Authentication method and device based on eUICC, equipment and medium

The eUICC-based identity verification method addresses user identity binding issues in eSIM scenarios by using a pre-installed hardware identifier to securely associate with identity information, enhancing security and enabling cross-operator identity sharing.

CN120321649APending Publication Date: 2025-07-15BEIJING TSINGTENG MICROSYSTEM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510720507.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

In the eSIM cardless scenario, the existing technology cannot effectively solve the problem of user identity binding, and there are problems such as identity binding vulnerabilities and poor identity binding.

Method used

The hardware identification and identity information of eUICC are bound in the authentication database. The operator server sends a verification request to the authentication database based on the hardware identification, determines whether there is bound identity information, and sends a configuration file after the verification is passed, and uses the unique hardware identification preset in the factory to associate it with the identity information to achieve identity verification and strong binding.

Benefits of technology

Ensure strong binding of eUICC devices to user identity information, avoid eSIM abuse, improve security, and support cross-operator identity information sharing, avoid duplicate authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321649A_ABST
    Figure CN120321649A_ABST
Patent Text Reader

Abstract

The invention relates to an authentication method, device and equipment based on eUICC and a medium, and the method comprises the steps that user equipment sends a configuration file downloading request to an operator server; the configuration file downloading request carries a hardware identifier of an eUICC in the user equipment; the operator server sends a verification request to an authentication database according to the hardware identifier of the eUICC so as to determine whether binding identity information of the hardware identifier of the eUICC exists in the authentication database; and under the condition that the binding identity information of the hardware identifier of the eUICC exists in the authentication database, sending a configuration file to the user equipment. According to the technical scheme, when the user equipment remotely requests to download the configuration file, identity verification is achieved through the hardware identifier of the eUICC, strong binding between the eUICC equipment and the user identity information is ensured without depending on a physical card, eSIM abuse is avoided, and safety is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication security technologies, and in particular, to an authentication method, apparatus, device, and medium based on eUICC. Background Art

[0002] Currently, eSIM realizes cardless operation through remote download of Profile, and an embedded Universal Integrated Circuit Card (abbreviated as eUICC) is set in a user device. The popularization and application of eSIM technology not only simplifies the card opening process but also poses new requirements on the existing real-name management system.

[0003] In related technologies, SIM card identity authentication depends on the binding of a physical card and identity information. In a cardless scenario, it is impossible to verify the identity through the traditional "card purchase" link, and there are identity binding vulnerabilities during multi-Profile dynamic switching. Therefore, a solution to the user identity binding problem in the eSIM cardless scenario is needed. Summary of the Invention

[0004] To solve the above technical problems, the present disclosure provides an authentication method, apparatus, device, and medium based on eUICC.

[0005] In a first aspect, an embodiment of the present disclosure provides an authentication method based on eUICC, which is applied to an operator server, and the method includes:

[0006] Receiving a configuration file download request sent by a user device; the configuration file download request carries a hardware identifier of the eUICC in the user device;

[0007] Sending a verification request to an authentication database according to the hardware identifier of the eUICC to determine whether there is bound identity information of the hardware identifier of the eUICC in the authentication database;

[0008] When there is bound identity information of the hardware identifier of the eUICC in the authentication database, sending the configuration file to the user device.

[0009] In a second aspect, an embodiment of the present disclosure provides another authentication method based on eUICC, which is applied to a user device, and the method includes:

[0010] Sending a configuration file download request to an operator server; the configuration file download request carries a hardware identifier of the eUICC in the user device;

[0011] Receiving an encrypted configuration file sent by the operator server;

[0012] Decrypt the encrypted configuration file according to the hardware identifier to obtain a configuration file.

[0013] In a third aspect, an embodiment of the present disclosure provides an eUICC-based authentication device, including:

[0014] A receiving module, configured to receive a configuration file download request sent by a user equipment; the configuration file download request carries the hardware identifier of the eUICC in the user equipment;

[0015] A verification module, configured to send a verification request to an authentication database according to the hardware identifier of the eUICC to determine whether there is bound identity information of the hardware identifier of the eUICC in the authentication database;

[0016] A sending module, configured to send the configuration file to the user equipment when there is bound identity information of the hardware identifier of the eUICC in the authentication database.

[0017] In a fourth aspect, an embodiment of the present disclosure provides an electronic device, including: a processor; a memory for storing executable instructions executable by the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the above-mentioned eUICC-based authentication method.

[0018] In a fifth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, where the storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned eUICC-based authentication method is implemented.

[0019] The technical solution provided by the embodiment of the present disclosure has the following advantages compared with the prior art: By sending a configuration file download request from a user equipment to an operator server, the configuration file download request carries the hardware identifier of the eUICC in the user equipment, and the operator server sends a verification request to an authentication database according to the hardware identifier of the eUICC to determine whether there is bound identity information of the hardware identifier of the eUICC in the authentication database. When there is bound identity information of the hardware identifier of the eUICC in the authentication database, the configuration file is sent to the user equipment. Thus, the unique hardware identifier pre-installed at the eUICC factory is associated with the identity information in a specified authentication database to solve the user identity binding problem in the eSIM cardless scenario. When the user equipment remotely requests to download a configuration file, identity verification is implemented through the hardware identifier of the eUICC. Without relying on a physical card, strong binding between the eUICC device and the user identity information is ensured, eSIM abuse is avoided, and security is improved. Moreover, cross-operator identity information sharing is supported, and repeated authentication is avoided. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present disclosure and, together with the specification, are used to explain the principles of the present disclosure.

[0021] To more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0022] Figure 1 It is a schematic flowchart of a method for eUICC-based authentication provided by an embodiment of the present disclosure;

[0023] Figure 2 It is a schematic flowchart of another method for eUICC-based authentication provided by an embodiment of the present disclosure;

[0024] Figure 3 It is a schematic structural diagram of an eUICC-based authentication device provided by an embodiment of the present disclosure. Detailed implementation manners

[0025] In order to more clearly understand the above objects, features, and advantages of the present disclosure, the following will further describe the solutions of the present disclosure. It should be noted that, without conflict, the embodiments of the present disclosure and the features in the embodiments can be combined with each other.

[0026] Many specific details are set forth in the following description in order to fully understand the present disclosure, but the present disclosure can also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only a part of the embodiments of the present disclosure, rather than all of the embodiments.

[0027] Figure 1 It is a schematic flowchart of a method for eUICC-based authentication provided by an embodiment of the present disclosure. The method provided by the embodiment of the present disclosure can be executed by an eUICC-based authentication device, and the device can be implemented by software and / or hardware and can be integrated on any electronic device with computing capabilities.

[0028] As Figure 1 shown, the eUICC-based authentication method provided by the embodiment of the present disclosure may include:

[0029] Step 101, receiving a configuration file download request sent by a user device.

[0030] Among them, the configuration file download request carries the hardware identifier of the eUICC in the user device.

[0031] In this embodiment, the user equipment is an eUICC device, and the eUICC device includes an eUICC. When the user equipment requests a profile from the operator server, the user equipment obtains the hardware identifier of the eUICC to generate a profile download request carrying the hardware identifier, and sends the profile download request to the operator server. The operator server receives the profile download request and parses the hardware identifier of the eUICC carried in the profile download request.

[0032] Step 102: Send a verification request to the authentication database according to the hardware identifier of the eUICC to determine whether there is bound identity information of the hardware identifier of the eUICC in the authentication database.

[0033] In this embodiment, the authentication database is used to store the correspondence between the hardware identifier and the identity information. After receiving the verification request and the hardware identifier of the eUICC sent by the operator server, the authentication database queries the correspondence according to the hardware identifier of the eUICC to determine whether there is identity information corresponding to the hardware identifier of the eUICC. If so, it is determined that there is bound identity information of the hardware identifier of the eUICC in the authentication database.

[0034] As an example, the category of the identity information is the personal category. The user equipment can be a user personal terminal device such as a mobile phone. The user equipment uploads the user identity information and the hardware identifier of the eUICC in the user equipment to the authentication database through a specified interface to establish the correspondence between the user identity information and the hardware identifier of the eUICC in the authentication database, realizing the binding of the eUICC and the identity information. After the binding is successful, the authentication database returns a binding success identifier to the user equipment, and automatic verification is performed when the user equipment downloads the profile subsequently.

[0035] As another example, the category of the identity information is the enterprise category. The user equipment can be an Internet of Things device. The user equipment uploads the enterprise identity information and a list of hardware identifiers of the eUICC through a specified interface. The list of hardware identifiers includes multiple hardware identifiers, and the multiple hardware identifiers correspond to multiple Internet of Things devices one by one. The correspondence between the enterprise identity information and the hardware identifier of the eUICC is established in the authentication database, realizing the binding of the eUICC and the identity information. After the binding is successful, the authentication database returns a binding success identifier to the user equipment, and automatic verification is performed when the user equipment downloads the profile subsequently.

[0036] In an embodiment of the present disclosure, before sending a verification request to a verification database according to the hardware identifier of the eUICC, the method further includes: when it is detected that the hardware identifier is bound for the first time or switched across operators, the operator server sends a verification request to the user equipment in a preset manner, the user equipment obtains verification information according to the verification request, and sends the verification information to the operator server, and the operator server receives the verification information sent by the user equipment and determines a verification result according to the verification information.

[0037] In this embodiment, when the verification result is passed, the operator server executes the step of sending a verification request to the verification database according to the hardware identifier of the eUICC. When the verification result is not passed, the operator server returns the verification result to the user equipment and prompts the verification result through the user terminal. Thus, secondary authentication can be performed when it is detected that the hardware identifier is bound for the first time or switched across operators, further improving data security.

[0038] Among them, the preset manner includes but is not limited to SMS verification codes, face recognition authentication, etc.

[0039] Step 103, when there is bound identity information of the hardware identifier of the eUICC in the authentication database, send the configuration file to the user equipment.

[0040] In this embodiment, when there is bound identity information of the hardware identifier of the eUICC in the authentication database, it is determined that the verification is passed, and the operator server issues a digitally signed configuration file to the user equipment, and the user equipment performs an activation operation according to the downloaded configuration file. Otherwise, the configuration file is refused to be sent to the user equipment. Optionally, the digital signature of the configuration file is generated using the national cipher SM2 algorithm (elliptic curve public key cryptography algorithm), and the configuration file is encrypted using a preset certificate to improve transmission security.

[0041] In an embodiment of the present disclosure, sending the configuration file to the user equipment includes: generating signature data according to the hardware identifier and the operator identifier; generating a key according to the signature data and a preset certificate, and encrypting the configuration file using the key to obtain an encrypted configuration file; sending the encrypted configuration file to the user equipment.

[0042] In this embodiment, the signature data includes the hardware identifier of the eUICC and the operator identifier. After receiving the encrypted configuration file, the user equipment can decrypt the encrypted configuration file based on the hardware identifier of the eUICC and the operator identifier by using a predetermined policy to obtain the configuration file. Optionally, the signature data further includes bound identity information. After receiving the encrypted configuration file, the user equipment can decrypt the encrypted configuration file based on the hardware identifier of the eUICC, the operator identifier, and the input identity information by using a predetermined policy to obtain the configuration file. Among them, the operator server generates the signature data according to the hardware identifier, the bound identity information, and the operator identifier, generates a key according to the signature data and a preset certificate, and encrypts the configuration file by using the key, and sends the encrypted configuration file to the user equipment. Among them, the bound identity information includes user identity information and enterprise identity information.

[0043] As an example, generating signature data according to the hardware identifier and the operator identifier includes: if the category of the bound identity information is an enterprise category, the operator server receives the enterprise identifier sent by the authentication database, and generates the signature data according to the hardware identifier, the enterprise identifier, and the operator identifier. Among them, the operator server generates a key according to the signature data and a preset certificate, and encrypts the configuration file by using the key, and sends the encrypted configuration file to the user equipment.

[0044] In an embodiment of the present disclosure, sending the configuration file to the user equipment includes: if the category of the bound identity information is an enterprise category, receiving the enterprise identifier sent by the authentication database; generating signature data according to the enterprise identifier; generating a key according to the signature data and a preset certificate, and encrypting the configuration file by using the key to obtain an encrypted configuration file; sending the encrypted configuration file to the user equipment. In this embodiment, the signature data includes the enterprise identifier. After receiving the encrypted configuration file, the user equipment can decrypt the encrypted configuration file based on the enterprise identifier by using a predetermined policy to obtain the configuration file. Furthermore, the configuration file can be batch-activated through the application programming interface to solve the problem of low authentication efficiency during the massive activation of Internet of Things devices.

[0045] According to the technical solution of the embodiment of the present disclosure, a configuration file download request is sent from a user device to an operator server. The configuration file download request carries the hardware identifier of the eUICC in the user device. The operator server sends a verification request to an authentication database according to the hardware identifier of the eUICC to determine whether there is bound identity information of the hardware identifier of the eUICC in the authentication database. When there is bound identity information of the hardware identifier of the eUICC in the authentication database, the configuration file is sent to the user device. Thus, the unique hardware identifier (EID) pre-installed at the factory of the eUICC is associated with the identity information in the specified authentication database, which is used to solve the problem of user identity binding in the eSIM cardless scenario. When the user device remotely requests to download the configuration file, identity verification is implemented through the hardware identifier of the eUICC. Without relying on a physical card, it ensures a strong binding between the eUICC device and the user identity information, avoids eSIM abuse, improves security, and supports cross-operator identity information sharing to avoid repeated authentication.

[0046] Based on the above embodiment, Figure 2 FIG. is a schematic flowchart of another eUICC-based authentication method provided by the embodiment of the present disclosure. As Figure 2 shown, the method includes:

[0047] Step 201, sending a configuration file download request to an operator server.

[0048] Wherein, the configuration file download request carries the hardware identifier of the eUICC in the user device.

[0049] In this embodiment, when the user device requests a configuration file from the operator server, the user device obtains the hardware identifier of the eUICC to generate a configuration file download request carrying the hardware identifier, and sends the configuration file download request to the operator server. The operator server receives the configuration file download request, parses to obtain the hardware identifier of the eUICC carried in the configuration file download request, sends a verification request to the authentication database according to the hardware identifier of the eUICC to determine whether there is bound identity information of the hardware identifier of the eUICC in the authentication database. Further, when there is bound identity information of the hardware identifier of the eUICC in the authentication database, signature data is generated according to the hardware identifier, a key is generated according to the signature data and a preset certificate, and the configuration file is encrypted with the key to obtain an encrypted configuration file, and the encrypted configuration file is sent to the user device.

[0050] Step 202, receiving the encrypted configuration file sent by the operator server.

[0051] Step 203, decrypting the encrypted configuration file according to the hardware identifier to obtain the configuration file.

[0052] In this embodiment, the user equipment performs an activation operation according to the downloaded configuration file.

[0053] In an embodiment of the present disclosure, the steps of binding the hardware identifier of the eUICC to the user identity include: in response to obtaining the identity information input by the user, determining the category of the identity information; if the category of the identity information is a personal category, requesting face detection from the user; if the face detection passes, reading the hardware identifier of the eUICC in the user equipment, and sending the hardware identifier of the eUICC and the identity information input by the user to the authentication database.

[0054] As an example, the user identity information and face liveness detection data are collected through the operator client of the user equipment, and the user identity information, face data, and the hardware identifier of the eUICC are uploaded to the authentication database for storage. Among them, the authentication database can be a designated official authentication database, which is used to store the mapping relationship between the hardware identifier of the eUICC and the user identity information, and provide a verification interface. The user identity information includes document images for representing the user identity, etc.

[0055] In an embodiment of the present disclosure, the steps of binding the hardware identifier of the eUICC to the user identity include: in response to obtaining the identity information input by the user, determining the category of the identity information; if the category of the identity information is an enterprise category, requesting a list of hardware identifiers from the user; sending the list of hardware identifiers and the identity information input by the user to the authentication database.

[0056] As an example, the enterprise identity information and the list of eUICC hardware identifiers are submitted to the authentication database through the user equipment. After the authentication database passes the review, an enterprise-specific signature key is generated. The enterprise can batch-activate the configuration file through the application programming interface and apply it to Internet of Things devices to achieve batch authentication of Internet of Things devices.

[0057] In the embodiments of the present disclosure, the unique hardware identifier pre-set by the eUICC at the factory is associated with the identity information in the designated authentication database to solve the problem of user identity binding in the eSIM cardless scenario. When the user equipment remotely requests to download the configuration file, identity verification is implemented through the hardware identifier of the eUICC. Without relying on a physical card, it ensures a strong binding between the eUICC device and the user identity information, avoids the abuse of eSIM, improves security, and supports the sharing of cross-operator identity information to avoid repeated authentication. In addition, it can support the authentication of user personal devices and Internet of Things devices, meeting the real-name authentication requirements of personal device scenarios and enterprise batch device scenarios.

[0058] Figure 3 FIG. is a schematic structural diagram of an authentication device based on eUICC provided by an embodiment of the present disclosure, as Figure 3As shown in the figure, the eUICC-based authentication device includes: a receiving module 31, a verification module 32, and a sending module 33.

[0059] The receiving module 31 is configured to receive a configuration file download request sent by a user device; the configuration file download request carries the hardware identifier of the eUICC in the user device.

[0060] The verification module 32 is configured to send a verification request to the authentication database according to the hardware identifier of the eUICC to determine whether there is bound identity information of the hardware identifier of the eUICC in the authentication database.

[0061] The sending module 33 is configured to send the configuration file to the user device when there is bound identity information of the hardware identifier of the eUICC in the authentication database.

[0062] In an embodiment of the present disclosure, the sending module 33 is specifically configured to:

[0063] Generate signature data according to the hardware identifier and the operator identifier.

[0064] Generate a key according to the signature data and a preset certificate, and encrypt the configuration file with the key to obtain an encrypted configuration file.

[0065] Send the encrypted configuration file to the user device.

[0066] In an embodiment of the present disclosure, the sending module 33 is specifically configured to:

[0067] If the category of the bound identity information is an enterprise category, receive the enterprise identifier sent by the authentication database.

[0068] Generate signature data according to the hardware identifier, the enterprise identifier, and the operator identifier.

[0069] In an embodiment of the present disclosure, the device further includes:

[0070] A verification module, configured to send a verification request to the user device in a preset manner when it is detected that the hardware identifier is bound for the first time or when there is a cross-operator switch; receive the verification information sent by the user device, and determine the verification result according to the verification information; wherein, when the verification result is passed, execute sending a verification request to the verification database according to the hardware identifier of the eUICC.

[0071] An embodiment of the present disclosure further provides another eUICC-based authentication device, which includes: a sending module 41, a receiving module 42, and a decryption module 43.

[0072] A sending module 41 sends a configuration file download request to an operator server. The configuration file download request carries the hardware identifier of the eUICC in the user device.

[0073] A receiving module 42 receives the encrypted configuration file sent by the operator server.

[0074] A decryption module 43 decrypts the encrypted configuration file according to the hardware identifier to obtain the configuration file.

[0075] In an embodiment of the present disclosure, the device further includes:

[0076] A first binding module is configured to, in response to obtaining the identity information input by the user, determine the category of the identity information.

[0077] If the category of the identity information is a personal category, a face detection is requested from the user.

[0078] If the face detection passes, the hardware identifier of the eUICC in the user device is read, and the hardware identifier of the eUICC and the identity information input by the user are sent to an authentication database.

[0079] In an embodiment of the present disclosure, the device further includes:

[0080] A second binding module is configured to, in response to obtaining the identity information input by the user, determine the category of the identity information.

[0081] If the category of the identity information is an enterprise category, a hardware identifier list is requested from the user.

[0082] The hardware identifier list and the identity information input by the user are sent to an authentication database.

[0083] The authentication device based on eUICC provided by the embodiments of the present disclosure can execute any authentication method based on eUICC provided by the embodiments of the present disclosure, and has functional modules and beneficial effects corresponding to the execution of the method. The content not described in detail in the device embodiments of the present disclosure can be referred to the description in any method embodiment of the present disclosure.

[0084] An electronic device provided by an embodiment of the present disclosure includes one or more processors and a memory. The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions. The memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage media, and the processor may run the program instructions to implement the methods of the embodiments of the present disclosure above and / or other desired functions. Various contents such as input signals, signal components, noise components, etc. may also be stored in the computer-readable storage media.

[0085] In one example, the electronic device may further include: an input device and an output device, and these components are interconnected through a bus system and / or other forms of connection mechanisms. In addition, the input device may include, for example, a keyboard, a mouse, etc. The output device may output various information to the outside, including the determined distance information, direction information, etc. The output device may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc. In addition, according to specific application scenarios, the electronic device may further include any other appropriate components such as a bus, an input / output interface, etc.

[0086] In addition to the above methods and devices, an embodiment of the present disclosure may also be a computer program product, which includes computer program instructions that cause the processor to execute any method provided by the embodiment of the present disclosure when being run by the processor.

[0087] The computer program product may be written in any combination of one or more programming languages to write program code for performing the operations of the embodiments of the present disclosure. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0088] In addition, an embodiment of the present disclosure may also be a computer-readable storage medium storing computer program instructions, which, when run by a processor, cause the processor to execute any method provided by the embodiments of the present disclosure.

[0089] The computer-readable storage medium may employ any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may, for example, include but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0090] It should be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article, or device comprising the element.

[0091] The above are only specific embodiments of the present disclosure, enabling those skilled in the art to understand or implement the present disclosure. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to the embodiments described herein, but rather will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An authentication method based on eUICC, characterized in that, Applied to the operator server, the method includes: Receiving a configuration file download request sent by a user device; the configuration file download request carries the hardware identifier of the eUICC in the user device; Sending a verification request to the authentication database according to the hardware identifier of the eUICC to determine whether there is bound identity information of the hardware identifier of the eUICC in the authentication database; When there is bound identity information of the hardware identifier of the eUICC in the authentication database, sending the configuration file to the user device.

2. The method according to claim 1, characterized in that, The sending the configuration file to the user device includes: Generating signature data according to the hardware identifier and the operator identifier; Generating a key according to the signature data and a preset certificate, and encrypting the configuration file with the key to obtain an encrypted configuration file; Sending the encrypted configuration file to the user device.

3. The method according to claim 2, wherein The generating signature data according to the hardware identifier and the operator identifier includes: If the category of the bound identity information is an enterprise category, receiving an enterprise identifier sent by the authentication database; Generating the signature data according to the hardware identifier, the enterprise identifier and the operator identifier.

4. The method according to claim 1, wherein Before sending a verification request to the verification database according to the hardware identifier of the eUICC, the method further includes: When it is detected that the hardware identifier is bound for the first time or switched across operators, sending a verification request to the user device in a preset manner; Receiving verification information sent by the user device, and determining a verification result according to the verification information; wherein, when the verification result is passed, executing sending a verification request to the verification database according to the hardware identifier of the eUICC.

5. An authentication method based on eUICC, characterized in that, Applied to the user device, the method includes: Sending a configuration file download request to the operator server; the configuration file download request carries the hardware identifier of the eUICC in the user device; Receiving the encrypted configuration file sent by the operator server; Decrypting the encrypted configuration file according to the hardware identifier to obtain a configuration file.

6. The method according to claim 5, wherein The method further includes: In response to obtaining the identity information input by the user, judging the category of the identity information; If the category of the identity information is a personal category, requesting face detection from the user; If the face detection is passed, reading the hardware identifier of the eUICC in the user device, and sending the hardware identifier of the eUICC and the identity information input by the user to the authentication database.

7. The method according to claim 5, wherein The method further includes: In response to obtaining the identity information input by the user, judging the category of the identity information; If the category of the identity information is an enterprise category, requesting a hardware identifier list from the user; Sending the hardware identifier list and the identity information input by the user to the authentication database.

8. An authentication device based on eUICC, characterized in that, Includes: A receiving module, configured to receive a configuration file download request sent by a user device; The configuration file download request carries the hardware identifier of the eUICC in the user device; A verification module, configured to send a verification request to an authentication database according to the hardware identifier of the eUICC, so as to determine whether there is bound identity information of the hardware identifier of the eUICC in the authentication database; A sending module, configured to send a configuration file to the user equipment when there is bound identity information of the hardware identifier of the eUICC in the authentication database.

9. An electronic device, characterized in that, Comprising: A processor; A memory for storing executable instructions of the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the eUICC-based authentication method according to any one of claims 1-7 above.

10. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and when the computer program is executed by a processor, the eUICC-based authentication method according to any one of claims 1-7 above is implemented.