WO2015180243A1 - 一种智能卡动态绑定方法、设备和系统 - Google Patents

一种智能卡动态绑定方法、设备和系统 Download PDF

Info

Publication number
WO2015180243A1
WO2015180243A1 PCT/CN2014/082168 CN2014082168W WO2015180243A1 WO 2015180243 A1 WO2015180243 A1 WO 2015180243A1 CN 2014082168 W CN2014082168 W CN 2014082168W WO 2015180243 A1 WO2015180243 A1 WO 2015180243A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
uicc
usim
basic file
binding
Prior art date
Application number
PCT/CN2014/082168
Other languages
English (en)
French (fr)
Inventor
吴传喜
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Priority to US15/313,952 priority Critical patent/US10356602B2/en
Priority to EP14893167.8A priority patent/EP3136761A4/en
Publication of WO2015180243A1 publication Critical patent/WO2015180243A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/186Processing of subscriber group data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/084Access security using delegated authorisation, e.g. open authorisation [OAuth] protocol
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/40Security arrangements using identity modules
    • H04W12/48Security arrangements using identity modules using secure binding, e.g. securely binding identity modules to devices, services or applications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/183Processing at user equipment or user record carrier
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/70Services for machine-to-machine communication [M2M] or machine type communication [MTC]

Definitions

  • the present invention relates to a terminal communication technology, and in particular, to a smart card dynamic binding method, device, and system.
  • BACKGROUND OF THE INVENTION As an important part of the emerging high-tech industry, the Internet of Things has been regarded as one of the key technologies for coping with the economic crisis and revitalizing the economy.
  • the IoT business can be widely applied to many industries, including vehicles, electricity, finance, environmental protection, petroleum, personal and corporate security, hydrology, military, fire, weather, coal, agriculture and forestry, elevators, etc. It is expected that in the next few years, the Internet of Things business will enter many industries rapidly, and its number of users will also grow rapidly.
  • the scheme for network side authentication which needs to add a device identification register (EDO according to the International Mobile Equipment Identity (IMEI) information to the EIR.
  • EIR International Mobile Equipment Identity
  • the registers are configured in white, black, and gray.
  • the Mobile Switching Center (MSC) and the Visiting Location Register (VLR) request the IMEI from the terminal and send it to the EIR, which the EIR will receive.
  • the IMEI compares with the white, black, and gray tables, and sends the result to the MSC or the VLR, so that the MSC or the VLR decides whether to allow the terminal to enter the network.
  • This method needs to add additional equipment input on the network side, and has a network.
  • the signaling interaction between the two increases the channel occupation of the air interface invisibly.
  • the implementation process is more complicated. 2.
  • the terminal actively identifies the scheme.
  • the scheme is also widely used at present.
  • Common lock cards, lock networks, and smart card bindings are mainly used.
  • the Chinese patent "A method and device for realizing and releasing the binding of terminal equipment and user identification cards" is representative of such an implementation scheme.
  • the implementation of these types of schemes is basically similar, that is, by developing corresponding ones on the terminal.
  • the authentication code is used to interact with the Subscriber Identity Module (SIM) card/Universal Subscriber Identity Module (USIM) card, and the information of the specified file is read by the SIM/USIM card, and is connected to the terminal.
  • SIM Subscriber Identity Module
  • USB Universal Subscriber Identity Module
  • the authentication codes are compared with each other to implement locking or binding between the SIM/USIM card and the terminal.
  • the second scheme is simpler than the first scheme, it needs to be unlocked on the terminal (unbind) Locking (binding) operations, the use is very cumbersome; and once locked (bound), will result in users not being able to use the terminal under other carrier networks, As a result, the user experience and resource waste are extremely poor, and with the development of the Internet of Things technology, the existing smart card binding technology is far from meeting the binding and locking requirements between the M2M device and the user card of the Internet of Things, and many things.
  • the security requirements for the binding of terminals and user cards by networked applications are also increasing.
  • the smart card dynamic binding method provided by the embodiment of the present invention includes: a first basic file and a second basic file are disposed on an integrated circuit card (UICC), wherein The first basic file is used to pre-store an IMEI of one or a group of terminals, and the second basic file is used to store a status flag of a binding check result;
  • UICC integrated circuit card
  • the USIM in the UICC sets the personal identification number (PIN) to the blocked state before the application is selected, and indicates to the terminal that the USIM Service Table supports the additional terminal configuration (Additional TERMINAL PROFILE) and receives the configuration from the terminal. Download the (Profile download) command; after determining that the terminal supports the PROVIDE LOCAL INFORMATION command, the USIM sends an active local information command to the terminal;
  • the UICC receives the terminal response (TERMINAL RESPONSE) of the IMEI of the terminal, and matches the IMEI number with the IMEI number in the first basic file. When the matching is successful, it is determined that the binding check is successful, and the binding check is successful. The status flag is set to the second basic file, the initialization process of the USIM is started, and the PIN is set to an unblocked state and a disabled state.
  • the sending the local information command to the terminal includes: sending, by using an application, a sending of a local information command, where the application is pre-embedded in the UICC as a code of an operating system in the UICC.
  • the matching, by the UICC, the IMEI number and the IMEI number in the first basic file includes: performing, by using a script file, a matching between an IMEI number of the terminal and an IMEI number in the first basic file.
  • the script file is embedded in the UICC in advance as a code of an operating system in the UICC.
  • the method further includes: the UICC adopts an OTA mechanism, and accepts dynamic management of the first basic file by the management platform.
  • the method further includes: the UICC, through the OTA mechanism, providing the background personnel with the reading of the status flag of the binding check result in the second basic file.
  • the method further includes: when the UICC interacts with the terminal, the terminal determines that the first basic file has changed data, performs a restart and reset operation of the terminal, and the UICC initializes after the terminal is restarted, and performs the re-operation. Binding check of UICC and terminal.
  • the method further includes: when the data change occurs in the first basic file, the UICC sends an active refresh command to the terminal, triggers a reset of the 3G session or the UICC, initializes after the terminal is refreshed, and re-executes the UICC and Binding check of the terminal.
  • the method for dynamically binding a smart card includes: receiving, by the terminal, an indication that the USIM service table sent by the USIM in the UICC supports additional terminal configuration, and returns a configuration download command; the terminal receives the local delivery sent by the USIM in the UICC. An information command, and transmitting a terminal response including the IMEI number of the terminal to the UICC.
  • the method further includes: when the UICC interacts with the terminal, the terminal determines that a data change occurs in the first basic file, and performs a restart and reset operation of the terminal.
  • the method further includes: when receiving the active refresh command sent by the UICC, the terminal performs a refresh operation to trigger a reset of the 3G session or the UICC.
  • a method for dynamically binding a smart card according to an embodiment of the present invention includes:
  • the first basic file and the second basic file are set on the UICC, where the first basic file is used to pre-store the IMEI number of one or a group of terminals, and the second basic file is used to store the status of the binding check result. Sign
  • the USIM in the UICC sets the PIN to the locked state before the application is selected, and indicates to the terminal that the USIM service table supports the additional terminal configuration.
  • the terminal receives the USIM service table sent by the USIM in the UICC to support the indication of the additional terminal configuration, and returns a configuration download command.
  • the USIM receives the configuration download command, and after receiving the command to support providing the local information, sends a local information command to the terminal; the terminal receives the local information command sent by the USIM, and sends a terminal response including the IMEI number of the terminal to the UICC.
  • the UICC matches the IMEI number of the terminal with the IMEI number in the first basic file.
  • a UICC is provided in the embodiment of the present invention, where the UICC is provided with a first basic file and a second basic file, where the first basic file is used to pre-store the IMEI of one or a group of terminals, and the second basic The file is used to store a status flag of the binding check result; the UICC further includes: a USIM application module, a matching module, where
  • the USIM application module is configured to set the PIN to the locked state before the application is selected, and indicate to the terminal that the USIM service table supports additional terminal configuration, receives the configuration download command from the terminal, and sends the active provision after determining that the terminal supports the local information command.
  • the local information command is sent to the terminal, and after the initialization process of the USIM is started, the PIN is set to an unlocked state and a failed state;
  • the matching module is configured to receive a terminal response including the IMEI of the terminal, and the IMEI number and the first The IMEI numbers in the basic file match.
  • the binding check is determined to be successful.
  • the status flag of the successful binding check is set to the second basic file, and the initialization process of the USIM is started.
  • the USIM application module is specifically configured to perform the initiative to provide the sending of the local information command by the application, and the application is pre-embedded in the UICC as the code of the operating system in the UICC.
  • the matching module is specifically configured to perform, by using a script file, a matching of an IMEI number of the terminal with an IMEI number in the first basic file.
  • the UICC further includes: a dynamic management module, configured to accept dynamic management of the first basic file by the management platform by using an OTA mechanism.
  • the dynamic management module is further configured to provide the background personnel with the reading of the status flag of the binding check result in the second basic file by using the OTA mechanism.
  • the UICC further includes: a rebinding module, configured to notify the USIM application module after the terminal is restarted; or, when the data change occurs in the first basic file, send an active refresh command to the terminal, triggering 3G The session or UICC reset, after the terminal is refreshed, notifies the USIM application module.
  • the terminal includes: a configuration download instruction providing module, and an IMEI number providing module; wherein, the command sending and receiving module is configured to receive an indication that the USIM service table sent by the USIM in the UICC supports additional terminal configuration, and Return to the configuration download command;
  • the IMEI number providing module is configured to receive a proactive local information request sent by the USIM in the UICC, and send a terminal response including the IMEI number of the terminal to the UICC.
  • the terminal further includes: a restarting module, configured to determine that a data change occurs in the first basic file in the UICC, and perform a restart and reset operation of the terminal.
  • the terminal further includes: a refreshing module, configured to perform a refresh operation when the active refresh command sent by the UICC is received, triggering a reset of the 3G session or the UICC.
  • the smart card dynamic binding system includes: a UICC and a terminal; wherein the UICC is provided with a first basic file and a second basic file, where the first basic file is used for pre-storage The IMEI of the one or a group of terminals, the second basic file is used to store a status flag of the binding check result; the UICC is set to set the PIN to the locked state by the USIM of the user before the application is selected, and the USIM The terminal instructs the USIM service table to support the additional terminal configuration, and receives the configuration download command. After determining that the terminal supports the local information request, the USIM sends an active local information command to the terminal, and the UICC is further configured to receive the terminal.
  • the terminal response of the IMEI number matches the IMEI number with the IMEI number in the first basic file.
  • the matching is successful, it is determined that the binding check is successful, and the status flag of the binding check is successfully set to the first
  • the initialization process of the USIM is started, and the PIN is set to the unlock state and the invalid state; the terminal is set to receive the UICC.
  • the USIM service table sent by the USIM supports the indication of the additional terminal configuration, and returns a configuration download command; and receives the proactive local information request sent by the USIM in the UICC, and sends a terminal response including the IMEI number of the terminal to the UICC.
  • An embodiment of the present invention provides a smart card dynamic binding method, device, and system.
  • the first basic file and the second basic file are disposed on an integrated circuit card (UICC), where the first basic file is used to store one in advance. Or a set of terminal International Mobile Equipment Identity (IMEI), the second basic file is used to store a status flag of the binding check result; the Global Subscriber Identity Module (USIM) sets a personal identification number (PIN) before selecting the application
  • UICC integrated circuit card
  • IMEI International Mobile Equipment Identity
  • USIM Global Subscriber Identity Module
  • PIN personal identification number
  • the USIM Service Table is instructed to support the additional terminal configuration (Additional TERMINAL PROFILE), and the configuration download (Profile download) command is received, and the terminal supports the provision of local information (PROVIDE LOCAL INFORMATION).
  • the sending a local information command is provided to the terminal, and the UICC receives a terminal response (TERMINAL RESPONSE) including the IMEI number of the terminal, and matches the IMEI number with the IMEI number in the first basic file,
  • TERMINAL RESPONSE terminal response
  • the status flag of the binding check success is set to the second basic file
  • the initialization process of the USIM is started, and the PIN is set to an unblocked state and a disabled state
  • the UICC can be bound to the terminal actively, and the smart card in the embodiment of the present invention is dynamically tied.
  • the method is simple, easy to implement, and can meet the security requirements of terminal and smart card binding in the IoT environment.
  • FIG. 1 is a schematic flowchart of a method for dynamically binding a smart card according to an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of a method for dynamically binding a smart card according to Embodiment 2 of the present invention
  • FIG. 3 is a schematic diagram of implementing dynamic card dynamics according to Embodiment 3 of the present invention
  • 4 is a schematic structural diagram of a UICC according to Embodiment 4 of the present invention
  • FIG. 5 is a schematic structural diagram of a terminal implemented according to Embodiment 5 of the present invention
  • FIG. 6 is a dynamic binding of a smart card implemented in Embodiment 6 of the present invention
  • the USIM Application Toolkit (USAT) tool technology adds the ability of the SIM card to new active operations based on the existing passive operation mode of the SIM card.
  • the USAT technology allows an application in an integrated circuit card (UICC) to interact with a terminal supporting the application, that is, to support an active dialogue between the UICC and the terminal, thereby enabling the mobile user to have a personalized additional service.
  • UICC integrated circuit card
  • the active (Proactive) commands supported by UICC include various types, such as PROVIDE LOCAL INFORMATION, display text (DISPLAY TEXT), reset (REFRESH), and send short messages ( SEND SHORT MESSAGE ), SET UP CALL, etc.
  • the PROVIDE LOCAL INFORMATION command requires the terminal to provide some parameters, such as: Mobile Country Code (MCC), Mobile Network Code (MNC), Location Area Code (LAC), Tracking Area Code (TAC, Tracking Area). Code) The cell ID of the current service area, the IMEI of the terminal, or the International Mobile Equipment Identification Software Version (IMEISV).
  • MCC Mobile Country Code
  • MNC Mobile Network Code
  • LAC Location Area Code
  • TAC Tracking Area Code
  • IMEISV International Mobile Equipment Identification Software Version
  • the first basic file and the second basic file are set on the UICC, where the first basic file is used to pre-store the port of one or a group of terminals, and the second basic file is used for storing the binding.
  • the status flag of the check result is determined; before the application is selected, the USIM setting PIN in the UICC is locked, indicating to the terminal that the USIM service table supports additional terminal configuration, and receiving the configuration download command, after determining that the terminal supports the local information command, sending Proactively providing a local information command to the terminal; the UICC receives the terminal response including the IMEI number of the terminal, and matches the IMEI number with the IMEI number in the first basic file, and determines the binding check when the matching is successful. Succeeded, the status flag of the binding check success is set to the second basic file, the initialization process of the USIM is started, and the PIN is set to the unlock state and the invalid state.
  • the UICC generally refers to a UICC for a 3G network that can use the USAT technology, or other smart cards that can be used by a professional to be used as a user identification card by using a USAT technology; the terminal may be a mobile device ( ME) or an IoT device capable of using the UICC.
  • ME mobile device
  • IoT device capable of using the UICC.
  • the first embodiment of the present invention implements a smart card dynamic binding method. As shown in FIG. 1 , the method includes the following steps: Step 101: UICC initialization, before the application is selected, the USIM setting PIN in the UICC is locked. Step 102: The USIM sends an indication that the USIM service table supports the additional terminal configuration to the terminal.
  • Step 103 The USIM receives the configuration download command returned by the terminal.
  • Step 104 After determining that the terminal supports the local information request, the USIM sends the active local request.
  • An information command is sent to the terminal; where the sending the proactively providing local information command to the terminal comprises: performing, by using an application, actively sending a local information command, where the application is pre-embedded in the UICC, and The code for the operating system (COS) within the UICC.
  • Step 105 The UICC receives a terminal response including an IMEI number of the terminal.
  • Step 106 The UICC matches the IMEI number of the terminal with the IMEI number in the first basic file of the UICC.
  • the binding check is successful, and the status flag of the binding check is successfully set to the second basic file of the UICC.
  • the first basic file and the second basic file are preset on the UICC, where the first basic file is used to pre-store an IMEI number of one or a group of terminals, and the first basic file is read.
  • the permission is set to always, and the other permissions are set to never;
  • the second basic file is used to store a status flag of the binding check result, and the status flag of the binding check result may be the last time
  • the status flag of the binding check result of the UICC and the terminal may also be a status flag of the binding check result of the last N times UICC and the terminal, N is an integer greater than 1, and the read permission of the second basic file is set to total Always, the other privilege is set to never, in addition, the second basic file may also store the IMEI number of the terminal corresponding to the status flag;
  • the IMEI number of the file execution terminal matches the IMEI number in the first basic file.
  • the script file is pre-embedded in the UICC, and can be used as a code of the operating system (COS) in the UICC, and the code is extensible.
  • Step 107 The UICC starts the initialization process of the USIM, and sets the PIN to an unlocked state and a failed state.
  • the step 104 further includes: when the USIM determines that the terminal does not support the local information request, determines that the binding check fails, and does not perform the steps after step 104.
  • the step 106 further includes: when the IMEI number of the terminal does not match the IMEI number in the first basic file of the UICC, determining that the binding check fails, and the step after step 106 is no longer performed.
  • the UICC may also receive dynamic management of the first basic file by the management platform by using an OTA (over the AT interface) mechanism, including: adding an IMEI number stored in the first basic file.
  • OTA over the AT interface
  • the management platform may be a group of servers.
  • the UICC may also provide the background personnel with the status flag of the binding check result in the second basic file through the 0TA mechanism, so that the background personnel maintain the binding relationship between the UICC and the terminal.
  • the method of the embodiment further includes: when the UICC interacts with the terminal, the terminal determines whether the first basic file has changed data, and if there is data change, restarts and resets the terminal, UICC After the terminal is restarted, initialization is performed, and the binding check of the UICC and the terminal in the above step 101 107 is performed again.
  • the UICC sends an active refresh (REFRESH) command to the terminal to trigger a 3G session or a reset of the UICC. After the terminal is refreshed, the initialization is performed, and the above step 101 is performed again.
  • UICC and terminal binding check implements a smart card dynamic binding method. As shown in FIG.
  • Step 201 The terminal receives an indication that the USIM service table sent by the USIM in the UICC supports additional terminal configuration. And returning the configuration download instruction;
  • Step 202 The terminal receives the proactive local information request sent by the USIM in the UICC, and sends a terminal response including the IMEI number of the terminal to the UICC.
  • the terminal may be an ME or an Internet of Things device capable of using the UICC.
  • the first basic file and the second basic file are pre-configured on the UICC, wherein the first basic file is used to pre-store an IMEI number of one or a group of terminals, and the read permission of the first basic file is set to Always, all other permissions are set to never; the second basic file is used to store a status flag of the binding check result, and the status flag of the binding check result may be the last UICC and the terminal.
  • the status flag of the binding check result may also be the status flag of the binding check result of the last N times UICC and the terminal, N is an integer greater than 1, and the read permission of the second basic file is set to always (always And the other basic privilege is set to never, and the second basic file may further store the IMEI number of the terminal corresponding to the status flag; the terminal may read the binding check in the second basic file.
  • the status flag of the result thereby determining if the binding was successful.
  • the terminal when receiving the active refresh (REFRESH) command sent by the UICC, the terminal performs a refresh operation, triggering a 3G session (session) or a reset of the UICC, so that the UICC is initialized, and the UICC and the terminal are re-bound. an examination.
  • Embodiment 3 The third embodiment of the present invention implements a smart card dynamic binding method. As shown in FIG. 3, the method includes the following steps: Step 301: UICC initialization, before the application is selected, the USIM setting PIN in the UICC is locked. The USIM sends the USIM service table to the terminal to support the indication of the additional terminal configuration.
  • Step 303 The terminal receives the indication that the USIM service table sent by the USIM in the UICC supports the additional terminal configuration, and returns a configuration download command.
  • Step 304 Receive the USIM.
  • the configuration download command is returned by the terminal;
  • Step 305 After determining that the terminal supports the local information request, the USIM sends an active local information command to the terminal.
  • the sending the local information command to the terminal includes:
  • the application program is actively provided to provide the transmission of the local information command, and the application is pre-embedded in the UICC and can be used as the code of the operating system in the UICC.
  • Step 306 The terminal receives a local information request sent by the USIM in the UICC, and sends a terminal response including the IMEI number of the terminal to the UICC.
  • Step 307 The UICC receives the terminal response including the IMEI number of the terminal.
  • Step 308 The UICC matches the IMEI number of the terminal with the IMEI number in the first basic file of the UICC. If the matching is successful, the binding check is successful, and the binding is successful. Setting the status flag of the successful check to the second basic file of the UICC; specifically, presetting the first basic file and the second basic file on the UICC, wherein the first basic file is used to pre-store one or a group
  • the IMEI number of the terminal, the read permission of the first basic file is set to always, and the other rights are set to never; the second basic file is used to store the status flag of the binding check result.
  • the status flag of the binding check result may be a status flag of the last UICC and the binding check result of the terminal, or may be a status flag of the last N times of the UICC and the binding check result of the terminal, where N is an integer greater than 1.
  • the read permission of the second basic file is set to always, the other permissions are set to never, and the second basic file may also be saved. And storing an IMEI number of the terminal corresponding to the status flag;
  • the script file is used to perform matching of the IMEI number of the terminal with the IMEI number in the first basic file.
  • the script file is pre-embedded in the UICC, and can be used as a code of the operating system (COS) in the UICC, and the code is extensible. .
  • Step 309 The UICC starts the initialization process of the USIM, and sets the PIN to an unlocked state and a failed state.
  • the step 305 further includes: when the USIM determines that the terminal does not support the local information request, determines that the binding check fails, and does not perform the steps after step 305.
  • the step 308 further includes: when the IMEI number of the terminal does not match the IMEI number in the first basic file of the UICC, determining that the binding check fails, and the step after step 308 is no longer performed. Specifically, when the IMEI number of the terminal is not successfully matched with the IMEI number in the first basic file, the status flag of the binding check failure is set to the second basic file.
  • the UICC may also receive dynamic management of the first basic file by the management platform by using an OTA mechanism, including: adding, deleting, changing, and the like of the IMEI number stored in the first basic file. Operation, realizing dynamic binding of the terminal and the UICC, where the management platform may be a group of servers.
  • the UICC may also provide the background personnel with the status flag of the binding check result in the second basic file through the OTA mechanism, so that the background personnel maintain the binding relationship between the UICC and the terminal.
  • the method of the embodiment further includes: when the UICC interacts with the terminal, the terminal determines whether the first basic file has changed data. If there is data change, the terminal restarts and resets, and the UICC restarts after the terminal restarts.
  • the fourth embodiment of the present invention provides a UICC, where the UICC is provided with a first basic file and a second basic file, where the first basic file is used to store one or one in advance.
  • the IMEI of the group terminal, the second basic file is used to store the status flag of the binding check result; as shown in FIG. 4, the UICC further includes: a USIM application module 41, a matching module 42;
  • the USIM application module 41 is configured to set the PIN to the locked state before the application is selected, and indicate to the terminal that the USIM service table supports the additional terminal configuration, receives the configuration download command from the terminal, and sends the active command after determining that the terminal supports the local information request.
  • the matching module 42 is configured to receive a terminal response including the IMEI of the terminal, and the IMEI number and the The IMEI numbers in the first basic file are matched.
  • the binding check is determined to be successful, and the status flag of the successful binding check is set to the second basic file, and the initialization process of the USIM is started.
  • the UICC generally refers to a UICC for a 3G network that can use the USAT technology, or other smart cards that can be used by a professional to judge the use of the user identification card.
  • the USIM application module 41 is specifically configured to perform, by using an application, to actively send a local information command, where the application is pre-embedded in the UICC and can be used as a code of an operating system in the UICC.
  • the first basic file and the second basic file need to be preset on the UICC, where the first basic file is used to pre-store the IMEI number of one or a group of terminals, and the reading of the first basic file
  • the permission is set to always, and the other permissions are set to never;
  • the second basic file is used to store a status flag of the binding check result, and the status flag of the binding check result may be the most recent
  • the status flag of the binding check result of the UICC and the terminal may be the status flag of the binding check result of the last N times UICC and the terminal, N is an integer greater than 1, and the read permission of the second basic file is set to Always, the other privilege is set to never, and the second basic file may further store the IMEI number of the terminal corresponding to the status flag
  • the matching module 42 is specifically configured to pass the script. Matching the IMEI number of the file execution terminal with the IMEI number in the first basic file, the script file is pre-embedded in the UICC, and can be used as the code of the operating system in the UICC, and The code is extensible.
  • the USIM application module 41 is further configured to determine that the terminal does not support the provision of the local information command, determine that the binding check fails, and not notify the information transceiver module 42; the matching module 42 is specifically configured to be the IMEI number and the terminal at the terminal. If the IMEI number in the basic file does not match, it is determined that the binding check fails.
  • the UICC further includes: a dynamic management module 43 configured to accept dynamic management of the first basic file by the management platform by using an OTA mechanism, including: adding, deleting, and deleting an IMEI number stored in the first basic file And changing the scope and the like to implement dynamic binding of the terminal and the UICC.
  • the management platform may be a group of servers.
  • the dynamic management module 43 is further configured to provide, by the OTA mechanism, the background personnel to read the status flag of the binding check result in the second basic file, so that the background personnel maintain the binding relationship between the UICC and the terminal.
  • the UICC may further include: a rebinding module 44, configured to notify the USIM application module 41 after the terminal is restarted; or, when the data change occurs in the first basic file, send an active refresh (REFRESH) to the terminal.
  • the command triggers a reset of the 3G session or the UICC, and then, after the terminal is refreshed, notifies the USIM application module 41.
  • Embodiment 5 In order to implement the foregoing method embodiment, the fifth embodiment of the present invention provides a terminal. As shown in FIG.
  • the terminal includes: a configuration download instruction providing module 51 and an IMEI number providing module 52; wherein, the command sending and receiving module 51, Set to receive an indication that the USIM service table sent by the USIM in the UICC supports additional terminal configuration, and return a configuration download instruction;
  • the IMEI number providing module 52 is configured to receive an active local information command sent by the USIM in the UICC, and send a terminal response including the IMEI number of the terminal to the UICC.
  • the terminal further includes: a restarting module 53, configured to determine whether a data change occurs in the first basic file in the UICC, and if there is a data change, perform a restart and reset operation of the terminal, After the UICC is restarted, the UICC is re-initialized, and the binding check of the UICC and the terminal is performed during the initialization process.
  • the terminal further includes: a refreshing module 54 configured to perform a refresh operation when the active refresh (REFRESH) command sent by the UICC is received, triggering a reset of the 3G session or the UICC, The UICC is re-initialized, and the binding check of the UICC and the terminal is performed during the initialization process.
  • a refreshing module 54 configured to perform a refresh operation when the active refresh (REFRESH) command sent by the UICC is received, triggering a reset of the 3G session or the UICC, The UICC is re-initialized, and the binding check of the UICC and the terminal is performed during the initialization process.
  • the sixth embodiment of the present invention provides a smart card dynamic binding system. As shown in FIG. 6, the system includes: a UICC 61 and a terminal 62.
  • the UICC 61 is provided with a first basic a file and a second basic file, the first basic file being used to pre-store an IMEI of one or a group of terminals, the second The basic file is used to store the status flag of the binding check result. In addition, the second basic file may further store the IMEI number of the terminal corresponding to the status flag.
  • the UICC 61 is set to be the USIM of the user before selecting the application. Setting the PIN to the locked state, the USIM indicates to the terminal that the USIM service table supports the additional terminal configuration, and receives the configuration download command. After determining that the terminal supports the local information request, the USIM sends an active local information command to the terminal.
  • the UICC is further configured to receive a terminal response including the IMEI number of the terminal, and match the IMEI number with the IMEI number in the first basic file.
  • the status indicator of the successful check is set to the second basic file, the initialization process of the USIM is started, and the PIN is set to the unlocked state and the invalid state.
  • the terminal 62 is configured to receive the indication that the USIM service table sent by the USIM in the UICC supports the additional terminal configuration. And returning the configuration download command; and receiving the proactive local mail sent by the USIM in the UICC And transmitting a terminal response including the IMEI number of the terminal to the UICC.
  • the UICC 61 includes: a USIM application module 41, a matching module 42;
  • the USIM application module 41 is configured to set the PIN to the locked state before the application is selected, and indicate to the terminal that the USIM service table supports the additional terminal configuration, receives the configuration download command from the terminal, and sends the active command after determining that the terminal supports the local information request.
  • the matching module 42 is configured to receive a terminal response including the IMEI of the terminal, and the IMEI number and the The IMEI numbers in the first basic file are matched.
  • the terminal 62 includes: a configuration download instruction providing module 51, and an IMEI number providing module 52.
  • the command sending and receiving module 51 is configured to receive an indication that the USIM service table sent by the USIM in the UICC supports additional terminal configuration. And returning the configuration download instruction;
  • the IMEI number providing module 52 is configured to receive the proactive local information command sent by the USIM in the UICC, and send a terminal response including the IMEI number of the terminal to the UICC.
  • a smart card dynamic binding method, device, and system provided by an embodiment of the present invention have the following beneficial effects:
  • the smart card dynamic binding method according to the embodiment of the present invention is simple in operation, easy to implement, and can satisfy the Internet of Things. Security requirements for terminal and smart card binding in the environment.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Telephone Function (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

公开了一种智能卡动态绑定方法,集成电路卡(UICC)上设置有第一基本文件和第二基本文件,在选择应用前,全球用户识别模块(USIM)设置个人识别码(PIN)为锁定状态,向终端指示USIM业务表支持额外终端配置,并接收配置下载指令,在确定终端支持提供本地信息命令后,发送主动式提供本地信息命令给所述终端;UICC接收包括终端的国际移动设备识别码(IMEI)的终端响应,将所述IMEI号码与所述第一基本文件中的IMEI号码相匹配,在匹配成功时,将绑定检查成功的状态标志设置到所述第二基本文件中,启动USIM的初始化过程,设置PIN为解锁状态和失效状态;还公开了一种智能卡动态绑定设备和系统。

Description

一种智能卡动态绑定方法、 设备和系统 技术领域 本发明涉及终端通信技术, 尤其涉及一种智能卡动态绑定方法、 设备和系统。 背景技术 物联网作为新兴高技术产业的重要组成部分, 已被世界各国当作应对经济危机、 振兴经济的重点技术之一。 物联网业务可以广泛地应用到众多的行业中, 包括车辆、 电力、 金融、 环保、 石油、 个人与企业安防、 水文、 军事、 消防、 气象、 煤炭、 农业 与林业、 电梯等。 预计未来几年间, 物联网业务将快速地进入很多行业, 其用户数也 将快速成长, 预计至 2015年底, 中国国内物联网产业规模将达到 7500亿, 物联网应 用也会在若干年后成为长期演进(LTE) 以及第 5代(5G)通信技术的核心应用之一, 具有广阔的发展前景。 目前物联网业务的应用类型中, 有些应用是终端要求只能使用 指定范围的用户卡, 有些应用是用户卡要求被配置到指定的终端上去, 还有些应用要 求是指定范围的终端可以配对指定标识的用户卡, 这都涉及到终端和用户卡之间的绑 定问题。 目前市场上有很多绑定方案, 比较主流的方案如: 1、 网络侧鉴别的方案, 该 方案需要在终端上新增设备标识寄存器 (EDO, 按照国际移动设备识别码 (IMEI)信 息, 将 EIR寄存器配置成白、 黑、 灰三种表, 在终端进行网络交互过程中, 移动交换 中心 (MSC) 和拜访位置寄存器 (VLR) 向终端请求 IMEI, 并把它发送给 EIR, EIR 将收到的 IMEI与白、 黑、 灰三种表格进行比较, 把结果发送给 MSC或 VLR, 以便 MSC或 VLR决定是否允许所述终端进入网络。 该方式需要在网络侧增加额外的设备 投入, 并且有与网络之间的信令交互操作, 无形中增加了空口的信道占用, 实现过程 比较复杂。 2、 终端主动识别方案, 该方案目前使用也较广泛, 常见的锁卡、 锁网、 智 能卡绑定主要有几种类型: 锁网格、 锁子网、 锁运营商、 合作者绑定等等, 例如申请 号为 200710106103.6、 名称为 《一种实现及解除终端设备和用户识别卡绑定的方法和 设备》的中国专利即是这种实现方案的代表, 这些类型的方案, 实现的实质基本相似, 即通过在终端上开发相应的鉴权代码, 通过与用户识别模块(SIM, Subscriber Identity Module) 卡 /通用用户身份识别模块 (USIM, Universal Subscriber Identity Module) 卡 交互, 采用读取 SIM/USIM卡指定文件的信息, 并与终端上的鉴权代码相互比较, 从 而实现 SIM/USIM卡和终端之间的锁定或绑定。 第 2种方案实现上尽管相比第 1种方 案简单, 但需要在终端上进行相应的解锁 (解除绑定)、 加锁 (绑定)操作, 使用非常 繁琐; 并且一旦锁定 (绑定), 将会导致用户不能在其他运营商网络下使用所述终端, 从而导致极差的用户体验和资源浪费, 并且随着物联网技术的发展, 现有的智能卡绑 定技术远远不能满足物联网的 M2M设备和用户卡之间的绑定和锁定要求, 而且许多 物联网应用对终端和用户卡的绑定安全性要求也越来越高。 发明内容 为解决现有存在的技术问题, 本发明实施例主要提供一种智能卡动态绑定方法、 设备和系统。 本发明实施例的技术方案是这样实现的: 本发明实施例提供的一种智能卡动态绑定方法, 该方法包括: 集成电路卡(UICC)上设置有第一基本文件和第二基本文件, 其中, 所述第一基 本文件用于预先存储一个或一组终端的 IMEI,所述第二基本文件用于存储绑定检查结 果的状态标志;
UICC中的 USIM在应用选择前, 设置个人识别码(PIN)为锁定(blocked)状态, 向终端指示 USIM 业务表 (USIM Service Table ) 支持额外终端配置 (Additional TERMINAL PROFILE), 并接收来自终端的配置下载 (Profile download) 指令; USIM在确定终端支持提供本地信息 (PROVIDE LOCAL INFORMATION) 命令 后, 发送主动式提供本地信息命令给所述终端;
UICC接收包括终端的 IMEI的终端响应(TERMINAL RESPONSE),将所述 IMEI 号码与所述第一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检查成功的状态标志设置到所述第二基本文件中, 启动 USIM的初始化过程, 设置 PIN为解锁 (unblocked) 状态和失效 (Disable) 状态。 上述方案中, 所述发送提供本地信息命令给所述终端包括: 通过应用程序执行提 供本地信息命令的发送, 所述应用程序预先内嵌在 UICC内, 作为 UICC内操作系统 的代码。 上述方案中, 所述 UICC将所述 IMEI号码与所述第一基本文件中的 IMEI号码相 匹配包括:通过脚本文件执行终端的 IMEI号码与第一基本文件中的 IMEI号码的匹配。 上述方案中, 所述脚本文件预先内嵌在 UICC内, 作为 UICC内操作系统的代码。 上述方案中, 该方法还包括: 所述 UICC通 OTA机制, 接受管理平台对第一基本 文件的动态管理。 上述方案中, 该方法还包括: 所述 UICC通过 OTA机制, 向后台人员提供第二基 本文件中绑定检查结果的状态标志的读取。 上述方案中, 该方法还包括: 当 UICC与终端发生了 OTA交互时, 终端确定第一 基本文件发生了数据变化, 进行终端的重启、 复位操作, UICC 在终端重启后, 进行 初始化, 并重新进行 UICC和终端的绑定检查。 上述方案中, 该方法还包括: UICC 在第一基本文件发生了数据变化时, 向终端 发送主动式刷新命令, 触发 3G会话或 UICC的复位, 在终端刷新后, 进行初始化, 并重新进行 UICC和终端的绑定检查。 本发明实施例提供的一种智能卡动态绑定方法, 该方法包括: 终端接收 UICC中 USIM发送的 USIM业务表支持额外终端配置的指示, 并返回 配置下载指令; 终端接收 UICC中 USIM发送的提供本地信息命令, 并向所述 UICC发送包括终 端的 IMEI号码的终端响应。 上述方案中, 该方法还包括: 当 UICC与终端发生了 OTA交互时, 所述终端确定 第一基本文件发生了数据变化, 进行终端的重启、 复位操作。 上述方案中, 该方法还包括: 所述终端在收到 UICC发送的主动式刷新命令时, 进行刷新操作, 触发 3G会话或 UICC的复位。 本发明实施例提供的一种智能卡动态绑定方法, 该方法包括:
UICC 上设置有第一基本文件和第二基本文件, 其中, 所述第一基本文件用于预 先存储一个或一组终端的 IMEI号码, 所述第二基本文件用于存储绑定检查结果的状 态标志;
UICC中的 USIM在选择应用前, 设置 PIN为锁定状态, 向终端指示 USIM业务 表支持额外终端配置; 终端接收 UICC中 USIM发送的 USIM业务表支持额外终端配置的指示, 并返回 配置下载指令; USIM接收配置下载指令, 在确定终端支持提供本地信息命令后, 发送提供本地 信息命令给所述终端; 终端接收 USIM发送的提供本地信息命令, 并向所述 UICC发送包括终端的 IMEI 号码的终端响应; UICC将所述终端的 IMEI号码与所述第一基本文件中的 IMEI号码相匹配, 在匹 配成功时, 确定绑定检查成功, 将绑定检查成功的状态标志设置到所述第二基本文件 中, 启动 USIM的初始化过程, 设置 PIN为解锁状态和失效状态。 本发明实施例提供的一种 UICC, 该 UICC上设置有第一基本文件和第二基本文 件, 其中, 所述第一基本文件用于预先存储一个或一组终端的 IMEI, 所述第二基本文 件用于存储绑定检查结果的状态标志; 该 UICC还包括: USIM应用模块、 匹配模块; 其中,
USIM应用模块, 设置为在选择应用前, 设置 PIN为锁定状态, 向终端指示 USIM 业务表支持额外终端配置, 接收来自终端的配置下载指令, 在确定终端支持提供本地 信息命令后, 发送主动式提供本地信息命令给所述终端, 并在启动 USIM的初始化过 程后, 设置 PIN为解锁状态和失效状态; 匹配模块, 设置为接收包括终端的 IMEI的终端响应, 将所述 IMEI号码与所述第 一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检查 成功的状态标志设置到所述第二基本文件中, 启动 USIM的初始化过程。 上述方案中, 所述 USIM应用模块, 具体设置为通过应用程序执行主动式提供本 地信息命令的发送, 所述应用程序预先内嵌在 UICC内, 作为 UICC内操作系统的代 码。 上述方案中, 所述匹配模块, 具体设置为通过脚本文件执行终端的 IMEI号码与 第一基本文件中的 IMEI号码的匹配。 上述方案中, 所述 UICC还包括: 动态管理模块, 设置为通过 OTA机制, 接受管 理平台对第一基本文件的动态管理。 上述方案中, 所述动态管理模块, 还设置为通过 OTA机制, 向后台人员提供第二 基本文件中绑定检查结果的状态标志的读取。 上述方案中, 所述 UICC还包括: 重绑定模块, 设置为在终端重启后, 通知 USIM 应用模块; 或者, 在第一基本文件发生了数据变化时, 向终端发送主动式刷新命令, 触发 3G会话或 UICC的复位, 在终端刷新后, 通知 USIM应用模块。 本发明实施例提供的一种终端, 该终端包括: 配置下载指令提供模块、 IMEI号码 提供模块; 其中, 指令收发模块, 设置为接收 UICC中 USIM发送的 USIM业务表支持额外终端配 置的指示, 并返回配置下载指令;
IMEI号码提供模块,设置为接收 UICC中 USIM发送的主动式提供本地信息命令, 并向所述 UICC发送包括终端的 IMEI号码的终端响应。 上述方案中, 所述终端还包括: 重启模块, 设置为确定 UICC中的第一基本文件 发生了数据变化, 进行终端的重启、 复位操作。 上述方案中, 所述终端还包括: 刷新模块, 设置为在收到 UICC发送的主动式刷 新命令时, 进行刷新操作, 触发 3G会话或 UICC的复位。 本发明实施例提供的一种智能卡动态绑定系统,该系统包括: UICC、终端; 其中, 所述 UICC上设置有第一基本文件和第二基本文件, 所述第一基本文件用于预先 存储一个或一组终端的 IMEI, 所述第二基本文件用于存储绑定检查结果的状态标志; 所述 UICC, 设置为在选择应用前, 由自身的 USIM设置 PIN为锁定状态, 所述 USIM向终端指示 USIM业务表支持额外终端配置, 并接收配置下载指令, 在确定终 端支持提供本地信息命令后, 所述 USIM发送主动式提供本地信息命令给所述终端, 所述 UICC还设置为接收包括终端的 IMEI号码的终端响应, 将所述 IMEI号码与所述 第一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检 查成功的状态标志设置到所述第二基本文件中, 启动 USIM的初始化过程, 设置 PIN 为解锁状态和失效状态; 终端,设置为接收 UICC中 USIM发送的 USIM业务表支持额外终端配置的指示, 并返回配置下载指令; 以及接收 UICC中 USIM发送的主动式提供本地信息命令, 并 向所述 UICC发送包括终端的 IMEI号码的终端响应。 本发明实施例提供了一种智能卡动态绑定方法、设备和系统,集成电路卡(UICC) 上设置有第一基本文件和第二基本文件, 其中, 所述第一基本文件用于预先存储一个 或一组终端的国际移动设备识别码 (IMEI), 所述第二基本文件用于存储绑定检查结 果的状态标志; 在选择应用前, 全球用户识别模块 (USIM) 设置个人识别码 (PIN) 为锁定 (blocked)状态, 向终端指示 USIM业务表(USIM Service Table)支持额外终 端配置(Additional TERMINAL PROFILE), 并接收配置下载(Profile download)指令, 在确定终端支持提供本地信息 (PROVIDE LOCAL INFORMATION) 命令后, 发送主 动式提供本地信息命令给所述终端, UICC 接收包括终端的 IMEI 号码的终端响应 (TERMINAL RESPONSE), 将所述 IMEI号码与所述第一基本文件中的 IMEI号码相 匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检查成功的状态标志设置到所述第 二基本文件中, 启动 USIM的初始化过程, 设置 PIN为解锁 (unblocked)状态和失效 (Disable) 状态; 如此, 能够使 UICC主动与终端绑定, 本发明实施例的智能卡动态 绑定方法, 操作简单、 易于实现、 能满足物联网环境下的终端和智能卡绑定的安全需 要。 附图说明 图 1为本发明实施例一实现智能卡动态绑定方法的流程示意图; 图 2为本发明实施例二实现智能卡动态绑定方法的流程示意图; 图 3为本发明实施例三实现智能卡动态绑定方法的流程示意图; 图 4为本发明实施例四实现的 UICC的结构示意图; 图 5为本发明实施例五实现的终端的结构示意图; 图 6为本发明实施例六实现的智能卡动态绑定系统的结构示意图。 具体实施方式
USIM应用工具箱 (USAT, USIM Application Toolkit) 技术, 是在已有的 SIM卡 被动式的操作模式基础上, 增加了 SIM卡新的主动式操作的能力。 USAT技术允许集 成电路卡 (UICC, Universal Integrated Circuit Card) 中的应用与支持所述应用的终端 进行交互操作, 即支持 UICC与终端之间的主动式对话, 从而使移动用户拥有个人化 附加业务。 根据 3GPP最新版本 3GPP TS 31.111 12.3.0版本(2014.03发布), UICC支 持的主动 (Proactive) 命令包括多种, 如 PROVIDE LOCAL INFORMATION、 显示文 本 (DISPLAY TEXT )、 重置 ( REFRESH )、 发送短消息 ( SEND SHORT MESSAGE )、 建立呼叫 (SET UP CALL) 等等。 其中, PROVIDE LOCAL INFORMATION命令是要求终端提供一些自身的参数, 如: 移动国家码(MCC), 移动网络码(MNC), 位置区码(LAC, Location Area Code) /跟踪区码(TAC, Tracking Area Code ) 当前服务区的小区标识(cell ID)、终端的 IMEI 或国际移动设备识别软件版本 (IMEISV) 等等数据。 本发明实施例中, UICC 上设置有第一基本文件和第二基本文件, 其中, 所述第 一基本文件用于预先存储一个或一组终端的 ΙΜΕΙ,所述第二基本文件用于存储绑定检 查结果的状态标志; 在选择应用前, UICC中的 USIM设置 PIN为锁定状态, 向终端 指示 USIM业务表支持额外终端配置, 并接收配置下载指令, 在确定终端支持提供本 地信息命令后,发送主动式提供本地信息命令给所述终端; UICC接收包括终端的 IMEI 号码的终端响应, 将所述 IMEI号码与所述第一基本文件中的 IMEI号码相匹配, 在匹 配成功时, 确定绑定检查成功, 将绑定检查成功的状态标志设置到所述第二基本文件 中, 启动 USIM的初始化过程, 设置 PIN为解锁状态和失效状态。 这里, 所述 UICC 一般是指能够使用 USAT技术的用于 3G网络的 UICC、或其他能够使用 USAT技术的 由专业人员判断可以作为用户识别卡用途的各种智能卡; 所述终端可以是移动设备 (ME) 或能够使用所述 UICC的物联网设备。 下面通过附图及具体实施例对本发明做进一步的详细说明。 实施例一 本发明实施例一实现一种智能卡动态绑定方法, 如图 1所示, 该方法包括以下几 个步骤: 步骤 101: UICC初始化, 在选择应用前, UICC中的 USIM设置 PIN为锁定状态; 步骤 102: USIM向终端发送 USIM业务表支持额外终端配置的指示; 步骤 103 : USIM接收终端返回的配置下载指令; 步骤 104: USIM在确定终端支持提供本地信息命令后,发送主动式提供本地信息 命令给所述终端; 这里, 所述发送主动式提供本地信息命令给所述终端包括: 通过应用程序执行主 动式提供本地信息命令的发送, 所述应用程序预先内嵌在 UICC 内, 可以作为 UICC 内操作系统 (COS) 的代码。 步骤 105: UICC接收包括终端的 IMEI号码的终端响应; 步骤 106: UICC将终端的 IMEI号码与 UICC的第一基本文件中的 IMEI号码相 匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检查成功的状态标志设置到 UICC 的第二基本文件中; 具体的, 在 UICC上预先设置第一基本文件和第二基本文件, 其中, 所述第一基 本文件用于预先存储一个或一组终端的 IMEI号码, 所述第一基本文件的读取权限设 置为总是 (always), 其他权限均设置为从不 (never); 所述第二基本文件用于存储绑 定检查结果的状态标志, 所述绑定检查结果的状态标志可以是最近一次 UICC和终端 的绑定检查结果的状态标志, 也可以是最近 N次 UICC和终端的绑定检查结果的状态 标志, N为大于 1的整数, 所述第二基本文件的读取权限设置为总是 (always), 其他 权限均设置为从不 (never), 另外, 所述第二基本文件还可以存储所述状态标志对应 的终端的 IMEI号码; 通过脚本文件执行终端的 IMEI号码与第一基本文件中的 IMEI号码的匹配,所述 脚本文件预先内嵌在 UICC内, 可以作为 UICC内操作系统 (COS) 的代码, 且所述 代码具有扩充性。 步骤 107: UICC启动 USIM的初始化过程, 设置 PIN为解锁状态和失效状态。 本实施例中, 步骤 104还包括: USIM确定终端不支持提供本地信息命令时, 确 定绑定检查失败, 并不再执行步骤 104后的步骤。 步骤 106还包括: 在终端的 IMEI号码与 UICC的第一基本文件中的 IMEI号码不 匹配时, 确定绑定检查失败, 并不再执行步骤 106后的步骤。 具体的, 在终端的 IMEI 号码与第一基本文件中的 IMEI号码匹配不成功时, 将绑定检查失败的状态标志设置 到第二基本文件中。 本实施例所述方法中, 所述 UICC还可以通过 OTA (over the AT interface) 机制, 接受管理平台对第一基本文件的动态管理, 包括: 对存储在第一基本文件中的 IMEI 号码的增加、 删除、 改变范围等操作, 实现终端和 UICC的动态绑定, 这里, 所述管 理平台可以是一组服务器。 另外, 所述 UICC还可以通过 0TA机制, 向后台人员提供第二基本文件中绑定检 查结果的状态标志的读取, 以使后台人员维护 UICC和终端的绑定关系。 本实施例所述方法还包括: 当 UICC与终端发生了 OTA交互时, 终端判断第一基 本文件是否发生了数据变化, 如果有数据变化, 则进行终端的重启、 复位操作, UICC 在终端重启后, 进行初始化, 并重新进行上述步骤 101 107的 UICC和终端的绑定检 查。 或者, UICC 在第一基本文件发生了数据变化时, 向终端发送主动式刷新 (REFRESH) 命令, 触发 3G会话 (session) 或 UICC的复位, 在终端刷新后, 进行 初始化, 并重新进行上述步骤 101 107的 UICC和终端的绑定检查。 实施例二 本发明实施例二实现一种智能卡动态绑定方法, 如图 2所示, 该方法包括以下几 个步骤: 步骤 201 : 终端接收 UICC中 USIM发送的 USIM业务表支持额外终端配置的指 示, 并返回配置下载指令; 步骤 202: 终端接收 UICC中 USIM发送的主动式提供本地信息命令, 并向所述 UICC发送包括终端的 IMEI号码的终端响应。 这里, 所述终端可以是 ME或能够使用所述 UICC的物联网设备。 所述 UICC上预先设置有第一基本文件和第二基本文件, 其中, 所述第一基本文 件用于预先存储一个或一组终端的 IMEI号码, 所述第一基本文件的读取权限设置为 总是 (always), 其他权限均设置为从不 (never); 所述第二基本文件用于存储绑定检 查结果的状态标志, 所述绑定检查结果的状态标志可以是最近一次 UICC和终端的绑 定检查结果的状态标志,也可以是最近 N次 UICC和终端的绑定检查结果的状态标志, N为大于 1的整数, 所述第二基本文件的读取权限设置为总是(always), 其他权限均 设置为从不 (never), 另外, 所述第二基本文件还可以存储所述状态标志对应的终端 的 IMEI号码; 所述终端可以读取第二基本文件中的绑定检查结果的状态标志, 从而 确定绑定是否成功。 当 UICC与终端发生了 OTA交互时,所述终端判断第一基本文件是否发生了数据 变化, 如果有数据变化, 则进行终端的重启、 复位操作, 以使 UICC在终端重启后, 进行初始化, 并重新进行 UICC和终端的绑定检查。 或者, 所述终端在收到 UICC发送的主动式刷新 (REFRESH)命令时, 进行刷新 操作, 触发 3G会话 (session)或 UICC的复位, 以使 UICC进行初始化, 并重新进行 UICC和终端的绑定检查。 实施例三 本发明实施例三实现一种智能卡动态绑定方法, 如图 3所示, 该方法包括以下几 个步骤: 步骤 301 : UICC初始化, 在选择应用前, UICC中的 USIM设置 PIN为锁定状态; 步骤 302: USIM向终端发送 USIM业务表支持额外终端配置的指示; 步骤 303 : 终端接收 UICC中 USIM发送的 USIM业务表支持额外终端配置的指 示, 并返回配置下载指令; 步骤 304: USIM接收终端返回的配置下载指令; 步骤 305: USIM在确定终端支持提供本地信息命令后,发送主动式提供本地信息 命令给所述终端; 这里, 所述发送主动式提供本地信息命令给所述终端包括: 通过应用程序执行主 动式提供本地信息命令的发送, 所述应用程序预先内嵌在 UICC 内, 可以作为 UICC 内操作系统的代码。 步骤 306: 终端接收 UICC中 USIM发送的提供本地信息命令, 并向所述 UICC发 送包括终端的 IMEI号码的终端响应。 步骤 307: UICC接收包括终端的 IMEI号码的终端响应; 步骤 308: UICC将终端的 IMEI号码与 UICC的第一基本文件中的 IMEI号码相 匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检查成功的状态标志设置到 UICC 的第二基本文件中; 具体的, 在 UICC上预先设置第一基本文件和第二基本文件, 其中, 所述第一基 本文件用于预先存储一个或一组终端的 IMEI号码, 所述第一基本文件的读取权限设 置为总是 (always), 其他权限均设置为从不 (never); 所述第二基本文件用于存储绑 定检查结果的状态标志, 所述绑定检查结果的状态标志可以是最近一次 UICC和终端 的绑定检查结果的状态标志, 也可以是最近 N次 UICC和终端的绑定检查结果的状态 标志, N为大于 1的整数, 所述第二基本文件的读取权限设置为总是 (always), 其他 权限均设置为从不 (never), 另外, 所述第二基本文件还可以存储所述状态标志对应 的终端的 IMEI号码; 通过脚本文件执行终端的 IMEI号码与第一基本文件中的 IMEI号码的匹配,所述 脚本文件预先内嵌在 UICC内, 可以作为 UICC内操作系统 (COS) 的代码, 且所述 代码具有扩充性。 步骤 309: UICC启动 USIM的初始化过程, 设置 PIN为解锁状态和失效状态。 本实施例中, 步骤 305还包括: USIM确定终端不支持提供本地信息命令时, 确 定绑定检查失败, 并不再执行步骤 305后的步骤。 步骤 308还包括: 在终端的 IMEI号码与 UICC的第一基本文件中的 IMEI号码不 匹配时, 确定绑定检查失败, 并不再执行步骤 308后的步骤。 具体的, 在终端的 IMEI 号码与第一基本文件中的 IMEI号码匹配不成功时, 将绑定检查失败的状态标志设置 到第二基本文件中。 本实施例所述方法中, 所述 UICC还可以通过 OTA机制, 接受管理平台对第一基 本文件的动态管理, 包括: 对存储在第一基本文件中的 IMEI号码的增加、 删除、 改 变范围等操作, 实现终端和 UICC的动态绑定, 这里, 所述管理平台可以是一组服务 器。 另外, 所述 UICC还可以通过 OTA机制, 向后台人员提供第二基本文件中绑定检 查结果的状态标志的读取, 以使后台人员维护 UICC和终端的绑定关系。 本实施例所述方法还包括: 当 UICC与终端发生了 OTA交互时, 终端判断第一基 本文件是否发生了数据变化, 如果有数据变化, 则进行终端的重启、 复位操作, UICC 在终端重启后, 重新进行初始化, 并在初始化过程中进行上述步骤 301 309的 UICC 和终端的绑定检查。 或者, UICC 在第一基本文件发生了数据变化时, 向终端发送主动式刷新 (REFRESH) 命令, 触发 3G session或 UICC的复位, 在终端刷新后, 重新进行初始 化, 并在初始化过程中进行上述步骤 301 309的 UICC和终端的绑定检查。 实施例四 为了实现上述方法实施例,本发明实施例四提供一种 UICC,该 UICC上设置有第 一基本文件和第二基本文件, 其中, 所述第一基本文件用于预先存储一个或一组终端 的 IMEI,所述第二基本文件用于存储绑定检查结果的状态标志;如图 4所示,该 UICC 还包括: USIM应用模块 41、 匹配模块 42; 其中, USIM应用模块 41,设置为在选择应用前,设置 PIN为锁定状态,向终端指示 USIM 业务表支持额外终端配置, 接收来自终端的配置下载指令, 在确定终端支持提供本地 信息命令后, 发送主动式提供本地信息命令给所述终端, 并在启动 USIM的初始化过 程后, 设置 PIN为解锁状态和失效状态; 匹配模块 42,设置为接收包括终端的 IMEI的终端响应,将所述 IMEI号码与所述 第一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检 查成功的状态标志设置到所述第二基本文件中, 启动 USIM的初始化过程。 这里, 所述 UICC—般是指能够使用 USAT技术的用于 3G网络的 UICC、 或其他 能够使用 USAT技术的由专业人员判断可以作为用户识别卡用途的各种智能卡。 所述 USIM应用模块 41, 具体设置为通过应用程序执行主动式提供本地信息命令 的发送, 所述应用程序预先内嵌在 UICC内, 可以作为 UICC内操作系统的代码。 本实施例中, 需要在 UICC上预先设置第一基本文件和第二基本文件, 其中, 所 述第一基本文件用于预先存储一个或一组终端的 IMEI号码, 所述第一基本文件的读 取权限设置为总是 (always), 其他权限均设置为从不 (never); 所述第二基本文件用 于存储绑定检查结果的状态标志,所述绑定检查结果的状态标志可以是最近一次 UICC 和终端的绑定检查结果的状态标志, 也可以是最近 N次 UICC和终端的绑定检查结果 的状态标志, N为大于 1的整数,所述第二基本文件的读取权限设置为总是(always), 其他权限均设置为从不 (never), 另外, 所述第二基本文件还可以存储所述状态标志 对应的终端的 IMEI号码; 所述匹配模块 42, 具体设置为通过脚本文件执行终端的 IMEI号码与第一基本文 件中的 IMEI号码的匹配, 所述脚本文件预先内嵌在 UICC内, 可以作为 UICC内操作 系统的代码, 且所述代码具有扩充性。 所述 USIM应用模块 41, 还设置为确定终端不支持提供本地信息命令时, 确定绑 定检查失败, 不再通知信息收发模块 42; 所述匹配模块 42,具体设置为在终端的 IMEI号码与第一基本文件中的 IMEI号码 不匹配时,确定绑定检查失败;具体的,在终端的 IMEI号码与第一基本文件中的 IMEI 号码匹配不成功时,所述匹配模块 42将绑定检查失败的状态标志设置到第二基本文件 中。 另外, 所述 UICC还包括: 动态管理模块 43, 设置为通过 OTA机制, 接受管理 平台对第一基本文件的动态管理, 包括: 对存储在第一基本文件中的 IMEI号码的增 力口、 删除、 改变范围等操作, 实现终端和 UICC的动态绑定, 这里, 所述管理平台可 以是一组服务器。 所述动态管理模块 43, 还设置为通过 OTA机制, 向后台人员提供第二基本文件 中绑定检查结果的状态标志的读取, 以使后台人员维护 UICC和终端的绑定关系。 所述 UICC还可以包括: 重绑定模块 44, 设置为在终端重启后, 通知所述 USIM 应用模块 41 ; 或者, 在第一基本文件发生了数据变化时, 向终端发送主动式刷新 (REFRESH) 命令, 触发 3G session或 UICC的复位, 进而在终端刷新后, 通知所述 USIM应用模块 41。 实施例五 为了实现上述方法实施例, 本发明实施例五提供一种终端, 如图 5所示, 该终端 包括: 配置下载指令提供模块 51、 IMEI号码提供模块 52; 其中, 指令收发模块 51, 设置为接收 UICC中 USIM发送的 USIM业务表支持额外终端 配置的指示, 并返回配置下载指令;
IMEI号码提供模块 52,设置为接收 UICC中 USIM发送的主动式提供本地信息命 令, 并向所述 UICC发送包括终端的 IMEI号码的终端响应。 在本实施例的另一个实例中, 所述终端还包括: 重启模块 53, 设置为判断 UICC 中的第一基本文件是否发生了数据变化, 如果有数据变化, 则进行终端的重启、 复位 操作, 以使 UICC在终端重启后, 重新进行初始化, 并在初始化过程中进行 UICC和 终端的绑定检查。 在本实施例的另一个实例中,所述终端还包括:刷新模块 54,设置为在收到 UICC 发送的主动式刷新 (REFRESH) 命令时, 进行刷新操作, 触发 3G session或 UICC的 复位, 以使 UICC重新进行初始化, 并在初始化过程中进行 UICC和终端的绑定检查。 实施例六 为了实现上述方法实施例, 本发明实施例六提供一种智能卡动态绑定系统, 如图 6所示, 该系统包括: UICC61、 终端 62; 其中, 所述 UICC61上设置有第一基本文件 和第二基本文件, 所述第一基本文件用于预先存储一个或一组终端的 IMEI, 所述第二 基本文件用于存储绑定检查结果的状态标志, 另外, 所述第二基本文件还可以存储所 述状态标志对应的终端的 IMEI号码; 所述 UICC61 , 设置为在选择应用前, 由自身的 USIM设置 PIN为锁定状态, 所 述 USIM向终端指示 USIM业务表支持额外终端配置, 并接收配置下载指令, 在确定 终端支持提供本地信息命令后,所述 USIM发送主动式提供本地信息命令给所述终端, 所述 UICC还设置为接收包括终端的 IMEI号码的终端响应, 将所述 IMEI号码与所述 第一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检 查成功的状态标志设置到所述第二基本文件中, 启动 USIM的初始化过程, 设置 PIN 为解锁状态和失效状态; 终端 62, 设置为接收 UICC中 USIM发送的 USIM业务表支持额外终端配置的指 示, 并返回配置下载指令; 以及接收 UICC中 USIM发送的主动式提供本地信息命令, 并向所述 UICC发送包括终端的 IMEI号码的终端响应。 所述 UICC61 , 如图 4所示, 包括: USIM应用模块 41、 匹配模块 42; 其中,
USIM应用模块 41,设置为在选择应用前,设置 PIN为锁定状态,向终端指示 USIM 业务表支持额外终端配置, 接收来自终端的配置下载指令, 在确定终端支持提供本地 信息命令后, 发送主动式提供本地信息命令给所述终端, 并在启动 USIM的初始化过 程后, 设置 PIN为解锁状态和失效状态; 匹配模块 42,设置为接收包括终端的 IMEI的终端响应,将所述 IMEI号码与所述 第一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检 查成功的状态标志设置到所述第二基本文件中, 启动 USIM的初始化过程。 所述终端 62, 如图 5所示, 包括: 配置下载指令提供模块 51、 IMEI号码提供模 块 52; 其中, 指令收发模块 51, 设置为接收 UICC中 USIM发送的 USIM业务表支持额外终端 配置的指示, 并返回配置下载指令; IMEI号码提供模块 52,设置为接收 UICC中 USIM发送的主动式提供本地信息命 令, 并向所述 UICC发送包括终端的 IMEI号码的终端响应。 以上所述, 仅为本发明的较佳实施例而已, 并非用于限定本发明的保护范围, 凡 在本发明的精神和原则之内所作的任何修改、 等同替换和改进等, 均应包含在本发明 的保护范围之内。 工业实用性 如上所述, 本发明实施例提供的一种智能卡动态绑定方法、 设备和系统具有 以下有益效果: 本发明实施例的智能卡动态绑定方法, 操作简单、 易于实现、 能满 足物联网环境下的终端和智能卡绑定的安全需要。

Claims

权 利 要 求 书 、 一种智能卡动态绑定方法, 该方法包括:
集成电路卡(UICC)上设置有第一基本文件和第二基本文件, 其中, 所述 第一基本文件用于预先存储一个或一组终端的国际移动设备识别码 (IMEI), 所述第二基本文件用于存储绑定检查结果的状态标志;
UICC 中的全球用户识别模块 (USIM) 在应用选择前, 设置个人识别码 (PIN)为锁定(blocked)状态, 向终端指示 USIM业务表(USIM Service Table) 支持额外终端配置(Additional TERMINAL PROFILE), 并接收来自终端的配置 下载 (Profile download) 指令;
USIM在确定终端支持提供本地信息(PROVIDE LOCAL INFORMATION) 命令后, 发送主动式提供本地信息命令给所述终端;
UICC接收包括终端的 IMEI的终端响应(TERMINAL RESPONSE), 将所 述 IMEI号码与所述第一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定 绑定检查成功, 将绑定检查成功的状态标志设置到所述第二基本文件中, 启动 USIM的初始化过程, 设置 PIN为解锁 (unblocked) 状态和失效 (Disable) 状 态。 、 根据权利要求 1所述的智能卡动态绑定方法, 其中, 所述发送提供本地信息命 令给所述终端包括: 通过应用程序执行提供本地信息命令的发送, 所述应用程 序预先内嵌在 UICC内, 作为 UICC内操作系统的代码。 、 根据权利要求 1所述的智能卡动态绑定方法, 其中, 所述 UICC将所述 IMEI 号码与所述第一基本文件中的 IMEI号码相匹配包括: 通过脚本文件执行终端 的 IMEI号码与第一基本文件中的 IMEI号码的匹配。 、 根据权利要求 3所述的智能卡动态绑定方法, 其中, 所述脚本文件预先内嵌在 UICC内, 作为 UICC内操作系统的代码。 、 根据权利要求 1所述的智能卡动态绑定方法,其中, 该方法还包括: 所述 UICC 通 OTA机制, 接受管理平台对第一基本文件的动态管理。 、 根据权利要求 1所述的智能卡动态绑定方法,其中, 该方法还包括: 所述 UICC 通过 OTA机制,向后台人员提供第二基本文件中绑定检查结果的状态标志的读 取。 、 根据权利要求 1所述的智能卡动态绑定方法, 其中, 该方法还包括: 当 UICC 与终端发生了 OTA交互时,终端确定第一基本文件发生了数据变化,进行终端 的重启、 复位操作, UICC在终端重启后, 进行初始化, 并重新进行 UICC和终 端的绑定检查。 、 根据权利要求 1所述的智能卡动态绑定方法, 其中, 该方法还包括: UICC在 第一基本文件发生了数据变化时, 向终端发送主动式刷新命令, 触发 3G会话 或 UICC的复位, 在终端刷新后, 进行初始化, 并重新进行 UICC和终端的绑 定检查。 、 一种智能卡动态绑定方法, 该方法包括:
终端接收 UICC中 USIM发送的 USIM业务表支持额外终端配置的指示, 并返回配置下载指令;
终端接收 UICC中 USIM发送的提供本地信息命令, 并向所述 UICC发送 包括终端的 IMEI号码的终端响应。 0、 根据权利要求 9所述的智能卡动态绑定方法, 其中, 该方法还包括: 当 UICC 与终端发生了 OTA交互时,所述终端确定第一基本文件发生了数据变化,进行 终端的重启、 复位操作。 1、 根据权利要求 9所述的智能卡动态绑定方法, 其中, 该方法还包括: 所述终端 在收到 UICC发送的主动式刷新命令时, 进行刷新操作, 触发 3G会话或 UICC 的复位。 、 一种智能卡动态绑定方法, 该方法包括:
UICC 上设置有第一基本文件和第二基本文件, 其中, 所述第一基本文件 用于预先存储一个或一组终端的 IMEI号码, 所述第二基本文件用于存储绑定 检查结果的状态标志;
UICC中的 USIM在选择应用前,设置 PIN为锁定状态, 向终端指示 USIM 业务表支持额外终端配置; 终端接收 UICC中 USIM发送的 USIM业务表支持额外终端配置的指示, 并返回配置下载指令;
USIM接收配置下载指令, 在确定终端支持提供本地信息命令后, 发送提 供本地信息命令给所述终端;
终端接收 USIM发送的提供本地信息命令, 并向所述 UICC发送包括终端 的 IMEI号码的终端响应;
UICC将所述终端的 IMEI号码与所述第一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检查成功的状态标志设置到所述第 二基本文件中, 启动 USIM的初始化过程, 设置 PIN为解锁状态和失效状态。 、 一种 UICC, 该 UICC上设置有第一基本文件和第二基本文件, 其中, 所述第一 基本文件用于预先存储一个或一组终端的 IMEI,所述第二基本文件用于存储绑 定检查结果的状态标志; 该 UICC还包括: USIM应用模块、 匹配模块; 其中,
USIM应用模块, 设置为在选择应用前, 设置 PIN为锁定状态, 向终端指 示 USIM业务表支持额外终端配置, 接收来自终端的配置下载指令, 在确定终 端支持提供本地信息命令后, 发送主动式提供本地信息命令给所述终端, 并在 启动 USIM的初始化过程后, 设置 PIN为解锁状态和失效状态;
匹配模块, 设置为接收包括终端的 IMEI的终端响应, 将所述 IMEI号码与 所述第一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检查成功的状态标志设置到所述第二基本文件中, 启动 USIM的初始化 过程。 、 根据权利要求 13所述的 UICC, 其中, 所述 USIM应用模块, 具体设置为通过 应用程序执行主动式提供本地信息命令的发送,所述应用程序预先内嵌在 UICC 内, 作为 UICC内操作系统的代码。 、 根据权利要求 13所述的 UICC, 其中, 所述匹配模块, 具体设置为通过脚本文 件执行终端的 IMEI号码与第一基本文件中的 IMEI号码的匹配。 、 根据权利要求 13所述的 UICC, 其中, 所述 UICC还包括: 动态管理模块, 设 置为通过 OTA机制, 接受管理平台对第一基本文件的动态管理。 、 根据权利要求 16所述的 UICC, 其中, 所述动态管理模块, 还设置为通过 OTA 机制, 向后台人员提供第二基本文件中绑定检查结果的状态标志的读取。 、 根据权利要求 13所述的 UICC, 其中, 所述 UICC还包括: 重绑定模块, 设置 为在终端重启后, 通知 USIM应用模块; 或者, 在第一基本文件发生了数据变 化时, 向终端发送主动式刷新命令, 触发 3G会话或 UICC的复位, 在终端刷 新后, 通知 USIM应用模块。 、 一种终端, 该终端包括: 配置下载指令提供模块、 IMEI号码提供模块; 其中, 指令收发模块, 设置为接收 UICC中 USIM发送的 USIM业务表支持额外 终端配置的指示, 并返回配置下载指令;
IMEI号码提供模块,设置为接收 UICC中 USIM发送的主动式提供本地信 息命令, 并向所述 UICC发送包括终端的 IMEI号码的终端响应。 、 根据权利要求 19所述的终端, 其中, 所述终端还包括: 重启模块, 设置为确定 UICC中的第一基本文件发生了数据变化, 进行终端的重启、 复位操作。 、 根据权利要求 19所述的终端, 其中, 所述终端还包括: 刷新模块, 设置为在收 到 UICC发送的主动式刷新命令时,进行刷新操作,触发 3G会话或 UICC的复 位。 、 一种智能卡动态绑定系统, 该系统包括: UICC、 终端; 其中, 所述 UICC上设置有第一基本文件和第二基本文件, 所述第一基本文件用 于预先存储一个或一组终端的 IMEI,所述第二基本文件用于存储绑定检查结果 的状态标志;
所述 UICC, 设置为在选择应用前, 由自身的 USIM设置 PIN为锁定状态, 所述 USIM向终端指示 USIM业务表支持额外终端配置,并接收配置下载指令, 在确定终端支持提供本地信息命令后, 所述 USIM发送主动式提供本地信息命 令给所述终端, 所述 UICC还设置为接收包括终端的 IMEI号码的终端响应, 将所述 IMEI号码与所述第一基本文件中的 IMEI号码相匹配, 在匹配成功时, 确定绑定检查成功, 将绑定检查成功的状态标志设置到所述第二基本文件中, 启动 USIM的初始化过程, 设置 PIN为解锁状态和失效状态;
终端, 设置为接收 UICC中 USIM发送的 USIM业务表支持额外终端配置 的指示, 并返回配置下载指令; 以及接收 UICC中 USIM发送的主动式提供本 地信息命令, 并向所述 UICC发送包括终端的 IMEI号码的终端响应。
PCT/CN2014/082168 2014-05-27 2014-07-14 一种智能卡动态绑定方法、设备和系统 WO2015180243A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US15/313,952 US10356602B2 (en) 2014-05-27 2014-07-14 Method, device, and system for dynamically binding a smart card
EP14893167.8A EP3136761A4 (en) 2014-05-27 2014-07-14 Method, device, and system for dynamically binding a smart card

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410229152.9 2014-05-27
CN201410229152.9A CN105228125A (zh) 2014-05-27 2014-05-27 一种智能卡动态绑定方法、设备和系统

Publications (1)

Publication Number Publication Date
WO2015180243A1 true WO2015180243A1 (zh) 2015-12-03

Family

ID=54697966

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/082168 WO2015180243A1 (zh) 2014-05-27 2014-07-14 一种智能卡动态绑定方法、设备和系统

Country Status (4)

Country Link
US (1) US10356602B2 (zh)
EP (1) EP3136761A4 (zh)
CN (1) CN105228125A (zh)
WO (1) WO2015180243A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108270931A (zh) * 2016-12-30 2018-07-10 联芯科技有限公司 基于imei标记的移动电话防诈骗防骚扰方法

Families Citing this family (20)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE102015001900A1 (de) * 2015-02-09 2016-08-11 Giesecke & Devrient Gmbh Verfahren zum Betreiben eines Sicherheitselements
EP3082355A1 (en) * 2015-04-17 2016-10-19 Gemalto Sa A method for controlling remotely the permissions and rights of a target secure element
KR102545897B1 (ko) * 2015-12-22 2023-06-22 삼성전자 주식회사 프로파일 제공 방법 및 장치
US10346147B2 (en) * 2015-12-22 2019-07-09 Samsung Electronics Co., Ltd. Method and apparatus for providing a profile
CN105721650B (zh) * 2016-01-27 2018-12-04 努比亚技术有限公司 一种实现手机卡识别方法及终端
CN105760908B (zh) * 2016-02-24 2019-02-01 腾讯科技(深圳)有限公司 智能卡识别的方法和装置、智能卡识别数据的处理方法和装置
CN107426801A (zh) * 2016-05-23 2017-12-01 中兴通讯股份有限公司 一种智能卡的控制方法、装置、终端设备及智能卡
CN107872786B (zh) * 2016-09-23 2021-06-25 中国移动通信有限公司研究院 一种控制方法及智能卡
AU2016427098B2 (en) * 2016-10-20 2021-05-20 Huawei Technologies Co., Ltd. Method and apparatus for managing embedded universal integrated circuit card eUICC
CN106972963B (zh) * 2017-03-23 2020-01-03 数据通信科学技术研究所 业务模块的启用控制方法、崩溃重启后的启用控制方法
IT201700106423A1 (it) * 2017-09-22 2019-03-22 St Microelectronics Srl Procedimento per gestire schede a circuito integrato, scheda ed apparecchiatura corrispondenti
CN107666664B (zh) * 2017-10-11 2021-04-20 深圳辉烨物联科技有限公司 一种机卡绑定的方法、装置、设备和存储介质
CN109729515B (zh) * 2017-10-27 2021-12-21 中国电信股份有限公司 用于实现机卡绑定的方法、用户识别卡和物联网终端
US11516672B2 (en) * 2017-12-19 2022-11-29 Huawei Technologies Co., Ltd. Profile management method, embedded universal integrated circuit card, and terminal
KR102536948B1 (ko) * 2018-10-29 2023-05-25 삼성전자주식회사 Ssp의 번들을 관리하는 방법 및 장치
CN112449341B (zh) * 2019-08-29 2022-08-09 华为云计算技术有限公司 IoT设备数据管理方法、装置和系统
CN112004222B (zh) * 2020-08-25 2022-08-23 中国联合网络通信集团有限公司 Usat应用匹配管理方法、终端、usim及系统
CN112804102B (zh) * 2021-01-12 2023-05-16 北京嘀嘀无限科技发展有限公司 设备绑定方法、装置和终端
CN113630762B (zh) * 2021-08-17 2023-06-27 中国联合网络通信集团有限公司 信息交互方法、usim、移动设备和用户终端
WO2024136262A1 (en) * 2022-12-19 2024-06-27 Samsung Electronics Co., Ltd. Methods and apparatus for selecting a security profile in a wireless communication systems

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070145734A1 (en) * 2002-06-28 2007-06-28 Xin Wen Manufacturing system and process for personalized greeting cards
CN101072403A (zh) * 2007-06-12 2007-11-14 中兴通讯股份有限公司 一种实现sim/usim卡锁定到专门终端上的方法
CN101170823A (zh) * 2007-11-19 2008-04-30 中兴通讯股份有限公司 用户识别模块和终端之间的认证方法
CN102510391A (zh) * 2011-10-10 2012-06-20 中国联合网络通信集团有限公司 应用管理方法、装置及智能卡
CN102833066A (zh) * 2011-06-15 2012-12-19 中兴通讯股份有限公司 一种三方认证方法、装置及支持双向认证的智能卡
CN103107878A (zh) * 2011-11-15 2013-05-15 中兴通讯股份有限公司 移动用户身份识别卡与机器类通信设备绑定的方法及装置
CN103619013A (zh) * 2013-12-04 2014-03-05 孙国华 手机与智能卡交互应用的安全绑定方法

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7596373B2 (en) * 2002-03-21 2009-09-29 Mcgregor Christopher M Method and system for quality of service (QoS) monitoring for wireless devices
CN101141718B (zh) * 2006-09-04 2010-12-01 中兴通讯股份有限公司 一种移动终端锁卡方法
CN100488304C (zh) * 2007-05-25 2009-05-13 中兴通讯股份有限公司 一种实现及解除终端设备和用户识别卡绑定的方法和设备
EP2356836B1 (en) 2008-11-17 2017-01-11 Sierra Wireless, Inc. Method and apparatus for associating identity modules and terminal equipment
IT1404159B1 (it) * 2010-12-30 2013-11-15 Incard Sa Metodo e sistema di controllo di una comunicazione tra una carta universale a circuito integrato ed una applicazione esterna

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070145734A1 (en) * 2002-06-28 2007-06-28 Xin Wen Manufacturing system and process for personalized greeting cards
CN101072403A (zh) * 2007-06-12 2007-11-14 中兴通讯股份有限公司 一种实现sim/usim卡锁定到专门终端上的方法
CN101170823A (zh) * 2007-11-19 2008-04-30 中兴通讯股份有限公司 用户识别模块和终端之间的认证方法
CN102833066A (zh) * 2011-06-15 2012-12-19 中兴通讯股份有限公司 一种三方认证方法、装置及支持双向认证的智能卡
CN102510391A (zh) * 2011-10-10 2012-06-20 中国联合网络通信集团有限公司 应用管理方法、装置及智能卡
CN103107878A (zh) * 2011-11-15 2013-05-15 中兴通讯股份有限公司 移动用户身份识别卡与机器类通信设备绑定的方法及装置
CN103619013A (zh) * 2013-12-04 2014-03-05 孙国华 手机与智能卡交互应用的安全绑定方法

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"Universal Subscriber Identity Module (USIM) Application Toolkit (USAT) (Release 9", 3RD GENERATION PARTNERSHIP PROJECT: TECHNICAL SPECIFICATION GROUP CORE NETWORK AND TERNIMALS., 30 June 2010 (2010-06-30), pages 16, XP055239811 *
See also references of EP3136761A4 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108270931A (zh) * 2016-12-30 2018-07-10 联芯科技有限公司 基于imei标记的移动电话防诈骗防骚扰方法
CN108270931B (zh) * 2016-12-30 2020-02-07 联芯科技有限公司 基于imei标记的移动电话防诈骗防骚扰方法

Also Published As

Publication number Publication date
EP3136761A1 (en) 2017-03-01
US10356602B2 (en) 2019-07-16
CN105228125A (zh) 2016-01-06
US20170188226A1 (en) 2017-06-29
EP3136761A4 (en) 2017-04-26

Similar Documents

Publication Publication Date Title
WO2015180243A1 (zh) 一种智能卡动态绑定方法、设备和系统
WO2015180242A1 (zh) 一种机卡动态绑定方法、设备和系统
US9198026B2 (en) SIM lock for multi-SIM environment
ES2555970T3 (es) Procedimiento para exportar datos de una UICC a un servidor seguro
US7088988B2 (en) Over-the-air subsidy lock resolution
JP6401280B2 (ja) サービスにアクセスするための方法及び装置
US9325704B2 (en) Data access method and device
KR102116269B1 (ko) 단말 장치에 내장되어 설치되는 가입자 인증 모듈의 프로파일 관리 방법 및 이를 이용하는 가입자 인증 장치
CN109743722B (zh) 网络连接处理方法和装置
WO2013023510A1 (zh) 一种用户信息存储方法及设备
JP5653714B2 (ja) 移動通信端末
US9609506B2 (en) Identity suspension method for a mobile device
ES2342171T3 (es) Sincronizacion de base de datos.
JP6445185B2 (ja) 少なくとも1つの設定パラメータの破損を検出する方法及びチップ
US10362479B2 (en) Management of access to a plurality of security modules incorporated into a data-processing device
US8989731B1 (en) Detection and self-healing of a mobile communication device network access failure
US9014669B1 (en) Limit failed network connection attempts with factory default settings
CN110062440B (zh) Wlan连接控制方法、电子设备及存储介质
EP3133849A1 (en) Method, token and system for switching from a first to a second mobile operator according to a network access technology
EP2890164A1 (en) Method for accessing a service, corresponding device and system

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14893167

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 15313952

Country of ref document: US

REEP Request for entry into the european phase

Ref document number: 2014893167

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2014893167

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE