Method, system and device for deploying Profile and electronic equipment

By generating encrypted profile packages and binding them to dedicated financial and general public networks, and automatically switching profiles based on application scenarios, the system solves the data security problem caused by sharing the same network resources for entertainment and financial security activities. This enables secure transmission and storage of financial data, reduces the risk of data leakage, and improves the security and efficiency of the device.

CN121858047APending Publication Date: 2026-04-14BEIJING TSINGTENG MICROSYSTEM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-09
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

On mobile devices, the sharing of the same network resources between entertainment and financial security activities can lead to the transmission of financial data in an insecure network environment or access by malicious applications, posing a data security risk.

Method used

By generating encrypted profile packages, binding them to both dedicated financial networks and ordinary residential networks, and writing them to secure and insecure storage areas respectively, and automatically switching profiles according to application scenarios, dual isolation of networks and data is achieved to ensure the security of financial data.

Benefits of technology

It enables secure transmission and storage of financial data, avoids sharing the same network channel with personal data, reduces the risk of data leakage, minimizes security risks caused by user operations, and improves the security and efficiency of the equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121858047A_ABST
    Figure CN121858047A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication networks, and discloses a method, a system and a device for deploying a Profile, and electronic equipment, and the method comprises the steps: responding to a package handling operation of a user, and obtaining a Profile encrypted package; the Profile encrypted packet comprises a financial exclusive Profile and a life common Profile; writing the financial exclusive Profile into a secure storage area, writing the life common Profile into a non-secure storage area, and activating the financial exclusive Profile and the life common Profile; monitoring the starting state of the application, and switching the current Profile into a financial exclusive Profile or a life common Profile according to the started target application; and according to the data type of the target application, storing the financial data to a secure storage area, and storing the life data to a non-secure storage area. The security of the financial data of the user can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication network technology, such as a method, system, apparatus, and electronic device for deploying a profile. Background Technology

[0002] With the rapid development of mobile internet and the popularization of digital finance, users are increasingly engaging in both "lifestyle and entertainment" and "financial security" online activities simultaneously on the same mobile device. These two types of activities differ significantly in risk level and security requirements. Lifestyle and entertainment activities mainly include games, video streaming, and social networking; these activities typically require high network speed and stability but have relatively lower requirements for data security. Financial security activities mainly include mobile banking, mobile payments, and securities trading; these activities have extremely high requirements for data security and privacy protection because they involve users' sensitive information and financial security.

[0003] In related technologies, mobile phones are connected to a single, shared network operated by a mobile carrier to enable internet access. Residential and financial internet access share the same network channel, IP resources, and data links.

[0004] In the process of implementing the embodiments of this disclosure, at least the following problems were found in the related art: Because recreational activities and financial security activities share the same network resources, financial data may be transmitted in an insecure network environment or accessed by malicious applications.

[0005] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this application, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0006] To provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. This summary is not intended as a general commentary, nor is it intended to identify key / important components or describe the scope of protection of these embodiments, but rather as a prelude to the detailed description that follows.

[0007] This disclosure provides a method, system, apparatus, and electronic device for deploying profiles to improve the security of user financial data.

[0008] In some embodiments, the method for deploying a Profile includes: in response to a user's subscription to a service plan, obtaining a Profile encryption package; the Profile encryption package includes a financial-specific Profile associated with a financial-specific network and a general-purpose Profile associated with a general-purpose network; the financial-specific Profile and the general-purpose Profile are bound to the same user number; the financial-specific Profile is written to a secure storage area, the general-purpose Profile is written to a non-secure storage area, and the financial-specific Profile and the general-purpose Profile are activated; the application startup status is monitored, and the current Profile is switched to either the financial-specific Profile or the general-purpose Profile based on the target application being launched; based on the data type of the target application, financial data is stored in the secure storage area, and general-purpose data is stored in the non-secure storage area.

[0009] Optionally, the Profile encryption package is generated by the operator; the operator generates the Profile encryption package in the following manner: establish a logically isolated financial dedicated network and a general life network; configure a Profile association template in SM-DP+; the Profile association template includes a financial dedicated Profile and a general life Profile; in response to a request to obtain the Profile encryption package, the operator generates the Profile encryption package based on the user number through the Profile association template.

[0010] Optionally, obtaining the Profile encrypted packet includes: establishing a TLS1.3 secure channel with SM-DP+ and completing bidirectional authentication with SM-DP+; after successful authentication, obtaining the Profile encrypted packet transmitted by SM-DP+ through the TLS1.3 secure channel.

[0011] Optionally, the financial profile is written to the secure storage area, and the ordinary profile is written to the insecure storage area. The financial profile and the ordinary profile are then activated. This includes: calling the multi-profile parallel write interface to write the financial profile and the ordinary profile to the secure storage area and the insecure storage area, respectively; wherein the financial profile needs to be verified before writing; and in response to the collaborative activation command, the financial profile and the ordinary profile are activated simultaneously.

[0012] Optionally, the system monitors the application startup status and switches the current profile to either a financial-specific profile or a general lifestyle profile based on the target application being launched. This includes: when launching the target application, determining whether the target application belongs to a preset whitelist of financial scenario applications; if the target application belongs to the whitelist of financial scenario applications, switching the current profile to the financial-specific profile, and if the target application is out of the background for more than a preset time, switching the financial-specific profile to a general lifestyle profile; and if the target application does not belong to the whitelist of financial scenario applications, switching the current profile to a general lifestyle profile.

[0013] Optionally, the method for deploying a profile also includes: if the target application is on the whitelist of financial scenario applications and a financial-specific profile is unavailable, switching the current profile to a general life profile, encrypting the data of the target application, and prompting the user.

[0014] Optionally, the method for deploying a profile further includes: updating the network parameters of the financial-specific profile and the general-purpose profile in response to a remote update command from SM-DP+; and / or periodically verifying the integrity of the financial-specific profile and the general-purpose profile, stopping the use of the financial-specific profile and sending an alarm message to the operator if the financial-specific profile is detected to have been tampered with; and / or switching the current profile in response to a user's profile switching command.

[0015] In some embodiments, the system for deploying Profiles includes: a device MEP module configured to obtain a Profile encryption package in response to a user's package application; the Profile encryption package includes a financial-specific Profile associated with a financial-specific network and a general-purpose Profile associated with a general-purpose network; the financial-specific Profile and the general-purpose Profile are bound to the same user number; and the financial-specific Profile is written to a secure storage area, the general-purpose Profile is written to an insecure storage area, and the financial-specific Profile and the general-purpose Profile are activated; an application scenario identification module configured to monitor the application startup status and switch the current Profile to either the financial-specific Profile or the general-purpose Profile based on the target application being launched; and a data isolation module configured to store financial data in a secure storage area and store general-purpose data in an insecure storage area based on the data type of the target application.

[0016] In some embodiments, the apparatus for deploying a profile includes a processor and a memory storing program instructions, the processor being configured to execute the method for deploying a profile as described above when the program instructions are executed.

[0017] In some embodiments, the electronic device includes: an electronic device body; and a system for deploying a profile as described above or an apparatus for deploying a profile as described above, which is mounted on the electronic device body.

[0018] The method, system, apparatus, and electronic device for deploying profiles provided in this disclosure can achieve the following technical effects: In this embodiment, the financial-specific profile and the general profile are bound to the same user number, but connected to separate financial and general networks, achieving network isolation and ensuring the security of financial data transmission, thus preventing the sharing of the same network channel with personal data. Writing the financial-specific profile and the general profile to secure and insecure storage areas respectively achieves dual isolation of network and data. Storing financial data in the secure storage area and personal data in the insecure storage area prevents malicious applications from accessing financial data, improving the security of user financial data. Furthermore, automatically switching the current profile by monitoring application startup status avoids the tedious manual switching operation and reduces security risks caused by improper user operation.

[0019] The above general description and the description below are exemplary and illustrative only and are not intended to limit this application. Attached Figure Description

[0020] One or more embodiments are illustrated by way of example with reference to the accompanying drawings. These illustrations and drawings do not constitute a limitation on the embodiments. Elements having the same reference numerals in the drawings are shown as similar elements. The drawings are not to be scaled. And wherein: Figure 1 This is a schematic diagram of a method for deploying a Profile provided in an embodiment of this disclosure; Figure 2 This is a schematic diagram of a method for generating a Profile encrypted package provided in an embodiment of this disclosure; Figure 3 This is a schematic diagram of another method for deploying a Profile provided in an embodiment of this disclosure; Figure 4 This is a schematic diagram of a system for deploying Profiles provided in an embodiment of this disclosure; Figure 5This is a schematic diagram of another system for deploying Profiles provided in this disclosure embodiment; Figure 6 This is a schematic diagram of an apparatus for deploying a profile provided in an embodiment of this disclosure. Detailed Implementation

[0021] To provide a more detailed understanding of the features and technical content of the embodiments of this disclosure, the implementation of the embodiments of this disclosure will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for illustrative purposes only and are not intended to limit the embodiments of this disclosure. In the following technical description, for ease of explanation, several details are used to provide a full understanding of the disclosed embodiments. However, one or more embodiments may still be implemented without these details. In other cases, well-known structures and devices may be simplified in their depiction to simplify the drawings.

[0022] The terms "first," "second," etc., used in the technical solutions described in this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this disclosure described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion.

[0023] Unless otherwise stated, the term "multiple" means two or more.

[0024] In this embodiment of the disclosure, the character " / " indicates that the objects before and after it are in an "or" relationship. For example, A / B means: A or B.

[0025] The term "and / or" describes an association between objects, indicating that three relationships can exist. For example, A and / or B means: A or B, or A and B.

[0026] The term "correspondence" can refer to an association or binding relationship. The correspondence between A and B means that there is an association or binding relationship between A and B.

[0027] Combination Figure 1 As shown, this disclosure provides a method for deploying a Profile. The execution entity of this method can be a processor of an electronic device, including devices that support eUICC (Embedded Universal Integrated Circuit Card) functionality, such as smartphones, tablets, smartwatches, and IoT terminals. The method includes: S101, the processor responds to the user's package application operation and obtains the Profile encrypted package; the Profile encrypted package includes the financial exclusive profile associated with the financial exclusive network and the ordinary life profile associated with the ordinary life network.

[0028] The financial profile and the general profile are linked to the same user number.

[0029] S102, the processor writes the financial-specific profile to the secure storage area and the ordinary profile to the insecure storage area, and then activates both the financial-specific profile and the ordinary profile.

[0030] S103: The processor monitors the application startup status and switches the current profile to either a financial profile or a general lifestyle profile based on the target application being launched.

[0031] S104, the processor stores financial data in a secure storage area and stores personal data in a non-secure storage area according to the data type of the target application.

[0032] In this embodiment, the financial-specific profile and the general profile are bound to the same user number, but connected to separate financial and general networks, achieving network isolation and ensuring the security of financial data transmission, thus preventing the sharing of the same network channel with personal data. Writing the financial-specific profile and the general profile to secure and insecure storage areas respectively achieves dual isolation of network and data. Storing financial data in the secure storage area and personal data in the insecure storage area prevents malicious applications from accessing financial data, improving the security of user financial data. Furthermore, automatically switching the current profile by monitoring application startup status avoids the tedious manual switching operation and reduces security risks caused by improper user operation.

[0033] Optionally, the Profile encryption package is generated by the operator; the operator generates the Profile encryption package in the following manner: establish a logically isolated financial dedicated network and a general life network; configure a Profile association template in SM-DP+; the Profile association template includes a financial dedicated Profile and a general life Profile; in response to a request to obtain the Profile encryption package, the operator generates the Profile encryption package based on the user number through the Profile association template.

[0034] Combination Figure 2As shown in the embodiments of this disclosure, a method for generating a Profile encrypted packet is provided. The subject executing this method may be an operator, and the method includes: S201, operators build a logically isolated financial-dedicated network and a general-purpose network for daily life.

[0035] S202, the operator configures profile association templates in SM-DP+; profile association templates include financial-specific profiles and general life profiles.

[0036] S203, In response to the request to obtain the Profile encrypted package, the operator generates the Profile encrypted package based on the user's number using the Profile association template.

[0037] In this embodiment, network-level security isolation is achieved by establishing logically isolated dedicated financial networks and ordinary residential networks. Financial data is transmitted in independent network channels, avoiding the sharing of the same network channel with residential data, significantly reducing the risk of data leakage. Furthermore, the dedicated financial network can be optimized for the low latency and high reliability requirements of financial transactions, while the ordinary residential network can be optimized for bandwidth and latency to meet the needs of entertainment and social applications. By configuring profile association templates in SM-DP+ (Subscription Manager - Data Preparation), the binding and management of dedicated financial profiles and ordinary residential profiles are realized. Users can use two different networks under the same number, eliminating the need for multiple phone numbers and reducing communication costs. Operators can centrally manage profile association templates through SM-DP+, facilitating easy updates and maintenance of profile configurations. Finally, encrypted profile packages are generated from the profile association templates, ensuring secure transmission and deployment of the profile.

[0038] Optionally, the financial-dedicated network is an independent 5G / 6G network slice or an independent APN (Access Point Name), with core network nodes physically isolated from ordinary residential networks, and supports end-to-end encryption.

[0039] Optionally, the standalone network slice includes: a 5G URLLC (5G Ultra-Reliable Low-Latency Communication Slice) slice, with the slice identifier S-NSSAI=1122.

[0040] Optionally, the independent APN includes: CM-FIN (Customized Mobile Financial Network Identifier).

[0041] Optionally, the core network nodes of the financial dedicated network include: core network AMF (Access and Mobility Management Function) and UPF (User Plane Function).

[0042] Optionally, the financial-dedicated network supports end-to-end IPsec (Internet Protocol Security) encryption.

[0043] Optionally, a financial-dedicated network may only allow financial data transmission.

[0044] Alternatively, the ordinary network for daily use is an existing shared network slice of the operator or a public APN.

[0045] Optionally, the shared network slice includes: a 5G eMBB (5G Enhanced Mobile Broadband Slice) slice, with the slice identifier S-NSSAI=3344.

[0046] Optionally, ordinary residential networks support the transmission of non-sensitive data such as daily entertainment and social interactions.

[0047] Optionally, the financial-specific profile can be associated with the slice parameters of the financial-specific network (S-NSSAI, DNN=CM-FIN), the financial data encryption key (such as AES-256), and access permissions can be granted only to financial applications.

[0048] Optionally, the slice parameters (S-NSSAI, DNN=CMNET) of the ordinary life profile are associated with the ordinary life network, and the life data storage rules are opened to full application access.

[0049] Optionally, the financial profile and the general profile share the same IMSI (International Mobile Subscriber Identity), Ki (Authentication Key), and OPC (Operator Password Code). The only differences between the financial profile and the general profile are network parameters and security policies.

[0050] Optionally, the user's package application process includes: the user applies for a package through the operator's channels (APP / business hall), submits identity verification information (mobile phone number, ID card number) and device eUICC identifier; after the operator's system verifies the information, it sends a Profile encrypted packet retrieval request to SM-DP+, the request containing the user's number, EID (Embedded Identity), and Profile associated template ID.

[0051] Optionally, obtaining the Profile encrypted packet includes: establishing a TLS1.3 secure channel with SM-DP+ and completing bidirectional authentication with SM-DP+; after successful authentication, obtaining the Profile encrypted packet transmitted by SM-DP+ through the TLS1.3 secure channel.

[0052] In this embodiment, establishing a TLS 1.3 (Transport Layer Security Protocol Version 1.3) secure channel ensures the confidentiality and integrity of data transmission. TLS 1.3 provides a strong encryption mechanism, effectively resisting man-in-the-middle attacks and data leakage risks. Furthermore, TLS 1.3 optimizes the handshake process, reducing connection establishment time and improving data transmission efficiency. Two-way authentication with SM-DP+ ensures the legitimacy of both communicating parties. This two-way authentication mechanism ensures that only legitimate devices can obtain the Profile encryption packet from SM-DP+, preventing unauthorized devices from accessing the network. After two-way authentication, obtaining the Profile encryption packet through the secure channel ensures the security and integrity of the Profile data. From generation to transmission to deployment, the Profile encryption packet remains encrypted, ensuring data security at every stage.

[0053] Optionally, two-way authentication includes: device verification of the SM-DP+ certificate, and SM-DP+ verification of the eUICC certificate.

[0054] Optionally, the financial profile is written to the secure storage area, and the ordinary profile is written to the insecure storage area. The financial profile and the ordinary profile are then activated. This includes: calling the multi-profile parallel write interface to write the financial profile and the ordinary profile to the secure storage area and the insecure storage area, respectively; wherein the financial profile needs to be verified before writing; and in response to the collaborative activation command, the financial profile and the ordinary profile are activated simultaneously.

[0055] In this embodiment, data storage isolation is achieved by writing a financial-specific profile to a secure storage area and a general-purpose profile to a non-secure storage area. Financial data is stored in a highly secure area, preventing malicious programs from accessing or tampering with it and significantly reducing the risk of data leakage. Non-sensitive general-purpose data is stored in a regular area, avoiding waste of high-security storage resources and improving device storage efficiency. Efficient deployment of both financial-specific and general-purpose profiles is achieved by calling a multi-profile parallel write interface. Verification is performed before writing the financial-specific profile to ensure its integrity and legitimacy, preventing the injection of malicious profiles. The simultaneous activation of both the financial-specific and general-purpose profiles in response to a collaborative activation command ensures the availability of both profiles.

[0056] Optionally, the financial profile may be verified, including by using biometrics or a PIN (Personal Identification Number) to access the financial profile.

[0057] Optionally, the system monitors the application startup status and switches the current profile to either a financial-specific profile or a general lifestyle profile based on the target application being launched. This includes: when launching the target application, determining whether the target application belongs to a preset whitelist of financial scenario applications; if the target application belongs to the whitelist of financial scenario applications, switching the current profile to the financial-specific profile, and if the target application is out of the background for more than a preset time, switching the financial-specific profile to a general lifestyle profile; and if the target application does not belong to the whitelist of financial scenario applications, switching the current profile to a general lifestyle profile.

[0058] Combination Figure 3 As shown in the embodiments of this disclosure, another method for deploying a Profile is provided, including: S301, the processor responds to the user's package application operation by obtaining a Profile encrypted package; the Profile encrypted package includes a financial exclusive profile associated with the financial exclusive network and a life ordinary profile associated with the ordinary life network.

[0059] S302: The processor writes the financial-specific profile to the secure storage area and the ordinary profile to the insecure storage area, and then activates both the financial-specific profile and the ordinary profile.

[0060] S303: When the processor starts the target application, it determines whether the target application belongs to the preset financial scenario application whitelist. If it does, it executes S304; otherwise, it executes S306.

[0061] S304: The processor switches the current profile to a financial-specific profile and stores the financial data in a secure storage area.

[0062] S305, the processor determines whether the target application has been out of the background for more than a preset time. If so, it executes S306.

[0063] S306, the processor switches the current profile to a normal life profile and stores the life data in the insecure storage area.

[0064] In this embodiment, intelligent network management is achieved by monitoring the application's startup status and automatically switching profiles according to preset rules. If the target application is on the financial scenario application whitelist, it automatically switches to the financial-specific profile. If the target application is not on the financial scenario application whitelist, it switches to the general user profile. By automatically switching to the financial-specific profile in financial scenarios, the security of financial data is ensured. The use of the financial-specific profile and the network ensures the security of financial data during transmission and storage, preventing malicious programs from eavesdropping and attacking. Background management is achieved by setting a preset timeout for the target application to exit the background. When the financial application exits the background for more than the preset timeout (e.g., 5 minutes), the device automatically switches the profile back to the general user profile, ensuring that the device can use the public network in non-financial scenarios.

[0065] Optionally, applications included in the financial scenario application whitelist include: mobile banking apps, Alipay / WeChat payment plugins, and securities apps.

[0066] Optionally, applications not included in the financial application whitelist include: games / social apps.

[0067] Optionally, in this embodiment of the disclosure, a financial-specific profile and a general-purpose profile are online simultaneously. The electronic device can select different line profiles to perform network access authentication and other operations on different lines, thereby achieving profile switching.

[0068] In this embodiment, two profiles are online simultaneously, allowing the device to flexibly choose which profile to use as needed, thereby improving resource utilization. This avoids the latency and resource waste caused by frequent profile activation and deactivation, thus improving the overall performance of the device.

[0069] Optionally, the current profile can be switched to a financial-specific profile, including: switching the device to the operating environment of the financial-specific profile and suspending the normal life profile; performing network authentication between the financial modem connected to the financial-specific PDN network and the financial-specific Prifle; and using the financial-specific PDN network to handle network traffic data while simultaneously transmitting data via the financial-specific network. Furthermore, the financial modem connected to the financial-specific PDN network can read data from the secure storage area.

[0070] Optionally, the current profile can be switched to a standard lifestyle profile, including: switching the device to the standard lifestyle profile's operating environment and suspending the financial profile; performing network authentication between the lifestyle modem connected to the standard lifestyle network PDN and the standard lifestyle profile; handling network traffic data through the standard lifestyle network PDN connection and simultaneously using the standard lifestyle network for transmission. Furthermore, the lifestyle modem connected to the standard lifestyle network PDN can read data from insecure storage areas.

[0071] Optionally, the method for deploying a profile also includes: if the target application is on the whitelist of financial scenario applications and a financial-specific profile is unavailable, switching the current profile to a general life profile, encrypting the data of the target application, and prompting the user.

[0072] In this embodiment, when the financial-specific profile becomes unavailable, the system switches to a general-purpose profile, ensuring users can continue to use related services and enhancing the system's fault tolerance. Data transmission security is ensured by encrypting the data of the target application. Even if the financial-specific profile is unavailable, data encryption effectively protects the confidentiality and integrity of financial data. Users are notified of the current profile status, such as "Current financial network unavailable, encrypted transmission enabled," enhancing their awareness of the security status. Through flexible degradation strategies, service availability is ensured while maximizing data security.

[0073] Optionally, the data of the target application may be encrypted, including encrypting the data of the target application using AES-256 (Advanced Encryption Standard with a 256-bit key) or the Chinese national cryptographic algorithm SM4.

[0074] Optionally, financial data includes all data generated by financial applications (such as payment messages and account information), which can only be accessed by financial-specific profiles; lifestyle data includes all data generated by lifestyle applications, which can only be accessed by ordinary lifestyle profiles.

[0075] Optionally, the method for deploying a profile further includes: updating the network parameters of the financial-specific profile and the general-purpose profile in response to a remote update command from SM-DP+; and / or periodically verifying the integrity of the financial-specific profile and the general-purpose profile, stopping the use of the financial-specific profile and sending an alarm message to the operator if the financial-specific profile is detected to have been tampered with; and / or switching the current profile in response to a user's profile switching command.

[0076] In this embodiment, network parameters for both the financial-specific profile and the general-purpose profile are updated promptly in response to remote update commands from SM-DP+. Operators can dynamically update profile parameters based on network optimization or security needs, eliminating the need for manual user intervention. This remote update mechanism ensures the device always uses the latest network configuration, improving system responsiveness and security. The integrity of both the financial-specific profile and the general-purpose profile is periodically verified to ensure they have not been tampered with. Regular verification promptly detects and prevents tampering, ensuring profile security and reliability. Upon detection of tampering, the device immediately stops using that profile to prevent further escalation of potential security risks. Alarm information is sent to the operator, facilitating timely action such as re-issuing the profile or investigating the cause of the tampering. The device also responds to user profile switching commands, allowing users to manually switch their currently used profile. Users can switch profiles at any time according to their needs (e.g., financial transactions or entertainment), improving device usability and user satisfaction.

[0077] Optionally, update the network parameters for the financial-specific profile and the general profile, including obtaining the difference update parameters for SM-DP+. This way, only the difference parameters are updated, without needing to re-download the complete profile.

[0078] The method for deploying a profile provided in this disclosure will be described below with a specific embodiment.

[0079] First, the operator network is built, deploying two types of 5G network slices: a dedicated financial slice and a general-purpose residential slice. The dedicated financial slice has S-NSSAI=1122, DNN=CM-FIN, and physically independent UPF nodes. It only allows financial data transmission within the 10.100.0.0 / 16 IP range and supports end-to-end IPsec encryption. The general-purpose residential slice has S-NSSAI=3344, DNN=CMNET, uses shared UPF nodes, and supports data transmission across the entire IP range. Then, create a "Profile Association Template V1.0" in SM-DP+. Within the template, configure the slice parameters (S-NSSAI=1122, DNN=CM-FIN) and secure storage path ( / SE / Finance / ) for the financial-specific Profile, and the slice parameters (S-NSSAI=3344, DNN=CMNET) and regular storage path ( / Data / Life / ) for the general life Profile. Both Profiles share IMSI=460011234567890 and Ki=ABCDEF1234567890. The smartphone comes pre-installed with the MEPV3.0 module (supporting dual-profile collaborative activation), an application scenario recognition module (with a built-in whitelist of financial scenario applications: ICBC APP, Alipay), and a data isolation module (supporting targeted storage path allocation).

[0080] Then, during the user's package selection phase, they choose the "One Number, Dual Networks - Financial Security Package" in the "Operator APP," enter their mobile phone number and ID card number, and upload a facial photo to complete real-name authentication. The operator's system connects to the public security facial recognition system. After successful verification, it sends a request to SM-DP+: "User, EID, Template ID=V1.0." SM-DP+ generates a Profile encrypted package (approximately 80KB in size, containing complete configurations for financial and lifestyle profiles) and an activation QR code (index=PKG-FIN-20250501-001, signature=SHA256withECDSA, valid for 15 minutes). The user opens the "Operator APP" on their phone and scans the QR code. The APP calls the MEP (Mobile Equipment Environment) module, and the MEP establishes a TLS 1.3 channel with SM-DP+. The MEP sends the mobile eUICC certificate (issued by the operator's CA), and SM-DP+ verifies the certificate's legitimacy. After SM-DP+ authenticates with eUICC via LPAD (Local Profile Assistant Daemon), it transmits an encrypted package to eUICC, thus completing the download and installation of dual profiles. The financial-specific profile is then written to the secure storage area; the general-purpose profile is written to the insecure storage area. MEP sends a "cooperative activation" command, and eUICC simultaneously activates both profiles, establishing two PDN connections: PDN1 is the financial-specific network, IP=10.100.1.5, status "activated"; PDN2 is the general-purpose network, IP=10.200.3.8, status "activated". A pop-up message on the phone indicates "Dual network activation successful; the general-purpose network is currently used by default."

[0081] During user interaction, if a user taps the "ICBC APP" on their phone's home screen, the application scenario recognition module detects that the APP is on the whitelist and immediately sends a "switch to financial-specific profile" command to the MEP (Mobile Electronic Provider). When a user performs a "transfer of 1000 yuan" operation within the ICBC APP, after the transfer message is generated, the data isolation module stores the message in the phone's secure storage area and transmits it to the financial-specific network via PDN1, using AES-256 encryption during transmission. When the user exits the ICBC APP and opens a game APP, the application scenario recognition module detects a non-whitelisted application and sends a "switch to general-purpose profile" command to the MEP. Game data is transmitted via PDN2 and stored in the regular storage area, using the general-purpose network throughout.

[0082] Furthermore, when a user travels to a remote area, the dedicated financial network signal may be weak. Upon detecting a PDN1 connection interruption, the device immediately triggers a downgrade mechanism, keeping PDN2 active and enabling "additional encryption for financial data" (SM4 algorithm). Simultaneously, a pop-up message appears on the phone stating, "Financial network unavailable. Local network encryption has been enabled. Please be aware of security." After the user completes the transfer, the device records the downgrade event and synchronizes it to the operator's system. The operator then pushes a "Financial Profile Network Parameter Update Package" (adjusting S-NSSAI to backup slice 1123) to the user via SM-DP+. Upon receiving this package, the MEP only updates the slice parameters of the financial profile, eliminating the need for re-downloading; the update takes less than 3 seconds.

[0083] Combination Figure 4 As shown in the illustration, this disclosure provides a system 400 for deploying profiles, including: a device MEP module 401, an application scenario identification module 402, and a data isolation module 403. The device MEP module is configured to, in response to a user's package application operation, obtain a profile encryption package; the profile encryption package includes a financial-specific profile associated with a financial-specific network and a general-purpose profile associated with a general-purpose network; the financial-specific profile and the general-purpose profile are bound to the same user number; and the financial-specific profile is written to a secure storage area, the general-purpose profile is written to an insecure storage area, and both the financial-specific profile and the general-purpose profile are activated. The application scenario identification module is configured to monitor the application startup status and switch the current profile to either the financial-specific profile or the general-purpose profile based on the target application being launched. The data isolation module is configured to, based on the data type of the target application, store financial data in a secure storage area and store general-purpose data in an insecure storage area.

[0084] Combination Figure 5 As shown in the embodiments of this disclosure, the device MEP module 401, application scenario identification module 402, and data isolation module 403 can be configured in the eUICC device 501. The eUICC device has a built-in secure storage area and a non-secure storage area, which respectively store financial-specific profiles and ordinary life profiles, supporting parallel activation and integrity verification of dual profiles. The device MEP module is responsible for interacting with SM-DP+ to download dual profiles, collaboratively activating dual profiles, and executing profile switching commands. The application scenario identification module monitors the application startup status in real time through a preset financial application whitelist and triggers profile switching commands. The data isolation module restricts cross-profile data access by selectively allocating storage areas for financial data or life data, ensuring data isolation.

[0085] Optionally, combined Figure 5 As shown, the system used to deploy Profiles also includes: Carrier 502. The Carrier communicates with the eUICC device. The Carrier includes: Carrier Distributed Network Layer 503, SM-DP+ Server 504, and Carrier Business System 505. The Carrier Distributed Network Layer includes a dedicated financial network (independent slice / APN, isolated core network nodes) and a general residential network (shared slice / APN), achieving logical isolation and independent operation and maintenance of the two types of networks. The SM-DP+ Server stores "Profile association templates," generates Profile encrypted packages and activation credentials, and supports differential updates between dual Profiles. The Carrier Business System is responsible for user identity verification (interfacing with the public security real-name authentication system), package management, and forwards Profile generation requests to SM-DP+.

[0086] The method and system for deploying profiles provided in this disclosure achieve dual isolation of network and data, significantly improving security. The dedicated financial network is physically isolated from the residential network, and financial data is stored in a secure storage area, preventing malicious programs from eavesdropping and reading it in residential scenarios, reducing the risk of financial data leakage by more than 90%. The two profiles share the same user number, eliminating the need for multiple numbers and reducing communication costs by 50%; a single download allows for long-term reuse, avoiding redundant configuration and improving operational efficiency by 80%. Profiles are automatically switched based on application startup status, requiring no manual user operation; response latency in financial scenarios is less than 1 second, avoiding security risks caused by forgotten operations. Through the differentiated service of "dedicated financial network + dual profiles," operators can launch high-value-added security packages (such as "financial security packages"), enhancing user stickiness and differentiating themselves from traditional shared network services. It supports 5G / 6G network slicing and national cryptographic algorithms, and can be extended to IoT financial terminals (such as smart POS and in-vehicle payment devices), adapting to the secure network needs of multiple industries.

[0087] Combination Figure 6 As shown, this disclosure provides an apparatus 600 for deploying a profile, including a processor 601 and a memory 602. Optionally, the apparatus may further include a communication interface 603 and a bus 604. The processor 601, communication interface 603, and memory 602 can communicate with each other via the bus 604. The communication interface 603 can be used for information transmission. The processor 601 can invoke logical instructions in the memory 602 to execute the method for deploying a profile as described in the above embodiments.

[0088] Furthermore, the logic instructions in the aforementioned memory 602 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium.

[0089] The memory 602, as a computer-readable storage medium, can be used to store software programs and computer-executable programs, such as program instructions / modules corresponding to the methods in the embodiments of this disclosure. The processor 601 executes functional applications and data processing by running the program instructions / modules stored in the memory 602, that is, it implements the method for deploying the Profile in the above embodiments.

[0090] The memory 602 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the terminal device. Furthermore, the memory 602 may include high-speed random access memory and may also include non-volatile memory.

[0091] This disclosure provides an electronic device, including: an electronic device body, and the aforementioned means for deploying a profile. The means for deploying the profile is installed in the electronic device body. The installation relationship described herein is not limited to placement inside the electronic device, but also includes installation connections with other components of the electronic device, including but not limited to physical connections, electrical connections, or signal transmission connections. Those skilled in the art will understand that the means for deploying the profile can be adapted to feasible electronic device bodies to achieve other feasible embodiments.

[0092] This disclosure provides a computer-readable storage medium storing computer-executable instructions configured to perform the above-described method for deploying a profile.

[0093] The technical solutions of this disclosure can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes one or more instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in this disclosure. The aforementioned storage medium can be a non-transitory storage medium, including: a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and other media capable of storing program code.

[0094] The foregoing description and accompanying drawings fully illustrate embodiments of this disclosure to enable those skilled in the art to practice them. Other embodiments may include structural, logical, electrical, procedural, and other changes. The embodiments represent only possible variations. Individual components and functions are optional unless explicitly required, and the order of operation may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. Moreover, the terminology used in this application is for describing embodiments only and is not intended to limit the technical solutions described herein. As used in the technical solutions described herein, the singular forms “a,” “an,” and “the” are intended to equally include the plural forms unless the context clearly indicates otherwise. Similarly, the term “and / or” as used herein refers to any and all possible combinations of one or more of the associated listed elements. Additionally, when used in this application, the term "comprise" and its variations "comprises" and / or "comprising" refer to the presence of stated features, integrals, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof. Without further limitations, an element defined by the phrase "comprises a..." does not exclude the presence of other identical elements in the process, method, or apparatus that includes said element. In this document, each embodiment may focus on the differences from other embodiments, and similar or identical parts between embodiments can be referred to mutually. For methods, products, etc., disclosed in the embodiments, if they correspond to the method section disclosed in the embodiments, the relevant parts can be referred to the description of the method section.

[0095] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of this disclosure. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0096] The methods and products disclosed in the embodiments herein (including but not limited to devices and equipment) can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For instance, the division of units may be merely a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of devices or units may be electrical, mechanical, or other forms. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to implement this embodiment according to actual needs. In addition, the functional units in the embodiments of this disclosure may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0097] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than that shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. In the descriptions corresponding to the flowcharts and block diagrams in the accompanying drawings, the operations or steps corresponding to different blocks may also occur in a different order than disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. Each block in a block diagram and / or flowchart, and combinations of blocks in a block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

Claims

1. A method for deploying a Profile, characterized in that, include: In response to the user's package application, a Profile encrypted package is obtained; the Profile encrypted package includes a Financial Exclusive Profile associated with the Financial Exclusive Network and a General Profile associated with the General Life Network; the Financial Exclusive Profile and the General Life Profile are bound to the same user number; Write the financial profile to the secure storage area and the ordinary profile to the insecure storage area, and activate both the financial profile and the ordinary profile. Monitor the application startup status and switch the current profile to a financial profile or a general lifestyle profile based on the target application being launched. Depending on the data type of the target application, financial data is stored in a secure storage area, while personal data is stored in a non-secure storage area.

2. The method according to claim 1, characterized in that, The Profile encryption package is generated by the operator; the operator generates the Profile encryption package in the following manner: Establish a logically isolated financial network and a general public network; Configure profile association templates in SM-DP+; profile association templates include financial-specific profiles and general lifestyle profiles. In response to the request to obtain the encrypted Profile package, the encrypted Profile package is generated based on the user's number using the Profile association template.

3. The method according to claim 2, characterized in that, Obtain the encrypted Profile package, including: Establish a TLS 1.3 secure channel with SM-DP+ and complete two-way authentication with SM-DP+; After successful authentication, the encrypted Profile packet transmitted via SM-DP+ is obtained through the TLS 1.3 secure channel.

4. The method according to claim 1, characterized in that, Write the financial profile to the secure storage area and the general profile to the insecure storage area, and activate both the financial profile and the general profile, including: The multi-profile parallel write interface is called to write the financial profile and the general profile to the secure storage area and the insecure storage area respectively; the financial profile needs to be verified before writing. In response to the collaborative activation command, both the financial profile and the general profile will be activated simultaneously.

5. The method according to claim 1, characterized in that, Monitor application startup status and switch the current profile to a financial-specific profile or a general lifestyle profile based on the target application being launched, including: When launching the target application, determine whether the target application belongs to the preset whitelist of financial scenario applications; If the target application is on the whitelist of financial application scenarios, switch the current profile to the financial profile. If the target application is out of the background for more than a preset time, switch the financial profile to the ordinary profile. If the target application is not on the whitelist of financial application scenarios, switch the current profile to a general life profile.

6. The method according to claim 5, characterized in that, Also includes: If the target application is on the whitelist of financial application scenarios and the financial-specific profile is unavailable, switch the current profile to a general life profile, encrypt the data of the target application, and notify the user.

7. The method according to any one of claims 1 to 6, characterized in that, Also includes: Responding to the remote update command of SM-DP+, update the network parameters of the financial profile and the general profile; And / or, Regularly verify the integrity of the financial profile and the general profile; if the financial profile is detected to have been tampered with, stop using the financial profile and send an alarm message to the operator; and / or, In response to the user's profile switching command, switch the current profile.

8. A system for deploying profiles, characterized in that, include: The device's MEP module is configured to obtain a Profile encrypted package in response to a user's package application. The Profile encrypted package includes a financial exclusive profile associated with the financial exclusive network and a general profile associated with the general life network. The financial exclusive profile and the general life profile are bound to the same user number. And write the financial profile to the secure storage area, write the ordinary profile to the insecure storage area, and activate the financial profile and the ordinary profile. The application scenario identification module is configured to monitor the application startup status and switch the current profile to a financial-specific profile or a general life profile based on the target application being launched. The data isolation module is configured to store financial data in a secure storage area and store personal data in a non-secure storage area, depending on the data type of the target application.

9. An apparatus for deploying a profile, comprising a processor and a memory storing program instructions, characterized in that, The processor is configured to perform the method for deploying a profile as described in any one of claims 1 to 7 when executing the program instructions.

10. An electronic device, characterized in that, include: The electronic device itself; The system for deploying a profile as described in claim 8 or the apparatus for deploying a profile as described in claim 9 is installed on the electronic device body.