Terminal binding method and device and terminal

By verifying the card-side and terminal-side binding status before binding the terminal to the identity card, and combining key generation and encryption mechanisms, the security risks in the terminal binding process are resolved, ensuring the security of user privacy and avoiding the risk of identity cards being bound arbitrarily.

CN121908279APending Publication Date: 2026-04-21SPREADTRUM COMM (TIANJIN) INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SPREADTRUM COMM (TIANJIN) INC
Filing Date
2026-02-25
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In existing technologies, the binding method between the terminal and the identity card has security risks, and user privacy information is easily leaked. In particular, when the identity card is lost or stolen, the identity card and the terminal can be arbitrarily bound, leading to the leakage of privacy information.

Method used

By obtaining the card-side identity code and binding status of the identity card, and combining it with the terminal-side binding status, the binding is performed only when the user is qualified to bind. The security of the binding process is ensured by using key generation and encryption mechanisms.

Benefits of technology

This effectively prevents identity cards that have already been bound to a target terminal from being bound to other terminals again, reducing the risk of user privacy information leakage and improving user privacy security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121908279A_ABST
    Figure CN121908279A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, in particular to a terminal binding method and device and a terminal. The method is applied to the terminal and comprises the following steps: acquiring a card side identity code of an identity card and a card side binding state of the identity card; under the condition that the card side binding state represents binding, reading an end side binding identifier from the security area to determine an end side binding state of the terminal, and determining a verification result according to the card side binding state and the end side binding state; and when the verification result is that the terminal has the binding qualification, binding the terminal and the identity card based on the card side identity code. By adopting the method, the security of user privacy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a terminal binding method, apparatus and terminal. Background Technology

[0002] Some terminals need to be bound to a user's identity card such as an eSIM card or SIM card before leaving the factory. In related technologies, the terminal and the identity card can be bound directly without any verification.

[0003] In cases where a user's identity card and / or terminal is stolen or copied, the stolen terminal can be re-bound to another identity card for use, and similarly, a stolen user's identity card can be bound to another terminal for use. Since the identity card may store the user's private information, the device-identity card binding method in this technology poses a significant security risk, and user privacy is at risk of being leaked if the user's identity card is lost.

[0004] Therefore, how to improve the security of user privacy is an urgent problem that needs to be solved. Summary of the Invention

[0005] Therefore, it is necessary to provide a terminal binding method, device, and terminal that can improve user privacy and security in response to the above-mentioned technical problems.

[0006] Firstly, this application provides a terminal binding method applied to a terminal, the method comprising:

[0007] Obtain the card-side identification code of the identity card and the card-side binding status of the identity card;

[0008] If the card-side binding status indicates that the terminal is already bound, the terminal-side binding identifier is read from the secure area to determine the terminal-side binding status, and the verification result is determined based on the card-side binding status and the terminal-side binding status.

[0009] If the verification result indicates that the device is eligible for binding, the terminal is bound to the identity card based on the card-side identity code.

[0010] In one embodiment, the method further includes:

[0011] If the card-side binding status indicates that the card is not bound, the verification result is determined to indicate that the card is qualified to be bound.

[0012] In one embodiment, determining the verification result based on the card-side binding status and the terminal-side binding status includes:

[0013] When the terminal binding status indicates that the terminal is already bound, obtain the target terminal-side identity code of the target terminal that was previously bound to the identity card, and read the terminal-side identity code of the terminal and the target card-side identity code of the target identity card that was previously bound to the terminal from the secure area.

[0014] If the target card-side identity code matches the card-side identity code, and the target terminal-side identity code matches the terminal-side identity code, the verification result is determined to be that the user is qualified to bind the device.

[0015] In one embodiment, binding the terminal and the identity card based on the card-side identity code includes:

[0016] The system receives the initial ciphertext sent by the identity card and decrypts the initial ciphertext using the private key of the first key to obtain the public key of the second key; the initial ciphertext is obtained by the identity card encrypting the public key of the second key based on the public key of the first key.

[0017] A terminal key group is generated based on the public key of the second key, the private key of the third key, and the terminal identity code. Binding authentication information is generated based on the terminal key group, and the binding authentication information is sent to the identity card for binding authentication.

[0018] Based on the authentication result sent by the identity card for the bound authentication information, determine whether the binding was successful.

[0019] In one embodiment, the endpoint key set includes an endpoint encryption key and an endpoint authentication key; the binding authentication information includes a first ciphertext and a first authentication code; generating the binding authentication information based on the endpoint key set includes:

[0020] The public key of the third key is encrypted based on the terminal encryption key to obtain the first ciphertext;

[0021] The first authentication code is generated based on the terminal authentication key and the first ciphertext.

[0022] In one embodiment, the method further includes:

[0023] If the terminal and the identity card are successfully bound, the terminal-side identity code and the terminal-side key group are written into the secure area, and the card-side identity code of the identity card is written into the secure area as the target card-side identity code.

[0024] In one embodiment, the method further includes:

[0025] In the authentication state, the card-side binding status of the connected identity card to be authenticated is obtained, and the terminal-side binding identifier is read from the secure area to determine the terminal-side binding status.

[0026] When both the terminal-side binding status and the card-side binding status of the identity card to be authenticated indicate that they are already bound, the terminal and the identity card to be authenticated are authenticated.

[0027] In one embodiment, the authentication of the terminal and the identity card to be authenticated includes:

[0028] The authentication string sent by the identity card to be authenticated is received, and the authentication string is verified based on the terminal authentication key to obtain the verification result; the authentication string is generated by the identity card to be authenticated based on the card-side authentication key.

[0029] If the verification result is successful, the authentication string is encrypted based on the terminal encryption key to obtain the authentication string, and the authentication string is sent to the identity card to be authenticated.

[0030] Based on the authentication result sent by the identity card to be authenticated, it is determined whether the authentication was successful; the authentication result is determined by the identity card to be authenticated based on the comparison between the decryption result and the authentication string, and the decryption result is obtained by the identity card to be authenticated decrypting the authentication string based on the card-side encryption key.

[0031] Secondly, this application also provides a terminal binding device, the device comprising a card-side information acquisition module, a verification result determination module, and a binding module, wherein:

[0032] The card-side information acquisition module is used to acquire the card-side identity code of the identity card and the card-side binding status of the identity card;

[0033] The verification result determination module is used to read the terminal binding identifier from the security area to determine the terminal binding status when the card-side binding status indicates that the terminal is already bound, and to determine the verification result based on the card-side binding status and the terminal binding status.

[0034] The binding module is used to bind the terminal and the identity card based on the card-side identity code when the verification result indicates that the terminal is qualified to bind.

[0035] Thirdly, this application also provides a terminal, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the terminal binding method as described in any one of the first aspects above.

[0036] Fourthly, this application also provides a chip configured in a terminal, the chip including a processor and a communication interface, the processor being configured to cause the chip to perform the steps of the terminal binding method as described in any one of the first aspects above.

[0037] Fifthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the terminal binding method as described in any one of the first aspects above.

[0038] Sixthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the terminal binding method as described in any one of the first aspects above.

[0039] The aforementioned terminal binding method, device, and terminal, where the card-side binding status indicates that an unbound identity card is qualified to bind with any terminal, means that after obtaining the card-side binding status of the identity card, if the terminal determines that the card-side binding status indicates that it is already bound, the terminal needs to further verify the binding qualification of the identity card by combining its own terminal-side binding status. The purpose of the terminal verifying the card-side binding status by combining its own terminal-side binding status with the card-side binding status is: only if the terminal-side binding status indicates that it is already bound, and the target terminal bound to the identity card is the current terminal, then the verification result is determined that the identity card is qualified to bind with the current terminal; otherwise, the verification result is determined that the identity card is not qualified to bind with the current terminal. This can prevent identity cards that have been bound to a target terminal from being bound to other terminals again, which greatly reduces the probability of identity information of associated users being leaked due to identity cards that have been bound to target terminals being arbitrarily bound, thereby improving the security of user privacy. Attached Figure Description

[0040] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0041] Figure 1 This is a flowchart illustrating a terminal binding method in one embodiment;

[0042] Figure 2 This is a flowchart illustrating the process of determining the verification result in one embodiment;

[0043] Figure 3 This is a logical diagram illustrating the binding of qualification verification in one embodiment;

[0044] Figure 4 This is a schematic diagram of the specific process bound in one embodiment;

[0045] Figure 5 This is a schematic diagram of the authentication process in one embodiment;

[0046] Figure 6 This is an interactive diagram illustrating the authentication qualification verification process in one embodiment.

[0047] Figure 7 This is a schematic diagram illustrating the authentication process in one embodiment.

[0048] Figure 8 This is a structural block diagram of a terminal binding device in one embodiment;

[0049] Figure 9 This is a diagram of the internal structure of a terminal in one embodiment. Detailed Implementation

[0050] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0051] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0052] The terminal binding method provided in this application is applied to a terminal; wherein, an identity card is configured in the terminal, and the terminal can be pre-bound to the identity card; for a successfully bound terminal and identity card, the terminal performs authentication with the identity card, and after the authentication is passed, the terminal can access the operator's network through the identity card to access Internet data.

[0053] The terminals can be, but are not limited to, various personal computers, laptops, smartphones, tablets, drones, low-altitude aircraft, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted displays, etc. Head-mounted displays can include virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc.

[0054] In one exemplary embodiment, such as Figure 1 As shown, a terminal binding method is provided, which is applied to Figure 1 Terminals or applications Figure 1 Taking a chip / chip module with data processing capabilities as an example, the explanation includes the following steps 10-30, wherein:

[0055] Step 10: Obtain the card-side identification code and the card-side binding status of the identity card.

[0056] In this embodiment of the application, when an identity card is connected to the terminal, a binding command can be triggered by the terminal. The terminal, in response to the user-triggered binding command, first performs a binding qualification verification, and then executes the binding task after the verification is successful. At the start of the binding qualification verification, the identity card sends its card-side identity code and card-side binding status to the terminal.

[0057] The identity card can be a SIM card or an eSIM card; the card-side identity code represents the unique identity of the identity card and is assigned by the operator; the card-side binding status indicates whether the card has been bound to the target terminal.

[0058] Step 20: If the card-side binding status indicates that the card is already bound, read the terminal-side binding identifier from the secure area to determine the terminal's terminal-side binding status, and determine the verification result based on the card-side binding status and the terminal-side binding status.

[0059] In the application embodiment, after receiving the card-side binding status of the identity card, the terminal parses the card-side binding status to determine whether the identity card has been bound to the target terminal. The terminal needs to combine its own terminal-side binding status and the identity card's card-side binding status to determine the verification result; the verification result indicates whether the identity card is qualified to be bound to the terminal. The terminal-side binding status indicates whether the terminal has bound the target identity card.

[0060] When the card-side binding status indicates that the unbound identity card is a new card; for a new card, after the user binds the new card to the terminal, the user needs to associate their identity information with the identity card, thereby achieving user-identity card binding on the operator's side to activate the identity card; the card-side binding status indicates that the identity card bound to the terminal is associated with the user's identity information. In other words, the identity card bound to the terminal is associated with the user's private identity information.

[0061] Therefore, in the application embodiment, the verification principle for binding qualification is: first, verify the card-side binding status; for card-side binding status representing an unbound identity card (new card), since the card is not associated with any user's identity information, the identity card is allowed to be bound to any terminal; that is, determine that the current identity card has the qualification to bind with the terminal.

[0062] If the identity card representation is already bound, the terminal needs to further consider the terminal's end-side binding status to determine whether binding can proceed.

[0063] If the card-side binding status indicates that the bound identity card (old card) has been bound, and the terminal-side binding status indicates that the terminal has already bound the target identity card, then it is necessary to further determine whether the target identity card bound to the terminal is the current identity card. If the current identity card is the same as the target identity card bound to the terminal last time, then it is determined that the current identity card is qualified to be bound to the terminal. If the target identity card bound to the terminal is different from the current identity card, then it is determined that the identity card is not qualified to be bound to the terminal.

[0064] Step 30: If the verification result indicates that the device is eligible for binding, bind the terminal and the identity card based on the card-side identity code.

[0065] In the embodiments of this application, when the terminal determines that the current identity card is qualified to be bound to the terminal, the terminal enters the binding process and binds the identity card based on the card-side identity code received from the identity card.

[0066] In the aforementioned terminal binding method, the card-side binding status indicates that an unbound identity card is qualified to bind with any terminal. Therefore, after obtaining the card-side binding status of the identity card, if the terminal determines that the card-side binding status indicates that the identity card is already bound, the terminal needs to further verify the binding qualification of the identity card by combining its own terminal-side binding status. The purpose of the terminal verifying the card-side binding status by combining its own terminal-side binding status with the card-side binding status is: only if the terminal-side binding status indicates that the identity card is already bound, and the target terminal bound to the identity card is the current terminal, then the verification result is determined that the identity card is qualified to bind with the current terminal; otherwise, the verification result is determined that the identity card is not qualified to bind with the current terminal. This can prevent identity cards that have been bound to a target terminal from being bound to other terminals again, which greatly reduces the probability of identity cards that have been bound to a target terminal being arbitrarily bound, leading to the leakage of the associated user's identity information, thereby improving the security of user privacy.

[0067] In one embodiment, reference Figure 2 In step 20, the terminal determines the verification result based on the card-side binding status and the terminal-side binding status, which may specifically include steps 21 and 22, wherein:

[0068] Step 21: Obtain the target terminal-side identity code of the target terminal that was previously bound to the identity card, and read the terminal-side identity code of the terminal and the target card-side identity code of the target identity card that was previously bound to the terminal from the secure area;

[0069] Step 22: If the target card-side identity code matches the card-side identity code, and the target terminal-side identity code matches the terminal-side identity code, then the verification result is determined to be that the user is qualified to bind the device.

[0070] Specifically, in one example scenario, a terminal already bound to a target identity card may need to be returned for factory repair or testing. Upon completion of the repair, the terminal needs to be rebound to the target identity card. During the binding qualification verification process, if the terminal's end-side binding status indicates it is already bound, it is necessary to further verify whether the target terminal bound to the identity card is the current terminal. If it is determined that the identity card undergoing binding qualification verification with the current terminal is indeed the target terminal, then the identity card and the current terminal are deemed to be qualified for binding. Specifically, if the target card's identity code matches the card-side identity code, and the target end-side identity code matches the end-side identity code, then the identity card undergoing binding qualification verification with the current terminal and the current terminal are mutually bound objects.

[0071] Conversely, during the binding qualification verification process, if the terminal's end-side binding status indicates that it is already bound, but the target terminal of the identity card that is being bound to the current terminal is different from the current terminal, then it is determined that the identity card and the current terminal do not have binding qualification.

[0072] By using steps 21 and 22, the terminal and identity card, which are already bound to each other, can be bound again. At the same time, the identity card that has been bound to the target terminal cannot be bound to other terminals besides the target terminal. In this way, the identity information bound to the identity card can be prevented from being read on untrusted terminals, thereby improving the security of user privacy.

[0073] In summary, the binding qualifications corresponding to the card-side state and the terminal-side state are shown in Table (1).

[0074] Table (1)

[0075] The following details the interaction logic between the terminal and the identity card during the binding qualification verification process.

[0076] For terminal environment deployment: A first key (M1) is generated using a security server or HSM (Hardware Security Module). The private key (M1-B) of the first key is provided to the terminal, and the public key (M1-A) of the first key is provided to the identity card (SIM or eSIM). The identity card uses the public key (M1-A) of the first key to encrypt data before sending it to the terminal. The terminal uses the private key (M1-B) of the first key to decrypt the data sent to the terminal by the identity card during the binding qualification verification phase and the binding phase.

[0077] Specifically, the terminal is equipped with a binding authentication identifier when it leaves the factory, and the binding authentication identifier is modified every time a binding or authentication operation is performed; secondly, after the first binding, the terminal stores the terminal-side identity code in the TEE security environment (security zone); finally, the terminal can determine the terminal-side binding status by judging whether the binding integrity identifier and the security zone exist.

[0078] During the qualification verification phase, the interaction process between the terminal and the identity card includes af, where:

[0079] a: The identity card sends its card-side identity code and card-side binding status to the terminal;

[0080] b: The terminal judges the received card binding status (performs binding qualification verification);

[0081] If the card binding status is unbound, allow binding and continue to step c.

[0082] If the card-side binding status is "bound," the terminal checks its own security area for the presence of the terminal's end-side identity code, the target card-side identity code of the bound target identity card, the end-side encryption key, and the end-side authentication key. If at least one of these is missing, it indicates that the device is a new device that has never been bound to a target identity card, and the new device is not allowed to bind to an old card that is already bound.

[0083] If both exist, compare the target identity code of the bound target identity card stored in the secure area of ​​the terminal with the received card-side identity code. If they match, binding is allowed, and step c continues; if they do not match, binding is not allowed.

[0084] c: The terminal reads the binding authentication identifier. If the binding authentication identifier is an initialization identifier, it can be determined without doubt that the terminal has not been bound to any identity card; then the terminal sends its own terminal-side identity code to the identity card, and the identity card saves the received terminal-side identity code. If the terminal's binding authentication identifier is not an initialization identifier, it indicates that the terminal has previously performed authentication, that is, the terminal has been bound to another identity card; then the terminal does not send its own identity code to the identity card and proceeds directly to the next step d.

[0085] d: Generate a second key (M2) from the identity card, or directly read the pre-stored second key (M2).

[0086] e: The identity card uses the public key of the first key (M1-A) to encrypt the public key of the second key (M2-A) and the target terminal's identity code bound to the identity card, and sends the encrypted data to the terminal together;

[0087] f: The terminal compares its own terminal identity code stored in the secure area with the target terminal identity code sent by the received identity card. If the target terminal identity code matches, it indicates that the target identity card bound to the terminal is the current identity card, and binding is allowed. The verification process then ends, and subsequent binding tasks continue. If the target terminal identity code does not match, it indicates that the terminal has bound a target identity card before, but the bound target identity card is different from the current identity card. Binding is then disallowed, and the verification process ends.

[0088] The above step af constitutes the interaction content of the terminal's authentication process for binding the identity card; the terminal's authentication logic for binding the identity card is as follows: Figure 3 As shown.

[0089] The following content further elaborates on the steps involved in binding the terminal and the identity card during the task binding phase.

[0090] In one embodiment, such as Figure 4As shown, step 30 may specifically include steps 31-33, wherein:

[0091] Step 31: Receive the initial ciphertext sent by the identity card, and use the private key of the first key to decrypt the initial ciphertext to obtain the public key of the second key.

[0092] Specifically, the initial ciphertext is obtained by encrypting the public key of the second key (M2-A) with the public key of the first key (M1-A) by the identity card; the identity card sends the initial ciphertext to the terminal to prevent the key from being leaked during transmission.

[0093] Step 32: Generate a terminal key group based on the public key of the second key, the private key of the third key, and the terminal identity code; generate binding authentication information based on the terminal key group; and send the binding authentication information to the identity card for binding authentication.

[0094] Specifically, the terminal-side key set includes a terminal-side encryption key and a terminal-side authentication key; the bound authentication information includes a first ciphertext and a first authentication code. Specifically, the process of the terminal generating the terminal-side key set includes: the terminal calculating the terminal-side session key based on the public key (M2-A) of the second key and the private key (M3-B) of the third key; and the terminal deriving the terminal-side encryption key and the terminal-side authentication key based on the terminal-side identity code and the session key.

[0095] Furthermore, the process of the terminal generating binding authentication information based on the terminal-side key group includes: encrypting the public key (M3-A) of the third key based on the terminal-side encryption key to obtain the first ciphertext; and generating the first authentication code based on the terminal-side authentication key and the first ciphertext.

[0096] Step 33: Determine whether the binding was successful based on the authentication result sent by the identity card for the bound authentication information.

[0097] Specifically, after receiving the binding authentication information, the identity card authenticates the information, including: calculating the card-side session key using the private key (M2-B) of the second key and the public key (M3-B) of the third key; deriving the card-side encryption key and the card-side authentication key using the card-side session key and the terminal identity code. Further, the identity card encrypts the public key (M3-A) of the third key based on the card-side encryption key to obtain the second ciphertext; the identity card calculates the second authentication code of the second ciphertext using the card-side authentication key. The identity card compares the second authentication code with the first authentication code. If they match, the authentication is successful, and the identity card sends a successful authentication result to the terminal; otherwise, the authentication fails, and the identity card sends a failed authentication result to the terminal.

[0098] In one embodiment, after step 33, the terminal is successfully bound to the identity card; when the terminal confirms that the terminal is successfully bound to the identity card, it writes the terminal-side identity code and the terminal-side key group into the secure area, and writes the card-side identity code of the identity card as the target card-side identity code into the secure area.

[0099] In other words, only when the terminal confirms successful binding with the identity card will it save its own terminal identity card, along with the terminal key group and session key calculated during the binding process, to the secure area. The terminal's secure area has a high level of access, making data modification difficult; therefore, by determining whether the terminal's terminal identity code exists in the secure area, the terminal's terminal binding status can be determined.

[0100] The above embodiments describe the steps of the binding qualification verification stage and the binding stage in the process of binding the terminal and the identity card. The following embodiments further illustrate the authentication process between the terminal and the identity card.

[0101] In one embodiment, such as Figure 5 As shown, the authentication process performed by the terminal in the authentication state specifically includes steps 01 and 02, wherein:

[0102] Step 01: In the authentication state, obtain the card-side binding status of the connected identity card to be authenticated, and read the end-side binding identifier from the secure area to determine the end-side binding status of the terminal.

[0103] Step 02: When both the terminal-side binding status and the card-side binding status of the identity card to be authenticated indicate that they are already bound, authenticate the terminal and the identity card to be authenticated.

[0104] Specifically, the terminal enters the authentication state in response to the authentication command triggered by the user. In the authentication state, the terminal first verifies the authentication qualification of the identity card to be authenticated, and after the authentication qualification verification is passed, the terminal executes the authentication steps with the identity card to be authenticated.

[0105] In the authentication and verification phase, the interaction process between the terminal and the identity card to be authenticated is as follows: Figure 6 As shown, where:

[0106] a: The identity card to be authenticated sends its card-side identity code and card-side binding status to the terminal; among them, the identity card to be authenticated communicates directly with the terminal's MODEM (modem), and the REE (Rich Execution Environment, conventional operating system environment) in the terminal is compiled with instructions from the RIL (Radio Interface Layer) to realize communication with the MODEM (modem).

[0107] b: The terminal reads its own endpoint binding identifier from its Trusted Execution Environment (TEE) and compares it with the card-side binding identifier. If both the card-side and endpoint binding identifiers are initialization identifiers indicating no binding, this is considered an abnormal situation, and authentication fails. If at least one of the card-side and endpoint binding identifiers is an initialization identifier, this is also considered an abnormal situation, and authentication fails. Authentication is only allowed when both the card-side and endpoint binding identifiers indicate a bound state.

[0108] Further, the terminal checks whether the terminal-side identity code, the card-side identity code of the bound target identity card, the terminal-side encryption key, and the terminal-side authentication key exist in the secure area TEE. If they do not exist, it is determined to be an abnormal situation, and authentication fails. If they exist, the terminal compares the card-side identity code of the bound target identity card stored in the secure area with the card-side identity code sent by the identity card to be authenticated. If they do not match, it is determined to be an abnormal situation, that is, the terminal and the identity card to be authenticated are not mutually bound target objects, and authentication fails. If they match, it is determined that the terminal and the identity card to be authenticated are mutually bound target objects, and authentication can be performed.

[0109] In one embodiment, the authentication process between the terminal and the identity card to be authenticated specifically includes:

[0110] Receive the authentication string sent by the identity card to be authenticated, and verify the authentication string based on the terminal authentication key to obtain the verification result; the authentication string is generated by the identity card to be authenticated based on the card-side authentication key.

[0111] If the verification result is successful, the authentication string is encrypted based on the terminal encryption key to obtain the authentication string, and then the authentication string is sent to the identity card to be authenticated.

[0112] The authentication success is determined based on the authentication result sent by the identity card to be authenticated. The authentication result is determined by the identity card to be authenticated based on the comparison between the decryption result and the authentication string. The decryption result is obtained by the identity card to be authenticated decrypting the authentication string based on the card-side encryption key.

[0113] Specifically, the interaction process between the terminal and the identity card to be authenticated during the authentication process is as follows: Figure 7 As shown;

[0114] c: The identity card to be authenticated uses the card-side authentication key stored during the binding process of the target terminal to generate an authentication string and send it to the terminal's MODEM; after receiving the authentication string, the terminal's MODEM compiles it through RIL and transmits it to REE.

[0115] d: The terminal's REE uses the terminal authentication key stored during the binding of the target identity card to verify the received authentication string;

[0116] e: If the terminal verifies the authentication string, proceed to the next step; if the terminal fails to verify the authentication string, authentication fails.

[0117] f: The terminal's REE uses the stored end-side encryption key to encrypt the received authentication string, obtain the authentication string, and then sends the authentication string to the MODEM after being compiled by the RIL. The MODEM then sends it to the identity card to be authenticated.

[0118] g: The identity card to be authenticated uses the card-side encryption key to decrypt the received authentication string and obtain the decryption result;

[0119] h: The identity card to be authenticated compares the decryption result with the authentication string. If the decryption result matches the authentication string, the authentication is successful, and a successful authentication instruction is sent to the terminal; otherwise, the authentication fails, and a failed authentication instruction is sent to the terminal.

[0120] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0121] Based on the same inventive concept, this application also provides a terminal binding device for implementing the terminal binding method described above. This device can be applied to or integrated into a chip or chip module, for example. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more terminal binding device embodiments provided below can be found in the limitations of the terminal binding method described above, and will not be repeated here.

[0122] In one exemplary embodiment, such as Figure 8 As shown, a terminal binding device 800 is provided, including a card-side information acquisition module 801, a verification result determination module 802, and a binding module 803, wherein:

[0123] The card-side information acquisition module 801 is used to acquire the card-side identity code of the identity card and the card-side binding status of the identity card;

[0124] The verification result determination module 802 is used to read the terminal binding identifier from the secure area to determine the terminal binding status when the card-side binding status indicates that the terminal is already bound, and to determine the verification result based on the card-side binding status and the terminal binding status.

[0125] The binding module 803 is used to bind the terminal and the identity card based on the card-side identity code when the verification result shows that the terminal is qualified to bind.

[0126] In the aforementioned terminal binding device 800, the card-side binding status indicates that an unbound identity card is qualified to be bound to any terminal. Therefore, after obtaining the card-side binding status of the identity card, if the terminal determines that the card-side binding status indicates that the identity card is already bound, the terminal needs to further verify the binding qualification of the identity card by combining its own terminal-side binding status. The purpose of the terminal verifying the card-side binding status by combining its own terminal-side binding status with the card-side binding status is: only if the terminal-side binding status indicates that the identity card is already bound, and the target terminal bound to the identity card is the current terminal, then the verification result is determined that the identity card is qualified to be bound to the current terminal; otherwise, the verification result is determined that the identity card is not qualified to be bound to the current terminal. This can prevent identity cards that have been bound to a target terminal from being bound to other terminals again, which greatly reduces the probability of identity cards that have been bound to a target terminal being arbitrarily bound, leading to the leakage of the associated user's identity information, thereby improving the security of user privacy.

[0127] In one embodiment, the verification result determination module 802 is further configured to:

[0128] If the card-side binding status indicates that the card is not bound, the verification result is determined to be qualified for binding.

[0129] In one embodiment, the verification result determination module 802 is specifically used for:

[0130] If the terminal binding status indicates that the terminal is already bound, obtain the target terminal's identity code that the identity card was previously bound to, and read the terminal's terminal identity code and the target identity card's identity code that the terminal was previously bound to from the secure area.

[0131] If the target card-side identity code matches the card-side identity code, and the target terminal-side identity code matches the terminal-side identity code, the verification result is determined to be that the user is qualified to bind the device.

[0132] In one embodiment, the binding module 803 is specifically used for:

[0133] The system receives the initial ciphertext sent by the identity card and decrypts it using the private key of the first key to obtain the public key of the second key. The initial ciphertext is obtained by the identity card encrypting the public key of the second key based on the public key of the first key.

[0134] A terminal key group is generated based on the public key of the second key, the private key of the third key, and the terminal identity code. Binding authentication information is generated based on the terminal key group and sent to the identity card for binding authentication.

[0135] The binding success is determined based on the authentication result sent by the identity card for the bound authentication information.

[0136] In one embodiment, the endpoint key set includes an endpoint encryption key and an endpoint authentication key; the binding authentication information includes a first ciphertext and a first authentication code; the binding module 803 is specifically used for:

[0137] The public key of the third key is encrypted using the end-side encryption key to obtain the first ciphertext;

[0138] The first authentication code is generated based on the terminal authentication key and the first ciphertext.

[0139] In one embodiment, the binding module 803 is further configured to:

[0140] Once it is confirmed that the terminal and the identity card are successfully bound, the terminal-side identity code and the terminal-side key group are written into the secure area, and the card-side identity code of the identity card is written into the secure area as the target card-side identity code.

[0141] In one embodiment, the terminal binding device 800 further includes an authentication verification module and an authentication module, wherein:

[0142] The authentication and verification module is specifically used to obtain the card-side binding status of the connected identity card to be authenticated during the authentication state, and to read the end-side binding identifier from the secure area to determine the end-side binding status of the terminal.

[0143] The authentication module is specifically used to authenticate the terminal and the identity card to be authenticated when both the terminal-side binding status and the card-side binding status of the identity card to be authenticated indicate that they are already bound.

[0144] In one embodiment, the authentication module is specifically used for:

[0145] Receive the authentication string sent by the identity card to be authenticated, and verify the authentication string based on the terminal authentication key to obtain the verification result; the authentication string is generated by the identity card to be authenticated based on the card-side authentication key.

[0146] If the verification result is successful, the authentication string is encrypted based on the terminal encryption key to obtain the authentication string, and then the authentication string is sent to the identity card to be authenticated.

[0147] The authentication success is determined based on the authentication result sent by the identity card to be authenticated. The authentication result is determined by the identity card to be authenticated based on the comparison between the decryption result and the authentication string. The decryption result is obtained by the identity card to be authenticated decrypting the authentication string based on the card-side encryption key.

[0148] Regarding the modules / units included in the various devices and products described in the above embodiments, they can be software modules / units, hardware modules / units, or a combination of both. For example, for various devices and products applied to or integrated into a chip, all of their modules / units can be implemented using hardware methods such as circuits, or at least some modules / units can be implemented using software programs that run on a processor integrated within the chip, while the remaining (if any) modules / units can be implemented using hardware methods such as circuits; for various devices and products applied to or integrated into a chip module, all of their modules / units can be implemented using hardware methods such as circuits, and different modules / units can be located in the same component (e.g., chip, circuit module, etc.) or different components of the chip module, or at least some modules / units can be implemented using hardware methods such as circuits. The components can be implemented using software programs that run on the processor integrated within the chip module. The remaining (if any) modules / units can be implemented using hardware methods such as circuits. For various devices and products applied to or integrated into the terminal, each of its components / units can be implemented using hardware methods such as circuits. Different modules / units can be located in the same component (e.g., chip, circuit module, etc.) or in different components within the terminal. Alternatively, at least some modules / units can be implemented using software programs that run on the processor integrated within the terminal, while the remaining (if any) modules / units can be implemented using hardware methods such as circuits.

[0149] In one exemplary embodiment, a terminal is provided, which may be a terminal whose internal structure diagram may be as follows: Figure 9As shown, the terminal includes a processor, memory, input / output interface, communication interface, display unit, and input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interface. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interface is used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a terminal binding method. The display unit is used to form a visually visible image and can be a display screen, projection device, or virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the terminal can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the terminal shell, or external keyboards, touchpads, or mice, etc.

[0150] Those skilled in the art will understand that Figure 9 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the terminal to which the present application is applied. A specific terminal may include more or fewer components than those shown in the figure, or may combine certain components, or may have different component arrangements.

[0151] In one exemplary embodiment, a terminal is provided, including a memory and a processor, the memory storing a computer program, the processor executing the computer program to implement any of the steps in the terminal binding method embodiments described above.

[0152] Based on the same inventive concept, this application also provides a chip, including a processor and a communication interface; the communication interface is used to receive or send data; the processor is configured to cause the chip to perform any of the steps in the above-described terminal binding method embodiments.

[0153] It is understood that the chip involved in the embodiments of this application may be a field-programmable gate array (FPGA), may be an application-specific integrated circuit (ASIC), may be a system on chip (SoC), may be a central processor unit (CPU), may be a network processor (NP), may be a digital signal processor (DSP), may be a microcontroller unit (MCU), may be a programmable logic device (PLD), or other integrated chips, etc.

[0154] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements any of the steps in the terminal binding method embodiments described above.

[0155] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements any of the steps in the terminal binding method embodiments described above.

[0156] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0157] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0158] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0159] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A terminal binding method, characterized in that, Applied to a terminal, the method includes: Obtain the card-side identification code of the identity card and the card-side binding status of the identity card; If the card-side binding status indicates that the terminal is already bound, the terminal-side binding identifier is read from the secure area to determine the terminal-side binding status, and the verification result is determined based on the card-side binding status and the terminal-side binding status. If the verification result indicates that the device is eligible for binding, the terminal is bound to the identity card based on the card-side identity code.

2. The method according to claim 1, characterized in that, The method further includes: If the card-side binding status indicates that the card is not bound, the verification result is determined to indicate that the card is qualified to be bound.

3. The method according to claim 1, characterized in that, The step of determining the verification result based on the card-side binding status and the terminal-side binding status includes: When the terminal binding status indicates that the terminal is already bound, obtain the target terminal-side identity code of the target terminal that was previously bound to the identity card, and read the terminal-side identity code of the terminal and the target card-side identity code of the target identity card that was previously bound to the terminal from the secure area. If the target card-side identity code matches the card-side identity code, and the target terminal-side identity code matches the terminal-side identity code, the verification result is determined to be that the user is qualified to bind the device.

4. The method according to claim 3, characterized in that, The binding of the terminal and the identity card based on the card-side identity code includes: The system receives the initial ciphertext sent by the identity card and decrypts the initial ciphertext using the private key of the first key to obtain the public key of the second key; the initial ciphertext is obtained by the identity card encrypting the public key of the second key based on the public key of the first key. A terminal key group is generated based on the public key of the second key, the private key of the third key, and the terminal identity code. Binding authentication information is generated based on the terminal key group, and the binding authentication information is sent to the identity card for binding authentication. Based on the authentication result sent by the identity card for the bound authentication information, it is determined whether the binding was successful.

5. The method according to claim 4, characterized in that, The endpoint key set includes an endpoint encryption key and an endpoint authentication key; the binding authentication information includes a first ciphertext and a first authentication code; generating binding authentication information based on the endpoint key set includes: The public key of the third key is encrypted based on the terminal encryption key to obtain the first ciphertext; The first authentication code is generated based on the terminal authentication key and the first ciphertext.

6. The method according to claim 4 or 5, characterized in that, The method further includes: If the terminal and the identity card are successfully bound, the terminal-side identity code and the terminal-side key group are written into the secure area, and the card-side identity code of the identity card is written into the secure area as the target card-side identity code.

7. The method according to claim 6, characterized in that, The method further includes: In the authentication state, the card-side binding status of the connected identity card to be authenticated is obtained, and the terminal-side binding identifier is read from the secure area to determine the terminal-side binding status. When both the terminal-side binding status and the card-side binding status of the identity card to be authenticated indicate that they are already bound, the terminal and the identity card to be authenticated are authenticated.

8. The method according to claim 7, characterized in that, The authentication of the terminal and the identity card to be authenticated includes: The authentication string sent by the identity card to be authenticated is received, and the authentication string is verified based on the terminal authentication key to obtain the verification result; the authentication string is generated by the identity card to be authenticated based on the card-side authentication key. If the verification result is successful, the authentication string is encrypted based on the terminal encryption key to obtain the authentication string, and the authentication string is sent to the identity card to be authenticated. Based on the authentication result sent by the identity card to be authenticated, it is determined whether the authentication was successful; the authentication result is determined by the identity card to be authenticated based on the comparison between the decryption result and the authentication string, and the decryption result is obtained by the identity card to be authenticated decrypting the authentication string based on the card-side encryption key.

9. A terminal binding device, characterized in that, The device includes a card-side information acquisition module, a verification result determination module, and a binding module, wherein: The card-side information acquisition module is used to acquire the card-side identity code of the identity card and the card-side binding status of the identity card; The verification result determination module is used to read the terminal binding identifier from the security area to determine the terminal binding status when the card-side binding status indicates that the terminal is already bound, and to determine the verification result based on the card-side binding status and the terminal binding status. The binding module is used to bind the terminal and the identity card based on the card-side identity code when the verification result indicates that the terminal is qualified to bind.

10. A terminal comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 8.