Embedded SIM (Subscriber Identity Module) policy configuration method, device, equipment, medium and system

By acquiring encrypted embedded SIM activation information and performing signature verification, seamless integration of embedded SIM profile download and policy configuration is achieved, solving the problem of policy activation delay in the eSIM activation process and improving device security and management efficiency.

CN121968112APending Publication Date: 2026-05-01BEIJING TSINGTENG MICROSYSTEM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING TSINGTENG MICROSYSTEM CO LTD
Filing Date
2026-01-26
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

The existing eSIM activation process only focuses on the network access configuration of the device, and fails to effectively solve the configuration of usage policies after the device is connected to the network. This may result in the device being in an uncontrolled state before the policy takes effect, causing security vulnerabilities and management risks.

Method used

By obtaining encrypted embedded SIM activation information, performing signature verification, obtaining plaintext information, binding the policy description file, and generating an activation code, the download of the embedded SIM profile and policy configuration are seamlessly integrated, so that the policy takes effect upon activation and avoids secondary distribution.

Benefits of technology

This implementation ensures that the policy takes effect immediately upon activation of the embedded SIM Profile, avoiding the uncontrolled state before the network usage policy takes effect, improving device security and reducing management complexity and cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121968112A_ABST
    Figure CN121968112A_ABST
Patent Text Reader

Abstract

The invention relates to an embedded SIM (Subscriber Identity Module) policy configuration method, device, equipment, medium and system. The embedded SIM policy configuration method comprises the following steps: acquiring encrypted embedded SIM activation information comprising attribute information of an embedded SIM profile, an SM-DP + server address and a policy description file; when encrypted embedded SIM activation information signature verification is carried out, plaintext embedded SIM activation information is sent to an SM-DP + server, so that the SM-DP + server binds attribute information of an embedded SIM profile with a strategy description file; according to the method, the embedded SIM profile is downloaded based on the activation code sent by the SM-DP + server, and corresponding injection and activation operations are executed, so that a strategy can be bound with the profile, the strategy takes effect when the profile is activated, zero time delay is realized, and the equipment security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to an embedded SIM strategy configuration method, apparatus, device, medium and system. Background Technology

[0002] Embedded SIM (eSIM) is a digital SIM card technology that is directly embedded inside a device. It is a new generation SIM card standard developed by the GSMA (Global System for Mobile Communications Association). Its core is to integrate the functions of a traditional physical SIM card into the device chip. Users can access and switch networks remotely by downloading and managing operator profiles without having to insert or remove a physical card.

[0003] The current eSIM activation process follows the GSMA SGP.22 standard and mainly uses two methods to download and install the operator's profile. The first is manual input by the user, where the user manually enters the address of the SM-DP+ server and the activation code to trigger the profile download process. The second is QR code scanning, where the user scans a QR code containing the address of the SM-DP+ server and the activation code using the device's camera. The device's built-in local configuration assistant automatically parses the QR code content and starts the download and installation of the profile, ultimately enabling the device to access the mobile network.

[0004] However, the standardized process described above only focuses on solving the "connectivity configuration" problem, that is, ensuring that the device can successfully download and install the operator's profile to achieve network access. However, the configuration of usage policies after the device is connected to the network needs to be redistributed through independent device management and other technologies after eSIM activation and successful network connection. This has a time delay, which may cause the device to be in an uncontrolled state before the policy takes effect, thereby causing security vulnerabilities and management risks. Summary of the Invention

[0005] To address the aforementioned technical problems, this disclosure provides an embedded SIM policy configuration method, apparatus, device, medium, and system.

[0006] A first aspect of this disclosure provides an embedded SIM policy configuration method, including: Obtain encrypted embedded SIM activation information, which includes the embedded SIM profile's attribute information, SM-DP+ server address, and policy description file; The encrypted embedded SIM activation information is signed and verified. If the signature verification of the encrypted embedded SIM activation information is successful, the plaintext embedded SIM activation information is obtained and sent to the SM-DP+ server. This allows the SM-DP+ server to bind the attribute information of the embedded SIM profile and the policy description file, and generate an activation code and embedded SIM profile based on the plaintext embedded SIM activation information. The activation code is then sent to the terminal device. Receive the activation code sent by the SM-DP+ server, download the embedded SIM profile based on the activation code, and perform the injection and activation operations of the embedded SIM profile.

[0007] A second aspect of this disclosure provides an embedded SIM policy configuration apparatus, comprising: The information acquisition module is used to acquire encrypted embedded SIM activation information, which includes the attribute information of the embedded SIM profile, the SM-DP+ server address, and the policy description file. The signature verification module is used to verify the signature of the encrypted embedded SIM activation information. If the signature verification of the encrypted embedded SIM activation information is successful, the plaintext embedded SIM activation information is obtained and sent to the SM-DP+ server. This allows the SM-DP+ server to bind the attribute information of the embedded SIM profile and the policy description file, and generate an activation code and embedded SIM profile based on the plaintext embedded SIM activation information. The activation code is then sent to the terminal device. The injection and activation module is used to receive the activation code sent by the SM-DP+ server, download the embedded SIM profile based on the activation code, and perform the injection and activation operations of the embedded SIM profile.

[0008] A third aspect of this disclosure provides an electronic device, including: processor; Memory, used to store executable instructions; The processor is used to read executable instructions from memory and execute the executable instructions to implement the embedded SIM strategy configuration method provided in the first aspect above.

[0009] A fourth aspect of this disclosure provides a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to implement the embedded SIM strategy configuration method provided in the first aspect.

[0010] A fifth aspect of this disclosure provides a computer program product comprising a computer program or instructions that, when executed by a processor, implement the embedded SIM strategy configuration method of the first aspect described above.

[0011] A sixth aspect of this disclosure provides an embedded SIM policy configuration system, comprising: a policy configuration generation terminal, configured to generate plaintext embedded SIM activation information based on user service requirement information, send the plaintext embedded SIM activation information to a target signature authentication server, and receive encrypted embedded SIM activation information sent by the target signature authentication server; encapsulate the encrypted embedded SIM activation information to obtain a target payload message, and send the target payload message to a terminal device; The target signature authentication server is used to receive plaintext embedded SIM activation information sent by the policy configuration generation terminal, digitally sign the plaintext embedded SIM activation information based on the private key to obtain encrypted embedded SIM activation information, and send the encrypted embedded SIM activation information to the policy configuration generation terminal. The SM-DP+ server is used to bind the attribute information and policy description file of the embedded SIM profile in the plaintext embedded SIM activation information, and generate an activation code and embedded SIM profile based on the plaintext embedded SIM activation information, and send the activation code to the terminal device. Terminal devices are electronic devices as described in the third aspect above.

[0012] The technical solution provided in this disclosure has the following advantages compared with the prior art: The embedded SIM policy configuration method, apparatus, device, medium, and system provided in this disclosure can obtain encrypted embedded SIM activation information, which includes attribute information of the embedded SIM profile, SM-DP+ server address, and policy description file. After obtaining the encrypted embedded SIM activation information, the encrypted embedded SIM activation information is signed and verified. If the signature verification of the encrypted embedded SIM activation information is successful, plaintext embedded SIM activation information is obtained and sent to the SM-DP+ server, so that the SM-DP+ server binds the attribute information of the embedded SIM profile and the policy description file, and generates an activation code and embedded SIM profile based on the plaintext embedded SIM activation information, and sends the activation code to the terminal device. The device receives the activation code sent by the SM-DP+ server, downloads the embedded SIM profile based on the activation code, and performs the injection and activation operations of the embedded SIM profile. This allows for seamless integration of embedded SIM profile download and installation (connectivity configuration) with policy configuration. During embedded SIM profile generation, the embedded SIM profile and network usage policy are atomically bound, ensuring that the policy takes effect upon embedded SIM profile injection and activation. This eliminates the need for secondary distribution and configuration of network usage policies after embedded SIM profile activation, achieving zero latency in network usage policy configuration. It also avoids security vulnerabilities and management risks caused by the device being in an uncontrolled state before the network usage policy takes effect, thereby improving device security. Attached Figure Description

[0013] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0014] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 This is a flowchart of an embedded SIM policy configuration method provided in an embodiment of this disclosure; Figure 2 This is a schematic diagram of an embedded SIM policy configuration system provided in an embodiment of this disclosure; Figure 3This is a flowchart of another embedded SIM policy configuration method provided in this disclosure embodiment; Figure 4 This is a schematic diagram of the structure of an embedded SIM policy configuration device provided in an embodiment of this disclosure; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Detailed Implementation

[0016] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0017] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.

[0018] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0019] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0020] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0021] Typically, the current eSIM activation process follows the GSMA SGP.22 standard, primarily using two methods to download and install the operator's profile. The first is manual input by the user, where the user manually enters the address of the SM-DP+ server and the activation code to trigger the profile download process. The second is QR code scanning, where the user scans a QR code containing the SM-DP+ server address and activation code using the device's camera. The device's built-in local profile assistant automatically parses the QR code content and initiates the profile download and installation, ultimately enabling the device to access mobile networks.

[0022] However, the aforementioned standardized process only focuses on resolving the "connectivity configuration" issue, i.e., ensuring that the device can successfully download and install the operator's profile to achieve network access. However, the configuration of usage policies after the device is connected to the network needs to be redistributed through independent device management technologies after eSIM activation and successful device network connection. This introduces a time delay, potentially causing the device to be in an uncontrolled state before the policy takes effect, leading to security vulnerabilities and management risks. Furthermore, it requires deploying and maintaining a complex backend system to manage policies for thousands of devices, resulting in high complexity and operational costs. To address this issue, this disclosure provides an embedded SIM policy configuration method, which will be described below with reference to specific embodiments.

[0023] Figure 1 This is a flowchart illustrating an embedded SIM policy configuration method provided in an embodiment of this disclosure. This method can be executed by an embedded SIM policy configuration device, which can be implemented in software and / or hardware. The embedded SIM policy configuration device can be configured in an electronic device, such as a server or terminal, where the terminal specifically includes a mobile phone, computer, or tablet computer. Furthermore, this method can be applied to… Figure 2 The embedded SIM policy configuration system shown includes a policy configuration generation terminal, a target signature authentication server, a terminal device, and an SM-DP+ server. It is understood that the embedded SIM policy configuration method provided in this embodiment can also be applied to other scenarios.

[0024] like Figure 2 As shown, the policy configuration generation terminal 10, the target signature authentication server 20, the terminal device 30, and the SM-DP+ server 40 can interact via wired or wireless communication. For example, they can communicate via Near Field Communication (NFC).

[0025] The policy configuration generation terminal 10 can generate plaintext embedded SIM activation information based on user business requirements, send the plaintext embedded SIM activation information to the target signature authentication server 20, and receive encrypted embedded SIM activation information sent by the target signature authentication server 20. It then encapsulates the encrypted embedded SIM activation information to obtain a target payload message and sends the target payload message to the terminal device 30. For example, the policy configuration generation terminal 10 can transmit data or information via an NFC interface. The policy configuration generation terminal 10 can be a smart terminal device, such as a self-service machine, tablet computer, point-of-sale (POS) terminal, or industrial handheld device. The policy configuration generation terminal 10 can determine the target signature authentication server based on preset access control permissions.

[0026] The target signature authentication server 20 can receive plaintext embedded SIM activation information sent by the policy configuration generation terminal, digitally sign the plaintext embedded SIM activation information based on its private key to obtain encrypted embedded SIM activation information, and then send the encrypted embedded SIM activation information to the policy configuration generation terminal. To ensure data transmission security, the policy configuration generation terminal 10 and the target signature authentication server 20 can communicate through a secure channel. For example, communication is conducted via TLS 1.2 and encryption. Meanwhile, the private key, which is the foundation of the entire trust system, is protected using a Hardware Security Module (HSM), meaning the private key is stored in the hardware security module.

[0027] Terminal device 30 can be used to obtain encrypted embedded SIM activation information, which includes attribute information of the embedded SIM profile, SM-DP+ server address, and policy description file. It performs signature verification on the encrypted embedded SIM activation information. If the signature verification is successful, it obtains plaintext embedded SIM activation information and sends it to SM-DP+ server 40. It receives an activation code from SM-DP+ server 40, downloads the embedded SIM profile based on the activation code, and performs the injection and activation operations of the embedded SIM profile. Terminal device 30 can be a user's terminal device. Terminal device 30 can be configured with an NFC component and an eUICC supporting embedded SIMs, and runs a local profile assistant eLPA with extended functionality. eLPA can receive the encrypted embedded SIM activation information sent by terminal 10 through the policy configuration via the NFC component, and parse and extract the policy description file based on the data parsing unit. It performs signature verification on the encrypted embedded SIM activation information using a preset public key based on the policy verification unit. If the signature verification is successful, it performs the download, injection, and activation operations of the embedded SIM profile based on the profile download unit and policy execution unit. For example, terminal device 30 can be a smart terminal such as a mobile phone or an in-vehicle infotainment system. It should be noted that the pre-installed public key is distributed and updated through secure, native system channels to prevent it from being maliciously compromised or attacked.

[0028] The SM-DP+ server 40 can be used to bind the attribute information of the embedded SIM profile and the policy description file in the plaintext embedded SIM activation information, and generate an activation code and embedded SIM profile based on the plaintext embedded SIM activation information, and send the activation code to the terminal device 30.

[0029] The following is combined Figure 2 The application scenarios shown are for Figure 1 The embedded SIM policy configuration method shown is introduced, for example, Figure 2 The terminal device 30 in the middle can execute this method. For example... Figure 1 As shown, the embedded SIM policy configuration method provided in this embodiment includes the following steps.

[0030] S110, Obtain the activation information of the encrypted embedded SIM.

[0031] In this embodiment of the disclosure, the encrypted embedded SIM activation information may include attribute information of the embedded SIM profile, the SM-DP+ server address, and a policy description file.

[0032] In this embodiment of the disclosure, the encrypted embedded SIM activation information can be understood as digitally signed embedded SIM activation information.

[0033] The embedded SIM profile's attribute information may include one or more of the following: whether deletion, invalidation, remote update information, profile name, owner, and other rules (such as preset standard specifications).

[0034] The policy description file is used to define the network usage policies of the embedded SIM. It adopts a structured data format, such as JavaScript object notation (JSON) or Extensible Markup Language (XML). The policy description file may include at least one of the following: policy validity period, data traffic limit, list of allowed and / or prohibited roaming countries, list of allowed and / or prohibited applications, bound access point name, network sharing configuration information, and virtual private network configuration information. It may also include policy identification information, issuer, and issuance timestamp. The policy description file uses unique identification information to ensure that the policy in the policy description file is used only once and to prevent the policy with the same signature from being reused on multiple different terminal devices.

[0035] The encrypted embedded SIM activation information is generated by the policy configuration generation terminal based on the user's business requirements. This plaintext embedded SIM activation information is then sent to the target signature authentication server, which digitally signs the plaintext information using a pre-set private key. The target signature authentication server then sends the generated encrypted embedded SIM activation information to the policy configuration generation terminal. The user's business requirements can be determined by the user through a graphical user interface, such as selecting business requirements or filling in policy information. This improves the flexibility of policy settings and adaptability to various business scenarios.

[0036] In some embodiments of this disclosure, the terminal device can obtain encrypted embedded SIM activation information via Near Field Communication (NFC).

[0037] In other embodiments of this disclosure, the electronic device can obtain encrypted embedded SIM activation information by scanning a QR code.

[0038] S120. Perform signature verification on the encrypted embedded SIM activation information. If the signature verification of the encrypted embedded SIM activation information is successful, obtain the plaintext embedded SIM activation information and send the plaintext embedded SIM activation information to the SM-DP+ server so that the SM-DP+ server binds the attribute information of the embedded SIM profile and the policy description file, and generates an activation code and embedded SIM profile based on the plaintext embedded SIM activation information, and sends the activation code to the terminal device.

[0039] In this embodiment of the disclosure, the activation code is used by the terminal device to download the embedded SIM profile from the SM-DP+ server.

[0040] The SM-DP+ server is determined based on the SM-DP+ server address.

[0041] Specifically, the terminal device can decrypt and sign the encrypted embedded SIM activation information based on the local profile assistant eLPA and a pre-set public key to obtain the plaintext embedded SIM activation information and the original hash value corresponding to the encrypted embedded SIM activation information; calculate the target hash value corresponding to the plaintext embedded SIM activation information; compare the target hash value and the original hash value to perform signature verification on the encrypted embedded SIM activation information, and obtain the signature verification result. If the target hash value and the original hash value are consistent, the signature verification is considered successful; otherwise, it is not. Further, if the signature verification of the encrypted embedded SIM activation information is successful, the plaintext embedded SIM activation information is sent to the SM-DP+ server, so that the SM-DP+ server binds the attribute information and policy description file of the embedded SIM profile, and generates an activation code and embedded SIM profile based on the plaintext embedded SIM activation information, and sends the activation code to the terminal device. The specific implementation method of the SM-DP+ server generating the activation code and embedded SIM profile based on the plaintext embedded SIM activation information is similar to the existing methods for generating embedded SIM profiles and activation codes, and will not be elaborated here.

[0042] S130: Receive the activation code sent by the SM-DP+ server, download the embedded SIM profile based on the activation code, and perform the injection and activation operations of the embedded SIM profile.

[0043] Specifically, the terminal device can receive an activation code sent by the SM-DP+ server through communication with the SM-DP+ server. After obtaining the activation code, it downloads the embedded SIM profile based on the activation code. After the embedded SIM profile is downloaded, it sends a download completion message to the SM-DP+ server. Upon receiving the download completion message, the SM-DP+ server generates an injection activation command based on the relevant configuration in the embedded SIM activation information and sends the injection activation command to the terminal device. After receiving the injection activation command, the terminal device performs the injection and activation operations of the embedded SIM profile based on the injection activation command.

[0044] In this embodiment, encrypted embedded SIM activation information can be obtained. This encrypted embedded SIM activation information includes attribute information of the embedded SIM profile, the SM-DP+ server address, and a policy description file. After obtaining the encrypted embedded SIM activation information, a signature verification is performed on it. If the signature verification passes, plaintext embedded SIM activation information is obtained and sent to the SM-DP+ server. This allows the SM-DP+ server to bind the attribute information and policy description file of the embedded SIM profile, generate an activation code and the embedded SIM profile based on the plaintext embedded SIM activation information, and send the activation code to the terminal device. The device then receives the activation code from the SM-DP+ server, downloads the embedded SIM profile based on the activation code, and performs the injection and activation operations for the embedded SIM profile. This allows for seamless integration of embedded SIM profile download and installation (connectivity configuration) with policy configuration. During embedded SIM profile generation, the embedded SIM profile and network usage policy are atomically bound, ensuring that the policy takes effect upon embedded SIM profile injection and activation. This eliminates the need for secondary distribution and configuration of network usage policies after embedded SIM profile activation, achieving zero latency in network usage policy configuration. It also avoids security vulnerabilities and management risks caused by the device being in an uncontrolled state before the network usage policy takes effect, thereby improving device security.

[0045] Based on the embodiments disclosed above, by atomically binding the embedded SIM Profile with network usage policies, the management of thousands of device policies through the backend system is avoided, greatly reducing the management complexity and maintenance costs of the backend system, as well as the signaling load, and improving response speed and system efficiency. Simultaneously, by encrypting and digitally signing the embedded SIM activation information and verifying the signature, the policy is prevented from being tampered with or attacked during transmission, ensuring the integrity and authenticity of the embedded SIM activation information and policy description file.

[0046] In some embodiments of this disclosure, obtaining encrypted embedded SIM activation information may specifically include: receiving a target payload message sent by a terminal that generates a policy configuration based on near-field communication; and parsing the target payload message to obtain encrypted embedded SIM activation information.

[0047] In this embodiment of the disclosure, the target payload message is obtained by the policy configuration generation terminal encapsulating encrypted embedded SIM activation information based on a preset protocol. For example, the preset protocol can be the NFC Data Exchange Format (NDEF protocol).

[0048] The target payload message may include embedded SIM profile attribute information, SM-DP+ server address, and policy description file, and may also include an activation code for downloading the embedded SIM profile from SM-DP+. The specific details can be flexibly determined based on the application scenario and are not limited here.

[0049] In this embodiment of the disclosure, receiving the target load message sent by the terminal based on the near-field communication method to receive the target load message may specifically include: receiving the target load message based on the near-field communication component and determining whether the target load message is a load message of a preset type; In this embodiment of the disclosure, the preset type may include a first type corresponding to the activation code and / or a second type corresponding to the policy description file.

[0050] For example, the first type is TNF_WELL_KNOWN, RTD_URI. Here, TNF_WELL_KNOWN represents the activation code format information as a specific TNF type; RTD_URI represents the download location information of the embedded SIM profile.

[0051] The second type is TNF_MIME_MEDIA. TNF_MIME_MEDIA indicates that the record's type field contains a media type (MIME type) construct defined by RFC2046.

[0052] MIME types can be customized and standardized media types according to user needs.

[0053] Specifically, the terminal device can receive target load messages based on the near-field communication component, and filter the received target load messages based on the preset intent filter in the near-field communication component to determine whether the target load message is a load message of a preset type.

[0054] Furthermore, the target payload message is parsed to obtain encrypted embedded SIM activation information. Specifically, this may include: if the target payload message is determined to be a payload message of a preset type, the target payload message is parsed to obtain encrypted embedded SIM activation information.

[0055] In this embodiment, encrypted embedded SIM activation information can be obtained via Near Field Communication (NFC). This means a fully configured, compliant embedded SIM can be obtained simply by tapping it against another device, greatly simplifying the embedded SIM deployment process. It avoids complex device registration and policy push procedures, improving the convenience of obtaining encrypted embedded SIM activation information and reducing manpower and time costs. Furthermore, by determining whether the target payload message is of a preset type, the accuracy and effectiveness of the obtained encrypted embedded SIM activation information are improved.

[0056] In other embodiments of this disclosure, obtaining encrypted embedded SIM activation information may specifically include: identifying target barcode information and obtaining encrypted embedded SIM activation information based on the activation code.

[0057] In this embodiment of the disclosure, the target barcode information may be QR code information generated based on encrypted embedded SIM activation information.

[0058] In this embodiment of the disclosure, encrypted embedded SIM activation information can be obtained by recognizing barcode information, thereby improving the flexibility of obtaining encrypted embedded SIM activation information.

[0059] In this embodiment of the disclosure, after verifying the signature of the encrypted embedded SIM activation information, the embedded SIM policy configuration method may further include: detecting the validity of the plaintext embedded SIM activation information.

[0060] Specifically, the terminal device can verify the owner's identity in the plaintext embedded SIM activation information; verify the validity period in the plaintext embedded SIM activation information, etc., to determine whether the owner's identity is legitimate and whether the plaintext embedded SIM activation information is within its validity period. If the owner's identity is legitimate and the plaintext embedded SIM activation information is within its validity period, the plaintext embedded SIM activation information is sent to the SM-DP+ server for subsequent operations. If the owner's identity is illegitimate and / or the plaintext embedded SIM activation information is not within its validity period, an error message is displayed to the user. This ensures the validity of the plaintext embedded SIM activation information and the legitimacy of the owner.

[0061] In this embodiment of the disclosure, the embedded SIM policy configuration method may further include: if the embedded SIM activation information signature verification fails, or if the injection and activation operation of the embedded SIM profile fails, calling the target interface and performing a rollback operation based on the target interface.

[0062] Specifically, if the terminal device determines that the embedded SIM activation information signature verification has failed, or if the injection and activation operations of the embedded SIM profile have failed, it calls the target interface and executes the corresponding rollback logic based on the target interface to restore the system data to the state before the operation. The target interface is a pre-set rollback interface.

[0063] In the embodiments of this disclosure, a rollback operation can be performed in a timely manner when an operation fails during the signature verification and / or embedded SIM profile injection and activation operations, avoiding intermediate states such as "number without policy" or "policy partially effective", thus ensuring the effectiveness and stability of embedded SIM policy configuration and embedded SIM profile injection and activation.

[0064] Figure 3 This is a flowchart of another embedded SIM policy configuration method provided in this disclosure embodiment, such as... Figure 3 As shown, the embedded SIM policy configuration method may include the following steps: S310. Obtain the encrypted embedded SIM activation information and perform signature verification on the encrypted embedded SIM activation information.

[0065] S320. If the signature verification of the encrypted embedded SIM activation information fails, perform a rollback operation.

[0066] S330. If the signature verification of the encrypted embedded SIM activation information passes, obtain the plaintext embedded SIM activation information and send it to the SM-DP+ server so that the SM-DP+ server binds the attribute information of the embedded SIM profile and the policy description file, and generates an activation code and embedded SIM profile based on the plaintext embedded SIM activation information, and sends the activation code to the terminal device.

[0067] S340 receives the activation code sent by the SM-DP+ server, downloads the embedded SIM profile based on the activation code, and performs the injection and activation operations of the embedded SIM profile.

[0068] S350. If the injection and activation operations fail, perform a rollback operation.

[0069] It should be noted that the specific implementation methods of steps S310 to S350 are similar to those of the relevant steps in the above embodiments of this disclosure, and will not be repeated here.

[0070] In this embodiment, the download and installation of the embedded SIM profile (i.e., connectivity configuration) and policy configuration are seamlessly integrated. During the generation of the embedded SIM profile, the embedded SIM profile and network usage policy are atomically bound, so the policy takes effect when the embedded SIM profile is injected and activated. This achieves policy effectiveness upon embedded SIM profile activation, eliminating the need for secondary distribution and configuration of network usage policies after activation. This achieves zero latency in network usage policy configuration and avoids security vulnerabilities and management risks caused by the device being in an uncontrolled state before the network usage policy takes effect, thereby improving device security. Furthermore, in the event of operation failure, a rollback operation is performed promptly, avoiding intermediate states such as "number present but no policy" or "partially effective policy," ensuring the effectiveness and stability of embedded SIM policy configuration and the injection and activation of the embedded SIM profile.

[0071] Figure 4 This is a schematic diagram of the structure of an embedded SIM strategy configuration device provided in an embodiment of this disclosure.

[0072] In this embodiment, the embedded SIM strategy configuration device can be located within an electronic device and is understood as a functional module within the aforementioned electronic device. Specifically, the electronic device can be a server or a terminal, wherein the terminal specifically includes mobile phones, computers, or tablet computers, etc., without limitation.

[0073] like Figure 4 As shown, the embedded SIM policy configuration device 400 may include an information acquisition module 410, a signature verification module 420, and an injection and activation module 430.

[0074] The information acquisition module 410 can be used to acquire encrypted embedded SIM activation information, which includes the attribute information of the embedded SIM profile, the SM-DP+ server address, and the policy description file. The signature verification module 420 can be used to verify the signature of the encrypted embedded SIM activation information. If the signature verification of the encrypted embedded SIM activation information is successful, the plaintext embedded SIM activation information is obtained and sent to the SM-DP+ server so that the SM-DP+ server binds the attribute information of the embedded SIM profile and the policy description file, and generates an activation code and embedded SIM profile based on the plaintext embedded SIM activation information, and sends the activation code to the terminal device. The injection and activation module 430 can be used to receive the activation code sent by the SM-DP+ server, download the embedded SIM profile based on the activation code, and perform the injection and activation operations of the embedded SIM profile.

[0075] In this embodiment, encrypted embedded SIM activation information can be obtained. This encrypted embedded SIM activation information includes attribute information of the embedded SIM profile, the SM-DP+ server address, and a policy description file. After obtaining the encrypted embedded SIM activation information, a signature verification is performed on it. If the signature verification passes, plaintext embedded SIM activation information is obtained and sent to the SM-DP+ server. This allows the SM-DP+ server to bind the attribute information and policy description file of the embedded SIM profile, generate an activation code and the embedded SIM profile based on the plaintext embedded SIM activation information, and send the activation code to the terminal device. The device then receives the activation code from the SM-DP+ server, downloads the embedded SIM profile based on the activation code, and performs the injection and activation operations for the embedded SIM profile. This allows for seamless integration of embedded SIM profile download and installation (connectivity configuration) with policy configuration. During embedded SIM profile generation, the embedded SIM profile and network usage policy are atomically bound, ensuring that the policy takes effect upon embedded SIM profile injection and activation. This eliminates the need for secondary distribution and configuration of network usage policies after embedded SIM profile activation, achieving zero latency in network usage policy configuration. It also avoids security vulnerabilities and management risks caused by the device being in an uncontrolled state before the network usage policy takes effect, thereby improving device security.

[0076] In some embodiments of this disclosure, the policy description file is a file used to define the network usage policy of the embedded SIM, and adopts a structured data format; the policy description file includes at least one of the following: policy validity period, data traffic limit, list of allowed and / or prohibited roaming countries, list of allowed and / or prohibited applications, bound access point name, network sharing configuration information, and virtual private network configuration information.

[0077] In some embodiments of this disclosure, the information acquisition module 410 may be specifically used to receive a target load message sent by the policy configuration generation terminal based on near-field communication. The target load message is obtained by the policy configuration generation terminal encapsulating encrypted embedded SIM activation information based on a preset protocol. The target payload message is parsed to obtain the encrypted embedded SIM activation information.

[0078] In some embodiments of this disclosure, the information acquisition module 410 may also be specifically used to receive a target load message based on a near-field communication component and determine whether the target load message is a load message of a preset type; if the target load message is determined to be a load message of a preset type, the target load message is parsed to obtain encrypted embedded SIM activation information.

[0079] In some embodiments of this disclosure, the encrypted embedded SIM activation information is generated by a policy configuration generation terminal based on the user's service requirement information, which generates plaintext embedded SIM activation information and sends it to a target signature authentication server. The target signature authentication server then digitally signs the plaintext embedded SIM activation information to generate the encrypted embedded SIM activation information.

[0080] In some embodiments of this disclosure, the embedded SIM policy configuration device 400 may further include a rollback module.

[0081] The rollback module can be used to call the target interface and perform a rollback operation based on the target interface if the embedded SIM activation information signature verification fails, or if the injection and activation operations of the embedded SIM profile fail.

[0082] It should be noted that, Figure 4 The embedded SIM strategy configuration device 400 shown can execute the various steps in the above method embodiments and realize the various processes and effects in the above method embodiments, which will not be elaborated here.

[0083] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure.

[0084] In this embodiment of the disclosure, Figure 5 The electronic devices shown can be servers or terminals, where terminals specifically include mobile phones, computers, or tablets, etc., without limitation.

[0085] like Figure 5 As shown, the electronic device may include a processor 510 and a memory 520 storing computer program instructions.

[0086] Specifically, the processor 510 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this disclosure.

[0087] Memory 520 may include a large-capacity storage device for information or instructions. For example, and not limitingly, memory 520 may include a hard disk drive (HDD), a floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or a Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 520 may include removable or non-removable (or fixed) media. Where appropriate, memory 520 may be internal or external to the integrated gateway device. In a particular embodiment, memory 520 is a non-volatile solid-state memory. In a particular embodiment, memory 520 includes read-only memory (ROM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (Electrically Programmable ROM, EPROM), an electrically erasable programmable PROM (EEPROM), an electrically alterable ROM (EAROM), or flash memory, or a combination of two or more of these.

[0088] The processor 510 reads and executes computer program instructions stored in the memory 520 to perform the steps of the embedded SIM strategy configuration method provided in the embodiments of this disclosure.

[0089] In one example, the electronic device may also include a transceiver 530 and a bus 540. Wherein, as... Figure 5 As shown, the processor 510, memory 520 and transceiver 530 are connected via bus 540 and communicate with each other.

[0090] Bus 540 may include hardware, software, or both. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industrial Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, bus 540 may include one or more buses.

[0091] This disclosure also provides a computer-readable storage medium that can store a computer program that, when executed by a processor, enables the processor to implement the embedded SIM strategy configuration method provided in this disclosure.

[0092] The aforementioned storage medium may include, for example, a memory 520 containing computer program instructions, which can be executed by a processor 510 of an electronic device to complete the embedded SIM strategy configuration method provided in this embodiment. Optionally, the storage medium may be a non-transitory computer-readable storage medium, such as a ROM, random access memory (RAM), compact disc ROM (CD-ROM), magnetic tape, floppy disk, and optical data storage device.

[0093] This disclosure also provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a processor, they implement the embedded SIM strategy configuration method provided in this disclosure and can achieve the various processes and effects in the above embodiments of this disclosure, which will not be elaborated here.

[0094] This disclosure also provides an embedded SIM policy configuration system, comprising: a policy configuration generation terminal, configured to generate plaintext embedded SIM activation information based on user service requirement information, send the plaintext embedded SIM activation information to a target signature authentication server, and receive encrypted embedded SIM activation information sent by the target signature authentication server; encapsulate the encrypted embedded SIM activation information to obtain a target payload message, and send the target payload message to a terminal device; a target signature authentication server, configured to receive the plaintext embedded SIM activation information sent by the policy configuration generation terminal, digitally sign the plaintext embedded SIM activation information based on a private key to obtain encrypted embedded SIM activation information, and send the encrypted embedded SIM activation information to the policy configuration generation terminal; and an SM-DP+ server, configured to bind the attribute information of the embedded SIM profile in the plaintext embedded SIM activation information to a policy description file, and generate an activation code and an embedded SIM profile based on the plaintext embedded SIM activation information, and send the activation code to the terminal device; the terminal device can execute each step in the above method embodiments and implement each process and effect in the above method embodiments, which will not be elaborated here.

[0095] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An embedded SIM strategy configuration method, characterized in that, The method includes: Obtain encrypted embedded SIM activation information, which includes attribute information of the embedded SIM profile, SM-DP+ server address, and policy description file; The encrypted embedded SIM activation information is signed and verified. If the signature verification of the encrypted embedded SIM activation information is successful, the plaintext embedded SIM activation information is obtained and sent to the SM-DP+ server. The SM-DP+ server binds the attribute information of the embedded SIM profile with the policy description file and generates an activation code and embedded SIM profile based on the plaintext embedded SIM activation information. The activation code is then sent to the terminal device. The system receives the activation code sent by the SM-DP+ server, downloads the embedded SIM profile based on the activation code, and performs the injection and activation operations of the embedded SIM profile.

2. The method according to claim 1, characterized in that, The policy description file is a file used to define the network usage policy of the embedded SIM, and adopts a structured data format. The policy description file includes at least one of the following: policy validity period, data traffic limit, list of allowed and / or prohibited roaming countries, list of allowed and / or prohibited applications, bound access point name, network sharing configuration information, and virtual private network configuration information.

3. The method according to claim 1, characterized in that, The process of obtaining the encrypted embedded SIM activation information includes: The target payload message is received by the strategy configuration generation terminal based on near-field communication. The target payload message is obtained by the strategy configuration generation terminal encapsulating the encrypted embedded SIM activation information based on a preset protocol. The target payload message is parsed to obtain the encrypted embedded SIM activation information.

4. The method according to claim 3, characterized in that, The target payload message sent by the terminal based on the near-field communication method receiving strategy configuration includes: The target load message is received based on the near-field communication component, and it is determined whether the target load message is a load message of a preset type. The step of parsing the target payload message to obtain the encrypted embedded SIM activation information includes: If the target payload message is determined to be a payload message of a preset type, the target payload message is parsed to obtain the encrypted embedded SIM activation information.

5. The method according to claim 1, characterized in that, The encrypted embedded SIM activation information is generated by the policy configuration generation terminal based on the user's business requirements information, and then sent to the target signature authentication server. The target signature authentication server digitally signs the plaintext embedded SIM activation information to generate the encrypted embedded SIM activation information.

6. The method according to claim 1, characterized in that, The method further includes: If the embedded SIM activation information signature verification fails, or if the injection and activation operation of the embedded SIM profile fails, the target interface is invoked, and a rollback operation is performed based on the target interface.

7. An embedded SIM strategy configuration device, characterized in that, include: The information acquisition module is used to acquire encrypted embedded SIM activation information, which includes attribute information of the embedded SIM profile, SM-DP+ server address and policy description file; The signature verification module is used to verify the signature of the encrypted embedded SIM activation information. If the signature verification of the encrypted embedded SIM activation information is successful, the plaintext embedded SIM activation information is obtained and sent to the SM-DP+ server so that the SM-DP+ server binds the attribute information of the embedded SIM profile with the policy description file, and generates an activation code and embedded SIM profile based on the plaintext embedded SIM activation information, and sends the activation code to the terminal device. The injection and activation module is used to receive the activation code sent by the SM-DP+ server, download the embedded SIM profile based on the activation code, and perform the injection and activation operations of the embedded SIM profile.

8. An electronic device, characterized in that, include: processor; Memory, used to store executable instructions; The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the embedded SIM strategy configuration method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, causes the processor to implement the embedded SIM strategy configuration method according to any one of claims 1-6.

10. An embedded SIM policy configuration system, characterized in that, include: The strategy configuration generation terminal is used to generate plaintext embedded SIM activation information based on the user's business requirements information, send the plaintext embedded SIM activation information to the target signature authentication server, and receive encrypted embedded SIM activation information sent by the target signature authentication server. The encrypted embedded SIM activation information is encapsulated to obtain a target payload message, and the target payload message is sent to the terminal device. The target signature authentication server is used to receive plaintext embedded SIM activation information sent by the policy configuration generation terminal, digitally sign the plaintext embedded SIM activation information based on the private key to obtain encrypted embedded SIM activation information, and send the encrypted embedded SIM activation information to the policy configuration generation terminal. The SM-DP+ server is used to bind the attribute information and policy description file of the embedded SIM profile in the plaintext embedded SIM activation information, and generate an activation code and embedded SIM profile based on the plaintext embedded SIM activation information, and send the activation code to the terminal device. The terminal device is the electronic device as described in claim 8 above.