CN105323746B - A kind of method that realizing safety management, terminal, platform and system - Google Patents

A kind of method that realizing safety management, terminal, platform and system Download PDF

Info

Publication number
CN105323746B
CN105323746B CN201410277358.9A CN201410277358A CN105323746B CN 105323746 B CN105323746 B CN 105323746B CN 201410277358 A CN201410277358 A CN 201410277358A CN 105323746 B CN105323746 B CN 105323746B
Authority
CN
China
Prior art keywords
seid
platform
security services
terminal
services component
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201410277358.9A
Other languages
Chinese (zh)
Other versions
CN105323746A (en
Inventor
张学智
江志峰
熊小敏
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Telecom Corp Ltd
Original Assignee
China Telecom Corp Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Telecom Corp Ltd filed Critical China Telecom Corp Ltd
Priority to CN201410277358.9A priority Critical patent/CN105323746B/en
Publication of CN105323746A publication Critical patent/CN105323746A/en
Application granted granted Critical
Publication of CN105323746B publication Critical patent/CN105323746B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Telephonic Communication Services (AREA)
  • Telephone Function (AREA)

Abstract

The invention discloses a kind of method for realizing safety management, terminal, platform and systems.This method comprises: terminal is switched on, Security Services component in the terminal is in operating status, and detects whether the terminal is in connected state, if it is, then the Security Services component accesses SE by the machine card interface between operating system, obtains SEID from the SE;The Security Services component carries the SEID and platform establishes connection;Whether the platform judgement has reported the loss with the SE of the SEID, if so, sending SE application lock instruction to the Security Services component, and is sent to the SE by the machine card interface and carries out using locking.The present invention can carry out safe handling to SE.

Description

A kind of method that realizing safety management, terminal, platform and system
Technical field
The present invention relates to communication and mobile Internet field more particularly to a kind of method for realizing safety management, terminal, put down Platform and system.
Background technique
TSM platform (trusted service management platform) be one it is trusty, provide for every profession and trade based on SE (security module) All kinds of SE Application issuances and card management public open service platform.TSM platform can be logical by short message, cell phone client etc. Road provides the aerial downloading and management service of SE application for user, realizes one card for multiple uses.
Multiple applications, including off line fund account etc. are loaded in user's SIM card (or UIM card).User's SIM card (or UIM card) lose or be stolen when, SE is reported the loss, and TSM platform needs the application on SE or SE carrying out associated safety processing (such as lock) is to reduce the loss of user to the greatest extent.
For the SE of SIM card form, TSM platform is received after user mobile phone number reports the loss request, issues SE by short message channel Using lock instruction, the application provider's system user SE for notifying user to order has been reported the loss.But because of the stabilization of short message channel The influence of property and mobile phone shutdown etc. reason, the above process are likely to failure.After failure, TSM platform is not because knowing user network Network situation and when it is switched on, can not determines when to be attempted again.Therefore, aforesaid way not can guarantee SE in user's SIM card The locking of application not can guarantee the safety of off line account in user's SIM card.
TSM platform can also carry out above-mentioned processing by cell phone client, and user necessarily is in login shape in this case State, but on the mobile phone of loss open cell phone client and log in probability it is very low.
Above situation causes TSM platform to be unable to complete the management to SE, and therefore, the safety of SE is on the hazard.
Summary of the invention
The technical problem to be solved by the present invention is to carry out safe handling to SE.
According to an aspect of the present invention, a kind of terminal for realizing safety management, including Security Services component, operating system are proposed And SE, in which:
The Security Services component is used to access SE by the machine card interface between operating system, obtains from the SE SEID, and carry the SEID and establish connection with platform;
The operating system is used to provide the machine card interface between the Security Services component;
The SE is supplied to the Security Services component for saving the SEID;
Wherein, whether the platform judgement has reported the loss with the SE of the SEID, if so, to the security service Component sends SE application lock instruction, and is sent to the SE by the machine card interface and carries out using locking.
Further, the SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code of finished product card (ICCID) or the sequence number of empty calorie.
According to an aspect of the present invention, it is also proposed that a kind of platform for realizing safety management, including connection establishment module, judge mould Block and instruction issue module, in which:
The connection establishment module is used to establish connection with the terminal for carrying SEID;
The judgment module is used to judge whether the SE with the SEID has reported the loss;
Described instruction issues module for by Security Services component of the established connection to the terminal reported the loss Send SE application lock instruction;
Wherein, the Security Services component of the terminal accesses SE by machine card interface between operating system, from described SE obtains SEID, and carries the SEID and establish connection with the platform;The Security Services component receives the SE application lock Fixed instruction, and the SE is sent to by the machine card interface and is carried out using locking.
Further, the SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code of finished product card (ICCID) or the sequence number of empty calorie.
According to an aspect of the present invention, it is also proposed that a kind of system for realizing safety management, including any of the above-described terminal with And any of the above-described platform.
According to an aspect of the present invention, it is also proposed that a method of realize safety management, comprising:
Terminal is switched on, and the Security Services component in the terminal is in operating status, and detects whether the terminal is in Connected state, if it is, the Security Services component accesses SE by the machine card interface between operating system, from the SE Obtain SEID;
The Security Services component carries the SEID and platform establishes connection;
Wherein, whether the platform judgement has reported the loss with the SE of the SEID, if so, to the security service Component sends SE application lock instruction, and is sent to the SE by the machine card interface and carries out using locking.
Further, the SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code of finished product card (ICCID) or the sequence number of empty calorie.
According to an aspect of the present invention, it is also proposed that a method of realize safety management, comprising:
Platform and the terminal for carrying SEID establish connection;
Judge whether the SE with the SEID has reported the loss, if reported the loss, by established connection to The Security Services component for the terminal reported the loss sends SE application lock instruction;
Wherein, the Security Services component of the terminal accesses SE by machine card interface between operating system, from described SE obtains SEID, and carries the SEID and establish connection with the platform;The Security Services component receives the SE application lock Fixed instruction, and the SE is sent to by the machine card interface and is carried out using locking.
Further, the SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code of finished product card (ICCID) or the sequence number of empty calorie.
According to an aspect of the present invention, it is also proposed that a method of realize safety management, comprising:
Terminal is switched on, and the Security Services component in the terminal is in operating status;
Detect whether the terminal is in connected state, if it is, the Security Services component by with operating system Between machine card interface access SE, from the SE obtain SEID;
The Security Services component carries the SEID and platform establishes connection;
Whether the platform judgement has reported the loss with the SE of the SEID, if so, to the Security Services component SE application lock instruction is sent, and the SE is sent to by the machine card interface and is carried out using locking.
In the present invention, the available SEID of the Security Services component of terminal, and be sent to and establish the flat of connection with the terminal Platform sends SE application lock instruction from platform to the Security Services component for the SEID terminal reported the loss, and carries out application lock to SE It is fixed.It is thus possible to carry out safe handling to SE.
By referring to the drawings to the detailed description of exemplary embodiment of the present invention, other feature of the invention and its Advantage will become apparent.
Detailed description of the invention
The attached drawing for constituting part of specification describes the embodiment of the present invention, and together with the description for solving Release the principle of the present invention.
The present invention can be more clearly understood according to following detailed description referring to attached drawing, in which:
Fig. 1 is a kind of structural schematic diagram of terminal for realizing safety management.
Fig. 2 is a kind of structural schematic diagram of platform for realizing safety management.
Fig. 3 is the structural schematic diagram for the system that the present invention realizes safety management.
Fig. 4 is a kind of flow diagram of method for realizing safety management.
Fig. 5 is a kind of flow diagram of method for realizing safety management.
Specific embodiment
Carry out the various exemplary embodiments of detailed description of the present invention now with reference to attached drawing.It should also be noted that unless in addition having Body explanation, the unlimited system of component and the positioned opposite of step, numerical expression and the numerical value otherwise illustrated in these embodiments is originally The range of invention.
Simultaneously, it should be appreciated that for ease of description, the size of various pieces shown in attached drawing is not according to reality Proportionate relationship draw.
Be to the description only actually of at least one exemplary embodiment below it is illustrative, never as to the present invention And its application or any restrictions used.
Technology, method and apparatus known to person of ordinary skill in the relevant may be not discussed in detail, but suitable In the case of, the technology, method and apparatus should be considered as authorizing part of specification.
It is shown here and discuss all examples in, any occurrence should be construed as merely illustratively, without It is as limitation.Therefore, the other examples of exemplary embodiment can have different values.
It should also be noted that similar label and letter indicate similar terms in following attached drawing, therefore, once a certain Xiang Yi It is defined in a attached drawing, then in subsequent attached drawing does not need that it is further discussed.
The present invention installs Security Services component in terminal side, and terminal is switched on and is in connected state, then Security Services component SE is accessed by the machine card interface between operating system, obtains SEID from the SE, and carries the SEID and platform foundation Connection.Whether the platform judgement has reported the loss with the SE of the SEID, answers if so, sending SE to the Security Services component With lock instruction, and the SE is sent to by the machine card interface and is carried out using locking.To which platform can find corresponding SE simultaneously carries out associated safety processing.
To make the objectives, technical solutions, and advantages of the present invention clearer, below in conjunction with specific embodiment, and reference Attached drawing, the present invention is described in more detail.
Fig. 1 is a kind of structural schematic diagram of terminal for realizing safety management, which includes Security Services component 110, behaviour Make system 120 and security module (SE) 130, in which:
The Security Services component 110 is used to access SE by the machine card interface between operating system, obtains from the SE SEID is taken, the login interface of calling platform automatically logs into platform, and carries the SEID and establish connection with platform.It is referred to herein Platform be, for example, TSM platform.Wherein, SE refers to security module, can secure storage multiple SE application, realize one card for multiple uses.SE can To be independent security module etc. on SIM card, SD card or cell phone mainboard, the SE of SIM card form is provided simultaneously with communication card function.SE Using referring to the applications of IC cards such as bank card, bus card, member card.The SEID is the unique identification of SE, can be unique identification one SE.The SEID is, for example, ICCID (Integrate circuit card identity, the integrated circuit card identification of finished product card Code) or empty calorie sequence number.Standard HTTPS protocol communication is used between the Security Services component 110 and platform, establishes HTTPS Connection.
The operating system 120 is used to provide the machine card interface between the Security Services component.
The SE130 is supplied to the Security Services component for saving the SEID.Wherein, SEID is stored in SE In, when card vendor's fabrication, is written, and can be synchronized to platform, such as TSM platform after the completion of fabrication by telecommunications card pipe platform.That is SE peace SEID is stored in platform.
Wherein, user can be reported the loss by the various ways such as telecom business office, voice progress SE, and user reports the loss rear telecommunications IT system Cell-phone number can be reported the loss state notifying to telecommunication platform by system, and the SE equipment of correspondence SEID is set to the state of reporting the loss by telecommunication platform. Certainly, if it is accidentally reporting the loss, user can hold effective identity certificate to telecom business office cancel loss report.
The platform receives the SEID of Security Services component transmission, judges whether the SE with the SEID has hung It loses, if so, sending SE application lock instruction to the Security Services component, which is, for example, APDU instruction, and is led to Cross the machine card interface be sent to the SE carry out using locking.After SE application locking, SE application cannot be used.
For example, it is public transport application that the SE, which is applied, then user will not pass through brush mobile phone and realize brush public transport POS machine tool, pass through This mode can ensure the safety of the offline wallet fund in user SE, that is, the people for finding the SE cannot use this to report the loss SE。
If locked without SE application, even if the communication function of SE (beats electricity after telecommunications IT system completion cell-phone number is reported the loss Words etc.) it cannot use, what above-mentioned bankcard consumption function still can be used, because the swiping card is that have in partner's POS machine Upper progress.
In this embodiment, the available SEID of the Security Services component of terminal, and be sent to and establish connection with the terminal Platform, send SE application lock instruction from platform to the Security Services component for the SEID terminal reported the loss, and SE answered With locking.It is thus possible to carry out safe handling to SE.
That is, terminal is in the state of booting parallel-connection network, so that it may realize and carry out safe handling to SE.Do not need according to By short message channel, thus the influence that the unstability for reducing short message channel handles terminal security.In addition, terminal is in connection SEID actively can be reported to platform, execute safe handling by platform by net state, then platform does not need to judge Network status and root Safe handling is executed according to Network status, reduces platform and carries out the operation for repeatedly issuing trial under terminal power-off state.In addition, Client in terminal needs not be at logging state, therefore, reduce platform carry out safe handling during for client The dependence at end.
Fig. 2 is a kind of structural schematic diagram of platform for realizing safety management, which includes connection establishment module 210, sentences Disconnected module 220 and instruction issue module 230, which is, for example, TSM platform.Wherein:
The connection establishment module 210 is used to establish connection with the terminal for carrying SEID.
The judgment module 220 is used to judge whether the SE with the SEID has reported the loss.
Described instruction issues module 230 for by security service group of the established connection to the terminal reported the loss Part sends SE application lock instruction.
Wherein, the Security Services component of the terminal accesses SE by machine card interface between operating system, from described SE obtains SEID, and carries the SEID and establish connection with the platform;The Security Services component receives the SE application lock Fixed instruction, and the SE is sent to by the machine card interface and is carried out using locking.
In this embodiment, the available SEID of the Security Services component of terminal, and be sent to and establish connection with the terminal Platform, send SE application lock instruction from platform to the Security Services component for the SEID terminal reported the loss, and SE answered With locking.It is thus possible to carry out safe handling to SE.
That is, terminal is in the state of booting parallel-connection network, so that it may realize and carry out safe handling to SE.Do not need according to By short message channel, thus the influence that the unstability for reducing short message channel handles terminal security.In addition, terminal is in connection SEID actively can be reported to platform, execute safe handling by platform by net state, then platform does not need to judge Network status and root Safe handling is executed according to Network status, reduces platform and carries out the operation for repeatedly issuing trial under terminal power-off state.In addition, Client in terminal needs not be at logging state, therefore, reduce platform carry out safe handling during for client The dependence at end.
The present invention also proposes a kind of system for realizing safety management.The system includes terminal and platform.Wherein, terminal peace Platform is as described above, this will not be detailed here.
In the following with reference to the drawings and specific embodiments, the present invention will be further described.
Fig. 3 is the structural schematic diagram for the system that the present invention realizes safety management.In the system, terminal includes: security service Component 310, operating system 320 and SE330.Here platform is TSM platform 340.
It to business hall or makes a phone call to report the loss using the user of telecommunications NFC mobile phone wallet business, user reports the loss rear telecommunications IT system Cell-phone number can be reported the loss state notifying and give telecommunications TSM platform by system, and the SE equipment of correspondence SEID is set to and reports the loss by telecommunications TSM platform State.
This is reported the loss message informing to using provider (such as bank, public transit system) by telecommunications, using provider by user It is reported the loss using account, such as bank card account.
The Security Services component 310 is used to access SE by the machine card interface between operating system, obtains from the SE SEID is taken, and carries the SEID and establishes connection with TSM platform 340.
The operating system 320 is used to provide the machine card interface between the Security Services component.
The SE330 is supplied to the Security Services component for saving the SEID.
TSM platform 340 is telecommunications side entity, carries out SE application locking processing by short message channel.If it succeeds, completing Locking to SE application.If it fails, for example, user's UIM cartoon telecommunication function is closed or user mobile phone falls without mobile phone The place of signal, the TSM detection of platform Security Services component log-in events, according to the transmission of the Security Services component of login SEID, judges whether the SE with the SEID has reported the loss, if so, sending SE application lock to the Security Services component Fixed instruction, which is APDU instruction, and is sent to the SE by the machine card interface and carries out using locking.SE application After locking, SE application cannot be used.
The present invention can be used for the mobile Internets application system platform such as mobile network, mobile payment, particularly TSM.For example, Implement in China Telecom's mobile phone wallet business and apply, solves the mistake of user mobile phone wallet UIM jam and the operational administrative of SE is asked Topic improves the safety of various SE applications in user UIM card.It can be also used for aerial hair fastener, SE parameter over-the-air updating etc..
Fig. 4 is a kind of flow diagram of method for managing security.Method includes the following steps:
In step 410, terminal is switched on, and the Security Services component in the terminal is in operating status.
It in step 420, detects whether the terminal is in connected state, if so, executing step 430, otherwise, terminates.
In step 430, the Security Services component accesses SE by the machine card interface between operating system, from the SE Obtain SEID.Wherein, the SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code of finished product card (ICCID) or the sequence number of empty calorie.
In step 440, the Security Services component carries the SEID and platform establishes connection.Wherein, the platform is sentenced Whether the disconnected SE with the SEID has reported the loss, if so, continuing to execute step 450, otherwise, terminates process.
In step 450, the Security Services component receives the SE application lock instruction that the platform is sent, and by described Machine card interface is sent to the SE and carries out using locking.
In this embodiment, the available SEID of the Security Services component of terminal, and be sent to and establish connection with the terminal Platform, send SE application lock instruction from platform to the Security Services component for the SEID terminal reported the loss, and SE answered With locking.It is thus possible to carry out safe handling to SE.
That is, terminal is in the state of booting parallel-connection network, so that it may realize and carry out safe handling to SE.Do not need according to By short message channel, thus the influence that the unstability for reducing short message channel handles terminal security.In addition, terminal is in connection SEID actively can be reported to platform, execute safe handling by platform by net state, then platform does not need to judge Network status and root Safe handling is executed according to Network status, reduces platform and carries out the operation for repeatedly issuing trial under terminal power-off state.In addition, Client in terminal needs not be at logging state, therefore, reduce platform carry out safe handling during for client The dependence at end.
Fig. 5 is a kind of flow diagram of method for managing security.Method includes the following steps:
In step 510, platform and the terminal for carrying SEID establish connection.Wherein, the SEID is the unique identification of SE, institute State the sequence number of the integrated circuit card identification code (ICCID) that SEID is finished product card or empty calorie.
In step 520, judge whether the SE with the SEID has reported the loss, if reported the loss, execute step 530, Otherwise, terminate.
In step 530, SE application is sent to the Security Services component for the terminal reported the loss by the connection established Lock instruction.
Wherein, the Security Services component of the terminal accesses SE by machine card interface between operating system, from described SE obtains SEID, and carries the SEID and establish connection with the platform;The Security Services component receives the SE application lock Fixed instruction, and the SE is sent to by the machine card interface and is carried out using locking.
In this embodiment, the available SEID of the Security Services component of terminal, and be sent to and establish connection with the terminal Platform, send SE application lock instruction from platform to the Security Services component for the SEID terminal reported the loss, and SE answered With locking.It is thus possible to carry out safe handling to SE.
That is, terminal is in the state of booting parallel-connection network, so that it may realize and carry out safe handling to SE.Do not need according to By short message channel, thus the influence that the unstability for reducing short message channel handles terminal security.In addition, terminal is in connection SEID actively can be reported to platform, execute safe handling by platform by net state, then platform does not need to judge Network status and root Safe handling is executed according to Network status, reduces platform and carries out the operation for repeatedly issuing trial under terminal power-off state.In addition, Client in terminal needs not be at logging state, therefore, reduce platform carry out safe handling during for client The dependence at end.
Below by a specific embodiment, the present invention will be further described.
It to business hall or makes a phone call to report the loss using the user of telecommunications NFC mobile phone wallet business, user reports the loss rear telecommunications IT system Cell-phone number can be reported the loss state notifying and give telecommunications TSM platform by system, and the SE equipment of correspondence SEID is set to and reports the loss by telecommunications TSM platform State.
User mobile phone booting, Security Services component starting, Security Services component are periodically detected, and detect user hand Interconnection plane, then Security Services component accesses SE by the machine card interface between operating system, obtains SEID in current phone, with TSM platform establishes connection.
This is reported the loss message informing to using provider (such as bank, public transit system) by telecommunications.
Account, such as bank card account is applied to report the loss user using provider.
TSM platform is telecommunications side entity, carries out SE application locking processing by short message channel.If it succeeds, completion pair The locking of SE application.
If it fails, for example, user's UIM cartoon telecommunication function is closed or user mobile phone falls on the ground of not mobile phone signal Side, TSM detection of platform Security Services component log-in events, that is, whether have Security Services component with SEID identity logs to be reported the loss TSM platform has been arrived, according to the SEID that the Security Services component of login transmits, has judged whether the SE with the SEID has hung It loses, if so, sending SE application lock instruction to the Security Services component, which is APDU instruction, and passes through institute The machine card interface of stating is sent to the SE and carries out using locking.After SE application locking, SE application cannot be used.Otherwise, TSM etc. It is accessed to the SE.
So far, the present invention is described in detail.In order to avoid covering design of the invention, it is public that this field institute is not described The some details known.Those skilled in the art as described above, completely it can be appreciated how implementing technology disclosed herein Scheme.
Method and device of the invention may be achieved in many ways.For example, can by software, hardware, firmware or Person's software, hardware, firmware any combination realize method and device of the invention.The step of for the method it is above-mentioned Sequence is merely to be illustrated, and the step of method of the invention is not limited to sequence described in detail above, unless with other sides Formula illustrates.In addition, in some embodiments, the present invention can be also embodied as recording program in the recording medium, these Program includes for realizing machine readable instructions according to the method for the present invention.Thus, the present invention also covers storage for executing The recording medium of program according to the method for the present invention.
Although some specific embodiments of the invention are described in detail by example, the skill of this field Art personnel it should be understood that above example merely to being illustrated, the range being not intended to be limiting of the invention.The skill of this field Art personnel are it should be understood that can without departing from the scope and spirit of the present invention modify to above embodiments.This hair Bright range is defined by the following claims.

Claims (6)

1. a kind of terminal for realizing safety management, which is characterized in that including Security Services component, operating system and security module (SE), in which:
The Security Services component is used to access SE by the machine card interface between operating system, obtains SEID from the SE, And it carries the SEID and establishes connection with platform;
The operating system is used to provide the machine card interface between the Security Services component;
The SE is supplied to the Security Services component for saving the SEID;
Wherein, whether the platform judgement has reported the loss with the SE of the SEID, if so, to the Security Services component SE application lock instruction is sent, and the SE is sent to by the machine card interface and is carried out using locking;
Wherein, the platform is that trusted service manages platform;
The SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code (ICCID) or empty calorie of finished product card Sequence number.
2. a kind of platform for realizing safety management, which is characterized in that issued including connection establishment module, judgment module and instruction Module, in which:
The connection establishment module is used to establish connection with the terminal for carrying SEID;
The judgment module is used to judge whether the SE with the SEID has reported the loss;
Described instruction issue module for by established connection to the Security Services component for the terminal reported the loss transmission SE application lock instruction;
Wherein, the Security Services component of the terminal accesses SE by the machine card interface between operating system, obtains from the SE SEID is taken, and carries the SEID and establishes connection with the platform;The Security Services component receives the SE and refers to using locking It enables, and the SE is sent to by the machine card interface and is carried out using locking;
Wherein, the platform is that trusted service manages platform;
The SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code (ICCID) or empty calorie of finished product card Sequence number.
3. a kind of system for realizing safety management, including terminal as described in claim 1 and platform as claimed in claim 2.
4. a kind of method for realizing safety management characterized by comprising
Terminal is switched on, and the Security Services component in the terminal is in operating status, and detects whether the terminal is in networking State obtains if it is, the Security Services component accesses SE by the machine card interface between operating system from the SE SEID;
The Security Services component carries the SEID and platform establishes connection;
Wherein, whether the platform judgement has reported the loss with the SE of the SEID, if so, to the Security Services component SE application lock instruction is sent, and the SE is sent to by the machine card interface and is carried out using locking;
Wherein, the platform is that trusted service manages platform;
The SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code (ICCID) or empty calorie of finished product card Sequence number.
5. a kind of method for realizing safety management characterized by comprising
Platform and the terminal for carrying SEID establish connection;
Judge whether reported the loss with the SE of the SEID, if reported the loss, by established connection to having reported the loss The terminal Security Services component send SE application lock instruction;
Wherein, the Security Services component of the terminal accesses SE by the machine card interface between operating system, obtains from the SE SEID is taken, and carries the SEID and establishes connection with the platform;The Security Services component receives the SE and refers to using locking It enables, and the SE is sent to by the machine card interface and is carried out using locking;
Wherein, the platform is that trusted service manages platform;
The SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code (ICCID) or empty calorie of finished product card Sequence number.
6. a kind of method for realizing safety management characterized by comprising
Terminal is switched on, and the Security Services component in the terminal is in operating status;
Detect whether the terminal is in connected state, if it is, the Security Services component passes through between operating system Machine card interface access SE, from the SE obtain SEID;
The Security Services component carries the SEID and platform establishes connection;
Whether the platform judgement has reported the loss with the SE of the SEID, if so, sending to the Security Services component SE application lock instruction, and the SE is sent to by the machine card interface and is carried out using locking;
Wherein, the platform is that trusted service manages platform;
The SEID is the unique identification of SE, and the SEID is the integrated circuit card identification code (ICCID) or empty calorie of finished product card Sequence number.
CN201410277358.9A 2014-06-20 2014-06-20 A kind of method that realizing safety management, terminal, platform and system Active CN105323746B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201410277358.9A CN105323746B (en) 2014-06-20 2014-06-20 A kind of method that realizing safety management, terminal, platform and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201410277358.9A CN105323746B (en) 2014-06-20 2014-06-20 A kind of method that realizing safety management, terminal, platform and system

Publications (2)

Publication Number Publication Date
CN105323746A CN105323746A (en) 2016-02-10
CN105323746B true CN105323746B (en) 2019-01-22

Family

ID=55250163

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201410277358.9A Active CN105323746B (en) 2014-06-20 2014-06-20 A kind of method that realizing safety management, terminal, platform and system

Country Status (1)

Country Link
CN (1) CN105323746B (en)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110768696B (en) * 2018-07-26 2021-06-18 ***通信有限公司研究院 NFC SIM card identification method and device
CN111669426B (en) * 2020-04-20 2021-12-07 河南芯盾网安科技发展有限公司 Method and system for sharing security carrier by cross-platform terminals

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1541015A (en) * 2003-10-31 2004-10-27 大唐微电子技术有限公司 Method and system of preventing handset from theft by using international id code of mobile facilities
CN1801869A (en) * 2005-01-06 2006-07-12 杭州波导软件有限公司 Anti-theft method for mobile communication terminal and its anti-theft system
CN101183469A (en) * 2006-11-14 2008-05-21 中兴通讯股份有限公司 Method of loss report and anti-fraudulent use for electronic purse
CN103699997A (en) * 2013-12-27 2014-04-02 Tcl集团股份有限公司 Method, device and electronic equipment for locking mobile payment service

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1541015A (en) * 2003-10-31 2004-10-27 大唐微电子技术有限公司 Method and system of preventing handset from theft by using international id code of mobile facilities
CN1801869A (en) * 2005-01-06 2006-07-12 杭州波导软件有限公司 Anti-theft method for mobile communication terminal and its anti-theft system
CN101183469A (en) * 2006-11-14 2008-05-21 中兴通讯股份有限公司 Method of loss report and anti-fraudulent use for electronic purse
CN103699997A (en) * 2013-12-27 2014-04-02 Tcl集团股份有限公司 Method, device and electronic equipment for locking mobile payment service

Also Published As

Publication number Publication date
CN105323746A (en) 2016-02-10

Similar Documents

Publication Publication Date Title
US11216549B2 (en) Security verification method and device
CN106453330B (en) A kind of identity authentication method and system
CN104468611B (en) The data safety processing method and device switched based on dual system
US8718602B2 (en) Method and system for remote control of smart card
CN109905312A (en) Information push method, apparatus and system
CN101521886B (en) Method and device for authenticating terminal and telecommunication smart card
CN101499190B (en) Security management method, system and apparatus for electronic purse
CN104901805B (en) A kind of identification authentication methods, devices and systems
CN105992125B (en) Method and device for protecting safety of electronic equipment
CN107404740B (en) Method for switching network, device and the terminal device of safety
JP2019510316A (en) Method and device for providing account linking and service processing
CN104700021A (en) Remote unlocking method and system
TWI526936B (en) Change the way smart card application type, intelligent terminal, service level Taiwan and systems
CN106031050A (en) Information processing method and NFC terminal
CN112987942B (en) Method, device and system for inputting information by keyboard, electronic equipment and storage medium
CN105721511A (en) Identity verifying method of mobile terminal
CN105323746B (en) A kind of method that realizing safety management, terminal, platform and system
CN106779662A (en) The processing method and financial terminal of a kind of financial business
CN101699915B (en) Mainboard, method for realizing network locking/ card locking function and mobile terminal
CN106209735A (en) A kind of information processing method, device and Electronic Health Record system
CN105894624A (en) Method, device and system for controlling opening of gate
CN104361304A (en) Method and device for downloading application program of smart card
CN103136881A (en) Payment method and payment system
CN105873018B (en) A kind of virtual SIM card information storage means and system
CN109324843A (en) A kind of finger prints processing system, method and fingerprint equipment

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant