WO2015027485A1 - Procédé de changement d'abonnement à distance, et appareil associé - Google Patents

Procédé de changement d'abonnement à distance, et appareil associé Download PDF

Info

Publication number
WO2015027485A1
WO2015027485A1 PCT/CN2013/082720 CN2013082720W WO2015027485A1 WO 2015027485 A1 WO2015027485 A1 WO 2015027485A1 CN 2013082720 W CN2013082720 W CN 2013082720W WO 2015027485 A1 WO2015027485 A1 WO 2015027485A1
Authority
WO
WIPO (PCT)
Prior art keywords
management platform
remote management
target
terminal
response message
Prior art date
Application number
PCT/CN2013/082720
Other languages
English (en)
Chinese (zh)
Inventor
李永华
钱点点
宋琦
衣强
金辉
Original Assignee
华为终端有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为终端有限公司 filed Critical 华为终端有限公司
Priority to PCT/CN2013/082720 priority Critical patent/WO2015027485A1/fr
Priority to CN201380002239.6A priority patent/CN103782568A/zh
Publication of WO2015027485A1 publication Critical patent/WO2015027485A1/fr

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data

Definitions

  • the invention belongs to the field of communication technologies, and in particular relates to a remote change signing method and device thereof.
  • Embedded Universal Integrated Circuit Card (embedded Universal Integrated Circuit Card, eUICC) is a remotely configurable universal circuit card (Universal Integrated Circuit Card, The embedded card of the UICC) code number can also be an embedded card that remotely switches or accesses the mobile operator's network.
  • eUICC is currently mainly used in the field of Internet of Things.
  • the eUICC is embedded in the IoT device, and the operator and subscription data to which the eUICC belongs can be modified by means of post-writing.
  • the eUICC-based network architecture includes mobile network operators (Mobile Network). Operator, MNO), contract management secure routing unit (Subscription Manager-Secure Routing, SM-SR), contract management data preparation unit (Subscription Manager-Data Preparing, SM-DP) and eUICC terminals. Their functions are as follows:
  • the MNO provides functions such as network access, user authentication, and user-signed billing;
  • SM-DP prepares data for a profile, such as encrypting it, so that only the designated terminal can decrypt it;
  • the SM-SR performs secure routing, loading, deleting, activating, deactivating, and the like on the profile prepared and encrypted by the SM-DP.
  • One SM-DP and one SM-SR form a contract management (Subscription Manager, SM) equipment, also known as remote management platform;
  • SM Subscribescription Manager
  • the eUICC terminal is a terminal embedded in the UICC and needs to be remotely configured, and is referred to as a terminal in this specification.
  • FIG. 1 is a schematic diagram of an eUICC network architecture.
  • the relationship between MNO, SM-DP, and SM-SR is illustrated by taking the components in FIG. 1 as an example.
  • SM1 consisting of SM1-DP and SM1-SR.
  • SM1 is responsible for the contract management of MNO1;
  • SM2 and SM2 composed of SM2-DP and SM2-SR are responsible for the contract management of MNO2, SM3-DP and SM3-
  • the SM3 and SM3 composed of SR are responsible for the contract management of MNO3.
  • FIG. 1 shows the internal logic structure of the eUICC.
  • the modules related to the present invention include:
  • Profile The Installer, PI is used to verify, decrypt, install, and manage files, and belongs to the same logical layer as SM-DP;
  • Profile Block The manager, PM is used to load, delete, activate or deactivate the profile, which belongs to the same logical layer as the SM-SR.
  • Preparatory file Profile is used to download the executable file OP (operational Profile), including information such as the application and key required to establish a connection and transmission between the terminal and the SM-SR.
  • the operational profile OP includes one or more network access applications.
  • NAA Network Access Application
  • OP#1 indicates the OP currently being used
  • OP#2 indicates the OP to be loaded into the eUICC in the future.
  • NAA is a network access application that provides authentication when accessing the network.
  • NAA0, NAA1, and NAA 2 are for indicating different NAAs.
  • Figure 3 shows the certificate assignment diagram
  • Profile Installer Credential is a key existing on the eUICC and SM side to ensure that the eUICC correctly decrypts and installs an encrypted profile obtained from the outside.
  • Key pair PIC-PKT is used in the present invention /PIC-KT.
  • the public key PIC-PKT is stored in the SM-DP for encrypting the profile, and the private key PIC-KT is used to decrypt the received encrypted profile.
  • the private key PIC-KT is included in the eUICC.
  • the key pair can be generated by an eUICC or SM or a third party entity in the terminal. In the present invention, before the terminal works normally, the public key and the private key in the key pair have been stored on the eUICC of the terminal and the SM to which the terminal belongs.
  • Profile Management Credential is the key of the eUICC and SM side of the terminal, which is used to ensure secure and reliable communication between the eUICC and the outside.
  • Key pair PKT / KT is used in the present invention .
  • the public key PKT is stored in the SM-SR and is used to encrypt routing requests or profiles.
  • Private key KT It is stored on the eUICC of the terminal and used to decrypt the received encrypted data.
  • the key is included in the eUICC.
  • the key pair can be generated by an eUICC or SM or a third party entity.
  • Contract Management Security Routing Unit Access Certificate (SM-SR Access) Credential) is an access certificate for the SM to authenticate the terminal, and is generated by the SM.
  • the eUICC contains the key and has a corresponding record on the SM side.
  • the prior art can implement the subscription switching in a single SM, that is, the user subscription information of the MMO1 and the MMO2 are all managed by the SM1, and the terminal can use the subscription information to switch the user subscription from the MMO1 to the MMO2 through the SM1.
  • the user has signed up with MNO1 and works normally and accesses the network of MNO1.
  • the user wants to switch the subscription to MNO2 for various reasons.
  • the switching process is:
  • the terminal initiates a change signing request to SM1;
  • the SM1-SR receives the replacement subscription request and initiates a data preparation request to the SM1-DP.
  • SM1-DP returns the prepared OP#2 to SM1-SR;
  • the terminal uses OP#2 to access the network of the MNO2;
  • the terminal returns the status of OP#2 to SM1.
  • the above process omits the process of encryption and decryption and authentication in the process of replacing the contract.
  • the switchover of the prior art can only be switched within the same SM.
  • the UE requests to switch from the MNO1 to the MNO2, and the MNO1 and the MNO2 are managed by different subscription management entities SM, the cross-SM cannot be implemented according to the prior art technical solution. Switch the contract.
  • An object of the present invention is to provide a remote change subscription method, which aims to solve the problem that the existing technical solution cannot achieve cross-SM handover subscription.
  • a first aspect of the present invention provides a remote change signing method for a terminal, the method comprising:
  • the execution file is activated, and the activated target file is used to access the target carrier network.
  • the target remote management platform is determined by the source remote management platform according to the change subscription request message, and specifically includes:
  • the source remote management platform determines, according to the target operator information in the change subscription request message and the current location information of the terminal, where the current location information of the terminal is carried in the change subscription request message or remotely from the source.
  • the management platform obtains from the home location register of the terminal/home subscriber server query
  • the execution file of the target carrier network that is sent by the receiving target remote management platform according to the change subscription request message includes:
  • the execution file of the target carrier network that is sent by the receiving target remote management platform according to the change subscription request message includes:
  • the target remote management platform encrypts the change subscription request response message by using a public key of the first key pair, and the terminal decrypts the change subscription by using a private key of the first key pair after receiving the change subscription response message.
  • Response message ; and/or
  • the target remote management platform encrypts the execution file of the target carrier network by using the public key of the second key pair, and the terminal adopts the second key pair after receiving the executed file of the encrypted target carrier network.
  • the private key decrypts the executable file of the encrypted target carrier network to obtain an execution file of the target carrier network.
  • the method further includes:
  • the terminal generates a third key pair and a fourth key pair, and sends the public key in the third and fourth key pairs to the target remote management platform.
  • a second aspect of the present invention provides a remote change subscription method for a source remote management platform, the method comprising:
  • the source remote management platform receives the change subscription request message sent by the terminal, where the change subscription request message is used to request to change the subscription of the terminal to the target operator, and the source remote management platform remotely manages the target operator according to the change subscription request message. platform;
  • the source remote management platform sends the change subscription request message to the target remote management platform, so that the terminal acquires an execution file of the target carrier network from the target remote management platform.
  • the source remote management platform according to the change subscription request message, the target remote management platform of the target operator, specifically includes:
  • the source remote management platform determines the target remote management platform of the target operator according to the target operator information in the change subscription request message and the current location information of the terminal, where the current location information of the terminal is carried in the change subscription
  • the request message is either obtained by the source remote management platform from the home location register/home subscriber server of the terminal.
  • the acquiring, by the terminal, the execution file of the target carrier network from the target remote management platform specifically includes:
  • the terminal Sending, by the terminal, the response message carrying the address information of the target remote management platform to the terminal, so that the terminal establishes a connection with the target remote management platform according to the address information of the target remote management platform, and passes the The connection acquires an execution file of the target carrier network.
  • the acquiring, by the terminal, the execution file of the target carrier network from the target remote management platform specifically includes:
  • the source remote management platform receives the change subscription request response message returned by the target remote management platform according to the change subscription request.
  • the response message carries address information of the target remote management platform and a temporary access certificate of the target remote management platform,
  • the terminal Sending, by the terminal, the response message carrying the address information of the target remote management platform and the temporary access certificate to the terminal, so that the terminal establishes a connection with the target remote management platform according to the address information of the target remote management platform.
  • the execution file of the target carrier network is obtained through the connection.
  • the acquiring, by the terminal, the execution file of the target carrier network from the target remote management platform specifically includes:
  • a third aspect of the present invention provides a remote change signing method for a target remote management platform, the method comprising:
  • the target remote management platform receives the change subscription request message sent by the source remote management platform, and the change subscription request message is sent by the terminal to the source remote management platform, for requesting to change the subscription of the terminal to the target operator;
  • the target remote management platform provides the terminal with an execution file of the target carrier network requested by the terminal.
  • the target remote management platform provides the terminal with an execution file of the target carrier network that is requested by the terminal, and specifically includes:
  • the target remote management platform returns a change subscription request response message of the change contract request to the source remote management platform, so that the source remote management platform sends the response message to the terminal, where the response message includes: Address information of the target remote management platform;
  • the target remote management platform establishes a connection with the terminal, and sends an execution file of the target carrier network to the terminal through the connection.
  • the target remote management platform provides the terminal with an execution file of the target carrier network that is requested by the terminal, and specifically includes:
  • the target remote management platform returns a change subscription request response message of the change contract request to the source remote management platform, so that the source remote management platform sends the response message to the terminal, where the response message includes: The address information of the target remote management platform and the temporary access certificate of the target remote management platform;
  • the target remote management platform establishes a connection with the terminal, and after completing the verification of the terminal according to the temporary access certificate, sends an execution file of the target carrier network requested by the terminal to the terminal.
  • the target remote management platform provides the terminal with an execution file of the target carrier network that is requested by the terminal, and specifically includes:
  • a change subscription request response message carrying an execution file of the target carrier network to the source remote management platform according to the change subscription request message, so that the source remote management platform sends the response message To the terminal.
  • a fourth aspect of the present invention provides a remote change subscription device for a terminal, the device comprising:
  • a sending unit configured to send a change subscription request message to the source remote management platform of the source operator, so that the source remote management platform sends the change subscription request message to the target remote management platform of the target operator, where the change subscription request is The message is used to request to change the subscription of the user to which the terminal belongs to the target operator, and the target remote management platform is determined by the source remote management platform according to the change subscription request message.
  • a receiving unit configured to receive an execution file of the target carrier network that is provided by the target remote management platform according to the change subscription request message
  • an activation unit configured to activate the execution file, and access the target carrier network by using the activated execution file.
  • the receiving unit includes:
  • a first receiving module configured to receive a change subscription request response message returned by the target remote management platform sent by the source remote management platform, where the response message includes address information of the target remote management platform;
  • a first execution file obtaining submodule configured to establish a connection with the target remote management platform according to the address information of the target remote management platform, and obtain an execution file of the target carrier network through the connection, or
  • a second receiving module configured to receive a change subscription request response message returned by the target remote management platform sent by the source remote management platform, where the response message includes address information of the target remote management platform and a temporary access certificate of the target remote management platform;
  • a second execution file obtaining submodule configured to establish a connection with the target remote management platform according to the address information of the target remote management platform, and complete the authentication with the target remote management platform according to the temporary access certificate, and pass the The connection obtains an execution file of the target carrier network, or
  • a third receiving module configured to receive a change subscription request response message returned by the target remote management platform sent by the source remote management platform, where the response message carries an execution file of the target carrier network;
  • a third execution file obtaining submodule configured to obtain an execution file of the target carrier network from the response message.
  • the device also includes:
  • the decryption unit is configured to decrypt the response message and the execution file respectively by using the private key in the key pair.
  • the decryption unit decrypts the change subscription response message by using the private key of the first key pair to obtain the change.
  • the decryption unit 74 uses the private key of the second key pair to execute the file of the encrypted target carrier network. Decrypt to obtain the execution file of the target carrier network, or,
  • the target remote management platform uses the public key of the third key pair to obtain a response message for executing the file request message
  • the response message is sent by the target remote management platform according to the terminal after the terminal establishes a connection with the target remote management platform.
  • the decryption unit decrypting the response message of the execution execution file request message by using the private key of the third key pair to obtain the execution file response message of the acquisition target carrier network Encrypted executable file, or,
  • the decryption unit 74 decrypts the acquisition execution file by using the private key of the fourth key pair.
  • the encrypted execution file carried in the response message of the request message is obtained to obtain the decrypted execution file carried in the execution file response message of the target carrier network.
  • the apparatus further includes:
  • a key generation unit configured to generate a third key pair and a fourth key pair, where the third and fourth key pairs are used to respectively obtain a response message for executing a file request message and a target carried in the response message
  • the execution file of the carrier network is encrypted and decrypted.
  • the response message is a response message returned by the target remote management platform according to the acquired execution file request message sent by the terminal after the terminal establishes a connection with the target remote management platform.
  • a fifth aspect of the present invention provides a remote change subscription device for a source remote management platform, the device comprising:
  • a request message receiving unit configured to receive a change subscription request message sent by the terminal, where the change subscription request message is used to request to change the subscription of the terminal to the target operator;
  • a determining unit configured to determine a target remote management platform of the target operator according to the change subscription request message
  • a request message sending unit configured to send the change subscription request message to the target remote management platform, so that the terminal can acquire an execution file of the target carrier network from the target remote management platform.
  • the device further includes:
  • a first response message receiving unit configured to receive a change subscription request response message returned by the target remote management platform according to the change subscription request, where the response message carries address information of the target remote management platform;
  • a first response message sending unit configured to send the response message carrying the address information of the target remote management platform to the terminal, so that the terminal according to the address information of the target remote management platform and the The target remote management platform establishes a connection, and acquires an execution file of the target carrier network through the connection.
  • the second response message receiving unit is configured to receive a change subscription request response message returned by the target remote management platform according to the change subscription request.
  • the response message carries address information of the target remote management platform and a temporary access certificate of the target remote management platform;
  • a second response message sending unit configured to send the response message carrying the address information of the target remote management platform and the temporary access certificate to the terminal, so that the terminal according to the address information of the target remote management platform
  • the execution file of the target carrier network is obtained through the connection.
  • a third response message receiving unit configured to receive a change subscription request response message returned by the target remote management platform according to the change subscription request message, where the response message carries an execution file of the target carrier network;
  • a third response message sending unit configured to send the response message that carries the execution file of the target operator to the terminal, so that the terminal acquires an execution file of the target carrier network.
  • a sixth aspect of the present invention provides a remote change subscription device for a target remote management platform, the device comprising:
  • a request message receiving unit configured to receive a change subscription request message sent by the source remote management platform, where the change subscription request message is sent by the terminal to the source remote management platform, to request to change the subscription of the terminal to the target operator;
  • an execution file sending unit configured to provide, to the terminal, an execution file of the target carrier network requested by the terminal.
  • the execution file sending unit specifically includes:
  • a first response message sending module configured to return a change subscription request response message of the change contract request to the source remote management platform, so that the source remote management platform sends the response message to the terminal, the response
  • the message includes: address information of the target remote management platform;
  • a first execution file sending module configured to establish a connection between the target remote management platform and the terminal, and send an execution file of the target carrier network to the terminal by using the connection.
  • a second response message sending module configured to return a change subscription request response message of the change contract request to the source remote management platform, so that the source remote management platform sends the response message to the terminal, the response
  • the message includes: address information of the target remote management platform and a temporary access certificate of the target remote management platform;
  • a second execution file sending module configured to establish a connection between the target remote management platform and the terminal, and after the verification of the terminal is completed according to the temporary access certificate, send the terminal request to the terminal
  • the execution file of the target carrier network or,
  • a third response message sending module configured to return, to the source remote management platform, a change subscription request response message carrying an execution file of the target carrier network according to the change subscription request message, so that the source remote management platform A response message is sent to the terminal.
  • the device further includes:
  • An encryption unit for encrypting a response message or an execution file by using a public key in a key pair
  • the encryption unit encrypts the change subscription request response message by using a public key of the first key pair.
  • the encryption unit encrypts an execution file of the target carrier network by using a public key of the second key pair.
  • the encryption unit obtains a response message for executing the file request message by using the public key of the third key pair, and the response message is executed by the target remote management platform according to the acquisition sent by the terminal after the terminal establishes a connection with the target remote management platform.
  • the response message returned by the file request message.
  • the encryption unit uses the public key of the fourth key pair to obtain an execution file carried in the response message of the execution file request message, where the response message is established by the target remote management platform after the terminal establishes a connection with the target remote management platform.
  • the response message sent by the terminal to obtain the execution file request message.
  • the terminal after the terminal sends a change subscription request message to the source remote management platform of the source operator, the terminal receives the execution file of the target carrier network provided by the target remote management platform, and activates the execution.
  • the file realizes the access of the target operator network, so that the above method realizes the switch signing across the remote management platform, that is, the signing change to the target remote management platform by connecting with the source remote management platform, and realizing the signing change of the cross-remote management platform.
  • FIG. 1 is a schematic diagram of an existing eUICC network architecture
  • FIG. 2 is a schematic diagram of an internal logical structure of an existing eUICC
  • Figure 3 is a diagram showing the distribution of existing certificates
  • FIG. 5, and FIG. 6 are flowcharts of a remote change signing method according to an embodiment of the present invention.
  • FIG. 7, FIG. 8, and FIG. 9 are flowcharts of a remote change signing device according to an embodiment of the present invention.
  • FIG. 10 is a schematic diagram of a technical scenario for implementing a remote change subscription method according to an embodiment of the present invention.
  • FIG. 11 is a flowchart of a remote change signing method according to an embodiment of the present invention.
  • FIG. 12 is a flowchart of a remote change signing method according to another embodiment of the present invention.
  • FIG. 13 is a flowchart of a remote change subscription method according to still another embodiment of the present invention.
  • FIG. 14 is a block diagram showing the hardware structure of a terminal according to an embodiment of the present invention.
  • FIG. 15 is a structural diagram of an apparatus according to an embodiment of the present invention.
  • a specific embodiment of the present invention provides a remote change signing method for a terminal, which is executed by a terminal, as shown in FIG. 4, and includes:
  • the terminal sends a change subscription request message to the source remote management platform of the source operator, so that the source remote management platform sends the change subscription request message to the target remote management platform of the target operator.
  • the change subscription request message is used to request to change the subscription of the terminal to the target operator.
  • the target remote management platform is determined by the source remote management platform according to the change subscription request message.
  • the source remote management platform may determine the target remote management platform of the target operator according to the target operator information in the change subscription request message and the current location information of the terminal.
  • the current location information of the terminal may be carried in the change subscription request message, or may be obtained by the source remote management platform from the home location register of the terminal/home subscriber server.
  • the terminal receives an execution file of the target carrier network that is provided by the target remote management platform according to the change subscription request message.
  • the terminal activates the execution file, and accesses the target carrier network by using the activated execution file.
  • the method provided by the specific embodiment of the present invention sends a change subscription request message to the source remote management platform of the source operator, receives an execution file of the target carrier network provided by the target remote management platform, and activates the execution file to implement the target carrier network. Access, thus achieving cross-transportation platform switching contract, that is, through the source remote management platform and the target remote management platform, to achieve cross-remote management platform signing changes.
  • step S42 includes at least the following three specific implementation manners:
  • step S42 may specifically include:
  • the terminal receives the change subscription request response message returned by the target remote management platform sent by the source remote management platform, where the response message includes address information of the target remote management platform.
  • the terminal establishes a connection with the target remote management platform according to the address information of the target remote management platform, and acquires an execution file of the target carrier network through the connection.
  • the obtaining the execution file of the target carrier network may be based on the connection, and the terminal requests the target remote management platform to send the execution file of the target carrier network, or the target remote management platform directly sends the target operator network. Execution file.
  • step S42 may specifically include:
  • the terminal receives the change subscription request response message returned by the target remote management platform sent by the source remote management platform, where the response message includes the address information of the target remote management platform and the temporary access certificate of the target remote management platform;
  • the terminal After the terminal establishes a connection with the target remote management platform according to the address information of the target remote management platform, and completes the authentication with the target remote management platform according to the temporary access certificate, the terminal acquires the target carrier network through the connection. Execution file.
  • the obtaining the execution file of the target carrier network may be based on the connection, and the terminal requests the target remote management platform to send the execution file of the target carrier network, or the target remote management platform directly sends the target operator network. Execution file.
  • the foregoing manner 1 and/or method 2 further includes:
  • the target remote management platform encrypts the change subscription request response message by using a public key of the first key pair. After receiving the encrypted change subscription response message, the terminal decrypts the change subscription response message by using a private key of the first key pair to obtain a temporary access certificate and/or target in the change subscription response message.
  • Remote management platform address information
  • the target remote management platform may encrypt the execution file of the target carrier network by using a public key of the second key pair.
  • the above manner 1 and/or method 2 further includes:
  • the terminal After receiving the executable file of the encrypted target carrier network, the terminal decrypts the executable file of the encrypted target carrier network by using the private key of the second key pair to obtain an execution file of the target carrier network.
  • the foregoing first key pair and the second key pair may be separately used to encrypt and decrypt the response message or the execution file, or may be used simultaneously, and the response message is encrypted and decrypted by the first key pair, and the second key is used. Encrypt and decrypt the executable file.
  • the obtaining the execution file of the target carrier network by using the connection may include:
  • the terminal generates a third and fourth key pair, and sends the public key in the third and fourth key pairs to the target remote management platform, where the public key in the third and fourth key pairs may be sent. Sending by a key update request message;
  • the terminal sends a Get Execution File Request message to the target remote management platform, where the request message may be encrypted by the private key in the third key pair;
  • the target remote management platform receives the acquisition execution file request message, and may decrypt the request message by the public key in the third key pair;
  • the target remote management platform provides an execution file of the target carrier network according to the Get Execution File Request message, where the execution file of the target carrier network is carried by a response message for acquiring an Execution File Request message, and the response message may be
  • the public key of the triple key pair is encrypted, and the execution file may be encrypted by the public key of the fourth key pair.
  • the terminal may decrypt the private key of the third key pair to obtain the decrypted response message, and the fourth key pair is used in the response message.
  • the execution file of the target carrier network of the key encryption uses the private key of the fourth key pair to decrypt the execution file of the encrypted target carrier network to obtain the execution file of the target carrier network.
  • step S42 may specifically include:
  • the terminal acquires an execution file of the target carrier network from the response message.
  • the response message and the execution file may be encrypted, and the step S42 may specifically include:
  • the target remote management platform sent by the terminal receiving source remote management platform returns a change subscription request response message encrypted by the public key of the first key pair, and the response message carries the public key encrypted by the second key pair.
  • the execution file of the target carrier network
  • the terminal decrypts the response message by using the private key of the first key pair, acquires the change subscription request response message, and uses the private key of the second key pair to the encrypted target carrier network.
  • the execution file is decrypted to obtain the execution file of the target carrier network.
  • the above encryption process is implemented by the target remote management platform.
  • the first and second key pairs may be pre-stored in the terminal device and the source remote management platform. For example, when signing a contract, the operator writes the terminal to the source remote management platform.
  • the public key in the first and second key pairs of the target remote management platform can be received from the source remote management platform.
  • the first key pair and the second key pair may be the same key pair, or may be different key pairs.
  • the first key pair may be a PKT/KT key pair.
  • the second key pair can be a PIC-PKT/PIC-KT.
  • the third and fourth key pairs are different key pairs from the first and second key pairs.
  • the specific embodiment of the present invention further provides a remote change subscription method for a source remote management platform, which is executed by a source remote management platform. As shown in FIG. 5, the method includes:
  • the source remote management platform receives the change subscription request message sent by the terminal.
  • the change subscription request message is used to request to change the subscription of the terminal to the target operator.
  • the source remote management platform determines the target remote management platform of the target operator according to the change subscription request message.
  • the request message includes target operator information.
  • the source remote management platform determines the target remote management platform of the target operator according to the target operator information in the change subscription request message and the current location information of the terminal, where the current location information of the terminal may be carried in the change
  • the subscription request message is either obtained by the source remote management platform from the home location register/home subscriber server (HLR/HSS) query of the terminal.
  • HLR/HSS home location register/home subscriber server
  • the source remote management platform determines the remote management platform of the target operator where the terminal is currently located according to the location information included in the change subscription request message.
  • the source remote management platform can query the HLR/HSS, and the HLR/HSS returns the current location of the terminal user, and the source remote management platform determines the current location of the terminal by using the received location information.
  • Location of the target operator's remote management platform Specifically, the operator can maintain a correspondence table between the location of the terminal, the operator, and the corresponding remote management platform address on the remote management platform, so that the source remote management platform can determine the current terminal according to the target operator and location information requested by the user.
  • the remote management platform of the target operator at the location The information about the current location of the terminal may be the country code of the network where the terminal is currently located, or the tracking area identifier TAI, the routing area identifier RAI, or the location area identifier LAI where the terminal is currently located.
  • the location information of the terminal may also be the identifier of the network entity where the terminal is currently located, such as the identifier information or the address information of the MME or the SGSN. This embodiment does not limit this.
  • the target remote management platform defaults to the remote management platform of the target operator that the source remote management platform can connect to.
  • the source remote management platform sends the change subscription request message to the target remote management platform, so that the terminal can obtain an execution file of the target carrier network from the target remote management platform.
  • the source remote management platform sends the change subscription request message to the target remote management platform, so that the target remote management platform can provide the execution file of the target carrier network required for the terminal handover. Therefore, the method provided by the embodiment of the present invention can implement switching subscriptions across a remote management platform.
  • the terminal obtains the execution file of the target carrier network from the target remote management platform, and may include at least the following three modes:
  • the execution file of the target carrier network is obtained from the target remote management platform, and specifically includes:
  • the source remote management platform receives the change subscription request response message returned by the target remote management platform according to the change subscription request.
  • the response message carries address information of the target remote management platform.
  • the terminal Sending, by the terminal, the response message carrying the address information of the target remote management platform to the terminal, so that the terminal establishes a connection with the target remote management platform according to the address information of the target remote management platform, and passes the The connection acquires an execution file of the target carrier network.
  • the execution file of the target carrier network is obtained from the target remote management platform, and specifically includes:
  • the source remote management platform receives the change subscription request response message returned by the target remote management platform according to the change subscription request.
  • the response message carries address information of the target remote management platform and a temporary access certificate of the target remote management platform,
  • the terminal Sending, by the terminal, the response message carrying the address information of the target remote management platform and the temporary access certificate to the terminal, so that the terminal establishes a connection with the target remote management platform according to the address information of the target remote management platform.
  • the execution file of the target carrier network is obtained through the connection.
  • the execution file of the target carrier network is obtained from the target remote management platform, and specifically includes:
  • the source remote management platform receives the change subscription request response message returned by the target remote management platform according to the change subscription request message, where the response message carries an execution file of the target carrier network;
  • the response message may be encrypted by the public key of the first key pair, and the execution file of the target carrier network carried in the response message may be publicized by the second key pair.
  • the terminal may use the private key of the first key pair to decrypt the response message, obtain the response message, and use the private key pair of the second key pair.
  • the executable file of the encrypted target carrier network is decrypted to obtain an execution file of the target carrier network.
  • the first and second key pairs may be pre-stored in the terminal and the source remote management platform.
  • the terminal writes the terminal and the source remote management platform, and the target remote management platform is the first.
  • the public key of the second key pair can be sent by the source remote management platform.
  • the first key pair and the second key pair may be the same key pair, or may be different key pairs.
  • the first key pair may be a PKT/KT key pair.
  • the second key pair can be a PIC-PKT/PIC-KT.
  • the embodiment of the present invention further provides a remote change signing method for a target remote management platform, which is executed by a target remote management platform, as shown in FIG. 6, the method includes:
  • the target remote management platform receives the change subscription request message sent by the source remote management platform.
  • the change subscription request message is sent by the terminal to the source remote management platform and sent by the source remote management platform to the target remote management platform.
  • the change subscription request message is used to request to change the subscription of the terminal to the target operator.
  • the target remote management platform provides the terminal with an execution file of the target carrier network requested by the terminal.
  • the target remote management platform receives the change subscription request message sent by the source remote management platform, and provides the execution file of the target carrier network to the terminal, so that the terminal achieves the target according to the execution file. Access to the carrier network.
  • the above method implements switching subscriptions across remote management platforms.
  • step S62 includes at least the following three implementation manners.
  • step S62 may specifically include:
  • the target remote management platform returns a change subscription request response message of the change contract request to the source remote management platform, so that the source remote management platform sends the response message to the terminal, where the response message includes: Address information of the target remote management platform;
  • the target remote management platform establishes a connection with the terminal, and sends an execution file of the target carrier network to the terminal through the connection.
  • step S62 may specifically include: the target remote management platform returns a change subscription request response message of the change subscription request to the source remote management platform, so that the source remote The management platform sends the response message to the terminal.
  • the response message includes: address information of the target remote management platform and a temporary access certificate of the target remote management platform;
  • the target remote management platform establishes a connection with the terminal, and after completing the verification of the terminal according to the temporary access certificate, sends an execution file of the target carrier network requested by the terminal to the terminal.
  • the target remote management platform establishes a connection with the terminal, and sends an execution file of the target carrier network to the terminal by using the connection, which may specifically include
  • the target remote management platform receives the acquisition execution file request message sent by the terminal to obtain the execution file of the target operator.
  • the obtaining the execution file request message is sent to the target remote management platform after the terminal receives the address information of the target remote management platform in the change subscription request response message.
  • the target remote management platform After receiving the operation file request message, the target remote management platform returns a response message for obtaining the execution file request message to the terminal.
  • the response message of the acquiring the file request message carries the execution file of the target carrier network.
  • the method may further include:
  • the terminal sends an acquisition execution file request message to the target remote management platform according to the address information of the target remote management platform in the change subscription request response message.
  • the target operator remote management platform returns a response message of the execution file request message to the terminal, where the response message of the execution file request message carries the execution file of the target carrier network, which may include:
  • the terminal sends a Get Execution File Request message to the target remote management platform, where the request message may be encrypted by the private key in the third key pair;
  • the target remote management platform receives the get executable file request message, and may decrypt the request message by using the public key in the third key pair;
  • the target remote management platform provides an execution file of the target carrier network according to the Get Execution File Request message.
  • the execution file of the target carrier network is carried by a response message for obtaining an execution file request message.
  • the response message may be encrypted by a public key of a third key pair, which may be encrypted by a public key of the fourth key pair.
  • the terminal may decrypt the private key of the third key pair to obtain a response message for obtaining the execution file request message, where the response message is fourth.
  • the execution file of the target carrier network encrypted by the key to the public key is decrypted by the private key of the fourth key pair to obtain the execution file of the target carrier network.
  • step S62 may specifically include: the target remote management platform returns a change of the execution file carrying the target carrier network to the source remote management platform according to the change subscription request message.
  • the subscription request response message is sent to the source remote management platform to send the response message to the terminal.
  • the response message may be encrypted by the public key of the first key pair, and the execution file of the target carrier network carried in the response message may be encrypted by the public key of the second key pair;
  • the terminal may use the private key of the first key pair to decrypt the response message, obtain the response message, and use the private key pair of the second key pair.
  • the executable file of the encrypted target carrier network is decrypted to obtain an execution file of the target carrier network.
  • the first and second key pairs may be pre-stored in the terminal device and the source remote management platform.
  • the operator writes the terminal and the source remote management platform, and the source remote management platform can send the public key in the first and second key pairs to the target remote management platform.
  • the first key pair and the second key pair may be the same key pair, or may be different key pairs.
  • the first key pair may be a PKT/KT key pair.
  • the second key pair can be a PIC-PKT/PIC-KT.
  • a specific embodiment of the present invention provides a remote change signing device for a terminal. As shown in FIG. 7, the method includes:
  • the sending unit 71 is configured to send a change subscription request message to the source remote management platform of the source operator, so that the source remote management platform sends the change subscription request message to the target remote management platform of the target operator, where the change subscription is
  • the request message is used to request to change the terminal subscription to the target operator, and the target remote management platform is determined by the source remote management platform according to the change subscription request message;
  • the receiving unit 72 is configured to receive an execution file of the target carrier network that is provided by the target remote management platform according to the change subscription request message;
  • the activation unit 73 is configured to activate the execution file, and access the target carrier network by using the activated execution file.
  • the receiving unit 72 includes:
  • the first receiving module 721 is configured to receive a change subscription request response message returned by the target remote management platform sent by the source remote management platform, where the response message includes address information of the target remote management platform;
  • the first execution file obtaining sub-module 722 is configured to establish a connection with the target remote management platform according to the address information of the target remote management platform, and obtain an execution file of the target carrier network through the connection. or,
  • the second receiving module 723 is configured to receive a change subscription request response message returned by the target remote management platform sent by the source remote management platform, where the response message includes address information of the target remote management platform and a temporary access certificate of the target remote management platform;
  • a second execution file obtaining sub-module 724 configured to establish a connection with the target remote management platform according to the address information of the target remote management platform, and complete the authentication with the target remote management platform according to the temporary access certificate, and then The connection acquires an execution file of the target carrier network.
  • the third receiving module 725 is configured to receive a change subscription request response message returned by the target remote management platform sent by the source remote management platform, where the response message carries an execution file of the target carrier network;
  • the third execution file obtaining sub-module 726 is configured to obtain an execution file of the target carrier network from the response message.
  • the apparatus of the embodiment of the present invention may further include:
  • the decryption unit 74 is configured to decrypt the response message and the execution file respectively by using the private key in the key pair.
  • the target remote management platform may encrypt the change subscription request response message by using a public key of the first key pair, and the terminal receiving unit 72 receives the change subscription response message. Then, the decryption unit 74 decrypts the change subscription response message by using the private key of the first key pair to obtain the temporary access certificate in the change subscription response message and/or the address information of the target remote management platform.
  • the target remote management platform may also encrypt the execution file of the target carrier network by using a public key of the second key pair, and the terminal receiving unit 72 receives the execution of the encrypted target carrier network.
  • the decryption unit 74 decrypts the executable file of the encrypted target carrier network by using the private key of the second key pair to obtain an execution file of the target carrier network.
  • the target remote management platform may also obtain a response message for executing a file request message by using a public key of the third key pair, where the response message is obtained by the target remotely after the terminal establishes a connection with the target remote management platform.
  • the management platform obtains the response message returned by the execution file request message sent by the terminal, and after the terminal receiving unit 72 receives the response message for acquiring the execution file request message, the decryption unit 74 decrypts the private key of the third key pair. Obtaining a response message of the execution file request message to obtain the encrypted execution file in the execution file response message of the acquisition target carrier network.
  • the target remote management platform may also use the public key of the fourth key pair to obtain an execution file carried in the response message of the execution file request message, and the terminal receiving unit 72 receives the acquisition execution file request.
  • the decryption unit 74 decrypts the encrypted execution file carried in the response message of the execution file request message by using the private key of the fourth key pair to obtain the execution file response of the acquisition target carrier network. The decrypted execution file carried in the message.
  • the apparatus of the embodiment of the present invention may further include:
  • the key generation unit 75 is configured to generate a third key pair and a fourth key pair, and the third and fourth key pairs are respectively used for respectively acquiring a response message for executing the file request message and the target carried in the response message.
  • the execution file of the carrier network is encrypted and decrypted.
  • the response message is a response message returned by the target remote management platform according to the acquired execution file request message sent by the terminal after the terminal establishes a connection with the target remote management platform.
  • a specific embodiment of the present invention provides a remote change subscription device for a source remote management platform. As shown in FIG. 8, the device includes:
  • the request message receiving unit 81 is configured to receive a change subscription request message sent by the terminal, where the change subscription request message is used to request to change the subscription of the terminal to the target operator;
  • a determining unit 82 configured to determine, according to the change subscription request message, a target remote management platform of the target operator
  • the request message includes target operator information.
  • the source remote management platform determines the target remote management platform of the target operator according to the target operator information in the change subscription request message and the current location information of the terminal, where the current location information of the terminal is carried in the change subscription
  • the request message is either obtained by the source remote management platform from the home location register/home subscriber server (HLR/HSS) query of the terminal.
  • HLR/HSS home location register/home subscriber server
  • the source remote management platform determines, according to the location information included in the change subscription request message, a remote management platform of the target operator where the terminal is currently located.
  • the source remote management platform can query the HLR/HSS, and the HLR/HSS returns the current location of the terminal user, and the source remote management platform determines the current location of the terminal by using the received location information.
  • Location of the target operator's remote management platform Specifically, the operator can maintain a list of the location of the terminal, the operator, and the corresponding remote management platform address in the remote management platform, so that the source remote management platform determines the current location of the terminal according to the target operator and location information requested by the user.
  • the remote management platform of the target operator wherein the information terminal indicating the current location of the terminal may be the country code of the current network of the terminal, indicating that the current location information of the terminal may also be the tracking area identifier TAI and routing area where the terminal is currently located.
  • the identifier of the RAI or the location area identifier LAI which indicates that the location information of the terminal is currently located, may also be the identifier of the network entity where the terminal is currently located, such as the identifier information or the address information of the MME or the SGSN, which is not limited in this embodiment.
  • the target remote management platform defaults to the remote management platform of the target operator that the source remote management platform can connect to.
  • the request message sending unit 83 is configured to send the change subscription request message to the target remote management platform, so that the terminal can acquire an execution file of the target carrier network from the target remote management platform.
  • the device also includes:
  • the first response message receiving unit 84 is configured to receive a change subscription request response message returned by the target remote management platform according to the change subscription request, where the response message carries address information of the target remote management platform;
  • the first response message sending unit 85 is configured to send the response message carrying the address information of the target remote management platform to the terminal, so that the terminal according to the address information and location of the target remote management platform
  • the target remote management platform establishes a connection, and obtains an execution file of the target carrier network through the connection.
  • the second response message receiving unit 86 is configured to receive a change subscription request response message returned by the target remote management platform according to the change subscription request.
  • the response message carries address information of the target remote management platform and a temporary access certificate of the target remote management platform;
  • a second response message sending unit 87 configured to send the response message carrying the address information of the target remote management platform and the temporary access certificate to the terminal, so that the terminal according to the address of the target remote management platform
  • the information is connected to the target remote management platform, and after the authentication with the target remote management platform is completed according to the temporary access certificate, the execution file of the target carrier network is obtained through the connection.
  • the third response message receiving unit 88 is configured to receive a change subscription request response message that is returned by the target remote management platform according to the change subscription request message, where the response message carries an execution file of the target carrier network;
  • the third response message sending unit 89 is configured to send the response message carrying the execution file of the target operator to the terminal, so that the terminal acquires an execution file of the target carrier network.
  • a specific embodiment of the present invention provides a remote change signing device for a target remote management platform. As shown in FIG. 9, the method includes:
  • the request message receiving unit 91 is configured to receive a change subscription request message sent by the source remote management platform, where the change subscription request message is sent by the terminal to the source remote management platform, for requesting to change the subscription of the terminal to the target operator;
  • the execution file sending unit 92 is configured to provide the terminal with an execution file of the target carrier network requested by the terminal.
  • the execution file sending unit 92 may specifically include:
  • the first response message sending module 921 is configured to return a change subscription request response message of the change contract request to the source remote management platform, so that the source remote management platform sends the response message to the terminal,
  • the response message includes: address information of the target remote management platform;
  • the first execution file sending module 922 is configured to establish a connection between the target remote management platform and the terminal, and send an execution file of the target carrier network to the terminal by using the connection. or,
  • a second response message sending module 923 configured to return a change subscription request response message of the change contract request to the source remote management platform, so that the source remote management platform sends the response message to the terminal,
  • the response message includes: address information of the target remote management platform and a temporary access certificate of the target remote management platform;
  • a second execution file sending module 924 configured to establish a connection between the target remote management platform and the terminal, and after the verification of the terminal is completed according to the temporary access certificate, send the terminal request to the terminal An execution file of the target carrier network;
  • the third response message sending module 925 is configured to return, to the source remote management platform, a change subscription request response message carrying the execution file of the target carrier network according to the change subscription request message, so that the source remote management platform will The response message is sent to the terminal.
  • the device further includes:
  • the encryption unit 93 is configured to encrypt the response message or the execution file by using the public key in the key pair.
  • the encryption unit 93 may encrypt the change subscription request response message by using a public key of the first key pair. or,
  • the encryption unit 93 may also encrypt the execution file of the target carrier network by using the public key of the second key pair. or,
  • the encryption unit 93 may also use the public key of the third key pair to obtain a response message for executing the file request message, where the response message is sent by the target remote management platform according to the terminal after the terminal establishes a connection with the target remote management platform. Get the response message returned by the execution file request message. or,
  • the encryption unit 93 may also use the public key of the fourth key pair to obtain an execution file carried in the response message of executing the file request message, where the response message is after the terminal establishes a connection with the target remote management platform, and the target remote The management platform obtains a response message returned by the execution file request message according to the terminal.
  • This embodiment provides a remote change signing method, which is applied to the technical scenario shown in FIG. 10, and specifically includes:
  • the terminal includes an eUICC, and the eUICC includes: a PI module and a PM module.
  • the source remote management platform SM1 includes SM1-SR and SM1-DP, the source operator network MNO1, and the corresponding execution file is OP#1, and the user subscription of the MNO1 is managed by SM1.
  • the target remote management platform SM2 includes SM2-SR and SM2-DP, the target operator network MNO2, and the corresponding execution file is OP#2, and the user subscription of the MNO2 is managed by the SM2, wherein the SM1 does not govern the MNO2. Signing up.
  • the terminal is currently managed by the SM1 under the MNO1 network of the operator.
  • the user expects to change the subscription from MNO1 to MNO2.
  • the key pair required for the change process is already stored in the eUICC and the SM1 side of the UE.
  • the key pair is specifically: public key PIC-PKT And the private key PIC-KT, wherein the public key PIC-PKT is stored in the SM1-DP, the PIC-KT is stored in the PI module of the eUICC of the terminal; the public key PKT and the private key KT, wherein the public key PKT is stored in the SM1- In the SR, the KT is stored in the PM module of the eUICC of the terminal.
  • the method provided in this embodiment is as shown in FIG.
  • the PM module of the eUICC sends a change subscription request message to the SM1-SR, where the request message is used to request that the subscription of the terminal be changed from MNO1 to MMO2.
  • the request message carries: the target operator identification information, and optionally carries the location information of the current location of the terminal, where the current location information of the terminal may be the country code of the current network of the terminal, and the current location information of the terminal may also be
  • the current location information of the terminal may also be the identifier of the network entity where the terminal is currently located, such as the identifier information or address information of the MME or the SGSN.
  • the embodiment does not limit this.
  • the existing key is used for encryption and authentication between the terminal and the SM1-SR. This process uses the prior art and will not be described again.
  • the SM1-SR finds that the target remote management platform is the SM2 when the MNO2 is not in the scope of the jurisdiction, and the SM1-SR searches for the executable file stored by itself according to the target operator information MNO2 carried in the change subscription request message. Whether the execution file of the target carrier network exists. If the execution file of the target carrier network does not exist, it can be found that the MNO2 is not under its jurisdiction.
  • the process of determining the target remote management platform as SM2 includes:
  • the source remote management platform determines the remote management platform of the target operator where the terminal is currently located according to the location information included in the change subscription request message in step S1102.
  • the source remote management platform can query the HLR/HSS, and the HLR/HSS returns the current location of the terminal user, and the source remote management platform determines the current location of the terminal by using the received location information.
  • Location of the target operator's remote management platform Specifically, the operator can maintain a list of the location of the terminal, the operator, and the corresponding remote management platform address in the remote management platform, so that the source remote management platform determines the current location of the terminal according to the target operator and location information requested by the user.
  • the remote management platform of the target operator wherein the information terminal indicating the current location of the terminal may be the country code of the current network of the terminal, indicating that the current location information of the terminal may also be the tracking area identifier TAI and routing area where the terminal is currently located.
  • the identifier of the RAI or the location area identifier LAI which indicates that the location information of the terminal is currently located, may also be the identifier of the network entity where the terminal is currently located, such as the identifier information or the address information of the MME or the SGSN, which is not limited in this embodiment.
  • the target remote management platform defaults to the remote management platform of the target carrier network to which the source remote management platform can connect.
  • S1103, SM1-SR send the change subscription request message to the SM2-SR, and the change subscription request message is used to notify the SM2-SR that the terminal needs to replace the subscription to the MNO2;
  • S1104 and SM1-SR allow the SM2-SR to manage the subscription of the terminal user, and the SM2-SR can manage the subscription of the terminal.
  • the S1105 and the SM1-SR send the information of the eUICC to the SM2-SR, where the information of the eUICC includes: PIC-PKT, PKT, and eUICC related information (for example, eUICC identification information, etc.);
  • the information in this step may be carried by a separate signaling message or carried in the change subscription request message in step 1103.
  • SM2-SR request OP#2 file from SM2-DP, and send public key PIC-PKT and eUICC identification information to SM2-DP;
  • S1107 and SM2-DP request the network entity of the MNO2 to authenticate the user, apply for the IMSI, and obtain the OP#2 file.
  • SM2-DP encrypt the OP#2 file by using PIC-PKT, and send the encrypted OP#2 file to SM2-SR;
  • the SM2-SR returns a response message for changing the subscription request to the SM1-SR, where the response message carries the encrypted OP#2 file, and uses PKT to encrypt the response message of the change subscription request.
  • S1110 The SM1-SR returns a response message of the change subscription request carrying the encrypted OP#2 file to the terminal.
  • the PM module of the eUICC acquires the acquired profile file response message, and decrypts the response message of the change subscription request by using KT, acquires the encrypted OP#2 included in the response message, and obtains the acquired encryption.
  • OP#2 is sent to the PI module of eUICC;
  • S1112 The PI module of the eUICC decrypts the encrypted OP#2 file by using PIC-KT to obtain an activatable OP#2 file;
  • the PI module of the eUICC of the terminal installs the OP#2 file, activates the OP#2 file, and activates the OP#1 file;
  • the eUICC of the terminal establishes a fixed connection with the MNO2 through the NAA2 in the OP#2 file;
  • S1115 The PM module of the eUICC sends file status information to the SM1-SR, and the SM1-SR determines that the UE is currently managed by the SM2-SR, and sends the file status information to the SM2-SR.
  • the method determines that the target transit management platform is SM2 according to the target operator identification information sent by the terminal and the location information of the terminal, and sends the change subscription request message to the SM1-SR.
  • the SM2-SR, the SM2-SR obtains the OP#2 file of the MMO2 according to the change subscription request message, and then sends the OP#2 file to the eUICC of the terminal through the SM1-SR, and the eUICC of the terminal obtains the OP#2 file, and accesses the file through the OP#2 file.
  • the OP#2 file and the response message in the above method can also be sent by encryption, thereby improving the security of the OP#2 file transmission.
  • the embodiment provides a remote change signing method.
  • the technical solution implemented in this embodiment is the same as the embodiment shown in FIG. 11.
  • the method provided in this embodiment is as shown in FIG. 12, and includes:
  • the PM module of the eUICC sends a change subscription request message to the SM1-SR, where the request message is used to request that the subscription of the terminal is changed from the MNO1 to the MMO2, where the request message carries: the target carrier identifier information optional carrier terminal current Location information, where the location information of the terminal may be the country code of the network where the terminal is currently located, or the tracking area identifier TAI or the routing area identifier RAI or the location area identifier LAI where the terminal is currently located, or the current location of the terminal.
  • the identifier of the network entity such as the identifier information or the address information of the MME or the SGSN, is not limited in this embodiment.
  • the source remote management platform determines the remote management platform of the target operator of the current location of the terminal according to the location information. For the process of determining the remote management platform of the target operator where the terminal is currently located, refer to the description in S1101.
  • the SM1-SR finds that the MNO2 is not in its jurisdiction, and determines that the target remote management platform of the current location of the terminal is SM2 according to the step S1201.
  • S1203, SM1-SR send the change subscription request message to the SM2-SR, and the change subscription request message is used to notify the SM2-SR that the terminal needs to replace the subscription to the MNO2;
  • S1204 and SM1-SR allow the SM2-SR to manage the subscription of the terminal user. At this time, the SM2-SR can manage the subscription of the terminal.
  • the SM1-SR sends the information of the eUICC to the SM2-SR, where the information of the eUICC includes: PIC-PKT, PKT, and eUICC related information (for example, eUICC identification information, etc.);
  • S1206 and SM2-SR generate a temporary access certificate according to the change subscription request, and the temporary access certificate is used for authentication between the subsequent eUICC and the SM2-SR.
  • the SM2-SR sends a PKT-encrypted change subscription response message to the SM1-SR, where the change subscription response message carries the temporary access certificate and the address information of the SM2-SR.
  • S1208 The SM1-SR sends a change subscription response message carrying the temporary access certificate and the address information of the SM2-SR to the PM module of the eUICC.
  • the PM module of the eUICC uses the KT to decrypt the change subscription response message, and obtains the temporary access certificate and the address information of the SM2-SR in the change subscription response message.
  • the PM module of the eUICC sends a profile file request message to the SM2-SR according to the address information of the SM2-SR, and carries a temporary access certificate in the request message, so that the terminal and the SM2-SR pass the temporary access. Certificate completion and SM2-SR authentication;
  • the SM2-SR generates the temporary access certificate, and the eUICC uses the temporary access certificate and the SM2-SR to complete the authentication.
  • the file request message may also be obtained by the KT encryption in the eUICC, and the SM2-SR is obtained from the SM1.
  • the SM2-SR receives the profile file request message, and requests the OP#2 file from the SM2-DP according to the acquiring the profile file request message. In this step, the SM2-SR can receive the temporary access certificate by receiving the authentication. Obtain a profile file request message or obtain a profile file request message by using PKT decryption.
  • S1212 The SM2-DP requests the network entity of the MMO2 to authenticate the user, apply for the IMSI, and obtain the OP#2 file.
  • S1213 and SM2-DP use the PIC-PKT encryption to obtain the OP#2 file, and send the encrypted OP#2 file to the SM2-SR.
  • S1214 The SM2-SR returns a response message for obtaining a profile file request to the terminal, where the response message carries the encrypted OP#2 file, and uses PKT to encrypt the acquired profile file response message.
  • the PM module of the eUICC receives the response message for obtaining the profile file request, and decrypts the response message of the profile file request by using the KT, obtains the encrypted OP#2 file in the response message, and obtains the acquired OP. #2 file sent to the PI module of eUICC;
  • the PI module of S1216 and eUICC decrypts the obtained encrypted OP#2 file by using PIC-KT to obtain an activatable OP#2 file;
  • the eUICC of the terminal installs the OP#2 file, activates the OP#2 file, and activates the OP#1 file;
  • S1218 The eUICC of the terminal establishes a fixed connection with the MNO2 through the NAA2 in the OP#2 file.
  • the PM module of the eUICC accesses the SM2-SR and returns profile status information.
  • S1220 and SM2-SR return the terminal profile status information to the SM1-SR.
  • the method provided in this embodiment sends a change subscription request message of the terminal to the SM2 through the SM1, and the SM2 returns a response message according to the change request message, and establishes a connection between the terminal and the SM2 by using the SM2 address information carried in the response message, and the terminal passes the connection.
  • the execution file of the MNO2 is obtained, and the MNO2 network is accessed through the execution file, thereby implementing the subscription switching across the SM.
  • the embodiment of the present invention provides a further embodiment.
  • the embodiment provides a remote change signing method.
  • the technical solution implemented in this embodiment is the same as the embodiment shown in FIG. Show, including:
  • the steps S1301-S1309 are the same as the steps S1201-S1209 in FIG. 12, and details are not described herein again.
  • eUICC sends the public keys N-PIC-PKT and N-PKT in the new key to SM2.
  • eUICC can send the new key to SM2 through the key update request message.
  • the PM module of the eUICC sends a key update request message to the SM2-SR according to the obtained address information of the SM2-SR, and carries the temporary access certificate in the request message, so that the terminal and the SM2-SR pass the temporary access.
  • the certificate completes the authentication with the SM2-SR and establishes a connection for communication.
  • the security delivery process of the message is similar to other steps, and will not be described here.
  • the SM2-SR generates a temporary access certificate, and the eUICC uses the temporary access certificate and the SM2-SR to complete the authentication as an optional operation, and may also update the request message by the KT encryption key in the eUICC, which is used by the SM2-SR.
  • the PKT received by the SM1-SR is decrypted to implement authentication between the eUICC and the SM2-SR.
  • S1312 The SM2-SR receives the key sent by the eUICC and returns a key update confirmation message after authenticating the eUICC.
  • the secure delivery process of this message is similar to other steps and will not be described here.
  • eUICC and SM2 After successfully receiving the key message, eUICC and SM2 will delete the old keys PIC-KT/KT and PIC-PKT respectively. /PKT.
  • the PM module of the eUICC sends a profile file request message to the SM2-SR, and the message may be encrypted by the N-KT in the eUICC to be securely sent to the SM2-SR.
  • the SM2-SR receives the profile file request message, and requests the OP#2 file from the SM2-DP according to the acquiring the profile file request message. In this step, the SM2-SR can receive the profile file request through the N-PKT decryption. Message.
  • S1315 and SM2-DP request the network entity of the MMO2 to authenticate the user, apply for the IMSI, and obtain the OP#2 file.
  • SM2-DP encrypts the OP#2 file by using N-PIC-PKT, and sends the encrypted OP#2 file to the SM2-SR;
  • the SM2-SR returns a response message for obtaining a profile file request to the terminal, where the response message carries the OP#2 file encrypted by the N-PIC-PKT, and uses the N-PKT to encrypt the acquired profile file response message.
  • the PM module of the eUICC receives the response message for obtaining the profile file request, and decrypts the response message of the profile file request by using the N-KT, and obtains the encrypted OP#2 file in the response message, and The obtained OP#2 file is sent to the PI module of the eUICC;
  • the PI module of the eUICC decrypts the obtained encrypted OP#2 file by using the N-PIC-KT to obtain an activatable OP#2 file.
  • the eUICC of the terminal installs the OP#2 file, activates the OP#2 file, and activates the OP#1 file;
  • S1322 The PM module of the eUICC accesses the SM2-SR, and returns profile status information.
  • S1323 and SM2-SR return the terminal profile status information to the SM1-SR.
  • a new key pair is generated by the eUICC, and in subsequent OP# 2 File acquisition uses a new key to encrypt the transmission file and the response message, further enhancing the security of the transmission process.
  • the UE sends a change subscription request message to the source remote management platform, where the UE sends a change subscription request message to the source remote management platform of the current serving UE, or when the UE roams, the request message is directly sent to the source of the roaming place.
  • the remote management platform corresponding to the remote management platform.
  • FIG. 14 is a block diagram showing the hardware structure of a terminal according to an embodiment of the present invention.
  • the terminal is used to run the remote change signing method according to the embodiment of the present invention. For the convenience of explanation, only the parts related to the present embodiment are shown.
  • the terminal includes a processor 141, a memory 142, and a bus 143, wherein the processor 141 and the memory 142 communicate with each other via a bus 143 for storing a program, and the processor 141 is configured to execute the memory 142.
  • a stored program that, when executed, is used to:
  • the execution file is activated, and the activated target file is used to access the target carrier network.
  • the target remote management platform is determined by the source remote management platform according to the change subscription request message, and specifically includes:
  • the source remote management platform determines, according to the target operator information in the change subscription request message and the current location information of the terminal, where the current location information of the terminal is carried in the change subscription request message or remotely from the source.
  • the management platform obtains from the home location register of the terminal/home subscriber server query
  • the receiving, by the target remote management platform, the execution file of the target carrier network according to the change subscription request message specifically:
  • the execution file of the target carrier network that is sent by the receiving target remote management platform and returned according to the change subscription request message includes:
  • the execution file of the target carrier network that is sent by the receiving target remote management platform according to the change subscription request message includes:
  • the response message and the execution file may be encrypted, and then the step (step) of receiving, by the target remote management platform, an execution file of the target carrier network provided according to the change subscription request message, Specifically, it may include:
  • the target remote management platform sent by the terminal receiving source remote management platform returns a change subscription request response message encrypted by the public key of the first key pair, and the response message carries the public key encrypted by the second key pair.
  • the execution file of the target carrier network
  • the terminal decrypts the response message by using the private key of the first key pair, obtains an encrypted execution file of the target carrier network, and uses the private key of the second key pair to encrypt the The execution file of the target carrier network is decrypted to obtain an execution file of the target carrier network.
  • the first and second key pairs may be pre-stored in the terminal device and the source remote management platform.
  • the terminal writes the terminal and the source remote management platform
  • the target remote management platform is the first.
  • the public key in the second key pair can be sent by the source remote management platform.
  • the first key pair and the second key pair may be the same key pair, or may be different key pairs.
  • the first key pair may be a PKT/KT key pair.
  • the second key pair can be a PIC-PKT/PIC-KT.
  • FIG. 15 is a structural diagram of a remote management platform according to an embodiment of the present invention.
  • the specific embodiments of the present invention do not limit the specific implementation of the device.
  • Apparatus 1500 includes:
  • Processor 1510 communication interface (Communications Interface 1520, memory 1530, bus 1540.
  • the processor 1510, the communication interface 1520, and the memory 1530 complete communication with each other via the bus 1540.
  • the communication interface 1520 is configured to communicate with the network element.
  • the processor 1510 is configured to execute the program 1532.
  • program 1532 can include program code, the program code including computer operating instructions.
  • the processor 1510 may be a central processing unit CPU or a specific integrated circuit ASIC (Application) Specific Integrated Circuit), or one or more integrated circuits configured to implement embodiments of the present invention.
  • ASIC Application Specific Integrated Circuit
  • the memory 1530 is configured to store the program 1532.
  • the memory 1530 may include a high speed RAM memory and may also include a non-volatile memory (non-volatile memory) Memory), such as at least one disk storage.
  • the program 1532 can be specifically used to:
  • the change subscription request message is used to request to change the subscription of the terminal to the target operator;
  • the source remote management platform sends the change subscription request message to the target remote management platform, so that the target remote management platform can provide the execution file of the target carrier network required for the terminal handover. Therefore, the method provided by the embodiment of the present invention can implement switching subscriptions across a remote management platform.
  • the execution file of the target carrier network is obtained from the target remote management platform, and specifically includes:
  • the source remote management platform receives the change subscription request response message returned by the target remote management platform according to the change subscription request.
  • the response message carries address information of the target remote management platform.
  • the terminal Sending, by the terminal, the response message carrying the address information of the target remote management platform to the terminal, so that the terminal establishes a connection with the target remote management platform according to the address information of the target remote management platform, and passes the The connection acquires an execution file of the target carrier network.
  • the execution file of the target carrier network is obtained from the target remote management platform, and specifically includes:
  • the source remote management platform receives the change subscription request response message returned by the target remote management platform according to the change subscription request.
  • the response message carries address information of the target remote management platform and a temporary access certificate of the target remote management platform,
  • the terminal Sending, by the terminal, the response message carrying the address information of the target remote management platform and the temporary access certificate to the terminal, so that the terminal establishes a connection with the target remote management platform according to the address information of the target remote management platform.
  • the execution file of the target carrier network is obtained through the connection.
  • the execution file of the target carrier network is obtained from the target remote management platform, and specifically includes:
  • the source remote management platform receives the change subscription request response message returned by the target remote management platform according to the change subscription request message, where the response message carries an execution file of the target carrier network;
  • the response message may be encrypted by the public key of the first key pair, and the execution file of the target carrier network carried in the response message may be encrypted by the public key of the second key pair;
  • the terminal may use the private key of the first key pair to decrypt the response message, obtain an encrypted execution file of the target carrier network, and adopt the second key.
  • the private key of the pair decrypts the executable file of the encrypted target carrier network to obtain an execution file of the target carrier network.
  • the first and second key pairs may be pre-stored in the terminal and the source remote management platform.
  • the terminal writes the terminal and the source remote management platform, and the target remote management platform is the first.
  • the public key of the second key pair can be sent by the source remote management platform.
  • the first key pair and the second key pair may be the same key pair, or may be different key pairs.
  • the first key pair may be a PKT/KT key pair.
  • the second key pair can be a PIC-PKT/PIC-KT.
  • program 1532 can be specifically used for:
  • the target remote management platform provides the terminal with an execution file of the target carrier network requested by the terminal.
  • the target remote management platform receives the change subscription request message sent by the source remote management platform, and provides the execution file of the target carrier network to the terminal, so that the terminal implements the target operator according to the execution file. Network access.
  • the above method implements switching subscriptions across remote management platforms.
  • the target remote management platform provides the terminal with an execution file of the target carrier network that is requested by the terminal, and specifically includes:
  • the target remote management platform returns a change subscription request response message of the change contract request to the source remote management platform, so that the source remote management platform sends the response message to the terminal, where the response message includes: Address information of the target remote management platform;
  • the target remote management platform establishes a connection with the terminal, and sends an execution file of the target carrier network to the terminal through the connection.
  • the target remote management platform provides the terminal with an execution file of the target carrier network that is requested by the terminal, and specifically includes:
  • the target remote management platform returns a change subscription request response message of the change contract request to the source remote management platform, so that the source remote management platform sends the response message to the terminal, where the response message includes: The address information of the target remote management platform and the temporary access certificate of the target remote management platform;
  • the target remote management platform establishes a connection with the terminal, and after completing the verification of the terminal according to the temporary access certificate, sends an execution file of the target carrier network requested by the terminal to the terminal.
  • the target remote management platform provides the terminal with an execution file of the target carrier network that is requested by the terminal, and specifically includes:
  • a change subscription request response message carrying an execution file of the target carrier network to the source remote management platform according to the change subscription request message, so that the source remote management platform sends the response message To the terminal.

Landscapes

  • Engineering & Computer Science (AREA)
  • Databases & Information Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

La présente invention appartient au domaine des communications et porte sur un procédé de changement d'abonnement à distance, un appareil et un terminal. Le procédé consiste à: envoyer un message de demande de changement d'abonnement à une plateforme de gestion à distance source d'un opérateur source de manière à permettre à la plateforme de gestion à distance source d'envoyer le message de demande de changement d'abonnement à une plateforme de gestion à distance cible, le message de demande de changement d'abonnement étant utilisé pour demander de changer l'abonnement d'un terminal pour un opérateur cible; recevoir un fichier d'exécution d'un réseau d'opérateur cible fourni par la plateforme de gestion à distance cible sur la base du message de demande de changement d'abonnement; activer le fichier d'exécution et accéder au réseau d'opérateur cible par le biais du fichier d'exécution activé. Le système technique décrit par la présente invention offre l'avantage d'exécuter un basculement d'abonnement entre des plateformes de gestion à distance.
PCT/CN2013/082720 2013-08-30 2013-08-30 Procédé de changement d'abonnement à distance, et appareil associé WO2015027485A1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2013/082720 WO2015027485A1 (fr) 2013-08-30 2013-08-30 Procédé de changement d'abonnement à distance, et appareil associé
CN201380002239.6A CN103782568A (zh) 2013-08-30 2013-08-30 远程变更签约方法及其装置

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2013/082720 WO2015027485A1 (fr) 2013-08-30 2013-08-30 Procédé de changement d'abonnement à distance, et appareil associé

Publications (1)

Publication Number Publication Date
WO2015027485A1 true WO2015027485A1 (fr) 2015-03-05

Family

ID=50573011

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/082720 WO2015027485A1 (fr) 2013-08-30 2013-08-30 Procédé de changement d'abonnement à distance, et appareil associé

Country Status (2)

Country Link
CN (1) CN103782568A (fr)
WO (1) WO2015027485A1 (fr)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3337206A4 (fr) * 2015-08-14 2018-08-01 ZTE Corporation Euicc et procédé d'activation correspondant, système d'internet des objets, et plate-forme de gestion d'abonnement à distance

Families Citing this family (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106851628B (zh) 2013-12-05 2020-08-07 华为终端有限公司 下载运营商的文件的方法及设备
CN110267254B (zh) 2014-05-23 2022-04-05 华为技术有限公司 eUICC的管理方法、eUICC、SM平台和系统
EP3148235B1 (fr) * 2014-07-07 2021-03-17 Huawei Technologies Co., Ltd. Procédé et appareil d'autorisation pour la gestion d'une carte à circuit intégré universelle incorporée
CN106797565B (zh) * 2014-09-01 2020-07-14 华为技术有限公司 一种通信方法、移动网络设备、终端、应用服务器及系统
KR102333395B1 (ko) 2015-02-17 2021-12-03 삼성전자 주식회사 이동통신 시스템의 단말에서 프로파일 수신을 위한 방법 및 장치
CA2988014A1 (fr) * 2015-06-03 2016-12-08 Deutsche Telekom Ag Methode de transmission de donnees de parametre entre un reseau de telecommunication et un terminal de communication et servant a activer, changer et desactiver un profil de communication sur le terminal de telecommunication, lequel terminal de communication etant defini ou demarque par les donnees de parametre, le systeme de transmission des donnees de ...
KR102490497B1 (ko) * 2015-12-28 2023-01-19 삼성전자주식회사 통신 시스템에서 프로파일을 송수신하는 방법 및 장치
CN107623908B (zh) * 2016-07-15 2020-10-30 中国移动通信有限公司研究院 一种发卡方法及用户识别模块卡
CN106899568A (zh) * 2016-10-10 2017-06-27 中国移动通信有限公司研究院 一种物联网设备的认证凭证更新的方法及设备
CN108011715B (zh) * 2016-10-31 2021-03-23 华为技术有限公司 一种密钥的分发方法、相关设备和系统
CN108123917B (zh) * 2016-11-29 2021-07-23 中国移动通信有限公司研究院 一种物联网终端的认证凭证更新的方法及设备
CN108235302A (zh) * 2016-12-14 2018-06-29 中兴通讯股份有限公司 智能卡的远程签约管理平台切换方法及装置、智能卡、sm-sr
CN109196891B (zh) * 2017-01-13 2020-09-08 华为技术有限公司 一种签约数据集的管理方法、终端及服务器
CN109756882B (zh) * 2017-11-03 2021-11-19 中国电信股份有限公司 通信方法、系统、smsr以及计算机可读存储介质
CN107911224B (zh) * 2017-11-28 2019-04-02 恒宝股份有限公司 嵌入式通用集成电路卡的续证方法和系统
CN111356121B (zh) * 2018-12-21 2024-01-26 西安佰才邦网络技术有限公司 一种基于区块链绑定签约数据的方法及设备

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102076124A (zh) * 2009-11-19 2011-05-25 中兴通讯股份有限公司 一种变更签约数据的系统、方法及设备
CN102547657A (zh) * 2010-12-31 2012-07-04 中兴通讯股份有限公司 远程改变机器对机器设备的归属运营商的方法
CN102883300A (zh) * 2012-09-14 2013-01-16 中国联合网络通信集团有限公司 用户卡签约信息迁移方法、替换方法和装置

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2013036011A2 (fr) * 2011-09-05 2013-03-14 주식회사 케이티 Procédé permettant de gérer un profil d'uicc intégrée et uicc intégrée, terminal équipé d'une uicc intégrée, procédé d'approvisionnement et procédé de modification de mno associé

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102076124A (zh) * 2009-11-19 2011-05-25 中兴通讯股份有限公司 一种变更签约数据的系统、方法及设备
CN102547657A (zh) * 2010-12-31 2012-07-04 中兴通讯股份有限公司 远程改变机器对机器设备的归属运营商的方法
CN102883300A (zh) * 2012-09-14 2013-01-16 中国联合网络通信集团有限公司 用户卡签约信息迁移方法、替换方法和装置

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3337206A4 (fr) * 2015-08-14 2018-08-01 ZTE Corporation Euicc et procédé d'activation correspondant, système d'internet des objets, et plate-forme de gestion d'abonnement à distance

Also Published As

Publication number Publication date
CN103782568A (zh) 2014-05-07

Similar Documents

Publication Publication Date Title
WO2015027485A1 (fr) Procédé de changement d'abonnement à distance, et appareil associé
CN105723648A (zh) 一种密钥配置方法、系统和装置
WO2019107977A1 (fr) Procédé et dispositif électronique de fourniture de services de communication
WO2017039320A1 (fr) Procédé et dispositif de téléchargement de profil dans un système de communications
WO2021167399A1 (fr) Appareil et procédé de génération de clés spécifiques à une application au moyen d'une clé dérivée d'une authentification d'accès au réseau
WO2019050325A1 (fr) Procédé et appareil de prise en charge d'un transfert de profil entre des dispositifs dans un système de communication sans fil
WO2016163796A1 (fr) Procédé et appareil de téléchargement d'un profil dans un système de communication sans fil
WO2016167551A1 (fr) Technique permettant de gérer un profil dans un système de communication
WO2015061941A1 (fr) Procédé et appareil de configuration de clé
WO2019216739A1 (fr) Procédé et appareil de protection de sécurité dans un système de communication sans fil
WO2020171672A1 (fr) Procédé d'interfonctionnement entre un processus de téléchargement de faisceau et un processus de téléchargement de profil esim par un terminal ssp
WO2012165794A2 (fr) Système et procédé destinés à un service de transmission de données simultanée dans un réseau hétérogène
WO2020222578A1 (fr) Procédé de gestion de session et de mobilité au moyen de protocoles nas
WO2020080909A1 (fr) Procédé et appareil de traitement d'exception de gestion de profils à distance
WO2019107876A1 (fr) Procédé et appareil de gestion d'événement dans un système de communication
WO2019177397A1 (fr) Procédé et appareil permettant d'établir support radio
WO2014063360A1 (fr) Procédé et dispositif de commande pour accès à service
WO2022045789A1 (fr) Procédé et appareil de récupération de profil en cas de défaillance d'un changement de dispositif
EP3854115A1 (fr) Procédé et appareil de traitement d'exception de gestion de profils à distance
WO2017096596A1 (fr) Procédé et système d'authentification de véhicule aérien sans pilote et procédé et système de communication sécurisée
WO2020105892A1 (fr) Procédé par lequel un dispositif partage une clé numérique
WO2015000117A1 (fr) Procédé et dispositif de simulation d'un test de numérotation d'un côté utilisateur et d'un côté réseau
WO2015106459A1 (fr) Procédé de transmission de données transférées de façon transparente, et entité de service commune
WO2018143769A1 (fr) Procédé et dispositif de commande de transmission de données, procédé et appareil de commande de continuité d'ue
WO2016159679A1 (fr) Procédé et appareil permettant de mettre en œuvre une distribution de contenu rapide dans un réseau d'évolution à long terme

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13892608

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13892608

Country of ref document: EP

Kind code of ref document: A1