Embedded universal integrated circuit card data downloading method, device, equipment and medium

By establishing a contactless channel between the operator's system and the user terminal, obtaining device identity information and generating a profile, the problem of process interruption and resource consumption caused by scanning codes in eSIM network access services is solved, and efficient and secure profile download is achieved.

CN121728448APending Publication Date: 2026-03-24CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-09
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing technologies require users to scan a code during the eSIM network access process, which leads to business process interruptions and increased resource consumption, while failing to effectively protect user privacy.

Method used

By establishing a contactless channel between the operator's system and the user terminal, the device's identity information is obtained and a carrier code data configuration file (Profile) is generated. The Profile is then written into the eUICC card using the contactless channel, avoiding the need for the user to scan a code.

Benefits of technology

It enables automated profile downloads without requiring users to scan codes, improving efficiency, reducing business resource consumption, and protecting user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121728448A_ABST
    Figure CN121728448A_ABST
Patent Text Reader

Abstract

The invention relates to the field of communication, and provides an embedded universal integrated circuit card data downloading method and device, equipment and a medium. The method comprises the following steps: acquiring equipment identity information of a user terminal from an eUICC card of the user terminal through a non-contact channel under the condition that a non-contact channel connection is established between an operator system and the user terminal; the equipment identity information comprises IMEI and / or EID; determining operator code number data corresponding to the eUICC card according to the equipment identity information and sending the operator code number data to the SM-DP + platform; the SM-DP + platform is indicated to generate an operator code number data configuration file Profile; under the condition that the Profile is generated in the SM-DP + platform, downloading the Profile from the SM-DP + platform through an operator system; and the Profile is written into the eUICC card through the non-contact channel. According to the technical scheme, the service resource consumption is relatively low.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and particularly relates to an embedded universal integrated circuit card data downloading method, device, equipment and medium. BACKGROUND

[0002] An eSIM (Embedded-Subscriber Identity Module) is an embedded SIM card technology, which directly integrates the functions of a traditional SIM card into a chip of a device, does not require a physical slot, and can solve the problems of inconvenience in changing a number of a traditional SIM card, occupation of space, and damage, and is a next-generation evolution direction of a SIM card technology.

[0003] According to a GSMA (Global System for Mobile Communications Association) specification, network access, card replacement, card changing, and number portability and other business processes involved in online / offline services of an operator for an eSIM. In related technologies, for a business process of offline network access, generally includes: 1, a clerk first takes a photo of a device terminal for retention, inputs IMEI (International Mobile Equipment Identity) information and EID (eUICC Identifier) information of a user terminal device, and verifies legality of the terminal; 2, verifies user network access conditions, and guides the user to select a number and a package; 3, a province side prepares code number data, and an SM-DP+ platform generates a configuration file Profile representing operator code number data or a SIM card data image; 4, the clerk holds an eSIM device, scans a two-dimensional code through a native application to trigger profile downloading, and completes installation on site; 5, after successful downloading and installation, a province system activates new card data on a network side.

[0004] However, the above technology needs a user to scan a code in a network access business process, which interrupts the network access business process, and causes large consumption of entire business resources. SUMMARY

[0005] Embodiments of the present application provide an embedded universal integrated circuit card data downloading method, device, equipment and medium, to solve the technical problem that a user needs to scan a code in a network access business process, which interrupts the network access business process, and causes large consumption of entire business resources.

[0006] In a first aspect, an embodiment of the present application provides an embedded universal integrated circuit card data downloading method, comprising: In a case that the operator system and the user terminal establish a non-contact channel connection, device identity information corresponding to the user terminal is acquired from an embedded universal integrated circuit card (eUICC) card of the user terminal through the non-contact channel; the device identity information includes an international mobile equipment identity (IMEI) of the user terminal and / or an identifier (EID) of the eUICC card; The eUICC card corresponding operator number data is determined according to the device identity information, and the operator number data is sent to a subscription management data preparation (SM-DP+) platform; the operator number data is used to instruct the SM-DP+ platform to generate an operator number data profile corresponding to the operator number data through the operator number data; In a case that the SM-DP+ platform generates the Profile, the Profile is downloaded from the SM-DP+ platform through the operator system; The Profile is written into the eUICC card through the non-contact channel.

[0007] In an embodiment, the Profile is downloaded from the SM-DP+ platform through the operator system, including: The Profile is downloaded from the SM-DP+ platform through a cloud local profile assistant (LPA) module in the operator system; The Profile is written into the eUICC card through the non-contact channel, including: The Profile is written from the cloud LPA module into the eUICC card through the non-contact channel.

[0008] In an embodiment, the Profile is written from the cloud LPA module into the eUICC card through the non-contact channel, including: The Profile in the cloud LPA module is encrypted to obtain an encrypted Profile; The encrypted Profile is split into a plurality of application protocol data unit (APDU) instructions, and each APDU instruction is written from the cloud LPA module into the eUICC card through the non-contact channel.

[0009] In an embodiment, before the Profile is written from the cloud LPA module into the eUICC card through the non-contact channel, the method further includes: An authentication response message of the SM-DP+ platform is received; the authentication response message is used to represent success or failure of two-way authentication between the SM-DP+ platform and the eUICC card; In a case that the authentication response message represents that the bidirectional authentication between the SM-DP+ platform and the eUICC card is successful, the step of writing the Profile from the cloud LPA module into the eUICC card through the non-contact channel is performed.

[0010] In one embodiment, before the step of determining the operator code number data corresponding to the eUICC card according to the device identity information, the method further comprises: sending the device identity information to an authorization management system ECS, wherein the device identity information is used to instruct the ECS to verify whether the user terminal is a valid device based on the device identity information; receiving a verification message sent by the ECS, wherein the verification message is used to represent whether the user terminal is a valid device; in a case that the user terminal is a valid device, performing the step of determining the operator code number data corresponding to the eUICC card according to the device identity information.

[0011] In one embodiment, before the step of determining the operator code number data corresponding to the eUICC card according to the device identity information, the method further comprises: verifying whether the user terminal meets a network access condition; in a case that the user terminal meets the network access condition, obtaining a target number selected by a user for the eUICC card of the user terminal; The step of determining the operator code number data corresponding to the eUICC card according to the device identity information comprises: determining the operator code number data corresponding to the eUICC card according to the device identity information and the target number.

[0012] In one embodiment, the non-contact channel comprises a near field communication (NFC) channel.

[0013] In a second aspect, an embedded universal integrated circuit card data downloading method is provided, comprising: in a case that a non-contact channel connection is established between an operator system and a user terminal, receiving an operator code number data configuration file Profile written by the operator system into an embedded universal integrated circuit card (eUICC) of the user terminal through the non-contact channel; The aforementioned Profile is generated in the subscription management data preparation SM-DP+ platform. The operator system downloads the Profile from the SM-DP+ platform. The SM-DP+ platform generates the Profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the device identity information of the user terminal. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID identifier of the eUICC card, which is obtained by the operator system through the contactless channel eUICC card.

[0014] In one embodiment, the above method further includes: After the Profile is written to the eUICC card, an update event is generated via the HCI protocol; the update event is used to indicate that the Profile information in the eUICC card has changed. The update event is sent to the LPA module or native application module in the user terminal via the HCI protocol; the update event is used to instruct the LPA module or native application module in the user terminal to obtain the Profile from the eUICC card and update its own Profile information.

[0015] Thirdly, embodiments of this application provide an embedded general-purpose integrated circuit card data download device, comprising: The device information acquisition module is used to obtain the device identity information corresponding to the user terminal from the embedded universal integrated circuit card (eUICC card) of the user terminal through a contactless channel connection when the operator system and the user terminal establish a contactless channel connection; the device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the identifier (EID) of the eUICC card. The code number data sending module is used to determine the operator code number data corresponding to the eUICC card based on the device identity information, and send the operator code number data to the subscription management data preparation SM-DP+ platform; the above operator code number data is used to instruct the SM-DP+ platform to generate the operator code number data configuration file corresponding to the operator code number data. The configuration file download module is used to download the profile from the SM-DP+ platform through the operator's system when a profile is generated in the SM-DP+ platform. The configuration file writing module is used to write the Profile to the eUICC card via a contactless channel.

[0016] Fourthly, embodiments of this application provide an embedded general-purpose integrated circuit card data download device, comprising: The receiving module is used to receive the operator code number data configuration file Profile written by the operator system to the embedded general-purpose integrated circuit card eUICC card of the user terminal through the contactless channel when the operator system and the user terminal establish a contactless channel connection. The aforementioned Profile is generated in the subscription management data preparation SM-DP+ platform. The operator system downloads the Profile from the SM-DP+ platform. The SM-DP+ platform generates the Profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the device identity information of the user terminal. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID identifier of the eUICC card, which is obtained by the operator system through the contactless channel eUICC card.

[0017] Fifthly, embodiments of this application provide a network device, including a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and performing the following operations: When a contactless channel connection is established between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the embedded universal integrated circuit card (eUICC card) of the user terminal through the contactless channel; the aforementioned device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the identifier (EID) of the eUICC card. Based on the device identity information, the operator code data corresponding to the eUICC card is determined, and the operator code data is sent to the subscription management data preparation SM-DP+ platform; the above operator code data is used to instruct the SM-DP+ platform to generate the operator code data configuration file corresponding to the operator code data. When a profile is generated in the SM-DP+ platform, the profile is downloaded from the SM-DP+ platform through the operator's system; The profile is written to the eUICC card via a contactless channel.

[0018] Sixthly, embodiments of this application provide a terminal, including a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and performing the following operations: When a contactless channel connection is established between the operator system and the user terminal, the operator system receives the operator code number data configuration file (Profile) written to the user terminal's embedded general-purpose integrated circuit card (eUICC) via the contactless channel. The aforementioned Profile is generated in the subscription management data preparation SM-DP+ platform. The operator system downloads the Profile from the SM-DP+ platform. The SM-DP+ platform generates the Profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the device identity information of the user terminal. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID identifier of the eUICC card, which is obtained by the operator system through the contactless channel eUICC card.

[0019] In a seventh aspect, embodiments of this application provide an electronic device, including a processor and a memory storing a computer program, wherein the processor executes the program to implement the steps of the embedded general-purpose integrated circuit card data download method described in the first aspect and / or the second aspect.

[0020] Eighthly, embodiments of this application provide a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the embedded general-purpose integrated circuit card data download method described in the first and / or second aspects.

[0021] Ninthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the steps of the embedded general-purpose integrated circuit card data download method described in the first and / or second aspects.

[0022] The embedded general-purpose integrated circuit card data download method, apparatus, device, and medium provided in this application embodiment obtain the device identity information corresponding to the user terminal from the eUICC card of the user terminal through a contactless channel connection established between the operator system and the user terminal. Based on the device identity information, the operator code number data corresponding to the eUICC card is determined, and the operator code number data is sent to the SM-DP+ platform to generate an operator code number data configuration file Profile corresponding to the operator code number data. If the Profile is generated in the SM-DP+ platform, it is downloaded from the SM-DP+ platform through the operator system. The Profile is written to the eUICC card through a contactless channel. The device identity information includes the IMEI of the user terminal and the EID of the eUICC card. In this method, the operator's system can read the eUICC card information through a contactless channel to generate and download the configuration file Profile on the SM-DP+ platform. Simultaneously, the Profile downloaded from the SM-DP+ platform can be written to the eUICC card through the contactless channel. This eliminates the need for users to scan a QR code to download the Profile, automatically and efficiently completing the reading of eUICC card information, the download of the Profile, and the writing of the Profile to the eUICC card. This improves the download efficiency of the Profile and reduces the consumption of business resources. It also facilitates business processing at service centers, avoiding the need to hand user terminals to sales staff and protecting user privacy. Furthermore, the operator's system can directly download the Profile from the SM-DP+ platform and write it to the eUICC card on the user's terminal, eliminating the need to display the Profile QR code to the user. This avoids the problem of the Profile QR code being transmitted externally, ensuring the security of the entire eUICC card registration and activation process. Attached Figure Description

[0023] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0024] Figure 1 This is a schematic diagram of the architecture and process for downloading embedded SIM chip code number data in the RSP technical specification; Figure 2 This is a sequence diagram of data preparation for downloading code number data; Figure 3 This is a sequence diagram of the download and installation of the code number data profile; Figure 4 This is a schematic diagram of the offline network access process in related technologies; Figure 5 This is a schematic diagram of the architecture of the embedded general-purpose integrated circuit card data download system provided in the embodiments of this application; Figure 6 This is one of the flowcharts illustrating the embedded general-purpose integrated circuit card data download method provided in the embodiments of this application; Figure 7 This is a second schematic flowchart of the embedded general-purpose integrated circuit card data download method provided in the embodiments of this application; Figure 8 This is a timing diagram showing the interaction between the user terminal, the operator system, and the SM-DP+ system provided in the embodiments of this application; Figure 9 This is a schematic diagram of the eSIM certificate chain provided in the embodiments of this application; Figure 10 This is one of the structural schematic diagrams of the embedded general-purpose integrated circuit card data download device provided in the embodiments of this application; Figure 11 This is a second schematic diagram of the embedded general-purpose integrated circuit card data download device provided in the embodiments of this application; Figure 12 This is a schematic diagram of the network device provided in the embodiments of this application; Figure 13 This is a schematic diagram of the terminal structure provided in the embodiments of this application; Figure 14 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] To facilitate the explanation of the technical solutions of the embodiments of this application, the relevant technical background of this application will be explained first.

[0027] The GSMA SGP.22 "RSP Technical Specification" defines the architecture and process for downloading code data from existing embedded SIM chips. (See [link to relevant documentation]). Figure 1 As shown, the main network elements involved in the code number data download process under this RSP technical specification include: Device: User equipment used in conjunction with an eUICC to connect to a mobile network. Examples include a tablet, wearable device, smartphone, or handset.

[0028] eUICC (Embedded Universal Integrated Circuit Card): A UICC that enables remote and / or local management of profiles in a secure manner. NOTE: The term originates from "embedded UICC".

[0029] EUM: eUICC Manufacturer.

[0030] CI (Certificate Issuer): An entity that is authorized to issue digital certificates.

[0031] Local Profile Assistant (LPA): A functional element in the Device or eUICC that provides Local Profile Download (LPD), Local Discovery Services (LDS), and Local User Interface (LUI) features. When the LPA is located in the Device, it is called LPAd, LPDd, LUId, or LDSd. When the LPA is located in the eUICC, it is called LPAe, LPDe, LUIe, or LDSe. The specific name (LPA, LPD, LDS, or LUI) depends on the element's location within the Device or eUICC. When using LPA, LPD, LDS, or LUI, they are applicable to elements independent of their location in the device or eUICC.

[0032] Local Profile Management refers to operations that are initiated locally on the End User (ESeu) interface.

[0033] Operator: A mobile network operator or mobile virtual network operator; a company providing wireless cellular network services.

[0034] Profile (Carrier Code Number Data Configuration File): A combination of data and applications to be provisioned on an eUICC for the purpose of providing services.

[0035] Remote SIM Provisioning: This involves downloading, installing, enabling, disabling, and deleting a profile on an eUICC.

[0036] Subscription Manager Data Preparation+ (SM-DP+ platform): This role prepares Profile Packages, secures them with a ProfileProtection Key, stores Profile Protection Keys securely, and stores the Protected Profile Packages in a Profile Package repository. It then allocates these Protected Profile Packages to specified EIDs. SM-DP+ binds the Protected Profile Packages to the respective EID and securely downloads these bound Profile Packages to the LPA of the respective eUICC.

[0037] Subscription Manager Discovery Server (SM-DS): This server is responsible for providing addresses of one or more SM-DP+(s) to an LDS.

[0038] The main process includes: I. Data preparation.

[0039] See Figure 2The sequence diagram shown is for the data preparation of the code number data download. The preparation process for downloading this code number data is also the download initiation process, which consists of the following sub-processes: A. Contract signing process; B. Download preparation process; C. Contract finalization process; D. Subscription activation process (optional)

[0040] II. Profile Download and Installation.

[0041] See Figure 3 The sequence diagram shown illustrates the download and installation of the code number data profile. The procedures in this process may include: 1. (Optionally, ie for option (a)) The LPAd parses the ActivationCode and finds the SM-DP+ address, Activation Code Token, and optional SM-DP+OID. If the format of the Activation Code is invalid, the procedure SHALL bestopped with an error message provided by the LPAd to the End User. (Optionally, for option (a)) LPAd parses the activation code and finds the SM-DP+ address, activation code token, and optional SM-DP+OID. If the activation code is invalid, the program should stop and LPAd should provide an error message to the end user.

[0042] 2、The common mutual authentication procedure defined in section 3.1.2SHALL be executed. When this procedure is used for Profile download andinstallation, SM-XX is SM-DP+. CERT.XXauth.ECDSA, PK.XXauth.ECDSA andSK.XXauth.ECDSA are CERT.DPauth.ECDSA, PK.DPauth.ECDSA and SK.DPauth.ECDSArespectively. ESXX is ES9+. During the common mutual authentication procedure at step (10), theLPAd SHALL verify that the SM-DP+ OID contained in the CERT.DPauth.ECDSAreturned by the SM-DP+ is identical to the SM-DP+ OID if the LPAd hasacquired it from the Activation Code at step (1). If the comparison fails,the LPAd SHALL inform the End User and the procedure SHALL be stopped. During the common mutual authentication procedure at step (10), theLPAd SHALL build the ctxParams1 data object to provide the MatchingID, DeviceInfo to the eUICC for signature. The value of the MatchingID SHALL be set asfollows: If an Activation Code is used, the MatchingID value SHALL be set toActivation Code Token. If an SM-DS is used, the MatchingID value SHALL be set to EventID. If a Default SM-DP+ is used, the MatchingID SHALL be missing. The generic mutual authentication procedure defined in Section 3.1.2 should be executed. When this procedure is used for configuration file download and installation, SM-XX is SM-DP+. CERT.XX authentication. ECDSA, PK.XX authentication. ECDSA and SK.XXauth. ECDSA is the authentication certificate. ECDSA, PK.DPauth. ECDSA and SK.DPauth. ECDSA respectively. ESXX is ES9+.

[0043] During the mutual authentication process in step (10), LPAd should verify the SM-DP+OID contained in CERT.DPauth. If LPAd obtained the ECDSA returned by SM-DP+ from the activation code in step (1), then the ECDSA is the same as the SM-DP+OID. If the comparison fails, LPAd should notify the end user and stop the procedure.

[0044] During the mutual authentication process in step (10), LPAd should construct a ctxParams1 data object to provide the matching ID and device information to eUICC for signing. The value of MatchingID should be set as follows: If an activation code is used, the matching ID value should be set to the activation code token.

[0045] If using SM-DS, the MatchingID value should be set to EventID.

[0046] If the default SM-DP+ is used, a matching ID should be missing.

[0047] 3. After having successfully authenticated the eUICC at the end of the step (2) above, the SM-DP+ SHALL: Verify that there is a related pending Profile download order forprovided the MatchingID. If this Profile download order is already linked to an EID, verifythat it matches the EID of the authenticated eUICC. Verify that the Profile corresponding to the pending Profile downloadorder is in 'Released' state, or, in case of a retry due to a previousinstallation failure, in 'Downloaded' state (section 3.1.6). If any of these verifications fail, the SM-DP+ SHALL return arelevant error status and the procedure SHALL be stopped. The SM-DP+ SHALL increment the count of download attempts for theidentified Profile. If the maximum number of attempts has been exceeded, theSM-DP+ SHALL terminate the corresponding Profile download order and notifythe Operator by calling the "ES2+.HandleDownloadProgressInfo" function withan operation status indicating 'Failed' with the relevant error status, andthe procedure SHALL be stopped. Otherwise, the SM-DP+ SHALL perform appropriate eligibility checks,based on the Device Info and / or eUICCInfo2. These checks SHALL include thecheck if the eUICC can install one more Profile. See Annex F for more information on Eligibility checks. After successfully authenticating eUICC at the end of step (2) above, SM-DP+ should: Verify that the provided MatchingID has a related pending configuration file download order.

[0048] If this configuration file download order is linked to EID, verify that it matches the EID of the authenticated eUICC.

[0049] Verify whether the configuration file corresponding to the download order of the pending configuration file is in the "Published" state, or, if retried due to a previous installation failure, in the "Downloaded" state (Section 3.1.6).

[0050] If any of these verifications fail, SM-DP+ should return the relevant error status and should stop the program.

[0051] SM-DP+ should increase the number of download attempts for the identified configuration file. If the maximum number of attempts is exceeded, SM-DP+ should terminate the download order of the corresponding configuration file and notify the operator by calling the "ES2+.HandleDownloadProgressInfo" function. This function should display a "failed" status and the relevant error status, and the program should stop.

[0052] Otherwise, SM-DP+ should perform appropriate qualification checks based on the device information and / or eUICInfo2. These checks should include whether the eUICC can install another profile. For more information on qualification checks, please refer to Annex F.

[0053] 4. (Optional step) Depending on the agreed behavior with the Operator (out of scope of this specification), the SM-DP+ SHALL notify the Operator with the outcome of the eligibility check using the function "ES2+.HandleDownloadProgressInfo". The SM-DP+ SHALL provide the EID, the ICCID, the identification of the point reached (in that case it SHALL be 'Eligibility check'), the timestamp when this point was reached, and the execution result of this step. NOTE:This notification step MAY be done asynchronously. (Optional Step) Based on the agreed-upon procedure with the operator (not within the scope of this specification), SM-DP+ shall use the function “ES2+.HandleDownloadProgressInfo” to notify the operator of the eligibility check results. SM-DP+ shall provide the EID, ICCID, identifier of the arrival point (in this case, “Eligibility Check”), timestamp of arrival at the point, and the execution result of this step.

[0054] Note: This notification step can be completed asynchronously.

[0055] 5. If the eligibility check fails, the SM-DP+ SHALL: Set the Profile corresponding with the pending Profile download order in 'Error' state (section 3.1.6). Return an error status to the LPAd and the procedure SHALL bestopped. Otherwise, the SM-DP+ SHALL: Determine whether the Profile is already bound to the EID from a previous unsuccessful download attempt. If so, the SMDP+ MAY include theotPK.eUICC.ECKA obtained in the previous session in the smdpSigned2 datastructure. Determine if a Confirmation Code is required for this pending order. Generate a smdpSigned2 data structure containing the TransactionID and the Confirmation Code Required Flag. Compute the smdpSignature2 over smdpSigned2 and euiccSignature1 using the SK.DPpb.ECDSA. If the eligibility check fails, SM-DP+ should: Set the configuration file corresponding to the order in which the pending configuration files were downloaded to an "error" status (Section 3.1.6).

[0056] If an error status is returned to LPAd, the program should stop.

[0057] Otherwise, SM-DP+ should: Determine if the configuration file has been bound to the EID from previous unsuccessful download attempts. If so, SMDP+ may include otPK.eUICC. ECKA is obtained in the previous session from the smdpSigned2 data structure.

[0058] Determine if this pending order requires a confirmation code.

[0059] Generate an smdpSigned2 data structure containing the TransactionID and the required confirmation code flag.

[0060] Calculate smdpSignature2 using SK.DPpb via smdpSigned2 and euiccSignature1. ECDSA.

[0061] 6、SM-DP+返回事务ID、配置文件元数据、smdpSigned2、smdpSignature2和CERT.DPpb.ECDSA给LPAd。 The SM-DP+ returns the TransactionID, ProfileMetadata, smdpSigned2, smdpSignature2 and CERT.DPpb.ECDSA to the LPAd.

[0062] 7、收到SM-DP+响应后,LPAd应检查配置文件元数据是否包含PPR。 a) 如果配置文件元数据包含PPR,目标eUICC是可移除的,并且LPAd不支持下载带有PPR的配置文件,无论可移除eUICC中的RAT如何,则LPAd应继续执行以下“配置文件下载和安装 - 下载拒绝”子过程,原因代码为“PPR不允许”。 b) 如果配置文件元数据包含PPR,并且LPAd尚未拥有规则授权表,则LPAd应通过调用“ES10b.GetRAT”函数从eUICC请求规则授权表。 c) If the ProfileMetadata contains PPR1 and the LPAd does not already have the list of installed Profiles, then the LPAd SHALL request the information from the eUICC by calling the "ES10b.GetProfilesInfo" function. Upon receiving the SM-DP+ response, LPAd should check whether ProfileMetadata contains PPR.

[0063] a) If ProfileMetadata contains a PPR, the target eUICC is removable, and LPAd does not support downloading a configuration file with a PPR regardless of the RAT in the removable eUICC, then LPAd should proceed with the following sub-procedure "Configuration File Download and Installation - Download Rejected" with the reason code "PPR Not Allowed".

[0064] b) If ProfileMetadata contains PPR, and LPAd does not yet have a rule grant table, then LPAd should request the rule grant table from eUICC by calling the "ES10b.GetRAT" function.

[0065] c) If ProfileMetadata contains PPR1 and LPAd does not yet have a list of configuration files installed, LPAd should request information from eUICC by calling the "ES10b.GetProfilesInfo" function. If ProfileMetadata contains PPR1 and the operation configuration file is installed, LPAd should execute the following subroutine "Configuration File Download and Installation - Download Rejected" with the reason code "PPR Not Allowed".

[0066] 8、If the ProfileMetadata contains PPR(s), the LPAd SHALL check if thePPR(s) is / are allowed based on the Rules Authorisation Table defined insection 2.9.2.3. If one or more PPR(s) are not allowed, the LPAd SHALLcontinue the Sub-procedure "Profile Download and installation – Downloadrejection" hereunder with reason code ‘PPR not allowed’. If any PPR issubject to additional End User consent according to the RAT, LPAd SHOULD askfor Strong Confirmation by showing relevant information concerning the PPR(s). This information SHOULD include the consequences of the Profile PolicyRule to the End User. This message SHALL be formulated in a descriptive andnon-discriminatory manner (e.g. for "Non-Delete" Profile Policy Rule: "Theprofile that you are about to install can be deleted only under the terms youhave agreed with your service provider. Enter your PIN to approveinstallation").If the Profile Metadata does not contain any Profile PolicyRule(s) subject to additional End User consent, the LPAd SHALL ask for SimpleConfirmation (eg, simple 'Yes' or 'No' or 'Not Now') on the Profiledownload. If the ProfileMetadata contains a Profile Policy Rejection (PPR), LPAd should check whether the PPR is allowed according to the rule authorization table defined in Section 2.9.2.3. If one or more PPRs are not allowed, LPAd should proceed with the following subroutine "Profile Download and Installation - Download Denied" with the reason code "PPR Not Allowed". If, according to the RAT, any PPR requires additional end-user consent, LPAd should request strong confirmation by displaying relevant information about the PPR. This information should include the impact of the profile policy rule on the end-user. This message should be presented in a descriptive and non-discriminatory manner (e.g., for a "Do Not Delete" profile policy rule: "The profile you are installing may only be deleted if you have agreed to the terms with the service provider. Enter your PIN to approve the installation"). If the profile metadata does not contain any profile policy rule agreed to by the end-user, LPAd should request simple confirmation upon profile download (e.g., a simple "Yes" or "No" or "Not Now").

[0067] It should be noted that the above Figures 1-3 The text in this document does not affect the technical essence of the embodiments of this application; it only describes the relevant download process of the Profile file in the technical specification.

[0068] Based on the aforementioned architecture and process for downloading embedded SIM chip number data, and according to GSMA specifications, operators handle online / offline eSIM services including network access, SIM card replacement, SIM card swapping, and number portability. The current offline network access process can be found in [link to relevant documentation]. Figure 4The diagram shown illustrates the offline network access process, which includes: 1. The salesperson takes a photo of the device and enters the user's IMEI and EID information to verify the device's legitimacy; 2. Verifying the user's network access eligibility and guiding the user to select a number and plan; 3. The provincial side prepares the number data, and the SM-DP+ platform generates a profile representing the operator's number data or a mirror image of the SIM card data; 4. The salesperson holds the eSIM device and scans a QR code using the native application to trigger the profile download and completes the installation on-site; 5. After successful download and installation, the provincial system activates the new card data on the network side. However, the above technology has the following problems: 1. Scanning a code is required during the user's registration process, which interrupts the entire registration process, causing delays and increasing resource consumption; 2. It is impossible to verify the presence of the phone on-site through technical means, but rather through taking a photo of the device. This cannot ensure that the eSIM device is held by the applicant, and may result in issues such as someone else voluntarily going to the business hall to open an account; 3. The salesperson scans the code to complete the installation, which may lead to the problem of the downloaded QR code being photographed and then transmitted externally. In addition, the salesperson needs to hold the user's terminal to photograph the QR code on the screen, and users who are concerned about their privacy are unwilling to hand over their phones to the salesperson for operation; 4. On-site confirmation from the salesperson is required to complete the Profile data download at the business hall to avoid the problem of someone else opening an account at the business hall.

[0069] Based on this, embodiments of this application provide a method, apparatus, device, and medium for downloading data from an embedded general-purpose integrated circuit card, which can solve the above-mentioned technical problems.

[0070] The embedded general-purpose integrated circuit card data download method of this application embodiment can be applied to an embedded general-purpose integrated circuit card data download system. A schematic diagram of the system architecture can be found in [reference needed]. Figure 5 As shown, this includes the ECS authorization management system, the operator system, the SM-DP+ platform, a contactless reader / writer, and an eSIM device. The operator system can be a BOSS or CRM management system, including a cloud-based local configuration file assistant (LPA) module; that is, the operator system includes an LPA module, referred to as the cloud LPA module. The contactless reader / writer can be a reader with read / write capabilities, which can be installed on the hardware device (such as a computer) installed on the operator system, or it can be installed independently and integrated with the hardware device installed on the operator system. The contactless reader / writer and the hardware device installed on the operator system together constitute the operator system's hardware system. The eSIM device can be a user terminal with eSIM functionality, such as a user's mobile phone, tablet, or wearable device; the eSIM device can include an operator's APP (application), OpenMobile API (Open Mobile Application Programming Interface), an LPA module or native application module, an NFC module, and an eUICC card.

[0071] In this embodiment, the operator system can read information from the eUICC card of the eSIM device through a contactless reader and transmit it to the SM-DP+ platform to generate an operator number data configuration file (Profile). The Profile is then downloaded from the SM-DP+ platform by the cloud LPA module in the operator system and written to the eUICC card of the eSIM device by the contactless reader. This Profile download process is seamless for the user. The user only needs to bring the eSIM device (i.e., the user terminal) close to the contactless reader to automatically generate, download, and write the Profile to the eUICC card. The entire Profile download and writing process is more convenient and efficient, and it can also protect user privacy and avoid the problem of unauthorized personnel opening accounts at the business hall.

[0072] Based on the above-described embedded general-purpose integrated circuit card data download system, the following embodiments will use the operator system and the user terminal as examples to illustrate the embedded general-purpose integrated circuit card data download method of this application.

[0073] First, we will explain the data download method for embedded general-purpose integrated circuit cards, which uses the operator's system as the execution entity.

[0074] Figure 6 One of the flowcharts illustrating the embedded general-purpose integrated circuit card data download method provided in this application embodiment is shown below. Figure 6 As shown, the method may include the following steps: Step 602: When a contactless channel connection is established between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the eUICC card of the user terminal through the contactless channel; the device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID of the eUICC card.

[0075] The user terminal can be an eSIM device with an embedded SIM card, specifically an Embedded Universal Integrated Circuit Card (eUICC). The eUICC of the user terminal is pre-configured with device identity information related to the user terminal. This device identity information may include the user terminal's IMEI information and the eUICC card's EID information, where IMEI stands for International Mobile Equipment Identity, and EID is the eUICC ID, the identifier of the eUICC card.

[0076] Additionally, operators can pre-install contactless readers in their service centers. These readers can read information from the user's eUICC card and transmit it to the operator's system. The user's terminal also needs a communication module compatible with the contactless reader, such as a Near Field Communication (NFC) module, to establish a contactless channel for data or information transmission. Optionally, this contactless channel includes an NFC channel, meaning it connects the operator's system to the contactless reader, then to the user's terminal's NFC module, and finally to the user's eUICC card. This contactless channel eliminates the need for users to hand their terminals to service center staff; users simply place or bring their terminals near the contactless reader to perform subsequent profile file generation, download, and writing processes, ensuring user privacy.

[0077] Specifically, when an operator needs to set up network access services for a user terminal, the user can first place the user terminal near or on a contactless reader / writer. This allows the communication module in the user terminal to establish a contactless channel with the reader / writer. This contactless channel connects the operator's system to the contactless reader / writer, then to the user terminal's communication module, and finally to the eUICC card. The contactless reader / writer can then read the device identification information from the user terminal's eUICC card through this contactless channel and transmit the information to the operator's system. This device identification information may include the user terminal's IMEI information and the eUICC card's EID information, etc.

[0078] Step 604: Determine the carrier code data corresponding to the eUICC card based on the device identity information, and send the carrier code data to the subscription management data preparation SM-DP+ platform; the aforementioned carrier code data is used to instruct the SM-DP+ platform to generate a carrier code data configuration file corresponding to the carrier code data.

[0079] In this step, after obtaining the device identity information of the user terminal, the operator system (BOSS or CRM, etc.) can first establish a binding relationship between the IMEI information and EID information in the device identity information. If the user terminal is opening a new SIM card, the SIM card will be opened and a number will be assigned based on this binding relationship, thus obtaining the operator code number data; or, the IMEI information and EID information in the device identity information can be established first. If the user terminal is using a previous number, the operator code number data will be generated through this binding relationship and the user terminal's existing number.

[0080] After the operator system obtains the operator code number data corresponding to the user terminal's eUICC card, it can send the operator code number data to the SM-DP+ platform. The SM-DP+ platform then generates a corresponding operator code number data configuration file, denoted as Profile, based on this operator code number data. This Profile file is used to write the eUICC card number into the eUICC card.

[0081] Step 606: If a Profile is generated in the SM-DP+ platform, download the Profile from the SM-DP+ platform through the operator's system.

[0082] In this step, after the Profile file is generated on the SM-DP+ platform, a notification message can be sent to the operator system to inform that the Profile file corresponding to the eUICC card has been generated on the SM-DP+ platform. After receiving the notification message, the operator system can download the Profile file from the SM-DP+ platform.

[0083] Step 608: Write the Profile to the eUICC card via a contactless channel.

[0084] In this step, after the operator system downloads the Profile file, it can write the Profile file to the user terminal's eUICC card via a contactless channel. Specifically, the operator system can write the Profile file to the user terminal's eUICC card via the contactless channel: operator system - contactless reader - user terminal's communication module - user terminal's eUICC card.

[0085] In this embodiment, by establishing a contactless channel connection between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the eUICC card of the user terminal through the contactless channel. Based on the device identity information, the operator code data corresponding to the eUICC card is determined, and the operator code data is sent to the SM-DP+ platform to generate the operator code data configuration file Profile corresponding to the operator code data. If the Profile is generated in the SM-DP+ platform, the Profile is downloaded from the SM-DP+ platform through the operator system, and the Profile is written to the eUICC card through the contactless channel. The device identity information includes the IMEI of the user terminal and the EID of the eUICC card. In this method, the operator's system can read the eUICC card information through a contactless channel to generate and download the configuration file Profile on the SM-DP+ platform. Simultaneously, the Profile downloaded from the SM-DP+ platform can be written to the eUICC card through the contactless channel. This eliminates the need for users to scan a QR code to download the Profile, automatically and efficiently completing the reading of eUICC card information, the download of the Profile, and the writing of the Profile to the eUICC card. This improves the download efficiency of the Profile and reduces the consumption of business resources. It also facilitates business processing at service centers, avoiding the need to hand user terminals to sales staff and protecting user privacy. Furthermore, the operator's system can directly download the Profile from the SM-DP+ platform and write it to the eUICC card on the user's terminal, eliminating the need to display the Profile QR code to the user. This avoids the problem of the Profile QR code being transmitted externally, ensuring the security of the entire eUICC card registration and activation process.

[0086] The following examples illustrate the specific process of downloading and writing Profile files in the operator's system.

[0087] In one embodiment, step 606 above, downloading the Profile from the SM-DP+ platform via the operator's system, includes: Download the profile from the SM-DP+ platform using the Cloud Local Profile Assistant (LPA) module in the operator's system.

[0088] The operator system includes a cloud LPA module, which functions identically to the LPA module on the user terminal, capable of downloading and writing profile files. In this embodiment, after the operator system learns that a profile file has been generated on the SM-DP+ platform, it can download the generated profile file from the SM-DP+ platform through the cloud LPA module. This cloudification of the LPA module from the user terminal to the operator system allows branch staff to fully verify the download results of the profile file based on the operator system. Download and installation issues are easily resolved on-site, and all instructions are sent directly from the operator system, allowing for direct log recording.

[0089] Accordingly, in step 608 above, writing the Profile to the eUICC card via a contactless channel includes: The profile is written from the cloud LPA module to the eUICC card via a contactless channel.

[0090] After the Profile file is downloaded to the cloud LPA module in the operator's system, the operator's system can write the Profile file from the cloud LPA module to the user terminal's eUICC card through a contactless channel. That is, it is first transmitted from the cloud LPA module to the contactless reader, then transmitted from the contactless reader to the user terminal's communication module (i.e., NFC module), and finally transmitted from the communication module to the user terminal's eUICC card.

[0091] In this embodiment, the Profile is downloaded through the cloud LPA module of the operator system, and the Profile in the cloud LPA module of the operator system is written to the eUICC card of the user terminal through a contactless channel. This makes it easy for the staff of the business hall to fully confirm the download result of the Profile file based on the operator system. Download and installation problems can be easily solved on-site. All instructions are sent directly by the operator system and can be directly logged.

[0092] The following examples illustrate the specific process by which the operator system writes the Profile file into the eUICC card.

[0093] In one embodiment, writing the Profile from the cloud LPA module to the eUICC card via a contactless channel in the above steps may include: Encrypt the Profile in the cloud LPA module to obtain the encrypted Profile; The encrypted profile is split into multiple Application Protocol Data Units (APDUs) instructions, and each APDU instruction is written from the cloud LPA module to the eUICC card via a contactless channel.

[0094] In this system, the cloud LPA module downloads the Profile file from the SM-DP+ platform and then encrypts it using a preset encryption method to obtain an encrypted Profile file, which is referred to as the encrypted Profile file. The preset encryption method can be set according to the actual situation, such as digest encryption or key encryption.

[0095] After obtaining the encrypted profile file, the operator system can segment the encrypted profile file according to the Application Protocol Data Unit (APDU) to obtain multiple APDU instructions. Then, these multiple APDU instructions are written from the operator system's cloud LPA module to the user terminal's eUICC card through a contactless channel.

[0096] In this embodiment, the Profile file in the cloud LPA module is encrypted and then divided into multiple APDU instructions. These multiple APDU instructions are written from the cloud LPA module to the eUICC card through a contactless channel. This ensures the security of writing the Profile file and improves the writing efficiency of the Profile file.

[0097] The following examples illustrate the authentication process before the operator system writes the Profile file.

[0098] In one embodiment, before writing the Profile from the cloud LPA module to the eUICC card via a contactless channel in the above steps, the method may further include: Receive authentication response messages from the SM-DP+ platform; the aforementioned authentication response messages are used to indicate whether the two-way authentication between the SM-DP+ platform and the eUICC card is successful or unsuccessful. If the authentication response message indicates that the two-way authentication between the SM-DP+ platform and the eUICC card is successful, perform the above steps to write the Profile from the cloud LPA module to the eUICC card through the contactless channel.

[0099] In this system, certificates can be pre-configured on both the user terminal's eUICC card and the SM-DP+ platform. After the cloud LPA module in the operator's system downloads the Profile file from the SM-DP+ platform, it can first notify the SM-DP+ platform and the eUICC card to perform two-way authentication. Specifically, the SM-DP+ platform can authenticate the eUICC card based on the pre-configured certificate through the ES6 channel (or ES9+-ES10x or ES8+), while the eUICC card can authenticate the SM-DP+ platform based on the pre-configured certificate through the ES6 channel (or ES9+-ES10x or ES8+). After both authentications are completed, the SM-DP+ platform can obtain the two-way authentication result, which includes whether the two-way authentication between the SM-DP+ platform and the eUICC card was successful or failed. The SM-DP+ platform can then encapsulate this two-way authentication result into an authentication response message and send it to the operator's system.

[0100] After receiving the authentication response message, the operator system can obtain the two-way authentication result, thus determining whether the two-way authentication between the SM-DP+ platform and the eUICC card was successful or failed. If the two-way authentication between the SM-DP+ platform and the eUICC card fails, it indicates that either the eUICC card or the SM-DP+ platform is unreliable, and the Profile file cannot be written to the eUICC card in this case. If the two-way authentication between the SM-DP+ platform and the eUICC card succeeds, it indicates that both the eUICC card and the SM-DP+ platform are reliable, and therefore the steps described above for writing the Profile file from the cloud LPA module to the eUICC card can be performed to achieve the purpose of writing the Profile file to the eUICC card.

[0101] In this embodiment, the operator system can receive an authentication response message sent by the SM-DP+ platform to indicate whether the two-way authentication between the SM-DP+ platform and the eUICC card is successful or unsuccessful. If the authentication is successful, the Profile can be written from the cloud LPA module to the eUICC card, thus ensuring the security of the user terminal.

[0102] The following examples illustrate the device verification process before the operator system determines the operator code data.

[0103] In one embodiment, before determining the carrier code data corresponding to the eUICC card based on the device identity information in step 604, the method further includes: The device identity information is sent to the authorized management system ECS; the aforementioned device identity information is used to instruct the ECS to verify whether the user terminal is a valid device based on the device identity information. Receive the verification message sent by ECS; the verification message is used to identify whether the user terminal is a valid device. If the user terminal is a valid device, perform the steps described above to determine the operator code data corresponding to the eUICC card based on the device identity information.

[0104] After the operator's system reads the device identity information from the eUICC card via a contactless channel, it can first send this device identity information to the authorized management system (ECS). Upon receiving the device identity information, the ECS can first verify whether the user terminal is a valid device based on this information. The ECS stores the device identity information of pre-registered legitimate devices. During verification, the ECS can compare the user terminal's device identity information with the stored legitimate device identity information. If the comparison is successful, it means that the user terminal is a valid / legitimate device; otherwise, it means that the user terminal is not a valid / legitimate device.

[0105] After verifying whether the user terminal is a valid device, the ECS obtains a verification result, which indicates whether the user terminal is a valid device. The ECS then encapsulates this verification result into a verification message and sends it to the operator system. Upon receiving this verification message, the operator system can determine whether the user terminal is a valid device. If the user terminal is a valid device, it can continue to execute the step 604 above, which involves determining the operator code number data corresponding to the eUICC card based on the device identity information. This includes subsequent processes such as generating code number data, generating and downloading the Profile file, and writing the data.

[0106] In addition to verifying the validity of the user terminal, the network access conditions of the user terminal can also be verified. Optionally, before determining the operator code data corresponding to the eUICC card based on the device identity information in step 604 above, the method also includes: Verify whether the user terminal meets the network access requirements; If the user terminal meets the network access requirements, obtain the target number selected by the user for the eUICC card of the user terminal; The above-mentioned data for determining the carrier code number corresponding to the eUICC card based on the device identity information includes: Based on the device identification information and the target number, determine the carrier code data corresponding to the eUICC card.

[0107] The user terminal can have its network access license information stored on the back, which can be input by the user into the operator's system, allowing the operator to obtain this information. Alternatively, the user terminal's eUICC card can also contain this information, which the operator can access by reading the eUICC card via a contactless channel. After obtaining this network access license information, the operator can compare it with the aforementioned device identity information and other data with the information of pre-registered legitimate devices. If the comparison is successful, the user terminal meets the network access requirements; otherwise, it does not.

[0108] If the user terminal meets the network access requirements, the business hall staff can guide the user to select a number and package on the operator's system. The number selected by the user is recorded as the target number. After obtaining the target number selected by the user, the operator's system can continue to execute the step 604 above, which involves determining the operator code data corresponding to the eUICC card based on the device identity information.

[0109] When a user terminal does not meet the network access requirements or when the user terminal SIM card is replaced, the steps of selecting a number and plan can be skipped.

[0110] Specifically, when performing step 604 above to determine the operator code data corresponding to the eUICC card based on the device identity information, the operator system can first establish a binding relationship between the IMEI information and EID information in the device identity information, and then combine the binding relationship with the target number to obtain the operator code data.

[0111] In this embodiment, the operator system can send device identity information to the ECS to verify device validity, thus ensuring the legitimacy of the user terminal. Additionally, the operator system can verify whether the user terminal meets the network access requirements and, if so, obtain the target number selected by the user to generate operator code data, thereby ensuring the security of the user terminal accessing the network.

[0112] The following describes a data download method for embedded general-purpose integrated circuit cards with the user terminal as the execution subject.

[0113] Figure 7 The second flowchart of the embedded general-purpose integrated circuit card data download method provided in this application embodiment is shown below. Figure 7 As shown, the method may include the following steps: Step 702: When the operator system and the user terminal establish a contactless channel connection, receive the operator code number data configuration file Profile written by the operator system to the embedded general-purpose integrated circuit card eUICC card of the user terminal through the contactless channel.

[0114] The aforementioned Profile is generated in the subscription management data preparation SM-DP+ platform. The operator system downloads the Profile from the SM-DP+ platform. The SM-DP+ platform generates the Profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the device identity information of the user terminal. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID identifier of the eUICC card, which is obtained by the operator system through the contactless channel eUICC card.

[0115] In this step, the process of the operator system reading device identity information from the user terminal's eUICC card through a contactless channel, generating operator code data, generating a profile file, downloading the profile file, and writing the profile file to the eUICC card can all be found in the explanation of the above-mentioned operator system-side embodiment, and will not be repeated here.

[0116] In this embodiment, by establishing a contactless channel connection between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the eUICC card of the user terminal through the contactless channel. Based on the device identity information, the operator code data corresponding to the eUICC card is determined, and the operator code data is sent to the SM-DP+ platform to generate the operator code data configuration file Profile corresponding to the operator code data. If the Profile is generated in the SM-DP+ platform, the Profile is downloaded from the SM-DP+ platform through the operator system, and the Profile is written to the eUICC card through the contactless channel. The device identity information includes the IMEI of the user terminal and the EID of the eUICC card. In this method, the operator's system can read the eUICC card information through a contactless channel to generate and download the configuration file Profile on the SM-DP+ platform. Simultaneously, the Profile downloaded from the SM-DP+ platform can be written to the eUICC card through the contactless channel. This eliminates the need for users to scan a QR code to download the Profile, automatically and efficiently completing the reading of eUICC card information, the download of the Profile, and the writing of the Profile to the eUICC card. This improves the download efficiency of the Profile and reduces the consumption of business resources. It also facilitates business processing at service centers, avoiding the need to hand user terminals to sales staff and protecting user privacy. Furthermore, the operator's system can directly download the Profile from the SM-DP+ platform and write it to the eUICC card on the user's terminal, eliminating the need to display the Profile QR code to the user. This avoids the problem of the Profile QR code being transmitted externally, ensuring the security of the entire eUICC card registration and activation process.

[0117] In one embodiment, the above method may further include the following steps: After the Profile is written to the eUICC card, an update event is generated via the HCI protocol; the update event is used to indicate that the Profile information in the eUICC card has changed. The update event is sent to the LPA module or native application module in the user terminal via the HCI protocol; the update event is used to instruct the LPA module or native application module in the user terminal to obtain the Profile from the eUICC card and update its own Profile information.

[0118] After the operator system writes the Profile file to the user terminal's eUICC card, the user terminal's eUICC card can generate an update event (i.e., an HCI event) through the HCI (Host-Controller Bluetooth Controller) protocol. This update event indicates that the Profile information in the eUICC card has changed, such as the addition of a new Profile file for the user terminal.

[0119] Subsequently, the user terminal's eUICC card can transmit this update event, generated based on the HCI protocol, via the communication module (such as the NFC module) and the OpenMobile API to the user terminal's LPA module or native application module through the HCI / SWP protocol. This native application module could be, for example, the user terminal's settings module or a settings section within the settings module.

[0120] After receiving an update event, the LPA module or native application module of the user terminal can interact with the eUICC card to synchronize the profile information between the two. For example, it can update the profile file added by the eUICC card to the LPA module or native application module of the user terminal.

[0121] In this embodiment, after the eUICC card finishes writing the Profile file, it can generate an event through the HCI protocol and notify the LPA / terminal native application module in the user terminal of the event, informing that the Profile information in the eUICC card has changed. The LPA / terminal native application module in the user terminal interacts with the eUICC card to update the Profile information. This facilitates the quick and accurate synchronization of Profile information between the eUICC card and the LPA module or native application module in the user terminal.

[0122] To facilitate a detailed description of the embodiments of this application, the following describes in detail the embedded general-purpose integrated circuit card data download method of this application embodiment using the interaction process between the user terminal, the operator system, and the SM-DP+ system. See [link to relevant documentation]. Figure 8 The interaction timing diagram shown illustrates the interaction between the user terminal, the operator system, and the SM-DP+ system. This method may include the following steps: 1. When a user applies for eSIM service, they place their terminal (i.e., the eSIM device, such as a mobile phone) on the contactless reader. The operator's system activates the NFC reader and connects to the eUICC card in the eSIM device through the contactless channel to begin processing the service for the user.

[0123] 2. Send commands via the NFC channel to read the IMEI, EID and other information of the user terminal.

[0124] 3. Obtain information such as the IMEI and EID of the user terminal.

[0125] 4. Send the device to the authorized management system ECS to verify its validity. If the device is found to be invalid, the processing will be terminated.

[0126] 5. Verify the user's eligibility for network access and guide the user to select a number and plan. If the SIM card is changed, ignore this step.

[0127] 6. The operator system prepares the operator code number data and sends it to the SM-DP+ platform.

[0128] 7. The SM-DP+ platform generates the corresponding Profile.

[0129] 8. The cloud LPA module in the operator's system initiates the Profile download process.

[0130] 9. The cloud LPA module in the operator's system connects to the eUICC card through a contactless channel. First, it performs two-way authentication through a pre-set certificate. After successful authentication, the cloud LPA module splits the encrypted Profile data into APDU instructions and writes them into the eUICC card through a contactless reader.

[0131] 10. After writing the Profile data to the eUICC card, an event is generated via the HCI protocol.

[0132] 11. The user terminal system notifies the LPA module / native application module in the user terminal of the event, and the Profile information in the eUICC card changes.

[0133] 12. The LPA module / native application module in the user terminal interacts with the eUICC card to update profile information.

[0134] 13. After the user activates the downloaded Profile, they connect to the operator's network, and the operator's system activates the card data on the network side.

[0135] Regarding the certificate used for two-way authentication between the SM-DP+ platform and the eUICC card, according to GSMASGP.22 "RSP Technical Specification", the certificate chain requirements for eSIM are as follows: the certificate issuer (CI) should be a CA authority recognized by the operator. (See [link to relevant documentation]). Figure 9The diagram illustrates the eSIM certificate chain. Certificates issued by the CI include: CI certificate (CERT.CI.ECDSA); card vendor certificate (CERT.EUM.ECDSA); SM-DP+ certificates (CERT.DPauth.ECDSA and CERT.DPpb.ECDSA, the former used for two-way authentication with the eSIM, and the latter for profile binding); and SM-DP+ TLS certificate (CERT.DP.TLS). Certificates issued by the card vendor include: eSIM certificate (CERT.EUICC.ECDSA).

[0136] In summary, this application embodiment achieves profile download via NFC, including contactless terminal verification, the operator implementing LPA functionality on the platform side and directly issuing commands through the contactless channel to complete profile data download and installation, and synchronizing the profile result to the LPA and native application module via the HCI event interface. This contactless method of downloading number data reduces the scanning process compared to using an app, making data download faster. It also facilitates business transactions at service centers, avoiding the need to hand the user's phone to a salesperson. Furthermore, existing technologies provide a best-effort notification upon successful download, which cannot fully confirm the download result. The technical solution of this application embodiment allows for confirmation of the profile download result at the service center, facilitating on-site resolution of download and installation issues. All commands are sent directly by the operator's system and can be directly logged. Simultaneously, with LPA cloudification, the system can obtain real-time information on interactions with the eUICC card, confirming the profile download result. Compared to the GSMA solution, which only provides a best-effort notification and the operator may not know the download result, the technical solution of this application embodiment provides a more definitive download result. Additionally, this application's technical solution can verify the user's device through technical means, thus replacing photo recording.

[0137] The embedded general-purpose integrated circuit card data download device provided in the embodiments of this application is described below. The embedded general-purpose integrated circuit card data download device described below and the embedded general-purpose integrated circuit card data download method described above can be referred to in correspondence with each other.

[0138] Figure 10 This is one of the structural schematic diagrams of the embedded general-purpose integrated circuit card data download device provided in the embodiments of this application. See also... Figure 10 As shown, the device may include: The device information acquisition module 1001 is used to acquire the device identity information corresponding to the user terminal from the embedded universal integrated circuit card (eUICC card) of the user terminal through a contactless channel connection when the operator system and the user terminal establish a contactless channel connection; the device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the identifier (EID) of the eUICC card. The code number data sending module 1002 is used to determine the operator code number data corresponding to the eUICC card based on the device identity information, and send the operator code number data to the subscription management data preparation SM-DP+ platform; the above-mentioned operator code number data is used to instruct the SM-DP+ platform to generate the operator code number data configuration file corresponding to the operator code number data. The configuration file download module 1003 is used to download the profile from the SM-DP+ platform through the operator system when a profile is generated in the SM-DP+ platform. The configuration file writing module 1004 is used to write the Profile to the eUICC card via a contactless channel.

[0139] In one embodiment, the above-mentioned configuration file download module 1003 is specifically used to download the Profile from the SM-DP+ platform through the Cloud Local Configuration File Assistant (LPA) module in the operator system; The aforementioned configuration file writing module 1004 is specifically used to write the Profile from the cloud LPA module to the eUICC card via a contactless channel.

[0140] In one embodiment, the above-mentioned configuration file writing module 1004 is specifically used to encrypt the Profile in the cloud LPA module to obtain an encrypted Profile; split the encrypted Profile into multiple Application Protocol Data Unit (APDU) instructions, and write each APDU instruction from the cloud LPA module to the eUICC card through a contactless channel.

[0141] In one embodiment, before the above-mentioned configuration file writing module 1004 writes the Profile from the cloud LPA module to the eUICC card via a contactless channel, the above-mentioned device further includes: The authentication module is used to receive authentication response messages from the SM-DP+ platform. These authentication response messages indicate whether the bidirectional authentication between the SM-DP+ platform and the eUICC card is successful or not. If the authentication response message indicates that the bidirectional authentication between the SM-DP+ platform and the eUICC card is successful, the steps described above for writing the Profile from the cloud LPA module to the eUICC card via a contactless channel are executed.

[0142] In one embodiment, before the code number data sending module 1002 determines the operator code number data corresponding to the eUICC card based on the device identity information, the device further includes: The device verification module is used to send device identity information to the authorization management system ECS; the device identity information is used to instruct the ECS to verify whether the user terminal is a valid device based on the device identity information; receive the verification message sent by the ECS; the verification message is used to indicate whether the user terminal is a valid device; if the user terminal is a valid device, perform the above steps of determining the operator code data corresponding to the eUICC card based on the device identity information.

[0143] In one embodiment, before the code number data sending module 1002 determines the operator code number data corresponding to the eUICC card based on the device identity information, the device further includes: The network access verification module is used to verify whether the user terminal meets the network access conditions; if the user terminal meets the network access conditions, it obtains the target number selected by the user for the eUICC card of the user terminal. The aforementioned code number data sending module 1002 is specifically used to determine the operator code number data corresponding to the eUICC card based on the device identity information and the target number.

[0144] In one embodiment, the contactless channel described above includes a near-field communication (NFC) channel.

[0145] Figure 11 This is the second structural schematic diagram of the embedded general-purpose integrated circuit card data download device provided in the embodiments of this application. See also... Figure 11 As shown, the device may include: The receiving module 1101 is used to receive the operator code number data configuration file Profile written by the operator system to the embedded general-purpose integrated circuit card eUICC card of the user terminal through the contactless channel when the operator system and the user terminal establish a contactless channel connection. The aforementioned Profile is generated in the subscription management data preparation SM-DP+ platform. The operator system downloads the Profile from the SM-DP+ platform. The SM-DP+ platform generates the Profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the device identity information of the user terminal. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID identifier of the eUICC card, which is obtained by the operator system through the contactless channel eUICC card.

[0146] In one embodiment, the above-mentioned apparatus further includes: The update module is used to generate an update event via the HCI protocol after the profile is written to the eUICC card. The update event is used to indicate that the profile information in the eUICC card has changed. The update event is sent to the LPA module or native application module in the user terminal via the HCI protocol. The update event is used to instruct the LPA module or native application module in the user terminal to obtain the profile from the eUICC card and update its own profile information.

[0147] Furthermore, the network devices involved in the embodiments of this application can be hardware devices corresponding to the aforementioned operator systems, such as backend servers or terminals corresponding to the operator systems, or they can be base stations, which may include multiple cells providing services to terminals. Depending on the specific application, a base station may also be called an access point, or a device in the access network that communicates with wireless terminal devices through one or more sectors on the air interface, or other names.

[0148] Figure 12 This is a schematic diagram of the structure of a network device according to an embodiment of this application, with reference to... Figure 12 This application embodiment also provides a network device, which may include: a memory 1210, a transceiver 1220 and a processor 1230; Memory 1210 is used to store computer programs; transceiver 1220 is used to send and receive data under the control of processor 1230; processor 1230 is used to read the computer program in memory 1210 and perform the following operations: When a contactless channel connection is established between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the embedded universal integrated circuit card (eUICC card) of the user terminal through the contactless channel. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID of the eUICC card. Based on the device identity information, the operator code data corresponding to the eUICC card is determined and sent to the subscription management data preparation SM-DP+ platform. The operator code data is used to instruct the SM-DP+ platform to generate an operator code data configuration file (Profile) corresponding to the operator code data. If the Profile is generated in the SM-DP+ platform, it is downloaded from the SM-DP+ platform through the operator system. The Profile is then written to the eUICC card through the contactless channel.

[0149] Among them, Figure 12In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 1230) and memory (memory 1210). The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides an interface. Transceiver 1220 may be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. Processor 1230 is responsible for managing the bus architecture and general processing, and memory 1210 may store data used by processor 1230 during operation.

[0150] Optionally, the processor 1230 is also used to perform the following operations: The Profile is downloaded from the SM-DP+ platform via the Cloud Local Profile Assistant (LPA) module in the operator's system; the Profile is then written from the cloud LPA module to the eUICC card via a contactless channel.

[0151] Optionally, the processor 1230 is also used to perform the following operations: The Profile in the cloud LPA module is encrypted to obtain the encrypted Profile; the encrypted Profile is split into multiple Application Protocol Data Units (APDUs) and each APDU is written from the cloud LPA module to the eUICC card through a contactless channel.

[0152] Optionally, the processor 1230 is also used to perform the following operations: Receive the authentication response message from the SM-DP+ platform; the authentication response message is used to indicate whether the two-way authentication between the SM-DP+ platform and the eUICC card is successful or not; if the authentication response message indicates that the two-way authentication between the SM-DP+ platform and the eUICC card is successful, perform the above steps of writing the Profile from the cloud LPA module to the eUICC card through the contactless channel.

[0153] Optionally, the processor 1230 is also used to perform the following operations: The device identity information is sent to the authorized management system ECS; the device identity information is used to instruct the ECS to verify whether the user terminal is a valid device based on the device identity information; the verification message sent by the ECS is received; the verification message is used to indicate whether the user terminal is a valid device; if the user terminal is a valid device, the above steps of determining the operator code data corresponding to the eUICC card based on the device identity information are performed.

[0154] Optionally, the processor 1230 is also used to perform the following operations: Verify whether the user terminal meets the network access requirements; if the user terminal meets the network access requirements, obtain the target number selected by the user for the eUICC card of the user terminal; determine the operator code data corresponding to the eUICC card based on the device identity information and the target number.

[0155] Optionally, the aforementioned contactless channel includes a near-field communication (NFC) channel.

[0156] Furthermore, the user terminal involved in the embodiments of this application may be a device that provides voice and / or data connectivity to a user, a handheld device with wireless connectivity, or other processing devices connected to a wireless modem, etc. The name of the terminal device may also differ in different systems; for example, in a 5G system, the terminal device may be called User Equipment (UE).

[0157] Figure 13 This is a schematic diagram of the terminal structure according to an embodiment of this application, with reference to... Figure 13 This application embodiment also provides a terminal, which may include: a memory 1310, a transceiver 1320 and a processor 1330; Memory 1310 is used to store computer programs; transceiver 1320 is used to send and receive data under the control of processor 1330; processor 1330 is used to read the computer program in memory 1310 and perform the following operations: When a contactless channel connection is established between the operator system and the user terminal, the system receives the operator code number data configuration file Profile written by the operator system to the embedded universal integrated circuit card (eUICC card) of the user terminal through the contactless channel. This Profile is downloaded from the SM-DP+ platform when a Profile is generated in the subscription management data preparation platform. The SM-DP+ platform generates the Profile based on the operator code number data corresponding to the eUICC card sent by the operator system. The operator code number data is determined according to the user terminal's device identity information, which includes the user terminal's International Mobile Equipment Identity (IMEI) and / or the eUICC card's identifier (EID), and is obtained by the operator system from the eUICC card through the contactless channel.

[0158] Among them, Figure 13In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, such as one or more processors represented by processor 1330 and memory represented by memory 1310. The bus architecture can also link together various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 1320 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, user interface 1340 can also be an interface capable of connecting external or internal devices as needed.

[0159] The processor 1330 is responsible for managing the bus architecture and general processing, while the memory 1310 can store the data used by the processor 1330 when performing operations.

[0160] The processor 1330 executes any of the methods described in the embodiments of this application by calling a computer program stored in the memory 1310, according to the obtained executable instructions. The processor and the memory may also be physically separated.

[0161] Optionally, the processor 1330 is also used to perform the following operations: After the profile is written to the eUICC card, an update event is generated via the HCI protocol. The update event is used to indicate that the profile information in the eUICC card has changed. The update event is sent to the LPA module or native application module in the user terminal via the HCI protocol. The update event is used to instruct the LPA module or native application module in the user terminal to retrieve the profile from the eUICC card and update its own profile information.

[0162] It should be noted that the terminal and network device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0163] Figure 14 This example illustrates the physical structure of an electronic device, which can be a network device or a terminal, such as... Figure 14As shown, the electronic device may include: a processor 1410, a communication interface 1420, a memory 1430, and a communication bus 1440, wherein the processor 1410, the communication interface 1420, and the memory 1430 communicate with each other via the communication bus 1440. The processor 1410 can call a computer program stored in the memory 1430 to execute the steps of an embedded general-purpose integrated circuit card data download method, apparatus, device, and medium method, such as including: When a contactless channel connection is established between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the embedded universal integrated circuit card (eUICC card) of the user terminal through the contactless channel. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID of the eUICC card. Based on the device identity information, the operator code data corresponding to the eUICC card is determined and sent to the subscription management data preparation SM-DP+ platform. The operator code data is used to instruct the SM-DP+ platform to generate an operator code data configuration file (Profile) corresponding to the operator code data. If the Profile is generated in the SM-DP+ platform, it is downloaded from the SM-DP+ platform through the operator system. The Profile is then written to the eUICC card through the contactless channel.

[0164] Alternatively, when a contactless channel connection is established between the operator system and the user terminal, the operator system receives a profile containing operator code data written to the user terminal's embedded universal integrated circuit card (eUICC) via the contactless channel. This profile is downloaded from the SM-DP+ platform when a profile is generated in the subscription management data preparation platform. The SM-DP+ platform generates the profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the user terminal's device identity information, which includes the user terminal's International Mobile Equipment Identity (IMEI) and / or the eUICC card's identifier (EID), and is obtained by the operator system from the eUICC card via the contactless channel.

[0165] Furthermore, the logical instructions in the aforementioned memory 1430 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0166] On the other hand, this application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can perform the steps of the embedded general-purpose integrated circuit card data download method, apparatus, device, and medium method provided in the above embodiments, such as including: When a contactless channel connection is established between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the embedded universal integrated circuit card (eUICC card) of the user terminal through the contactless channel. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID of the eUICC card. Based on the device identity information, the operator code data corresponding to the eUICC card is determined and sent to the subscription management data preparation SM-DP+ platform. The operator code data is used to instruct the SM-DP+ platform to generate an operator code data configuration file (Profile) corresponding to the operator code data. If the Profile is generated in the SM-DP+ platform, it is downloaded from the SM-DP+ platform through the operator system. The Profile is then written to the eUICC card through the contactless channel.

[0167] Alternatively, when a contactless channel connection is established between the operator system and the user terminal, the operator system receives a profile containing operator code data written to the user terminal's embedded universal integrated circuit card (eUICC) via the contactless channel. This profile is downloaded from the SM-DP+ platform when a profile is generated in the subscription management data preparation platform. The SM-DP+ platform generates the profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the user terminal's device identity information, which includes the user terminal's International Mobile Equipment Identity (IMEI) and / or the eUICC card's identifier (EID), and is obtained by the operator system from the eUICC card via the contactless channel.

[0168] On the other hand, embodiments of this application also provide a processor-readable storage medium storing a computer program for causing a processor to perform the steps of the methods provided in the above embodiments, such as including: When a contactless channel connection is established between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the embedded universal integrated circuit card (eUICC card) of the user terminal through the contactless channel. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID of the eUICC card. Based on the device identity information, the operator code data corresponding to the eUICC card is determined and sent to the subscription management data preparation SM-DP+ platform. The operator code data is used to instruct the SM-DP+ platform to generate an operator code data configuration file (Profile) corresponding to the operator code data. If the Profile is generated in the SM-DP+ platform, it is downloaded from the SM-DP+ platform through the operator system. The Profile is then written to the eUICC card through the contactless channel.

[0169] Alternatively, when a contactless channel connection is established between the operator system and the user terminal, the operator system receives a profile containing operator code data written to the user terminal's embedded universal integrated circuit card (eUICC) via the contactless channel. This profile is downloaded from the SM-DP+ platform when a profile is generated in the subscription management data preparation platform. The SM-DP+ platform generates the profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the user terminal's device identity information, which includes the user terminal's International Mobile Equipment Identity (IMEI) and / or the eUICC card's identifier (EID), and is obtained by the operator system from the eUICC card via the contactless channel.

[0170] The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., CD, DVD, BD, HVD), and semiconductor memory (e.g., ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)).

[0171] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0172] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0173] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for downloading data from an embedded general-purpose integrated circuit card, characterized in that, include: When a contactless channel connection is established between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the embedded universal integrated circuit card (eUICC card) of the user terminal through the contactless channel; the device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the identifier (EID) of the eUICC card; Based on the device identity information, the operator code data corresponding to the eUICC card is determined, and the operator code data is sent to the subscription management data preparation SM-DP+ platform; the operator code data is used to instruct the SM-DP+ platform to generate an operator code data configuration file corresponding to the operator code data; When the Profile is generated in the SM-DP+ platform, the Profile is downloaded from the SM-DP+ platform through the operator system; The Profile is written to the eUICC card via the contactless channel.

2. The embedded general-purpose integrated circuit card data download method according to claim 1, characterized in that, The step of downloading the Profile from the SM-DP+ platform through the operator's system includes: The Profile is downloaded from the SM-DP+ platform through the Cloud Local Profile Assistant (LPA) module in the operator system. The step of writing the Profile to the eUICC card through the contactless channel includes: The Profile is written from the cloud LPA module to the eUICC card via the contactless channel.

3. The embedded general-purpose integrated circuit card data download method according to claim 2, characterized in that, The step of writing the Profile from the cloud LPA module to the eUICC card through the contactless channel includes: The Profile in the cloud LPA module is encrypted to obtain an encrypted Profile; The encrypted profile is split into multiple Application Protocol Data Units (APDUs), and each APDU is written from the cloud LPA module to the eUICC card through the contactless channel.

4. The embedded general-purpose integrated circuit card data download method according to claim 2 or 3, characterized in that, Before writing the Profile from the cloud LPA module to the eUICC card via the contactless channel, the method further includes: Receive the authentication response message from the SM-DP+ platform; the authentication response message is used to indicate whether the bidirectional authentication between the SM-DP+ platform and the eUICC card is successful or unsuccessful. If the authentication response message indicates that the bidirectional authentication between the SM-DP+ platform and the eUICC card is successful, the step of writing the Profile from the cloud LPA module to the eUICC card through the contactless channel is executed.

5. The embedded general-purpose integrated circuit card data download method according to any one of claims 1 to 3, characterized in that, Before determining the carrier code data corresponding to the eUICC card based on the device identity information, the method further includes: The device identity information is sent to the authorization management system ECS; the device identity information is used to instruct the ECS to verify whether the user terminal is a valid device based on the device identity information. Receive the verification message sent by the ECS; the verification message is used to identify whether the user terminal is a valid device; If the user terminal is a valid device, the step of determining the operator code data corresponding to the eUICC card based on the device identity information is performed.

6. The embedded general-purpose integrated circuit card data download method according to any one of claims 1 to 3, characterized in that, Before determining the carrier code data corresponding to the eUICC card based on the device identity information, the method further includes: Verify whether the user terminal meets the network access requirements; If the user terminal meets the network access conditions, obtain the target number selected by the user for the eUICC card of the user terminal; The step of determining the carrier code data corresponding to the eUICC card based on the device identity information includes: Based on the device identity information and the target number, determine the carrier code data corresponding to the eUICC card.

7. The embedded general-purpose integrated circuit card data download method according to any one of claims 1 to 3, characterized in that, The contactless channel includes a near-field communication (NFC) channel.

8. A method for downloading data from an embedded general-purpose integrated circuit card, characterized in that, include: When a contactless channel connection is established between the operator system and the user terminal, the operator code number data configuration file Profile is received by the operator system through the contactless channel and written to the embedded general-purpose integrated circuit card eUICC card of the user terminal. The Profile is generated in the subscription management data preparation SM-DP+ platform. The operator system downloads the Profile from the SM-DP+ platform. The SM-DP+ platform generates the Profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the device identity information of the user terminal. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID of the eUICC card, and is obtained by the operator system from the eUICC card through the contactless channel.

9. The embedded general-purpose integrated circuit card data download method according to claim 8, characterized in that, The method further includes: Once the Profile is written to the eUICC card, an update event is generated via the HCI protocol; the update event is used to indicate that the Profile information in the eUICC card has changed. The update event is sent to the LPA module or native application module in the user terminal via the HCI protocol; the update event is used to instruct the LPA module or native application module in the user terminal to obtain the Profile from the eUICC card and update its own Profile information.

10. A data download device for an embedded general-purpose integrated circuit card, characterized in that, include: The device information acquisition module is used to acquire the device identity information corresponding to the user terminal from the embedded universal integrated circuit card (eUICC card) of the user terminal through the contactless channel when the operator system and the user terminal establish a contactless channel connection; the device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the identifier (EID) of the eUICC card; The code number data sending module is used to determine the operator code number data corresponding to the eUICC card based on the device identity information, and send the operator code number data to the subscription management data preparation SM-DP+ platform; the operator code number data is used to instruct the SM-DP+ platform to generate an operator code number data configuration file corresponding to the operator code number data. The configuration file download module is used to download the Profile from the SM-DP+ platform through the operator system when the Profile is generated in the SM-DP+ platform. The configuration file writing module is used to write the Profile to the eUICC card through the contactless channel.

11. A data download device for an embedded general-purpose integrated circuit card, characterized in that, include: The receiving module is used to receive the operator code number data configuration file Profile written by the operator system to the embedded general-purpose integrated circuit card (eUICC card) of the user terminal through the contactless channel when the operator system and the user terminal establish a contactless channel connection. The Profile is generated in the subscription management data preparation SM-DP+ platform. The operator system downloads the Profile from the SM-DP+ platform. The SM-DP+ platform generates the Profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the device identity information of the user terminal. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID of the eUICC card, and is obtained by the operator system from the eUICC card through the contactless channel.

12. A network device, characterized in that, Includes memory, transceiver, and processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and performing the following operations: When a contactless channel connection is established between the operator system and the user terminal, the device identity information corresponding to the user terminal is obtained from the embedded universal integrated circuit card (eUICC card) of the user terminal through the contactless channel; the device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the identifier (EID) of the eUICC card; Based on the device identity information, the operator code data corresponding to the eUICC card is determined, and the operator code data is sent to the subscription management data preparation SM-DP+ platform; the operator code data is used to instruct the SM-DP+ platform to generate an operator code data configuration file corresponding to the operator code data; When the Profile is generated in the SM-DP+ platform, the Profile is downloaded from the SM-DP+ platform through the operator system; The Profile is written to the eUICC card via the contactless channel.

13. A terminal, characterized in that, Includes memory, transceiver, and processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and performing the following operations: When a contactless channel connection is established between the operator system and the user terminal, the operator code number data configuration file Profile is received by the operator system through the contactless channel and written to the embedded general-purpose integrated circuit card eUICC card of the user terminal. The Profile is generated in the subscription management data preparation SM-DP+ platform. The operator system downloads the Profile from the SM-DP+ platform. The SM-DP+ platform generates the Profile based on the operator code data corresponding to the eUICC card sent by the operator system. The operator code data is determined according to the device identity information of the user terminal. The device identity information includes the International Mobile Equipment Identity (IMEI) of the user terminal and / or the EID of the eUICC card, and is obtained by the operator system from the eUICC card through the contactless channel.

14. An electronic device comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the embedded general-purpose integrated circuit card data download method according to any one of claims 1 to 7, or implements the steps of the embedded general-purpose integrated circuit card data download method according to any one of claims 8 to 9.

15. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the embedded general-purpose integrated circuit card data download method as described in any one of claims 1 to 7, or the embedded general-purpose integrated circuit card data download method as described in any one of claims 8 to 9.

16. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the embedded general-purpose integrated circuit card data download method according to any one of claims 1 to 7, or implements the steps of the embedded general-purpose integrated circuit card data download method according to any one of claims 8 to 9.