Terminal operation method, apparatus, device, and storage medium

By establishing a binding relationship between the terminal and the eSIM card and querying its status, the operation of unbound eSIM cards is restricted, thus solving the problem of eSIM card abuse and improving security and usage restrictions.

CN122227222APending Publication Date: 2026-06-16GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411844700.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2026-06-16

AI Technical Summary

Technical Problem

In existing technologies, eSIM cards are easily removed and transferred to other devices for illegal activities, leading to the abuse of virtual numbers and a lack of effective binding and restriction mechanisms.

Method used

By establishing a binding relationship between the terminal and the eSIM card, the binding status of the eSIM card can be queried, and its operation can be restricted if it is not bound, including verifying the binding relationship and restricting the use of the eSIM card.

Benefits of technology

It enables secure binding of eSIM cards, preventing their use on unauthorized devices, thus improving security and preventing abuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122227222A_ABST
    Figure CN122227222A_ABST
Patent Text Reader

Abstract

The application discloses a terminal running method and device, equipment and storage medium, and relates to the field of mobile communication. The method comprises the following steps: a binding state query request is sent to an embedded subscriber identity module (eSIM) card, the binding state query request is used for querying the binding state of the eSIM card; the binding state is used for indicating whether the eSIM card is bound with a device; in the case that the binding state is bound, the binding relationship between the eSIM card and the terminal is checked to obtain a checking result; the binding relationship is used for indicating whether the device bound with the eSIM card is the terminal; and in the case that the checking result indicates that the eSIM card is not bound with the terminal, the running of the eSIM card is limited. The terminal can be bound with the eSIM card, and the running of the eSIM card on the terminal is limited according to the binding state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of mobile communications, and in particular to a terminal operation method, apparatus, device, and storage medium. Background Technology

[0002] eSIM (Embedded-SIM) is a technology that embeds a traditional SIM (Subscriber Identity Module) card directly onto a device's chip. Users can select and activate a carrier network through the device's settings menu or a carrier application. The entire process does not require disassembling the device or replacing the SIM card; it only requires an internet connection. eSIM uses Remote SIM Provisioning (RSP) technology to activate and manage the user's communication services.

[0003] Because eSIM cards support online activation of virtual numbers, some users activate the eSIM card in their devices, then remove it, solder it into a regular SIM card, and insert this regular SIM card into their terminals to commit illegal activities. After the virtual number is blocked, they remove the eSIM card, put it back in the device, and reactivate a virtual number, thus activating a large number of virtual numbers to carry out illegal activities.

[0004] Therefore, a solution is urgently needed to limit this behavior. Summary of the Invention

[0005] This application provides a terminal operation method, apparatus, device, and storage medium that can bind a terminal to an eSIM card and restrict the operation of the eSIM card on the terminal based on the binding details. The technical solution is as follows:

[0006] According to one aspect of this application, a terminal operation method is provided, the method being executed by the terminal, the method comprising:

[0007] A binding status query request is sent to the embedded user identity recognition module (eSIM card). The binding status query request is used to query the binding status of the eSIM card. The binding status is used to indicate whether the eSIM card is bound to the device.

[0008] If the binding status is "bound", the binding relationship between the eSIM card and the terminal is verified to obtain a verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal.

[0009] If the verification result indicates that the eSIM card is not bound to the terminal, the operation of the eSIM card is restricted.

[0010] According to one aspect of this application, a terminal operation method is provided, the method being executed by an eSIM card in the terminal, the method comprising:

[0011] In response to the binding status query request sent by the terminal, a binding status is sent to the terminal; the binding status is used to indicate whether the eSIM card is bound to the device.

[0012] If the binding status is "bound", the binding relationship between the eSIM card and the terminal is verified to obtain a verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal.

[0013] If the verification result indicates that the eSIM card is not bound to the terminal, the operation of the eSIM card is restricted.

[0014] According to one aspect of this application, a terminal operating device is provided, the device comprising:

[0015] The first query module is used to send a binding status query request to the eSIM card. The binding status query request is used to query the binding status of the eSIM card. The binding status is used to indicate whether the eSIM card is bound to the device.

[0016] The first verification module is used to verify the binding relationship between the eSIM card and the terminal when the binding status is "bound" to obtain a verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal.

[0017] The first control module is used to restrict the operation of the eSIM card when the verification result indicates that the eSIM is not bound to the terminal.

[0018] According to one aspect of this application, a terminal operating device is provided, the device comprising:

[0019] The second query module is used to respond to the binding status query request sent by the terminal and send the binding status to the terminal; the binding status is used to indicate whether the eSIM card is bound to the device;

[0020] The second verification module is used to verify the binding relationship between the eSIM card and the terminal when the binding status is "bound" to obtain a verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal.

[0021] The second control module is used to restrict the operation of the eSIM card when the verification result indicates that the eSIM is not bound to the terminal.

[0022] According to one aspect of this application, a terminal is provided, the terminal comprising: a processor; a transceiver connected to the processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to load and execute the executable instructions to implement the terminal operation method as described above.

[0023] According to one aspect of this application, a terminal is provided, the terminal comprising: a processor; a transceiver connected to the processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to load and execute the executable instructions to implement the terminal operation method as described above.

[0024] According to one aspect of this application, a computer-readable storage medium is provided, wherein executable program code is stored therein, the executable program code being loaded and executed by a processor to implement the terminal operation method as described above.

[0025] According to one aspect of this application, a chip is provided, the chip including programmable logic circuitry and / or program instructions, which, when the chip is run on a communication device, are used to implement the terminal operation method as described above.

[0026] According to one aspect of this application, a computer program product is provided, which, when executed by a processor of a communication device, is used to implement the terminal operation method described above.

[0027] According to one aspect of this application, a computer program is provided to be executed by a processor of a communication device to implement the terminal operation method described above.

[0028] The technical solutions provided in this application have at least the following beneficial effects:

[0029] Bind the terminal to the eSIM card. The terminal can query the eSIM card's binding status and verify whether the eSIM card is bound to the current terminal. If the eSIM card is not bound to the current terminal, its operation is restricted. This ensures that the eSIM card can only be used on the bound terminal, limiting its migration to other devices and restricting the use of unbound eSIM cards on the terminal, thus improving eSIM card security and preventing its abuse. Attached Figure Description

[0030] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0031] Figure 1 A block diagram of a terminal provided in an exemplary embodiment of this application is shown;

[0032] Figure 2 A schematic diagram of a terminal provided in an exemplary embodiment of this application is shown;

[0033] Figure 3 A flowchart illustrating a terminal operation method provided in an exemplary embodiment of this application is shown;

[0034] Figure 4 A flowchart illustrating a terminal operation method provided in an exemplary embodiment of this application is shown;

[0035] Figure 5 A flowchart illustrating a terminal operation method provided in an exemplary embodiment of this application is shown;

[0036] Figure 6 A flowchart illustrating a terminal operation method provided in an exemplary embodiment of this application is shown;

[0037] Figure 7 A flowchart illustrating a terminal operation method provided in an exemplary embodiment of this application is shown;

[0038] Figure 8 A flowchart illustrating a terminal operation method provided in an exemplary embodiment of this application is shown;

[0039] Figure 9 A flowchart illustrating a terminal operation method provided in an exemplary embodiment of this application is shown;

[0040] Figure 10 A flowchart illustrating a terminal operation method provided in an exemplary embodiment of this application is shown;

[0041] Figure 11 A flowchart illustrating a terminal operation method provided in an exemplary embodiment of this application is shown;

[0042] Figure 12 A block diagram of a terminal operating device provided in an exemplary embodiment of this application is shown;

[0043] Figure 13 A block diagram of a terminal operating device provided in an exemplary embodiment of this application is shown;

[0044] Figure 14 A schematic diagram of the structure of a communication device provided in an exemplary embodiment of this application is shown. Detailed Implementation

[0045] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0046] In this document, the terms "system" and "network" are often used interchangeably. The term "and / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Additionally, the character " / " generally indicates an "or" relationship between the preceding and following related objects. It should also be understood that "instruction" mentioned in the embodiments of this application can be a direct instruction, an indirect instruction, or an indication of a related relationship. For example, A instructing B can mean that A directly instructs B, for example, B can be obtained through A; it can also mean that A indirectly instructs B, for example, A instructs C, B can be obtained through C; or it can mean that there is a related relationship between A and B. It should also be understood that "correspondence" mentioned in the embodiments of this application can indicate a direct or indirect correspondence between two objects, or an related relationship between two objects, or a relationship of instruction and being instructed, configuration and being configured, etc. It should also be understood that the "predefined," "protocol agreement," "predetermined," or "predefined rule" mentioned in the embodiments of this application can be implemented by pre-storing corresponding codes, tables, or other methods that can be used to indicate relevant information in the device (e.g., including network devices and terminals). This application does not limit the specific implementation method. For example, predefined can refer to what is defined in a protocol. It should also be understood that in the embodiments of this application, the "protocol" can refer to standard protocols in the field of communication, such as the LTE protocol, the NR protocol, and related protocols applied to future communication systems. This application does not limit this.

[0047] To facilitate understanding of the solutions shown in the embodiments of this application, several terms appearing in the embodiments of this application will be introduced below.

[0048] Mobile data network: In this technical field, the mobile data network can be provided by an operator. To facilitate user billing and statistics, operators typically provide users with a user account. Users log into this user account on their terminals and receive and send data through the mobile data network corresponding to that user account.

[0049] In one possible scenario, the terminal can log in to the user account via a SIM (Subscriber Identity Module) card.

[0050] eSIM (Embedded-SIM) cards are a technology that embeds a traditional SIM card directly onto the device's chip. eSIM cards allow users to remotely select and activate a carrier network through device settings or carrier applications, without needing to replace the physical card, providing greater flexibility and convenience while saving space. eSIM cards are widely used in smartphones, smartwatches, and IoT devices, enabling users to easily switch carriers and enjoy a seamless connectivity experience.

[0051] COS (OS on eSIM, the built-in operating system of eSIM) is the operating system software residing within the eSIM card. It is responsible for receiving and processing various information sent to the eSIM card from external sources (such as mobile phones or card readers), and executing corresponding instructions, such as authentication operations, managing the card's internal memory space, and sending response information back to the outside world. COS is a newly designed, highly automated, and intelligent system that supports eSIM card technology, enabling real-time monitoring, identification, and management of eSIM cards, and can be customized according to user needs. Furthermore, to ensure data security and network stability, COS also has powerful firewall capabilities to prevent malicious attacks and data leaks.

[0052] EUICC (Embedded Universal Integrated Circuit Card), also known as a programmable SIM card, is a SIM card chip technology that can be pre-installed during device manufacturing and remotely managed and configured via a network. In the embodiments of this application, EUICC is equivalent to an eSIM card.

[0053] RSA (Rivest-Shamir-Adleman) is a widely used asymmetric encryption algorithm. Proposed by Ron Rivest, Adi Shamir, and Leonard Adleman in the 1970s, it uses a pair of keys (public and private) for encryption and decryption, with the public key used for encryption and the private key for decryption, ensuring secure data transmission.

[0054] Elliptic Curve Cryptography (ECC) is another important asymmetric encryption algorithm. Based on elliptic curve mathematics, it performs encryption and decryption operations using points on an elliptic curve. Compared to RSA, ECC offers a shorter key length and higher security.

[0055] TEE (Trusted Execution Environment) is a secure area on the CPU (Central Processing Unit) of a mobile device. It includes both hardware and software components and is designed to provide necessary support for applications, ensuring that sensitive operations (such as fingerprint recognition, key processing, etc.) are executed in a secure environment and protecting sensitive data from being leaked.

[0056] QSEE (Qualcomm Secure Execution Environment) is a trusted execution environment implemented by Qualcomm based on TrustZone technology. It is a hardware-isolated area within Qualcomm chips, similar to a TEE, providing a secure environment for Android operating system and application developers to handle sensitive data. QSEE enhances device security and prevents malware attacks by isolating and protecting sensitive data.

[0057] For example, the terminal operation method shown in the embodiments of this application can be applied to a terminal that has a display screen and the function of switching mobile data networks. The terminal may include a mobile phone, tablet computer, laptop computer, desktop computer, all-in-one computer, server, workstation, television, set-top box, smart glasses, smartwatch, digital camera, MP4 playback terminal, MP5 playback terminal, learning machine, e-reader, e-book, electronic dictionary, or vehicle terminal, etc.

[0058] Please refer to Figure 1 , Figure 1 This is a structural block diagram of a terminal provided in an exemplary embodiment of this application, such as... Figure 1 As shown, the terminal includes a processor 120 and a memory 140. The memory 140 stores at least one instruction, which is loaded and executed by the processor 120 to implement the terminal operation method as described in the various method embodiments of this application.

[0059] In this application, terminal 100 is an electronic device that supports eSIM cards. When terminal 100 is powered on, it can query the binding status of the eSIM card. If the eSIM card is not bound, a binding process is initiated. If the eSIM card is already bound, the system waits for the eSIM card to initiate a verification process; it verifies whether the device bound to the eSIM card is terminal 100. If so, the system controls the normal operation of the eSIM card; otherwise, the operation of the eSIM card on terminal 100 is restricted.

[0060] Processor 120 may include one or more processing cores. Processor 120 connects to various parts within terminal 100 using various interfaces and lines, and performs various functions and processes data of terminal 100 by running or executing instructions, programs, code sets, or instruction sets stored in memory 140, and by calling data stored in memory 140. Optionally, processor 120 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). Processor 120 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for display on the screen; and the modem handles wireless communication. It is understood that the modem may also not be integrated into processor 120 and may be implemented as a separate chip.

[0061] The memory 140 may include random access memory (RAM) or read-only memory. Optionally, the memory 140 may include a non-transitory computer-readable storage medium. The memory 140 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 140 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the various method embodiments described below, etc.; the data storage area may store data involved in the various method embodiments described below, etc.

[0062] In one alternative embodiment, such as Figure 2As shown, terminal 100 includes an operating system (e.g., Android) 101, a modem 102, a TZ (TrustZone) 103, and an eSIM card 104. The operating system 101 contains resident processes. The modem 102 includes a UIM (User Identity Module). The TZ 103 includes SecureApp and RPMB (Replay Protected Memory Block) storage. The eSIM card 104 includes COS, application, and SIM file storage.

[0063] Figure 3 A flowchart of a terminal operation method provided in an exemplary embodiment of this application is shown. The method is executed by a terminal and includes at least one of the following steps.

[0064] In some embodiments, if the terminal includes a first operating system, the method can be executed by the first operating system. For example, the first operating system can be an Android system, HarmonyOS, or a similar operating system.

[0065] In some embodiments, the terminal includes a first operating system and a second operating system. The method can be executed by the first operating system, for example, the first operating system can be an Android system, HarmonyOS, or a similar operating system. The second operating system can be an RTOS system or a HarmonyOS or a similar system. The power consumption and performance of the second operating system are lower than those of the first operating system. In some embodiments, the terminal includes a first processor and a second processor. The first processor is used to run the first operating system, and the second processor is used to run the second operating system. The first processor and the second processor can also be two separate chips, or they can be packaged in the same chip.

[0066] Step 210: Send a binding status query request to the eSIM card. The binding status query request is used to query the binding status of the eSIM card. The binding status is used to indicate whether the eSIM card is bound to the device.

[0067] This method can be executed by the terminal, or by the operating system within the terminal, or by a resident process within the operating system. A resident process can be a process that runs automatically after the terminal is powered on.

[0068] The method provided in this application establishes a binding relationship between a terminal and an eSIM card. A terminal is uniquely bound to one eSIM card, or a terminal may allow the binding of at least one eSIM card. One eSIM card is uniquely bound to one terminal. After binding, the eSIM card is only allowed to be used on the bound terminal and its use is prohibited or restricted on other devices. Similarly, the terminal only allows the use of the bound eSIM card and does not allow the use of other unbound eSIM cards. This prevents users from migrating an eSIM card from one terminal to another.

[0069] For example, after the terminal is powered on, it will check the binding status of the eSIM card. If the eSIM card is not bound to a device, a binding process will be initiated to establish a binding with the eSIM card. If the eSIM card is already bound, it will verify whether the device bound to the eSIM card is the current terminal. If the device bound to the eSIM card is not the current terminal, the operation of the eSIM card will be restricted.

[0070] Optionally, after the terminal is powered on, it sends a binding status query request to the eSIM card to check whether the eSIM card is already bound to a device. If it is already bound, it waits for the eSIM card to verify whether the current terminal is a bound device. If it is not bound, the terminal can initiate a binding process to bind with the eSIM card. If the eSIM card returns a query error, the eSIM card may not support the binding function.

[0071] The binding status query request is used to query the binding status of an eSIM card. For example, eSIM cards from different vendors can use corresponding binding status query requests to query their binding status. For instance, after powering on, the terminal can obtain the eSIM card's card identifier, identify the eSIM card's vendor based on the card identifier, and send a binding status query request corresponding to that vendor to the eSIM card, thus initiating the binding status query process for that vendor.

[0072] In one alternative embodiment, for some already circulating terminals, the eSIM card firmware may not support device-SIM card binding (i.e., binding the terminal to the eSIM card). To prevent malicious actors from maliciously blocking device-SIM card binding, a persistent process checks for eSIM card firmware upgrades and initiates device-SIM card binding upon terminal startup.

[0073] For example, in response to terminal startup, the terminal upgrades the firmware of the eSIM card; if the eSIM card's firmware is the latest version, a binding status query request is sent to the eSIM card. Optionally, if different card manufacturers use different firmware upgrade methods, the terminal can obtain the eSIM card's card identifier; determine the eSIM card manufacturer based on the card identifier; and send the corresponding firmware upgrade request to the eSIM card. After the firmware is upgraded to the latest version, a binding status query request is sent to the eSIM card.

[0074] eSIM cards can be divided into those that support device-to-SIM card (DSIM) binding and those that do not. When an eSIM card that supports DSIM binding receives a binding status query request, it can return a binding status to the terminal, which can be either "bound" or "not bound." When an eSIM card that does not support DSIM binding receives a binding status query request, it will return a query error to the terminal.

[0075] If the eSIM card is already bound, proceed to steps 220 and 230 to verify whether the device bound to the eSIM card is the current terminal. If the eSIM card is not bound, the terminal initiates a binding process to establish a binding relationship with the eSIM card. If the eSIM card returns a query error, the terminal can check its own binding status. If the terminal is already bound to another eSIM card, power off that eSIM card; if the terminal is not bound to another eSIM card, it can control the normal operation of the eSIM card.

[0076] For example, the method provided in this application embodiment is only described using the example of an eSIM card returning a binding status to a terminal. In other optional embodiments, the eSIM card can also return a binding status and a device fingerprint to itself. The device fingerprint is the device fingerprint of the device to which the eSIM card is bound. The terminal can also verify whether the eSIM card is bound to itself based on the device fingerprint. For example, the device fingerprint may include at least one of the terminal's CPU chip identifier, the eMMC (Embedded Multi Media Card) chip identifier, and IMEI (International Mobile Equipment Identity).

[0077] Step 220: If the binding status is "bound", verify the binding relationship between the eSIM card and the terminal to obtain the verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is a terminal.

[0078] If the binding status returned by the eSIM card to the terminal is "bound", it means that the eSIM card has already established a binding relationship with a device. In this case, it is necessary to further verify whether the device bound to the eSIM card is the current terminal.

[0079] Optionally, if the terminal is already bound, it can end the binding status query process and wait for the eSIM card to initiate the binding device verification process. Alternatively, the terminal can initiate the binding device verification process to the eSIM card even if the binding status is already bound.

[0080] The verification process is used to verify the binding relationship between the eSIM card and the terminal. The binding relationship can include: the device bound to the eSIM card is the terminal, or the device bound to the eSIM card is not the terminal.

[0081] For example, during the establishment of a binding relationship, the terminal and eSIM card exchange and store information. The terminal and eSIM card can verify the stored information to identify whether the other is the device / eSIM card bound to them. For instance, the eSIM card stores the terminal's device fingerprint, and the terminal stores the eSIM card's card identifier; and / or, the terminal and eSIM card each store a binding key generated during the binding process. Using the information stored during these binding processes, it is possible to verify whether a binding relationship has been established between the eSIM card and the terminal.

[0082] For example, an eSIM card can verify its binding relationship with the current terminal in several ways. For instance, the eSIM card can send the device fingerprint of the bound device to the terminal, allowing the terminal to verify whether the device fingerprint sent by the eSIM card matches its own device fingerprint. Alternatively, the eSIM card can request the terminal to send its own device fingerprint, and the eSIM card can verify whether the terminal's device fingerprint matches the device fingerprint of the bound device.

[0083] The eSIM card can send its own card information to the terminal, allowing the terminal to verify whether the card information sent by the eSIM card matches the card information of the eSIM card bound to the terminal. Alternatively, the eSIM card can request the terminal to send the card information of the bound eSIM card, and the eSIM card can verify whether the card information sent by the terminal matches its own card information. The card information may include at least one of a card identifier and a chip identifier.

[0084] Alternatively, both the eSIM card and the terminal store a binding key. The eSIM card can use the binding key to send an encrypted checksum to the terminal, allowing the terminal to verify whether the binding keys of both parties match based on the checksum, thereby identifying whether the eSIM card is bound to the current terminal. Alternatively, the eSIM card can request the terminal to send an encrypted checksum using the binding key, allowing the eSIM card to verify whether the binding keys of both parties match based on the checksum, thereby identifying whether the eSIM card is bound to the current terminal.

[0085] That is, the terminal can verify the binding relationship to obtain the verification result and then send the verification result back to the eSIM card. Alternatively, the eSIM card can verify the binding relationship to obtain the verification result and then send the verification result back to the terminal. Or, both parties can jointly verify the relationship to obtain the verification result, with the party verifying first sending the verification result back to the party verifying later.

[0086] Step 230: If the verification result indicates that the eSIM card is not bound to the terminal, restrict the operation of the eSIM card.

[0087] The verification result includes: verification success and verification failure. Verification success indicates that the eSIM card and the terminal are bound together, while verification failure indicates that the eSIM card and the terminal are not bound together. When verification fails, it means that the eSIM card is not bound to the current terminal, thus restricting the operation of the eSIM card on that terminal.

[0088] Restricting the operation of an eSIM card can include at least one of the following: stopping the eSIM card from operating (e.g., powering off the eSIM card), restricting some functions of the eSIM card, restricting the execution of some programs on the eSIM card, restricting some file reads on the eSIM card, identifying the eSIM card as an untrusted object, or restricting the eSIM card's network access. Restricting the operation of the eSIM card on unlinked devices can improve the security of eSIM card usage.

[0089] Figure 4 A flowchart of a terminal operation method provided by an exemplary embodiment of this application is shown. The method is performed by an eSIM card in the terminal and includes at least one of the following steps.

[0090] Step 240: In response to the binding status query request sent by the terminal, send the binding status to the terminal; the binding status is used to indicate whether the eSIM card is bound to the device.

[0091] The eSIM card receives a binding status query request from the terminal, which can be sent by the terminal after startup. If the eSIM card supports SIM card / device binding, the eSIM card queries the binding status and returns it to the terminal. The binding status includes one of the following: bound or not bound. If the eSIM card does not support SIM card / device binding, the eSIM card returns a query error to the terminal.

[0092] Step 250: If the binding status is "bound", verify the binding relationship between the eSIM card and the terminal to obtain the verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is a terminal.

[0093] If the binding status is unbound, wait for the terminal to initiate the binding process.

[0094] In the event of an error in the query, the terminal will check its own binding status. If the terminal is already bound, it will power off the eSIM card; or, in the event of an error in the query, the terminal will directly power off the eSIM card; or, in the event of an error in the query, the terminal will restrict the operation of the eSIM card.

[0095] Step 260: If the verification result indicates that the eSIM card is not bound to the terminal, restrict the operation of the eSIM card.

[0096] For example, the operation of the eSIM card may be restricted by the terminal, or the operation of the eSIM card itself may be restricted.

[0097] In summary, the method provided in this embodiment binds a terminal to an eSIM card. The terminal can query the binding status of the eSIM card and verify whether the eSIM card is bound to the current terminal. If the eSIM card is not bound to the current terminal, its operation is restricted. This ensures that the eSIM card can only be used on the bound terminal, limiting its migration to other devices and restricting the use of unbound eSIM cards on the terminal, thereby improving the security of eSIM card use and preventing its abuse.

[0098] In one alternative embodiment, such as Figure 5 As shown, after the terminal powers on, it powers on the eSIM card. Then, step 310 is executed, where the terminal initiates a query process to check if the eSIM card is already bound. If not bound, step 330 is executed, where the terminal initiates a binding process to bind with the eSIM card. If already bound, step 350 is executed, where the eSIM card initiates a verification process to verify if the device bound to the eSIM card is the current terminal.

[0099] Examples of the query process, binding process, and verification process are given below.

[0100] 1. The query process includes: the terminal sends a binding status query request to the eSIM card, and the eSIM card returns the binding status to the terminal, which includes either "bound" or "not bound". If the binding status is "not bound", the binding process is executed; if the binding status is "bound", the terminal waits for the eSIM card to initiate a verification process.

[0101] If the eSIM card returns a query error, it indicates that the eSIM card may not support the binding function. In the event of an eSIM card query error, the terminal checks its binding status; if the terminal is already bound, the eSIM card is powered off. The eSIM card returns a query error to the terminal; the terminal uses this information to power off the eSIM card if it receives a query error and is already bound.

[0102] Once a terminal establishes a binding relationship with an eSIM card, the terminal's trusted execution environment (TEX) stores the binding key between the terminal and the eSIM card. The terminal can obtain its binding status by reading the binding key and verifying its format integrity. If the binding key is stored in the terminal's TEX and the binding key data is complete and correctly formatted, the terminal is in a bound state; if the binding key is not stored in the terminal's TEX, the terminal is in an unbound state.

[0103] The binding key can be either KENC (card encryption key) or KMAC (message authentication key). KENC can be used to encrypt transmitted and stored data; KMAC can be used for message authentication or key verification, and KMAC can be used to verify the C-MAC (Cipher-based Message Authentication Code) used by external authentication commands.

[0104] For example, the terminal reads the second KENC and the second KMAC from secure storage; if the read and verification are successful, it is determined that the terminal has been bound. The second KENC and the second KMAC are binding keys calculated by the terminal during the binding process and are stored in the terminal's trusted execution environment.

[0105] For example, such as Figure 6 As shown, after the terminal powers on, the resident process 401 of the operating system (e.g., Android) queries the binding status of EUICC / UICC (Universal Integrated Circuit Card) (i.e., eSIM card) 402. The eSIM card 402 returns the binding status to the operating system 401. The operating system 401 determines whether the query was successful. If successful, it executes the binding or verification process based on the query result. If unsuccessful (i.e., the eSIM card 402 returns a query error to the operating system 401), the operating system 401 resends the binding status query request to the eSIM card 402. If three repeated queries return query errors, the operating system 401 queries the trusted execution environment (e.g., QSEE) 403 for the terminal's binding key (second KENC and second KMAC). If the trusted execution environment 403 successfully reads the binding key from the RPMB secure storage, the terminal powers down the eSIM card 402. If the binding key is not successfully read, the eSIM card 402 is controlled to operate normally.

[0106] 2. Binding process as follows Figure 7 As shown, it includes the following steps.

[0107] Step 321: If the binding status is unbound, the terminal sends a binding request to the eSIM card. If the binding status is unbound, the eSIM card receives the binding request sent by the terminal.

[0108] When the terminal is in an unbound state, it initiates the binding process between the terminal and the eSIM card.

[0109] For example, the binding request includes the device fingerprint of the terminal. The device fingerprint includes at least one of the terminal's central processing unit chip identifier, the eSIM card chip identifier, and the terminal's IMEI (International Mobile Equipment Identity).

[0110] For example, the eSIM card stores a shared public key pre-provided by the terminal, and the terminal stores a shared private key; the terminal uses the shared private key to sign the device fingerprint, and sends the device fingerprint signed with the shared private key to the eSIM card in the binding request. The eSIM card verifies the signature of the device fingerprint based on the shared public key; if the verification is successful, the eSIM card saves the device fingerprint.

[0111] Step 322: The eSIM card sends its card key to the terminal. The terminal receives the card key returned by the eSIM card.

[0112] For example, the eSIM card generates an EUICC key pair, which includes a card public key and a card private key. The card key includes the card public key. The eSIM card encrypts the card public key in the EUICC key pair using a shared public key and then sends the encrypted card public key to the terminal.

[0113] For example, the eSIM card stores a shared public key pre-provided by the terminal, and the terminal stores a shared private key for the eSIM card. The eSIM card generates an EUICC key pair, which includes a card public key and a card private key. The eSIM card uses the shared public key to encrypt the card public key to obtain an encrypted card public key and sends the encrypted card public key to the terminal. The terminal uses the shared private key to decrypt the encrypted card public key to obtain the card public key. The terminal receives the encrypted card public key returned by the eSIM card, which is obtained by encrypting the card public key using the shared public key. The terminal forwards the encrypted card public key to a trusted execution environment (TEA) and decrypts it using the shared private key to obtain the card public key.

[0114] Step 323: The terminal sends an authentication code to the eSIM card; the authentication code is generated based on the card key and the terminal's device key. The eSIM card receives the authentication code sent by the terminal; the authentication code is generated based on the card key and the terminal's device key.

[0115] For example, the terminal generates a device key pair, which includes a device public key and a device private key. The device key can be the device private key.

[0116] For example, the terminal generates a second KENC and a second KMAC based on the device private key, the card public key, and the device fingerprint. Optionally, the terminal generates a symmetric key based on the device private key and the card public key; calculates the second KENC and the second KMAC using a hash algorithm based on the symmetric key and the device fingerprint; and saves the second KENC and the second KMAC to secure storage.

[0117] The terminal sends the device public key and CMAC to the eSIM card; the CMAC is generated based on the second KMAC and the device public key. Optionally, the terminal encrypts the device public key to obtain an encrypted device public key; it then calls the CMAC algorithm to generate the CMAC based on the encrypted device public key and the second KMAC. The eSIM card is used to generate the first KENC and the first KMAC based on the device public key, the card private key, and the device fingerprint, and to verify the CMAC.

[0118] Step 324: The eSIM card verifies the authentication code to obtain the binding result.

[0119] For example, the authentication code may include CMAC, which is generated by the terminal based on the second KMAC and the device public key; the second KMAC is generated by the terminal based on the device private key, the card public key and the device fingerprint.

[0120] The eSIM card generates and saves a first KENC and a first KMAC based on the device's public key, card's private key, and device fingerprint. Optionally, the eSIM card generates a symmetric key based on the device's public key and card's private key; based on the symmetric key and device fingerprint, the first KENC and first KMAC are calculated using a hash algorithm.

[0121] The eSIM card calculates the CMAC based on the first KMAC and the device public key; optionally, the eSIM card encrypts the device public key to obtain an encrypted device public key; and calls the CMAC algorithm to generate the CMAC based on the encrypted device public key and the first KMAC.

[0122] If the CMAC calculation result matches that of the terminal, the eSIM card determines that the binding result is complete; if the CMAC calculation result does not match that of the terminal, a binding error is returned to the terminal.

[0123] Step 325: The eSIM card sends the binding result to the terminal. The terminal receives the binding result returned by the eSIM card; the binding result is obtained by verifying the authentication code of the eSIM card.

[0124] For example, such as Figure 8 As shown, the binding process may include the following steps.

[0125] The operating system 401 provides a shared public key to the eSIM card 402 in advance, and the operating system 401 stores the shared private key. When the terminal is powered on, it queries the eSIM card 402 to determine whether the eSIM card 402 has been successfully bound.

[0126] 1) If binding is not completed, a binding request is initiated to the eSIM card via 402. The request includes the device fingerprint signed with the shared private key. The device fingerprint can typically be the terminal's CPU chip ID, the eMMC chip ID, or the IMEI, etc.

[0127] 2) After receiving the request, the eSIM card 402 uses the shared public key to verify the device fingerprint and saves it.

[0128] 3) The eSIM card 402 generates an EUICC key pair (for example, using asymmetric encryption algorithms such as RSA or ECC; the following explanation uses the ECC algorithm as an example), and encrypts the card public key in the EUICC key pair using the shared public key, and returns it to the operating system 401.

[0129] 4) The operating system 401 forwards the encrypted card public key to the QSEE / TEE trusted execution environment 403, which decrypts the card public key.

[0130] 5) The operating system 401 also generates a device key pair (for example, using asymmetric encryption algorithms such as RSA or ECC; the following explanation uses the ECC algorithm as an example).

[0131] 6) The operating system 401 uses the device private key and card public key in the device key pair through the ECDH (Elliptic curve Diffie-Hellman) algorithm to obtain a symmetric key, and then uses a specific HASH algorithm with the device fingerprint to obtain the second KENC and the second KMAC respectively.

[0132] 7) The operating system 401 saves the second KENC and the second KMAC to the RPMB secure storage.

[0133] 8) The operating system 401 encrypts the device public key and the device public key using AES (Advanced Encryption Standard), and then uses the CMAC algorithm to obtain the CMAC (Cipher Block Chaining-Message Authentication Code). The operating system then sends the device public key and the CMAC together to the eSIM card 402.

[0134] 9) The eSIM card 402 receives the device public key, obtains the first KMAC and the first KENC through the same algorithm, and saves them.

[0135] 10) eSIM card 402 calculates CMAC and compares the calculation result with the CMAC sent by operating system 401. If they match, the binding is completed; otherwise, an error is returned and the binding status is cleared.

[0136] In one optional embodiment, the verification process is as follows: Figure 9 As shown, it includes the following steps.

[0137] Step 331: The eSIM card sends a verification request to the terminal, the verification request including a first verification value. The terminal receives the verification request sent by the eSIM card.

[0138] For example, the verification request includes a challenge code and a first verification value, which is obtained by the eSIM card using a first KMAC to encrypt the challenge code and the terminal's device fingerprint; the first KMAC is a KMAC stored by the eSIM card. The challenge code is a random number generated by the eSIM card.

[0139] For example, the eSIM card generates a challenge code; the challenge code and the terminal's device fingerprint are encrypted using a first KMAC to obtain a first verification value; a verification request is sent to the terminal, the verification request including the challenge code and the first verification value.

[0140] For example, the eSIM card uses the CMAC algorithm to obtain the CMAC calculated value based on the first KMAC encryption challenge code and the device fingerprint. The CMAC calculated value is the first verification value.

[0141] Step 332: If the first verification value is valid, the terminal sends a second verification value to the eSIM card. The eSIM card uses this second verification value to verify its validity and obtain a verification result. The eSIM card receives the second verification value sent by the terminal; the second verification value is sent by the terminal after verifying that the first verification value is valid.

[0142] For example, the terminal uses a second KMAC encryption challenge code and a device fingerprint to obtain a first encryption result; the second KMAC is a KMAC stored by the terminal; if the first encryption result matches the first checksum, the first checksum is determined to be valid. Alternatively, the terminal may also use the CMAC algorithm to obtain the first encryption result based on the second KMAC encryption challenge code and the device fingerprint.

[0143] If the terminal and eSIM card are bound together, the second KMAC stored in the terminal is the same as the first KMAC stored in the eSIM card, and the second KENC stored in the terminal is the same as the first KENC stored in the eSIM card. Therefore, the encryption results obtained by the eSIM card and the terminal using the CMAC algorithm based on the KMAC encryption challenge code and the device fingerprint should be the same; that is, the first encryption result and the first verification value should be the same. Similarly, the second verification value generated by the terminal later should be the same as the second encryption result.

[0144] If the terminal and the eSIM card are not bound together, the second KMAC stored in the terminal is different from the first KMAC stored in the eSIM card, and the first encryption result and the first verification value are different. The terminal can determine that the verification has failed and return the verification failure result to the eSIM card.

[0145] The terminal uses the second KENC encryption challenge code and the device fingerprint to obtain the second verification value; the second KENC is the KENC stored by the terminal; the second verification value is sent to the eSIM card; wherein, the eSIM card is used to verify the legality of the second verification value using the first KENC encryption challenge code and the device fingerprint; the first KENC is the KENC stored by the eSIM card.

[0146] Step 333: The eSIM card verifies the validity of the second verification value and obtains the verification result.

[0147] The eSIM card returns the verification result to the terminal.

[0148] For example, the second verification value is obtained by the terminal using the second KENC encryption challenge code and the terminal's device fingerprint; the eSIM card uses the first KENC encryption challenge code and the terminal's device fingerprint to obtain the second encryption result; if the second encryption result matches the second verification value, the verification result is determined to be valid; if the second encryption result does not match the second verification value, the verification result is determined to be invalid. The eSIM card returns the verification result to the terminal.

[0149] In one alternative embodiment, if the verification result is invalid, the terminal or eSIM card denies partial program execution and file access. If the verification result is valid, the eSIM card operates normally.

[0150] For example, such as Figure 10As shown, after the terminal powers on, the operating system 401 powers on the eSIM card 402. After power-on, the eSIM card 402 generates a challenge code, calculates the CMAC based on the challenge code and device fingerprint, and sends a verification request to the operating system 401, carrying the challenge code and CMAC. Upon receiving the verification request, the operating system 401 forwards it to the trusted execution environment 403. Based on the challenge code and device fingerprint, it calculates the CMAC using the second KMAC stored in the RPMB secure storage. It compares the CMAC calculated by the terminal with the CMAC sent by the eSIM card 402. If they match, the verification is valid; otherwise, it is invalid, and a verification failure result is returned. If the verification is successful, the trusted execution environment 403 uses the challenge value and device fingerprint, and encrypts it using the second KENC with the AES algorithm to obtain the second verification value. The operating system 401 then forwards the second verification value to the eSIM card 402. The eSIM card 402 uses the first KENC encryption challenge value and the device fingerprint to verify whether the encryption result is the same as the second verification value, and then verifies whether the first KENC is the same as the second KENC. If they are the same, the verification is deemed valid; if they are different, the verification is deemed invalid, and the verification result is returned to the operating system 401.

[0151] It should be noted that the embodiments in this application are only illustrated using the above encryption algorithm as an example. Those skilled in the art can also use other encryption algorithms to complete the key exchange and negotiation process.

[0152] In summary, the method provided in this embodiment offers a binding query process, a binding process, and a verification process for device-SIM card binding. The terminal can query the binding status of the eSIM card after powering on to identify whether the eSIM card is bound to a device. If the eSIM card is bound to a device, a verification process is executed to check if the eSIM card is bound to the current terminal. If the verification passes, the eSIM card can be used normally; if the verification fails, the operation of the eSIM card is restricted. If the eSIM card is not bound to a device, a binding process is executed to establish a binding relationship between the terminal and the eSIM card, generating a binding key to verify the binding relationship and encrypt communication between the terminal and the eSIM card. By providing a complete device-SIM card binding system, it ensures that the terminal can only use the bound eSIM card, that the eSIM card can only be used normally on the bound terminal, restricts the abuse of the eSIM card, and improves the security of eSIM card use.

[0153] In one optional embodiment, to ensure compatibility with multiple card vendors, during the eSIM card's COS firmware upgrade, the eSIM card vendor can be identified based on the eSIM card's card identifier, thereby enabling different firmware upgrades and SIM card binding processes to be performed for different vendors. For example... Figure 11 As shown, the method includes the following steps.

[0154] Step 701: After the terminal is activated, if the eSIM card vendor is unknown, obtain the eSIM card identifier. If the identifier is successfully obtained, or if the identifier acquisition fails more than three times, a firmware update request is initiated. If the vendor is known, read the eSIM card configuration file. If the read is successful, a firmware update request is also initiated. Otherwise, after a 5-second delay, retry is initiated. If the retry fails after three attempts, a firmware update request is initiated directly.

[0155] Step 702: The terminal determines the card manufacturer to which the eSIM card belongs based on the obtained card identifier, and performs a firmware update using the corresponding firmware update process according to the card manufacturer.

[0156] For example, when the eSIM card belongs to the first card provider, the system first checks if the current firmware is up-to-date. If it is, step 703 is executed to check the binding status. If not, a firmware upgrade is performed. After the firmware upgrade is complete, it checks if the eSIM card needs to be reset. If so, the eSIM card is reset, and its status is updated to "Not Ready, Updating". Then, the firmware update request process is re-initiated. If a reset is not required, the firmware update ends, confirming that the firmware is updated to the latest version, and step 703 is executed to check the binding status.

[0157] For example, when the eSIM card belongs to a second card provider, the firmware update is performed directly. After the firmware update is completed, the firmware update is confirmed to be successful, or the firmware is confirmed to be updated to the latest version, and then step 703 is executed to check the binding status.

[0158] Step 703: After the eSIM card is ready, the terminal checks the binding status. First, it determines the eSIM card vendor and initiates different binding status query processes based on the vendor.

[0159] For example, when the eSIM card belongs to the first card vendor, the terminal uses the binding status query request corresponding to the first card vendor to query the binding status. When the eSIM card is in a bound state, OP_OEM_GD_VERIFY_START is sent to initiate the device-card verification process. When the eSIM card is in an unbound state, the device-card binding process is initiated. If the query fails, a firmware update is re-requested. If the firmware update fails and retries more than three times, it is determined whether the eSIM card is an out-of-type card (out-of-type cards do not support device-card binding function).

[0160] For example, when the eSIM card belongs to a second-party provider, the binding status query request corresponding to that provider is used to check the binding status. If the card is already bound, an authentication process may or may not be performed. If the card is not bound, a binding process is initiated. If the query fails, a general binding status query request is used to continue checking the binding status. If the query succeeds, the binding or verification process is executed based on the query result. If the query fails more than three times, a firmware update is re-initiated to check if the firmware has not been updated.

[0161] In summary, the method provided in this embodiment can identify the eSIM card vendor by obtaining the eSIM card's card identifier, or by obtaining the eSIM card's configuration file. Then, it can use the firmware update process corresponding to each vendor to update the eSIM card's firmware. Furthermore, it can use the binding status query process corresponding to each vendor to query the binding status, making the method provided in this embodiment compatible with multiple vendors. It achieves two-way binding between the device and the SIM card. When the eSIM card is removed, it cannot be used on other devices, and the terminal cannot use other unbound eSIM cards, achieving the goal of one-to-one binding between the eSIM card and the terminal, thus improving the security of using both the eSIM card and the terminal.

[0162] It should be noted that the above embodiments can be separated or freely combined, and this application does not limit the separation or combination of the embodiments.

[0163] Figure 12 A block diagram of a terminal operating device provided in an exemplary embodiment of this application is shown. See also: Figure 12 The device includes:

[0164] The first query module 801 is used to send a binding status query request to the eSIM card. The binding status query request is used to query the binding status of the eSIM card. The binding status is used to indicate whether the eSIM card is bound to the device.

[0165] The first verification module 802 is used to verify the binding relationship between the eSIM card and the terminal to obtain a verification result when the binding status is "bound"; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal.

[0166] The first control module 803 is used to restrict the operation of the eSIM card when the verification result indicates that the eSIM card is not bound to the terminal.

[0167] In an optional embodiment, the first verification module 802 is configured to receive a verification request sent by the eSIM card, the verification request including a first verification value;

[0168] The first verification module 802 is used to send a second verification value to the eSIM card if the first verification value is valid;

[0169] The eSIM card is used to verify the validity of the second verification value to obtain the verification result.

[0170] In one optional embodiment, the verification request includes a challenge code and a first verification value, wherein the first verification value is obtained by the eSIM card encrypting the challenge code and the device fingerprint of the terminal using a first message authentication key (KMAC); the first KMAC is a KMAC stored by the eSIM card.

[0171] The first verification module 802 is used to encrypt the challenge code and the device fingerprint using the second KMAC to obtain a first encryption result; the second KMAC is a KMAC stored by the terminal;

[0172] The first verification module 802 is used to determine that the first verification value is valid if the first encryption result is consistent with the first verification value;

[0173] The first verification module 802 is used to encrypt the challenge code and the device fingerprint using the second card encryption key KENC to obtain a second verification value; the second KENC is a KENC stored by the terminal;

[0174] The first verification module 802 is used to send the second verification value to the eSIM card;

[0175] The eSIM card is used to encrypt the challenge code and the device fingerprint using a first KENC, and to verify the legality of the second verification value; the first KENC is a KENC stored in the eSIM card.

[0176] In an optional embodiment, the device further includes:

[0177] The first binding module 804 is used to initiate the binding process between the terminal and the eSIM card when the binding status is unbound.

[0178] In an optional embodiment, the first binding module 804 is used to send a binding request to the eSIM card;

[0179] The first binding module 804 is used to receive the card key returned by the eSIM card;

[0180] The first binding module 804 is used to send an authentication code to the eSIM card; the authentication code is generated based on the card key and the terminal's device key;

[0181] The first binding module 804 is used to receive the binding result returned by the eSIM card; the binding result is obtained by the eSIM card verifying the authentication code.

[0182] In one alternative embodiment, the binding request includes the device fingerprint of the terminal;

[0183] The card key includes a card public key, and the card public key and card private key belong to the EUICC key pair of the embedded general-purpose integrated circuit card, and the EUICC key pair is generated by the eSIM card;

[0184] The device key includes a device private key, and the device private key and the device public key belong to a device key pair, which is generated by the terminal.

[0185] The first binding module 804 is used to generate a second KENC and a second KMAC based on the device private key, the card public key and the device fingerprint;

[0186] The first binding module 804 is used to send the device public key and the password-based message authentication code (CMAC) to the eSIM card;

[0187] The CMAC is generated based on the second KMAC and the device public key; the eSIM card is used to generate a first KENC and a first KMAC based on the device public key, the card private key and the device fingerprint, and to verify the CMAC.

[0188] In one optional embodiment, the eSIM card stores a shared public key pre-provided by the terminal, and the terminal stores a shared private key; the binding request includes the device fingerprint signed using the shared private key; the eSIM card is used to verify the signature of the device fingerprint based on the shared public key.

[0189] In one optional embodiment, the eSIM card stores a shared public key pre-provided by the terminal, and the terminal stores a shared private key;

[0190] The first binding module 804 is used to receive the encrypted card public key returned by the eSIM card, wherein the encrypted card public key is obtained by encrypting the card public key using the shared public key;

[0191] The first binding module 804 is used to forward the encrypted card public key to the trusted execution environment and obtain the card public key by decryption based on the shared private key.

[0192] In an optional embodiment, the first binding module 804 is used to generate a symmetric key based on the device private key and the card public key;

[0193] The first binding module 804 is used to calculate the second KENC and the second KMAC based on the symmetric key and the device fingerprint using a hash algorithm;

[0194] The first binding module 804 is used to save the second KENC and the second KMAC to secure storage.

[0195] In an optional embodiment, the first binding module 804 is used to encrypt the device public key to obtain an encrypted device public key;

[0196] The first binding module 804 is used to call the CMAC algorithm to generate the CMAC based on the public key of the encryption device and the second KAMC.

[0197] In one optional embodiment, the device fingerprint includes at least one of the terminal's central processing unit chip identifier, the eSIM card's chip identifier, and the terminal's International Mobile Identity Registry (IMEI).

[0198] In an optional embodiment, the first query module 801 is configured to perform a firmware upgrade on the eSIM card in response to terminal startup;

[0199] The first query module 801 is used to send the binding status query request to the eSIM card when the firmware of the eSIM card is the latest version.

[0200] In an optional embodiment, the first query module 801 is used to obtain the card identifier of the eSIM card;

[0201] The first query module 801 is used to determine the card manufacturer of the eSIM card based on the card identifier;

[0202] The first query module 801 is used to send a binding status query request corresponding to the cardholder to the eSIM card.

[0203] In an optional embodiment, the first query module 801 is used to query the binding status of the terminal if the eSIM card returns a query error;

[0204] The first control module 803 is used to power off the eSIM card when the terminal is already bound.

[0205] In an optional embodiment, the first query module 801 is configured to read the second KENC and the second KMAC from secure storage;

[0206] The first query module 801 is used to determine that the terminal has been bound if the reading and verification are successful.

[0207] It should be noted that the apparatus provided in the above embodiments is only illustrated by the division of the above functional modules when implementing its functions. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0208] Figure 13 A block diagram of a terminal operating device provided in an exemplary embodiment of this application is shown. See also: Figure 13 The device includes:

[0209] The second query module 805 is used to send a binding status to the terminal in response to a binding status query request sent by the terminal; the binding status is used to indicate whether the eSIM card is bound to the device.

[0210] The second verification module 806 is used to verify the binding relationship between the eSIM card and the terminal to obtain a verification result when the binding status is "bound"; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal.

[0211] The second control module 807 is used to restrict the operation of the eSIM card when the verification result indicates that the eSIM card is not bound to the terminal.

[0212] In an optional embodiment, the second verification module 806 is configured to send a verification request to the terminal, the verification request including a first verification value;

[0213] The second verification module 806 is used to receive a second verification value sent by the terminal; the second verification value is sent by the terminal after verifying that the first verification value is valid;

[0214] The second verification module 806 is used to verify the legality of the second verification value and obtain the verification result.

[0215] In an optional embodiment, the second verification module 806 is used to generate a challenge code;

[0216] The second verification module 806 is used to encrypt the challenge code and the device fingerprint of the terminal using the first KMAC to obtain the first verification value;

[0217] The second verification module 806 is used to send the verification request to the terminal, the verification request including the challenge code and the first verification value.

[0218] In one optional embodiment, the second verification value is obtained by the terminal encrypting the challenge code and the terminal's device fingerprint using a second KENC.

[0219] The second verification module 806 is used to encrypt the challenge code and the device fingerprint of the terminal using the first KENC to obtain a second encryption result;

[0220] The second verification module 806 is used to determine that the verification result is valid if the second encryption result is consistent with the second verification value;

[0221] The second verification module 806 is used to determine that the verification result is invalid if the second encryption result is inconsistent with the second verification value.

[0222] In an optional embodiment, the second control module 807 is configured to refuse partial program execution and file access if the verification result is invalid.

[0223] In an optional embodiment, the device further includes:

[0224] The second binding module 808 is used to receive a binding request sent by the terminal when the binding status is unbound;

[0225] The second binding module 808 is used to send a card key to the terminal;

[0226] The second binding module 808 is used to receive the authentication code sent by the terminal; the authentication code is generated based on the card key and the terminal's device key;

[0227] The second binding module 808 is used to verify the authentication code and obtain the binding result;

[0228] The second binding module 808 is used to send the binding result to the terminal.

[0229] In one optional embodiment, the eSIM card stores a shared public key pre-provided by the terminal, and the terminal stores a shared private key; the binding request includes the device fingerprint signed using the shared private key;

[0230] The second binding module 808 is used to verify the signature of the device fingerprint using the shared public key;

[0231] The second binding module 808 is used to save the device fingerprint if the verification is successful.

[0232] In one optional embodiment, the eSIM card stores a shared public key pre-provided by the terminal, and the terminal stores a shared private key; the card key includes the card public key;

[0233] The second binding module 808 is used to generate an EUICC key pair, wherein the EUICC key pair includes the card public key and the card key;

[0234] The second binding module 808 is used to encrypt the card public key using the shared public key to obtain the encrypted card public key;

[0235] The second binding module 808 is used to send the encryption card public key to the terminal; the terminal is used to decrypt the encryption card public key using the shared private key to obtain the card public key.

[0236] In one alternative embodiment, the binding request includes the device fingerprint of the terminal;

[0237] The card key includes a card public key, and the card public key and card private key belong to the EUICC key pair of the embedded general-purpose integrated circuit card, and the EUICC key pair is generated by the eSIM card;

[0238] The device key includes a device private key, and the device private key and the device public key belong to a device key pair, which is generated by the terminal.

[0239] The authentication code includes a CMAC, which is generated by the terminal based on a second KMAC and the device public key; the KMAC is generated by the terminal based on the device private key, the card public key, and the device fingerprint.

[0240] The second binding module 808 is used to generate and save a first KENC and a first KMAC based on the device public key, the card private key and the device fingerprint;

[0241] The second binding module 808 is used to calculate the CMAC based on the first KMAC and the device public key;

[0242] The second binding module 808 is used to determine that the binding result is complete when the calculation result of CMAC is consistent with the terminal;

[0243] The second binding module 808 is used to return a binding error to the terminal if the calculation result of CMAC is inconsistent with the terminal.

[0244] In an optional embodiment, generating the first KENC and the first KMAC based on the device public key, the card private key, and the device fingerprint includes:

[0245] The second binding module 808 is used to calculate the first KENC and the first KMAC based on the symmetric key and the device fingerprint using a hash algorithm.

[0246] In an optional embodiment, the second binding module 808 is used to encrypt the device public key to obtain an encrypted device public key;

[0247] The second binding module 808 is used to call the CMAC algorithm to generate the CMAC based on the public key of the encryption device and the first KAMC.

[0248] In one optional embodiment, the device fingerprint includes at least one of the terminal's central processing unit chip identifier, the eSIM card's chip identifier, and the terminal's International Mobile Identity Registry (IMEI).

[0249] In an optional embodiment, the second query module 805 is used to return a query error to the terminal; the terminal is used to power off the eSIM card when it receives the query error and the terminal is in a bound state.

[0250] It should be noted that the apparatus provided in the above embodiments is only illustrated by the division of the above functional modules when implementing its functions. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0251] Figure 14 A schematic diagram of the structure of a communication device provided in an exemplary embodiment of this application is shown. The communication device includes: a processor 1401, a receiver 1402, a transmitter 1403, a memory 1404, and a bus 1405.

[0252] Processor 1401 includes one or more processing cores. Processor 1401 executes various functional applications and information processing by running software programs and modules. Receiver 1402 and transmitter 1403 can be implemented as a communication component, which can be a communication chip. Memory 1404 is connected to processor 1401 via bus 1405.

[0253] The memory 1404 can be used to store at least one program code, and the processor 1401 is used to execute the at least one program code to implement the various steps in the above method embodiments.

[0254] Furthermore, the communication device can be a terminal. The memory 1404 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, including but not limited to: magnetic disks or optical disks, EEPROM (Electrically Erasable Programmable Read Only Memory), EPROM (Erasable Programmable Read Only Memory), SRAM (Static Random Access Memory), ROM (Read Only Memory), magnetic storage, flash memory, and programmable read only memory (PROM).

[0255] In an exemplary embodiment, a computer-readable storage medium is also provided, wherein executable program code is stored in the storage medium, the executable program code being loaded and executed by a processor to implement the terminal operation method executed by the communication device provided in the above-described method embodiments.

[0256] In an exemplary embodiment, a chip is provided, the chip including programmable logic circuitry and / or program instructions, which, when the chip is run on a communication device, are used to implement the terminal operation method provided in the various method embodiments.

[0257] In an exemplary embodiment, a computer program product is provided, which, when executed by the processor of a communication device, is used to implement the terminal operation method provided in the above-described method embodiments.

[0258] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0259] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A terminal operation method, characterized in that, The method is executed by a terminal, and the method includes: A binding status query request is sent to the embedded user identity recognition module (eSIM card). The binding status query request is used to query the binding status of the eSIM card; the binding status is used to indicate whether the eSIM card is bound to the device. If the binding status is "bound", the binding relationship between the eSIM card and the terminal is verified to obtain a verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal. If the verification result indicates that the eSIM card is not bound to the terminal, the operation of the eSIM card is restricted.

2. The method according to claim 1, characterized in that, The verification of the binding relationship between the eSIM card and the terminal to obtain the verification result includes: Receive a verification request sent by the eSIM card, the verification request including a first verification value; If the first verification value is valid, a second verification value is sent to the eSIM card; The eSIM card is used to verify the validity of the second verification value to obtain the verification result.

3. The method according to claim 2, characterized in that, The verification request includes a challenge code and a first verification value. The first verification value is obtained by the eSIM card encrypting the challenge code and the device fingerprint of the terminal using a first message authentication key (KMAC). The first KMAC is a KMAC stored by the eSIM card. If the first verification value is valid, sending a second verification value to the eSIM card includes: The challenge code and the device fingerprint are encrypted using the second KMAC to obtain the first encryption result; the second KMAC is the KMAC stored by the terminal; If the first encryption result matches the first verification value, the first verification value is determined to be valid. The challenge code and the device fingerprint are encrypted using the second card encryption key KENC to obtain a second verification value; the second KENC is a KENC stored by the terminal; Send the second verification value to the eSIM card; The eSIM card is used to encrypt the challenge code and the device fingerprint using a first KENC, and to verify the legality of the second verification value; the first KENC is a KENC stored in the eSIM card.

4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: If the binding status is unbound, initiate the binding process between the terminal and the eSIM card.

5. The method according to claim 4, characterized in that, The process of initiating the binding between the terminal and the eSIM card includes: Send a binding request to the eSIM card; Receive the card key returned by the eSIM card; Send an authentication code to the eSIM card; the authentication code is generated based on the card key and the terminal's device key; Receive the binding result returned by the eSIM card; the binding result is obtained by the eSIM card verifying the authentication code.

6. The method according to any one of claims 1 to 3, characterized in that, Sending a binding status query request to the embedded user identity recognition module eSIM card includes: In response to terminal startup, the eSIM card undergoes firmware upgrade; If the firmware of the eSIM card is the latest version, the binding status query request is sent to the eSIM card.

7. The method according to any one of claims 1 to 3, characterized in that, The method further includes: If the eSIM card returns a query error, query the binding status of the terminal; If the terminal is already bound, power off the eSIM card.

8. A terminal operation method, characterized in that, The method is executed by the eSIM card in the terminal, and the method includes: In response to the binding status query request sent by the terminal, a binding status is sent to the terminal; the binding status is used to indicate whether the eSIM card is bound to the device. If the binding status is "bound", the binding relationship between the eSIM card and the terminal is verified to obtain a verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal. If the verification result indicates that the eSIM card is not bound to the terminal, the operation of the eSIM card is restricted.

9. The method according to claim 8, characterized in that, The verification of the binding relationship between the eSIM card and the terminal to obtain the verification result includes: Send a verification request to the terminal, the verification request including a first verification value; The terminal receives a second verification value; the second verification value is sent by the terminal after verifying that the first verification value is valid. Verify the validity of the second verification value to obtain the verification result.

10. The method according to claim 9, characterized in that, Sending a verification request to the terminal includes: Generate challenge code; The challenge code and the device fingerprint of the terminal are encrypted using the first KMAC to obtain the first verification value; The verification request is sent to the terminal, and the verification request includes the challenge code and the first verification value.

11. The method according to claim 9, characterized in that, The second verification value is obtained by the terminal encrypting the challenge code and the terminal's device fingerprint using the second KENC. The verification of the validity of the second verification value to obtain the verification result includes: The challenge code and the device fingerprint of the terminal are encrypted using the first KENC to obtain the second encryption result; If the second encryption result matches the second verification value, the verification result is determined to be valid. If the second encryption result is inconsistent with the second verification value, the verification result is determined to be invalid.

12. The method according to any one of claims 9 to 11, characterized in that, The step of restricting the operation of the eSIM card when the verification result indicates that the eSIM is not bound to the terminal includes: If the verification result is invalid, partial program execution and file access will be denied.

13. The method according to any one of claims 8 to 11, characterized in that, The method further includes: If the binding status is unbound, receive the binding request sent by the terminal; Send the card key to the terminal; Receive the authentication code sent by the terminal; the authentication code is generated based on the card key and the terminal's device key; Verify the authentication code to obtain the binding result; Send the binding result to the terminal.

14. The method according to any one of claims 8 to 11, characterized in that, The method further includes: The terminal returns a query error to the terminal; the terminal is used to power off the eSIM card when it receives the query error and the terminal is in a bound state.

15. A terminal operating device, characterized in that, The device includes: The first query module is used to send a binding status query request to the eSIM card. The binding status query request is used to query the binding status of the eSIM card. The binding status is used to indicate whether the eSIM card is bound to the device. The first verification module is used to verify the binding relationship between the eSIM card and the terminal when the binding status is "bound" to obtain a verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal. The first control module is used to restrict the operation of the eSIM card when the verification result indicates that the eSIM is not bound to the terminal.

16. A terminal operating device, characterized in that, The device includes: The second query module is used to respond to the binding status query request sent by the terminal and send the binding status to the terminal; the binding status is used to indicate whether the eSIM card is bound to the device; The second verification module is used to verify the binding relationship between the eSIM card and the terminal when the binding status is "bound" to obtain a verification result; the binding relationship is used to indicate whether the device bound to the eSIM card is the terminal. The second control module is used to restrict the operation of the eSIM card when the verification result indicates that the eSIM is not bound to the terminal.

17. A terminal, characterized in that, The terminal includes: processor; A transceiver connected to the processor; Memory for storing the executable program code of the processor; The processor is configured to load and execute the executable program code to implement the terminal operation method as described in any one of claims 1 to 7.

18. A terminal, characterized in that, The terminal includes: processor; A transceiver connected to the processor; Memory for storing the executable program code of the processor; The processor is configured to load and execute the executable program code to implement the terminal operation method as described in any one of claims 8 to 14.

19. A computer-readable storage medium, characterized in that, The readable storage medium stores executable program code, which is loaded and executed by a processor to implement the terminal operation method as described in any one of claims 1 to 14.

20. A computer program product, characterized in that, When the computer program product is executed by the processor of a terminal or network device, it is used to implement the terminal operation method as described in any one of claims 1 to 14.