SIM card-based data processing method and apparatus, electronic device, and storage medium

By using quantum key information in the SIM card and a cryptographic management platform to collaboratively encrypt data storage, the problem of low data storage security in terminal devices is solved, and data is stored in encrypted form with enhanced security.

WO2026016294A1PCT designated stage Publication Date: 2026-01-22CHINA TELECOM QUANTUM TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/120825
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-19
Filing Date
2024-09-24
Publication Date
2026-01-22

AI Technical Summary

Technical Problem

Data storage security in terminal devices is low, making them vulnerable to theft by unauthorized applications or owners, leading to data leaks.

Method used

Data is encrypted using quantum key information in the SIM card. A first data encryption key is generated through a password management platform and transmitted to the terminal device in ciphertext form. The terminal device decrypts the data based on the first key information to obtain a second key for encrypted storage.

Benefits of technology

It improves data storage security, prevents unauthorized users from stealing keys to decrypt data, ensures data is stored in encrypted form, reduces hardware costs, and enhances data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024120825_22012026_PF_FP_ABST
    Figure CN2024120825_22012026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a SIM card-based data processing method and apparatus, an electronic device, and a storage medium. The method belongs to the technical field of communications, and the method is applied to a terminal device. The method comprises: in response to receiving a data storage request, acquiring data to be stored; acquiring first key information from a SIM card, and sending the first key information to a password management platform, so that the password management platform encrypts a second key on the basis of the first key information to obtain a first data encryption key, and feeds back the first data encryption key to the terminal device; decrypting the first data encryption key on the basis of the first key information, and obtaining the second key; and using the second key to encrypt the data to be stored, and obtaining encrypted data and storing the encrypted data. The embodiments achieve encrypted storage of the data to be stored in the terminal device, and improve the security of the data to be stored.
Need to check novelty before this filing date? Find Prior Art

Description

SIM card-based data processing method and device, electronic equipment and storage medium

[0001] The present application claims priority to the Chinese patent application No. 202410983800.3, filed on July 19, 2024, and entitled "SIM card-based data processing method and device, electronic equipment and storage medium", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application belongs to the field of communication technology, in particular relates to a SIM card-based data processing method and device, electronic equipment and storage medium. BACKGROUND

[0003] After the application software (App) in the terminal device obtains picture, video, audio, file and other data, the application software can store these data in the terminal device for other application software to access. In related technologies, the data obtained by the application software is stored in the storage space of the terminal device in plaintext form, and other application software directly calls these data from the storage space.

[0004] However, this data storage method has the risk of data leakage. For example, an illegal application program can easily obtain the data, and an illegal holder of the terminal device can directly export the data from the storage space, and the data storage security in the terminal device is low.

[0005] SUMMARY

[0006] The present application provides a SIM card-based data processing method and device, electronic equipment and storage medium to solve the technical problem of low data storage security in the terminal device in related technologies.

[0007] In a first aspect, the present application provides a SIM card-based data processing method, which is applied to a terminal device, and the method comprises:

[0008] In response to receiving a data storage request, obtaining data to be stored;

[0009] Obtaining first key information from the SIM card and sending the first key information to a password management platform, so that the password management platform encrypts a second key according to the first key information to obtain a first data encryption key, and feeds back the first data encryption key to the terminal device;

[0010] Decrypting the first data encryption key based on the first key information to obtain a second key;

[0011] Encrypting the data to be stored using the second key to obtain encrypted data and storing the encrypted data.

[0012] In a second aspect, the present application provides a SIM card based data processing apparatus, which is applied to a terminal device, and the method comprises:

[0013] The first obtaining module is configured to obtain the data to be stored in response to receiving the data storage request.

[0014] The first sending module is configured to obtain the first key information from the SIM card, and send the first key information to the password management platform, so that the password management platform encrypts the second key according to the first key information to obtain the first data encryption key, and feeds back the first data encryption key to the terminal device.

[0015] The second obtaining module is configured to decrypt the first data encryption key based on the first key information to obtain the second key.

[0016] The encrypted storage module is configured to encrypt the data to be stored using the second key to obtain encrypted data and store the encrypted data.

[0017] In a third aspect, the present application provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to realize the above-mentioned SIM card based data processing method.

[0018] In a fourth aspect, the present application provides a computer program comprising computer readable code which, when executed on an electronic device, causes the electronic device to perform a SIM card based data processing method as claimed in the first aspect above.

[0019] In a fifth aspect, the present application provides a computer readable medium in which a computer program as claimed in the fourth aspect is stored.

[0020] In the embodiment of the present application, the first key information is stored in the SIM card, and the user does not need to replace the customized interrupt device, but only needs to use the SIM filled with the first key corresponding to the first key information to realize the method of the embodiment, thereby reducing the hardware cost for realizing the embodiment. The second key in the third-party password management platform is used to encrypt the to-be-stored data, instead of using the key stored in the terminal device to encrypt the to-be-stored data, thereby avoiding the problem that when the terminal device is lost, an illegal user steals the key from the terminal device to decrypt the encrypted data, resulting in data leakage. The password management platform encrypts the second key by using the first key information, feeds back the encrypted first data encryption key to the terminal device, and transmits the second key in the form of ciphertext between the terminal device and the password management platform, thereby improving the security of the key for encrypting the to-be-stored data, and further improving the security of the encrypted to-be-stored data. The embodiment realizes the ciphertext form storage of the to-be-stored data, improves the storage security of the to-be-stored data, and solves the problem of low data storage security in the related art. The problem of low data storage security in the process of using the application software in the terminal device (for example, a mobile phone) is solved, and the security of the locally stored data of the terminal device is improved. BRIEF DESCRIPTION OF DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without any creative effort.

[0022] FIG. 1 is a step flowchart of a data processing method based on a SIM card according to an embodiment of the present application;

[0023] FIG. 2 is a specific step flowchart of another data processing method based on a SIM card according to an embodiment of the present application;

[0024] FIG. 3 is a structural block diagram of a data processing system based on a SIM card according to an embodiment of the present application;

[0025] FIG. 4 is a connection structural block diagram of a quantum password management platform and a SIM card quantum security chip according to an embodiment of the present application;

[0026] FIG. 5 is a specific step flowchart of another data processing method based on a SIM card according to an embodiment of the present application;

[0027] FIG. 6 is a structural block diagram of a data processing apparatus based on a SIM card according to an embodiment of the present application;

[0028] FIG. 7 is a structural schematic diagram of an electronic device according to an embodiment of the present application;

[0029] FIG. 8 is a structural schematic diagram of a storage unit for program code according to an embodiment of the present application. DETAILED DESCRIPTION

[0030] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0031] Some nouns or terms appearing in the present application are applicable to the following explanations:

[0032] A Subscriber Identity Module (SIM) card, in which a secure storage chip is arranged, and the secure storage chip stores quantum keys pre-charged by a password management platform and encrypted identity information. The middleware App obtains the quantum keys to perform encryption and decryption processing on the to-be-stored data, and performs authentication on the user identity according to the encrypted identity information.

[0033] Android Interface Definition Language (AIDL), through which the middleware SDK and the access application perform data interaction in an anonymous shared manner.

[0034] A Software Development Kit (SDK) of the middleware, which is used to provide the function of the middleware App for encrypting and storing the to-be-stored data to the access application in the form of an interface through an anonymous shared memory manner of AIDL.

[0035] Object Management Architecture (OMA), a communication protocol through which the middleware App and the secure storage medium of the SIM card perform data interaction.

[0036] Inter-Process Communication (IPC), a manner in which the middleware SDK calls the middleware App.

[0037] Application Protocol Data Unit (APDU) instruction, a communication protocol used when the smart card SIM card communicates with the card reader. It can be used to perform specific operations on the SIM card, such as reading data, writing data, verifying identity, etc.

[0038] Figure 1 is a step flowchart of a data processing method based on a SIM card according to an embodiment of the present application. As shown in Figure 1, the method can include:

[0039] Step 101, in response to receiving a data storage request, obtaining the data to be stored.

[0040] The method of the present embodiment is applied to a terminal device, which can be a mobile phone, a tablet computer with a SIM card, or other terminal devices that can install a SIM card. The data to be stored can be text, video, audio, or other data.

[0041] For example, the terminal device is installed with a second application program, and the second application program obtains the data to be stored in response to the data storage request sent by the first application program.

[0042] Further, the first application program is an access application that needs to store the data to be stored in the terminal device in the form of ciphertext, and the second application program is a middleware App used to store the data to be stored after encryption processing. For example, the access application passes the data to be stored to the middleware App by calling the file encryption storage interface of the middleware SDK.

[0043] Step 102, obtaining the first key information from the SIM card and sending the first key information to the password management platform, so that the password management platform encrypts the second key according to the first key information to obtain the first data encryption key, and feeds back the first data encryption key to the terminal device.

[0044] For example, the password management platform uses the first key information to encrypt the second key using a symmetric encryption algorithm to obtain the first data encryption key.

[0045] The SIM card stores the first key pre-charged by the password management platform, and the first key has first key information, which can include a first key identifier. The first key can be a quantum key, and the first key can be stored in the secure storage chip of the SIM.

[0046] Further, the password management platform stores the first key locally when refilling the first key for the SIM card. The second application installed in the terminal device acquires the key identifier in the first key information from the SIM card, sends the key identifier to the password management platform, and the password management platform acquires the key data of the first key corresponding to the key identifier from the locally stored key, encrypts the second key by using the key data to obtain the first data encryption key, and feeds back the first data encryption key to the second application installed in the terminal device.

[0047] The second application is an application that can access the first application and encrypt the to-be-stored data stored by the first application. The second application can be a chat application, an audio and video processing application, a picture collection application, or other applications, and the type of the second application is not limited in the present application.

[0048] In step 103, the first data encryption key is decrypted based on the first key information to obtain the second key.

[0049] The first key information includes the key data and the key identifier of the first key. By acquiring the key data in the first key information, the first data encryption key is decrypted by using the key data to obtain the second key.

[0050] For example, the symmetric encryption algorithm used by the password management platform to encrypt the second key by using the first key information to obtain the first data encryption key is acquired, and the first data encryption key is decrypted by using the first key information by using the symmetric encryption algorithm to obtain the second key.

[0051] In step 104, the to-be-stored data is encrypted by using the second key to obtain encrypted data and store the encrypted data.

[0052] After the to-be-stored data is encrypted by using the second key to obtain the encrypted data, the encrypted data can be stored in the system sandbox of the terminal device operating system (such as the Android system).

[0053] In the related art, the mobile terminal App of the terminal device such as a mobile phone stores the data such as pictures, videos, audios, and files in the storage space (such as a disk) of the terminal device in a plaintext state after acquiring the data. Any software can access the data in the storage space, which may cause the data to be stolen by illegal application software, and in addition, the data in the storage space may be easily acquired by others after the terminal device is lost. The data storage method in the related art has the problem of low data storage security.

[0054] In the embodiment of the present application, after obtaining the data to be stored, the first key information is obtained from the SIM card, the first key information is stored in the SIM card, and the user only needs to use the SIM filled with the first key corresponding to the first key information to realize the method of the embodiment, thereby reducing the hardware cost for realizing the embodiment. The first key information is sent to the password management platform, the password management platform encrypts the second key using the first key information to obtain the first data encryption key, the first data encryption key is fed back to the terminal device, the terminal device decrypts the first data encryption key based on the first key information, obtains the second key, and encrypts the data to be stored, obtains the encrypted data, and stores it. The second key in the third-party password management platform is used to encrypt the data to be stored, instead of using the key stored in the terminal device to encrypt the data to be stored, thereby avoiding the problem that when the terminal device is lost, an illegal user steals the key from the terminal device to decrypt the encrypted data, resulting in data leakage. The password management platform encrypts the second key through the first key information, feeds back the encrypted first data encryption key to the terminal device, transmits the second key in the form of ciphertext between the terminal device and the password management platform, improves the security of the key for encrypting the data to be stored, and further improves the security of the encrypted data to be stored.

[0055] The embodiment realizes the ciphertext form storage of the data to be stored, improves the storage security of the data to be stored, and solves the problem of low data storage security in the related art caused by storing data in the form of plaintext. The problem of low data storage security of the user in the process of using the application software in the terminal device (such as a mobile phone) is solved, and the security of the local data storage of the terminal device is improved.

[0056] FIG. 2 is another data processing method based on a SIM card provided by an embodiment of the present application. Referring to FIG. 2, the method can include the following steps:

[0057] Step 201, obtaining, by the second application program, the data to be stored sent by the first application program to the second application program in the form of anonymous shared memory in response to the data storage request sent by the first application program.

[0058] For example, the first application program is an access application, and the second application program is a middleware App installed in the terminal device and used for data management based on the first key information stored in the SIM card. The access application program can call the file encryption storage interface of the middleware SDK to pass the data to be stored to the second application program in the form of anonymous shared memory.

[0059] Sub-step 2011, obtaining the first token information carried by the data storage request in response to the data storage request sent by the first application program.

[0060] The second application program installed in the terminal device acquires first token information carried by the data storage request in response to the data storage request sent by the first application program.

[0061] For example, the first application program is an access application, and the second application program is a middleware App. The access application accesses an interface SDK of the middleware App, and configures an application authentication AppKey provided by an official platform for accessing the middleware App. The AppKey is sent to the middleware App, and the first token information fed back by the second application program is acquired, and then the first token information is sent to the middleware App.

[0062] In substep 2012, if it is determined according to the first token information that the first application program has the permission to store the to-be-stored data, the to-be-stored data indicated by the data storage request is acquired.

[0063] For example, the first token information is compared with token information stored by the second application program of the terminal device and having the permission to store data. If the first token information is the same as any one of the stored token information, it is determined that the first application program has the permission to store the to-be-stored data. If the first token information is different from all the stored token information, it is determined that the first application program does not have the permission to store the to-be-stored data.

[0064] If it is determined according to the first token information that the first application program has the permission to store the to-be-stored data, the to-be-stored data indicated by the data storage request is received. If it is determined according to the first token information that the first application program does not have the permission to store the to-be-stored data, the to-be-stored data indicated by the data storage request is refused to be received.

[0065] In step 202, first key information is acquired from quantum key information stored in a secure storage chip of the SIM card.

[0066] The quantum key information stored in the secure storage chip is stored by a password management platform, and the password management platform stores the quantum key information.

[0067] Specifically, the password management platform randomly generates a plurality of quantum keys, fills the plurality of quantum keys in the secure storage chip of the SIM card, and stores the quantum keys filled in the secure storage chip of the SIM card in the password management platform locally.

[0068] For example, the first key information includes a key identifier of the first key; and correspondingly, after step 204, the method further includes:

[0069] Step 203, send the key identification of the first key to the password management platform, so that the password management platform obtains the first key corresponding to the key identification from the stored quantum key information, and encrypts the randomly generated second key using the first key to obtain the first data encryption key, and feeds back the first data encryption key to the terminal device.

[0070] In an example, the password management platform comprises a quantum random number generator, a quantum exchange key machine, and a quantum key replenishment machine. The quantum random number generator generates a quantum key, stores the quantum key in the quantum exchange key machine, and stores the quantum key in the SIM card through the quantum key replenishment machine. The first key has a key identification. Thus, the password management platform and the SIM card both store the first key. After the password management platform obtains the key identification of the first key, it obtains the first key corresponding to the key identification from the locally stored key, and encrypts the randomly generated second key using the first key to obtain the first data encryption key.

[0071] Step 204, decrypt the first data encryption key based on the first key information to obtain the second key.

[0072] The method of this step has been described in the foregoing step 103, and will not be repeated here.

[0073] Step 205, encrypt the data to be stored using the second key to obtain encrypted data and store it.

[0074] In this embodiment, in response to the data storage request sent by the first application program, the first token information carried by the data storage request is obtained, the first application program is authorized according to the first token information, and after the authorization is passed, the data to be stored sent by the first application program in an anonymous sharing manner is obtained. Through authorization, it can avoid illegal application to access the second application storage data, and through the anonymous sharing manner to send the data to be stored, the data transmission rate is improved.

[0075] The first key information is a quantum key stored in the SIM card secure storage chip. By storing the first key in the SIM card secure storage chip, the first key can be protected from being easily leaked, and the security of the first key is improved. The key identification of the first key is sent to the password management platform, instead of directly sending the key data of the first key to the password management platform, which can prevent the key data from being leaked.

[0076] The password management platform uses the key identifier to encrypt the second key with the corresponding first key to obtain a first data encryption key. Since the second key is randomly generated, the first data encryption key is fed back to the terminal device. After the terminal device decrypts the first data encryption key to obtain the second key, the second key is used to encrypt the data to be stored. Different second keys can be used to encrypt and store different data to be stored, and the data to be stored is encrypted and stored "once per key". Compared with the method in which the second key is a fixed key, using the randomly generated second key to obtain the first data encryption key can avoid the problem of second key leakage, which reduces the security of the data to be stored.

[0077] The password management platform transmits the first data key encrypted with the second key, rather than directly transmitting the second key. The entire life cycle of the key is transmitted in the form of ciphertext, which can prevent the second key used to encrypt the data to be stored from being leaked, improve the security of key transmission, and improve the storage security of the data to be stored.

[0078] In one embodiment, after step 205, the method further comprises:

[0079] Step 206: In response to the data read request sent by the third application program, obtaining user identity information.

[0080] For example, the third application program is an access program, and the third application program can be the same as or different from the first application program.

[0081] For example, the first application program is an image acquisition application program, and the third application program is a chat application program; for another example, the first application program and the third application program are both chat application programs.

[0082] For example, step 206 can include the following sub-steps:

[0083] Sub-step 2061: In response to the data read request sent by the third application program, obtaining the second token information carried by the data read request through the second application program.

[0084] For example, the third application program is an access application, and the second application program is a middleware APP. The access application accesses the interface SDK of the middleware App and configures the application authentication AppKey provided by the official platform for accessing the middleware App. The AppKey is sent to the middleware App, and the first token information fed back by the middleware APP is obtained, and then the first token information is sent to the middleware App.

[0085] Sub-step 2062: If it is determined that the third application program has the permission to read the data to be stored according to the second token information, the step of obtaining the user identity information is performed.

[0086] The first token information and the token information stored by the second application of the terminal device are compared. If the first token information is the same as the token information stored locally, it is determined that the third application has the permission to store the to-be-stored data. If the second token information is different from the token information stored locally, it is determined that the third application does not have the permission to store the to-be-stored data.

[0087] If it is determined that the third application has the permission to store the to-be-stored data according to the second token information, the step of obtaining user identity information is performed. If it is determined that the third application does not have the permission to store the to-be-stored data according to the second token information, the step of obtaining user identity information is refused to be performed, and the subsequent data reading operation is not performed.

[0088] The step 206 can include the following sub-steps.

[0089] In the sub-step 2063, a user information input interface is displayed in response to the data reading request sent by the third application.

[0090] The user identity information can include a password, a gesture, a fingerprint, face information, or other information that can identify the identity of the user.

[0091] Correspondingly, the user information input interface can include a control for inputting a password, an interface for receiving user gesture information, and an interface for collecting user fingerprint or face information.

[0092] In the sub-step 2064, user identity information is obtained in response to an input operation of the user on the user information input interface.

[0093] For example, if the user information is a password, after the user information input interface for inputting the password is displayed, the password information input by the user is received after the user inputs the password in the user information input interface.

[0094] The step 206 can include the following sub-steps.

[0095] In the sub-step 2065, fourth key information is obtained from the key stored in the SIM card, and the fourth key information is sent to the password management platform, so that the password management platform encrypts the fifth key by using the fourth key information to obtain an identity encryption key, and feeds back the identity encryption key to the terminal device.

[0096] The fourth key information is obtained from the quantum key information stored in the secure storage chip of the SIM card. The fourth key information is information of the fourth key, and can include key data and a key identifier of the fourth key.

[0097] For example, the quantum key can be randomly selected from the quantum keys stored in the secure storage chip of the SIM card as the fourth key, and the key information is taken as the fourth key information.

[0098] The password management platform obtains the fourth key corresponding to the key identifier of the fourth key from the locally stored quantum keys according to the key identifier of the fourth key, and encrypts the fifth key using the key data of the fourth key to obtain an identity encryption key.

[0099] In substep 2066, the identity encryption key is decrypted based on the fourth key information to obtain the fifth key.

[0100] The encryption algorithm used by the password management platform to encrypt the fifth key to obtain the identity encryption key through the fourth key information is obtained, and the identity encryption key is decrypted using the fourth key information based on the encryption algorithm to obtain the fifth key.

[0101] In substep 2067, the user identity information is encrypted using the fifth key to obtain target encrypted identity information.

[0102] For example, the user identity information is encrypted using the fifth encryption key through a symmetric encryption algorithm to obtain the target encrypted identity information.

[0103] In substep 2068, the user identity information is authenticated according to the pre-stored encrypted identity information and the target encrypted identity information.

[0104] If the target encrypted identity information is the same as any of the pre-stored encrypted identity information, it is determined that the user identity information authentication is passed, and if the target encrypted identity information is different from all the pre-stored encrypted identity information, it is determined that the user identity information authentication is not passed.

[0105] For example, before substep 2065, it further includes:

[0106] The identity information of the user is collected through the second application program of the terminal device, the quantum key and the SIM card identifier are obtained from the secure chip of the SIM card, the quantum key is sent to the password management platform, the password management platform generates a random number and stores the correspondence between the random number and the SIM card identifier. The random number is encrypted using the quantum key to obtain an encryption key and is fed back to the second application program, the second application program decrypts the encryption key using the quantum key to obtain the random number, encrypts the identity information using the random number to obtain encrypted identity information and sends it to the SIM card for storage. The encrypted identity information stored in the SIM card is encrypted using the random number corresponding to the SIM identifier.

[0107] Correspondingly, the password service platform acquires the key identifier of the fourth key and the SIM card identifier, acquires the fourth key according to the key identifier, acquires the random number according to the SIM card identifier, and determines the random number corresponding to the SIM card identifier as the fifth key. The fourth key is used to encrypt the fifth key to obtain the identity encryption key. The identity encryption key is fed back to the second application program, the second application program uses the fourth key to decrypt the identity encryption key to obtain the fifth key, and uses the fifth key to encrypt the identity information to obtain the target encrypted identity information.

[0108] For the same SIM card, the SIM card identifier is the same, therefore, the fifth key used to encrypt the identity information is the random number used to encrypt the identity information of the legal user. If the acquired identity information is the identity information of the legal user in the identity information authentication, the target identity encryption information obtained after the identity information is encrypted by the fifth key should be the same as the encrypted identity information stored in the SIM card.

[0109] Further, after the target encrypted identity information is acquired, the target encrypted identity information is forwarded to the SIM card, and the SIM card stores the encrypted identity information obtained by encrypting the identity information by the fifth key. By comparing the encrypted identity information stored in the SIM card and the target encrypted identity information, if the target encrypted identity information is the same as any of the encrypted identity information stored in the SIM card, it is determined that the user identity information authentication is passed, otherwise, it is determined that the user identity information authentication is not passed.

[0110] The access permission of the user to the to-be-stored data is controlled by the password, gesture, fingerprint, face and other user identity information. The user identity information is encrypted and stored in the dynamic storage area of the SIM card security medium. Based on the stored encrypted identity information and the target encrypted identity information, it can be quickly judged whether the user has the permission to acquire the to-be-stored data. The identity information is stored in the state of the encrypted identity information, which can prevent the identity information from being leaked. For example, after the terminal device and the SIM card are lost, the identity information in the SIM card is acquired by others. Therefore, the security of the identity information storage is ensured.

[0111] In step 207, if the user identity information authentication is passed, the third key information is acquired from the SIM card and sent to the password management platform, so that the password management platform encrypts the second key according to the third key information to obtain the second data encryption key, and feeds back the second data encryption key to the terminal device.

[0112] Specifically, the password management platform acquires the third key corresponding to the key identifier of the third key from the quantum key stored locally in the password management platform according to the key identifier in the third key information, and uses the key data of the third key to decrypt the second key to obtain the second data encryption key.

[0113] Step 208, decrypt the second data encryption key based on the third key information to obtain the second key.

[0114] The symmetric encryption algorithm used by the password management platform to encrypt the second key to obtain the second data encryption key is acquired, and based on the symmetric encryption algorithm, the second data encryption key is decrypted using the third key information to obtain the second key.

[0115] Step 209, decrypt the encrypted data using the second key to obtain the decrypted data to be stored, and feed back to the third application program.

[0116] The symmetric encryption algorithm used to encrypt the data to be stored using the second key to obtain the encrypted data is acquired, and based on the second key, the encrypted data is decrypted using the symmetric encryption algorithm to obtain the decrypted data to be stored.

[0117] Further, in the foregoing process of encrypting and storing the data to be stored, the password management platform receives the first key information and the data identifier (such as name, number, etc.) of the data to be stored sent by the terminal device, then generates a random number, uses the random number as the second key, and stores the correspondence between the random number and the data identifier. After encrypting the second key using the first key in the first key information, the obtained first data key is fed back to the terminal device to obtain the second key decrypted by the terminal device, and the second key is used to encrypt the data to be stored.

[0118] Correspondingly, in this step, if the user identity information is passed, the third key information is acquired from the SIM card, and the data identifier in the data reading request is acquired, and the third key information and the data identifier are sent to the password management platform. The password management platform acquires the key data of the third key according to the key identifier in the third key information, and acquires the second key corresponding to the data identifier according to the data identifier and the correspondence between the stored data identifier and the second key, and then encrypts the second key using the third key to obtain the second data encryption key and feed back to the terminal device.

[0119] Therefore, after the terminal device decrypts the second data encryption key using the third key, the obtained second key is the key when encrypting the data to be stored, and based on the second key, the encrypted data obtained by decrypting the encrypted data to be stored can be decrypted to obtain the decrypted data.

[0120] In summary, in response to the data read request sent by the third application program, the user identity information is acquired, and in the case that the user identity information is authenticated, it is indicated that the user using the third application program to acquire the to-be-stored data is a legal user with data read permission, in this case, the second key sent by the password management platform in an encrypted manner is acquired to avoid leakage of the second key, and the encrypted data is decrypted using the second key to obtain decrypted to-be-stored data. The embodiment can avoid that an illegal application program or a user without data acquisition permission acquires the to-be-stored data, and improves the storage security of the to-be-stored data.

[0121] For example, referring to FIG. 3, the SIM card-based data processing system includes a terminal device (such as a mobile phone) as a quantum key management platform of a password management platform. The terminal device is installed with an access application as a first application program and a middleware App as a second application program. The middleware App has a file encryption cabinet, which can be a terminal device operating system sandbox. The quantum key management platform generates a quantum key, stores the quantum key, and charges the quantum key into a secure storage chip of a SIM card.

[0122] Referring to FIG. 4, the quantum key management platform produces a quantum key through a quantum random number generator 10, and stores the quantum key in a quantum exchange cipher machine 20. The quantum exchange cipher machine 20 receives the quantum key sent by the quantum random number generator 10, and provides a key service for the middleware App.

[0123] The quantum exchange cipher machine 20 has a key pre-stored therein, which is a quantum key pre-generated by the quantum random number generator 10 and stored in the quantum exchange cipher machine 20. A quantum key charging machine 30 is connected to an output end of the quantum exchange cipher machine 20, and is used to charge the quantum key into a quantum secure chip 40 of a SIM card. The quantum key stored in the quantum exchange cipher machine 20 and the key in the quantum secure chip 40 of the SIM card are symmetric keys. Further, the quantum key management platform realizes data interaction with an instant messaging system and the quantum secure chip through a network respectively, and a quantum cipher management service system is directly connected to the quantum cipher exchange machine, and is used to provide an encryption key and an identity authentication function. The quantum secure chip in the SIM card is the secure storage chip in the foregoing embodiments.

[0124] Further, the SIM card has a quantum secure chip for storing a quantum secure key and medium information, wherein the medium information can be a medium identifier (such as a medium ID), for example, the medium identifier can be a SIM identifier. The key stored in each quantum secure chip and the key pre-stored in the quantum exchange cipher machine are symmetric keys, and the secure key in the quantum secure chip is symmetrically authenticated through a network and the quantum cipher management service system.

[0125] For example, the second application program is a middleware App, and the third-party application program calls the file encryption and decryption storage function of the middleware App by integrating the middleware SDK. The middleware App obtains a quantum key pre-charged in a SIM card secure storage chip through OMA, and the quantum key is the first key in the foregoing embodiment. Then, the quantum key is used to decrypt a quantum session key of the secure platform to obtain a decrypted session key. The quantum session key is a first data encryption key obtained by encrypting a second key using the first key, and the decrypted session key is the second key. The file is encrypted using the decrypted session key and stored in an application sandbox.

[0126] FIG. 5 is a step flowchart of a SIM card-based data processing method provided by an embodiment of the present application. The SIM card-based data processing method of the present application is further exemplarily described below in combination with FIG. 3 and FIG. 5. Referring to FIG. 5, the method can include the following steps:

[0127] In step S1, an interface SDK of an application is accessed to an interface of a middleware App, an Appkey for application authentication is configured, initialization of a middleware SDK is completed, and the middleware App is woken up.

[0128] The AppKey for authentication is provided by an official platform.

[0129] The application in this step corresponds to the first application program in the foregoing embodiment, and the middleware App corresponds to the second application program in the foregoing embodiment.

[0130] The middleware SDK is a basic service component with simple interface design, and the identity authorization login method of the middleware App based on the SIM card secure storage chip can be completed by one-key calling.

[0131] In step S2, the middleware SDK interface is called, and the middleware App is called through an IPC mode to perform application authentication of the application.

[0132] The application completes the application authentication of the middleware App by calling the interface of the SDK to obtain the use capability of the SDK. Specifically, the application authentication is completed according to the AppKey.

[0133] In step S3, a file encryption storage interface of the middleware SDK is called, and file data is transmitted to the middleware App in an anonymous shared memory mode.

[0134] The file data is the data to be stored in the foregoing embodiment. The application calls the file encryption storage interface of the SDK, and transmits the file data to the middleware App in the anonymous shared memory mode.

[0135] Step S4: The middleware App sends an APDU instruction to the SIM card by the OMA method to obtain the pre-charged quantum key in the SIM card security medium.

[0136] The SIM card security medium is a SIM card security storage chip. The pre-charged quantum key in the SIM security medium is charged in the SIM card security medium after being generated by the quantum key management platform. The quantum key management platform also stores the quantum key locally when charging the quantum key into the SIM card security medium.

[0137] Step S5: The middleware App uses the pre-charged quantum key obtained from the SIM card security medium to negotiate with the quantum password management platform to obtain a file encryption key.

[0138] The file encryption key is equivalent to the first data encryption key in the foregoing embodiment. The middleware App obtains the pre-charged quantum key in the SIM card security medium, sends the key identifier of the obtained quantum key to the quantum password management platform, and negotiates with the quantum password management platform to obtain a file encryption key. Specifically, the quantum password management platform uses the key identifier to encrypt a random number to obtain the file encryption key.

[0139] Step S6: The middleware App performs symmetric encryption of the file data according to the file encryption key, and stores the encrypted file data in the local sandbox.

[0140] In this embodiment, the quantum key is pre-charged in the SIM card security storage chip, and the quantum key is protected by the security storage chip, thereby improving the security of the quantum key. Storing the encrypted file data in the local sandbox can effectively prevent other applications from illegally accessing the file data. The middleware App uses the quantum key in the SIM card security storage chip to obtain the service key encrypted by the quantum key management platform, and stores the file data based on the service key.

[0141] According to steps S1 to S6, the access application obtains the success state callback result of the middleware App, and completes the encryption and disk writing of the local file data.

[0142] Step S7, the access application accesses the interface SDK of the middleware App, and configures the Appkey used for access application authentication, completes the initialization of the middleware SDK, and wakes up the middleware App.

[0143] This step can refer to the description of step S1, which will not be repeated here.

[0144] Step S8, call the interface of the SDK, and call the middleware App by the IPC method to perform application authentication of the access application.

[0145] Further, the interface of the SDK is called to call the middleware App through the IPC mode to complete the application authentication of the access application and obtain the use ability of the SDK.

[0146] Step S9, the file decryption obtaining interface of the SDK is called.

[0147] The file decryption obtaining interface of the SDK is called, and the user authentication interface of the middleware App is jumped to.

[0148] Step S10, the middleware App opens the user authentication interface of the password, gesture, fingerprint, face, etc. for the user to select the corresponding mode for authentication.

[0149] The user authentication interface provides the user with selectable authentication modes, and the user selects the corresponding mode for authentication. The middleware App encrypts the user authentication data by quantum key.

[0150] Step S11, the middleware App encrypts the user authentication data by quantum key.

[0151] The encrypted authentication data of the middleware App is transmitted into the SIM card security medium and compared with the pre-stored encrypted authentication password, gesture, fingerprint, face, etc. in the SIM card security medium data.

[0152] Step S12, the middleware App transmits the encrypted authentication data into the SIM card security medium and compares it with the pre-stored encrypted authentication password, gesture, fingerprint, face, etc. in the SIM card security medium.

[0153] Specifically, the SIM compares the encrypted authentication data and the pre-stored encrypted authentication data of the legal user, and returns the comparison result to the middleware App. The middleware App obtains the comparison result of the user authentication data, and enters the file pre-selection interface if the condition is met.

[0154] Step S13, the middleware App obtains the comparison result of the user authentication data, and enters the file pre-selection interface if the condition is met.

[0155] If the comparison result is that the encrypted authentication data received by the SIM card and the pre-stored encrypted authentication data of the legal user are the same, it is determined that the comparison result is that the condition is met, otherwise, it is determined that the comparison result is that the condition is not met.

[0156] After the user selects the corresponding file data, the middleware App obtains the pre-charged quantum key in the SIM card security storage chip, and uses the pre-charged quantum key of the SIM card storage chip to negotiate with the quantum password management platform to obtain the file decryption key.

[0157] Step S14, after obtaining the file data selected by the user, the middleware App sends an APDU instruction to the SIM card through the OMA mode to obtain the pre-charged quantum key in the SIM card security medium. The middleware App decrypts the file selected by the user and returns the decrypted file to the middleware SDK

[0158] Step S15, the middleware App uses the pre-charged quantum key of the SIM card security medium to negotiate with the quantum password management platform to obtain the file decryption key. The middleware SDK returns the decrypted file data to the calling application, and completes the extraction operation of the file from the file encryption cabinet. The specific method of this step can refer to the description of steps 207 to 208 described above, and will not be described here.

[0159] Step S16, the middleware App decrypts the selected file data and returns the decrypted file data to the middleware SDK in the form of anonymous shared memory. Through the method of anonymous memory sharing, the data transmission efficiency can be improved.

[0160] S17: The middleware SDK returns the decrypted file data to the access application calling the middleware SDK, and completes the extraction operation of the file data from the local sandbox. The local sandbox is equivalent to the file encryption cabinet.

[0161] In this embodiment, the quantum key is pre-charged in the SIM card security storage chip, and the quantum key is protected by the security storage chip, thereby improving the security of the quantum key. The encrypted file data is stored in the local sandbox, which can effectively prevent other applications from illegally accessing the file data. The middleware App uses the quantum key in the SIM card security storage chip to obtain the service key encrypted by the quantum password management platform through the quantum key, and performs one-time pad decryption on the file data based on the service key, and extracts the decrypted file data from the sandbox. In addition, the middleware App uses the quantum key in the SIM card security storage chip to identify and verify the user identity information such as password, gesture, fingerprint, and face, which can avoid illegal users from obtaining file data. The application has less changes to the access application and is non-intrusive, and the access application can use the authorization scheme for self-defined login authorization products at will. Only the secure SIM card needs to be replaced, and the custom machine does not need to be replaced, thereby reducing the security threshold and cost

[0162] FIG. 6 is a structural block diagram of a data processing apparatus based on a SIM card according to an embodiment of the present application. The apparatus 60 can include:

[0163] The first obtaining module 601 is configured to obtain to-be-stored data in response to receiving a data storage request.

[0164] The first sending module 602 is configured to acquire first key information from the SIM card, and send the first key information to the password management platform, so that the password management platform encrypts a second key according to the first key information to obtain a first data encryption key, and feeds back the first data encryption key to the terminal device.

[0165] The second acquiring module 603 is configured to decrypt the first data encryption key based on the first key information to obtain the second key.

[0166] The encrypted storage module 604 is configured to encrypt the to-be-stored data using the second key to obtain encrypted data and store the encrypted data.

[0167] Optionally, the first sending module 602 can include a first acquiring sub-module configured to acquire the first key information from quantum key information stored in a secure storage chip of the SIM card, wherein the quantum key information stored in the secure storage chip is stored by the password management platform, the password management platform stores the quantum key information, and the first key information includes a key identifier of the first key.

[0168] The first sending module 602 can further include a first sending sub-module configured to send the key identifier of the first key to the password management platform, so that the password management platform acquires the first key corresponding to the key identifier from the stored quantum key information, encrypts a randomly generated second key using the first key to obtain the first data encryption key, and feeds back the first data encryption key to the terminal device.

[0169] Optionally, the first acquiring module can include a second acquiring sub-module configured to acquire first token information carried in a data storage request sent by the first application program in response to the data storage request, and a third acquiring sub-module configured to acquire to-be-stored data indicated by the data storage request if it is determined that the first application program has the permission to store the to-be-stored data according to the first token information.

[0170] Optionally, the third acquiring sub-module can include a first acquiring unit configured to acquire to-be-stored data sent by the first application program to the second application program in an anonymous shared memory manner by the second application program in response to the data storage request sent by the first application program.

[0171] Optionally, the apparatus 60 further includes a third acquiring module configured to, after the to-be-stored data is encrypted using the second key to obtain encrypted data and the encrypted data is stored, further include:

[0172] The fourth acquiring module is configured to acquire user identity information in response to a data reading request sent by the third application program.

[0173] The fifth obtaining module is configured to, if the user identity information is authenticated, obtain third key information from the SIM card and send the third key information to the password management platform, so that the password management platform encrypts the second key according to the third key information to obtain a second data encryption key, and feeds back the second data encryption key to the terminal device.

[0174] The sixth obtaining module is configured to decrypt the second data encryption key based on the third key information to obtain the second key.

[0175] The decryption module is configured to decrypt the encrypted data using the second key to obtain decrypted data to be stored and feed back to the third application program.

[0176] Optionally, the fourth obtaining module can include: a display sub-module configured to, in response to a data reading request sent by the third application program, display a user information input interface; and a fourth obtaining sub-module configured to, in response to an input operation of the user on the user information input interface, obtain the user identity information.

[0177] Optionally, the apparatus 60 further includes: a seventh obtaining module configured to, after obtaining the user identity information, obtain fourth key information from the key stored in the SIM card and send the fourth key information to the password management platform, so that the password management platform encrypts a fifth key using the fourth key information to obtain an identity encryption key and feeds back the identity encryption key to the terminal device; an eighth obtaining module configured to decrypt the identity encryption key based on the fourth key information to obtain the fifth key; a ninth obtaining module configured to encrypt the user identity information using the fifth key to obtain target encrypted identity information; and an identity authentication module configured to authenticate the user identity information according to pre-stored encrypted identity information and the target encrypted identity information.

[0178] Optionally, the apparatus 60 further includes: a tenth obtaining module configured to, before obtaining the user identity information, in response to a data reading request sent by the third application program, obtain second token information carried by the data reading request through the second application program; and an execution module configured to, if it is determined that the third application program has the permission to read the data to be stored according to the second token information, execute the step of obtaining the user identity information.

[0179] In summary, the second key in the third-party password management platform is used to encrypt the data to be stored, instead of using the key stored in the terminal device to encrypt the data to be stored, so as to avoid the problem that after the terminal device is lost, an illegal user steals the key from the terminal device to decrypt the encrypted data, resulting in data leakage. The password management platform encrypts the second key by using the first key information, and feeds back the encrypted first data encryption key to the terminal device, so that the second key is transmitted between the terminal device and the password management platform in the form of ciphertext, thereby improving the security of the key for encrypting the data to be stored, and further improving the security of the encrypted data to be stored. For the apparatus embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the related parts can be referred to the part of the method embodiment.

[0180] The various component embodiments of the present application can be implemented in hardware, or implemented in software modules running on one or more processors, or implemented in a combination thereof. Those skilled in the art should understand that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the electronic device according to the embodiments of the present application. The present application can also be implemented as a device or apparatus program (for example, a computer program and a computer program product) for executing part or all of the methods described herein. The program implementing the present application can be stored on a computer readable medium, or can have one or more signals in the form. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0181] For example, Fig. 7 shows an electronic device which can implement the method according to the present application. The electronic device traditionally comprises a processor 1010 and a computer program in the form of a memory 1020, which, when executed by the processor 1020, implements the above described SIM card based data processing method. The memory 1020 can be an electronic memory such as a flash memory, an EEPROM (Electrically Erasable Programmable Read-Only Memory), an EPROM, a hard disk or a ROM. The memory 1020 has a storage space 1030 for program code 1031 for performing any of the method steps in the above described method. For example, the storage space 1030 for program code can comprise individual program codes 1031 for implementing the various steps in the above described method, respectively. These program codes can be read from or written to one or more computer program products. These computer program products comprise program code carriers such as hard disks, compact disks (CDs), memory cards or floppy disks. Such computer program products are typically portable or stationary memory units as described with reference to Fig. 8. The memory unit can have a storage section, a storage space or the like arranged similarly to the memory 1020 in the electronic device of Fig. 7. The program code can be compressed, for example, in a suitable form. Typically, the memory unit comprises computer readable code 1031', i.e. code which can be read by a processor such as 1010, which, when executed by the electronic device, causes the electronic device to perform the various steps in the above described method.

[0182] It should be noted that the various information, data, acquired in the embodiments of the present application, are acquired with authorization from the information / data holder. The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other apparatus. Various general purpose systems can be used with these teachings, based on the description as provided herein. Structure for a variety of these systems will be apparent to those of skill in the art from the above description. Additionally, the present application is not intended to be limited to any particular programming language. It will be appreciated that a variety of programming languages can be used to implement the teachings of the present application as described herein, and any references below to specific languages are provided for disclosure of enablement of the present application.

[0183] Various component embodiments of the present application can be implemented in hardware, or as software modules running in one or more processors, or in combinations thereof. As will be appreciated by persons skilled in the art, a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all of the functionality of some or all of the components in the sequencing apparatus according to the present application. The present application can also be implemented as a program for executing part or all of the methods described herein on a device or apparatus. Such a program can be stored on a computer readable medium which can be any medium, tangible or intangible, in which data can be stored and which can be accessed by a general purpose or special purpose computer system. The program can be downloaded by the Internet from an Internet website, or can be provided on a carrier wave, or in any other form.

[0184] It should be noted that the above-mentioned embodiments illustrate rather than limit the application, and that those skilled in the art will be able to design many alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word 'comprising' does not exclude the presence of elements or steps other than those listed in a claim. The word 'a' or 'an' preceding an element does not exclude the presence of a plurality of such elements. The application can be implemented by means of both hardware and software, and any combination thereof. In the claims, the word 'first','second', 'third', etc. does not imply any order. These words are to be interpreted as names.

[0185] The user information (including but not limited to the user's device information, user personal information, etc.) and related data involved in the present application are information authorized by the user or authorized by each party. The above only describes the preferred embodiments of the present application and does not limit the present application. Any modification, equivalent replacement and improvement made within the spirit and principle of the present application shall be included in the protection scope of the present application. The above only describes the specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which shall be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A data processing method based on a SIM card, wherein, The method is applied to a terminal device, and the method comprises: In response to receiving a data storage request, obtaining to-be-stored data; Obtaining first key information from the SIM card and sending the first key information to a password management platform, so that the password management platform encrypts a second key according to the first key information to obtain a first data encryption key, and feeds back the first data encryption key to the terminal device; Decrypting the first data encryption key based on the first key information to obtain the second key; Encrypting the to-be-stored data using the second key to obtain encrypted data and storing the encrypted data.

2. The method of claim 1, wherein, The first key information is obtained from quantum key information stored in a secure storage chip of the SIM card; the quantum key information stored in the secure storage chip is stored by the password management platform, and the password management platform stores the quantum key information; The first key information comprises a key identifier of the first key; and the first key information is sent to the password management platform, so that the password management platform obtains the first key corresponding to the key identifier from the stored quantum key information, and encrypts the randomly generated second key using the first key to obtain the first data encryption key, and feeds back the first data encryption key to the terminal device. In response to the data storage request sent by the first application program, obtaining first token information carried by the data storage request; If it is determined that the first application program has the permission to store the to-be-stored data according to the first token information, obtaining to-be-stored data indicated by the data storage request.

3. The method of claim 1, wherein, The to-be-stored data indicated by the data storage request is obtained by the second application program in response to the data storage request sent by the first application program, and the to-be-stored data is sent to the second application program in the form of an anonymous shared memory. In response to a data read request sent by a third application program, obtaining user identity information; If the user identity information is authenticated, obtaining third key information from the SIM card and sending the third key information to the password management platform, so that the password management platform encrypts the second key according to the third key information to obtain a second data encryption key, and feeds back the second data encryption key to the terminal device; 4. The method of claim 3, wherein, Decrypting the second data encryption key based on the third key information to obtain the second key; Decrypting the encrypted data using the second key to obtain decrypted to-be-stored data and feeding back the decrypted to-be-stored data to the third application program.

5. The method of claim 1, wherein, In response to the data read request sent by the third application program, displaying a user information input interface; ​ ​ ​ ​ 6. The method of claim 5, wherein, ​ ​ In response to a user input operation on the user information input interface, the user identity information is acquired.

7. The method of claim 5, wherein, After the user identity information is acquired, further comprising: A fourth key information is acquired from the key stored in the SIM card, and the fourth key information is sent to the password management platform, so that the password management platform encrypts a fifth key by using the fourth key information to obtain an identity encryption key, and feeds back the identity encryption key to the terminal device; The identity encryption key is decrypted based on the fourth key information to obtain the fifth key; The user identity information is encrypted by using the fifth key to obtain target encrypted identity information; The user identity information is authenticated according to the pre-stored encrypted identity information and the target encrypted identity information.

8. The method of claim 5, wherein, Before the user identity information is acquired, further comprising: In response to a data reading request sent by the third application program, second token information carried by the data reading request is acquired by a second application program; If it is determined that the third application program has the permission to read the to-be-stored data according to the second token information, the step of acquiring the user identity information is executed.

9. A SIM card based data processing apparatus, wherein, The device is applied to a terminal device, and the device comprises: A first acquisition module is configured to acquire to-be-stored data in response to receiving a data storage request; A first sending module is configured to acquire first key information from a SIM card, and send the first key information to a password management platform, so that the password management platform encrypts a second key according to the first key information to obtain a first data encryption key, and feeds back the first data encryption key to the terminal device; A second acquisition module is configured to decrypt the first data encryption key based on the first key information to obtain the second key; An encrypted storage module is configured to encrypt the to-be-stored data by using the second key to obtain encrypted data and store the encrypted data.

10. An electronic device, comprising: The device comprises: A processor, a memory, and a computer program stored on the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1-8 when executing the program.

11. A computer program comprising computer readable code which, when run on an electronic device, causes the electronic device to perform a SIM card-based data processing method according to any one of claims 1-8.

12. A computer readable medium having stored therein the computer program according to claim 11.

Citation Information

Patent Citations

  • Encrypted storage method based on quantum key and encrypted storage card

    CN110650011A

  • Key generation and encryption and decryption method and device and SIM card chip

    CN112566124A

  • Quantum key encryption method and device, equipment and storage medium

    CN116055042A

  • Method, gateway and system for protecting communication data through quantum encryption

    CN117640084A

  • Quantum-safe SIM card-based communication system and method, quantum-safe SIM card, and key service platform

    WO2022143727A1