User equipment control method and device based on eSIM (Embedded Subscriber Identity Module) and user equipment
By pre-storing application permission control information in eSIM and performing signature verification, the problem of improper application permission management in user equipment is solved, and a secure and differentiated application permission management is achieved.
Patent Information
- Application Number
- CN202510082823.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-23
AI Technical Summary
The prior art improper management of the permissions of applications in user equipment leads to security problems, especially when application updates or device information acquisition, the permissions of applications to access user equipment cannot be differentiatedly managed and controlled.
The user equipment control method based on eSIM is adopted to store application permission control information in advance through eSIM, including application unique identification, access object information and permission information. This method receives the encrypted application access request, decrypts and verifies the application signature information, performs permission verification based on the pre-stored permission information, and returns the verification result.
It realizes the management and control of application access rights relatively safely, avoids illegal applications accessing user devices, ensures the accuracy of application authentication and permission verification, and provides differentiated permission management capabilities.
Smart Images

Figure CN120034860A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of communication technology, and in particular, relates to a user equipment control method, device and user equipment based on eSIM. Background Art
[0002] During the process of installing or running an application on a user's device, the application may request to obtain some permission information of the user's device, such as permission to access identifier information, namely mobile phone number, permission to obtain biometric information, namely fingerprint information and face information, permission to obtain content information, namely photos, videos, and text messages, permission to obtain function information, namely camera shooting, etc.
[0003] In this way, if the application permissions are not managed properly, security issues will arise. Summary of the invention
[0004] The embodiments of the present application provide a user equipment control method, device and user equipment based on eSIM, which can manage and control the access rights of applications more securely.
[0005] In a first aspect, an embodiment of the present application provides a user equipment control method based on eSIM, which is applied to eSIM, and the eSIM pre-stores application permission control information, the application permission control information including an application unique identifier, access object information and permission information corresponding to the application unique identifier; the method includes: receiving an encrypted application access request, the application access request carries an application unique identifier of a target application, application signature information of the target application and access object information of a target access object; decrypting the application access request to obtain a decrypted application access request; based on a pre-stored signature certificate of the target application, verifying the application signature information in the decrypted application access request; if the verification passes, performing a permission check on the application access request based on the application permission control information to obtain a permission check result, the permission check result being used to characterize whether the target application has permission to access the target access object; and returning the permission check result for the application access request.
[0006] In an optional implementation of the first aspect, returning a permission verification result for an application access request includes: signing and encrypting the permission verification result to obtain a signed and encrypted permission verification result; sending the signed and encrypted permission verification result to a target application so that the target application decrypts the signed and encrypted permission verification result, and verifies the signature information in the decrypted permission verification result based on a pre-stored eSIM signature certificate, and obtains the permission verification result after the verification passes.
[0007] In an optional implementation of the first aspect, the method also includes: receiving an encrypted control information update request, the control information update request carrying at least an application unique identifier of the target application, access object information to be updated, and permission information to be updated; decrypting the control information update request to obtain a decrypted control information update request; and updating the application permission control information based on the decrypted control information update request.
[0008] In an optional implementation of the first aspect, the control information update request is sent by the server through a user equipment management system, and receiving the encrypted control information update request includes: receiving an encrypted device authentication instruction, the device authentication instruction carrying the signature information of the user equipment management system; decrypting the device authentication instruction to obtain the signature information of the user equipment management system; verifying the signature information of the user equipment management system; and if the verification is successful, establishing a secure channel between the user equipment management system and the server, and the secure channel is used to receive the control information update request.
[0009] In an optional implementation of the first aspect, the process of pre-storing application permission control information by the eSIM includes: receiving an encrypted application permission configuration request, the application permission configuration request carries application permission control information, the application permission configuration request is sent by the server through the user equipment management system, and the application permission control information is generated by the server based on a device access request sent by the target application; storing the application permission control information.
[0010] In a second aspect, an embodiment of the present application provides a user equipment control method based on eSIM, which is applied to a target application, where the target application runs on a user equipment, the user equipment includes an eSIM, and the eSIM pre-stores application permission control information, where the application permission control information includes an application unique identifier, access object information corresponding to the application unique identifier, and permission information; the user equipment control method based on eSIM includes: sending an encrypted application access request to the eSIM, where the application access request carries the application unique identifier of the target application, the application signature information of the target application, and the access object information of the target access object, so that the eSIM decrypts the application access request to obtain the decrypted application access request, and based on the pre-stored signature certificate of the target application, verifies the application signature information in the decrypted application access request, and if the verification passes, performs permission verification on the application access request based on the application permission control information to obtain a permission verification result; if the permission verification result indicates that the target application has permission to access the target access object, accesses the target access object.
[0011] In an optional implementation of the second aspect, before accessing the target access object, the method further includes: receiving a signed and encrypted authority verification result sent by the eSIM.
[0012] In an optional implementation of the second aspect, the method further includes: when the permission verification result indicates that the target application does not have permission to access the target access object, sending an access permission application request to the server, the access permission application request carries at least an application unique identifier of the target application and access object information, so that the server sends a control information update request to the user equipment management system, the control information update request is used to enable the user equipment management system to update the application permission control information pre-stored in the eSIM.
[0013] In an optional implementation of the second aspect, accessing a target access object includes: obtaining access permission data when a permission verification result is used to characterize that a target application has permission to access the target access object; generating an access instruction based on the access permission data and application signature information of the target application; sending the access instruction to a user device management system so that the user device management system verifies the application signature information in the access instruction based on a pre-stored signature certificate of the target application, and if the verification passes, sending data corresponding to the target access object to the target application based on the obtained access permission data; and receiving the data of the target access object.
[0014] In a third aspect, an embodiment of the present application provides a user equipment control method based on eSIM, which is applied to a user equipment, the user equipment runs a target application, the user equipment includes an eSIM, and the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information corresponding to the application unique identifier, and permission information; the method includes: receiving an access instruction sent by the target application; based on the access instruction, obtaining access permission data, the access permission data is obtained when the permission verification result indicates that the target application has the permission to access the target access object, the permission verification result is that the eSIM decrypts the application access request, obtains the decrypted application access request, and based on the pre-stored signature certificate of the target application, verifies the application signature information in the decrypted application access request, and if the verification passes, verifies the application access request based on the application permission control information; if the access permission data is obtained, sends the data of the target access object to the target application.
[0015] In an optional embodiment of the third aspect, the access instruction carries at least application signature information of the target application, and based on the access instruction, obtaining access permission data includes: verifying the application signature information in the access instruction based on a pre-stored signature certificate of the target application; if the verification passes, determining whether there is access permission data in the access instruction; if there is access permission data in the access instruction, obtaining the access permission data.
[0016] In an optional embodiment of the third aspect, the method further includes: receiving an encrypted control information update request, the control information update request being used to update application permission control information pre-stored in the eSIM; and updating the application permission control information pre-stored in the eSIM based on the control information update request.
[0017] In an optional embodiment of the third aspect, receiving an encrypted control information update request includes: sending an encrypted device authentication instruction to the eSIM, enabling the eSIM to decrypt the device authentication instruction, obtaining signature information of the user equipment management system, and verifying the signature information of the user equipment management system based on a pre-stored signature certificate of the user equipment management system; receiving encrypted response data sent by the eSIM, the response data carrying the signature information of the eSIM; verifying the signature information in the response data based on a pre-stored signature certificate of the eSIM; if the verification passes, establishing a secure channel with the server, the secure channel being used to receive the control information update request.
[0018] In a fourth aspect, an embodiment of the present application provides a user equipment control system based on eSIM, the system comprising a user equipment and a server, the user equipment running a target application, the user equipment comprising an eSIM, the eSIM pre-stored with application permission control information, the application permission control information comprising an application unique identifier, access object information and permission information corresponding to the application unique identifier; wherein the server is used to generate application permission control information based on a device access request sent by the target application, and send the application permission control information to the eSIM through a user equipment management system; the eSIM is used to receive an encrypted application access request, decrypt the application access request, obtain a decrypted application access request, and verify the application signature information in the decrypted application access request based on a pre-stored signature certificate of the target application. If the verification passes, the application access request is subjected to permission verification based on the application permission control information to obtain a permission verification result, the application access request carries the application unique identifier of the target application, the application signature information of the target application and the access object information of the target access object, and the permission verification result is used to characterize whether the target application has permission to access the target access object.
[0019] In a fifth aspect, an embodiment of the present application provides a user equipment control device based on eSIM, which is applied to eSIM, and the eSIM pre-stores application permission control information, the application permission control information including an application unique identifier, access object information and permission information corresponding to the application unique identifier; the user equipment control device based on eSIM includes: a first receiving module, used to receive an encrypted application access request, the application access request carries the application unique identifier of the target application, the application signature information of the target application and the access object information of the target access object; a decryption module, used to decrypt the application access request and obtain the decrypted application access request; a verification module, used to verify the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application; a verification module, used to perform permission verification on the application access request based on the application permission control information when the verification passes, and obtain a permission verification result, the permission verification result is used to characterize whether the target application has the permission to access the target access object; a return module, used to return the permission verification result for the application access request.
[0020] In a sixth aspect, an embodiment of the present application provides a user equipment control device based on eSIM, which is applied to a target application, where the target application runs on a user equipment, the user equipment includes an eSIM, and the eSIM pre-stores application permission control information, where the application permission control information includes an application unique identifier, access object information corresponding to the application unique identifier, and permission information; the user equipment control device based on eSIM includes: a first sending module, used to send an encrypted application access request to the eSIM, where the application access request carries the application unique identifier of the target application, the application signature information of the target application, and the access object information of the target access object, so that the eSIM decrypts the application access request to obtain the decrypted application access request, and verifies the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application. If the verification passes, the application access request is subjected to permission verification based on the application permission control information to obtain a permission verification result; an access module, used to access the target access object when the permission verification result indicates that the target application has permission to access the target access object.
[0021] In the seventh aspect, an embodiment of the present application provides a user equipment control device based on eSIM, which is applied to a user equipment, the user equipment runs a target application, the user equipment includes an eSIM, and the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information corresponding to the application unique identifier, and permission information; the user equipment control device based on eSIM includes: a second receiving module, used to receive an access instruction sent by the target application; an acquisition module, used to obtain access permission data based on the access instruction, the access permission data is obtained when the permission verification result indicates that the target application has the permission to access the target access object, the permission verification result is that the eSIM decrypts the application access request, obtains the decrypted application access request, and verifies the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application. If the verification passes, the application access request is subjected to permission verification based on the application permission control information; a second sending module, used to send the data of the target access object to the target application when the access permission data is obtained.
[0022] In an eighth aspect, an embodiment of the present application provides a computer storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, an eSIM-based user equipment control method is implemented as described in any one of the first aspect, the second aspect, or the third aspect.
[0023] In the ninth aspect, an embodiment of the present application provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes an eSIM-based user equipment control method such as any one of the first aspect, the second aspect, or the third aspect.
[0024] In the tenth aspect, an embodiment of the present application provides a user device, the user device comprising an eSIM, a processor, and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the eSIM-based user device control method as described in any one of the first aspect, the second aspect, or the third aspect.
[0025] In the eSIM-based user equipment control method of the embodiment of the present application, the eSIM decrypts the received encrypted application access request to obtain the decrypted application access request. Since the application access request carries the application signature information of the target application, the application signature information in the application access request can be verified based on the pre-stored signature certificate of the target application, so that the identity of the target application can be verified relatively quickly to prevent illegal applications from accessing the user equipment. In the case where the identity authentication of the target application is passed, based on the application permission control information pre-stored in the eSIM, whether the target application has the permission to access the target access object is verified to obtain the permission verification result, and the permission verification result is returned for the application access request, so that the target application can be prevented from tampering with its own access rights, that is, the target application is prevented from accessing the target access object when it has no right to access the target access object, thereby realizing a relatively safe control and management of the application's access rights. It can be seen that the eSIM-based user equipment control method of the present application encrypts and signs the communication information between the target application and the eSIM, so that the communication information can be prevented from being tampered with and leaked, and the pre-stored application permission control information is used to verify the access rights of the target application, thereby realizing a relatively safe management and control of the permissions of the target application. In addition, by presetting application permission control information in the eSIM, different access permissions can be provided to different applications more flexibly, thereby achieving differentiated control and management of application permissions. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solution of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0027] Figure 1 This is a schematic diagram of the architecture of an eSIM-based user equipment control system provided by an embodiment of the present application;
[0028] Figure 2 It is a flowchart of a method for controlling a user equipment based on eSIM provided by an embodiment of the present application;
[0029] Figure 3 It is a schematic diagram of verifying application signature information of a target application provided by an embodiment of the present application;
[0030] Figure 4 It is a schematic diagram of whether a target application has permission to access a target access object provided by an embodiment of the present application;
[0031] Figure 5It is a schematic flow chart for updating application permission control information of eSIM provided by an embodiment of the present application;
[0032] Figure 6 It is a schematic flow chart of a user equipment control method based on eSIM provided by another embodiment of the present application;
[0033] Figure 7 It is a schematic flow chart for determining a permission verification result based on application permission control information provided by an embodiment of the present application;
[0034] Figure 8 It is a schematic flow chart of a user equipment control method based on eSIM provided by another embodiment of the present application;
[0035] Fig. 9 It is an interaction schematic diagram of a target application, a server, a user equipment management system and eSIM provided by an embodiment of the present application;
[0036] Fig.10 It is an interaction schematic diagram of a target application, a user equipment management system and eSIM provided by an embodiment of the present application;
[0037] Fig.11 It is a schematic structural diagram of a user equipment control device based on eSIM provided by an embodiment of the present application;
[0038] Fig.12 It is a schematic structural diagram of a user equipment control device based on eSIM provided by another embodiment of the present application;
[0039] Fig.13 It is a schematic structural diagram of a user equipment control device based on eSIM provided by another embodiment of the present application;
[0040] Fig.14 It is a schematic structural diagram of a user equipment provided by an embodiment of the present application.
[0041] Among them, the above-mentioned drawings include the following reference numerals:
[0042] 100, eSIM; 101, user equipment; 102, target application; 103, server; 1110, first receiving module; 1120, decryption module; 1130, verification module; 1140, verification module; 1150, return module; 1210, first sending module; 1220, access module; 1310, second receiving module; 1320, acquisition module; 1330, second sending module; 1401, processor; 1402, memory; 1403, communication interface; 1410, bus. Detailed implementation manners
[0043] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is only to provide a better understanding of the present application by illustrating the examples of the present application.
[0044] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "include..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0045] During the process of installing or running an application on a user's device, the application may request to obtain some permission information of the user's device, such as permission to access identifier information, namely mobile phone number, permission to obtain biometric information, namely fingerprint information and face information, permission to obtain content information, namely photos, videos, and text messages, permission to obtain function information, namely camera shooting, etc.
[0046] In this way, if the application permissions are not managed properly, security issues will arise.
[0047] For example, when updating applications or obtaining device information on a user device, the permissions of the application provided by the user device management system must be relied upon, but this does not allow for differentiated management and control of the permissions of the application to access the user device. In addition, the relevant keys of the user device are stored in the relevant storage area of the user device, and the corresponding security level is low, which makes it impossible to manage and control the permissions of the application more securely.
[0048] The embodiment of the present application provides a user equipment control method, device and user equipment based on eSIM. The eSIM decrypts the received encrypted application access request and can obtain the decrypted application access request. Since the application access request carries the application signature information of the target application, the application signature information in the application access request can be verified based on the signature certificate of the pre-stored target application, so that the identity of the target application can be verified relatively quickly to prevent illegal applications from accessing the user equipment. In the case where the identity authentication of the target application is passed, based on the application permission control information pre-stored in the eSIM, whether the target application has the permission to access the target access object is verified, and the permission verification result is obtained, and the permission verification result is returned for the application access request, so that the target application can be prevented from tampering with its own access rights, that is, the target application is prevented from accessing the target access object when it has no right to access the target access object, thereby realizing a relatively safe control and management of the application's access rights. It can be seen that the user equipment control method based on eSIM of the present application encrypts and signs the communication information between the target application and the eSIM, so that the communication information can be prevented from being tampered with and leaked, and the access rights of the target application are verified by using the pre-stored application permission control information, thereby realizing a relatively safe management and control of the permissions of the target application. In addition, by presetting application permission control information in the eSIM, different access permissions can be provided to different applications more flexibly, thereby achieving differentiated control and management of application permissions.
[0049] For ease of understanding, the eSIM-based user equipment control system of the present application is first introduced. Figure 1 As shown, the eSIM-based user equipment control system provided in the embodiment of the present application includes a user equipment 101 and a server 103. The user equipment 101 runs a target application 102, and the user equipment 101 includes an eSIM 100, and the eSIM 100 pre-stores application permission control information, and the application permission control information includes an application unique identifier, access object information corresponding to the application unique identifier, and permission information.
[0050] in,
[0051] The server 103 is used to generate application permission control information based on the device access request sent by the target application 102, and send the application permission control information to the eSIM 100 through the user equipment management system.
[0052] eSIM100 is used to receive an encrypted application access request, decrypt the application access request, obtain the decrypted application access request, and verify the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application 102. If the verification passes, the application access request is subjected to permission verification based on the application permission control information to obtain a permission verification result. The application access request carries the application unique identifier of the target application 102, the application signature information of the target application 102, and the access object information of the target access object. The permission verification result is used to characterize whether the target application 102 has the permission to access the target access object.
[0053] Optionally, an eSIM (Embedded SIM card) is an electronic SIM card, which is a data file. In actual applications, the eSIM can be downloaded to a user device through a network.
[0054] Optionally, the signature certificate is a digital certificate, which is mainly used to verify the authenticity and integrity of the digital signature. The signature information is a special information used to verify the identity and ensure the integrity of the content. The signature information in the digital field can be a digital signature.
[0055] Optionally, encryption is the process of converting information into ciphertext through a specific algorithm. Specifically, the encryption in the embodiments of the present application can be symmetric encryption or asymmetric encryption. Among them, symmetric encryption uses the same key for encryption and decryption. Asymmetric encryption includes a public key and a private key, using the public key to encrypt information and using the private key to decrypt the encrypted information.
[0056] Optionally, the target access object in the embodiment of the present application may include user data, system information and network resources. For example, user data includes but is not limited to personal information. System resources include but are not limited to hardware resources and storage resources, wherein hardware resources may be the camera and microphone of the user's device, etc., and storage resources may be application configuration information, cached data and user downloaded files, etc. Network resources may be software update packages and information news, etc.
[0057] Next, the process of pre-storing application permission control information in the eSIM is introduced.
[0058] There are many ways to pre-store application permission control information in the eSIM.
[0059] In one embodiment, the application permission control information may be stored in the eSIM via the user equipment.
[0060] In another embodiment, the application permission control information can be stored in the eSIM through the server. Specifically, the eSIM receives an encrypted application permission configuration request, the application permission configuration request carries the application permission control information, the application permission configuration request is sent by the server through the user equipment management system, and the application permission control information is generated by the server based on the device access request sent by the target application; and stores the application permission control information.
[0061] That is to say, the target application sends a device access request to the server, and the device access request carries the application unique identifier of the target application. When the server receives the device access request sent by the target application, it determines the application permission control information of the target application based on the application unique identifier of the target application. After determining the application permission control information, the server generates an application permission configuration request based on the application permission control information and encrypts the application permission configuration request. The server sends the encrypted application permission configuration request to the user equipment management system. The user equipment management system sends the application permission configuration request to the eSIM. The eSIM decrypts the encrypted application permission configuration request, obtains the application permission control information after decryption, and stores the application permission control information.
[0062] The application permission control information is stored in the eSIM through the server, which makes it easier for the server to centrally manage and control the permissions of different user devices and different target applications. At the same time, through the application permission control information, different access rights can also be provided to different applications, realizing differentiated management of application access rights. In addition, if the application permission control information needs to be updated later, the application permission control information can be updated relatively quickly through the server.
[0063] The following uses eSIM as the execution subject to introduce the eSIM-based user equipment control method in the embodiment of the present application.
[0064] Figure 2 1 is a flow chart of a method for controlling a user device based on an eSIM provided in an embodiment of the present application. Figure 2 As shown, the eSIM-based user equipment control method provided in the embodiment of the present application may include steps S201 to S205.
[0065] In step S201, an encrypted application access request is received, where the application access request carries an application unique identifier of a target application, application signature information of the target application, and access object information of a target access object.
[0066] Optionally, the application unique identifier may be an application identifier (Application Identifier, APPID), or a package name (Package Name), etc.
[0067] Optionally, the application signature information of the target application is signature information of the target application.
[0068] There are multiple implementation methods for the eSIM to receive the encrypted application access request.
[0069] In one embodiment, the target application sends the encrypted application access request to the user equipment management system, and then the user equipment management system forwards the encrypted application access request to the eSIM.
[0070] In another implementation, when the target application and the eSIM can communicate, the target application can send an encrypted application access request to the eSIM.
[0071] To facilitate understanding of application access requests, an example is given below. If the target application needs to access the "microphone" on the user's device, the information carried in the application access request may include the target application's unique application identifier, such as the APP ID, the target application's application signature information, and the target access object, such as the microphone.
[0072] In step S202, the application access request is decrypted to obtain the decrypted application access request.
[0073] After decrypting the application access request, the application unique identifier, application signature information, and target access object of the target application in the application access request can be obtained.
[0074] In step S203, based on the pre-stored signature certificate of the target application, the application signature information in the decrypted application access request is verified.
[0075] Based on the signature certificate of the target application stored in the embedded SIM, the application signature information in the received application access request is verified. This can quickly and accurately verify the identity of the target application, prevent illegal applications from accessing the user device, and thus avoid data information leakage of the user device, making the user device safer.
[0076] like Figure 3 As shown, the eSIM 100 verifies the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application 102. If the verification fails, the eSIM 100 may sign and encrypt the information "Verification failed". If the verification passes, the eSIM 100 may sign and encrypt the information "Verification passed".
[0077] In one embodiment, Figure 3As shown, the eSIM 100 can send the signed and encrypted "verification failed" information to the target application through the user device 101, so that the target application 102 can display "illegal". Alternatively, the eSIM 100 sends the signed and encrypted "verification failed" information to the target application, so that the target application 102 can display "illegal".
[0078] In another embodiment, Figure 3 As shown, the eSIM 100 can send the signed and encrypted "verification passed" information to the target application through the user device 101, so that the target application 102 can display "legitimate". Alternatively, the eSIM 100 sends the signed and encrypted "verification passed" information to the target application 102, so that the target application 102 can display "legitimate".
[0079] In step S204, when the verification is passed, a permission check is performed on the application access request based on the application permission control information to obtain a permission check result, which is used to indicate whether the target application has permission to access the target access object.
[0080] By decrypting the application access request, the application unique identifier and the access object information of the target access object in the application access request can be obtained. Based on the application unique identifier and the access object information of the target access object in the application access request, it is possible to quickly determine whether the target application has the authority to access the target access object from the application permission control information pre-stored in the eSIM.
[0081] In step S205, a permission verification result is returned for the application access request.
[0082] After obtaining the permission verification result based on the application permission control information and the application unique identifier in the application access request, the eSIM returns the permission verification result to the target application for the application access request.
[0083] In the embodiment of the present application, when the identity authentication of the target application is passed, based on the application permission control information pre-stored in the eSIM, the target application is checked for permission to access the target access object, and a permission verification result is obtained, which can prevent the target application from tampering with its own access rights, that is, preventing the target application from accessing the target access object when it has no permission to access the target access object, thereby achieving more secure control and management of application access rights. By presetting application permission control information in the eSIM, different access rights can be provided to different applications more flexibly, thereby achieving differentiated control and management of application permissions.
[0084] In an optional embodiment of the present application, a permission verification result is returned in response to an application access request, including: signing and encrypting the permission verification result to obtain a signed and encrypted permission verification result; sending the signed and encrypted permission verification result to a target application so that the target application decrypts the signed and encrypted permission verification result, verifies the signature information in the decrypted permission verification result based on a pre-stored eSIM signature certificate, and obtains the permission verification result after the verification passes.
[0085] The eSIM encrypts and signs the permission verification result, and sends the encrypted and signed permission verification result to the target application, which can prevent the permission verification result from being tampered with and leaked during the communication process.
[0086] Optionally, the eSIM may return the permission verification result to the user equipment management system, and the user equipment management system then sends the signed and encrypted permission verification result to the target application.
[0087] like Figure 4 As shown, the eSIM sends the signed and encrypted permission verification result to the target application. The target application verifies the signature information in the decrypted permission verification result based on the pre-stored eSIM signature certificate. After the verification is passed, the target application can obtain the permission verification result. In the case where the permission verification result indicates that the target application does not have the permission to access the target access object, "No access" can be displayed on the target application. In the case where the permission verification result indicates that the target application has the permission to access the target access object, "Has access" can be displayed on the target application.
[0088] In one embodiment, when the permission verification result indicates that the target application has permission to access the target access object, the target application can obtain access permission data based on the permission verification result, and generate an access instruction based on the access permission data and the application signature information of the target application. Afterwards, the target application can access the target access object on the user device based on the access instruction.
[0089] In another embodiment, when the permission check result indicates that the target application does not have permission to access the target access object, the user can authorize the target application to apply to the server or user device for permission to access the target access object through the display interface, so that the server or user device updates the application permission control information on the eSIM.
[0090] In another embodiment, the user can initially authorize the target application, so that when the permission check result indicates that the target application does not have the permission to access the target access object, the user can apply to the server or user device for permission to access the target access object, so that the server or user device updates the application permission control information on the eSIM.
[0091] In an optional embodiment of the present application, the eSIM-based user equipment control method in the embodiment of the present application also includes: receiving an encrypted control information update request, the control information update request carries at least an application unique identifier of the target application, access object information to be updated, and permission information to be updated; decrypting the control information update request to obtain a decrypted control information update request; and updating the application permission control information based on the decrypted control information update request.
[0092] Since the control information update request includes the application unique identifier of the target application, the access object information to be updated, and the permission information to be updated, the eSIM can update the application permission control information relatively quickly based on the control information update request.
[0093] To facilitate understanding of the access object information to be updated and the permission information to be updated, the following example uses the target application applying for the access permission for "microphone" as an example. When the target application applies for the access permission for "microphone", the access object information to be updated may be "microphone", and the permission information to be updated may be "authorized" or "can access".
[0094] In an optional embodiment of the present application, the control information update request is sent by the server through the user equipment management system, and receiving the encrypted control information update request includes: receiving an encrypted device authentication instruction, the device authentication instruction carries the signature information of the user equipment management system; decrypting the device authentication instruction to obtain the signature information of the user equipment management system; verifying the signature information of the user equipment management system; and if the verification is successful, establishing a secure channel with the server through the user equipment management system, and the secure channel is used to receive the control information update request.
[0095] Based on the pre-stored signature certificate of the user equipment management system, the signature information of the user equipment management system in the received device authentication instruction is verified. If the verification passes, it is determined to establish a secure channel with the server through the user equipment management system, so as to prevent the application permission control information in the eSIM from being maliciously tampered with.
[0096] Figure 5 The flowchart of updating the application permission control information of the eSIM is shown in FIG.
[0097] In step S501, the eSIM receives the encrypted device authentication instruction, and verifies the signature information of the user equipment management system in the decrypted device authentication instruction based on the pre-stored signature certificate of the user equipment management system.
[0098] In step S502, it is determined whether the user equipment has passed the verification. If the verification has passed, steps S503 to S506 are executed; if the verification has not passed, the process ends.
[0099] In step S503, when the user equipment passes the verification, the eSIM sends the encrypted response data to the user equipment management system so that the user equipment verifies the eSIM. The response data carries the signature information in the eSIM. The user equipment management system can decrypt the response data and verify the signature information of the decrypted response data based on the pre-stored signature certificate of the eSIM.
[0100] In step S504, it is determined whether the eSIM has passed verification. If the verification is passed, steps S505 and S506 are executed; if the verification is not passed, the process ends.
[0101] In step S505 , when the eSIM passes the verification, the user equipment establishes a secure channel with the server.
[0102] In step S506, the server updates the application permission control information in the eSIM through the user equipment management system.
[0103] The following introduces the eSIM-based user equipment control method in the embodiment of the present application, taking the target application as the execution subject.
[0104] Figure 6 1 is a flow chart of a method for controlling a user device based on an eSIM provided in an embodiment of the present application. Figure 6 As shown, the eSIM-based user equipment control method provided in the embodiment of the present application may include step S601 and step S602.
[0105] In step S601, an encrypted application access request is sent to the eSIM, where the application access request carries an application unique identifier of the target application, application signature information of the target application, and access object information of the target access object, so that the eSIM decrypts the application access request, obtains the decrypted application access request, and verifies the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application. If the verification passes, the application access request is subjected to permission verification based on the application permission control information to obtain a permission verification result.
[0106] There may be multiple implementations for the target application to send the encrypted application access request to the eSIM.
[0107] In one embodiment, when the target application establishes a communication connection with the eSIM, the target application may send an application access request to the eSIM.
[0108] In another embodiment, the target application sends the encrypted application access request to the user equipment management system, and then the user equipment management system sends the encrypted application access request to the eSIM.
[0109] There may be multiple implementation forms for the eSIM to send the permission verification result to the target application.
[0110] In an optional embodiment of the present application, the eSIM sends the signed and encrypted permission verification result directly to the target application, and the target application receives the signed and encrypted permission verification result sent by the eSIM. In this solution, the target application receives the permission verification result sent by the eSIM, thus preventing the permission verification result from being tampered with during the communication process.
[0111] In another embodiment, the eSIM sends the signed and encrypted permission verification result to the user equipment management system, and the user equipment management system sends the signed and encrypted permission verification result to the target application.
[0112] After receiving the signed and encrypted permission verification result sent by the eSIM, the target application decrypts the permission verification result and verifies the signature in the permission verification result based on the pre-stored eSIM signature certificate. If the verification passes, the target application obtains the permission verification result.
[0113] In step S602, when the permission check result indicates that the target application has permission to access the target access object, the target access object is accessed.
[0114] In the embodiment of the present application, when the identity authentication of the target application is passed, based on the application permission control information pre-stored in the eSIM, the target application is checked for permission to access the target access object, and a permission verification result is obtained, which can prevent the target application from tampering with its own access rights, that is, prevent the target application from accessing the target access object when it has no permission to access the target access object, thereby achieving relatively safe control and management of application access rights. By presetting application permission control information in the eSIM, different access rights can be provided for different applications, thereby achieving differentiated control and management of application permissions.
[0115] In an optional embodiment of the present application, the eSIM-based user equipment control method of the present application also includes: when the permission verification result indicates that the target application does not have the permission to access the target access object, sending an access permission application request to the server, the access permission application request carries at least the application unique identifier of the target application and the access object information, so that the server sends a control information update request to the user equipment management system, and the control information update request is used to enable the user equipment management system to update the application permission control information pre-stored in the eSIM.
[0116] When the target application does not have permission to access the target access object, the target application can apply to the server for permission to access the target access object, thereby updating the application permission control information stored in the eSIM through the server, and further enabling the server to centrally manage access rights of different devices and different applications.
[0117] Optionally, the target application may send an access permission application request to the user device, that is, the target application may apply to the user device for permission to access the target access object.
[0118] In an optional embodiment of the present application, accessing a target access object includes: obtaining access permission data when a permission verification result is used to characterize that a target application has permission to access the target access object; generating an access instruction based on the access permission data and application signature information of the target application; sending the access instruction to a user device management system so that the user device management system verifies the application signature information in the access instruction based on a pre-stored signature certificate of the target application, and if the verification passes, sending data corresponding to the target access object to the target application based on the obtained access permission data; and receiving the data of the target access object.
[0119] The user device management system verifies the application signature information in the access instruction based on the signature certificate of the pre-stored target application, so that the user device management system can further verify the legitimacy of the target application and prevent illegal applications from accessing the target access object of the user device based on the access instruction. In addition, the user device management system sends the data corresponding to the target access object to the target application based on the access permission data, so that the target application can be prevented from tampering with its own access permission, that is, preventing the target application from accessing the target access object without permission.
[0120] In an optional embodiment, the eSIM sends the signed encrypted permission verification result to the user equipment management system. The user equipment management system verifies the signature information in the permission verification result based on the pre-stored eSIM signature certificate. If the verification is successful, the user equipment management system obtains the permission verification result. If the permission verification result indicates that the target application has the permission to access the target access object, the user equipment management system can directly send the data of the target access object to the target application, which can reduce the number of passes between the target application and the user device and save communication resources. If the permission verification result indicates that the target application does not have the permission to access the target access object, the user equipment management system can directly deny the target application access to the target access object, that is, the user equipment management system can send unauthorized access information to the target application.
[0121] Figure 7 The flowchart of determining the permission verification result based on the application permission control information is shown in FIG.
[0122] In step S701, the eSIM receives an application access request and obtains a unique application identifier.
[0123] In step S702 , the eSIM determines whether the target application has permission to access the target access object.
[0124] In step S703, it is determined whether the application unique identifier exists. If so, steps S704 to S709 are executed; if not, steps S710 to S714 are executed.
[0125] In step S704, when the application unique identifier exists, the eSIM compares the access rights of the target application based on the application permission control information.
[0126] In step S705, it is determined whether the permissions are consistent. If the permissions are consistent, steps S706 to S709 are executed; if the permissions are inconsistent, steps S710 to S714 are executed.
[0127] In step S706, when the permissions are consistent, the eSIM sends the signed and encrypted permission verification result to the target application.
[0128] In step S707, upon receiving the permission verification result, the target application decrypts the permission verification result and verifies the signature information in the permission verification result based on the pre-stored eSIM signature certificate. If the verification is successful and the permission verification result indicates that the target application has access to the target access object, the target application generates a corresponding access instruction.
[0129] In step S708, the target application sends the access instruction to the user equipment management system. The user equipment management system receives the access instruction sent by the target application and verifies the signature information of the target application.
[0130] In step S709, if the verification is successful, the user equipment management system sends the data of the target access object to the target application.
[0131] In step S710, when the application unique identifier does not exist and / or the permissions are inconsistent, the eSIM prompts that the target application has no access rights.
[0132] In step S711 , the target application sends an access rights application request to the server.
[0133] In step S712, the server sends a control information update request to the user equipment management system.
[0134] In step S713, when the user equipment management system receives the control information update request, the user equipment and the eSIM perform two-way authentication.
[0135] In step S714, when the two-way verification passes, the user equipment updates the application permission control information in the eSIM.
[0136] The following describes the eSIM-based user equipment control method of the present application, taking the user equipment as the execution subject.
[0137] Figure 8 1 is a flow chart of a method for controlling a user device based on an eSIM provided in an embodiment of the present application. Figure 8 As shown, the eSIM-based user equipment control method provided in the embodiment of the present application may include steps S801 to S803.
[0138] In step S801, an access instruction sent by a target application is received.
[0139] In step S802, based on the access instruction, access permission data is obtained, the access permission data is obtained when the permission verification result indicates that the target application has the permission to access the target access object, the permission verification result is that the eSIM decrypts the application access request, obtains the decrypted application access request, and based on the pre-stored signature certificate of the target application, verifies the application signature information in the decrypted application access request, and when the verification passes, performs permission verification on the application access request based on the application permission control information.
[0140] In step S803, when the access permission data is acquired, the data of the target access object is sent to the target application.
[0141] In the embodiment of the present application, when the identity authentication of the target application is passed, based on the application permission control information pre-stored in the eSIM, the target application is checked for permission to access the target access object, and a permission verification result is obtained, which can prevent the target application from tampering with its own access rights, that is, preventing the target application from accessing the target access object when it has no permission to access the target access object, thereby achieving more secure control and management of application access rights. By presetting application permission control information in the eSIM, different access rights can be provided to different applications more flexibly, thereby achieving differentiated control and management of application permissions.
[0142] In an optional embodiment of the present application, the access instruction carries at least application signature information of the target application, and based on the access instruction, access permission data is obtained, including: verifying the application signature information in the access instruction based on a pre-stored signature certificate of the target application; if the verification passes, determining whether there is access permission data in the access instruction; if there is access permission data in the access instruction, obtaining the access permission data.
[0143] The user device management system verifies the application signature information in the access instruction based on the signature certificate of the pre-stored target application, so that the user device management system can verify the identity of the target application relatively quickly. If the verification is successful, it is determined whether there is access permission data in the access instruction. If there is access permission data in the access instruction, the access permission data is obtained. Subsequently, the user device management system can determine that the target application has the permission to access the target access object based on the access permission data, and thus send the data corresponding to the target access object to the target application.
[0144] In an optional embodiment of the present application, the eSIM-based user equipment control method of the present application also includes: receiving an encrypted control information update request, the control information update request is used to update the application permission control information pre-stored in the eSIM; based on the encrypted control information update request, updating the application permission control information pre-stored in the eSIM.
[0145] Based on the encrypted control information update request, the application permission control information pre-stored in the eSIM is updated, which not only realizes the update of the application permission control information, but also can update the application permission control information more safely.
[0146] In an optional embodiment of the present application, receiving an encrypted control information update request includes: sending an encrypted device authentication instruction to the eSIM, allowing the eSIM to decrypt the device authentication instruction, obtaining the signature information of the user equipment management system, and verifying the signature information of the user equipment management system based on a pre-stored signature certificate of the user equipment management system, that is, if the verification passes, the eSIM sends the encrypted response data to the user equipment management system; the user equipment management system receives the encrypted response data sent by the eSIM, the response data carries the signature information of the eSIM; the user equipment management system verifies the signature information in the response data based on the pre-stored signature certificate of the eSIM; if the verification passes, establishes a secure channel with the server, and the secure channel is used to receive the control information update request.
[0147] When the two-way authentication between the user device and the eSIM is passed, the user device and the server establish a secure channel, that is, the server updates the application permission control information in the eSIM through the user device, thereby achieving a relatively safe update of the application permission control information and avoiding illegal or malicious tampering with the application permission control information in the eSIM.
[0148] For ease of understanding, this embodiment is based on Fig. 9 The eSIM-based user equipment control method in the present application is further described. The eSIM-based user equipment control method includes steps S901 to S915.
[0149] In step S901, the target application sends a device access request to the server. The device access request carries the application unique identifier of the target application and the application signature information of the target application.
[0150] In step S902, the server may determine the application permission control information corresponding to the target application based on the application unique identifier of the target application. The server sends an encrypted application permission configuration request carrying the application permission control information to the user equipment management system.
[0151] In step S903, the user equipment management system sends the encrypted application permission configuration request to the eSIM.
[0152] In step S904, the eSIM decrypts the application permission configuration request, obtains application permission control information, and stores the application permission control information. The application permission control information includes the application unique identifier, access object information corresponding to the application unique identifier, and permission information.
[0153] In step S905 , the target application sends an application access request to the user equipment management system.
[0154] In step S906 , the user equipment management system sends an application access request to the eSIM.
[0155] In step S907, the eSIM determines the permission verification result based on the application permission control information. Specifically, the eSIM decrypts the application access request to obtain the decrypted application access request, verifies the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application, and if the verification passes, performs permission verification on the application access request based on the application permission control information to obtain the permission verification result.
[0156] In step S908, the eSIM sends the signed and encrypted permission check result to the target application. If the permission check result indicates that the target application has the permission to access the target access object, steps S909 and S910 are executed. If the permission check result indicates that the target application does not have the permission to access the target access object, steps S911 to S915 are executed.
[0157] In step S909, if the permission check result indicates that the target application has permission to access the target access object, the target application obtains the access permission data, generates an access instruction based on the access permission data and the application signature information of the target application, and sends the access instruction to the user device management system.
[0158] In step S910, upon receiving the access instruction, the user equipment management system verifies the signature information in the access instruction based on the pre-stored signature certificate of the target application. If the verification is successful, the user equipment management system sends the data of the target access object to the target application.
[0159] In step S911 , when the permission check result indicates that the target application does not have permission to access the target access object, the target application sends an access permission application request to the server.
[0160] In step S912, the server sends a control information update request to the user equipment management system.
[0161] In step S913, the user equipment management system sends a device authentication instruction to the eSIM. The eSIM decrypts the device authentication instruction, obtains the signature information of the user equipment management system, and verifies the signature information in the device authentication instruction based on the pre-stored signature certificate of the user equipment management system.
[0162] In step S914, if the verification is successful, the eSIM sends response data to the user equipment management system. The user equipment management system verifies the signature information in the response data based on the pre-stored signature certificate of the eSIM.
[0163] In step S915, when the verification is successful, the server establishes a secure channel with the user equipment to update the application permission control information in the eSIM.
[0164] For ease of understanding, this embodiment is based on Fig.10 The eSIM-based user equipment control method in the present application is further described. The eSIM-based user equipment control method includes steps S1001 to S1013.
[0165] In step S1001, the target application sends a device access request to the user device management system. The device access request carries the application unique identifier of the target application and the application signature information of the target application.
[0166] In step S1002, the user equipment management system may determine the application permission control information corresponding to the target application based on the application unique identifier of the target application. The user equipment management system sends an encrypted application permission configuration request carrying the application permission control information to the eSIM.
[0167] In step S1003, the eSIM decrypts the application permission configuration request, obtains application permission control information, and stores the application permission control information.
[0168] In step S1004, the target application sends an application access request to the user equipment management system.
[0169] In step S1005 , the user equipment management system sends an application access request to the eSIM.
[0170] In step S1006, the eSIM determines the permission verification result based on the application permission control information. Specifically, the eSIM decrypts the application access request to obtain the decrypted application access request, verifies the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application, and if the verification passes, performs permission verification on the application access request based on the application permission control information to obtain the permission verification result.
[0171] In step S1007, the eSIM sends the signed and encrypted permission verification result to the target application. If the permission verification result indicates that the target application has the permission to access the target access object, steps S1008 and S1009 are executed. If the permission verification result indicates that the target application does not have the permission to access the target access object, steps S1010 to S1013 are executed.
[0172] In step S1008, if the permission check result indicates that the target application has permission to access the target access object, the target application obtains the access permission data, generates an access instruction based on the access permission data and the application signature information of the target application, and sends the access instruction to the user device management system.
[0173] In step S1009, upon receiving the access instruction, the user equipment management system verifies the signature information in the access instruction based on the pre-stored signature certificate of the target application. If the verification is successful, the user equipment management system sends the data of the target access object to the target application.
[0174] In step S1010 , when the permission check result indicates that the target application does not have permission to access the target access object, the target application sends an access permission application request to the user device management system.
[0175] In step S1011, the user equipment management system sends a device authentication instruction to the eSIM. The eSIM decrypts the device authentication instruction, obtains the signature information of the user equipment management system, and verifies the signature information in the device authentication instruction based on the pre-stored signature certificate of the user equipment management system.
[0176] In step S1012, if the verification is successful, the eSIM sends response data to the user equipment management system. The user equipment management system verifies the signature information in the response data based on the pre-stored signature certificate of the eSIM.
[0177] In step S1013, when the verification is successful, the server establishes a secure channel with the user equipment to update the application permission control information in the eSIM.
[0178] It should be noted that the eSIM-based user equipment control device is a device corresponding to the above-mentioned eSIM-based user equipment control method. All implementation methods in the above-mentioned method embodiments are applicable to the embodiments of the device and can achieve the same technical effects, which will not be repeated here.
[0179] Based on the same inventive concept, the embodiment of the present application also provides a user equipment control device based on eSIM. The user equipment control device based on eSIM is applied to eSIM, and the eSIM pre-stores application permission control information, which includes the application unique identifier, the access object information and permission information corresponding to the application unique identifier; specifically combined with Fig.11 The eSIM-based user equipment control device provided in an embodiment of the present application is described in detail.
[0180] Fig.1111 is a schematic diagram of a structure of a user equipment control device based on eSIM provided in an embodiment of the present application. The user equipment control device based on eSIM includes a first receiving module 1110, a decryption module 1120, a verification module 1130, a check module 1140 and a return module 1150.
[0181] The first receiving module 1110 is used to receive an encrypted application access request, where the application access request carries an application unique identifier of a target application, application signature information of the target application, and access object information of a target access object.
[0182] The decryption module 1120 is used to decrypt the application access request and obtain the decrypted application access request.
[0183] The verification module 1130 is used to verify the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application.
[0184] The verification module 1140 is used to perform permission verification on the application access request based on the application permission control information when the verification is passed, and obtain a permission verification result, which is used to indicate whether the target application has the permission to access the target access object.
[0185] The return module 1150 is used to return the permission verification result for the application access request.
[0186] In one embodiment, the return module can be used to sign and encrypt the permission verification result to obtain the signed and encrypted permission verification result; send the signed and encrypted permission verification result to the target application so that the target application decrypts the signed and encrypted permission verification result, and verifies the signature information in the decrypted permission verification result based on the pre-stored eSIM signature certificate. After the verification is passed, the permission verification result is obtained.
[0187] In one embodiment, the eSIM-based user equipment control device of the present application further includes a third receiving module, a decryption module and a first updating module. Among them, the third receiving module can be used to receive an encrypted control information update request, which at least carries the application unique identifier of the target application, the access object information to be updated and the permission information to be updated; the decryption module can be used to decrypt the control information update request to obtain the decrypted control information update request; the first updating module can be used to update the application permission control information based on the decrypted control information update request.
[0188] In one embodiment, the control information update request is sent by the server through the user equipment management system. The third receiving module can also be used to receive an encrypted device authentication instruction, which carries the signature information of the user equipment management system; decrypt the device authentication instruction to obtain the signature information of the user equipment management system; verify the signature information of the user equipment management system; and if the verification is successful, determine to establish a secure channel with the server through the user equipment management system, and the secure channel is used to receive the control information update request.
[0189] In one embodiment, the eSIM-based user equipment control device of the present application also includes a fourth receiving module, which can be used to receive an encrypted application permission configuration request, the application permission configuration request carries application permission control information, the application permission configuration request is sent by the server through the user equipment management system, and the application permission control information is generated by the server based on the device access request sent by the target application; store the application permission control information.
[0190] Based on the same inventive concept, the embodiment of the present application also provides a user equipment control device based on eSIM. The user equipment control device based on eSIM is applied to a target application, the target application runs on a user equipment, the user equipment includes an eSIM, and the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information corresponding to the application unique identifier, and permission information; specifically combined with Fig.12 The eSIM-based user equipment control device provided in an embodiment of the present application is described in detail.
[0191] Fig.12 1 is a schematic diagram of a structure of a user equipment control device based on eSIM provided in an embodiment of the present application. The user equipment control device based on eSIM includes a first sending module 1210 and an access module 1220.
[0192] The first sending module 1210 is used to send an encrypted application access request to the eSIM, where the application access request carries an application unique identifier of the target application, application signature information of the target application, and access object information of the target access object, so that the eSIM decrypts the application access request, obtains the decrypted application access request, and verifies the application signature information in the decrypted application access request based on a pre-stored signature certificate of the target application. If the verification passes, the application access request is subjected to permission verification based on the application permission control information to obtain a permission verification result.
[0193] The access module 1220 is configured to access the target access object when the permission check result indicates that the target application has permission to access the target access object.
[0194] In one embodiment, the eSIM-based user equipment control device of the present application further includes a fifth receiving module. The fifth receiving module is used to receive the signed and encrypted authority verification result sent by the eSIM before accessing the target access object.
[0195] In one embodiment, the eSIM-based user equipment control device of the present application further includes a fourth sending module. The fourth sending module may be used to send an access permission application request to a server when the permission verification result indicates that the target application does not have permission to access the target access object, and the access permission application request carries at least the application unique identifier of the target application and the access object information, so that the server sends a control information update request to the user equipment management system, and the control information update request is used to enable the user equipment management system to update the application permission control information pre-stored in the eSIM.
[0196] In one embodiment, the access module can also be used to obtain access permission data when the permission verification result is used to characterize that the target application has the permission to access the target access object; generate an access instruction based on the access permission data and the application signature information of the target application; send the access instruction to the user device management system, so that the user device management system verifies the application signature information in the access instruction based on the pre-stored signature certificate of the target application, and when the verification passes, sends the data corresponding to the target access object to the target application based on the obtained access permission data; and receives the data of the target access object.
[0197] Based on the same inventive concept, the embodiment of the present application also provides a user equipment control device based on eSIM. The user equipment control device based on eSIM is applied to a user equipment, the user equipment runs a target application, the user equipment includes an eSIM, and the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information corresponding to the application unique identifier, and permission information; specifically combined with Fig.13 The eSIM-based user equipment control device provided in an embodiment of the present application is described in detail.
[0198] Fig.13 13 is a schematic diagram of a structure of a user equipment control device based on eSIM provided in an embodiment of the present application. The user equipment control device based on eSIM includes a second receiving module 1310 , an acquiring module 1320 and a second sending module 1330 .
[0199] The second receiving module 1310 is used to receive an access instruction sent by a target application.
[0200] The acquisition module 1320 is used to obtain access permission data based on the access instruction. The access permission data is obtained when the permission verification result indicates that the target application has the permission to access the target access object. The permission verification result is that the eSIM decrypts the application access request, obtains the decrypted application access request, and verifies the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application. When the verification passes, the application access request is verified based on the application permission control information.
[0201] The second sending module 1330 is configured to send the data of the target access object to the target application when the access permission data is acquired.
[0202] In one embodiment, the access instruction carries at least the application signature information of the target application, and the acquisition module can also be used to verify the application signature information in the access instruction based on the pre-stored signature certificate of the target application; if the verification passes, determine whether there is access permission data in the access instruction; if there is access permission data in the access instruction, obtain the access permission data.
[0203] In one embodiment, the eSIM-based user equipment control device of the present application further includes a sixth receiving module and a first updating module. The sixth receiving module can be used to receive an encrypted control information update request, which is used to update the application permission control information pre-stored in the eSIM; the first updating module can be used to update the application permission control information pre-stored in the eSIM based on the encrypted control information update request.
[0204] In one embodiment, the sixth receiving module can also be used to send an encrypted device authentication instruction to the eSIM, so that the eSIM decrypts the device authentication instruction, obtains the signature information of the user equipment management system, and verifies the signature information of the user equipment management system based on a pre-stored signature certificate of the user equipment management system; receives encrypted response data sent by the eSIM, the response data carries the signature information of the eSIM; verifies the signature information in the response data based on the pre-stored signature certificate of the eSIM; and if the verification passes, establishes a secure channel with the server, and the secure channel is used to receive a control information update request.
[0205] Fig.14 A schematic diagram of the hardware structure of a user device provided in an embodiment of the present application is shown.
[0206] The user equipment may include an eSIM, a processor 1401, and a memory 1402 storing computer program instructions. Specifically, the processor 1401 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0207] The memory 1402 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 1402 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. In appropriate cases, the memory 1402 may include a removable or non-removable (or fixed) medium. In appropriate cases, the memory 1402 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 1402 is a non-volatile solid-state memory.
[0208] The memory may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical or other physical / tangible memory storage devices. Thus, typically, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of the present application.
[0209] The processor 1401 implements any one of the eSIM-based user equipment control methods in the above embodiments by reading and executing computer program instructions stored in the memory 1402 .
[0210] In one example, the user equipment may further include a communication interface 1403 and a bus 1410. Fig.14 As shown, the processor 1401, the memory 1402, and the communication interface 1403 are connected via a bus 1410 and communicate with each other.
[0211] The communication interface 1403 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.
[0212] Bus 1410 includes hardware, software or the parts of both are coupled to each other.For example, but not limitation, bus may include accelerated graphics port (AGP) or other graphics bus, enhanced industrial standard architecture (EISA) bus, front side bus (FSB), hypertransport (HT) interconnection, industrial standard architecture (ISA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel architecture (MCA) bus, peripheral component interconnection (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more of these combinations. In appropriate cases, bus 1410 may include one or more buses. Although the present application embodiment describes and shows a specific bus, the application considers any suitable bus or interconnection.
[0213] The user equipment can execute the user equipment control method based on eSIM in the embodiment of the present application, thereby realizing the combination Figures 2 to 10 The present invention describes a user equipment control method based on eSIM.
[0214] In addition, in combination with the eSIM-based user equipment control method in the above embodiments, the present application embodiment may provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any of the eSIM-based user equipment control methods in the above embodiments is implemented.
[0215] An embodiment of the present application also provides a computer program product, including a computer program, which, when processed and executed, implements any one of the eSIM-based user equipment control methods in the above embodiments.
[0216] It should be clear that the present application is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present application.
[0217] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
[0218] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiment, or in a different order from the embodiment, or several steps can be performed simultaneously.
[0219] The above reference is according to the method of the embodiment of the present application, the flow chart of the device (system) and the computer program product and / or the block diagram described various aspects of the present application.It should be understood that each square box in the flow chart and / or the block diagram and the combination of each square box in the flow chart and / or the block diagram can be realized by computer program instructions.These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed by the processor of the computer or other programmable data processing device enable the realization of the function / action specified in one or more square boxes of the flow chart and / or the block diagram.Such a processor can be but is not limited to a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit.It can also be understood that each square box in the block diagram and / or the flow chart and the combination of the square boxes in the block diagram and / or the flow chart can also be realized by the dedicated hardware that performs the specified function or action, or can be realized by the combination of dedicated hardware and computer instructions.
[0220] The above is only a specific implementation of the present application. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the protection scope of the present application is not limited to this. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed in this application, and these modifications or replacements should be included in the protection scope of this application.
Claims
1. A user equipment control method based on eSIM, characterized in that: Applied to an eSIM, the eSIM pre-stores application permission control information, the application permission control information including an application unique identifier, access object information and permission information corresponding to the application unique identifier; the method comprises: Receive an encrypted application access request, the application access request carrying an application unique identifier of a target application, application signature information of the target application, and access object information of a target access object; Decrypting the application access request to obtain the decrypted application access request; Based on the pre-stored signature certificate of the target application, verifying the application signature information in the decrypted application access request; If the verification is successful, performing a permission check on the application access request based on the application permission control information to obtain a permission check result, wherein the permission check result is used to indicate whether the target application has permission to access the target access object; The permission verification result is returned for the application access request.
2. The method according to claim 1, characterized in that Returning the permission verification result for the application access request includes: Signing and encrypting the permission verification result to obtain the signed and encrypted permission verification result; The signed and encrypted permission verification result is sent to the target application, so that the target application decrypts the signed and encrypted permission verification result, and verifies the signature information in the decrypted permission verification result based on the pre-stored signature certificate of the eSIM. After the verification is passed, the permission verification result is obtained.
3. The method according to claim 1, characterized in that The method further comprises: receiving an encrypted control information update request, wherein the control information update request carries at least an application unique identifier of the target application, access object information to be updated, and permission information to be updated; decrypting the control information update request to obtain the decrypted control information update request; The application permission control information is updated based on the decrypted control information update request.
4. The method according to claim 3, characterized in that The control information update request is sent by the server through the user equipment management system; Receive an encrypted control information update request, including: Receiving an encrypted device authentication instruction, the device authentication instruction carrying signature information of the user device management system; Decrypting the device authentication instruction to obtain the signature information of the user device management system; Verifying the signature information of the user equipment management system; When the verification is successful, a secure channel is established between the user equipment management system and the server, and the secure channel is used to receive the control information update request.
5. The method according to any one of claims 1 to 4, characterized in that: The process of pre-storing the application permission control information by the eSIM includes: receiving an encrypted application permission configuration request, the application permission configuration request carrying the application permission control information, the application permission configuration request being sent by the server through the user device management system, and the application permission control information being generated by the server based on a device access request sent by the target application; The application permission control information is stored.
6. A user equipment control method based on eSIM, characterized in that: Applied to a target application, the target application is run on a user device, the user device includes an eSIM, the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information and permission information corresponding to the application unique identifier; the method includes: sending an encrypted application access request to the eSIM, the application access request carrying an application unique identifier of the target application, application signature information of the target application, and access object information of the target access object, so that the eSIM decrypts the application access request to obtain the decrypted application access request, and verifies the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application. If the verification passes, performing permission verification on the application access request based on the application permission control information to obtain a permission verification result; In a case where the permission check result indicates that the target application has permission to access the target access object, the target access object is accessed.
7. The method according to claim 6, characterized in that Before accessing the target access object, the method further includes: Receive the signed and encrypted authority verification result sent by the eSIM.
8. The method according to claim 6, characterized in that The method further comprises: In a case where the permission verification result indicates that the target application does not have permission to access the target access object, an access permission application request is sent to the server, where the access permission application request carries at least an application unique identifier of the target application and access object information, so that the server sends a control information update request to the user equipment management system, where the control information update request is used to enable the user equipment management system to update the application permission control information pre-stored in the eSIM.
9. The method according to any one of claims 6 to 8, characterized in that Accessing the target access object includes: When the permission verification result is used to indicate that the target application has permission to access the target access object, obtaining access permission data; Generate an access instruction based on the access permission data and the application signature information of the target application; Sending the access instruction to a user device management system, so that the user device management system verifies the application signature information in the access instruction based on the pre-stored signature certificate of the target application, and if the verification passes, sends the data corresponding to the target access object to the target application based on the acquired access permission data; Receive data of the target access object.
10. A user equipment control method based on eSIM, characterized in that: Applied to a user equipment, the user equipment runs a target application, the user equipment includes an eSIM, the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information and permission information corresponding to the application unique identifier; the method includes: Receiving an access instruction sent by the target application; Based on the access instruction, obtaining access permission data, the access permission data is obtained when the permission verification result indicates that the target application has permission to access the target access object, the permission verification result is that the eSIM decrypts the application access request, obtains the decrypted application access request, and verifies the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application. If the verification passes, the application access request is verified based on the application permission control information to obtain the permission; When the access permission data is acquired, the data of the target access object is sent to the target application.
11. The method according to claim 10, characterized in that The access instruction at least carries the application signature information of the target application, and obtaining access permission data based on the access instruction includes: Verifying the application signature information in the access instruction based on the pre-stored signature certificate of the target application; If the verification is successful, determining whether the access permission data exists in the access instruction; When the access permission data exists in the access instruction, the access permission data is acquired.
12. The method according to claim 10, characterized in that The method further comprises: receiving an encrypted control information update request, where the control information update request is used to update the application permission control information pre-stored in the eSIM; Based on the encrypted control information update request, the application permission control information pre-stored in the eSIM is updated.
13. The method according to claim 12, characterized in that Receive an encrypted control information update request, including: Sending an encrypted device authentication instruction to the eSIM, causing the eSIM to decrypt the device authentication instruction, obtain signature information of the user equipment management system, and verify the signature information of the user equipment management system based on a pre-stored signature certificate of the user equipment management system; receiving encrypted response data sent by the eSIM, where the response data carries signature information of the eSIM; Verifying the signature information in the response data based on the pre-stored signature certificate of the eSIM; If the verification is successful, a secure channel is established with the server, where the secure channel is used to receive the control information update request.
14. A user equipment control system based on eSIM, characterized in that: The system includes a user device and a server, the user device runs a target application, the user device includes an eSIM, the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information and permission information corresponding to the application unique identifier; wherein, The server is used to generate application permission control information based on the device access request sent by the target application, and send the application permission control information to the eSIM through the user equipment management system; The eSIM is used to receive an encrypted application access request, decrypt the application access request, obtain the decrypted application access request, and verify the application signature information in the decrypted application access request based on the pre-stored signature certificate of the target application. If the verification passes, the application access request is subjected to a permission check based on the application permission control information to obtain a permission check result, wherein the application access request carries an application unique identifier of the target application, the application signature information of the target application, and the access object information of the target access object, and the permission check result is used to characterize whether the target application has the permission to access the target access object.
15. A user equipment control device based on eSIM, characterized in that: Applied to eSIM, the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information and permission information corresponding to the application unique identifier; the device includes: A first receiving module is used to receive an encrypted application access request, wherein the application access request carries an application unique identifier of a target application, application signature information of the target application, and access object information of a target access object; A decryption module, used to decrypt the application access request and obtain the decrypted application access request; A verification module, configured to verify the application signature information in the decrypted application access request based on a pre-stored signature certificate of the target application; A verification module, configured to, if the verification is successful, perform a permission verification on the application access request based on the application permission control information to obtain a permission verification result, wherein the permission verification result is used to indicate whether the target application has permission to access the target access object; The return module is used to return the permission verification result for the application access request.
16. A user equipment control device based on eSIM, characterized in that: Applied to a target application, the target application is run on a user device, the user device includes an eSIM, the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information and permission information corresponding to the application unique identifier; The device comprises: a first sending module, configured to send an encrypted application access request to the eSIM, the application access request carrying an application unique identifier of the target application, application signature information of the target application, and access object information of the target access object, so that the eSIM decrypts the application access request to obtain the decrypted application access request, and verifies the application signature information in the decrypted application access request based on a pre-stored signature certificate of the target application. If the verification passes, the application access request is subjected to permission verification based on the application permission control information to obtain a permission verification result; The access module is used to access the target access object if the permission verification result indicates that the target application has permission to access the target access object.
17. A user equipment control device based on eSIM, characterized in that: Applied to a user equipment, the user equipment runs a target application, the user equipment includes an eSIM, the eSIM pre-stores application permission control information, the application permission control information includes an application unique identifier, access object information and permission information corresponding to the application unique identifier; The device comprises: A second receiving module, used to receive an access instruction sent by the target application; an acquisition module, configured to acquire access permission data based on the access instruction, the access permission data being acquired when a permission verification result indicates that the target application has permission to access the target access object, the permission verification result being that the eSIM decrypts the application access request, obtains the decrypted application access request, and verifies application signature information in the decrypted application access request based on a pre-stored signature certificate of the target application, and when the verification passes, performs permission verification on the application access request based on the application permission control information to obtain the access permission data; The second sending module is used to send the data of the target access object to the target application when the access permission data is acquired.
18. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by the processor, the eSIM-based user equipment control method is implemented as described in any one of claims 1 to 5 or 6 to 9 or 10 to 13.
19. A computer program product, characterized in that When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the eSIM-based user equipment control method as described in any one of claims 1 to 5 or 6 to 9 or 10 to 13.
20. A user equipment, characterized in that: The user equipment comprises: an eSIM, a processor, and a memory storing computer program instructions; When the processor executes the computer program instructions, the eSIM-based user equipment control method is implemented as described in any one of claims 1 to 5 or 6 to 9 or 10 to 13.