Multi-source priority automatic switching method based on eSIM (Embedded Subscriber Identity Module)
By identifying key services in the eSIM terminal, collecting historical release performance data from multiple sources and performing comprehensive scoring and ranking, caching identity credentials and restoring session context, the problems of transaction success rate and identity continuity in eSIM network handover are solved, achieving efficient network selection and service continuity.
Patent Information
- Application Number
- CN202511453528.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-13
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2045-10-13
AI Technical Summary
In eSIM technology, how can we quickly select the most suitable information source without disclosing business content to ensure transaction success rate and identity continuity during network switching for financial payments, online banking, or government services, and avoid authentication link interruption and consistency issues caused by network switching?
By identifying key services at the terminal side, collecting historical data on the release performance of multiple information sources, using the comprehensive scoring formula U=PLK to sort and select the optimal information source, and caching identity credentials, mapping external network identifiers, and restoring session context during the handover process, business continuity is ensured.
It significantly improves the success rate and reliability of critical business operations, reduces CAPTCHA loss and authentication interruptions, enhances user experience and business continuity, and is suitable for scenarios with high security requirements.
Smart Images

Figure CN120935535A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of eSIM network handover, and more specifically, to an automatic handover method based on eSIM with multiple signal source priorities. Background Technology
[0002] In eSIM technology, the eUICC (Embedded Universal Integrated Circuit Card) of the terminal device supports storing multiple operator profiles simultaneously. Each profile is equivalent to a virtual SIM card, capable of independently providing network access capabilities. Unlike traditional SIM cards, which are fixed to a single operator, eSIM's multi-profile feature allows the terminal to flexibly switch to the most suitable signal source based on service needs, network environment, or compliance requirements. More importantly, this switching does not require physically replacing the card; it can be completed through software commands, thus far surpassing traditional SIM cards in terms of switching speed, manageability, and automation.
[0003] As mentioned above, mobile terminals with eSIM capabilities can manage multiple carrier sources simultaneously, obtaining continuous mobile data services by accessing and switching between different networks. Unlike everyday entertainment or information access, financial payments, online banking, and government services are critical businesses that are extremely sensitive to security compliance and authentication links: backend risk control typically assesses risk based on source IP / ASN and geographic information; transaction processes heavily rely on the reception and timeliness of SMS or voice verification codes; and network source consistency is required within a transaction window. If only general indicators such as throughput and latency are used to select or switch networks, it may lead to a decrease in the first-pass rate of transactions, fluctuations in SMS or voice verification code reception rates, or even session interruptions and re-verification due to switching. At the same time, terminals find it difficult to accurately determine the approval capability of each candidate source at the moment a critical service is initiated, and lack a mechanism to structure historical approval performance data for real-time sorting and access priority adjustment. How to build an executable evaluation system based on observable metrics such as transaction success rate and SMS or voice verification code reception rate without disclosing business content, and how to quickly select a more favorable candidate information source when critical business is initiated, while avoiding the interruption of the authentication link due to switching, has become an urgent problem to be solved in this field. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a method for automatic switching of multiple information source priorities based on eSIM, so as to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention adopts the following technical solution: An automatic handover method based on eSIM with multiple information source priorities includes the following steps: On the terminal side, it is possible to identify whether the service that a user is about to initiate belongs to a preset key service, which includes financial payment, online banking, or government services. Collect historical release performance data of multiple different candidate information sources in eSIM under the key service. The historical release performance data includes transaction first pass rate, SMS or voice verification code reception rate and source network consistency rate. The candidate information sources are ranked based on their historical release performance data to assess their success rate in releasing information in the target service. When a critical business activity is detected, it is prioritized according to the aforementioned sorting.
[0006] In some embodiments, the process of ranking candidate information sources includes: The candidate information sources are collected for the transaction first-pass rate P, the source network consistency rate L, and the SMS or voice verification code reception rate K under each key business; the source network consistency rate is used to characterize the probability of maintaining the same IP address in a key business transaction; The comprehensive score is calculated based on the following formula. U : U=PLK; The candidate sources are ranked according to the comprehensive score, and the source with the highest score is selected as the optimal source.
[0007] In some embodiments, the method further includes: selecting the candidate source with the smallest average transaction completion latency from the top N candidate sources as the final access source.
[0008] In some embodiments, the terminal caches the identity credential information of the current session before switching and replays the identity credential after switching to the new information source to restore the authentication link of the service session.
[0009] In some embodiments, the identity credential information includes cookies, tokens, and TLS session tickets.
[0010] In some embodiments, before the switchover, the terminal's external network identifier is mapped to a preset compliant exit address or an encrypted tunnel identifier registered with the operator; after the switchover, the compliant exit address or tunnel identifier continues to be used for external communication, thereby maintaining a consistent source identity in the back-end system of financial payment or government services.
[0011] In some embodiments, when a source switch occurs during the execution of critical services, the terminal maintains transaction continuity through a session context transfer mechanism, which includes: Before switching, export a context snapshot of the current transaction, which includes the transaction identifier, authentication progress, verification code status, and session sequence number; After switching to the new information source, the transaction state is restored in the new session based on the context snapshot.
[0012] In some embodiments, the candidate information sources correspond to multiple operator profiles in eUICC, and key business compliance tags are set in the profiles. The key business compliance tags are used to identify compliant information sources suitable for financial payments or government services. When a key business is detected, the profile with the compliance tag is activated first.
[0013] In some embodiments, collecting historical release performance data of different candidate information sources under the critical service includes: Record the access logs of each candidate information source in critical business transactions in the terminal or back-end system; Based on the log statistics, the transaction first-pass rate, SMS or voice verification code reception results, and source network consistency rate are analyzed. The historical release performance data is stored in a time-series format.
[0014] In some embodiments, the method further includes pre-screening candidate sources based on rules, including whether the network protocol support required by the target service is met; and collecting historical release performance data only for candidate sources that meet the rules.
[0015] The advantages of this invention compared to existing technologies lie in its use of historical pass-through performance data as the core evaluation criterion for network switching. This effectively addresses the limitations of traditional network selection, which relies solely on general indicators such as latency. In critical business areas like financial payments, it significantly improves transaction success rates and reliability. For example, it reduces verification code loss or authentication interruptions caused by network incompatibility, ensuring smooth user operations and reducing security risks. Furthermore, by using a comprehensive scoring formula that combines transaction first-pass rate, source network consistency rate, and SMS or voice verification code reception rate to rank and select the optimal source, it optimizes pass-through capabilities across multiple dimensions, preventing a single weakness from amplifying the overall failure probability. In addition, during the switchover process, caching identity credentials such as cookies or tokens and replaying sessions to restore them, as well as mapping external network identifiers to compliant exit addresses, maintains the consistency of source identities, prevents backend systems from misjudging abnormal behavior, and improves business continuity. The session context transfer mechanism exports transaction snapshots including authentication progress and verification code status, and restores the status in the new source, further reducing the need for resets due to interruptions and improving user experience. The setting of pre-screening rules and compliance labels ensures the applicability of the source, and combined with historical data statistics stored in time series, it makes decisions more accurate and dynamically adaptable to changes. These improvements collectively enhance the robustness of eSIM multi-source environments, making it suitable for scenarios with high security requirements. Attached Figure Description
[0016] Figure 1 This is an overall structural diagram of the present invention; Figure 2 This is a diagram of the sorting and selection structure of the present invention; Figure 3 This is a schematic diagram illustrating the session continuity of the present invention; Figure 4 This is a schematic diagram of data acquisition according to the present invention. Detailed Implementation
[0017] The specific embodiments of the present invention will now be described with reference to the accompanying drawings.
[0018] This invention provides a method for automatic switching of multiple information source priorities based on eSIM. The method aims to optimize the network access strategy of terminal devices when processing critical services, so as to ensure smooth service operation and maintain identity consistency.
[0019] Traditional network handover methods often focus only on general metrics such as latency or signal strength. However, when it comes to critical transactions involving financial payments, online banking, or government services, these metrics may be insufficient to guarantee success, as these transactions have higher requirements for efficiency and identity continuity. For example, in financial payments, if verification code reception fails or the source identity changes due to network issues or network handover, the backend system may consider it an anomaly and reject the transaction, thus impacting user experience and security.
[0020] To solve the above problems, such as Figure 1 As shown, the present invention includes steps such as service identification on the terminal side, collection and processing of historical release performance data, and sorting and priority adjustment of candidate information sources.
[0021] More specifically, the method of this invention addresses this problem by introducing historical data on transaction processing performance as the core evaluation criterion. Specifically, the method first identifies on the terminal side whether the service a user is about to initiate belongs to a pre-defined critical service. These critical services specifically refer to security-sensitive operations such as financial payments, online banking, or government services. The identification process can be achieved by monitoring the application's startup behavior or API calls. For example, when a user opens a banking application and navigates to the transfer interface, the terminal's operating system or embedded software module parses the application's intent tag or URL pattern to determine if it matches a pre-defined list of critical services. This list can be pre-stored in the terminal's local database and updated periodically with the latest definitions from a server to adapt to changes in business requirements.
[0022] Once a critical service is confirmed to be initiating, or during the preparatory phase before the critical service occurs, the method of this invention collects historical release performance data of different candidate information sources under that critical service. These candidate information sources typically correspond to multiple operator profiles in eUICC, each profile representing an activatable SIM card configuration supporting network access from different operators. Historical release performance data includes transaction first-pass rate, SMS or voice verification code reception rate, and source network consistency rate. The transaction first-pass rate reflects the success rate of completing the service on the first attempt; for example, in financial payments, it reflects whether the entire process from order submission to payment confirmation is uninterrupted. The SMS or voice verification code reception rate measures the reliability of the verification code sent from the server to the terminal, which is crucial in two-factor authentication. The source network consistency rate characterizes the probability of maintaining the same IP address throughout a critical service transaction, avoiding authentication failures due to IP changes. IP address hopping occurs because operators typically use large-scale NAT technology in their core network to save public IPv4 addresses. User sessions may be assigned new external IP addresses due to NAT port reuse or gateway migration, resulting in different source information at different stages of a transaction. On the other hand, network load balancing, link redundancy, or area switching may temporarily change the egress gateway, causing users' public IP addresses to jump. In IPv6 scenarios, terminal addresses may automatically update within a short period of time due to privacy extension mechanisms, further exacerbating the instability of external source identifiers.
[0023] The collection of this data requires recording the access logs of each candidate information source during critical business transactions in the terminal or backend system, as shown in Figure 4. In practice, the terminal can maintain a log database to record the start time, end time, information source used, whether it passed on the first attempt, verification code reception status, and IP address change records after each critical business execution.
[0024] Based on these logs, the system can calculate the first-pass rate of transactions, such as by dividing the number of successful transactions in the past 30 days by the total number of transactions; the SMS or voice verification code reception rate is derived by recording the ratio of sent requests to successful receptions; and the source network consistency rate can be calculated by determining the proportion of unique IP addresses within a transaction period. These statistical results are stored in a time-series format, for example, using an SQLite database stored locally on the terminal, grouped by date and source, facilitating subsequent querying and analysis. This time-series storage allows the system to capture trend changes; for example, if a source's performance declines during peak periods, recent data can be weighted and considered during sorting.
[0025] Furthermore, as shown in Figure 2, after data collection, this invention ranks the candidate information sources based on historical release performance data to assess their success rate in the target service. The specific ranking process involves collecting the candidate information sources' transaction first-pass rate P, source network consistency rate L, and SMS or voice verification code reception rate K for each key service. These metrics can be extracted from the aforementioned logs; for example, P equals the number of successful transactions divided by the total number of transactions, L equals the number of transactions maintaining the same IP address divided by the total number of transactions, and K equals the number of transactions successfully receiving verification codes divided by the number of transactions involving verification codes.
[0026] Then, the comprehensive score is calculated using the formula U=PLK. This formula multiplies the three indicators to emphasize that weakness in any single indicator will significantly lower the overall score, thus prioritizing sources that perform well in all aspects. After calculation, candidate sources are ranked from highest to lowest based on the comprehensive score, and the source with the highest score is selected as the optimal source. For example, if there are three candidate sources A, B, and C with scores of 0.9, 0.85, and 0.7 respectively, then A is selected as the optimal source. This multiplicative formula is more suitable than addition because it amplifies multi-dimensional risks and prevents overall collapse due to a single failure point in critical business operations.
[0027] When a critical service request is detected, such as a user clicking the payment button, the system prioritizes the data based on this order and automatically switches to the optimal information source. This switching utilizes the eSIM's dynamic activation feature, activating the corresponding configuration file via the eUICC manager API call to ensure seamless integration.
[0028] Furthermore, the method of this invention also includes selecting the candidate source with the smallest average transaction completion latency from the top N candidate sources as the final access source. Here, N can be set to 3 or 5, dynamically adjusted according to the terminal configuration. The motivation is that although access performance data is the primary consideration, latency can also affect user experience at the same performance level. For example, when the top three scores are similar after ranking, the system further queries the average latency data of each source, which can be obtained from historical logs, such as the average completion time of past transactions. Then, the source with the smallest latency is selected as the final access source, achieving a balance between access capacity and efficiency.
[0029] To further enhance reliability, the method of this invention pre-screens candidate information sources based on rules before collecting historical release performance data. These rules include whether the source meets the network protocol support requirements of the target service; for example, financial payments may require support for TLS 1.3 or specific encryption standards. Pre-screening is achieved by checking metadata in the eUICC configuration file, collecting historical data only from candidate information sources that meet the rules, avoiding unnecessary calculations and improving efficiency. For example, if a source does not support IPv6 but the service requires it, it is directly excluded.
[0030] Furthermore, as shown in Figure 3, if a source switching occurs during the execution of critical business operations, such as due to signal attenuation or load balancing, the method of this invention provides multiple mechanisms to ensure identity consistency and transaction continuity.
[0031] First, when a handover occurs, the terminal caches the identity credentials of the current session before the handover and replays these credentials after switching to the new information source to restore the authentication link of the business session. Identity credentials include cookies, tokens, or TLS session tickets. These credentials are exported before the handover via the browser or application's session management module, for example, by saving cookies using the WebStorage API or extracting tokens from HTTP response headers. After the handover, the terminal injects these credentials when establishing a new connection, for example, by attaching a cookie header or an Authorization header carrying the token when sending a request, thus making the backend server believe that the session has not been interrupted. The motivation for this mechanism is to prevent re-authentication requirements caused by the handover, especially in financial payments, where repeated authentication may trigger risk control alerts.
[0032] Secondly, when a source switch occurs during critical business operations, before the switch, the terminal's external network identifier is mapped to a pre-defined compliant egress address or an encrypted tunnel identifier registered with the operator. After the switch, the compliant egress address or tunnel identifier continues to be used for external communication, thus maintaining a consistent source identity in the back-end systems of financial payments or government services. The external network identifier typically refers to an IP address or NAT egress. The mapping process can be implemented through a VPN or proxy service. For example, the terminal can be pre-configured with a compliant egress address, such as a fixed IP pool provided by the operator, and current traffic can be routed to this address before the switch. After the switch, traffic from the new source is also forced to pass through the same egress, ensuring that the back-end sees the same source IP. This method solves the identity consistency problem because many critical business back-ends rely on IP as an auxiliary authentication method; if the IP changes, it may be considered a fraudulent attempt. The encrypted tunnel identifier involves using tunnels such as IPsec or WireGuard. The terminal establishes a tunnel before the switch and registers the tunnel ID with the operator; the same tunnel ID is reused after the switch.
[0033] Furthermore, when a source switch occurs during critical business operations, the terminal maintains transaction continuity through a session context transfer mechanism. This mechanism involves exporting a context snapshot of the current transaction before the switch. This snapshot includes the transaction identifier, authentication progress, verification code status, and session sequence number. For example, the transaction identifier can be a unique UUID, the authentication progress record could be "password verification passed, verification code failed," the verification code status includes the received verification code value and its validity period, and the session sequence number is used to prevent replay attacks. The export process serializes this data to JSON format and temporarily stores it in the terminal's memory or an encrypted file. After switching to the new source, the transaction state is restored in the new session based on the context snapshot, for example, by sending this data along with a recovery request, allowing the server to rebuild the session. This mechanism ensures that transactions do not start from scratch, especially in government services, such as switching midway through an online application, avoiding the need for users to repeatedly enter information.
[0034] Furthermore, the method of this invention corresponds candidate information sources to multiple operator profiles in eUICC, and sets key business compliance tags in the profiles. These tags identify compliant information sources suitable for financial payments or government services; for example, a tag value of "financial_compliant" indicates that relevant compliance certifications have been passed. When a key business initiation is detected, the profile with the aforementioned compliance tag is activated first. In specific implementation, the eUICC management software filters profiles before sorting, only scoring those with tags. If an untagged information source scores higher, it can also be considered, but its priority is reduced. This tag setting can be embedded by the operator when issuing the profile, and the terminal queries the tag value via API to ensure compliance priority.
[0035] The implementation of this invention relies on the terminal's software framework, such as integrating an eSIM management module and logging service into Android or iOS systems. Data storage uses a local database to protect privacy. The backend system can optionally aggregate data from multiple terminals, but must comply with data protection regulations. Historical data updates can be performed periodically, such as daily, to reflect network changes. Through these refined steps, this method not only improves the success rate of critical services but also maintains identity continuity during switching scenarios, avoiding the failure risks caused by ignoring pass-through behavior in traditional methods. In actual deployment, the terminal can further integrate a user feedback mechanism; for example, if a transaction fails after a switch, users can manually mark it to optimize future data collection and sorting logic, thus forming a closed-loop improvement.
[0036] To make the data collection process more accurate, access logs can be broken down into multiple fields: transaction type (e.g., payment or login), source ID, start timestamp, end timestamp, pass flag (0 or 1), CAPTCHA receipt flag, IP change count, etc. During statistical analysis, a weighted average is used, with recent data having a higher weight (e.g., 0.6 for the past 7 days and 0.4 for the past 30 days) to capture dynamic changes. Pre-screening rules can also be extended to check the compliance history of sources; for example, sources that have been blacklisted in the past are excluded. The ranking algorithm can introduce a threshold; if the highest score is below 0.5, the user is prompted to check their network or delay service initiation.
[0037] Regarding identity credential caching, the replay process must consider security, such as using encrypted storage of credentials to avoid plaintext leakage. Replaying TLS session tickets can be achieved by restoring the TLS context, using libraries like OpenSSL to simulate session recovery on the endpoint. For context snapshots, sequence number consistency must be verified during recovery to prevent man-in-the-middle attacks. Mapping compliant egress addresses can be combined with SD-WAN technology to achieve intelligent routing, ensuring all critical traffic travels through fixed paths.
[0038] Furthermore, in eUICC configuration file management, compliance label settings can be dynamically updated, with new labels pushed through a remote management platform, allowing for timely adjustments when new regulations are introduced. The priority activation process involves rapid eSIM switching, typically completed within seconds, avoiding service interruptions. The overall approach is highly scalable; for example, it can be integrated with 5G slicing technology in the future, extending the information source to dedicated network slices to further optimize the performance of critical services.
[0039] In practical scenarios such as mobile banking applications, the method of this invention can significantly improve payment success rates while maintaining a seamless session during switching, reducing user frustration. The time-series format of log storage allows for advanced analytics, such as using simple trend prediction models to calculate future performance on the terminal, without requiring complex machine learning; linear regression alone suffices.
[0040] In summary, this invention provides a novel priority switching method specifically for financial payments, online banking, or government services, effectively filling a gap in this field.
[0041] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A method for automatic handover of multiple information source priorities based on eSIM, characterized in that, Includes the following steps: On the terminal side, it is possible to identify whether the service that a user is about to initiate belongs to a preset key service, which includes financial payment, online banking, or government services. Collect historical release performance data of multiple different candidate information sources in eSIM under the key service. The historical release performance data includes transaction first pass rate, SMS or voice verification code reception rate and source network consistency rate. The candidate information sources are ranked based on their historical release performance data to assess their success rate in releasing information in the target service. When a critical business activity is detected, it is prioritized according to the aforementioned sorting.
2. The method for automatic handover of multiple information source priorities based on eSIM according to claim 1, characterized in that, The process of ranking candidate information sources includes: The candidate information sources are collected for the transaction first-pass rate P, the source network consistency rate L, and the SMS or voice verification code reception rate K under each key business; the source network consistency rate is used to characterize the probability of maintaining the same IP address in a key business transaction; The comprehensive score is calculated based on the following formula. U : U=PLK; The candidate sources are ranked according to the comprehensive score, and the source with the highest score is selected as the optimal source.
3. The method for automatic handover of multiple information source priorities based on eSIM according to claim 1, characterized in that, The method further includes: selecting the candidate source with the smallest average transaction completion latency from the top N candidate sources as the final access source.
4. The method according to claim 1, characterized in that, When a source switch occurs during the execution of critical business operations, the terminal caches the identity credential information of the current session before the switch and replays the identity credential after switching to the new source to restore the authentication link of the business session.
5. The method for automatic handover of multiple information source priorities based on eSIM according to claim 4, characterized in that, The identity credentials include cookies, tokens, and TLS session tickets.
6. The method according to claim 1, characterized in that, When a source switch occurs during the execution of critical business operations, the external network identifier of the terminal is mapped to a preset compliant exit address or an encrypted tunnel identifier registered with the operator before the switch. After the switch, continue to use the compliant exit address or tunnel identifier for external communication, thereby maintaining a consistent source identity in the back-end systems of financial payments or government services.
7. The method according to claim 1, characterized in that, When a source switch occurs during the execution of critical business operations, the terminal maintains transaction continuity through a session context transfer mechanism, which includes: Before switching, export a context snapshot of the current transaction, which includes the transaction identifier, authentication progress, verification code status, and session sequence number; After switching to the new information source, the transaction state is restored in the new session based on the context snapshot.
8. The method according to claim 1, characterized in that, The candidate information sources correspond to multiple operator profiles in eUICC, and key business compliance tags are set in the profiles. The key business compliance tags are used to identify compliant information sources suitable for financial payments or government services. When a key business is detected, the profile with the compliance tag is activated first.
9. The method according to claim 1, characterized in that, The historical release performance data of different candidate information sources under the aforementioned critical service includes: Record the access logs of each candidate information source in critical business transactions in the terminal or back-end system; Based on the log statistics, the transaction first-pass rate, SMS or voice verification code reception results, and source network consistency rate are analyzed. The historical release performance data is stored in a time-series format.
10. The method according to claim 9, characterized in that, The method also includes pre-screening candidate information sources based on rules, including whether they meet the network protocol support requirements of the target service; and collecting historical release performance data only for candidate information sources that meet the rules.
Citation Information
Patent Citations
Multi-operator network automatic selection method and device, equipment and storage medium
CN115379522A
Vehicle adaptive network switching and traffic sharing method based on multi-source cooperation
CN120224321A
Automatic network switching method for information sources of different operators on end side based on multi-mode eSIM (evolved Subscriber Identity Module)
CN120603005A
Subscriber tag-based shunting method and system in 5g network
WO2017004858A1