Secure apparatus and method for communication

By generating and downloading gear modules to terminal devices or eUICC through the engine, the problem of insufficient SIM card security functions is solved, enabling flexible management and enhanced security of various security applications in terminal devices.

CN122003897APending Publication Date: 2026-05-08HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2024-10-28
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing SIM cards have limitations in terms of security features, making it difficult to meet the needs of multiple security applications, especially the privacy and encryption requirements when storing sensitive data in important applications such as banking.

Method used

By introducing the gear module, which generates and downloads the data to the terminal device or eUICC through the engine, security functions such as blockchain, privacy protection, and cryptography are provided. Security is ensured through mutual authentication and session keys, thereby achieving security for the terminal device.

Benefits of technology

It enables flexible management and enhancement of security functions in SIM cards or terminal devices, supports a variety of security applications, and improves data privacy and encryption security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122003897A_ABST
    Figure CN122003897A_ABST
Patent Text Reader

Abstract

Exemplary embodiments relate to an apparatus, method, device, system, and computer readable storage medium for communication. In one aspect, a first device comprises at least one of: a first module to generate a gear module for a second device, where the gear module is to provide one or more security functions in the second device; the second module is used for downloading the gear module from the first device to a second device; or the third module is used for associating the gear module with the second device before the gear module is downloaded to the second device. Thus, the gear module can be generated and stored in the first module, associated with the second device, and downloaded to the second device, thereby flexibly realizing a security function in the second device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications

[0002] This application claims priority to Indian patent application No. 202331073120, filed on October 27, 2023, the entire contents of which are incorporated herein by reference. Technical Field

[0003] Exemplary implementations of this disclosure generally relate to the field of communications, and more particularly to security devices and methods for communications such as wireless communications. Background Technology

[0004] For example, a Subscriber Identity Module (SIM) card can authenticate mobile devices to cellular networks. Since its evolution, the functionality of SIM cards has expanded from basic authentication to secure mobile payments. While Java cards offer security features, they only provide limited security capabilities related to cryptographic services. As multiple security applications are being implemented in SIM cards, their security features should be further enhanced. Summary of the Invention

[0005] Overall, the exemplary implementations of this disclosure provide a solution for communication security.

[0006] In a first aspect, a first device is provided. The first device includes at least one of the following: a first module for generating a gear module for a second device, wherein the gear module is used to provide one or more security functions in the second device; a second module for performing the downloading of the gear module from the first device to the second device; or a third module for associating the gear module with the second device before downloading the gear module to the second device. Thus, the gear module can be generated and sent from the first device, such as an engine, to the second device, such as a device or an embedded universal integrated circuit card (eUICC) within the device, to provide security functions in the second device.

[0007] In one implementation, the first device further includes at least one of the following: a fourth module for storing the gear module before downloading it to the second device; or a fifth module for performing at least one operation on the gear module after it has been downloaded to the second device. In this way, the first device can flexibly manage the security functions in the second device.

[0008] In one implementation, the second device is a terminal device; or a security device within the terminal device. This allows for flexible implementation of the security function within the terminal device or, for example, within the security device of the eUICC within the terminal device.

[0009] In one implementation, the security device includes at least one of the following: a universal integrated circuit card (UICC); an embedded universal integrated circuit card (eUICC); a subscriber identity module (SIM); an embedded subscriber identity module (eSIM); or a smart card. This allows for flexible implementation of security in different formats.

[0010] In a second aspect, a method is provided performed by a first device. The method includes: receiving from a third device a request from the first device to generate a gear module for a second device, wherein the gear module is used to provide one or more security functions in the second device; generating the gear module for the second device according to the request; and sending a response to the request to the third device. Thus, the first device, for example, an engine, can generate the gear module upon request, thereby flexibly providing security functions in the second device.

[0011] In one implementation, the method further includes: after generating the gear module, associating the generated gear module with an identifier of the second device. In this way, the generated gear module can be associated with a separate second device to distinguish different gear modules having different second devices.

[0012] In one implementation, the method further includes storing the generated gear module in the first device. This way, the gear module does not need to be regenerated after its initial generation and can be easily sent to the second device.

[0013] In a third aspect, a method performed by a third device is provided. The method includes: sending a request to a first device for the first device to generate a gear module for a second device, wherein the gear module is used to provide one or more security functions in the second device; and receiving a response to the request from the first device. Thus, a third device, such as an operator device, can cause the first device to generate the gear module for flexibly providing security functions in the second device.

[0014] In one implementation, the request includes at least one of the following: at least one requirement for the gear module; at least one quantity of gear modules; or an identifier for the second device. The requirement information includes: at least one security function, the number of gear modules to be generated, an International Mobile Subscriber Identity (IMSI), an eUICC Identification Number (EID), etc. Thus, the first device can accurately generate the gear modules according to the requirements.

[0015] In one implementation, the response includes at least one of the following: an indication of success or failure of the gear module's generation; or a reason for the failure. Thus, the first device can send the accurate status of the gear module's generation to the third device.

[0016] In a fourth aspect, a method is provided performed by a first device. The method includes: receiving, at the first device, a request from a terminal device to download a gear module from the first device to a second device; binding the gear module to a session key generated for the second device; and sending the gear module to the second device, wherein the gear module is used to provide one or more security functions in the second device. Thus, the gear module can be securely sent from the first device to the second device and can flexibly provide security functions in the second device.

[0017] In one implementation, the method further includes performing mutual authentication between the first device and the second device, wherein the session key is generated during the mutual authentication. This allows the gear module to be sent securely.

[0018] In one implementation, the method further includes: obtaining at least one parameter for generating the session key from the second device during the mutual authentication; and generating the session key based on the at least one parameter obtained during the mutual authentication. This allows the generation of a session key, thereby enabling the secure transmission of the gear module from the first device to the second device.

[0019] In one implementation, the gear module is associated with the second device. This allows for the flexible generation of different gear modules for different second devices.

[0020] In one implementation, the second device is a terminal device; or a security device within the terminal device. Thus, the gear module can flexibly provide security functions within the terminal device or within a security device within the terminal device, such as the eUICC.

[0021] In one implementation, the second device is a terminal device, and the method further includes: receiving a request from the terminal device to download the gear module from the first device to the terminal device. Thus, the gear module can be downloaded and installed on the terminal device according to the request.

[0022] In one implementation, the method further includes: searching for the gear module in the first device based on the identifier of the second device before binding the gear module and the session key. This allows the accurate gear module to be downloaded and installed into the second device.

[0023] In one implementation, the method further includes receiving an indication from the second device that the download of the gear module was successful or failed. This allows the first device to obtain accurate information about the download status of the gear module from the second device.

[0024] In one implementation, the method further includes: based on receiving the successful download indication from the gear module, sending an instruction to a third device to download the gear module to the second device. In this way, the third device can obtain the accurate status of the gear module download through the first device.

[0025] In a fifth aspect, a method performed by a second device is provided. The method includes: sending a request to a first device to download a gear module from the first device to the second device; receiving the gear module from the first device, wherein the gear module is bound to a session key generated for the second device, and wherein the gear module is used to provide one or more security functions in the second device. Thus, the second device can receive and install the gear module according to the request, flexibly providing security functions in the second device.

[0026] In one implementation, the second device includes at least one of the following: a terminal device; or a security device in the terminal device. Thus, the gear module can flexibly provide security functions in the terminal device or in the security device in the terminal device, such as the eUICC.

[0027] In one implementation, the method further includes performing mutual authentication between the first device and the second device, wherein the session key is generated during the mutual authentication. This allows the gear module to be sent securely.

[0028] In one implementation, the method includes at least one of the following: if the second device is a terminal device, the terminal device or a security device in the terminal device performs the mutual authentication with the first device; or if the second device is the security device in the terminal device, the security device performs the mutual authentication with the first device. Thus, the terminal device or the security device in the terminal device can perform mutual authentication for securely downloading the gear module.

[0029] In one implementation, the method further includes: generating at least one parameter for generating a session key during the mutual authentication process; and providing the at least one parameter to the first device during the mutual authentication process. This allows for secure downloading of the gear module.

[0030] In one implementation, the method further includes sending an indication to the first device whether the download of the gear module was successful or failed. This allows the second device to send the first device an accurate status update regarding the download of the gear module.

[0031] Those skilled in the art will understand that the above aspects and implementation methods can be combined.

[0032] In a sixth aspect, an apparatus is provided. The apparatus includes: at least one processor coupled to at least one memory storing programming instructions executable by the at least one processor, which, when executed by the at least one processor, cause the apparatus to perform the methods of the second, third, fourth, and fifth aspects.

[0033] In one implementation, the apparatus includes the at least one memory.

[0034] In one implementation, the at least one processor is integrated with the at least one memory.

[0035] In a seventh aspect, a computer-readable storage medium storing instructions that, when executed by one or more processors of a computing device, cause the computing device to perform at least the methods of the second, third, fourth, and fifth aspects.

[0036] In an eighth aspect, an apparatus is provided. The apparatus includes: at least one processor coupled to at least one communication interface for inputting and / or outputting signals, which, when programming instructions are executed by the at least one processor or when logic circuitry in the at least one processor is operational, cause the apparatus to perform the methods of the second, third, fourth, and fifth aspects.

[0037] In a ninth aspect, a computer program is provided. The computer program includes instructions that, when executed by a device, cause the device to perform at least the methods of the second, third, fourth, and fifth aspects.

[0038] In a tenth aspect, a communication system is provided. The communication system includes the first and second devices described in the first aspect.

[0039] It should be understood that the summary section is not intended to identify key or essential features of the implementation of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0040] Some exemplary implementations will now be described with reference to the accompanying drawings, in which:

[0041] Figure 1A Examples of communication systems in which one exemplary implementation of the present disclosure may be implemented are shown;

[0042] Figure 1B This disclosure illustrates the system architecture.

[0043] Figure 2A An example of a block diagram showing a first apparatus in which one exemplary implementation of the present disclosure may be implemented;

[0044] Figure 2B An example of a block diagram of an engine in which one of the exemplary implementations of this disclosure may be implemented;

[0045] Figure 3 An example of a process flow for generating a gear module is shown, in which one of the exemplary implementations of this disclosure can be implemented;

[0046] Figure 4 An example of a process flow for downloading and installing a gear module is shown, in which one of the exemplary implementations of this disclosure may be carried out;

[0047] Figure 5 An example of a process flow for downloading and installing a gear module in eUICC, in which one of the exemplary implementations of this disclosure is shown;

[0048] Figure 6 An example of a process flow for mutual authentication between eUICC and the engine, in which one of the exemplary implementations of this disclosure can be implemented, is shown;

[0049] Figure 7 An example of a process flow for downloading and installing a gear module into a device, in which one of the exemplary implementations of this disclosure may be carried out, is shown;

[0050] Figure 8 An example of a process flow for mutual authentication between a device and an engine, in which one of the exemplary implementations of this disclosure may be implemented, is shown;

[0051] Figure 9 An example of a process flow for downloading and installing a gear module into a device with the help of eUICC is shown, in which one of the exemplary implementations of this disclosure can be implemented;

[0052] Figure 10 An example of the process flow of a first apparatus for one exemplary implementation of this disclosure;

[0053] Figure 11 An example of the process flow of a third apparatus according to one exemplary implementation of this disclosure;

[0054] Figure 12 An example of the process flow of a first apparatus for one exemplary implementation of this disclosure;

[0055] Figure 13An example of the process flow of a second apparatus illustrating one exemplary implementation of this disclosure;

[0056] Figure 14 A simplified block diagram of a communication apparatus suitable for implementing one exemplary embodiment of the present disclosure is shown;

[0057] Figure 15 Another simplified block diagram of a first apparatus suitable for implementing one exemplary embodiment of the present disclosure is shown;

[0058] Figure 16 A simplified block diagram of a third apparatus suitable for implementing one exemplary embodiment of the present disclosure is shown;

[0059] Figure 17 A simplified block diagram of a second apparatus suitable for implementing one of the exemplary implementations of this disclosure is shown.

[0060] In the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation

[0061] The principles of this disclosure will now be described with reference to one exemplary implementation. It should be understood that these implementations are described merely to illustrate and assist those skilled in the art in understanding and implementing this disclosure, and do not impose any limitation on the scope of this disclosure. The inventive content described herein can be implemented in various ways other than those described below.

[0062] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0063] References to "an embodiment," "embodiment," "exemplary embodiment," etc., in this disclosure indicate that the described embodiments may include specific features, structures, or characteristics, but not every embodiment must include specific features, structures, or characteristics. Furthermore, these phrases do not necessarily refer to the same embodiment. Moreover, when a specific feature, structure, or characteristic is described in connection with an embodiment, it should be understood that, whether explicitly described or not, those skilled in the art will recognize how such a feature, structure, or characteristic can be combined with other implementations.

[0064] It should be understood that while the terms “first” and “second” may be used in this document to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the exemplary implementation. The term “and / or” as used herein includes any and all combinations of one or more of the listed items.

[0065] The terminology used herein is intended to describe specific implementations only and is not intended to limit the exemplary implementations. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “the” used herein are intended to include the plural forms as well. It should also be understood that the terms “comprises / comprising,” “has / having,” and / or “includes / including”, when used herein, specify the presence of the stated features, elements, and / or components, but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0066] As used herein, the term "communication network" refers to a network that conforms to any suitable communication standard, such as Long Term Evolution (LTE), LTE-Advanced (LTE-A), High-Speed ​​Packet Access (HSPA), Narrow Band Internet of Things (NB-IoT), etc. This communication network can be used for fifth-generation (5G) networks. th This disclosure applies to communication systems such as 5G New Radio (NR) communication systems, and can also be used for other evolved communication systems after 5G, such as 6G. The methods proposed in the implementations of this disclosure can also be used in remote Internet of Things (IoT) systems such as LoRa (remote), or vehicle-to-everything (V2X) systems. The methods proposed in the implementations of this disclosure can also be used in satellite communication systems, which can be integrated with the aforementioned communication systems. Furthermore, communication between terminal devices and network devices in the communication network can be performed according to any suitable generation of communication protocol, including but not limited to: fourth-generation (4G), 4.5G, fifth-generation (5G) communication protocols and / or any other protocols currently known or to be developed in the future beyond 5G communication. The implementations of this disclosure can be applied to various communication systems. Given the rapid development of communication technologies, future communication technologies and systems embodying this disclosure will inevitably emerge in the future. The scope of this disclosure should not be limited to the aforementioned systems.

[0067] The term "terminal equipment" refers to any terminal device capable of wireless communication. By way of example and not limitation, terminal equipment may also be referred to as communication equipment, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices may include, but are not limited to: mobile phones, cellular phones, smartphones, voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, customer-premises equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in industrial and / or automated processing chain environments), consumer electronics devices, and devices operating on commercial and / or industrial wireless networks. Terminal equipment can also be called user equipment (UE), mobile station (MS), mobile terminal (MT), etc., or it is a device used to provide voice or data connectivity to user equipment or IoT devices. For example, terminal equipment includes handheld devices with wireless connectivity, vehicle-mounted devices, etc.In this disclosure, the terminal device can be: a mobile phone, tablet computer, laptop computer, PDA, mobile internet device (MID), wearable device (e.g., smartwatch, smart bracelet, pedometer, etc.), in-vehicle device (e.g., car, bicycle, electric car, airplane, ship, train, high-speed rail, etc.), satellite terminal, virtual reality (VR) device, augmented reality (AR) device, smart point of sale (POS) machine, wireless terminal in industrial control, smart home device (e.g., refrigerator, TV, air conditioner, electricity meter, etc.), smart robot, robotic arm, workshop equipment, unmanned driving wireless terminal, wireless terminal in telemedicine, wireless terminal in smart grid, wireless terminal in traffic safety, wireless terminal in smart city, or wireless terminal in smart home, flying device (e.g., smart robot, hot air balloon, drone, airplane, etc.), etc. The terminal device can also be other devices with terminal functions; for example, the terminal device can also be a device used as a terminal function in device-to-device (D2D) communication. In the following description, the terms "terminal equipment", "communication equipment", and "terminal" are used interchangeably.

[0068] As mentioned above, devices such as subscriber identity module (SIM) cards can authenticate mobile devices to cellular networks. Since its evolution, the functionality of SIM cards has expanded from basic authentication to secure mobile payments. While Java cards offer security features, they only provide limited security related to cryptographic services. Given the numerous security applications being implemented in SIM cards, their security features should be further enhanced. SIM cards require advanced security features because they are used in several important applications, such as banking, to store sensitive data. Currently, SIM cards offer features such as encryption and digital signatures, but privacy and authentication are essential for the future use of SIM cards.

[0069] This application proposes an architecture and protocol for initializing, associating, and downloading security modules, such as gear modules, from SIM cards or terminal devices. These security modules include security functions such as security entities within the SIM card or terminal device. The gear module incorporates security functions such as blockchain, proof-of-stake, privacy protection, and cryptography, enabling applications on the SIM card or terminal device to access these security functions. To support remote management of gear modules within SIM cards or terminal devices, an engine is proposed, defining corresponding functions for initialization, association, and downloading. The engine can generate and associate security modules, such as gear modules, and download them to the terminal device or security devices such as SIM cards within the terminal device to implement security functions.

[0070] Figure 1A An example of a communication system in which one of the exemplary implementations of this disclosure is shown.

[0071] In one implementation, the communication system 100 includes at least one device 101, such as a terminal device, an eUICC 103, at least one engine 105, and an operator 107. The eUICC 103 may be an embedded general-purpose integrated circuit card within the terminal device. The engine 105 may be a first device, the device 101 or eUICC 103 may be a second device, and the operator 107 may be a third device. The third device may request the first device to generate a gear module. The second device may download the gear module from the first device and install it in the second device, enabling the gear module to provide security functions in the second device. Those skilled in the art will understand that the second device may also be a relay device or a network device. The engine 105 may be a server or service module in applications such as network services or online banking. The operator 107 may be a server or service module for operating or managing a wireless communication network. The engine 105 may be implemented in software or hardware, and the operator 107 may be implemented in software or hardware.

[0072] Figure 1B The system architecture in this disclosure is shown.

[0073] In one implementation, system architecture 110 includes an eUICC manufacturer (EUM) 111, an operator 107, an engine 105, and terminal devices such as mobile devices and eUICCs 113. Remote management 119 serves as the interface between the engine 105 and the mobile devices and eUICCs 113. Gear initialization and association 117 is the communication interface between the engine 105 and the operator 107. The order interface for eUICCs 115 between the operator 107 and the EUM 111 can be an offline process, where the operator 107 orders eUICCs from the EUM 111. Those skilled in the art will understand that eUICC 115 orders can also be performed online.

[0074] Figure 2A An example block diagram of a first apparatus in which one of the exemplary implementations of this disclosure may be implemented is shown.

[0075] In block diagram 200, a first module 203, a second module 205, and a third module 207 exist in the first device 201. The first module 203 is used to generate a gear module for the second device, wherein the gear module provides one or more security functions in the second device. The second module 205 is used to download the gear module from the first device 201 to the second device. The third module 207 is used to associate the gear module with the second device before downloading it. A fourth module 208 and a fifth module 209 may also exist in the first device 201. The fourth module 208 is used to store the gear module before downloading it to the second device. The fifth module 209 is used to perform at least one operation on the gear module after downloading it to the second device. The operation may be enabling the gear module, disabling the gear module, updating the gear module, adding an enabler module to the gear module, deleting an enabler module from the enabler module, etc. In this way, the gear module can be generated and stored in the first module 201, associated with the second device and downloaded to the second device to flexibly implement the security functions in the second device.

[0076] Figure 2B An example block diagram of an engine in which one of the exemplary implementations of this disclosure may be shown.

[0077] In block diagram 210, engine 105 includes a gear initialization module 211, a gear association module 213, a gear_DB module 215, a gear download module 217, and a gear remote manager module 219. Engine 105 can be... Figure 1AThe implementation method of the first device 201 in the text. The gear initialization module 211, gear association module 213, gear_DB module 215, gear download module 217 and gear remote manager module 219 can be implemented separately as the first module 203, the third module 207, the fourth module 208, the second module 205 and the fifth module 209.

[0078] In one implementation, the gear initialization module 211 creates a gear module according to the operator's requirements. The gear association module 213 links the gear module to a target element, such as terminal device 101 or eUICC 103. Terminal device 101 or eUICC 103 can be an implementation of a second device. The gear download module 217 downloads the gear module to terminal device 101 or eUICC 103. The gear_DB module or gear database module 215 stores associated gear modules and prepared gear modules, ready to be downloaded to device 101 or eUICC 103. The gear remote manager module 219 performs remote gear management operations, such as enabling, disabling, and updating the gear, and uses enabler function commands such as updating enabler, adding function enabler, deleting function enabler, disabling enabler, deleting enabler, and locking enabler to perform remote enabler module management operations. In this way, the gear module can be generated and stored in engine 105, associated with device 101 or eUICC 103, and downloaded to device 101 or eUICC 103, thereby flexibly implementing the security functions in device 101 or eUICC 103. In one implementation, eUICC 103 can be replaced by a subscriber identity module (SIM), an embedded subscriber identity module (eSIM), or a smart card.

[0079] Figure 3 An example of a process flow for generating a gear module is shown, in which one of the exemplary implementations of this disclosure can be carried out.

[0080] In process flow 300, for example, a third device 301 of operator 107 sends (305) a request 310 for generating gear modules to a first device 201 of engine 105; the first device receives the request 310. The request 310 includes at least one of the following: at least one requirement information for the gear modules; at least one quantity of gear modules; or an identifier of a second device. The requirement information includes: at least one security function, a gear identifier (ID) for the gear modules. For example, at least one security function includes one or more of encryption functions, post-quantum encryption functions, and homomorphic functions. For example, the device identifier includes the International Mobile Subscriber Identity (IMSI) in a SIM card or eUICC, the eUICC Identification Number (EID) of an eUICC, etc. At 315, the first device performs gear initialization, for example, generating gear modules according to request 310, for example, generating gear modules using the gear ID in request 310. At point 325, the first device 201 sends (325) an acknowledgment or response 330 of the completed process to the third device 301, and the third device 301 receives the response 330. The response 330 includes success or failure. Additionally, the response 330 may include a reason for failure. In one implementation, before sending the (325) response 325, at point 320, the first device 201 performs gear association, for example, associating the gear module with IMSI and EID, and storing the generated gear module in Gear_DB 215 in the first device 201. This allows for flexible generation of gear modules in the first device 210 according to the requirements of the third device 301.

[0081] Figure 4 An example of a process flow for downloading and installing a gear module is shown, in which one of the exemplary implementations of this disclosure can be carried out.

[0082] In one implementation, the second device 401 sends (405) a request 410 to the first device 201 for downloading the gear module, and the first device 201 receives the request 410. Mutual authentication 420 (415) is performed between the first device 201 and the second device 401. Optionally, mutual authentication 420 can be performed before the second device 401 sends (405) the request 410. At 430, the first device binds the gear module to a session key. The session key can be used as an encryption key in sessions such as gear downloads between the first device 201 and the second device 401 to ensure secure communication between them. The first device 201 sends (435) a request for the gear module 440 to the second device 401, and the second device 401 receives the gear module 440. At 450, the second device 401 installs the gear module. In this way, the gear module can be securely downloaded from the first device 201 using a session key and installed in the second device 401 to provide security functions in the second device 401.

[0083] Figure 5 An example of a process flow for downloading and installing a gear module into an eUICC, which can implement one exemplary implementation of this disclosure, is shown. In process flow 500, engine 105, eUICC 103, and operator 107 can individually implement first device 201, second device 401, and third device 301. Figure 5 In process flow 500, the gear module can be securely downloaded from engine 105 to eUICC 103 via device 101 and installed in eUICC 103, ultimately providing flexible security functions in eUICC 103.

[0084] In one implementation, the initial conditions for process flow 500 are that eUICC 103 has an enabled configuration file in the gear module, the gear requirement has been submitted to engine 105 by operator 107, and the gear module has been initialized, associated, and stored in Gear_DB 215. Device 101 sends a (505) download request 510 to engine 105. Download request 510 includes at least one of the following: at least one requirement information for the gear module; at least one number of gear modules; or an identifier of a second device, such as the EID of the received eUICC information. eUICC 103 and engine 105 perform a (515) secure channel establishment 520 through device 101 for gear download from engine 105 to eUICC 103. Secure channel establishment 520 includes mutual authentication and session key generation between engine 105 and eUICC 103. At 530, engine 105 searches for the gear module associated with the received eUICC information, such as the corresponding EID, in gear_DB 215. At 540, engine 105 binds the gear module to the session key generated by eUICC 103 in gear association module 213. Using gear download module 217, engine 105 sends (545) the gear module 550 with the session key to eUICC 103 via device 101. At 560, eUICC 103 installs the gear module. eUICC 103 sends (565) a notification 570 to engine 105 via device 101 regarding the success or failure of the download operation. Engine 105 sends (575) a notification 580 to operator 107 regarding the download of the gear module. In this way, eUICC 103 can download the appropriate gear module from engine 105 via a secure channel upon request, then install the gear module, and flexibly provide security functions after the gear module is installed.

[0085] Figure 6 This illustration shows an example of a process flow for mutual authentication between eUICC and the engine, which can implement one exemplary implementation of this disclosure. Process flow 600 may be... Figure 5 The implementation method of establishing a secure channel in 520.

[0086] In one implementation, at 610, eUICC 103 generates a nonce_eUICC, which is a random number generated by eUICC 103. eUICC 103 sends (613) nonce_eUICC 615 to device 101, and device 101 sends (617) nonce_eUICC 615 to engine 105. In some embodiments, operations such as receiving (613) nonce_eUICC 615 from eUICC 103, sending (617) nonce_eUICC 615 to engine 105, and other operations in device 101 can be implemented in a management entity in device 101. At 620, engine 105 generates a nonce_Engine, which is a random number generated in engine 105, and signs the random numbers such as nonce_eUICC and nonce_Engine with a private key. Engine 105 sends (623) random number information 625 to device 101. The random number information is determined based on the engine's certificate, the random number signature, and the random number. For example, random number information 625 is engine_certificate || engine_sign( nonce_eUICC, nonce_engine )|| nonce_engine || nonce_eUICC 625. "||" is the connection operation, and "engine_sign" is the signature operation in engine 105. At 630, device 101 verifies the certificate with the engine ID and forwards the information. Device 101 sends (632) random number information 625 to eUICC 103. At 635, eUICC 103 verifies the certificate and public key information using the public key extracted from the verified certificate, and verifies the signature of engine 105. Then, eUICC 103 generates session key parameters and signs the parameters using the private key. eUICC 103 sends (638) session key information 640 to device 101. The session key information is determined based on the eUICC certificate, the signature of the random number, the session key parameters, the eUICC information, the device information, and the random number. For example, the session key information is eUICC_certificate || eUICC_sign(nonce_eUICC, nonce_engine, session key parameters, eUICC information, device information) || nonce_engine || nonce_eUICC || session key parameters, eUICC information, device information 640 to device 101. The session key parameters can be Diffie-Hellman key exchange parameters of the Diffie-Hellman scheme, or Elliptic-curve Diffie-Hellman (ECDH) parameters.Those skilled in the art will understand that the session key parameter can also be other parameters. "||" represents a connection operation, and "eUICC_sign" represents a signature operation in eUICC 103. Device 101 forwards (642) the following to engine 105: eUICC_certificate || eUICC_sign(nonce_eUICC, nonce_engine, session key parameter, eUICC information, device information) || nonce_engine || nonce_eUICC || session key parameter, eUICC information, device information 640. At 645, engine 105 verifies the certificate and the public key information in the certificate, and verifies the signature of the eUICC using the public key extracted from the verified certificate. At 650, engine 105 generates a session key based on the session key parameters exchanged during mutual authentication. Thus, eUICC 103 and engine 105 mutually verify each other by signing with a private key and verifying with a public key. The session key can be generated as a symmetric encryption key during the communication session between eUICC 103 and engine 105 to reduce encryption complexity. After establishing a secure channel, data can be encrypted and subjected to a secure MAC. Those skilled in the art will understand that the session key parameter can be other parameters.

[0087] Figure 7 An example of a process flow for downloading and installing a gear module into a device, which may implement one exemplary implementation of the present disclosure, is shown. In process flow 700, engine 105, device 101, and operator 107 may respectively implement first device 201, second device 401, and third device 301. In one implementation, the initial conditions of process flow 700 are that device 101 has an enabled configuration file, a gear requirement has been submitted by operator 107, and the gear module has been initialized, associated, and stored in Gear_DB 215. Figure 7 In process flow 700, the gear module can be securely downloaded from engine 105 to device 101 and installed in device 101, ultimately providing security functions flexibly in device 101.

[0088] In one implementation, device 101 sends a download request 710 (708) to engine 105. Device 101 and engine 105 perform a secure channel establishment 715 (713). The secure channel establishment 715 includes mutual authentication and session key generation between engine 105 and device 101. At 720, engine 105 looks up the gear module in gear_DB 215 associated with the eUICC information received, such as the corresponding EID from the download request 710. At 725, engine 105 binds the gear module to the session key generated by device 101. Engine 105 sends the gear module 730 (728) to device 101. At 735, device 101 installs the gear module. Device 101 sends a notification 740 (738) to engine 105 regarding the success or failure of the download operation. Engine 105 sends a notification 743 (743) to operator 107 regarding the download of the gear module. In this way, device 101 can download the appropriate gear module from engine 105 via a secure channel upon request, and flexibly provide security functions after the gear module is installed.

[0089] Figure 8 An example of a process flow for mutual authentication between a device and an engine, in which one exemplary implementation of this disclosure is shown, is illustrated. Process flow 800 may be... Figure 7 The implementation method of establishing a secure channel in 715.

[0090] In one implementation, at 810, device 101 generates a nonce_device, or a random number generated within device 101. The device sends (613) nonce_device 815 to engine 105. At 820, engine 105 generates a nonce_engine and signs the random number with its private key. Engine 105 sends (823) random number information 825 to device 101, which is determined based on the engine's certificate, the random number's signature, and the random number. For example, random number information 825 is engine_certificate || engine_sign( nonce_device, nonce_engine ) || nonce_engine || nonce_device 825. "||" can be a concatenation operation, and "engine_sign" can be a signature operation within engine 105. At 830, device 101 verifies the certificate and public key information using the public key extracted from the verified certificate, and verifies the signature of engine 105. Device 101 also generates session key parameters and signs the parameters with its private key. Device 101 sends (833) a request for eUICC information to eUICC 103 (835). eUICC 103 sends (838) a response for eUICC information (840). Device 101 sends (843) session key information to engine 105 (840), the session key information being determined based on device 101's certificate, the signature of the random number, the session key parameters, the eUICC information, the device information, and the random number, session key parameters, and device information. For example, the session key information is device_certificate || device_sign(nonce_device, nonce_engine, session key parameters, device information, eUICC information) || nonce_engine || nonce_device || session key parameters, device information to engine 105. At 850, engine 105 verifies the certificate and the public key information in the certificate, then verifies device 101's signature using the public key extracted from the verified certificate, and then checks the device requirements. At 855, engine 105 generates a session key using parameters exchanged during mutual authentication. Thus, device 101 and engine 105 mutually authenticate each other by signing with a private key and verifying with a public key. The session key can be generated as a symmetric encryption key during the communication session between device 101 and engine 105 to reduce encryption complexity. After establishing a secure channel, data is encrypted and subjected to a secure MAC.

[0091] Figure 9An example of a process flow for downloading and installing a gear module into a device with the aid of eUICC, which can implement one exemplary implementation of this disclosure, is shown. In process flow 800, engine 105, device 101, and operator 107 can be implemented individually as first device 201, second device 401, and third device 301. In one implementation, the initial conditions of process flow 900 are that device 101 has an enabled configuration file, the gear requirement has been submitted by operator 107, and the gear module has been initialized, associated, and stored in Gear_DB 215. Figure 9 In process flow 900, the gear module can be safely downloaded from engine 105 to device 101 with the help of eUICC 103 and installed in device 101, ultimately providing security functions flexibly in device 101.

[0092] In one implementation, device 101 sends a download request (905) 910 to engine 105. eUICC 103 and engine 105 perform a secure channel establishment (915) 920 via device 101. The secure channel establishment 920 includes mutual authentication and session key generation between engine 105 and eUICC 103. At 930, engine 105 locates the gear module associated with eUICC information received from request 910, such as the EID. At 940, engine 105 binds the gear module to target device 101. Engine 105 sends a (945) request for the gear module to device 101 950. At 960, device 101 installs the gear module. Device 101 sends a (965) notification (975) to engine 105 regarding the success or failure of the download operation 970. Engine 105 sends a (975) notification (980) to operator 107 regarding the download of the gear module. In this way, device 101 can download the appropriate gear module from engine 105 via a secure channel upon request, and flexibly provide security functions after the gear module is installed.

[0093] In one implementation, during the mutual authentication between the engine and the eUICC in 920, eUICC 103 authenticates engine 105 by verifying the certificate and public key information, and by verifying the signature of engine 105 using the public key extracted from the verified certificate. Engine 105 authenticates eUICC 103 by verifying the certificate and the public key information in the certificate, and by verifying the signature of device 101 using the public key extracted from the verified certificate. The session key is generated from the parameters exchanged during mutual authentication. In one implementation, the entire process of establishing the secure channel in 920 can be synchronized with... Figure 6The process flow is the same as 600. After establishing a secure channel, the data is encrypted and a secure MAC is applied. A session key can be generated as a symmetric encryption key during the communication session between device 101 and engine 105 to reduce encryption complexity. After establishing a secure channel, the data is encrypted and a secure MAC is applied.

[0094] Figure 10 An example of the process flow of a first apparatus 201 illustrating one exemplary implementation of the present disclosure is provided.

[0095] In block 1010, the first device 201 receives a request from the third device 301 to generate a gear module for the second device 401, wherein the gear module is used to provide one or more security functions in the second device 401. In block 1020, the first device 201 generates the gear module for the second device 401 according to the request. In block 1030, the first device 201 sends a response to the request to the third device 301.

[0096] In one implementation, after generating the gear module, the first device 201 also associates the generated gear module with the identifier of the second device. In another implementation, the first device 201 also stores the generated gear module in the first device 201.

[0097] Figure 11 An example of the process flow of a third apparatus 301 illustrating one exemplary implementation of this disclosure is provided.

[0098] In block 1110, the third device 301 sends a request to the first device 201 for the first device 201 to generate a gear module for the second device 401, wherein the gear module is used to provide one or more security functions in the second device 401. In block 1120, the third device 301 receives a response to the request from the first device 201.

[0099] In one implementation, the request includes at least one of the following: at least one requirement information for the gear module; at least one quantity of gear modules; or an identifier of the second device. In one implementation, the response includes at least one of the following: an indication of successful or failed generation of the gear module; or a reason for failure.

[0100] Figure 12 An example of the process flow of a first apparatus 201 illustrating one exemplary implementation of the present disclosure is provided.

[0101] In block 1210, the first device 201 receives a request from the terminal device to download the gear module from the first device 201 to the second device 401. In block 1220, the first device 201 binds the gear module to a session key generated for the second device 401. In block 1230, the first device 201 sends the gear module to the second device 401, wherein the gear module is used to provide one or more security functions in the second device 401.

[0102] In one implementation, the first device 201 further performs mutual authentication between the first device 201 and the second device 401, wherein the session key is generated during the mutual authentication. In another implementation, the first device 201 further obtains at least one parameter for generating the session key from the second device during the mutual authentication; and generates the session key based on the at least one parameter obtained during the mutual authentication.

[0103] In one implementation, the gear module is associated with a second device 401. In one implementation, the second device 401 is one of the following: a terminal device; or a security device within the terminal device. In one implementation, the second device 401 is a terminal device, and the first device 201 also receives a request from the terminal device to download the gear module from the first device 201 to the terminal device.

[0104] In one implementation, before binding the gear module and session key, the first device 201 further searches for the gear module in the first device based on the identifier of the second device. In another implementation, the first device 201 also receives an indication from the second device 401 indicating whether the gear module download was successful or failed. In yet another implementation, upon receiving an indication that the gear module download was successful, the first device 201 further sends an instruction to the third device 301 to download the gear module to the second device 401.

[0105] Figure 13 An example of the process flow of a second apparatus 401 illustrating one exemplary implementation of this disclosure is provided.

[0106] In block 1310, the second device 401 sends a request to the first device to download the gear module from the first device 201 to the second device 401. In block 1320, the second device 401 performs mutual authentication between the first device 201 and the second device 401. In block 1330, the second device 401 receives the gear module from the first device 201. The gear module is bound to a session key generated for the second device 401, wherein the gear module is used to provide one or more security functions in the second device.

[0107] In one implementation, if the second device 401 is a terminal device, the terminal device or its security device performs mutual authentication with the first device 201. Alternatively, if the second device 401 is a security device within the terminal device, the security device performs mutual authentication with the first device 201.

[0108] In one implementation, the second device 401 further generates at least one parameter for generating a session key during mutual authentication; and provides at least one parameter to the first device 201 during mutual authentication. In one implementation, the second device 401 further sends an indication to the first device 201 of whether the gear module download was successful or failed. In one implementation, the second device 401 includes at least one of the following: a terminal device; or a security device within the terminal device.

[0109] Figure 14 A simplified block diagram of a communication device 1400 suitable for implementing one exemplary embodiment of the present disclosure is shown. For example, the communication device 1400 may be provided to implement the first device 201, the second device 401, or the third device 301.

[0110] like Figure 14 As shown, the communication device 1400 includes one or more processors 1410 and one or more communication interfaces 1420. Optionally, the communication device 1400 includes one or more memories 1430. The memories 1430 may be integrated with the processors 1410 or external to the communication device 1400. The processors 1410 may be of any type suitable for a local technology network and may include one or more of the following: general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), and processors based on multi-core processor architectures, as non-limiting examples. The communication device 1400 may have multiple processors, such as application-specific integrated circuit chips that are time-dependent on a clock synchronized with a main processor.

[0111] Memory 1430 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to: read-only memory (ROM), electrically programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital video disk (DVD), and other magnetic and / or optical storage. Examples of volatile memories include, but are not limited to: random access memory (RAM) and other volatile memories that cannot retain data during power outages.

[0112] Communication interface 1420 can be used for bidirectional communication. The memory can be integrated with the processor or external to the communication device. Communication interface 1420 may have at least one antenna to facilitate communication. Communication interface 1420 can represent any interface required for communication with other network elements.

[0113] Processor 1410 is used to control communication interface 1420 to receive and send signals. Memory 1430 is used to store computer programs. Processor 1410 is used to retrieve and run the computer program from memory 1430, enabling communication device 1400 to execute corresponding processes and / or operations in various implementations of the communication method in this application.

[0114] Figure 15 Another simplified block diagram of a first apparatus suitable for implementing one exemplary embodiment of the present disclosure is shown. (See diagram below.) Figure 15 As shown, the first device 201 includes a transmission unit 1510, a receiving unit 1520, and a processing unit 1530.

[0115] In one implementation, receiving unit 1520 receives from third device 301 a request from first device 201 to generate a gear module for second device 401, wherein the gear module is used to provide one or more security functions in second device 401. Transmitting unit 1510 sends a response to the request to third device 301. Determining unit 1530 generates a gear module for second device 401 according to the request.

[0116] In one implementation, receiving unit 1520 receives a request from a terminal device to download a gear module from a first device to a second device 401. Transmitting unit 1510 sends the gear module to the second device 401, wherein the gear module is used to provide one or more security functions in the second device 401. Processing unit 1530 binds the gear module to a session key generated for the second device 401.

[0117] Figure 16 A simplified block diagram of a third apparatus suitable for implementing one exemplary embodiment of this disclosure is shown. Figure 16 As shown, the third device 301 includes a transmission unit 1610 and a receiving unit 1620. The transmission unit 1610 sends a request to the first device 201 to generate a gear module for the second device 401, wherein the gear module is used to provide one or more security functions in the second device 401. The receiving unit 1620 receives a response to the request from the first device 201.

[0118] Figure 17 Another simplified block diagram of a second apparatus suitable for implementing one exemplary embodiment of this disclosure is shown. (See diagram below.) Figure 17 As shown, the second device 401 includes a transmission unit 1710, a receiving unit 1720, and a processing unit 1730. The receiving unit 1720 receives a gear module from the first device 201. The transmission unit 1710 sends a request to the first device 201 to download the gear module from the first device 201 to the second device 401. The processing unit 1730 performs mutual authentication between the first device 201 and the second device 401 and installs the gear module in the second device 401, wherein the gear module is used to provide one or more security functions in the second device 401.

[0119] Those skilled in the art will recognize that, based on the units and algorithm steps described in the examples of the implementations disclosed in this specification, this application can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether the function is executed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but should not consider such implementations to be beyond the scope of this application.

[0120] Those skilled in the art will clearly understand that, for ease of description and simplification, the specific working processes of the above-described systems, devices, and units are referred to the corresponding processes in the above-described method implementations, and details will not be described further herein.

[0121] Among the several implementations provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the described apparatus embodiments are merely examples. For instance, the unit division is only a logical functional division, and other division methods may exist in actual implementation. For example, multiple units or components may be merged or integrated into another system, or some features may be ignored or not performed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed can be implemented through some interfaces. Indirect coupling or communication connection between apparatuses or units can be implemented electronically, mechanically, or in other forms.

[0122] Units described as individual components may or may not be physically separate; components displayed as units may or may not be physical units, may be located in the same location, or may be distributed among multiple network units. Some or some units can be selected to achieve the purpose of this implementation scheme according to actual requirements.

[0123] Furthermore, in the implementation of this application, the functional units can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0124] When these functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to conventional solutions, or a portion of the technical solution, can be implemented in the form of a software product. This software product is stored in a storage medium and includes several instructions to instruct a computer device (which may be a personal computer, server, or network device) to execute all or part of the steps of the method described in the implementation of this application. The aforementioned storage medium includes any medium capable of storing program code, such as a USB flash drive, a portable hard drive, read-only memory (ROM), random access memory (RAM), a magnetic disk, or an optical disk.

[0125] The above description is merely a specific implementation of this application and is not intended to limit the scope of protection of this application. Any variations or substitutions that are readily conceived by those skilled in the art within the scope of the technology disclosed in this application are within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A first device, characterized in that, Includes at least one of the following: A first module is used to generate a gear module for a second device, wherein the gear module is used to provide one or more security functions in the second device; The second module is used to perform the downloading of the gear module from the first device to the second device; or The third module is used to associate the gear module with the second device before downloading the gear module to the second device.

2. The first device according to claim 1, characterized in that, It also includes at least one of the following: A fourth module is used to store the gear module before downloading it to the second device; or The fifth module is used to perform at least one operation on the gear module after it has been downloaded to the second device.

3. The first device according to claim 1 or 2, characterized in that, The second device is one of the following: Terminal equipment; or The security device in the terminal equipment.

4. The first device according to claim 3, characterized in that, The safety device includes at least one of the following: Universal Integrated Circuit Card (UICC); Embedded Universal Integrated Circuit Card (eUICC); User identification module (SIM); Embedded User Identity Module (eSIM); or Smart card.

5. A method, characterized in that, include: The first device receives a request from the third device to generate a gear module for the second device, wherein the gear module is used to provide one or more security functions in the second device; Generate the gear module for the second device according to the request; Send a response to the request to the third device.

6. The method according to claim 5, characterized in that, Also includes: After the gear module is generated, the generated gear module is associated with the identifier of the second device.

7. The method according to claim 5 or 6, characterized in that, Also includes: The generated gear module is stored in the first device.

8. A method, characterized in that, include: The third device sends a request to the first device for the first device to generate a gear module for the second device, wherein the gear module is used to provide one or more security functions in the second device; Receive a response to the request from the first device.

9. The method according to any one of claims 5 to 8, characterized in that, The request includes at least one of the following: At least one requirement for the gear module; At least the number of gear modules; or The identifier of the second device.

10. The method according to any one of claims 5 to 9, characterized in that, The response includes at least one of the following: The gear module generation success or failure indication; or The reason for the failure.

11. A method, characterized in that, include: At the first device, a request is received from the terminal device to download the gear module from the first device to the second device; Bind the gear module to the session key generated for the second device; The gear module is sent to the second device, wherein the gear module is used to provide one or more security functions in the second device.

12. The method according to claim 11, characterized in that, Also includes: Mutual authentication is performed between the first device and the second device, wherein the session key is generated during the mutual authentication.

13. The method according to claim 11 or 12, characterized in that, Also includes: During the mutual authentication process, at least one parameter for generating the session key is obtained from the second device; The session key is generated based on at least one parameter obtained during the mutual authentication process.

14. The method according to any one of claims 11 to 13, characterized in that, The gear module is associated with the second device.

15. The method according to any one of claims 11 to 14, characterized in that, The second device is one of the following: Terminal equipment; or The security device in the terminal equipment.

16. The method according to claim 15, characterized in that, The second device is a terminal device, and the method further includes: Receive a request from the terminal device to download the gear module from the first device to the terminal device.

17. The method according to any one of claims 11 to 16, characterized in that, Also includes: Before binding the gear module and the session key, the gear module is searched for in the first device based on the identifier of the second device.

18. The method according to any one of claims 11 to 17, characterized in that, Also includes: Receive an indication from the second device whether the download of the gear module was successful or failed.

19. The method according to claim 18, characterized in that, Also includes: Based on the received indication that the gear module has been successfully downloaded, an instruction is sent to the third device to download the gear module to the second device.

20. A method, characterized in that, include: The second device sends a request to the first device to download the gear module from the first device to the second device. Perform mutual authentication between the first device and the second device; Receive the gear module from the first device. The gear module is bound to a session key generated for the second device, and the gear module is used to provide one or more security functions in the second device.

21. The method according to claim 20, characterized in that, The method further includes: Mutual authentication is performed between the first device and the second device, wherein the session key is generated during the mutual authentication.

22. The method according to claim 21, characterized in that, Satisfy at least one of the following: When the second device is a terminal device, the terminal device or the security device in the terminal device performs the mutual authentication with the first device. or In the case where the second device is the security device in the terminal device, the security device performs the mutual authentication with the first device.

23. The method according to claim 21 or 22, characterized in that, Also includes: During the mutual authentication process, at least one parameter is generated for generating the session key; During the mutual authentication process, at least one parameter is provided to the first device.

24. The method according to any one of claims 20 to 23, characterized in that, Also includes: Send an indication to the first device whether the download of the gear module was successful or failed.

25. The method according to any one of claims 20 to 24, characterized in that, The second device is one of the following: Terminal equipment; or The security device in the terminal equipment.

26. An apparatus, characterized in that, include: At least one processor is coupled to at least one memory, the memory storing programming instructions executable by the at least one processor, which, when executed by the at least one processor, cause the apparatus to perform the method according to any one of claims 5 to 24.

27. A computer-readable storage medium, characterized in that, The device stores instructions that, when executed by one or more processors of the device, cause the computing device to perform the method according to any one of claims 5 to 24.

28. A computer program, characterized in that, Includes instructions that, when executed by the device, cause the device to perform the method according to any one of claims 5 to 24.

29. A communication device, characterized in that, include: A receiving unit is configured to receive from a third device a request from the communication device to generate a gear module for a second device, wherein the gear module is configured to provide one or more security functions in the second device; Processing unit, configured to generate the gear module for the second device according to the request; A transmission unit is used to send a response to the request to the third device.

30. The communication device according to claim 29, characterized in that, The processing unit is further configured to associate the generated gear module with the identifier of the second device after generating the gear module.

31. The communication device according to claim 29 or 30, characterized in that, The processing unit is also used to store the generated gear module in the communication device.

32. A communication device, characterized in that, include: A transmission unit is configured to send a request to a first device for the first device to generate a gear module for a second device, wherein the gear module is configured to provide one or more security functions in the second device; A receiving unit is configured to receive a response to the request from the first device.

33. The communication device according to any one of claims 29 to 32, characterized in that, The request includes at least one of the following: At least one requirement for the gear module; At least the number of gear modules; or The identifier of the second device.

34. The apparatus according to any one of claims 29 to 33, characterized in that, The response includes at least one of the following: The gear module generation success or failure indication; or The reason for the failure.

35. A communication device, characterized in that, include: A receiving unit is configured to receive from a terminal device a request to download the gear module from the communication device to a second device; A processing unit is configured to bind the gear module to a session key generated for the second device; A transmission unit is configured to send the gear module to the second device, wherein the gear module is configured to provide one or more security functions in the second device.

36. The communication device according to claim 35, characterized in that, The processing unit is further configured to perform mutual authentication between the communication device and the second device, wherein the session key is generated during the mutual authentication.

37. The communication device according to claim 35 or 36, characterized in that: The processing unit is further configured to obtain at least one parameter for generating the session key from the second device during the mutual authentication; and generate the session key based on the at least one parameter obtained during the mutual authentication.

38. The communication device according to any one of claims 35 to 37, characterized in that, The gear module is associated with the second device.

39. The communication device according to any one of claims 35 to 38, characterized in that, The second device is one of the following: Terminal equipment; or The security device in the terminal equipment.

40. The communication device according to claim 39, characterized in that, The second device is a terminal device, and the receiving unit is further configured to receive from the terminal device a request to download the gear module from the communication device to the terminal device.

41. The communication device according to any one of claims 35 to 40, characterized in that, The processing unit is also configured to search for the gear module in the communication device based on the identifier of the second device before binding the gear module and the session key.

42. The communication device according to any one of claims 35 to 41, characterized in that, The receiving unit is also used to receive an indication from the second device whether the download of the gear module was successful or failed.

43. The communication device according to claim 42, characterized in that, The transmission unit is used to send an instruction to the third device to download the gear module to the second device according to the instruction that the download of the gear module is successful received.

44. A communication device, characterized in that, include: A transmission unit is configured to send a request to the first device to download the gear module from the first device to the communication device. A processing unit is configured to perform mutual authentication between the first device and the communication device; A receiving unit is configured to receive the gear module from the first device; The gear module is bound to a session key generated for the communication device, and the gear module is used to provide one or more security functions in the communication device.

45. The communication device according to claim 44, characterized in that, The processing unit is further configured to perform mutual authentication between the first device and the communication device, wherein the session key is generated during the mutual authentication.

46. ​​The communication device according to claim 45, characterized in that, Satisfy at least one of the following: When the communication device is a terminal device, the terminal device or the security device in the terminal device performs the mutual authentication with the first device; or In the case where the communication device is the security device in the terminal device, the security device performs the mutual authentication with the first device.

47. The communication device according to claim 45 or 46, characterized in that, The processing unit is further configured to generate at least one parameter for generating the session key during the mutual authentication process; and to provide the at least one parameter to the first device during the mutual authentication process.

48. The apparatus according to any one of claims 44 to 47, characterized in that, The transmission unit is also used to send an indication to the first device whether the download of the gear module was successful or failed.

49. The apparatus according to any one of claims 44 to 48, characterized in that, The communication device is one of the following: Terminal equipment; or The security device in the terminal equipment.