System integration scheme of ai terminal device and esim security chip

CN122802911APending Publication Date: 2026-09-22SHENZHEN LINKS FIELD NETWORKS LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610945074.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-29
Publication Date
2026-09-22

AI Technical Summary

Benefits of technology

[0010]基于硬件信任根的 Token 防窃取与限额控制技术,其中涉及基于设备硬件绑定的 Token 消耗凭证,每次推理请求必须附带 eSIM 芯片的硬件签名;动态限额控制算法,基于设备行为画像的自适应限额调整;异常消耗熔断机制,突发高频调用的检测与自动阻断;Token余额的硬件级保护,防止设备本地篡改余额数据。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802911A_ABST
    Figure CN122802911A_ABST
Patent Text Reader

Abstract

System integration scheme of AI terminal device and eSIM security chip The present application relates to the field of wireless communication, eSIM cellular communication and RSP remote configuration, OTA remote upgrade communication technology, SE security chip underlying hardware security technology, embedded terminal software and hardware integrated development technology, end-side lightweight data, end-cloud collaboration, AI context memory migration technology; cryptography method for generating migration token based on hardware root of trust; AI terminal device identity hierarchical authorization and dynamic revocation technology; terminal device life cycle tamper-proof technology; eSIM number and AI model account mapping technology; AI-eSIM module integrated baseband, eSIM security SE, hardware integrated design reduces terminal PCB area and reduces overall power consumption; relying on hardware unique identity to open up large model authentication-free, reducing cloud computing power pressure; at the same time, relying on independent security partition to realize AI business data hardware encryption, large model calling behavior full-link traceability and active network risk control, making up the short board of traditional module security; supporting operators to create "traffic + large model Token" fusion subscription value-added services. Forming a disruptive innovation from six dimensions of underlying hardware architecture, end-cloud collaboration mechanism, security trust system, all industry scenarios, business model and industry development method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication, including eSIM cellular communication and RSP remote configuration and OTA remote upgrade communication technologies, SE security chip underlying hardware security technologies, embedded terminal software and hardware integration development technologies, edge-side lightweight data, edge-cloud collaboration, and AI context memory migration technologies; cryptographic methods for generating migration tokens based on hardware root of trust; AI terminal device identity hierarchical authorization and dynamic revocation technologies; terminal device lifecycle anti-tampering technologies; and eSIM number and AI model account mapping technologies. The system integration solution of this application for AI terminal devices and eSIM security chips relies on the dual technical barriers of identity security and AI to achieve integrated implementation of communication, hardware security, large AI models, and operations. Background Technology

[0002] Traditional eSIMs only guarantee network access security, and eSIM modules only have cellular networking and remote number configuration capabilities, lacking local computing power support. The combination of AI large-scale models and eSIM security chips completely changes the industry pain point that traditional eSIMs only serve as a "network channel" and AI terminals "lose intelligence when the network is down." The AI-eSIM module integrates baseband and eSIM security SE, and the integrated hardware design can reduce terminal PCB area and reduce overall power consumption. Relying on the unique hardware identity, it enables large-scale models to access the network without authentication, reducing the computing power pressure on the cloud. At the same time, relying on independent security partitions, it realizes hardware encryption of AI business data, full-link traceability of large-scale model call behavior, and proactive network risk control, making up for the security shortcomings of traditional modules. It supports operators to create integrated subscription value-added services of "data traffic + large-scale model token". It forms a disruptive innovation from six dimensions: underlying hardware architecture, edge-cloud collaboration mechanism, security trust system, full industry scenarios, business model, and industrial development method. Summary of the Invention

[0003] The system integration solution for AI terminal devices and eSIM security chips in this invention aims to provide a highly compatible, low-power, and highly secure integrated hardware and software system in which AI terminal devices and eSIM security chips work together. These will be described in detail below:

[0004] Device identity dynamic migration technology based on a hardware root of trust addresses how to securely migrate an identity from an old device to a new device when the device is damaged, lost, or transferred, while preventing "two-factor authentication" (the same identity existing on two devices simultaneously). This technology uses cryptographic techniques based on the eSIM secure hardware root of trust to generate migration tokens. Atomic migration operations ensure the indivisibility of old identity deregistration and new identity activation. A migration interruption recovery mechanism (state rollback in case of network disconnection / device power failure) is included. Two-factor authentication detection is a method to detect that the same identity cannot be active simultaneously.

[0005] Cross-cryptographic algorithm system device identity mutual recognition technology enables devices using different cryptographic algorithms (such as Chinese national cryptography SM2 vs international ECC / AES) to mutually verify each other's identities. Cross-system identity mutual recognition can be more specifically described as the encoding method of cryptographic algorithm identifiers, cross-algorithm negotiation protocol, handshake and negotiation process when the two algorithms are different, hybrid trust chain construction method (combination and verification of signatures of different algorithms), and cross-algorithm key derivation method (key conversion without exposing the private key).

[0006] Device identity hierarchical authorization and dynamic revocation technology, including cryptographic generation methods for sub-identity certificates, encoding format of permission matrix, offline certificate verification methods (certificate chain-based verification in network-free environments), and dynamic revocation mechanism: methods for issuing and propagating revoked certificates.

[0007] The device identity lifecycle anti-tampering auditing technology can be described in detail as ensuring that every operation (activation / migration / authorization / cancellation) of the AI ​​terminal device identity is auditable and tamper-proof, and supports third-party supervision and verification. This involves the construction of audit logs based on cryptographic hash chains, privacy-preserving encryption and decryption technologies for audit logs, third-party verification interfaces, methods for detecting and repairing broken log chains, and methods for long-term archiving and retrieval of audit logs.

[0008] The dynamic mapping technology between eSIM numbers and AI large model accounts, and the "number as model account" design of AI-eSIM, enable one number to map to multiple large models, and synchronize the migration of AI usage history during identity migration. The core technologies are a one-code-multiple-model mapping algorithm, a cryptographic binding method for the mapping relationship (preventing mapping from being tampered with), a binding mechanism between AI usage history and identity (keeping the memory intact when changing devices), a linkage control method for token usage and identity permissions, and a mapping migration method when switching model service providers.

[0009] OTA key remote update technology addresses the need for different key update strategies for different chip types (domestic / imported) to achieve unified OTA delivery while ensuring security. More specifically, this includes automatic chip type identification technology (OTA channel identifies device chip type); algorithm selection strategy (automatically selects based on chip type, security level, and regional regulations); secure OTA update transmission technology; update failure rollback mechanism (handling different rollback strategies for different chips); and concurrent control and progress tracking for batch OTA updates.

[0010] The token anti-theft and limit control technology based on hardware root of trust involves token consumption credentials based on device hardware binding, requiring each inference request to be accompanied by the hardware signature of the eSIM chip; dynamic limit control algorithm, adaptive limit adjustment based on device behavior profile; abnormal consumption circuit breaker mechanism, detection and automatic blocking of sudden high-frequency calls; and hardware-level protection of token balance to prevent local tampering of balance data on the device. Attached Figure Description

[0011] Figure 1 The terminal device identity migration flowchart is a flowchart illustrating how the identity of an AI device is securely migrated from the old device to the new device when the device is damaged, lost, or transferred in an embodiment.

[0012] Figure 2 The cross-cryptographic identity mutual recognition handshake interaction diagram is an example of an interaction diagram for devices using different cryptographic algorithms to verify each other's identities and achieve cross-system identity mutual recognition.

[0013] Figure 3 The device identity hierarchical authorization matrix is ​​a diagram of the permission management architecture between AI devices and different users in this embodiment.

[0014] Figure 4 The dynamic mapping diagram shows the dynamic mapping relationship between the code number of the AI-eSIM terminal device and the large model account in the embodiment.

[0015] Figure 5 The OTA key update flowchart is a flowchart of the key update strategy for different chip types in the embodiment.

[0016] Figure 6 The security anti-theft flowchart is a method for preventing token theft and limiting transactions based on eSIM hardware root of trust, as shown in the embodiment.

[0017] Figure 7 A comprehensive overview of core technologies. Detailed Implementation

[0018] To make the purpose, technical solution, and advantages of this invention patent application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. The specific embodiments described herein are merely illustrative of this application and are not intended to limit the scope of this application.

[0019] The combination of AI big data models and eSIM security chips, with its integrated hardware design, leverages the unique identity of the eSIM security chip to enable authentication-free access to big data models, reducing the pressure on cloud computing power. At the same time, it relies on independent security partitions to achieve hardware encryption of AI business data, full-link traceability of big data model call behavior, and proactive network risk control, making up for the security shortcomings of traditional eSIM and AI terminals. It represents a disruptive innovation in terms of underlying hardware architecture, edge-cloud collaboration mechanism, security trust system, industry scenarios, business models, and industrial development methods.

[0020] According to this embodiment, refer to Figure 1 This flowchart illustrates the process of securely migrating the identity of an AI device from an old device to a new device when it is damaged, lost, or transferred. It utilizes eSIM-based dynamic device identity migration technology with a secure hardware root of trust to prevent "dual authentication" (the same identity existing on two or more devices simultaneously). First, the old device A initiates migration preparation, reading the hardware root of trust certificate to generate a migration request. The platform verifies device A's root certificate C1 and device information, and generates a one-time migration token based on the hardware root of trust. The new device B receives the migration request, submits its root certificate C2, migration token, and device information to the platform. The platform verifies the request and simultaneously issues migration instructions to both devices A and B. Device A prepares for identity deregistration, while device B prepares for identity activation. The old and new devices simultaneously perform atomic-level synchronization. Upon successful synchronization and migration, the platform verifies the migration, device A's root certificate C1 is marked as invalid, and device B is activated. The entire migration process is then securely completed.

[0021] According to this embodiment, refer to Figure 2Cross-cryptosystem identity mutual authentication handshake interaction diagram, which shows a process for devices using different cryptographic algorithms to mutually authenticate identities and implement cross-system identity mutual recognition. AI-eSIM device A uses algorithm X, and AI-eSIM device B uses algorithm Y. Device A initiates the homogeneous core protocol handshake and marks the algorithm identifier of device A. After device B receives the request and passes the verification of the information, it exchanges algorithm identifiers with device A. Meanwhile, devices A and B perform a cross-algorithm negotiation protocol with the server platform. After the platform passes the verification, it constructs a mixed trust chain (different algorithm signatures + platform signature) and feeds it back to both devices. Devices A and B perform verification according to each other's algorithm identifiers and pass the verification. Thus, the identity mutual authentication handshake verification for cross-algorithm keys succeeds. It should be particularly noted that in this example, the cross-algorithm key derivation technology implements key conversion on the premise that the private key is not exposed, and the encoding method of cryptographic algorithm identifiers and the certificate header format realize the combination and verification of signatures from different algorithms on the premise of ensuring information security.

[0022] According to this embodiment, refer to Figure 3 Dynamic management architecture diagram for hierarchical identity permissions of AI devices and different users; first, the holder of the primary account of an AI-eSIM device generates a valid sub-identity certificate through signing with an eSIM certificate, primary identity signature, permission matrix, validity period, device identifier, etc. When another user logs in to the device, the device verifies their corresponding identity certificate and grants corresponding operation permissions according to the permission matrix. Meanwhile, when the sub-identity certificate expires, fails verification, or the primary account holder issues a revocation operation, the corresponding sub-identity is dynamically changed in real time. The focus of this example lies in the cryptographic generation method of sub-identity certificates (signature + encryption + permission encoding), the encoding format of the permission matrix (operation type, time window, device scope), the offline certificate chain-based verification method, and the issuing and propagation mechanism for dynamic certificate revocation.

[0023] According to this embodiment, refer to Figure 4 Dynamic mapping diagram, which shows the dynamic mapping relationship network between numbers of AI-eSIM terminal devices and large model accounts; the "number is model account" design of AI-eSIM realizes that one number maps multiple large models, and the AI usage history is synchronously migrated when identity migration occurs. Through the platform's unique one-number multiple-model mapping algorithm, the number, model and timestamp are signed and bound with the identity, AI historical data is bound, and Tokens are used for linkage control with identities and devices, so as to realize dynamic mapping migration for model service providers.

[0024] According to this embodiment, refer to Figure 5The OTA key update flowchart outlines key update strategies for different chip types, such as SM2 / SM4 encryption algorithms for domestic chips and AES / RSA encryption algorithms for imported chips. When performing a key update operation, the platform selects the corresponding encryption algorithm based on the device's chip type and remotely sends the encrypted data to the device. The device then performs the key update process, and the real-time data status is synchronized with the backend. Key features of this key update technology include automatic chip type identification, automatic selection of encryption algorithms based on chip type, security level, and regional regulations, secure OTA update transmission technology (encryption + signature + integrity verification), a rollback mechanism for update failures (handling different rollback strategies for different chips), and support for concurrent control and progress tracking of batch OTA updates.

[0025] According to this embodiment, refer to Figure 6 This embodiment describes a token theft prevention and limit control method based on an eSIM hardware root of trust. IoT devices are highly vulnerable to hacking. If a device is compromised, a hacker could unleash a barrage of calls to the AI ​​interface, exhausting the enterprise's token budget, as in a DDoS attack. For each token request interaction, the AI-eSIM device uses a secure eSIM hardware signature and device identifier on its own device. Simultaneously, the platform performs comprehensive security verification, including signature validity, hardware validity, token consumption limits, and detection of abnormal device call frequencies. Failure to verify any of these will trigger an alert, and in severe cases, immediately halt the token supply. The core of this technology lies in the token consumption credential record bound to the device's eSIM hardware; the dynamic limit control algorithm: adaptive limit adjustment based on device behavior profiles; the abnormal consumption circuit breaker mechanism: detection and automatic blocking of sudden high-frequency calls; and hardware-level protection of the token balance: preventing local device tampering with balance data.

[0026] It is also necessary to explain the unique AI-eSIM device identity lifecycle anti-tampering auditing technology in this embodiment. This technology can be described in detail as ensuring that every operation related to device identity, including but not limited to activation / migration / authorization / cancellation, is auditable and tamper-proof, and supports third-party regulatory verification. This technology is based on a cryptographic hash chain-based audit log construction method; sensitive information in the audit log is encrypted, such as operation type + timestamp + SM3 / ECC hash + signature, which can only be decrypted by authorized personnel; the complete log chain record is in a chain structure, supporting chain break detection and repair methods; it also supports third-party verification interfaces, such as regulatory agencies verifying log integrity.

[0027] Compared with existing traditional technical solutions, the above description of this invention combines AI with eSIM, relying on a unique hardware identity to enable large-scale models to operate without authentication, reducing the pressure on cloud computing power; simultaneously, it relies on an independent security partition to achieve hardware encryption of AI business data, full-link traceability of large-scale model call behavior, and proactive network risk control, making up for the security shortcomings of traditional modules; the complete back-end remote management system has global coverage, high reliability, real-time, and full-service capabilities, forming a disruptive innovation. The design concept of this invention is not limited to this; any non-substantial modifications to this invention using this concept shall be considered as infringing upon the scope of protection of this invention.

Claims

1. System integration solution for AI terminal devices and eSIM security chips. Its features include OTA remote upgrade communication technology, SE security chip underlying hardware security technology, embedded terminal software and hardware integration development technology, edge-side lightweight data, edge-cloud collaboration, and AI context memory migration technology. A cryptographic method for generating migration tokens based on a hardware root of trust; AI terminal device identity-based hierarchical authorization and dynamic revocation technology; terminal device lifecycle anti-tampering technology; eSIM number and AI model account mapping technology; leveraging unique hardware identities to enable large-scale model authentication without login, reducing cloud computing power pressure; and simultaneously relying on independent security partitions to achieve hardware encryption of AI business data, full-link traceability of large-scale model call behavior, and proactive network risk control, forming a comprehensive end-to-end cloud collaboration mechanism—a system integration solution combining AI and eSIM security.

2. The integration scheme according to claim 1, further characterized in that... This includes device identity dynamic migration technology based on eSIM secure hardware root of trust to prevent "two-factor authentication" (the same identity existing on two or more devices at the same time). Migration interruption recovery mechanism; dual authentication detection.

3. The integration scheme according to claim 1, further characterized in that... This includes cross-cryptographic algorithm system device identity mutual recognition; construction of hybrid trust chains for the combination and verification of signatures from different algorithms; and cross-algorithm key derivation methods.

4. The integrated scheme according to claim 1 further includes device identity hierarchical authorization and dynamic revocation technology; cryptographic generation method for sub-identity certificates; encoding format of permission matrix; offline certificate verification method (certificate chain-based verification in a network-free environment); and dynamic revocation mechanism: method for issuing and propagating revoked certificates.

5. The integrated scheme according to claim 1 further includes a device identity lifecycle anti-tampering audit technology, a cryptographic hash chain audit log construction, a privacy protection encryption and decryption technology for audit logs, a third-party verification interface, a log chain break detection and repair method, and a long-term archiving and retrieval method for audit logs.

6. The integration scheme according to claim 1 further includes a dynamic mapping technology between eSIM number and AI large model account, a one-code-multiple-model mapping algorithm, a cryptographic binding method for mapping relationship (to prevent mapping from being tampered with), a binding mechanism between AI usage history and identity (same memory when changing devices), a linkage control method for token usage and identity permissions, and a mapping migration method when switching model service providers.

7. The integration scheme according to claim 1, further comprising: OTA key remote update method technology, automatic chip type identification, algorithm selection strategy, concurrency control and progress tracking of batch OTA updates, and handling of different rollback strategies for different chips.

8. The integrated scheme according to claim 1, further comprising hardware root of trust token anti-theft and limit control technology, dynamic limit control algorithm, and hardware-level protection of token balance.