Access method and device of terminal equipment, equipment and medium
Through the multi-factor binding authentication mechanism, combining biometrics, device identification and eSIM card IMSI, a real-time authentication value is generated, which solves the eSIM card binding security issue and improves the access permission authentication security and anti-cloning capability of the terminal device.
Patent Information
- Application Number
- CN202510809400.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-09-16
AI Technical Summary
The binding of eSIM cards to devices has single binding vulnerabilities and static key risks, and the existing authentication mechanism is easily cloned or stolen by attackers.
A multi-factor binding authentication mechanism is adopted to collect the user's biometrics, the device identification of the terminal device and the IMSI of the eSIM card, use an encryption algorithm to generate a value to be authenticated, and compare it with the pre-stored authentication credential value to authenticate the user's identity in real time.
It achieves strong binding of "device-card-person", improves the security level of access right authentication, enhances anti-cloning capabilities, and prevents SIM card theft and device hijacking.
Smart Images

Figure CN120659053A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of terminal technology, and in particular to a method, apparatus, device, and medium for accessing a terminal device. Background Art
[0002] Currently, eSIM card and device binding solutions present significant security issues, such as the following: Single binding vulnerability: eSIM card and device binding are linked solely through the International Mobile Subscriber Identity (IMSI) and the device's physical identifier (such as the IMEI). Attackers can bypass security mechanisms by cloning the IMSI or forging the device ID. Static key risk: Traditional solutions store sensitive information such as the IMSI in plain text, making it vulnerable to side-channel attacks.
[0003] Therefore, to address the security issues of binding eSIM cards to devices, a stronger and more secure authentication mechanism is needed. Summary of the Invention
[0004] In order to solve the above technical problems, the present disclosure provides a method, apparatus, device and medium for accessing a terminal device.
[0005] According to one aspect of the present disclosure, a method for accessing a terminal device is provided, the method comprising:
[0006] When the terminal device receives the access request, it collects the user's target biometric features;
[0007] Convert the target biometric, the device identifier of the terminal device, and the IMSI of the eSIM card built into the terminal device into a value to be authenticated according to a preset encryption algorithm;
[0008] Comparing the value to be authenticated with a pre-stored authentication credential value;
[0009] If the value to be authenticated matches the pre-stored authentication credential value, the user is authorized to access the terminal device;
[0010] If the value to be authenticated does not match the pre-stored authentication credential value, it is determined that the authentication has failed and the user is denied access to the terminal device.
[0011] According to another aspect of the present disclosure, there is also provided an access device for a terminal device, the device comprising:
[0012] A feature collection module is used to collect the user's target biometric features when the terminal device receives an access request;
[0013] an encryption conversion module, configured to convert the target biometric feature, the device identification of the terminal device, and the IMSI of the built-in eSIM card of the terminal device into a value to be authenticated according to a preset encryption algorithm;
[0014] a comparison module, configured to compare the value to be authenticated with a pre-stored authentication credential value;
[0015] an authorization access module, configured to authorize the user to access the terminal device if the value to be authenticated is matched with a pre-stored authentication credential value;
[0016] The access denial module is configured to determine that the authentication has failed and deny the user access to the terminal device if the value to be authenticated does not match the pre-stored authentication credential value.
[0017] According to another aspect of the present disclosure, an electronic device is provided, comprising:
[0018] processor;
[0019] a memory for storing instructions executable by the processor;
[0020] The processor is configured to read the executable instructions from the memory and execute the instructions to implement the above method.
[0021] According to another aspect of the present disclosure, a computer-readable storage medium is provided, wherein the storage medium stores a computer program, and the computer program is used to execute the above method.
[0022] The technical solution provided by the embodiments of the present disclosure has the following advantages over the prior art:
[0023] The technical solution provided by the embodiment of the present disclosure includes: when the terminal device receives an access request, collecting the user's target biometric features; according to a preset encryption algorithm, converting the target biometric features, the device identification of the terminal device and the IMSI of the built-in eSIM card of the terminal device into a value to be authenticated; comparing the value to be authenticated with a pre-stored authentication credential value; if the value to be authenticated is consistent with the pre-stored authentication credential value, authorizing the user to access the terminal device; if the value to be authenticated is inconsistent with the pre-stored authentication credential value, determining that the authentication has failed and denying the user access to the terminal device.
[0024] In this technical solution, each time an access request is received, it is necessary to collect the target biometric features in real time and generate a value to be authenticated, and then compare the consistency of the value to be authenticated with the authentication credential value, which can prevent accidents such as SIM card cloning or terminal device hijacking; wherein, the device identification (machine) of the terminal device, the IMSI (card) of the eSIM card and the target biometric features (person) of the user are integrated through an encryption function to generate a real-time value to be authenticated, and the consistency of the device identification, IMSI and target biometric features needs to be authenticated in real time to achieve a strong binding of "machine-card-person"; the above multi-factor linkage of "machine-card-person" requires the attacker to obtain the IMSI, device identification and biometric template of the eSIM card and the user at the same time, which greatly increases the difficulty of cracking and can effectively improve the security level and anti-cloning capability of access permission authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0026] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0027] Figure 1 This is a schematic diagram of the structure of the terminal device according to an embodiment of the present disclosure;
[0028] Figure 2 This is a flowchart of the method for accessing a terminal device according to an embodiment of the present disclosure;
[0029] Figure 3 This is a schematic diagram of the structure of the access device of the terminal device according to the embodiment of the present disclosure;
[0030] Figure 4 This is a schematic diagram of the structure of the electronic device described in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0031] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features therein can be combined with each other in the absence of conflict.
[0032] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.
[0033] This disclosure addresses the security issues associated with binding eSIM cards to devices. While some solutions incorporate fingerprint verification, they only bind the fingerprint template to the device without linking it to the eSIM card information. This can result in stolen SIM cards still being usable by others. This, combined with security issues such as single-binding vulnerabilities and the risk of static keys, necessitates a stronger and more secure authentication mechanism.
[0034] Based on this, the embodiments of the present disclosure provide a terminal device access method, apparatus, device, and medium. This solution multi-dimensionally binds the eSIM card, terminal device, and user biometrics, providing a multi-factor binding authentication mechanism, enabling dynamic authentication of network access rights and enhancing the security of access rights authentication. To facilitate understanding, the embodiments of the present disclosure are described in detail below.
[0035] The terminal device access method provided by the embodiment of the present disclosure can be applied to terminal devices using eSIM cards, such as mobile phones, wearable devices, tablets, PCs, and smart speakers. In one example, Figure 1 As shown, the terminal device may include: a biometric module, a device main control, a BP internet baseband chip and an eSIM card; wherein the eSIM card includes an SE module and an EUICC module.
[0036] As a specific example, the device main control is connected to the biometric module and the BP Internet baseband chip through a universal interface; the device main control is connected to the SE module in the eSIM card through the SPI interface; the BP Internet baseband chip is connected to the eUICC module in the eSIM card through the 7816 interface; in the eSIM card, the SE module is connected to the EUICC module through the internal event interface.
[0037] Based on the above terminal devices, Figure 2 This is a flowchart of a method for accessing a terminal device provided by an embodiment of the present disclosure. The method can be executed by an access device of the terminal device, which can be implemented using software and / or hardware. Figure 2 , the access method of the terminal device may include the following steps.
[0038] S102: When the terminal device receives the access request, it collects the target biometric features of the user.
[0039] In this embodiment, when a user unlocks the terminal device screen or logs into the network, the terminal device receives an access request based on the user's action. Upon receiving the access request, a multi-factor authentication process is triggered. In this multi-factor authentication process, one of the factors to be authenticated is a target biometric characteristic strongly associated with the user. The terminal device then invokes the biometric recognition module to collect the user's target biometric characteristic. This target biometric characteristic can be, without limitation, the user's fingerprint, pupil, voice, or face.
[0040] S104: According to a preset encryption algorithm, the target biometric feature, the device identification of the terminal device, and the IMSI of the built-in eSIM card of the terminal device are converted into a value to be authenticated.
[0041] After collecting the user's target biometric features, this embodiment performs multi-factor linkage with the target biometric features, the device identification of the terminal device, and the IMSI of the terminal device's built-in eSIM card, and combines the above multiple factors to perform security authentication of access rights.
[0042] When implementing security authentication for access rights, the target biometric, device identifier, and IMSI of the eSIM card are first converted into a value to be authenticated based on a preset encryption algorithm. Specifically, the preset encryption algorithm may include a hash function (such as SM3). Based on this, this embodiment can hash the target biometric, the device identifier of the terminal device, and the IMSI of the eSIM card built into the terminal device based on the hash function to generate the value to be authenticated.
[0043] S106: Compare the value to be authenticated with the pre-stored authentication credential value.
[0044] The authentication credential value is the result of converting the biometric template, device ID, and IMSI using the aforementioned encryption algorithm. The biometric template is the biometric characteristic entered by the user during registration and used as the authentication standard. The authentication credential value is determined through a multi-factor linkage, and the biometric template, device ID, and IMSI are all secure and accurate information. Therefore, the authentication credential value has high and reliable credential validity during the access rights authentication process.
[0045] The above authentication credential value can be encrypted with a salt value and stored in the SE module of the eSIM card. This can resist physical disassembly and side channel attacks, prevent physical theft, and improve hardware-level security.
[0046] Based on steps S102 and S104 above, each time a user accesses the terminal device, a new authentication value is dynamically generated based on the target biometrics collected in real time. This authentication value is then compared with the pre-stored authentication credential value. Depending on the comparison result, step S108 or S110 is executed.
[0047] S108: If the value to be authenticated is consistent with the pre-stored authentication credential value, the user is authorized to access the terminal device.
[0048] S110: If the value to be authenticated does not match the pre-stored authentication credential value, it is determined that the authentication has failed and the user is denied access to the terminal device.
[0049] In order to better understand the solution, the above embodiment will be described in more detail below.
[0050] In this embodiment, the encryption algorithm for generating the value to be authenticated and the authentication credential value may include a hash function, and the hash function is:
[0051] Fingerprint Hash = Hash_SM3(IMSI || Device_ID || Fingerprint_) (1)
[0052] Wherein, Device_ID represents a device identifier, and when Fingerprint_ represents a target biometric, FingerprintHash represents a value to be authenticated, and when Fingerprint_ represents a biometric template, FingerprintHash represents an authentication credential value.
[0053] Typically, before a user can legally use a terminal device, they need to register or bind first, and generate an authentication credential value during the user registration or binding phase. Based on this, this embodiment first provides a method for generating an authentication credential value, including:
[0054] Obtain the biometric template entered by the user during registration; convert the biometric template, device identification and IMSI into an authentication credential value based on the encryption algorithm; encrypt the authentication credential value with a salt value and store it in the SE module of the eSIM card.
[0055] Specifically, the terminal device can obtain the device identification through the device main control, read the IMSI of the eSIM card built into the terminal device, and call the biometric recognition module to collect the biometric feature template input by the user.
[0056] The device master can hash the biometric template, the device identifier of the terminal device, and the IMSI of the built-in eSIM card of the terminal device according to the hash function to generate the authentication credential value; refer to the following formula (2):
[0057] Fingerprint Hash = Hash_SM3(IMSI || Device_ID || Fingerprint_Template) (2)
[0058] Fingerprint_Template represents the biometric template, and Fingerprint Hash represents the authentication credential value.
[0059] This embodiment implements triple binding by hashing the IMSI of the eSIM card, the device identification of the terminal device, and the user's biometric template to form an irreversible binding credential, which can effectively solve the problem that a single binding is easily cracked.
[0060] The encryption algorithm in this embodiment complies with the 3GPP TS 33.201 security specification and supports the extension of the national encryption algorithm.
[0061] This implementation encrypts sensitive and important authentication credential values with salt values and stores them in the SE module of the eSIM card, which can resist physical disassembly and side-channel attacks, prevent physical theft, and improve security.
[0062] After completing registration or binding, the user can legally use the terminal device. During the process of logging into the network or unlocking the screen, whenever the terminal device receives an access request from the user, the device master obtains the device identifier, calls the biometric module to collect the user's target biometric features in real time, and reads the IMSI from the EUICC module of the eSIM card.
[0063] Then, according to the preset encryption algorithm, the target biometrics, device identification and IMSI collected in real time are converted back into the authentication value, and the new authentication value is sent to the SE module of the eSIM card.
[0064] In the SE module, the value to be authenticated is compared with the pre-stored authentication credential value. If the comparison matches, that is, the value to be authenticated is consistent with the authentication credential value, the user is authorized to access the terminal device and network access. Otherwise, if the value to be authenticated is inconsistent with the authentication credential value, the authentication is determined to have failed and the user is denied access to the terminal device and network access.
[0065] Each time this embodiment receives a user access request, it recollects the user's target biometrics and recalculates the authentication value. This means that even if the IMSI is stolen, the lack of the device identifier and biometric template prevents the generation of a valid and accurate authentication credential value. This prevents cloning attacks and enables dynamic, secure authentication. In other words, this embodiment can only generate a valid and accurate authentication credential value and pass authorization authentication by simultaneously acquiring the eSIM card's IMSI, device identifier, and user's biometric template, significantly increasing the difficulty of cracking authorization authentication.
[0066] Based on the above embodiments, this embodiment provides a "lock mechanism" handled by the eSIM card core. The "lock mechanism" is an event mechanism, an internal event initiated by the SE module of the eSIM card to the eUICC module. After the terminal device obtains the target biometric, it sends the device identifier and target biometric to the SE module via the SPI interface for authentication. If authentication is successful, a "lock mechanism" event is generated and notified to the eUICC module. The eUICC module then tags whether Internet access is allowed. When the BP Internet baseband chip sends an Internet access authorization command to the eUICC module, the eUICC module returns appropriate response data based on the tag, thereby enabling or disabling the network.
[0067] Based on the above-mentioned “locking mechanism”, this embodiment provides a method for comparing a value to be authenticated with a pre-stored authentication credential value, including:
[0068] The SE module of the eSIM card compares the value to be authenticated with the pre-stored authentication credential value; an internal event is generated based on the comparison result, and the internal event is notified to the eUICC module of the eSIM card so that a tag is added through the eUICC module. The tag is used to indicate whether the user is authorized to access the terminal device.
[0069] Specifically, if the value to be authenticated is consistent with the authentication credential value, the internal event generated by the SE module is an authentication success event, and the authentication success event is notified to the eUICC module of the eSIM card, so that the eUICC module adds a tag authorizing the user to access the terminal device.
[0070] If the value to be authenticated does not match the authentication credential value, the SE module generates an internal event as an authentication failure event, and notifies the eUICC module of the eSIM card of the authentication failure event, so that the eUICC module can add a tag denying the user access to the terminal device.
[0071] This embodiment further includes: the BP internet access baseband chip of the terminal device initiating an internet access authentication instruction to the eUICC module, so that the eUICC module returns response data to the eUICC module based on the tag; wherein, when the tag indicates that the user is authorized to access the terminal device, the response data is to enable the network; and when the tag indicates that the user is denied access to the terminal device, the response data is to disable the network.
[0072] If the value to be authenticated is inconsistent with the authentication credential value, the method provided in this embodiment may further include:
[0073] Record the number of consecutive authentication failures; when the number of consecutive failures exceeds a preset value (e.g., 5), the terminal device is locked and / or the eSIM card is disabled from network functions, and an alarm is sent to a preset management platform, such as a carrier server or IoT device.
[0074] In one embodiment, the bound biometric template can also be updated remotely through the Trusted Execution Environment (TEE) and the IoT device can be updated synchronously.
[0075] Based on the above embodiments, this embodiment provides two specific solutions by taking a mobile phone application scenario and an IoT device application scenario as examples.
[0076] For smartphone application scenarios, during the user registration phase, the device identification of the terminal device, the IMSI of the eSIM card, and the biometric template (such as fingerprint template) entered by the user are obtained, and the hash function is executed: Hash(IMSI||Device_ID||Fingerprint_Template), and the authentication credential value is obtained; the authentication credential value is encrypted with a salt value and stored in the SE module of the eSIM card.
[0077] During the network access phase, when a user attempts to unlock the screen or connect to a 5G network, the terminal device pops up a biometric authentication interface. Based on the biometric authentication interface, the user's target biometric is collected in real time. This target biometric is combined with the current IMSI and device identifier to generate a real-time authentication value. This authentication value is then compared with the authentication credential value stored in the SE module. If the two match, authentication succeeds, authorizing the user to access the terminal device's network. If the two do not match, authentication fails, denying the user access to the terminal device's network. If the number of consecutive authentication failures exceeds a preset number, the terminal device is locked and / or the eSIM card disables the network function, and an alarm is sent to the preset management platform.
[0078] For IoT device application scenarios, during the binding phase of IoT devices, the unique device identifier of the industrial sensor, the IMSI of the eSIM card, and the biometric template entered by the administrator are obtained, and then the authentication credential value is generated by executing a hash function to prevent the IoT device from being illegally connected to the monitoring network.
[0079] During the use phase of an IoT device, when a user attempts to access the IoT device, the IoT device collects the user's target biometrics in real time. This target biometric is combined with the current IMSI and device identifier to generate a real-time authentication value. This authentication value is then compared with the authentication credential value stored in the SE module. If the two match, authentication succeeds, and the user is authorized to access the IoT device. If the two do not match, authentication fails, and the user is denied access to the IoT device. If the number of consecutive authentication failures exceeds a preset number, the terminal device is locked and / or the eSIM card's network function is disabled, and an alarm is sent to the preset management platform.
[0080] In summary, the access method of the terminal device provided by the above embodiment includes: when the terminal device receives an access request, collecting the target biometric characteristics of the user; according to a preset encryption algorithm, converting the target biometric characteristics, the device identification of the terminal device and the IMSI of the built-in eSIM card of the terminal device into a value to be authenticated; comparing the value to be authenticated with a pre-stored authentication credential value; if the value to be authenticated is consistent with the pre-stored authentication credential value, authorizing the user to access the terminal device; if the value to be authenticated is inconsistent with the pre-stored authentication credential value, determining that the authentication has failed and denying the user access to the terminal device.
[0081] In this technical solution, each time an access request is received, it is necessary to collect the target biometric features in real time and generate a value to be authenticated, and then compare the consistency of the value to be authenticated with the authentication credential value, which can prevent accidents such as SIM card cloning or terminal device hijacking; wherein, the device identification (machine) of the terminal device, the IMSI (card) of the eSIM card and the target biometric features (person) of the user are integrated through an encryption function to generate a real-time value to be authenticated, and the consistency of the device identification, IMSI and target biometric features needs to be authenticated in real time to achieve a strong binding of "machine-card-person"; the above multi-factor linkage of "machine-card-person" requires the attacker to obtain the IMSI, device identification and biometric template of the eSIM card and the user at the same time, which greatly increases the difficulty of cracking and can effectively improve the security level and anti-cloning capability of access permission authentication.
[0082] In addition, this technical solution is suitable for scenarios such as smartphones and IoT devices, and can better meet the high security requirements of the 5G / 6G era.
[0083] Figure 3 This is a schematic diagram of the structure of an access device for a terminal device provided in an embodiment of the present disclosure. The device can be used to implement the access method for the terminal device described above. The device may include the following modules:
[0084] The feature collection module 210 is used to collect the user's target biometric features when the terminal device receives an access request;
[0085] The encryption conversion module 220 is configured to convert the target biometric feature, the device identification of the terminal device, and the IMSI of the built-in eSIM card of the terminal device into a value to be authenticated according to a preset encryption algorithm;
[0086] a comparison module 230, configured to compare the value to be authenticated with a pre-stored authentication credential value;
[0087] an authorized access module 240 for authorizing the user to access the terminal device if the to-be-authenticated value matches a pre-stored authentication credential value;
[0088] The access denial module 250 is configured to determine that the authentication has failed and deny the user access to the terminal device if the value to be authenticated does not match the pre-stored authentication credential value.
[0089] The device provided in this embodiment has the same implementation principle and technical effects as those of the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference may be made to the corresponding contents in the aforementioned method embodiment.
[0090] Figure 4 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present disclosure. Figure 4 As shown, the electronic device 300 includes one or more processors 301 and a memory 302 .
[0091] The processor 301 may be a central processing unit (CPU) or other forms of processing units having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 300 to perform desired functions.
[0092] The memory 302 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), a hard disk, a flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 301 may execute the program instructions to implement the access method of the terminal device of the embodiment of the present disclosure described above and / or other desired functions. Various contents such as input signals, signal components, noise components, etc. may also be stored in the computer-readable storage medium.
[0093] In one example, the electronic device 300 may further include an input device 303 and an output device 304 , and these components are interconnected via a bus system and / or other forms of connection mechanisms (not shown).
[0094] In addition, the input device 303 may also include, for example, a keyboard, a mouse, and the like.
[0095] The output device 304 can output various information to the outside, including determined distance information, direction information, etc. The output device 304 can include, for example, a display, a speaker, a printer, a communication network and its connected remote output device, etc.
[0096] Of course, to simplify, Figure 4Only some of the components related to the present disclosure in the electronic device 300 are shown, and components such as a bus, an input / output interface, etc. are omitted. In addition, the electronic device 300 may further include any other appropriate components according to specific application scenarios.
[0097] Furthermore, this embodiment also provides a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program is used to execute the access method of the terminal device.
[0098] The embodiments of the present disclosure provide a computer program product for a terminal device access method, apparatus, electronic device, and medium, including a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the methods described in the previous method embodiments. For specific implementation, please refer to the method embodiments and will not be repeated here.
[0099] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0100] The foregoing description is intended only to provide specific embodiments of the present disclosure, intended to enable those skilled in the art to understand and implement the present disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the embodiments described herein, but rather to be construed in the broadest manner consistent with the principles and novel features disclosed herein.
Claims
1. A method for accessing a terminal device, characterized in that: The method comprises: When the terminal device receives the access request, it collects the user's target biometric features; Convert the target biometric, the device identifier of the terminal device, and the IMSI of the eSIM card built into the terminal device into a value to be authenticated according to a preset encryption algorithm; Comparing the value to be authenticated with a pre-stored authentication credential value; If the value to be authenticated matches the pre-stored authentication credential value, the user is authorized to access the terminal device; If the value to be authenticated does not match the pre-stored authentication credential value, it is determined that the authentication has failed and the user is denied access to the terminal device.
2. The method according to claim 1, characterized in that The method further comprises: Get the biometric template entered by the user during registration; converting the biometric template, the device identifier, and the IMSI into the authentication credential value according to the encryption algorithm; The authentication credential value is encrypted with a salt value and stored in the SE module of the eSIM card.
3. The method according to claim 1 or 2, characterized in that The encryption algorithm includes a hash function, which is: Fingerprint Hash=Hash_SM3(IMSI||Device_ID||Fingerprint_) Wherein, Device_ID represents the device identifier, and when Fingerprint_ represents the target biometric feature, FingerprintHash represents the value to be authenticated, and when Fingerprint_ represents the biometric feature template, FingerprintHash represents the authentication credential value.
4. The method according to claim 3, characterized in that The converting, according to a preset encryption algorithm, the target biometric feature, the device identification of the terminal device, and the IMSI of the built-in eSIM card of the terminal device into a value to be authenticated includes: According to the hash function, the target biometric feature, the device identification of the terminal device and the IMSI of the built-in eSIM card of the terminal device are hashed to generate a value to be authenticated.
5. The method according to claim 1, characterized in that The comparing the to-be-authenticated value with a pre-stored authentication credential value includes: Comparing the to-be-authenticated value with a pre-stored authentication credential value through the SE module of the eSIM card; An internal event is generated according to the comparison result, and the internal event is notified to the eUICC module of the eSIM card, so that a tag is added through the eUICC module, where the tag is used to indicate whether the user is authorized to access the terminal device.
6. The method according to claim 5, characterized in that The method further comprises: The BP internet access baseband chip of the terminal device initiates an internet access authentication instruction to the eUICC module, so that the eUICC module returns response data to the eUICC module based on the tag; wherein, when the tag indicates that the user is authorized to access the terminal device, the response data is to enable the network; and when the tag indicates that the user is denied access to the terminal device, the response data is to disable the network.
7. The method according to claim 1, characterized in that The method further comprises: Record the number of consecutive authentication failures; When the number of consecutive occurrences exceeds a preset number, the terminal device is locked and / or the eSIM card disables the network function, and an alarm message is sent to a preset management platform.
8. An access device for a terminal device, characterized in that: The device comprises: A feature collection module is used to collect the user's target biometric features when the terminal device receives an access request; an encryption conversion module, configured to convert the target biometric feature, the device identification of the terminal device, and the IMSI of the built-in eSIM card of the terminal device into a value to be authenticated according to a preset encryption algorithm; a comparison module, configured to compare the value to be authenticated with a pre-stored authentication credential value; an authorization access module, configured to authorize the user to access the terminal device if the value to be authenticated is matched with a pre-stored authentication credential value; The access denial module is configured to determine that the authentication has failed and deny the user access to the terminal device if the value to be authenticated does not match the pre-stored authentication credential value.
9. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed on a terminal device, the terminal device implements the method according to any one of claims 1 to 7.