Configuration processing method and device of eSIM, equipment, medium and program product

By embedding a global access field in the eSIM profile and combining it with a comparison mechanism between application identifiers and whitelists, the storage waste and security risks caused by the strong binding of applications and profiles in eSIM are resolved, efficient configuration processing and dynamic management are achieved, and the security and flexibility of the eSIM ecosystem are improved.

CN120602910APending Publication Date: 2025-09-05CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510686995.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In existing eSIM technology, due to the strong binding between applications and profiles, applications in inactivated profiles cannot be reused by other profiles, resulting in wasted storage space and increased chip storage pressure. At the same time, local applications in inactivated profiles cannot be enabled in an offline environment, posing security risks, low configuration processing efficiency and insufficient dynamic management capabilities.

Method used

During the configuration file download phase, a global access field is embedded as a security anchor. A dynamic classification mechanism is established through source type identification. Combined with the precise comparison of application identifiers with pre-stored whitelists, an access barrier based on identity authentication is constructed to implement a closed-loop protection system from entry verification to deployment isolation, preventing illegal configuration intrusions and service interruptions of legitimate applications due to identifier conflicts.

Benefits of technology

It significantly enhances the eSIM ecosystem's defense depth against configuration tampering attacks, improves configuration processing efficiency and dynamic management capabilities, and ensures the flexibility and security of multi-profile parallel management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602910A_ABST
    Figure CN120602910A_ABST
Patent Text Reader

Abstract

The invention provides an eSIM configuration processing method and device, equipment, a medium and a program product, and relates to the technical field of mobile communication, and the method comprises the steps: obtaining a configuration file in response to a downloading request of the configuration file of an eSIM; the configuration file carries a global access field; identifying a source type of a source carried by the global access field; obtaining an application identifier carrying the source according to the source type; obtaining a global application identifier list; judging whether the carrying source exists in the global application identifier list or not according to the application identifier and the global application identifier list; if the carried source exists in the global application identifier list, returning configuration file error information; if the carried source does not exist in the global application identifier list, installing a configuration file in the eSIM; and the configuration processing efficiency and the dynamic management capability are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of mobile communication technologies, and in particular to an eSIM configuration processing method, apparatus, device, medium, and program product. Background Art

[0002] In current eSIM technology, a strong binding mechanism between profiles and application functions is a common industry design principle. This design not only breaks through the functional limitations of traditional SIM cards, but also meets the requirements of enterprise applications and IoT devices for dynamic configuration, multi-identity management, and high security through security enhancements. This opens up new paths for cross-operator collaboration and intelligent device upgrades. Therefore, developing more efficient eSIM configuration processing methods has become a promising direction.

[0003] Existing eSIM configuration methods primarily integrate network parameters and application functionality into profiles, combining dynamic activation status management with hardware-level security domain isolation to achieve flexible binding and on-demand activation of operator services and application ecosystems. Users can switch activated profiles based on the scenario, instantly accessing corresponding security services or communication functions. Hardware isolation also ensures that multiple profile data do not interfere with each other.

[0004] However, in the existing technology, due to the strong binding between applications and profiles, applications in inactivated profiles cannot be reused by other profiles, resulting in a waste of storage space; at the same time, users need to repeatedly download applications with the same functions for different scenarios, increasing the storage pressure of the chip; in addition, since local applications in inactivated profiles cannot be enabled in an offline environment, there are security risks and the original results cannot be retained, resulting in technical problems such as low configuration processing efficiency and insufficient dynamic management capabilities. Summary of the Invention

[0005] The eSIM configuration processing method, apparatus, device, medium, and program product provided in this application are used to achieve the technical effect of improving configuration processing efficiency and dynamic management capabilities.

[0006] In a first aspect, the present application provides an eSIM configuration processing method, comprising:

[0007] Responding to a configuration file download request from the eSIM, obtaining the configuration file; the configuration file carries a global access field;

[0008] Identifies the source type of the global access field;

[0009] According to the source type, obtain the application identifier that carries the source;

[0010] Get the list of global application identifiers;

[0011] According to the application identifier and the global application identifier list, determining whether the carried source exists in the global application identifier list;

[0012] If the source exists in the global application identifier list, a configuration file error message is returned;

[0013] If the source does not exist in the global application identifier list, the configuration file is installed in the eSIM.

[0014] In a possible implementation, the source type includes application and security domain.

[0015] In a possible implementation, obtaining the application identifier carrying the source according to the source type includes:

[0016] If the source type is application, obtain the application identifier of the application;

[0017] If the source type is a security domain, obtain the application identifier of the security domain and the application identifier of the application under the security domain.

[0018] In a possible implementation, before obtaining the configuration file, the method further includes:

[0019] Adjust the permissions of the source based on the global access field.

[0020] In one possible implementation, the source type includes application and security domain;

[0021] Accordingly, adjust the permissions for carrying sources based on the global access fields, including:

[0022] If the application has a global access field, adjust the application's access permissions to allow global access.

[0023] If the security domain has a global access field, adjust the access rights of the security domain to allow global access to all applications in the security domain.

[0024] In a possible implementation, if the source does not exist in the global application identifier list, after the eSIM installs the configuration file, the method further includes:

[0025] In response to a download request for a source, obtaining the source;

[0026] Determine whether the source carries a global access field;

[0027] If the source carries a global access field, obtain the global application identifier list;

[0028] Determine whether the carried source exists in the global application identifier list;

[0029] If the source exists in the global application identifier list, the installation fails.

[0030] If the source does not exist in the global application identifier list, install the source;

[0031] Add the application identifier corresponding to the source to the global application identifier list.

[0032] In a possible implementation, if the source does not exist in the global application identifier list, after the eSIM installs the configuration file, the method further includes:

[0033] In response to an update request for a global access field, determining an update operation corresponding to the update request; the update operation includes adding or deleting;

[0034] Based on the update operation, the global application identifier list is updated.

[0035] In a second aspect, the present application provides an eSIM configuration processing device, including:

[0036] A first acquisition module is configured to acquire a configuration file in response to a configuration file download request of the eSIM; the configuration file carries a global access field;

[0037] an identification module for identifying a source type of a carrying source of a global access field;

[0038] A second acquisition module is used to obtain an application identifier carrying a source according to a source type;

[0039] A third acquisition module is used to obtain a global application identifier list;

[0040] a determination module, configured to determine, based on the application identifier and the global application identifier list, whether the carried source exists in the global application identifier list;

[0041] A first processing module is configured to return a configuration file error message if the source of the carried application exists in the global application identifier list;

[0042] The second processing module is configured to install the configuration file in the eSIM if the carrying source does not exist in the global application identifier list.

[0043] In a possible implementation, the identification module is also used for source types, including applications and security domains.

[0044] In a possible implementation, the second acquisition module is further configured to:

[0045] If the source type is application, obtain the application identifier of the application;

[0046] If the source type is a security domain, obtain the application identifier of the security domain and the application identifier of the application under the security domain.

[0047] In a possible implementation, the first acquisition module is further configured to:

[0048] Adjust the permissions of the source based on the global access field.

[0049] In one possible implementation, the source type includes application and security domain;

[0050] Accordingly, the first acquisition module is further configured to:

[0051] If the application has a global access field, adjust the application's access permissions to allow global access.

[0052] If the security domain has a global access field, adjust the access rights of the security domain to allow global access to all applications in the security domain.

[0053] In a possible implementation, the second processing module is further configured to:

[0054] In response to a download request for a source, obtaining the source;

[0055] Determine whether the source carries a global access field;

[0056] If the source carries a global access field, obtain the global application identifier list;

[0057] Determine whether the carried source exists in the global application identifier list;

[0058] If the source exists in the global application identifier list, the installation fails.

[0059] If the source does not exist in the global application identifier list, install the source;

[0060] Add the application identifier corresponding to the source to the global application identifier list.

[0061] In a possible implementation manner, the second processing module is further configured to:

[0062] In response to an update request for a global access field, determining an update operation corresponding to the update request; the update operation includes adding or deleting;

[0063] Based on the update operation, the global application identifier list is updated.

[0064] In a third aspect, the present application provides an eSIM configuration processing device, including: a memory, a processor;

[0065] Memory stores computer-executable instructions;

[0066] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.

[0067] In a fourth aspect, the present application provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, they are used to implement the above first aspect and / or various possible implementation methods of the first aspect.

[0068] In a fifth aspect, the present application provides a computer program product, comprising a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementations of the first aspect.

[0069] This application provides an eSIM configuration processing method, apparatus, device, medium, and program product. This method embeds a global access field as a security anchor during the configuration file download phase, establishes a dynamic classification mechanism through source type identification, and builds an access barrier based on identity authentication by combining precise comparisons of application identifiers with pre-stored whitelists (global application identifier lists). This design intercepts illegal configurations before installation, preventing unauthorized applications from invading the eSIM security domain through forged configuration files and avoiding service interruptions for legitimate applications due to identifier conflicts. By replacing traditional post-audits with pre-emptive verification, a closed-loop protection system from entry verification to deployment isolation is formed while ensuring the flexibility of concurrent management of multiple profiles. This significantly enhances the eSIM ecosystem's defense depth against configuration tampering attacks, thereby achieving the technical effect of improving configuration processing efficiency and dynamic management capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0071] Figure 1 A schematic diagram of an application data processing system architecture provided in an embodiment of the present application;

[0072] Figure 2 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 1 ;

[0073] Figure 3 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 2 ;

[0074] Figure 4 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 3 ;

[0075] Figure 5 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 4 ;

[0076] Figure 6 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 5 ;

[0077] Figure 7 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 6 ;

[0078] Figure 8 A schematic diagram of the structure of an eSIM configuration processing device provided in an embodiment of the present application;

[0079] Figure 9 A schematic diagram of the structure of the eSIM configuration processing device provided in an embodiment of the present application.

[0080] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0081] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0082] Due to the strong binding between applications and profiles in existing technologies, applications in inactivated profiles cannot be reused by other profiles, resulting in a waste of storage space. At the same time, users need to repeatedly download applications with the same functions for different scenarios, increasing the storage pressure of the chip. In addition, since local applications in inactivated profiles cannot be enabled in an offline environment, there are security risks and the original results cannot be retained, resulting in low configuration processing efficiency and insufficient dynamic management capabilities.

[0083] To address the above-mentioned issues, the present application provides an eSIM configuration processing method, apparatus, device, medium, and program product. This method embeds a global access field as a security anchor during the configuration file download phase, establishes a dynamic classification mechanism through source type identification, and builds an access barrier based on identity authentication by combining precise comparison of application identifiers with a pre-stored whitelist (global application identifier list). This design intercepts illegal configurations before installation, preventing unauthorized applications from invading the eSIM security domain through forged configuration files and avoiding service interruptions for legitimate applications due to identifier conflicts. By replacing traditional post-audits with pre-emptive verification, while ensuring the flexibility of concurrent management of multiple profiles, a closed-loop protection system is formed from entry verification to deployment isolation, significantly enhancing the eSIM ecosystem's defense depth against configuration tampering attacks, thereby achieving the technical effect of improving configuration processing efficiency and dynamic management capabilities.

[0084] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0085] Figure 1 This is a schematic diagram of an application data processing system architecture provided in an embodiment of the present application. The application data processing system is a computer device. Figure 1 As shown, the above architecture includes at least one of a data acquisition device 101 , a processing device 102 and a display device 103 .

[0086] It is understood that the structure illustrated in the embodiments of this application does not constitute a specific limitation on the architecture of the application data processing system. In other feasible implementations of this application, the above architecture may include more or fewer components than shown, or combine or split certain components, or arrange the components differently. The specific configuration can be determined based on the actual application scenario and is not limited here. Figure 1 The components shown can be implemented in hardware, software, or a combination of software and hardware.

[0087] In a specific implementation process, the data acquisition device 101 may include an input / output interface and may also include a communication interface. The data acquisition device 101 may be connected to the processing device via the input / output interface or the communication interface.

[0088] Processing device 102 can implement a configuration security management mechanism based on dynamic source verification. Its core principle is to implement multi-dimensional identity authentication before configuration files are installed by correlating the global access field with a pre-stored whitelist (global application identifier list). First, the global access field carried in the configuration file is parsed to identify the request source type. The corresponding application identifier is then extracted for dual verification (double matching of source type and application identifier). Finally, access control decisions are made by comparing it with the global application identifier list. This concept breaks away from the traditional post-audit model of eSIM configuration management. By proactively intercepting illegal configuration files, it forms a closed-loop security protection system from entry verification to deployment control. While ensuring the flexibility of multiple profiles, it effectively defends against configuration tampering attacks, creating a lightweight and highly reliable security enhancement framework for the eSIM ecosystem.

[0089] The display device 103 may also be a touch screen display or a screen of a terminal device, which is used to receive user instructions while displaying the above content to achieve interaction with the user.

[0090] It should be understood that the above-mentioned processing device can be implemented by a processor reading instructions in a memory and executing the instructions, or it can be implemented by a chip circuit.

[0091] In addition, the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0092] Figure 2 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 1 ,like Figure 2 As shown, the eSIM configuration processing method provided in this embodiment includes:

[0093] S201. In response to a configuration file download request from an eSIM, obtain a configuration file; the configuration file carries a global access field.

[0094] When a user initiates a configuration file download request, the system first obtains the configuration file containing the global access field. This field indicates that the relevant security domain or application has special permissions for cross-profile use.

[0095] S202. Identify the source type of the source carried by the global access field.

[0096] By parsing the subject type carried by the global access field, the system can identify whether the permission setting object is a single application or the entire security domain.

[0097] S203. Obtain an application identifier that carries the source according to the source type.

[0098] Depending on the source type, the system will perform differentiated acquisition operations to obtain the corresponding application identifier carrying the source.

[0099] In a possible implementation, the source type includes application and security domain.

[0100] In this embodiment, a secure domain is a logical or physical unit in the eSIM card used to isolate different applications and data. Each secure domain has independent permissions, encryption keys, and access control policies to ensure data isolation and security between different applications. Applications must be deployed in a specific secure domain and have independent permissions and installation parameters.

[0101] S204: Obtain a list of global application identifiers.

[0102] The system retrieves a pre-maintained list of global application identifiers, which is the whitelist. It records all entities authorized to access across profiles, and standardizes permission control through centralized management.

[0103] S205: Determine, based on the application identifier and the global application identifier list, whether the carried source exists in the global application identifier list.

[0104] By comparing the application identifier with the global application identifier list, the system can determine whether the carried source exists in the global application identifier list.

[0105] S206: If the source exists in the global application identifier list, a configuration file error message is returned.

[0106] If the source is present in the global application identifier list, the system immediately terminates the installation and returns an error message.

[0107] S207: If the source does not exist in the global application identifier list, install the configuration file in the eSIM.

[0108] If the source does not exist in the global application identifier list, the system completes the installation of the profile in the eSIM.

[0109] The present application provides a configuration processing method for eSIM, which embeds a global access field as a security anchor point during the configuration file download phase, establishes a dynamic classification mechanism through source type identification, and builds an access barrier based on identity authentication by combining the precise comparison of application identifiers with pre-stored whitelists. This design intercepts illegal configurations before installation, preventing unauthorized applications from invading the eSIM security domain through forged configuration files, and avoiding service interruptions caused by identifier conflicts for legitimate applications. By replacing traditional post-audits with pre-emptive verification, while ensuring the flexibility of parallel management of multiple profiles, a closed-loop protection system from entry verification to deployment isolation is formed, significantly improving the defense depth of the eSIM ecosystem against configuration tampering attacks, thereby achieving the technical effect of improving configuration processing efficiency and dynamic management capabilities.

[0110] Figure 3 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 2 ,like Figure 3 As shown, this embodiment, based on the above embodiment, describes in detail the process of obtaining the application identifier, including:

[0111] S301. Identify the source type of the source carried by the global access field.

[0112] The system identifies the source type by parsing the subject of the global access field in the configuration file. Global access permissions can be set at the application or security domain level: if the field is attached to a specific application, the source type is application; if the field is attached to a security domain, the source type is security domain. This determination is a prerequisite for subsequent identifier retrieval. Because global access permissions for a security domain cascade across all subordinate applications, processing logic must be differentiated by source type.

[0113] S302: If the source type is application, obtain the application identifier of the application.

[0114] When the source type is determined to be an application, the application identifier of the application is directly extracted.

[0115] S303: If the source type is a security domain, obtain an application identifier of the security domain and an application identifier of the application under the security domain.

[0116] When the source type is determined to be a security domain, a dual identifier acquisition operation is required: first, the application identifier of the security domain itself is obtained, and then the application identifiers of all deployed applications under its jurisdiction are recursively obtained.

[0117] The eSIM configuration processing method provided in the embodiment of the present application can achieve differentiated acquisition of application identifiers by the system through accurate identification of the type of subject carrying global access rights, thereby realizing independent permission management at the application level and ensuring the complete transmission of all subordinate application identifiers when the security domain-level permissions are changed, thereby avoiding omission or crossing of global access capabilities due to misjudgment of the permission source, and providing accurate basic data for subsequent whitelist verification, thereby ensuring the accuracy of global access rights granted and the security of system operation in multiple security domains and multiple application scenarios within the eSIM card from the source, thereby achieving the technical effect of improving configuration processing efficiency and dynamic management capabilities.

[0118] Figure 4 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 3 ,like Figure 4 As shown, this embodiment, based on the above embodiment, describes in detail the process of obtaining the configuration file of the eSIM, including:

[0119] S401. Adjust the permission of the source according to the global access field.

[0120] The system dynamically adjusts the access permissions of related security domains or applications by parsing the global access fields carried in the configuration file.

[0121] If the field is marked as enabled, the corresponding entity is granted global access capabilities based on the source type (application or security domain);

[0122] When acting on a security domain, global access permissions are activated for all subordinate applications simultaneously. If a field is marked as disabled, the permissions are narrowed to the scope of the current profile. This process is achieved by modifying the reserved fields in the permission structure, ensuring that the permission status is strictly consistent with the configuration file content.

[0123] S402: In response to the eSIM configuration file download request, obtain the configuration file; the configuration file carries a global access field.

[0124] When a user initiates a configuration file download request, the system starts the configuration acquisition process. The acquired configuration file contains a key parameter, the global access field. This field acts as a permission identifier and triggers the permission verification mechanism between the security domain and the application during the download process.

[0125] By identifying the subject type carried in the field, the system can determine the specific scope of permissions that need to be adjusted (a single application or a security domain and its sub-applications), providing basic configuration data for subsequent permission verification and installation operations, and ensuring that global access capabilities are granted according to preset rules.

[0126] The eSIM configuration processing method provided in the embodiment of the present application dynamically adjusts permissions by parsing the global access field during downloading, which can not only activate / contract the global access capability of the security domain or application, but also implement differentiated permission configuration according to the carrier type. The permission status is pre-verified during the configuration acquisition stage to avoid the installation of invalid configuration files, ensure the accuracy of the global access permission granted in the eSIM card and the security of the system operation, thereby achieving the technical effect of improving configuration processing efficiency and dynamic management capabilities.

[0127] Figure 5 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 4 ,like Figure 5 As shown, this embodiment, based on the above embodiment, describes in detail the process of adjusting the authority of carrying the source, including:

[0128] S501: If the application carries a global access field, adjust the access permission of the application to allow global access.

[0129] When it is detected that an application carries a global access field, the system marks its access rights as globally accessible by modifying the preset reserved fields in the application's permission structure.

[0130] Specifically, as shown in the following table, when an application is detected to carry a global access field, bit b4 is selected in the reserved field of the third byte in the original security domain and application permissions and set as the global access field, indicating that the security domain or application can be globally accessed, that is, it can still be selected and used even if the profile is disabled and is not affected by the profile.

[0131] Table 1 Security domain and application permissions (first byte)

[0132]

[0133] Table 2 Security domain and application permissions (second byte)

[0134]

[0135] Table 3 Security domain and application permissions (3rd byte)

[0136]

[0137] It should be noted that this operation is only effective for the individual application and does not affect the permission configuration of other applications in the security domain to which it belongs or the security domain itself. This ensures that the application can still run independently when the profile to which it belongs is disabled. However, if the profile is deleted, the application will be removed simultaneously.

[0138] S502: If the security domain carries a global access field, adjust the access rights of the security domain so that all applications under the security domain are allowed global access.

[0139] When a security domain carries a global access field, the system activates its global access capability by modifying the reserved fields of the security domain permission structure and automatically extends the cascade permissions to all applications under the jurisdiction of the security domain.

[0140] This operation is implemented through the global application identifier list: the security domain global application identifier and its subordinate application global application identifiers are synchronously added to the whitelist (global application identifier list), allowing the entire security domain system to break through the Profile activation status restrictions and achieve cross-Profile access, but it must follow the rule of removing all subordinate applications when deleting the security domain.

[0141] The eSIM configuration processing method provided in the embodiment of the present application realizes the granting of global access capabilities at the application level or security domain level by dynamically adjusting access rights. It supports both independent operation of a single application across profiles and batch activation of global access rights for all applications under a security domain. Combined with the automated management of the global application identifier list, it ensures the atomicity and security of permission changes. At the same time, it avoids the residual of invalid resources through the Profile deletion linkage mechanism, thereby achieving the technical effect of improving configuration processing efficiency and dynamic management capabilities.

[0142] Figure 6 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 5 ,like Figure 6 As shown, this embodiment, based on the above embodiment, provides a supplementary description of the subsequent process after the configuration file is installed on the eSIM, including:

[0143] S601. In response to a download request for a source, obtain the source and determine whether the source carries a global access field.

[0144] When a user initiates a new download request (such as installing a security domain or application), the system first extracts the target entity (application or security domain) in the request and checks whether it contains a global access field. This operation is achieved by parsing the reserved fields of the entity's permission structure to determine whether the current installation operation involves granting global access rights.

[0145] S602: If the source carries a global access field, obtain a global application identifier list.

[0146] If it is detected that the target entity carries a global access field, the system needs to retrieve the pre-maintained global application identifier list.

[0147] This list records all security domains and global application identifiers that are authorized to access across profiles. It is the core basis for subsequent permission verification and ensures that the granting of global access capabilities is controlled by the whitelist mechanism.

[0148] S603: Determine whether the carrying source exists in the global application identifier list.

[0149] The system compares the target entity's application global application identifier with the global list to verify whether it already exists in the global application identifier list.

[0150] S604: If the source exists in the global application identifier list, an installation failure message is returned.

[0151] If the source exists in the global application identifier list, the system determines that this installation will result in repeated granting of global access rights. To avoid permission conflicts, the installation process is immediately terminated and an installation failure message is returned to prevent management confusion caused by repeated authorization.

[0152] S605: If the carried source does not exist in the global application identifier list, install the carried source.

[0153] If the source does not exist in the global application identifier list, the system determines that this installation is a legitimate new permission granting operation and continues to execute the standard installation process to install the source.

[0154] S606: Add the application identifier corresponding to the source to the global application identifier list.

[0155] After the installation is complete, the system adds the global application identifier of the newly deployed entity (the security domain must include the global application identifiers of all its subordinate applications) to the global application identifier list to complete the closed-loop management of permission granting.

[0156] The configuration processing method of the eSIM provided in the embodiment of the present application automatically detects the global access permission configuration when receiving a download request through the dynamic verification mechanism in the installation process, and implements access control in combination with the pre-maintained global application identifier list. When it is detected that the entity to be installed has obtained global access authorization, the system immediately terminates the installation and feedbacks the failure information, effectively avoiding the management chaos caused by repeated granting of permissions; for legal new permission granting operations, its identifier is automatically entered into the whitelist after the entity deployment is completed, forming a closed-loop management of permission granting. This mechanism not only ensures the integrity of permission inheritance through security domain cascade verification, but also uses automated processes to reduce the risk of manual intervention, ensure the dynamic consistency of global access capabilities within the eSIM card, and achieve dual enhancement of permission control and system security, thereby achieving the technical effect of improving configuration processing efficiency and dynamic management capabilities.

[0157] Figure 7 Schematic diagram of the process of configuring the eSIM provided in the embodiment of the present application Figure 6 ,like Figure 7 As shown, this embodiment, based on the above embodiment, continues to provide additional explanations on the subsequent process after the eSIM configuration file is installed, including:

[0158] S701 : In response to an update request for a global access field, determine an update operation corresponding to the update request; the update operation includes adding or deleting.

[0159] When the system receives an update instruction for global access rights, it first analyzes the operation type (addition or deletion) of the instruction. This process is achieved by detecting the operation identifier preset in the instruction;

[0160] For example, specific field values ​​are used to distinguish between "adding authorization" and "revoking authorization." The system then determines subsequent processing logic based on the operation type: if it's an add operation, the global application identifier of the target entity (application or security domain) is whitelisted (global application identifier list); if it's a delete operation, the global application identifier entry to be removed is located and marked, providing operational instructions for dynamically adjusting global access permissions.

[0161] S702: Update the global application identifier list according to the update operation.

[0162] The system updates the whitelist (global application identifier list) based on the operation type determined in S701 above:

[0163] When the operation type is add, add the global application identifier of the target entity (including the global application identifiers of all its subordinate applications if it is a security domain) to the global application identifier list, and perform permission verification to ensure that there are no duplicate entries;

[0164] When the operation type is delete, the target global application identifier and its associated cascade entries are removed from the whitelist (for example, when a security domain is deleted, its sub-application global application identifiers are removed simultaneously).

[0165] The eSIM configuration processing method provided in the embodiment of the present application realizes accurate update and maintenance of the whitelist by dynamically parsing the add and delete operation instructions of global access rights. When new authorization is required, the system automatically includes the identifiers of the target entity and its associated applications in the global control scope, and ensures the integrity of the security domain permission changes through cascading processing; when the revocation operation is performed, the relevant identifiers are removed synchronously and the cascade entries are cleared to avoid residual permissions. This process, through real-time verification and atomic update mechanisms, not only ensures the flexibility of granting global access capabilities, but also prevents security vulnerabilities caused by inconsistent permission status, while reducing the need for manual intervention, improving the degree of automation and operational security of permission management in the eSIM card, thereby achieving the technical effect of improving configuration processing efficiency and dynamic management capabilities.

[0166] Figure 8 This is a schematic diagram of the structure of the eSIM configuration processing device provided in an embodiment of the present application. The device of this embodiment can be in the form of software and / or hardware. Figure 8 As shown, the eSIM configuration processing device 800 provided in an embodiment of the present application includes: a first acquisition module 801, an identification module 802, a second acquisition module 803, a third acquisition module 804, a judgment module 805, a first processing module 806, and a second processing module 807:

[0167] A first acquisition module 801 is configured to acquire a configuration file in response to a configuration file download request from an eSIM; the configuration file carries a global access field;

[0168] Identification module 802, used to identify the source type of the source carried by the global access field;

[0169] The second acquisition module 803 is used to obtain the application identifier of the source according to the source type;

[0170] The third acquisition module 804 is used to obtain a global application identifier list;

[0171] A determination module 805 is configured to determine whether the carrying source exists in the global application identifier list based on the application identifier and the global application identifier list;

[0172] A first processing module 806 is configured to return a configuration file error message if the source of the carried application exists in the global application identifier list;

[0173] The second processing module 807 is configured to install the configuration file in the eSIM if the carrying source does not exist in the global application identifier list.

[0174] In a possible implementation, the identification module 802 is further used for source types, including applications and security domains.

[0175] In a possible implementation, the second obtaining module 803 is further configured to:

[0176] If the source type is application, obtain the application identifier of the application;

[0177] If the source type is a security domain, obtain the application identifier of the security domain and the application identifier of the application under the security domain.

[0178] In a possible implementation, the first obtaining module 801 is further configured to:

[0179] Adjust the permissions of the source based on the global access field.

[0180] In one possible implementation, the source type includes application and security domain;

[0181] Accordingly, the first obtaining module 801 is further configured to:

[0182] If the application has a global access field, adjust the application's access permissions to allow global access.

[0183] If the security domain has a global access field, adjust the access rights of the security domain to allow global access to all applications in the security domain.

[0184] In a possible implementation, the second processing module 807 is further configured to:

[0185] In response to a download request for a source, obtaining the source;

[0186] Determine whether the source carries a global access field;

[0187] If the source carries a global access field, obtain the global application identifier list;

[0188] Determine whether the carried source exists in the global application identifier list;

[0189] If the source exists in the global application identifier list, the installation fails.

[0190] If the source does not exist in the global application identifier list, install the source;

[0191] Add the application identifier corresponding to the source to the global application identifier list.

[0192] In a possible implementation, the second processing module 807 is further configured to:

[0193] In response to an update request for a global access field, determining an update operation corresponding to the update request; the update operation includes adding or deleting;

[0194] Based on the update operation, the global application identifier list is updated.

[0195] The eSIM configuration processing device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effects are similar and will not be described in detail in this embodiment.

[0196] Figure 9 This is a structural diagram of the eSIM configuration processing device provided in the embodiment of the present application. Figure 9 As shown, the eSIM configuration processing device 900 provided in this embodiment includes: at least one processor 901 and a memory 902. Optionally, the device 900 also includes a communication component 903. The processor 901, the memory 902, and the communication component 903 are connected via a bus.

[0197] During the specific implementation process, at least one processor 901 executes the computer-executable instructions stored in the memory 902, so that the at least one processor 901 performs the above method.

[0198] The specific implementation process of the processor 901 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.

[0199] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASICs), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly executed by a hardware processor or by a combination of hardware and software modules within the processor.

[0200] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage.

[0201] A bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be categorized as address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.

[0202] An embodiment of the present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0203] An embodiment of the present application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above-mentioned method is implemented.

[0204] The readable storage medium may be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0205] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.

[0206] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, either through an interface, electrical, mechanical, or other means.

[0207] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0208] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0209] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the method of the present invention. The aforementioned storage medium includes various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.

[0210] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0211] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.

Claims

1. A method for configuring an eSIM, characterized in that: include: Responding to a download request for a configuration file of the eSIM, obtaining the configuration file; The configuration file carries a global access field; Identifying a source type of a carrying source of the global access field; According to the source type, obtaining an application identifier of the carrying source; Get the list of global application identifiers; determining, based on the application identifier and the global application identifier list, whether the carrying source exists in the global application identifier list; If the carrying source exists in the global application identifier list, a configuration file error message is returned; If the carrying source does not exist in the global application identifier list, the configuration file is installed in the eSIM.

2. The method according to claim 1, characterized in that The source types include application and security domain.

3. The method according to claim 2, characterized in that The acquiring, according to the source type, an application identifier of the carrying source includes: If the source type is application, obtaining an application identifier of the application; If the source type is a security domain, an application identifier of the security domain and an application identifier of an application under the security domain are obtained.

4. The method according to claim 1, wherein Before obtaining the configuration file, the method further includes: According to the global access field, the authority of the carrying source is adjusted.

5. The method according to claim 4, characterized in that The source types include application and security domain; Accordingly, adjusting the permission of the carrying source according to the global access field includes: If the application carries the global access field, adjusting the access permission of the application to allow global access; If the security domain carries the global access field, the access rights of the security domain are adjusted so that all applications under the security domain are allowed global access.

6. The method according to any one of claims 1 to 5, characterized in that If the carrying source does not exist in the global application identifier list, after the eSIM installs the configuration file, the method further includes: In response to a download request for a source, obtaining the source; Determining whether the carrying source carries the global access field; If the carrying source carries the global access field, obtaining a global application identifier list; Determining whether the carrying source exists in the global application identifier list; If the source exists in the global application identifier list, an installation failure message is returned; If the carrying source does not exist in the global application identifier list, installing the carrying source; Add the application identifier corresponding to the carrying source to the global application identifier list.

7. The method according to any one of claims 1 to 5, characterized in that If the carrying source does not exist in the global application identifier list, after the eSIM installs the configuration file, the method further includes: In response to an update request for a global access field, determining an update operation corresponding to the update request; the update operation includes adding or deleting; According to the update operation, the global application identifier list is updated.

8. An eSIM configuration processing device, characterized in that: include: A first acquisition module, configured to acquire the configuration file in response to a download request of the configuration file of the eSIM; The configuration file carries a global access field; an identification module, configured to identify a source type of a source carried by the global access field; A second acquisition module is used to acquire the application identifier of the carrying source according to the source type; A third acquisition module is used to obtain a global application identifier list; a determination module, configured to determine, based on the application identifier and the global application identifier list, whether the carrying source exists in the global application identifier list; A first processing module, configured to return configuration file error information if the carrying source exists in the global application identifier list; The second processing module is configured to install the configuration file in the eSIM if the carrying source does not exist in the global application identifier list.

9. An eSIM configuration processing device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.

11. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when executed by a processor.