SE and USIM dual-chip sealing card device and application method thereof

Through the SE and USIM dual-chip sealing solution, physical isolation and independent operation are achieved, security risks in shared chip design are solved, security and integration of smart cards are improved, and the modification and communication process of hardware terminals are simplified.

CN120493972APending Publication Date: 2025-08-15EASTCOMPEACE TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510507668.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the existing smart card technology, SE and USIM share a chip design that poses security risks, SE-related keys or services face risks of leakage, and users' requirements for security levels are constantly increasing.

Method used

Using the SE and USIM dual-chip sealing scheme, the SE and USIM chips are physically isolated. The respective keys are generated, stored and updated by different managers, and communicated through the SE chip to simulate the 7816 signal, providing a consistent 7816 interface for independent operation and high integration.

Benefits of technology

Enhanced security, prevent SE-related information from being leaked, improve product security level, reduce the size and cost of smart cards, simplify the changes and communication process of hardware terminals, and ensure independent operation and no interference between SE and USIM.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120493972A_ABST
    Figure CN120493972A_ABST
Patent Text Reader

Abstract

The invention provides an SE and USIM dual-chip sealing card device and an application method thereof, the device comprises a contact module, an SE chip and a USIM chip, a plurality of pins of the SE chip and the USIM chip are correspondingly connected with a plurality of contacts of the contact module respectively, and VCC, GND, RST and CLK pins of the SE chip and the USIM chip are shared; an IO pin of the SE chip is connected with a contact C7 of the contact module, an IO pin of the USIM chip is connected with a GPIO pin of the SE chip, and 7816 signals are simulated through the GPIO pin of the SE chip for communication; the SE chip and the USIM chip are physically isolated, a secret key of the SE chip is generated, stored, updated and distributed by a first management party, and a secret key of the USIM chip is generated, stored, updated and distributed by a second management party. According to the invention, a novel SE and USIM dual-chip sealing scheme is provided, and the SE and the USIM are physically isolated, so that the risk that a secret key or service related to the SE is leaked is effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of smart cards, and in particular to a SE and USIM dual-chip sealing card device and method thereof. Background Art

[0002] With the rapid development of smart card technology, its application in finance, communications, transportation, and other fields is becoming increasingly widespread. In existing smart card technology, the secure element (SE) and user identity module (USIM) often share a single chip. While this design simplifies the smart card structure to a certain extent, it also introduces a series of security issues.

[0003] Specifically, the SE, as the core security module in the smart card, is responsible for storing and processing sensitive information such as keys and certificates. The USIM, on the other hand, stores user identity information and enables communication with the network. In existing co-chip designs, SE applications are typically installed in the USIM's SSD (Secure Storage Domain) or ISD (Identification Storage Domain). Because the USIM itself is managed by the operator, this design exposes SE-related keys or services to the risk of leakage.

[0004] On the one hand, operators may inadvertently access sensitive information in the SE during the management and maintenance of USIM cards. On the other hand, once the USIM card is illegally obtained or cracked, attackers may be able to extract the secret keys or business data in the SE through reverse engineering and other means, seriously threatening user information security.

[0005] Furthermore, with the continuous advancement of smart card technology, users are demanding higher security levels. In applications like mobile payments and identity verification, any security vulnerability can lead to significant financial losses or privacy breaches. Therefore, improving the security of smart cards has become a pressing issue for the industry. Summary of the Invention

[0006] In view of the serious security risks posed by the design of sharing a chip between the SE and the USIM in existing smart card technology, the present invention provides a SE and USIM dual-chip card sealing device and method, and provides a new SE and USIM dual-chip sealing solution. By physically isolating the SE and the USIM, the risk of leakage of SE-related secret keys or services is effectively prevented.

[0007] The present invention achieves the above-mentioned purpose through the following technical solutions:

[0008] A SE and USIM dual-chip card sealing device, comprising:

[0009] Contact module, SE chip and USIM chip, multiple pins of SE chip and USIM chip are respectively connected to multiple contacts of the contact module, and VCC, GND, RST and CLK pins of SE chip and USIM chip are shared;

[0010] Among them, the IO pin of the SE chip is connected to the contact C7 of the contact module, and the IO pin of the USIM is connected to the GPIO pin of the SE. Communication is performed by simulating the 7816 signal through the GPIO pin of the SE chip;

[0011] The SE chip and the USIM chip are physically isolated. The key of the SE chip is generated, stored, updated and distributed by the first management party, while the key of the USIM chip is generated, stored, updated and distributed by the second management party.

[0012] According to the present invention, a SE and USIM dual-chip sealed card device is provided, and the contact module includes contact C1, contact C2, contact C3, contact C4, contact C5, contact C6, contact C7, and contact C8. The terminal provides power to the card device through contact C1, and the VCC pins of the SE chip and the USIM chip are commonly connected to contact C1, sharing a power input; the terminal resets the card device through contact C2, and the RST pins of the SE chip and the USIM chip are commonly connected to contact C2, sharing a reset pin; the terminal provides a 7816 clock signal to the card device through contact C3, and the CLK pins of the SE chip and the USIM chip are commonly connected to contact C3, sharing a clock signal source; the GND pins of the SE chip and the USIM chip are commonly connected to contact C5; the terminal sends data to the card device through contact C7, the IO pin of the SE chip is connected to contact C7, and the IO pin of the USIM chip is connected to the GPIO pin of the SE chip. The SE chip simulates 7816 communication through the GPIO pin.

[0013] According to the present invention, a SE and USIM dual-chip card sealing device further includes:

[0014] The first management party business processing module is used to implement the business functions of the first management party APP on the mobile terminal and the business management functions of the PC-side issuance management tool by accessing the SE chip in the card sealing device; the first management party business functions comply with the GM-T 0017-2012 Intelligent Password Key Password Application Interface Data Format Specification;

[0015] The driver interface provides a module that provides an interface API for the first management party's business. The mobile terminal provides a driver interface in .SO format, and the PC terminal provides a driver interface in DLL format. The provided driver interface complies with the GM-T 0016-2012 specification;

[0016] The second management party business processing module is used to access the USIM chip in the card sealing device through the SE, and is at least used to implement the operator's OTA, STK and network access authentication business functions.

[0017] An application method of a SE and USIM dual-chip card sealing device, which is applied to the above-mentioned SE and USIM dual-chip card sealing device, comprises the following steps:

[0018] When the terminal is powered on, the card sealing device is reset according to the 7816 specification timing, and the card sealing device returns the response reset ATR information of the SE chip;

[0019] After the SE chip is powered on and initialized, it communicates with the terminal using the default baud rate;

[0020] The SE chip and the USIM chip communicate at a pre-configured fixed baud rate;

[0021] When the USIM chip is powered on, it receives the protocol and parameter selection PPS command sent by the SE chip to negotiate the communication baud rate;

[0022] The card sealing device receives the application protocol data APDU sent by the terminal and determines whether the APDU is to be processed by the SE chip or the USIM chip according to the application selected on the current logical channel;

[0023] When the APDU is determined to be a command from the USIM chip, the SE chip implements transparent transmission processing, transparently transmits the APDU to the USIM chip for processing, and returns the response of the USIM chip to the terminal;

[0024] When the SE chip processes the protocol and parameter selection PPS request from the terminal, it negotiates a new communication rate with the terminal.

[0025] According to an application method of a SE and USIM dual-chip card sealing device provided by the present invention, the SE chip also implements a card reader function. During the transparent transmission process, the following steps are specifically performed to achieve communication with the USIM chip:

[0026] Receive instructions from the terminal directed to the USIM chip, accurately pass the instructions to the USIM chip for processing, and receive the response generated by the USIM chip in response to the instructions to ensure that the response is returned to the terminal accurately.

[0027] According to an application method of the SE and USIM dual-chip card sealing device provided by the present invention, the SE chip acts as an intermediate medium to realize communication between the terminal and the USIM card, and is applicable to the following instruction formats:

[0028] CASE 1: 7816 instruction format, no input and no output;

[0029] CASE 2: 7816 instruction format, no input but response;

[0030] CASE 3: 7816 instruction format, input but no response;

[0031] CASE 4: 7816 instruction format, with input and response.

[0032] According to an application method of an SE and USIM dual-chip card sealing device provided by the present invention, the interaction between the SE chip and the USIM card specifically includes the following steps:

[0033] The SE chip receives the 5-byte APDU header from the terminal and transparently transmits it to the USIM chip;

[0034] The SE chip receives the response from the USIM chip after processing the 5-byte APDU header, as well as the length of the data returned by the USIM chip;

[0035] The SE chip determines how the USIM chip processes the APDU header based on the first byte of the received data:

[0036] If the first byte is 0x60, ignore this byte and continue to receive the data returned by the USIM chip;

[0037] If the first byte is neither 0x60 nor ACK byte, it is determined to be a two-byte status word processed by the USIM chip, indicating that the USIM command reported an error or the terminal sent a CASE 1 command;

[0038] If the first byte is an ACK byte, further judgment and processing are performed based on the length of the received data.

[0039] According to an application method of a SE and USIM dual-chip card sealing device provided by the present invention, when the first byte of the data received by the SE chip is ACK and the data length is greater than 1, the terminal instruction received at this time is CASE2, and the following steps are performed:

[0040] The SE chip returns the ACK byte and the response data to the terminal as a response to the terminal instruction.

[0041] According to an application method of a SE and USIM dual-chip card sealing device provided by the present invention, when the first byte of data received by the SE chip is ACK and the data length is equal to 1, the following steps are performed:

[0042] The SE chip returns the ACK byte to the terminal;

[0043] The SE chip then receives the remaining APDU body of the current command sent by the terminal;

[0044] The SE chip transparently transmits the received APDU body to the USIM chip;

[0045] The SE chip receives the response of the USIM chip to the APDU body, which is a two-byte status word.

[0046] According to an application method of an SE and USIM dual-chip card sealing device provided by the present invention, when a terminal sends a CASE3 or CASE4 instruction and the SE chip has transparently transmitted the corresponding APDU body to the USIM card, the SE chip receives the USIM card's response to the APDU body, which is only a two-byte status word. The SE chip determines the type of instruction sent by the terminal based on the received two-byte status word:

[0047] If the terminal sends a CASE 3 command, the SE chip confirms that the command processing is complete and returns a two-byte status word to the terminal as a response;

[0048] If the terminal sends a CASE 4 command and the received two-byte status word indicates that no error is reported, the SE chip prepares to receive subsequent commands sent by the terminal to obtain the specific response data of the USIM card for the CASE 4 command; in this case, the SE chip does not directly return the two-byte status word as the final response, but waits for further instructions from the terminal to continue the interaction process.

[0049] It can be seen that compared with the prior art, the present invention has the following beneficial effects:

[0050] 1. Physical isolation for enhanced security: This invention physically isolates the SE chip and USIM chip. Their respective keys are owned by different individuals and operated and used by different personnel. This effectively prevents information leakage and mutual interference between the SE and USIM, ensuring the independence and security of the keys. Even if the USIM chip is illegally obtained or cracked, the sensitive information in the SE chip cannot be directly accessed, thereby significantly improving the overall security level of the product.

[0051] 2. High integration and reduced size: Mobile phone terminals already require an SE chip and a USIM communication chip. This invention achieves higher integration by combining the two chips, making the smart card smaller and lighter. This not only improves the portability and aesthetics of hardware terminals such as mobile phones, but also reduces production costs and manufacturing difficulty.

[0052] 3. Consistent interface, no need to change hardware terminals: The sealed chip of the present invention provides a 7816 interface consistent with a single chip, which means that hardware terminals such as mobile phones can be used directly without any changes. This compatibility design greatly simplifies the deployment and application process of smart cards and reduces the user's usage threshold and cost.

[0053] 4. Pin-to-Pin Sealing, Independent Operation: This invention utilizes a pin-to-pin sealing solution for the SE and USIM chips, achieving a close physical connection while ensuring operational independence of the two chips. This design facilitates chip packaging and manufacturing while ensuring independent operation of SE and USIM applications without interfering with each other.

[0054] 5. Software-based card reader functionality simplifies communication: This invention utilizes the SE chip to implement a card reader, allowing the mobile phone terminal to communicate directly with the USIM chip. This simplifies the communication process and improves communication efficiency and stability. Furthermore, since the SE chip, as the master chip, manages and controls the communication process, it further enhances communication security.

[0055] In summary, the SE and USIM dual-chip sealing solution of the present invention has significant beneficial effects, not only improving the safety and integration of the product, but also simplifying the modification and communication process of the hardware terminal.

[0056] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 This is a pin schematic diagram of an embodiment of a SE and USIM dual-chip card sealing device of the present invention.

[0058] Figure 2 This is a schematic diagram of a first management party, a driving interface, and a second management party in an embodiment of an application method of an SE and USIM dual-chip card sealing device of the present invention.

[0059] Figure 3 This is a flow chart of interaction with a terminal in an embodiment of an application method of an SE and USIM dual-chip card sealing device of the present invention.

[0060] Figure 4 This is a flow chart of the interaction between the SE chip and the USIM chip in an embodiment of an application method of an SE and USIM dual-chip card sealing device of the present invention. DETAILED DESCRIPTION

[0061] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0062] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0063] See also Figure 1 and Figure 2 This embodiment provides a SE and USIM dual-chip card sealing device, including:

[0064] Contact module, SE chip and USIM chip, multiple pins of SE chip and USIM chip are respectively connected to multiple contacts of the contact module, and VCC, GND, RST and CLK pins of SE chip and USIM chip are shared;

[0065] Among them, the IO pin of the SE chip is connected to the contact C7 of the contact module, and the IO pin of the USIM is connected to the GPIO pin of the SE. Communication is performed by simulating the 7816 signal through the GPIO pin of the SE chip;

[0066] The SE chip and the USIM chip are physically isolated. The key of the SE chip is generated, stored, updated and distributed by the first management party, while the key of the USIM chip is generated, stored, updated and distributed by the second management party.

[0067] Among them, the keys of the SE chip are used to protect highly sensitive data stored in the SE, including but not limited to the device unique identification key (HUK), device root key (DRK), authentication key and signature key; the keys of the USIM chip are used to protect the security context and communication keys stored in the USIM to ensure faster reconnection and data security when the user is at home and roaming.

[0068] In order to achieve the sealing of two chips and communicate with the mobile terminal using the 7816 interface, this embodiment proposes the following solution:

[0069] The SE and USIM chips share the VCC, GND, RST, and CLK pins. The SE's IO pin is connected to the C7 pin, and the USIM's IO pin is connected to the SE's GPIO (the SE's GPIO pin simulates the 7816 signal).

[0070] SE is the main chip responsible for communicating with the mobile terminal (card reader, etc.) 7816.

[0071] SE is the main chip, and its software is responsible for distributing instructions to the USIM card and obtaining the response from the USIM card and returning it to the mobile terminal, so that the mobile terminal can communicate with the USIM card through the SE main chip to realize the functions of the main 7816.

[0072] Provide the corresponding SDK to allow upper-level mobile applications to access the Applet in SE, and do not conflict with mobile phone network authentication or operator OTA management of USIM.

[0073] In this embodiment, the contact module includes contact C1, contact C2, contact C3, contact C4, contact C5, contact C6, contact C7, and contact C8. The terminal provides power to the card device through contact C1. The VCC pins of the SE chip and the USIM chip are connected to contact C1, sharing a common power input. The terminal resets the card device through contact C2. The RST pins of the SE chip and the USIM chip are connected to contact C2, sharing a common reset pin. The terminal provides a 7816 clock signal to the card device through contact C3. The CLK pins of the SE chip and the USIM chip are connected to contact C3, sharing a common clock signal source. The GND pins of the SE chip and the USIM chip are connected to contact C5. The terminal sends data to the card device through contact C7. The IO pin of the SE chip is connected to contact C7, and the IO pin of the USIM chip is connected to the GPIO pin of the SE chip. The SE chip simulates 7816 communication through the GPIO pin. Among them, the IDC4 / C8 / C6 contacts are not used yet in this embodiment.

[0074] In this embodiment, the device further includes:

[0075] The first management party business processing module is used to implement the business functions of the first management party APP on the mobile terminal and the business management functions of the PC-side issuance management tool by accessing the SE chip in the card sealing device; the first management party's business functions comply with the GM-T 0017-2012 smart password key password application interface data format specification.

[0076] The driver interface provides a module that provides an interface API for the first management party's business. The mobile terminal provides a driver interface in .SO format, and the PC terminal provides a driver interface in DLL format. The provided driver interface complies with the GM-T 0016-2012 specification.

[0077] The second management party business processing module is used to access the USIM chip in the card sealing device through the SE, and is at least used to implement the operator's OTA, STK and network access authentication business functions.

[0078] Among them, the first management party business processing module, the driver interface providing module and the second management party business processing module are independent of each other and work together to ensure the safe and efficient operation of the sealing card in different business scenarios.

[0079] In this embodiment, the first management party includes but is not limited to police services. Other government agencies such as tax, customs, and social security may also need to access the SE to perform specific security services. Financial institutions such as banks and securities companies may need to use the SE to ensure the security of services such as mobile payments, online transactions, and customer identity verification. Alternatively, in the field of the Internet of Things, the SE can be used for device authentication, data encryption, and access control to ensure the security of the IoT system. Developers who provide application software or services that require high security support may also need to use the SE to enhance the security of their products.

[0080] In summary, the first management party can be any organization or system that requires the security features provided by an SE to ensure the security of its business. These organizations or systems may span different industries, but they all require an SE to provide secure and reliable authentication, data encryption, and access control services. This includes user apps on mobile devices and issuance management tools on PCs. This type of service involves accessing the SE within the sealed card and complies with GM-T 0017-2012, "Intelligent Password Key Cryptographic Application Interface Data Format Specification," which defines the data format interface standard for intelligent password keys in cryptographic applications.

[0081] The driver interface is the API provided to the service. The mobile version is a .SO (Shared Object, commonly used in Android systems), and the PC version is a DLL (Dynamic Link Library, commonly used in Windows systems). The service interface complies with GM-T 0016-2012.

[0082] The second management party includes, but is not limited to, carrier services. Carrier services such as OTA (Over-The-Air), STK (SIM Tool Kit), and network access authentication access the USIM module through the SE. Carrier services use the SE as a secure intermediary to interact with the USIM module to implement functions such as OTA updates, STK application execution, and user network access authentication.

[0083] An application method embodiment of a SE and USIM dual-chip sealing card device

[0084] like Figure 3 and Figure 4As shown, this embodiment provides an application method of a SE and USIM dual-chip card sealing device. The method is applied to the above-mentioned SE and USIM dual-chip card sealing device, and includes the following steps:

[0085] When the terminal is powered on, the card sealing device is reset according to the 7816 specification timing, and the card sealing device returns the response reset ATR information of the SE chip;

[0086] After the SE chip is powered on and initialized, it communicates with the terminal using the default baud rate;

[0087] The SE chip and the USIM chip communicate at a pre-configured fixed baud rate;

[0088] When the USIM chip is powered on, it receives the protocol and parameter selection PPS command sent by the SE chip to negotiate the communication baud rate;

[0089] The card sealing device receives the application protocol data APDU sent by the terminal and determines whether the APDU is to be processed by the SE chip or the USIM chip according to the application selected on the current logical channel;

[0090] When the APDU is determined to be a command from the USIM chip, the SE chip implements transparent transmission processing, transparently transmits the APDU to the USIM chip for processing, and returns the response of the USIM chip to the terminal;

[0091] When the SE chip processes the protocol and parameter selection PPS request from the terminal, it negotiates a new communication rate with the terminal.

[0092] In this embodiment, the SE chip also implements the card reader function. During the transparent transmission process, the following steps are specifically performed to achieve communication with the USIM chip:

[0093] Receive instructions from the terminal directed to the USIM chip, accurately pass the instructions to the USIM chip for processing, and receive the response generated by the USIM chip in response to the instructions to ensure that the response is returned to the terminal accurately.

[0094] Among them, the card sealing device implements specific applications through the security element (SE), such as GM-T0017 and other applications required by the user, and calls them through the software development kit (SDK) application program interface (API) defined by GM-T 0016.

[0095] In this embodiment, the SE chip acts as an intermediate medium to realize communication between the terminal and the USIM card, and is applicable to the following instruction formats:

[0096] CASE 1: 7816 instruction format, no input and no output;

[0097] CASE 2: 7816 instruction format, no input but response;

[0098] CASE 3: 7816 instruction format, input but no response;

[0099] CASE 4: 7816 instruction format, with input and response.

[0100] Specifically, the interaction process between the SE and USIM dual-chip sealing card device and a mobile phone or other terminal includes the following steps:

[0101] Step 1: When the terminal is powered on, the card sealing device will be reset according to the 7816 standard timing. At this time, the card sealing device returns the SE ATR.

[0102] Step 2: After the SE is powered on and initialized, it uses the default baud rate of 11 to communicate with the terminal.

[0103] Step 3: The SE and USIM communicate using a fixed baud rate. That is, the PPS between the SE and USIM can be configured to a common baud rate such as 94, 95, or 96.

[0104] Step 4: After the USIM module is powered on, it receives the PPS command from the SE to negotiate the communication baud rate.

[0105] Step 5: Since it is a sealed card, it will receive instructions from the SE application and the UISM module. The SE needs to determine whether the currently received APDU is to be processed by the SE application or the USIM module (depending on whether the application selected on the current logical channel is SE or USIM).

[0106] Step 6: The USIM command needs to be transparently transmitted to the USIM module for processing.

[0107] Step 7: SE applications, i.e., applications such as GM-T 0017 that the first management party needs to implement, are called through the SDK API defined by GM-T0016.

[0108] Step 8: SE processes the PPS request from the terminal. The sealing card (i.e., the main SE) needs to negotiate a new communication rate with the terminal, such as 94, 95, 96, etc.

[0109] Step 9: Transparent transmission processing, that is, SE needs to implement the card reader function, send the command sent by the terminal to the USIM, and return the USIM response to the terminal.

[0110] In this embodiment, the interaction between the SE chip and the USIM card specifically includes the following steps:

[0111] The SE chip receives the 5-byte APDU header from the terminal and transparently transmits it to the USIM chip;

[0112] The SE chip receives the response from the USIM chip after processing the 5-byte APDU header, as well as the length of the data returned by the USIM chip;

[0113] The SE chip determines how the USIM chip processes the APDU header based on the first byte of the received data:

[0114] If the first byte is 0x60, ignore this byte and continue to receive the data returned by the USIM chip;

[0115] If the first byte is neither 0x60 nor ACK byte, it is determined to be a two-byte status word processed by the USIM chip, indicating that the USIM command reported an error or the terminal sent a CASE 1 command;

[0116] If the first byte is an ACK byte, further judgment and processing are performed based on the length of the received data.

[0117] When the first byte of the data received by the SE chip is ACK and the data length is greater than 1, the terminal instruction received at this time is CASE2, and the following steps are performed:

[0118] The SE chip returns the ACK byte and the response data to the terminal as a response to the terminal instruction.

[0119] When the first byte of data received by the SE chip is ACK and the data length is 1, the following steps are performed:

[0120] The SE chip returns the ACK byte to the terminal;

[0121] The SE chip then receives the remaining APDU body of the current command sent by the terminal;

[0122] The SE chip transparently transmits the received APDU body to the USIM chip;

[0123] The SE chip receives the response of the USIM chip to the APDU body, which is a two-byte status word.

[0124] When the terminal sends a CASE 3 or CASE 4 command and the SE chip has transparently transmitted the corresponding APDU body to the USIM card, the SE chip receives the USIM card's response to the APDU body. The response is only a two-byte status word. The SE chip determines the type of command sent by the terminal based on the received two-byte status word:

[0125] If the terminal sends a CASE 3 command, the SE chip confirms that the command processing is complete and returns a two-byte status word to the terminal as a response;

[0126] If the terminal sends a CASE 4 command and the received two-byte status word indicates that no error is reported, the SE chip prepares to receive subsequent commands sent by the terminal to obtain the specific response data of the USIM card for the CASE 4 command; in this case, the SE chip does not directly return the two-byte status word as the final response, but waits for further instructions from the terminal to continue the interaction process.

[0127] Specifically, the interaction process between the SE chip and the USIM chip in this embodiment includes the following steps:

[0128] Step 1: At this time, the SE receives the 5-byte APDU header sent by the terminal and transparently transmits it to the USIM.

[0129] Step 2: The SE receives the response from the USIM and processes the 5-byte APDU header and the length of the data returned by the USIM.

[0130] Step 3: Determine the USIM's processing of the APDU header based on the first byte of the data received in step 2.

[0131] Step 4: If 0x60 byte is received, it means that the USIM needs longer processing time. In this case, ignore this byte and continue to receive data returned by the USIM.

[0132] Step 5: If the received byte is neither 0x60 nor ACK byte, then the received byte is a two-byte status word processed by the USIM. In this case, the USIM command reports an error or the terminal sends a CASE 1 command.

[0133] Step 6: If the first byte of the USIM response received is ACK, the command sent by the terminal may be Case 2, Case 3, or Case 4. The received data length must be determined to determine the correct processing. If the received data length is greater than 1, it indicates Case 2 and the ACK and response data must be returned to the terminal, which is Step 7. If the received data length is 1, the ACK must be returned to the terminal and the APDU body must be received, which is Step 8.

[0134] Step 7: At this time, the first byte received is ACK, and the data length is greater than 1, then the ACK and response data need to be returned to the terminal.

[0135] Step 8: At this time, the first byte received is ACK, and the data length is equal to 1. At this time, the terminal command received is CASE 3 or CASE 4. It is necessary to return ACK to the terminal, receive the remaining APDU body of the current command, and then transparently transmit it to the USIM, which is step 9.

[0136] Step 9: Send the APDU body of CASE 3 and CASE 4 instructions to the USIM, and then receive the USIM response.

[0137] Step 10: The response received at this time can only be a two-byte status word. If the terminal sends a CASE 3 command, the command processing ends here. If the terminal sends a CASE 4 command and no error is reported here, the response data requires the terminal to send the command again to obtain the USIM response data.

[0138] In summary, this embodiment physically isolates the SE chip and the USIM chip. Their respective keys are owned by different individuals and operated and used by different personnel. This effectively prevents information leakage and mutual interference between the SE and USIM, ensuring the independence and security of the keys. Even if the USIM chip is illegally obtained or cracked, sensitive information in the SE chip cannot be directly accessed, greatly improving the overall security level of the product.

[0139] Furthermore, this embodiment achieves higher integration through the sealing solution of two chips, making the smart card smaller and lighter, which not only contributes to the portability and aesthetics of hardware terminals such as mobile phones, but also reduces production costs and manufacturing difficulty.

[0140] Furthermore, the sealed chip of this embodiment provides a 7816 interface consistent with a single chip, which means that hardware terminals such as mobile phones can be used directly without any modifications. This compatibility design greatly simplifies the deployment and application process of smart cards and reduces the user's usage threshold and cost.

[0141] Furthermore, this embodiment uses a pin-to-pin solution for the SE and USIM chips, achieving a close physical connection while ensuring operational independence of the two chips. This design facilitates chip packaging and manufacturing while ensuring independent operation of the SE and USIM applications without interfering with each other.

[0142] Furthermore, in terms of software, this embodiment uses the SE chip to implement a card reader effect, allowing the mobile terminal to communicate directly with the USIM chip, simplifying the communication process and improving communication efficiency and stability. At the same time, because the SE chip acts as the main chip responsible for managing and controlling the communication process, it also further enhances communication security.

[0143] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0144] The above embodiments are only preferred embodiments of the present invention and cannot be used to limit the scope of protection of the present invention. Any non-substantial changes and replacements made by technicians in this field on the basis of the present invention fall within the scope of protection required by the present invention.

Claims

1. A SE and USIM dual-chip card sealing device, characterized in that: include: Contact module, SE chip and USIM chip, multiple pins of SE chip and USIM chip are respectively connected to multiple contacts of the contact module, and VCC, GND, RST and CLK pins of SE chip and USIM chip are shared; Among them, the IO pin of the SE chip is connected to the contact C7 of the contact module, and the IO pin of the USIM chip is connected to the GPIO pin of the SE chip. Communication is performed by simulating the 7816 signal through the GPIO pin of the SE chip; The SE chip and the USIM chip are physically isolated. The key of the SE chip is generated, stored, updated and distributed by the first management party, while the key of the USIM chip is generated, stored, updated and distributed by the second management party.

2. The device according to claim 1, characterized in that: The contact module includes contact C1, contact C2, contact C3, contact C4, contact C5, contact C6, contact C7, and contact C8. The terminal provides power to the card device through contact C1. The VCC pins of the SE chip and the USIM chip are connected to contact C1, sharing a common power input. The terminal resets the card device through contact C2. The RST pins of the SE chip and the USIM chip are connected to contact C2, sharing a common reset pin. The terminal provides a 7816 clock signal to the card device through contact C3. The CLK pins of the SE chip and the USIM chip are connected to contact C3, sharing a common clock signal source. The GND pins of the SE chip and the USIM chip are connected to contact C5. The terminal sends data to the card device through contact C7. The IO pin of the SE chip is connected to the contact C7, and the IO pin of the USIM chip is connected to the GPIO pin of the SE chip. The SE chip simulates 7816 communication through the GPIO pin.

3. The device according to claim 2, characterized in that Also includes: The first management party business processing module is used to implement the business functions of the first management party APP on the mobile terminal and the business management functions of the PC-side issuance management tool by accessing the SE chip in the card sealing device; the first management party business functions comply with the GM-T 0017-2012 Intelligent Password Key Password Application Interface Data Format Specification; The driver interface provides a module that provides an interface API for the first management party's business. The mobile terminal provides a driver interface in .SO format, and the PC terminal provides a driver interface in DLL format. The provided driver interface complies with the GM-T 0016-2012 specification; The second management party business processing module is used to access the USIM chip in the card sealing device through the SE chip, and is at least used to implement the operator's OTA, STK and network access authentication business functions.

4. An application method of a SE and USIM dual-chip card sealing device, characterized in that: The method is applied to the SE and USIM dual-chip sealing card device according to any one of claims 1 to 3, and the method comprises the following steps: When the terminal is powered on, the card sealing device is reset according to the 7816 specification timing, and the card sealing device returns the response reset ATR information of the SE chip; After the SE chip is powered on and initialized, it communicates with the terminal using the default baud rate; The SE chip and the USIM chip communicate at a pre-configured fixed baud rate; When the USIM chip is powered on, it receives the protocol and parameter selection PPS command sent by the SE chip to negotiate the communication baud rate; The card sealing device receives the application protocol data APDU sent by the terminal and determines whether the APDU is to be processed by the SE chip or the USIM chip according to the application selected on the current logical channel; When the APDU is determined to be a command from the USIM chip, the SE chip implements transparent transmission processing, transparently transmits the APDU to the USIM chip for processing, and returns the response of the USIM chip to the terminal; When the SE chip processes the protocol and parameter selection PPS request from the terminal, it negotiates a new communication rate with the terminal.

5. The method according to claim 4, characterized in that: The SE chip also implements the card reader function. During the transparent transmission process, the following steps are performed to achieve communication with the USIM chip: Receive instructions from the terminal directed to the USIM chip, accurately pass the instructions to the USIM chip for processing, and receive the response generated by the USIM chip in response to the instructions to ensure that the response is returned to the terminal accurately.

6. The method according to claim 4, characterized in that: The SE chip acts as an intermediary to enable communication between the terminal and the USIM card, and is applicable to the following instruction formats: CASE 1: 7816 instruction format, no input and no output; CASE 2: 7816 instruction format, no input but response; CASE 3: 7816 instruction format, input but no response; CASE 4: 7816 instruction format, with input and response.

7. The method according to claim 6, characterized in that The interaction between the SE chip and the USIM card specifically includes the following steps: The SE chip receives the 5-byte APDU header from the terminal and transparently transmits it to the USIM chip; The SE chip receives the response from the USIM chip after processing the 5-byte APDU header, as well as the length of the data returned by the USIM chip; The SE chip determines how the USIM chip processes the APDU header based on the first byte of the received data: If the first byte is 0x60, ignore this byte and continue to receive the data returned by the USIM chip; If the first byte is neither 0x60 nor ACK byte, it is determined to be a two-byte status word processed by the USIM chip, indicating that the USIM command reported an error or the terminal sent a CASE 1 command; If the first byte is an ACK byte, further judgment and processing are performed based on the length of the received data.

8. The method according to claim 7, characterized in that When the first byte of the data received by the SE chip is ACK and the data length is greater than 1, the terminal instruction received at this time is CASE2, and the following steps are performed: The SE chip returns the ACK byte and the response data to the terminal as a response to the terminal instruction.

9. The method according to claim 8, characterized in that When the first byte of data received by the SE chip is ACK and the data length is 1, the following steps are performed: The SE chip returns the ACK byte to the terminal; The SE chip then receives the remaining APDU body of the current command sent by the terminal; The SE chip transparently transmits the received APDU body to the USIM chip; The SE chip receives the response of the USIM chip to the APDU body, which is a two-byte status word.

10. The method according to claim 9, characterized in that: When the terminal sends a CASE 3 or CASE 4 command and the SE chip has transparently transmitted the corresponding APDU body to the USIM card, the SE chip receives the USIM card's response to the APDU body. This response is only a two-byte status word. The SE chip determines the type of command sent by the terminal based on the received two-byte status word: If the terminal sends a CASE 3 command, the SE chip confirms that the command processing is complete and returns a two-byte status word to the terminal as a response; If the terminal sends a CASE 4 command and the received two-byte status word indicates that no error is reported, the SE chip prepares to receive subsequent commands sent by the terminal to obtain the specific response data of the USIM card for the CASE 4 command; in this case, the SE chip does not directly return the two-byte status word as the final response, but waits for further instructions from the terminal to continue the interaction process.

Citation Information

Patent Citations

  • Double-chip safety SIM card

    CN111160508A

  • Multi-application physically isolated encrypted SIM card implementation device, method and terminal

    CN111400737A

  • Communication method and device between intelligent cards and storage medium

    CN113286357A

  • Intelligent card integrated with multiple chips and control method thereof

    CN116702821A