Near field communication routing method and device, storage medium and electronic equipment

By establishing a secure communication link in the eSIM terminal to obtain the card application list and configure routing data, the problem of unclear NFC routing targets is solved, enabling accurate routing in multi-activation configuration file scenarios, improving the accuracy and security of NFC functions, and enhancing the user experience.

CN121126477APending Publication Date: 2025-12-12CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511157652.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-19
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In scenarios with multiple active profiles, the NFC routing target of the eSIM terminal is unclear and the card application selection strategy in the profile is missing, which causes the NFC function to malfunction and affects the user experience.

Method used

By establishing a secure communication link to obtain the card application list and writing its routing data into the near-field communication routing table or the chip operating system of the embedded general-purpose integrated circuit card, the routing of near-field communication is configured to ensure the accuracy and flexibility of routing.

Benefits of technology

It enables precise routing configuration in multi-activation configuration scenarios, improves the accuracy, flexibility and system security of near-field communication routing, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121126477A_ABST
    Figure CN121126477A_ABST
Patent Text Reader

Abstract

The invention discloses a near field communication routing method and device, a storage medium and electronic equipment, and relates to the technical field of terminals, and the method can establish a secure communication link, and obtains a card application list through the secure communication link. And writing the routing data of the card application list into a routing table of the near field communication or a chip operating system of the embedded universal integrated circuit card so as to configure the routing of the near field communication. Wherein the secure communication link is established and generated based on the trusted service management platform and an embedded universal integrated circuit card of the terminal equipment. By applying the technical scheme of the invention, the routing data of the near field communication is written into the near field communication routing table or the chip operating system, accurate routing configuration can be realized, and routing conflicts in a multi-activation configuration file scene are solved, so that the accuracy and flexibility of the near field communication routing and the system security are improved, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of terminal technology, and in particular to a near-field communication routing method, apparatus, storage medium and electronic device. Background Technology

[0002] In the field of mobile terminal technology, eSIM (Embedded Subscriber Identification Module) is an electronic chip soldered onto the device circuit board. It can store multiple operator profiles and support users to switch operator services through software, realizing multiple enabled profiles (MEP) scenarios, that is, activating multiple profiles at the same time to flexibly use different operator services.

[0003] Meanwhile, NFC (Near Field Communication) technology, as a key capability for terminals to achieve short-range wireless interaction, widely supports card applications such as transportation cards and access control cards. These card applications rely on data in a specific carrier to complete the interaction. For eSIM terminals or physical SIM card terminals activated with a single profile, NFC interaction data is routed to a single secure carrier (such as a physical SIM card or a single-profile eSIM), and data forwarding is completed through a preset routing table or internal carrier logic.

[0004] However, the above methods can only meet the NFC configuration of a single carrier or a single configuration file. Since eSIM terminals support multiple active configuration files and each configuration file can install card applications with the same application ID, problems such as unclear NFC routing targets and missing card application selection strategies in the configuration files will occur. As a result, the NFC function of eSIM terminals cannot be used normally in multi-active configuration file scenarios, thus affecting the user experience of eSIM terminals. Summary of the Invention

[0005] In view of this, this application provides a near-field communication routing method, apparatus, storage medium, and electronic device to solve the problems of unclear NFC routing targets and missing card application selection strategies in multi-activation profile scenarios.

[0006] In a first aspect, this application provides a near-field communication routing method applied to a terminal device, the method comprising:

[0007] A secure communication link is established, which is generated based on the trusted service management platform and the embedded general-purpose integrated circuit card of the terminal device.

[0008] The card application list is obtained through the secure communication link;

[0009] The routing data of the card application list is written into at least one of the near-field communication routing table and the chip operating system of the embedded general-purpose integrated circuit card to configure the routing of the near-field communication.

[0010] In some embodiments of this application, establishing a secure communication link includes: sending a configuration file identifier to the trusted service management platform so that the trusted service management platform returns a first random number based on the configuration file identifier; receiving the first random number; transmitting the first random number to the embedded general-purpose integrated circuit card so that the embedded general-purpose integrated circuit card generates a second random number based on the first random number; performing encryption authentication on the first random number and the second random number to establish the secure communication link based on the authentication result of the encryption authentication.

[0011] In some embodiments of this application, the step of performing encryption authentication on the first random number and the second random number includes: encrypting the first random number and the second random number using a preset symmetric key to generate a first ciphertext; sending the first ciphertext and the second random number to the trusted service management platform, so that the trusted service management platform generates a first process key based on the symmetric key and generates a second ciphertext based on the symmetric key; receiving the second ciphertext fed back by the trusted service management platform; transparently transmitting the second ciphertext to the embedded general-purpose integrated circuit card, so that the embedded general-purpose integrated circuit card authenticates the second ciphertext; and generating a second process key based on the symmetric key in response to successful authentication of the second ciphertext.

[0012] In some embodiments of this application, obtaining the card application list through the secure communication link includes: sending a request to obtain the card application list to the trusted service management platform through the secure communication link; receiving an encrypted instruction from the trusted service management platform based on the request; and obtaining the card application list based on the encrypted instruction.

[0013] In some embodiments of this application, obtaining the card application list based on the encryption instruction includes: transmitting the encryption instruction to the embedded general-purpose integrated circuit card, so that the embedded general-purpose integrated circuit card decrypts the encryption instruction and obtains a first list in response to the decrypted encryption instruction; encrypting the first list to generate an encrypted list; sending the encrypted list to the trusted service management platform, so that the trusted service management platform decrypts the encrypted list to generate a second list; and receiving the second list fed back by the trusted service management platform to obtain the card application list.

[0014] In some embodiments of this application, writing the routing data of the card application list into the routing table of near-field communication includes: parsing the application identifier, configuration file identifier, and security carrier of the card application list; and writing the application identifier, configuration file identifier, and security carrier into the routing table of near-field communication.

[0015] In some embodiments of this application, writing the routing data of the card application list into the chip operating system of the embedded general-purpose integrated circuit card includes: parsing the application identifier, configuration file identifier, and security carrier of the card application list; and writing the application identifier, configuration file identifier, and security carrier into the chip operating system of the embedded general-purpose integrated circuit card.

[0016] In some embodiments of this application, the method further includes: responding to a selection instruction input by a user based on a configuration file list, parsing the target configuration file associated with the selection instruction, wherein the configuration file list is used to record configuration files in an activated state; setting the security carrier as the embedded general-purpose integrated circuit card in the routing table; and writing the configuration file identifier of the target configuration file into the chip operating system of the embedded general-purpose integrated circuit card to generate a default route for the near-field communication.

[0017] In some embodiments of this application, the method further includes: responding to a selection instruction input by a user based on a configuration file list, parsing the target configuration file associated with the selection instruction, the configuration file list including configuration files in an activated state; setting the security carrier as the embedded general-purpose integrated circuit card in the routing table; and writing the configuration file identifier of the target configuration file into the routing table to generate a default route for the near-field communication.

[0018] In some embodiments of this application, the method further includes: in response to an installation event of the card application, obtaining application information of the card application, the application information including an application identifier of the card application and a file identifier of the configuration file corresponding to the card application; and writing the application information into at least one of the routing table of the near-field communication and the chip operating system of the embedded general-purpose integrated circuit card.

[0019] In some embodiments of this application, the method further includes: in response to an interaction command from near-field communication, detecting a routing record of the terminal device, the interaction command including a target application identifier; in response to the routing record including target data, routing the interaction command to a corresponding first security carrier according to the routing record, so that the terminal device responds to the interaction command based on the first security carrier; the target data including at least one of the correspondence between the target application identifier and the security carrier recorded in the routing table, and the correspondence between the target application identifier and the configuration file recorded in the chip operating system; in response to the routing record not including the target data, routing the interaction command to a corresponding second security carrier according to a default route, so that the terminal device responds to the interaction command based on the second security carrier; the second security carrier is the security carrier corresponding to the default route.

[0020] Secondly, this application also provides a near-field communication routing device, comprising:

[0021] Embedded general-purpose integrated circuit cards are configured to store configuration files;

[0022] The controller is configured as follows:

[0023] A secure communication link is established, which is generated based on the trusted service management platform and the embedded general-purpose integrated circuit card.

[0024] The card application list is obtained through the secure communication link;

[0025] The routing data of the card application list is written into at least one of the near-field communication routing table and the chip operating system of the embedded general-purpose integrated circuit card to configure the routing of the near-field communication.

[0026] Thirdly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described in the first aspect.

[0027] Fourthly, this application provides an electronic device, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor executes the computer program to implement the method described in the first aspect.

[0028] Fifthly, this application provides a computer program product having a computer program stored thereon, wherein the computer program product, when executed by a processor, implements the method described in the first aspect.

[0029] As can be seen from the above technical solutions, the near-field communication routing method, apparatus, storage medium, and electronic device disclosed in this application relate to the field of terminal technology. The method can establish a secure communication link and obtain a card application list through the secure communication link. Then, the routing data of the card application list is written into the near-field communication routing table or the chip operating system of the embedded general-purpose integrated circuit card to configure the near-field communication routing. The secure communication link is established and generated based on a trusted service management platform and the embedded general-purpose integrated circuit card of the terminal device. By applying the technical solutions of this application, writing the near-field communication routing data into the near-field communication routing table or chip operating system, accurate routing configuration can be achieved, resolving routing conflicts in multi-activation configuration file scenarios, thereby improving the accuracy, flexibility, and system security of near-field communication routing and enhancing the user experience.

[0030] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0031] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0032] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0033] Figure 1 A schematic diagram of the architecture of the eSIM terminal provided in an embodiment of this application is shown;

[0034] Figure 2 The diagram shows the display effect of the NFC settings page provided in an embodiment of this application;

[0035] Figure 3 A flowchart illustrating a near-field communication routing method provided in an embodiment of this application is shown;

[0036] Figure 4 A timing diagram of the NFC setup process provided in an embodiment of this application is shown;

[0037] Figure 5 A schematic diagram of the NFC interaction process provided in an embodiment of this application is shown;

[0038] Figure 6The diagram shows the display effect of the configuration file settings page provided in an embodiment of this application;

[0039] Figure 7 A schematic diagram of a near-field communication routing device provided in an embodiment of this application is shown. Detailed Implementation

[0040] The embodiments of this application will now be described in more detail with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0041] In the field of mobile terminal technology, an eSIM terminal is a terminal device with a built-in eSIM. The eSIM is used to store operator credentials and user information, enabling the terminal device to connect to the network. The eSIM can be configured via software to select or change operators without replacing the physical SIM card. In other words, an eSIM can store profiles of multiple operators, allowing users to switch operator services via software.

[0042] The profile on an eSIM contains authentication and configuration data specific to a particular operator, enabling the terminal device to connect to that operator's network. For example, when a user wants to use a particular operator's service, the operator securely downloads the profile to the eSIM. In some embodiments, the eSIM can store multiple profiles, and multiple different profiles, or MEPs, can be activated simultaneously. This allows users to switch between different profiles as needed to use different operator services.

[0043] eSIM can install and manage various built-in applications and services. In some embodiments, eSIM has multi-application carrying capabilities, integrating multiple application instances with different functional attributes, thereby enabling the reuse of a single card in multiple scenarios. For example, it can function as a transportation card, access card, or campus card based on NFC technology.

[0044] However, since eSIM terminals can support MEP, each profile file can install an APP (Application) with the same application ID, i.e., a card application. Therefore, in MEP scenarios, there will be problems such as unclear NFC routing targets and missing card application selection strategies in the configuration file, which will affect the use of NFC functions.

[0045] To address the aforementioned issues, some embodiments of this application provide a near-field communication routing method. This method can be applied to terminal devices, enabling precise routing configuration and resolving routing conflicts in scenarios with multiple active configuration files.

[0046] like Figure 1As shown, in some embodiments, the terminal device can be an eSIM terminal, which may include CLF (Contactless Front-end), eUICC (Embedded Universal Integrated Circuit Card), LPA (Local Profile Assistant), eSE (Embedded Secure Element), a first APP (such as an operator APP or / or system APP), a card application management server, and a second APP (such as an operator-specific APP installed via over-the-air download).

[0047] The CLF (Content Flow Framework) is a key component supporting NFC functionality, responsible for handling the transmission and reception of radio frequency signals. The CLF integrates an NFC controller, which is responsible for parsing various protocols in the NFC standard, supporting different NFC operating modes, and routing. The NFC controller determines where received data is directed based on the contents of the NFC routing table. For example, the routing table can be configured to route NFC data to a specific secure carrier by default, such as eSE, eUICC, or SIM card, or it can specify the AID (Application Identifier) ​​of a particular card application to route to a specific secure carrier.

[0048] The eUICC can store profiles from multiple operators and allow users to activate different profiles as needed. The LPA is used to manage and download eSIM profiles. The eSE is used to implement mobile wallet services for terminal manufacturers. The first app can manage the profile files in the eUICC card by calling the relevant interfaces of the LPA. The card application management server, namely DSOP (Data Security Operation Platform), manages the card applications and personalized data in the eUICC card. The second application can obtain data from the card application management server, write card applications or personalized data into the eUICC card, and trigger the management of card applications in the eUICC card through the UI display.

[0049] For the default NFC swipe setting, i.e., the default route for near-field communication, the terminal device can respond to the user's selection command based on the profile list, and parse the target profile associated with the selection command, i.e., the profile selected by the user. The profile list records the profiles in an active state. In other words, the user can select a profile from the active profiles as the default swipe setting, i.e., the default route for NFC. Then, the terminal device needs to record the routing options corresponding to the selected target profile. These routing options can include the security carrier and the profile identifier (i.e., the profile identifier) ​​corresponding to the profile.

[0050] To facilitate user selection, in some embodiments, the terminal device may display the NFC settings page based on a list of configuration files. The NFC settings page includes active configuration files and options for built-in applications.

[0051] For example, for eSIM terminals, the NFC settings page displays the terminal wallet and HCE (Host Card Emulation) applications, as well as a list of activated profile files on the terminal obtained via LPA. Figure 2 As shown, users can... Figure 2 The NFC settings page shown specifies the default NFC route, which is the default route when swiping a card.

[0052] In some embodiments, for the routing option record of the default route, the security carrier is set to an embedded general-purpose integrated circuit card in the routing table, and the configuration file identifier of the target configuration file is written into the chip operating system of the embedded general-purpose integrated circuit card to generate the default route for near-field communication.

[0053] In other words, the security carrier is set to eUICC in the NFC routing table, and the profile identifier of the target configuration file is written into the eUICC's COS (Chip Operating System). That is, the NFC routing table is set to route to the eUICC chip according to the target configuration file, and the NFC routing options are recorded in the eUICC's COS. When a card is swiped (an NFC interaction command is received), the eUICC's COS forwards the interaction command to the corresponding profile (target configuration file) for data exchange.

[0054] Alternatively, in some embodiments, the security carrier is set to an embedded general-purpose integrated circuit card in the routing table, and the configuration file identifier of the target configuration file is written into the routing table to generate a default route for near-field communication.

[0055] In other words, the security carrier is set to eUICC in the NFC routing table, and the profile identifier of the target configuration file is written into the routing table. Specifically, the CLF chip is modified, and the relevant fields for the profile identifier on the eUICC are added to the NFC routing table. When a user selects to route to the target configuration file on the NFC settings page, the terminal device can add a corresponding record to the NFC routing table via the appropriate API (Application Programming Interface), including the security carrier being the eUICC card and the profile identifier of the target configuration file. When the card is swiped, the NFC routing table record directly routes to the specified profile (i.e., the target configuration file).

[0056] Based on the above embodiments, for the default NFC swipe settings, after the user selects a profile on the eSIM terminal's NFC settings page, the terminal device can record the routing options in two ways: first, it can point the route to the eUICC, which will then forward the data to the target profile via its COS; second, it can expand the NFC routing table of the CLF chip by adding a profile identifier field, directly recording the security carrier and the specific profile identifier to achieve direct data delivery, and only displaying activated profiles to ensure the validity of the routing target. This improves routing flexibility, allowing users to select as needed and avoiding invalid routes; the two recording methods optimize routing efficiency and ensure accurate data flow.

[0057] For the NFC settings pre-configured in the profile, such as Figure 3 As shown, the near-field communication routing method provided in this application embodiment may include the following procedural steps:

[0058] S301. Establish a secure communication link.

[0059] The secure communication link is established based on the embedded general-purpose integrated circuit card of the terminal device through the trusted service management platform. The trusted service management platform is TSM (Trusted Service Manager).

[0060] In some embodiments, the terminal device may be triggered to execute step S301 in response to a download event of a configuration application. For example, when a card application is pre-configured in the eSIM profile, and the profile is downloaded to the eUICC card and the download is complete, the terminal device is triggered to execute the step of establishing a secure communication link in order to obtain the card application list corresponding to the profile through the secure communication link.

[0061] In some embodiments, when establishing a secure communication link, the terminal device sends a configuration file identifier to the trusted service management platform, so that the trusted service management platform returns a first random number, i.e., a server random number, based on the configuration file identifier. The configuration file identifier is the profile identifier corresponding to the currently downloaded profile. The terminal device receives the first random number and then transmits it transparently to the embedded general-purpose integrated circuit card (IPC card), so that the IPC card generates a second random number, i.e., a card random number, based on the first random number. Then, encryption authentication is performed on the first and second random numbers to establish a secure communication link based on the authentication result.

[0062] In some embodiments, when performing encryption authentication on the first and second random numbers, the embedded general-purpose integrated circuit card (EPSC) can encrypt the first and second random numbers using a preset symmetric key to generate a first ciphertext. Then, the terminal device sends the first ciphertext and the second random number to a trusted service management platform, which generates a first process key based on the symmetric key and then generates a second ciphertext based on the symmetric key. The terminal device receives the second ciphertext from the trusted service management platform and then transmits it transparently to the EPSC to authenticate the second ciphertext. Finally, in response to successful authentication of the second ciphertext, a second process key is generated based on the symmetric key.

[0063] In some embodiments, the process key (including a first process key and a second process key) is generated by distributing a preset key.

[0064] For example, when the eSIM profile has a pre-installed card application, and the profile is downloaded to the eUICC card and the download is complete, such as Figure 4As shown, the terminal device's operating system sends a profile identifier to the TSM platform (S1) to request the establishment of a secure channel, i.e., a secure communication link, between the TSM and the eUICC card. The TSM platform generates a server random number (S2) and returns it to the terminal device's operating system (S3). The terminal device's operating system then transmits the server random number to the eUICC card (S4). Upon receiving the transmitted server random number, the eUICC card generates its own random number and encrypts both the card's random number and the server's random number using the same preset symmetric key as the server, generating ciphertext (S5), i.e., the first ciphertext. The eUICC card returns its random number and ciphertext to the terminal device's operating system (S6) so that the operating system can transmit the card's random number and ciphertext to the TSM server (S7). The TSM server encrypts both the card's random number and the server's random number using the symmetric key and compares the ciphertext for correctness. If correct, it distributes the preset key to generate a process key and uses the symmetric key to encrypt both the server's random number and the card's random number, generating ciphertext (S8), i.e., the second ciphertext. The TSM server returns the ciphertext to the terminal device's operating system (S9); the operating system then transmits the ciphertext to the eUICC card (S10). The eUICC card uses a symmetric key to encrypt the server's random number and the card's random number, comparing the ciphertext for correctness. If correct, it performs a process key generation using the preset key (S11), at which point authentication is complete. The eUICC card returns the successful two-way authentication result to the terminal device's operating system (S12), thus establishing a secure communication link.

[0065] According to the above embodiments, through the two-way encryption authentication mechanism of the terminal device's operating system, TSM platform, and eUICC card, the server's random number and the card's random number are encrypted and compared based on a preset symmetric key to ensure the authenticity and legitimacy of the identities of all parties involved in the communication, effectively preventing unauthorized access. The random number and process key are encrypted throughout the process, which can prevent sensitive information from being stolen or tampered with during transmission, ensuring the confidentiality and integrity of the data. At the same time, by generating a dedicated process key through step-by-step verification, a reliable communication foundation is built for subsequent core operations such as obtaining the card application list and configuring routing, ensuring the stable and secure interaction between the eSIM terminal and the platform.

[0066] S302. Obtain the card application list through a secure communication link.

[0067] After establishing the secure link between TSM and eUICC, the terminal device can obtain the data corresponding to the card application list through this secure link. The card application list is a pre-configured list of card applications in the configuration file.

[0068] In some embodiments, to obtain the card application list, a request to obtain the card application list is sent to the trusted service management platform via a secure communication link. The trusted service management platform then receives an encrypted instruction based on the request, and the card application list is obtained based on the encrypted instruction, thus ensuring the security of data transmission.

[0069] In some embodiments, the encrypted instruction is an instruction assembled by the trusted service management platform to obtain the card application list, and the generated instruction is encrypted using a process key.

[0070] In some embodiments, when obtaining the card application list based on encrypted instructions, the encrypted instructions can be transparently transmitted to the embedded general-purpose integrated circuit (GPIB) card, enabling the GPIB card to decrypt the encrypted instructions and obtain a first list in response to the decrypted instructions. The first list is then encrypted again to generate an encrypted list. The encrypted list is then sent to the trusted service management platform, which decrypts it to generate a second list. The second list is received from the trusted service management platform to obtain the card application list.

[0071] For example, such as Figure 4 As shown, after completing two-way authentication, the terminal device's operating system sends a request to the TSM platform to obtain the card application list for that profile (S13). The TSM platform assembles the instruction to obtain the application list and encrypts it using the process key (S14). The TSM platform sends the encrypted instruction to the terminal device's operating system (S15), causing the terminal device's operating system to pass the encrypted instruction to the eUICC card (S16). The eUICC card decrypts and executes the encrypted instruction, obtains the card application list (i.e., the first list) in the specified profile, and encrypts it using the process key (S17), i.e., the encrypted list. The eUICC card returns the encrypted card application list data to the terminal device's operating system (S18). The terminal device's operating system passes the encrypted card application list data to the TSM platform (S19), causing the TSM platform to decrypt the card application list (S20). Then, the TSM platform returns the card application list to the terminal device's operating system (S21) to complete the acquisition of the card application list.

[0072] According to the above embodiments, through the established secure communication link, the instructions and data for obtaining the card application list are encrypted and transmitted using the process key, ensuring the confidentiality and integrity of the card application information preset in the profile during the interaction between the terminal device's operating system, TSM platform and eUICC card, and preventing the data from being illegally stolen or tampered with.

[0073] S303. Write the routing data of the card application list into the routing table of near-field communication, or at least one of the chip operating system of the embedded general-purpose integrated circuit card, to configure the routing of near-field communication.

[0074] After obtaining the card application list, the routing data corresponding to the card application list is written to the NFC routing table, or the routing data of the card application list can be written to the eUICC's COS. The routing data corresponding to the card application list may include the application's AID, profile identifier, security carrier, etc.

[0075] Therefore, in some embodiments, when writing the routing data of the card application list into the NFC routing table, the application identifier, profile identifier, and security carrier of the card application list can be parsed. Then, the application identifier, profile identifier, and security carrier are written into the NFC routing table. That is, the terminal device's operating system writes the AID, profile identifier, and security carrier into the NFC routing table one by one.

[0076] In some embodiments, when writing the routing data of the card application list into the chip operating system of the embedded general-purpose integrated circuit card, the application identifier, profile identifier, and security carrier of the card application list are parsed. Then, the application identifier, profile identifier, and security carrier are written into the chip operating system of the embedded general-purpose integrated circuit card. That is, the terminal device's operating system writes the AID, profile identifier, and security carrier into the eUICC's COS line by line.

[0077] Based on the above embodiments, for the NFC settings of pre-installed applications in the profile, a secure communication link is established through two-way encrypted authentication between the terminal device's operating system, TSM platform, and eUICC card. This ensures the authenticity of identity verification and the confidentiality of data transmission, preventing unauthorized access and information leakage. The application list instructions and data are encrypted throughout the process using a process key, ensuring the integrity of pre-installed information interaction in the profile and preventing data tampering. Finally, data such as AID, profile identifier, and security carrier are written into the NFC routing table or eUICC's COS, enabling precise binding between pre-installed applications and corresponding profiles. This provides an accurate mapping relationship for NFC routing, ensuring that data can be efficiently routed along a preset path when swiping the card, thus improving the security, accuracy, and reliability of near-field communication in the eSIM terminal.

[0078] For NFC settings of card applications downloaded via OTA (Over-The-Air) download, in some embodiments, the application information of the card application is obtained in response to the card application's installation event. This application information includes the application identifier of the card application and the file identifier of the corresponding configuration file for the card application. The application information is then written into at least one of the near-field communication routing table and the chip operating system of the embedded general-purpose integrated circuit card.

[0079] In some embodiments, the terminal device can write the application information of the obtained card application into the NFC routing table or the COS of the eUICC through the API provided by the operating system. That is, for card applications downloaded via over-the-air (OTA), the terminal device can write the application information of the card application, such as AID, corresponding profile identifier, and security carrier, into the NFC routing table or the COS of the eUICC through the terminal device's API after the card application is installed, to ensure the accurate association between the OTA-downloaded card application and the profile, and to provide an accurate basis for NFC routing.

[0080] Based on the above embodiments, remote wireless download of card applications is realized. After installation, routing data configuration is automatically completed, ensuring that applications downloaded via OTA are accurately associated with the corresponding profile, improving the flexibility, accuracy and convenience of NFC communication in eSIM terminals, and complementing the pre-built application routing mechanism.

[0081] When the NFC function is triggered, the near-field communication routing method provided in the above embodiments is as follows: Figure 5 As shown, in some embodiments, the method further includes:

[0082] S501, in response to near-field communication interaction commands, detects the routing records of the terminal device.

[0083] The interaction command includes a target application identifier, which is an AID selection command generated when NFC is triggered (e.g., by swiping a card). This command includes the AID of the card application to be used. For ease of distinction, this implementation represents the AID of the card application to be used as either a target application identifier or a target AID. The terminal device can respond to the interaction command by detecting routing records in the device.

[0084] S502, In response to the routing record including the target data, the interaction command is routed to the corresponding first security carrier according to the routing record, so that the terminal device responds to the interaction command based on the first security carrier.

[0085] The target data includes at least one of the following: the mapping between the target application identifier and the security carrier recorded in the routing table; and the mapping between the target application identifier and the configuration file recorded in the chip operating system. In other words, if the target AID exists in the terminal device's NFC routing table or in the eUICC's COS, the data for this NFC interaction will be routed according to the recorded data.

[0086] For example, when using NFC card swiping with application A, the NFC reader sends a selection command containing the AID of application A to the terminal device as the interaction command for this NFC transaction. In response to this interaction command, the terminal device detects a mapping between the target AID and the security carrier recorded in its routing table. It then sets the route according to the security carrier and corresponding profile recorded in the routing table to perform NFC data exchange through the configured route.

[0087] For example, when using NFC card swiping with application A, the NFC reader sends a selection command containing the AID of application A to the terminal device as the interaction command for this NFC transaction. In response to this interaction command, the terminal device detects that the eUICC's COS records the correspondence between the target AID and the profile, and then forwards the data to the corresponding profile through the eUICC's COS to perform the NFC data interaction.

[0088] S503. In response to the fact that the routing record does not include the target data, the interaction command is routed to the corresponding second security carrier according to the default route, so that the terminal device responds to the interaction command based on the second security carrier. Here, the second security carrier is the security carrier corresponding to the default route.

[0089] In other words, if the routing record does not contain the aforementioned target AID, meaning there is no record of the target AID in the terminal device's NFC routing table and also no record of the target AID in the eUICC's COS, then NFC data interaction will be performed according to the default NFC swipe settings, such as using the default route described in the above embodiment.

[0090] To avoid conflicts, in some embodiments, when a routing record for the target application identifier needs to be updated again, in response to a routing record update event, the original routing record is overwritten, meaning the last setting takes effect. Alternatively, in some embodiments, when a routing record for the target application identifier needs to be updated again, in response to a routing record update event, the record is directly updated to the first recorded routing record, meaning only the first setting is effective.

[0091] In some embodiments, the terminal device also responds to the deactivation command of the configuration file by deleting the routing record corresponding to the configuration file associated with the deactivation command, so as to ensure the accuracy of data usage.

[0092] In some embodiments, the deactivation command can be a command entered by the user based on the configuration file settings page, such as the user unchecking the selection of a certain configuration file on the eSIM profile settings page to deactivate it.

[0093] For example, such as Figure 6As shown in the eSIM profile settings page, when a user selects a deactivation profile, the terminal device synchronously modifies the NFC routing record. If the NFC routing record is in the eUICC's COS, the eUICC card must simultaneously delete the relevant routing record for that profile from the COS when deactivating the profile. If the NFC routing record is in the NFC routing table, the terminal device's operating system must delete the relevant routing record for that profile from the routing table via the relevant API when deactivating the profile. This ensures data integrity by synchronously deleting the NFC routing record after deactivating the profile.

[0094] According to the above deactivation embodiment, if you want to route to that profile again when NFC card swiping after reactivating the profile, you need to follow the method provided in the above embodiment, such as... Figure 2 Reselect in the NFC settings page shown.

[0095] Based on the above embodiments, by synchronously deleting the corresponding NFC routing record when the profile is deactivated, the routing information is ensured to match the profile status in real time, thus avoiding invalid routes. After reactivation, the route needs to be manually reset, which not only ensures the accuracy of the route, but also improves the rigor of NFC routing management and the stability of the system through the status linkage mechanism.

[0096] Based on the near-field communication routing method provided in the above embodiments, some embodiments of this application provide a near-field communication routing device, such as... Figure 7 As shown, it includes an embedded general-purpose integrated circuit card 71 and a controller 72. Wherein:

[0097] The embedded general-purpose integrated circuit card 71 is configured to store configuration files.

[0098] The controller 72 is configured to establish a secure communication link, which is generated based on a trusted service management platform and the embedded general-purpose integrated circuit card; obtain a card application list through the secure communication link; and write the routing data of the card application list into at least one of the near-field communication routing table and the chip operating system of the embedded general-purpose integrated circuit card 71 to configure the routing of the near-field communication.

[0099] In some embodiments, the near-field communication routing device may include Figure 1 The terminal device shown has more or fewer components.

[0100] Based on the above, Figure 3 Accordingly, this embodiment also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method. Figure 3 The method shown.

[0101] Based on the above, Figure 3 Accordingly, this embodiment also provides a computer program product on which a computer program is stored, which, when executed by a processor, implements the above-described method. Figure 3 The method shown.

[0102] Based on this understanding, the technical solution of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as CD-ROM, USB flash drive, mobile hard drive, etc.) and includes several instructions to cause a computer device (such as personal computer, server, or network device, etc.) to execute the methods of various implementation scenarios of this application.

[0103] Based on the above, Figure 3 The method shown, and Figure 7 To achieve the above objectives, this application also provides an electronic device, such as a terminal device or an eSIM terminal, in accordance with the virtual device embodiment shown. This electronic device includes a storage medium and a processor; the storage medium stores a computer program; and the processor executes the computer program to implement the above-described virtual device. Figure 3 The method shown.

[0104] Optionally, the aforementioned physical devices may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Wi-Fi interfaces), etc.

[0105] Those skilled in the art will understand that the physical device structure provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or combine certain components, or have different component arrangements.

[0106] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the aforementioned physical device, supporting the execution of information processing programs and at least one of other software or programs. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software within the information processing physical device.

[0107] As can be seen from the above technical solutions, the near-field communication routing method, apparatus, storage medium and electronic device disclosed in this application, by applying the technical solutions of this application, writes the routing data of near-field communication into the near-field communication routing table or chip operating system, which can achieve accurate routing configuration, solve routing conflicts in multi-activation configuration file scenarios, thereby improving the accuracy, flexibility and system security of near-field communication routing, and improving the user experience.

[0108] The technical solution provided in this application embodiment can provide an NFC default setting mechanism for eSIM terminals, displaying activated configuration files through the terminal's NFC settings page, allowing users to select and record NFC routing records (such as routing to the chip operating system of the embedded general-purpose integrated circuit card or directly writing to the NFC routing table); it also provides an NFC routing configuration mechanism for pre-installed applications in the configuration file. After the configuration file is downloaded, the terminal device obtains the list of pre-installed card applications by establishing a secure communication link with the trusted service management platform, and writes the application identifier and configuration file identifier into the NFC routing table or the chip operating system of the embedded general-purpose integrated circuit card.

[0109] Furthermore, this application embodiment also provides an over-the-air download NFC routing configuration mechanism for card applications. After installing the card application, the application information is written into the NFC routing table or the chip operating system of the embedded general-purpose integrated circuit card via API. It also provides an NFC routing conflict resolution mechanism. When card applications with the same application identifier exist, the conflict is resolved according to the routing record by using the "last setting takes effect" or "first setting takes effect" rule. A routing record synchronization mechanism is also provided when the configuration file is deactivated. When the configuration file is deactivated, the corresponding routing record is deleted synchronously. After reactivation, the routing needs to be reset.

[0110] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platform, or it can be implemented by hardware.

[0111] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0112] The above description is merely a specific embodiment of this application, enabling those skilled in the art to understand or implement this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A near-field communication routing method, characterized in that, Applied to a terminal device, the method includes: A secure communication link is established, which is generated based on the trusted service management platform and the embedded general-purpose integrated circuit card of the terminal device. The card application list is obtained through the secure communication link; The routing data of the card application list is written into at least one of the near-field communication routing table and the chip operating system of the embedded general-purpose integrated circuit card to configure the routing of the near-field communication.

2. The near-field communication routing method according to claim 1, characterized in that, The establishment of a secure communication link includes: Send a configuration file identifier to the trusted service management platform so that the trusted service management platform returns a first random number based on the configuration file identifier; Receive the first random number; The first random number is transmitted to the embedded general-purpose integrated circuit card so that the embedded general-purpose integrated circuit card generates a second random number based on the first random number. Encryption authentication is performed on the first random number and the second random number to establish the secure communication link based on the authentication result of the encryption authentication.

3. The near-field communication routing method according to claim 2, characterized in that, The encryption authentication of the first random number and the second random number includes: The first random number and the second random number are encrypted using a preset symmetric key to generate the first ciphertext; The first ciphertext and the second random number are sent to the trusted service management platform, so that the trusted service management platform generates a first process key based on the symmetric key and generates a second ciphertext based on the symmetric key; Receive the second ciphertext fed back by the trusted service management platform; The second ciphertext is transparently transmitted to the embedded general-purpose integrated circuit card so that the embedded general-purpose integrated circuit card authenticates the second ciphertext; In response to the successful authentication of the second ciphertext, a second process key is generated based on the symmetric key.

4. The near-field communication routing method according to claim 1, characterized in that, The process of obtaining the card application list through the secure communication link includes: A request to obtain the card application list is sent to the trusted service management platform through the secure communication link; Receive the encrypted instruction from the trusted service management platform based on the acquisition request; The card application list is obtained based on the encrypted instructions.

5. The near-field communication routing method according to claim 4, characterized in that, The step of obtaining the card application list based on the encryption instruction includes: The encryption command is transparently transmitted to the embedded general-purpose integrated circuit card, so that the embedded general-purpose integrated circuit card decrypts the encryption command and obtains a first list in response to the decrypted encryption command; Encrypt the first list to generate an encrypted list; The encrypted list is sent to the trusted service management platform so that the trusted service management platform can decrypt the encrypted list to generate a second list; Receive a second list from the trusted service management platform to obtain the card application list.

6. The near-field communication routing method according to claim 1, characterized in that, The step of writing the routing data of the card application list into the near-field communication routing table includes: Parse the application identifier, configuration file identifier, and security carrier of the card application list; The application identifier, configuration file identifier, and security carrier are written into the routing table of the near-field communication.

7. The near-field communication routing method according to claim 1, characterized in that, The step of writing the routing data of the card application list into the chip operating system of the embedded general-purpose integrated circuit card includes: Parse the application identifier, configuration file identifier, and security carrier of the card application list; The application identifier, configuration file identifier, and security carrier are written into the chip operating system of the embedded general-purpose integrated circuit card.

8. The near-field communication routing method according to claim 1, characterized in that, Also includes: In response to a user's selection instruction based on a list of configuration files, the target configuration file associated with the selection instruction is parsed, and the list of configuration files is used to record configuration files that are in an active state. The embedded general-purpose integrated circuit card is set as the security carrier in the routing table. The configuration file identifier of the target configuration file is written into the chip operating system of the embedded general-purpose integrated circuit card to generate the default route for the near-field communication.

9. The near-field communication routing method according to claim 1, characterized in that, Also includes: In response to a user's selection instruction based on a list of configuration files, the target configuration file associated with the selection instruction is parsed, the list of configuration files including those that are already in an active state; The embedded general-purpose integrated circuit card is set as the security carrier in the routing table. The configuration file identifier of the target configuration file is written into the routing table to generate the default route for the near-field communication.

10. The near-field communication routing method according to claim 1, characterized in that, Also includes: In response to the card application installation event, the application information of the card application is obtained, including the application identifier of the card application and the file identifier of the configuration file corresponding to the card application; The application information is written into at least one of the routing table of the near-field communication and the chip operating system of the embedded general-purpose integrated circuit card.

11. The near-field communication routing method according to any one of claims 1-10, characterized in that, Also includes: In response to an interaction command from near-field communication, the routing record of the terminal device is detected, wherein the interaction command includes a target application identifier; In response to the routing record including target data, the interaction instruction is routed to the corresponding first security carrier according to the routing record, so that the terminal device responds to the interaction instruction based on the first security carrier; the target data includes at least one of the correspondence between the target application identifier and the security carrier recorded in the routing table, and the correspondence between the target application identifier and the configuration file recorded in the chip operating system; In response to the fact that the routing record does not include the target data, the interaction command is routed to the corresponding second security carrier according to the default route, so that the terminal device responds to the interaction command based on the second security carrier; The second security carrier is the security carrier corresponding to the default route.

12. A near-field communication routing device, characterized in that, include: Embedded general-purpose integrated circuit cards are configured to store configuration files; The controller is configured as follows: A secure communication link is established, which is generated based on the trusted service management platform and the embedded general-purpose integrated circuit card. The card application list is obtained through the secure communication link; The routing data of the card application list is written into at least one of the near-field communication routing table and the chip operating system of the embedded general-purpose integrated circuit card to configure the routing of the near-field communication.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 11.

14. An electronic device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 11.

15. A computer program product having a computer program stored thereon, characterized in that, When the computer program product is executed by a processor, it implements the method of any one of claims 1 to 11.