WO2018058725A1 - 一种防止eSIM文件被篡改的方法及移动终端 - Google Patents

一种防止eSIM文件被篡改的方法及移动终端 Download PDF

Info

Publication number
WO2018058725A1
WO2018058725A1 PCT/CN2016/103877 CN2016103877W WO2018058725A1 WO 2018058725 A1 WO2018058725 A1 WO 2018058725A1 CN 2016103877 W CN2016103877 W CN 2016103877W WO 2018058725 A1 WO2018058725 A1 WO 2018058725A1
Authority
WO
WIPO (PCT)
Prior art keywords
mobile terminal
verification information
verification
information
new
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2016/103877
Other languages
English (en)
French (fr)
Inventor
郭辰
徐宇杰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Original Assignee
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yulong Computer Telecommunication Scientific Shenzhen Co Ltd filed Critical Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Publication of WO2018058725A1 publication Critical patent/WO2018058725A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method and a mobile terminal for preventing an eSIM file from being tampered with.
  • eSIM embedded Subscriber Identification Module
  • the eSIM establishes a connection with the operator through the terminal, in actual applications, the eSIM file may be maliciously tampered with due to a hacker attack, and thus the user's personal data has a security risk, which makes the security of the terminal low.
  • the embodiment of the invention discloses a method for preventing an eSIM file from being tampered with and a mobile terminal, which can effectively prevent the eSIM file from being maliciously falsified and improve the security of the mobile terminal.
  • the first aspect of the embodiment of the present invention discloses a method for preventing an eSIM file from being tampered with.
  • the mobile terminal includes a common environment and a security environment, where the security environment is an environment in which the mobile terminal runs under the security domain TZ.
  • Methods include:
  • the mobile terminal detects, in the normal environment, a first update request sent by a network server, where the first update request is used to request to update an original embedded user identification module eSIM file in the mobile terminal;
  • the mobile terminal starts a target application in the security environment according to the first update request
  • the mobile terminal detects the first verification information and the target eSIM file sent by the network server by using the target application, where the first verification information is information for verifying an identity of the network server;
  • the mobile terminal performs verification on the first verification information in the security environment
  • the mobile terminal When the mobile terminal successfully verifies the first verification information in the security environment, the mobile terminal updates the original eSIM file by using the target eSIM file.
  • the method also includes:
  • the mobile terminal acquires second verification information in the security environment, where the second verification information is information used to verify security of the target application;
  • the mobile terminal verifies the second verification information in the security environment
  • the mobile terminal updates the original eSIM file by using the target eSIM file, including:
  • the mobile terminal If the mobile terminal successfully verifies the second verification information, the mobile terminal updates the original eSIM file by using the target eSIM file.
  • the method also includes:
  • the mobile terminal outputs a first verification instruction, where the first verification instruction is used to instruct the user to input the first biometric information;
  • the mobile terminal updates the original eSIM file by using the target eSIM file, including:
  • the mobile terminal determines that the first biometric information input by the user passes, the mobile terminal updates the original eSIM file by using the target eSIM file.
  • the method further includes:
  • the mobile terminal maps the target eSIM file in the security environment to the common environment through a shared buffer to update an eSIM file in the normal environment.
  • the method further includes:
  • the mobile terminal detects a second update request in the security environment, where the second update request is used to request to update the second verification information in the security environment, where the second update request carries a new Second verification information and third verification information;
  • the mobile terminal performs verification on the new second verification information and the third verification information in the security environment
  • the mobile terminal When the mobile terminal successfully verifies the new second verification information and the third verification information, the mobile terminal updates the second verification information by using the new second verification information.
  • the method further includes:
  • the mobile terminal detects a third update request in the security environment, where the third update request is used to request to update the target application and the second verification information in the security environment, the third The update request carries a new target application, new second verification information, and third verification information;
  • the mobile terminal performs verification on the new second verification information and the third verification information in the security environment
  • the mobile terminal When the mobile terminal verifies that the new second verification information and the third verification information are successful, the mobile terminal updates the target application by using the new target application, and utilizes the new The second verification information updates the second verification information.
  • the mobile terminal after the mobile terminal successfully verifies the new second verification information and the third verification information, the mobile terminal updates the target by using the new target application. Before the application, and updating the second verification information by using the new second verification information, the method further includes:
  • the mobile terminal performs signature information verification on the new target application
  • the mobile terminal determines whether the verification of the signature information is passed
  • the updating, by the mobile terminal, the target application by using the new target application, and updating the second verification information by using the new second verification information includes:
  • the mobile terminal updates the target application by using the new target application, and updates the second verification information by using the new second verification information.
  • the mobile terminal updates the target application by using the new target application, and updates by using the new second verification information.
  • the method further includes:
  • the mobile terminal outputs a second verification instruction, where the second verification instruction is used to instruct the user to input the second biometric information;
  • the updating, by the mobile terminal, the target application by using the new target application, and updating the second verification information by using the new second verification information includes:
  • the mobile terminal updates the target application by using the new target application, and updates the second by using the new second verification information. verify message.
  • the second aspect of the embodiment of the present invention discloses a mobile terminal, where the mobile terminal includes a common environment and a security environment, where the security environment is an environment in which the mobile terminal runs under the security domain TZ, and the mobile terminal includes:
  • a first detecting unit configured to detect, in the normal environment, a first update request sent by a network server, where the first update request is used to request to update an original embedded user identification module eSIM file in the mobile terminal;
  • Activating unit configured to start a target application in the security environment according to the first update request
  • the first detecting unit is further configured to detect the first verification information and the target eSIM file sent by the network server by using the target application, where the first verification information is used to perform identity of the network server Verified information;
  • a verification unit configured to verify the first verification information in the security environment
  • a first updating unit configured to update the original eSIM file by using the target eSIM file when the verification unit successfully verifies the first verification information in the security environment.
  • the mobile terminal further includes:
  • An obtaining unit configured to: after the verifying unit successfully verifies the first verification information in the security environment, before the first update unit updates the original eSIM file by using the target eSIM file, Obtaining second verification information in the security environment, where the second verification information is information used to verify security of the target application;
  • the verification unit is further configured to perform verification on the second verification information in the security environment
  • the first update unit is specifically configured to update the original eSIM file by using the target eSIM file when the verification unit successfully verifies the second verification information.
  • the mobile terminal further includes:
  • a first output unit configured to: after the verification unit successfully verifies the first verification information in the security environment, before the first update unit updates the original eSIM file by using the target eSIM file And outputting a first verification instruction, where the first verification instruction is used to instruct the user to input the first biometric information;
  • a first determining unit configured to determine whether the first biometric information input by the user is verified to pass
  • the first update unit is specifically configured to update the original eSIM file by using the target eSIM file when the first determining unit determines that the first biometric information input by the user passes.
  • the mobile terminal further includes:
  • mapping unit configured to map the target eSIM file in the security environment to the common environment through a shared buffer to update an eSIM file in the normal environment.
  • the mobile terminal further includes:
  • a second detecting unit configured to detect a second update request in the security environment, wherein the second update request is for requesting to update the second verification information, and the second update request carries a new second Verification information and third verification information;
  • the verification unit is further configured to perform verification on the new second verification information and the third verification information respectively in the security environment;
  • a second updating unit configured to update the second verification by using the new second verification information when the verification unit successfully verifies the new second verification information and the third verification information information.
  • the mobile terminal further includes:
  • a third detecting unit configured to detect a third update request in the security environment, wherein the third update request is used to request to update the target application and the second verification information, where the third update request carries There are new target applications, new second verification information, and third verification information;
  • the verification unit is further configured to perform verification on the new second verification information and the third verification information respectively in the security environment;
  • a third update unit configured to: when the verification unit successfully verifies the new second verification information and the third verification information, update the target application by using the new target application, and utilize The new second verification information updates the second verification information.
  • the verification unit is further configured to: after verifying that both the new second verification information and the third verification information are successfully verified, the third update unit utilizes the The new target application updates the target application, and performs signature information verification on the new target application before updating the second verification information by using the new second verification information;
  • the mobile terminal further includes:
  • a second determining unit configured to determine whether the verification of the signature information is passed
  • the third update unit is specifically configured to: when the second determining unit determines that the signature information is verified to pass, update the target application by using the new target application, and update the location by using the new second verification information.
  • the second verification information is described.
  • the mobile terminal further includes:
  • a second output unit configured to: after the second determining unit determines that the signature information is verified, the third update unit updates the target application by using the new target application, and utilizes the new second Before the verification information updates the second verification information, outputting a second verification instruction, where the second verification instruction is used to instruct the user to input the second biometric information;
  • the second determining unit is further configured to determine whether the second biometric information input by the user is verified to pass;
  • the third updating unit is specifically configured to: when the second determining unit determines that the second biometric information verification passes, update the target application by using the new target application, and utilize the new second The verification information updates the second verification information.
  • the embodiment of the invention has the following beneficial effects:
  • the mobile terminal starts the target application in the security environment by detecting the first update request sent by the network server in a common environment, so that the first verification information sent by the network server is detected by the target application, in a security environment.
  • the mobile terminal updates the original eSIM file with the target eSIM file.
  • FIG. 1 is a schematic flowchart of a method for preventing an eSIM file from being tampered with according to an embodiment of the present invention
  • FIG. 2 is a schematic diagram of a specific principle for preventing an eSIM file from being tampered with according to an embodiment of the present invention
  • FIG. 3 is a schematic flow chart of another method for preventing an eSIM file from being tampered with according to an embodiment of the present invention
  • FIG. 4 is a schematic diagram of another specific principle for preventing an eSIM file from being tampered with according to an embodiment of the present invention
  • FIG. 5 is a schematic structural diagram of a mobile terminal according to an embodiment of the present disclosure.
  • FIG. 6 is a schematic structural diagram of another mobile terminal according to an embodiment of the present disclosure.
  • FIG. 7 is a schematic structural diagram of still another mobile terminal according to an embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of still another mobile terminal according to an embodiment of the present invention.
  • the embodiment of the invention discloses a method for preventing an eSIM file from being tampered with and a mobile terminal, which can effectively prevent the eSIM file from being maliciously falsified and improve the security of the mobile terminal. The details are described below separately.
  • FIG. 1 is a schematic flowchart of a method for preventing an tampering of an eSIM file according to an embodiment of the present disclosure.
  • the method is applied to a mobile terminal, where the mobile terminal includes a common environment and a security environment, where the security environment is mobile.
  • the terminal runs in an environment under the security domain TZ.
  • the method for preventing tampering of an eSIM file may include the following steps.
  • the mobile terminal detects, in a normal environment, a first update request sent by the network server.
  • the first update request is used to request to update the original eSIM file in the mobile terminal.
  • the mobile terminal may include various mobile terminals such as a mobile phone, a tablet, a Personal Digital Assistant (PDA), a Mobile Internet Device (MID), and a smart wearable device (such as a smart watch, a smart bracelet).
  • PDA Personal Digital Assistant
  • MID Mobile Internet Device
  • smart wearable device such as a smart watch, a smart bracelet.
  • the embodiment of the invention is not limited.
  • the mobile terminal may include a common environment and a security environment, where the security environment may be referred to as a TZ (TrustZone) environment, and is an environment in which the mobile terminal runs under the TZ, specifically, based on TZ technology builds a secure operating environment by opening up a trusted code area in the embedded kernel.
  • the normal environment is the original environment in the mobile terminal, and is a non-TZ environment.
  • the user can perform various operations (such as making a call, surfing the Internet, sending a message, etc.).
  • the general environment and the security environment are two independent and non-interfering working environments in the mobile terminal.
  • the mobile terminal starts the target application in the security environment according to the first update request.
  • the mobile terminal detects the first verification information and the target eSIM file sent by the network server by using the target application.
  • the first verification information is information used to verify the identity of the network server, that is, used to verify the authenticity of the network server.
  • the first authentication information may be the network key cipher_key_A delivered by the network server.
  • the mobile terminal verifies the first verification information in a secure environment. If the mobile terminal successfully verifies the first verification information, step 105 is performed; otherwise, the process ends.
  • the mobile terminal performs the matching verification between the first verification information and the preset first verification information in a security environment, and if the matching is successful, determines that the first verification information passes the verification.
  • the first authentication information may be the network key cipher_key_A delivered by the network server.
  • the mobile terminal matches the received network key with the preset network key. If the matching is successful, the mobile terminal updates the original eSIM file by using the target eSIM file. Meanwhile, the network key delivered by the network server may be It is used to verify the authenticity of the network server. If the network key matches the default network key successfully, it indicates that the network key is delivered by the real network server; if the matching is unsuccessful, it may be a network server spoofed by the hacker. Then, the mobile terminal will not update the original eSIM file with the target eSIM file, that is, the original eSIM file is prevented from being tampered with to protect the original eSIM file.
  • the mobile terminal updates the original eSIM file by using the target eSIM file.
  • the method described in FIG. 1 further includes the following steps:
  • the mobile terminal acquires the second verification information in a security environment, where the second verification information is information used to verify the security of the target application;
  • step 105 The mobile terminal verifies the second verification information in a secure environment. If the verification passes, step 105 is performed; otherwise, the process ends.
  • the second verification information is information for verifying the security of the target application.
  • the second verification information may be an application security key HMAC_key_A, which may be used to verify whether the target application is currently in a secure state, and the application security key may be pre-stored by the mobile terminal, or may be obtained from the operator security tool.
  • HMAC_key_A an application security key
  • the embodiment of the invention is not limited.
  • the method described in FIG. 1 further includes the following steps:
  • the mobile terminal outputs a first verification instruction, where the first verification instruction is used to instruct the user to input the first biometric information;
  • the mobile terminal determines whether the first biometric information input by the user passes the verification. If yes, step 105 is performed; otherwise, the process ends.
  • the first biometric information may be fingerprint information, iris information, voiceprint information, facial image information, retina information, and the like of the user, which is not limited in this embodiment.
  • the first biometric information may be fingerprint information of the user.
  • the eSIM file When the eSIM file is updated, the user outputs a verification instruction, and the user inputs a fingerprint. When the fingerprint of the user matches the preset fingerprint, the eSIM file may be updated. ; if it does not match, the eSIM file cannot be updated.
  • the mobile terminal can update the original eSIM file by using the target eSIM file, thereby preventing the eSIM file from being maliciously falsified and improving the security of the mobile terminal.
  • the method described in FIG. 1 further includes the following steps:
  • the mobile terminal maps the target eSIM file in the secure environment to the common environment through the shared buffer to update the eSIM file in the common environment.
  • the eSIM file in the security environment is isolated from the eSIM file in the normal environment.
  • the mobile terminal can perform a security recovery process to prevent malicious tampering of the eSIM file.
  • FIG. 2 is a schematic diagram of a specific principle of preventing an eSIM file from being tampered with according to an embodiment of the present invention.
  • the schematic diagram shown in FIG. 2 is taken as an example to illustrate an eSIM file disclosed in an embodiment of the present invention.
  • the method of being tampered with, the mobile terminal includes a normal environment (Non-secure world) and a secure environment (Secure world).
  • the network (true/false) server sends the request (ie, the first update request) to the eSimApp application in the normal environment;
  • the eSimApp application notifies the SCM Driver of the single-chip driver, and the network requests to update the eSIM file;
  • the mobile terminal enters the TZ environment, and starts the Sec-eSimApp application (ie, the target application), notifying the SCM Driver module that the Sec-eSimApp application is ready;
  • the SCM Driver module notifies the eSimApp application that the Sec-eSimApp application is ready;
  • the eSimApp application notifies the web server and performs the following operations
  • the network server sends a network key cipher_key_A (ie, the first verification information);
  • the mobile terminal sends a network key cipher_key_A and an application security key HMAC_key_A (ie, the second verification information) to the Crypto module for validity verification (ie, verification);
  • the application security key may be pre-stored by the mobile terminal or may be obtained from an operator security tool.
  • the server may be a pseudo server or a server exception, ending the update process.
  • the Crypto module successfully verifies the validity of the network key and the application security key, notifies the Sec-eSimApp application that the application is successful, and performs subsequent operations;
  • the web server delivers the eSIM file (ie, the target eSIM file) to the Sec-eSimApp application;
  • the file server FileService saves the eSIM file as a temporary eSIM file
  • the security identification module starts the biometric APP
  • the biometric APP notifies the user to confirm the biometric information
  • the user inputs the biometric information (ie, the first biometric information) to confirm the operation;
  • the biometric APP transmits the biometric information input by the user to the biometric module
  • the biometric module determines that the first biometric information input by the user passes the verification, and notifies the biometric information input by the FileService user that the verification is successful;
  • FileService saves the temporary eSIM file as a formal secure eSIM file to the SFS (Security Files System) system;
  • the secure eSIM file in the SFS system performs secure file mapping in the shared buffer, and the mapping generates an eSIM file in a common environment;
  • the embodiment of the invention verifies the user's selection and modification authority through the biometric identification technology, thereby greatly enhancing the security and effectively preventing the occurrence of equipment loss or misoperation. Moreover, when a hacker maliciously tampers with an eSIM file, the mobile terminal can perform a security recovery process to prevent malicious tampering by the hacker.
  • the mobile terminal when the method described in FIG. 1 is implemented, when the user needs to update the eSIM file, the mobile terminal needs to perform verification of the first verification information in a secure environment. When the verification is successful, the mobile terminal can use the target eSIM file to update. Original eSIM file. It can be seen that the implementation of the embodiment of the present invention can effectively prevent the eSIM file from being maliciously falsified and improve the security of the mobile terminal.
  • FIG. 3 is a schematic flowchart diagram of another method for preventing tampering of an eSIM file according to an embodiment of the present disclosure.
  • the method is applied to a mobile terminal, and the mobile terminal includes a general environment and a security environment, where the security environment is The mobile terminal runs in an environment under the security domain TZ.
  • the method of preventing tampering of an eSIM file may include the following steps.
  • the mobile terminal detects, in a normal environment, a first update request sent by the network server.
  • the first update request is used to request to update the original eSIM file in the mobile terminal.
  • the mobile terminal starts the target application in the security environment according to the first update request.
  • the mobile terminal detects the first verification information and the target eSIM file sent by the network server by using the target application.
  • the first verification information is information used to verify the identity of the network server.
  • the first authentication information may be the network key cipher_key_A delivered by the network server.
  • the mobile terminal checks the first verification information in a secure environment. If the mobile terminal successfully verifies the first verification information, step 305 is performed; otherwise, the process ends.
  • the mobile terminal performs the matching verification between the first verification information and the preset first verification information in a security environment, and if the matching is successful, determines that the first verification information passes the verification.
  • the mobile terminal acquires the second verification information in a secure environment.
  • the second verification information is information used to verify the security of the target application.
  • the second verification information may be an application security key HMAC_key_A, which may be used to verify whether the target application is currently in a secure state, and the application security key may be pre-stored by the mobile terminal, or may be obtained from the operator security tool.
  • HMAC_key_A an application security key
  • the embodiment of the invention is not limited.
  • the mobile terminal performs verification on the second verification information in a security environment. If the verification succeeds, step 307 is performed; otherwise, the process ends.
  • the mobile terminal performs the matching verification between the second verification information and the preset second verification information in a security environment, and if the matching is successful, determines that the second verification information passes the verification.
  • the mobile terminal updates the original eSIM file by using the target eSIM file.
  • the mobile terminal needs to perform verification of the first verification information and verification of the second verification information, and after both of the verifications are successful, the original eSIM file can be updated by using the target eSIM file, thereby effectively improving the movement. Terminal security.
  • the method described in FIG. 3 further includes the following steps:
  • the mobile terminal detects the second update request in the security environment, and the second update request is used to request to update the second verification information in the security environment, where the second update request carries the new second verification information and the third verification information;
  • step 33 The mobile terminal performs verification on the new second verification information and the third verification information in a security environment respectively. If the verification is successful, step 33) is performed; otherwise, the process ends.
  • the mobile terminal updates the second verification information with the new second verification information.
  • the third verification information may be used to verify the security of the source of the second update request.
  • the second update request may be issued by the operator security tool. Since the operator security tool may be falsified by the hacker, the identity of the operator security tool may be verified by the third verification information.
  • the mobile terminal may perform verification of the second verification information after the first verification information is verified, and may also perform verification of the second verification information, and then perform verification of the first verification information; The verification information and the second verification information are simultaneously verified, and the embodiment is not limited.
  • the third verification information may be used to verify the security of the source of the second update request.
  • the second update request may be issued by the operator security tool. Since the operator security tool may be falsified by the hacker, the identity of the operator security tool may be verified by the third verification information.
  • the mobile terminal can perform the update of the new second verification information, thereby preventing the second verification information from being maliciously modified, thereby improving the movement. Terminal security.
  • FIG. 4 is a schematic diagram of another specific principle for preventing tampering of an eSIM file according to an embodiment of the present invention.
  • the schematic diagram shown in FIG. 4 is taken as an example to illustrate another prevention disclosed by the embodiment of the present invention.
  • the method in which the eSIM file is tampered with, the mobile terminal includes a normal environment (Non-secure world) and a secure environment (Secure world).
  • the new security key is obtained from the carrier security tool.
  • HMAC_key_A ie, the new second authentication information
  • the network key ie, the third verification information
  • the Sec-eSimApp application sends the new application security key HMAC_key_A and network key obtained from the carrier security tool to the Crypto module for security verification;
  • the carrier security tool is secure, and the new application security key HMAC_key_A is verified.
  • Update the application security key by overwriting the original security key with the security key downloaded from the carrier security tool.
  • the application security key and the network key are successfully verified, and before the application security key is updated, the biometric information of the user may be collected to verify the identity of the user.
  • the method described in FIG. 3 further includes the following steps:
  • the mobile terminal detects a third update request in a security environment, the third update request is used to request to update the target application and the second verification information in the security environment, and the third update request carries a new target application, a new second Verification information and third verification information;
  • step 36 The mobile terminal performs verification on the new second verification information and the third verification information in a security environment respectively. If the verification is successful, step 36 is performed; otherwise, the process ends.
  • the mobile terminal updates the target application with the new target application and updates the second verification information with the new second verification information.
  • the third verification information may be used to verify the security of the source of the third update request.
  • the third update request may be sent by the operator security tool. Since the operator security tool may be forged by the hacker, the identity of the operator security tool may be verified by the third verification information.
  • the method described in FIG. 3 further includes the following steps:
  • the mobile terminal performs signature information verification on the new target application, and if the verification passes, performs step 36); otherwise, the process ends.
  • the signature information may be used to verify the security of the new target application; if the signature information of the new target application fails, the new target application may have a security risk, thereby ending the process; The verification of the signature information of the target application indicates that the new target application is secure and can proceed to the next step.
  • the method described in FIG. 3 further includes the following steps:
  • the mobile terminal outputs a second verification instruction, where the second verification instruction is used to instruct the user to input the second biometric information;
  • the mobile terminal determines whether the second biometric information input by the user passes the verification. If the verification passes, step 310 is performed; otherwise, the process ends.
  • the mobile terminal updates the target application with the new target application, and updates the second verification information with the new second verification information.
  • FIG. 4 is a schematic diagram of another specific principle for preventing tampering of an eSIM file according to an embodiment of the present invention.
  • the schematic diagram shown in FIG. 4 is taken as an example to illustrate another prevention disclosed by the embodiment of the present invention.
  • the method in which the eSIM file is tampered with, the mobile terminal includes a normal environment (Non-secure world) and a secure environment (Secure world).
  • the network key (ie, the third verification information) can also be obtained from the operator security tool.
  • the TZ technology and the signature fuse are used to prevent the hacker from updating the cracked Sec-eSimApp application through the physical connection.
  • the security identification module notifies the biometric APP to start;
  • the biometric APP notifies the user to confirm the biometric information
  • the biometric APP transmits the biometric information input by the user to the biometric module
  • the security identification module notifies the file server that the FileService security process is fully verified
  • the eSimApp application connects to the web server to request an update
  • FIG. 5 is a schematic structural diagram of a mobile terminal according to an embodiment of the present invention, which may be used to perform a method for preventing an eSIM file from being tampered with disclosed in the embodiment of the present invention.
  • the mobile terminal includes a common environment and a security environment, where the security environment is an environment in which the mobile terminal operates in the security domain TZ environment, and the mobile terminal may include:
  • the first detecting unit 501 is configured to detect, in the normal environment, a first update request sent by the network server, where the first update request is used to request to update an original embedded user identification module eSIM file in the mobile terminal;
  • the startup unit 502 is configured to start the target application in the security environment according to the first update request.
  • the first detecting unit 501 is further configured to: detect, by the target application, the first verification information and the target eSIM file sent by the network server, where the first verification information is information used for verifying the identity of the network server;
  • the verification unit 503 is configured to verify the first verification information in a secure environment
  • the first update unit 505 is configured to update the original eSIM file with the target eSIM file when the verification unit 503 successfully verifies the first verification information in a secure environment.
  • FIG. 6 is a schematic structural diagram of another mobile terminal according to an embodiment of the present invention.
  • the mobile terminal shown in FIG. 6 is further optimized based on the mobile terminal shown in FIG. 5.
  • the mobile terminal shown in FIG. 6 may further include:
  • the obtaining unit 505 is configured to obtain the second verification information in a secure environment before the first update unit 504 updates the original eSIM file by using the target eSIM file after the verification unit 503 successfully verifies the first verification information in the security environment.
  • the second verification information is information for verifying security of the target application;
  • the verification unit 503 is further configured to verify the second verification information in a secure environment
  • the first update unit 504 is specifically configured to update the original eSIM file with the target eSIM file when the verification unit 503 successfully verifies the second verification information.
  • the mobile terminal in FIG. 6 may further include:
  • the first output unit 506 is configured to: after the verification unit 503 successfully verifies the first verification information in the security environment, before the first update unit 504 updates the original eSIM file by using the target eSIM file, output a first verification instruction, where the first output unit 504 a verification instruction is used to instruct the user to input the first biometric information;
  • the first determining unit 507 is configured to determine whether the first biometric information input by the user is verified to pass;
  • the first updating unit 504 is specifically configured to update the original eSIM file by using the target eSIM file when the first determining unit 507 determines that the first biometric information input by the user passes.
  • the mobile terminal shown in FIG. 6 may further include:
  • the mapping unit 508 is configured to map the target eSIM file in the secure environment to the normal environment through the shared buffer.
  • the mobile terminal shown in FIG. 6 may further include:
  • the second detecting unit 509 is configured to detect a second update request in the security environment, where the second update request is used to request to update the second verification information, and the second update request carries the new second verification information and the third verify message;
  • the verification unit 503 is further configured to perform verification on the new second verification information and the third verification information respectively in a security environment;
  • the second update unit 510 is configured to update the second verification information by using the new second verification information when the verification unit 503 successfully verifies both the new second verification information and the third verification information.
  • FIG. 7 is a schematic structural diagram of still another mobile terminal according to an embodiment of the present invention.
  • the mobile terminal shown in FIG. 7 is further optimized based on the mobile terminal shown in FIG. 5.
  • the mobile terminal shown in FIG. 7 may further include:
  • the third detecting unit 511 is configured to detect a third update request in the security environment, where the third update request is used to request to update the target application and the second verification information, where the third update request carries a new target application, new Second verification information and third verification information;
  • the verification unit 503 is further configured to perform verification on the new second verification information and the third verification information respectively in a security environment;
  • the third updating unit 512 is configured to: when the verification unit 503 verifies that both the new second verification information and the third verification information are successful, update the target application with the new target application, and update the new application with the second second verification information. Second verification information.
  • the verification unit 503 is further configured to: after the new second verification information and the third verification information are successfully verified, the third update unit 512 updates the target application by using the new target application, And verifying the signature information of the new target application before updating the second verification information by using the new second verification information;
  • the mobile terminal further includes:
  • the second determining unit 513 is configured to determine whether the verification of the signature information is passed;
  • the third update unit 512 is specifically configured to update the target application with the new target application and update the second verification information with the new second verification information when the second determination unit 513 determines that the signature information is verified to pass.
  • the mobile terminal shown in FIG. 7 further includes:
  • the second output unit 514 is configured to, after the second determining unit 513 determines that the signature information is verified, the third update unit 512 updates the target application with the new target application, and updates the second verification information by using the new second verification information, And outputting a second verification instruction, where the second verification instruction is used to instruct the user to input the second biometric information;
  • the second determining unit 513 is further configured to determine whether the second biometric information input by the user is verified to pass;
  • the third updating unit 512 is specifically configured to: when the second determining unit 513 determines that the second biometric information verification passes, update the target application with the new target application, and update the second verification information by using the new second verification information. .
  • the user needs to perform verification of the first verification information and the second verification information when performing the update of the eSIM file, the target application, and the new second verification information.
  • the verification of the biometric information can be performed to update the eSIM file, the target application, and the new second verification information.
  • the implementation of the embodiment of the present invention can effectively prevent the eSIM file from being maliciously falsified and improve the security of the mobile terminal.
  • FIG. 8 is a schematic structural diagram of another mobile terminal according to an embodiment of the present invention, which may be used to perform a method for preventing an eSIM file from being tampered with disclosed in the embodiment of the present invention.
  • the mobile terminal 800 can include at least one processor 801, at least one input device 802, at least one output device 803, a memory 804, and the like. Among them, these components can be communicatively connected through one or more buses 805. It can be understood by those skilled in the art that the structure of the mobile terminal shown in FIG. 8 does not constitute a limitation on the embodiment of the present invention. It may be a bus-shaped structure or a star-shaped structure, and may also include more than the illustration. Or fewer parts, or combine some parts, or different parts. among them:
  • the processor 801 is a control center of the mobile terminal that connects various portions of the entire mobile terminal using various interfaces and lines, by running or executing programs and/or modules stored in the memory 804, and recalling data stored in the memory 804, To perform various functions and process data of the mobile terminal.
  • the processor 801 may be composed of an integrated circuit (IC), for example, may be composed of a single packaged IC, or may be composed of a plurality of packaged ICs having the same function or different functions.
  • the processor 801 may include only a central processing unit (CPU), or may be a CPU, a digital signal processor (DSP), or a graphics processing unit (GPU). And a combination of various control chips.
  • the CPU may be a single operation core, and may also include multiple operation cores.
  • the input device 802 can include a standard touch screen, a keyboard, etc., and can also include a wired interface, a wireless interface, etc., and can be used to interact with a web server.
  • the output device 803 may include a display screen, a speaker, etc., and may also include a wired interface, a wireless interface, and the like.
  • the memory 804 can be used to store software programs and modules, and the processor 801, the input device 802, and the output device 803 perform various functional applications of the mobile terminal and implement data processing by calling software programs and modules stored in the memory 804.
  • the memory 804 mainly includes a program storage area and a data storage area, wherein the program storage area can store an operating system, an application required for at least one function, and the like; the data storage area can store data created according to usage of the mobile terminal and the like.
  • the operating system may be an Android system, an iOS system, a Windows operating system, or the like.
  • a common environment and a security environment are included, wherein the security environment is an environment in which the mobile terminal runs in a security domain TZ environment, and the processor 801 calls an application stored in the memory 804, Do the following:
  • the target application Detecting, by the target application, the first verification information and the target eSIM file sent by the network server, where the first verification information is information used for verifying the identity of the network server;
  • the original eSIM file is updated with the target eSIM file.
  • the processor 801 may also invoke the application stored in the memory 804 and execute The following operations:
  • Second verification information in a security environment, where the second verification information is information used to verify security of the target application
  • the specific implementation manner in which the processor 801 updates the original eSIM file by using the target eSIM file may be:
  • the original eSIM file is updated with the target eSIM file.
  • the processor 801 may also invoke the application stored in the memory 804 and execute The following operations:
  • the trigger output device 803 outputs a first verification instruction, which is used to instruct the user to input the first biometric information through the input device 802;
  • the specific implementation manner in which the processor 801 updates the original eSIM file by using the target eSIM file may be:
  • the original eSIM file is updated with the target eSIM file.
  • the processor 801 can also invoke an application stored in the memory 804 and perform the following operations:
  • the target eSIM file in a secure environment is mapped to the normal environment through the shared buffer.
  • the processor 801 can also invoke an application stored in the memory 804 and perform the following operations:
  • the second update request is detected in a security environment, where the second update request is used to request to update the second verification information, and the second update request carries the new second verification information and the third verification information;
  • the second verification information is updated with the new second verification information.
  • the processor 801 can also invoke an application stored in the memory 804 and perform the following operations:
  • the third update request is detected in a security environment, wherein the third update request is used to request to update the target application and the second verification information, where the third update request carries the new target application, the new second verification information, and the third verification information. ;
  • the target application is updated with the new target application, and the second verification information is updated with the new second verification information.
  • the processor 801 can also invoke an application stored in the memory 804 and perform the following operations:
  • the specific implementation manner in which the processor 801 updates the target application by using the new target application and updates the second verification information by using the new second verification information may be:
  • the target application is updated with the new target application, and the second verification information is updated with the new second verification information.
  • the processor 801 may also invoke the application stored in the memory 804. Program and do the following:
  • the trigger output device 803 outputs a second verification instruction, which is used to instruct the user to input the second biometric information through the input device 802;
  • the specific implementation manner in which the processor 801 updates the target application by using the new target application and updates the second verification information by using the new second verification information may be:
  • the target application is updated with the new target application, and the second verification information is updated with the new second verification information.
  • the user needs to perform verification of the first verification information and the second verification information when performing the update of the eSIM file, the target application, and the new second verification information, and the verification is successful.
  • the update of the eSIM file, the target application, and the new second verification information can be performed. It can be seen that the implementation of the embodiment of the present invention can effectively prevent the eSIM file from being maliciously falsified and improve the security of the mobile terminal.
  • modules or units in all embodiments of the present invention may be implemented by a general-purpose integrated circuit, such as a CPU, or by an ASIC (Application Specific Integrated Circuit).
  • a general-purpose integrated circuit such as a CPU
  • ASIC Application Specific Integrated Circuit
  • the units in the mobile terminal in the embodiment of the present invention may be combined, divided, and deleted according to actual needs.
  • the storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Bioethics (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • Telephone Function (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明实施例公开了一种防止eSIM文件被篡改的方法及移动终端,该方法包括:移动终端在普通环境下检测网络服务器发送的第一更新请求,第一更新请求用于请求更新移动终端中的原始嵌入式用户识别模块eSIM文件;移动终端根据第一更新请求,启动安全环境下的目标应用;移动终端通过目标应用检测网络服务器发送的第一验证信息和目标eSIM文件,其中,第一验证信息为用于对网络服务器的身份进行验证的信息;移动终端在安全环境下对第一验证信息进行校验;当移动终端在安全环境下对第一验证信息校验成功时,移动终端利用目标eSIM文件更新原始eSIM文件。实施本发明实施例,能够有效防止eSIM文件被恶意篡改,提高移动终端的安全性。

Description

一种防止eSIM文件被篡改的方法及移动终端
本申请要求于2016年9月29日提交中国专利局,申请号为201610866774.1、发明名称为“一种防止eSIM文件被篡改的方法及移动终端”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及通信技术领域,尤其涉及一种防止eSIM文件被篡改的方法及移动终端。
背景技术
随着移动通信的快速发展,已经逐渐出现将eSIM(embedded Subscriber Identification Module,嵌入式用户识别模块)取代传统的SIM卡应用于终端中。与传统的SIM卡相比,eSIM不是作为独立的可移除零部件加入终端中,而是直接嵌入到终端芯片中,eSIM的出现使得用户在无需购买新终端的提前下,即可以自由选择、随时切换运营商。
由于eSIM通过终端与运营商建立连接,因此在实际应用中,可能会由于黑客的攻击,使得eSIM文件恶意地被篡改,因此用户的个人数据存在安全隐患,使得终端的安全性低下。
发明内容
本发明实施例公开了一种防止eSIM文件被篡改的方法及移动终端,能够有效防止eSIM文件被恶意篡改,提高移动终端的安全性。
本发明实施例第一方面公开了一种防止eSIM文件被篡改的方法,移动终端包括普通环境和安全环境,其中,所述安全环境为所述移动终端运行在安全域TZ下的环境,所述方法包括:
所述移动终端在所述普通环境下检测网络服务器发送的第一更新请求,所述第一更新请求用于请求更新所述移动终端中的原始嵌入式用户识别模块eSIM文件;
所述移动终端根据所述第一更新请求,启动所述安全环境下的目标应用;
所述移动终端通过所述目标应用检测所述网络服务器发送的第一验证信息和目标eSIM文件,其中,所述第一验证信息为用于对所述网络服务器的身份进行验证的信息;
所述移动终端在所述安全环境下对所述第一验证信息进行校验;
当所述移动终端在所述安全环境下对所述第一验证信息校验成功时,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件。
作为一种可选的实施方式,所述移动终端在所述安全环境下对所述第一验证信息校验成功之后,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件之前,所述方法还包括:
所述移动终端在所述安全环境下获取第二验证信息,所述第二验证信息为用于对所述目标应用的安全性进行验证的信息;
所述移动终端在所述安全环境下对所述第二验证信息进行校验;
其中,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件,包括:
若所述移动终端对所述第二验证信息校验成功,则所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件。
作为一种可选的实施方式,所述移动终端在所述安全环境下对所述第一验证信息校验成功之后,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件之前,所述方法还包括:
所述移动终端输出第一验证指令,所述第一验证指令用于指示用户输入第一生物特征信息;
所述移动终端判断用户输入的第一生物特征信息是否校验通过;
其中,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件,包括:
若所述移动终端判断用户输入的所述第一生物特征信息校验通过,则所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件。
作为一种可选的实施方式,所述方法还包括:
所述移动终端将所述安全环境下的所述目标eSIM文件通过共享缓冲器映射至所述普通环境下,以更新所述普通环境下的eSIM文件。
作为一种可选的实施方式,所述方法还包括:
所述移动终端在所述安全环境下检测第二更新请求,其中,所述第二更新请求用于请求更新所述安全环境下的所述第二验证信息,所述第二更新请求携带有新的第二验证信息和第三验证信息;
所述移动终端在所述安全环境下分别对所述新的第二验证信息和所述第三验证信息进行校验;
当所述移动终端对所述新的第二验证信息和所述第三验证信息均校验成功时,所述移动终端利用所述新的第二验证信息更新所述第二验证信息。
作为一种可选的实施方式,所述方法还包括:
所述移动终端在所述安全环境下检测第三更新请求,其中,所述第三更新请求用于请求更新所述安全环境下的所述目标应用和所述第二验证信息,所述第三更新请求携带有新的目标应用、新的第二验证信息和第三验证信息;
所述移动终端在所述安全环境下分别对所述新的第二验证信息和所述第三验证信息进行校验;
当所述移动终端对所述新的第二验证信息和所述第三验证信息均校验成功时,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
作为一种可选的实施方式,所述移动终端对所述新的第二验证信息和所述第三验证信息均校验成功之后,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息之前,所述方法还包括:
所述移动终端对所述新的目标应用进行签名信息验证;
所述移动终端判断所述签名信息验证是否通过;
其中,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息,包括:
若所述移动终端判断所述签名信息验证通过,则所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
作为一种可选的实施方式,所述移动终端判断所述签名信息验证通过之后,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息之前,所述方法还包括:
所述移动终端输出第二验证指令,所述第二验证指令用于指示用户输入第二生物特征信息;
所述移动终端判断用户输入的第二生物特征信息是否校验通过;
其中,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息,包括:
若所述移动终端判断所述第二生物特征信息校验通过,则所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
本发明实施例第二方面公开一种移动终端,所述移动终端包括普通环境和安全环境,其中,所述安全环境为所述移动终端运行在安全域TZ下的环境,所述移动终端包括:
第一检测单元,设置为在所述普通环境下检测网络服务器发送的第一更新请求,所述第一更新请求用于请求更新所述移动终端中的原始嵌入式用户识别模块eSIM文件;
启动单元,设置为根据所述第一更新请求,启动所述安全环境下的目标应用;
所述第一检测单元,还设置为通过所述目标应用检测所述网络服务器发送的第一验证信息和目标eSIM文件,其中,所述第一验证信息为用于对所述网络服务器的身份进行验证的信息;
校验单元,设置为在所述安全环境下对所述第一验证信息进行校验;
第一更新单元,设置为当所述校验单元在所述安全环境下对所述第一验证信息校验成功时,利用所述目标eSIM文件更新所述原始eSIM文件。
作为一种可选的实施方式,所述移动终端还包括:
获取单元,设置为在所述校验单元在所述安全环境下对所述第一验证信息校验成功之后,所述第一更新单元利用所述目标eSIM文件更新所述原始eSIM文件之前,在所述安全环境下获取第二验证信息,所述第二验证信息为用于对所述目标应用的安全性进行验证的信息;
所述校验单元,还设置为在所述安全环境下对所述第二验证信息进行校验;
所述第一更新单元具体设置为当所述校验单元对所述第二验证信息校验成功时,利用所述目标eSIM文件更新所述原始eSIM文件。
作为一种可选的实施方式,所述移动终端还包括:
第一输出单元,设置为当所述校验单元在所述安全环境下对所述第一验证信息校验成功之后,所述第一更新单元利用所述目标eSIM文件更新所述原始eSIM文件之前,输出第一验证指令,所述第一验证指令用于指示用户输入第一生物特征信息;
第一判断单元,设置为判断用户输入的第一生物特征信息是否校验通过;
所述第一更新单元具体设置为当所述第一判断单元判断用户输入的所述第一生物特征信息校验通过时,利用所述目标eSIM文件更新所述原始eSIM文件。
作为一种可选的实施方式,所述移动终端还包括:
映射单元,设置为将所述安全环境下的所述目标eSIM文件通过共享缓冲器映射至所述普通环境下,以更新所述普通环境下的eSIM文件。
作为一种可选的实施方式,所述移动终端还包括:
第二检测单元,设置为在所述安全环境下检测第二更新请求,其中,所述第二更新请求用于请求更新所述第二验证信息,所述第二更新请求携带有新的第二验证信息和第三验证信息;
所述校验单元,还设置为在所述安全环境下分别对所述新的第二验证信息和所述第三验证信息进行校验;
第二更新单元,设置为当所述校验单元对所述新的第二验证信息和所述第三验证信息均校验成功时,利用所述新的第二验证信息更新所述第二验证信息。
作为一种可选的实施方式,所述移动终端还包括:
第三检测单元,设置为在所述安全环境下检测第三更新请求,其中,所述第三更新请求用于请求更新所述目标应用和所述第二验证信息,所述第三更新请求携带有新的目标应用、新的第二验证信息和第三验证信息;
所述校验单元,还设置为在所述安全环境下分别对所述新的第二验证信息和所述第三验证信息进行校验;
第三更新单元,设置为当所述校验单元对所述新的第二验证信息和所述第三验证信息均校验成功时,利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
作为一种可选的实施方式,所述校验单元,还设置为在对所述新的第二验证信息和所述第三验证信息均校验成功之后,所述第三更新单元利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息之前,对所述新的目标应用进行签名信息验证;
所述移动终端还包括:
第二判断单元,设置为判断所述签名信息验证是否通过;
所述第三更新单元具体设置为当所述第二判断单元判断所述签名信息验证通过时,利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
作为一种可选的实施方式,所述移动终端还包括:
第二输出单元,设置为在所述第二判断单元判断所述签名信息验证通过之后,所述第三更新单元利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息之前,输出第二验证指令,所述第二验证指令用于指示用户输入第二生物特征信息;
所述第二判断单元,还设置为判断用户输入的第二生物特征信息是否校验通过;
所述第三更新单元具体设置为当所述第二判断单元判断所述第二生物特征信息校验通过时,利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
与现有技术相比,本发明实施例具有以下有益效果:
本发明实施例中,移动终端在普通环境下通过检测网络服务器发送的第一更新请求,启动安全环境下的目标应用,从而通过目标应用检测网络服务器发送的第一验证信息,当在安全环境下对第一验证信息校验成功时,移动终端利用目标eSIM文件更新原始eSIM文件。可见,实施本发明实施例,当移动终端检测到网络服务器发起的eSIM文件更新时,需在TZ环境下对网络服务器的身份信息校验成功后才能进行eSIM文件的更新,从而能够有效防止eSIM文件被恶意篡改,提高移动终端的安全性。
附图说明
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是本发明实施例公开的一种防止eSIM文件被篡改的方法的流程示意图;
图2是本发明实施例公开的一种防止eSIM文件被篡改的具体原理示意图;
图3是本发明实施例公开的另一种防止eSIM文件被篡改的方法的流程示意图;
图4是本发明实施例公开的另一种防止eSIM文件被篡改的具体原理示意图;
图5是本发明实施例公开的一种移动终端的结构示意图;
图6是本发明实施例公开的另一种移动终端的结构示意图;
图7是本发明实施例公开的又一种移动终端的结构示意图;
图8是本发明实施例公开的又一种移动终端的结构示意图;
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
本发明实施例公开了一种防止eSIM文件被篡改的方法及移动终端,能够有效防止eSIM文件被恶意篡改,提高移动终端的安全性。以下分别进行详细说明。
请参阅图1,图1是本发明实施例公开的一种防止eSIM文件被篡改的方法的流程示意图,该方法应用于移动终端,且移动终端包括普通环境和安全环境,其中,安全环境为移动终端运行在安全域TZ下的环境。如图1所示,该防止eSIM文件被篡改的方法可以包括以下步骤。
101、移动终端在普通环境下检测网络服务器发送的第一更新请求。
本发明实施例中,该第一更新请求用于请求更新移动终端中的原始eSIM文件。移动终端可以包括移动手机、平板电脑、个人数字助理(Personal Digital Assistant,PDA)、移动互联网设备(Mobile Internet Device,MID)、智能穿戴设备(如智能手表、智能手环)等各种移动终端,本发明实施例不作限定。
本发明实施例中,移动终端可以包括普通环境和安全环境,其中,安全环境又可称为TZ(TrustZone,安全域)环境,是移动终端运行在TZ下的一种环境,具体的,是基于TZ技术通过在嵌入式内核中开辟出一块可信代码区来构建安全运行的环境。普通环境是移动终端中原有的环境,是一种非TZ环境,如普通Android系统下用户可以正常进行各项操作(如打电话、上网、发信息等)的环境。普通环境和安全环境为移动终端中两个独立且互不干扰的工作环境。
102、移动终端根据第一更新请求,启动安全环境下的目标应用。
103、移动终端通过目标应用检测网络服务器发送的第一验证信息和目标eSIM文件。
本发明实施例中,第一验证信息为用于对网络服务器的身份进行验证的信息,即用于验证网络服务器的真伪。第一验证信息可以是网络服务器下发的网络密钥cipher_key_A。
104、移动终端在安全环境下对第一验证信息进行校验,若移动终端对第一验证信息校验成功,则执行步骤105;否则,结束本流程。
本发明实施例中,移动终端在安全环境下将第一验证信息与预设的第一验证信息进行匹配验证,若匹配成功,则确定第一验证信息通过校验。第一验证信息可以是网络服务器下发的网络密钥cipher_key_A。具体的,移动终端将接收到的网络密钥与预设的网络密钥进行匹配验证,若匹配成功,则移动终端利用目标eSIM文件更新原始eSIM文件;同时,网络服务器下发的网络密钥可以用来验证网络服务器的真伪,若该网络密钥与预设的网络密钥匹配成功,则说明是真网络服务器下发的网络密钥;若匹配不成功,则可能是黑客伪装的网络服务器,则移动终端将不利用目标eSIM文件更新原始eSIM文件,即防止原始eSIM文件文件被篡改,以对原始eSIM文件进行保护。
105、移动终端利用目标eSIM文件更新原始eSIM文件。
作为一种可选的实施方式,移动终端在安全环境下对第一验证信息校验成功之后,以及移动终端利用目标eSIM文件更新原始eSIM文件之前,图1描述的方法还包括以下步骤:
11)移动终端在安全环境下获取第二验证信息,第二验证信息为用于对目标应用的安全性进行验证的信息;
12)移动终端在安全环境下对第二验证信息进行校验,若校验通过,则执行步骤105;否则,结束本流程。
该实施方式中,第二验证信息为用于对目标应用的安全性进行验证的信息。第二验证信息可以是应用安全密钥HMAC_key_A,可以用来验证目标应用当前是否处于安全状态,且应用安全密钥可以是移动终端预先存储的,也可以是从运营商安全工具中获取的,本发明实施例不作限定。
作为一种可选的实施方式,移动终端在安全环境下对第一验证信息校验成功之后,以及移动终端利用目标eSIM文件更新原始eSIM文件之前,图1描述的方法还包括以下步骤:
13)移动终端输出第一验证指令,第一验证指令用于指示用户输入第一生物特征信息;
14)移动终端判断用户输入的第一生物特征信息是否校验通过,若通过,则执行步骤105;否则,结束本流程。
该实施方式中,第一生物特征信息可以是用户的指纹信息、虹膜信息、声纹信息、脸像信息、视网膜信息等,该实施方式不作限定。举例来说,第一生物特征信息可以是用户的指纹信息,用户在进行eSIM文件更新时,输出验证指令,用户输入指纹,当用户的指纹与预设指纹匹配时,则可以进行eSIM文件的更新;若不匹配,则不能进行eSIM文件的更新。
该实施方式中,由于用户需要输入生物特征信息,并且验证成功,移动终端才能利用目标eSIM文件更新原始eSIM文件,从而能够防止eSIM文件被恶意篡改,提高移动终端的安全性。
作为一种可选的实施方式,图1描述的方法还包括以下步骤:
15)移动终端将安全环境下的目标eSIM文件通过共享缓冲器映射至普通环境下,以更新所述普通环境下的eSIM文件。
该实施方式中,将安全环境下的eSIM文件与普通环境下的eSIM文件相隔离,黑客进行恶意篡改时,移动终端可以进行安全恢复流程,从而来防止eSIM文件的恶意篡改。
请参阅图2,图2是本发明实施例公开的一种防止eSIM文件被篡改的具体原理示意图,以图2所示的原理示意图为例,来说明本发明实施例公开的一种防止eSIM文件被篡改的方法,移动终端包括普通环境(Non-secure world)和安全环境(Secure world)。
如图2所示,具体实施例的流程步骤与图2标注的步骤一致,具体流程如下:
(1)网络(真/伪)服务器发送请求(即第一更新请求)到普通环境下的eSimApp应用;
(2)eSimApp应用通知单片机驱动程序SCM Driver,网络请求更新eSIM文件;
(3)SCM Driver通知监测器Monitor有网络更新;
(4)移动终端进入TZ环境,并且启动Sec-eSimApp应用(即目标应用),通知SCM Driver模块Sec-eSimApp应用准备就绪;
(5)SCM Driver模块通知eSimApp应用,Sec-eSimApp应用准备就绪;
(6)eSimApp应用通知网络服务器,并进行以下操作;
(7)网络服务器下发网络密钥cipher_key_A(即第一验证信息);
(8)移动终端发送网络密钥cipher_key_A和应用安全密钥HMAC_key_A (即第二验证信息)到Crypto模块进行有效性验证(即进行校验);
具体地,应用安全密钥可以是移动终端预先存储的,也可以是从运营商安全工具中获取的。
(9)若Crypto模块对网络密钥以及应用安全密钥的有效性验证失败,通知Sec-eSimApp应用效验失败不再进行后续操作;
有效性验证失败,则说明服务器可能为伪服务器或服务器异常,从而结束更新流程。
(10)Crypto模块对网络密钥以及应用安全密钥的有效性验证成功,通知Sec-eSimApp应用效验成功,并进行后续操作;
(11)Sec-eSimApp应用通知网络服务器,并进行下步操作;
(12)网络服务器下发eSIM文件(即目标eSIM文件)到Sec-eSimApp应用;
(13)文件服务器FileService将eSIM文件保存为临时eSIM文件;
(14)FileService通知安全识别模块进行安全效验流程;
(15)安全识别模块启动生物识别APP;
(16)生物识别APP通知用户进行生物特征信息的确认;
(17)用户输入生物特征信息(即第一生物特征信息)确认操作;
(18)生物识别APP把用户输入的生物特征信息传输给生物识别模块;
(19)生物识别模块判断用户输入的所述第一生物特征信息校验通过,则通知FileService用户输入的生物特征信息验证成功;
(20)FileService把临时eSIM文件作为正式安全eSIM文件保存到SFS(Security Files System,安全文件系统)系统中;
(21)SFS系统中的安全eSIM文件在共享buffer中做安全文件映射,映射生成普通环境下的eSIM文件;
(22)其它需要使用eSIM功能的模块通过EFS(Encrypting File System,加密文件系统)系统使用eSIM文件。
本发明实施例通过生物识别技术校验用户的选择及修改权限,大大加强了安全性,有效防止因为设备丢失或误操作的产生。并且,当遇到黑客进行恶意篡改eSIM文件时,移动终端可以做安全恢复流程,从而来防止黑客的恶意篡改。
可见,实施图1所描述的方法,用户需要进行eSIM文件的更新时,移动终端需要在安全环境下进行第一验证信息的校验,当校验成功时,移动终端才可以利用目标eSIM文件更新原始eSIM文件。可见,实施本发明实施例,能够有效防止eSIM文件被恶意篡改,提高移动终端的安全性。
请参阅图3,图3是本发明实施例公开的另一种防止eSIM文件被篡改的方法的流程示意图,该方法应用于移动终端,且移动终端包括普通环境和安全环境,其中,安全环境为移动终端运行在安全域TZ下的环境。如图3所示,该防止eSIM文件被篡改的方法可以包括以下步骤。
301、移动终端在普通环境下检测网络服务器发送的第一更新请求。
本发明实施例中,该第一更新请求用于请求更新移动终端中的原始eSIM文件。
302、移动终端根据第一更新请求,启动安全环境下的目标应用。
303、移动终端通过目标应用检测网络服务器发送的第一验证信息和目标eSIM文件。
本发明实施例中,第一验证信息为用于对网络服务器的身份进行验证的信息。第一验证信息可以是网络服务器下发的网络密钥cipher_key_A。
304、移动终端在安全环境下对第一验证信息进行校验,若移动终端对第一验证信息校验成功,则执行步骤305;否则,结束本流程。
本发明实施例中,移动终端在安全环境下将第一验证信息与预设的第一验证信息进行匹配验证,若匹配成功,则确定第一验证信息通过校验。
305、移动终端在安全环境下获取第二验证信息。
本发明实施例中,第二验证信息为用于对目标应用的安全性进行验证的信息。第二验证信息可以是应用安全密钥HMAC_key_A,可以用来验证目标应用当前是否处于安全状态,且应用安全密钥可以是移动终端预先存储的,也可以是从运营商安全工具中获取的,本发明实施例不作限定。
306、移动终端在安全环境下对第二验证信息进行校验,若校验成功,则执行步骤307;否则,结束本流程。
本发明实施例中,移动终端在安全环境下将第二验证信息与预设的第二验证信息进行匹配验证,若匹配成功,则确定第二验证信息通过校验。
307、移动终端利用目标eSIM文件更新原始eSIM文件。
本发明实施例中,移动终端需要进行第一验证信息的校验以及第二验证信息的校验,并且两者均校验成功后,才能利用目标eSIM文件更新原始eSIM文件,从而能够有效提高移动终端的安全性。
作为一种可选的实施方式,图3描述的方法还包括以下步骤:
31)移动终端在安全环境下检测第二更新请求,第二更新请求用于请求更新安全环境下的第二验证信息,第二更新请求携带有新的第二验证信息和第三验证信息;
32)移动终端在安全环境下分别对新的第二验证信息和第三验证信息进行校验,若校验成功,则执行步骤33);否则,结束本流程。
33)移动终端利用新的第二验证信息更新第二验证信息。
该实施方式中,第三验证信息可以用于对第二更新请求的来源的安全性进行验证。第二更新请求可以是运营商安全工具下发的,由于运营商安全工具可能是黑客伪造的,所以可以通过第三验证信息来对运营商安全工具的身份进行校验。
该实施方式中,移动终端可以在第一验证信息验证通过之后,进行第二验证信息的验证;也可以先进行第二验证信息的验证,再进行第一验证信息的验证;还可以将第一验证信息与第二验证信息同时进行验证,本实施方式不作限定。
该实施方式中,第三验证信息可以用于对第二更新请求的来源的安全性进行验证。第二更新请求可以是运营商安全工具下发的,由于运营商安全工具可能是黑客伪造的,所以可以通过第三验证信息来对运营商安全工具的身份进行校验。
该实施方式中,新的第二验证信息以及第三验证信息均需要通过验证后,移动终端才能进行新的第二验证信息的更新,从而可以防止第二验证信息被恶意修改,进而提高了移动终端的安全性。
请参阅图4,图4是本发明实施例公开的另一种防止eSIM文件被篡改的具体原理示意图,以图4所示的原理示意图为例,来说明本发明实施例公开的另一种防止eSIM文件被篡改的方法,移动终端包括普通环境(Non-secure world)和安全环境(Secure world)。
如图4所示,举例来说,当移动终端收到运营商安全工具下发的更新应用安全密钥的请求(即第二更新请求)时,从运营商安全工具获取新的应用安全密钥HMAC_key_A(即新的第二验证信息),以及获取运营商安全工具下发的网络密钥(即第三验证信息);
Sec-eSimApp应用将从运营商安全工具获取的新的应用安全密钥HMAC_key_A和网络密钥发送至至Crypto模块中,以进行安全性验证;
若运营商安全工具下发的网络密钥与移动终端中预先存储的匹配成功,则说明该运营商安全工具是安全的,同时进行新的应用安全密钥HMAC_key_A的验证,若均验证成功,则进行应用安全密钥的更新,即利用从运营商安全工具中下载的安全密钥覆盖掉原先的安全密钥。可选的,在应用安全密钥和网络密钥均验证成功,在更新应用安全密钥之前,还可以采集用户的生物特征信息对用户的身份进行验证。
作为一种可选的实施方式,图3描述的方法还包括以下步骤:
34)移动终端在安全环境下检测第三更新请求,第三更新请求用于请求更新安全环境下的目标应用和第二验证信息,且第三更新请求携带有新的目标应用、新的第二验证信息和第三验证信息;
35)移动终端在安全环境下分别对新的第二验证信息和第三验证信息进行校验,若校验成功,则执行步骤36;否则,结束本流程。
36)所述移动终端利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息。
该实施方式中,第三验证信息可以用于对第三更新请求的来源的安全性进行验证。第三更新请求可以是运营商安全工具下发的,由于运营商安全工具可能是黑客伪造的,所以可以通过第三验证信息来对运营商安全工具的身份进行校验。
作为一种可选的实施方式,在执行完步骤35)之后,在执行步骤36)之前,图3描述的方法还包括以下步骤:
37)移动终端对新的目标应用进行签名信息验证,若验证通过,则执行步骤36);否则,结束本流程。
该实施方式中,签名信息可以用来验证新的目标应用的安全性;若新的目标应用的签名信息未通过,则说明新的目标应用可能存在安全隐患,从而结束本流程,;若新的目标应用的签名信息通过验证,则说明新的目标应用是安全的,可以进行下一步操作。
作为一种可选的实施方式,在执行完步骤37)之后,在执行步骤36)之前,图3描述的方法还包括以下步骤:
38)移动终端输出第二验证指令,第二验证指令用于指示用户输入第二生物特征信息;
39)移动终端判断用户输入的第二生物特征信息是否校验通过,若校验通过,则执行步骤310;否则结束本流程。
310)移动终端利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息。
请参阅图4,图4是本发明实施例公开的另一种防止eSIM文件被篡改的具体原理示意图,以图4所示的原理示意图为例,来说明本发明实施例公开的另一种防止eSIM文件被篡改的方法,移动终端包括普通环境(Non-secure world)和安全环境(Secure world)。
如图4所示,具体实施例的流程步骤与图4标注的步骤一致,具体流程如下:
(1)通过运营商安全工具下载Sec-eSimApp应用和应用安全密钥HMAC_key_A(即第三更新请求),且将其保存为临时文件;
具体地,还可以从运营商安全工具获取网络密钥(即第三验证信息)。
(2)发送网络密钥cipher_key_A和应用安全密钥HMAC_key_A 到Crypto模块中,以进行有效性验证;
(3)若Crypto模块对网络密钥以及应用安全密钥的有效性验证失败,通知Sec-eSimApp应用效验失败,从而删除临时Sec-eSimApp应用和应用安全密钥HMAC_key_A文件,结束更新流程;
(4)若Crypto模块对网络密钥以及应用安全密钥的有效性验证成功,则将下载的临时Sec-eSimApp应用相关的证书信息传递到TZ PIL中,且进行以下流程;
(5)在Fuse模块中进行Sec-eSimApp应用签名信息的验证;
该实施方式中,通过TZ技术和签名熔丝,防止了黑客通过物理连接来更新破解Sec-eSimApp应用。
(6)Fuse模块将验证结果通知安全识别模块;
(7)若签名不匹配,通知Sec-eSimApp应用效验失败,从而删除临时Sec-eSimApp应用和HMAC_key_A文件,结束更新流程;
(8)若签名匹配,安全识别模块通知生物识别APP启动;
(9)生物识别APP通知用户进行生物特征信息的确认;
(10)用户输入生物特征信息确认操作;
(11)生物识别APP把用户输入的生物特征信息传输给生物识别模块;
(12)若生物识别模块验证成功,则进行以下流程;
(13)安全识别模块通知文件服务器FileService安全流程效验全部完成;
(14)FileService把临时Sec-eSimApp应用和HMAC_key_A文件覆盖之前早期文件,以实现Sec-eSimApp应用和应用安全密钥HMAC_key_A的更新;
(15)FileService通知SCM;
(16)SCM通知Monitor;
(17)Monitor通知SCM Driver已完成安全环境下Sec-eSimApp应用的更新;
(18)SCMDriver通知eSimApp应用进行更新;
(19)eSimApp应用连接网络服务器请求更新;
(20)下载最新eSimApp应用,以完成普通环境下eSimApp应用的更新。
可见,实施图3描述的方法,用户在进行eSIM文件、目标应用和新的第二验证信息的更新时,需要进行第一验证信息和第二验证信息的校验,并且均校验成功后,通过生物特征信息的验证,才能进行eSIM文件、目标应用和新的第二验证信息的更新。可见,实施本发明实施例,能够有效防止eSIM文件被恶意篡改,提高移动终端的安全性。
请参阅图5,图5是本发明实施例公开的一种移动终端的结构示意图,可以用于执行本发明实施例公开的防止eSIM文件被篡改的方法。如图5所示,该移动终端包括普通环境和安全环境,其中,安全环境为移动终端运行在安全域TZ环境下的环境,该移动终端可以包括:
第一检测单元501,设置为在所述普通环境下检测网络服务器发送的第一更新请求,所述第一更新请求用于请求更新所述移动终端中的原始嵌入式用户识别模块eSIM文件;
启动单元502,设置为根据第一更新请求,启动安全环境下的目标应用;
上述第一检测单元501,还设置为通过目标应用检测网络服务器发送的第一验证信息和目标eSIM文件,其中,第一验证信息为用于对网络服务器的身份进行验证的信息;
校验单元503,设置为在安全环境下对第一验证信息进行校验;
第一更新单元505,设置为当校验单元503在安全环境下对第一验证信息校验成功时,利用目标eSIM文件更新原始eSIM文件。
请一并参阅图6,图6是本发明实施例公开的另一种移动终端的结构示意图。其中,图6所示的移动终端是在图5所示的移动终端的基础上进一步优化得到的。与图5所示的移动终端相比,图6所示的移动终端中还可以包括:
获取单元505,设置为在校验单元503在安全环境下对第一验证信息校验成功之后,第一更新单元504利用目标eSIM文件更新原始eSIM文件之前,在安全环境下获取第二验证信息,第二验证信息为用于对目标应用的安全性进行验证的信息;
校验单元503,还设置为在安全环境下对第二验证信息进行校验;
第一更新单元504具体设置为当校验单元503对第二验证信息校验成功时,利用目标eSIM文件更新原始eSIM文件。
作为一种可选的实施方式,图6所述的移动终端还可以包括:
第一输出单元506,设置为当校验单元503在安全环境下对第一验证信息校验成功之后,第一更新单元504利用目标eSIM文件更新原始eSIM文件之前,输出第一验证指令,该第一验证指令用于指示用户输入第一生物特征信息;
第一判断单元507,设置为判断用户输入的第一生物特征信息是否校验通过;
相应地,第一更新单元504具体设置为当第一判断单元507判断用户输入的第一生物特征信息校验通过时,利用目标eSIM文件更新原始eSIM文件。
作为一种可选的实施方式,图6所示的移动终端还可以包括:
映射单元508,设置为将安全环境下的目标eSIM文件通过共享缓冲映射至普通环境下。
作为一种可选的实施方式,图6所示的移动终端还可以包括:
第二检测单元509,设置为在所述安全环境下检测第二更新请求,其中,第二更新请求用于请求更新第二验证信息,第二更新请求携带有新的第二验证信息和第三验证信息;
校验单元503,还设置为在安全环境下分别对新的第二验证信息和第三验证信息进行校验;
第二更新单元510,设置为当校验单元503对新的第二验证信息和第三验证信息均校验成功时,利用新的第二验证信息更新第二验证信息。
请一并参阅图7,图7是本发明实施例公开的又一种移动终端的结构示意图。其中,图7所示的移动终端是在图5所示的移动终端的基础上进一步优化得到的。与图5所示的移动终端相比,图7所示的移动终端中还可以包括:
第三检测单元511,设置为在所述安全环境下检测第三更新请求,其中,第三更新请求用于请求更新目标应用和第二验证信息,第三更新请求携带有新的目标应用、新的第二验证信息和第三验证信息;
校验单元503,还设置为在安全环境下分别对新的第二验证信息和第三验证信息进行校验;
第三更新单元512,设置为当校验单元503对新的第二验证信息和第三验证信息均校验成功时,利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息。
作为一种可选的实施方式,校验单元503,还设置为在对新的第二验证信息和第三验证信息均校验成功之后,第三更新单元512利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息之前,对新的目标应用进行签名信息验证;
所述移动终端还包括:
第二判断单元513,设置为判断所述签名信息验证是否通过;
相应地,第三更新单元512具体设置为当第二判断单元513判断签名信息验证通过时,利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息。
作为一种可选的实施方式,图7所示的移动终端还包括:
第二输出单元514,设置为在第二判断单元513判断签名信息验证通过之后,第三更新单元512利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息之前,输出第二验证指令,第二验证指令用于指示用户输入第二生物特征信息;
所述第二判断单元513,还设置为判断用户输入的第二生物特征信息是否校验通过;
相应地,第三更新单元512具体设置为当第二判断单元513判断第二生物特征信息校验通过时,利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息。
可见,实施图5、图6和图7所示的移动终端,用户在进行eSIM文件、目标应用和新的第二验证信息的更新时,需要进行第一验证信息和第二验证信息的校验,并且均校验成功后,通过生物特征信息的验证,才能进行eSIM文件、目标应用和新的第二验证信息的更新。可见,实施本发明实施例,能够有效防止eSIM文件被恶意篡改,提高移动终端的安全性。
请参阅图8,图8是本发明实施例公开的又一种移动终端的结构示意图,可以用于执行本发明实施例公开的防止eSIM文件被篡改的方法。如图8所示,该移动终端800可以包括:至少一个处理器801,至少一个输入装置802,至少一个输出装置803,存储器804等组件。其中,这些组件可以通过一条或多条总线805进行通信连接。本领域技术人员可以理解,图8中示出的移动终端的结构并不构成对本发明实施例的限定,它既可以是总线形结构,也可以是星型结构,还可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。其中:
处理器801为移动终端的控制中心,利用各种接口和线路连接整个移动终端的各个部分,通过运行或执行存储在存储器804内的程序和/或模块,以及调用存储在存储器804内的数据,以执行移动终端的各种功能和处理数据。处理器801可以由集成电路(Integrated Circuit,简称IC)组成,例如可以由单颗封装的IC所组成,也可以由连接多颗相同功能或不同功能的封装IC而组成。举例来说,处理器801可以仅包括中央处理器(Central Processing Unit,简称CPU),也可以是CPU、数字信号处理器(Digital Signal Processor,简称DSP)、图形处理器(Graphic Processing Unit,简称GPU)及各种控制芯片的组合。在本发明实施方式中,CPU可以是单运算核心,也可以包括多运算核心。
输入装置802可以包括标准的触摸屏、键盘等,也可以包括有线接口、无线接口等,可以用于与网络服务器进行交互。
输出装置803可以包括显示屏、扬声器等,也可以包括有线接口、无线接口等。
存储器804可用于存储软件程序以及模块,处理器801、输入装置802以及输出装置803通过调用存储在存储器804中的软件程序以及模块,从而执行移动终端的各项功能应用以及实现数据处理。存储器804主要包括程序存储区和数据存储区,其中,程序存储区可存储操作系统、至少一个功能所需的应用程序等;数据存储区可存储根据移动终端的使用所创建的数据等。在本发明实施例中,操作系统可以是Android系统、iOS系统或Windows操作系统等等。
在图8所示的移动终端中,包括普通环境和安全环境,其中,安全环境为所述移动终端运行在安全域TZ环境下的环境,处理器801调用存储在存储器804中的应用程序,用于执行以下操作:
在普通环境下检测网络服务器发送的第一更新请求,第一更新请求用于请求更新移动终端中的原始嵌入式用户识别模块eSIM文件;
根据第一更新请求,启动安全环境下的目标应用;
通过目标应用检测网络服务器发送的第一验证信息和目标eSIM文件,其中,第一验证信息为用于对网络服务器的身份进行验证的信息;
在安全环境下对第一验证信息进行校验;
当在安全环境下对第一验证信息校验成功时,利用目标eSIM文件更新原始eSIM文件。
一个实施例中,处理器801在安全环境下对第一验证信息校验成功之后,以及利用目标eSIM文件更新原始eSIM文件之前,处理器801还可以调用存储在存储器804中的应用程序,并执行以下操作:
在安全环境下获取第二验证信息,该第二验证信息为用于对目标应用的安全性进行验证的信息;
在安全环境下对第二验证信息进行校验;
其中,处理器801利用目标eSIM文件更新原始eSIM文件的具体实施方式可以为:
当在安全环境下对第二验证信息校验成功时,利用目标eSIM文件更新原始eSIM文件。
一个实施例中,处理器801在安全环境下对第一验证信息校验成功之后,以及利用目标eSIM文件更新原始eSIM文件之前,处理器801还可以调用存储在存储器804中的应用程序,并执行以下操作:
触发输出装置803输出第一验证指令,该第一验证指令用于指示用户通过输入装置802输入第一生物特征信息;
判断用户输入的第一生物特征信息是否校验通过;
其中,处理器801利用目标eSIM文件更新原始eSIM文件的具体实施方式可以为:
当判断用户输入的第一生物特征信息校验通过时,利用目标eSIM文件更新原始eSIM文件。
一个实施例中,处理器801还可以调用存储在存储器804中的应用程序,并执行以下操作:
将安全环境下的目标eSIM文件通过共享缓冲器映射至普通环境下。
一个实施例中,处理器801还可以调用存储在存储器804中的应用程序,并执行以下操作:
在安全环境下检测第二更新请求,其中,该第二更新请求用于请求更新第二验证信息,且第二更新请求携带有新的第二验证信息和第三验证信息;
在安全环境下分别对新的第二验证信息和第三验证信息进行校验;
当对新的第二验证信息和第三验证信息均校验成功时,利用新的第二验证信息更新第二验证信息。
一个实施例中,处理器801还可以调用存储在存储器804中的应用程序,并执行以下操作:
在安全环境下检测第三更新请求,其中,第三更新请求用于请求更新目标应用和第二验证信息,第三更新请求携带有新的目标应用、新的第二验证信息和第三验证信息;
在安全环境下分别对新的第二验证信息和第三验证信息进行校验;
当对新的第二验证信息和第三验证信息均校验成功时,利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息。
一个实施例中,处理器801对新的第二验证信息和第三验证信息均校验成功之后,利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息之前,处理器801还可以调用存储在存储器804中的应用程序,并执行以下操作:
对新的目标应用进行签名信息验证;
判断签名信息验证是否通过;
其中,处理器801利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息的具体实施方式可以为:
若判断签名信息验证是否通过,则利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息。
一个实施例中,处理器判断签名信息通过之后,利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息之前,处理器801还可以调用存储在存储器804中的应用程序,并执行以下操作:
触发输出装置803输出第二验证指令,该第二验证指令用于指示用户通过输入装置802输入第二生物特征信息;
判断用户输入的第二生物特征信息是否校验通过;
其中,处理器801利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息的具体实施方式可以为:
若判断用户输入的第二生物特征信息校验通过,则利用新的目标应用更新目标应用,以及利用新的第二验证信息更新第二验证信息。
可见,实施图8所示的移动终端,用户在进行eSIM文件、目标应用和新的第二验证信息的更新时,需要进行第一验证信息和第二验证信息的校验,并且均校验成功后,通过生物特征信息的验证,才能进行eSIM文件、目标应用和新的第二验证信息的更新。可见,实施本发明实施例,能够有效防止eSIM文件被恶意篡改,提高移动终端的安全性。
本发明所有实施例中的模块或单元,可以通过通用集成电路,例如CPU,或通过ASIC (Application Specific Integrated Circuit,专用集成电路)来实现。
需要说明的是,对于前述的各个方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本发明并不受所描述的动作顺序的限制,因为依据本发明,某一些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作和模块并不一定是本发明所必须的。
本发明实施例方法中的步骤可以根据实际需要进行顺序调整、合并和删减。
本发明实施例移动终端中的单元可以根据实际需要进行合并、划分和删减。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机程序来指令相关的硬件来完成,所述的程序可存储于一计算机可读取存储介质中,该程序在执行时,可包括如上述各方法的实施例的流程。其中,所述的存储介质可为磁碟、光盘、只读存储记忆体(Read-Only Memory,ROM)或随机存取存储器(Random Access Memory,简称RAM)等。
以上对本发明实施例公开的一种防止eSIM文件被篡改的方法及移动终端进行了详细介绍,本文中应用了具体个例对本发明的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本发明的方法及其核心思想;同时,对于本领域的一般技术人员,依据本发明的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本发明的限制。

Claims (16)

  1. 一种防止eSIM文件被篡改的方法,其特征在于,移动终端包括普通环境和安全环境,其中,所述安全环境为所述移动终端运行在安全域TZ下的环境,所述方法包括:
    所述移动终端在所述普通环境下检测网络服务器发送的第一更新请求,所述第一更新请求用于请求更新所述移动终端中的原始嵌入式用户识别模块eSIM文件;
    所述移动终端根据所述第一更新请求,启动所述安全环境下的目标应用;
    所述移动终端通过所述目标应用检测所述网络服务器发送的第一验证信息和目标eSIM文件,其中,所述第一验证信息为用于对所述网络服务器的身份进行验证的信息;
    所述移动终端在所述安全环境下对所述第一验证信息进行校验;
    当所述移动终端在所述安全环境下对所述第一验证信息校验成功时,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件。
  2. 根据权利要求1所述的方法,其特征在于,所述移动终端在所述安全环境下对所述第一验证信息校验成功之后,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件之前,所述方法还包括:
    所述移动终端在所述安全环境下获取第二验证信息,所述第二验证信息为用于对所述目标应用的安全性进行验证的信息;
    所述移动终端在所述安全环境下对所述第二验证信息进行校验;
    其中,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件,包括:
    若所述移动终端对所述第二验证信息校验成功,则所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件。
  3. 根据权利要求1所述的方法,其特征在于,所述移动终端在所述安全环境下对所述第一验证信息校验成功之后,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件之前,所述方法还包括:
    所述移动终端输出第一验证指令,所述第一验证指令用于指示用户输入第一生物特征信息;
    所述移动终端判断用户输入的第一生物特征信息是否校验通过;
    其中,所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件,包括:
    若所述移动终端判断用户输入的所述第一生物特征信息校验通过,则所述移动终端利用所述目标eSIM文件更新所述原始eSIM文件。
  4. 根据权利要求1~3任一项所述的方法,其特征在于,所述方法还包括:
    所述移动终端将所述安全环境下的所述目标eSIM文件通过共享缓冲器映射至所述普通环境下,以更新所述普通环境下的eSIM文件。
  5. 根据权利要求2所述的方法,其特征在于,所述方法还包括:
    所述移动终端在所述安全环境下检测第二更新请求,其中,所述第二更新请求用于请求更新所述第二验证信息,所述第二更新请求携带有新的第二验证信息和第三验证信息;
    所述移动终端在所述安全环境下分别对所述新的第二验证信息和所述第三验证信息进行校验;
    当所述移动终端对所述新的第二验证信息和所述第三验证信息均校验成功时,所述移动终端利用所述新的第二验证信息更新所述第二验证信息。
  6. 根据权利要求2所述的方法,其特征在于,所述方法还包括:
    所述移动终端在所述安全环境下检测第三更新请求,其中,所述第三更新请求用于请求更新所述目标应用和所述第二验证信息,所述第三更新请求携带有新的目标应用、新的第二验证信息和第三验证信息;
    所述移动终端在所述安全环境下分别对所述新的第二验证信息和所述第三验证信息进行校验;
    当所述移动终端对所述新的第二验证信息和所述第三验证信息均校验成功时,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
  7. 根据权利要求6所述的方法,其特征在于,所述移动终端对所述新的第二验证信息和所述第三验证信息均校验成功之后,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息之前,所述方法还包括:
    所述移动终端对所述新的目标应用进行签名信息验证;
    所述移动终端判断所述签名信息验证是否通过;
    其中,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息,包括:
    若所述移动终端判断所述签名信息验证通过,则所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
  8. 根据权利要求7所述的方法,其特征在于,所述移动终端判断所述签名信息验证通过之后,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息之前,所述方法还包括:
    所述移动终端输出第二验证指令,所述第二验证指令用于指示用户输入第二生物特征信息;
    所述移动终端判断用户输入的第二生物特征信息是否校验通过;
    其中,所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息,包括:
    若所述移动终端判断所述第二生物特征信息校验通过,则所述移动终端利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
  9. 一种移动终端,其特征在于,所述移动终端包括普通环境和安全环境,其中,所述安全环境为所述移动终端运行在安全域TZ下的环境,所述移动终端包括:
    第一检测单元,设置为在所述普通环境下检测网络服务器发送的第一更新请求,所述第一更新请求用于请求更新所述移动终端中的原始嵌入式用户识别模块eSIM文件;
    启动单元,设置为根据所述第一更新请求,启动所述安全环境下的目标应用;
    所述第一检测单元,还设置为通过所述目标应用检测所述网络服务器发送的第一验证信息和目标eSIM文件,其中,所述第一验证信息为用于对所述网络服务器的身份进行验证的信息;
    校验单元,设置为在所述安全环境下对所述第一验证信息进行校验;
    第一更新单元,设置为当所述校验单元在所述安全环境下对所述第一验证信息校验成功时,利用所述目标eSIM文件更新所述原始eSIM文件。
  10. 根据权利要求9所述的移动终端,其特征在于,所述移动终端还包括:
    获取单元,设置为在所述校验单元在所述安全环境下对所述第一验证信息校验成功之后,所述第一更新单元利用所述目标eSIM文件更新所述原始eSIM文件之前,在所述安全环境下获取第二验证信息,所述第二验证信息为用于对所述目标应用的安全性进行验证的信息;
    所述校验单元,还设置为在所述安全环境下对所述第二验证信息进行校验;
    所述第一更新单元具体设置为当所述校验单元对所述第二验证信息校验成功时,利用所述目标eSIM文件更新所述原始eSIM文件。
  11. 根据权利要求9所述的移动终端,其特征在于,所述移动终端还包括:
    第一输出单元,设置为当所述校验单元在所述安全环境下对所述第一验证信息校验成功之后,所述第一更新单元利用所述目标eSIM文件更新所述原始eSIM文件之前,输出第一验证指令,所述第一验证指令用于指示用户输入第一生物特征信息;
    第一判断单元,设置为判断用户输入的第一生物特征信息是否校验通过;
    所述第一更新单元具体设置为当所述第一判断单元判断用户输入的所述第一生物特征信息校验通过时,利用所述目标eSIM文件更新所述原始eSIM文件。
  12. 根据权利要求9~11任一项所述的移动终端,其特征在于,所述移动终端还包括:
    映射单元,设置为将所述安全环境下的所述目标eSIM文件通过共享缓冲器映射至所述普通环境下,以更新所述普通环境下的eSIM文件。
  13. 根据权利要求10所述的移动终端,其特征在于,所述移动终端还包括:
    第二检测单元,设置为在所述安全环境下检测第二更新请求,其中,所述第二更新请求用于请求更新所述第二验证信息,所述第二更新请求携带有新的第二验证信息和第三验证信息;
    所述校验单元,还设置为在所述安全环境下分别对所述新的第二验证信息和所述第三验证信息进行校验;
    第二更新单元,设置为当所述校验单元对所述新的第二验证信息和所述第三验证信息均校验成功时,利用所述新的第二验证信息更新所述第二验证信息。
  14. 根据权利要求10所述的移动终端,其特征在于,所述移动终端还包括:
    第三检测单元,设置为在所述安全环境下检测第三更新请求,其中,所述第三更新请求用于请求更新所述目标应用和所述第二验证信息,所述第三更新请求携带有新的目标应用、新的第二验证信息和第三验证信息;
    所述校验单元,还设置为在所述安全环境下分别对所述新的第二验证信息和所述第三验证信息进行校验;
    第三更新单元,设置为当所述校验单元对所述新的第二验证信息和所述第三验证信息均校验成功时,利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
  15. 根据权利要求14所述的移动终端,其特征在于,
    所述校验单元,还设置为在对所述新的第二验证信息和所述第三验证信息均校验成功之后,所述第三更新单元利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息之前,对所述新的目标应用进行签名信息验证;
    所述移动终端还包括:
    第二判断单元,设置为判断所述签名信息验证是否通过;
    所述第三更新单元具体设置为当所述第二判断单元判断所述签名信息验证通过时,利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
  16. 根据权利要求15所述的移动终端,其特征在于,所述移动终端还包括:
    第二输出单元,设置为在所述第二判断单元判断所述签名信息验证通过之后,所述第三更新单元利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息之前,输出第二验证指令,所述第二验证指令用于指示用户输入第二生物特征信息;
    所述第二判断单元,还设置为判断用户输入的第二生物特征信息是否校验通过;
    所述第三更新单元具体设置为当所述第二判断单元判断所述第二生物特征信息校验通过时,利用所述新的目标应用更新所述目标应用,以及利用所述新的第二验证信息更新所述第二验证信息。
PCT/CN2016/103877 2016-09-29 2016-10-29 一种防止eSIM文件被篡改的方法及移动终端 Ceased WO2018058725A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610866774.1 2016-09-29
CN201610866774.1A CN106446719B (zh) 2016-09-29 2016-09-29 一种防止eSIM文件被篡改的方法及移动终端

Publications (1)

Publication Number Publication Date
WO2018058725A1 true WO2018058725A1 (zh) 2018-04-05

Family

ID=58171340

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/103877 Ceased WO2018058725A1 (zh) 2016-09-29 2016-10-29 一种防止eSIM文件被篡改的方法及移动终端

Country Status (2)

Country Link
CN (1) CN106446719B (zh)
WO (1) WO2018058725A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9949113B1 (en) * 2017-06-02 2018-04-17 Apple Inc. Updating profiles for secondary wireless devices
CN108684036B (zh) * 2018-04-28 2021-11-23 南京润阳淀粉制品有限责任公司 电子终端及其基于可信执行环境的eSIM数据处理方法

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105100098A (zh) * 2015-07-27 2015-11-25 中国联合网络通信集团有限公司 一种机卡交互安全授权方法及装置

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1536606A1 (fr) * 2003-11-27 2005-06-01 Nagracard S.A. Méthode d'authentification d'applications
CN102056077B (zh) * 2009-10-29 2013-11-06 中国移动通信集团公司 一种通过密钥进行智能卡应用的方法和装置
KR101651808B1 (ko) * 2012-02-07 2016-08-26 애플 인크. 네트워크 보조형 사기 검출 장치 및 방법
CN103813303B (zh) * 2012-11-12 2018-02-23 中国移动通信集团公司 一种eSIM卡更新签约关系的方法、系统及相应设备
US9510186B2 (en) * 2014-04-04 2016-11-29 Apple Inc. Tamper prevention for electronic subscriber identity module (eSIM) type parameters
US9524158B2 (en) * 2015-02-23 2016-12-20 Apple Inc. Managing firmware updates for integrated components within mobile devices
CN105243311B (zh) * 2015-10-19 2017-02-22 广东欧珀移动通信有限公司 一种指纹信息的安全调用方法、装置及移动终端

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105100098A (zh) * 2015-07-27 2015-11-25 中国联合网络通信集团有限公司 一种机卡交互安全授权方法及装置

Also Published As

Publication number Publication date
CN106446719B (zh) 2020-09-11
CN106446719A (zh) 2017-02-22

Similar Documents

Publication Publication Date Title
WO2021025482A1 (en) Electronic device and method for generating attestation certificate based on fused key
WO2019231252A1 (en) Electronic device for authenticating user and operating method thereof
WO2021107506A1 (en) Electronic device for providing augmented reality service and operating method thereof
WO2011079753A1 (zh) 认证方法、认证交易系统和认证装置
WO2021060857A1 (ko) 원격 실행 코드 기반 노드의 제어 플로우 관리 시스템 및 그에 관한 방법
WO2015163736A1 (en) Methods of providing social network service and server performing the same
WO2010124565A1 (zh) 签名方法、设备及系统
WO2018082482A1 (zh) 一种网络共享方法、接入网络方法及系统
WO2017054481A1 (zh) 一种信息验证和处理方法、装置、以及信息处理系统
WO2016126052A2 (ko) 인증 방법 및 시스템
WO2020105892A1 (ko) 디바이스가 디지털 키를 공유하는 방법
WO2019132555A1 (ko) 이모지가 포함된 메시지를 송수신하는 전자 장치 및 그 전자 장치를 제어하는 방법
WO2019164281A1 (en) Electronic device and control method thereof
WO2019124826A1 (ko) 펌웨어를 업데이트하는 인터페이스 장치, 모바일 장치 및 펌웨어 업데이트 방법
WO2015194836A1 (ko) 키 공유 방법 및 장치
WO2019107946A1 (en) Electronic device and method for processing remote payment
WO2019035491A1 (ko) 사용자 인증방법 및 장치
WO2020149500A1 (ko) 공유된 키를 등록하기 위한 방법 및 장치
WO2017188497A1 (ko) 무결성 및 보안성이 강화된 사용자 인증방법
WO2019000466A1 (zh) 人脸识别方法、装置、存储介质及电子设备
WO2021015568A1 (en) Electronic device and method for protecting personal information using secure switch
WO2017092498A1 (zh) 一种信息管理方法及用户终端
WO2020141773A1 (ko) 출입 관리 시스템 및 이를 이용한 출입 관리 방법
WO2019194428A1 (ko) 외부 전자 장치의 키를 공유하는 전자 장치 및 전자 장치의 동작 방법
WO2022196932A1 (ko) 생체 데이터를 암호화하는 전자 장치 및 전자 장치의 동작 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16917472

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16917472

Country of ref document: EP

Kind code of ref document: A1