Internet of Things terminal and secure transmission platform based on eSIM (Embedded Subscriber Identity Module)

By integrating security and isolation chips into eSIM IoT terminals, combined with two-way authentication and encryption modules, the security issues of eSIM cards are solved, achieving highly secure and scalable device connection management, suitable for various IoT application scenarios.

CN223798241UActive Publication Date: 2026-01-13XIAMEN FOUR FAITH COMM TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202520296043.2
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2026-01-13
Estimated Expiration
2035-02-24

AI Technical Summary

Technical Problem

eSIM cards have security issues during download and storage, making them vulnerable to theft or tampering. Attackers can forge configuration files to gain unauthorized access or steal user data, and remote configuration is also susceptible to attack.

Method used

Design an eSIM-based IoT terminal, comprising an eSIM chip, a communication module, a security chip, a main control chip, a power management module, and an isolation chip. It supports the GSMA RSP protocol, has a built-in secure storage area, achieves hardware-level protection through two-way authentication and a secure transmission platform, and uses the SM4 national cryptographic encryption module for encryption and decryption operations, combined with electrical isolation protection for the main control chip.

Benefits of technology

It achieves highly secure, flexible, and scalable device connectivity management, provides reliable data transmission and management services, and ensures the security of eSIM communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN223798241U_ABST
    Figure CN223798241U_ABST
Patent Text Reader

Abstract

The utility model provides an internet of things terminal based on an eSIM. The internet of things terminal comprises an eSIM chip, a communication module, a security chip, a main control chip, a power management module, an isolation chip and a sensor interface, wherein the main control chip is electrically connected with the eSIM chip, the communication module and the sensor interface, and the security chip is connected with the eSIM chip; the power management module is electrically connected with the main control chip through an isolation chip; wherein the eSIM chip supports a GSMA RSP protocol, is internally provided with a security storage area, is used for storing an encryption key and an operator configuration file, and realizes security authentication with a remote security transmission platform through bidirectional authentication; the security chip is used for executing encryption, decryption and signature security operations and providing hardware-level protection for the Internet of Things terminal; and the isolation chip is used for performing electrical isolation protection on the main control chip.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This utility model relates to the field of Internet of Things (IoT) technology, and in particular to an IoT terminal and secure transmission platform based on eSIM. Background Technology

[0002] With the increasing popularity and development of GSMA eSIM technology, more and more IoT products are adopting eSIM modules to replace traditional physical SIM cards, and are widely used in fields such as vehicle networking, smart water and electricity meters, construction machinery, drones, smart homes, and smart water management.

[0003] While eSIM cards offer significant advantages in flexibility and convenience, their security is also a major concern. For example, the eSIM card's configuration file (including carrier keys, user data, etc.) could be stolen or tampered with during download and storage, allowing attackers to gain unauthorized access or steal user data by forging the configuration file. Furthermore, because eSIMs support remote configuration and carrier switching, attackers could forge remote configuration requests to tamper with eSIM configurations or steal data. Therefore, data security is paramount during the use of eSIM cards. Utility Model Content

[0004] In view of this, the purpose of this utility model is to provide an IoT terminal and secure transmission platform based on eSIM to improve the above-mentioned problems.

[0005] This utility model provides an eSIM-based Internet of Things (IoT) terminal, comprising: an eSIM chip, a communication module, a security chip, a main control chip, a power management module, an isolation chip, and a sensor interface; wherein, the main control chip is electrically connected to the eSIM chip, the communication module, and the sensor interface, the security chip is connected to the eSIM chip, and the power management module is electrically connected to the main control chip through the isolation chip;

[0006] The eSIM chip supports the GSMA RSP protocol, has a built-in secure storage area for storing encryption keys and operator configuration files, and achieves secure authentication with a remote secure transmission platform through two-way authentication.

[0007] The security chip is used to perform encryption, decryption, and signature security operations, providing hardware-level protection for the IoT terminal;

[0008] The isolation chip is used to provide electrical isolation protection for the main control chip.

[0009] Preferably, the communication module supports network standards including 4G, 5G, NB-IoT, and LoRa.

[0010] Preferably, the sensor interface includes a USB interface and a UART interface, supporting the acquisition of temperature, humidity, and GPS data.

[0011] Preferably, the main control chip is a low-power processor.

[0012] This utility model embodiment also provides a secure transmission platform suitable for secure communication with the eSIM-based IoT terminal described above; wherein:

[0013] The IoT terminal is used to register with the platform and report hardware information upon startup;

[0014] After receiving the hardware information, the secure transmission platform determines whether the eSIM configuration file needs to be updated. If so, it sends an encrypted eSIM configuration file to the IoT terminal.

[0015] After receiving the encrypted eSIM configuration file, the IoT terminal decrypts it through the security chip and updates the eSIM chip's configuration file according to the decrypted eSIM configuration file.

[0016] Preferably, the secure transmission platform is also used to receive the collected data transmitted by the IoT terminal after being encrypted by the security chip, and to store it after decryption.

[0017] Preferably, the secure transmission platform is also used to monitor the device status of IoT terminals in real time and to remotely configure or update IoT terminals.

[0018] Preferably, the secure transmission platform performs two-way authentication with the IoT terminal to ensure the legitimacy of the identity.

[0019] In summary, the eSIM-based IoT terminal and secure transmission platform of this embodiment achieves highly secure, flexible, and scalable device connection management. Its hardware-level security protection and remote configuration capabilities are suitable for various IoT application scenarios, providing users with reliable and efficient data transmission and management services, and ensuring the security of eSIM-based communication. Attached Figure Description

[0020] Figure 1 This is a schematic diagram illustrating the communication between an eSIM-based IoT terminal and a secure transmission platform, as provided in an embodiment of this utility model. Detailed Implementation

[0021] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.

[0022] Please see Figure 1 This utility model embodiment provides an eSIM-based Internet of Things (IoT) terminal 100, which includes: an eSIM chip 10, a communication module 20, a security chip 30, a main control chip 40, a power management module 50, an isolation chip 60, and a sensor interface 70; wherein, the main control chip 40 is electrically connected to the eSIM chip 10, the communication module 20, and the sensor interface 70, the security chip 30 is connected to the eSIM chip 10, and the power management module 50 is electrically connected to the main control chip 40 through the isolation chip 60.

[0023] In this embodiment, the eSIM chip 10 supports the GSMA RSP (Remote SIM Configuration) protocol and has a built-in secure storage area for storing encryption keys and operator configuration files.

[0024] In this embodiment, the communication module 20 supports multiple network standards (such as 4G, 5G, NB-IoT, LoRa) to ensure full network coverage.

[0025] In this embodiment, the security chip 30 may adopt the SM4 national cryptographic encryption module, which is used to perform security operations such as encryption, decryption, and signing, and provides hardware-level protection.

[0026] In this embodiment, the main control chip 40 can be a low-power processor that supports edge computing and processes local data. In this embodiment, since complex operations such as encryption and decryption are handled by the security chip 30, the main control chip 40 can be a low-power processor, thereby reducing the overall cost of the terminal and increasing overall battery life.

[0027] In this embodiment, the power management module 50 provides the electrical energy required for the entire IoT terminal to operate, and the voltage supplied by it is distributed to each functional unit through the main control chip 40. To protect the main control chip 40, an isolation chip 60 is also provided between the power management module 50 and the main control chip 40.

[0028] In this embodiment, the sensor interface 70 supports data acquisition from various sensors (such as temperature, humidity, and GPS).

[0029] The working principle of this utility model is described in detail below:

[0030] In this embodiment, the initial activation of the ESIM chip 10 of the IoT terminal 100 can be performed at the factory or manually activated by the user after receiving the device. Subsequently, upon startup, the IoT terminal 100 can register with the secure transmission platform 200 and report hardware information. Upon receiving the hardware information, the secure transmission platform 200 determines whether an eSIM configuration file update is needed. If so, it sends a decrypted eSIM configuration file to the IoT terminal 100. Upon receiving the decrypted eSIM configuration file, the IoT terminal 100 uses the secure chip 30 to decrypt it to obtain the plaintext eSIM configuration file and updates the configuration of the eSIM chip 10 accordingly.

[0031] Then, before each communication, the IoT terminal 100 needs to perform two-way authentication with the secure transmission platform 200 to ensure the legitimacy of its identity.

[0032] After successful two-way authentication, the IoT terminal 100 can encrypt the collected data using protocols such as TLS / DTLS and transmit it to the secure transmission platform 200 for storage, preventing the data from being stolen or tampered with.

[0033] The secure transmission platform 200 can also remotely manage the IoT terminal 100 and the eSIM chip 10, including:

[0034] 1. Monitor device status in real time and remotely configure eSIM and terminal device parameters.

[0035] 2. Monitor device connection status in real time and detect abnormal behavior.

[0036] 3. Remotely switch between multiple operators, for example, dynamically switch operators based on factors such as network coverage and tariffs.

[0037] Furthermore, the secure transmission platform 200 can also support large-scale device access through its scalable design:

[0038] For example, by adopting a distributed architecture, it can support millions of devices to connect simultaneously.

[0039] It also supports integration with third-party systems by providing open API interfaces.

[0040] In summary, the eSIM-based IoT terminal and secure transmission platform of this embodiment achieves highly secure, flexible, and scalable device connection management. Its hardware-level security protection and remote configuration capabilities are suitable for various IoT application scenarios, providing users with reliable and efficient data transmission and management services, and ensuring the security of eSIM-based communication.

[0041] The above description is merely a preferred embodiment of one or more embodiments of this specification and is not intended to limit the scope of one or more embodiments of this specification. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of one or more embodiments of this specification should be included within the protection scope of one or more embodiments of this specification.

Claims

1. An eSIM-based Internet of Things terminal, characterized by, Comprise: An eSIM chip, a communication module, a security chip, a master control chip, a power management module, an isolation chip, and a sensor interface; wherein the master control chip is electrically connected with the eSIM chip, the communication module, and the sensor interface, the security chip is connected with the eSIM chip; the power management module is electrically connected with the master control chip through the isolation chip; Wherein, the eSIM chip supports GSMA RSP protocol, has a built-in security storage area for storing encryption keys and operator configuration files, and realizes security authentication with a remote security transmission platform through bidirectional authentication; The security chip is used for performing encryption, decryption, and signature security operations to provide hardware-level protection for the Internet of Things terminal; The isolation chip is used for electrical isolation protection of the master control chip.

2. The eSIM-based IoT terminal of claim 1, wherein, The communication module supports network standards including 4G, 5G, NB-IoT, and LoRa.

3. The eSIM-based IoT terminal of claim 1, wherein, The sensor interface includes a USB interface and a UART interface, and supports data collection of temperature, humidity, and GPS.

4. The eSIM-based IoT terminal of claim 1, wherein, The master control chip adopts a low-power processor.

5. A security transmission platform adapted to realize secure communication with the eSIM-based Internet of Things terminal according to any one of claims 1 to 4; wherein: The Internet of Things terminal is configured to register with the platform and report hardware information when starting; The security transmission platform is configured to determine whether the eSIM configuration file needs to be updated after receiving the hardware information, and if so, to issue an encrypted eSIM configuration file to the Internet of Things terminal; The Internet of Things terminal is configured to decrypt the encrypted eSIM configuration file through the security chip and update the configuration file of the eSIM chip according to the decrypted eSIM configuration file.

6. The security transmission platform of claim 5, wherein: The security transmission platform is further configured to receive the collected data encrypted by the security chip transmitted by the Internet of Things terminal, decrypt the data, and store the decrypted data.

7. The security transmission platform of claim 5, wherein: The security transmission platform is further configured to monitor the device status of the Internet of Things terminal in real time and remotely configure or update the Internet of Things terminal.

8. The secure transfer platform of claim 5, wherein: The security transmission platform and the Internet of Things terminal perform bidirectional authentication to ensure the legitimacy of the identity.