ESIM protection method and device, computer equipment and storage medium
By sending a challenge key to the eSIM module through the main control chip and encrypting it, and combining the number of keys and other monitoring factors to confirm the security status of the eSIM module, the problem of easy disassembly and illegal use of eSIM modules in the existing technology is solved, and more efficient security protection is achieved.
Patent Information
- Application Number
- CN202511097302.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-12-02
AI Technical Summary
Existing eSIM anti-tampering technologies are unable to withstand high-precision microscopic disassembly techniques, and sensor detection is susceptible to environmental interference leading to misjudgments. They cannot effectively prevent the illegal use of eSIM modules after disassembly, posing security risks of user privacy leakage and operator service theft.
The main control chip periodically sends challenge keys to the eSIM module, uses the tamper-proof verification key for encryption to generate a response key, and determines the security status of the eSIM module based on the verification result and the number of keys, and takes corresponding protection measures, such as locking the communication function, destroying privacy information, and sending alarm information.
It enables accurate security verification of the eSIM module, effectively preventing disassembly, improving eSIM security, and reducing the risk of information leakage.
Smart Images

Figure CN121056876A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of mobile terminal technology, specifically to an eSIM protection method, apparatus, computer device, and storage medium. Background Technology
[0002] With the widespread adoption of eSIM (embedded Subscriber Identity Module) technology, the security of eSIM modules in IoT devices, smartphones, and other terminals is becoming increasingly important. eSIM modules store sensitive data such as International Mobile Subscriber Identity (IMSI) and Key Identifier (KI). Security breaches (e.g., malicious removal and transfer to other devices) could lead to security risks such as user privacy leaks and unauthorized use of operator services.
[0003] Existing eSIM tamper protection technologies largely rely on hardware structural protection (such as tamper-proof solder joints and mechanical latches) or single sensor detection, but these have significant limitations. Hardware structural protection is vulnerable to high-precision microscopic disassembly techniques, while sensor detection is susceptible to environmental interference leading to false alarms, and cannot prevent the unauthorized use of the eSIM module after disassembly at the data level. Therefore, an effective eSIM protection method is urgently needed to accurately confirm the security status of the eSIM and ensure its security. Summary of the Invention
[0004] Therefore, it is necessary to provide an eSIM protection method, apparatus, computer device, and storage medium that can accurately confirm the eSIM security status in response to the above-mentioned technical problems.
[0005] Firstly, this application provides an eSIM protection method applied to a main control chip, the method comprising:
[0006] According to a preset cycle, a challenge key is periodically sent to the eSIM module, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip;
[0007] Determine the verification result of the response key;
[0008] In the case of a verification failure, determine the number of keys for the response key that resulted in a verification failure.
[0009] The security status of the eSIM module is determined based on the number of keys whose verification results are failure responses.
[0010] In one embodiment, determining the verification result of the response key includes:
[0011] The response key is decrypted to obtain the candidate key;
[0012] The candidate key is matched with the challenge key to obtain the verification result.
[0013] In one embodiment, when the verification result is a verification failure, determining the number of keys for the response key where the verification result is a verification failure includes:
[0014] If the verification result is a failure, obtain the first preset time period;
[0015] Determine the number of keys whose verification result is a failure response key within the first preset time period.
[0016] In one embodiment, the security status of the eSIM module is determined based on the number of keys whose verification result is a failed response key, including:
[0017] If the number of keys whose verification results are failures exceeds the threshold, obtain the voltage change and communication monitoring status of the eSIM module.
[0018] If the voltage change is abnormal and the communication monitoring is abnormal, it is determined that the eSIM module has been disassembled.
[0019] In one embodiment, the method further includes:
[0020] If the drop in the power supply voltage of the eSIM module exceeds a preset threshold within the second preset time period, the voltage change is determined to be an abnormal voltage change.
[0021] In one embodiment, the method further includes:
[0022] If the duration of a communication signal interruption exceeds the preset interruption duration or the bit error rate exceeds the bit error rate threshold, the communication monitoring situation is determined to be abnormal.
[0023] In one embodiment, after determining that the security status of the eSIM module indicates that disassembly has occurred, the method further includes:
[0024] Send an alarm command to the safety response unit so that the safety response unit can perform safety protection operations based on the alarm command.
[0025] In one embodiment, the security operation includes at least one of locking the communication function of the eSIM module, destroying the privacy information stored in the eSIM module, and sending an alarm message to a remote server through a backup channel;
[0026] Alarm information includes at least one of the following: device identification, disassembly time, and abnormal monitoring data.
[0027] In one embodiment, the tamper verification key is written to the secure storage unit of the eSIM module when the eSIM module is manufactured or when user data is written to the eSIM module.
[0028] Secondly, this application provides an eSIM protection device configured in a main control chip, the device comprising:
[0029] The sending module is used to periodically send a challenge key to the eSIM module according to a preset period, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip;
[0030] The first determining module is used to determine the verification result of the response key;
[0031] The second determining module is used to determine the number of keys for the response key where the verification result is a verification failure when the verification result is a verification failure.
[0032] The third determination module is used to determine the security status of the eSIM module based on the number of keys whose verification results are response keys that failed to verify.
[0033] Thirdly, this application also provides a computer device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0034] According to a preset cycle, a challenge key is periodically sent to the eSIM module, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip;
[0035] Determine the verification result of the response key;
[0036] In the case of a verification failure, determine the number of keys for the response key that resulted in a verification failure.
[0037] The security status of the eSIM module is determined based on the number of keys whose verification results are failure responses.
[0038] Fourthly, this application also provides a computer-readable storage medium on which a computer program is stored, and which, when executed by a processor, performs the following steps:
[0039] According to a preset cycle, a challenge key is periodically sent to the eSIM module, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip;
[0040] Determine the verification result of the response key;
[0041] In the case of a verification failure, determine the number of keys for the response key that resulted in a verification failure.
[0042] The security status of the eSIM module is determined based on the number of keys whose verification results are failure responses.
[0043] Fifthly, this application also provides a computer program product comprising a computer program that, when executed by a processor, performs the following steps:
[0044] According to a preset cycle, a challenge key is periodically sent to the eSIM module, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip;
[0045] Determine the verification result of the response key;
[0046] In the case of a verification failure, determine the number of keys for the response key that resulted in a verification failure.
[0047] The security status of the eSIM module is determined based on the number of keys whose verification results are failure responses.
[0048] The aforementioned eSIM protection method, apparatus, computer equipment, and storage medium periodically send challenge keys to the eSIM module according to a preset cycle. The eSIM module encrypts the challenge keys based on the tamper-proof verification key, generates a response key, and sends the response key to the main control chip. The verification result of the response key is determined. If the verification result is a failure, the number of response keys with failed verification results is determined. Based on the number of response keys with failed verification results, the security status of the eSIM module is determined. In this application, challenge keys are periodically sent to the eSIM module, causing the eSIM module to encrypt the challenge keys based on the tamper-proof verification key, generate a response key, and send the response key to the main control chip. The main control chip determines the verification result of the response key. If the verification result is a failure, the number of response keys with failed verification results is determined. Finally, based on the number of keys, the security status of the eSIM module is accurately determined, enabling the user or the main control chip to take appropriate protective measures to protect the eSIM module if a security problem is determined (e.g., tampering has occurred). Attached Figure Description
[0049] Figure 1 This is an application environment diagram of an eSIM protection method provided in this embodiment;
[0050] Figure 2 This is a flowchart illustrating the first eSIM protection method provided in this embodiment;
[0051] Figure 3 This is a flowchart illustrating the process of determining the number of keys provided in this embodiment;
[0052] Figure 4 This is a flowchart illustrating the process of determining the security status of the eSIM module in this embodiment.
[0053] Figure 5 This is a flowchart illustrating the second eSIM protection method provided in this embodiment;
[0054] Figure 6 This is a structural block diagram of an eSIM protection device provided in this embodiment;
[0055] Figure 7 This is an internal structural diagram of the computer device provided in this embodiment. Detailed Implementation
[0056] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0057] The eSIM protection method provided in this application embodiment can be applied to, for example... Figure 1 In the illustrated application environment, the main control chip periodically sends a challenge key to the eSIM module according to a preset cycle. The eSIM module then encrypts the challenge key based on the tamper-proof verification key, generates a response key, and sends the response key back to the main control chip. The main control chip determines the verification result of the response key. If the verification fails, the main control chip determines the number of response keys that failed verification. Finally, the main control chip determines the security status of the eSIM module based on the number of response keys that failed verification.
[0058] The main control chip refers to the control chip that establishes a communication connection with the eSIM module, can randomly generate challenge keys, and verify the response keys returned by the eSIM module. It can be a processor, a System on Chip (SoC), or the terminal's application processor (AP).
[0059] The eSIM (embedded Subscriber Identity Module) module has a built-in secure storage unit for storing user identification information, challenge keys, and tamper-proof verification keys, and has an interface for secure communication with the main control chip.
[0060] In one embodiment, Figure 2 This is a flowchart illustrating an eSIM protection method according to an embodiment of this application, applied to... Figure 1 Taking the main control chip in the example, the method includes the following steps:
[0061] S201, according to a preset period, periodically sends a challenge key to the eSIM module, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip.
[0062] The preset period refers to the pre-defined time interval for periodically sending the challenge key to the eSIM module, for example, 5 seconds. The tamper verification key is a key pre-written into the eSIM module that can be used to encrypt the challenge key. The response key is the key obtained by encrypting the challenge key with the tamper verification key. The challenge key is a key randomly generated by the main control chip to determine the security status of the eSIM module. It should be noted that, under normal circumstances, the eSIM module needs to perform encryption operations on each challenge key to obtain the corresponding response key.
[0063] Optionally, in this embodiment, the tamper verification key is written to the secure storage unit of the eSIM module during the production of the eSIM module or when user data is written to the eSIM module. The secure storage unit refers to the storage unit within the eSIM module used to securely store user and operator information; for example, it can be a storage chip, memory card, etc. For example, after the phone is powered on, the main control chip completes initial authentication with the eSIM module and writes the tamper verification key to the eSIM module when writing user data. During phone use, the main control chip generates a 128-bit random challenge key every 5 seconds and sends it to the eSIM module via the secure SPI (Serial Peripheral Interface) protocol. The eSIM module uses the tamper verification key and employs the AES (Advanced Encryption Standard)-128 encryption algorithm to encrypt the challenge key, generate a response key, and return it to the main control chip.
[0064] S202, Determine the verification result of the response key.
[0065] The verification result refers to the verification result of the response key.
[0066] As an optional implementation of this application, the response key is decrypted to obtain a candidate key. The candidate key is then matched with the challenge key to obtain a verification result. Specifically, the main control chip stores a security verification key corresponding to the tamper-proof verification key. The response key is decrypted based on the security verification key to obtain a candidate key. The candidate key is then matched with the challenge key to obtain a verification result. The security verification key and the tamper-proof verification key are similar to a public-private key pair.
[0067] S203, if the verification result is a verification failure, determine the number of response keys for which the verification result is a verification failure.
[0068] The number of keys refers to the number of response keys whose verification result is a failure.
[0069] Optionally, in this embodiment, if the verification result is a verification failure, a first number of response keys with a verification failure result is determined. The number of challenge keys for which no feedback was received is taken as a second number; that is, the number of challenge keys for which the main control chip sends a challenge key to the eSIM module but the eSIM module does not send back a corresponding response key is also taken into account. Finally, the sum of the first number and the second number is taken as the key count.
[0070] S204. Determine the security status of the eSIM module based on the number of keys for which the verification result is a failed response key.
[0071] Optionally, in this embodiment, the security status of the eSIM module is determined based on the relationship between the number of response keys whose verification results are failures and the number threshold.
[0072] The aforementioned eSIM protection method periodically sends a challenge key to the eSIM module according to a preset cycle. The eSIM module then encrypts the challenge key based on the tamper-proof verification key, generates a response key, and sends the response key to the main control chip. The verification result of the response key is determined. If the verification fails, the number of response keys with failed verification results is determined. Based on the number of keys, the security status of the eSIM module is determined. In this application, a challenge key is periodically sent to the eSIM module, causing the eSIM module to encrypt the challenge key based on the tamper-proof verification key, generate a response key, and send the response key to the main control chip. The main control chip determines the verification result of the response key. If the verification fails, the number of response keys with failed verification results is determined. Finally, based on the number of response keys with failed verification results, the security status of the eSIM module is accurately determined, enabling the user or the main control chip to take appropriate protective measures to protect the eSIM module if a security problem is detected (e.g., tampering has occurred).
[0073] In one embodiment, to make the determined number of keys more valuable for reference, and thus improve the accuracy of the final determination of the desired security situation, such as... Figure 3 As shown, in step S203, when the verification result is a verification failure, the optional implementation of determining the number of keys for the response key where the verification result is a verification failure includes:
[0074] S301, if the verification result is a verification failure, obtain the first preset time period.
[0075] The first preset time period refers to a pre-set time period used to determine the number of keys.
[0076] Optionally, in this embodiment, the first preset time period is retrieved from the storage module.
[0077] S302, determine the number of response keys whose verification result is a verification failure within the first preset time period.
[0078] As an optional implementation of this application, the number of keys whose consecutive verification results are verification failures within a first preset time period is determined, i.e., the number of keys with consecutive verification failures. For example, three consecutive verification failures.
[0079] Another optional implementation of this application involves determining a first number of response keys whose verification result is verification failure within a first preset time period; and a second number of challenge keys for which no feedback was received within the first preset time period. That is, the number of challenge keys for which the eSIM module does not respond after the main control chip sends a challenge key to the eSIM module is also taken into account. Finally, the sum of the first number and the second number is taken as the total number of keys. For example, if three response keys with verification failure results and two challenge keys do not receive feedback within one minute, the final number of keys is 5.
[0080] In this embodiment, if the verification result is a failure, a first preset time period is obtained. The number of response keys whose verification result is a failure within the first preset time period is determined. This embodiment makes the number of keys more valuable for reference, thereby improving the accuracy of security status confirmation.
[0081] In one embodiment, to improve the accuracy of the determined security situation, such as Figure 4 As shown, one optional implementation of determining the security status of the eSIM module based on the number of keys in S204 includes:
[0082] S401: When the number of keys exceeds the threshold, obtain the voltage change and communication monitoring status of the eSIM module.
[0083] Among these, voltage variation refers to changes in the power supply voltage of the eSIM module. Communication monitoring refers to the monitoring of the communication signals of the eSIM module.
[0084] Optionally, in this embodiment, voltage changes are acquired based on a power supply monitoring circuit. This power supply monitoring circuit may consist of a voltage sensor and / or a current sensor.
[0085] Optionally, in this embodiment, communication monitoring information can be obtained based on a communication signal monitoring circuit. The main monitoring parameters are the duration of communication signal interruptions and / or the bit error rate.
[0086] Optionally, in this embodiment, if the number of keys exceeds a threshold, the voltage change and communication monitoring status of the eSIM module are obtained. Based on the voltage change and communication monitoring status, the security status of the eSIM module is determined.
[0087] S402, if the voltage change is abnormal and the communication monitoring is abnormal, it is determined that the eSIM module has been disassembled.
[0088] Optionally, in this embodiment, if the drop in the power supply voltage of the eSIM module exceeds a preset threshold within the second preset time period, the voltage change is determined to be an abnormal voltage change. For example, the power supply voltage or current drops by more than 30% within 100ms.
[0089] Optionally, in this embodiment, if the duration of a communication signal interruption exceeds a preset interruption duration or the bit error rate exceeds a bit error rate threshold, the communication monitoring situation is determined to be abnormal. For example, the duration of a communication signal interruption exceeds 500ms or the bit error rate exceeds 30%.
[0090] Optionally, in this embodiment, after determining that the security status of the eSIM module is that there has been a disassembly, an optional implementation of the eSIM module protection method is to send an alarm command to the security response unit, so that the security response unit performs security protection operations based on the alarm command.
[0091] Optionally, the security measures in this embodiment include at least one of the following: locking the communication function of the eSIM module, destroying the privacy information stored in the eSIM module, and sending alarm information to a remote server via a backup channel. The alarm information includes at least one of the following: device identifier, disassembly time, and abnormal monitoring data. The backup channel may include Bluetooth or NFC (Near Field Communication).
[0092] In this embodiment, if the number of keys exceeds a threshold, the voltage change is abnormal, and the communication monitoring is abnormal, the security status of the eSIM module is determined to be that it has been disassembled. This embodiment effectively improves the accuracy of security status confirmation and implements corresponding protective measures, which can effectively enhance the security of privacy and sensitive information and reduce the risk of information leakage.
[0093] In one embodiment, such as Figure 5 As shown, an optional implementation of an eSIM protection method includes:
[0094] S501: When manufacturing an eSIM module or writing user data to an eSIM module, write an anti-tamper verification key to the secure storage unit of the eSIM module.
[0095] S502 periodically sends a challenge key to the eSIM module according to a preset cycle, so that the eSIM module encrypts the challenge key based on the tamper-proof verification key, generates a response key, and sends the response key to the main control chip.
[0096] S503, decrypt the response key to obtain the candidate key.
[0097] S504, match the candidate key with the challenge key to obtain the verification result.
[0098] S505, if the verification result is a verification failure, obtain the first preset time period.
[0099] S506, determine the number of response keys whose verification result is a verification failure within the first preset time period.
[0100] S507: If the number of response keys with verification failure results exceeds the number threshold, obtain the voltage change and communication monitoring status of the eSIM module.
[0101] S508, if the drop in the power supply voltage of the eSIM module exceeds a preset threshold within the second preset time period, the voltage change is determined to be an abnormal voltage change.
[0102] S509: If the duration of a communication signal interruption exceeds a preset interruption duration or the bit error rate exceeds a bit error rate threshold, the communication monitoring situation is determined to be abnormal.
[0103] S510, if the voltage change is abnormal and the communication monitoring is abnormal, it is determined that the eSIM module has been disassembled.
[0104] S511, send an alarm command to the security response unit so that the security response unit can perform security protection operations based on the alarm command. The security protection operations include locking the communication function of the eSIM module, destroying privacy information stored in the eSIM module, and sending alarm information to a remote server via a backup channel. The alarm information includes at least one of the following: device identifier, disassembly time, and abnormal monitoring data.
[0105] The eSIM protection method in this embodiment periodically sends a challenge key to the eSIM module according to a preset period. The eSIM module encrypts the challenge key based on the tamper-proof verification key, generates a response key, and sends the response key to the main control chip. The verification result of the response key is determined. If the verification result is a failure, the number of response keys with a failed verification result is determined. Based on the number of keys, the security status of the eSIM module is determined. In this application, a challenge key is periodically sent to the eSIM module, which then encrypts the challenge key based on the tamper-proof verification key, generates a response key, and sends the response key to the main control chip. The main control chip determines the verification result of the response key. If the verification result is a failure, the number of response keys with a failed verification result is determined. Finally, if the number of keys exceeds a threshold, the voltage change is abnormal, and the communication monitoring is abnormal, the security status of the eSIM module is determined to be that tampering has occurred. At this time, an alarm command is sent to the security response unit, causing the security response unit to perform security protection operations based on the alarm command. The security measures include at least one of the following: locking the eSIM module's communication functions, destroying private information stored in the eSIM module, and sending an alarm message to a remote server via a backup channel. The alarm message includes at least one of the following: device identifier, removal time, and abnormal monitoring data. This effectively enhances the information security of the eSIM module and prevents information leakage.
[0106] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0107] Based on the same inventive concept, this application also provides an eSIM protection device for implementing the eSIM protection method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more eSIM protection device embodiments provided below can be found in the limitations of the eSIM protection method described above, and will not be repeated here.
[0108] In one embodiment, by Figure 6A structural block diagram of an eSIM protection device in one embodiment is shown. Figure 6 As shown, an eSIM protection device 1 is provided, which includes: a transmitting module 10, a first determining module 20, a second determining module 30, and a third determining module 40, wherein:
[0109] The sending module 10 is used to periodically send a challenge key to the eSIM module according to a preset period, so that the eSIM module encrypts the challenge key based on the tamper-proof verification key, generates a response key, and sends the response key to the main control chip.
[0110] The first determining module 20 is used to determine the verification result of the response key;
[0111] The second determining module 30 is used to determine the number of keys of the response key whose verification result is verification failure when the verification result is verification failure.
[0112] The third determination module 40 is used to determine the security status of the eSIM module based on the number of keys whose verification result is a failed response key.
[0113] In one embodiment, the first determining module 20 is further specifically used for:
[0114] The response key is decrypted to obtain the candidate key;
[0115] The candidate key is matched with the challenge key to obtain the verification result.
[0116] In one embodiment, the second determining module 30 is further specifically used for:
[0117] If the verification result is a failure, obtain the first preset time period;
[0118] Determine the number of keys whose verification result is a failure response key within the first preset time period.
[0119] In one embodiment, the third determining module 40 is further specifically used for:
[0120] If the number of keys exceeds the threshold, obtain the voltage change and communication monitoring status of the eSIM module;
[0121] If the voltage change is abnormal and the communication monitoring is abnormal, it is determined that the eSIM module has been disassembled.
[0122] In one embodiment, an eSIM protection device 1 further includes:
[0123] The fourth determination module is used to determine that the voltage change is abnormal if the drop ratio of the power supply voltage of the eSIM module exceeds a preset ratio threshold within the second preset time period.
[0124] In one embodiment, an eSIM protection device 1 further includes:
[0125] The fifth determination module is used to determine that the communication monitoring situation is abnormal when the signal interruption duration of the monitored communication signal exceeds the preset interruption duration or the bit error rate exceeds the bit error rate threshold.
[0126] In one embodiment, an eSIM protection device 1 further includes:
[0127] The sending module is used to send alarm commands to the safety response unit, so that the safety response unit can perform safety protection operations based on the alarm commands.
[0128] In one embodiment, the security operation includes at least one of locking the communication function of the eSIM module, destroying the privacy information stored in the eSIM module, and sending an alarm message to a remote server through a backup channel;
[0129] Alarm information includes at least one of the following: device identification, disassembly time, and abnormal monitoring data.
[0130] In one embodiment, the tamper verification key is written to the secure storage unit of the eSIM module when the eSIM module is manufactured or when user data is written to the eSIM module.
[0131] The modules in the aforementioned eSIM protection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.
[0132] In one embodiment, a computer device is provided, which may be a platform-side device, and its internal structure diagram may be as follows: Figure 7As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The database stores eSIM protection information. The network interface communicates with an external user via a network connection. When the computer program is executed by the processor, it implements an eSIM protection method.
[0133] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specifically, the computer device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0134] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0135] According to a preset cycle, a challenge key is periodically sent to the eSIM module, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip;
[0136] Determine the verification result of the response key;
[0137] In the case of a verification failure, determine the number of keys for the response key that resulted in a verification failure.
[0138] The security status of the eSIM module is determined based on the number of keys whose verification results are failure responses.
[0139] In one embodiment, when the processor executes the computer program, it further performs the following steps: determining the verification result of the response key, including:
[0140] The response key is decrypted to obtain the candidate key;
[0141] The candidate key is matched with the challenge key to obtain the verification result.
[0142] In one embodiment, when the processor executes the computer program, it further performs the following steps: determining the number of keys for a response key where the verification result is a verification failure, in the event that the verification result is a verification failure, including:
[0143] If the verification result is a failure, obtain the first preset time period;
[0144] Determine the number of keys whose verification result is a failure response key within the first preset time period.
[0145] In one embodiment, when the processor executes the computer program, it further performs the following steps: determining the security status of the eSIM module based on the number of keys for which the verification result is a failed verification response key, including:
[0146] If the number of keys whose verification results are failures exceeds the threshold, obtain the voltage change and communication monitoring status of the eSIM module.
[0147] The security status of the eSIM module is determined based on voltage changes and communication monitoring.
[0148] In one embodiment, when the processor executes the computer program, it further performs the following steps: determining the security status of the eSIM module based on voltage changes and communication monitoring, including:
[0149] If the voltage change is abnormal and the communication monitoring is abnormal, it is determined that the eSIM module has been disassembled.
[0150] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0151] If the drop in the power supply voltage of the eSIM module exceeds a preset threshold within the second preset time period, the voltage change is determined to be an abnormal voltage change.
[0152] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0153] If the duration of a communication signal interruption exceeds the preset interruption duration or the bit error rate exceeds the bit error rate threshold, the communication monitoring situation is determined to be abnormal.
[0154] In one embodiment, the processor, while executing the computer program, further implements the following steps: after determining that the security status of the eSIM module indicates that tampering has occurred, the method further includes:
[0155] Send an alarm command to the safety response unit so that the safety response unit can perform safety protection operations based on the alarm command.
[0156] In one embodiment, when the processor executes the computer program, it also performs the following steps: the security operation includes at least one of locking the communication function of the eSIM module, destroying the privacy information stored in the eSIM module, and sending an alarm message to a remote server through a backup channel;
[0157] Alarm information includes at least one of the following: device identification, disassembly time, and abnormal monitoring data.
[0158] In one embodiment, the processor, when executing the computer program, further implements the following steps: the tamper-proof verification key is written to the secure storage unit of the eSIM module when the eSIM module is manufactured or when user data is written to the eSIM module.
[0159] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0160] According to a preset cycle, a challenge key is periodically sent to the eSIM module, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip;
[0161] Determine the verification result of the response key;
[0162] In the case of a verification failure, determine the number of keys for the response key that resulted in a verification failure.
[0163] The security status of the eSIM module is determined based on the number of keys whose verification results are failure responses.
[0164] In one embodiment, when the computer program is executed by a processor, it further performs the following steps: determining the verification result of the response key, including:
[0165] The response key is decrypted to obtain the candidate key;
[0166] The candidate key is matched with the challenge key to obtain the verification result.
[0167] In one embodiment, when the computer program is executed by a processor, it further performs the following steps: in the case that the verification result is a verification failure, determining the number of keys for the response key where the verification result is a verification failure, including:
[0168] If the verification result is a failure, obtain the first preset time period;
[0169] Determine the number of keys whose verification result is a failure response key within the first preset time period.
[0170] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: determining the security status of the eSIM module based on the number of keys whose verification result is a failed response key, including:
[0171] If the number of keys whose verification results are failures exceeds the threshold, obtain the voltage change and communication monitoring status of the eSIM module.
[0172] The security status of the eSIM module is determined based on voltage changes and communication monitoring.
[0173] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: determining the security status of the eSIM module based on voltage changes and communication monitoring, including:
[0174] If the voltage change is abnormal and the communication monitoring is abnormal, it is determined that the eSIM module has been disassembled.
[0175] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0176] If the drop in the power supply voltage of the eSIM module exceeds a preset threshold within the second preset time period, the voltage change is determined to be an abnormal voltage change.
[0177] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0178] If the duration of a communication signal interruption exceeds the preset interruption duration or the bit error rate exceeds the bit error rate threshold, the communication monitoring situation is determined to be abnormal.
[0179] In one embodiment, when the computer program is executed by the processor, it further implements the following steps: after determining that the security status of the eSIM module indicates that tampering has occurred, the method further includes:
[0180] Send an alarm command to the safety response unit so that the safety response unit can perform safety protection operations based on the alarm command.
[0181] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: the security operation includes at least one of locking the communication function of the eSIM module, destroying the privacy information stored in the eSIM module, and sending an alarm message to a remote server through a backup channel;
[0182] Alarm information includes at least one of the following: device identification, disassembly time, and abnormal monitoring data.
[0183] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: the tamper-proof verification key is written to the secure storage unit of the eSIM module when the eSIM module is manufactured or when user data is written to the eSIM module.
[0184] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0185] According to a preset cycle, a challenge key is periodically sent to the eSIM module, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip;
[0186] Determine the verification result of the response key;
[0187] In the case of a verification failure, determine the number of keys for the response key that resulted in a verification failure.
[0188] The security status of the eSIM module is determined based on the number of keys whose verification results are failure responses.
[0189] In one embodiment, when the computer program is executed by a processor, it further performs the following steps: determining the verification result of the response key, including:
[0190] The response key is decrypted to obtain the candidate key;
[0191] The candidate key is matched with the challenge key to obtain the verification result.
[0192] In one embodiment, when the computer program is executed by a processor, it further performs the following steps: in the case that the verification result is a verification failure, determining the number of keys for the response key where the verification result is a verification failure, including:
[0193] If the verification result is a failure, obtain the first preset time period;
[0194] Determine the number of keys whose verification result is a failure response key within the first preset time period.
[0195] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: determining the security status of the eSIM module based on the number of keys whose verification result is a failed response key, including:
[0196] If the number of keys whose verification results are failures exceeds the threshold, obtain the voltage change and communication monitoring status of the eSIM module.
[0197] The security status of the eSIM module is determined based on voltage changes and communication monitoring.
[0198] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: determining the security status of the eSIM module based on voltage changes and communication monitoring, including:
[0199] If the voltage change is abnormal and the communication monitoring is abnormal, it is determined that the eSIM module has been disassembled.
[0200] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0201] If the drop in the power supply voltage of the eSIM module exceeds a preset threshold within the second preset time period, the voltage change is determined to be an abnormal voltage change.
[0202] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0203] If the duration of a communication signal interruption exceeds the preset interruption duration or the bit error rate exceeds the bit error rate threshold, the communication monitoring situation is determined to be abnormal.
[0204] In one embodiment, when the computer program is executed by the processor, it further implements the following steps: after determining that the security status of the eSIM module indicates that tampering has occurred, the method further includes:
[0205] Send an alarm command to the safety response unit so that the safety response unit can perform safety protection operations based on the alarm command.
[0206] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: the security operation includes at least one of locking the communication function of the eSIM module, destroying the privacy information stored in the eSIM module, and sending an alarm message to a remote server through a backup channel;
[0207] Alarm information includes at least one of the following: device identification, disassembly time, and abnormal monitoring data.
[0208] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: the tamper-proof verification key is written to the secure storage unit of the eSIM module when the eSIM module is manufactured or when user data is written to the eSIM module.
[0209] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these. The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combinations of these technical features are not contradictory, they should be considered within the scope of this specification.
[0210] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. An eSIM protection method, characterized in that, Applied to a main control chip, the method includes: According to a preset cycle, a challenge key is periodically sent to the embedded SIM card eSIM module, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip; Determine the verification result of the response key; In the event that the verification result is a verification failure, determine the number of response keys for which the verification result is a verification failure; The security status of the eSIM module is determined based on the number of keys for which the verification result is a failed response key.
2. The method according to claim 1, characterized in that, The determination of the verification result of the response key includes: The response key is decrypted to obtain the candidate key; The candidate key is matched with the challenge key to obtain the verification result.
3. The method according to claim 1, characterized in that, The step of determining the number of response keys for which the verification result is a verification failure when the verification result is a verification failure includes: If the verification result is a verification failure, a first preset time period is obtained; Determine the number of response keys whose verification result is a verification failure within the first preset time period.
4. The method according to claim 1, characterized in that, Determining the security status of the eSIM module based on the number of keys for which the verification result is a failed response key includes: If the number of keys whose verification result is a failure exceeds a certain threshold, the voltage change and communication monitoring status of the eSIM module are obtained. If the voltage change is abnormal and the communication monitoring is abnormal, it is determined that the eSIM module has been disassembled.
5. The method according to claim 4, characterized in that, The method further includes: If, within a second preset time period, the decrease in the power supply voltage of the eSIM module exceeds a preset threshold, the voltage change is determined to be an abnormal voltage change.
6. The method according to claim 4, characterized in that, The method further includes: If the duration of a communication signal interruption exceeds a preset interruption duration or the bit error rate exceeds a bit error rate threshold, the communication monitoring situation is determined to be an abnormality.
7. The method according to claim 4, characterized in that, After determining that the security status of the eSIM module indicates that disassembly has occurred, the method further includes: An alarm command is sent to the safety response unit so that the safety response unit can perform safety protection operations based on the alarm command.
8. The method according to claim 7, characterized in that, The security measures include at least one of the following: locking the communication function of the eSIM module, destroying the privacy information stored in the eSIM module, and sending an alarm message to a remote server through a backup channel. The alarm information includes at least one of the following: device identification, disassembly time, and abnormal monitoring data.
9. The method according to claim 1, characterized in that, The tamper-proof verification key is written to the secure storage unit of the eSIM module when the eSIM module is manufactured or when user data is written into the eSIM module.
10. An eSIM protection device, characterized in that, The device, configured in the main control chip, includes: The sending module is used to periodically send a challenge key to the eSIM module according to a preset period, so that the eSIM module encrypts the challenge key based on the anti-tamper verification key, generates a response key, and sends the response key to the main control chip; The first determining module is used to determine the verification result of the response key; The second determining module is used to determine the number of keys of the response key whose verification result is verification failure when the verification result is verification failure. The third determining module is used to determine the security status of the eSIM module based on the number of keys for which the verification result is a failed verification response key.
11. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 9.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 9.
13. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 9.