WO2019206201A1 - 一种配置文件传输方法及相关设备和存储介质 - Google Patents

一种配置文件传输方法及相关设备和存储介质 Download PDF

Info

Publication number
WO2019206201A1
WO2019206201A1 PCT/CN2019/084161 CN2019084161W WO2019206201A1 WO 2019206201 A1 WO2019206201 A1 WO 2019206201A1 CN 2019084161 W CN2019084161 W CN 2019084161W WO 2019206201 A1 WO2019206201 A1 WO 2019206201A1
Authority
WO
WIPO (PCT)
Prior art keywords
server
identifier
terminal
configuration file
file
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2019/084161
Other languages
English (en)
French (fr)
Inventor
于小博
龙水平
范姝男
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to EP19792124.0A priority Critical patent/EP3761606B1/en
Priority to US16/982,998 priority patent/US11669342B2/en
Priority to KR1020207029514A priority patent/KR102334501B1/ko
Priority to JP2020559510A priority patent/JP7055901B2/ja
Publication of WO2019206201A1 publication Critical patent/WO2019206201A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/06Protocols specially adapted for file transfer, e.g. file transfer protocol [FTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/35Protecting application or service provisioning, e.g. securing SIM application provisioning
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/445Program loading or initiating
    • G06F9/44505Configuring for program initiating, e.g. using registry, configuration files
    • G06F9/4451User profiles; Roaming
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/2866Architectures; Arrangements
    • H04L67/30Profiles
    • H04L67/303Terminal profiles
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/34Network arrangements or protocols for supporting network services or applications involving the movement of software or configuration parameters 
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present application relates to the field of terminals, and in particular, to a configuration file transmission method, related devices, and storage media.
  • SIM subscriber identification module
  • the embedded universal integrated circuit card (eUICC) has become more and more popular as a new generation of SIM cards.
  • the eUICC allows users to be free from the services of an operator.
  • the profile for connecting to the operator is downloaded without replacing the SIM card, and the operator server determines the configuration file corresponding to the eUICC according to the eUICC identity information (EID, eUICC identification).
  • EID eUICC identity information
  • the configuration files running on different OSs are different, and the configuration file determined by the carrier server according to the EID may not be currently running by the terminal.
  • the configuration file matched by the OS affects the accuracy of the terminal downloading the configuration file.
  • the embodiment of the present application provides a configuration file transmission method, a related device, and a storage medium, which ensure that the terminal can download the configuration file to the corresponding OS, thereby improving the accuracy of downloading the configuration file by the terminal.
  • a first aspect of the present application provides a method for transmitting profile information, the method includes: when a terminal runs on a first operating system OS, the terminal acquires a second OS identifier, and the second OS identifier and the second configuration File matching; the terminal switches to the second OS according to the second OS identifier; the terminal sends a target message to the server, the target message is used to request the second configuration file; The server acquires the second configuration file.
  • the OS provided by each operator server is configured with a corresponding OS identifier, and the terminal determines that the corresponding OS is running according to the obtained OS identifier, and then downloads the configuration file from the carrier server, thereby ensuring that the terminal can Downloading the configuration file to the corresponding OS improves the accuracy of the terminal downloading the configuration file.
  • the method for the terminal to obtain the second OS identifier may be: the terminal acquires an activation code, where the activation code is generated by the server according to the second OS identifier, and the terminal extracts the activation code from the The second OS identifier is described.
  • the solution provides a specific implementation manner for the terminal to obtain the second OS identifier, which improves the achievability of the solution.
  • the method for the terminal to obtain the second OS identifier may be: the terminal sends an OS identifier list and a matching identifier to the server, where the matching identifier has a unique correspondence relationship with the second configuration file, where the terminal Receiving, by the server, a second OS identifier, where the second OS identifier is determined by the server according to the matching identifier from the OS identifier list.
  • the solution provides another implementation manner for the terminal to obtain the second OS identifier, which improves the flexibility of the solution.
  • the terminal sends the second OS identifier to the server, where the server stores a remote configuration file management RPM corresponding to the second OS identifier.
  • the terminal acquires the RPM information from the server, and the RPM information is used to manage the second configuration file.
  • the RPM information determined by the server is implemented based on the currently running OS of the terminal, which improves the accuracy and security of the RPM.
  • the second aspect of the present application provides a method for transmitting profile information, the method includes: the server receives a target message sent by the terminal, where the target message is that the terminal switches to the first according to the second OS identifier. After the second OS is generated, the second OS identifier is acquired when the terminal runs on the first OS, and the second OS identifier matches the second configuration file, and the server determines the second according to the target message. a configuration file, the server sending the second configuration file to the terminal.
  • the OS provided by each operator server is configured with a corresponding OS identifier, and the terminal determines that the corresponding OS is running according to the obtained OS identifier, and then downloads the configuration file from the carrier server, thereby ensuring that the terminal can Downloading the configuration file to the corresponding OS improves the accuracy of the terminal downloading the configuration file.
  • the server before the server receives the target message sent by the terminal, the server generates an activation code according to the second OS identifier.
  • the server receives the OS identifier list and the matching identifier sent by the terminal, where the matching identifier has a unique correspondence relationship with the second configuration file, and the server is configured according to the server.
  • the matching identifier determines the second OS identifier from the OS identifier list, and sends the second OS identifier to the terminal.
  • the server receives the second OS identifier sent by the terminal, where the server stores a second OS identifier corresponding to the second OS identifier.
  • the server sends the RPM information to the terminal, and the RPM information is used to manage the second configuration file.
  • a third aspect of the present application provides a method for packet file Bundle transmission, the method comprising: a terminal sending a first message to a server, where the first message is used to request a package file from the server, where the package file includes an operating system The OS file and the profile profile, the terminal receives the package file identifier sent by the server, and when the package file identifier matches the rule authorization table RAT preset on the terminal, the terminal acquires the location from the server.
  • the OS file and the configuration file is a method for packet file Bundle transmission, the method comprising: a terminal sending a first message to a server, where the first message is used to request a package file from the server, where the package file includes an operating system The OS file and the profile profile, the terminal receives the package file identifier sent by the server, and when the package file identifier matches the rule authorization table RAT preset on the terminal, the terminal acquires the location from the server.
  • the OS file and the configuration file is a packet file Bundle transmission.
  • the terminal can download the package file including the OS file and the configuration file from the server at one time, and the OS file matches the configuration file, which improves the efficiency of the terminal downloading and installing the OS and the configuration file.
  • the terminal before the terminal receives the package file identifier sent by the server, the terminal sends a package file identifier list to the server, where the package file identifier is determined by the server according to the package file identifier list.
  • the method for the terminal to obtain the OS file and the configuration file from the server may be: the terminal downloads the OS file from the server to the first security domain, where the first security domain is configured by the server.
  • the terminal downloads the configuration file from the server to a second security domain, and the second security domain is configured by the server.
  • the fourth aspect of the present application provides a method for packet file Bundle transmission, the method comprising: receiving, by a server, a first message sent by a terminal, where the first message is used to request a package file from the server, where the package file includes an operation. a system OS file and a profile profile, the server sending a package file identifier to the terminal, and when the package file identifier matches a rule authorization table RAT preset on the terminal, the server sends the file to the terminal The OS file and the configuration file.
  • the terminal can download the package file including the OS file and the configuration file from the server at one time, and the OS file matches the configuration file, which improves the efficiency of the terminal downloading and installing the OS and the configuration file.
  • the server before the server sends the package file identifier to the terminal, the server receives a package file identifier list sent by the terminal, and the server determines the package file identifier according to the package file identifier list.
  • the method for the server to send the OS file and the configuration file to the terminal may be: the server configures a first security domain and a second security domain, and the server sends the OS file to The first security domain and sending the configuration file to the second security domain.
  • a fifth aspect of the present application provides a method for updating an issuer security domain root ISD-R, the method comprising: when the embedded universal integrated circuit card eUICC runs on a first operating system OS, the eUICC sends the The first issuer security domain of the OS corresponds to the first version information of the root ISD-R to the primary platform PP, and when the eUICC runs on the second operating system OS, the eUICC receives the first a version information, if the first version information does not match the second version information of the second ISD-R corresponding to the second OS, the eUICC acquires the data information corresponding to the second version information, The data information is used to update the second ISD-R.
  • the ISD-R version information on the main platform is updated, the ISD-R version information is notified to other OSs installed on the eUICC, so that other OSs that do not update the ISD-R version information can be based on the latest ISD.
  • the -R version information obtains the latest ISD-R data packets from the update server to achieve ISD-R compatibility between different OSs and the main platform.
  • a sixth aspect of the present application provides a method for transmitting profile information, the method includes: when a terminal runs on a first operating system OS, the terminal acquires a second OS identifier, and the second OS identifier and the second configuration File matching, the terminal acquires a key from a second OS, the second OS is determined by the terminal according to the second OS identifier, and the terminal sends the key to the server, when the server determines When the key verification is successful, the terminal acquires a second configuration file from the server.
  • a seventh aspect of the present application provides a method for transmitting profile information, the method comprising: receiving, by a server, a key sent by a terminal, the key being acquired by the terminal from a second OS, where the second OS is The terminal determines, according to the second OS identifier, that the second OS identifier is acquired when the terminal runs on the first OS, and the second OS identifier matches the second configuration file, when the server is configured to the secret When the key verification is successful, the server sends the second configuration file to the terminal.
  • the terminal downloads the configuration file corresponding to the second OS, the terminal does not have to switch to the system environment of the second OS first, and the configuration file corresponding to the second OS is directly downloaded based on the first OS.
  • the flexibility of this program if the terminal downloads the configuration file corresponding to the second OS, the terminal does not have to switch to the system environment of the second OS first, and the configuration file corresponding to the second OS is directly downloaded based on the first OS.
  • the eighth aspect of the present application provides a terminal, which specifically implements a function corresponding to the profile file transmission method provided by the foregoing first aspect.
  • the functions may be implemented by hardware or by executing corresponding software programs through hardware.
  • the hardware and software include one or more unit modules corresponding to the functions described above, which may be software and/or hardware.
  • the terminal includes: a first acquiring unit, configured to acquire a second OS identifier when the terminal runs on the first operating system OS, where the second OS identifier matches the second configuration file; a unit, configured to switch to the second OS according to the second OS identifier, a sending unit, configured to send a target message to the server, the target message is used to request the second configuration file, and a second acquiring unit And for acquiring the second configuration file from the server.
  • the first obtaining unit includes: an obtaining module, configured to acquire an activation code, where the activation code is generated by the server according to the second OS identifier; and an extraction module, configured to extract, from the activation code The second OS identifier.
  • the first obtaining unit includes: a sending module, configured to send, to the server, an OS identifier list and a matching identifier, where the matching identifier has a unique correspondence relationship with the second configuration file; Receiving a second OS identifier sent by the server, where the second OS identifier is determined by the server from the OS identifier list according to the matching identifier.
  • the sending unit is further configured to send the second OS identifier to the server, where the second acquiring unit is further configured to: when the server stores a remote corresponding to the second OS identifier When the configuration file manages the RPM information, the RPM information is obtained from the server, and the RPM information is used to manage the second configuration file.
  • the terminal includes: a memory, one or more processors, and one or more programs; wherein the one or more programs are stored in the memory;
  • the processor executes the one or more programs for performing all or part of the steps performed by the terminal in the method of the first aspect.
  • a ninth aspect of the present application provides a server, which specifically implements a function corresponding to the profile transmission method provided by the foregoing second aspect.
  • the functions may be implemented by hardware or by executing corresponding software programs through hardware.
  • the hardware and software include one or more unit modules corresponding to the functions described above, which may be software and/or hardware.
  • the server includes: a receiving unit, configured to receive a target message sent by the terminal, where the target message is generated after the terminal switches to the second OS according to the second OS identifier.
  • the second OS identifier is obtained when the terminal is running on the first OS, and the second OS identifier is matched with the second configuration file, and the determining unit is configured to determine the second configuration file according to the target message.
  • a sending unit configured to send the second configuration file to the terminal.
  • the server further includes: a generating unit, configured to generate an activation code according to the second OS identifier.
  • the receiving unit is further configured to receive the OS identifier list and the matching identifier sent by the terminal, where the matching identifier has a unique correspondence relationship with the second configuration file
  • the determining unit is further configured to: Determining, according to the matching identifier, the second OS identifier from the OS identifier list; the sending unit is further configured to send the second OS identifier to the terminal.
  • the receiving unit is further configured to receive the second OS identifier sent by the terminal, where the sending unit is further configured to: when the server stores a remote configuration corresponding to the second OS identifier When the file manages the RPM information, the RPM information is sent to the terminal, and the RPM information is used to manage the second configuration file.
  • the server includes: a memory, one or more processors, and one or more programs; wherein the one or more programs are stored in the memory;
  • the processor executes the one or more programs for performing all or part of the steps performed by a server in the method of the second aspect.
  • a tenth aspect of the present application provides a terminal, which specifically implements a function corresponding to the packet file Bundle transmission method provided by the foregoing third aspect.
  • the functions may be implemented by hardware or by executing corresponding software programs through hardware.
  • the hardware and software include one or more unit modules corresponding to the functions described above, which may be software and/or hardware.
  • the terminal includes: a sending unit, configured to send a first message to the server, where the first message is used to request a package file from the server, where the package file includes an operating system OS file and a configuration a receiving unit, configured to receive a package file identifier sent by the server, and an acquiring unit, configured to acquire, from the server, when the package file identifier matches a rule authorization table RAT preset on the terminal The OS file and the configuration file.
  • the sending unit is further configured to send, to the server, a package file identifier list, where the package file identifier is determined by the server according to the package file identifier list.
  • the obtaining unit includes: a first downloading module, configured to download the OS file from the server to a first security domain, where the first security domain is configured by the server; and a second downloading module, And for downloading the configuration file from the server to a second security domain, where the second security domain is configured by the server.
  • the server includes: a memory, one or more processors, and one or more programs; wherein the one or more programs are stored in the memory;
  • the processor executes the one or more programs for performing all or part of the steps performed by the terminal in the method of the third aspect.
  • An eleventh aspect of the present application provides a server, which specifically implements a function corresponding to the packaged file Bundle transmission method provided by the foregoing fourth aspect.
  • the functions may be implemented by hardware or by executing corresponding software programs through hardware.
  • the hardware and software include one or more unit modules corresponding to the functions described above, which may be software and/or hardware.
  • the server includes: a receiving unit, configured to receive a first message sent by the terminal, where the first message is used to request a package file from the server, where the package file includes an operating system OS file and a configuration file, a first sending unit, configured to send a package file identifier to the terminal, and a second sending unit, configured to: when the package file identifier matches a rule authorization table RAT preset on the terminal, The terminal transmits the OS file and the configuration file.
  • a receiving unit configured to receive a first message sent by the terminal, where the first message is used to request a package file from the server, where the package file includes an operating system OS file and a configuration file
  • a first sending unit configured to send a package file identifier to the terminal
  • a second sending unit configured to: when the package file identifier matches a rule authorization table RAT preset on the terminal, The terminal transmits the OS file and the configuration file.
  • the receiving unit is further configured to receive a package file identifier list sent by the terminal; the server further includes: a determining unit, configured to determine the package file identifier according to the package file identifier list.
  • the second sending unit includes: a configuration module, configured to configure a first security domain and a second security domain; and a sending module, configured to send the OS file to the first security domain, and The configuration file is sent to the second security domain.
  • the server includes: a memory, one or more processors, and one or more programs; wherein the one or more programs are stored in the memory;
  • the processor executes the one or more programs for performing all or part of the steps performed by a server in the method of the fourth aspect.
  • the twelfth aspect of the present application provides an eUICC, which specifically implements the function corresponding to the update method of the ISD-R provided by the fifth aspect.
  • the functions may be implemented by hardware or by executing corresponding software programs through hardware.
  • the hardware and software include one or more unit modules corresponding to the functions described above, which may be software and/or hardware.
  • the eUICC includes: a sending unit, configured to send, when the eUICC runs on the first operating system OS, a first issuer security domain-root ISD-R corresponding to the first OS
  • the first version information is sent to the main platform PP
  • the receiving unit is configured to receive the first version information sent by the PP when the eUICC runs on the second operating system OS
  • the acquiring unit is configured to: If the version information does not match the second version information of the second ISD-R corresponding to the second OS, acquiring data information corresponding to the second version information, where the data information is used to update the second ISD-R.
  • the eUICC includes: a memory, one or more processors, and one or more programs; wherein the one or more programs are stored in the memory; The processor executes the one or more programs for performing all or part of the steps of eUICC execution in the method of the fifth aspect.
  • a thirteenth aspect of the present application provides a terminal, which specifically implements a function corresponding to the profile transmission method provided by the sixth aspect.
  • the functions may be implemented by hardware or by executing corresponding software programs through hardware.
  • the hardware and software include one or more unit modules corresponding to the functions described above, which may be software and/or hardware.
  • the terminal includes: a first acquiring unit, configured to acquire a second OS identifier when the terminal runs on the first operating system OS, where the second OS identifier matches the second configuration file; a second obtaining unit, configured to acquire a key from the second OS, where the second OS is determined by the terminal according to the second OS identifier, a sending unit, configured to send the key to the server, and a third acquiring And a unit, configured to acquire a second configuration file from the server when the server determines that the key verification is successful.
  • the terminal includes: a memory, one or more processors, and one or more programs; wherein the one or more programs are stored in the memory;
  • the processor executes the one or more programs for performing all or part of the steps performed by the terminal in the method of the sixth aspect.
  • a fourteenth aspect of the present application provides a terminal server, which specifically implements a function corresponding to the configuration file profile transmission method provided by the foregoing seventh aspect.
  • the functions may be implemented by hardware or by executing corresponding software programs through hardware.
  • the hardware and software include one or more unit modules corresponding to the functions described above, which may be software and/or hardware.
  • the server includes: a receiving unit, configured to receive a key sent by the terminal, where the key is acquired by the terminal from a second OS, and the second OS is used by the terminal according to the The second OS identifier determines that the second OS identifier is acquired when the terminal runs on the first OS, and the second OS identifier matches the second configuration file, and the sending unit is configured to: when the server pairs the When the key verification is successful, the server sends the second configuration file to the terminal.
  • the server includes: a memory, one or more processors, and one or more programs; wherein the one or more programs are stored in the memory;
  • the processor executes the one or more programs for performing all or part of the steps performed by a server in the method of the seventh aspect.
  • a fifteenth aspect of the present application provides a computer readable storage medium having stored therein instructions that, when executed on a computer, cause the computer to perform any of the above first to seventh aspects The method described on the one hand.
  • the embodiments of the present application have the following advantages:
  • the terminal terminal when the terminal runs on the first operating system OS, the terminal terminal acquires the second OS identifier, and the second OS identifier matches the second configuration file, and then, the terminal is according to the second
  • the OS identifier is switched to the second OS, and a target message is sent to the server, where the target message is used to request a second configuration file from the server, and the terminal acquires the second configuration file from the server.
  • the OS provided by each operator server is configured with a corresponding OS identifier.
  • the terminal determines that the corresponding OS is running according to the obtained OS identifier, and then downloads the configuration file from the carrier server to ensure the terminal.
  • the configuration file can be downloaded to the corresponding OS, which improves the accuracy of downloading the configuration file by the terminal.
  • FIG. 1 is a schematic diagram of information exchange between a terminal and a network in an embodiment of the present application
  • FIG. 2 is a schematic diagram of an embodiment of a method for transmitting a configuration file according to the present application
  • FIG. 3 is a schematic diagram of another embodiment of a method for transmitting a configuration file according to the present application.
  • FIG. 4 is a schematic diagram of another embodiment of a method for transmitting a configuration file according to the present application.
  • FIG. 5 is a schematic diagram of an embodiment of an RPM management method according to the present application.
  • FIG. 6 is a schematic diagram of an embodiment of a method for transmitting a packaged file according to the present application.
  • FIG. 7 is a schematic diagram of an embodiment of an ISD-R update method according to the present application.
  • FIG. 8 is a schematic diagram of another embodiment of a method for transmitting a configuration file according to the present application.
  • FIG. 9 is a schematic diagram of an embodiment of a terminal according to the present application.
  • FIG. 10 is a schematic diagram of another embodiment of a terminal according to the present application.
  • FIG. 11 is a schematic diagram of an embodiment of a server of the present application.
  • FIG. 12 is a schematic diagram of another embodiment of a terminal according to the present application.
  • FIG. 13 is a schematic diagram of another embodiment of a terminal according to the present application.
  • FIG. 14 is a schematic diagram of another embodiment of a server of the present application.
  • FIG. 15 is a schematic diagram of another embodiment of a server of the present application.
  • 16 is a schematic diagram of an embodiment of an eUICC according to the present application.
  • FIG. 17 is a schematic diagram of another embodiment of a terminal according to the present application.
  • FIG. 18 is a schematic diagram of another embodiment of a server of the present application.
  • FIG. 19 is a schematic structural diagram of a terminal according to the present application.
  • 20 is a schematic structural diagram of a server of the present application.
  • the embodiment of the present application provides a configuration file transmission method, a related device, and a storage medium, which ensure that the terminal can download the configuration file to the corresponding OS, thereby improving the accuracy of downloading the configuration file by the terminal.
  • the terminal device 101 performs information interaction with a server such as the operator server 102 and the configuration file server 103 through a network.
  • the terminal device (referred to as a terminal) may include user equipment, a vehicle networking device, a wearable device, an Internet of Things device, or an intelligent robot device, etc., which exist in various forms, for example, a mobile phone, a tablet computer, a smart watch, an in-vehicle terminal. , smart water meters, smart meters and other equipment.
  • the terminal device includes a software and hardware module such as a SIM card 1011, a local profile assistant (LPA) 1012, and an operator operating system (OS).
  • LPA local profile assistant
  • OS operator operating system
  • the configuration file in the embodiments of the present application refers to a general term for storing and running a series of files and data related to an operator within the eUICC.
  • the configuration file includes user identification information and service subscription information, and the user identification information includes user identity, authentication parameters, operator customization parameters, applications, file systems, configuration file metadata, and the like.
  • the SIM card in the terminal device is an eUICC, and the eUICC can also be called an eSIM.
  • the eUICC card can be remotely managed by a plurality of communication carriers.
  • the eUICC card can be inserted into the terminal through plugging and soldering. in.
  • the user can download the configuration file required to connect to the carrier and use the configuration file in the eUICC card to access the selected carrier network.
  • the eUICC interacts with the terminal through the ISO protocol and the 7816 interface protocol related to the IC card.
  • LPA can be used for configuration file download management, service discovery, and providing users with UI interfaces (such as configuration file installation list), so that users can manage eUICC local configuration files (such as activation, deactivation, deletion, or unlocking of configuration files). ).
  • the terminal device may also retrieve an eUICC identification (EID) and/or an integrated circuit card ID (ICCID) through the LPA module.
  • EID eUICC identification
  • ICCID integrated circuit card ID
  • the LPA module can be a virtual logic module or a physical module, such as a field programmable gate array.
  • the LPA includes a local discovery service (LDS), a local configuration file download (local configuration file download, LPD), and a local user interface (LUI).
  • LDS local discovery service
  • LPD local configuration file download
  • LPI local user interface
  • the user equipment and the LPA in the eUICC may be composed of any one or more of LDS, LPD, and LUI.
  • the operator can be a basic operator, such as: China Mobile, China Unicom, France Telecom, etc.; it can also be a terminal manufacturer as a service provider; it can also be a card provider as a service provider; As a service provider, it can also be a virtual carrier as a service provider.
  • the server that the carrier provides for the wireless communication service deployed by the operator such as a mobile network operator (MNO) server, a service platform server provided by the terminal manufacturer for its brand terminal, or a service provided by the enterprise for its enterprise user Platform server, etc.
  • MNO mobile network operator
  • service platform server provided by the terminal manufacturer for its brand terminal
  • service provided by the enterprise for its enterprise user Platform server etc.
  • the profile server may also be referred to as a subscription management server, and may specifically include a subscription manager data preparation (SM-DP) server and a subscription manager discovery service (SM-DS) server, where SM- The DP server includes an SM-DP+ server.
  • SM-DP subscription manager data preparation
  • SM-DS subscription manager discovery service
  • the SM-DP+ server is responsible for generating a configuration file, associating the configuration file to the specified eUICC, and downloading the configuration file to the eUICC.
  • the remote management request of the operator can be executed, and the eUICC belonging to the carrier configuration file is downloaded and installed to send the remote
  • the management request, the eUICC performs a remote management request, thereby implementing remote management, and the remote management request includes activating, deactivating, deleting, reviewing the eUICC status, updating the configuration file data, and the like.
  • the main function of the SM-DS server is to provide a mechanism for the SM-DP+ server to contact the LPA.
  • the LDS in the LPA contacts the SM-DS server to obtain the address of the SM-DP+ server.
  • the SM-DP+ server has a configuration file downloaded to the eUICC
  • the SM-DP+ server registers its address on the SM-DS server
  • the SM-DP+ server has a remote management request to be sent to the eUICC
  • SM-DP+ The server registers its address or event to the SM-DS server.
  • the LDS can contact SM-DP+ to download the configuration file or obtain a remote management request.
  • the operator OS may be an OS of an eUICC running a configuration file, or an OS of a software application (application, APP) that provides services to an operator installed on the terminal, for example, an OS of an operator's handheld business office APP, and may also It is other OS, such as the OS of the financial industry, the OS developed by the terminal manufacturer, and the OS related to the industry application.
  • APP software application
  • the carrier OS includes an upper part and a lower part at the software level, and the upper part of the operator OS includes a local profile assistant service (LPA services), a telecom framework, a profile policy enabler, and a configuration. Profile package interpreter, etc.
  • the underlying part of the operator OS includes an issuer security domain root (ISD-R), an eUICC controlling authority security domain (ECASD), and an encryption algorithm.
  • ISD-R is mainly used to create a new issuer security domain profile (ISD-P) and is responsible for the lifecycle management of all ISD-Ps. There is only one ISD-R in each eUICC. ISD-R is installed and personalized by the SIM card manufacturer during eUICC production, and ISD-R cannot be deleted or invalidated.
  • ISD-P issuer security domain profile
  • ECASD is mainly used to securely store credentials to support the security domain on eUICC. There is only one ECASD on each eUICC. During eUICC production, SIM card manufacturers need to install and personalize ECASD.
  • ECASD includes:
  • the eUICC private key is used to establish the signature of the ECDSA
  • the eUICC certificate is used for authentication of the eUICC, and the eUICC certificate includes the eUICC public key;
  • the public key of the certificate issuer used to verify the certificate of the network element (such as SM-DP+) outside the eUICC.
  • the ECASD may contain the same public key or multiple public keys.
  • the SIM card manufacturer's key set for the key and certificate update The SIM card manufacturer's key set for the key and certificate update.
  • the ECASD can create a signature of the eUICC according to the information provided by the ISD-R, and can authenticate the network element other than the eUICC (for example, SM-DP+) by using the public key of the CI.
  • the network element other than the eUICC for example, SM-DP+
  • the terminal may be installed with multiple OSs of different operators at the same time, for example, the first OS of China Unicom and the second OS of China Mobile. If the terminal needs to download the configuration file provided by China Mobile, the terminal needs the current terminal. It runs on the second OS of China Mobile. This ensures that the configuration file provided by the operator can be downloaded to the OS corresponding to the carrier.
  • the method for configuring file transmission in the embodiment of the present application includes:
  • the eUICC on the terminal is installed with at least two OSs of different operators.
  • the terminal runs on the first OS, the terminal acquires a second OS identifier that matches the second configuration file, where the first The first configuration file is installed on the OS.
  • first configuration file provided by the first operator needs to run on the first OS
  • second configuration file provided by the second operator needs to run on the second OS
  • the terminal interacts with the second operator's SM-DP+ server through the LPA.
  • the terminal may extract the second OS identifier from the activation code generated by the server.
  • the server may generate a two-dimensional code that includes the second OS identifier according to the second OS identifier, and the terminal scans the two-dimensional code.
  • a second OS identification can be obtained from the server.
  • the second OS identifier may be obtained by the server according to the user subscription information when the user subscribes.
  • the terminal may send the OS identifier list and the matching ID to the server, where the matching identifier has a unique correspondence with the second configuration file, where the OS identifier list includes each OS installed on the terminal.
  • the server determines, according to the matching identifier, a second OS identifier that matches the second configuration file from the OS identifier list, and sends the second OS identifier to the terminal.
  • the terminal obtains a package file identifier that is a second OS identifier and a second profile identifier.
  • the format of the second OS identifier may be: a combination of an operator identifier + a country code + an OS version number.
  • the terminal switches to the second OS according to the second OS identifier.
  • the terminal After the terminal is currently running on the first OS, the terminal will switch to the second OS according to the second OS identifier after receiving the second OS identifier, so that the terminal runs on the second OS.
  • the terminal sends a target message to the server.
  • the server target message is used to request the downloading of the second configuration file.
  • the target message sent to the server may carry an indication that the server terminal is currently running on the second OS.
  • the server sends a second configuration file to the terminal.
  • the server may find the corresponding second configuration file according to the second OS identifier, and send the second configuration file to the terminal.
  • the server may send the second configuration file after learning that the terminal runs on the second OS.
  • the terminal terminal when the terminal runs on the first operating system OS, the terminal terminal acquires the second OS identifier, and the second OS identifier matches the second configuration file, and then, the terminal is according to the second
  • the OS identifier is switched to the second OS, and a target message is sent to the server, where the target message is used to request a second configuration file from the server, and the terminal acquires the second configuration file from the server.
  • the OS provided by each operator server is configured with a corresponding OS identifier.
  • the terminal determines that the corresponding OS is running according to the obtained OS identifier, and then downloads the configuration file from the carrier server to ensure the terminal.
  • the configuration file can be downloaded to the corresponding OS, which improves the accuracy of downloading the configuration file by the terminal.
  • Scenario 1 The terminal obtains the second OS identifier by using an activation code provided by the server.
  • the terminal includes an LPA and an eUICC, where the eUICC is installed with the first OS and the second OS, and the server is the SM-DP+ server of the second operator.
  • the eUICC may be a security module embedded in the terminal chip or an independent security module.
  • the LPA may obtain the second OS identifier from the activation code provided by the second operator.
  • the activation code further includes address information of the SM-DP+ server, where the activation code may be provided by the second operator.
  • the two-dimensional code, the two-dimensional code contains the information of the second OS identifier, and the second OS identifier can be parsed by scanning the two-dimensional code LPA.
  • the LPA sends an authentication server (authenticate server) message to the eUICC, where the authentication message includes a second OS identifier and a matching ID.
  • the Mathcing ID can be used for index data in the server, such as an activation code token or an event identifier Event ID.
  • the activation code token is used to index a contract relationship before the server. For example, the user signs a server through the handheld business hall, and the server generates an associated configuration file for the contracted service, so as to avoid security considerations such as exposing the configuration file, The code token indexes the configuration file, so that the terminal takes the activation code token to obtain the associated configuration file.
  • the eUICC activates the second OS according to the received second OS identifier, so that the eUICC runs the second OS. It can be understood that when the eUICC receives the second OS identifier, if the eUICC is running on the first OS, the eUICC switches. To the second OS, if the eUICC is running on the second OS, the second OS is continued to run.
  • the LPA obtains, from the eUICC, information about the eUICC used for authentication by the server, where the information of the eUICC includes eUICC challenge, eUICC related information, and the like, and is used for security of the two-way authentication and verification eUICC between the server and the terminal. Sex.
  • the LPA sends an initial authentication (initiate authentiation) message to the SM-DP+ server, where the message includes the information of the eUICC, the eUICC challenge, and the address information of the SM-DP+ server.
  • the server returns an authentication server (authenticate server) message to the LPA, including a server-related certificate, a transaction identifier, a server challenge, a server address, and the like.
  • authentication server authenticate server
  • the server verification is sent ( Authenticate server) message to eUICC.
  • the eUICC verifies the information carried in the received authentication server message. After the verification is passed, the eUICC sends the eUICC information again, including the received transaction identifier, the server challenge, the eUICC related information, the second OS identifier, and the matching. Identifying and encrypting the eUICC information to generate eUICC encrypted information, including eUICC signed, eUICC signature, etc., and then the eUICC sends the eUICC encrypted information to the LPA.
  • the LPA sends an authentication client (authenticate client) message to the SM-DP+ server, where the authentication client message carries the eUICC encryption information. It can be understood that the message is used to request the second configuration from the SM-DP+ server. file.
  • the SM-DP+ server verifies the eUICC encrypted information.
  • the SM-DP+ server may determine the second configuration file according to the second OS identifier and the matching identifier.
  • the second configuration file is downloaded and installed between the eUICC and the SM-DP+ server.
  • Scenario 2 The server determines the second OS identifier from the list of OS identifiers reported by the terminal.
  • the terminal includes an LPA, an eUICC, and a primary platform (PP), wherein the first OS and the second OS are installed on the eUICC, and the server is the SM-DP+ of the second carrier. server.
  • the main platform is the hardware platform of the terminal, and also includes a low-level operating system OS for the upper-layer OS to access the hardware resources of the underlying main platform.
  • the eUICC can be a security module embedded in the terminal chip, and can be an independent security module.
  • the eUICC obtains the installed OS identifier list information in the eUICC.
  • the eUICC may send a message for obtaining an OS identifier list to the main platform, where the main platform sends the local OS identifier list to the eUICC, where the OS identifier list includes an OS corresponding to each OS installed on the terminal. OS logo.
  • the main platform provides a unified management module for installing the OS in the eUICC.
  • the management module for installing the OS in the unified management eUICC may also be provided on the eUICC platform side.
  • the eUICC sends the eUICC encryption information to the LPA, where the eUICC encryption information includes an OS identifier list and a matching identifier, and the eUICC signature (eUICC signed, or eUICC signature) is completed by the OS identifier list and the matching identifier to obtain the eUICC encryption information.
  • the eUICC encryption information includes an OS identifier list and a matching identifier
  • the eUICC signature eUICC signed, or eUICC signature
  • the LPA sends an authentication client message to the SM-DP+ server, where the authentication client message carries the eUICC encryption information.
  • the SM-DP+ server verifies the eUICC encrypted information.
  • the SM-DP+ server determines the second OS identifier from the OS identifier list according to the matching identifier.
  • the SM-DP+ server sends server encryption information to the eUICC, where the server encryption information includes a second OS identifier.
  • the eUICC activates the second OS according to the received second OS identifier, so that the eUICC runs the second OS. It can be understood that when the eUICC receives the second OS identifier, if the eUICC is running on the first OS, the eUICC switches. To the second OS, if the eUICC is running on the second OS, the second OS is continued to run.
  • the LPA obtains information about the eUICC used for authentication by the server from the eUICC, where the information of the eUICC includes eUICC challenge, eUICC related information, and the like, and is used for securing the eUICC between the server and the terminal. Sex.
  • the LPA sends a startup authentication message to the SM-DP+ server, where the startup authentication message includes the information of the eUICC, the eUICC challenge, and the address information of the SM-DP+ server.
  • the server returns an authentication server (authenticate server) message to the LPA, including a server-related certificate, a transaction identifier, a server challenge, a server address, and the like.
  • authentication server authenticate server
  • the server verification is sent ( Authenticate server) message to eUICC.
  • the eUICC verifies the information carried in the received authentication server message. After the verification is passed, the eUICC sends the eUICC information again, including the received transaction identifier, the server challenge, the eUICC related information, the second OS identifier, and the matching. Identifying and encrypting the eUICC information to generate eUICC encrypted information, including eUICC signed, eUICC signature, etc., and then the eUICC sends the eUICC encrypted information to the LPA.
  • the LPA sends an authentication client message to the SM-DP+ server, where the client verification message carries the eUICC encryption information.
  • the SM-DP+ server verifies the eUICC encrypted information.
  • the SM-DP+ server may determine the second configuration file according to the second OS identifier and the matching identifier.
  • the second configuration file is downloaded and installed between the eUICC and the SM-DP+ server.
  • the server can remotely manage the configuration file on the terminal.
  • the terminal includes an LPA and an eUICC
  • the server includes an MNO server, an SM-DP+ server, and an SM-DS server.
  • the eUICC downloads and installs the configuration file to the corresponding OS, and the eUICC can obtain the corresponding OS identifier.
  • the eUICC downloads and installs the configuration file to the corresponding OS, and the eUICC can obtain the corresponding OS identifier.
  • the MNO server sends a Remote Profile Management (RPM) command to the SM-DP+ server, where the OS identifier, the matching identifier, the eUICC identifier, and the SM-DS server address are included.
  • RPM Remote Profile Management
  • the SM-DP+ server generates an RPM packet according to the RPM command, and different RPM packets correspond to different events.
  • the SM-DP+ server sends a registration event message to the SM-DS server, where the registration event message includes an eUICC identifier, an OS identifier, an event identifier, and an SM-DP+ server address.
  • the LPA will periodically obtain its own registration event from the SM-DS server.
  • the LPA obtains eUICC encryption information from the eUICC, where the eUICC encryption information includes an OS identifier and a matching identifier.
  • the LPA sends a startup authentication message to the SM-DS server, where the message includes an OS identifier.
  • the SM-DS server After receiving the OS identifier sent by the LPA, the SM-DS server queries the locally stored OS identifier. If the same OS identifier is stored locally, the RPM event corresponding to the eUICC exists.
  • the SM-DS server sends an event identifier corresponding to the RPM event to the LPA.
  • the LPA After obtaining the event identifier, the LPA sends the event identifier and the OS identifier to the SM-DP+ server. Specifically, the LPA may send the event identifier and the OS identifier to the SM in the process of bidirectional authentication with the SM-DP+ server. -DP+ server.
  • the SM-DP+ server determines the corresponding RPM packet according to the event identifier and the OS identifier reported by the LPA, and the RPM package determined by the SM-DP+ server is based on the currently running OS of the eUICC, which improves the accuracy and security of the RPM.
  • the embodiments described above are based on the scenario in which the OS is installed on the terminal.
  • the solution provides a method for packaging and downloading the OS file and the configuration file.
  • the terminal includes an LPA, an eUICC, and a primary platform (PP), and the server is an SM-DP+ server.
  • the eUICC performs bidirectional authentication through the LPA and the SM-DP+ server. In the process of bidirectional authentication, the eUICC
  • the SM-DP+ server requests a package file, wherein the package file includes at least a configuration file and an OS file corresponding to the configuration file, and may also include other application files (Application, APP). It can be understood that each package file is configured with a corresponding package file identifier, and the package file identifier can be obtained by the MNO server according to the user's contract process, and then the package file identifier is sent to the SM-DP+ server. The SM-DP+ can also select the corresponding package file identifier from the package file identifier list reported by the terminal.
  • Application Application
  • the SM-DP+ server may determine the package file according to the matching identifier obtained in the two-way authentication process.
  • the matching identifier determining configuration file is obtained, and the OS file corresponding to the configuration file is further determined, and then the configuration file is packaged with the OS file to obtain a package file.
  • the SM-DP+ server sends the package file identifier to the LPA, where the SM-DP+ server can send the SM-DP+ encrypted information carrying the package file identifier to the LPA.
  • the LPA may send a message requesting a Rule Authorisation Table (RAT) to the eUICC, or send a message requesting the RAT to the primary platform, where the embodiment sends an example to the primary platform, where
  • the RAT is a pre-configured package file identifier corresponding to the package file that can be downloaded by the eUICC.
  • the primary platform sends the RAT to the LPA.
  • the RAT is requested from the eUICC, it is returned to the LPA by the eUICC.
  • the LPA verifies the package file identifier sent by the SM-DP+ server according to the received RAT. If the matching package file identifier in the RAT is found, the verification succeeds.
  • the LPA sends a download preparation message to the eUICC, where the message includes SM-DP+ encryption information.
  • the eUICC that receives the download preparation message may generate eUICC encryption information, and send the eUICC encryption information to the SM-DP+ server through the LPA.
  • the SM-DP+ server After verifying the eUICC encrypted information, the SM-DP+ server sends the packaged file to the LPA.
  • the LPA loads the package file, and configures an issuer security domain-package file (Issuer Secure Domain-Bundle, ISD-B) for storing the package file for the eUICC.
  • ISD-B issuer security domain-package file
  • the ISD-B may be further divided into a storage OS.
  • the eUICC can download the OS file and the configuration file to the corresponding security domain.
  • the eUICC configuration ISD-B may be performed at any step before step 609.
  • the download of the configuration file mentioned above may be downloaded to the eUICC as a bundle with the OS and installed.
  • the issuer security domain root of the OS in the bundle may be generated (Issuer Security Domain Root)
  • the terminal includes an LPA, an eUICC, and a primary platform (PP).
  • the first UI and the second OS are installed on the eUICC
  • the server includes an SM-DP+ server and an update server.
  • the update server may be a functional entity in the SD-DP+ server, or an update server deployed by a card vendor, a terminal manufacturer, or a chip manufacturer.
  • the eUICC When the eUICC runs on the first OS, the eUICC establishes a connection with the update server through the LPA, and obtains the latest ISD-R data packet from the update server, and completes the update of the ISD-R on the first OS.
  • the eUICC sends the latest ISD-R version information to the main platform, so that the ISD-R version information on the main platform is updated.
  • the main platform may obtain the ISD-R version according to the received ISD-R version on the first OS.
  • the corresponding ISD-R data packet completes the update of the main platform ISD-R.
  • the primary platform sends the updated ISD-R version information to the eUICC.
  • the eUICC running on the second OS establishes a connection with the update server through the LPA, and updates from the update.
  • the server obtains the latest ISD-R data packet and completes the update of the ISD-R on the second OS.
  • the update server can be the same server or a different update server. This embodiment considers the same update server as an example.
  • the ISD-R version information on the main platform is updated, the ISD-R version information is notified to other OSs installed on the eUICC, so that other OSs that do not update the ISD-R version information may be updated according to the latest version.
  • the ISD-R version information is obtained from the update server to obtain the latest ISD-R data packet to achieve ISD-R compatibility between different OSs and the main platform.
  • the OS of multiple different operators can be installed on the eUICC. If some of the OSs are activated and the other OS is not activated, the inactive OS cannot be downloaded to the corresponding configuration. File, so when eUICC needs to run on the activated OS, download the configuration file corresponding to the inactive OS from the server, which is described in detail below:
  • the terminal includes an LPA, an eUICC, and a primary platform (Primary Platform, PP).
  • the first UI and the second OS are installed on the eUICC, and the server includes an SM-DP+ server.
  • the eUICC running on the first OS obtains the second OS identifier, and the process is similar to the step of the eUICC acquiring the second OS in the embodiment shown in FIG. 3 or FIG. 4, and details are not described herein again.
  • the eUICC may search for the corresponding second OS according to the second OS identifier, and then request the second OS key from the primary OS by using the primary platform, and the primary platform forwards the key of the second OS to the first OS. eUICC.
  • the eUICC sends the eUICC encryption information to the LPA, where the eUICC encryption information includes a matching identifier, a second OS identifier, and a second OS key.
  • the LPA sends an authentication client message to the SM-DP+ server, where the authentication client message carries the eUICC encryption information.
  • the SM-DP+ server verifies the eUICC encrypted information. It can be understood that the SM-DP+ server needs to verify the second OS key carried in the eUICC encrypted information.
  • the second configuration file may be determined according to the second OS identifier and the matching identifier.
  • the configuration file corresponding to the second OS may be directly downloaded based on the first OS. Increased the flexibility of the program.
  • the above is an introduction to the method embodiment in the embodiment of the present application.
  • the terminal and the server in the embodiment of the present application are introduced from the perspective of a functional module and a hardware implementation.
  • the terminal includes at least the following functional modules:
  • the first acquiring unit 901 is configured to acquire a second OS identifier when the terminal runs on the first operating system OS, where the second OS identifier matches the second configuration file.
  • the switching unit 902 is configured to switch to the second OS according to the second OS identifier
  • a sending unit 903 configured to send a target message to the server, where the target message is used to request the second configuration file;
  • the second obtaining unit 904 is configured to acquire the second configuration file from the server.
  • the first acquiring unit 901 acquires the second OS identifier, and the second OS identifier matches the second configuration file, and then, the switching unit 902 is configured according to the first The second OS identifier is switched to the second OS, and the sending unit 903 sends a target message to the server, where the target message is used to request a second configuration file from the server, and further, the second obtaining unit 904 obtains the The second configuration file.
  • the OS provided by each operator server is configured with a corresponding OS identifier.
  • the terminal determines that the corresponding OS is running according to the obtained OS identifier, and then downloads the configuration file from the carrier server to ensure the terminal.
  • the configuration file can be downloaded to the corresponding OS, which improves the accuracy of downloading the configuration file by the terminal.
  • the first obtaining unit 1001, the switching unit 1002, the sending unit 1003, and the second obtaining unit 1004 perform the actions performed by the above unit and the unit shown in FIG. The actions are similar, and will not be described here.
  • the first obtaining unit 1001 includes:
  • the obtaining module 10011 is configured to obtain an activation code, where the activation code is generated by the server according to the second OS identifier.
  • the extracting module 10012 is configured to extract the second OS identifier from the activation code.
  • the first obtaining unit 1001 includes:
  • the sending module 10013 is configured to send an OS identifier list and a matching identifier to the server, where the matching identifier has a unique correspondence relationship with the second configuration file.
  • the receiving module 10014 is configured to receive a second OS identifier sent by the server, where the second OS identifier is determined by the server according to the matching identifier from the OS identifier list.
  • the sending unit 1003 is further configured to send the second OS identifier to the server, where the second acquiring unit 1004 is further configured to: when the server stores a remote configuration file corresponding to the second OS identifier When the RPM information is managed, the RPM information is obtained from the server, and the RPM information is used to manage the second configuration file.
  • the server includes at least the following functional modules:
  • the receiving unit 1101 is configured to receive a target message sent by the terminal, where the target message is generated after the terminal switches to the second OS according to the second OS identifier, where the second OS identifier is Obtained when the terminal runs on the first OS, and the second OS identifier matches the second configuration file;
  • a determining unit 1102 configured to determine a second configuration file according to the target message
  • the sending unit 1103 is configured to send the second configuration file to the terminal.
  • the server may further include:
  • the generating unit 1104 is configured to generate an activation code according to the second OS identifier.
  • the receiving unit 1101 is further configured to receive an OS identifier list and a matching identifier sent by the terminal, where the matching identifier has a unique correspondence relationship with the second configuration file.
  • the determining unit 1102 is further configured to determine, according to the matching identifier, the second OS identifier from the OS identifier list;
  • the sending unit 1103 is further configured to send the second OS identifier to the terminal.
  • the receiving unit 1101 is further configured to receive the second OS identifier sent by the terminal;
  • the sending unit 1103 is further configured to: when the server stores the remote configuration file management RPM information corresponding to the second OS identifier, send the RPM information to the terminal, where the RPM information is used by the management office.
  • the second configuration file is described.
  • the terminal includes at least the following functional modules:
  • the sending unit 1201 is configured to send a first message to the server, where the first message is used to request a package file from the server, where the package file includes an operating system OS file and a profile profile;
  • the receiving unit 1202 is configured to receive a package file identifier sent by the server.
  • the obtaining unit 1203 is configured to acquire the OS file and the configuration file from the server when the package file identifier matches the rule authorization table RAT preset on the terminal.
  • the sending unit 1301, the receiving unit 1302, and the obtaining unit 1303, the actions performed by the above unit are similar to the actions performed by the unit shown in FIG. Narration.
  • the sending unit 1301 is further configured to send, to the server, a package file identifier list, where the package file identifier is determined by the server according to the package file identifier list.
  • the obtaining unit 1303 includes:
  • a first downloading module 13031 configured to download the OS file from the server to a first security domain, where the first security domain is configured by the server;
  • the second downloading module 13032 is configured to download the configuration file from the server to the second security domain, where the second security domain is configured by the server.
  • the server includes at least the following functional modules:
  • the receiving unit 1401 is configured to receive a first message sent by the terminal, where the first message is used to request a package file from the server, where the package file includes an operating system OS file and a profile profile;
  • a first sending unit 1402 configured to send a package file identifier to the terminal
  • the second sending unit 1403 is configured to send the OS file and the configuration file to the terminal when the package file identifier matches the rule authorization table RAT preset on the terminal.
  • the receiving unit 1501, the first sending unit 1502, and the second sending unit 1503, the actions performed by the above unit are similar to the actions performed by the unit shown in FIG. I will not repeat them here.
  • the receiving unit 1501 is further configured to receive a package file identifier list sent by the terminal;
  • the server further includes:
  • the determining unit 1504 is configured to determine the package file identifier according to the package file identifier list.
  • the second sending unit 1503 includes:
  • the configuration module 15031 is configured to configure the first security domain and the second security domain.
  • the sending module 15032 is configured to send the OS file to the first security domain, and send the configuration file to the second security domain.
  • the eUICC includes at least the following functional modules:
  • the sending unit 1601 is configured to: when the eUICC runs on the first operating system OS, send first version information of the first issuer security domain-root ISD-R corresponding to the first OS to the main platform PP;
  • the receiving unit 1602 is configured to receive the first version information sent by the PP when the eUICC runs on the second operating system OS.
  • the obtaining unit 1603 is configured to acquire data information corresponding to the second version information if the first version information does not match the second version information of the second ISD-R corresponding to the second OS, where The data information is used to update the second ISD-R.
  • the terminal includes at least the following functional modules:
  • the first obtaining unit 1701 is configured to: when the terminal runs on the first operating system OS, acquire a second OS identifier, where the second OS identifier matches the second configuration file;
  • a second obtaining unit 1702 configured to acquire a key from the second OS, where the second OS is determined by the terminal according to the second OS identifier;
  • a sending unit 1703 configured to send the key to the server
  • the third obtaining unit 1704 is configured to acquire a second configuration file from the server when the server determines that the key verification is successful.
  • the server includes at least the following functional modules:
  • the receiving unit 1801 is configured to receive a key that is sent by the terminal, where the key is acquired by the terminal from the second OS, and the second OS is determined by the terminal according to the second OS identifier, where the second OS identifier is Obtained when the terminal runs on the first OS, and the second OS identifier matches the second configuration file;
  • the sending unit 1802 is configured to: when the server successfully verifies the key, the server sends the second configuration file to the terminal.
  • the server and the terminal in the embodiment of the present application are described above from the perspective of the modular functional entity.
  • the server and the terminal in the embodiment of the present application are described from the perspective of hardware processing:
  • the embodiment of the present application further provides a terminal. As shown in FIG. 19, for the convenience of description, only the parts related to the embodiment of the present application are shown. If the specific technical details are not disclosed, refer to the method part of the embodiment of the present application.
  • the terminal may be any terminal device including a mobile phone, a tablet computer, a personal digital assistant (PDA), a point of sales (POS), a car computer, and the like, and the terminal is a mobile phone as an example:
  • FIG. 19 is a block diagram showing a partial structure of a mobile phone related to a terminal provided by an embodiment of the present application.
  • the mobile phone includes: a radio frequency (RF) circuit 1910, a memory 1920, an input unit 1930, a display unit 1940, a sensor 1950, an audio circuit 1960, a wireless fidelity (WiFi) module 1970, and a processor 1980. And power supply 1990 and other components.
  • RF radio frequency
  • the structure of the handset shown in FIG. 19 does not constitute a limitation to the handset, and may include more or less components than those illustrated, or some components may be combined, or different components may be arranged.
  • the RF circuit 1910 can be used for receiving and transmitting signals during the transmission and reception of information or during a call. Specifically, after receiving the downlink information of the base station, the processing is processed by the processor 1980. In addition, the uplink data is designed to be sent to the base station.
  • RF circuit 1910 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, and the like.
  • RF circuitry 1910 can also communicate with the network and other devices via wireless communication.
  • the above wireless communication may use any communication standard or protocol, including but not limited to global system of mobile communication (GSM), general packet radio service (GPRS), code division multiple access (code division) Multiple access (CDMA), wideband code division multiple access (WCDMA), long term evolution (LTE), e-mail, short messaging service (SMS), and the like.
  • GSM global system of mobile communication
  • GPRS general packet radio service
  • CDMA code division multiple access
  • WCDMA wideband code division multiple access
  • LTE long term evolution
  • SMS short messaging service
  • the memory 1920 can be used to store software programs and modules, and the processor 1980 executes various functional applications and data processing of the mobile phone by running software programs and modules stored in the memory 1920.
  • the memory 1920 may mainly include a storage program area and a storage data area, wherein the storage program area may store an operating system, an application required for at least one function (such as a sound playing function, an image playing function, etc.), and the like; the storage data area may be stored according to Data created by the use of the mobile phone (such as audio data, phone book, etc.).
  • memory 1920 can include high speed random access memory, and can also include non-volatile memory, such as at least one magnetic disk storage device, flash memory device, or other volatile solid state storage device.
  • the input unit 1930 can be configured to receive input numeric or character information and to generate key signal inputs related to user settings and function controls of the handset.
  • the input unit 1930 may include a touch panel 1931 and other input devices 1932.
  • the touch panel 1931 also referred to as a touch screen, can collect touch operations on or near the user (such as the user using a finger, a stylus, or the like on the touch panel 1931 or near the touch panel 1931. Operation), and drive the corresponding connecting device according to a preset program.
  • the touch panel 1931 may include two parts: a touch detection device and a touch controller.
  • the touch detection device detects the touch orientation of the user, and detects a signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts the touch information into contact coordinates, and sends the touch information.
  • the processor 1980 is provided and can receive commands from the processor 1980 and execute them.
  • the touch panel 1931 can be implemented in various types such as resistive, capacitive, infrared, and surface acoustic waves.
  • the input unit 1930 may also include other input devices 1932.
  • other input devices 1932 may include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control buttons, switch buttons, etc.), trackballs, mice, joysticks, and the like.
  • Display unit 1940 can be used to display information entered by the user or information provided to the user as well as various menus of the handset.
  • the display unit 1940 may include a display panel 1941.
  • the display panel 1941 may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.
  • the touch panel 1931 may cover the display panel 1941. After the touch panel 1931 detects a touch operation thereon or nearby, the touch panel 1931 transmits to the processor 1980 to determine the type of the touch event, and then the processor 1980 according to the touch event. The type provides a corresponding visual output on display panel 1941.
  • the touch panel 1931 and the display panel 1941 are used as two independent components to implement the input and input functions of the mobile phone in FIG. 19, in some embodiments, the touch panel 1931 and the display panel 1941 may be integrated. Realize the input and output functions of the phone.
  • the handset may also include at least one type of sensor 1950, such as a light sensor, motion sensor, and other sensors.
  • the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor may adjust the brightness of the display panel 1941 according to the brightness of the ambient light, and the proximity sensor may close the display panel 1941 and/or when the mobile phone moves to the ear. Or backlight.
  • the accelerometer sensor can detect the magnitude of acceleration in all directions (usually three axes). When it is stationary, it can detect the magnitude and direction of gravity.
  • the mobile phone can be used to identify the gesture of the mobile phone (such as horizontal and vertical screen switching, related Game, magnetometer attitude calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for the mobile phone can also be configured with gyroscopes, barometers, hygrometers, thermometers, infrared sensors and other sensors, no longer Narration.
  • the gesture of the mobile phone such as horizontal and vertical screen switching, related Game, magnetometer attitude calibration
  • vibration recognition related functions such as pedometer, tapping
  • the mobile phone can also be configured with gyroscopes, barometers, hygrometers, thermometers, infrared sensors and other sensors, no longer Narration.
  • An audio circuit 1960, a speaker 1961, and a microphone 1962 can provide an audio interface between the user and the handset.
  • the audio circuit 1960 can transmit the converted electrical data of the received audio data to the speaker 1961, and convert it into a sound signal output by the speaker 1961; on the other hand, the microphone 1962 converts the collected sound signal into an electrical signal, by the audio circuit 1960. After receiving, it is converted into audio data, and then processed by the audio data output processor 1980, transmitted to the other mobile phone via the RF circuit 1910, or outputted to the memory 1920 for further processing.
  • WiFi is a short-range wireless transmission technology.
  • the mobile phone through the WiFi module 1970 can help users to send and receive e-mail, browse the web and access streaming media, etc. It provides users with wireless broadband Internet access.
  • FIG. 19 shows the WiFi module 1970, it can be understood that it does not belong to the essential configuration of the mobile phone, and can be omitted as needed within the scope of not changing the essence of the application.
  • the processor 1980 is the control center of the handset, which connects various portions of the entire handset using various interfaces and lines, by executing or executing software programs and/or modules stored in the memory 1920, and invoking data stored in the memory 1920, executing The phone's various functions and processing data, so that the overall monitoring of the phone.
  • the processor 1980 may include one or more processing units; preferably, the processor 1980 may integrate an application processor and a modem processor, where the application processor mainly processes an operating system, a user interface, an application, and the like.
  • the modem processor primarily handles wireless communications. It will be appreciated that the above described modem processor may also not be integrated into the processor 1980.
  • the mobile phone also includes a power source 1990 (such as a battery) that supplies power to various components.
  • a power source can be logically coupled to the processor 1980 through a power management system to manage functions such as charging, discharging, and power management through the power management system.
  • the mobile phone may further include a camera, a Bluetooth module, and the like, and details are not described herein again.
  • the processor 1980 is specifically configured to perform all or part of the actions performed by the terminal in the embodiment shown in FIG. 2 to FIG. 8 , and details are not described herein again.
  • FIG. 20 is a schematic structural diagram of a server provided by an embodiment of the present application.
  • the server 2000 may generate a large difference due to different configurations or performances, and may include one or more central processing units (CPUs) 2022 (for example, One or more processors and memory 2032, one or more storage media 2030 that store application 2042 or data 2044 (eg, one or one storage device in Shanghai).
  • the memory 2032 and the storage medium 2030 may be short-term storage or persistent storage.
  • the program stored on storage medium 2030 may include one or more modules (not shown), each of which may include a series of instruction operations in the server.
  • the central processor 2022 can be configured to communicate with the storage medium 2030 to perform a series of instruction operations in the storage medium 2030 on the server 2000.
  • the central processing unit 2022 can perform all or part of actions performed by the server (including the SM-DP+ server, the MNO server, the SM-DS server, and the update server) in the embodiment shown in FIG. 2 to FIG. 8 according to the command operation, specifically I won't go into details here.
  • Server 2000 may also include one or more power sources 2026, one or more wired or wireless network interfaces 2050, one or more input and output interfaces 2058, and/or one or more operating systems 2041, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM and more.
  • operating systems 2041 such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM and more.
  • the steps performed by the server in the above embodiment may be based on the server structure shown in FIG.
  • the disclosed system, apparatus, and method may be implemented in other manners.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
  • the units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • a computer readable storage medium A number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present application.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like, which can store program code. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Information Transfer Between Computers (AREA)
  • Stored Programmes (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephone Function (AREA)

Abstract

本申请实施例公开了一种配置文件传输方法及相关设备和存储介质,保证了终端能将配置文件下载到对应的OS上,提升了终端下载配置文件的准确性。本申请实施例方法包括:当终端运行于第一操作系统OS时,所述终端获取第二OS标识,所述第二OS标识与第二配置文件匹配;所述终端根据所述第二OS标识切换到所述第二OS;所述终端发送目标消息至所述服务器,所述目标消息用于请求所述第二配置文件;所述终端从所述服务器获取所述第二配置文件。

Description

一种配置文件传输方法及相关设备和存储介质 技术领域
本申请涉及终端领域,尤其涉及一种配置文件传输方法及相关设备和存储介质。
背景技术
当前的用户身份识别模块(subscriber identification module,SIM)卡最常见的是可插拔的SIM卡,在出厂时已烧入固定的SIM数据,通过固定的SIM数据连接运营商网络,且通过插拔来更换SIM卡及更换码号资源。
随着技术的发展,嵌入式通用集成电路卡(embedded universal integrated circuit card,eUICC)作为新一代的SIM卡已经越来越普及,eUICC可以使用户不用局限在一家运营商的服务中,用户可以任意下载用于连接运营商所需要的配置文件(Profile),而无需更换Sim卡,运营商服务器根据eUICC的身份信息(EID,eUICC identification)来确定与该eUICC对应的配置文件。
然而,若终端存在多个运营商的操作系统(OS,operating system),不同的OS上运行的配置文件也是不同的,导致运营商服务器根据EID确定的配置文件有可能并不是终端当前正在运行的OS所匹配的配置文件,影响了终端下载配置文件的准确性。
发明内容
本申请实施例提供了一种配置文件传输方法及相关设备和存储介质,保证了终端能将配置文件下载到对应的OS上,提升了终端下载配置文件的准确性。
本申请第一方面提供了一种配置文件Profile传输的方法,该方法包括:当终端运行于第一操作系统OS时,所述终端获取第二OS标识,所述第二OS标识与第二配置文件匹配;所述终端根据所述第二OS标识切换到所述第二OS;所述终端发送目标消息至所述服务器,所述目标消息用于请求所述第二配置文件;所述终端从所述服务器获取所述第二配置文件。
通过上述方式,每个运营商服务器提供的OS都配置有对应的OS标识,终端会根据获取到的OS标识确定对应的OS正在运行后,再从该运营商服务器下载配置文件,保证了终端能将配置文件下载到对应的OS上,提升了终端下载配置文件的准确性。
可选地,终端获取第二OS标识的方法可以是:所述终端获取激活码,所述激活码由所述服务器根据所述第二OS标识生成,所述终端从所述激活码中提取所述第二OS标识。
通过上述方式,本方案提供了一种终端获取第二OS标识的具体实现方式,提高了本方案的可实现性。
可选地,终端获取第二OS标识的方法可以是:所述终端向所述服务器发送OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系,所述终端接收所述服务器发送的第二OS标识,所述第二OS标识由所述服务器根据所述匹配标识从所述OS标识列表中确定。
通过上述方式,本方案提供了另一种终端获取第二OS标识的具体实现方式,提高 了本方案的灵活性。
可选地,终端从服务器获取到第二配置文件之后,所述终端向所述服务器发送所述第二OS标识,当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,所述终端从所述服务器获取所述RPM信息,所述RPM信息用于管理所述第二配置文件。
通过上述方式,可以实现服务器确定的RPM信息是基于终端当前运行的OS,提高了RPM的准确性及安全性。
本申请第二方面提供了一种配置文件Profile传输的方法,该方法包括:服务器接收终端发送的目标消息,其中,所述目标消息为所述终端根据所述第二OS标识切换到所述第二OS之后生成的,所述第二OS标识为所述终端运行于第一OS时获取的,且所述第二OS标识与第二配置文件匹配,所述服务器根据所述目标消息确定第二配置文件,所述服务器向所述终端发送所述第二配置文件。
通过上述方式,每个运营商服务器提供的OS都配置有对应的OS标识,终端会根据获取到的OS标识确定对应的OS正在运行后,再从该运营商服务器下载配置文件,保证了终端能将配置文件下载到对应的OS上,提升了终端下载配置文件的准确性。
可选地,服务器接收终端发送的目标消息之前,所述服务器根据所述第二OS标识生成激活码。
可选地,服务器接收终端发送的目标消息之前,所述服务器接收所述终端发送的OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系,所述服务器根据所述匹配标识从所述OS标识列表中确定所述第二OS标识,并发送所述第二OS标识至所述终端。
可选地,所述服务器发送所述第二配置文件至所述终端之后,所述服务器接收所述终端发送的所述第二OS标识,当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,所述服务器向所述终端发送所述RPM信息,所述RPM信息用于管理所述第二配置文件。
本申请第三方面提供了一种打包文件Bundle传输的方法,该方法包括:终端向服务器发送第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile,所述终端接收所述服务器发送的打包文件标识,当所述打包文件标识与所述终端上预置的规则授权表RAT匹配时,所述终端从所述服务器获取所述OS文件及所述配置文件。
通过上述方式,终端可以从服务器一次性下载到包括OS文件及配置文件的打包文件,并且OS文件与配置文件是匹配的,提高了终端下载安装OS和配置文件的效率。
可选地,所述终端接收所述服务器发送的打包文件标识之前,所述终端向所述服务器发送打包文件标识列表,所述打包文件标识由所述服务器根据所述打包文件标识列表确定。
可选地,终端从服务器获取OS文件及配置文件的方法可以是:所述终端从所述服务器将所述OS文件下载到第一安全域,所述第一安全域由所述服务器配置,所述终端从所述服务器将所述配置文件下载到第二安全域,所述第二安全域由所述服务器配置。
本申请第四方面提供了一种打包文件Bundle传输的方法,该方法包括:服务器接收 终端发送的第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile,所述服务器向所述终端发送打包文件标识,当所述打包文件标识与所述终端上预置的规则授权表RAT匹配时,所述服务器向所述终端发送所述OS文件及所述配置文件。
通过上述方式,终端可以从服务器一次性下载到包括OS文件及配置文件的打包文件,并且OS文件与配置文件是匹配的,提高了终端下载安装OS和配置文件的效率。
可选地,所述服务器向所述终端发送打包文件标识之前,所述服务器接收所述终端发送的打包文件标识列表,所述服务器根据所述打包文件标识列表确定所述打包文件标识。
可选地,所述服务器向所述终端发送所述OS文件及所述配置文件的方法可以是:所述服务器配置第一安全域及第二安全域,所述服务器将所述OS文件发送至所述第一安全域,并将所述配置文件发送至所述第二安全域。
本申请第五方面提供了一种发行者安全域根ISD-R的更新方法,该方法包括:当嵌入式通用集成电路卡eUICC运行于第一操作系统OS时,所述eUICC发送与所述第一OS对应的第一发行者安全域-根ISD-R的第一版本信息至主平台PP,当所述eUICC运行于第二操作系统OS时,所述eUICC接收所述PP发送的所述第一版本信息,若所述第一版本信息与所述第二OS所对应的第二ISD-R的第二版本信息不匹配,则所述eUICC获取所述第二版本信息所对应的数据信息,所述数据信息用于更新所述第二ISD-R。
通过上述方式,若主平台上的ISD-R版本信息得到更新,会将该ISD-R版本信息通知其他安装于eUICC上的OS,使其他没有更新ISD-R版本信息的OS可以根据最新的ISD-R版本信息从更新服务器获取最新的ISD-R数据包,以实现不同OS及主平台之间ISD-R的兼容。
本申请第六方面提供了一种配置文件Profile传输的方法,该方法包括:当终端运行于第一操作系统OS时,所述终端获取第二OS标识,所述第二OS标识与第二配置文件匹配,所述终端从第二OS获取密钥,所述第二OS由所述终端根据所述第二OS标识确定,所述终端发送所述密钥至所述服务器,当所述服务器确定所述密钥校验成功时,所述终端从所述服务器获取第二配置文件。
本申请第七方面提供了一种配置文件Profile传输的方法,该方法包括:服务器接收终端发送的密钥,所述密钥是所述终端从第二OS获取的,所述第二OS由所述终端根据第二OS标识确定,所述第二OS标识为所述终端运行于第一OS时获取的,且所述第二OS标识与第二配置文件匹配,当所述服务器对所述密钥校验成功时,所述服务器向所述终端发送所述第二配置文件。
通过上述方式,终端如果要下载与第二OS对应的配置文件,并不一定要先切换到第二OS的系统环境下,可以直接基于第一OS下载与第二OS对应的配置文件,提高了本方案的灵活性。
本申请第八方面提供了一种终端,具体实现对应于上述第一方面提供的配置文件Profile传输方法的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件程序实现。硬件和软件包括一个或多个与上述功能相对应的单元模块,所述单元模块可以是软件和/或硬件。
一种可能的设计中,所述终端包括:第一获取单元,用于当终端运行于第一操作系统OS时,获取第二OS标识,所述第二OS标识与第二配置文件匹配;切换单元,用于根据所述第二OS标识切换到所述第二OS;发送单元,用于发送目标消息至所述服务器,所述目标消息用于请求所述第二配置文件;第二获取单元,用于从所述服务器获取所述第二配置文件。
可选地,所述第一获取单元包括:获取模块,用于获取激活码,所述激活码由所述服务器根据所述第二OS标识生成;提取模块,用于从所述激活码中提取所述第二OS标识。
可选地,所述第一获取单元包括:发送模块,用于向所述服务器发送OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系;接收模块,用于接收所述服务器发送的第二OS标识,所述第二OS标识由所述服务器根据所述匹配标识从所述OS标识列表中确定。
可选地,所述发送单元,还用于向所述服务器发送所述第二OS标识;所述第二获取单元,还用于当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,从所述服务器获取所述RPM信息,所述RPM信息用于管理所述第二配置文件。
另一种可能的设计中,所述终端包括:包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行第一方面的所述的方法中的终端执行的全部或部分步骤。
本申请第九方面提供了一种服务器,具体实现对应于上述第二方面提供的配置文件Profile传输方法的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件程序实现。硬件和软件包括一个或多个与上述功能相对应的单元模块,所述单元模块可以是软件和/或硬件。
一种可能的设计中,所述服务器包括:接收单元,用于接收终端发送的目标消息,其中,所述目标消息为所述终端根据所述第二OS标识切换到所述第二OS之后生成的,所述第二OS标识为所述终端运行于第一OS时获取的,且所述第二OS标识与第二配置文件匹配;确定单元,用于根据所述目标消息确定第二配置文件;发送单元,用于向所述终端发送所述第二配置文件。
可选地,所述服务器还包括:生成单元,用于根据所述第二OS标识生成激活码。
可选地,所述接收单元,还用于接收所述终端发送的OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系;所述确定单元,还用于根据所述匹配标识从所述OS标识列表中确定所述第二OS标识;所述发送单元,还用于发送所述第二OS标识至所述终端。
可选地,所述接收单元,还用于接收所述终端发送的所述第二OS标识;所述发送单元,还用于当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,向所述终端发送所述RPM信息,所述RPM信息用于管理所述第二配置文件。
另一种可能的设计中,所述服务器包括:包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处 理器执行所述一个或多个程序,以用于执行第二方面的所述的方法中的服务器执行的全部或部分步骤。
本申请第十方面提供了一种终端,具体实现对应于上述第三方面提供的打包文件Bundle传输方法的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件程序实现。硬件和软件包括一个或多个与上述功能相对应的单元模块,所述单元模块可以是软件和/或硬件。
一种可能的设计中,所述终端包括:发送单元,用于向服务器发送第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile;接收单元,用于接收所述服务器发送的打包文件标识;获取单元,用于当所述打包文件标识与所述终端上预置的规则授权表RAT匹配时,从所述服务器获取所述OS文件及所述配置文件。
可选地,所述发送单元,还用于向所述服务器发送打包文件标识列表,所述打包文件标识由所述服务器根据所述打包文件标识列表确定。
可选地,所述获取单元包括:第一下载模块,用于从所述服务器将所述OS文件下载到第一安全域,所述第一安全域由所述服务器配置;第二下载模块,用于从所述服务器将所述配置文件下载到第二安全域,所述第二安全域由所述服务器配置。
另一种可能的设计中,所述服务器包括:包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行第三方面的所述的方法中的终端执行的全部或部分步骤。
本申请第十一方面提供了一种服务器,具体实现对应于上述第四方面提供的打包文件Bundle传输方法的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件程序实现。硬件和软件包括一个或多个与上述功能相对应的单元模块,所述单元模块可以是软件和/或硬件。
一种可能的设计中,所述服务器包括:接收单元,用于接收终端发送的第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile;第一发送单元,用于向所述终端发送打包文件标识;第二发送单元,用于当所述打包文件标识与所述终端上预置的规则授权表RAT匹配时,向所述终端发送所述OS文件及所述配置文件。
可选地,所述接收单元,还用于接收所述终端发送的打包文件标识列表;所述服务器还包括:确定单元,用于根据所述打包文件标识列表确定所述打包文件标识。
可选地,所述第二发送单元包括:配置模块,用于配置第一安全域及第二安全域;发送模块,用于将所述OS文件发送至所述第一安全域,并将所述配置文件发送至所述第二安全域。
另一种可能的设计中,所述服务器包括:包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行第四方面的所述的方法中的服务器执行的全部或部分步骤。
本申请第十二方面提供了一种eUICC,具体实现对应于上述第五方面提供的ISD-R 的更新方法的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件程序实现。硬件和软件包括一个或多个与上述功能相对应的单元模块,所述单元模块可以是软件和/或硬件。
一种可能的设计中,所述eUICC包括:发送单元,用于当所述eUICC运行于第一操作系统OS时,发送与所述第一OS对应的第一发行者安全域-根ISD-R的第一版本信息至主平台PP;接收单元,用于当所述eUICC运行于第二操作系统OS时,接收所述PP发送的所述第一版本信息;获取单元,用于若所述第一版本信息与所述第二OS所对应的第二ISD-R的第二版本信息不匹配,则获取所述第二版本信息所对应的数据信息,所述数据信息用于更新所述第二ISD-R。
另一种可能的设计中,所述eUICC包括:包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行第五方面的所述的方法中的eUICC执行的全部或部分步骤。
本申请第十三方面提供了一种终端,具体实现对应于上述第六方面提供的配置文件Profile传输方法的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件程序实现。硬件和软件包括一个或多个与上述功能相对应的单元模块,所述单元模块可以是软件和/或硬件。
一种可能的设计中,所述终端包括:第一获取单元,用于当终端运行于第一操作系统OS时,获取第二OS标识,所述第二OS标识与第二配置文件匹配;第二获取单元,用于从第二OS获取密钥,所述第二OS由所述终端根据所述第二OS标识确定;发送单元,用于发送所述密钥至所述服务器;第三获取单元,用于当所述服务器确定所述密钥校验成功时,从所述服务器获取第二配置文件。
另一种可能的设计中,所述终端包括:包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行第六方面的所述的方法中的终端执行的全部或部分步骤。
本申请第十四方面提供了一种终端服务器,具体实现对应于上述第七方面提供的配置文件Profile传输方法的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件程序实现。硬件和软件包括一个或多个与上述功能相对应的单元模块,所述单元模块可以是软件和/或硬件。
一种可能的设计中,所述服务器包括:接收单元,用于接收终端发送的密钥,所述密钥是所述终端从第二OS获取的,所述第二OS由所述终端根据第二OS标识确定,所述第二OS标识为所述终端运行于第一OS时获取的,且所述第二OS标识与第二配置文件匹配;发送单元,用于当所述服务器对所述密钥校验成功时,所述服务器向所述终端发送所述第二配置文件。
另一种可能的设计中,所述服务器包括:包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行第七方面的所述的方法中的服务器执行的全部或部分步骤。
本申请第十五方面提供了一种计算机可读存储介质,所述计算机可读存储介质中存储有指令,当其在计算机上运行时,使得计算机执行上述第一方面至第七方面中的任一方面所述的方法。
从以上技术方案可以看出,本申请实施例具有以下优点:
本申请实施例中,当终端运行于第一操作系统OS时,所述终端终端获取第二OS标识,所述第二OS标识与第二配置文件匹配,随后,所述终端根据所述第二OS标识切换到所述第二OS,并发送目标消息至所述服务器,所述目标消息用于向服务器请求第二配置文件,进而,所述终端从所述服务器获取所述第二配置文件。通过上述方式可知,每个运营商服务器提供的OS都配置有对应的OS标识,终端会根据获取到的OS标识确定对应的OS正在运行后,再从该运营商服务器下载配置文件,保证了终端能将配置文件下载到对应的OS上,提升了终端下载配置文件的准确性。
附图说明
图1为本申请实施例中的终端与网络进行信息交互的示意图;
图2为本申请配置文件传输方法的一个实施例示意图;
图3为本申请配置文件传输方法另一个实施例示意图;
图4为本申请配置文件传输方法另一个实施例示意图;
图5为本申请RPM管理方法的一个实施例示意图;
图6为本申请打包文件传输方法的一个实施例示意图;
图7为本申请ISD-R更新方法的一个实施例示意图;
图8为本申请配置文件传输方法另一个实施例示意图;
图9为本申请终端的一个实施例示意图;
图10为本申请终端的另一个实施例示意图;
图11为本申请服务器的一个实施例示意图;
图12为本申请终端的另一个实施例示意图;
图13为本申请终端的另一个实施例示意图;
图14为本申请服务器的另一个实施例示意图;
图15为本申请服务器的另一个实施例示意图;
图16为本申请eUICC的一个实施例示意图;
图17为本申请终端的另一个实施例示意图;
图18为本申请服务器的另一个实施例示意图;
图19为本申请终端的结构示意图;
图20为本申请服务器的结构示意图。
具体实施方式
本申请实施例提供了一种配置文件传输方法及相关设备和存储介质,保证了终端能将配置文件下载到对应的OS上,提升了终端下载配置文件的准确性。
本申请的说明书和权利要求书及附图中的术语“第一”、“第二”、“第三”、“第四”等(如果存在)是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理 解这样使用的数据在适当情况下可以互换,以便这里描述的实施例能够以除了在这里图示或描述的内容以外的顺序实施。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、系统、产品或设备不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或单元。
本申请实施例可应用于对eUICC进行远程管理的系统架构中,请参阅图1,终端设备101通过网络与运营商服务器102及配置文件服务器103等服务器进行信息交互。其中,终端设备(简称终端)可以包括以各种形式存在的用户设备、车联网设备、可穿戴设备、物联网设备、或智能机器人设备等等,例如:手机、平板电脑、智能手表、车载终端、智能水表、智能电表等设备。终端设备中包括SIM卡1011、本地配置文件助手(local Profile assistant,LPA)1012、运营商操作系统(OS,operating system)1013等软硬件模块。图1中所涉及的各实体及模块的功能介绍如下:
本申请各实施例中的配置文件指的是用于存储并运行在eUICC内部与某个运营商相关的一系列文件、数据的统称。配置文件包含用户识别信息和业务签约信息,用户识别信息包括用户身份、认证参数、运营商定制参数、应用、文件系统、配置文件元数据等信息。
终端设备中的SIM卡为eUICC,eUICC也可称为eSIM,是一种可由多个通信运营商远程管理签约用户的安全元件,eUICC卡可通过插拔式和焊接式两种方式放入到终端中。用户可以任意下载用于连接运营商所需要的配置文件,使用eUICC卡中的配置文件接入选定的运营商网络,eUICC通过ISO协议和IC卡相关的7816接口协议与终端交互。
LPA可用于配置文件下载管理、业务发现、为用户提供UI界面(如配置文件安装列表)等,以便用户可以管理eUICC本地的配置文件(例如对配置文件进行激活、去激活、删除或解锁等操作)。另外,终端设备还可以通过LPA模块检索eUICC标识(eUICC identification,EID)和/或集成电路卡标识(integrated circuit card ID,ICCID)。LPA模块可以为虚拟逻辑模块,也可以为实体模块,例如现场可编程门阵列。LPA包括本地发现服务(local discovery service,LDS)、本地配置文件下载(local配置文件download,LPD)以及本地用户接口UI界面(local user interface,LUI)。用户设备和eUICC中的LPA可以由LDS、LPD以及LUI中的任意一个或多个组成。
运营商可以是某基础运营商,例如:中国移动、中国联通、法国电信等运营商;还可以是某终端厂商作为业务提供商;还可以是某卡商作为业务提供商;还可以是某企业作为业务提供商,还可以是某虚拟运营商作为业务提供商等。
运营商服务器为运营商部署的提供无线通信服务的服务器,例如移动网络运营商(mobile network operator,MNO)服务器,终端厂商为其品牌终端提供的业务平台服务器,或企业为其企业用户提供的业务平台服务器等。
配置文件服务器也可以称为签约管理服务器,具体可以包括签约管理数据准备(subscription manager data preparation,SM-DP)服务器以及签约管理业务发现(subscription manager discovery service,SM-DS)服务器,其中,SM-DP服务器包括SM-DP+服务器。
SM-DP+服务器负责生成配置文件,关联配置文件到指定eUICC,并将配置文件下 载到eUICC,此外,还可以执行运营商的远程管理请求,向下载安装了属于该运营商配置文件的eUICC发送远程管理请求,eUICC执行远程管理请求,从而实现远程管理,远程管理请求包括激活、去激活、删除、审查eUICC状态、更新配置文件数据等。
SM-DS服务器的主要作用是提供一种机制能让SM-DP+服务器能与LPA联系,LPA中的LDS联系SM-DS服务器可以获得SM-DP+服务器的地址。比如,SM-DP+服务器上有下载到eUICC的配置文件时,SM-DP+服务器将其地址注册在SM-DS服务器上,SM-DP+服务器有要发送到eUICC上的远程管理请求时,SM-DP+服务器将其地址或事件注册到SM-DS服务器上,LDS获得SM-DP+服务器的地址或事件后,可以联系SM-DP+从而可以下载配置文件或获得远程管理请求。
运营商OS可以为运行配置文件的eUICC的OS,也可以是安装在终端上的运营商提供服务的软件应用程序(application,APP)的OS,例如,运营商掌上营业厅APP的OS,还可以是其他OS,例如金融行业的OS,终端厂商开发的OS,行业应用相关OS等。
该运营商OS在软件层面包含上层部分及底层部分,运营商OS的上层部分包含本地配置文件助手服务(LPA services)、电信框架(telecom framework)、配置文件策略启动器(profile policy enabler)及配置文件包解释器(profile package interpreter)等。运营商OS的底层部分包含发行者安全域-根(issuer security domain root,ISD-R)、eUICC控制权限安全域(eUICC controlling authority security domain,ECASD)及加密算法等。
ISD-R主要用来创建新的发行者安全域-配置文件(issuer security domain profile,ISD-P),并且负责所有ISD-P的生命周期管理,每个eUICC中只有一个ISD-R。ISD-R是在eUICC生产过程中由SIM卡制造商安装以及个性化的,ISD-R不能被删除或者无效。
ECASD主要用来安全存储凭据来支持eUICC上面的安全域,每个eUICC上面只有一个ECASD,在eUICC生产过程中,SIM卡制造商需要安装以及个性化ECASD。
其中,ECASD包括:
eUICC私钥,用来建立ECDSA的签名;
eUICC证书,用于eUICC的鉴权,eUICC证书中包括eUICC公钥;
证书颁发者(certificate issuer,CI)的公钥,用于验证eUICC之外网元(例如SM-DP+)的证书,ECASD可能含有同一个或者多个不同的公钥;
SIM卡制造商的证书;
SIM卡制造商的密钥集,用于密钥以及证书的更新。
ECASD可以根据ISD-R提供的信息创建eUICC的签名,并且可以利用CI的公匙对eUICC之外网元(例如SM-DP+)进行验证。
本申请实施例中,终端可以同时安装有多个不同运营商的OS,例如,中国联通的第一OS以及中国移动的第二OS,终端如果需要下载中国移动提供的配置文件,那么需要终端当前运行于中国移动的第二OS上,这样可以保证运营商提供的配置文件可以下载到该运营商对应的OS上。下面进行详细介绍:
请参阅图2,本申请实施例中配置文件传输的方法包括:
201、当终端运行于第一OS时,获取第二OS标识。
本申请实施例中,终端上的eUICC至少安装有两个不同运营商的OS,当终端运行 于第一OS时,终端将获取到与第二配置文件匹配的第二OS标识,其中,第一OS上安装有第一配置文件。
可以理解的是,第一运营商提供的第一配置文件需要运行于第一OS上,而第二运营商提供的第二配置文件需要运行于第二OS上。
可选地,终端通过LPA与第二运营商的SM-DP+服务器进行交互。
可选地,终端可以从服务器生成的激活码中提取到第二OS标识,例如,服务器根据第二OS标识可以生成一个包含该第二OS标识的二维码,终端通过扫描该二维码即可从服务器获取到第二OS标识。其中第二OS标识可以是用户签约时服务器根据用户签约信息获取。
可选地,终端可以向服务器发送OS标识列表以及匹配标识(matching ID),其中,匹配标识与第二配置文件具有唯一的对应关系,该OS标识列表中包含每个安装于该终端上的OS所对应的OS标识,服务器根据匹配标识从OS标识列表中确定与第二配置文件匹配的第二OS标识,并将第二OS标识发送至终端。
可选地,终端获取到可以是一个包含第二OS标识与第二配置文件标识的打包文件标识。
可选地,第二OS标识的格式可以是:运营商标识+国家码+OS版本号等组合。
202、终端根据第二OS标识切换到第二OS。
由于终端当前运行于第一OS,终端收到第二OS标识后将根据第二OS标识切换至第二OS,使终端运行于第二OS。
203、终端向服务器发送目标消息。
终端在切换到第二OS后,向服务器目标消息用于请求第二配置文件的下载,可选的,可在向服务器发送的目标消息中携带告知服务器终端当前已经运行于第二OS的指示。
204、服务器向终端发送第二配置文件。
服务器可以根据第二OS标识查到对应的第二配置文件,并将第二配置文件发送至终端。可选的,服务器可以在获知终端运行于第二OS后,发送第二配置文件。
本申请实施例中,当终端运行于第一操作系统OS时,所述终端终端获取第二OS标识,所述第二OS标识与第二配置文件匹配,随后,所述终端根据所述第二OS标识切换到所述第二OS,并发送目标消息至所述服务器,所述目标消息用于向服务器请求第二配置文件,进而,所述终端从所述服务器获取所述第二配置文件。通过上述方式可知,每个运营商服务器提供的OS都配置有对应的OS标识,终端会根据获取到的OS标识确定对应的OS正在运行后,再从该运营商服务器下载配置文件,保证了终端能将配置文件下载到对应的OS上,提升了终端下载配置文件的准确性。
下面结合具体场景对终端与服务器之间的信息交互进行详细介绍:
场景一:终端通过服务器提供的激活码获取到第二OS标识。
请参阅图3,本实施例中,终端上包括LPA及eUICC,其中,eUICC上安装有第一OS及第二OS,服务器为第二运营商的SM-DP+服务器。其中eUICC可以为嵌入到终端芯片中的安全模块,也可以为独立的安全模块。
301、LPA可以从第二运营商提供的激活码中获取到第二OS标识,此外,激活码中 还包含有SM-DP+服务器的地址信息,其中,激活码可以是由第二运营商提供的二维码,二维码中包含第二OS标识的信息,通过扫描二维码LPA即可解析得到到第二OS标识。
302、LPA向eUICC发送鉴权服务器(authenticate server)消息,该鉴权消息中包含第二OS标识及匹配标识(matching ID)。其中Mathcing ID可以为服务器中索引数据使用,例如是激活码token或事件标识Event ID。其中激活码token用于索引一个之前在服务器的签约关系,例如用户通过掌上营业厅签约一个服务器,服务器为该签约的服务生成相关联的配置文件,为避免暴露配置文件等安全考虑,因此通过激活码token来索引该配置文件,以便终端拿该激活码token来获取相关联的配置文件。
303、eUICC根据收到的第二OS标识激活第二OS,使eUICC运行第二OS,可以理解的是,在eUICC收到第二OS标识时,若eUICC正运行于第一OS,那么eUICC切换至第二OS,若eUICC正运行于第二OS,则继续运行第二OS。
304、LPA从eUICC获取得到与服务器鉴权使用的eUICC的信息,该eUICC的信息中包含eUICC挑战(eUICC challenge),eUICC相关信息等信息,用于服务器与终端之间双向鉴权验证eUICC的安全性。
305、LPA向SM-DP+服务器发送启动鉴权(initiate authentiation)消息,该消息中包含eUICC的信息、eUICC挑战及SM-DP+服务器的地址信息。
306、服务器向LPA返回鉴权服务器(authenticate server)消息,包括服务器相关证书,事务标识,服务器挑战(server challenge),服务器地址等信息,LPA初步验证该鉴权服务器消息后,将发送服务器验证(authenticate server)消息至eUICC。
307、eUICC对接收到的鉴权服务器消息中携带的信息进行验证,验证通过后,eUICC将再次发送eUICC信息,具体包括接收到的事务标识,服务器挑战,eUICC相关信息,第二OS标识以及匹配标识,并将该eUICC信息加密生成eUICC加密信息,包括eUICC signed,eUICC signature等处理,随后eUICC将eUICC加密信息发送至LPA。
308、LPA向SM-DP+服务器发送鉴权客户端(authenticate client)消息,该鉴权客户端消息中携带有eUICC加密信息,可以理解的是,该消息用于向SM-DP+服务器请求第二配置文件。
309、SM-DP+服务器对eUICC加密信息进行验证。
310、SM-DP+服务器在对eUICC加密信息验证完成后,可以根据第二OS标识以及匹配标识确定第二配置文件。
311、eUICC与SM-DP+服务器之间进行第二配置文件的下载及安装流程。
场景二:服务器从终端上报的OS标识列表中确定第二OS标识。
请参阅图4,本实施例中,终端上包括LPA、eUICC及主平台(primary platform,PP),其中,eUICC上安装有第一OS及第二OS,服务器为第二运营商的SM-DP+服务器。其中主平台为终端的硬件平台,还包含有低层级操作系统OS,供上层OS访问底层主平台硬件资源。其中eUICC可以为嵌入到终端芯片中的安全模块,可以为独立的安全模块。
401、eUICC获取eUICC中已安装OS标识列表信息。可选的,eUICC可向主平台发送获取OS标识列表的消息,主平台将存储于本地的OS标识列表发送至eUICC,其 中,OS标识列表中包含每个安装于该终端上的OS所对应的OS标识。主平台提供统一管理eUICC中安装OS的管理模块。可选的,还可通过在eUICC平台侧提供该统一管理eUICC中安装OS的管理模块。
402、eUICC向LPA发送eUICC加密信息,其中,eUICC加密信息中包含OS标识列表及匹配标识,将OS标识列表及匹配标识完成eUICC签名(eUICC signed,或eUICC signature)来获得eUICC加密信息。
403、LPA向SM-DP+服务器发送鉴权客户端消息,该鉴权客户端消息中携带有eUICC加密信息。
404、SM-DP+服务器对eUICC加密信息进行验证。
405、SM-DP+服务器根据匹配标识从OS标识列表中确定第二OS标识。
406、SM-DP+服务器向eUICC发送服务器加密信息,其中,服务器加密信息中包含第二OS标识。
407、eUICC根据收到的第二OS标识激活第二OS,使eUICC运行第二OS,可以理解的是,在eUICC收到第二OS标识时,若eUICC正运行于第一OS,那么eUICC切换至第二OS,若eUICC正运行于第二OS,则继续运行第二OS。
408、LPA从eUICC获取得到与服务器鉴权使用的eUICC的信息,该eUICC的信息中包含eUICC挑战(eUICC challenge),eUICC相关信息等信息,用于服务器与终端之间双向鉴权验证eUICC的安全性。
409、LPA向SM-DP+服务器发送启动鉴权消息,该启动鉴权消息中包含eUICC的信息、eUICC挑战及SM-DP+服务器的地址信息。
410、服务器向LPA返回鉴权服务器(authenticate server)消息,包括服务器相关证书,事务标识,服务器挑战(server challenge),服务器地址等信息,LPA初步验证该鉴权服务器消息后,将发送服务器验证(authenticate server)消息至eUICC。
411、eUICC对接收到的鉴权服务器消息中携带的信息进行验证,验证通过后,eUICC将再次发送eUICC信息,具体包括接收到的事务标识,服务器挑战,eUICC相关信息,第二OS标识以及匹配标识,并将该eUICC信息加密生成eUICC加密信息,包括eUICC signed,eUICC signature等处理,随后eUICC将eUICC加密信息发送至LPA。
412、LPA向SM-DP+服务器发送鉴权客户端消息,该客户端验证消息中携带有eUICC加密信息。
413、SM-DP+服务器对eUICC加密信息进行验证。
414、SM-DP+服务器在对eUICC加密信息验证完成后,可以根据第二OS标识以及匹配标识确定第二配置文件。
415、eUICC与SM-DP+服务器之间进行第二配置文件的下载及安装流程。
上面描述了终端将配置文件下载到对应的OS上的场景,在终端完成配置文件的下载及安装之后,服务器可以对终端上的配置文件进行远程管理,下面进行详细描述:
请参阅图5,本实施例中,终端上包括LPA及eUICC,服务器包括MNO服务器、SM-DP+服务器及SM-DS服务器。
501、eUICC将配置文件下载并安装到对应的OS上,eUICC可以获取到对应的OS标识,具体过程可以参照图3或图4所示的实施例的描述,此处不再赘述。
502、MNO服务器向SM-DP+服务器发送远程配置文件管理(Remote Profile Management,RPM)指令,其中包含OS标识、匹配标识、eUICC标识及SM-DS服务器地址。
503、SM-DP+服务器根据RPM指令生成RPM包,不同的RPM包对应不同的事件。
504、SM-DP+服务器发送注册事件消息至SM-DS服务器,其中,该注册事件消息中包含eUICC标识、OS标识、事件标识及SM-DP+服务器地址。LPA将向SM-DS服务器定期获取自己的注册事件。
505、LPA从eUICC获取eUICC加密信息,其中,eUICC加密信息中包含OS标识以及匹配标识。
506、LPA向SM-DS服务器发送启动鉴权消息,该消息中包含OS标识。
507、SM-DS服务器收到LPA发送的OS标识后,查询本地存储的OS标识,若本地存储有相同的OS标识,即说明存在与eUICC对应的RPM事件。
508、SM-DS服务器将与RPM事件对应的事件标识发送至LPA。
509、LPA获取到事件标识后再将该事件标识以及OS标识发送至SM-DP+服务器,具体地,LPA可以在与SM-DP+服务器双向鉴权的过程中将该事件标识及OS标识发送至SM-DP+服务器。
510、SM-DP+服务器根据LPA上报的事件标识以及OS标识确定对应的RPM包,可以实现SM-DP+服务器确定的RPM包是基于eUICC当前运行的OS,提高了RPM的准确性及安全性。
以上描述的实施例都是基于终端上已经安装了OS的场景,在OS及配置文件的下载流程中,本方案提供了一种将OS文件与配置文件进行打包下载的方式,下面进行详细描述:
请参阅图6,本实施例中,终端上包括LPA、eUICC及主平台(primary platform,PP),服务器为SM-DP+服务器。
601、eUICC通过LPA与SM-DP+服务器进行双向鉴权,在双向鉴权的过程中,eUICC向
SM-DP+服务器请求打包文件(bundle),其中,打包文件至少包含配置文件以及与该配置文件对应的OS文件,还可以包含其他应用文件(Application,APP)。可以理解的是,每个打包文件都配置有对应的打包文件标识,该打包文件标识可以由MNO服务器根据和用户的签约流程获得,之后再将该打包文件标识发送至SM-DP+服务器,此外,SM-DP+也可以从终端上报的打包文件标识列表中选择相应的打包文件标识。
602、SM-DP+服务器可以根据在双向鉴权过程中获取到的匹配标识确定打包文件。可选的,可获取匹配标识确定配置文件,并进一步确定与该配置文件对应的OS文件,再将配置文件与OS文件进行打包得到打包文件。
603、SM-DP+服务器向LPA发送打包文件标识,其中,SM-DP+服务器可以通过发送携带有打包文件标识的SM-DP+加密信息至LPA。
604、LPA收到打包文件标识后,可向eUICC发送请求规则授权表(Rules Authorisation Table,RAT)的消息,或向主平台发送请求RAT的消息,本实施例以向主平台发送举例,其中,RAT为主平台上预先配置的包含有eUICC可以下载的打包文件所 对应的打包文件标识。
605、主平台将RAT发送至LPA。可选的,当向eUICC请求RAT时则由eUICC返回给LPA。
606、LPA根据收到的RAT对SM-DP+服务器下发的打包文件标识进行验证,如果查到RAT中有匹配的打包文件标识即说明验证成功。
607、在打包文件标识验证成功后,LPA向eUICC发送下载准备的消息,该消息中包含SM-DP+加密信息。
608、收到下载准备消息的eUICC可以生成eUICC加密信息,并通过LPA将eUICC加密信息发送至SM-DP+服务器。
609、SM-DP+服务器对eUICC加密信息进行验证后,将打包文件发送至LPA。
610、LPA加载该打包文件,并为eUICC配置用于存储打包文件的发行者安全域-打包文件(Issuer Secure Domain–Bundle,ISD-B),具体的,该ISD-B又可以划分为存储OS文件的安全域以及存储配置文件的安全域,之后,eUICC可以将OS文件及配置文件分别下载到对应的安全域中。
可选的,eUICC配置ISD-B可以在步骤609之前任意步骤执行。
上面介绍了配置文件的下载可能是随OS一起以bundle的形式下载到eUICC并且安装,当主平台上面搭载多个bundle时,可能会产生bundle中的OS的发行者安全域-根(Issuer Security Domain Root,ISD-R)的版本信息和主平台中的ISD-R版本信息不兼容的问题,为此本实施例提供了一种ISD-R的更新方法,下面进行详细描述。
请参阅图7,本实施例中,终端上包括LPA、eUICC及主平台(primary platform,PP),其中,eUICC上安装有第一OS及第二OS,服务器包括SM-DP+服务器及更新服务器。其中更新服务器可以为SD-DP+服务器中的一个功能实体,或由卡商、终端厂商、芯片厂商部署的更新服务器。
701、eUICC运行于第一OS时,eUICC通过LPA与更新服务器建立连接,并从更新服务器获取最新的ISD-R数据包,完成ISD-R在第一OS上的更新。
702、第一OS上的ISD-R完成更新后,eUICC将最新的ISD-R版本信息发送至主平台,使主平台上的ISD-R版本信息得到更新。其中,可选的,当主平台中的ISD-R版本低于第一OS上的ISD-R版本时,主平台可根据接收到的第一OS上的ISD-R版本,获取该ISD-R版本对应的ISD-R数据包,完成主平台ISD-R的更新。
703、当eUICC运行于第二OS时,主平台将更新后的ISD-R版本信息发送至eUICC。
704、若第二OS上的ISD-R版本信息与从主平台获取到的最新的的ISD-R版本信息不匹配,则运行于第二OS的eUICC通过LPA与更新服务器建立连接,并从更新服务器获取最新的ISD-R数据包,完成ISD-R在第二OS上的更新。其中更新服务器可以为同一服务器,也可能为不同的更新服务器。本实施例以为同一更新服务器举例。
本申请实施例中,若主平台上的ISD-R版本信息得到更新,会将该ISD-R版本信息通知其他安装于eUICC上的OS,使其他没有更新ISD-R版本信息的OS可以根据最新的ISD-R版本信息从更新服务器获取最新的ISD-R数据包,以实现不同OS及主平台之间ISD-R的兼容。
由于用户可以同时与多个不同的运营商签约,即eUICC上可以安装多个不同运营商的OS,如果其中一部分OS已经激活,而另一部分OS未激活,未激活的OS无法联网下载对应的配置文件,所以需要eUICC运行于已激活的OS上时从服务器下载未激活的OS所对应的配置文件,下面进行详细描述:
请参阅图8,本实施例中,终端上包括LPA、eUICC及主平台(Primary Platform,PP),其中,eUICC上安装有第一OS及第二OS,服务器包括SM-DP+服务器。
801、运行于第一OS的eUICC获取到第二OS标识,该过程与如图3或图4所示实施例中eUICC获取第二OS的步骤类似,具体此处不再赘述。
802、eUICC根据第二OS标识可以查找到对应的第二OS,之后通过主平台向第二OS请求第二OS的密钥,主平台将第二OS的密钥转发给运行于第一OS的eUICC。
803、eUICC向LPA发送eUICC加密信息,其中,eUICC加密信息中包含匹配标识、第二OS标识及第二OS密钥。
804、LPA向SM-DP+服务器发送鉴权客户端消息,该鉴权客户端消息中携带有eUICC加密信息。
805、SM-DP+服务器对eUICC加密信息进行验证,可以理解的是,SM-DP+服务器需要对eUICC加密信息中携带的第二OS密钥进行验证。
806、SM-DP+服务器对第二OS密钥校验完成后,可以根据第二OS标识以及匹配标识确定第二配置文件。
807、运行于第一OS的eUICC与SM-DP+服务器之间进行第二配置文件的下载,进而可以将下载到的第二配置文件转发至第二OS。
本申请实施例中,eUICC如果要下载与第二OS对应的配置文件,并不一定要先切换到第二OS的系统环境下,可以直接基于第一OS下载与第二OS对应的配置文件,提高了本方案的灵活性。
以上是对本申请实施例中的方法实施例的介绍,下面从功能模块角度以及硬件实现角度对本申请实施例中的终端及服务器进行介绍。
如图9所示,在本申请终端的一个实施例中,终端至少包括以下功能模块:
第一获取单元901,用于当终端运行于第一操作系统OS时,获取第二OS标识,所述第二OS标识与第二配置文件匹配;
切换单元902,用于根据所述第二OS标识切换到所述第二OS;
发送单元903,用于发送目标消息至所述服务器,所述目标消息用于请求所述第二配置文件;
第二获取单元904,用于从所述服务器获取所述第二配置文件。
本申请实施例中,当终端运行于第一操作系统OS时,第一获取单元901获取第二OS标识,所述第二OS标识与第二配置文件匹配,随后,切换单元902根据所述第二OS标识切换到所述第二OS,发送单元903发送目标消息至所述服务器,所述目标消息用于向服务器请求第二配置文件,进而,第二获取单元904从所述服务器获取所述第二配置文件。通过上述方式可知,每个运营商服务器提供的OS都配置有对应的OS标识,终端会根据获取到的OS标识确定对应的OS正在运行后,再从该运营商服务器下载配置文件,保证了终端能将配置文件下载到对应的OS上,提升了终端下载配置文件的准确 性。
如图10所示,在一些具体的实施例中,第一获取单元1001、切换单元1002、发送单元1003及第二获取单元1004,以上单元所执行的动作与图9所示的单元所执行的动作类似,具体此处不再赘述。
可选地,第一获取单元1001包括:
获取模块10011,用于获取激活码,所述激活码由所述服务器根据所述第二OS标识生成;
提取模块10012,用于从所述激活码中提取所述第二OS标识。
可选地,第一获取单元1001包括:
发送模块10013,用于向所述服务器发送OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系;
接收模块10014,用于接收所述服务器发送的第二OS标识,所述第二OS标识由所述服务器根据所述匹配标识从所述OS标识列表中确定。
可选地,发送单元1003,还用于向所述服务器发送所述第二OS标识;第二获取单元1004,还用于当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,从所述服务器获取所述RPM信息,所述RPM信息用于管理所述第二配置文件。
如图11所示,在本申请服务器的一个实施例中,服务器至少包括以下功能模块:
接收单元1101,用于接收终端发送的目标消息,其中,所述目标消息为所述终端根据所述第二OS标识切换到所述第二OS之后生成的,所述第二OS标识为所述终端运行于第一OS时获取的,且所述第二OS标识与第二配置文件匹配;
确定单元1102,用于根据所述目标消息确定第二配置文件;
发送单元1103,用于向所述终端发送所述第二配置文件。
可选地,服务器还可以包括:
生成单元1104,用于根据所述第二OS标识生成激活码。
可选地,所述接收单元1101,还用于接收所述终端发送的OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系;
所述确定单元1102,还用于根据所述匹配标识从所述OS标识列表中确定所述第二OS标识;
所述发送单元1103,还用于发送所述第二OS标识至所述终端。
可选地,所述接收单元1101,还用于接收所述终端发送的所述第二OS标识;
所述发送单元1103,还用于当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,向所述终端发送所述RPM信息,所述RPM信息用于管理所述第二配置文件。
如图12所示,在本申请终端的另一个实施例中,终端至少包括以下功能模块:
发送单元1201,用于向服务器发送第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile;
接收单元1202,用于接收所述服务器发送的打包文件标识;
获取单元1203,用于当所述打包文件标识与所述终端上预置的规则授权表RAT匹 配时,从所述服务器获取所述OS文件及所述配置文件。
如图13所示,在一些具体的实施例中,发送单元1301、接收单元1302及获取单元1303,以上单元所执行的动作与图12所示的单元所执行的动作类似,具体此处不再赘述。
可选地,发送单元1301,还用于向所述服务器发送打包文件标识列表,所述打包文件标识由所述服务器根据所述打包文件标识列表确定。
可选地,获取单元1303包括:
第一下载模块13031,用于从所述服务器将所述OS文件下载到第一安全域,所述第一安全域由所述服务器配置;
第二下载模块13032,用于从所述服务器将所述配置文件下载到第二安全域,所述第二安全域由所述服务器配置。
如图14所示,在本申请服务器的另一个实施例中,服务器至少包括以下功能模块:
接收单元1401,用于接收终端发送的第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile;
第一发送单元1402,用于向所述终端发送打包文件标识;
第二发送单元1403,用于当所述打包文件标识与所述终端上预置的规则授权表RAT匹配时,向所述终端发送所述OS文件及所述配置文件。
如图15所示,在一些具体的实施例中,接收单元1501、第一发送单元1502及第二发送单元1503,以上单元所执行的动作与图14所示的单元所执行的动作类似,具体此处不再赘述。
可选地,所述接收单元1501,还用于接收所述终端发送的打包文件标识列表;
所述服务器还包括:
确定单元1504,用于根据所述打包文件标识列表确定所述打包文件标识。
可选地,所述第二发送单元1503包括:
配置模块15031,用于配置第一安全域及第二安全域;
发送模块15032,用于将所述OS文件发送至所述第一安全域,并将所述配置文件发送至所述第二安全域。
如图16所示,在本申请eUICC的一个实施例中,eUICC至少包括以下功能模块:
发送单元1601,用于当所述eUICC运行于第一操作系统OS时,发送与所述第一OS对应的第一发行者安全域-根ISD-R的第一版本信息至主平台PP;
接收单元1602,用于当所述eUICC运行于第二操作系统OS时,接收所述PP发送的所述第一版本信息;
获取单元1603,用于若所述第一版本信息与所述第二OS所对应的第二ISD-R的第二版本信息不匹配,则获取所述第二版本信息所对应的数据信息,所述数据信息用于更新所述第二ISD-R。
如图17所示,在本申请终端的另一个实施例中,终端至少包括以下功能模块:
第一获取单元1701,用于当终端运行于第一操作系统OS时,获取第二OS标识,所述第二OS标识与第二配置文件匹配;
第二获取单元1702,用于从第二OS获取密钥,所述第二OS由所述终端根据所述 第二OS标识确定;
发送单元1703,用于发送所述密钥至所述服务器;
第三获取单元1704,用于当所述服务器确定所述密钥校验成功时,从所述服务器获取第二配置文件。
如图18所示,在本申请服务器的另一个实施例中,服务器至少包括以下功能模块:
接收单元1801,用于接收终端发送的密钥,所述密钥是所述终端从第二OS获取的,所述第二OS由所述终端根据第二OS标识确定,所述第二OS标识为所述终端运行于第一OS时获取的,且所述第二OS标识与第二配置文件匹配;
发送单元1802,用于当所述服务器对所述密钥校验成功时,所述服务器向所述终端发送所述第二配置文件。
上面从模块化功能实体的角度对本申请实施例中的服务器及终端进行了描述,下面从硬件处理的角度对本申请施例中的服务器及终端进行描述:
本申请实施例还提供了一种终端,如图19所示,为了便于说明,仅示出了与本申请实施例相关的部分,具体技术细节未揭示的,请参照本申请实施例方法部分。该终端可以为包括手机、平板电脑、个人数字助理(personal digital assistant,PDA)、销售终端(point of sales,POS)、车载电脑等任意终端设备,以终端为手机为例:
图19示出的是与本申请实施例提供的终端相关的手机的部分结构的框图。参考图19,手机包括:射频(radio frequency,RF)电路1910、存储器1920、输入单元1930、显示单元1940、传感器1950、音频电路1960、无线保真(wireless fidelity,WiFi)模块1970、处理器1980、以及电源1990等部件。本领域技术人员可以理解,图19中示出的手机结构并不构成对手机的限定,可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。
下面结合图19对手机的各个构成部件进行具体的介绍:
RF电路1910可用于收发信息或通话过程中,信号的接收和发送,特别地,将基站的下行信息接收后,给处理器1980处理;另外,将设计上行的数据发送给基站。通常,RF电路1910包括但不限于天线、至少一个放大器、收发信机、耦合器、低噪声放大器(low noise amplifier,LNA)、双工器等。此外,RF电路1910还可以通过无线通信与网络和其他设备通信。上述无线通信可以使用任一通信标准或协议,包括但不限于全球移动通讯系统(global system of mobile communication,GSM)、通用分组无线服务(general packet radio service,GPRS)、码分多址(code division multiple access,CDMA)、宽带码分多址(wideband code division multiple access,WCDMA)、长期演进(long term evolution,LTE)、电子邮件、短消息服务(short messaging service,SMS)等。
存储器1920可用于存储软件程序以及模块,处理器1980通过运行存储在存储器1920的软件程序以及模块,从而执行手机的各种功能应用以及数据处理。存储器1920可主要包括存储程序区和存储数据区,其中,存储程序区可存储操作系统、至少一个功能所需的应用程序(比如声音播放功能、图像播放功能等)等;存储数据区可存储根据手机的使用所创建的数据(比如音频数据、电话本等)等。此外,存储器1920可以包括高速随机存取存储器,还可以包括非易失性存储器,例如至少一个磁盘存储器件、闪存 器件、或其他易失性固态存储器件。
输入单元1930可用于接收输入的数字或字符信息,以及产生与手机的用户设置以及功能控制有关的键信号输入。具体地,输入单元1930可包括触控面板1931以及其他输入设备1932。触控面板1931,也称为触摸屏,可收集用户在其上或附近的触摸操作(比如用户使用手指、触笔等任何适合的物体或附件在触控面板1931上或在触控面板1931附近的操作),并根据预先设定的程式驱动相应的连接装置。可选的,触控面板1931可包括触摸检测装置和触摸控制器两个部分。其中,触摸检测装置检测用户的触摸方位,并检测触摸操作带来的信号,将信号传送给触摸控制器;触摸控制器从触摸检测装置上接收触摸信息,并将它转换成触点坐标,再送给处理器1980,并能接收处理器1980发来的命令并加以执行。此外,可以采用电阻式、电容式、红外线以及表面声波等多种类型实现触控面板1931。除了触控面板1931,输入单元1930还可以包括其他输入设备1932。具体地,其他输入设备1932可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆等中的一种或多种。
显示单元1940可用于显示由用户输入的信息或提供给用户的信息以及手机的各种菜单。显示单元1940可包括显示面板1941,可选的,可以采用液晶显示器(liquid crystal display,LCD)、有机发光二极管(organic light-emitting diode,OLED)等形式来配置显示面板1941。进一步的,触控面板1931可覆盖显示面板1941,当触控面板1931检测到在其上或附近的触摸操作后,传送给处理器1980以确定触摸事件的类型,随后处理器1980根据触摸事件的类型在显示面板1941上提供相应的视觉输出。虽然在图19中,触控面板1931与显示面板1941是作为两个独立的部件来实现手机的输入和输入功能,但是在某些实施例中,可以将触控面板1931与显示面板1941集成而实现手机的输入和输出功能。
手机还可包括至少一种传感器1950,比如光传感器、运动传感器以及其他传感器。具体地,光传感器可包括环境光传感器及接近传感器,其中,环境光传感器可根据环境光线的明暗来调节显示面板1941的亮度,接近传感器可在手机移动到耳边时,关闭显示面板1941和/或背光。作为运动传感器的一种,加速计传感器可检测各个方向上(一般为三轴)加速度的大小,静止时可检测出重力的大小及方向,可用于识别手机姿态的应用(比如横竖屏切换、相关游戏、磁力计姿态校准)、振动识别相关功能(比如计步器、敲击)等;至于手机还可配置的陀螺仪、气压计、湿度计、温度计、红外线传感器等其他传感器,在此不再赘述。
音频电路1960、扬声器1961,传声器1962可提供用户与手机之间的音频接口。音频电路1960可将接收到的音频数据转换后的电信号,传输到扬声器1961,由扬声器1961转换为声音信号输出;另一方面,传声器1962将收集的声音信号转换为电信号,由音频电路1960接收后转换为音频数据,再将音频数据输出处理器1980处理后,经RF电路1910以发送给比如另一手机,或者将音频数据输出至存储器1920以便进一步处理。
WiFi属于短距离无线传输技术,手机通过WiFi模块1970可以帮助用户收发电子邮件、浏览网页和访问流式媒体等,它为用户提供了无线的宽带互联网访问。虽然图19示出了WiFi模块1970,但是可以理解的是,其并不属于手机的必须构成,完全可以根据 需要在不改变申请的本质的范围内而省略。
处理器1980是手机的控制中心,利用各种接口和线路连接整个手机的各个部分,通过运行或执行存储在存储器1920内的软件程序和/或模块,以及调用存储在存储器1920内的数据,执行手机的各种功能和处理数据,从而对手机进行整体监控。可选的,处理器1980可包括一个或多个处理单元;优选的,处理器1980可集成应用处理器和调制解调处理器,其中,应用处理器主要处理操作系统、用户界面和应用程序等,调制解调处理器主要处理无线通信。可以理解的是,上述调制解调处理器也可以不集成到处理器1980中。
手机还包括给各个部件供电的电源1990(比如电池),优选的,电源可以通过电源管理系统与处理器1980逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。
尽管未示出,手机还可以包括摄像头、蓝牙模块等,在此不再赘述。
在本申请实施例中,处理器1980具体用于执行图2至图8所示实施例中终端所执行的全部或部分动作,具体此处不再赘述。
图20是本申请实施例提供的一种服务器结构示意图,该服务器2000可因配置或性能不同而产生比较大的差异,可以包括一个或一个以上中央处理器(central processing units,CPU)2022(例如,一个或一个以上处理器)和存储器2032,一个或一个以上存储应用程序2042或数据2044的存储介质2030(例如一个或一个以上海量存储设备)。其中,存储器2032和存储介质2030可以是短暂存储或持久存储。存储在存储介质2030的程序可以包括一个或一个以上模块(图示没标出),每个模块可以包括对服务器中的一系列指令操作。更进一步地,中央处理器2022可以设置为与存储介质2030通信,在服务器2000上执行存储介质2030中的一系列指令操作。
该中央处理器2022可以根据指令操作执行如图2至图8所示实施例中服务器(包括SM-DP+服务器、MNO服务器、SM-DS服务器及更新服务器)所执行的全部或部分动作,具体此处不再赘述。
服务器2000还可以包括一个或一个以上电源2026,一个或一个以上有线或无线网络接口2050,一个或一个以上输入输出接口2058,和/或,一个或一个以上操作系统2041,例如Windows ServerTM,Mac OS XTM,UnixTM,LinuxTM,FreeBSDTM等等。
上述实施例中由服务器所执行的步骤可以基于该图20所示的服务器结构。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统,装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示 的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,read-only memory)、随机存取存储器(RAM,random access memory)、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,以上实施例仅用以说明本申请的技术方案,而非对其限制;尽管参照前述实施例对本申请进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本申请各实施例技术方案的精神和范围。

Claims (42)

  1. 一种配置文件Profile传输的方法,其特征在于,包括:
    当终端运行于第一操作系统OS时,所述终端获取第二OS标识,所述第二OS标识与第二配置文件匹配;
    所述终端根据所述第二OS标识切换到所述第二OS;
    所述终端发送目标消息至所述服务器,所述目标消息用于请求所述第二配置文件;
    所述终端从所述服务器获取所述第二配置文件。
  2. 根据权利要求1所述的方法,其特征在于,所述终端获取第二OS标识包括:
    所述终端获取激活码,所述激活码由所述服务器根据所述第二OS标识生成;
    所述终端从所述激活码中提取所述第二OS标识。
  3. 根据权利要求1所述的方法,其特征在于,所述终端获取第二OS标识包括:
    所述终端向所述服务器发送OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系;
    所述终端接收所述服务器发送的第二OS标识,所述第二OS标识由所述服务器根据所述匹配标识从所述OS标识列表中确定。
  4. 根据权利要求1至3中任一项所述的方法,其特征在于,所述终端从所述服务器获取第二配置文件之后,所述方法还包括:
    所述终端向所述服务器发送所述第二OS标识;
    当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,所述终端从所述服务器获取所述RPM信息,所述RPM信息用于管理所述第二配置文件。
  5. 一种配置文件Profile传输的方法,其特征在于,包括:
    服务器接收终端发送的目标消息,其中,所述目标消息为所述终端根据所述第二OS标识切换到所述第二OS之后生成的,所述第二OS标识为所述终端运行于第一OS时获取的,且所述第二OS标识与第二配置文件匹配;
    所述服务器根据所述目标消息确定第二配置文件;
    所述服务器向所述终端发送所述第二配置文件。
  6. 根据权利要求5所述的方法,其特征在于,服务器接收终端发送的目标消息之前,所述方法还包括:
    所述服务器根据所述第二OS标识生成激活码。
  7. 根据权利要求5所述的方法,其特征在于,服务器接收终端发送的目标消息之前,所述方法还包括:
    所述服务器接收所述终端发送的OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系;
    所述服务器根据所述匹配标识从所述OS标识列表中确定所述第二OS标识,并发送所述第二OS标识至所述终端。
  8. 根据权利要求5至7中任一项所述的方法,其特征在于,所述服务器发送所述第二配置文件至所述终端之后,所述方法还包括:
    所述服务器接收所述终端发送的所述第二OS标识;
    当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,所 述服务器向所述终端发送所述RPM信息,所述RPM信息用于管理所述第二配置文件。
  9. 一种打包文件Bundle传输的方法,其特征在于,包括:
    终端向服务器发送第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile;
    所述终端接收所述服务器发送的打包文件标识;
    当所述打包文件标识与所述终端上预置的规则授权表RAT匹配时,所述终端从所述服务器获取所述OS文件及所述配置文件。
  10. 根据权利要求9所述的方法,其特征在于,所述终端接收所述服务器发送的打包文件标识之前,所述方法还包括:
    所述终端向所述服务器发送打包文件标识列表,所述打包文件标识由所述服务器根据所述打包文件标识列表确定。
  11. 根据权利要求9或10所述的方法,其特征在于,所述终端从所述服务器获取所述OS文件及所述配置文件包括:
    所述终端从所述服务器将所述OS文件下载到第一安全域,所述第一安全域由所述服务器配置;
    所述终端从所述服务器将所述配置文件下载到第二安全域,所述第二安全域由所述服务器配置。
  12. 一种打包文件Bundle传输的方法,其特征在于,包括:
    服务器接收终端发送的第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile;
    所述服务器向所述终端发送打包文件标识;
    当所述打包文件标识与所述终端上预置的规则授权表RAT匹配时,所述服务器向所述终端发送所述OS文件及所述配置文件。
  13. 根据权利要求12所述的方法,其特征在于,所述服务器向所述终端发送打包文件标识之前,所述方法还包括:
    所述服务器接收所述终端发送的打包文件标识列表;
    所述服务器根据所述打包文件标识列表确定所述打包文件标识。
  14. 根据权利要求12或13所述的方法,其特征在于,所述服务器向所述终端发送所述OS文件及所述配置文件包括:
    所述服务器配置第一安全域及第二安全域;
    所述服务器将所述OS文件发送至所述第一安全域,并将所述配置文件发送至所述第二安全域。
  15. 一种发行者安全域根ISD-R的更新方法,其特征在于,包括:
    当嵌入式通用集成电路卡eUICC运行于第一操作系统OS时,所述eUICC发送与所述第一OS对应的第一发行者安全域-根ISD-R的第一版本信息至主平台PP;
    当所述eUICC运行于第二操作系统OS时,所述eUICC接收所述PP发送的所述第一版本信息;
    若所述第一版本信息与所述第二OS所对应的第二ISD-R的第二版本信息不匹配,则所述eUICC获取所述第二版本信息所对应的数据信息,所述数据信息用于更新所述第 二ISD-R。
  16. 一种配置文件Profile传输的方法,其特征在于,包括:
    当终端运行于第一操作系统OS时,所述终端获取第二OS标识,所述第二OS标识与第二配置文件匹配;
    所述终端从第二OS获取密钥,所述第二OS由所述终端根据所述第二OS标识确定;
    所述终端发送所述密钥至所述服务器;
    当所述服务器确定所述密钥校验成功时,所述终端从所述服务器获取第二配置文件。
  17. 一种配置文件Profile传输的方法,其特征在于,包括:
    服务器接收终端发送的密钥,所述密钥是所述终端从第二OS获取的,所述第二OS由所述终端根据第二OS标识确定,所述第二OS标识为所述终端运行于第一OS时获取的,且所述第二OS标识与第二配置文件匹配;
    当所述服务器对所述密钥校验成功时,所述服务器向所述终端发送所述第二配置文件。
  18. 一种终端,其特征在于,包括:
    第一获取单元,用于当终端运行于第一操作系统OS时,获取第二OS标识,所述第二OS标识与第二配置文件匹配;
    切换单元,用于根据所述第二OS标识切换到所述第二OS;
    发送单元,用于发送目标消息至所述服务器,所述目标消息用于请求所述第二配置文件;
    第二获取单元,用于从所述服务器获取所述第二配置文件。
  19. 根据权利要求18所述的终端,其特征在于,所述第一获取单元包括:
    获取模块,用于获取激活码,所述激活码由所述服务器根据所述第二OS标识生成;
    提取模块,用于从所述激活码中提取所述第二OS标识。
  20. 根据权利要求18所述的终端,其特征在于,所述第一获取单元包括:
    发送模块,用于向所述服务器发送OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系;
    接收模块,用于接收所述服务器发送的第二OS标识,所述第二OS标识由所述服务器根据所述匹配标识从所述OS标识列表中确定。
  21. 根据权利要求18至20所述的终端,其特征在于,
    所述发送单元,还用于向所述服务器发送所述第二OS标识;
    所述第二获取单元,还用于当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,从所述服务器获取所述RPM信息,所述RPM信息用于管理所述第二配置文件。
  22. 一种服务器,其特征在于,包括:
    接收单元,用于接收终端发送的目标消息,其中,所述目标消息为所述终端根据所述第二OS标识切换到所述第二OS之后生成的,所述第二OS标识为所述终端运行于第 一OS时获取的,且所述第二OS标识与第二配置文件匹配;
    确定单元,用于根据所述目标消息确定第二配置文件;
    发送单元,用于向所述终端发送所述第二配置文件。
  23. 根据权利要求22所述的服务器,其特征在于,所述服务器还包括:
    生成单元,用于根据所述第二OS标识生成激活码。
  24. 根据权利要求22所述的服务器,其特征在于,
    所述接收单元,还用于接收所述终端发送的OS标识列表及匹配标识,所述匹配标识与所述第二配置文件具有唯一的对应关系;
    所述确定单元,还用于根据所述匹配标识从所述OS标识列表中确定所述第二OS标识;
    所述发送单元,还用于发送所述第二OS标识至所述终端。
  25. 根据权利要求22至24所述的服务器,其特征在于,
    所述接收单元,还用于接收所述终端发送的所述第二OS标识;
    所述发送单元,还用于当所述服务器存储有与所述第二OS标识对应的远程配置文件管理RPM信息时,向所述终端发送所述RPM信息,所述RPM信息用于管理所述第二配置文件。
  26. 一种终端,其特征在于,包括:
    发送单元,用于向服务器发送第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile;
    接收单元,用于接收所述服务器发送的打包文件标识;
    获取单元,用于当所述打包文件标识与所述终端上预置的规则授权表RAT匹配时,从所述服务器获取所述OS文件及所述配置文件。
  27. 根据权利要求26所述的终端,其特征在于,
    所述发送单元,还用于向所述服务器发送打包文件标识列表,所述打包文件标识由所述服务器根据所述打包文件标识列表确定。
  28. 根据权利要求26或27所述的终端,其特征在于,所述获取单元包括:
    第一下载模块,用于从所述服务器将所述OS文件下载到第一安全域,所述第一安全域由所述服务器配置;
    第二下载模块,用于从所述服务器将所述配置文件下载到第二安全域,所述第二安全域由所述服务器配置。
  29. 一种服务器,其特征在于,包括:
    接收单元,用于接收终端发送的第一消息,所述第一消息用于向所述服务器请求打包文件,所述打包文件包括操作系统OS文件及配置文件Profile;
    第一发送单元,用于向所述终端发送打包文件标识;
    第二发送单元,用于当所述打包文件标识与所述终端上预置的规则授权表RAT匹配时,向所述终端发送所述OS文件及所述配置文件。
  30. 根据权利要求29所述的服务器,其特征在于,
    所述接收单元,还用于接收所述终端发送的打包文件标识列表;
    所述服务器还包括:
    确定单元,用于根据所述打包文件标识列表确定所述打包文件标识。
  31. 根据权利要求29或30所述的服务器,其特征在于,所述第二发送单元包括:
    配置模块,用于配置第一安全域及第二安全域;
    发送模块,用于将所述OS文件发送至所述第一安全域,并将所述配置文件发送至所述第二安全域。
  32. 一种嵌入式通用集成电路卡eUICC,其特征在于,包括:
    发送单元,用于当所述eUICC运行于第一操作系统OS时,发送与所述第一OS对应的第一发行者安全域-根ISD-R的第一版本信息至主平台PP;
    接收单元,用于当所述eUICC运行于第二操作系统OS时,接收所述PP发送的所述第一版本信息;
    获取单元,用于若所述第一版本信息与所述第二OS所对应的第二ISD-R的第二版本信息不匹配,则获取所述第二版本信息所对应的数据信息,所述数据信息用于更新所述第二ISD-R。
  33. 一种终端,其特征在于,包括:
    第一获取单元,用于当终端运行于第一操作系统OS时,获取第二OS标识,所述第二OS标识与第二配置文件匹配;
    第二获取单元,用于从第二OS获取密钥,所述第二OS由所述终端根据所述第二OS标识确定;
    发送单元,用于发送所述密钥至所述服务器;
    第三获取单元,用于当所述服务器确定所述密钥校验成功时,从所述服务器获取第二配置文件。
  34. 一种服务器,其特征在于,包括:
    接收单元,用于接收终端发送的密钥,所述密钥是所述终端从第二OS获取的,所述第二OS由所述终端根据第二OS标识确定,所述第二OS标识为所述终端运行于第一OS时获取的,且所述第二OS标识与第二配置文件匹配;
    发送单元,用于当所述服务器对所述密钥校验成功时,所述服务器向所述终端发送所述第二配置文件。
  35. 一种终端,包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行如权利要求1至4中任一项所述的方法。
  36. 一种服务器,包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行如权利要求5至8中任一项所述的方法。
  37. 一种终端,包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行如权利要求9至11中任一项所述的方法。
  38. 一种服务器,包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行如权利要求12至14中任一项所述的方法。
  39. 一种嵌入式通用集成电路卡eUICC,包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行如权利要求15所述的方法。
  40. 一种终端,包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行如权利要求16所述的方法。
  41. 一种服务器,包括存储器,一个或多个处理器,以及一个或多个程序;其中所述一个或多个程序被存储在所述存储器中;其特征在于,所述处理器执行所述一个或多个程序,以用于执行如权利要求17所述的方法。
  42. 一种计算机可读存储介质,包括指令,当其在计算机上运行时,使得计算机执行如权利要求1-17中任一项所述的方法。
PCT/CN2019/084161 2018-04-25 2019-04-25 一种配置文件传输方法及相关设备和存储介质 Ceased WO2019206201A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
EP19792124.0A EP3761606B1 (en) 2018-04-25 2019-04-25 Method for transmitting configuration file, related device and storage medium
US16/982,998 US11669342B2 (en) 2018-04-25 2019-04-25 Profile transmission method, related device, and storage medium
KR1020207029514A KR102334501B1 (ko) 2018-04-25 2019-04-25 프로파일 전송 방법, 관련 디바이스 및 저장 매체
JP2020559510A JP7055901B2 (ja) 2018-04-25 2019-04-25 プロファイル伝送方法、関連デバイス、および記憶媒体

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201810390590.1 2018-04-25
CN201810390590.1A CN110401687B (zh) 2018-04-25 2018-04-25 一种配置文件传输方法及相关设备和存储介质

Publications (1)

Publication Number Publication Date
WO2019206201A1 true WO2019206201A1 (zh) 2019-10-31

Family

ID=68293479

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/084161 Ceased WO2019206201A1 (zh) 2018-04-25 2019-04-25 一种配置文件传输方法及相关设备和存储介质

Country Status (6)

Country Link
US (1) US11669342B2 (zh)
EP (1) EP3761606B1 (zh)
JP (1) JP7055901B2 (zh)
KR (1) KR102334501B1 (zh)
CN (3) CN114172888A (zh)
WO (1) WO2019206201A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115242775A (zh) * 2022-07-04 2022-10-25 中国银联股份有限公司 资源文件获取方法、装置、设备、介质及产品
JPWO2022234665A1 (zh) * 2021-05-07 2022-11-10

Families Citing this family (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114095916A (zh) * 2017-12-19 2022-02-25 华为技术有限公司 配置文件管理的方法、嵌入式通用集成电路卡和终端
CN114172888A (zh) * 2018-04-25 2022-03-11 华为技术有限公司 一种打包文件传输的方法及相关设备和存储介质
CN115191124B (zh) * 2020-02-28 2025-04-15 三星电子株式会社 用于远程管理和远程管理权限的验证的方法和设备
US12335246B2 (en) * 2020-03-16 2025-06-17 Samsung Electronics Co., Ltd Method and device for online moving of bundles or profiles between devices
CN111586673B (zh) * 2020-04-28 2022-09-16 东信和平科技股份有限公司 配置文件中imsi的重复利用方法、装置、系统和存储介质
CN113784331B (zh) * 2020-06-09 2022-12-30 华为技术有限公司 更新用户身份识别模块卡系统数据的方法及装置
CN111654403B (zh) * 2020-06-24 2022-04-22 迈普通信技术股份有限公司 无线接入点配置方法、装置、通信设备及可读存储介质
US12288077B2 (en) * 2021-03-23 2025-04-29 Capital One Services, Llc Multi-boot architecture for electronic interaction device
US12445444B2 (en) * 2021-08-26 2025-10-14 Pearson Education, Inc. Whitelist-authenticated image and interactive service
CN114090127A (zh) * 2021-11-24 2022-02-25 中国建设银行股份有限公司 电子设备及其配置文件的加载方法和介质
CN114019820A (zh) * 2021-12-13 2022-02-08 美智光电科技股份有限公司 一种智能家居的配置方法、装置及系统
WO2023219621A1 (en) * 2022-05-12 2023-11-16 Jt (Jersey) Limited System and method for activating a user device
CN116827793B (zh) * 2022-12-28 2026-04-10 慧之安信息技术股份有限公司 基于java的本地发现服务器运行方法、系统及设备
WO2024225866A1 (ko) * 2023-04-28 2024-10-31 삼성전자 주식회사 무선 통신 시스템에서 이벤트를 관리하기 위한 방법 및 장치
CN116755421B (zh) * 2023-05-26 2026-01-20 深蓝汽车科技有限公司 车辆控制器的信息配置方法、装置、设备及介质
WO2025054174A1 (en) * 2023-09-06 2025-03-13 Apple Inc. Source device cross platform esim profile transfer
CN121795006A (zh) * 2023-09-06 2026-04-03 苹果公司 目标设备和授权服务器跨平台eSIM配置文件传递
CN117014860B (zh) * 2023-09-27 2024-01-05 紫光同芯微电子有限公司 用于下载配置文件的方法及装置、esim卡、存储介质
JP7749062B1 (ja) 2024-05-02 2025-10-03 エレコム株式会社 入力機器

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2008121744A2 (en) * 2007-03-30 2008-10-09 Cisco Technology, Inc. Network context triggers for activating virtualized computer applications
CN102346725A (zh) * 2010-08-05 2012-02-08 鸿富锦精密工业(深圳)有限公司 更改设备配置文件的消息通知装置及方法
CN103020500A (zh) * 2011-09-28 2013-04-03 联想(北京)有限公司 登录认证方法和电子设备
CN104679532A (zh) * 2013-11-27 2015-06-03 腾讯科技(深圳)有限公司 内核模块加载方法和装置

Family Cites Families (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7412353B2 (en) 2005-09-28 2008-08-12 Intel Corporation Reliable computing with a many-core processor
US8903897B2 (en) * 2011-07-08 2014-12-02 Google Inc. System and method for providing interactive content to non-native application environments
US8949813B2 (en) * 2011-07-29 2015-02-03 Dell Products Lp Systems and methods for facilitating activation of operating systems
KR101624700B1 (ko) 2014-03-27 2016-05-26 주식회사 누보원 가상 운영체제 환경에서 다중화면 제어가 가능한 가상화 클라이언트
KR102231948B1 (ko) * 2014-07-17 2021-03-25 삼성전자 주식회사 프로파일 관리서버의 업데이트 방법 및 장치
WO2016032842A2 (en) 2014-08-25 2016-03-03 Apple Inc. ENFORCING SERVICE POLICIES IN EMBEDDED UICCs
US9843674B2 (en) * 2014-09-24 2017-12-12 Oracle International Corporation Managing selection and triggering of applications on a card computing device
EP3082355A1 (en) * 2015-04-17 2016-10-19 Gemalto Sa A method for controlling remotely the permissions and rights of a target secure element
KR102460274B1 (ko) 2015-10-29 2022-10-28 삼성전자 주식회사 연락처 정보 제공 방법 및 장치
KR102278811B1 (ko) 2015-12-02 2021-07-19 삼성전자주식회사 모바일 장치를 이용한 호스트 장치의 부팅 방법
WO2017147873A1 (zh) * 2016-03-03 2017-09-08 华为技术有限公司 一种配置文件下载方法及相关设备、系统
CN105722061B (zh) * 2016-03-31 2019-04-12 宇龙计算机通信科技(深圳)有限公司 多操作系统的业务管理方法、业务管理系统和终端
US10506439B2 (en) * 2016-09-16 2019-12-10 Apple Inc. Secure control of profile policy rules
FR3059194B1 (fr) * 2016-11-21 2019-06-28 Oberthur Technologies Installation d'un profil dans un module d'identite de souscripteur embarque
CN106648685B (zh) * 2016-12-29 2020-07-28 东软集团股份有限公司 智能终端系统应用的处理方法、装置及智能终端
CN106851621A (zh) * 2017-02-17 2017-06-13 惠州Tcl移动通信有限公司 一种基于rsp的lpa应用实现方法及实现系统
US10769279B2 (en) * 2017-08-24 2020-09-08 Apple Inc. Secure element operating system update notification
CN107959951A (zh) * 2017-12-15 2018-04-24 恒宝股份有限公司 eSIM卡、自动切换eSIM卡的配置文件的方法及系统
KR102394334B1 (ko) * 2017-12-19 2022-05-06 삼성전자주식회사 보안 엘리먼트를 이용하여 통신 서비스를 제공하는 방법 및 이를 위한 전자 장치
IT201800004293A1 (it) * 2018-04-06 2019-10-06 Procedimento di gestione di sistemi operativi multipli in carte a circuito integrato, corrispondente sistema e prodotto informatico
CN114172888A (zh) * 2018-04-25 2022-03-11 华为技术有限公司 一种打包文件传输的方法及相关设备和存储介质

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2008121744A2 (en) * 2007-03-30 2008-10-09 Cisco Technology, Inc. Network context triggers for activating virtualized computer applications
CN102346725A (zh) * 2010-08-05 2012-02-08 鸿富锦精密工业(深圳)有限公司 更改设备配置文件的消息通知装置及方法
CN103020500A (zh) * 2011-09-28 2013-04-03 联想(北京)有限公司 登录认证方法和电子设备
CN104679532A (zh) * 2013-11-27 2015-06-03 腾讯科技(深圳)有限公司 内核模块加载方法和装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3761606A4 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPWO2022234665A1 (zh) * 2021-05-07 2022-11-10
CN115242775A (zh) * 2022-07-04 2022-10-25 中国银联股份有限公司 资源文件获取方法、装置、设备、介质及产品

Also Published As

Publication number Publication date
KR20200130731A (ko) 2020-11-19
CN110401687A (zh) 2019-11-01
CN114124930A (zh) 2022-03-01
CN110401687B (zh) 2021-10-22
KR102334501B1 (ko) 2021-12-02
US20210011737A1 (en) 2021-01-14
JP7055901B2 (ja) 2022-04-18
CN114124930B (zh) 2023-01-13
EP3761606A4 (en) 2021-05-05
CN114172888A (zh) 2022-03-11
EP3761606A1 (en) 2021-01-06
US11669342B2 (en) 2023-06-06
JP2021519990A (ja) 2021-08-12
EP3761606B1 (en) 2025-01-22

Similar Documents

Publication Publication Date Title
CN114124930B (zh) 配置文件传输方法、终端、服务器和存储介质
EP3716656B1 (en) Profile generation method, profile acquisition method, and related device and storage medium
CN114205805B (zh) 一种迁移配置文件的方法及装置
US20210336780A1 (en) Key updating method, apparatus, and system
CN110247887B (zh) 电子装置及其基于用户身份信息提供通信服务的方法
US11937080B2 (en) Method for updating network access application authentication information, terminal, and server
EP4262146A1 (en) Iot device and method for onboarding iot device to server
EP3817322A1 (en) Method for upgrading service application range of electronic identity card, and terminal device
CN112130866A (zh) 一种应用部署方法和相关装置
CN105871867A (zh) 身份认证方法、系统及设备
CN104901991B (zh) 虚拟资源转移方法、装置和系统
WO2017185711A1 (zh) 控制智能设备的方法、装置、系统和存储介质
WO2019128982A1 (zh) 一种设备引导的方法、终端以及服务器
CN107423099B (zh) 键码烧写方法、服务器、终端、键码烧写系统及存储介质
CN108028749A (zh) 用于虚拟化可再编程的通用集成电路芯片的装置、方法以及系统
CN109257793B (zh) 网络连接方法、装置、设备及存储介质
CN110209339A (zh) 一种存储空间的管理方法、安全元件以及终端
CN105488433B (zh) 终端密钥生成方法及装置
CN114510295B (zh) 一种应用资源的加载方法、智能终端及存储介质
CN108737341B (zh) 业务处理方法、终端及服务器
CN117203997A (zh) 电子装置和用于在电子装置中安装嵌入式订户识别模块的配置文件的方法
WO2013168446A1 (ja) 情報端末および個人情報格納端末

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19792124

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2019792124

Country of ref document: EP

Effective date: 20201001

ENP Entry into the national phase

Ref document number: 20207029514

Country of ref document: KR

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 2020559510

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE