 to the first processing module, wherein the response command 4 carries the eSIM binding information and R-MAC.
[0773] S1932. The first processing module verifies the R-MAC through the ShS, the host identifier and the EID, decrypts the device random number and the eSIM identifier from the eSIM binding information, and verifies the decrypted device random number.
[0774] S1933. After the first processing module verifies the decrypted device random number, it stores the eSIM identifier in the TEE.
[0775] S1934. After the first processing module verifies the decrypted device random number, it sends a store data command 3 to the eSIM module. The store data command 3 is used to indicate the end of the device-card binding interaction.
[0776] S1935. After receiving the Storedata command 3, the eSIM module sets the device binding state to the bound state and stores the device identification.
[0777] S1936. The eSIM module returns a binding completion status code to the first processing module. The binding completion status code is used to indicate that the machine-card binding is completed.
[0778] For detailed description of steps S1925 to S1936, please refer to the above Fig.18 Steps S1811 to S1822 in the illustrated embodiment.
[0779] By implementing an eSIM authentication method provided by the present application, the first processing module and the eSIM module in the first electronic device can be implemented. When the first electronic device is on the production line before leaving the factory, or when the system of the first electronic device is upgraded after leaving the factory, or when the first electronic device is turned on for the first time after leaving the factory, the temporary public keys of both parties are first verified, and then the shared security key is negotiated based on its own temporary private key and the temporary public key of the other party. The first processing module encrypts the device identifier by the shared security key, generates device binding information, and sends the device binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the device binding information by the shared security key pair, and store the first device identifier. The eSIM module can also encrypt the first eSIM identifier by the shared security key to generate the eSIM binding information. The eSIM module can send the eSIM binding information to the first processing module. The first processing module can use the shared security key to decrypt the first eSIM identifier from the eSIM binding information, and store the first device identifier in the TEE. In this way, the two-way binding of the eSIM module and the first processing module can be completed.
[0780] Fig. 20 A schematic diagram of the process of two-way verification of machine and card in an eSIM authentication method provided in an embodiment of the present application is shown.
[0781] The eSIM authentication method can be applied to an electronic device including a second CPU and an eSIM module. The second CPU can run REE and TEE. REE can run RiL and encryption and decryption CA, and TEE can run encryption and decryption TA. For detailed descriptions of REE and TEE, please refer to the aforementioned Figure 2-Figure 4 The embodiment shown or Fig.11 , Fig.12 It should be noted that RiL is only an example for explaining the present application and is not intended to be limiting. When implemented, the function of RiL can also be used in other modules integrated in other REEs.
[0782] like Fig. 20 As shown, the process of machine card verification may include the following steps:
[0783] S2001. The second processing module detects that the ROM upgrade is completed.
[0784] S2002. The second processing module detects the bound eSIM identity 1.
[0785] S2003. The eSIM module sends a refresh command to the second Modem.
[0786] The refresh command may be a proactive command.
[0787] S2004. The second modem powers on the eSIM module.
[0788] The second modem may re-power on the eSIM module after receiving the eSIM module.
[0789] S2005. After powering on the eSIM module, the second modem sends a reset command to the eSIM module.
[0790] S2006. The eSIM module can detect that the eSIM module has completed the machine-card binding.
[0791] After receiving the reset command, the eSIM module can complete the reset operation and detect that the machine-card binding has been completed through the binding device mark.
[0792] S2007. The eSIM module may send the ATR to the second processing module via the second modem.
[0793] The ATR is used to indicate that the eSIM module reset is complete.
[0794] S2008. The second processing module sends an eUICC random number acquisition command to the eSIM module.
[0795] Among them, the RiL in the REE can send an eUICC random number acquisition command to the eSIM module.
[0796] S2009. The eSIM module sends the eUICC random number A to the second processing module.
[0797] The eSIM module sends the eUICC random number A to RiL in REE.
[0798] S2010. The second processing module obtains the device identification and the device random number C of the electronic device.
[0799] RiL in REE can be the device identification and device random number C of the electronic device.
[0800] S2011. The second processing module can use the shared security key generated by TEE to encrypt the device identification, eUICC random number A and device random number C to obtain verification information.
[0801] RiL in REE can call the encryption and decryption TA in TEE through the encryption and decryption CA, and use the shared security key generated by TEE to encrypt the device identity, eUICC random number A and device random number C to obtain verification information
[0802] S2012. The second processing module sends the device verification information to the eSIM module.
[0803] S2013. The eSIM module may use the shared security key generated by the eSIM module to decrypt the device identification 2, the eUICC random number B, and the device random number D from the device verification information.
[0804] S2014. The eSIM module may determine whether the device identity 2 is the same as the device identity 1 and the eUICC random number B is the same as the eUICC random number A.
[0805] S2015. If the device identification 2 is different from the device identification 1 or the eUICC random number B is different from the eUICC random number A, the device card authentication fails and the eSIM module is prohibited from performing mobile communication services.
[0806] S2016. If the device identification 2 is the same as the device identification 1 and the eUICC random number B is the same as the eUICC random number A, the eSIM module obtains the eSIM identification.
[0807] S2017. The eSIM module uses the shared security key generated by the eSIM module to encrypt the eSIM identifier and the device random number D to obtain the eSIM verification information.
[0808] S2018. The eSIM module sends the eSIM verification information to the second processing module.
[0809] S2019. The second processing module uses the shared security key generated in the TEE to decrypt the eSIM identifier 2 and the device random number E from the eSIM verification information.
[0810] RiL in REE can call encryption and decryption TA in TEE through encryption and decryption CA to decrypt the eSIM identification 2 and device random number E from the eSIM verification information.
[0811] S2020. The second processing module determines whether the eSIM identifier 2 is the same as the eSIM identifier 1 and the device random number E is the same as the device random number C.
[0812] Among them, RiL in REE can determine whether eSIM identifier 2 is the same as eSIM identifier 1 and whether the device random number E is the same as the device random number C.
[0813] S2021. If the eSIM identifier 2 is different from the eSIM identifier 1 or the device random number E is different from the device random number C, the machine card verification fails and the use of the eSIM module for mobile communication services is prohibited.
[0814] In a possible implementation, the eSIM identifier 2 is different from the eSIM identifier 1 or the device random number E is different from the device random number C, and the RiL in the REE can notify the modem to prohibit the use of the eSIM module for mobile communication services.
[0815] S2022. If the eSIM identifier 2 is the same as the eSIM identifier 1 and the device random number E is the same as the device random number C, the machine card verification is passed and the eSIM module can be used normally for mobile communication services.
[0816] If the machine-card verification fails, it indicates that the second processing module is not bound to the eSIM module.
[0817] In a possible implementation, if the second processing module does not receive the eSIM verification information sent by the eSIM module after the eSIM module is powered off and then powered on, or if the eSIM module does not receive the device verification information sent by the second processing module after the eSIM module is powered off and then powered on, the machine-card verification fails.
[0818] In one possible implementation, if the second processing module fails the machine-card verification with the eSIM module, the second processing module may perform the machine-card verification with the eSIM module again. If the machine-card verification fails for more than a specified number of times (for example, 3 times), the second processing module and the eSIM module are permanently locked.
[0819] By implementing an eSIM authentication method provided by the present application, it can be achieved that when the eSIM module is powered on again or before a mobile communication service is to be carried out, the eSIM module can allow the second processing module communicating with the eSIM module to mutually verify the legitimacy of each other. In this way, it can prevent the eSIM module in the electronic device from being disassembled and inserted into other devices to access the mobile communication network, and also prevent the electronic device from being used by the disassembled eSIM module of other devices to access the mobile communication network, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0820] In some embodiments, an eSIM authentication method is applied to an electronic device including a processing module and a second eSIM module, the method including: a first eSIM identifier sent by a first eSIM module is stored in the TEE of the processing module; after the second eSIM module is powered off and then powered on, the second eSIM module obtains the second eSIM identifier of the second eSIM module; the second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; the second eSIM module sends the eSIM verification information to the processing module; the processing module decrypts the second eSIM identifier from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, the processing module prohibits the use of the second eSIM module for mobile communication services.
[0821] Through an eSIM authentication method provided in an embodiment of the present application, a processing module and a first eSIM module in an electronic device can be implemented to first negotiate a shared key, and then the first eSIM module encrypts the eSIM identifier through the shared security key to generate eSIM binding information, and sends the eSIM binding information to the processing module. The processing module can decrypt the first eSIM identifier from the eSIM binding information through the shared security key pair and store the first eSIM identifier. When the eSIM module is powered on again or before a mobile communication service is to be performed, the processing module can allow the second eSIM module that is communicating with the processing module at this time to obtain the second eSIM identifier, and encrypt the second eSIM identifier through the shared security key to generate eSIM verification information. The processing module can decrypt the second eSIM identifier from the eSIM verification information through the shared security key. If the second eSIM identifier is the same as the first eSIM identifier stored in the TEE of the processing module, it indicates that the second eSIM module and the first eSIM module bound to the processing module are the same eSIM module, so the processing module can perform mobile communication services normally. If the second eSIM identifier is different from the first eSIM identifier stored in the TEE of the processing module or the processing module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, it indicates that the second eSIM module is not the same as the first eSIM module bound to the processing module. Therefore, the processing module can prohibit the use of the second eSIM for mobile communication services. In this way, the eSIM module in the electronic device can be prevented from being inserted into other devices to access the mobile communication network after being disassembled, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0822] In a possible implementation, before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: the processing module receives eSIM binding information sent by the first eSIM module; after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
[0823] In a possible implementation, after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information by using the shared security key generated by the TEE in the processing module.
[0824] In a possible implementation, after receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: after receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
[0825] In a possible implementation, before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: the processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; the processing module receives the eUICC temporary working public key generated by the first processing module; and the processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
[0826] In a possible implementation manner, before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: the processing module receives TEE signature data sent by the first processing module; the processing module verifies the legitimacy of the eUICC signature data by the eUICC public key in the eUICC certificate; the processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: after the processing module verifies the legitimacy of the eUICC signature data, obtaining the eUICC temporary working public key from the eUICC signature data.
[0827] In a possible implementation, before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: the processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; the processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; after the processing module verifies the legitimacy of the EUM certificate, the processing module verifies the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate; after the processing module verifies the legitimacy of the eUICC certificate, the processing module obtains the eUICC public key from the eUICC certificate.
[0828] In a possible implementation, the method further includes: the processing module generating the TEE temporary working private key and the TEE temporary working public key in the TEE, the TEE temporary working private key and the TEE temporary working public key being a pair of public-private keys; the processing module signing the TEE temporary working public key by using the TEE private key to obtain TEE signature data; the processing module sending the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, the eUICC temporary working private key and the eUICC temporary working public key being a pair of public-private keys.
[0829] In a possible implementation, before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: after detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier into the eSIM verification information.
[0830] In a possible implementation, the method also includes: the processing module decrypts a second device random number from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module to perform mobile communication services, specifically including: if the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally uses the second eSIM module to perform mobile communication services.
[0831] For details, the process of binding and verifying the processing module with the eSIM module can be referred to the aforementioned embodiment and will not be described in detail here.
[0832] In some embodiments, an eSIM authentication method provided in an embodiment of the present application can be applied to an electronic device including a second processing module and a second eSIM module, the method comprising: a first eSIM identifier sent by a first eSIM module is stored in the TEE of the second processing module; a first device identifier sent by the first processing module is stored in the second eSIM module; after the second eSIM module is powered off and then powered on again, the second eSIM module obtains the second eSIM identifier of the second eSIM module; the second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; the second eSIM module sends the eSIM verification information to the second processing module; the second processing module obtains the second device identifier, encrypts the second device identifier, and obtains the device verification information; the second processing module A second eSIM identifier is decrypted from the eSIM verification information; the second eSIM module decrypts a second device identifier from the device verification information; if the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier, the electronic device can normally use the second eSIM module for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the second device identifier is different from the first device identifier or the second processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, the electronic device is prohibited from using the second eSIM module for mobile communication services.
[0833] Through an eSIM authentication method provided in an embodiment of the present application, the second processing module is legally bound to the first eSIM module, so the TEE of the second processing module stores the first eSIM identifier of the first eSIM module and the shared security key negotiated with the first eSIM module. The second eSIM module is legally bound to the first processing module, so the second eSIM module stores the first device identifier of the first processing module and the shared security key negotiated with the first processing module. When the second processing module cooperates with the second eSIM module, if the second eSIM module is powered on or before performing mobile communication services, the second processing module can obtain the second device identifier of the second processing module, and use the shared security key to encrypt the second device identifier into device verification information and send it to the second eSIM module. The second eSIM module can also obtain the second eSIM identifier of the second eSIM module, and encrypt the second eSIM identifier into eSIM verification information through the shared security key and send it to the second processing module. The second processing module can decrypt the second eSIM identifier from the eSIM verification information by sharing the security key, and the second eSIM module can decrypt the second device identifier from the device verification information by sharing the security key. If the second eSIM identifier is the same as the first eSIM identifier stored in the TEE of the processing module and the second device identifier is the same as the first device identifier, it indicates that the second eSIM module and the second processing module are bound to each other, so the second processing module can normally use the second eSIM module for mobile communication services. If the second eSIM identifier is different from the first eSIM identifier stored in the TEE of the processing module or the second device identifier is different from the first device identifier or the second processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, it indicates that the second eSIM module and the second processing module are not bound to each other, so the second processing module can prohibit the use of the second eSIM for mobile communication services. In this way, it can prevent the eSIM module in the electronic device from being disassembled and inserted into other devices to access the mobile communication network, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0834] For details, the process of binding and verifying the processing module with the eSIM module can be referred to the aforementioned embodiment and will not be described in detail here.
[0835] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. An embedded user identification eSIM authentication method, characterized in that: Applied to the eSIM module, the method includes: The eSIM module stores the first device identification sent by the first processing module; After detecting that the power is off and then on, the eSIM module receives the device verification information sent by the second processing module; The eSIM module decrypts the second device identifier from the device verification information; If the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally; If the first device identifier is different from the second device identifier or the eSIM module does not receive the device verification information sent by the second processing module after detecting power failure and power-on, the eSIM module is prohibited from performing mobile communication services.
2. The method according to claim 1, characterized in that Before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: The eSIM module receives the device binding information sent by the first processing module; After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information and stores the first device identifier.
3. The method according to claim 2, characterized in that After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information, specifically including: After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information using the shared security key generated by the eSIM module.
4. The method according to any one of claims 1 to 3, characterized in that After receiving the device verification information, the eSIM module decrypts the second device identifier from the device verification information, specifically including: After receiving the device verification information, the eSIM module decrypts the second device identifier from the verification information using the shared security key generated by the eSIM module.
5. The method according to any one of claims 3 or 4, characterized in that Before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key; The eSIM module receives the TEE temporary working public key generated by the first processing module; The eSIM module generates a shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
6. The method according to claim 5, characterized in that Before the eSIM module receives the TEE temporary working public key sent by the first processing module, the method further includes: The eSIM module receives the TEE signature data sent by the first processing module; The eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; The eSIM module receives the TEE temporary working public key sent by the first processing module, specifically including: After verifying the legitimacy of the TEE signature data, the eSIM module obtains the TEE temporary working public key from the TEE signature data.
7. The method according to claim 6, characterized in that Before the eSIM module receives the TEE signature data sent by the first processing module, the method further includes: The eSIM module verifies the legitimacy of the TEE certificate; After verifying the legitimacy of the TEE certificate, the eSIM module obtains the TEE public key from the TEE certificate.
8. The method according to claim 7, characterized in that The TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
9. The method according to claim 7, characterized in that: The TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; Before the eSIM module verifies the legitimacy of the TEE certificate, the method further includes: The eSIM module receives the TEE certificate sent by the first processing module; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the device certificate using the terminal manufacturer's root public key in the terminal manufacturer's root certificate; After verifying the legitimacy of the device certificate, the eSIM module uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
10. The method according to claim 7, characterized in that The TEE certificate is a terminal manufacturer root certificate, and the terminal manufacturer root certificate is pre-set in the eSIM module; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal manufacturer's root certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
11. The method according to any one of claims 7 to 10, characterized in that: The method further comprises: The eSIM module generates the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key are a pair of public and private keys; The eSIM module signs the eUICC temporary working public key by using the eUICC private key to obtain eUICC signature data; The eSIM module sends the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key, and generate a shared security key based on the eUICC temporary working public key and the TEE temporary working private key, wherein the TEE temporary working private key and the TEE temporary working public key are a pair of public-private keys.
12. The method according to claim 11, characterized in that The method further comprises: The eSIM module sends the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by the EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes the eUICC public key, the eUICC public key and the eUICC private key are a pair of public and private keys, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
13. The method according to any one of claims 1 to 12, characterized in that The first device identifier is a chip identifier of the first processing module, and the second device identifier is a chip identifier of the second processing module; or, The first device identifier is the International Mobile Equipment Identity (IMEI) of the first processing module, and the second device identifier is the IMEI of the second processing module; or, The first device identifier is a chip identifier of the first processing module and an IMEI of the first processing module, and the second device identifier is a chip identifier of the second processing module and an IMEI of the second processing module.
14. The method according to any one of claims 1 to 13, characterized in that After detecting that the power is off and then on, the eSIM module receives the device verification information sent by the second processing module, specifically including: After detecting power failure and then power on, the eSIM module sends a first request to the second processing module, where the first request is used to request the second processing module to send a device identification to the eSIM module.
15. The method according to claim 14, characterized in that The first request includes a first eUICC random number, and the first eUICC random number is used to be encrypted by the second processing module together with the second device identifier into the device verification information.
16. The method according to claim 15, characterized in that The method further comprises: The eSIM module decrypts a second eUICC random number from the device verification information; If the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally, specifically including: If the first device identifier is the same as the second device identifier and the second eUICC random number is the same as the first eUICC random number, the eSIM module performs the mobile communication service normally.
17. The method according to claim 14 or 15, characterized in that The first request is a GetInput command.
18. The method according to claim 2, characterized in that The eSIM module receives the device binding information sent by the first processing module, specifically including: The eSIM module receives the device binding information sent by the first processing module through a store data Storedata command.
19. An eSIM authentication method, characterized in that: Applied to an electronic device including an eSIM module and a second processing module, the method includes: The eSIM module stores the first device identification sent by the first processing module; After detecting that power is off and then on, the eSIM module sends a first request to the second processing module, where the first request is used to request the second processing module to send a device identification to the eSIM module; The second processing module obtains a second device identifier; The second processing module encrypts the second device identification to obtain device verification information; The second processing module sends the device verification information to the eSIM module; The eSIM module decrypts the second device identifier from the device verification information; If the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally; If the first device identifier is different from the second device identifier or the eSIM module does not receive the device verification information sent by the second processing module after detecting power failure and power-on, the eSIM module prohibits mobile communication services.
20. The method according to claim 19, characterized in that Before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: The eSIM module receives the device binding information sent by the first processing module; After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information and stores the first device identifier.
21. The method according to claim 20, characterized in that After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information, specifically including: After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information using a shared security key.
22. The method according to any one of claims 19 to 21, characterized in that After receiving the verification information, the eSIM module decrypts the second device identifier from the device verification information, specifically including: After receiving the device verification information, the eSIM module decrypts the second device identifier from the verification information using a shared security key.
23. The method according to claim 21 or 22, characterized in that Before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key; The eSIM module receives the TEE temporary working public key generated by the first processing module; The eSIM module generates the shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
24. The method according to claim 23, characterized in that Before the eSIM module receives the TEE temporary working public key generated by the first processing module, the method further includes: The eSIM module receives the TEE signature data sent by the first processing module; The eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; The eSIM module receives the TEE temporary working public key generated by the first processing module, specifically including: After verifying the legitimacy of the TEE signature data, the eSIM module obtains the TEE temporary working public key from the TEE signature data.
25. The method according to claim 24, characterized in that Before the eSIM module receives the TEE signature data sent by the first processing module, the method further includes: The eSIM module verifies the legitimacy of the TEE certificate; After verifying the legitimacy of the TEE certificate, the eSIM module obtains the TEE public key from the TEE certificate.
26. The method according to claim 25, characterized in that The TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
27. The method according to claim 26, characterized in that The TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
28. The method according to claim 26, characterized in that The TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; Before the eSIM module verifies the legitimacy of the TEE certificate, the method further includes: The eSIM module receives the TEE certificate sent by the first processing module; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the device certificate using the terminal manufacturer's root public key in the terminal manufacturer's root certificate; After verifying the legitimacy of the device certificate, the eSIM module uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
29. The method according to claim 26, characterized in that The TEE certificate is a terminal manufacturer root certificate, and the terminal manufacturer root certificate is pre-set in the eSIM module; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal manufacturer's root certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
30. The method according to any one of claims 26 to 29, characterized in that The method further comprises: The eSIM module generates the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key are a pair of public and private keys; The eSIM module signs the eUICC temporary working public key by using the eUICC private key to obtain eUICC signature data; The eSIM module sends the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key, and generate the shared security key based on the eUICC temporary working public key and the TEE temporary working private key, and the TEE temporary working private key and the TEE temporary working public key are a pair of public-private keys.
31. The method according to claim 30, characterized in that The method further comprises: The eSIM module sends the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by the EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes the eUICC public key, the eUICC public key and the eUICC private key are a pair of public and private keys, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
32. The method according to any one of claims 19 to 31, characterized in that The first device identifier is a chip identifier of the first processing module, and the second device identifier is a chip identifier of the second processing module; or, The first device identifier is the International Mobile Equipment Identity (IMEI) of the first processing module, and the second device identifier is the IMEI of the second processing module; or, The first device identifier is a chip identifier of the first processing module and an IMEI of the first processing module, and the second device identifier is a chip identifier of the second processing module and an IMEI of the second processing module.
33. The method according to any one of claims 19 to 32, characterized in that The first request includes a first eUICC random number; The second processing module encrypts the second device identifier to obtain device verification information, specifically including: The second processing module encrypts the first eUICC random number and the second device identifier to obtain the device verification information.
34. The method according to claim 33, characterized in that The method further comprises: The eSIM module decrypts a second eUICC random number from the device verification information; If the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally, specifically including: If the first device identifier is the same as the second device identifier and the second eUICC random number is the same as the first eUICC random number, the eSIM module performs the mobile communication service normally.
35. The method according to claim 33 or 34, characterized in that The first request is a Get Input command.
36. The method according to claim 20, characterized in that The eSIM module receives the device binding information sent by the first processing module, specifically including: The eSIM module receives the device binding information sent by the first processing module through a Storedata command.
37. An eSIM authentication method, characterized in that: Applied to a processing module, the method comprises: The TEE of the processing module stores the first eSIM identifier sent by the first eSIM module; The processing module receives the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on; The processing module decrypts the second eSIM identifier from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module for mobile communication services; If the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, the processing module prohibits using the second eSIM module for mobile communication services.
38. The method according to claim 37, characterized in that Before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: The processing module receives the eSIM binding information sent by the first eSIM module; After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
39. The method according to claim 38, characterized in that After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the processing module.
40. The method according to any one of claims 37 to 39, characterized in that After receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: After receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
41. The method according to claim 39 or 40, characterized in that Before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: The processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; The processing module receives the eUICC temporary working public key generated by the first processing module; The processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
42. The method according to claim 41, characterized in that Before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: The processing module receives the TEE signature data sent by the first processing module; The processing module verifies the legitimacy of the eUICC signature data through the eUICC public key in the eUICC certificate; The processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: After verifying the legitimacy of the eUICC signature data, the processing module obtains the eUICC temporary working public key from the eUICC signature data.
43. The method according to claim 42, characterized in that Before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: The processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; The processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; After verifying the legitimacy of the EUM certificate, the processing module uses the EUM public key in the EUM certificate to verify the legitimacy of the eUICC certificate; The processing module obtains the eUICC public key from the eUICC certificate after verifying the legitimacy of the eUICC certificate.
44. The method according to claim 42 or 43, characterized in that The method further comprises: The processing module generates the TEE temporary working private key and the TEE temporary working public key in the TEE, wherein the TEE temporary working private key and the TEE temporary working public key are a pair of public and private keys; The processing module signs the TEE temporary working public key through the TEE private key to obtain TEE signature data; The processing module sends the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, and the eUICC temporary working private key and the eUICC temporary working public key are a pair of public-private keys.
45. The method according to any one of claims 37 to 44, characterized in that Before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: After detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier into the eSIM verification information.
46. The method according to claim 45, characterized in that The method further comprises: The processing module decrypts the second device random number from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module to perform mobile communication services, specifically including: If the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally uses the second eSIM module to perform mobile communication services.
47. An eSIM authentication method, characterized in that: Applied to an electronic device including a processing module and a second eSIM module, the method includes: The TEE of the processing module stores the first eSIM identifier sent by the first eSIM module; After the second eSIM module is powered off and then powered on again, obtaining a second eSIM identifier of the second eSIM module; The second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; The second eSIM module sends eSIM verification information to the processing module; The processing module decrypts the second eSIM identifier from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module for mobile communication services; If the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, the processing module prohibits using the second eSIM module for mobile communication services.
48. The method according to claim 47, characterized in that Before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: The processing module receives the eSIM binding information sent by the first eSIM module; After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
49. The method according to claim 48, characterized in that After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the processing module.
50. The method according to any one of claims 47 to 49, characterized in that After receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: After receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
51. The method according to claim 49 or 50, characterized in that Before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: The processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; The processing module receives the eUICC temporary working public key generated by the first processing module; The processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
52. The method according to claim 51, characterized in that Before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: The processing module receives the TEE signature data sent by the first processing module; The processing module verifies the legitimacy of the eUICC signature data through the eUICC public key in the eUICC certificate; The processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: After verifying the legitimacy of the eUICC signature data, the processing module obtains the eUICC temporary working public key from the eUICC signature data.
53. The method according to claim 52, characterized in that Before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: The processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; The processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; After verifying the legitimacy of the EUM certificate, the processing module uses the EUM public key in the EUM certificate to verify the legitimacy of the eUICC certificate; The processing module obtains the eUICC public key from the eUICC certificate after verifying the legitimacy of the eUICC certificate.
54. The method according to claim 52 or 53, characterized in that The method further comprises: The processing module generates the TEE temporary working private key and the TEE temporary working public key in the TEE, wherein the TEE temporary working private key and the TEE temporary working public key are a pair of public and private keys; The processing module signs the TEE temporary working public key through the TEE private key to obtain TEE signature data; The processing module sends the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, and the eUICC temporary working private key and the eUICC temporary working public key are a pair of public-private keys.
55. The method according to any one of claims 37 to 54, characterized in that Before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: After detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier into the eSIM verification information.
56. The method according to claim 55, characterized in that The method further comprises: The processing module decrypts the second device random number from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module to perform mobile communication services, specifically including: If the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally uses the second eSIM module to perform mobile communication services.
57. An eSIM authentication method, characterized in that: Applied to an electronic device including a second processing module and a second eSIM module, the method includes: The TEE of the second processing module stores the first eSIM identifier sent by the first eSIM module; The second eSIM module stores the first device identification sent by the first processing module; After the second eSIM module is powered off and then powered on again, obtaining a second eSIM identifier of the second eSIM module; The second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; The second eSIM module sends eSIM verification information to the second processing module; The second processing module obtains the second device identifier, encrypts the second device identifier, obtains device verification information, and sends the device verification information to the second eSIM module; The second processing module decrypts the second eSIM identifier from the eSIM verification information; The second eSIM module decrypts the second device identifier from the device verification information; If the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier, the electronic device normally uses the second eSIM module for mobile communication services; If the second eSIM identifier is different from the first eSIM identifier or the second device identifier is different from the first device identifier or the second processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information sent by the second processing module after being powered off and then powered on, the electronic device is prohibited from using the second eSIM module for mobile communication services.
58. The method according to claim 57, characterized in that Before the second eSIM module stores the first device identifier sent by the first processing module, the method further includes: The second eSIM module receives the device binding information sent by the first processing module; After receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information and stores the first device identifier.
59. The method according to claim 58, characterized in that After receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information, specifically including: After receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information using the shared security key generated by the second eSIM module.
60. The method according to any one of claims 57 to 59, characterized in that After receiving the device verification information, the second eSIM module decrypts the second device identifier from the device verification information, specifically including: After receiving the device verification information, the second eSIM module decrypts the second device identifier from the verification information using the shared security key generated by the second eSIM module.
61. The method according to any one of claims 61 or 62, characterized in that Before the second eSIM module stores the first device identifier sent by the first processing module, the method further includes: The second eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key; The second eSIM module receives the TEE temporary working public key generated by the first processing module; The second eSIM module generates a shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
62. The method according to claim 61, characterized in that Before the second eSIM module receives the TEE temporary working public key sent by the first processing module, the method further includes: The second eSIM module receives the TEE signature data sent by the first processing module; The second eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; The second eSIM module receives the TEE temporary working public key sent by the first processing module, specifically including: After verifying the legitimacy of the TEE signature data, the second eSIM module obtains the TEE temporary working public key from the TEE signature data.
63. The method according to claim 62, characterized in that Before the second eSIM module receives the TEE signature data sent by the first processing module, the method further includes: The second eSIM module verifies the legitimacy of the TEE certificate; After verifying the legitimacy of the TEE certificate, the second eSIM module obtains the TEE public key from the TEE certificate.
64. The method according to claim 63, characterized in that The TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; The second eSIM module verifies the legitimacy of the TEE certificate, specifically including: The second eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
65. The method according to claim 63, characterized in that The TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; Before the eSIM module verifies the legitimacy of the TEE certificate, the method further includes: The second eSIM module receives the TEE certificate sent by the first processing module; The second eSIM module verifies the legitimacy of the TEE certificate, specifically including: The second eSIM module verifies the legitimacy of the device certificate using the terminal manufacturer root public key in the terminal manufacturer root certificate; After verifying the legitimacy of the device certificate, the second eSIM module uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
66. The method according to claim 63, characterized in that The TEE certificate is a terminal manufacturer root certificate, and the terminal manufacturer root certificate is preset in the second eSIM module; The second eSIM module verifies the legitimacy of the TEE certificate, specifically including: The second eSIM module verifies the legitimacy of the terminal manufacturer's root certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
67. The method according to any one of claims 63 to 66, characterized in that The method further comprises: The second eSIM module generates the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key are a pair of public and private keys; The second eSIM module signs the eUICC temporary working public key by using the eUICC private key to obtain eUICC signature data; The second eSIM module sends the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key, and generate a shared security key based on the eUICC temporary working public key and the TEE temporary working private key, and the TEE temporary working private key and the TEE temporary working public key are a pair of public-private keys.
68. The method according to claim 67, characterized in that The method further comprises: The second eSIM module sends the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by the EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes the eUICC public key, the eUICC public key and the eUICC private key are a pair of public and private keys, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
69. The method according to any one of claims 59 to 68, characterized in that The first device identifier is a chip identifier of the first processing module, and the second device identifier is a chip identifier of the second processing module; or, The first device identifier is the International Mobile Equipment Identity (IMEI) of the first processing module, and the second device identifier is the IMEI of the second processing module; or, The first device identifier is a chip identifier of the first processing module and an IMEI of the first processing module, and the second device identifier is a chip identifier of the second processing module and an IMEI of the second processing module.
70. The method according to any one of claims 59 to 69, characterized in that Before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the second processing module, the method further includes: The second processing module receives the eSIM binding information sent by the first eSIM module; After receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
71. The method according to claim 70, characterized in that After receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: After receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the second processing module.
72. The method according to any one of claims 69 to 71, characterized in that After receiving the eSIM verification information, the second processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: After receiving the eSIM verification information, the second processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
73. The method according to claim 71 or 72, characterized in that Before the second processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: The second processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; The second processing module receives the eUICC temporary working public key generated by the first processing module; The second processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
74. The method according to claim 73, characterized in that Before the second processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: The second processing module receives the TEE signature data sent by the first processing module; The second processing module verifies the legitimacy of the eUICC signature data by using the eUICC public key in the eUICC certificate; The second processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: The second processing module obtains the eUICC temporary working public key from the eUICC signature data after verifying the legitimacy of the eUICC signature data.
75. The method according to claim 74, characterized in that Before the second processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: The second processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; The second processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; After verifying the legitimacy of the EUM certificate, the second processing module uses the EUM public key in the EUM certificate to verify the legitimacy of the eUICC certificate; The second processing module obtains the eUICC public key from the eUICC certificate after verifying the legitimacy of the eUICC certificate.
76. The method according to claim 74 or 75, characterized in that The method further comprises: The second processing module generates the TEE temporary working private key and the TEE temporary working public key in the TEE, wherein the TEE temporary working private key and the TEE temporary working public key are a pair of public and private keys; The second processing module signs the TEE temporary working public key by using the TEE private key to obtain TEE signature data; The second processing module sends the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, and the eUICC temporary working private key and the eUICC temporary working public key are a pair of public-private keys.
77. The method according to any one of claims 59 to 76, characterized in that The method further comprises: After detecting that the second eSIM module is powered off and then powered on, the second processing module sends an eUICC random number acquisition command to the second processing module, where the eUICC random number acquisition command is used to request the second processing module to send an eUICC random number to the second processing module; After receiving the eUICC random number acquisition command, the second eSIM module generates a first eUICC random number and sends the first eUICC random number to the second processing module; The second processing module generates a first device random number; The second processing module acquires the second device identifier, encrypts the second device identifier, and obtains device verification information, specifically including: The second processing module obtains the second device identifier, and encrypts the second device identifier, the first device random number, and the first eUICC random number to obtain device verification information.
78. The method according to claim 77, characterized in that The method further comprises: After receiving the device verification information, the second eSIM module decrypts the second eUICC random number and the third device random number from the device verification information; The second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information, specifically including: The second eSIM module encrypts the second eSIM identifier and the third device random number to obtain the eSIM verification information.
79. The method according to claim 78, characterized in that The method further comprises: The second processing module decrypts the second device random number from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier, the electronic device normally uses the second eSIM module to perform a mobile communication service, specifically including: If the second eSIM identifier is the same as the first eSIM identifier, the second device identifier is the same as the first device identifier, the second device random number is the same as the first device random number, and the second eUICC random number is the same as the first eUICC random number, the electronic device normally uses the second eSIM module for mobile communication services.
80. An eSIM module, characterized in that: include: A processing circuit, a storage circuit and an interface circuit, wherein the storage circuit is used to store data and code instructions, and the interface circuit is used to send commands to the processing module through a modem or receive commands sent by the processing module through the modem; the processing circuit is used to run the code instructions to execute the method as described in any one of claims 1-18.
81. A processing module, characterized in that include: A processing circuit, a storage circuit and an interface circuit, wherein the storage circuit is used to store data and code instructions, and the interface circuit is used to send commands to the eSIM module through a modem or receive commands sent by the eSIM module through the modem; the processing circuit is used to run the code instructions to execute the method as described in any one of claims 37-46.
82. An electronic device, characterized in that: include: An eSIM module, a second processing module and one or more memories, wherein the one or more memories are coupled to the second processing module, and the one or more memories are used to store a computer program, so that when the second processing module executes the computer program, the electronic device executes the method as described in any one of claims 19-36.
83. An electronic device, characterized in that: include: A second eSIM module, a processing module and one or more memories, wherein the one or more memories are coupled to the processing module, and the one or more memories are used to store a computer program, so that when the processing module executes the computer program, the electronic device executes the method as described in any one of claims 47-56.
84. An electronic device, characterized in that: include: A second eSIM module, a second processing module and one or more memories, wherein the one or more memories are coupled to the second processing module, and the one or more memories are used to store a computer program, so that when the second processing module executes the computer program, the electronic device executes the method as described in any one of claims 57-79.
85. A computer storage medium, characterized in that It comprises computer instructions, which, when executed on a processor of an electronic device, cause the electronic device to execute a method as claimed in any one of claims 47 to 56.
86. A computer storage medium, characterized in that It comprises computer instructions, which, when executed on a processor of an electronic device, cause the electronic device to execute a method as claimed in any one of claims 57 to 79.