Profile activation method and device, equipment and medium
By deploying service terminals on geographically critical nodes, using NFC to interact with user terminals, the automatic activation of eSIM Profile is achieved, and the high latency and network unreachable problems in cross-border scenarios are solved, and the user experience is improved.
Patent Information
- Application Number
- CN202510794065.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-07-25
AI Technical Summary
In cross-border scenarios, the remote download of eSIM Profile is inefficient and cannot quickly obtain the local recommended operator's profile, which is inconvenient to operate, especially in case of poor network coverage or high latency.
Deploy a service terminal on a geographically critical node, establish a connection with the user terminal through NFC, obtain eUICC information and request server authentication, establish a secure channel, receive and send Profile data, and realize the full process automation of the Profile discovery-download-check-activation.
In the absence of WAN connection, the automatic activation of the Profile is achieved through near-field communication, solving the problems of high latency and network unreachability in cross-border scenarios, improving user experience, and reducing manual operation steps.
Smart Images

Figure CN120378868A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of near - field communication technology, and particularly to a Profile activation method, apparatus, device, and medium. Background Art
[0002] Currently, eSIM realizes card - less operation by remotely downloading a configuration file Profile. An Embedded Universal Integrated Circuit Card (abbreviated as eUICC) is set in a user device.
[0003] The Profile is remotely downloaded through the SM - DP + platform and depends on a remote server. In scenarios with poor network coverage or high cross - border latency, the efficiency is low, and it may even be unable to download. For scenarios such as international roaming and cross - border devices, users need to obtain and pre - download the filtered Profile in advance, and cannot quickly obtain the Profile of the local recommended operator, which is inconvenient to operate. Summary of the Invention
[0004] To solve the above - mentioned technical problems, the present disclosure provides a Profile activation method, apparatus, device, and medium.
[0005] In a first aspect, an embodiment of the present disclosure provides a Profile activation method, which is applied to a service terminal deployed at a geographical key node. The method includes:
[0006] In response to establishing a connection with a user terminal through NFC, obtain the eUICC information of the user terminal;
[0007] Send the eUICC information to a server to request eUICC authentication from the server;
[0008] Receive the response information returned by the server after successful authentication, and send the response information to the user terminal so that the user terminal establishes a secure channel;
[0009] Receive the Profile data sent by the server through the secure channel, and send the Profile data to the user terminal.
[0010] In a second aspect, an embodiment of the present disclosure provides a Profile activation method, which is applied to a user terminal. The method includes:
[0011] In response to establishing a connection with a service terminal through NFC, send the eUICC information of the user terminal to the service terminal to request eUICC authentication;
[0012] Receive the response information returned by the service terminal after successful authentication, and establish a secure channel based on the response information;
[0013] In response to the establishment of the secure channel, receive the Profile data sent by the service terminal, and perform activation processing based on the Profile data.
[0014] In a third aspect, an embodiment of the present disclosure provides a Profile activation device, including:
[0015] A sending module, configured to send the eUICC information of the user terminal to the service terminal to request eUICC authentication in response to establishing a connection with the service terminal through NFC;
[0016] A response module, configured to receive the response information returned by the service terminal after successful authentication, and establish a secure channel based on the response information;
[0017] An activation module, configured to receive the Profile data sent by the service terminal in response to the establishment of the secure channel, and perform activation processing based on the Profile data.
[0018] In a fourth aspect, an embodiment of the present disclosure provides an electronic device, including: a processor; a memory for storing executable instructions of the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the above-mentioned Profile activation method.
[0019] In a fifth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, where the storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned Profile activation method is implemented.
[0020] The technical solutions provided by the embodiments of the present disclosure have the following advantages compared with the prior art: By deploying service terminals at geographical key nodes, the service terminals establish connections with user terminals through NFC, obtain the eUICC information of the user terminals, and send the eUICC information to the server to request eUICC authentication from the server. Furthermore, the service terminals receive the response information returned by the server after successful authentication, and send the response information to the user terminals to enable the user terminals to establish a secure channel, and receive the Profile data sent by the server through the secure channel and send the Profile data to the user terminals to achieve Profile activation. Thus, the Profile management function of the traditional SM-DP+ is sunk to the near-field edge network, enabling the user terminals to directly interact with the service terminals through near-field communication protocols such as NFC in the absence of a wide-area network connection, realizing the full automation of the discovery-download-verification-activation process of the target Profile, replacing the dependence on the centralized SM-DP+ through distributed service terminals, solving the problems of high latency and network unreachability in cross-border scenarios, eliminating the need for users to pre-screen and download Profiles in advance, and enhancing the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The accompanying drawings are incorporated herein and form a part of this specification, showing embodiments consistent with the present disclosure and, together with the specification, are used to explain the principles of the present disclosure.
[0022] To more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings required for describing the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0023] Figure 1 It is a schematic flowchart of a Profile activation method provided by an embodiment of the present disclosure;
[0024] Figure 2 It is a schematic flowchart of another Profile activation method provided by an embodiment of the present disclosure;
[0025] Figure 3 It is a schematic structural diagram of a Profile activation device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] In order to better understand the above objects, features, and advantages of the present disclosure, the solutions of the present disclosure will be further described below. It should be noted that, without conflict, the embodiments of the present disclosure and the features in the embodiments may be combined with each other.
[0027] In the following description, many specific details are set forth to facilitate a thorough understanding of the present disclosure. However, the present disclosure may also be implemented in other ways different from those described herein. Obviously, the embodiments in the specification are only a part of the embodiments of the present disclosure, rather than all of the embodiments.
[0028] Figure 1 The flowchart of a Profile activation method provided by an embodiment of the present disclosure. The method provided by the embodiment of the present disclosure can be executed by a Profile activation device, which can be implemented by software and / or hardware and integrated on any electronic device with computing capabilities.
[0029] As Figure 1 shown, the Profile activation method provided by the embodiment of the present disclosure may include:
[0030] Step 101, in response to establishing a connection with the user terminal through NFC, obtain the eUICC information of the user terminal.
[0031] In this embodiment, the execution entity is a service terminal. The service terminal is built-in with an NFC (Near Field Communication) module and deployed at geographical key nodes. Among them, the geographical key nodes are set for scenarios such as international roaming and cross-border devices, and the geographical key nodes include, but are not limited to, places such as airports, customs, stations, and hotels. The user terminal supports eUICC (Embedded Universal Integrated Circuit Card) and NFC functions and pre-installs an offline Profile download interface.
[0032] In cross-regional scenarios such as cross-border tourism, when the user arrives at a geographical key node, there is a need to obtain the Profile of the recommended local operator. In this embodiment, the user brings the user terminal close to the service terminal so that the user terminal and the service terminal interact through NFC. The service terminal obtains the eUICC information from the eUICC of the user terminal to build a secure channel.
[0033] Step 102, send the eUICC information to the server to request eUICC authentication from the server.
[0034] In this embodiment, after the service terminal obtains the eUICC information from the eUICC of the user terminal through NFC, it sends the eUICC information to the server to request eUICC authentication from the server. Among them, the server is used for Profile generation, encryption, and authentication response.
[0035] As an example, the service terminal obtains the eUICC information and a temporary random number from the eUICC of the user terminal, and sends the eUICC information and the temporary random number to the server. In this example, the server is an SM-DP+ (Subscription Manager – Data Preparation +) server.
[0036] Step 103, receive the response information returned after the server authentication is passed, and send the response information to the user terminal so that the user terminal establishes a secure channel.
[0037] In this embodiment, after the server authentication is passed, a response information is generated and relayed to the user terminal through the service terminal. The user terminal receives the response information and establishes a secure channel. Among them, the response information includes a random number, a digital signature, etc.
[0038] Step 104, receive the Profile data sent by the server through the secure channel, and send the Profile data to the user terminal.
[0039] In this embodiment, after the secure channel is established, the server generates an encrypted Profile and pushes it to the temporary buffer area of the service terminal. The service terminal implements protocol conversion and data processing, and sends the encrypted Profile to the user terminal through NFC.
[0040] The following describes how the service terminal sends the Profile data to the user terminal.
[0041] As an example, the service terminal performs data packet splitting on the Profile data to split the Profile data into multiple APDU (Application Protocol Data Unit) data. Furthermore, the multiple APDU data are sent to the user terminal one by one so that the user terminal verifies and executes the APDU data one by one to achieve Profile writing. In this example, during the eUICC development stage, ISD-R (Issuer Security Domain Root) is pre-configured as an optional near-field communication module to support contactless selection. Optionally, the service terminal sends the multiple APDU data to the ISD-R of the user terminal one by one through the NFC channel so that the ISD-R verifies and executes the APDU data one by one to achieve Profile writing.
[0042] As another example, the service terminal sends the Profile data to the user terminal, so that the user terminal disassembles the Profile data into APDU data and installs it item by item. In this example, if the space of the eUICC of the user terminal is greater than the threshold and has the Profile parsing ability, the service terminal can send all the data to the eUICC cache of the user terminal at one time, and the eUICC disassembles the Profile data into APDU data and installs it item by item, so as to reduce the time for the user terminal to be attached to the service terminal.
[0043] In an embodiment of the present disclosure, the service terminal calculates the hash value corresponding to the Profile data, and sends the Profile data and the corresponding hash value to the user terminal, so that the user terminal verifies the Profile data according to the hash value to ensure the transmission integrity. For example, taking the Profile data block transmission as an example, the service terminal calculates the first hash value of each block of data, and sends each block of data and the corresponding first hash value to the user terminal, and the user terminal calculates the second hash value and performs verification according to the first hash value and the second hash value.
[0044] According to the technical solution of the embodiment of the present disclosure, by deploying service terminals at geographical key nodes, the service terminals establish connections with user terminals through NFC, obtain the eUICC information of the user terminals and send the eUICC information to the server to request eUICC authentication from the server. Furthermore, receive the response information returned after the server authentication passes, and send the response information to the user terminal, so that the user terminal establishes a secure channel, and receive the Profile data sent by the server through the secure channel, and send the Profile data to the user terminal to achieve Profile activation. Thus, the Profile management function of the traditional SM-DP+ is sunk to the near-field edge network, so that the user terminal can directly interact with the service terminal through near-field communication protocols such as NFC without a wide area network connection, realizing the full process automation of target Profile discovery-download-verification-activation. By replacing the centralized SM-DP+ dependence with distributed service terminals, the problems of high latency and network unreachability in cross-border scenarios are solved. Moreover, the user only needs to touch once or confirm with one key to trigger the end-to-end automated activation process, reducing the manual operation steps compared with the cumbersome multiple network connection verification processes of the traditional solution and improving the user experience.
[0045] Based on the above embodiments, the following will be described in conjunction with the user terminal side. Figure 2 It is a schematic flowchart of another Profile activation method provided by the embodiment of the present disclosure. As Figure 2 shown, the method includes:
[0046] Step 201, in response to establishing a connection with the service terminal via NFC, send the eUICC information of the user terminal to the service terminal to request eUICC authentication.
[0047] In this embodiment, the execution entity is the user terminal, and the service terminal is set at a geographical key node. The user brings the user terminal close to the service terminal so that the user terminal and the service terminal interact via NFC. The service terminal obtains the eUICC information from the eUICC of the user terminal and forwards it to the server to request eUICC authentication. Optionally, the service terminal obtains the eUICC information and a temporary random number from the eUICC of the user terminal, and sends the eUICC information and the temporary random number to the server.
[0048] In an embodiment of the present disclosure, establishing a connection with the service terminal via NFC includes: selecting the ISD-R security domain via NFC to establish a connection with the service terminal. Among them, the ISD-R is pre-configured as an optional near-field communication module during the eUICC development stage to support non-contact selection.
[0049] In an embodiment of the present disclosure, the user terminal establishes a connection with the service terminal through the following steps: in response to obtaining the first verification code input by the user, send the first verification code to the eUICC. Furthermore, during the connection establishment process, receive the second verification code sent by the service terminal, so that the eUICC verifies through the first verification code and the second verification code. In the case where the verification result is passed, establish a connection with the service terminal via NFC. In this embodiment, the first verification code is generated by the service terminal.
[0050] As an example, the service terminal provides a display interface, and the display interface shows the Profile options of multiple operators. After the user selects the Profile option on the display interface, the service terminal generates and displays a QR code. The user scans the QR code to start one-time dynamic verification. Among them, the verification code is generated after scanning the QR code. The user opens the offline Profile download function interface of the user terminal and inputs the first verification code, and the user terminal sends the first verification code to the eUICC. Furthermore, the user brings the user terminal close to the service terminal, selects the ISD-R security domain via NFC to establish a connection, and the service terminal sends the aforementioned generated verification code to the user terminal to complete the verification with the eUICC, realizing the establishment of a near-field connection and the construction of a secure channel.
[0051] Step 202, receive the response information returned by the service terminal after successful authentication, and establish a secure channel according to the response information.
[0052] In this embodiment, after the server authentication is passed, response information is generated and relayed to the user terminal through the service terminal. The user terminal receives the response information and establishes a secure channel. Among them, the response information includes a random number, a digital signature, etc.
[0053] As an example, after the SM-DP+ server passes, it relays the random number, digital signature, etc. to the ISD-R of the user terminal through the service terminal to establish a secure channel.
[0054] Step 203, in response to the establishment of the secure channel, receive the Profile data sent by the service terminal and perform activation processing according to the Profile data.
[0055] In this embodiment, the server generates an encrypted Profile and pushes it to the temporary buffer of the service terminal. The service terminal implements protocol conversion and data processing, and sends the encrypted Profile to the user terminal through NFC. Furthermore, the user terminal performs activation processing according to the Profile data.
[0056] As an example, the service terminal performs data packet splitting on the Profile data to split the Profile data into multiple APDU data. Furthermore, the multiple APDU data are sent to the ISD-R of the user terminal one by one, so that the ISD-R verifies and executes the APDU data one by one to implement Profile writing. Or, the service terminal sends the Profile data to the eUICC buffer of the user terminal, so that the eUICC disassembles the Profile data into APDU data and installs them one by one. In this example, when the transmission of the Profile data is completed, the user terminal generates a first prompt message to prompt the user that the Profile download is completed. At this time, the user terminal can be taken away to end the interaction with the service terminal. Furthermore, when the Profile installation is completed, a second prompt message is generated, and the user can open the Profile activation interface to manually activate this Profile.
[0057] In an embodiment of the present disclosure, since the ISD-R is configured to be non-contact selectable, it is also necessary to perform permission management on the ISD-R. When the ISD-R communicates through a non-contact channel, obtain the type of the operation to be executed. If the type of the operation to be executed does not match the preset permission information, the operation to be executed is prohibited. Among them, the preset permission information includes query, authentication, Profile download operations. For example, when the type of the operation to be executed is query, authentication, Profile download operation, the operation is allowed to be executed. When the type of the operation to be executed is activation, non-Profile download, deletion, initialization, the operation is prohibited from being executed. Thus, the ISD-R can only perform limited operations on the non-contact channel, avoiding operations such as deleting existing Profiles and clearing the eUICC card without the user's awareness.
[0058] In the embodiments of the present disclosure, the Profile management function of the traditional SM-DP+ is sunk to the near-field edge network, enabling the user terminal to directly interact with the service terminal through near-field communication protocols such as NFC in the absence of a wide area network connection, realizing the full process automation of discovery-download-verification-activation of the target Profile, replacing the dependence on the centralized SM-DP+ with a distributed service terminal, solving the problems of high latency and network unreachability in cross-border scenarios, and moreover, the user only needs to touch once or confirm with one key to trigger the end-to-end automated activation process, reducing the manual operation steps compared with the cumbersome multiple network connection verification processes in the traditional solution and improving the user experience.
[0059] The embodiments of the present disclosure also propose a Profile activation system, including: a user terminal, a service terminal, and a server. Among them, the service terminal is deployed at a geographical key node, and the user terminal is used to establish a connection with the service terminal through NFC.
[0060] As an example, a near-field Profile distribution network is set up at geographical key nodes. For example, eSIM service terminals are deployed in places such as airports, customs, and hotels, with the Profile data of the mainstream operators in the target region built in. The eSIM service terminal is built in with an NFC module, supporting one-key download by the user through NFC touch. The eSIM service terminal is used for the local profile assistant (LPA) function to implement protocol conversion and data packet processing, realizing the virtualized LPA function of the service terminal. On the user terminal side, the ISD-R is pre-configured as contactless optional to interact with the eSIM service terminal to realize a restricted ISD-R security domain.
[0061] In this embodiment, the service terminal is used to obtain the eUICC information of the user terminal and send the eUICC information to the server to request eUICC authentication from the server. The service terminal is also used to receive the response information returned after the server's authentication passes and send the response information to the user terminal. The user terminal is also used to establish a secure channel according to the response information. The service terminal is also used to receive the Profile data sent by the server through the secure channel and send the Profile data to the user terminal. The user terminal is also used to perform activation processing according to the Profile data.
[0062] As an example, taking the airport scenario as an example, an eSIM service terminal is set up at the airport. The user scans the eSIM service terminal through a mobile terminal, selects the option for the target region, touches the eSIM service terminal via NFC to download the Profile. After verifying the legality and integrity of the Profile, it is sent to the eUICC and the installation of the Profile is gradually completed. Taking the cross-border bus scenario as an example, an eSIM service terminal is deployed inside the bus. The user interacts with the eSIM service terminal through the mobile terminal to obtain the built-in operator Profile, and immediately switches the network after downloading and activating it.
[0063] Figure 3 The following is a schematic structural diagram of a Profile activation device provided by an embodiment of the present disclosure, as Figure 3 shown. The Profile activation device includes: a sending module 31, a response module 32, and an activation module 33.
[0064] The sending module 31 is configured to, in response to establishing a connection with the service terminal via NFC, send the eUICC information of the user terminal to the service terminal to request eUICC authentication;
[0065] The response module 32 is configured to receive the response information returned by the service terminal after the authentication is passed, and establish a secure channel according to the response information;
[0066] The activation module 33 is configured to, in response to the establishment of the secure channel, receive the Profile data sent by the service terminal, and perform activation processing according to the Profile data.
[0067] In an embodiment of the present disclosure, establishing a connection with the service terminal via NFC includes: selecting the ISD-R security domain via NFC to establish a connection with the service terminal; wherein, the ISD-R is pre-configured as an optional near-field communication module during the eUICC development stage to support non-contact selection.
[0068] In an embodiment of the present disclosure, establishing a connection with the service terminal via NFC includes: in response to obtaining the first verification code input by the user, sending the first verification code to the eUICC; wherein, the first verification code is generated by the service terminal; during the process of establishing the connection, receiving the second verification code sent by the service terminal, so that the eUICC verifies through the first verification code and the second verification code; in the case where the verification result is passed, establishing a connection with the service terminal via NFC.
[0069] In an embodiment of the present disclosure, the device further includes:
[0070] The permission management module is used to obtain the type of the operation to be executed when ISD-R communicates through the non-contact channel; if the type of the operation to be executed does not match the preset permission information, the operation to be executed is prohibited.
[0071] Another Profile activation device is proposed in an embodiment of the present disclosure, including: an acquisition module, a request module, an information interaction module, and a forwarding module.
[0072] Among them, the acquisition module is used to obtain the eUICC information of the user terminal in response to establishing a connection with the user terminal through NFC;
[0073] The request module is used to send the eUICC information to the server to request eUICC authentication from the server;
[0074] The information interaction module is used to receive the response information returned by the server after successful authentication and send the response information to the user terminal to enable the user terminal to establish a secure channel;
[0075] The forwarding module is used to receive the Profile data sent by the server through the secure channel and send the Profile data to the user terminal.
[0076] In an embodiment of the present disclosure, the forwarding module is specifically used for:
[0077] Performing data packet splitting on the Profile data to split the Profile data into multiple APDU data;
[0078] Sending the multiple APDU data to the ISD-R of the user terminal one by one, so that the ISD-R verifies and executes the APDU data one by one to achieve Profile writing; or,
[0079] Sending the Profile data to the eUICC cache of the user terminal, so that the eUICC disassembles the Profile data into APDU data and installs them one by one.
[0080] In an embodiment of the present disclosure, the forwarding module is specifically used for:
[0081] Calculating the hash value corresponding to the Profile data;
[0082] Sending the Profile data and the corresponding hash value to the user terminal.
[0083] The Profile activation device provided by the embodiment of the present disclosure can execute the Profile activation method provided by the embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects for executing the method. The content not described in detail in the device embodiment of the present disclosure can be referred to the description in any method embodiment of the present disclosure.
[0084] An electronic device provided by an embodiment of the present disclosure further includes one or more processors and a memory. The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions. The memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage media, and the processor may run the program instructions to implement the methods of the embodiments of the present disclosure above and / or other desired functions. Various contents such as input signals, signal components, noise components, etc. may also be stored in the computer-readable storage media.
[0085] In one example, the electronic device may further include: an input device and an output device, and these components are interconnected through a bus system and / or other forms of connection mechanisms. In addition, the input device may include, for example, a keyboard, a mouse, etc. The output device may output various information to the outside, including the determined distance information, direction information, etc. The output device may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc. In addition, according to specific application scenarios, the electronic device may further include any other appropriate components such as a bus, an input / output interface, etc.
[0086] In addition to the above methods and devices, an embodiment of the present disclosure may also be a computer program product, which includes computer program instructions that cause the processor to execute any method provided by the embodiment of the present disclosure when the computer program instructions are run by the processor.
[0087] The computer program product may be written in any combination of one or more programming languages to write program code for performing the operations of the embodiments of the present disclosure. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as an independent software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0088] In addition, an embodiment of the present disclosure may also be a computer-readable storage medium having computer program instructions stored thereon, and when the computer program instructions are run by a processor, the processor is caused to execute any method provided by the embodiments of the present disclosure.
[0089] The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may, for example, include but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0090] It should be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device including a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including a..." does not exclude the presence of additional identical elements in the process, method, article, or device including the element.
[0091] The above are only specific embodiments of the present disclosure, enabling those skilled in the art to understand or implement the present disclosure. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to the embodiments described herein, but rather will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A Profile activation method, characterized in that Applied to a service terminal deployed at a geographical key node, the method includes: In response to establishing a connection with a user terminal via NFC, obtain the eUICC information of the user terminal; Send the eUICC information to a server to request eUICC authentication from the server; Receive the response information returned by the server after successful authentication and send the response information to the user terminal, so that the user terminal establishes a secure channel; Receive the Profile data sent by the server via the secure channel and send the Profile data to the user terminal.
2. The method according to claim 1, characterized in that The sending the Profile data to the user terminal includes: Perform data packet splitting on the Profile data to split the Profile data into multiple APDU data; Send the multiple APDU data to the ISD-R of the user terminal one by one, so that the ISD-R verifies and executes the APDU data one by one to achieve Profile writing; or, Send the Profile data to the eUICC cache of the user terminal, so that the eUICC disassembles the Profile data into APDU data and installs them one by one.
3. The method according to claim 1, characterized in that, The sending the Profile data to the user terminal includes: Calculate the hash value corresponding to the Profile data; Send the Profile data and the corresponding hash value to the user terminal.
4. A Profile activation method, characterized in that, Applied to a user terminal, the method includes: In response to establishing a connection with a service terminal via NFC, send the eUICC information of the user terminal to the service terminal to request eUICC authentication; Receive the response information returned by the service terminal after successful authentication to establish a secure channel according to the response information; In response to the establishment of the secure channel, receive the Profile data sent by the service terminal and perform activation processing according to the Profile data.
5. The method according to claim 4, characterized in that, The establishing a connection with a service terminal via NFC includes: Select the ISD-R security domain via NFC to establish a connection with the service terminal; wherein, the ISD-R is pre-configured as an optional near-field communication module during the eUICC development phase to support contactless selection.
6. The method according to claim 4, wherein, The establishing a connection with a service terminal via NFC includes: In response to obtaining a first verification code input by the user, send the first verification code to the eUICC; wherein, the first verification code is generated by the service terminal; During the connection establishment process, receive a second verification code sent by the service terminal, so that the eUICC verifies through the first verification code and the second verification code; In the case where the verification result is passed, establish a connection with the service terminal via NFC.
7. The method according to claim 5, wherein The method further includes: In the case where the ISD-R communicates via a contactless channel, obtain the type of the operation to be executed; If the type of the operation to be executed does not match the preset permission information, prohibit the operation to be executed.
8. A Profile activation device, characterized in that, Includes: A sending module, configured to send the eUICC information of the user terminal to the service terminal to request eUICC authentication in response to establishing a connection with the service terminal via NFC; A response module, configured to receive the response information returned by the service terminal after successful authentication, and establish a secure channel according to the response information; An activation module, configured to receive the Profile data sent by the service terminal in response to the establishment of the secure channel, and perform activation processing according to the Profile data.
9. An electronic device, characterized in that, Comprising: A processor; A memory for storing executable instructions of the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the Profile activation method according to any one of claims 1-7 above.
10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and when the computer program is executed by the processor, the Profile activation method according to any one of claims 1-7 above is implemented.