Communication methods, terminals, network devices, system and storage medium

By using the LPA module in the terminal to determine the locking of the eSIM card PUK code and sending notifications to the network device, the problem of the inability to use the eSIM card PUK code after locking is solved, and the protection of user privacy and security risks are achieved.

WO2025102324A1PCT designated stage expired Publication Date: 2025-05-22BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2023/132141
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-16
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

After the eSIM card PUK code in the terminal is locked, the terminal cannot be used normally and the operator cannot be notified in time, resulting in a security risk of user confidential data leakage.

Method used

The terminal's LPA module determines that the PUK code of the Profile in the eUICC chip is locked, the terminal's Profile status is set to the locked state, and a notification information is generated. The notification information is sent to the network device through the LPA module to limit the use of the eSIM card.

Benefits of technology

It solves the problem that the terminal eSIM card cannot be used normally after locking the PUK code. By sending PUK code lock notifications to network devices, users' privacy is protected and the security risk of user confidential data leakage is avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2023132141_22052025_PF_FP_ABST
    Figure CN2023132141_22052025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to communication methods, terminals, network devices, a system, and a storage medium. A method comprises: determining that a personal identity recognition unlocking PUK code of a network information configuration Profile in an eUICC chip is locked, and setting the Profile state of a terminal to be a locked state or an unavailable state; determining that the Profile state is the locked state or the unavailable state, and generating first notification information, the first notification information being used for indicating that the PUK code of the Profile in the eUICC chip is locked; and sending the first notification information to a network device by means of an LPA module. Thus, the problem that a terminal cannot be normally used after a PUK code of an eSIM card of the terminal is locked is solved, and by sending a PUK code locking notification to a network device, the use of the eSIM card is limited, thus protecting user privacy, and avoiding the security risk of confidential data breaches of users.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, terminal, network device, system and storage medium Technical Field

[0001] The present disclosure relates to the field of communication technologies, and in particular to a communication method, terminal, network device, system, and storage medium. Background Art

[0002] eSIM (Embedded-SIM) technology is a digital SIM (Subscriber Identification Module) card technology. With the rapid adoption and promotion of eSIM technology in the consumer market, an increasing number of wearable products, tablets, and smartphones are incorporating eSIM functionality, making it a must-have feature for supporting a variety of mobile communication services.

[0003] Summary of the Invention

[0004] In order to solve the technical problem in the related art that the processing method after the PUK code of the eSIM card in the terminal is locked is unclear, the embodiments of the present disclosure propose a communication method, terminal, network device, system and storage medium.

[0005] According to a first aspect of an embodiment of the present disclosure, a communication method is provided, which is performed by a terminal, wherein the terminal includes an embedded universal integrated circuit (eUICC) chip and a local profile assistant (LPA) module. The method includes:

[0006] Determining that the personal identity unlocking (PUK) code of the network information configuration profile in the eUICC chip is locked, and setting the profile status of the terminal to a locked state or an unusable state;

[0007] Determine that the Profile status is the locked state or the unusable state, and generate a first notification message, where the first notification message is used to indicate that the PUK code of the Profile in the eUICC chip is locked

[0008] The first notification information is sent to the network device through the LPA module.

[0009] According to a second aspect of an embodiment of the present disclosure, a communication method is provided, which is performed by a network device. The method includes:

[0010] Receive first notification information sent by a terminal, where the first notification information is used to indicate that a PUK code of a profile in an eUICC chip in the terminal is locked.

[0011] According to a third aspect of an embodiment of the present disclosure, a terminal is provided, comprising:

[0012] a processing module configured to determine that a personal identity unlocking (PUK) code of the network information configuration profile in the eUICC chip is locked, and set the profile status of the terminal to a locked state or an unusable state;

[0013] A generating module is configured to determine that the Profile status is the locked state or the unusable state, and generate a first notification message, wherein the first notification message is used to indicate that the PUK code of the Profile in the eUICC chip is locked

[0014] The transceiver module is configured to send the first notification information to the network device through the LPA module.

[0015] According to a fourth aspect of an embodiment of the present disclosure, a network device is provided, the network device comprising:

[0016] The transceiver module is configured to receive first notification information sent by a terminal, where the first notification information is used to indicate that the PUK code of the Profile in the eUICC chip in the terminal is locked.

[0017] According to a fifth aspect of an embodiment of the present disclosure, a terminal is provided, including:

[0018] one or more processors;

[0019] A memory coupled to the one or more processors, the memory comprising executable instructions, which, when executed by the one or more processors, causes the terminal to execute the communication method described in any one of the first aspects of the present disclosure.

[0020] According to a sixth aspect of an embodiment of the present disclosure, a network device is provided, including:

[0021] one or more processors;

[0022] A memory coupled to the one or more processors, the memory comprising executable instructions, which, when executed by the one or more processors, causes the first device to execute any one of the communication methods described in the second aspect of the present disclosure.

[0023] According to the seventh aspect of an embodiment of the present disclosure, a communication system is provided, comprising a terminal and a network device, wherein the terminal is configured to implement the communication method described in any one of the first aspects of the present disclosure, and the network device is configured to implement the communication method described in any one of the second aspects of the present disclosure.

[0024] According to an eighth aspect of an embodiment of the present disclosure, a storage medium is provided, which stores instructions. When the instructions are executed on a communication device, the communication device executes a communication method as described in any one of the first aspect or the second aspect of the present disclosure.

[0025] Through the above method, it is determined that the personal identity unlocking (PUK) code of the network information configuration profile in the eUICC chip is locked, the terminal's profile status is set to a locked state or an unusable state, and after the profile status is determined to be locked or unusable, a first notification message is generated. The first notification message is used to indicate that the PUK code of the profile in the eUICC chip is locked, and the first notification message is sent to the network device via the LPA module. This solves the problem of being unable to use the terminal normally after the PUK code of the terminal eSIM card is locked. By sending a PUK code lock notification to the network device, the use of the eSIM card is restricted, user privacy is protected, and the security risk of leakage of user confidential data is avoided. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following drawings required for describing the embodiments are introduced. The following drawings are merely some embodiments of the present disclosure and do not impose specific limitations on the protection scope of the present disclosure.

[0027] FIG1 is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.

[0028] FIG2 is an interactive schematic diagram illustrating a communication method according to an embodiment of the present disclosure.

[0029] FIG3 is a flow chart of a communication method according to an embodiment of the present disclosure.

[0030] FIG4 is a flow chart showing a communication method according to an embodiment of the present disclosure.

[0031] FIG5 a is a flow chart showing a communication method according to an embodiment of the present disclosure.

[0032] FIG5 b is a schematic diagram showing warning prompt information in a terminal according to an embodiment of the present disclosure.

[0033] FIG5c is a schematic diagram showing the transition of Profile status in a terminal according to an embodiment of the present disclosure.

[0034] FIG5 d is a schematic diagram showing Profile status display in a terminal according to an embodiment of the present disclosure.

[0035] FIG6 is a schematic structural diagram of a terminal proposed in an embodiment of the present disclosure.

[0036] FIG7 is a schematic structural diagram of a network device 7100 proposed in an embodiment of the present disclosure.

[0037] FIG8 is a schematic structural diagram of a communication device proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0038] The embodiments of the present disclosure provide a communication method, a terminal, a network device, a system, and a storage medium.

[0039] In a first aspect, an embodiment of the present disclosure provides a communication method, performed by a terminal, the terminal including an embedded universal integrated circuit (eUICC) chip and a local profile assistant (LPA) module, the method comprising:

[0040] Determining that the personal identity unlocking (PUK) code of the network information configuration profile in the eUICC chip is locked, and setting the profile status of the terminal to a locked state or an unusable state;

[0041] Determine that the Profile status is the locked state or the unusable state, and generate a first notification message, where the first notification message is used to indicate that the PUK code of the Profile in the eUICC chip is locked

[0042] The first notification information is sent to the network device through the LPA module.

[0043] In conjunction with some embodiments of the first aspect, in some embodiments, setting the Profile status of the terminal to a locked state or an unusable state includes:

[0044] Sending, by the LPA module, first indication information to the eUICC chip, where the first indication information is used to instruct the eUICC chip to lock the Profile;

[0045] Determining that the eUICC chip completes the profile locking process, generating, through the eUICC chip, second notification information and sending it to the LPA module, where the second notification information is used to indicate a processing result of the first indication information in the eUICC chip;

[0046] The LPA module sets the profile status to the locked state or the unusable state based on the second notification information.

[0047] In conjunction with some embodiments of the first aspect, in some embodiments, the terminal includes a lock screen interface module, and the method further includes:

[0048] Determine that the PUK code is locked, and control the lock screen interface module to prohibit input of the PUK code.

[0049] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0050] It is determined that the PUK code is locked, and a prompt message is displayed in the terminal through the LPA module, where the prompt message is used to indicate that the Profile in the terminal is unavailable.

[0051] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0052] A PUK code lock notification is sent to the LPA module through the lock screen interface module, where the PUK code lock notification is used to instruct the LPA module to send first indication information to the eUICC chip.

[0053] In combination with some embodiments of the first aspect, in some embodiments, setting the status of the Profile to the locked state or the unusable state based on the second notification information includes:

[0054] Determining, based on the processing result information, that the eUICC chip completes the locking process;

[0055] The Profile state is set to the locked state or the unusable state.

[0056] In conjunction with some embodiments of the first aspect, in some embodiments, sending the first notification information to the network device through the LPA module includes:

[0057] Obtaining a PUK code lock notification from the eUICC chip through the LPA module;

[0058] Generate the first notification information based on the PUK code lock notification fed back by the eUICC chip;

[0059] The first notification information is sent to the network device through the LPA module.

[0060] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0061] Obtaining first counting information, where the first counting information is used to indicate the number of times the input PUK code does not match the preset PUK code;

[0062] Determine that the first counting information reaches a preset number threshold, and lock the PUK code of the Profile in the eUICC chip.

[0063] In conjunction with some embodiments of the first aspect, in some embodiments, determining that the personal identity unlocking PUK code of the Profile in the eUICC chip is locked includes:

[0064] Determine, through the eUICC chip, whether the PUK code of the eUICC chip is locked.

[0065] In combination with some embodiments of the first aspect, in some embodiments, the first notification information is further used to instruct the network device to prohibit the eUICC chip from issuing the profile corresponding to the profile according to the first notification information.

[0066] In combination with some embodiments of the first aspect, in some embodiments, the first notification information is further used to instruct the network device to delete the Profile information of the terminal.

[0067] In a second aspect, an embodiment of the present disclosure provides a communication method, which is performed by a network device. The method includes:

[0068] Receive first notification information sent by a terminal, where the first notification information is used to indicate that a PUK code of a profile in an eUICC chip in the terminal is locked.

[0069] In conjunction with some embodiments of the second aspect, in some embodiments, the network device includes a subscription management data preparation SM-DP+ module, and the method further includes:

[0070] The SM-DP+ module prohibits the eUICC chip from issuing the profile based on the first notification information.

[0071] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0072] The SM-DP+ module changes the Profile record status of the terminal in the network device to a locked state or an unusable state based on the first notification information.

[0073] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0074] Delete the profile information of the terminal according to the first notification information.

[0075] In a third aspect, an embodiment of the present disclosure provides a terminal, comprising:

[0076] a processing module configured to determine that a personal identity unlocking (PUK) code of the network information configuration profile in the eUICC chip is locked, and set the profile status of the terminal to a locked state or an unusable state;

[0077] A generating module is configured to determine that the Profile status is the locked state or the unusable state, and generate a first notification message, wherein the first notification message is used to indicate that the PUK code of the Profile in the eUICC chip is locked

[0078] The transceiver module is configured to send the first notification information to the network device through the LPA module.

[0079] In a fourth aspect, an embodiment of the present disclosure provides a network device, comprising:

[0080] The transceiver module is configured to receive first notification information sent by a terminal, where the first notification information is used to indicate that the PUK code of the Profile in the eUICC chip in the terminal is locked.

[0081] In a fifth aspect, an embodiment of the present disclosure provides a terminal, including:

[0082] one or more processors;

[0083] A memory coupled to the one or more processors, the memory comprising executable instructions, which, when executed by the one or more processors, causes the terminal to execute the communication method described in any one of the first aspects of the present disclosure.

[0084] In a sixth aspect, an embodiment of the present disclosure provides a network device, including:

[0085] one or more processors;

[0086] A memory coupled to the one or more processors, the memory comprising executable instructions, which, when executed by the one or more processors, causes the first device to execute any one of the communication methods described in the second aspect of the present disclosure.

[0087] In the seventh aspect, an embodiment of the present disclosure proposes a communication system, comprising a terminal and a network device, wherein the terminal is configured to implement the communication method described in any one of the first aspects of the present disclosure, and the network device is configured to implement the communication method described in any one of the second aspects of the present disclosure.

[0088] In an eighth aspect, an embodiment of the present disclosure proposes a storage medium storing instructions. When the instructions are executed on a communication device, the communication device executes a communication method as described in any one of the first aspect or the second aspect of the present disclosure.

[0089] Through the above method, it is determined that the personal identity unlocking (PUK) code of the network information configuration profile in the eUICC chip is locked, the terminal's profile status is set to a locked state or an unusable state, and after the profile status is determined to be locked or unusable, a first notification message is generated. The first notification message is used to indicate that the PUK code of the profile in the eUICC chip is locked, and the first notification message is sent to the network device via the LPA module. This solves the problem of being unable to use the terminal normally after the PUK code of the terminal eSIM card is locked. By sending a PUK code lock notification to the network device, the use of the eSIM card is restricted, user privacy is protected, and the security risk of leakage of user confidential data is avoided.

[0090] The present disclosure provides a communication method, terminal, network device, system, and storage medium. In some embodiments, the terms "communication method," "information processing method," and "communication method" are interchangeable; the terms "communication device," "information processing device," and "communication device" are interchangeable; and the terms "information processing system," "communication system," and "communication system" are interchangeable.

[0091] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0092] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.

[0093] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.

[0094] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.

[0095] In the embodiments of the present disclosure, “plurality” refers to two or more.

[0096] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.

[0097] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.

[0098] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.

[0099] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.

[0100] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0101] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.

[0102] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.

[0103] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.

[0104] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).

[0105] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)" "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.

[0106] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.

[0107] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it is also possible to set the structure in which the terminal has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.

[0108] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.

[0109] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.

[0110] In some embodiments, data, information, etc. may be obtained with the user's consent.

[0111] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.

[0112] FIG1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG1 , a communication system 100 includes a terminal 101 , an access network device 102 , and a core network device 103 .

[0113] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.

[0114] In some embodiments, the access network device 102 is, for example, a node or device that accesses a terminal to a wireless network. The access network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.

[0115] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0116] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.

[0117] In some embodiments, the core network device 103 may be a single device including a first network element 1031, a second network element 1032, etc., or may be a plurality of devices or a device group including all or part of the first network element 1031, the second network element 1032, etc. The network element may be virtual or physical. The core network may include, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0118] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.

[0119] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1 , or a portion thereof, but are not limited thereto. The entities shown in FIG1 are illustrative only. The communication system may include all or part of the entities shown in FIG1 , or may include other entities outside of FIG1 . The number and form of the entities are arbitrary, and the entities may be physical or virtual. The connection relationships between the entities are illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.

[0120] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).

[0121] In one embodiment, compared to traditional physical SIM cards, eSIM cards are embedded in devices as chips, significantly reducing the physical space occupied by the physical card slot and improving the stability, waterproofness, and shock resistance of the terminal device. Furthermore, the eSIM card dynamically downloads carrier profiles from the Remote SIM Provisioning (RSP) remote configuration platform primarily via OTA (Over the Air). Each profile represents a separate electronic SIM card. The LPA (Local Profile Assistant) application on the device then installs the profile into the eUICC chip on the terminal device. Once successfully installed, the user can activate and log in to the carrier network as normal.

[0122] In some implementations, while eSIM cards have no difference in communication functionality compared to physical SIM cards, due to changes in the chip carrier, the PUK (Personal Identification Number Unlock Key) unlocking PIN (Personal Identification Number) code of the currently enabled profile may be permanently locked after the maximum number of attempts has been reached. This prevents normal access to the terminal device, impacting the use of profiles from other operators. For example, a terminal may have multiple profiles loaded, with Profile A corresponding to operator A's server and Profile B corresponding to operator B's server. If the PUK unlocking PIN for Profile A in the terminal fails, the terminal needs to be controlled to lock Profile A alone without affecting the normal use of profiles from other operators. In this case, a method for resolving a locked Profile PUK code is required to prevent the terminal device and the normal use of profiles from other operators. At the same time, the operator's backend needs to be notified to restrict and manage the locked Profile to prevent the same terminal device from applying for a PUK again.

[0123] In some embodiments, a terminal equipped with an eSIM card function downloads and installs a profile from a remote SM-DP+ (Subscription Manager Data Preparation) server, then activates the profile and PIN (Personal Identification Number) protection as normal. When the terminal is powered on again, if the terminal user forgets or incorrectly enters the PIN code and the maximum number of attempts is reached, the terminal enters the lock screen interface. At this time, a PUK code is required to unlock the PIN code. If the terminal user enters the PUK code the maximum number of times, the PUK code is permanently locked and cannot be used subsequently. For example, if the terminal user incorrectly enters the PIN code after three attempts, the terminal enters the lock screen interface and is prompted to enter the PUK code to unlock the terminal's PIN code. If the terminal attempts to enter the PUK code on the lock screen interface to 10 times, the terminal's PUK code is permanently locked, and the terminal cannot subsequently use the profile communication function.

[0124] In some implementations, given the differences in form and usage between eSIM cards and physical pluggable SIM cards, multiple eSIM profiles are typically loaded onto the same communication chip in a terminal, with different eSIM profiles corresponding to different operator servers. Locking the PUK code for a particular profile does not affect the normal use of the terminal device or other profiles. Furthermore, once the PUK code of a traditional SIM card is locked, the card becomes permanently unusable, forcing the user to replace it at a carrier's location. At this point, the carrier will promptly process the core network data corresponding to the SIM card and prohibit its further use. However, once the PUK code of an eSIM card is locked, this status cannot be promptly notified to the carrier. If the eSIM card supports re-downloads, the eSIM profile could be re-issued after deletion by the terminal, potentially leading to illegal use or brute-force decryption of the user's sensitive personal data, posing a security risk of personal data leakage for the terminal user.

[0125] In some embodiments, after detecting that the PUK code number of the eSIM card is locked, the terminal actively notifies the LPA (Local Profile Assistant) module in the terminal to shut down the currently enabled eSIM card, allowing the terminal user to complete the startup process normally and enter the terminal device.

[0126] In some embodiments, after determining that the PUK code of the eSIM is locked, the terminal will add a profile-locked status indicator to the terminal based on the eSIM profile (network information configuration), prohibiting the terminal user from reactivating the profile. If the terminal user accidentally activates the profile or otherwise activates it, a warning message will be displayed on the terminal to remind the terminal user that data communication based on the profile is prohibited.

[0127] In some embodiments, for an eSIM Profile with a locked PUK code, the eUICC chip should automatically generate a PUK code lock notification. After the LPA application obtains the notification, it sends it to the operator's SM-DP+ platform via a network channel, informing the operator that the PUK code of the current Profile has been locked and that further downloading by scanning the QR code or other methods is prohibited.

[0128] FIG2 is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2 , the embodiment of the present disclosure relates to a communication method, which is performed by a terminal 101 and a network device 102, and the method includes:

[0129] In step S2101, the terminal 101 determines that the PUK code of the profile in the eUICC chip is locked, and sets the profile status of the terminal 101 to a locked state or an unusable state.

[0130] In some implementations, the terminal 101 of this embodiment includes an eUICC chip and an LPA module. The eUICC is an embedded universal integrated circuit card, also known as a programmable SIM card, which can be pre-installed during device manufacturing and can be remotely managed and configured over the network. Unlike traditional SIM cards, the eUICC can store information about multiple carrier servers, enabling switching between different carrier servers, thereby providing the terminal with more flexible and convenient mobile communication services. The eSIM is an application of the eUICC. The eSIM can be configured on the eUICC chip during device assembly and can be remotely managed and configured over the network. The eSIM application on the eUICC allows for convenient and quick SIM card switching and management at the terminal vendor.

[0131] For example, the LPA module is an independent system application installed in the terminal 101, which is used to manage the profile information on the eSIM card. The LPA module acts as a bridge between the SM-DP+ module and the eUICC chip in the network device 102. Through the LPA module, the terminal 101 can download the profile information from the SM-DP+ module of the network device 102. The LPA module provides a central location for terminal users to manage embedded subscription profiles. The terminal 101 can automatically discover available LPA modules and then route all eUICC operations in the terminal 101 through the LPA module instance.

[0132] For example, when terminal 101 detects that the PUK code of a profile in the eUICC chip is locked, the profile status in terminal 101 is set to a locked state or an unusable state. A profile is network configuration file information, and one profile corresponds to one operator. If the eUICC chip supports communication with multiple operators, multiple profiles can be configured in the eUICC chip. In this embodiment, a profile refers to an application on the eUICC, and the concept of a profile can be equivalent to an eSIM application in the eUICC chip. After determining that the PUK code of a profile in the eUICC chip is locked, the status of the profile is changed from the current enabled state to a locked state or an unusable state, while the status of other profiles in the eUICC chip remains unchanged. For example, if the eUICC chip of terminal 101 is configured with three profiles: Profile-1, Profile-2, and Profile-3, and if it is detected that the PUK code of Profile-2 in terminal 101 is locked, the current status of Profile-2 in terminal 101 is changed to a locked state or an unusable state.

[0133] In some implementations, after determining that the PUK code of the Profile is locked, the Profile status may also be changed to "prohibited status", "rejected status", "restricted status" or "disabled status", etc., which is not limited in this embodiment.

[0134] In some embodiments, when the PIN code in the terminal 101 is locked, the terminal 101 may detect the PUK code status of the profile currently used on the eUICC chip. For example, when the number of incorrect attempts by the terminal user to enter the PUK code reaches a set attempt threshold, the terminal 101 will lock the PUK code, thereby prohibiting the terminal user from attempting to enter the PUK code again.

[0135] Optionally, in some embodiments, the method further comprises:

[0136] The terminal 101 obtains first counting information, where the first counting information is used to indicate the number of times the input PUK code does not match the preset PUK code;

[0137] The terminal 101 determines that the first counting information reaches a preset number threshold, and locks the PUK code of the profile in the eUICC chip.

[0138] For example, after the PIN code in the terminal 101 is locked, it is necessary to enter the PUK code to unlock the locked state of the PIN code, and reset the PIN code so that the terminal 101 can reuse the PIN code for mobile communications. In this embodiment, the number of attempts to enter the PUK code by the terminal user in the terminal 101 is counted. When the PUK code entered by the terminal user does not match the preset PUK code, the corresponding counter accumulates once. The recorded value of the counter is read as the first counting information. When the first counting information reaches the preset number threshold, the PUK code of the Profile in the eUICC chip is locked. For example, the preset number threshold is determined to be 10 times. When the number of attempts by the terminal user to enter the PUK code reaches 10 times, the PUK code of the currently enabled Profile is changed to a locked state.

[0139] Optionally, in some implementations, the step of “determining whether the personal identity unlocking PUK code of the Profile in the eUICC chip is locked” includes:

[0140] The terminal 101 determines, through the eUICC chip, that the PUK code of the eUICC chip is locked.

[0141] For example, in this embodiment, the eUICC chip can also autonomously identify the status of the PUK code of the currently enabled profile in the terminal 101, detect the terminal 101 through the eUICC chip, and after determining that the PUK code of the corresponding profile is locked, start the locking process of the profile in the eUICC chip.

[0142] Optionally, in some embodiments, setting the terminal's Profile status to a locked state or an unusable state includes:

[0143] The terminal 101 sends first indication information to the eUICC chip through the LPA module, where the first indication information is used to instruct the eUICC chip to lock the profile;

[0144] The terminal 101 determines that the eUICC chip completes the profile locking process, generates a second notification message through the eUICC chip, and sends it to the LPA module. The second notification message is used to indicate the processing result of the first indication message in the eUICC chip.

[0145] The LPA module sets the Profile status to a locked state or an unusable state based on the second notification information.

[0146] For example, in this embodiment, after determining that the PUK code of the profile in the eUICC chip is locked, the terminal 101 sends PUK code locking information to the LPA module, and the LPA module configured in the terminal 101 sends first indication information to the eUICC chip to instruct the eUICC chip to complete the PUK code locking operation.

[0147] In some implementations, the first indication information is used to instruct the eUICC chip to lock the Profile corresponding to the PUK code.

[0148] In some implementations, the name of the first indication information is not limited, and may be, for example, a "Profile lock instruction," a "Profile prohibition instruction," a "Profile lock notification," a "lock Profile instruction," or the like.

[0149] After receiving the first indication information sent by the LPA module, the eUICC chip initiates a locking process for the corresponding profile based on the first indication information. For example, in this embodiment, the first indication information includes identification information of the profile corresponding to the PUK code. The eUICC chip initiates the locking process for the profile in the chip based on the identification information. Locking the profile in the eUICC chip does not affect the normal use of other profiles configured in the eUICC chip. After the locking process for the profile in the eUICC chip is completed, the terminal 101 cannot perform data communication with the corresponding operator based on the profile. However, the eUICC chip can perform data communication with other operators based on other profiles.

[0150] After receiving the first indication information, the eUICC chip initiates the profile locking process, closes the currently enabled eSIM profile, and changes the status of the currently enabled profile in the eUICC chip to a "locked" state or an "unusable" state. For example, after completing the profile locking process, the eUICC chip may send a second notification message to the LPA module, where the second notification message is used to indicate the processing result information of the locking process in the eUICC chip.

[0151] The LPA module in terminal 101 may set the profile status in terminal 101 to a locked state or an unusable state based on the second notification information fed back by the eUICC chip. For example, after the LPA module determines based on the second notification information that the eSIM profile locking process has been completed in the eUICC chip, it changes the currently enabled profile status to a locked state or an unusable state. The display module of terminal 101 may also display on terminal 101 that the currently enabled profile is prohibited from use or locked.

[0152] Optionally, in some implementations, the terminal 101 includes a lock screen interface module, and the method further includes:

[0153] The terminal 101 determines that the PUK code is locked, and controls the lock screen interface module to prohibit input of the PUK code.

[0154] For example, terminal 101 is configured with a lock screen interface module, which is used to manage the lock screen content displayed to the terminal user in the lock screen interface. When it is determined that the PUK code of the profile in the eUICC chip of terminal 101 is locked, the lock screen interface module prohibits the terminal user from entering the PUK code again. A limit is set on the number of attempts the terminal user can make to enter the PUK code. If the limit is exceeded, the user is prohibited from entering the PUK code, thereby improving the security of terminal 101 and protecting the terminal's privacy.

[0155] Optionally, in some embodiments, the method further comprises:

[0156] The terminal 101 determines that the PUK code is locked, and displays a prompt message in the terminal through the LPA module, where the prompt message is used to indicate that the Profile in the terminal is unavailable.

[0157] For example, after determining that the PUK code is locked, the LPA module may display a prompt message in the terminal based on the currently enabled profile, where the prompt message is used to indicate that the currently enabled profile in the terminal is unavailable or is locked.

[0158] Optionally, in some embodiments, the method further comprises:

[0159] The terminal 101 sends a PUK code lock notification to the LPA module through the lock screen interface module. The PUK code lock notification is used to instruct the LPA module to send first indication information to the eUICC chip.

[0160] For example, the terminal 101 is configured with a lock screen interface module, which detects whether the PUK code is locked. After determining that the PUK code of the currently enabled Profile is locked, a PUK code lock notification is sent to the LPA module, wherein the PUK code lock notification is used to instruct the LPA module to send a first indication information to the eUICC chip. The function of the first indication information is the same as in the above embodiment, and can be referred to the above embodiment, which will not be repeated here.

[0161] Optionally, in some implementations, the above step of “setting the status of the Profile to a locked state or an unusable state based on the second notification information” includes:

[0162] The terminal 101 determines, based on the processing result information, that the eUICC chip has completed the locking process;

[0163] The terminal 101 sets the profile status to a locked state or an unusable state.

[0164] For example, in this embodiment, after the LPA module receives the second notification information fed back by the eUICC chip, it determines the processing result information in the second notification information, and after determining that the locking process of the profile in the eUICC chip has been completed based on the processing result information, sets the status of the corresponding profile in the LPA module to a locked state or an unusable state.

[0165] In step S2102, the terminal 101 determines that the profile status is locked or unusable, and generates a first notification message, where the first notification message is used to indicate that the PUK code of the profile in the eUICC chip is locked.

[0166] For example, after the profile status in the LPA module is set from an enabled state to a locked state or an unusable state, a first notification message is generated, where the first notification message is used to indicate that the PUK code of the profile in the eUICC chip of the current terminal 101 is locked. The first notification message is an external notification message, and the terminal 101 sends the first notification message to the network device 102 to prompt the network device 102 that the PUK code of the profile in the current terminal 101 is in a locked state, so that the network device 102 can perform subsequent processing on the profile.

[0167] In step S2103 , the terminal 101 sends the first notification information to the network device through the LPA module.

[0168] For example, after the first notification information is generated in the above manner, the first notification information can be sent to the network device 102 through the LPA module, so that the network device 102 makes corresponding processing based on the first notification information, thereby preventing the terminal 101 from continuing to download the corresponding profile file from the network device again through the LPA module, thereby protecting the privacy security of the terminal 101.

[0169] Optionally, in some implementations, the step of “sending the first notification information to the network device through the LPA module” includes:

[0170] The terminal 101 obtains a PUK code lock notification from the eUICC chip through the LPA module;

[0171] The terminal 101 generates first notification information based on the PUK code lock notification fed back by the eUICC chip;

[0172] The terminal 101 sends the first notification information to the network device through the LPA module.

[0173] For example, in this embodiment, after determining that the profile locking process has been completed in the eUICC chip based on the locking instruction processing result fed back by the eUICC chip, the LPA module can obtain a PUK code locking notification from the eUICC chip. The eUICC chip generates a first notification message based on the currently locked profile and sends it to the LPA module. After receiving the first notification message, the LPA module sends the first notification message to the network device 102.

[0174] Optionally, in some implementations, the first notification information is further used to instruct the network device to prohibit the issuance of the profile corresponding to the eUICC chip according to the first notification information.

[0175] For example, in this embodiment, the first notification information is used to notify network device 102 that the PUK code of the currently enabled profile of terminal 101 is locked. Based on the first notification information, network device 102 can prohibit the eUICC chip of terminal 101 from downloading the corresponding profile information again. This prevents the profile of terminal 101 from being restored to an unlocked state by downloading the profile information again, prevents user data leakage, and improves terminal security.

[0176] Optionally, in some implementations, the first notification information is further used to instruct the network device to delete the Profile information of the terminal.

[0177] For example, in this embodiment, the first notification information can also be used to instruct the network device 102 to delete the Profile information corresponding to the terminal 101, thereby preventing the terminal 101 from restoring the currently prohibited Profile by downloading it again, thereby improving the security of the terminal's private data.

[0178] Step S2104 : The network device 102 receives the first notification information sent by the terminal 101 .

[0179] In some implementations, the first notification information is used to indicate that the PUK code of the Profile in the eUICC chip in the terminal is locked.

[0180] For example, the network device 102 takes corresponding response actions according to the first notification information sent by the terminal to prevent the terminal 101 from violently unlocking the current PUK code through other operation modes, thereby protecting the user's privacy data.

[0181] Optionally, in some embodiments, the network device includes a subscription management data preparation SM-DP+ module, and the method further includes:

[0182] The SM-DP+ module of the network device 102 prohibits the eUICC chip from issuing the corresponding profile based on the first notification information.

[0183] For example, the SM-DP+ module is the eSIM number storage and management platform configured in the network device 102. The LPA module configured in the terminal 101 can download the numbers from the SM-DP+ modules of different operators to achieve network communication with the operators. The SM-DP+ in the network device 102 ensures the security and integrity of the subscription profile, provides flexibility, allows the terminal 101 to switch between different network operators, and loads the operator's subscription configuration information into the eSIM card of the terminal 101 through a secure channel, thereby realizing remote management and updating of the terminal's subscription information.

[0184] The network device 102 passes the received first notification information to the SM-DP+ module. Based on the first notification information, the module prohibits the terminal 101 from issuing the profile corresponding to the eUICC chip, thereby protecting the privacy security of the terminal 101.

[0185] Optionally, in some embodiments, the method further comprises:

[0186] The SM-DP+ module of the network device 102 changes the Profile record status of the terminal in the network device to a locked state or an unusable state based on the first notification information.

[0187] For example, after receiving the first notification information, the SM-DP+ module changes the Profile record status of the terminal 101 in the network device 102, changing the Profile record status from the current enabled state to a locked state or an unusable state.

[0188] Optionally, in some embodiments, the method further comprises:

[0189] The network device 102 deletes the profile information of the terminal according to the first notification information.

[0190] For example, in this embodiment, after receiving the first notification information, the network device 102 deletes the profile information of the terminal 101 in the network device 102, thereby preventing the terminal 101 from downloading the profile information corresponding to the lock PUK code again. Protecting user privacy prevents leakage of user confidential data.

[0191] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codeword", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0192] In some embodiments, the terms "radio", "wireless", "radio access network (RAN)", "access network (AN)", "RAN-based" and the like may be used interchangeably.

[0193] In some embodiments, terms such as "synchronization signal (SS)", "synchronization signal block (SSB)", "reference signal (RS)", "pilot", and "pilot signal" can be used interchangeably.

[0194] In some embodiments, terms such as "moment", "time point", "time", and "time position" can be replaced with each other, and terms such as "duration", "period", "time window", "window", and "time" can be replaced with each other.

[0195] In some embodiments, "obtain", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation, etc.

[0196] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.

[0197] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "a certain", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, a certain A, any A, or first A, etc., but not limited to this.

[0198] In some embodiments, the determination or judgment can be performed by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values ​​(for example, comparison with a predetermined value), but is not limited thereto.

[0199] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or as not performing subsequent processing on the data after receiving it; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the recipient to respond to the content sent.

[0200] Through the above method, the terminal determines that the personal identity unlocking (PUK) code of the network information configuration profile in the eUICC chip is locked, sets the terminal's profile status to a locked state or an unusable state, determines that the profile status is locked or unusable, generates a first notification message, and the first notification message is used to indicate that the PUK code of the profile in the eUICC chip is locked. The first notification message is sent to the network device via the LPA module. This solves the problem of being unable to use the terminal normally after the PUK code of the terminal's eSIM card is locked. By sending a PUK code lock notification to the network device, the use of the eSIM card is restricted, user privacy is protected, and the security risk of leakage of user confidential data is avoided.

[0201] FIG3 is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3 , the embodiment of the present disclosure relates to a communication method, which is executed by terminal 101 and includes:

[0202] Step S3101: Determine that the personal identity unlocking PUK code of the network information configuration profile in the eUICC chip is locked, and set the profile status of the terminal to a locked state or an unusable state.

[0203] Optionally, in some implementations, setting the terminal's Profile status to a locked state or an unusable state includes:

[0204] Sending first indication information to the eUICC chip through the LPA module, where the first indication information is used to instruct the eUICC chip to lock the profile;

[0205] Determine that the eUICC chip completes the profile locking process, generate a second notification message through the eUICC chip, and send it to the LPA module. The second notification message is used to indicate the processing result of the first indication message in the eUICC chip;

[0206] The LPA module sets the Profile status to a locked state or an unusable state based on the second notification information.

[0207] Optionally, in some implementations, the terminal includes a lock screen interface module, and the method further includes:

[0208] Determine that the PUK code is locked and control the lock screen interface module to prohibit input of the PUK code.

[0209] Optionally, in some embodiments, the method further comprises:

[0210] If the PUK code is locked, the LPA module will display a prompt message on the terminal, indicating that the profile in the terminal is unavailable.

[0211] Optionally, in some embodiments, the method further comprises:

[0212] A PUK code lock notification is sent to the LPA module through the lock screen interface module. The PUK code lock notification is used to instruct the LPA module to send first indication information to the eUICC chip.

[0213] Optionally, in some implementations, setting the status of the Profile to a locked state or an unusable state based on the second notification information includes:

[0214] According to the processing result information, it is determined that the eUICC chip has completed the locking process;

[0215] Set the profile status to locked or unavailable.

[0216] Optionally, in some embodiments, the method further comprises:

[0217] Obtaining first counting information, where the first counting information is used to indicate the number of times the input PUK code does not match the preset PUK code;

[0218] It is determined that the first counting information reaches a preset number threshold, and the PUK code of the profile in the eUICC chip is locked.

[0219] Optionally, in some implementations, determining that the personal identity unlocking PUK code of the Profile in the eUICC chip is locked includes:

[0220] Through the eUICC chip, confirm that the PUK code of the eUICC chip is locked.

[0221] For example, the optional implementation of step S3101 in this embodiment can refer to the optional implementation of step S2101 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.

[0222] Step S3102: Determine that the Profile status is locked or unusable, and generate first notification information, where the first notification information is used to indicate that the PUK code of the Profile in the eUICC chip is locked.

[0223] For example, the optional implementation of step S3102 in this embodiment can refer to the optional implementation of step S2102 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.

[0224] Step S3103: Send the first notification information to the network device through the LPA module.

[0225] Optionally, in some implementations, sending the first notification information to the network device through the LPA module includes:

[0226] Obtain PUK code lock notification from the eUICC chip through the LPA module;

[0227] Generate first notification information based on the PUK code lock notification fed back by the eUICC chip;

[0228] The first notification information is sent to the network device through the LPA module.

[0229] Optionally, in some implementations, the first notification information is further used to instruct the network device to prohibit the issuance of the profile corresponding to the eUICC chip according to the first notification information.

[0230] Optionally, in some implementations, the first notification information is further used to instruct the network device to delete the Profile information of the terminal.

[0231] For example, the optional implementation of step S3103 in this embodiment can refer to the optional implementation of step S2103 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.

[0232] Through the above method, it is determined that the personal identity unlocking (PUK) code of the network information configuration profile in the eUICC chip is locked, the terminal's profile status is set to a locked state or an unusable state, and after the profile status is determined to be locked or unusable, a first notification message is generated. The first notification message is used to indicate that the PUK code of the profile in the eUICC chip is locked, and the first notification message is sent to the network device via the LPA module. This solves the problem of being unable to use the terminal normally after the PUK code of the terminal eSIM card is locked. By sending a PUK code lock notification to the network device, the use of the eSIM card is restricted, user privacy is protected, and the security risk of leakage of user confidential data is avoided.

[0233] FIG4 is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4 , the present disclosure embodiment relates to a communication method, which is executed by a network device 102 and includes:

[0234] Step S4101: Receive first notification information sent by a terminal, where the first notification information is used to indicate that the PUK code of the Profile in the eUICC chip in the terminal is locked.

[0235] Optionally, in some embodiments, the network device includes a subscription management data preparation SM-DP+ module, and the method further includes:

[0236] The SM-DP+ module prohibits the eUICC chip from issuing the corresponding profile based on the first notification information.

[0237] Optionally, in some embodiments, the method further comprises:

[0238] Based on the first notification information, the SM-DP+ module changes the Profile record status of the terminal in the network device to a locked state or an unusable state.

[0239] Optionally, in some embodiments, the method further comprises:

[0240] According to the first notification information, the Profile information of the terminal is deleted.

[0241] For example, the optional implementation of step S4101 in this embodiment can refer to the optional implementation of step S2104 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.

[0242] Through the above method, the network device receives the first notification information sent by the terminal, which indicates that the PUK code of the profile in the eUICC chip in the terminal has been locked. This solves the problem of being unable to use the terminal normally after the PUK code of the terminal's eSIM card is locked. By sending a PUK code lock notification to the network device, the use of the eSIM card is restricted, protecting user privacy and avoiding the security risk of leaking user confidential data.

[0243] Figure 5a is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in Figure 5a, the present disclosure embodiment relates to a communication method, which is executed by a terminal 101, which is configured with a lock screen interface module, an LPA application, and an eUICC chip. The method includes:

[0244] (1) The terminal user attempts to enter an incorrect PUK code in the terminal.

[0245] (2) After reaching the maximum number of attempts for dozens of times, the PUK code number in the terminal is locked, and the terminal lock screen interface module in the terminal 101 prohibits the terminal user from attempting to enter the PUK code again.

[0246] In some embodiments, FIG5b is a schematic diagram of a warning prompt message in a terminal according to an embodiment of the present disclosure. As shown in FIG5b , the terminal 101 is executed. The terminal 101 is configured with an eSIM card management module and a lock screen interface module. The LPA module displays the current activation status of the corresponding profile of each eSIM card in the eSIM card management module. For example, as shown in FIG5b , under the current usage status, the profile of operator 1 in this embodiment is in an inactive state; the profile of operator 2 is in a locked state or unavailable state. When the terminal user attempts to conduct data communication based on the profile of operator 2, a warning message is displayed at the bottom of the management page to prompt the terminal user: Your PUK code has been entered incorrectly too many times. The current eSIM card 2 is no longer usable. Please contact the network operator for details, thereby prompting the terminal user that the current eSIM card 2 is unavailable.

[0247] (3) The terminal lock screen sends a PUK code lock notification to the LPA application.

[0248] (4) The LPA application processes the PUK code lock notification and executes the lock current profile process.

[0249] (5) The LPA sends a lock command to the eUICC chip to lock the currently enabled Profile.

[0250] (6) After receiving the command, the eUICC chip closes the currently enabled Profile and changes the Profile status to "locked" or "unusable". It then generates a PUK code lock notification event to be sent to the operator's SM-DP+ platform, using the same format and coding as other notification events defined in the GSMA SGP.22 specification.

[0251] (7) The eUICC chip returns the lock command execution result.

[0252] (8) The LPA application changes the Profile status display to "locked" or "unavailable" according to the execution result of the lock command.

[0253] In some implementations, FIG5c is a schematic diagram illustrating a Profile state transition in a terminal according to an embodiment of the present disclosure, as shown in FIG5c , which is executed by the terminal 101 .

[0254] When the terminal 101 needs to communicate with the network based on the eUICC chip, the profile corresponding to the eUICC chip is in the enabled state. When the terminal 101 communicates data with the network based on another eUICC chip, the profile of the eUICC chip changes from the current enabled state to the disabled state. When it is detected that the PUK code number in the terminal 101 is locked, the profile of the eUICC chip changes from the current enabled state to the locked state or the unavailable state.

[0255] For example, FIG5d is a schematic diagram of the Profile status display in a terminal according to an embodiment of the present disclosure, as shown in FIG5d , and is executed by terminal 101. The eSIM card status management display page includes status information of each eSIM card for the Profile, as well as instruction information for adding an eSIM card. For example, as shown in FIG5d , on the eSIM card management page, the Profile of eSIM1 corresponding to operator 1 is in an unactivated state, the Profile of eSIM2 corresponding to operator 2 is in a locked state or unavailable state, and an "Add eSIM Card" option is displayed below the status display bar to facilitate terminal users to add new eSIM cards.

[0256] (9) The LPA reads the PUK code lock notification event to be sent to the operator's SM-DP+ platform from the eUICC chip.

[0257] (10) The eUICC chip returns a PUK code lock notification event.

[0258] (11) The LPA sends a PUK code lock notification to the operator's SM-DP+ platform. The SM-DP+ platform performs relevant processing and restricts the re-issuance of the profile in the network device.

[0259] (12) The SM-DP+ platform notifies the operator of the PUK code lock event of the current profile through the interface, and the operator's backend system performs subsequent processing.

[0260] The above method solves the problem of the lock screen failing to unlock after the terminal's eSIM card PUK code is locked, making it impossible for the user to use the terminal device normally. After the eSIM card PUK code is locked, the operator's backend should be notified in a timely manner to restrict and manage the use of the eSIM card and prohibit the re-issuance of the eSIM card. This is to prevent the security risk of illegally using the eSIM card by re-downloading the eSIM card or brute-forcing the eSIM card user PIN code, which may lead to the leakage of user confidential data.

[0261] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0262] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.

[0263] In the embodiments of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and implementing the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0264] Figure 6 is a schematic diagram of the structure of a terminal proposed in an embodiment of the present disclosure. As shown in Figure 6, terminal 6100 may include at least one of a processing module 6101, a generation module 6102, and a transceiver module 6103. In some embodiments, the processing module 6101 is configured to determine that the personal identity unlocking (PUK) code of the network information configuration profile in the eUICC chip is locked, and set the terminal's profile status to a locked state or an unusable state; the generation module 6102 is configured to determine that the profile status is locked or unusable, and generate a first notification message indicating that the PUK code of the profile in the eUICC chip is locked; and the transceiver module 6103 is configured to send the first notification message to the network device via the LPA module. Optionally, the transceiver module is configured to perform at least one of the communication steps, such as sending and / or receiving, performed by terminal 101 in any of the above methods, which are not further described here. Optionally, the processing module is configured to perform at least one of the other steps performed by terminal 101 in any of the above methods, which are not further described here.

[0265] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, and the transmitting module and the receiving module may be separate or integrated. Optionally, the transceiver module may be interchangeable with the transceiver.

[0266] In some embodiments, the generation module can be a single module or include multiple submodules. Optionally, the multiple submodules each execute all or part of the steps required to be executed by the generation module. Optionally, the generation module can be interchangeable with the generator.

[0267] In some embodiments, the processing module can be a single module or can include multiple submodules. Optionally, the multiple submodules respectively execute all or part of the steps required to be executed by the processing module. Optionally, the processing module can be interchangeable with the processor.

[0268] Figure 7 is a schematic diagram of the structure of the network device 7100 proposed in an embodiment of the present disclosure. The network device 7100 can be an access network device, a core network device, etc., or a terminal (such as a user device, etc.), or a chip, a chip system, or a processor that supports the network device to implement any of the above methods, or a chip, a chip system, or a processor that supports the terminal to implement any of the above methods. The network device 7100 may include: a transceiver module 7101, which is configured to receive a first notification message sent by the terminal, and the first notification message is used to indicate that the PUK code of the Profile in the eUICC chip in the terminal is locked. Optionally, the above-mentioned transceiver module 7101 is used to perform at least one of the communication steps such as sending and / or receiving performed by the network device 102 in any of the above methods, which will not be repeated here.

[0269] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, and the transmitting module and the receiving module may be separate or integrated. Optionally, the transceiver module may be interchangeable with the transceiver.

[0270] Figure 8 is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure. Communication device 8100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods. Communication device 8100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.

[0271] As shown in Figure 8, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process the communication protocol and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process program data. Optionally, the communication device 8100 is used to perform any of the above methods. Optionally, one or more processors 8101 are used to call instructions to enable the communication device 8100 to perform any of the above methods.

[0272] In some embodiments, the communication device 8100 further includes one or more transceivers 8102. When the communication device 8100 includes one or more transceivers 8102, the transceiver 8102 performs at least one of the communication steps, such as sending and / or receiving, in the above-described method, and the processor 8101 performs at least one of the other steps. In an optional embodiment, the transceiver may include a receiver and / or a transmitter, and the receiver and transmitter may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.

[0273] In some embodiments, the communication device 8100 further includes one or more memories 8103 for storing data. Alternatively, all or part of the memories 8103 may be located outside the communication device 8100. In alternative embodiments, the communication device 8100 may include one or more interface circuits 8104. Optionally, the interface circuits 8104 are connected to the memory 8102 and may be configured to receive data from the memory 8102 or other devices, or to send data to the memory 8102 or other devices. For example, the interface circuits 8104 may read data stored in the memory 8102 and send the data to the processor 8101.

[0274] The communication device 8100 described in the above embodiment may be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG8 . The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0275] The modules and / or devices described in various embodiments, such as virtual devices, physical devices, and chips, can be arbitrarily combined or separated according to circumstances. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0276] The present disclosure also proposes a storage medium having instructions stored thereon, which, when executed on the communication device 8100, causes the communication device 8100 to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto, and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto, and may also be a temporary storage medium.

[0277] The present disclosure also provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0278] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.

Claims

1. A communication method, It is characterized in that The method is executed by a terminal, wherein the terminal includes an embedded universal integrated circuit eUICC chip and a local profile assistant LPA module, and the method includes: Determining that the personal identity unlocking PUK code of the network information configuration Profile in the eUICC chip is locked, and setting the Profile status of the terminal to a locked state or an unusable state; determining that the Profile state is the locked state or the unusable state, and generating first notification information, where the first notification information is used to indicate that the PUK code of the Profile in the eUICC chip is locked; The first notification information is sent to the network device through the LPA module.

2. The method according to claim 1, It is characterized in that The setting of the Profile state of the terminal to a locked state or an unusable state includes: Sending, by the LPA module, first indication information to the eUICC chip, where the first indication information is used to instruct the eUICC chip to lock the Profile; Determine that the eUICC chip completes the locking process of the Profile, generate second notification information through the eUICC chip and send it to the LPA module, where the second notification information is used to indicate processing result information of the first indication information in the eUICC chip; The LPA module sets the Profile state to the locked state or the unusable state based on the second notification information.

3. The method according to claim 2, It is characterized in that The terminal includes a lock screen interface module, and the method further includes: Determine that the PUK code is locked, and control the lock screen interface module to prohibit input of the PUK code.

4. The method according to claim 2, It is characterized in that The method further comprises: It is determined that the PUK code is locked, and a prompt message is displayed in the terminal through the LPA module, where the prompt message is used to indicate that the Profile in the terminal is unavailable.

5. The method according to claim 3, It is characterized in that The method further comprises: A PUK code lock notification is sent to the LPA module through the lock screen interface module, where the PUK code lock notification is used to instruct the LPA module to send first indication information to the eUICC chip.

6. The method according to claim 2, It is characterized in that The step of setting the status of the Profile to the locked status or the unusable status based on the second notification information includes: Determining, according to the processing result information, that the eUICC chip completes the locking process; The Profile state is set to the locked state or the unusable state.

7. The method according to claim 1, It is characterized in that The sending the first notification information to the network device through the LPA module includes: Obtaining a PUK code locking notification from the eUICC chip through the LPA module; Generate the first notification information based on the PUK code locking notification fed back by the eUICC chip; The first notification information is sent to the network device through the LPA module.

8. The method according to claim 1, It is characterized in that The method further comprises: Acquire first counting information, where the first counting information is used to indicate the number of times the input PUK code does not match the preset PUK code; Determine that the first counting information reaches a preset number threshold, and lock the PUK code of the Profile in the eUICC chip.

9. The method according to claim 1, It is characterized in that The determining that the personal identity unlocking PUK code of the Profile in the eUICC chip is locked includes: By means of the eUICC chip, it is determined that the PUK code of the eUICC chip is locked.

10. The method according to any one of claims 1 to 9, It is characterized in that The first notification information is further used to instruct the network device to prohibit the eUICC chip from issuing the Profile according to the first notification information.

11. The method according to any one of claims 1 to 9, It is characterized in that The first notification information is also used to instruct the network device to delete the Profile information of the terminal.

12. A communication method, It is characterized in that Executed by a network device, the method includes: A first notification message sent by a terminal is received, where the first notification message is used to indicate that a PUK code of a Profile in an eUICC chip in the terminal is locked.

13. The method according to claim 12, It is characterized in that The network device includes a subscription management data preparation SM-DP+ module, and the method further includes: The SM-DP+ module prohibits the eUICC chip from issuing the Profile based on the first notification information.

14. The method according to claim 13, It is characterized in that The method further comprises: The SM-DP+ module changes the Profile record status of the terminal in the network device to a locked state or an unusable state based on the first notification information.

15. The method according to claim 12, It is characterized in that The method further comprises: According to the first notification information, the Profile information of the terminal is deleted.

16. A terminal, It is characterized in that The terminal comprises: a processing module configured to determine that a personal identity unlocking PUK code of a network information configuration profile in the eUICC chip is locked, and set a profile state of the terminal to a locked state or an unusable state; a generating module, configured to determine that the Profile state is the locked state or the unusable state, and generate first notification information, where the first notification information is used to indicate that the PUK code of the Profile in the eUICC chip is locked; The transceiver module is configured to send the first notification information to the network device through the LPA module.

17. A network device, It is characterized in that The network equipment includes: The transceiver module is configured to receive first notification information sent by the terminal, where the first notification information is used to indicate that the PUK code of the Profile in the eUICC chip in the terminal is locked.

18. A terminal, It is characterized in that include: one or more processors; A memory coupled to the one or more processors, the memory comprising executable instructions, and when the one or more processors execute the executable instructions, the terminal executes the communication method according to any one of claims 1 to 11.

19. A network device, It is characterized in that include: one or more processors; A memory coupled to the one or more processors, the memory comprising executable instructions, and when the one or more processors execute the executable instructions, the first device executes the communication method according to any one of claims 12 to 15.

20. A communication system, It is characterized in that The invention comprises a terminal and a network device, wherein the terminal is configured to implement the communication method according to any one of claims 1 to 11, and the network device is configured to implement the communication method according to any one of claims 12 to 15.

21. A storage medium storing instructions. It is characterized in that When the instruction is executed on a communication device, the communication device is enabled to execute the communication method according to any one of claims 1 to 11 or claims 12 to 15.

Citation Information

Patent Citations

  • User authority identifying method and fixed network wireless terminal with user authority identifying function

    CN101232684A

  • A communication method based on a mobile terminal smart card and associated devices

    CN105208546A

  • Customized pin / PUK remote provisioning

    US20200280839A1

  • Checking the identification number of a mobile subscriber

    US5907804A

  • Method and device for implementing parental lock

    WO2012159468A1