Self-authentication method, device and equipment of user identification card and computer storage medium
By autonomously completing the authentication process through the on-chip system of the user identification card, generating and storing service keys, the problem of sensitive SIM card data being exposed in the terminal environment is solved, thereby improving security and applicability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-07
- Publication Date
- 2026-04-14
AI Technical Summary
In existing technologies, the General Bootstrapping Architecture (GBA) authentication scheme of BeiDou short message service exposes core sensitive data in the SIM card to an open and uncontrollable terminal environment, posing a security risk.
The self-authentication method is implemented through the system-on-a-chip of the user identification card. The authentication request is obtained by the communication interface instruction receiving module, the authentication function unit of the system-on-a-chip generates the calculation key, and the business key is generated and stored by the network proxy function unit interacting with the remote authentication server, forming a self-closed-loop system to ensure that sensitive data and key calculations are completed within the card.
It enables sensitive data and key calculations to be completed within the hardware security boundary, avoiding the risk of data leakage on the terminal side, improving security and system maintainability, simplifying terminal design, and enhancing the applicability of user identification cards across different devices.
Smart Images

Figure CN121865262A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of wireless communication technology, and in particular relates to a self-authentication method, apparatus, device and computer storage medium for a user identification card. Background Technology
[0002] Among related technologies, the General Bootstrapping Architecture (GBA) authentication scheme relied upon by the BeiDou short message service is essentially a technical architecture that uses the terminal operating system as the authentication subject. Under this architecture, the terminal operating system needs to directly read the core sensitive data in the Subscriber Identity Module (SIM) to complete key calculation and storage, which exposes the SIM card's critical information to an open and uncontrollable terminal environment, posing a security risk. Summary of the Invention
[0003] This application provides a self-authentication method, apparatus, device, and computer storage medium for a user identification card, which can solve the problem of core sensitive data being exposed to an open and uncontrollable terminal environment.
[0004] In a first aspect, embodiments of this application provide a self-authentication method for a user identification card, applied to a system-on-a-chip (SoC) of the user identification card. The method includes: obtaining an authentication request from a terminal application through a communication interface instruction receiving module of the SoC; generating an authentication key by performing calculations on internally stored authentication data through an authentication function unit of the SoC; interacting with a remote authentication server via a network proxy function unit of the SoC based on the calculation key to obtain authentication results and a service key; storing the service key in the storage area inside the user identification card through a storage management unit of the SoC; and returning the authentication result or encrypted or decrypted data results to the terminal application.
[0005] In one technical solution of this application, before obtaining the authentication request from the terminal application through the communication interface instruction receiving module of the system-on-a-chip, the method further includes: triggering the automatic start of the authentication function unit and data encryption / decryption function unit inside the user identification card according to the power-on event of the user identification card, and completing the service registration in the communication interface instruction receiving module.
[0006] In one technical solution of this application, a service binding instruction is obtained through a communication interface instruction receiving module to establish a binding relationship with a registered service; wherein the service binding instruction is a type of communication interface instruction.
[0007] In one technical solution of this application, a function call instruction is obtained through a communication interface instruction receiving module, which then calls a function interface provided by an authentication function unit or a data encryption / decryption function unit; wherein, the function call instruction is a type of communication interface instruction.
[0008] In one technical solution of this application, the authentication function unit of the on-chip system calculates the authentication data stored internally to generate the calculation key, which includes: reading the preset authentication root key from the secure storage area of the user identification card according to the general authentication mechanism protocol, and performing key derivation operation in combination with random number parameters to generate the calculation key.
[0009] In one technical solution of this application, the authentication result and business key are obtained by interacting with a remote authentication server through the network proxy function unit of the on-chip system based on the computation key. This includes: establishing a secure transport layer connection with the bootstrap service function server through the network proxy function unit, and completing two-way authentication based on the computation key; after successful authentication, obtaining key generation parameters from the bootstrap service function server, and generating a business key inside the user identification card.
[0010] In one technical solution of this application, network interaction further includes: establishing an application layer session with a network application function server through a network proxy function unit, and using a business key to encrypt and transmit application data.
[0011] In one technical solution of this application, the self-authentication method of the user identification card further includes a data encryption and decryption step: obtaining data to be encrypted or decrypted according to the communication interface instruction from the terminal application; encrypting or decrypting the data using the stored business key by the data encryption and decryption function unit inside the user identification card; and returning the result data to the terminal application.
[0012] In one technical solution of this application, the communication interface instructions include service registration instructions, service binding instructions, or function call instructions.
[0013] Secondly, embodiments of this application provide a self-authentication device for a user identification card. The device includes: a communication interface instruction receiving module, a general authentication mechanism authentication module, a network proxy module, a secure storage module, and a data encryption / decryption module. The communication interface instruction receiving module is used to receive and parse communication interface instructions from the terminal operating system; the general authentication mechanism authentication module is used to perform authentication data reading and key calculation within the user identification card; the network proxy module is used to provide network communication capabilities for the authentication module; the secure storage module is used to securely store sensitive data within the user identification card; and the data encryption / decryption module is used to encrypt or decrypt data according to the communication interface instructions. The self-authentication device for the user identification card forms a self-closed-loop system decoupled from the terminal operating system.
[0014] Thirdly, embodiments of this application provide an electronic device, the device including: a processor and a memory, the memory storing computer program instructions, and the processor executing the computer program instructions to implement the self-authentication method of a user identification card as described in any of the above technical solutions.
[0015] Fourthly, embodiments of this application provide a computer storage medium storing computer program instructions, which, when executed by a processor, implement the self-authentication method for a user identification card as described in any of the above technical solutions.
[0016] Fifthly, embodiments of this application provide a computer program product, including a computer program, which, when executed, implements a self-authentication method for a user identification card as described in any of the above technical solutions.
[0017] The user identification card self-authentication method, apparatus, device, and computer storage medium of this application embodiment enable the user identification card's on-chip system to autonomously complete the entire authentication process. Specifically, the authentication function unit within the card independently generates the computation key based on its internally stored authentication data. This ensures that the sensitive key calculation process is completed entirely within the card's secure environment, avoiding the risk of key information leakage at the terminal. Simultaneously, the network proxy function unit directly interacts with the remote authentication server, transforming the user identification card from a component responding to terminal commands into a network entity capable of proactively initiating secure communication. Finally, the storage management unit securely stores the business key within the card, ensuring closed-loop management of the key's lifecycle. The entire process does not require physical contact with the terminal. The entire system, through the collaborative operation of its communication interface command receiving module, authentication function unit, network proxy function unit, and storage management unit, achieves cohesive integration and enhanced security of the authentication function. This effectively decouples the terminal application from the core authentication service, simplifying terminal design, enhancing system maintainability, and improving the applicability and portability of the user identification card across different devices by reducing dependence on the terminal environment's security and processing capabilities. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is one of the structural schematic diagrams of a self-authentication device for a user identification card provided in an embodiment of this application; Figure 2 This is a flowchart illustrating a self-authentication method for a user identification card provided in an embodiment of this application; Figure 3 This is a schematic diagram of the BeiDou short message application service process provided in the embodiments of this application; Figure 4 This is a second schematic diagram of the structure of a self-authentication device for a user identification card provided in an embodiment of this application; Figure 5 This is a schematic diagram of the authentication and data encryption process for BeiDou short message service based on a SIM card, provided in an embodiment of this application. Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0020] The features and exemplary embodiments of various aspects of the present invention will now be described in detail. To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are merely intended to explain the present invention and not to limit the present invention. For those skilled in the art, the present invention can be practiced without some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present invention by illustrating examples of the invention.
[0021] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0022] In order to solve existing technical problems, such as Figures 1 to 6 As shown, embodiments of this application provide a self-authentication method, apparatus, device, and computer storage medium for a user identification card.
[0023] like Figure 1 As shown, Figure 1A schematic diagram of a self-authentication device for a user identification card is shown. The self-authentication device 100 of the user identification card may include a communication interface instruction receiving module 110, a general authentication mechanism authentication module 120, a network proxy module 130, a secure storage module 140, and a data encryption / decryption module 150. The communication interface instruction receiving module 110 receives and parses communication interface instructions from the terminal operating system. The general authentication mechanism authentication module 120 performs authentication data reading and key calculation within the user identification card. The network proxy module 130 provides network communication capabilities for the authentication module. The secure storage module 140 securely stores sensitive data within the user identification card. The data encryption / decryption module 150 encrypts or decrypts data according to the communication interface instructions. The self-authentication device of the user identification card forms a self-closed-loop system decoupled from the terminal operating system.
[0024] In one embodiment, during the operation of the self-authentication device 100 of the user identification card, when an application on the terminal operating system initiates an authentication request via a standardized communication interface command, the communication interface command receiving module 110 first receives and parses the command and distributes it to the corresponding internal module. Subsequently, the general authentication mechanism authentication module 120 is activated, securely reads the preset authentication root key from the secure storage module 140, and performs key calculation within the card to generate a temporary calculation key. The network proxy module 130 establishes a secure connection on behalf of the device with remote authentication servers such as the Bootstrap Service (BSF), completes two-way authentication based on the calculation key, obtains key generation parameters, and finally generates a business key within the user identification card and securely stores it in the secure storage module 140. When data encryption or decryption is required, the data encryption / decryption module 150 calls the business key in the secure storage module 140 to encrypt or decrypt the data submitted by the terminal, and returns the result to the terminal application via the communication interface command receiving module 110. The above closed-loop process is completed autonomously within the user identification card, forming a self-closing system decoupled from the terminal operating system. This operational mechanism, by handling sensitive data reading (executed by module 120), key calculation (completed by module 120), network interaction (module 130), and secure storage (module 140), confines the entire process within hardware security boundaries, achieving the security effect of sensitive data not leaving the SIM card and completely eliminating the risk of core data exposure caused by the terminal operating system acting as the authentication entity. Simultaneously, the device provides services through standardized communication interfaces, allowing terminal applications to invoke security functions without pre-installation or high privileges, achieving complete decoupling from the terminal operating system and effectively solving the development bottleneck of large terminal adaptation workload. Furthermore, the design of storing the service key in the secure storage module 140 ensures compliance with the requirement that the SIM card is not separated during service execution at the hardware level, providing operators with an effective security control measure.
[0025] The self-authentication method for user identification cards provided in the embodiments of this application is described below.
[0026] Figure 2 A flowchart illustrating a self-authentication method for a user identification card according to an embodiment of this application is shown. Figure 1 As shown, this method is applied to a system-on-a-chip (SoC) of a user identification card, and the method may include the following steps: S202, obtains the authentication request from the terminal application through the on-chip system's communication interface instruction receiving module; S204 uses the on-chip system's authentication function unit to perform calculations on the internally stored authentication data to generate an authentication key. S206, based on the calculated key, the system-on-chip network proxy function unit interacts with the remote authentication server to obtain the authentication result and the business key. S208 stores the service key in the storage area inside the user identification card through the on-chip system's storage management unit; S210 returns the authentication result or the encrypted or decrypted data result to the terminal application.
[0027] The self-authentication method for user identification cards provided in this application can enclose the entire authentication process within the user identification card. First, in S202, the on-chip system's communication interface instruction receiving module parses the standard APDU (Application Protocol Data Unit) instruction packets sent by the terminal application, extracts and verifies the service identifier code and parameter length in the instruction header, accurately identifies the authentication request type, completes instruction format conversion, and distributes it to the internal processing unit. Then, in S204, the authentication function unit receives the parsed request, accesses the protected storage area in the embedded secure element through the secure bus, reads the preset operator root key, combines it with a true random number generated by the encryption coprocessor, performs key derivation operations according to the 3GPP standard GBA algorithm, and dynamically generates the computation key used for this session. Subsequently, in S206, the network proxy function unit activates the secure transport layer of the on-chip baseband processor, establishes a two-way authentication channel with the remote Bootstrapping Service Function (BSF), verifies the server's identity through a certificate chain, generates an authentication token based on the computation key to complete key negotiation, extracts key generation parameters from the server's response message, and derives the business key in the card's secure environment. In S208, the storage management unit delineates a secure storage area through the memory protection unit, encrypts the business key using a hardware encryption engine, writes it to the flash memory protection partition, and sets access control policies to ensure that only authenticated functional modules can access the key. Finally, in S210, the on-chip system constructs a standardized response message through the instruction receiving module, adds a digital signature to the processing result, and returns the authentication status code or encrypted business data to the application through the secure channel provided by the terminal operating system. The entire process ensures that sensitive data remains within the chip's security boundary through hardware isolation mechanisms, and atomic data transmission occurs between each step via the on-chip bus, forming a complete trusted execution environment.
[0028] Specifically, the communication interface commands refer to custom APDU (Application Protocol Data Unit) commands, which are the foundation for the interaction between the terminal application and the internal functions of the Subscriber Identity Module (SIM). The self-authentication method in this application begins with the terminal application initiating an authentication request by sending an APDU command, which triggers secure operations within the SIM card. The authentication function unit is specifically the GBA (General Bootstrapping Architecture) authentication module, which performs key calculations based on the inherent authentication data (such as the operator's key) securely stored within the SIM card to generate a temporary calculation key.
[0029] Subsequently, the network proxy function unit uses the computed key to represent the SIM card in directly and securely interacting with the remote authentication server, such as the Bootstrapping Service Function (BSF) and the Network Application Function (NAF). Ultimately, it obtains the service key required for the service and stores it in the card's internal storage area (i.e., the secure storage module).
[0030] This application constructs a self-closing security system completely decoupled from the terminal operating system. By confining the reading of sensitive data, key calculation, network interaction, and key storage entirely within the hardware security boundary of the SIM card chip, the technical effect of sensitive data not leaving the card is achieved, thus enhancing security. Throughout the entire process, the terminal operating system can only trigger instructions and receive results, unable to access any core data or computational logic. This reduces the risk of SIM card core data exposure caused by the terminal operating system acting as the authentication subject, improving the network operator's data security control capabilities. Simultaneously, since the authentication logic is built into the SIM card, it also lays the foundation for it to become a secure "token" that can be invoked by various applications. In other words, by constructing a self-closing security system that completes the entire process from triggering, authentication, interaction to storage within the user identification card, secure interaction is directly and effectively improved. This application confines the reading of sensitive data, key calculation, network interaction, and key storage entirely within the hardware security boundary of the SIM card chip, achieving the goal of sensitive data not leaving the card, fundamentally eliminating the risk of core data exposure caused by the terminal operating system acting as the authentication subject, and improving the network operator's data security control capabilities. Secondly, this self-closed-loop design ensures that the service key physically resides in the SIM card at all times, naturally guaranteeing "no separation between the device and the SIM card" during service use. This solves the compliance problems caused by asynchronous operations and enables operators to effectively and rigidly control service security. Finally, this solution simplifies the role of the terminal operating system to a channel that triggers processes and receives results through standardized communication interface commands (such as APDU), achieving complete decoupling from the terminal OS. This allows security capabilities to be flexibly invoked by various applications as a service, breaking through the development bottleneck of requiring the authentication module to be pre-installed in the underlying system and the large workload of terminal adaptation. This lays a solid foundation for plug-and-play services and ecosystem expansion.
[0031] In the embodiments of this application, before obtaining the authentication request from the terminal application through the communication interface instruction receiving module of the system-on-a-chip, the method further includes: triggering the automatic start of the authentication function unit and data encryption / decryption function unit inside the user identification card according to the power-on event of the user identification card, and completing the service registration in the communication interface instruction receiving module.
[0032] In this embodiment, when the SIM card is powered on, its internal authentication (GBA authentication module) and data encryption / decryption function unit are automatically activated, and it completes service registration with the communication interface instruction receiving module (i.e., APDU instruction receiving module).
[0033] Through a power-on self-startup mechanism, hardware-level secure initialization is achieved, ensuring that the secure environment is built and an initial root of trust is formed before the terminal operating system loads. Functional modules autonomously register with the instruction receiving module, constructing standardized service interfaces. This avoids terminal system intervention in the initialization process and lays the foundation for subsequent service calls. Ultimately, this achieves the "out-of-the-box" plug-and-play characteristic of the security service.
[0034] In the embodiments of this application, a service binding instruction is obtained through a communication interface instruction receiving module to establish a binding relationship with a registered service; wherein, the service binding instruction is a type of communication interface instruction.
[0035] In this embodiment, the terminal application sends a service binding instruction to the user identification card. This instruction is used to establish a binding relationship with a service already registered on the card. It should be noted that the service binding instruction is a specific type of communication interface instruction. The service binding mechanism establishes a dedicated channel between the application and the security service. Call permissions are confirmed through the binding relationship to prevent unauthorized access. Each application needs to be bound individually, achieving isolation and control of service access, ensuring both shared security capabilities across multiple applications and isolation of business data. This ultimately forms a flexible service architecture of "one-time registration, multiple bindings."
[0036] In the embodiments of this application, a function call instruction is obtained through the communication interface instruction receiving module, and the function interface provided by the authentication function unit or the data encryption / decryption function unit is invoked; wherein the function call instruction is a type of communication interface instruction.
[0037] In this embodiment, the terminal application sends a function call command to the user identification card. The functional unit within the SIM card provides the corresponding function interface according to the command. It should be noted that the function call command is a specific type of communication interface command. The function call command abstracts complex security operations into a standardized interface. The application does not need to concern itself with the underlying implementation details; it only needs to send a simple command to trigger the entire process, reducing development complexity and improving code reusability. At the same time, command-based operations facilitate permission management and usage traceability, enhancing system maintainability.
[0038] In the embodiments of this application, the authentication function unit of the on-chip system calculates the authentication data stored internally to generate an authentication key, including: the authentication function unit reads the preset authentication root key from the secure storage area of the user identification card according to the general authentication mechanism protocol, and performs key derivation operation in combination with random number parameters to generate the authentication key.
[0039] In this embodiment, the generation of the computation key may further include the following detailed steps, with the authentication function unit performing operations according to a general authentication mechanism protocol. First, a preset authentication root key is read from the secure storage area. Then, a key derivation operation is performed using random number parameters. Finally, the computation key used in the current session is generated. A hierarchical key derivation structure is adopted to enhance security. The root key is always statically stored in the secure area and does not participate in network transmission. The dynamically generated computation key is limited to use in the current session, achieving forward security. The introduction of random numbers ensures the uniqueness of the key for each session, so even if a key is leaked in a single session, it will not affect the overall system security.
[0040] In the embodiments of this application, based on the computation key, the system-on-chip network proxy function unit interacts with the remote authentication server to obtain the authentication result and the service key, including: establishing a secure transport layer connection with the bootstrap service function server through the network proxy function unit, and completing two-way authentication based on the computation key; after successful authentication, obtaining key generation parameters from the bootstrap service function server, and generating the service key inside the user identification card.
[0041] In this embodiment, network interaction may further include the following detailed steps: The network proxy function unit first establishes a secure transport layer connection with the bootstrapping service function server. After completing two-way authentication based on the computation key, it obtains key generation parameters from the server. Finally, a service key is generated within the user identification card. Network interaction is completed directly within the SIM card, avoiding the risk of terminal relay. Two-way authentication ensures the legitimacy of mutual recognition between the server and the SIM card. Parameter transmission takes place in an encrypted channel to prevent man-in-the-middle attacks. The service key is ultimately generated within the card, ensuring that it never leaves the card. This design places critical computations in a secure environment, reducing the attack surface.
[0042] In embodiments of this application, network interaction further includes: establishing an application layer session with a network application function server through a network proxy function unit, and using a business key to encrypt and transmit application data.
[0043] In this embodiment, network interaction may further include application layer session establishment. An application layer session is established between the network proxy function unit and the network application function server. Application data is encrypted and transmitted using a service key. Application layer encryption provides end-to-end security protection. The service key provides an independent encrypted channel for application data. Even if the network layer is breached, the application data remains protected. This layered security design adapts to the security requirements of different services while maintaining network transmission standard compatibility.
[0044] In the embodiments of this application, the self-authentication method of the user identification card further includes a data encryption and decryption step: obtaining data to be encrypted or decrypted according to the communication interface instruction from the terminal application; encrypting or decrypting the data using the stored business key by the data encryption and decryption function unit inside the user identification card; and returning the result data to the terminal application.
[0045] In this embodiment, the terminal application sends a communication interface command containing data. The data encryption / decryption unit within the user identification card processes the data using a business key. The processing result is returned to the application via a command response. Encryption and decryption functions are encapsulated as a standardized service. The application does not need to implement complex cryptographic algorithms, lowering the development threshold. The business key is managed by a secure system, avoiding storage in insecure environments. All encryption and decryption operations are completed within the card, eliminating the risk of key leakage. Ultimately, this provides transparent security services for the application.
[0046] In the embodiments of this application, the communication interface instructions include service registration instructions, service binding instructions, or function call instructions.
[0047] In this embodiment, the communication interface commands can also include various types. Specifically, they can include service registration commands, service binding commands, and function call commands. Each command corresponds to a different operation type and parameter format. The complete command system covers the entire lifecycle of security management. Service registration commands manage available system functions. Service binding commands control access permissions. Function call commands execute business operations, making security service management standardized and automated. It also facilitates the expansion of new commands to support future functions.
[0048] In the embodiments of this application, the user identification card is a super user identification module card, which has an on-chip operating system and computing power.
[0049] In this embodiment, the user identification card can be a Super User Identification Module (SSIM) card. The Super SIM card possesses an on-chip operating system and independent computing power. These hardware features support the implementation of the self-authentication method. Specifically, dedicated hardware provides a secure execution environment. The on-chip operating system ensures that code execution is not subject to external interference. Independent computing power guarantees the performance of encryption operations. This hardware foundation enables the implementation of complex security algorithms, ultimately forming an integrated hardware and software security solution.
[0050] like Figure 3 As shown, Figure 3 The illustrated process covers a scheme where authentication is led by the terminal operating system, and the specific steps include: S302: BeiDou short message application initiates service authentication; S304: The terminal operating system obtains SIM card data; S306: SIM card returns SIM card data; S308: The terminal operating system initiates GBA authentication; S310: The authentication platform returns authentication parameters; S312: The terminal operating system performs key calculations; S314: The authentication platform verifies the key calculation result; S316: The authentication platform returns the verification result; S318: The terminal operating system stores the key; S320: Return the authentication result; S322: Encryption of business data in BeiDou short message applications; S324: Encrypt data using a key; S326: Returns encrypted data.
[0051] In the above process, Figure 3 The current process begins with the BeiDou short message application initiating a service authentication request to the terminal operating system (S302). The terminal operating system then obtains sensitive data from the SIM card (S304), and the SIM card returns the data to the terminal (S306). Subsequently, the terminal operating system leads the subsequent process, including initiating GBA authentication to the remote authentication platform (S308), receiving authentication parameters (S310), and performing key calculation locally (S312). This causes the core key calculation to be out of the secure environment, constituting secondary data exposure. After the calculation is completed, the terminal sends the result to the authentication platform for verification (S314) and receives the returned result (S316). The verified key is stored on the terminal side (S318). Finally, the terminal notifies the application of the authentication result (S320). When the application needs to encrypt service data (S322), the encryption operation is still performed on the terminal side using the locally stored key (S324), and the generated ciphertext is returned to the application (S326). In the scheme of this application, all sensitive operations are completed in the internal module of the SIM card. This eliminates the need for the SIM card to return sensitive data to the terminal, reducing risk. Simultaneously, the GBA authentication module directly reads the root key from the secure storage module for computation, and the network proxy module interacts with the external server on behalf of the SIM card. The generated service key is ultimately stored back in the secure storage module. Throughout this process, the key materials remain within the SIM chip, preventing sensitive data from being exposed to a relatively open terminal environment.
[0052] like Figure 4 As shown, Figure 4 The technical architecture presented is a visual and concrete representation of the technical solution protected by the claims of this application. Specifically, Figure 4 The interaction between "Application 460" and the card's "User Identification Card System 400" is conducted through the APDU command receiving module 410, which corresponds to the communication interface command receiving function. The authentication process begins with an instruction initiated by the application (corresponding to an authentication request), which is responded to by the GBA authentication module 420 (i.e., the authentication function unit), which reads the "SIM DATA" (i.e., authentication data) from the data storage repository 400 and generates an computation key. Subsequently, the network proxy module 430, on behalf of the SIM card, interacts with the "GBA authentication network element 470" (i.e., the remote authentication server) on the right to complete authentication and generate a service key. This service key (labeled as "key" and "authentication key" in the diagram) is stored in the secure storage module 440 and can be called by the data encryption / decryption module 450 (corresponding to the data encryption / decryption function unit) to encrypt or decrypt the "application data". Finally, the processing result ("authentication result" or "encrypted data") is returned to the application through the same command interface. The "application" on the terminal, i.e. the application on the 460 side, can only trigger the process and obtain the result through a limited number of APDU instructions. It cannot access the sensitive data (such as IMSI, keys) and computing logic inside the card at all, which reflects the technical effect of decoupling from the terminal operating system and ensuring that sensitive data does not leave the card.
[0053] like Figure 5 As shown, Figure 5 This is a schematic diagram of the authentication and data encryption process for BeiDou short message service based on SIM cards. The specific steps include: S500: Initiated by the BeiDou short message application, it sends a service authentication request to the system on the SIM card.
[0054] S510: The system on the SIM card initiates a GBA authentication process to the remote authentication platform; S520: The authentication platform processes the request and returns the authentication parameters required to the system on the SIM card; S530: The system on the SIM card performs key calculations locally using the received parameters; S540: The system on the SIM card sends the calculation result back to the authentication platform for verification; S550: After the authentication platform completes the verification, it will return the verification result; S560: System-stored key on the SIM card; S570: The system on the SIM card returns the authentication result to the BeiDou short message application; S580: The Beidou short message application requests the system on the SIM card to encrypt the service data; S590: The system on the SIM card calls the service key stored therein to encrypt the data; S592: The system on the SIM card returns the encrypted data to the application, thus completing a full business operation.
[0055] In the above process, firstly, the BeiDou short message application initiates a service authentication request (S500), triggering a GBA authentication handshake between the system on the SIM card and the remote authentication platform (S510). This design decouples the service application from the underlying security protocol, reducing the implementation complexity of the service layer. After the authentication platform returns parameters (S520), the system on the SIM card performs key calculation locally (S530). This localized calculation effectively prevents key materials from being intercepted during transmission, improving the security of the key generation stage. Subsequently, a two-way verification mechanism (S540) ensures communication between the two parties. The authentication process ensures the legitimacy of the party's identity; the key is securely stored in the SIM card (S560), fundamentally realizing the security principle of "key not leaving the card" and eliminating the risk of key leakage in the terminal system; the authentication result is returned to the application (S570), establishing a trusted channel at the business level; finally, the end-to-end security of business data is ensured through the in-card encryption mechanism, and the encryption result is returned to the application (S592), thus fully realizing closed-loop security protection from identity authentication to data protection. This process, through layered security design, not only ensures the independent security of each link, but also forms a system-level security enhancement effect through process connection.
[0056] Figure 6 A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown.
[0057] The electronic device 600 may include a processor 601 and a memory 602 storing computer program instructions.
[0058] Specifically, the processor 601 may include a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0059] Memory 602 may include mass storage for data or instructions. For example, and not limitingly, memory 602 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. In one instance, memory 602 may include removable or non-removable (or fixed) media, or memory 602 may be non-volatile solid-state memory. Memory 602 may be internal or external to the integrated gateway disaster recovery device.
[0060] In one instance, memory 602 may be read-only memory (ROM). In one instance, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or flash memory, or a combination of two or more of these.
[0061] The processor 601 implements the self-authentication method of the user identification card in the embodiment by reading and executing computer program instructions stored in the memory 602.
[0062] In one example, electronic device 600 may further include communication interface 603 and bus 604. Wherein, as... Figure 3 As shown, the processor 601, memory 602, and communication interface 603 are connected through bus 604 and complete communication with each other.
[0063] The communication interface 603 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0064] Bus 604 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 604 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.
[0065] The electronic device 600 can execute the self-authentication method of the user identification card in this embodiment of the invention based on data transmission, thereby achieving a combination of... Figure 1 The self-authentication method for user identification cards is described.
[0066] Furthermore, in conjunction with the user identification card self-authentication method in the above embodiments, this invention can be implemented using a computer storage medium. This computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the user identification card self-authentication methods in the above embodiments.
[0067] This application also provides a computer program product, including a computer program that, when executed by a processor, implements any of the user identification card self-authentication methods described in the above embodiments.
[0068] It should be clarified that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the self-authentication method process of the user identification card of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of the present invention.
[0069] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this invention are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, read-only memory (ROM), flash memory, erasable read-only memory (EROM), floppy disks, compact disc read-only memory (CD-ROM), optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0070] It should also be noted that the exemplary embodiments mentioned in this invention describe methods or systems based on a series of steps or apparatus. However, this invention is not limited to the order of the steps described above; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0071] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0072] The above description is merely a specific embodiment of the present invention. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the protection scope of the present invention.
Claims
1. A self-authentication method for a user identification card, characterized in that, The method, applied to a system-on-a-chip (SoC) for a user identification card, includes: The system-on-chip obtains authentication requests from the terminal application through the communication interface instruction receiving module. The authentication function unit of the on-chip system calculates the internally stored authentication data to generate an authentication key. Based on the computation key, the system-on-chip network proxy function unit interacts with the remote authentication server to obtain the authentication result and the business key. The service key is stored in the storage area inside the user identification card through the storage management unit of the on-chip system; The authentication result or the encrypted or decrypted data result is returned to the terminal application.
2. The method according to claim 1, characterized in that, Before obtaining the authentication request from the terminal application through the communication interface instruction receiving module of the on-chip system, the method further includes: Based on the power-on event of the user identification card, the authentication function unit and data encryption / decryption function unit inside the user identification card are automatically activated, and service registration is completed in the communication interface instruction receiving module.
3. The method according to claim 2, characterized in that, Also includes: The service binding instruction is obtained through the communication interface instruction receiving module, and a binding relationship with the registered service is established. The service binding instruction is a type of communication interface instruction.
4. The method according to claim 3, characterized in that, Also includes: The function call instruction is obtained through the communication interface instruction receiving module, and the function interface provided by the authentication function unit or the data encryption / decryption function unit is called. The function call instruction is a type of communication interface instruction.
5. The method according to claim 1, characterized in that, The step of generating a calculation key from the internally stored authentication data through the authentication function unit of the on-chip system includes: The authentication function unit reads the preset authentication root key from the secure storage area of the user identification card according to the general authentication mechanism protocol, and performs key derivation operation in combination with random number parameters to generate the calculation key.
6. The method according to claim 1 or 5, characterized in that, The step of obtaining authentication results and business keys by interacting with a remote authentication server through the network proxy function unit of the on-chip system based on the calculated key includes: The network proxy function unit establishes a secure transport layer connection with the boot service function server and completes two-way authentication based on the computation key. After successful authentication, the key generation parameters are obtained from the bootstrap service function server, and the business key is generated inside the user identification card.
7. The method according to claim 6, characterized in that, The network interaction also includes: The network proxy function unit establishes an application layer session with the network application function server and uses the business key to encrypt and transmit application data.
8. The method according to claim 1, characterized in that, It also includes data encryption and decryption steps: According to the communication interface instructions from the terminal application, obtain the data to be encrypted or decrypted; The data encryption / decryption function unit inside the user identification card uses the stored business key to encrypt or decrypt the data; The results data are returned to the terminal application.
9. The method according to claim 1, characterized in that, The communication interface instructions include service registration instructions, service binding instructions, or function call instructions.
10. A self-authentication device for a user identification card, characterized in that, The self-authentication device of the user identification card is used in the system-on-a-chip of the user identification card, and the device includes: The communication interface instruction receiving module is used to receive and parse communication interface instructions from the terminal operating system. The universal authentication mechanism authentication module is used to perform authentication data reading and key calculation within the user identification card; The network proxy module provides network communication capabilities for the authentication module. A secure storage module is used to securely store sensitive data within the user identification card; The data encryption / decryption module is used to encrypt or decrypt data according to communication interface instructions; The user identification card's self-authentication device forms a self-closed-loop system decoupled from the terminal operating system.
11. An electronic device, characterized in that, It includes a processor and a memory, the memory storing computer program instructions, and the processor, when executing the computer program instructions, implements the self-authentication method for a user identification card as described in any one of claims 1-9.
12. A computer-readable storage medium, characterized in that, The device stores computer program instructions, which, when executed by a processor, implement the self-authentication method for a user identification card as described in any one of claims 1-9.
13. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the self-authentication method for a user identification card as described in any one of claims 1-9.