Esim authentication method and related apparatus
By implementing the checksum matching mechanism of device identification in the eSIM module, the problem of inserting other devices into the mobile communication network is solved, and the effect of improving the access security of the eSIM module is achieved.
Patent Information
- Application Number
- PCT/CN2024/131567
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-06
- Filing Date
- 2024-11-12
- Publication Date
- 2025-05-22
AI Technical Summary
After the eSIM module is disassembled, if it is inserted into other devices and connected to the mobile communication network, it will affect the security of the mobile communication network.
Through an eSIM authentication method, after detecting a power outage and then powering on, the eSIM module receives the device verification information and decrypts the device identifier. If the device identification matches the stored identification, mobile communication service is allowed; otherwise, mobile communication service is prohibited.
It effectively prevents the eSIM module from being inserted into other devices and connected to the mobile communication network after being disassembled, improving the security of the eSIM module when it is connected to the mobile communication network.
Smart Images

Figure CN2024131567_22052025_PF_FP_ABST
Abstract
Description
An eSIM authentication method and related device
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on November 14, 2023, with application number 202311520265.X and application name “A eSIM authentication method and related device”, and the Chinese patent application filed with the China Patent Office on February 6, 2024, with application number 202410173927.9 and application name “A eSIM authentication method and related device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to an eSIM authentication method and related devices. Background Art
[0003] In the mobile communications sector, one common mobile communications access solution is one based on subscriber identity authentication using a subscriber identity module (SIM). A common implementation involves a user inserting a SIM card into the SIM card slot of a mobile communications device, such as a phone or tablet. The mobile communications device then undergoes a legitimacy verification process at the communications service provider using the inserted SIM card. Once the verification is successful, the mobile communications device is allowed to access the mobile communications network.
[0004] With the development of mobile communications technology, the embedded SIM (eSIM) solution has been proposed, building upon the existing SIM card solution. The eSIM solution embeds the traditional SIM card directly into the chip of an electronic device, rather than inserting it as a separate, removable component. This eliminates the need for users to insert a physical SIM card. This solution allows users to more flexibly choose carriers and reprogram new numbers into the eSIM module of their electronic device.
[0005] Currently, users can write new phone numbers to the eSIM modules of devices such as watches on their phones, allowing them to use the watch and other devices independently to make calls and access the internet using the eSIM module. However, if the eSIM module is disassembled and then inserted into other devices to access the mobile communication network, it will affect the security of the mobile communication network.
[0006] Summary of the Invention
[0007] The present application provides an eSIM authentication method and related apparatus, which can prevent the eSIM module in an electronic device from being disassembled and then inserted into other devices to access a mobile communication network, thereby improving the security of the eSIM module when accessing a mobile communication network.
[0008] In a first aspect, the present application provides an eSIM authentication method, applied to an eSIM module, the method comprising: the eSIM module storing a first device identifier sent by a first processing module; the eSIM module receiving device verification information sent by the second processing module after detecting a power outage and then powering on; the eSIM module decrypting a second device identifier from the device verification information; if the first device identifier and the second device identifier are the same, the eSIM module performs mobile communication services normally; if the first device identifier and the second device identifier are different or the eSIM module does not receive the device verification information sent by the second processing module after detecting a power outage and then powering on, the eSIM module prohibits mobile communication services.
[0009] An eSIM authentication method provided in an embodiment of the present application enables a first processing module and an eSIM module in an electronic device to first negotiate a shared security key. The first processing module then encrypts a device identifier using the shared security key, generates device binding information, and sends the device binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the device binding information using the shared security key pair and store the first device identifier. When the eSIM module is powered on again or before performing a mobile communication service, the eSIM module can instruct a second processing module, currently in communication with the eSIM module, to obtain a second device identifier, encrypt the second device identifier using the shared security key, and generate device verification information. The eSIM module can decrypt the second device identifier from the device verification information using a shared security key. If the second device identifier is the same as the first device identifier stored in the eSIM module, it indicates that the second processing module and the first processing module bound to the eSIM module are the same processing module. Therefore, the eSIM module can normally perform mobile communication services. If the second device identifier is different from the first device identifier stored in the eSIM module or the eSIM module does not receive the device verification information sent by the second processing module after detecting a power outage and then powering on, it indicates that the second processing module and the first processing module bound to the eSIM module are not the same processing module. Therefore, the eSIM module can be prohibited from performing mobile communication services. This can prevent the eSIM module in the electronic device from being disassembled and inserted into other devices to access the mobile communication network, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0010] In one possible implementation, before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: receiving, by the eSIM module, device binding information sent by the first processing module; and after receiving the device binding information, decrypting, by the eSIM module, the first device identifier from the device binding information and storing the first device identifier.
[0011] In one possible implementation, after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information, specifically including: after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information using a shared security key generated by the eSIM module.
[0012] In one possible implementation, after receiving the device verification information, the eSIM module decrypts the second device identifier from the device verification information, specifically including: after receiving the device verification information, the eSIM module decrypts the second device identifier from the verification information using a shared security key generated by the eSIM module.
[0013] In one possible implementation, before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: generating, by the eSIM module, an eUICC temporary working public key and an eUICC temporary working private key; receiving, by the eSIM module, a TEE temporary working public key generated by the first processing module; and generating, by the eSIM module, a shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
[0014] In one possible implementation, before the eSIM module receives the TEE temporary working public key sent by the first processing module, the method further includes: the eSIM module receives the TEE signature data sent by the first processing module; the eSIM module verifies the legitimacy of the TEE signature data using the TEE public key; the eSIM module receives the TEE temporary working public key sent by the first processing module, specifically including: after the eSIM module verifies the legitimacy of the TEE signature data, obtaining the TEE temporary working public key from the TEE signature data.
[0015] In one possible implementation, before the eSIM module receives the TEE signature data sent by the first processing module, the method further includes: the eSIM module verifying the legitimacy of the TEE certificate; after the eSIM module successfully verifies the legitimacy of the TEE certificate, obtaining the TEE public key from the TEE certificate.
[0016] In one possible implementation, the TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
[0017] In one possible implementation, the TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; before the eSIM module verifies the legitimacy of the TEE certificate, the method also includes: the eSIM module receives the TEE certificate sent by the first processing module; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module uses the terminal manufacturer's root public key in the terminal manufacturer's root certificate to verify the legitimacy of the device certificate; after the eSIM module verifies the legitimacy of the device certificate, it uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
[0018] In one possible implementation, the TEE certificate is a terminal manufacturer root certificate, which is pre-installed in the eSIM module; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal manufacturer root certificate through the terminal manufacturer root public key in the terminal manufacturer root certificate.
[0019] In one possible implementation, the method further includes: generating, by the eSIM module, the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key form a public-private key pair; signing, by the eSIM module, the eUICC temporary working public key using the eUICC private key to obtain eUICC signature data; and sending, by the eSIM module, the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key and generate a shared security key based on the eUICC temporary working public key and the TEE temporary working private key, where the TEE temporary working private key and the TEE temporary working public key form a public-private key pair.
[0020] In one possible implementation, the method further includes: the eSIM module sending the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by an EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes the eUICC public key, the eUICC public key and the eUICC private key form a public-private key pair, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
[0021] In one possible implementation, the first device identifier is the chip identifier of the first processing module, and the second device identifier is the chip identifier of the second processing module; or, the first device identifier is the International Mobile Equipment Identity code IMEI of the first processing module, and the second device identifier is the IMEI of the second processing module; or, the first device identifier is the chip identifier of the first processing module and the IMEI of the first processing module, and the second device identifier is the chip identifier of the second processing module and the IMEI of the second processing module.
[0022] In one possible implementation, after detecting a power outage and then powering on, the eSIM module receives device verification information sent by the second processing module, specifically including: after detecting a power outage and then powering on, the eSIM module sends a first request to the second processing module, where the first request is used to request the second processing module to send a device identification to the eSIM module.
[0023] In a possible implementation, the first request includes a first eUICC random number, and the first eUICC random number is used to be encrypted by the second processing module together with the second device identifier to form the device verification information.
[0024] In one possible implementation, the method further includes: decrypting, by the eSIM module, a second eUICC random number from the device verification information; and if the first device identifier and the second device identifier are identical, the eSIM module performing the mobile communication service normally, specifically including: if the first device identifier and the second device identifier are identical and the second eUICC random number is identical to the first eUICC random number, the eSIM module performing the mobile communication service normally.
[0025] In a possible implementation, the first request is a Get Input command.
[0026] In a possible implementation, the eSIM module receives the device binding information sent by the first processing module, specifically including: the eSIM module receives the device binding information sent by the first processing module through a store data Storedata command.
[0027] In a second aspect, the present application provides an eSIM authentication method, which is applied to an electronic device including an eSIM module and a second processing module, the method comprising: the eSIM module stores a first device identification sent by the first processing module; the eSIM module sends a first request to the second processing module after detecting a power outage and then powering on, the first request being used to request the second processing module to send a device identification to the eSIM module; the second processing module obtains a second device identification; the second processing module encrypts the second device identification to obtain device verification information; the second processing module sends the device verification information to the eSIM module; the eSIM module decrypts the second device identification from the device verification information; if the first device identification is the same as the second device identification, the eSIM module performs mobile communication services normally; if the first device identification is different from the second device identification or the eSIM module does not receive the device verification information sent by the second processing module after detecting a power outage and then powering on, the eSIM module prohibits mobile communication services.
[0028] An eSIM authentication method provided in an embodiment of the present application enables a first processing module and an eSIM module in an electronic device to first negotiate a shared security key. The first processing module then encrypts a device identifier using the shared security key, generates device binding information, and sends the device binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the device binding information using the shared security key pair and store the first device identifier. When the eSIM module is powered on again or before performing a mobile communication service, the eSIM module can instruct a second processing module, currently in communication with the eSIM module, to obtain a second device identifier, encrypt the second device identifier using the shared security key, and generate device verification information. The eSIM module can decrypt the second device identifier from the device verification information using a shared security key. If the second device identifier is the same as the first device identifier stored in the eSIM module, it indicates that the second processing module and the first processing module bound to the eSIM module are the same processing module. Therefore, the eSIM module can normally perform mobile communication services. If the second device identifier is different from the first device identifier stored in the eSIM module or the eSIM module does not receive the device verification information sent by the second processing module after detecting a power outage and then powering on, it indicates that the second processing module and the first processing module bound to the eSIM module are not the same processing module. Therefore, the eSIM module can be prohibited from performing mobile communication services. This prevents the eSIM module in the electronic device from being disassembled and inserted into other devices to access the mobile communication network, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0029] In one possible implementation, before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: receiving, by the eSIM module, device binding information sent by the first processing module; and after receiving the device binding information, decrypting, by the eSIM module, the first device identifier from the device binding information and storing the first device identifier.
[0030] In a possible implementation, after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information, specifically including: after receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information using a shared security key.
[0031] In one possible implementation, after receiving the verification information, the eSIM module decrypts the second device identifier from the device verification information, specifically including: after receiving the device verification information, the eSIM module decrypts the second device identifier from the verification information using a shared security key.
[0032] In one possible implementation, before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: generating, by the eSIM module, an eUICC temporary working public key and an eUICC temporary working private key; receiving, by the eSIM module, a TEE temporary working public key generated by the first processing module; and generating, by the eSIM module, the shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
[0033] In one possible implementation, before the eSIM module receives the TEE temporary working public key generated by the first processing module, the method further includes: the eSIM module receives the TEE signature data sent by the first processing module; the eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; the eSIM module receives the TEE temporary working public key generated by the first processing module, specifically including: after the eSIM module verifies the legitimacy of the TEE signature data, obtaining the TEE temporary working public key from the TEE signature data.
[0034] In one possible implementation, before the eSIM module receives the TEE signature data sent by the first processing module, the method further includes: the eSIM module verifying the legitimacy of the TEE certificate; after the eSIM module successfully verifies the legitimacy of the TEE certificate, obtaining the TEE public key from the TEE certificate.
[0035] In one possible implementation, the TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
[0036] In one possible implementation, the TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
[0037] In one possible implementation, the TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; before the eSIM module verifies the legitimacy of the TEE certificate, the method also includes: the eSIM module receives the TEE certificate sent by the first processing module; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module uses the terminal manufacturer's root public key in the terminal manufacturer's root certificate to verify the legitimacy of the device certificate; after the eSIM module verifies the legitimacy of the device certificate, it uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
[0038] In one possible implementation, the TEE certificate is a terminal manufacturer root certificate, which is pre-installed in the eSIM module; the eSIM module verifies the legitimacy of the TEE certificate, specifically including: the eSIM module verifies the legitimacy of the terminal manufacturer root certificate through the terminal manufacturer root public key in the terminal manufacturer root certificate.
[0039] In one possible implementation, the method further includes: generating, by the eSIM module, the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key form a public-private key pair; signing, by the eSIM module, the eUICC temporary working public key using the eUICC private key to obtain eUICC signature data; and sending, by the eSIM module, the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key and generate the shared security key based on the eUICC temporary working public key and the TEE temporary working private key, where the TEE temporary working private key and the TEE temporary working public key form a public-private key pair.
[0040] In one possible implementation, the method further includes: the eSIM module sending the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by an EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes the eUICC public key, the eUICC public key and the eUICC private key form a public-private key pair, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
[0041] In one possible implementation, the first device identifier is the chip identifier of the first processing module, and the second device identifier is the chip identifier of the second processing module; or, the first device identifier is the International Mobile Equipment Identity code IMEI of the first processing module, and the second device identifier is the IMEI of the second processing module; or, the first device identifier is the chip identifier of the first processing module and the IMEI of the first processing module, and the second device identifier is the chip identifier of the second processing module and the IMEI of the second processing module.
[0042] In one possible implementation, the first request includes a first eUICC random number; and the second processing module encrypts the second device identifier to obtain device verification information, specifically including: the second processing module encrypts the first eUICC random number and the second device identifier to obtain the device verification information.
[0043] In one possible implementation, the method further includes: decrypting, by the eSIM module, a second eUICC random number from the device verification information; and if the first device identifier and the second device identifier are identical, the eSIM module performing the mobile communication service normally, specifically including: if the first device identifier and the second device identifier are identical and the second eUICC random number is identical to the first eUICC random number, the eSIM module performing the mobile communication service normally.
[0044] In a possible implementation, the first request is a Get Input command.
[0045] In a possible implementation, the eSIM module receives the device binding information sent by the first processing module, specifically including: the eSIM module receives the device binding information sent by the first processing module through a Storedata command.
[0046] In a third aspect, the present application provides an eSIM authentication method, which is applied to a processing module, the method including: a first eSIM identifier sent by a first eSIM module is stored in the TEE of the processing module; after the second eSIM module is powered off and then powered on, the processing module receives eSIM verification information sent by the second eSIM module; the processing module decrypts the second eSIM identifier from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, the processing module prohibits the use of the second eSIM module for mobile communication services.
[0047] An eSIM authentication method provided in an embodiment of the present application enables a processing module and a first eSIM module in an electronic device to first negotiate a shared key. The first eSIM module then encrypts an eSIM identifier using the shared security key to generate eSIM binding information, which is then sent to the processing module. The processing module can decrypt the first eSIM identifier from the eSIM binding information using the shared security key pair and store the first eSIM identifier. When the eSIM module is powered on again or before mobile communication services are to be performed, the processing module can instruct a second eSIM module currently communicating with the processing module to obtain a second eSIM identifier, encrypt the second eSIM identifier using the shared security key, and generate eSIM verification information. The processing module can decrypt the second eSIM identifier from the eSIM verification information using the shared security key. If the second eSIM identifier is identical to the first eSIM identifier stored in the processing module's TEE, this indicates that the second eSIM module and the first eSIM module bound to the processing module are the same eSIM module, and the processing module can therefore perform mobile communication services normally. If the second eSIM identifier is different from the first device identifier stored in the TEE of the processing module, or the processing module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on again, it indicates that the second eSIM module is not the same as the first eSIM module bound to the processing module. Therefore, the processing module can prohibit the use of the second eSIM for mobile communication services. In this way, it can prevent the eSIM module in the electronic device from being disassembled or obtained through other means from being inserted into the current device to access the mobile communication network, thereby improving the security of the current device when it also contains an eSIM module to access the mobile communication network.
[0048] In one possible implementation, before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: the processing module receiving eSIM binding information sent by the first eSIM module; after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
[0049] In one possible implementation, after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the processing module.
[0050] In one possible implementation, after receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: after receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
[0051] In one possible implementation, before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: generating, by the processing module, a TEE temporary working public key and a TEE temporary working private key through the TEE; receiving, by the processing module, the eUICC temporary working public key generated by the first processing module; and generating, by the processing module, a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
[0052] In a possible implementation, before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: receiving, by the processing module, TEE signature data sent by the first processing module;
[0053] The processing module verifies the legitimacy of the eUICC signature data using the eUICC public key in the eUICC certificate; and the processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: after the processing module verifies the legitimacy of the eUICC signature data, obtaining the eUICC temporary working public key from the eUICC signature data.
[0054] In one possible implementation, before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: the processing module receiving the EUM certificate and the eUICC certificate sent by the first eSIM module; the processing module verifying the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; after successfully verifying the legitimacy of the EUM certificate, the processing module verifying the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate; and after successfully verifying the legitimacy of the eUICC certificate, the processing module obtaining the eUICC public key from the eUICC certificate.
[0055] In one possible implementation, the method further includes: the processing module generating the TEE temporary working private key and the TEE temporary working public key in the TEE, where the TEE temporary working private key and the TEE temporary working public key form a public-private key pair; the processing module signing the TEE temporary working public key using the TEE private key to obtain TEE signature data; and the processing module sending the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, where the eUICC temporary working private key and the eUICC temporary working public key form a public-private key pair.
[0056] In one possible implementation, before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: after detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier to form the eSIM verification information.
[0057] In a possible implementation, the method further includes: decrypting, by the processing module, a second device random number from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally using the second eSIM module for mobile communication services, specifically including: if the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally using the second eSIM module for mobile communication services.
[0058] In a fourth aspect, the present application provides an eSIM authentication method, which is applied to an electronic device including a processing module and a second eSIM module, the method comprising: a first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module; the second eSIM module obtains the second eSIM identifier of the second eSIM module after power is off and then on; the second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; the second eSIM module sends the eSIM verification information to the processing module; the processing module decrypts the second eSIM identifier from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then on, the processing module prohibits the use of the second eSIM module for mobile communication services.
[0059] An eSIM authentication method provided in an embodiment of the present application enables a processing module and a first eSIM module in an electronic device to first negotiate a shared key. The first eSIM module then encrypts an eSIM identifier using the shared security key to generate eSIM binding information, which is then sent to the processing module. The processing module can decrypt the first eSIM identifier from the eSIM binding information using the shared security key pair and store the first eSIM identifier. When the eSIM module is powered on again or before mobile communication services are to be performed, the processing module can instruct a second eSIM module currently communicating with the processing module to obtain a second eSIM identifier, encrypt the second eSIM identifier using the shared security key, and generate eSIM verification information. The processing module can decrypt the second eSIM identifier from the eSIM verification information using the shared security key. If the second eSIM identifier is identical to the first eSIM identifier stored in the processing module's TEE, this indicates that the second eSIM module and the first eSIM module bound to the processing module are the same eSIM module, and the processing module can therefore perform mobile communication services normally. If the second eSIM identifier is different from the first eSIM identifier stored in the TEE of the processing module, it indicates that the second eSIM module is not the same as the first eSIM module bound to the processing module. Therefore, the processing module can prohibit the use of the second eSIM for mobile communication services. In this way, it can prevent the eSIM module in the electronic device from being disassembled or obtained through other means from being inserted into the current device to access the mobile communication network, thereby improving the security of the current device when it also contains an eSIM module to access the mobile communication network.
[0060] In one possible implementation, before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: the processing module receiving eSIM binding information sent by the first eSIM module; after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
[0061] In one possible implementation, after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the processing module.
[0062] In one possible implementation, after receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: after receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
[0063] In one possible implementation, before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: generating, by the processing module, a TEE temporary working public key and a TEE temporary working private key through the TEE; receiving, by the processing module, the eUICC temporary working public key generated by the first processing module; and generating, by the processing module, a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
[0064] In one possible implementation, before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: receiving, by the processing module, TEE signature data sent by the first processing module; verifying, by the processing module, the legitimacy of the eUICC signature data using the eUICC public key in the eUICC certificate; and receiving, by the processing module, the eUICC temporary working public key sent by the first eSIM module, specifically including: obtaining, by the processing module, the eUICC temporary working public key from the eUICC signature data after successfully verifying the legitimacy of the eUICC signature data.
[0065] In one possible implementation, before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: the processing module receiving the EUM certificate and the eUICC certificate sent by the first eSIM module; the processing module verifying the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; after successfully verifying the legitimacy of the EUM certificate, the processing module verifying the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate; and after successfully verifying the legitimacy of the eUICC certificate, the processing module obtaining the eUICC public key from the eUICC certificate.
[0066] In one possible implementation, the method further includes: the processing module generating the TEE temporary working private key and the TEE temporary working public key in the TEE, where the TEE temporary working private key and the TEE temporary working public key form a public-private key pair; the processing module signing the TEE temporary working public key using the TEE private key to obtain TEE signature data; and the processing module sending the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, where the eUICC temporary working private key and the eUICC temporary working public key form a public-private key pair.
[0067] In one possible implementation, before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: after detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier to form the eSIM verification information.
[0068] In a possible implementation, the method further includes: decrypting, by the processing module, a second device random number from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally using the second eSIM module for mobile communication services, specifically including: if the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally using the second eSIM module for mobile communication services.
[0069] In a fifth aspect, the present application provides an eSIM authentication method, which is applied to an electronic device including a second processing module and a second eSIM module, the method comprising: the first eSIM identifier sent by the first eSIM module is stored in the TEE of the second processing module; the first device identifier sent by the first processing module is stored in the second eSIM module; after the second eSIM module is powered off and then powered on again, the second eSIM module obtains the second eSIM identifier of the second eSIM module; the second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; the second eSIM module sends the eSIM verification information to the second processing module; the second processing module obtains the second device identifier, encrypts the second device identifier, obtains device verification information, and sends the device verification information to the second eSIM module; The second processing module decrypts the second eSIM identifier from the eSIM verification information; the second eSIM module decrypts the second device identifier from the device verification information; if the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier, the electronic device can use the second eSIM module normally for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the second device identifier is different from the first device identifier or the second processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, the electronic device is prohibited from using the second eSIM module for mobile communication services.
[0070] Through an eSIM authentication method provided in an embodiment of the present application, the second processing module is legally bound to the first eSIM module. Therefore, the TEE of the second processing module stores the first eSIM identifier of the first eSIM module and the shared security key negotiated with the first eSIM module. The second eSIM module is legally bound to the first processing module. Therefore, the second eSIM module stores the first device identifier of the first processing module and the shared security key negotiated with the first processing module. When the second processing module cooperates with the second eSIM module, if the second eSIM module is powered on or before performing mobile communication services, the second processing module can obtain the second device identifier of the second processing module and use the shared security key to encrypt the second device identifier into device verification information and send it to the second eSIM module. The second eSIM module can also obtain the second eSIM identifier of the second eSIM module and use the shared security key to encrypt the second eSIM identifier into eSIM verification information and send it to the second processing module. The second processing module can decrypt the second eSIM identifier from the eSIM verification information using the shared security key. The second eSIM module can also decrypt the second device identifier from the device verification information using the shared security key. If the second eSIM identifier is identical to the first eSIM identifier stored in the processing module's TEE, and the second device identifier is identical to the first device identifier, then the second eSIM module and the second processing module are bound to each other. Therefore, the second processing module can normally use the second eSIM module for mobile communication services. If the second eSIM identifier is different from the first eSIM identifier stored in the processing module's TEE, or the second device identifier is different from the first device identifier, or the second processing module does not receive the eSIM verification information after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information after the second eSIM module is powered off and then powered on, then the second processing module can prohibit the use of the second eSIM module for mobile communication services. This prevents the eSIM module from being disassembled from an electronic device and then inserted into another device to access the mobile communication network, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0071] In one possible implementation, before the second eSIM module stores the first device identifier sent by the first processing module, the method further includes: receiving, by the second eSIM module, device binding information sent by the first processing module; and after receiving the device binding information, decrypting, by the second eSIM module, the first device identifier from the device binding information and storing the first device identifier.
[0072] In one possible implementation, after receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information, specifically including: after receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information using a shared security key generated by the second eSIM module.
[0073] In one possible implementation, after receiving the device verification information, the second eSIM module decrypts the second device identifier from the device verification information, specifically including: after receiving the device verification information, the second eSIM module decrypts the second device identifier from the verification information using a shared security key generated by the second eSIM module.
[0074] In one possible implementation, before the second eSIM module stores the first device identifier sent by the first processing module, the method further includes: generating, by the second eSIM module, an eUICC temporary working public key and an eUICC temporary working private key; receiving, by the second eSIM module, the TEE temporary working public key generated by the first processing module; and generating, by the second eSIM module, a shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
[0075] In one possible implementation, before the second eSIM module receives the TEE temporary working public key sent by the first processing module, the method further includes: the second eSIM module receiving the TEE signature data sent by the first processing module; the second eSIM module verifying the legitimacy of the TEE signature data using the TEE public key; the second eSIM module receiving the TEE temporary working public key sent by the first processing module specifically includes: after the second eSIM module verifies the legitimacy of the TEE signature data, obtaining the TEE temporary working public key from the TEE signature data.
[0076] In one possible implementation, before the second eSIM module receives the TEE signature data sent by the first processing module, the method further includes: the second eSIM module verifying the legitimacy of the TEE certificate; after the second eSIM module successfully verifies the legitimacy of the TEE certificate, obtaining the TEE public key from the TEE certificate.
[0077] In one possible implementation, the TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; the second eSIM module verifies the legitimacy of the TEE certificate, specifically including: the second eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
[0078] In one possible implementation, the TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; before the eSIM module verifies the legitimacy of the TEE certificate, the method also includes: the second eSIM module receives the TEE certificate sent by the first processing module; the second eSIM module verifies the legitimacy of the TEE certificate, specifically including: the second eSIM module uses the terminal manufacturer's root public key in the terminal manufacturer's root certificate to verify the legitimacy of the device certificate; after the second eSIM module verifies the legitimacy of the device certificate, it uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
[0079] In one possible implementation, the TEE certificate is a terminal manufacturer root certificate, which is pre-installed in the second eSIM module; the second eSIM module verifies the legitimacy of the TEE certificate, specifically including: the second eSIM module verifies the legitimacy of the terminal manufacturer root certificate through the terminal manufacturer root public key in the terminal manufacturer root certificate.
[0080] In one possible implementation, the method further includes: generating, by the second eSIM module, the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key form a public-private key pair; signing, by the second eSIM module, the eUICC temporary working public key using the eUICC private key to obtain eUICC signature data; and sending, by the second eSIM module, the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key and generate a shared security key based on the eUICC temporary working public key and the TEE temporary working private key, where the TEE temporary working private key and the TEE temporary working public key form a public-private key pair.
[0081] In one possible implementation, the method further includes: the second eSIM module sending the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by an EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes the eUICC public key, the eUICC public key and the eUICC private key form a public-private key pair, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
[0082] In one possible implementation, the first device identifier is the chip identifier of the first processing module, and the second device identifier is the chip identifier of the second processing module; or, the first device identifier is the International Mobile Equipment Identity code IMEI of the first processing module, and the second device identifier is the IMEI of the second processing module; or, the first device identifier is the chip identifier of the first processing module and the IMEI of the first processing module, and the second device identifier is the chip identifier of the second processing module and the IMEI of the second processing module.
[0083] In one possible implementation, before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the second processing module, the method further includes: the second processing module receiving eSIM binding information sent by the first eSIM module; after receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
[0084] In one possible implementation, after receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: after receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the second processing module.
[0085] In one possible implementation, after receiving the eSIM verification information, the second processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: after receiving the eSIM verification information, the second processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
[0086] In one possible implementation, before the second processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: generating, by the second processing module, a TEE temporary working public key and a TEE temporary working private key through the TEE; receiving, by the second processing module, the eUICC temporary working public key generated by the first processing module; and generating, by the second processing module, a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
[0087] In one possible implementation, before the second processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: receiving, by the second processing module, TEE signature data sent by the first processing module; verifying, by the second processing module, the legitimacy of the eUICC signature data using the eUICC public key in the eUICC certificate; and receiving, by the second processing module, the eUICC temporary working public key sent by the first eSIM module, specifically including: obtaining, by the second processing module, the eUICC temporary working public key from the eUICC signature data after successfully verifying the legitimacy of the eUICC signature data.
[0088] In one possible implementation, before the second processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: the second processing module receiving the EUM certificate and the eUICC certificate sent by the first eSIM module; the second processing module verifying the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; after the second processing module successfully verifies the legitimacy of the EUM certificate, verifying the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate; and after the second processing module successfully verifies the legitimacy of the eUICC certificate, obtaining the eUICC public key from the eUICC certificate.
[0089] In one possible implementation, the method further includes: the second processing module generating the TEE temporary working private key and the TEE temporary working public key in the TEE, where the TEE temporary working private key and the TEE temporary working public key form a public-private key pair; the second processing module signing the TEE temporary working public key using the TEE private key to obtain TEE signature data; and the second processing module sending the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, where the eUICC temporary working private key and the eUICC temporary working public key form a public-private key pair.
[0090] In one possible implementation, the method further includes: after detecting that the second eSIM module is powered off and then powered on, the second processing module sending an eUICC random number acquisition command to the second processing module, the eUICC random number acquisition command being used to request the second processing module to send the eUICC random number to the second processing module; after receiving the eUICC random number acquisition command, the second eSIM module generating a first eUICC random number and sending the first eUICC random number to the second processing module; the second processing module generating a first device random number; and the second processing module acquiring the second device identifier and encrypting the second device identifier to obtain device verification information. Specifically, the method includes: the second processing module acquiring the second device identifier and encrypting the second device identifier, the first device random number, and the first eUICC random number to obtain device verification information.
[0091] In one possible implementation, the method further includes: after receiving the device verification information, the second eSIM module decrypting the second eUICC random number and the third device random number from the device verification information; and encrypting, by the second eSIM module, the second eSIM identifier to obtain the eSIM verification information, specifically including: encrypting, by the second eSIM module, the second eSIM identifier and the third device random number to obtain the eSIM verification information.
[0092] In a possible implementation, the method further includes: decrypting, by the second processing module, a second device random number from the eSIM verification information; and if the second eSIM identifier is identical to the first eSIM identifier and the second device identifier is identical to the first device identifier, the electronic device normally using the second eSIM module to perform mobile communication services, specifically including: if the second eSIM identifier is identical to the first eSIM identifier, the second device identifier is identical to the first device identifier, the second device random number is identical to the first device random number, and the second eUICC random number is identical to the first eUICC random number, the electronic device normally using the second eSIM module to perform mobile communication services.
[0093] In a sixth aspect, the present application provides an eSIM module, comprising: a processing circuit, a storage circuit, and an interface circuit, the storage circuit being used to store data and code instructions, the interface circuit being used to send commands to the processing module through a modem or to receive commands sent by the processing module through the modem; the processing circuit being used to run the code instructions to execute the method in the above-mentioned first aspect and any possible implementation of the first aspect.
[0094] In the seventh aspect, the present application provides a processing module, characterized in that it includes: a processing circuit, a storage circuit and an interface circuit, the storage circuit is used to store data and code instructions, the interface circuit is used to send commands to the eSIM module through the modem or receive commands sent by the eSIM module through the modem; the processing circuit is used to run the code instructions to execute the method in the above-mentioned third aspect and any possible implementation of the third aspect.
[0095] In an eighth aspect, the present application provides an electronic device comprising: an eSIM module, a second processing module and one or more memories, wherein the one or more memories are coupled to the second processing module, and the one or more memories are used to store a computer program. When the second processing module executes the computer program, the first electronic device executes the method in the above-mentioned second aspect and any possible implementation of the second aspect.
[0096] In the ninth aspect, the present application provides an electronic device comprising: a second eSIM module, a processing module and one or more memories, wherein the one or more memories are coupled to the processing module, and the one or more memories are used to store a computer program. When the processing module executes the computer program, the second electronic device executes the method in the above-mentioned fourth aspect and any possible implementation of the fourth aspect.
[0097] In the tenth aspect, the present application provides an electronic device comprising: a second eSIM module, a second processing module and one or more memories, wherein the one or more memories are coupled to the second processing module, and the one or more memories are used to store a computer program. When the second processing module executes the computer program, the electronic device executes the method in the above-mentioned fifth aspect and any possible implementation of the fifth aspect.
[0098] In the eleventh aspect, an embodiment of the present application provides a computer storage medium comprising computer instructions, which, when executed on a processor of an electronic device, enables the electronic device to execute a method in any possible implementation of the second aspect described above.
[0099] In the twelfth aspect, an embodiment of the present application provides a computer storage medium comprising computer instructions. When the computer instructions are executed on a processor of an electronic device, the electronic device executes the method in the above-mentioned fourth aspect and any possible implementation of the fourth aspect.
[0100] In the thirteenth aspect, an embodiment of the present application provides a computer storage medium comprising computer instructions, which, when the computer instructions are executed on a processor of an electronic device, enables the electronic device to execute the method in the above-mentioned fifth aspect and any possible implementation of the fifth aspect.
[0101] The beneficial effects of the second to thirteenth aspects mentioned above can refer to the beneficial effects of the first aspect mentioned above and any possible implementation method of the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0102] FIG1 is a schematic structural diagram of an electronic device provided in an embodiment of the present application;
[0103] FIG2 is a schematic diagram of the structure of a trusted execution environment of an electronic device provided in an embodiment of the present application;
[0104] FIG3 is a schematic diagram of a certificate chain in a TEE and an eSIM module of an electronic device provided in an embodiment of the present application;
[0105] FIG4 is a schematic diagram of a certificate signing process provided in an embodiment of the present application;
[0106] FIG5 is a schematic diagram of a process of binding a device to an eSIM in an eSIM authentication method according to an embodiment of the present application;
[0107] FIG6 is a schematic diagram of a process of device-card verification in an eSIM authentication method provided in an embodiment of the present application;
[0108] FIG7 is a schematic diagram of a signaling interaction process for device-card binding in an eSIM authentication method provided in an embodiment of the present application;
[0109] FIG8A is a schematic diagram of an encryption process of plain text data in a Storedata command provided in an embodiment of the present application;
[0110] FIG8B is a schematic diagram of an encryption process of response plaintext data in a Response command provided in an embodiment of the present application;
[0111] FIG9 is a schematic diagram of a signaling interaction flow for device-card verification in an eSIM authentication method provided in an embodiment of the present application;
[0112] FIG10 is a schematic diagram of a command format of a Get Input command provided in an embodiment of the present application;
[0113] FIG11 is a schematic diagram of the structure of an execution environment of an electronic device provided in an embodiment of the present application;
[0114] FIG12 is a schematic diagram of a certificate chain in a TEE and an eSIM module of an electronic device provided in an embodiment of the present application;
[0115] FIG13 is a flow chart of one-way binding of a device and a card in an eSIM authentication method provided in an embodiment of the present application;
[0116] FIG14 is a schematic diagram of a process of bidirectional binding of a device and a card in an eSIM authentication method provided in an embodiment of the present application;
[0117] FIG15 is a schematic diagram of a process of bidirectional binding of a device and a card in an eSIM authentication method provided in an embodiment of the present application;
[0118] FIG16 is a schematic diagram of a process of bidirectional verification of a card and a device in an eSIM authentication method provided in an embodiment of the present application;
[0119] FIG17 is a schematic diagram of the signaling interaction process for one-way binding of a device and a card in an eSIM authentication method provided in an embodiment of the present application;
[0120] FIG18 is a schematic diagram of the signaling interaction process for bidirectional binding of a device and a card in an eSIM authentication method provided in an embodiment of the present application;
[0121] FIG19 is a schematic diagram of the signaling interaction process for bidirectional binding of a device and a card in an eSIM authentication method provided in another embodiment of the present application;
[0122] Figure 20 is a schematic diagram of the process of two-way verification of the machine and card in an eSIM authentication method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0123] The following is a clear and detailed description of the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in the text is only a description of the association relationship between related objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.
[0124] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of the technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.
[0125] FIG1 shows a schematic structural diagram of an electronic device 100 .
[0126] The following embodiments are described in detail using electronic device 100 as an example. It should be understood that the electronic device 100 shown in FIG1 is merely an example, and that electronic device 100 may have more or fewer components than shown in FIG1 , may combine two or more components, or may have a different component configuration. The various components shown in the figure may be implemented in hardware, including one or more signal processing and / or application-specific integrated circuits, software, or a combination of hardware and software.
[0127] The electronic device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display 194, and an embedded SIM (eSIM) module 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0128] It should be understood that the structure illustrated in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0129] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.
[0130] The controller may be the nerve center and command center of the electronic device 100. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0131] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.
[0132] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.
[0133] The I2C interface is a bidirectional synchronous serial bus that includes a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 may include multiple I2C bus lines. The processor 110 may be coupled to the touch sensor 180K, the charger, the flash, the camera 193, and the like via different I2C bus interfaces. For example, the processor 110 may be coupled to the touch sensor 180K via the I2C interface, enabling communication between the processor 110 and the touch sensor 180K via the I2C bus interface, thereby enabling the touch function of the electronic device 100.
[0134] The I2S interface can be used for audio communication. In some embodiments, the processor 110 can include multiple I2S buses. The processor 110 can be coupled to the audio module 170 via the I2S bus to enable communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the I2S interface, enabling the function of answering calls through a Bluetooth headset.
[0135] The PCM interface can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled via a PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 via the PCM interface, enabling the function of answering calls via a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.
[0136] The UART interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. It converts the data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is typically used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 via the UART interface to implement Bluetooth functionality. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the UART interface, enabling the function of playing music through Bluetooth headphones.
[0137] The MIPI interface can be used to connect the processor 110 to peripheral devices such as the display 194 and the camera 193. MIPI interfaces include the camera serial interface (CSI) and the display serial interface (DSI). In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to implement the camera function of the electronic device 100. The processor 110 and the display 194 communicate via the DSI interface to implement the display function of the electronic device 100.
[0138] The GPIO interface can be configured via software. The GPIO interface can be configured as either a control signal or a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 to the camera 193, display 194, wireless communication module 160, audio module 170, sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.
[0139] The USB interface 130 is an interface that complies with USB standards and may be a Mini USB interface, a Micro USB interface, a USB Type-C interface, or the like. The USB interface 130 can be used to connect a charger to charge the electronic device 100, or to transfer data between the electronic device 100 and peripheral devices. It can also be used to connect headphones to play audio. This interface can also be used to connect other electronic devices, such as augmented reality devices.
[0140] It is understood that the interface connection relationship between the modules illustrated in the embodiment of the present invention is merely an illustrative illustration and does not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods from the above embodiments, or a combination of multiple interface connection methods.
[0141] The charging management module 140 is configured to receive charging input from a charger. The charger can be either a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 can receive charging input from the wired charger via the USB interface 130. In some wireless charging embodiments, the charging management module 140 can receive wireless charging input via the wireless charging coil of the electronic device 100. While charging the battery 142, the charging management module 140 can also provide power to the electronic device via the power management module 141.
[0142] The power management module 141 is used to connect the battery 142, the charging management module 140 and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, and provides power to the processor 110, the internal memory 121, the external memory, the display 194, the camera 193, and the wireless communication module 160. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance). In some other embodiments, the power management module 141 can also be set in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be set in the same device.
[0143] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor.
[0144] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.
[0145] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to the electronic device 100. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.
[0146] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the receiver 170B, etc.) or displays an image or video through the display screen 194. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be set in the same device as the mobile communication module 150 or other functional modules.
[0147] The wireless communication module 160 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., which are applied to the electronic device 100. The wireless communication module 160 can be one or more devices that integrate at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.
[0148] In some embodiments, the antenna 1 of the electronic device 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the electronic device 100 can communicate with a network and other devices through wireless communication technologies. The wireless communication technologies may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).
[0149] Electronic device 100 implements display functionality through a GPU, display screen 194, and an application processor. A GPU is a microprocessor for image processing that connects display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs that execute program instructions to generate or modify display information.
[0150] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD). The display screen panel can also be made of an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a miniLED, a microLED, a micro-OLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the electronic device 100 may include one or N display screens 194, where N is a positive integer greater than one.
[0151] The electronic device 100 can implement a shooting function through an ISP, a camera 193, a video codec, a GPU, a display screen 194, and an application processor.
[0152] The ISP processes data fed back by camera 193. For example, when taking a photo, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, which is then passed to the ISP for processing and converted into a visible image. The ISP can also perform algorithmic optimization on image noise, brightness, and other factors. It can also optimize parameters such as exposure and color temperature of the captured scene. In some embodiments, the ISP can be located within camera 193.
[0153] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then passes the electrical signal to the ISP for conversion into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the electronic device 100 may include 1 or N cameras 193, where N is a positive integer greater than 1.
[0154] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy.
[0155] Video codecs are used to compress or decompress digital video. Electronic device 100 may support one or more video codecs. This allows electronic device 100 to play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, and MPEG4.
[0156] The NPU is a neural network (NN) computing processor. Drawing on the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it rapidly processes input information and can continuously self-learn. The NPU can enable intelligent cognitive applications in electronic device 100, such as image recognition, face recognition, speech recognition, and text comprehension.
[0157] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 via the external memory interface 120 to implement data storage functions. For example, files such as music and videos can be stored on the external memory card.
[0158] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area can store data created during the use of the electronic device 100 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0159] The electronic device 100 can implement audio functions through the audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor, etc. For example, music playback and recording. The pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, the pressure sensor 180A can be set on the display screen 194. The gyroscope sensor 180B can be used to determine the movement posture of the electronic device 100. The air pressure sensor 180C is used to measure air pressure. The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can use the magnetic sensor 180D to detect the opening and closing of the flip leather case. The acceleration sensor 180E can detect the magnitude of the acceleration of the electronic device 100 in various directions (generally three axes). The distance sensor 180F is used to measure distance. The proximity light sensor 180G may include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The ambient light sensor 180L is used to sense the brightness of ambient light. The fingerprint sensor 180H is used to collect fingerprints. The temperature sensor 180J is used to detect temperature. The touch sensor 180K is also called a "touch panel." The touch sensor 180K can be set on the display screen 194. The touch sensor 180K and the display screen 194 form a touch screen, also called a "touch screen." The touch sensor 180K is used to detect touch operations acting on or near it. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through the display screen 194. In other embodiments, the touch sensor 180K can also be set on the surface of the electronic device 100, at a different location from the display screen 194. The bone conduction sensor 180M can obtain vibration signals. The buttons 190 include a power button, a volume button, etc. The motor 191 can generate vibration prompts. The indicator 192 can be an indicator light, which can be used to indicate the charging status, power changes, messages, missed calls, notifications, etc.
[0160] The eSIM module 195 can be embedded in the electronic device 100. The eSIM module is usually embedded inside the motherboard of the electronic device. It can replace the physical SIM card, but the eSIM is much smaller in size. Unlike the SIM card, the eSIM card can switch numbers or change operators at will because the information on the eSIM is rewritable. The eSIM card is remotely configured through over-the-air technology (OTA) writing card, which enables the download, installation, activation, deactivation and deletion of operator configuration files through the network download and installation to the terminal.
[0161] In an embodiment of the present application, the device type of the electronic device 100 may include any one of a smart phone, a smart watch, a smart speaker, a personal computer, a smart TV, a tablet computer, a smart socket, an air purifier, a smart desk lamp, a smart air conditioner, a smart curtain, a smart water heater, a smart door lock, a smart camera, and the like.
[0162] FIG2 is a schematic diagram of the structure of a trusted execution environment of an electronic device provided in an embodiment of the present application.
[0163] As shown in Figure 2, the electronic device 100 may include a central processing unit (CPU), a modem, and an eSIM module. The CPU can run two application environments: a rich execution environment (REE) and a trusted execution environment (TEE).
[0164] Applications running in the REE are called client applications, which can include a cryptographic client application (CA). The REE can also run a local profile assistant (LPA), a card application tool service (CatService), and a telephony manager.
[0165] Applications running in a TEE are called trusted applications (TAs). These applications can include encryption and decryption TAs, and the TEE can also manage digital certificates issued by digital certificate authorities. For example, digital certificates in a TEE can include authentication root certificates (CERT.CI.ECDSA), device certificates (CERT.DEVICE.ECDSA), and terminal certificates (CERT.OEM.ECDSA).
[0166] The operating system running in the REE can be called a Rich Execution Environment Operating System (REE OS), and the operating system running in the TEE can be called a Trusted Execution Environment Operating System (TEE OS). The TEE is a secure operating environment running in the CPU. The TEE's secure boot process must be verified and is separate from the REE. Applications running under the TEE are independent of each other and cannot access each other without authorization. This ensures that the resource and data processing of applications under the TEE is executed in a trusted environment, thereby providing security services for the REE OS. The TEE has its own execution space and a higher level of security than the REE OS. It is a security architecture that overlaps with the hardware architecture of the currently used CPU. The software and hardware resources accessible by the TEE are separate from the REE OS, providing hardware-supported isolation. Among them, the encryption and decryption CA and the encryption and decryption TA share memory. If the encryption and decryption CA needs to communicate with the encryption and decryption TA, the encryption and decryption CA can apply to the TEE OS to establish a session with the requested encryption and decryption TA. After the session between the encryption and decryption CA and the encryption and decryption TA is established, the encryption and decryption CA can send a processing request and the data to be processed to the encryption and decryption TA through the shared memory. After the encryption and decryption TA obtains the processing request and the data to be processed from the shared memory, it can execute the processing request in the TEE environment, and the obtained processing result is stored in the shared memory. The encryption and decryption CA can obtain the processing result of the encryption and decryption TA through the shared memory. After obtaining the processing result, if the encryption and decryption TA does not need to continue processing, the encryption and decryption CA can initiate a request to close the session (close session) to the TEE OS. After receiving the request to close the session (close session), TEEOS can reclaim the relevant resources of the encryption and decryption TA.
[0167] The LPA can invoke the device-card binding logic and send device-card binding instructions to the eSIM module. The LPA can interact with the eSIM module for device-card binding via Telephony Manager and Modem. The LPA can communicate with the encryption and decryption TA in the TEE by invoking the encryption and decryption CA, thereby invoking the encryption and decryption TA to provide encryption and decryption, certificate verification, and key negotiation services during the device-card binding interaction.
[0168] The eSIM module manages card binding logic, digital certificates, security status, and transmitter card verification commands. The digital certificates managed in the eSIM module include authentication root certificates, terminal manufacturer root certificates (CERT.OEMCI.ECDSA), and more.
[0169] The eSIM module can invoke the device-card binding logic and send a device-card verification command to the Cat Service via the modem, thereby triggering the device-card verification interaction between the eSIM module and the Cat Service. The Cat Service can communicate with the encryption and decryption TA in the TEE by calling the encryption and decryption CA, thereby invoking the encryption and decryption TA to provide encryption and decryption services during the device-card verification interaction.
[0170] 1. In the machine-card binding logic:
[0171] The LPA can first request the eSIM module's certificate chain and verify the eSIM module's certificate chain by calling the encryption and decryption TA through the encryption and decryption CA. After verifying the legitimacy of the eSIM module's certificate chain, the encryption and decryption TA can obtain the embedded universal integrated circuit card (eUICC) public key from the eSIM module's certificate chain. The LPA can call the encryption and decryption TA through the encryption and decryption CA to generate a TEE temporary working public key and a TEE temporary working private key, and call the encryption and decryption TA to sign the TEE temporary working public key using the TEE private key (for example, the OEM private key), and send the signature data including the TEE temporary working public key to the eSIM module.
[0172] The LPA can send the TEE's certificate chain to the eSIM module. The eSIM module can verify the TEE's certificate chain. After verifying the legitimacy of the TEE's certificate chain, the eSIM module can obtain the TEE public key (e.g., the OEM public key) from the TEE's certificate chain. The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key, signs the eUICC temporary working public key with the eUICC private key, and sends the signature data including the eUICC temporary working public key to the LPA.
[0173] The LPA can verify the signature data including the eUICC temporary working public key by calling the encryption and decryption TA using the eUICC public key, and obtain the eUICC temporary working public key after the verification is successful. The encryption and decryption TA can generate a shared security key based on the eUICC temporary working public key and the TEE temporary working private key.
[0174] The eSIM module can use the TEE public key (e.g., the OEM public key) to verify the signature data including the TEE temporary working public key, and obtain the TEE temporary working public key after the verification is successful. The eSIM module can generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key.
[0175] Among them, the eSIM module and the encryption and decryption TA can use each other's temporary working public key and their own temporary working private key to generate the same shared security key.
[0176] The LPA can obtain the device identifier 1 (for example, the CPU identifier and / or IMEI), and call the encryption and decryption TA to encrypt the device identifier 1 using the shared security key to obtain the binding information. The LPA can send the binding information to the eSIM module.
[0177] The eSIM module can decrypt the device identity from the binding information using the shared security key and store the device identity 1.
[0178] 2. In the machine card verification logic:
[0179] After the aforementioned machine-card binding logic, the eSIM module has been bound to device identification 1. When the eSIM module is powered on again or before initiating network registration, it can actively send a device identification acquisition request to Cat Service. After receiving the device identification acquisition request, Cat Service can obtain device identification 2 in the CPU and call the encryption and decryption TA to encrypt device identification 2 using the shared security key to obtain verification information. Cat Service can send the verification information to the eSIM module. The eSIM module can decrypt device identification 2 from the verification information using the shared security key. The eSIM module can determine whether the device identification 2 decrypted from the verification information is the same as the stored device identification 1. If device identification 2 is the same as device identification 1, the machine-card verification is passed, and the eSIM module can perform communication services normally. If device identification 2 is different from device identification 1, the machine-card verification fails, and the eSIM module is prohibited from performing communication services.
[0180] In one possible implementation, the device identification acquisition request may include a random number. The encryption / decryption TA can encrypt the device identification 2 and the random number together using a shared security key to obtain verification information. The eSIM module can decrypt the device identification 2 and the random number from the verification information using the shared security key. If the decrypted random number is the same as the random number included in the device identification acquisition request, and the device identification 2 is the same as the device identification 1, the device-card authentication succeeds. If the decrypted random number is different from the random number included in the device identification acquisition request, or if the device identification 2 is different from the device identification 1, the device-card authentication fails.
[0181] In the embodiment of the present application, the above-mentioned central processing unit is only an exemplary explanation of the present application and is not limiting. The central processing unit may also be other processing modules, and the processing modules may include the above-mentioned REE and TEE. For the functional description of REE and TEE and the architecture of the internal modules, please refer to the embodiment shown in Figure 2 above, which will not be repeated here.
[0182] In the embodiments of the present application, a CPU may be referred to as a processing module, a first CPU may be referred to as a first processing module, a second CPU may be referred to as a second processing module, the first CPU may be understood as an example of the first processing module, and the second CPU may be understood as an example of the second processing module. In some possible embodiments of the present application, the first processing module and the second processing module may be the same processing module or different processing modules.
[0183] In the embodiment of the present application, the electronic device 100 may be referred to as a terminal, and the processing module and the modem in the electronic device 100 may be collectively referred to as a terminal device. Therefore, the terminal may include a terminal device and an eSIM module.
[0184] FIG3 shows a schematic diagram of a certificate chain in a TEE and an eSIM module of an electronic device 100 provided in an embodiment of the present application.
[0185] As shown in Figure 3, the TEE can manage authentication root certificates (CERT.CI.ECDSA), device certificates, and terminal certificates (CERT.OEM.ECDSA). The authentication root certificate is the root certificate of the embedded UICC manufacturer (EUM) certificate in the eSIM module, and the EUM certificate is the root certificate of the eUICC certificate. In other words, the EUM certificate is signed by the private key corresponding to the authentication root certificate, and the eUICC certificate is signed by the private key corresponding to the EUM certificate.
[0186] Among them, the authentication root certificate (CERT.CI.ECDSA) can be imported into the TEE of the electronic device 100 through the authentication root certificate authorization public key infrastructure (PKI) device via OTA.
[0187] The TEE can generate a pair of OEM public and private keys, including an OEM public key (PK.OEM.ECDSA) and an OEM private key (SK.OEM.ECDSA). These keys can be based on the NIST P256 elliptic curve cryptography (ECC) standard. The signature algorithm used for these keys can be the elliptic curve digital signature algorithm (ECDSA).
[0188] Among them, TEE can import the TEE certificate into TEE offline through the device manufacturer certificate authorization PKI device. For example, the TEE certificate may include a device certificate, a terminal certificate, etc. Among them, TEE can send an offline certificate signing request to the device manufacturer certificate authorization PKI device. Among them, the offline certificate signing request includes the OEM public key (PK.OEM.ECDSA). The offline certificate signing request is used to request the device manufacturer certificate authorization PKI device to issue a digital certificate for the OEM public key. After receiving the offline certificate signing request, the device manufacturer certificate authorization PKI device can first issue a device certificate through the private key corresponding to the terminal manufacturer's root certificate, and then use the private key corresponding to the device certificate to issue a terminal certificate including the OEM public key. Among them, the terminal certificate includes the OEM public key (PK.OEM.ECDSA), and the private key corresponding to the terminal certificate is the OEM private key (SK.OEM.ECDSA).
[0189] For example, refer to the certificate signing process shown in FIG4 :
[0190] 1. The device manufacturer's root certificate authorization PKI device can store the terminal manufacturer's root certificate and the private key corresponding to the terminal manufacturer's root certificate (SK.OEMCI.ECDSA). The device manufacturer's root certificate authorization PKI device can use the private key corresponding to the terminal manufacturer's root certificate (SK.OEMCI.ECDSA) to sign the certificate content of the device certificate to generate a device certificate. The device certificate includes the device public key (PK.DEVICE.ECDSA), and the terminal manufacturer's root authorization PKI device stores the device private key (SK.DEVICE.ECDSA) paired with the device public key (PK.DEVICE.ECDSA).
[0191] 2. After receiving the offline certificate signing request sent by the TEE of the electronic device 100, the PKI device can obtain the OEM public key (PK.OEM.ECDSA) from the offline certificate signing request and generate the certificate content of the terminal certificate. The certificate content of the terminal certificate may include the OEM public key (PK.OEM.ECDSA), the specified signature algorithm (for example, ECDSA), the certificate validity period, the user, etc.
[0192] 3. The terminal manufacturer's root authorized PKI device can perform a hash operation on the terminal certificate's certificate content to generate a digital summary of the terminal certificate. The terminal manufacturer's root authorized PKI device can encrypt the terminal certificate's digital summary into the terminal certificate's certificate signature using the device's private key (SK.DEVICE.ECDSA) and a specified signature algorithm. The terminal manufacturer's root authorized PKI device can combine the terminal certificate's digital summary with the service root certificate's certificate signature to generate the terminal certificate.
[0193] The eSIM module can be pre-installed with the terminal manufacturer's root certificate, the authentication root certificate (CERT.CI.ECDSA), the EUM certificate, the eUICC certificate, the EUM private key corresponding to the EUM certificate, and the eUICC private key (SK.eUICC.ECDSA) corresponding to the eUICC certificate. The terminal manufacturer's root certificate includes the terminal manufacturer's root public key, the authentication root certificate (CERT.CI.ECDSA) includes the authentication root public key (PK.CI.ECDSA), the EUM certificate includes the EUM public key, and the eUICC certificate includes the eUICC public key (PK.eUICC.ECDSA). The authentication root private key corresponding to the authentication root certificate (CERT.CI.ECDSA) has signed the EUM certificate. The EUM private key corresponding to the EUM certificate has signed the EUM certificate.
[0194] TEE and the eSIM module can verify each other's certificate chains and exchange temporary working public keys.
[0195] in:
[0196] (1) The encryption and decryption TA in TEE can verify the certificate chain of the eSIM module.
[0197] The eSIM module's certificate chain includes the authentication root certificate, the EUM certificate, and the eUICC certificate. The eSIM module can send the EUM and eUICC certificates to the encryption / decryption TA. The encryption / decryption TA can verify the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate pre-configured within the TEE. If the EUM certificate's legitimacy is verified, the encryption / decryption TA can verify the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate. If the eUICC certificate's legitimacy is verified, the encryption / decryption TA can determine that the eSIM module's certificate chain has been verified.
[0198] (2) The eSIM module can verify the TEE certificate chain.
[0199] The TEE certificate chain includes the device certificate and the terminal certificate. The encrypted TA can send the device and terminal certificates to the eSIM module. The eSIM module can verify the legitimacy of the device certificate using the public key in the terminal manufacturer's root certificate pre-installed in the eSIM module. If the device certificate is verified, the eSIM module can verify the legitimacy of the terminal certificate using the device public key in the device certificate. If the terminal certificate is verified, the eSIM module can determine that the TEE certificate chain has been verified.
[0200] In one possible implementation, the TEE certificate can include the terminal manufacturer's root certificate. The terminal manufacturer's root certificate is self-signed by the terminal manufacturer's root private key corresponding to the terminal manufacturer's root certificate. In this case, the eSIM module can store the terminal manufacturer's root certificate after the OTA upgrade is completed. Because the TEE manages only the terminal manufacturer's root certificate as a device certificate, the LPA does not need to send the terminal manufacturer's root certificate to the eSIM module for verification. The eSIM module can directly verify the terminal manufacturer's root certificate by signing it after receiving the TEE temporary working public key.
[0201] (3) The encryption and decryption TA in TEE exchanges a temporary working public key with the eSIM module.
[0202] Among them, the encryption and decryption TA can generate the TEE temporary working public and private keys, wherein the TEE temporary working public and private keys include the TEE temporary working public key (otPK.TEE.ECKA) and the TEE temporary working private key (otSK.TEE.ECKA). After the encryption and decryption TA and the eSIM module have verified each other's certificate chains, the encryption and decryption TA can sign the TEE temporary working public key (otPK.TEE.ECDSA) using the OEM private key (SK.OEM.ECDSA) and send the TEE signature data including the TEE temporary working public key (otPK.TEE.ECKA) to the eSIM module.
[0203] After verifying the TEE's certificate chain, the eSIM module can obtain the OEM public key in the TEE's terminal certificate. The eSIM module can use the OEM public key to verify the TEE signature data including the TEE temporary working public key (otPK.TEE.ECKA). After successful verification, the eSIM module obtains the TEE temporary working public key (otPK.TEE.ECKA).
[0204] The eSIM module can generate eUICC temporary working public and private keys, which include the eUICC temporary working public key (otPK.eUICC.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA). The eSIM module can sign the eUICC temporary working public key (otPK.eUICC.ECKA) using the eUICC private key (SK.eUICC.ECDSA) and send the eUICC signature data including the eUICC temporary working public key (otPK.eUICC.ECKA) to the encryption and decryption TA.
[0205] After verifying the eSIM module's certificate chain, the encryption / decryption TA can obtain the eUICC public key (PK.eUICC.ECDSA) in the eUICC certificate. The encryption / decryption TA can use the eUICC public key (PK.eUICC.ECDSA) to verify the eUICC signature data including the eUICC temporary working public key (otPK.eUICC.ECKA). After successful verification, the encryption / decryption TA obtains the eUICC temporary working public key (otPK.TEE.ECKA).
[0206] The eSIM module can generate a shared security key (ShS) based on the TEE temporary working public key (otPK.TEE.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA).
[0207] The encryption and decryption TA can generate a shared security key (ShS) based on the eUICC temporary working public key (otPK.eUICC.ECKA) and the TEE temporary working private key (otSK.TEE.ECKA).
[0208] Since the TEE temporary working public key (otPK.TEE.ECKA) and the TEE temporary working private key (otSK.TEE.ECKA) are a public-private key pair, and the eUICC temporary working public key (otPK.eUICC.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA) are a public-private key pair, the eSIM module and the encryption / decryption TA can both use each other's temporary working public key and their own temporary working private key to generate the same shared security key (ShS).
[0209] In one possible implementation, the authentication root certificate (CERT.CI.ECDSA) can be a root certificate issued by an operator, a root certificate issued by a third-party organization, a root certificate issued by a terminal manufacturer, a root certificate issued by an EUM manufacturer, and so on.
[0210] In a possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be issued directly by the terminal manufacturer's root certificate or by an intermediate certificate issued by the terminal manufacturer's root certificate, or may be issued by an authentication root certificate.
[0211] In one possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be self-signed.
[0212] In a possible implementation, the device manufacturer root certificate (CERT.OEMCI.ECDSA) may be pre-installed in the eSIM module before the electronic device 100 leaves the factory.
[0213] In a possible implementation, the device manufacturer root certificate (CERT.OEMCI.ECDSA) may also be issued by the server to the electronic device 100 during an OTA upgrade after the electronic device 100 leaves the factory. The processing module (eg, CPU) in the electronic device 100 is pre-installed in the eSIM module.
[0214] The following is a unified description of the abbreviations of the certificates involved in the embodiments of this application.
[0215] (1) The abbreviation of the authentication root certificate may be CERT.CI.ECDSA, CERT.CI.SIG, or CERT.CNCI.SIG. The abbreviation of the authentication root public key of the authentication root certificate may be PK.CI.ECKA, PK.CNCI.ECKA, or PK.CNCI.SIG. The abbreviation of the authentication root private key corresponding to the authentication root certificate may be SK.CI.ECKA, SK.CNCI.ECKA, or SK.CNCI.SIG.
[0216] (2) The abbreviation of an EUM certificate can be CERT.EUM.ECDSA or CERT.EUM.SIG. The abbreviation of the EUM public key of an EUM certificate can be PK.EUM.ECKA or PK.EUM.ECKA or PK.EUM.SIG, etc. The abbreviation of the EUM private key corresponding to an EUM certificate can be SK.EUM.ECKA or SK.EUM.ECKA or SK.EUM.SIG, etc.
[0217] (3) The eUICC certificate may also be referred to as the eSIM certificate. The abbreviation of the eUICC certificate (also known as the eSIM certificate) may be CERT.eUICC.ECDSA or CERT.eUICC.SIG or CERT.eSIM.ECDSA or CERT.eSIM.SIG. Among them, the abbreviation of the eUICC public key (also known as the eSIM public key) of the eUICC certificate (also known as the eSIM certificate) may be PK.eUICC.ECKA or PK.eUICC.ECKA or PK.eUICC.SIG or PK.eSIM.ECKA or PK.eSIM.ECKA or PK.eSIM.SIG, etc. The abbreviation of the eUICC private key (also known as the eSIM private key) corresponding to the eUICC certificate (also known as the eSIM certificate) may be SK.eUICC.ECKA or SK.eUICC.ECKA or SK.eUICC.SIG or SK.eSIM.ECKA or SK.eSIM.ECKA or SK.eSIM.SIG, etc.
[0218] (4) The abbreviation of the terminal manufacturer root certificate can be CERT.OEMCI.ECDSA or CERT.OEMCI.SIG. The abbreviation of the terminal manufacturer root public key of the terminal manufacturer root certificate can be PK.OEMCI.ECKA or PK.OEMCI.SIG. The abbreviation of the terminal manufacturer root private key corresponding to the terminal manufacturer root certificate can be SK.OEMCI.ECKA or SK.OEMCI.SIG.
[0219] (5) The abbreviation of the device certificate can be CERT.DEVICE.ECDSA or CERT.DEVICE.SIG. The abbreviation of the device public key of the device certificate can be PK.DEVICE.ECKA or PK.DEVICE.SIG. The abbreviation of the device private key corresponding to the device certificate can be SK.DEVICE.ECKA or SK.DEVICE.SIG.
[0220] (6) The abbreviation of the terminal certificate can be CERT.OEM.ECDSA or CERT.OEM.SIG. The abbreviation of the terminal public key of the terminal certificate can be PK.OEM.ECKA or PK.OEM.SIG. The abbreviation of the device private key corresponding to the device certificate can be SK.OEM.ECKA or SK.OEM.SIG.
[0221] In order to facilitate the description of the certificate in the embodiment of the present application, the certificate is described in a uniform format ending with ".ECDSA".
[0222] The following describes an eSIM authentication method provided in an embodiment of the present application.
[0223] FIG5 shows a schematic diagram of the process of device-card binding in an eSIM authentication method provided in an embodiment of the present application.
[0224] The eSIM authentication method can be applied to a first electronic device including a first CPU and an eSIM module. The first CPU can run both an REE and a TEE. The REE can run both an LPA and a CA for encryption and decryption, while the TEE can run a TA for encryption and decryption. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 above and will not be repeated here.
[0225] As shown in Figure 5, the process of binding the device to the card may include the following steps:
[0226] S501. The first CPU can detect the first startup after leaving the factory, or the first startup after the system upgrades the machine card binding verification function.
[0227] The first CPU can detect the first power-on after leaving the factory, or the first power-on after the system upgrades the device-card binding verification function, and trigger the subsequent device-card binding process. The device-card binding process can include the following three stages: mutual certificate verification, exchange of temporary working public keys, and device identification binding.
[0228] The first electronic device can be pre-installed with a device-card binding function and a device-card verification function before leaving the factory. In this way, the first CPU and the eSIM module in the first electronic device can be bound when the first electronic device is turned on for the first time after leaving the factory, thereby preventing the eSIM module of the first electronic device from being disassembled and used normally on other devices.
[0229] In one possible implementation, the first electronic device can obtain the device-card binding function and the device-card verification function during an OTA system upgrade after leaving the factory. In this way, the first CPU and eSIM module in the already-sold electronic device can be bound through a system upgrade, thereby preventing the eSIM module of the already-sold first electronic device from being disassembled and used normally on other devices.
[0230] Phase 1: Certificate verification between both parties.
[0231] S502. The first CPU may send the TEE certificate to the eSIM module.
[0232] TEE certificates can include device certificates and terminal certificates. TEE certificates can be managed by the TEE. The TEE can also manage authentication root certificates.
[0233] In a possible implementation, the TEE certificate may be a terminal manufacturer root certificate, which is signed by the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
[0234] S503. The eSIM module may verify the legitimacy of the device certificate using the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
[0235] The eSIM module can be pre-installed with the terminal manufacturer's root certificate, authentication root certificate (CERT.CI.ECDSA), EUM certificate, eUICC certificate, the EUM private key corresponding to the EUM certificate, and the eUICC private key (SK.eUICC.ECDSA) corresponding to the eUICC certificate. The terminal manufacturer's root certificate includes the terminal manufacturer's root public key, the authentication root certificate (CERT.CI.ECDSA) includes the authentication root public key (PK.CI.ECDSA), the EUM certificate includes the EUM public key, and the eUICC certificate includes the eUICC public key (PK.eUICC.ECDSA). The authentication root private key corresponding to the authentication root certificate (CERT.CI.ECDSA) has signed the EUM certificate. The EUM private key corresponding to the EUM certificate has signed the eUICC certificate.
[0236] Specifically, the eSIM module can decrypt the device certificate's summary information 1 from the device certificate's signature using the terminal manufacturer's root public key in the terminal manufacturer's root certificate. The eSIM module can then perform a hash operation on the certificate content in the device certificate to obtain summary information 2. If summary information 2 is identical to summary information 1, the eSIM module can determine that the device certificate is legitimate. If summary information 2 is different from summary information 1, the eSIM module can determine that the device certificate is legitimate.
[0237] S504. After successfully verifying the legitimacy of the device certificate, the eSIM module may use the device public key in the device certificate to verify the legitimacy of the terminal certificate.
[0238] Specifically, the eSIM module can use the device public key in the device certificate to decrypt the terminal certificate's signature to obtain summary information 3 of the terminal certificate. The eSIM module can then perform a hash operation on the certificate content in the terminal certificate to obtain summary information 4. If summary information 3 and summary information 4 are the same, the eSIM module can determine that the terminal certificate is legitimate. If summary information 3 and summary information 4 are different, the eSIM module can determine that the terminal certificate is legitimate.
[0239] S505. The eSIM module may send the EUM certificate and the eUICC certificate to the first CPU after the legitimacy verification of the TEE certificate is passed.
[0240] S506. After receiving the EUM certificate and the eUICC certificate, the first CPU may use the authentication root public key in the authentication root certificate to verify the legitimacy of the EUM certificate.
[0241] Among them, the TEE run by the first CPU can manage the authentication root certificate (CERT.CI.ECDSA), device certificate, and terminal certificate (CERT.OEM.ECDSA). Among them, the authentication root certificate is the root certificate of the card manufacturer (embedded UICC manufacture, EUM) certificate in the eSIM module, and the EUM certificate is the root certificate of the eUICC certificate. That is, the EUM certificate is signed by the authentication root private key corresponding to the authentication root certificate, and the eUICC certificate is signed by the EUM private key corresponding to the EUM certificate. Among them, the terminal certificate is signed by the device private key corresponding to the device certificate, and the device certificate is signed by the terminal manufacturer root private key corresponding to the terminal manufacturer root certificate.
[0242] Specifically, after receiving the EUM certificate and eUICC certificate, the first CPU can first decrypt the EUM certificate's summary information 5 from the EUM certificate's certificate signature using the authentication root public key in the authentication root certificate. The first CPU can then perform a hash operation on the EUM certificate's certificate content to obtain summary information 6. If summary information 5 and summary information 6 are identical, the first CPU can determine that the EUM certificate is legitimate. If summary information 5 and summary information 6 are different, the first CPU can determine that the EUM certificate is legitimate.
[0243] S507. After the first CPU successfully verifies the legitimacy of the EUM certificate, it can use the EUM public key in the EUM certificate to verify the legitimacy of the eUICC certificate.
[0244] Specifically, the first CPU may first decrypt the eUICC certificate's summary information 7 from the eUICC certificate's certificate signature using the EUM public key in the EUM certificate. The first CPU may then perform a hash operation on the eUICC certificate's certificate content to obtain summary information 8. If summary information 7 and summary information 8 are identical, the first CPU may determine that the eUICC certificate is legitimate. If summary information 7 and summary information 8 are different, the first CPU may determine that the eUICC certificate is legitimate.
[0245] S508. After the legitimacy verification of the eUICC certificate passes, the first CPU sends a verification completion notification to the eSIM module.
[0246] The verification completion notification is used to indicate that the eUICC certificate verification has passed.
[0247] Phase 2: Both parties exchange temporary working public keys.
[0248] S509. After sending the verification completion notification to the eSIM module, the first CPU may generate a temporary TEE working public key and a temporary TEE working private key.
[0249] Among them, the TEE temporary working public key and the TEE temporary working private key are a pair of paired public and private keys.
[0250] S510. The first CPU may use the OEM private key to sign the TEE temporary working public key to obtain TEE signature data.
[0251] The OEM private key and OEM public key are a pair of public and private keys. The TEE signature data may include the TEE temporary working public key and the TEE signature value.
[0252] S511. After receiving the verification completion notification, the eSIM module may generate an eUICC temporary working public key and an eUICC temporary working private key.
[0253] The eUICC temporary working public key and the eUICC temporary working private key are a pair of paired public and private keys.
[0254] S512. The eSIM module may use the eUICC private key to sign the eUICC temporary working public key to obtain eUICC signature data.
[0255] The eUICC signature data includes the eUICC temporary working public key and the eUICC signature value.
[0256] S513: The first CPU may send the TEE signature data to the eSIM module.
[0257] S514. The eSIM module may send the eUICC signature data to the first CPU.
[0258] S515. The first CPU may verify the validity of the eUICC signature data using the eUICC public key in the eUICC certificate, and obtain the eUICC temporary working public key after the validity of the eUICC signature data is verified.
[0259] The first CPU can decrypt the eUICC signature value in the eUICC signature data using the eUICC public key in the eUICC certificate to obtain digest information 9. The first CPU can then perform a hash operation on the eUICC temporary working public key in the eUICC signature data to obtain digest information 10. If digest information 10 is identical to digest information 9, the first CPU can determine that the legitimacy verification of the eUICC signature data has passed, and the first CPU can save the eUICC temporary working public key in the eUICC signature data through the TEE.
[0260] S516. The eSIM module can verify the legitimacy of the TEE signature data through the OEM public key in the terminal certificate, and obtain the TEE temporary working public key after the legitimacy of the TEE signature data is verified.
[0261] The eSIM module can decrypt summary information 11 from the TEE signature value in the TEE signature data using the OEM public key in the terminal certificate. The eSIM module can then sign the TEE temporary working public key in the TEE signature data to obtain summary information 12. If summary information 12 is identical to summary information 11, the eSIM module can determine that the legitimacy verification of the TEE signature data has passed, and the eSIM module can save the TEE temporary working public key in the TEE signature data.
[0262] Phase 3: Device identification binding.
[0263] S517. The first CPU may generate a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0264] S518. The eSIM module may generate a shared security key (ShS) based on the eUICC temporary working private key and the TEE temporary working public key.
[0265] Since the TEE temporary working public key and TEE temporary working private key are a public-private key pair, and the eUICC temporary working public key and eUICC temporary working private key are a public-private key pair, the eSIM module and the encryption / decryption TA can both use each other's temporary working public key and their own temporary working private key to generate the same shared security key (ShS).
[0266] S519. The first CPU may obtain a device identification.
[0267] The device identifier may include a chip identifier (chipID) of the first CPU and / or an international mobile equipment identity (IMEI), and the like.
[0268] S520. The first CPU may encrypt the device identifier using the shared security key to obtain binding information.
[0269] S521: The first CPU may send the binding information to the eSIM module.
[0270] S522. The eSIM module may decrypt the device identifier from the binding information using the shared security key and store the device identifier.
[0271] Among them, after the eSIM module stores the device identification, the machine-card binding process is completed.
[0272] In some embodiments, the above step S501 is optional, and the above steps S502 to S522 may be performed on the production line before the electronic device leaves the factory.
[0273] In the embodiment shown in Figure 5 of the present application, the steps executed by the first CPU can specifically be executed by the LPA in the first CPU or by the LPA triggering the encryption and decryption TA in the TEE through the encryption and decryption CA. For example, in steps: S501 and S502, after the LPA detects the first power-on after leaving the factory or the first power-on after the system upgrade and card binding function, it can obtain the TEE certificate from the TEE and send the TEE certificate to the eSIM module. Steps: S506, S507, S509, S510, S515, S517, S519 and S520 are executed by the LPA triggering the encryption and decryption TA through the encryption and decryption CA. Steps: S509, S513 and S521 are executed by the LPA.
[0274] FIG6 shows a schematic diagram of the process of device-card verification in an eSIM authentication method provided in an embodiment of the present application.
[0275] This eSIM authentication method can be applied to an electronic device including a second CPU and an eSIM module. The second CPU can run both an REE and a TEE. The REE can run Cat Service and encryption / decryption CA, while the TEE can run encryption / decryption TA. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 above and will not be repeated here.
[0276] As shown in Figure 6, the process of machine card verification may include the following steps:
[0277] S601. When the eSIM module detects that it is powered on again, it can internally determine whether the eSIM module is bound to a device identifier based on the security status.
[0278] In a possible implementation, the eSIM module may also determine whether the eSIM module is bound to a device identifier when receiving a request for performing a communication service.
[0279] S602. If the eSIM module is bound with a device ID (device ID 1), a random number A is generated.
[0280] S603. The eSIM module sends a device identification acquisition request to the second CPU, wherein the device identification acquisition request carries a random number A.
[0281] S604: The second CPU may obtain the device identification of the electronic device (device identification 2).
[0282] The device identification of the electronic device may include a chip identification (chipID) and / or IMEI, etc.
[0283] S605. The second CPU may use the shared security key to encrypt the device identification 2 and the random number A to obtain verification information.
[0284] S606. The second CPU sends verification information to the eSIM module.
[0285] S607. The eSIM module may use the shared security key to decrypt the device identification 2 and the random number B from the verification information.
[0286] S608. The eSIM module may determine whether the device identification 2 is the same as the device identification 1 and the random number B is the same as the random number A.
[0287] S609. If the device identification 2 is the same as the device identification 1 and the random number B is the same as the random number A, the device card verification is passed and the eSIM module can perform mobile communication services normally.
[0288] S610. If the device identification 2 is different from the device identification 1 or the random number B is different from the random number A, the device card verification fails and the eSIM module is prohibited from performing mobile communication services.
[0289] In the embodiment of the present application, if the machine card verification is passed, it means that the second CPU is the same CPU as the first CPU in the embodiment shown in FIG. 5 , and the first electronic device is the same as the second electronic device.
[0290] If the machine-card verification fails, it means that the second CPU is not the same CPU as the first CPU in the embodiment shown in Figure 5 above, and the second electronic device and the first electronic device are not bound to the eSIM module.
[0291] In one possible implementation, if the eSIM module detects that the machine-card authentication fails for more than a specified number of times (for example, 3 times), it is permanently locked.
[0292] In the embodiment shown in FIG6 of the present application, the steps executed by the second CPU may be specifically executed by Catservice in the second CPU or by Catservice triggering the execution of encryption and decryption TA in the TEE through encryption and decryption CA. For example, the recipient of the device identification acquisition request in step S603 may be Catsevice, step S604 may be executed by Catservice, step S605 may be executed by Catservice triggering the execution of encryption and decryption TA through encryption and decryption CA, and step S606 may be executed by Catservice.
[0293] In a possible implementation, if the eSIM module does not receive verification information sent by the second CPU after sending a device identification acquisition request to the second CPU, the device-card authentication fails, and the eSIM module is prohibited from performing mobile communication services.
[0294] An eSIM authentication method provided in an embodiment of the present application enables a first CPU and an eSIM module in a first electronic device to negotiate a shared key after a system upgrade or initial factory power-up, for example. The first CPU then encrypts a device identifier using the shared security key, generates binding information, and sends the binding information to the eSIM module. The eSIM module decrypts the first device identifier from the binding information using the shared security key and stores the first device identifier. When the eSIM module is powered on again or before performing a mobile communication service, the eSIM module can instruct a second CPU, currently in communication with the eSIM module, to obtain a second device identifier and encrypt the second device identifier using the shared security key to generate verification information. The eSIM module decrypts the second device identifier from the verification information using the shared key. If the second device identifier matches the first device identifier stored in the eSIM module, the eSIM module can proceed with the mobile communication service normally. If the second device identifier differs from the first device identifier stored in the eSIM module, or if the eSIM module does not receive the device verification information sent by the second CPU after powering off and then on, the eSIM module can prohibit the mobile communication service. In this way, the eSIM module in the first electronic device can be prevented from being inserted into other devices and accessing the mobile communication network after being disassembled, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0295] The following describes in detail the process of device-card binding in the eSIM authentication method provided in the embodiment of the present application in conjunction with signaling.
[0296] FIG7 shows a schematic diagram of the signaling interaction process for device-card binding in an eSIM authentication method provided in an embodiment of the present application.
[0297] The eSIM authentication method can be applied to a first electronic device comprising a first CPU, a first modem, and an eSIM module. The first CPU can run both an REE and a TEE. The REE can run both an LPA and a CA for encryption and decryption, while the TEE can run a TA for encryption and decryption. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 above and will not be repeated here.
[0298] As shown in Figure 7, the signaling interaction process for device-card binding in the eSIM authentication method may include the following steps:
[0299] S701: The first CPU detects that the ROM upgrade is complete.
[0300] Among them, after detecting that the ROM upgrade is completed, the LPA can call the system upgrade management (OsUpdateManager) module to complete the patch (Patch) upgrade of the eSIM module.
[0301] S702. The eSIM module detects that the patch upgrade is complete.
[0302] After the ROM upgrade is complete, the TEE running on the first CPU can manage the TEE certificate and the authentication root certificate (CERT.CI.ECDSA). The authentication root certificate is the root certificate of the EUM certificate in the eSIM module, and the EUM certificate is the root certificate of the eUICC certificate. In other words, the EUM certificate is signed by the private key corresponding to the authentication root certificate, and the eUICC certificate is signed by the private key corresponding to the EUM certificate.
[0303] In one possible implementation, the TEE certificate may include a device certificate and a terminal certificate (CERT.OEM.ECDSA). The terminal certificate is signed by the device private key corresponding to the device certificate, the device certificate is signed by the terminal manufacturer's root private key corresponding to the terminal manufacturer's root certificate, and the terminal manufacturer's root certificate is self-signed by the terminal manufacturer's root private key corresponding to the terminal manufacturer's root certificate. In this case, after the patch upgrade is completed, the eSIM module may store the terminal manufacturer's root certificate. The eSIM module can use this terminal manufacturer's root certificate to verify the TEE certificate.
[0304] In one possible implementation, the TEE certificate may include the terminal manufacturer's root certificate. The terminal manufacturer's root certificate is self-signed by the terminal manufacturer's root private key corresponding to the terminal manufacturer's root certificate. In this case, the eSIM module can store the terminal manufacturer's root certificate after the patch upgrade is completed. Because the TEE-managed TEE certificate only includes the terminal manufacturer's root certificate, the LPA does not need to send the terminal manufacturer's root certificate to the eSIM module for verification. The eSIM module can directly perform self-verification on the stored terminal manufacturer's root certificate.
[0305] In the subsequent embodiments of this application, the device certificate includes the terminal manufacturer's root certificate, and the LPA does not need to send the terminal manufacturer's root certificate to the eSIM module for verification as an example for explanation.
[0306] After the eSIM module patch upgrade is completed, the terminal manufacturer's root certificate, authentication root certificate (CERT.CI.ECDSA), EUM certificate, eUICC certificate, EUM private key corresponding to the EUM certificate, and eUICC private key (SK.eUICC.ECDSA) corresponding to the eUICC certificate can be stored. The terminal manufacturer's root certificate includes the terminal manufacturer's root public key, the authentication root certificate (CERT.CI.ECDSA) includes the authentication root public key (PK.CI.ECDSA), the EUM certificate includes the EUM public key, and the eUICC certificate includes the eUICC public key (PK.eUICC.ECDSA). The authentication root private key corresponding to the authentication root certificate (CERT.CI.ECDSA) has signed the EUM certificate. The EUM private key corresponding to the EUM certificate has signed the EUM certificate.
[0307] In a possible implementation, the above steps S701 and S702 are optional, and the first CPU may complete subsequent steps S703 to S735 when the first electronic device is powered on for the first time after leaving the factory.
[0308] S703. The eSIM module may send a refresh command to the first modem.
[0309] The refresh command may be a proactive command.
[0310] S704. The first modem powers on the eSIM module.
[0311] The first modem may re-power on the eSIM module after receiving the eSIM module.
[0312] S705 . After powering on the eSIM module, the first modem sends a reset command to the eSIM module.
[0313] After the patch upgrade is completed, the eSIM module can set the value of the bound device identification bit to the initial value. For example, the value of the bound device identification bit can be set to "0x00".
[0314] The bound device identification bit is used to indicate the device binding status of the eSIM module. When the value of the bound device identification bit is the initial value, it means that the eSIM module is in an unbound state.
[0315] S706. The eSIM module may detect that the eSIM module has not completed the device-card binding.
[0316] After resetting, the eSIM module can detect that the eSIM module has not completed the device-card binding through the binding device identification bit.
[0317] S707. The eSIM module may send an answer to reset (ATR) to the first modem.
[0318] The ATR indicates that the eSIM module reset is complete.
[0319] S708. The first CPU may open a logical channel (open channel) with the eSIM module.
[0320] After the first modem receives the ATR, the first modem can complete the necessary machine-card interaction process with the eSIM module.
[0321] Among them, the first modem can trigger the LPA to call the machine-card binding logic and open a logical channel between the LPA and the eSIM module.
[0322] S709. The first CPU may send an electronic identity acquisition (GetEID) command to the eSIM module.
[0323] The LPA can determine whether it has already obtained the electronic identity (EID) of the eSIM module. If the eSIM module's EID has not been obtained, the LPA can send a GetEID command to the eSIM module to obtain the eSIM module's EID. If the eSIM module's EID has been obtained, the LPA does not need to send the GetEID command to the eSIM module.
[0324] S710. After receiving the electronic identity acquisition command, the eSIM module may return a response command 1 to the first CPU, wherein the response command 1 carries the EID.
[0325] For example, the response command 1 may be “BF3312 5A10 12345634202200001234512345112233”, where the EID is “12345634202200001234512345112233”.
[0326] S711. The first CPU may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0327] The LPA may send an eUICC random number acquisition command to the eSIM module to obtain an eUICC random number (eUICCChallenge).
[0328] S712. After receiving the eUICC random number acquisition command, the eSIM module may return a response command 2 to the first CPU. Response command 2 may carry the eUICC random number (eUICCChallenge).
[0329] For example, the response command 2 may be "BF2312 8010 76543212BE97D30B2D1FBECA7B7A9668", where the eUICC random number may be "76543212BE97D30B2D1FBECA7B7A9668".
[0330] S713. The first CPU may generate a TEE temporary working public key (otPK.TEE.ECKA), a TEE temporary working private key (otSK.TEE.ECKA), a device random number (deviceChallenge), and a host identifier (HostID).
[0331] Among them, LPA can call the encryption and decryption CA, and through the encryption and decryption CA, call the encryption and decryption TA to generate a temporary TEE temporary working public key, a TEE temporary working private key, and a device random number (deviceChallenge). Among them, the TEE temporary working public key and the TEE temporary working private key can meet the public and private key standard "ECC-256".
[0332] The host identifier (HostID) can be used to indicate the initiator identifier of the session currently established on the logical channel between the LPA and the eSIM module.
[0333] S714. The first CPU may generate TEE package data, wherein the TEE package data includes a TEE temporary working public key, a device random number, an eUICC random number, and a host identifier.
[0334] Among them, LPA can call the encryption and decryption CA, and call the encryption and decryption TA through the encryption and decryption CA to generate the TEE package data.
[0335] S715. The first CPU can use the TEE private key (SK.TEE.ECKA) to sign the TEE package data and obtain the TEE signature value (serverSignature).
[0336] LPA can call the encryption and decryption CA, and through the encryption and decryption CA, call the encryption and decryption TA to sign the TEE package data with the TEE private key (SK.TEE.ECDSA) to obtain the TEE signature value (serverSignature).
[0337] For example, the TEE package data may include, from front to back, the eUICC random number, the device random number, the host identifier, and the TEE temporary working public key.
[0338] Specifically, the encryption and decryption TA can first perform a hash operation on the TEE package data to obtain the summary information of the TEE package data. Then, the encryption and decryption TA can use the TEE private key (SK.TEE.ECDSA) and a specified signature algorithm (for example, the ECDSA signature algorithm) to encrypt the summary information of the TEE package data into a TEE signature value (serverSignature).
[0339] In one possible implementation, the TEE private key (SK.TEE.ECDSA) may be the OEM private key (SK.OEM.ECDSA) corresponding to the terminal certificate (CERT.OEM.ECDSA) in the aforementioned embodiment, and the TEE public key (PK.TEE.ECDSA) paired with the TEE private key (SK.TEE.ECDSA) may be the OEM public key (PK.OEM.ECDSA) in the terminal certificate (CERT.OEM.ECDSA) in the aforementioned embodiment.
[0340] In one possible implementation, the TEE private key (SK.TEE.ECDSA) can be the terminal manufacturer root private key (SK.OEMCI.ECDSA) corresponding to the terminal manufacturer root certificate in the aforementioned embodiment. The TEE public key (PK.TEE.ECDSA) paired with the TEE private key (SK.TEE.ECDSA) can be the terminal manufacturer root public key (PK.OEMCI.ECDSA) in the terminal manufacturer root certificate in the aforementioned embodiment.
[0341] S716. The first CPU may send a store data command 1 to the eSIM module. The store data command 1 may carry TEE signature data, which may include TEE package data and a TEE signature value.
[0342] For example, the store data command 1 may be:
[0343] S717. After receiving the store data command 1, the eSIM module can verify the TEE signature value and eUICC random number in the TEE signature data through the TEE public key (PK.TEE.ECDSA) stored in the TEE certificate.
[0344] The eSIM module can first decrypt summary information A from the TEE signature value using the TEE public key. The eSIM module can then perform a hash operation on the TEE package data to generate summary information B. The eSIM module can determine whether summary information A and summary information B are identical. If summary information A and summary information B are identical, the TEE signature value verification passes. If summary information A and summary information B are different, the TEE signature value verification fails.
[0345] After the TEE signature verification passes, the eSIM module can determine whether the eUICC random number in the TEE package data is the same as the eUICC random number previously generated by the eSIM module. If the eUICC random number in the TEE package data is the same as the eUICC random number previously generated by the eSIM module, the eUICC random number verification passes. If the eUICC random number in the TEE package data is different from the eUICC random number previously generated by the eSIM module, the eUICC random number verification fails.
[0346] When the TEE signature value verification fails and / or the eUICC random number verification fails, the eSIM module terminates subsequent steps.
[0347] After the TEE signature value and eUICC random number are verified, the S718.eSIM module can generate the eUICC temporary working public key (ot.PK.EUICC.ECKA) and eUICC temporary working private key (ot.SK.EUICC.ECKA).
[0348] S719. The eSIM module may generate eUICC packaging data, wherein the eUICC packaging data may include an eUICC temporary working public key and a device random number (deviceChallenge).
[0349] S720. The eSIM module may sign the eUICC package data using the eUICC private key (SK.eUICC.ECDSA) to obtain an eUICC signature value.
[0350] For example, the eUICC package data may be, from front to back, the device random number and the eUICC temporary working public key.
[0351] The eSIM module can first perform a hash operation on the eUICC package data to obtain a summary of the eUICC package data. The eSIM module can then use the eUICC private key (SK.eUICC.ECDSA) and a specified signature algorithm (e.g., the ECDSA signature algorithm) to encrypt the summary of the eUICC package data into an eUICC signature value (eUICCSignature).
[0352] S721. The eSIM module may send a response command 3 to the first CPU. Response command 3 may include the eUICC signature data, the EUM certificate (CERT.EUM.ECDSA), and the eUICC certificate (CERT.eUICC.ECDSA).
[0353] The eUICC signature data may include eUICC package data and an eUICC signature value.
[0354] For example, response command 3 may be:
[0355] Since the content carried in Response Command 3 is relatively large and exceeds a certain amount (e.g., 255 bytes), the first modem may continue to send Get Response commands based on the status word (SW) returned by the eSIM module to obtain the entire content of Response Command 3. The first modem may send the entire content of Response Command 3 to the LPA.
[0356] S722. After receiving the response command 3, the first CPU may verify the legitimacy of the EUM certificate and the eUICC certificate using the authentication root public key (PK.CI.ECDSA) in the stored authentication root certificate.
[0357] Specifically, the LPA can call the encryption and decryption CA, which in turn calls the encryption and decryption TA to verify the EUM certificate and eUICC certificate using the authentication root public key (PK.CI.ECDSA) stored in the authentication root certificate. The encryption and decryption TA can first decrypt the EUM certificate's summary information 5 from the EUM certificate's signature using the authentication root public key in the authentication root certificate. The encryption and decryption TA can then perform a hash operation on the EUM certificate's certificate content to obtain summary information 6. If summary information 5 and summary information 6 are identical, the encryption and decryption TA can determine that the EUM certificate is legitimate. If summary information 5 and summary information 6 are different, the encryption and decryption TA can determine that the EUM certificate is legitimate.
[0358] After verifying the legitimacy of the EUM certificate, the encryption / decryption TA can decrypt the eUICC certificate's summary information 7 from the eUICC certificate's signature using the EUM public key in the EUM certificate. The encryption / decryption TA can then perform a hash operation on the eUICC certificate's content to obtain summary information 8. If summary information 7 and summary information 8 are identical, the encryption / decryption TA can determine that the eUICC certificate is legitimate. If summary information 7 and summary information 8 are different, the encryption / decryption TA can determine that the eUICC certificate is legitimate.
[0359] S723. After verifying the legitimacy of the EUM certificate and the eUICC certificate, the first CPU may verify the device random number and the eUICC signature value using the eUICC public key in the eUICC certificate.
[0360] The encryption / decryption TA can use the eUICC public key (PK.EUICC.ECDSA) to decrypt the eUICC signature value to obtain digest information C. The encryption / decryption TA can then perform a hash operation on the eUICC package data to generate digest information D. The encryption / decryption TA can determine whether digest information C and digest information D are identical. If digest information C and digest information D are identical, the eUICC signature value verification passes. If digest information C and digest information D are different, the eUICC signature value verification fails.
[0361] After the eUICC signature verification passes, the encryption / decryption TA can determine whether the device random number in the eUICC package data is the same as the device random number generated by the encryption / decryption TA before. If the device random number in the eUICC package data is the same as the device random number generated by the encryption / decryption TA before, the device random number verification passes. If the device random number in the eUICC package data is different from the device random number generated by the encryption / decryption TA before, the device random number verification fails.
[0362] When the eUICC signature value verification fails and / or the device random number verification fails, the encryption and decryption TA terminates the subsequent steps.
[0363] S724. After the device random number and the eUICC signature value are verified, the first CPU generates a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key.
[0364] Among them, LPA can call the encryption and decryption TA, and the encryption and decryption TA can generate ShS based on the eUICC temporary working public key and TEE temporary working private key through the "TEE DeriveKey" interface.
[0365] S725: The first CPU may obtain a device identification, where the device identification may include a chip identification (ChipID) and / or an IMEI of the first CPU, etc.
[0366] For example, the LPA may call the file stream "read" interface to read the " / sys / devices / soc0 / serialnumber" storage path to obtain the chip ID (chipID) of the first CPU.
[0367] S726. The first CPU may encrypt the device identifier and the eUICC random number into binding information using the ShS, the host identifier, and the EID, and generate a command message authentication code (C-MAC).
[0368] S727: The first CPU may send a store data command 2 to the eSIM module. The store data command 2 may carry binding information and C-MAC.
[0369] Among them, the encryption and decryption TA can derive the original message authentication code chaining value (Initial MAC chaining value), session encryption key (S-ENC), and session message authentication code (S-MAC) based on ShS, host identifier and EID according to the "BSI TR-03111X9.63 Key Derivation Function" standard rules.
[0370] As shown in FIG8A , the encryption process of the plaintext data in the Storedata command can be as follows:
[0371] 1. Encryption and Decryption TA can generate command plaintext data based on the device identity and eUICC random number.
[0372] For example, the command plain text data can be:
[0373] "6F8002 XX
[0374]
Device identifier in TLV format
[0375] [eUICC random number in TLV format]".
[0376] 2. The encryption / decryption TA can add padding data after the command plaintext data, so that the total length of the command plaintext data and the padding data is an integer number of bytes. The padding data can start with "80".
[0377] 3. Encryption and Decryption TA can determine an integrity check value (ICV) 1 based on the count value 1 and S-ENC through the AES-CBC encryption algorithm. The length of the count value 1 can be 16 bytes.
[0378] 4. Encryption and Decryption TA can determine the command ciphertext data (ciphered command data field, CCDF) based on the command plaintext data after adding the padding data, the integrity check value 1 and S-ENC through the AEC-CBC encryption algorithm. The command ciphertext data is also the binding information mentioned above.
[0379] 5. The encryption and decryption TA can add the data length (Lcc) field before the command ciphertext data, add the flag bit (Tag) before the data length field, and add the Initial MAC chaining value before the flag bit to obtain the C-MAC data to be generated.
[0380] 6. The encryption / decryption TA can determine the C-MAC signature data based on the C-MAC data to be generated and the S-MAC using the C-MAC calculation algorithm, and use the most significant 8 bytes and the least significant 8 bytes of the C-MAC signature data as the new message authentication code chaining value (New MAC chaining value). The C-MAC calculation algorithm can be the "NIST SP 800-38B" standard algorithm.
[0381] 7. Encryption and Decryption TA can extract the most significant 8 bytes of data from the C-MAC signature data as C-MAC.
[0382] 8. The TA can return the C-MAC and command ciphertext data (CCDF) to the LPA through the encryption and decryption CA.
[0383] 9. After receiving the C-MAC and the command ciphertext data (CCDF), the LPA can assemble the above-mentioned Storedata command 2. Among them, the Storedata command 2 may include a flag bit, a data length field and a data field. Among them, the value of the flag bit can be "86". When the value of the flag bit can be "86", it can be used to indicate that the data structure of the Storedata command 2 located after the flag bit is a TLV data grid structure that complies with the GSMA specification requirements. The data length field is used to indicate the length of the data field. The data field of the Storedata command 2 may include command ciphertext data (CCDF) and C-MAC. Among them, the command ciphertext data (CCDF) of the Storedata command 2 is the above-mentioned binding information.
[0384] S728. After sending response command 3 to the first CPU, the eSIM module may generate an ShS based on the TEE temporary working public key and the eUICC temporary working private key.
[0385] S729. After receiving the Storedata command 2, the eSIM module can verify the C-MAC through the ShS, host identifier and EID, decrypt the binding information, obtain the device identifier and eUICC random number, and verify the decrypted eUICC random number.
[0386] Among them, the eSIM module can derive the Initial MAC chaining value, S-ENC, and S-MAC based on ShS, host identification, and EID in accordance with the "BSI TR-03111X9.63 Key Derivation Function" standard rules.
[0387] Then, the eSIM module adds the flag bit, data length field, and command ciphertext in the Stored Data Command 2 after the Initial MAC chaining value to form the MAC verification information, and re-determines the C-MAC based on the MAC verification information and S-MAC and the C-MAC calculation algorithm. The eSIM module can determine whether the re-determined C-MAC is the same as the C-MAC carried in the Stored Data Command 2. If they are the same, the C-MAC verification passes. The eSIM module can decrypt the device identifier and eUICC random number from the command ciphertext data (i.e., binding information) of the Stored Data Command 2 based on S-ENC and S-MAC.
[0388] The eSIM module can determine whether the eUICC random number decrypted from the Storedata command 2 is the same as the eUICC random number previously generated by the eSIM module. If they are the same, the eUICC random number verification is successful; if they are not the same, the eUICC random number verification is successful.
[0389] S730. After the eSIM module verifies the eUICC random number decrypted from the binding information, it encrypts the device random number into eUICC encrypted data using the shared security key, host identity, and EID, and generates a response message authentication code (R-MAC).
[0390] S731. The eSIM module may send a response command 4 to the first CPU. Response command 4 may carry the eUICC encrypted data and R-MAC.
[0391] As shown in FIG8B , the encryption process of the response plaintext data of the Response command 4 may be as follows:
[0392] 1. The eSIM module can assemble the response plaintext data of Response command 4 based on the device random number.
[0393] For example, the response plaintext data can be:
[0394] "6F8002 XX
[0395]
Device random number in TLV format
[0396] ”
[0397] 2. The eSIM module can add padding data after the plaintext response data, so that the total length of the response plaintext data and the padding data is an integer number of bytes. The padding data can start with "80".
[0398] 3. The eSIM module may determine an integrity check value (ICV) 2 based on the count value 2 and the S-ENC using an AES-CBC encryption algorithm. The count value 2 may be 16 bytes long.
[0399] 4. The eSIM module can determine the ciphered response data (CRDF) based on the response plaintext data after adding the padding data, the integrity check value 2, and the S-ENC through the AEC-CBC encryption algorithm. The ciphered response data is also the eUICC encrypted data.
[0400] 5. The eSIM module can add a data length (Lcc) field before the response ciphertext data, add a flag bit (Tag) before the data length field, and add a New MAC chaining value before the flag bit to obtain the R-MAC data to be generated.
[0401] 6. The eSIM module may determine the R-MAC signature data based on the R-MAC to be generated data and the S-MAC using an R-MAC calculation algorithm, and use the most significant 8 bytes of the R-MAC signature data as the R-MAC. The R-MAC calculation algorithm may be the "NIST SP 800-38B" standard algorithm.
[0402] 7. The eSIM module may assemble Response Command 4. Response Command 4 may include a flag, a data length field, and a data field. The data field in Response Command 4 may include Response Cipher Data (CRDF) and R-MAC. The data length field indicates the length of the data field. The Response Cipher Data (CRDF) in Response Command 4 is the eUICC encrypted data.
[0403] S732. The first CPU verifies the R-MAC using the ShS, host identifier, and EID, decrypts the device random number from the eUICC encrypted data, and verifies the decrypted device random number.
[0404] LPA can call the encryption and decryption TA to verify the R-MAC, decrypt the device random number from the eUICC encrypted data, and verify the decrypted device random number.
[0405] Among them, the process of encrypting and decrypting TA to verify R-MAC can refer to the process of verifying C-MAC by the above-mentioned eSIM module, and will not be repeated here.
[0406] S733. After verifying the decrypted device random number, the first CPU sends a StoreData command 3 to the eSIM module. The StoreData command 3 is used to indicate the end of the device-card binding interaction.
[0407] The Storedata command 3 includes a flag bit, a data length field, and a data field. The data field in the Storedata command 3 includes the end indication ciphertext and C-MAC encrypted from the end indication plaintext (e.g., "0F6001 03 03").
[0408] The encryption process of the end indication ciphertext and the generation process of the C-MAC in the Storedata command 3 can refer to the encryption process of the command ciphertext data and the generation process of the C-MAC in the embodiment shown in Figure 8A above. The count value used in the encryption process of the end indication ciphertext is incremented by 1 from the count value 1 shown in Figure 8A above.
[0409] S734. After receiving the Storedata command 3, the eSIM module sets the device binding state to the bound state and stores the device identification.
[0410] Among them, after receiving the Storedata command 3, the eSIM module can verify the C-MAC in the Storedata command 3, and after verifying that the C-MAC in the Storedata command 3 is passed, decrypt the end indication ciphertext in the Storedata command 3 to obtain the end indication plaintext (for example, "0F600103 03").
[0411] After receiving the end indication plaintext, the eSIM module may set the value of the bound device identification bit to the first value (eg, "0x12"). When the value of the bound device identification bit is the first value, it indicates that the eSIM module is in a bound state.
[0412] When the eSIM module completes device-card binding, it may assume that device-card verification is successful to improve compatibility. The eSIM module may also reset the binding information verification flag to a second value (e.g., "0x44"). When the binding information verification flag is the second value, it indicates that the eSIM module binding information verification is complete.
[0413] S735. The eSIM module returns a binding completion status code to the first CPU. The binding completion status code is used to indicate that the device-card binding is complete.
[0414] The eSIM module can return a binding completion status code to the LPA via status words SW1 and SW2. For example, the values of SW1 and SW2 can be 9000.
[0415] In some embodiments, the above steps S701 and S702 are optional, and the above steps S703 to S735 may be performed on the production line before the electronic device leaves the factory.
[0416] The following describes in detail the device-card verification process in the eSIM authentication method provided in the embodiment of the present application in conjunction with signaling.
[0417] FIG9 shows a schematic diagram of the signaling interaction process for machine-card verification in an eSIM authentication method provided in an embodiment of the present application.
[0418] The eSIM authentication method can be applied to a second electronic device comprising a second CPU, a second modem, and an eSIM module. The second CPU can run both an REE and a TEE. The REE can run CatService and encryption / decryption CA, while the TEE can run encryption / decryption TA. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 above and will not be repeated here.
[0419] As shown in Figure 9, the signaling interaction process for device-card verification in the eSIM authentication method may include the following steps:
[0420] S901. The eSIM module sends a refresh command to the second modem.
[0421] The refresh command may be a proactive command.
[0422] S902. The second modem powers on the eSIM module.
[0423] The second modem may re-power on the eSIM module after receiving the eSIM module.
[0424] S903. After powering on the eSIM module, the second modem sends a reset command to the eSIM module.
[0425] S904. The eSIM module can detect that the eSIM module has completed the device-card binding.
[0426] After receiving the reset command, the eSIM module can complete the reset operation and detect that the machine-card binding has been completed through the binding device mark.
[0427] S905. The eSIM module may send an ATR to the second modem.
[0428] The ATR indicates that the eSIM module reset is complete.
[0429] S906. The second modem may send a terminal profile command to the eSIM module.
[0430] S907. The eSIM module may send a setup menu command to the second modem.
[0431] S908. The second modem may send a terminal response (Terminal response) command 1 to the eSIM module.
[0432] S909. The eSIM module sends status code 1 (eg, “91xx”) to the second modem.
[0433] Among them, the status code 1 can be used to request Momdem to send a Fetch command to the eSIM module, thereby obtaining a Get Input command from the eSIM module.
[0434] S910. The second modem may send a Fetch command to the eSIM module.
[0435] S911. The eSIM module may generate a random number A and generate a message authentication code 1 (MAC1) for the random number A.
[0436] Among them, the eSIM module can perform MAC calculation on the random number A based on the S-MAC and C-MAC calculation algorithms derived from the above ShS (for example, the NIST SP 800-38B standard algorithm), and use the most significant 8 bytes of data in the calculation result as MAC1.
[0437] S912. The eSIM module may send a Get Input command to the second modem, wherein the Get Input command may carry a random number A and MAC1.
[0438] As shown in Figure 10, the Get Input command may include a proactive SIM command tag, a data length field, and a data field. The proactive SIM command tag may be used to indicate the type of the Get Input command. For example, the proactive SIM command tag in the Get Input command may be "D0." The data length field may be used to indicate the length of the data field. The data field may include a command details field, a device identifier field, a text string field, a response length field, and a default text field.
[0439] The text string field can include a text string tag, a text string length field, a text string encoding scheme field, and a text string data field. The text string tag can be used to mark the starting position of the text string field. The text string length field can be used to indicate the total length of the data encoding scheme field and the text string data field. The text string encoding scheme field can be used to indicate the encoding scheme of the text string data field.
[0440] The default text (textdefault) field can include a default text tag, a default text length field, a data encoding scheme field, and a default text data field. The default text tag can be used to mark the starting position of the default text field. The default text length field can be used to indicate the total length of the data in the default text encoding scheme field and the default text data field. The default text encoding scheme field can be used to indicate the encoding scheme of the default text data field.
[0441] The random number A and MAC1 may be carried in the default text data field of the default text field of the Get Input command. The text string data field of the text string field may include a specified string (e.g., the ASCII code of "Verify"). The ASCII code of the string "Verify" may be "566572696679".
[0442] For example, the values of the fields in the Get Input command may be as follows:
[0443] The active command SIM card command mark can be "D0";
[0444] The value of the data length field can be "XX";
[0445] The value of the command details field can be "8103012311";
[0446] The value of the device identification field can be "82028122";
[0447] The value of the text string field can be "0D0E01 566572696679";
[0448] The value of the response length field can be "6102FFFF";
[0449] The value of the default text field may be "970901[Random Number A][MAC1]".
[0450] In a possible implementation, the random number A and MAC1 may also be carried in the text string data domain of the text string field of the Get Input command, which is not limited here.
[0451] S913: The second modem sends a Get Input command to the second CPU, wherein the Get Input command carries the random number A and MAC1.
[0452] After receiving the Get Input command, the CatService running on the second CPU parses the Get Input command's data structure through the CommandParamsFactory class. After the CommandParamsFactory class extracts the specified string (for example, the ASCII code for "VerifyBinding") from the text string data field of the Get Input command, the CatService can then parse the default text field in the Get Input command.
[0453] S914. The second CPU verifies MAC1 and obtains device identification 2 after MAC1 passes verification.
[0454] Catservice can call the encryption and decryption CA, and then complete the verification of MAC1 through encryption and decryption TA. Among them, the verification of MAC1 can refer to the verification process of C-MAC or R-MAC in the embodiment shown in Figure 7 above, which will not be repeated here.
[0455] After MAC1 is verified, Catservice can obtain the random number A from the default text field and provide the random number A to the encryption and decryption TA.
[0456] S915. The second CPU encrypts the device identification 2 and the random number A into verification information through ShS, and generates MAC2.
[0457] Catservice can call the encryption and decryption TA to use ShS to derive S-ENC, S-MAC, and the initial MAC chaining value to encrypt the device identifier 2 and random number A into verification information and generate MAC2. The process of encrypting the device identifier 2 and random number A and generating MAC2 can refer to the encryption and C-MAC generation process in the embodiment shown in Figure 8A above and will not be repeated here.
[0458] S916: The second CPU sends a terminal response (TerminalResponse) command 2 to the second modem, wherein the TerminalResponse command 2 carries verification information and MAC2.
[0459] S917. The second modem sends Terminal response command 2 to the eSIM module.
[0460] S918. After receiving the Terminalresponse command 2, the eSIM module verifies MAC2, and after MAC2 verification passes, decrypts the device identification 2 and random number B from the verification information through ShS.
[0461] The process of the eSIM module verifying MAC2 may refer to the process of the eSIM module verifying C-MAC in step S729 of the embodiment shown in FIG. 7 , and will not be repeated here.
[0462] S919. The eSIM module determines whether the device identification 2 is the same as the device identification 1 bound to the eSIM module and whether the random number B is the same as the random number A.
[0463] S920. If the device identification 2 is the same as the device identification 1 bound to the eSIM module and the random number B is the same as the random number A, the device-card verification is successful and the eSIM module performs mobile communication services normally.
[0464] If the device-card verification passes, the eSIM module can set the value of the binding information verification flag to the second value (for example, "0x44"). When the value of the binding information verification flag is set to the second value (for example, "0x44"), it indicates that the eSIM module has passed the device-card verification.
[0465] If the machine-card verification passes, the eSIM module can set the value of the binding information verification flag to a third value (for example, "0x66"). When the value of the binding information verification flag is set to the third value (for example, "0x66"), it indicates that the eSIM module machine-card verification has failed.
[0466] S921. If the device identification 2 is different from the device identification 1 bound to the eSIM module or the random number B is different from the random number A, the device-card verification fails and the eSIM module is prohibited from performing mobile communication services.
[0467] For example, when the eSIM module triggers the on-network authentication process, the eSIM module can determine whether the binding information check bit flag indicates that the machine-card verification has been completed and passed the machine-card verification. If the binding information check bit flag indicates that the machine-card verification has been completed and passed the machine-card verification (for example, the value of the binding information check bit flag is "0x44"), the eSIM module completes the on-network authentication process. If the binding information check bit flag indicates that the machine-card verification has not passed the machine-card verification, the eSIM module returns a verification failure response to the second modem. The verification failure response is used to indicate that the eSIM module is not the eSIM bound to the second CPU.
[0468] In the embodiment of the present application, if the machine card verification is passed, it means that the second CPU is the same CPU as the first CPU in the embodiment shown in FIG. 7 , and the first electronic device is the same as the second electronic device.
[0469] If the machine-card verification fails, it means that the second CPU is not the same CPU as the first CPU in the embodiment shown in FIG. 7 , and the second electronic device and the first electronic device are not bound to the eSIM module.
[0470] In a possible implementation, if the eSIM module does not receive verification information sent by the second CPU after sending a device identification acquisition request to the second CPU, the device-card authentication fails, and the eSIM module is prohibited from performing mobile communication services.
[0471] In one possible implementation, if the eSIM module detects that the machine-card authentication fails for more than a specified number of times (for example, 3 times), it is permanently locked.
[0472] An eSIM authentication method provided in an embodiment of the present application enables a first CPU and an eSIM module in a first electronic device to negotiate a shared key after a system upgrade or initial factory power-up, for example. The first CPU then encrypts a device identifier using the shared security key, generates binding information, and sends the binding information to the eSIM module. The eSIM module decrypts the first device identifier from the binding information using the shared security key and stores the first device identifier. When the eSIM module is powered on again or before performing a mobile communication service, the eSIM module can instruct a second CPU, currently in communication with the eSIM module, to obtain a second device identifier and encrypt the second device identifier using the shared security key to generate verification information. The eSIM module decrypts the second device identifier from the verification information using the shared key. If the second device identifier matches the first device identifier stored in the eSIM module, the eSIM module can proceed with the mobile communication service normally. If the second device identifier differs from the first device identifier stored in the eSIM module, or if the eSIM module does not receive the device verification information sent by the second CPU after powering off and then on, the eSIM module can prohibit the mobile communication service. In this way, the eSIM module in the first electronic device can be prevented from being inserted into other devices and accessing the mobile communication network after being disassembled, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0473] The following describes the structure of an execution environment of another electronic device provided in an embodiment of the present application.
[0474] FIG11 is a schematic structural diagram of an execution environment of another electronic device provided in an embodiment of the present application.
[0475] As shown in Figure 11, electronic device 100 may include a processing module, a modem, and an eSIM module. The processing module can run two application environments: a common execution environment (REE) and a trusted execution environment (TEE). The processing module can be a CPU or other module with processing functions, without limitation.
[0476] Applications running in the REE can be referred to as client applications. Client applications in the REE can include a cryptographic client application (CA). The REE can also run a local profile assistant (LPA), a device card authentication module, and a telephony management module (Telephony Manager). The device card authentication module can include a card application tool service (CatService) and a verification module. For example, the verification module can be a radio interface layer (RiL). For ease of description, the embodiments of the present application are described using the RiL as an example verification module.
[0477] Applications running in a TEE are called trusted applications (TAs). These applications can include encryption and decryption TAs, and the TEE can also manage digital certificates issued by digital certificate authorities. For example, digital certificates in a TEE can include authentication root certificates (CERT.CI.ECDSA), device certificates (CERT.DEVICE.ECDSA), and terminal certificates (CERT.OEM.ECDSA).
[0478] The LPA can invoke the device-card binding logic and send device-card binding instructions to the eSIM module. The LPA can interact with the eSIM module for device-card binding via Telephony Manager and Modem. The LPA can communicate with the encryption and decryption TA in the TEE by invoking the encryption and decryption CA, thereby invoking the encryption and decryption TA to provide encryption and decryption, certificate verification, and key negotiation services during the device-card binding interaction.
[0479] The eSIM module can invoke the device-card binding logic and send a device-card verification command to the device-card verification module via the modem, thereby triggering device-card verification interaction between the eSIM module and the device-card verification module. The device-card verification module can communicate with the encryption and decryption TA in the TEE by invoking the encryption and decryption CA, thereby invoking the encryption and decryption TA to provide encryption and decryption services during the device-card verification interaction.
[0480] Specifically, the eSIM module can call the device-card binding logic and interact with the Cat Service through the modem to verify the legitimacy of the device, thereby triggering the eSIM module to verify the legitimacy of the device (which can also be understood as verifying the legitimacy of the processing module). Among them, the Cat Service can communicate with the encryption and decryption TA in the TEE by calling the encryption and decryption CA, thereby calling the encryption and decryption TA to provide encryption and decryption services during the process of verifying the legitimacy of the device.
[0481] The verification module can call the device-card binding logic and interact with the eSIM module through the modem to verify the legitimacy of the eSIM module, thereby triggering the verification module to verify the legitimacy of the eSIM module. Possibly, the verification module can also trigger the eSIM module to verify the legitimacy of the device (which can also be understood as verifying the legitimacy of the processing module). Among them, the verification module can communicate with the encryption and decryption TA in the TEE by calling the encryption and decryption CA, thereby calling the encryption and decryption TA to provide encryption and decryption services in the process of verifying the legitimacy of the eSIM module.
[0482] For the functional description of other modules, please refer to the embodiment shown in Figure 2 above, which will not be repeated here.
[0483] Figure 12 shows a schematic diagram of the certificate chain in the TEE and eSIM modules of an electronic device provided in an embodiment of the present application.
[0484] As shown in Figure 12, the TEE can manage an authentication root certificate (CERT.CI.ECDSA) and an endpoint certificate (CERT.OEM.ECDSA). The authentication root certificate is the root certificate of the embedded UICC manufacturer (EUM) certificate in the eSIM module, and the EUM certificate is the root certificate of the eUICC certificate. In other words, the EUM certificate is signed by the private key corresponding to the authentication root certificate, and the eUICC certificate is signed by the private key corresponding to the EUM certificate.
[0485] In one possible implementation, the authentication root certificate (CERT.CI.ECDSA) can be a root certificate issued by an operator, a root certificate issued by a third-party organization, a root certificate issued by a terminal manufacturer, a root certificate issued by an EUM manufacturer, and so on.
[0486] The terminal certificate (CERT.OEM.ECDSA) can be self-signed by the OEM private key corresponding to the terminal certificate (CERT.OEM.ECDSA).
[0487] In a possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be issued directly or indirectly by a terminal manufacturer root certificate, or may be issued by an authentication root certificate.
[0488] The eSIM module can be pre-installed with an authentication root certificate (CERT.CI.ECDSA), an EUM certificate, an eUICC certificate, the EUM private key corresponding to the EUM certificate, and the eUICC private key (SK.eUICC.ECDSA) corresponding to the eUICC certificate. The authentication root certificate (CERT.CI.ECDSA) includes an authentication root public key (PK.CI.ECDSA), the EUM certificate includes an EUM public key, and the eUICC certificate includes an eUICC public key (PK.eUICC.ECDSA). The authentication root private key corresponding to the authentication root certificate (CERT.CI.ECDSA) has signed the EUM certificate. The EUM private key corresponding to the EUM certificate has signed the EUM certificate. Optionally, the eSIM module can also be pre-installed with a terminal certificate (CERT.OEM.ECDSA). In one possible implementation, the eSIM module can obtain the terminal certificate (CERT.OEM.ECDSA) through the server during an OTA upgrade after leaving the factory.
[0489] The LPA can exchange temporary working public keys with the eSIM module.
[0490] in:
[0491] (1) LPA calls TEE to verify the certificate chain of the eSIM module.
[0492] The eSIM module's certificate chain includes the authentication root certificate, EUM certificate, and eUICC certificate. The eSIM module can send the EUM and eUICC certificates to the LPA. The LPA can call the encryption and decryption CA, which in turn calls the encryption and decryption TA to verify the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate pre-installed in the TEE. If the EUM certificate's legitimacy is verified, the encryption and decryption TA can verify the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate. If the eUICC certificate's legitimacy is verified, the encryption and decryption TA can confirm that the eSIM module's certificate chain has been verified.
[0493] (2) The eSIM module can verify the terminal certificate (CERT.OEM.ECDSA).
[0494] In a possible implementation, if the terminal certificate (CERT.OEM.ECDSA) is self-signed, the eSIM module may use the OEM public key in the terminal certificate (CERT.OEM.ECDSA) to verify the legitimacy of the terminal certificate (CERT.OEM.ECDSA).
[0495] In one possible implementation, if the terminal certificate (CERT.OEM.ECDSA) is passed through the device certificate, the eSIM module can verify the legitimacy of the device certificate using the public key in the root certificate pre-installed in the eSIM module. If the legitimacy of the device certificate is verified, the eSIM module can verify the legitimacy of the terminal certificate (CERT.OEM.ECDSA) using the device public key in the device certificate.
[0496] (3) LPA calls TEE to exchange temporary working public keys with the eSIM module.
[0497] Among them, LPA calls the encryption and decryption TA in TEE to generate TEE temporary working public and private keys, among which TEE temporary working public and private keys include TEE temporary working public key (otPK.TEE.ECKA) and TEE temporary working private key (otSK.TEE.ECKA).
[0498] LPA calls the encryption and decryption TA to sign the TEE temporary working public key (otPK.TEE.ECDSA) through the OEM private key (SK.OEM.ECDSA), and sends the TEE signature data including the TEE temporary working public key (otPK.TEE.ECKA) to the eSIM module.
[0499] The eSIM module can verify the TEE signature data including the TEE temporary working public key (otPK.TEE.ECKA) through the OEM public key, and obtain the TEE temporary working public key (otPK.TEE.ECKA) after successful verification.
[0500] The eSIM module can generate eUICC temporary working public and private keys, which include the eUICC temporary working public key (otPK.eUICC.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA). The eSIM module can sign the eUICC temporary working public key (otPK.eUICC.ECKA) using the eUICC private key (SK.eUICC.ECDSA) and send the eUICC signature data including the eUICC temporary working public key (otPK.eUICC.ECKA) to the LPA.
[0501] The LPA calls the encryption and decryption TA to verify the eUICC signature data including the eUICC temporary working public key (otPK.eUICC.ECKA) through the eUICC public key (PK.eUICC.ECDSA). After successful verification, the LPA obtains the eUICC temporary working public key (otPK.TEE.ECKA).
[0502] The eSIM module can generate a shared security key (ShS) based on the TEE temporary working public key (otPK.TEE.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA).
[0503] LPA calls the encryption and decryption TA to generate a shared security key (ShS) based on the eUICC temporary working public key (otPK.eUICC.ECKA) and the TEE temporary working private key (otSK.TEE.ECKA).
[0504] Since the TEE temporary working public key (otPK.TEE.ECKA) and the TEE temporary working private key (otSK.TEE.ECKA) are a public-private key pair, and the eUICC temporary working public key (otPK.eUICC.ECKA) and the eUICC temporary working private key (otSK.eUICC.ECKA) are a public-private key pair, the eSIM module and the encryption / decryption TA can both use each other's temporary working public key and their own temporary working private key to generate the same shared security key (ShS).
[0505] In one possible implementation, for example, on an electronic device production line, after the LPA calls the encryption and decryption TA in the TEE to generate a temporary working public and private key for the TEE, the temporary working public key of the TEE can be sent directly to the other party.
[0506] In one possible implementation, the authentication root certificate (CERT.CI.ECDSA) can be a root certificate issued by an operator, a root certificate issued by a third-party organization, a root certificate issued by a terminal manufacturer, a root certificate issued by an EUM manufacturer, and so on.
[0507] In a possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be issued directly by the terminal manufacturer's root certificate or by an intermediate certificate issued by the terminal manufacturer's root certificate, or may be issued by an authentication root certificate.
[0508] In one possible implementation, the terminal certificate (CERT.OEM.ECDSA) may be self-signed.
[0509] In a possible implementation, the device manufacturer root certificate (CERT.OEMCI.ECDSA) may be pre-installed in the eSIM module before the electronic device 100 leaves the factory.
[0510] In a possible implementation, the device manufacturer root certificate (CERT.OEMCI.ECDSA) may also be issued by the server to the electronic device 100 during an OTA upgrade after the electronic device 100 leaves the factory. The processing module (eg, CPU) in the electronic device 100 is pre-installed in the eSIM module.
[0511] FIG13 shows a flow chart of one-way binding of a machine and a card in an eSIM authentication method provided in an embodiment of the present application.
[0512] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. The first processing module can run an REE and a TEE. The REE can run an LPA and a CA for encryption and decryption, and the TEE can run a TA for encryption and decryption. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 or Figures 11 and 12, and will not be repeated here.
[0513] As shown in FIG13 , the process of device-card binding may include two stages: the two parties exchange temporary working private keys and device identification binding.
[0514] Phase A1: Both parties exchange temporary working private keys.
[0515] S1301. The first processing module generates a TEE temporary working public key and a TEE temporary working private key.
[0516] The encryption and decryption TA in the TEE of the first processing module can generate a TEE temporary working public key and a TEE temporary working private key, and store the TEE temporary working public key and the TEE temporary working private key in the TEE. The TEE temporary working public key and the TEE temporary working private key are a pair of public and private keys.
[0517] S1302. The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key.
[0518] The eUICC temporary working public key and the eUICC temporary working private key are a pair of paired public and private keys.
[0519] S1303. The first processing module sends the TEE temporary working public key to the eSIM module.
[0520] The LPA in the first processing module can obtain the TEE temporary working public key from the TEE by encrypting and decrypting the CA and encrypting and decrypting the TA, and send the TEE temporary working public key to the eSIM module.
[0521] S1304. The eSIM module sends the eUICC temporary working public key to the first processing module.
[0522] The eSIM module can send the eUICC temporary working public key to the LPA. The LPA can send the eUICC temporary working public key to the encryption and decryption TA through the encryption and decryption CA.
[0523] Phase A2: Device Identity Binding
[0524] S1305. The first processing module generates a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0525] Among them, the encryption and decryption TA can generate a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0526] S1306. The eSIM module generates a shared security key (ShS) based on the eUICC temporary working private key and the TEE temporary working public key.
[0527] Since the TEE temporary working public key and TEE temporary working private key are a public-private key pair, and the eUICC temporary working public key and eUICC temporary working private key are a public-private key pair, the eSIM module and the encryption / decryption TA can both use each other's temporary working public key and their own temporary working private key to generate the same shared security key (ShS).
[0528] S1307: The first processing module obtains a device identification, where the device identification may include a chip identification and / or IMEI of the first processing module.
[0529] Among them, LPA can obtain device identification.
[0530] S1308. The first processing module encrypts the device identifier using the shared security key generated in the TEE to obtain device binding information.
[0531] The LPA can pass the device ID to the encryption / decryption TA through the encryption / decryption CA, and call the encryption / decryption TA to encrypt the device ID using the shared security key to obtain the device binding information. The encryption / decryption TA can return the device binding information to the LPA through the encryption / decryption CA.
[0532] S1309. The first processing module sends the device binding information to the eSIM module.
[0533] Among them, LPA can send the encrypted and decrypted CA to the eSIM module.
[0534] S1310. The eSIM module decrypts the device identifier from the device binding information using the shared security key generated by the eSIM module, and stores the device identifier.
[0535] The eSIM authentication method provided by this application is secure and controllable on the production line, eliminating the need for security issues such as man-in-the-middle attacks. This eliminates the need for certificate verification and signatures when exchanging temporary working public keys between the first processing module and the eSIM module, thereby completing the binding between the eSIM module and the device identifier.
[0536] FIG14 shows a schematic flow chart of bidirectional binding of a device and a card in an eSIM authentication method provided in an embodiment of the present application.
[0537] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. The first processing module can run an REE and a TEE. The REE can run an LPA and a CA for encryption and decryption, and the TEE can run a TA for encryption and decryption. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 or Figures 11 and 12, and will not be repeated here.
[0538] As shown in FIG14 , the process of device-card binding may include two stages: the two parties exchange temporary working private keys and device identification binding.
[0539] Phase B1: Both parties exchange temporary working private keys.
[0540] S1401. The first processing module generates a TEE temporary working public key and a TEE temporary working private key.
[0541] S1402. The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key.
[0542] S1403. The first processing module sends the TEE temporary working public key to the eSIM module.
[0543] S1404. The eSIM module sends the eUICC temporary working public key to the first processing module.
[0544] Phase B2: Device Identity Binding
[0545] S1405. The first processing module generates a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0546] S1406. The eSIM module generates a shared security key (ShS) based on the eUICC temporary working private key and the TEE temporary working public key.
[0547] S1407: The first processing module obtains a device identification, where the device identification may include a CPU chip identification and / or an IMEI.
[0548] S1408. The first processing module encrypts the device identifier using the shared security key generated in the TEE to obtain device binding information.
[0549] S1409. The first processing module sends the device binding information to the eSIM module.
[0550] S1410. The eSIM module decrypts the device identifier from the device binding information using the shared security key generated by the eSIM module, and stores the device identifier.
[0551] Among them, steps S1401 to S1410 may refer to steps S1301 to S1310 in the embodiment shown in FIG. 13 .
[0552] S1411. The eSIM module obtains the eSIM identifier.
[0553] The eSIM identifier may be an embedded universal integrated circuit card identifier (eUICC ID) and / or other identifiers.
[0554] S1412. The eSIM module encrypts the eSIM identifier using the shared security key generated by the eSIM module to obtain the eSIM binding information.
[0555] S1413. The eSIM module sends the eSIM binding information to the first processing module.
[0556] The eSIM module may send the eSIM binding information to the LPA of the first processing module.
[0557] S1414. The first processing module decrypts the eSIM identifier from the eSIM binding information using the shared security key generated in the TEE, and stores the eSIM identifier.
[0558] LPA can pass the eSIM binding information to the encryption and decryption TA through the encryption and decryption CA, and call the encryption and decryption TA to decrypt the eSIM identifier from the eSIM binding information using the shared security key generated in the TEE, and store the eSIM identifier in the TEE.
[0559] The eSIM authentication method provided by this application is secure and controllable on the production line, eliminating the need for security issues such as man-in-the-middle attacks. This eliminates the need for certificate verification and signatures when exchanging temporary working public keys between the first processing module and the eSIM module, thereby completing bidirectional binding between the eSIM module and the device (specifically, the first processing module).
[0560] In some embodiments, steps S1401 to S1414 in the embodiment described in FIG. 14 above can also be triggered to execute by the first processing module and the eSIM module through OTA upgrade after the electronic device leaves the factory, thereby completing the binding of the processing module and the eSIM module in the electronic device even after the electronic device has been sold.
[0561] FIG15 shows a schematic flow chart of bidirectional binding of a device and a card in an eSIM authentication method provided in an embodiment of the present application.
[0562] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. The first processing module can run an REE and a TEE. The REE can run an LPA and a CA for encryption and decryption, and the TEE can run a TA for encryption and decryption. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 or Figures 11 and 12, and will not be repeated here.
[0563] As shown in FIG15 , the process of device-card binding may include two stages: the two parties exchange temporary working private keys and device identification binding.
[0564] S1501. The first processing module can detect the first startup after leaving the factory, or the first startup after the system upgrades the machine card binding verification function.
[0565] The first processing module can detect the first power-up of the device after leaving the factory, or the first power-up after the system upgrades the device-card binding verification function, and trigger the subsequent device-card binding process. The device-card binding process can include the following three stages: mutual certificate chain verification, exchange of temporary working public keys, and bidirectional binding of the device and card.
[0566] The first electronic device can be pre-installed with a device-card binding function and a device-card verification function before leaving the factory. In this way, the first processing module in the first electronic device can be bound to the eSIM module when the first electronic device is turned on for the first time after leaving the factory. This can prevent the eSIM module of the first electronic device from being disassembled and used normally on other devices, and also prevent the first electronic device from being used normally with the eSIM module of another device.
[0567] In one possible implementation, the first electronic device can acquire the device-card binding function and the device-card verification function when performing a system upgrade through the first processing module after leaving the factory. In this way, the first processing module and the eSIM module in the already-sold electronic device can be bidirectionally bound through the system upgrade, thereby preventing the eSIM module of the already-sold first electronic device from being disassembled and used normally on other devices, and also preventing the first electronic device from being equipped with the eSIM module of another device and being used normally.
[0568] S1502. The eSIM module stores the authentication root certificate, EUM certificate, eUICC certificate, and terminal certificate.
[0569] Phase C1: Certificate chain verification phase for both parties
[0570] S1503. The eSIM module verifies the legitimacy of the terminal certificate.
[0571] For specific details, please refer to the embodiment shown in FIG12 above, which will not be described in detail here.
[0572] S1504. The eSIM sends the EUM certificate and the eUICC certificate to the first processing module.
[0573] S1505. After receiving the EUM certificate and the eUICC certificate, the first processing module may use the authentication root public key in the authentication root certificate to verify the legitimacy of the EUM certificate.
[0574] S1506. After the first processing module verifies the legitimacy of the EUM certificate, it can use the EUM public key in the EUM certificate to verify the legitimacy of the eUICC certificate.
[0575] S1507. After the legitimacy verification of the eUICC certificate passes, the first processing module sends a verification completion notification to the eSIM module.
[0576] Phase C2: Both parties exchange temporary working public keys.
[0577] S1508. After sending the verification completion notification to the eSIM module, the first processing module may generate a TEE temporary working public key and a TEE temporary working private key.
[0578] S1509. The first processing module can use the OEM private key to sign the TEE temporary working public key to obtain TEE signature data.
[0579] S1510. After receiving the verification completion notification, the eSIM module may generate an eUICC temporary working public key and an eUICC temporary working private key.
[0580] S1511. The eSIM module may use the eUICC private key to sign the eUICC temporary working public key to obtain eUICC signature data.
[0581] S1512. The first processing module can send the TEE signature data to the eSIM module.
[0582] S1513. The eSIM module may send the eUICC signature data to the first processing module.
[0583] S1514. The first processing module may verify the validity of the eUICC signature data using the eUICC public key in the eUICC certificate, and obtain the eUICC temporary working public key after the validity of the eUICC signature data is verified.
[0584] The S1515.eSIM module can verify the legitimacy of the TEE signature data through the OEM public key in the terminal certificate, and obtain the TEE temporary working public key after the legitimacy of the TEE signature data is verified.
[0585] Phase C3: Two-way binding of machine and card.
[0586] S1516. The first processing module may generate a shared security key (ShS) based on the TEE temporary working private key and the eUICC temporary working public key.
[0587] S1517. The eSIM module may generate a shared security key (ShS) based on the eUICC temporary working private key and the TEE temporary working public key.
[0588] S1518. The first processing module may obtain a device identification.
[0589] S1519. The first processing module may encrypt the device identification using a shared security key to obtain device binding information.
[0590] S1520. The first processing module may send the device binding information to the eSIM module.
[0591] S1521. The eSIM module may decrypt the device identifier from the device binding information using the shared security key generated by the eSIM module, and store the device identifier.
[0592] For steps S1505 to S1521 , reference may be made to steps S506 to S522 in the embodiment shown in FIG. 5 .
[0593] S1522. The eSIM module obtains the eSIM identifier.
[0594] S1523. The eSIM module encrypts the eSIM identifier using the shared security key to obtain the eSIM binding information.
[0595] S1524. The eSIM module sends the eSIM binding information to the first processing module.
[0596] S1525. The eSIM module decrypts the eSIM identifier from the eSIM binding information using the shared security key generated in the TEE and stores the eSIM identifier.
[0597] The above steps S1522 to S1525 can refer to steps S1411 to S1414 in the embodiment shown in FIG14 , and are not described again here.
[0598] The eSIM authentication method provided by the present application can be implemented to enable a first processing module and an eSIM module in a first electronic device to first verify the certificate exchange temporary public keys of both parties after a system upgrade or the first factory startup, and then negotiate a shared security key based on its own temporary private key and the other party's temporary public key. The first processing module encrypts the device identifier using the shared security key, generates device binding information, and sends the device binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the device binding information using the shared security key pair and store the first device identifier. The eSIM module can also encrypt the first eSIM identifier using the shared security key to generate eSIM binding information. The eSIM module can send the eSIM binding information to the first processing module. The first processing module can use the shared security key to decrypt the first eSIM identifier from the eSIM binding information and store the first device identifier in the TEE. In this way, bidirectional binding between the eSIM module and the first processing module can be completed.
[0599] Figure 16 shows a schematic flow chart of machine-card bidirectional verification in an eSIM authentication method provided in an embodiment of the present application.
[0600] The eSIM authentication method can be applied to an electronic device including a second CPU and an eSIM module. The second CPU can run a REE and a TEE. The REE can run a RiL and an encryption and decryption CA, and the TEE can run an encryption and decryption TA. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 or Figures 11 and 12, and will not be repeated here. It should be noted that the RiL is only an example and is not intended to be limiting in this application. In a specific implementation, the functions of the RiL can also be used in other modules integrated in other REEs.
[0601] As shown in Figure 16, the process of machine card verification may include the following steps:
[0602] S1601. The TEE of the second processing module stores the eSIM identifier (eSIM identifier 1) of the eSIM module.
[0603] S1602. When the eSIM module detects that it is powered on again, it can internally determine whether the eSIM module is bound to a device identifier based on the security status.
[0604] S1603. If the eSIM module is bound to a device ID (device ID 1), execute the subsequent device-card verification process.
[0605] The subsequent machine-card verification process performed by the eSIM module includes subsequent steps S1604 to S1618.
[0606] S1604. The second processing module sends an eUICC random number acquisition command to the eSIM module.
[0607] Among them, the RiL in the REE can send an eUICC random number acquisition command to the eSIM module.
[0608] S1605. The eSIM module sends the eUICC random number A to the second processing module.
[0609] The eSIM module sends the eUICC random number A to the RiL in the REE.
[0610] S1606. The second processing module obtains the device identification of the electronic device and generates a device random number C.
[0611] The RiL in the REE can obtain the device identification of the electronic device and generate a device random number C.
[0612] S1607. The second processing module may use the shared security key generated by the TEE to encrypt the device identifier, the eUICC random number A, and the device random number C to obtain verification information.
[0613] The RiL in REE can call the encryption and decryption TA in TEE through the encryption and decryption CA, and use the shared security key generated by TEE to encrypt the device identity, eUICC random number A and device random number C to obtain verification information
[0614] S1608. The second processing module sends the device verification information to the eSIM module.
[0615] S1609. The eSIM module may use the shared security key generated by the eSIM module to decrypt the device identity 2, the eUICC random number B, and the device random number D from the device verification information.
[0616] S1610. The eSIM module may determine whether the device identity 2 is the same as the device identity 1 and the eUICC random number B is the same as the eUICC random number A.
[0617] S1611. If device identity 2 is different from device identity 1 or eUICC random number B is different from eUICC random number A, the device-card verification fails and the eSIM module is prohibited from performing mobile communication services.
[0618] S1612. If device identity 2 is the same as device identity 1 and eUICC random number B is the same as eUICC random number A, the eSIM module obtains the eSIM identity.
[0619] S1613. The eSIM module uses the shared security key generated by the eSIM module to encrypt the eSIM identifier and the device random number D to obtain the eSIM verification information.
[0620] S1614. The eSIM module sends the eSIM verification information to the second processing module.
[0621] S1615. The second processing module uses the shared security key generated in the TEE to decrypt the eSIM identifier 2 and the device random number E from the eSIM verification information.
[0622] The RiL in the REE can call the encryption and decryption TA in the TEE through the encryption and decryption CA to decrypt the eSIM identifier 2 and the device random number E from the eSIM verification information.
[0623] S1616. The second processing module determines whether the eSIM identifier 2 is the same as the eSIM identifier 1 and the device random number E is the same as the device random number C.
[0624] Among them, RiL in REE can determine whether eSIM identifier 2 is the same as eSIM identifier 1 and device random number E is the same as device random number C.
[0625] S1617. If the eSIM identifier 2 is different from the eSIM identifier 1 or the device random number E is different from the device random number C, the device card verification fails and the use of the eSIM module for mobile communication services is prohibited.
[0626] In a possible implementation, the eSIM identifier 2 is different from the eSIM identifier 1 or the device random number E is different from the device random number C. The RiL in the REE may notify the modem to prohibit the use of the eSIM module for mobile communication services.
[0627] S1618. If eSIM ID 2 is the same as eSIM ID 1 and device random number E is the same as device random number C, the device card verification is passed and the eSIM module can be used normally for mobile communication services.
[0628] If the machine-card verification fails, it indicates that the second processing module is not bound to the eSIM module.
[0629] In one possible implementation, if the second processing module does not receive the eSIM verification information sent by the eSIM module after the eSIM module is powered off and then powered on, or if the eSIM module does not receive the device verification information sent by the second processing module after the eSIM module is powered off and then powered on, the machine-card verification fails.
[0630] In one possible implementation, if the second processing module fails the machine-card verification with the eSIM module, the second processing module can perform machine-card verification with the eSIM module again. If the machine-card verification fails more than a specified number of times (for example, 3 times), the second processing module and the eSIM module are permanently locked.
[0631] By implementing the eSIM authentication method provided by this application, when the eSIM module is powered on again or before a mobile communication service is to be carried out, the eSIM module can ask the second processing module communicating with the eSIM module to mutually verify the legitimacy of the other party. This can prevent the eSIM module in the electronic device from being disassembled and inserted into other devices to access the mobile communication network, and also prevent the electronic device from being connected to the mobile communication network by the disassembled eSIM module of other devices, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0632] In the embodiment of the present application, device identity 1 may be referred to as a first device identity, device identity 2 may be referred to as a second device identity, eSIM identity 1 may be referred to as a first eSIM identity, eSIM identity 2 may be referred to as a second eSIM identity, eUICC random number A may be referred to as a first eUICC random number, eUICC random number B may be referred to as a second eUICC random number, device random number C may be referred to as a first device random number, device random number E may be referred to as a second device random number, and device random number D may be referred to as a third device random number.
[0633] In the embodiments of the present application, the eUICC random number may also be referred to as the eSIM random number. Therefore, the eUICC random number A may be referred to as the first eUICC random number or the first eSIM random number, and the eUICC random number B may be referred to as the second eSIM random number. The eUICC temporary working public key may also be referred to as the eSIM temporary working public key. The eUICC temporary working private key may also be referred to as the eSIM temporary working private key.
[0634] The following describes in detail the process of one-way binding of the device and card in the eSIM authentication method provided in the embodiment of the present application in combination with signaling.
[0635] Figure 17 shows a schematic diagram of the signaling interaction process for one-way binding of the machine and card in an eSIM authentication method provided in an embodiment of the present application.
[0636] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. The first processing module can run an REE and a TEE. The REE can run an LPA and a CA for encryption and decryption, and the TEE can run a TA for encryption and decryption. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 or Figures 11 and 12, and will not be repeated here.
[0637] As shown in Figure 17, the signaling interaction process for device-card binding in the eSIM authentication method may include the following steps:
[0638] S1701. The first processing module may open a logical channel (open channel) with the eSIM module.
[0639] The LPA in the first processing module may open a logical channel with the eSIM module.
[0640] S1702. The first processing module may send an electronic identity acquisition (GetEID) command to the eSIM module.
[0641] The LPA in the first processing module may send an electronic identity acquisition command to the eSIM module.
[0642] S1703. After receiving the electronic identity acquisition command, the eSIM module may return a response command 1 to the first processing module, wherein the response command 1 carries the EID.
[0643] The eSIM module may send the response command 1 to the LPA in the first processing module.
[0644] S1704. The first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0645] The LPA in the first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0646] S1705. After receiving the eUICC random number acquisition command, the eSIM module may return a response command 2 to the first processing module. Response command 2 may carry the eUICC random number (eUICCChallenge).
[0647] The eSIM module may return a response command 2 to the LPA in the first processing module.
[0648] S1706. The first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA), a TEE temporary working private key (otSK.TEE.ECKA), a device random number (deviceChallenge) and a host identifier (HostID).
[0649] Among them, the LPA in the first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA) and a TEE temporary working private key (otSK.TEE.ECKA) by calling the encryption and decryption TA through the encryption and decryption CA.
[0650] LPA can generate a device random number (deviceChallenge) and obtain a host identifier (HostID).
[0651] S1707. The first processing module sends a store data (Storedata) command 3 to the eSIM module, where the store data command 3 carries the device random number, host identifier, and TEE temporary working public key.
[0652] Among them, the LPA in the first processing module can send a store data (Storedata) command 3 to the eSIM module.
[0653] S1708. The eSIM module generates an eUICC temporary working public key (ot.PK.EUICC.ECKA) and an eUICC temporary working private key (ot.SK.EUICC.ECKA).
[0654] S1709. The eSIM module sends a response command 5 to the first processing module, wherein the response command 5 carries the eUICC temporary working public key.
[0655] The eSIM module sends a response command 5 to the LPA in the first processing module.
[0656] S1710. The first processing module generates a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key.
[0657] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA, generate a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key, and store the shared security key in the TEE.
[0658] S1711. The first processing module obtains a device identification, wherein the device identification may include a chip identification of the first processing module.
[0659] The LPA in the first processing module may obtain the device identification.
[0660] S1712. The first processing module encrypts the device identifier and the eUICC random number into device binding information through the ShS, the host identifier and the EID, and generates a command message authentication code (C-MAC).
[0661] Among them, the LPA in the first processing module calls the encryption and decryption TA using ShS, host identifier and EID through the encryption and decryption CA, encrypts the device identifier and eUICC random number into device binding information, and generates a command message authentication code (C-MAC).
[0662] For details about the process of encrypting the device identifier and the eUICC random number into the device binding information, reference may be made to step S726 in the embodiment shown in FIG. 7 , which will not be described in detail here.
[0663] S1713: The first processing module sends a StoreData command 2 to the eSIM module, wherein the StoreData command 2 carries the device binding information and the C-MAC.
[0664] The LPA in the first processing module may send a store data command 2 to the eSIM module. For a detailed description of the store data command 2, please refer to step S727 in the embodiment shown in FIG.
[0665] S1714. The eSIM module generates a shared security key (ShS) based on the TEE temporary working public key and the eUICC temporary working private key.
[0666] S1715. After receiving the Storedata command 2, the eSIM module can verify the C-MAC through the ShS, host identifier and EID, decrypt the binding information, obtain the device identifier and eUICC random number, and verify the decrypted eUICC random number.
[0667] S1716. After the eSIM module verifies the eUICC random number decrypted from the binding information, it encrypts the device random number into eUICC encrypted data using the shared security key, host identity, and EID, and generates a response message authentication code (R-MAC).
[0668] S1717. The eSIM module may send a response command 4 to the first processing module. Response command 4 may carry the eUICC encrypted data and R-MAC.
[0669] S1718. The first processing module verifies the R-MAC through the ShS, host identifier, and EID, decrypts the device random number from the eUICC encrypted data, and verifies the decrypted device random number.
[0670] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA, use ShS, host identification and EID to verify R-MAC, and decrypt the device random number from the eUICC encrypted data, and verify the decrypted device random number
[0671] S1719: After the first processing module verifies the decrypted device random number, it sends a StoreData command 3 to the eSIM module. The StoreData command 3 is used to indicate the end of the device-card binding interaction.
[0672] S1720. After receiving the Storedata command 3, the eSIM module sets the device binding state to the bound state and stores the device identification.
[0673] S1721. The eSIM module returns a binding completion status code to the first CPU. The binding completion status code is used to indicate that the device-card binding is complete.
[0674] For the specific description of steps S1714 to S1721, please refer to steps S728 to S735 in the embodiment shown in Figure 7 above, and will not be repeated here.
[0675] The eSIM authentication method provided by this application is secure and controllable on the production line, eliminating the need for security issues such as man-in-the-middle attacks. This eliminates the need for certificate verification and signatures when exchanging temporary working public keys between the first processing module and the eSIM module, thereby completing the binding between the eSIM module and the device identifier.
[0676] Figure 18 shows a schematic diagram of the signaling interaction process for bidirectional binding of machine and card in an eSIM authentication method provided in an embodiment of the present application.
[0677] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. The first processing module can run an REE and a TEE. The REE can run an LPA and a CA for encryption and decryption, and the TEE can run a TA for encryption and decryption. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 or Figures 11 and 12, and will not be repeated here.
[0678] As shown in Figure 18, the signaling interaction process for device-card binding in the eSIM authentication method may include the following steps:
[0679] S1801. The first processing module may open a logical channel (open channel) with the eSIM module.
[0680] The LPA in the first processing module may open a logical channel with the eSIM module.
[0681] S1802. The first processing module may send an electronic identity acquisition (GetEID) command to the eSIM module.
[0682] The LPA in the first processing module may send an electronic identity acquisition command to the eSIM module.
[0683] S1803. After receiving the electronic identity acquisition command, the eSIM module may return a response command 1 to the first processing module, wherein the response command 1 carries the EID.
[0684] The eSIM module may send the response command 1 to the LPA in the first processing module.
[0685] S1804. The first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0686] The LPA in the first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0687] S1805. After receiving the eUICC random number acquisition command, the eSIM module may return a response command 2 to the first processing module. Response command 2 may carry the eUICC random number (eUICCChallenge).
[0688] The eSIM module may return a response command 2 to the LPA in the first processing module.
[0689] S1806. The first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA), a TEE temporary working private key (otSK.TEE.ECKA), a device random number (deviceChallenge) and a host identifier (HostID).
[0690] Among them, the LPA in the first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA) and a TEE temporary working private key (otSK.TEE.ECKA) by calling the encryption and decryption TA through the encryption and decryption CA.
[0691] LPA can generate a device random number (deviceChallenge) and obtain a host identifier (HostID).
[0692] S1807. The first processing module sends a store data (Storedata) command 3 to the eSIM module, where the store data command 3 carries the device random number, host identifier, and TEE temporary working public key.
[0693] Among them, the LPA in the first processing module can send a store data (Storedata) command 3 to the eSIM module.
[0694] S1808. The eSIM module generates an eUICC temporary working public key (ot.PK.EUICC.ECKA) and an eUICC temporary working private key (ot.SK.EUICC.ECKA).
[0695] S1809. The eSIM module sends a response command 5 to the first processing module, wherein the response command 5 carries the eUICC temporary working public key.
[0696] The eSIM module sends a response command 5 to the LPA in the first processing module.
[0697] S1810. The first processing module generates a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key.
[0698] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA, generate a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key, and store the shared security key in the TEE.
[0699] S1811. The first processing module obtains a device identification, wherein the device identification may include a chip identification of the first processing module.
[0700] The LPA in the first processing module may obtain the device identification.
[0701] S1812. The first processing module encrypts the device identifier and the eUICC random number into device binding information through the ShS, the host identifier and the EID, and generates a command message authentication code (C-MAC).
[0702] Among them, the LPA in the first processing module calls the encryption and decryption TA using ShS, host identifier and EID through the encryption and decryption CA, encrypts the device identifier and eUICC random number into device binding information, and generates a command message authentication code (C-MAC).
[0703] For details about the process of encrypting the device identifier and the eUICC random number into the device binding information, reference may be made to step S726 in the embodiment shown in FIG. 7 , which will not be described in detail here.
[0704] S1813: The first processing module sends a StoreData command 2 to the eSIM module, wherein the StoreData command 2 carries device binding information and C-MAC.
[0705] The LPA in the first processing module may send a store data command 2 to the eSIM module. For a detailed description of the store data command 2, please refer to step S727 in the embodiment shown in FIG.
[0706] S1814. The eSIM module generates a shared security key (ShS) based on the TEE temporary working public key and the eUICC temporary working private key.
[0707] S1815. After receiving the Storedata command 2, the eSIM module can verify the C-MAC through the ShS, host identifier and EID, decrypt the binding information, obtain the device identifier and eUICC random number, and verify the decrypted eUICC random number.
[0708] S1816. After the eSIM module verifies the eUICC random number decrypted from the binding information, it encrypts the device random number and eSIM identity into eSIM binding information using the shared security key, host identity, and EID, and generates a response message authentication code (R-MAC).
[0709] S1817. The eSIM module may send a response command 4 to the first processing module. Response command 4 may carry the eSIM binding information and R-MAC.
[0710] For the specific steps of encrypting the eSIM binding information, reference may be made to the encryption process of the eUICC encrypted data in the embodiment described in FIG. 7 , which will not be described in detail here.
[0711] S1818. The first processing module verifies the R-MAC through the ShS, host identifier, and EID, decrypts the device random number and eSIM identifier from the eSIM binding information, and verifies the decrypted device random number.
[0712] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA, use the ShS, host identifier and EID to verify the R-MAC, and decrypt the device random number and eSIM identifier from the eSIM binding information, and verify the decrypted device random number.
[0713] For the decryption process of the eSIM binding information, reference may be made to the eUICC decryption process in the embodiment shown in FIG. 7 , which will not be described in detail here.
[0714] S1819. After the first processing module verifies the decrypted device random number, it stores the eSIM identifier in the TEE.
[0715] Among them, the LPA in the first processing module can call the encryption and decryption TA through the encryption and decryption CA to store the eSIM identity in the TEE.
[0716] S1820: The first processing module sends a store data (Storedata) command 3 to the eSIM module, wherein the Storedata command 3 is used to indicate the end of the device-card binding interaction.
[0717] S1821. After receiving the Storedata command 3, the eSIM module sets the device binding state to the bound state and stores the device identification.
[0718] S1822. The eSIM module returns a binding completion status code to the first CPU. The binding completion status code is used to indicate that the device-card binding is complete.
[0719] For the specific description of steps S1820 to S1822, please refer to steps S733 to S735 in the embodiment shown in Figure 7 above, and will not be repeated here.
[0720] The eSIM authentication method provided by this application is secure and controllable on the production line, eliminating the need for security issues such as man-in-the-middle attacks. This eliminates the need for certificate verification and signatures when exchanging temporary working public keys between the first processing module and the eSIM module, thereby completing bidirectional binding between the eSIM module and the device (specifically, the first processing module).
[0721] FIG19 shows a schematic diagram of the signaling interaction process for bidirectional binding of a device and a card in an eSIM authentication method provided in another embodiment of the present application.
[0722] The eSIM authentication method can be applied to a first electronic device including a first processing module and an eSIM module. The first processing module can run an REE and a TEE. The REE can run an LPA and a CA for encryption and decryption, and the TEE can run a TA for encryption and decryption. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 or Figures 11 and 12, and will not be repeated here.
[0723] As shown in Figure 19, the signaling interaction process for device-card binding in the eSIM authentication method may include the following steps:
[0724] S1901. The first processing module detects that the ROM upgrade is completed.
[0725] S1902. The eSIM module detects that the patch upgrade is complete.
[0726] S1903. The eSIM module may send a refresh command to the first modem.
[0727] S1904. The first modem powers on the eSIM module.
[0728] S1905. After powering on the eSIM module, the first modem sends a reset command to the eSIM module.
[0729] S1906. The eSIM module can detect that the eSIM module has not completed the device-card binding.
[0730] S1907. The eSIM module may send an answer to reset (ATR) to the first modem.
[0731] S1908. The first processing module may open a logical channel (open channel) with the eSIM module.
[0732] S1909. The first processing module may send an electronic identity acquisition (GetEID) command to the eSIM module.
[0733] S1910. After receiving the electronic identity acquisition command, the eSIM module may return a response command 1 to the first processing module, wherein the response command 1 carries the EID.
[0734] S1911. The first processing module may send an eUICC random number acquisition (GeteUICCChallenge) command to the eSIM module.
[0735] S1912. After receiving the eUICC random number acquisition command, the eSIM module may return a response command 2 to the first processing module. Response command 2 may carry the eUICC random number (eUICCChallenge).
[0736] S1913. The first processing module can generate a TEE temporary working public key (otPK.TEE.ECKA), a TEE temporary working private key (otSK.TEE.ECKA), a device random number (deviceChallenge) and a host identifier (HostID).
[0737] S1914. The first processing module may generate TEE package data, wherein the TEE package data includes a TEE temporary working public key, a device random number, an eUICC random number, and a host identifier.
[0738] S1915. The first processing module can use the TEE private key (SK.TEE.ECKA) to sign the TEE package data and obtain the TEE signature value (serverSignature).
[0739] LPA can call the encryption and decryption CA, and through the encryption and decryption CA, call the encryption and decryption TA to sign the TEE package data with the TEE private key (SK.TEE.ECDSA) to obtain the TEE signature value (serverSignature).
[0740] In one possible implementation, the TEE private key (SK.TEE.ECDSA) may be the OEM private key (SK.OEM.ECDSA) corresponding to the terminal certificate (CERT.OEM.ECDSA) in the aforementioned embodiment, and the TEE public key (PK.TEE.ECDSA) paired with the TEE private key (SK.TEE.ECDSA) may be the OEM public key (PK.OEM.ECDSA) in the terminal certificate (CERT.OEM.ECDSA) in the aforementioned embodiment.
[0741] S1916. The first processing module may send a store data command 1 to the eSIM module. The store data command 1 may carry TEE signature data, which may include TEE package data and a TEE signature value.
[0742] S1917. After receiving the store data command 1, the eSIM module can verify the TEE signature value and eUICC random number in the TEE signature data through the TEE public key (PK.TEE.ECDSA) stored in the TEE certificate.
[0743] After the TEE signature value and eUICC random number are verified, the S1918.eSIM module can generate the eUICC temporary working public key (ot.PK.EUICC.ECKA) and eUICC temporary working private key (ot.SK.EUICC.ECKA).
[0744] S1919. The eSIM module may generate eUICC packaging data, wherein the eUICC packaging data may include an eUICC temporary working public key and a device random number (deviceChallenge).
[0745] S1920.eSIM module can use the eUICC private key (SK.eUICC.ECDSA) to sign the eUICC package data and obtain the eUICC signature value.
[0746] S1921. The eSIM module may send a response command 3 to the first CPU. Response command 3 may include the eUICC signature data, the EUM certificate (CERT.EUM.ECDSA), and the eUICC certificate (CERT.eUICC.ECDSA).
[0747] S1922. After receiving the response command 3, the first processing module can verify the legitimacy of the EUM certificate and the eUICC certificate through the authentication root public key (PK.CI.ECDSA) in the stored authentication root certificate.
[0748] S1923. After verifying the legitimacy of the EUM certificate and the eUICC certificate, the first processing module may verify the device random number and the eUICC signature value using the eUICC public key in the eUICC certificate.
[0749] S1924. After the device random number and the eUICC signature value are verified, the first processing module generates a shared security key (ShS) based on the eUICC temporary working public key and the TEE temporary working private key.
[0750] For the detailed description of steps S1901 to S1924, reference may be made to steps S701 to S724 in the embodiment shown in FIG. 7 .
[0751] S1925: The first processing module may obtain a device identifier, wherein the device identifier may include a chip identifier (ChipID) and / or an IMEI of the first processing module, etc.
[0752] S1926. The first processing module may encrypt the device identifier and the eUICC random number into device binding information through the ShS, the host identifier, and the EID, and generate a command message authentication code (C-MAC).
[0753] S1927: The first processing module may send a store data command 2 to the eSIM module. The store data command 2 may carry device binding information and C-MAC.
[0754] S1928. After sending response command 3 to the first processing module, the eSIM module may generate ShS based on the TEE temporary working public key and the eUICC temporary working private key.
[0755] S1929. After receiving the Storedata command 2, the eSIM module can verify the C-MAC through ShS, host identification and EID, decrypt the device binding information, obtain the device identification and eUICC random number, and verify the decrypted eUICC random number.
[0756] S1930. After the eSIM module verifies the eUICC random number decrypted from the binding information, it encrypts the device random number and eSIM identity into eSIM binding information using the shared security key, host identity, and EID, and generates a response message authentication code (R-MAC).
[0757] S1931. The eSIM module may send a response command 4 to the first processing module. Response command 4 may carry the eSIM binding information and R-MAC.
[0758] S1932. The first processing module verifies the R-MAC through the ShS, host identifier and EID, decrypts the device random number and eSIM identifier from the eSIM binding information, and verifies the decrypted device random number.
[0759] S1933. After the first processing module verifies the decrypted device random number, it stores the eSIM identifier in the TEE.
[0760] S1934. After the first processing module verifies the decrypted device random number, it sends a StoreData command 3 to the eSIM module. The StoreData command 3 is used to indicate the end of the device-card binding interaction.
[0761] S1935. After receiving the Storedata command 3, the eSIM module sets the device binding state to the bound state and stores the device identification.
[0762] S1936. The eSIM module returns a binding completion status code to the first processing module. The binding completion status code is used to indicate that the device-card binding is complete.
[0763] For the specific description of steps S1925 to S1936, please refer to steps S1811 to S1822 in the embodiment shown in Figure 18 above.
[0764] The eSIM authentication method provided by the present application can be implemented so that a first processing module and an eSIM module in a first electronic device can verify the certificate and exchange temporary public keys before the first electronic device is on the production line before leaving the factory, during a system upgrade after the first electronic device is sold, or when the first electronic device is powered on for the first time after leaving the factory. The first processing module then negotiates a shared security key based on its own temporary private key and the other party's temporary public key. The first processing module encrypts the device identifier using the shared security key, generates device binding information, and sends the device binding information to the eSIM module. The eSIM module can decrypt the first device identifier from the device binding information using the shared security key pair and store the first device identifier. The eSIM module can also encrypt the first eSIM identifier using the shared security key to generate eSIM binding information. The eSIM module can send the eSIM binding information to the first processing module. The first processing module can use the shared security key to decrypt the first eSIM identifier from the eSIM binding information and store the first device identifier in the TEE. In this way, bidirectional binding between the eSIM module and the first processing module is completed.
[0765] Figure 20 shows a schematic flow chart of machine-card bidirectional verification in an eSIM authentication method provided in an embodiment of the present application.
[0766] The eSIM authentication method can be applied to an electronic device including a second CPU and an eSIM module. The second CPU can run a REE and a TEE. The REE can run a RiL and an encryption and decryption CA, and the TEE can run an encryption and decryption TA. For a detailed description of the REE and TEE, please refer to the embodiments shown in Figures 2-4 or Figures 11 and 12, and will not be repeated here. It should be noted that the RiL is only an example and is not intended to be limiting in this application. In a specific implementation, the functions of the RiL can also be used in other modules integrated in other REEs.
[0767] As shown in Figure 20, the process of machine card verification may include the following steps:
[0768] S2001. The second processing module detects that the ROM upgrade is completed.
[0769] S2002. The second processing module detects the bound eSIM ID 1.
[0770] S2003. The eSIM module sends a refresh command to the second modem.
[0771] The refresh command may be a proactive command.
[0772] S2004. The second modem powers on the eSIM module.
[0773] The second modem may re-power on the eSIM module after receiving the eSIM module.
[0774] S2005. After powering on the eSIM module, the second modem sends a reset command to the eSIM module.
[0775] S2006. The eSIM module can detect that the eSIM module has completed the device-card binding.
[0776] After receiving the reset command, the eSIM module can complete the reset operation and detect that the machine-card binding has been completed through the binding device mark.
[0777] S2007. The eSIM module may send the ATR to the second processing module via the second modem.
[0778] The ATR indicates that the eSIM module reset is complete.
[0779] S2008. The second processing module sends an eUICC random number acquisition command to the eSIM module.
[0780] Among them, the RiL in the REE can send an eUICC random number acquisition command to the eSIM module.
[0781] S2009. The eSIM module sends the eUICC random number A to the second processing module.
[0782] The eSIM module sends the eUICC random number A to the RiL in the REE.
[0783] S2010. The second processing module obtains the device identification and the device random number C of the electronic device.
[0784] The RiL in the REE can be the device identifier of the electronic device and the device random number C.
[0785] S2011. The second processing module may use the shared security key generated by the TEE to encrypt the device identifier, the eUICC random number A, and the device random number C to obtain verification information.
[0786] The RiL in REE can call the encryption and decryption TA in TEE through the encryption and decryption CA, and use the shared security key generated by TEE to encrypt the device identity, eUICC random number A and device random number C to obtain verification information
[0787] S2012. The second processing module sends the device verification information to the eSIM module.
[0788] S2013. The eSIM module may use the shared security key generated by the eSIM module to decrypt the device identification 2, the eUICC random number B, and the device random number D from the device verification information.
[0789] S2014. The eSIM module may determine whether the device identity 2 is the same as the device identity 1 and the eUICC random number B is the same as the eUICC random number A.
[0790] S2015. If the device identity 2 is different from the device identity 1 or the eUICC random number B is different from the eUICC random number A, the device-card authentication fails and the eSIM module is prohibited from performing mobile communication services.
[0791] S2016. If the device identity 2 is the same as the device identity 1 and the eUICC random number B is the same as the eUICC random number A, the eSIM module obtains the eSIM identity.
[0792] S2017. The eSIM module uses the shared security key generated by the eSIM module to encrypt the eSIM identifier and the device random number D to obtain the eSIM verification information.
[0793] S2018. The eSIM module sends the eSIM verification information to the second processing module.
[0794] S2019. The second processing module uses the shared security key generated in the TEE to decrypt the eSIM identifier 2 and the device random number E from the eSIM verification information.
[0795] The RiL in the REE can call the encryption and decryption TA in the TEE through the encryption and decryption CA to decrypt the eSIM identifier 2 and the device random number E from the eSIM verification information.
[0796] S2020. The second processing module determines whether the eSIM identifier 2 is the same as the eSIM identifier 1 and the device random number E is the same as the device random number C.
[0797] Among them, RiL in REE can determine whether eSIM identifier 2 is the same as eSIM identifier 1 and device random number E is the same as device random number C.
[0798] S2021. If eSIM ID 2 is different from eSIM ID 1 or device random number E is different from device random number C, the device card verification fails and the use of the eSIM module for mobile communication services is prohibited.
[0799] In a possible implementation, the eSIM identifier 2 is different from the eSIM identifier 1 or the device random number E is different from the device random number C. The RiL in the REE may notify the modem to prohibit the use of the eSIM module for mobile communication services.
[0800] S2022. If eSIM ID 2 is the same as eSIM ID 1 and device random number E is the same as device random number C, the device card verification is passed and the eSIM module can be used normally for mobile communication services.
[0801] If the machine-card verification fails, it indicates that the second processing module is not bound to the eSIM module.
[0802] In one possible implementation, if the second processing module does not receive the eSIM verification information sent by the eSIM module after the eSIM module is powered off and then powered on, or if the eSIM module does not receive the device verification information sent by the second processing module after the eSIM module is powered off and then powered on, the machine-card verification fails.
[0803] In one possible implementation, if the second processing module fails the machine-card verification with the eSIM module, the second processing module can perform machine-card verification with the eSIM module again. If the machine-card verification fails more than a specified number of times (for example, 3 times), the second processing module and the eSIM module are permanently locked.
[0804] By implementing the eSIM authentication method provided by this application, when the eSIM module is powered on again or before a mobile communication service is to be carried out, the eSIM module can ask the second processing module communicating with the eSIM module to mutually verify the legitimacy of the other party. This can prevent the eSIM module in the electronic device from being disassembled and inserted into other devices to access the mobile communication network, and also prevent the electronic device from being connected to the mobile communication network by the disassembled eSIM module of other devices, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0805] In some embodiments, an eSIM authentication method is applied to an electronic device including a processing module and a second eSIM module, the method including: a first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module; the second eSIM module obtains the second eSIM identifier of the second eSIM module after power is off and then on; the second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; the second eSIM module sends the eSIM verification information to the processing module; the processing module decrypts the second eSIM identifier from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module uses the second eSIM module normally for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then on, the processing module prohibits the use of the second eSIM module for mobile communication services.
[0806] An eSIM authentication method provided in an embodiment of the present application enables a processing module and a first eSIM module in an electronic device to first negotiate a shared key. The first eSIM module then encrypts an eSIM identifier using the shared security key to generate eSIM binding information, which is then sent to the processing module. The processing module can decrypt the first eSIM identifier from the eSIM binding information using the shared security key pair and store the first eSIM identifier. When the eSIM module is powered on again or before mobile communication services are to be performed, the processing module can instruct a second eSIM module currently communicating with the processing module to obtain a second eSIM identifier, encrypt the second eSIM identifier using the shared security key, and generate eSIM verification information. The processing module can decrypt the second eSIM identifier from the eSIM verification information using the shared security key. If the second eSIM identifier is identical to the first eSIM identifier stored in the processing module's TEE, this indicates that the second eSIM module and the first eSIM module bound to the processing module are the same eSIM module, and the processing module can therefore perform mobile communication services normally. If the second eSIM identifier is different from the first eSIM identifier stored in the processing module's TEE, or if the processing module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on again, it indicates that the second eSIM module is not the same as the first eSIM module bound to the processing module. Therefore, the processing module can prohibit the use of the second eSIM for mobile communication services. This can prevent the eSIM module in the electronic device from being disassembled and inserted into other devices to access the mobile communication network, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0807] In one possible implementation, before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: the processing module receiving eSIM binding information sent by the first eSIM module; after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
[0808] In one possible implementation, after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: after receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the processing module.
[0809] In one possible implementation, after receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: after receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
[0810] In one possible implementation, before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: generating, by the processing module, a TEE temporary working public key and a TEE temporary working private key through the TEE; receiving, by the processing module, the eUICC temporary working public key generated by the first processing module; and generating, by the processing module, a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
[0811] In one possible implementation, before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: receiving, by the processing module, TEE signature data sent by the first processing module; verifying, by the processing module, the legitimacy of the eUICC signature data using the eUICC public key in the eUICC certificate; and receiving, by the processing module, the eUICC temporary working public key sent by the first eSIM module, specifically including: obtaining, by the processing module, the eUICC temporary working public key from the eUICC signature data after successfully verifying the legitimacy of the eUICC signature data.
[0812] In one possible implementation, before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: the processing module receiving the EUM certificate and the eUICC certificate sent by the first eSIM module; the processing module verifying the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; after successfully verifying the legitimacy of the EUM certificate, the processing module verifying the legitimacy of the eUICC certificate using the EUM public key in the EUM certificate; and after successfully verifying the legitimacy of the eUICC certificate, the processing module obtaining the eUICC public key from the eUICC certificate.
[0813] In one possible implementation, the method further includes: the processing module generating the TEE temporary working private key and the TEE temporary working public key in the TEE, where the TEE temporary working private key and the TEE temporary working public key form a public-private key pair; the processing module signing the TEE temporary working public key using the TEE private key to obtain TEE signature data; and the processing module sending the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, where the eUICC temporary working private key and the eUICC temporary working public key form a public-private key pair.
[0814] In one possible implementation, before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: after detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier to form the eSIM verification information.
[0815] In a possible implementation, the method further includes: decrypting, by the processing module, a second device random number from the eSIM verification information; if the second eSIM identifier is the same as the first eSIM identifier, the processing module normally using the second eSIM module for mobile communication services, specifically including: if the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally using the second eSIM module for mobile communication services.
[0816] For details, the process of binding and verifying the processing module and the eSIM module can be referred to the aforementioned embodiment and will not be repeated here.
[0817] In some embodiments, an eSIM authentication method provided in the embodiments of the present application can be applied to an electronic device including a second processing module and a second eSIM module, the method comprising: the first eSIM identifier sent by the first eSIM module is stored in the TEE of the second processing module; the first device identifier sent by the first processing module is stored in the second eSIM module; after the second eSIM module is powered off and then powered on again, the second eSIM module obtains the second eSIM identifier of the second eSIM module; the second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; the second eSIM module sends the eSIM verification information to the second processing module; the second processing module obtains the second device identifier and encrypts the second device identifier to obtain device verification information; the second processing module A second eSIM identifier is decrypted from the eSIM verification information; the second eSIM module decrypts a second device identifier from the device verification information; if the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier, the electronic device can normally use the second eSIM module for mobile communication services; if the second eSIM identifier is different from the first eSIM identifier or the second device identifier is different from the first device identifier or the second processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, the electronic device is prohibited from using the second eSIM module for mobile communication services.
[0818] Through an eSIM authentication method provided in an embodiment of the present application, the second processing module is legally bound to the first eSIM module. Therefore, the TEE of the second processing module stores the first eSIM identifier of the first eSIM module and the shared security key negotiated with the first eSIM module. The second eSIM module is legally bound to the first processing module. Therefore, the second eSIM module stores the first device identifier of the first processing module and the shared security key negotiated with the first processing module. When the second processing module cooperates with the second eSIM module, if the second eSIM module is powered on or before performing mobile communication services, the second processing module can obtain the second device identifier of the second processing module and use the shared security key to encrypt the second device identifier into device verification information and send it to the second eSIM module. The second eSIM module can also obtain the second eSIM identifier of the second eSIM module and use the shared security key to encrypt the second eSIM identifier into eSIM verification information and send it to the second processing module. The second processing module can decrypt the second eSIM identifier from the eSIM verification information using the shared security key. The second eSIM module can also decrypt the second device identifier from the device verification information using the shared security key. If the second eSIM identifier is identical to the first eSIM identifier stored in the processing module's TEE, and the second device identifier is identical to the first device identifier, then the second eSIM module and the second processing module are bound to each other. Therefore, the second processing module can normally use the second eSIM module for mobile communication services. If the second eSIM identifier is different from the first eSIM identifier stored in the processing module's TEE, or the second device identifier is different from the first device identifier, or the second processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information sent by the second processing module after the second eSIM module is powered off and then powered on, then the second eSIM module and the second processing module are not bound to each other. Therefore, the second processing module can prohibit the use of the second eSIM module for mobile communication services. This prevents the eSIM module from being disassembled from the electronic device and then inserted into another device to access the mobile communication network, thereby improving the security of the eSIM module when accessing the mobile communication network.
[0819] For details, the process of binding and verifying the processing module and the eSIM module can be referred to the aforementioned embodiment and will not be repeated here.
[0820] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. An embedded user identification eSIM authentication method, characterized in that: Applied to the eSIM module, the method includes: The eSIM module stores the first device identification sent by the first processing module; After detecting that the power is off and then on, the eSIM module receives the device verification information sent by the second processing module; The eSIM module decrypts the second device identifier from the device verification information; If the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally; If the first device identifier is different from the second device identifier or the eSIM module does not receive the device verification information sent by the second processing module after detecting power failure and power-on, the eSIM module is prohibited from performing mobile communication services.
2. The method according to claim 1, characterized in that Before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: The eSIM module receives the device binding information sent by the first processing module; After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information and stores the first device identifier.
3. The method according to claim 2, characterized in that After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information, specifically including: After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information using the shared security key generated by the eSIM module.
4. The method according to any one of claims 1 to 3, characterized in that After receiving the device verification information, the eSIM module decrypts the second device identifier from the device verification information, specifically including: After receiving the device verification information, the eSIM module decrypts the second device identifier from the verification information using the shared security key generated by the eSIM module.
5. The method according to any one of claims 3 or 4, characterized in that Before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key; The eSIM module receives the TEE temporary working public key generated by the first processing module; The eSIM module generates a shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
6. The method according to claim 5, characterized in that Before the eSIM module receives the TEE temporary working public key sent by the first processing module, the method further includes: The eSIM module receives the TEE signature data sent by the first processing module; The eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; The eSIM module receives the TEE temporary working public key sent by the first processing module, specifically including: After verifying the legitimacy of the TEE signature data, the eSIM module obtains the TEE temporary working public key from the TEE signature data.
7. The method according to claim 6, characterized in that Before the eSIM module receives the TEE signature data sent by the first processing module, the method further includes: The eSIM module verifies the legitimacy of the TEE certificate; After verifying the legitimacy of the TEE certificate, the eSIM module obtains the TEE public key from the TEE certificate.
8. The method according to claim 7, characterized in that The TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
9. The method according to claim 7, characterized in that: The TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; Before the eSIM module verifies the legitimacy of the TEE certificate, the method further includes: The eSIM module receives the TEE certificate sent by the first processing module; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the device certificate using the terminal manufacturer's root public key in the terminal manufacturer's root certificate; After verifying the legitimacy of the device certificate, the eSIM module uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
10. The method according to claim 7, characterized in that The TEE certificate is a terminal manufacturer root certificate, and the terminal manufacturer root certificate is pre-set in the eSIM module; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal manufacturer's root certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
11. The method according to any one of claims 7 to 10, characterized in that: The method further comprises: The eSIM module generates the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key are a pair of public and private keys; The eSIM module signs the eUICC temporary working public key by using the eUICC private key to obtain eUICC signature data; The eSIM module sends the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key, and generate a shared security key based on the eUICC temporary working public key and the TEE temporary working private key, wherein the TEE temporary working private key and the TEE temporary working public key are a pair of public-private keys.
12. The method according to claim 11, characterized in that The method further comprises: The eSIM module sends the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by the EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes the eUICC public key, the eUICC public key and the eUICC private key are a pair of public and private keys, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
13. The method according to any one of claims 1 to 12, characterized in that The first device identifier is a chip identifier of the first processing module, and the second device identifier is a chip identifier of the second processing module; or, The first device identifier is the International Mobile Equipment Identity (IMEI) of the first processing module, and the second device identifier is the IMEI of the second processing module; or, The first device identifier is a chip identifier of the first processing module and an IMEI of the first processing module, and the second device identifier is a chip identifier of the second processing module and an IMEI of the second processing module.
14. The method according to any one of claims 1 to 13, characterized in that After detecting that the power is off and then on, the eSIM module receives the device verification information sent by the second processing module, specifically including: After detecting power failure and then power on, the eSIM module sends a first request to the second processing module, where the first request is used to request the second processing module to send a device identification to the eSIM module.
15. The method according to claim 14, characterized in that The first request includes a first eUICC random number, and the first eUICC random number is used to be encrypted by the second processing module together with the second device identifier into the device verification information.
16. The method according to claim 15, characterized in that The method further comprises: The eSIM module decrypts a second eUICC random number from the device verification information; If the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally, specifically including: If the first device identifier is the same as the second device identifier and the second eUICC random number is the same as the first eUICC random number, the eSIM module performs the mobile communication service normally.
17. The method according to claim 14 or 15, characterized in that The first request is a Get Input command.
18. The method according to claim 2, characterized in that The eSIM module receives the device binding information sent by the first processing module, specifically including: The eSIM module receives the device binding information sent by the first processing module through a store data Storedata command.
19. An eSIM authentication method, characterized in that: Applied to an electronic device including an eSIM module and a second processing module, the method includes: The eSIM module stores the first device identification sent by the first processing module; After detecting that power is off and then on, the eSIM module sends a first request to the second processing module, where the first request is used to request the second processing module to send a device identification to the eSIM module; The second processing module obtains a second device identifier; The second processing module encrypts the second device identification to obtain device verification information; The second processing module sends the device verification information to the eSIM module; The eSIM module decrypts the second device identifier from the device verification information; If the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally; If the first device identifier is different from the second device identifier or the eSIM module does not receive the device verification information sent by the second processing module after detecting power failure and power-on, the eSIM module prohibits mobile communication services.
20. The method according to claim 19, characterized in that Before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: The eSIM module receives the device binding information sent by the first processing module; After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information and stores the first device identifier.
21. The method according to claim 20, characterized in that After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information, specifically including: After receiving the device binding information, the eSIM module decrypts the first device identifier from the device binding information using a shared security key.
22. The method according to any one of claims 19 to 21, characterized in that After receiving the verification information, the eSIM module decrypts the second device identifier from the device verification information, specifically including: After receiving the device verification information, the eSIM module decrypts the second device identifier from the verification information using a shared security key.
23. The method according to claim 21 or 22, characterized in that Before the eSIM module stores the first device identifier sent by the first processing module, the method further includes: The eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key; The eSIM module receives the TEE temporary working public key generated by the first processing module; The eSIM module generates the shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
24. The method according to claim 23, characterized in that Before the eSIM module receives the TEE temporary working public key generated by the first processing module, the method further includes: The eSIM module receives the TEE signature data sent by the first processing module; The eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; The eSIM module receives the TEE temporary working public key generated by the first processing module, specifically including: After verifying the legitimacy of the TEE signature data, the eSIM module obtains the TEE temporary working public key from the TEE signature data.
25. The method according to claim 24, characterized in that Before the eSIM module receives the TEE signature data sent by the first processing module, the method further includes: The eSIM module verifies the legitimacy of the TEE certificate; After verifying the legitimacy of the TEE certificate, the eSIM module obtains the TEE public key from the TEE certificate.
26. The method according to claim 25, characterized in that The TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
27. The method according to claim 26, characterized in that The TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
28. The method according to claim 26, characterized in that The TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; Before the eSIM module verifies the legitimacy of the TEE certificate, the method further includes: The eSIM module receives the TEE certificate sent by the first processing module; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the device certificate using the terminal manufacturer's root public key in the terminal manufacturer's root certificate; After verifying the legitimacy of the device certificate, the eSIM module uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
29. The method according to claim 26, characterized in that The TEE certificate is a terminal manufacturer root certificate, and the terminal manufacturer root certificate is pre-set in the eSIM module; The eSIM module verifies the legitimacy of the TEE certificate, specifically including: The eSIM module verifies the legitimacy of the terminal manufacturer's root certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
30. The method according to any one of claims 26 to 29, characterized in that The method further comprises: The eSIM module generates the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key are a pair of public and private keys; The eSIM module signs the eUICC temporary working public key by using the eUICC private key to obtain eUICC signature data; The eSIM module sends the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key, and generate the shared security key based on the eUICC temporary working public key and the TEE temporary working private key, and the TEE temporary working private key and the TEE temporary working public key are a pair of public-private keys.
31. The method according to claim 30, characterized in that The method further comprises: The eSIM module sends the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by the EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes the eUICC public key, the eUICC public key and the eUICC private key are a pair of public and private keys, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
32. The method according to any one of claims 19 to 31, characterized in that The first device identifier is a chip identifier of the first processing module, and the second device identifier is a chip identifier of the second processing module; or, The first device identifier is the International Mobile Equipment Identity (IMEI) of the first processing module, and the second device identifier is the IMEI of the second processing module; or, The first device identifier is a chip identifier of the first processing module and an IMEI of the first processing module, and the second device identifier is a chip identifier of the second processing module and an IMEI of the second processing module.
33. The method according to any one of claims 19 to 32, characterized in that The first request includes a first eUICC random number; The second processing module encrypts the second device identifier to obtain device verification information, specifically including: The second processing module encrypts the first eUICC random number and the second device identifier to obtain the device verification information.
34. The method according to claim 33, characterized in that The method further comprises: The eSIM module decrypts a second eUICC random number from the device verification information; If the first device identifier is the same as the second device identifier, the eSIM module performs the mobile communication service normally, specifically including: If the first device identifier is the same as the second device identifier and the second eUICC random number is the same as the first eUICC random number, the eSIM module performs the mobile communication service normally.
35. The method according to claim 33 or 34, characterized in that The first request is a Get Input command.
36. The method according to claim 20, characterized in that The eSIM module receives the device binding information sent by the first processing module, specifically including: The eSIM module receives the device binding information sent by the first processing module through a Storedata command.
37. An eSIM authentication method, characterized in that: Applied to a processing module, the method comprises: The TEE of the processing module stores the first eSIM identifier sent by the first eSIM module; The processing module receives the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on; The processing module decrypts the second eSIM identifier from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module for mobile communication services; If the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, the processing module prohibits using the second eSIM module for mobile communication services.
38. The method according to claim 37, characterized in that Before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: The processing module receives the eSIM binding information sent by the first eSIM module; After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
39. The method according to claim 38, characterized in that After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the processing module.
40. The method according to any one of claims 37 to 39, characterized in that After receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: After receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
41. The method according to claim 39 or 40, characterized in that Before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: The processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; The processing module receives the eUICC temporary working public key generated by the first processing module; The processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
42. The method according to claim 41, characterized in that Before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: The processing module receives the TEE signature data sent by the first processing module; The processing module verifies the legitimacy of the eUICC signature data through the eUICC public key in the eUICC certificate; The processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: After verifying the legitimacy of the eUICC signature data, the processing module obtains the eUICC temporary working public key from the eUICC signature data.
43. The method according to claim 42, characterized in that Before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: The processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; The processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; After verifying the legitimacy of the EUM certificate, the processing module uses the EUM public key in the EUM certificate to verify the legitimacy of the eUICC certificate; The processing module obtains the eUICC public key from the eUICC certificate after verifying the legitimacy of the eUICC certificate.
44. The method according to claim 42 or 43, characterized in that The method further comprises: The processing module generates the TEE temporary working private key and the TEE temporary working public key in the TEE, wherein the TEE temporary working private key and the TEE temporary working public key are a pair of public and private keys; The processing module signs the TEE temporary working public key through the TEE private key to obtain TEE signature data; The processing module sends the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, and the eUICC temporary working private key and the eUICC temporary working public key are a pair of public-private keys.
45. The method according to any one of claims 37 to 44, characterized in that Before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: After detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier into the eSIM verification information.
46. The method according to claim 45, characterized in that The method further comprises: The processing module decrypts the second device random number from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module to perform mobile communication services, specifically including: If the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally uses the second eSIM module to perform mobile communication services.
47. An eSIM authentication method, characterized in that: Applied to an electronic device including a processing module and a second eSIM module, the method includes: The TEE of the processing module stores the first eSIM identifier sent by the first eSIM module; After the second eSIM module is powered off and then powered on again, obtaining a second eSIM identifier of the second eSIM module; The second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; The second eSIM module sends eSIM verification information to the processing module; The processing module decrypts the second eSIM identifier from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module for mobile communication services; If the second eSIM identifier is different from the first eSIM identifier or the processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, the processing module prohibits using the second eSIM module for mobile communication services.
48. The method according to claim 47, characterized in that Before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the processing module, the method further includes: The processing module receives the eSIM binding information sent by the first eSIM module; After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
49. The method according to claim 48, characterized in that After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: After receiving the eSIM binding information, the processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the processing module.
50. The method according to any one of claims 47 to 49, characterized in that After receiving the eSIM verification information, the processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: After receiving the eSIM verification information, the processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
51. The method according to claim 49 or 50, characterized in that Before the processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: The processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; The processing module receives the eUICC temporary working public key generated by the first processing module; The processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
52. The method according to claim 51, characterized in that Before the processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: The processing module receives the TEE signature data sent by the first processing module; The processing module verifies the legitimacy of the eUICC signature data through the eUICC public key in the eUICC certificate; The processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: After verifying the legitimacy of the eUICC signature data, the processing module obtains the eUICC temporary working public key from the eUICC signature data.
53. The method according to claim 52, characterized in that Before the processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: The processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; The processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; After verifying the legitimacy of the EUM certificate, the processing module uses the EUM public key in the EUM certificate to verify the legitimacy of the eUICC certificate; The processing module obtains the eUICC public key from the eUICC certificate after verifying the legitimacy of the eUICC certificate.
54. The method according to claim 52 or 53, characterized in that The method further comprises: The processing module generates the TEE temporary working private key and the TEE temporary working public key in the TEE, wherein the TEE temporary working private key and the TEE temporary working public key are a pair of public and private keys; The processing module signs the TEE temporary working public key through the TEE private key to obtain TEE signature data; The processing module sends the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, and the eUICC temporary working private key and the eUICC temporary working public key are a pair of public-private keys.
55. The method according to any one of claims 37 to 54, characterized in that Before the processing module receives the eSIM verification information sent by the second eSIM module, the method further includes: After detecting that the second eSIM module is powered off and then powered on, the processing module sends a first device random number to the second eSIM module, where the first device random number is used to be encrypted by the second eSIM module together with the second eSIM identifier into the eSIM verification information.
56. The method according to claim 55, characterized in that The method further comprises: The processing module decrypts the second device random number from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier, the processing module normally uses the second eSIM module to perform mobile communication services, specifically including: If the second eSIM identifier is the same as the first eSIM identifier and the second device random number is the same as the first device random number, the processing module normally uses the second eSIM module to perform mobile communication services.
57. An eSIM authentication method, characterized in that: Applied to an electronic device including a second processing module and a second eSIM module, the method includes: The TEE of the second processing module stores the first eSIM identifier sent by the first eSIM module; The second eSIM module stores the first device identification sent by the first processing module; After the second eSIM module is powered off and then powered on again, obtaining a second eSIM identifier of the second eSIM module; The second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information; The second eSIM module sends eSIM verification information to the second processing module; The second processing module obtains the second device identifier, encrypts the second device identifier, obtains device verification information, and sends the device verification information to the second eSIM module; The second processing module decrypts the second eSIM identifier from the eSIM verification information; The second eSIM module decrypts the second device identifier from the device verification information; If the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier, the electronic device normally uses the second eSIM module for mobile communication services; If the second eSIM identifier is different from the first eSIM identifier or the second device identifier is different from the first device identifier or the second processing module does not receive the eSIM verification information sent by the second eSIM module after the second eSIM module is powered off and then powered on, or the second eSIM module does not receive the device verification information sent by the second processing module after being powered off and then powered on, the electronic device is prohibited from using the second eSIM module for mobile communication services.
58. The method according to claim 57, characterized in that Before the second eSIM module stores the first device identifier sent by the first processing module, the method further includes: The second eSIM module receives the device binding information sent by the first processing module; After receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information and stores the first device identifier.
59. The method according to claim 58, characterized in that After receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information, specifically including: After receiving the device binding information, the second eSIM module decrypts the first device identifier from the device binding information using the shared security key generated by the second eSIM module.
60. The method according to any one of claims 57 to 59, characterized in that After receiving the device verification information, the second eSIM module decrypts the second device identifier from the device verification information, specifically including: After receiving the device verification information, the second eSIM module decrypts the second device identifier from the verification information using the shared security key generated by the second eSIM module.
61. [Corrected 27.11.2024 in accordance with Rule 91] A method according to any one of claims 59 or 60, characterized in that Before the second eSIM module stores the first device identifier sent by the first processing module, the method further includes: The second eSIM module generates an eUICC temporary working public key and an eUICC temporary working private key; The second eSIM module receives the TEE temporary working public key generated by the first processing module; The second eSIM module generates the shared security key based on the eUICC temporary working private key and the TEE temporary working public key.
62. The method according to claim 61, characterized in that Before the second eSIM module receives the TEE temporary working public key sent by the first processing module, the method further includes: The second eSIM module receives the TEE signature data sent by the first processing module; The second eSIM module verifies the legitimacy of the TEE signature data through the TEE public key; The second eSIM module receives the TEE temporary working public key sent by the first processing module, specifically including: After verifying the legitimacy of the TEE signature data, the second eSIM module obtains the TEE temporary working public key from the TEE signature data.
63. The method according to claim 62, characterized in that Before the second eSIM module receives the TEE signature data sent by the first processing module, the method further includes: The second eSIM module verifies the legitimacy of the TEE certificate; After verifying the legitimacy of the TEE certificate, the second eSIM module obtains the TEE public key from the TEE certificate.
64. The method according to claim 63, characterized in that The TEE certificate includes a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; The second eSIM module verifies the legitimacy of the TEE certificate, specifically including: The second eSIM module verifies the legitimacy of the terminal certificate through the OEM public key in the terminal certificate.
65. The method according to claim 63, characterized in that The TEE certificate includes a device certificate and a terminal certificate, and the TEE public key is the OEM public key in the terminal certificate; Before the eSIM module verifies the legitimacy of the TEE certificate, the method further includes: The second eSIM module receives the TEE certificate sent by the first processing module; The second eSIM module verifies the legitimacy of the TEE certificate, specifically including: The second eSIM module verifies the legitimacy of the device certificate using the terminal manufacturer root public key in the terminal manufacturer root certificate; After verifying the legitimacy of the device certificate, the second eSIM module uses the device public key in the device certificate to verify the legitimacy of the terminal certificate; wherein, if the legitimacy of the device certificate and the legitimacy of the terminal certificate are both passed, the legitimacy of the TEE certificate is passed.
66. The method according to claim 63, characterized in that The TEE certificate is a terminal manufacturer root certificate, and the terminal manufacturer root certificate is preset in the second eSIM module; The second eSIM module verifies the legitimacy of the TEE certificate, specifically including: The second eSIM module verifies the legitimacy of the terminal manufacturer's root certificate through the terminal manufacturer's root public key in the terminal manufacturer's root certificate.
67. The method according to any one of claims 63 to 66, characterized in that The method further comprises: The second eSIM module generates the eUICC temporary working private key and the eUICC temporary working public key, where the eUICC temporary working private key and the eUICC temporary working public key are a pair of public and private keys; The second eSIM module signs the eUICC temporary working public key by using the eUICC private key to obtain eUICC signature data; The second eSIM module sends the eUICC signature data to the first processing module; wherein the eUICC signature data is used by the first processing module to obtain the eUICC temporary working public key, and generate a shared security key based on the eUICC temporary working public key and the TEE temporary working private key, and the TEE temporary working private key and the TEE temporary working public key are a pair of public-private keys.
68. The method according to claim 67, characterized in that The method further comprises: The second eSIM module sends the EUM certificate and the eUICC certificate to the first processing module; wherein the eUICC certificate is signed by the EUM private key paired with the EUM public key in the EUM certificate, the EUM certificate includes the eUICC public key, the eUICC public key and the eUICC private key are a pair of public and private keys, and the eUICC public key is used by the first processing module to verify the legitimacy of the eUICC signature data.
69. The method according to any one of claims 59 to 68, characterized in that The first device identifier is a chip identifier of the first processing module, and the second device identifier is a chip identifier of the second processing module; or, The first device identifier is the International Mobile Equipment Identity (IMEI) of the first processing module, and the second device identifier is the IMEI of the second processing module; or, The first device identifier is a chip identifier of the first processing module and an IMEI of the first processing module, and the second device identifier is a chip identifier of the second processing module and an IMEI of the second processing module.
70. The method according to any one of claims 59 to 69, characterized in that Before the first eSIM identifier sent by the first eSIM module is stored in the TEE of the second processing module, the method further includes: The second processing module receives the eSIM binding information sent by the first eSIM module; After receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information and stores the first eSIM identifier in the TEE.
71. The method according to claim 70, characterized in that After receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information, specifically including: After receiving the eSIM binding information, the second processing module decrypts the first eSIM identifier from the eSIM binding information using the shared security key generated by the TEE in the second processing module.
72. The method according to any one of claims 69 to 71, characterized in that After receiving the eSIM verification information, the second processing module decrypts the second eSIM identifier from the eSIM verification information, specifically including: After receiving the eSIM verification information, the second processing module decrypts the second device identifier from the verification information using the shared security key generated by the TEE.
73. The method according to claim 71 or 72, characterized in that Before the second processing module stores the first eSIM identifier sent by the first eSIM module, the method further includes: The second processing module generates a TEE temporary working public key and a TEE temporary working private key through the TEE; The second processing module receives the eUICC temporary working public key generated by the first processing module; The second processing module generates a shared security key based on the TEE temporary working private key and the eUICC temporary working public key.
74. The method according to claim 73, characterized in that Before the second processing module receives the eUICC temporary working public key sent by the first eSIM module, the method further includes: The second processing module receives the TEE signature data sent by the first processing module; The second processing module verifies the legitimacy of the eUICC signature data by using the eUICC public key in the eUICC certificate; The second processing module receives the eUICC temporary working public key sent by the first eSIM module, specifically including: The second processing module obtains the eUICC temporary working public key from the eUICC signature data after verifying the legitimacy of the eUICC signature data.
75. The method according to claim 74, characterized in that Before the second processing module receives the eUICC signature data sent by the first eSIM module, the method further includes: The second processing module receives the EUM certificate and the eUICC certificate sent by the first eSIM module; The second processing module verifies the legitimacy of the EUM certificate using the authentication root public key in the authentication root certificate; After verifying the legitimacy of the EUM certificate, the second processing module uses the EUM public key in the EUM certificate to verify the legitimacy of the eUICC certificate; The second processing module obtains the eUICC public key from the eUICC certificate after verifying the legitimacy of the eUICC certificate.
76. The method according to claim 74 or 75, characterized in that The method further comprises: The second processing module generates the TEE temporary working private key and the TEE temporary working public key in the TEE, wherein the TEE temporary working private key and the TEE temporary working public key are a pair of public and private keys; The second processing module signs the TEE temporary working public key by using the TEE private key to obtain TEE signature data; The second processing module sends the TEE signature data to the first eSIM module; wherein the TEE signature data is used by the first eSIM module to obtain the TEE temporary working public key, and generate a shared security key based on the TEE temporary working public key and the eUICC temporary working private key, and the eUICC temporary working private key and the eUICC temporary working public key are a pair of public-private keys.
77. The method according to any one of claims 59 to 76, characterized in that The method further comprises: After detecting that the second eSIM module is powered off and then powered on, the second processing module sends an eUICC random number acquisition command to the second processing module, where the eUICC random number acquisition command is used to request the second processing module to send an eUICC random number to the second processing module; After receiving the eUICC random number acquisition command, the second eSIM module generates a first eUICC random number and sends the first eUICC random number to the second processing module; The second processing module generates a first device random number; The second processing module acquires the second device identifier, encrypts the second device identifier, and obtains device verification information, specifically including: The second processing module obtains the second device identifier, and encrypts the second device identifier, the first device random number, and the first eUICC random number to obtain device verification information.
78. The method according to claim 77, characterized in that The method further comprises: After receiving the device verification information, the second eSIM module decrypts the second eUICC random number and the third device random number from the device verification information; The second eSIM module encrypts the second eSIM identifier to obtain eSIM verification information, specifically including: The second eSIM module encrypts the second eSIM identifier and the third device random number to obtain the eSIM verification information.
79. The method according to claim 78, characterized in that The method further comprises: The second processing module decrypts the second device random number from the eSIM verification information; If the second eSIM identifier is the same as the first eSIM identifier and the second device identifier is the same as the first device identifier, the electronic device normally uses the second eSIM module to perform a mobile communication service, specifically including: If the second eSIM identifier is the same as the first eSIM identifier, the second device identifier is the same as the first device identifier, the second device random number is the same as the first device random number, and the second eUICC random number is the same as the first eUICC random number, the electronic device normally uses the second eSIM module for mobile communication services.
80. An eSIM module, characterized in that: include: A processing circuit, a storage circuit and an interface circuit, wherein the storage circuit is used to store data and code instructions, and the interface circuit is used to send commands to the processing module through a modem or receive commands sent by the processing module through the modem; the processing circuit is used to run the code instructions to execute the method as described in any one of claims 1-18.
81. A processing module, characterized in that include: A processing circuit, a storage circuit and an interface circuit, wherein the storage circuit is used to store data and code instructions, and the interface circuit is used to send commands to the eSIM module through a modem or receive commands sent by the eSIM module through the modem; the processing circuit is used to run the code instructions to execute the method as described in any one of claims 37-46.
82. An electronic device, characterized in that: include: An eSIM module, a second processing module and one or more memories, wherein the one or more memories are coupled to the second processing module, and the one or more memories are used to store a computer program, so that when the second processing module executes the computer program, the electronic device executes the method as described in any one of claims 19-36.
83. An electronic device, characterized in that: include: A second eSIM module, a processing module and one or more memories, wherein the one or more memories are coupled to the processing module, and the one or more memories are used to store a computer program, so that when the processing module executes the computer program, the electronic device executes the method as described in any one of claims 47-56.
84. An electronic device, characterized in that: include: A second eSIM module, a second processing module and one or more memories, wherein the one or more memories are coupled to the second processing module, and the one or more memories are used to store a computer program, so that when the second processing module executes the computer program, the electronic device executes the method as described in any one of claims 57-79.
85. A computer storage medium, characterized in that It comprises computer instructions, which, when executed on a processor of an electronic device, cause the electronic device to execute a method as claimed in any one of claims 47 to 56.
86. A computer storage medium, characterized in that It comprises computer instructions, which, when executed on a processor of an electronic device, cause the electronic device to execute a method as claimed in any one of claims 57 to 79.
Citation Information
Patent Citations
Method for switching terminals with shared eSIM information, terminal and server
CN105704705A
Embedded type SIM card registration method, embedded type SIM card authentication method and corresponding systems
CN105848153A
ESIM data processing methods, equipment and readable memory media
CN109451483A
MANAGING EMBEDDED UNIVERSAL INTEGRATED CIRCUIT CARD (eUICC) PROVISIONING WITH MULTIPLE CERTIFICATE ISSUERS (CIs)
US20190074983A1
Cited By
Security authentication method, device and equipment of eSIM (Embedded Subscriber Identity Module) and storage medium
CN121692167A