WO2016023199A1 - 一种安全域管理方法、装置及*** - Google Patents

一种安全域管理方法、装置及*** Download PDF

Info

Publication number
WO2016023199A1
WO2016023199A1 PCT/CN2014/084307 CN2014084307W WO2016023199A1 WO 2016023199 A1 WO2016023199 A1 WO 2016023199A1 CN 2014084307 W CN2014084307 W CN 2014084307W WO 2016023199 A1 WO2016023199 A1 WO 2016023199A1
Authority
WO
WIPO (PCT)
Prior art keywords
security domain
request message
sub
identifier
management
Prior art date
Application number
PCT/CN2014/084307
Other languages
English (en)
French (fr)
Inventor
常新苗
李国庆
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to EP14899640.8A priority Critical patent/EP3171566B1/en
Priority to CN201480075787.6A priority patent/CN106031119B/zh
Priority to US15/503,317 priority patent/US10270811B2/en
Priority to PCT/CN2014/084307 priority patent/WO2016023199A1/zh
Publication of WO2016023199A1 publication Critical patent/WO2016023199A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/04Network management architectures or arrangements
    • H04L41/046Network management architectures or arrangements comprising network management agents or mobile agents therefor
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • H04L41/0806Configuration setting for initial configuration or provisioning, e.g. plug-and-play
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/02Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/35Protecting application or service provisioning, e.g. securing SIM application provisioning

Definitions

  • the present invention relates to the field of communications, and in particular, to a security domain management method, apparatus, and system. Background technique
  • the mobile communication system uses smart cards to store user identity, user authentication parameters (keys, etc.) and algorithms, user's phone book and SMS data, and operator's customized parameters to facilitate the user identity and user data inclusiveness. And the differentiated customization between the operators, the smart card includes a SIM (Subscriber Identity Module) card, a USIM (Universal Subscriber Identity Module) card, and a RUIM (Removable User Identity Module) ) Cards, etc.
  • SIM Subscriber Identity Module
  • USIM Universal Subscriber Identity Module
  • RUIM Removable User Identity Module
  • Mobile payment services require security chips to store and manage payment applications and data that require high security (such as user IDs and keys). , attribute parameters and related applications).
  • the security chip can be placed on the mobile phone motherboard, the near field communication chip, and the secure digital card. It is common to integrate the security chip into a smart card such as a Universal Integrated Circuit Card (UICC), and An independent security domain match in an integrated circuit card that is dedicated to storing and managing applications and data with high security requirements related to payment and the like.
  • UICC Universal Integrated Circuit Card
  • eUICC embedded Universal Integrated Circuit Card
  • the requirements for eUICC include at least: The ability to create a mobile network operator (MNO) subscription data on an embedded universal integrated circuit card, and to enable embedded general-purpose integrated power
  • MNO mobile network operator
  • the configuration information and the security domain of the service are added to the subscription data of the mobile network operator of the road card to manage the security domain for storing the first service configuration information.
  • An embodiment of the present invention provides a security domain management method, apparatus, and system, which can manage a security domain for storing service configuration information according to a service state of a user subscription service.
  • a communication terminal where a mobile network operator configuration file is pre-configured, and the communication terminal includes: an acquiring unit, And a method for acquiring a management request message, where the management request message includes an issuer security domain configuration file identifier;
  • the management request message includes a configuration request message, where the management sub-security domain includes creating a sub-security domain;
  • the acquiring unit is configured to: when the first service is newly signed, obtain a configuration request message, where the configuration request message includes the issuer security domain configuration file identifier and configuration information of the first service, where The configuration information of a service includes an application and data of the first service;
  • the management unit is configured to create a sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier included in the configuration request message acquired by the acquiring unit, and
  • the configuration information of the first service is stored in the sub-security domain;
  • the communication terminal further includes:
  • the communications terminal further includes: a first sending unit, configured to send a configuration response message, where the configuration response message includes the And assigning an identifier of the sub-security domain allocated by the unit, so that the server manages the sub-security domain according to the configuration response message.
  • the management request message includes a deletion request message
  • the management sub-security domain includes a deletion sub-security domain
  • the acquiring unit is specifically configured to be in the first Obtaining a delete request message, where the delete request message includes the issuer security domain configuration file identifier and the identifier of the child security domain; the management unit is specifically configured to use the deletion obtained by the acquiring unit And deleting the identifier of the issuer security domain profile and the identifier of the child security domain, and deleting the child security domain in the mobile network operator profile corresponding to the issuer security domain profile identifier.
  • the communication terminal further includes: a detecting unit, configured to detect, according to the issuer security domain profile identifier and the identifier of the child security domain, that are included in the deletion request message acquired by the acquiring unit The application and the data to be saved in the child security domain; the second sending unit is configured to send a save request message, where the save request message includes the application and data that are to be saved by the detecting unit, so that the server saves according to the save The request message saves the application and the data to be saved; the management unit is specifically configured to: after the sending, send, by the second sending unit, the issuer security domain configuration file acquired by the acquiring unit The identifier and the identifier of the sub-security domain are deleted, and the application and data corresponding to the issuer security domain profile identifier are deleted.
  • the communications terminal further includes: a third sending unit, configured to delete the sub After the security domain, the delete response message is sent, where the delete response message includes the sub-security domain deletion success status information and the identifier of the sub-security domain deleted by the management unit.
  • the acquiring unit is further configured to acquire an activation request message;
  • the acquiring unit is further configured to: acquire the user instruction according to the activation request message acquired by the acquiring unit;
  • the communication terminal further includes: a changing unit, where the user instruction acquired by the acquiring unit is activated And instructing to change the state of the mobile network operator profile to an active state;
  • the fourth sending unit is configured to send the activation response message, where the activation response message includes the mobile network operation changed by the change unit The status of the quotient profile.
  • the second aspect provides a server, where the server may be pre-configured with a mobile network operator configuration file, where the server includes: a sending unit, configured to send a query request message to the subscription management security route, where the query request message includes The identifier of the subscription management security route and the identifier of the embedded integrated circuit card; the obtaining unit, configured to acquire the query response message sent by the subscription management security route, where the query response message includes an issuer of the mobile network operator configuration file a security domain profile identifier and a status of the mobile network operator profile; a checking unit, configured to check a status of the mobile network operator profile included in the query response message acquired by the acquiring unit; And a unit, configured to send a management request message when the state of the mobile network operator profile included in the query response message checked by the checking unit is an active state, so that the communication terminal manages the child security according to the management request message.
  • Domain wherein the configuration request message The issuer security domain containing a profile identifier, the sub-security domain configuration information storing first service.
  • the management request message includes a configuration request message, where the management sub-security domain includes creating a sub-security domain;
  • the sending unit is further configured to send a management request message when the state of the mobile network operator profile included in the query response message checked by the checking unit is an active state, so that the communication terminal according to the management request message
  • the management sub-security domain wherein the configuration request message includes the issuer security domain profile identifier, where the sub-security domain is configured to store configuration information of the first service, specifically:
  • the communication terminal Transmitting a configuration request message when the status of the mobile network operator profile included in the query response message checked by the first service is new, and the communication terminal sends a configuration request message according to the management request message Creating a child security domain, where the configuration request message includes the issuer security domain profile identifier and configuration information of the first service, and the configuration information of the first service includes application information of the first service and data.
  • the acquiring unit is further configured to obtain a configuration response message, where the configuration response message includes an identifier of a sub-security domain;
  • the server further includes: a configuration unit, configured to record the identifier of the sub-security domain acquired by the acquiring unit in the mobile network operator configuration file corresponding to the issuer security domain profile identifier.
  • the sending unit is further configured to record, in the configuration unit, the identifier of the sub-security domain in the issuer After the security domain profile identifies the corresponding mobile network operator profile, sending a first update request message to the subscription management security route, where the first update request message includes the mobile network operator configuration The configuration information of the file, so that the subscription management security route updates the configuration information of the mobile network operator profile according to the first update request message, where the configuration information of the mobile network operator profile includes a mobile network operator configuration File type, version, and sub-security domain information.
  • the management request message includes a deletion request message
  • the management sub-security domain includes a deletion sub-security domain
  • the acquiring unit is further configured to be in the first Obtain the identifier of the child security domain when the service ends;
  • the sending unit is further configured to send a management request message when the state of the mobile network operator profile included in the query response message checked by the checking unit is an active state, so that the communication terminal according to the management request message
  • the management sub-security domain wherein the configuration request message includes the issuer security domain profile identifier, where the sub-security domain is configured to store configuration information of the first service, specifically:
  • the terminal deletes the sub-security domain according to the management request message, where the deletion request message includes the issuer security domain profile identifier and the identifier of the sub-security domain.
  • the acquiring unit is further configured to obtain a save request message, where the save request message includes an application and data to be saved;
  • the server further includes: a saving unit, configured to save the application and data to be saved according to the save request message acquired by the acquiring unit.
  • the acquiring unit is further configured to obtain a deletion response message, where the deletion response message includes a sub-security domain deletion The success status information and the identifier of the deleted sub-security domain;
  • the server further includes: a configuration unit, configured to delete the sub-security domain deletion success status message obtained by the obtaining unit, and the deleted sub- The identity of the security domain, deleting the identity of the child security domain in the mobile network operator profile.
  • the sending unit is further configured to delete the sub-security in the mobile network operator configuration file in the configuration unit
  • the second update request message is sent to the subscription management security route, where the second update request message includes the mobile network operation in which the identifier of the sub-security domain is deleted by the configuration unit.
  • the configuration information of the quotient configuration file so that the subscription management security route updates the configuration information of the mobile network operator configuration file according to the second update request message.
  • the sending unit is further configured to include, by the check unit, the query response message The status of the mobile network operator profile is not activated.
  • Sending an activation request message ;
  • the obtaining unit is further configured to acquire an activation response message, where the activation response message includes a state of the mobile network operator configuration file;
  • the checking unit is further configured to check the acquiring unit Acquiring the status of the mobile network operator profile included in the activation response message;
  • the sending unit is further configured to: the mobile network operator profile included in the activation response message checked by the checking unit The status is sent when the management request message is sent.
  • a communication terminal in a third aspect, includes: a network interface, a processor, and a bus, where the network interface and the processor are connected to each other through the bus.
  • the network interface is configured to obtain a management request message, where the management request message includes an issuer security domain configuration file identifier, and the processor is configured to include, in the configuration request message acquired by the network interface,
  • the sub-security domain is configured to store configuration information of the first service, where the sub-security domain is configured.
  • the management request message includes a configuration request message, where the management sub-security domain includes creating a sub-security domain;
  • the network interface is configured to acquire a configuration request message when the first service is newly signed, where the configuration request message includes the issuer security domain configuration file identifier and configuration information of the first service, where The configuration information of a service includes an application and data of the first service;
  • the processor is configured to create a sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier included in the configuration request message acquired by the network interface, and The configuration information of the first service is stored in the sub-security domain;
  • the processor is further configured to manage the sub-security domain according to the identifier of the sub-security domain allocated by the processor.
  • the network interface is further configured to send a configuration response message, where the configuration response message includes the An identifier of the child security domain, such that the server manages the child security domain according to the configuration response message.
  • the management request message includes a deletion request message
  • the management sub-security domain includes a deletion sub-security domain
  • the network interface is specifically configured to be in the first Obtaining a delete request message, where the delete request message includes the issuer security domain configuration file identifier and the identifier of the child security domain; the processor is specifically configured to be used according to the network interface to obtain the deletion. And deleting the identifier of the issuer security domain profile and the identifier of the child security domain, and deleting the child security domain in the mobile network operator profile corresponding to the issuer security domain profile identifier.
  • the processor is further configured to use the issuer security included in the deletion request message acquired according to the network interface
  • the domain profile identifier and the identifier of the child security domain are detected, and the application and data to be saved in the child security domain are detected
  • the network interface is further configured to send a save request message, where the save request message includes the processor
  • the application and the data to be saved are detected, so that the server saves the application and the data to be saved according to the save request message
  • the processor is specifically configured to: after the network interface sends the save request message, Deleting the shift corresponding to the issuer security domain profile identifier according to the issuer security domain profile identifier and the identifier of the child security domain acquired by the network interface Use and data.
  • the network interface is further configured to send and delete after the processor deletes the sub-security domain And a reply message, where the delete response message includes a sub-security domain deletion success status information and an identifier of the sub-security domain deleted by the processor.
  • the network interface is further configured to acquire an activation request message;
  • the network interface is further configured to acquire a user instruction according to the activation request message acquired by the network interface, where the processor is further configured to: when the user instruction acquired by the network interface is an activation instruction, The state of the mobile network operator profile is changed to an active state; the network interface is further configured to send the activation response message, where the activation response message includes the mobile network operator profile changed by the processor status.
  • a server in a fourth aspect, includes: a network interface, a processor, and a bus, where the network interface and the processor are connected to each other through the bus, where the network interface is used to The subscription management security route sends a query request message, where the query request message includes the identifier of the subscription management security route and the identifier of the embedded integrated circuit card; the network interface is further configured to obtain the query sent by the subscription management security route a response message, where the query response message includes an issuer security domain profile identifier of the mobile network operator profile and a state of the mobile network operator profile; the processor is configured to check the location obtained by the network interface The status of the mobile network operator profile included in the query response message; the network interface is further configured to: the status of the mobile network operator profile included in the query response message checked by the processor is Sending a management request message when the state is activated, so that the communication terminal according to the tube Request message management sub-security domain, where The configuration request message includes the issuer security domain profile identifier, and the child security
  • the network interface is further configured to send a management request message when the state of the mobile network operator profile included in the query response message checked by the processor is an active state, so that the communication terminal according to the management request message
  • the management sub-security domain where the configuration request message includes the issuer security domain configuration file identifier, where the sub-security domain is used to store configuration information of the first service, specifically:
  • the network interface is further configured to obtain a configuration response message, where the configuration response message includes an identifier of a sub-security domain;
  • the processor is further configured to record the identifier of the sub-security domain acquired by the network interface in the mobile network operator configuration file corresponding to the issuer security domain profile identifier.
  • the network interface is further configured to record, in the processor, the identifier of the sub-security domain on the issuer After the security domain profile identifies the corresponding mobile network operator profile, sending a first update request message to the subscription management security route, where the first update request message includes the mobile network operator configuration Configuration information of the file, so that the subscription management security route updates configuration information of the mobile network operator configuration file according to the first update request message, where the mobile network operates
  • the configuration information of the quotient profile contains the type, version, and sub-security domain information of the mobile network operator profile.
  • the management request message includes a deletion request message, where the management sub-security domain includes deleting a sub-security domain, and the network interface is further used in the first Obtain the identifier of the child security domain when the service ends;
  • the network interface is further configured to send a management request message when the state of the mobile network operator profile included in the query response message checked by the processor is an active state, so that the communication terminal according to the management request message
  • the management sub-security domain where the configuration request message includes the issuer security domain configuration file identifier
  • the sub-security domain is configured to store configuration information of the first service, specifically: Sending a delete request message when the status of the mobile network operator profile included in the query response message is an active state, so that the communication terminal deletes the child security domain according to the management request message, where the delete request message includes the issuer
  • the security domain profile identifier and the identity of the child security domain is
  • the network interface is further configured to obtain a save request message, where the save request message includes an application and data to be saved;
  • the server further includes: a memory, wherein the memory is connected to the network interface and the processor through the bus; the memory is configured to save the requirement according to the save request message acquired by the network interface Saved apps and data.
  • the network interface is further configured to obtain a deletion response message, where the deletion response message includes a sub-security domain deletion Success status information and the identity of the deleted sub-security domain;
  • the processor is further configured to delete the sub-security domain deletion success status letter, the IT, and the deleted sub-security domain identifier obtained by the network interface, and delete the mobile network transport The identity of the child security domain in the business profile.
  • the network interface is further configured to delete, in the processor, the sub-security in the mobile network operator configuration file After the identifier of the domain, the second update request message is sent to the subscription management security route, where the second update request message includes the mobile network operation that is deleted by the processor by the identifier of the sub-security domain The configuration information of the quotient configuration file, so that the subscription management security route updates the configuration information of the mobile network operator configuration file according to the second update request message.
  • the network interface is further configured to include, by the processor, the query response message Sending an activation request message when the status of the mobile network operator profile is an inactive state;
  • the network interface is further configured to obtain an activation response message, where the activation response message includes a status of the mobile network operator configuration file, and the processor is further configured to check the activation response message acquired by the network interface. a status of the mobile network operator profile included; the network interface is further configured to send when the status of the mobile network operator profile included in the activation response message checked by the processor is an active state Manage request messages.
  • the fifth aspect provides a security domain management method, where the mobile network operator configuration file is pre-configured, and the security domain management method includes: acquiring a management request message, where the management request message includes an issuer security domain configuration file identifier. And managing the sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain configuration file identifier, where the sub-security domain is configured to store configuration information of the first service.
  • the management request message includes a configuration request message, where the management sub-security domain includes creating a sub-security domain, and acquiring a management request message when the first service is newly signed
  • the management request cancellation includes the issuer security domain configuration file identifier, and specifically includes:
  • Obtaining a configuration request message where the configuration request message includes an issuer security domain profile identifier of the mobile network operator profile and configuration information of the first service, where the configuration information of the first service includes the first
  • the application and the data of the service are configured to manage the sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain configuration file identifier, where the sub-security domain is configured to store the configuration information of the first service, specifically:
  • the security domain management method further includes: assigning an identifier to the child security domain; and managing the child security domain according to the identifier of the child security domain.
  • the security domain management method further includes: sending a configuration response message, where the configuration The response message includes an identifier of the child security domain, so that the server manages the child security domain according to the configuration response message.
  • the management request message includes a deletion request message, where the management sub-security domain includes deleting a sub-security domain, and acquiring a management request message when the first service is terminated.
  • the management request is deleted, and includes an issuer security domain configuration file identifier, which specifically includes:
  • the delete request message includes the issuer security domain profile identifier and the identifier of the child security domain; And managing the sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier, where the sub-security domain is configured to store the configuration information of the first service, specifically: according to the deletion request message And including the identifier of the issuer security domain profile and the identifier of the child security domain, and deleting the child security domain in the mobile network operator profile corresponding to the issuer security domain profile identifier.
  • the issuer security domain configuration file identifier and the identifier of the sub-security domain included in the deletion request message are deleted.
  • the method further includes: according to the issuer security domain configuration file included in the deletion request message Identifying an identifier of the sub-security domain, detecting an application and data to be saved in the sub-security domain; sending a save request message, where the save request message includes the application and data to be saved, so that the server saves according to the save The request message saves the application and data to be saved; and according to the issuer security domain profile identifier and the identifier of the child security domain included in the deletion request message, deleting the identifier corresponding to the issuer security domain profile identifier
  • the sub-security domain in the mobile network operator configuration file specifically includes: After the request message is saved, the mobile network operator configuration corresponding to the issuer security domain profile identifier is deleted according to the issuer security domain profile identifier and the identifier of the child security domain included in the delete request message. Said in the file
  • the method further includes: after deleting the sub-security domain, sending a delete response message, where the deleting Reply message Contains the sub-security domain deletion success status information and the identity of the sub-security domain.
  • the method before the acquiring the management request message, the method further includes: acquiring an activation request message; The activation request message acquires a user instruction; when the user instruction is an activation instruction, changing a state of the mobile network operator profile to an activation state; sending the activation response message, where the activation response message includes the The status of the mobile network operator profile.
  • the sixth aspect provides a security domain management method, where the mobile network operator configuration file is pre-configured, and the method includes: sending a query request message to the subscription management security route, where the query request message includes the subscription management security And the identifier of the embedded integrated circuit card; obtaining the query response message sent by the subscription management security route, where the query response message includes an issuer security domain profile identifier of the mobile network operator profile and the mobile network a status of the operator profile; checking a status of the mobile network operator profile included in the query response message;
  • the management request message includes a configuration request message, where the management sub-security domain includes creating a sub-security domain, and the mobile network operation included in the query response message Business profile Transmitting a management request message when the state is an active state, so that the communication terminal manages the child security domain according to the management request message, where the configuration request message includes the issuer security domain profile identifier, and the child security domain is used for storing
  • the configuration information of the first service includes:
  • the configuration request message includes the issuer security domain profile identifier and the configuration information of the first service, and the configuration information of the first service includes application information and data of the first service.
  • the method includes:
  • the configuration response message includes an identifier of the child security domain; and the identifier of the child security domain is recorded in the mobile network operator configuration file corresponding to the issuer security domain profile identifier.
  • the identifier of the sub-security domain is recorded in the mobile network operator corresponding to the issuer security domain profile identifier
  • the request message updates configuration information of the mobile network operator profile, where the configuration information of the mobile network operator profile includes a type, a version, and sub-security domain information of the mobile network operator profile.
  • the management request message includes a deletion request message, where the management sub-security domain includes deleting a sub-security domain;
  • the method further includes: before the sub-security domain is configured to store configuration information of the first service Obtain the identifier of the child security domain when the service ends;
  • the issuer security domain configuration file identifier is used to store the configuration information of the first service, which specifically includes:
  • the method further includes:
  • the save request message including an application and data to be saved
  • the application and data to be saved are saved according to the save request message.
  • the method further includes: acquiring a deletion response message, where the deletion response message includes a sub-security domain deletion success status And the identifier of the deleted sub-security domain; deleting the identifier of the sub-security domain in the mobile network operator profile according to the sub-security domain deletion success status information and the deleted sub-security domain identifier .
  • deleting the mobile network according to the sub-security domain deletion success status information and the deleted sub-security domain identifier The identity of the sub-security domain in the carrier profile
  • the method further includes: after deleting the identifier of the sub-security domain in the mobile network operator configuration file, sending a second update request message to the subscription management security route; wherein the second update request The message includes configuration information of the mobile network operator profile in which the identifier of the sub-security domain is deleted, so that the subscription management security route updates the mobile network operator profile according to the second update request message. Configuration information.
  • the method before the obtaining the management response message, the method further includes:
  • the security domain management method, device and system provided by the present invention can obtain a management request message by using a communication terminal, wherein the management request message includes the issuer security domain profile identifier, and then the communication terminal is in the release
  • the party security domain profile identifies the managed child security domain in the corresponding mobile network operator profile.
  • the management request message includes a configuration request message, the management sub-security domain includes a sub-security domain, and the configuration request message further includes configuration information of the first service, where the first service may be newly signed.
  • the configuration information of the service is stored in the sub-security domain; the management request message includes a deletion request message, the management sub-security domain includes a deletion sub-security domain, and the deletion request message includes an identifier of the sub-security domain.
  • the deletion of the sub-security domain may be implemented according to the identifier of the sub-security domain. Therefore the present invention provides The security domain management method, apparatus, and system can manage the security domain for storing the first service configuration information according to the service status of the user subscription service.
  • FIG. 1 is a schematic diagram of a system of a security domain management system according to an embodiment of the present invention
  • FIG. 2 is a schematic structural diagram of a communication terminal according to an embodiment of the present invention
  • FIG. 3 is a schematic structural diagram of another communication terminal according to an embodiment of the present invention
  • FIG. 4 is another schematic diagram of an embodiment of the present invention.
  • FIG. 5 is a schematic structural diagram of still another communication terminal according to an embodiment of the present invention
  • FIG. 6 is a schematic structural diagram of a communication terminal according to an embodiment of the present invention
  • FIG. 8 is a schematic structural diagram of another communication terminal according to an embodiment of the present invention
  • FIG. 9 is a schematic structural diagram of a server according to an embodiment of the present invention
  • 10 is a schematic structural diagram of another server according to an embodiment of the present invention
  • FIG. 11 is a schematic structural diagram of another server according to an embodiment of the present invention
  • FIG. 12 is a subscription management according to an embodiment of the present invention.
  • Schematic diagram of a secure route
  • FIG. 13 is a schematic structural diagram of another contract management security route according to an embodiment of the present invention
  • FIG. 14 is a schematic structural diagram of a trusted service manager according to an embodiment of the present invention
  • FIG. 15 is a schematic structural diagram of a communication terminal according to still another embodiment of the present invention.
  • FIG. 16 is a schematic structural diagram of a server according to still another embodiment of the present invention
  • FIG. 17 is a schematic structural diagram of a contract management security route according to another embodiment of the present invention
  • FIG. 19 is a schematic diagram of a security domain management method according to an embodiment of the present invention
  • FIG. 20 is a schematic diagram of a security domain management method according to another embodiment of the present invention
  • the flow of the management method is as follows:
  • FIG. 22 is a flowchart of another method for managing a security domain according to another embodiment of the present invention.
  • FIG. 22 is still another method for managing a security domain according to another embodiment of the present invention.
  • FIG. 23 is a flow chart of a method for managing a security domain according to still another embodiment of the present invention.
  • FIG. 24 is a flowchart showing still another method for managing a security domain according to still another embodiment of the present invention.
  • 25 is a schematic flowchart of a security domain management method provided by an embodiment of the present invention.
  • 26 is a schematic flow chart of a security domain management method according to an embodiment of the present invention.
  • FIG. 27 is a schematic diagram of data interaction of a security domain management method according to an embodiment of the present invention
  • FIG. 28 is a schematic diagram of data interaction of another security domain management method according to an embodiment of the present invention
  • FIG. 29 is a schematic diagram of data interaction of another security domain management method according to an embodiment of the present invention
  • FIG. 30 is a schematic diagram of data interaction of still another security domain management method according to an embodiment of the present invention. detailed description
  • an embodiment of the present invention provides a security domain management system, which may include a server, a communication terminal, and a subscription management secure routing (SM-SR) that can communicate with each other.
  • the server may be configured to carry a mobile network operator (Mobile Network Operator, ⁇ ), and may be used to send a message to notify the communication terminal to manage the mobile pre-configured on the communication terminal itself.
  • a security domain in the network operator configuration file where the security domain may be used to store configuration information of the first service, where the server is represented by ⁇ in the figure; the first service may be a mobile payment service, or another payment class.
  • Business or other business that requires the use of a secure domain to store business configuration information.
  • the communication terminal may be an embedded Universal Integrated Circuit Card (eUICC) itself, or may be a device that carries the embedded universal integrated circuit card, and the communication terminal may be used according to the server.
  • the issued message manages the security domain in the mobile network operator profile of the communication terminal itself, and the eUICC is taken as an example to represent the communication terminal in the drawing.
  • mobile payment services require a secure chip to store and manage payment applications and data (such as user IDs, keys, attribute parameters, and related applications) that are highly secure.
  • the security chip can be placed on a mobile phone motherboard, a near field communication chip, a secure digital card, or integrated into a universal integrated circuit card, and matched with a separate security domain in the universal integrated circuit card, specifically for storage. And applications and data that manage high security requirements related to payment, etc., wherein the universal integrated circuit card can include the embedded universal integrated circuit card. Therefore, the communication terminal capable of carrying the security chip may also be included in the security terminal management system provided by the embodiment of the present invention.
  • the communication terminal may be pre-configured with an embedded universal integrated circuit card; wherein the communication terminal may be used to implement data communication between the embedded universal integrated circuit card and other devices, and the data communication may include Obtaining at least one of data information and transmitting data information; and may also be used to implement data required for computing the embedded universal integrated circuit card.
  • the embedded universal integrated circuit card can complete information processing, information communication and the like by carrying the communication terminal of the same, and only implement various information according to various data obtained by the communication terminal carrying the embedded universal integrated circuit card.
  • the management of the security domain may also store the mobile network operator configuration file.
  • the subscription management security route may be used to store the mobile network operator profile related information, for example, the issuer security domain profile identifier of the mobile network operator profile; and may store the mobile network operator configuration.
  • the security domain management system may further include a trusted service manager.
  • the trusted service manager can be used to implement Trusted Sercive Management (TSM), and can also communicate with other devices in the secure domain management system.
  • TSM Trusted Sercive Management
  • the trusted service manager may be configured to transmit communication data for communication between the server and the communication terminal when the server does not directly communicate with the communication terminal, and refer to TSM in the figure. Represents the trusted service manager.
  • the server can manage content that needs to be managed by the trusted service manager, directly The communication terminal performs communication.
  • the security domain management system can be applied to the communication field, and can be applied to create a storage network operator profile (MNO Profile) in the communication terminal when the user newly signs the first service.
  • MNO Profile storage network operator profile
  • the security domain of the configuration information of the first service may also be applied to a scenario when the first service is terminated (such as expiration or user cancellation), and at this time, the mobile network of the embedded universal integrated circuit card side device may be The security domain that can be used to store the configuration information of the first service is deleted in the operator profile.
  • the security domain management system can obtain the sent management request message by using the communication terminal, where the management request message can include the issuer security domain configuration file identifier, and then the communication terminal is in the The issuer security domain profile identifies the managed child security domain in the corresponding mobile network operator profile.
  • the management request message may include a configuration request message
  • the management sub-security domain may include creating a sub-security domain
  • the configuration request message may further include configuration information of the first service
  • the communication The terminal may store the configuration information of the first service in the sub-security domain; when the first service is terminated, the management request message may include a deletion request message, and the management sub-security domain may include deleting the sub-security domain.
  • the deletion request message may include the identifier of the sub-security domain
  • the communication terminal may implement deletion of the sub-security domain according to the identifier of the sub-security domain. Therefore, the security domain management system provided by the present invention can manage the security domain that can be used to store the first service configuration information according to the service status of the user subscription service.
  • an embodiment of the present invention provides a communication terminal, which can be applied to the field of communications, and can be applied to the security domain management system shown in FIG. 1.
  • the communication terminal can be pre-configured with a mobile network operator configuration.
  • the communication terminal may include: an obtaining unit 201, configured to obtain a management request message sent by the server, where the management request message may include an issuer Security Domain Profile (ISD-P) identifier.
  • ISD-P issuer Security Domain Profile
  • the management unit 202 may be configured to manage the sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier included in the configuration request message acquired by the obtaining unit 201, where the sub-security domain It can be used to store configuration information of the first service.
  • the management request message may include a configuration request message, where the management sub-security domain may include creating a sub-security domain, and the obtaining unit 201 may be configured to obtain a configuration request when the first service is newly signed.
  • the message for example, the configuration request message sent by the server, the configuration request message may include the issuer security domain profile identifier and the configuration information of the first service, where the configuration information of the first service may include The application and data of the first service;
  • the management unit 202 may be configured to create a sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier included in the configuration request message acquired by the obtaining unit 201, where And storing configuration information of the first service in the sub-security domain;
  • the communication terminal may further include: an allocating unit 203, which may be used to create the sub-security i or an assignment identifier created by the management unit 202.
  • the management unit may also be used.
  • the sub-security domain is managed according to an identifier of the sub-security domain allocated according to the allocation unit.
  • the communication terminal may further include: a first sending unit 204, configured to send a configuration response message, for example, send a configuration response message to the server, where the configuration response message is sent
  • An identifier of the sub-security domain assigned by the allocating unit 203 may be included, so that the server manages the sub-security domain according to the configuration response message.
  • the management request message may include a deletion request message, where the management sub-security domain may include deleting a sub-security domain;
  • the obtaining unit 201 may be configured to: when the first service is terminated, obtain a delete request message, for example, obtain a delete request message sent by the server, where the delete request message may include the issuer security domain profile identifier. And the identity of the child security domain;
  • the management unit 202 may be configured to delete the issuer security domain according to the issuer security domain profile identifier and the identifier of the child security domain that are included in the deletion request message acquired by the acquiring unit 201.
  • the configuration file identifies the sub-security domain in the mobile network operator configuration file corresponding to the file.
  • the communication terminal may further include: a detecting unit 205, configured to be used according to the issuer security domain configuration file included in the deletion request message acquired by the obtaining unit 201. Identifying an identifier of the sub-security domain, and detecting an application and data to be saved in the sub-security domain; the second sending unit 206 may be configured to send a save request message, for example, send a save request message to the server, where The save request message may include the application and data to be saved detected by the detecting unit 205, so that the server saves the application and data that need to be saved according to the save request message;
  • the management unit 202 may be specifically configured to: after the sending, by the second sending unit 206, the save request message, the issuer security domain profile identifier and the child security domain acquired by the acquiring unit 201 Identifying, deleting the sub-security domain in the mobile network operator configuration file corresponding to the issuer security domain profile identifier, and the application and data in the sub-security domain.
  • the communication terminal may further include: a third sending unit 207, configured to send a delete response message after the management unit 202 deletes the sub-security domain, for example, to the The server sends a delete response message, where the delete response message may include the sub-security domain deletion success status information and the identifier of the sub-security domain deleted by the management unit 202.
  • the obtaining unit 201 is further configured to obtain an activation request message, where Obtaining an activation request message sent by the server; the obtaining unit 201 may be further configured to acquire a user instruction according to the activation request message acquired by the obtaining unit 201;
  • the communication terminal may further include: a changing unit 208, configured to configure the mobile network operator when the user command acquired by the acquiring unit 201 is an activation command The status of the file is changed to the active state;
  • the fourth sending unit 209 may be configured to send an activation response message, for example, send the activation response message to the server, where the activation response message may include a status of the mobile network operator profile changed by the changing unit 208.
  • the security domain management system may include the trusted service manager.
  • the acquiring unit 201 may be configured to acquire the first sent by the trusted service manager when the first service is newly contracted. a connection request message, where the first connection request message carries an integrated circuit card identifier;
  • the communication terminal may further include: a fifth sending unit 210, where the first connection request message acquired by the acquiring unit 201 carries an integrated circuit card identifier and the communication terminal itself
  • the first service response message is sent by the trusted service manager, and the first service request message may include the mobile network operator.
  • the issuer security domain profile identifier of the configuration file and the configuration information of the first service, the configuration information of the first service may include the application and data of the first service; and the management unit 202 may be used to
  • the sub-security domain is created under the issuer security domain configuration file, which is represented by the issuer security domain profile identifier of the first service request message that is acquired by the acquiring unit 201, and the sub-security domain may be used for storage.
  • Configuration information of the first service
  • the allocation unit 203 may be configured to allocate an identifier to the sub-security domain created by the management unit 202, where the sub-security domain may be used to store configuration information of the first service.
  • the fifth sending unit 210 may be configured to send a first service response message to the trusted service manager, where the first service response message carries an identifier of the sub-security domain allocated by the allocating unit 203.
  • the management unit 202 may be configured to record the identifier of the sub-security domain acquired by the obtaining unit 201 in the mobile network operator configuration file.
  • the security domain management system may include a trusted service manager: at this time, the obtaining unit 201 may be configured to obtain the first sent by the trusted service manager. a second connection request message, where the second connection request message carries an integrated circuit card identifier;
  • the fifth sending unit 210 may be configured to send a second connection response message when the second connection request message that is acquired by the acquiring unit 201 and the integrated circuit card identifier matches the communication terminal itself; the acquiring unit 201 And the second service request message sent by the trusted service manager, where the second service request message carries the identifier of the issuer security domain configuration file and the identifier of the child security domain;
  • the management unit 202 may be further configured to: delete the issuer according to the issuer security domain profile identifier and the identifier of the child security domain carried by the second service request message acquired by the acquiring unit 201.
  • the sub-security domain in the security domain configuration file may be configured to send a second connection response message when the second connection request message that is acquired by the acquiring unit 201 and the integrated circuit card identifier matches the communication terminal itself; the acquiring unit 201 And the second service request message sent by the trusted service manager, where the second service request message carries the identifier of the issuer security domain configuration file and the identifier of the child security domain
  • the communication terminal provided by the embodiment of the present invention can obtain the management request message sent by the server by using the communication terminal, where the management request message can include the issuer security domain configuration file. Identifying, then, the communication terminal is configured by the mobile network operator corresponding to the issuer security domain profile identifier File management sub-domain security.
  • the management request message may include a configuration request message, and the management sub-security domain may include creating a sub-security domain, where the configuration request message may further include configuration information of the first service, where the communication terminal may The configuration information of the first service is stored in the sub-security domain; when the first service is terminated, the management request message may include a deletion request message, and the management sub-security domain may include deleting the sub-security domain, and the deleting
  • the request message may include an identifier of the sub-security domain, and the communication terminal may implement deletion of the sub-security domain according to the identifier of the sub-security domain. Therefore, the security domain that can be used to store the first service configuration information can be managed according to the service status of the user's subscription service. Referring to FIG.
  • an embodiment of the present invention provides a server, which can be applied to the field of communications, and can be applied to the security domain management system shown in FIG. 1 , where the mobile network operator configuration file can be pre-configured.
  • the server may include: a sending unit 901, configured to send a query request message to the subscription management secure route, where the query request message may include an ID of the relevant SM-SR (SRID) and An identifier of the embedded integrated circuit card (eUICC-ID, EID); an obtaining unit 902, configured to obtain a query response message sent by the subscription management security route, where the query response message may include the mobile network operator configuration file The Issuer Security Domain Profile (ISD-P) identifier (Application ID, AID) and the status of the mobile network operator profile; the checking unit 903, may be configured to check the obtaining unit 902 to obtain The status of the mobile network operator profile included in the query response message;
  • the sending unit 901 is further configured to: when the status of the mobile network operator profile included in the query response message checked by the checking
  • the configuration information of the first service is stored.
  • the management request message may include a configuration request message, where the management sub-security domain may include creating a sub-security domain, and the sending unit 901 may be further configured to use the query response that is checked by the checking unit 903.
  • Sending a management request message for example, sending a management request message to the communication terminal, so that the communication terminal manages the message according to the management request message, when the state of the mobile network operator profile included in the message is an active state (Enabled) a security domain, where the configuration request message may include the issuer security domain configuration file identifier, and the sub-security domain may be used to store configuration information of the first service, and specifically include: the sending unit 901, which may be used And sending a configuration request message, for example, to the communication terminal, when the status of the mobile network operator profile included in the query response message checked by the first service is newly signed and the check unit 903 is in an active state.
  • the configuration request message may include the issuer security domain configuration file identifier
  • the sub-security domain may be used to store configuration information of the first service, and specifically include: the sending unit 901, which may be used
  • sending a configuration request message for example, to the communication terminal, when the status of the mobile network operator profile included in the query response message checked by the first service is newly signed and
  • the obtaining unit 902 may be further configured to obtain a configuration response message sent by the communication terminal, where the configuration response message may include an identifier of a sub-security domain;
  • the server may further include: a configuration unit 904, configured to record the identifier of the sub-security domain acquired by the obtaining unit 902 in the issuer security domain configuration file identifier.
  • a configuration unit 904 configured to record the identifier of the sub-security domain acquired by the obtaining unit 902 in the issuer security domain configuration file identifier.
  • the server may further include: a configuration unit 904, configured to record the identifier of the sub-security domain acquired by the obtaining unit 902 in the issuer security domain configuration file identifier.
  • a configuration unit 904 configured to record the identifier of the sub-security domain acquired by the obtaining unit 902 in the issuer security domain configuration file identifier.
  • the sending unit 901 is further configured to record, in the configuration unit 904, the identifier of the sub-security domain in the mobile network operator corresponding to the issuer security domain profile identifier.
  • the first update request message is sent to the subscription management security route; where the first update request message may include the mobile network operator Setting the configuration information of the file, so that the subscription management security route updates the configuration information of the mobile network operator configuration file according to the first update request message, so that the subscription management security route, the server, and the communication may be
  • the mobile network operator profile in the terminal is synchronized, and the configuration information of the mobile network operator profile may include the type, version, and sub-security domain information of the mobile network operator profile.
  • the management request message may include a deletion request message, where the management sub-security domain may include deleting a sub-security domain, and the obtaining unit 902 may be further configured to acquire a sub-security domain when the first service is terminated.
  • the sending unit 901 is further configured to: when the status of the mobile network operator profile included in the query response message checked by the checking unit 903 is an active state (Enabled), send a management request message.
  • the security domain may be used to store configuration information of the first service, and may include: the sending unit 901, where the mobile network operator profile included in the query response message that is checked by the checking unit 903 may be used.
  • Sending a delete request message when the state is an active state for example, sending a delete request to the communication terminal
  • the communication terminal deletes the sub-security domain according to the management request message, where the deletion request message may include the issuer security domain profile identifier and the identifier of the sub-security domain.
  • the obtaining unit 902 may be further configured to obtain a save request message sent by the communication terminal, where the save request message may include an application and data to be saved;
  • the server may further include: a saving unit 905, configured to save the application and data to be saved according to the save request message acquired by the obtaining unit 902.
  • the obtaining unit 902 may be further configured to obtain a deletion response message, for example, obtain a deletion response message sent by the communication terminal, where the deletion response message may include a sub-security domain deletion success status information and is deleted.
  • the server may further include: a configuration unit 904, configured to be used according to the sub-security domain deletion success status information acquired by the obtaining unit 902, and The identifier of the deleted sub-security domain deletes the identifier of the sub-security domain in the mobile network operator configuration file.
  • the sending unit 901 may be further configured to send, after the configuration unit 904 deletes the identifier of the sub-security domain in the mobile network operator configuration file, to the subscription management security route.
  • a second update request message where the second update request message may include configuration information of the mobile network operator profile that is deleted by the configuration unit 904 by the identifier of the child security domain, so that the subscription management is performed.
  • the secure routing updates the configuration information of the mobile network operator profile according to the second update request message, and may synchronize the subscription management secure route, the server, and the mobile network operator profile in the communication terminal.
  • the sending unit 901 is further configured to send an activation request message when the status of the mobile network operator profile included in the query response message checked by the checking unit 903 is an inactive state, for example, Sending an activation request message to the communication terminal;
  • the obtaining unit 902 may be further configured to obtain an activation response message, for example, acquiring an activation response message sent by the communication terminal, where the activation response message may include a status of the mobile network operator configuration file;
  • the status of the mobile network operator profile included in the activation response message acquired by the obtaining unit 902 may be used to check the status of the mobile network operator profile that is included in the checking unit 902.
  • sending a management request message when the status of the mobile network operator profile included in the activation response message is an active state for example, sending a management request to the communication terminal.
  • the security domain management system can include the trusted service manager: at this time, the sending unit 901 can also be used to newly sign the first service and the query response check by the checking unit 903.
  • the trusted service manager And sending, by the trusted service manager, a first forwarding request message, where the status of the mobile network operator profile included in the message is an active state, where the first forwarding request message may include the issuer security domain a configuration file identifier, an integrated circuit card ID (ICCID), and configuration information of the first service, where the configuration information of the first service may include application information and data of the first service, so that The trusted service manager forwards to the communication terminal;
  • the trusted service manager forwards to the communication terminal;
  • the obtaining unit 902 may be further configured to obtain a first forwarding response message sent by the trusted service manager, where the first forwarding response message may include an identifier of the child security domain.
  • the security domain management system may include a trusted service manager;
  • the sending unit 901 may be further configured to: when the status of the mobile network operator profile carried by the query response message checked by the checking unit 903 is an active state, send a second to the trusted service manager. Forwarding the request message, the second forwarding request message carrying the issuer security domain profile identifier, the integrated circuit card identifier, and the identifier of the child security domain, so that the trusted service manager forwards the message to the communication terminal;
  • the obtaining unit 902 may be further configured to obtain a second forwarding response message sent by the trusted service manager, where the second forwarding response message carries a sub-security domain deletion success status message, and the deleted sub-security domain Logo.
  • the configuration unit 904 may be further configured to delete the mobile network operator configuration according to the sub-security domain deletion success status information acquired by the obtaining unit 902 and the deleted sub-security domain identifier.
  • the server provided by the embodiment of the present invention can send a management request message to the communication terminal by using the server, where the management request message can include the issuer security domain configuration. And identifying, by the communication terminal, the sub-security domain in the mobile network operator configuration file corresponding to the issuer security domain profile identifier.
  • the management request message may include a configuration request message, and the management sub-security domain may include creating a sub-security domain, where the configuration request message may further include configuration information of the first service, where the communication
  • the terminal may store the configuration information of the first service in the sub-security domain; when the first service is terminated, the management request message may include a deletion request message, and the management sub-security domain may include deleting the sub-security domain.
  • the deletion request message may include the identifier of the sub-security domain, and the communication terminal may implement deletion of the sub-security domain according to the identifier of the sub-security domain. Therefore, the security domain that can be used to store the first service configuration information can be managed according to the service status of the user's subscription service.
  • the subscription management security route may include: an obtaining unit 1201, The method may be used to obtain a query request message sent by the server, where the query request message may include the identifier of the subscription management security route and the identifier of the embedded integrated circuit card; the obtaining unit 1201 may be further configured to use the acquiring unit.
  • the sending unit 1202 is configured to send a query response message to the server, where the query response message may include an issuer security domain profile identifier and a location of the mobile network operator profile obtained by the obtaining unit 1201. State of the mobile network operator profile for the Service is security domain management.
  • the subscription management security route may further include: a saving unit 1203.
  • the acquiring unit 1201 may be further configured to acquire, when the first service is newly signed, the first sent by the server.
  • An update request message where the first update request message is available
  • the configuration information of the mobile network operator configuration file is updated
  • the saving unit 1203 is configured to update configuration information of the mobile network operator configuration file according to the first update request message acquired by the acquiring unit 1201. Synchronizing the subscription management security route, the server, and the mobile network operator profile in the communication terminal, where the configuration information of the mobile network operator profile may include a type, version, and sub-profile of the mobile network operator profile Security domain information.
  • the configuration information of the mobile network operator profile may include a type, version, and sub-profile of the mobile network operator profile Security domain information.
  • the acquiring unit 1201 is further configured to acquire, when the first service is terminated, a second update request message sent by the server, where the second update request message is The configuration information of the mobile network operator profile that is deleted from the identifier of the sub-security domain; the saving unit 1203 is further configured to update according to the second update request message acquired by the obtaining unit 1201
  • the configuration information of the mobile network operator configuration file synchronizes the subscription management security route, the server, and the mobile network operator configuration file in the communication terminal.
  • the query request message sent by the server is obtained by signing the management security route; and the issuer security domain profile identifier of the mobile network operator profile and the state of the mobile network operator profile are obtained according to the query request message.
  • an embodiment of the present invention provides a trusted service manager, which can be applied to the field of communications, and can be applied to the security domain management system shown in FIG. 1.
  • the subscription management security route may include: The 1401 may be configured to obtain a first forwarding request message sent by the server when the first service is newly contracted, where the first forwarding request message may include the issuer security domain profile identifier, and an integrated circuit card identifier ( Circuit Card ID, ICCID) and configuration information of the first service, the configuration information of the first service may include application information and data of the first service, and the sending unit 1402 may be configured to send a first connection request to the communication terminal.
  • the first connection request message may include the integrated circuit card identifier acquired by the obtaining unit 1401;
  • the obtaining unit 1401 may be further configured to acquire a first connection response message sent by the communication terminal, where the sending unit 1402 may be further configured to: when the acquiring unit 1401 obtains the first connection response message, Sending a first service request message, where the first service request message may include an issuer security domain profile identifier of the mobile network operator profile and configuration information of the first service, and configuration information of the first service
  • the application and data of the first service may be included, so that the communication terminal configures a security domain for the first service;
  • the obtaining unit 1401 may be further configured to obtain a first service response message sent by the communications terminal, where the first service response message may include an identifier of a sub-security domain.
  • the sending unit 1402 may be further configured to send a first forwarding response message to the server, where the first forwarding response message may include an identifier of the sub-security domain acquired by the acquiring unit 1401.
  • the obtaining unit 1401 is further configured to: when the first service is terminated, acquire a second forwarding request message sent by the server, where the second forwarding request message may include the issuer security domain configuration. a file identifier, an integrated circuit card identifier, and an identifier of the sub-security domain; the sending unit 1402 may be further configured to send a second connection request message to the communication terminal, where the second connection request message may include the acquiring
  • the acquiring unit 1401 is obtained by the unit 1401, and the acquiring unit 1401 is further configured to acquire a second connection response message sent by the communication terminal;
  • the sending unit 1402 may be further configured to: when the acquiring unit 1401 acquires the second connection response message, send a second service request message to the communication terminal, where the second service request message may include the An issuer security domain profile identifier and an identifier of the child security domain, so that the communication terminal deletes the security domain; the obtaining unit 1401 may be further configured to acquire a second service response message sent by the communication terminal, where The second
  • the sending unit 1402 may be further configured to send a second forwarding response message to the server, where the second forwarding response message may include the sub-security domain deletion success status information acquired by the obtaining unit 1401 and the deleted sub-security An identifier of the domain, such that the server updates the mobile network operator profile according to the second forwarding response message.
  • the trusted service manager forwards the communication message between the server and the communication terminal, and the auxiliary server and the communication terminal perform the security domain that can be used to store the first service configuration information in the mobile network operator configuration file. management.
  • the embodiment of the present invention provides a communication terminal, which can be applied to the field of communication, and can be applied to the security domain management system shown in FIG. 1.
  • the communication terminal can be pre-configured with a mobile network operator configuration file, as shown in FIG.
  • the communication terminal can be embedded or itself a micro-processing computer, such as a general-purpose computer, a custom machine, a mobile phone terminal, or a portable device such as a tablet.
  • the communication terminal 1501 can include: at least one network interface 1501 1 , a processor 15012 , and
  • the bus 15014 may further include at least one memory 15013, and the at least one network interface 1501 1, the processor 15012, and the memory 15013 are connected by the bus 15014 and complete communication with each other.
  • the bus 15014 may be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component) bus, or an EISA (Extended Industry Standard Architecture) bus.
  • the bus 15014 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 15, but it does not mean that there is only one bus or one type of bus. among them:
  • Memory 15013 can be used to store executable program code, which can include computer operating instructions.
  • the memory 15013 may include a high speed RAM memory, and may also include a non-volatile memory such as at least one disk memory.
  • the processor 15012 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more configured to implement the embodiments of the present invention. integrated circuit.
  • the network interface 1501 1 may be configured to obtain a management request message, for example, obtain a management request message sent by the server, where the management request message may include a sender security i or a configuration file identifier;
  • the processor 15012 may be configured to manage a sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier included in the configuration request message acquired by the network interface 1501 1
  • the child security domain can be used to store configuration information of the first service.
  • the management request message may include a configuration request message, where the management sub-security domain may include creating a sub-security domain, and the network interface 1501 1 may be configured to obtain a configuration when the first service is newly signed.
  • the request message for example, the configuration request message sent by the server, where the configuration request message may include the issuer security domain configuration file identifier and the configuration information of the first service, where the configuration information of the first service may include The application and data of the first service;
  • the processor 15012 is specifically configured to create a sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier included in the configuration request message acquired by the network interface 1501 1 And storing the configuration information of the first service in the sub-security domain;
  • the processor 15012 may be further configured to allocate an identifier to the sub-security domain created by the processor 15012.
  • the processor 15012 may be further configured to manage the sub-security domain according to the identifier of the sub-security domain allocated by the processor 15012 itself.
  • the network interface 1501 1 may be further configured to send a configuration response message to the server, where the configuration response message may include an identifier of the sub-security domain allocated by the processor 15012, so that The server manages the sub-security domain according to the configuration response message.
  • the management request message may include a deletion request message, where the management sub-security domain may include deleting a sub-security domain; and the network interface 1501 1 may be configured to obtain a deletion request when the first service is terminated.
  • the message for example, the deletion request message sent by the server, the deletion request message may include the issuer security domain profile identifier and the identifier of the child security domain; the processor 15012 may be specifically configured to use the Deleting the issuer security domain profile identifier and the identifier of the child security domain included in the delete request message obtained by the network interface 1501, deleting the mobile network operator corresponding to the issuer security domain profile identifier The child security domain in the configuration file.
  • the processor 15012 is further configured to: use the issuer security domain profile identifier and the identifier of the child security domain that are included in the deletion request message acquired by the network interface 1501 1 Detecting the application and the data to be saved in the sub-security domain; the network interface 1501 1 may further be configured to send a save request message, for example, send a save request message to the server, where the save request message may include the process
  • the device 15012 detects the application and the data to be saved, so that the server saves the application and data that need to be saved according to the save request message; the processor 15012 is specifically configured to be used in the network interface 1501 1 After the save request message is sent, the issuer security domain configuration is deleted according to the issuer security domain profile identifier and the identifier of the child security domain acquired by the network interface 1501 1
  • the file identifies the sub-security domain in the mobile network operator configuration file and the application and data in the sub-security domain.
  • the network interface 15011 may be further configured to: after the processor 15012 deletes the sub-security domain, send a delete response message, for example, send a delete response message to the server, where the delete response message may be The sub-security domain deletion success status information and the identifier of the sub-security domain deleted by the processor 15012 are included.
  • the network interface 15011 is further configured to obtain an activation request message sent by the server.
  • the network interface 15011 is further configured to acquire a user instruction according to the activation request message acquired by the network interface 15011.
  • the processor 15012 is further configured to: the user instruction acquired by the network interface 15011 is When the command is activated, the state of the mobile network operator profile is changed to an active state; the network interface 15011 may be further configured to send the activation response message to the server, where the activation response message may include the The state of the mobile network operator profile changed by the processor 15012.
  • the security domain management system may include the trusted service manager: at this time, the network interface 15011 may be configured to acquire the first sent by the trusted service manager when the first service is newly contracted.
  • the first connection request message may include an integrated circuit card identifier; and the first connection request message acquired by the network interface 15011 when the network interface 15011 may include the integrated circuit card identifier and the communication terminal itself Sending a first connection response message, where the network interface 15011 is configured to obtain a first service request message sent by the trusted service manager, where the first service request message may include the mobile network operator profile The issuer security domain profile identifier and the configuration information of the first service, where the configuration information of the first service may include the application and the number of the first service According to;
  • the processor 15012 may be configured to create a sub-security under the mobile network operator configuration file corresponding to the issuer security domain profile identifier included in the first service request message acquired by the network interface 1501 1
  • the sub-security domain may be configured to store configuration information of the first service, where the processor 15012 may be configured to allocate an identifier to the sub-security domain created by the processor 15012, where the sub-security domain And can be used to store configuration information of the first service;
  • the network interface 1501 1 may be configured to send a first service response message to the trusted service manager, where the first service response message may include an identifier of the sub-security domain assigned by the processor 15012.
  • the security domain management system may include a trusted service manager: at this time, the network interface 1501 1 may be configured to acquire, when the first service ends, the second sent by the trusted service manager. a connection request message, where the second connection request message may include an integrated circuit card identifier;
  • the network interface 1501 1 may send a second connection response message when the second connection request message acquired by the network interface 1501 1 may include that the integrated circuit card identifier matches the communication terminal itself; the network interface 1501 1
  • the second service request message sent by the trusted service manager may be obtained, where the second service request message may include the issuer security domain profile identifier and the identifier of the child security domain; 15012.
  • the method further includes: deleting the issuer security domain configuration according to the issuer security domain profile identifier and the identifier of the child security domain included in the second service request message acquired by the network interface 1501 1
  • the file identifier corresponds to the sub-security domain in the mobile network operator configuration file; the network interface 1501 1 may be further configured to: after the processor 15012 deletes the sub-security domain, to the trusted The service manager sends a second service response message, the The second service response message may include sub-security domain deletion success status information and the processor
  • the communication terminal provided by the embodiment of the present invention can obtain the management request message sent by the server through the communication terminal, where the management request message can include the issuer security domain profile identifier, and then the communication terminal is in the release
  • the party security domain profile identifies the managed child security domain in the corresponding mobile network operator profile.
  • the management request message may include a configuration request message, and the management sub-security domain may include creating a sub-security domain, where the configuration request message may further include configuration information of the first service, where the communication
  • the terminal may store the configuration information of the first service in the sub-security domain; when the first service is terminated, the management request message may include a deletion request message, and the management sub-security domain may include deleting the sub-security domain.
  • the deletion request message may include the identifier of the sub-security domain, and the communication terminal may implement deletion of the sub-security domain according to the identifier of the sub-security domain.
  • the security domain management method, apparatus, and system provided by the present invention can manage the security domain that can be used to store the first service configuration information according to the service status of the user subscription service.
  • the embodiment of the present invention provides a server, which can be applied to the field of communications, and can be applied to the security domain management system shown in FIG. 1.
  • the server may be pre-configured with a mobile network operator configuration file, as shown in FIG.
  • the server may be embedded or itself a microprocessor computer, such as a general purpose computer, a custom machine, a mobile phone terminal or a tablet device, and the server 1601 may include: at least one network interface 1601 1, a processor 16012, and a bus 16014.
  • At least one memory 16013 can be included, the at least one network interface 1601 1, the processor 16012, and the memory 16013 being connected by the bus 16014 and completing communication with each other.
  • the bus 16014 may be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component) bus, or an EISA (Extended Industry Standard Architecture) bus.
  • the bus 16014 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 16, but it does not mean only There is a bus or a type of bus. among them:
  • the memory 16013 can be used to store executable program code, which can include computer operating instructions.
  • the memory 16013 may include a high speed RAM memory, and may also include a non-volatile memory such as at least one disk memory.
  • the processor 16012 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more configured to implement the embodiments of the present invention. integrated circuit.
  • the network interface 1601 1 may be configured to send a query request message to the subscription management security route, where the query request message may include an identifier of the subscription management security route and an identifier of the embedded integrated circuit card;
  • the query response message sent by the subscription management security route may be used, where the query response message may include an issuer security domain profile identifier of the mobile network operator profile and the mobile network operator.
  • the processor 16012 configured to check a status of the mobile network operator configuration file included in the query response message acquired by the network interface 1601 1; the network interface 1601 1 And sending a management request message when the state of the mobile network operator profile included in the query response message checked by the processor 16012 is an active state, for example, sending a management request to the communication terminal, so as to
  • the communication terminal manages the sub-security domain according to the management request message, where
  • the configuration request message may include the issuer security domain profile identifier, and the child security domain may be used to store configuration information of the first service.
  • the management request message may include a configuration request message, where the management sub-security domain may include creating a sub-security domain; the network interface 1601 1 may also be used to check at the processor 16012. Sending a management request message when the state of the mobile network operator profile included in the query response message is an active state, for example, sending a management request to the communication terminal, so that the communication terminal manages the message according to the management request message.
  • the security domain where the configuration request message may include the issuer security domain configuration file identifier, where the sub-security domain may be used to store configuration information of the first service, and specifically, the network interface 1601 1 Transmitting a configuration request message, for example, to the communication terminal, when the state of the mobile network operator profile included in the query response message included in the first service newly contracted by the processor 16012 is an active state Sending a configuration request message, so that the communication terminal creates a child security domain according to the management request message, where the configuration request message may include the issuer security domain profile identifier and the configuration information of the first service, where The configuration information of the first service may include the application of the first service Information and data.
  • the network interface 1601 1 may be further configured to obtain a configuration response message, for example, obtain a configuration response message sent by the communication terminal, where the configuration response message may include an identifier of a sub-security domain;
  • the identifier of the sub-security domain acquired by the network interface 1601 1 is recorded in the mobile network operator configuration file corresponding to the issuer security domain profile identifier.
  • the network interface 1601 1 may be further configured to record, in the processor 16012, the identifier of the sub-security domain in the mobile network operator corresponding to the issuer security domain profile identifier.
  • the first update request message is sent to the subscription management security route, where the first update request message may include configuration information of the mobile network operator configuration file, so that the subscription management security route Updating the configuration information of the mobile network operator profile according to the first update request message, so that the subscription management security route, the server, and the mobile network operator profile in the communication terminal may be synchronized,
  • the configuration information of the mobile network operator profile may include the type, version, and sub-security domain information of the mobile network operator profile.
  • the management request message may include a deletion request message, where the management sub-security domain may include deleting a sub-security domain; and the network interface 1601 1 may also be used to The identifier of the sub-security domain is obtained when the first service is terminated; the network interface 1601 1 is further configured to be used by the processor 16012 to check the status of the mobile network operator profile included in the query response message.
  • Sending a management request message when the state is active for example, sending a management request to the communication terminal, so that the communication terminal manages the child security domain according to the management request message, wherein the configuration request message may include the issuer
  • the signaling terminal sends a deletion request message, so that the communication terminal deletes the sub-security domain according to the management request message, where the deletion request message may include the issuer security domain configuration file identifier and the identifier of the sub-security domain.
  • the network interface 1601 1 may be further configured to acquire a save request message sent by the communication terminal, where the save request message may include an application and data to be saved; and the memory 16013 may be used for And saving the application and data that need to be saved according to the save request message acquired by the network interface.
  • the network interface 1601 1 may be further configured to obtain a deletion response message, for example, obtain a deletion response message sent by the communication terminal, where the deletion response message may include a sub-security domain deletion success status information and a The ID of the deleted sub-security domain;
  • the processor 16012 may be further configured to: delete, according to the network interface 1601 1 the sub-security domain deletion success status information and the deleted sub-security domain identifier, delete In addition to the identity of the sub-security domain in the mobile network operator profile. Further, optionally, the network interface 1601 1 may be further configured to send, after the processor 16012 deletes the identifier of the sub-security domain in the mobile network operator configuration file, to the subscription management security route.
  • the second update request message may include configuration information of the mobile network operator profile that is deleted by the processor 16012 by the identifier of the sub-security domain, so that the signing is performed
  • the management security route updates the configuration information of the mobile network operator configuration file according to the second update request message, so that the subscription management security route, the server, and the mobile network operator configuration file in the communication terminal are synchronized.
  • the network interface 1601 1 is further configured to: when the status of the mobile network operator profile included in the query response message checked by the processor 16012 is an inactive state, to the communication The terminal sends an activation request, and the network interface 1601 1 is further configured to obtain an activation response message sent by the communication terminal, where the activation response message may include a status of the mobile network operator profile.
  • the processor 16012 may be further configured to check a status of the mobile network operator profile included in the activation response message acquired by the network interface 1601 1; the network interface 1601 1 may also be used in the When the status of the mobile network operator profile included in the activation response message checked by the processor 16012 is an active state, the management request message is sent to the communication terminal.
  • the security domain management system may include a trusted service manager: at this time, the network interface 16012 may be used to newly sign the first service and the query response message checked by the checking unit. And transmitting, by the trusted service manager, a first forwarding request message, where the status of the mobile network operator profile is in an active state, where the first forwarding request message may include the issuer security domain configuration a file identifier, an integrated circuit card ID (ICCID), and configuration information of the first service, where the configuration information of the first service may include the Application information and data of the first service, so that the trusted service manager forwards to the communication terminal;
  • ICCID integrated circuit card ID
  • the network interface 16012 may be further configured to obtain a first forwarding response message sent by the trusted service manager, where the first forwarding response message may include an identifier of the sub-security domain.
  • the processor 16012 may be configured to record the identifier of the sub-security domain acquired by the network interface 16012 in the mobile network operator configuration file corresponding to the issuer security domain profile identifier.
  • the security domain management system may include a trusted service manager, where the network interface 16012 is further configured to be included in the first service and the query response message that is checked by the checking unit is included And sending, by the trusted service manager, a second forwarding request message, where the status of the mobile network operator profile is an active state, where the second forwarding request message may include the issuer security domain profile identifier, and the integration a circuit card identifier and an identifier of the sub-security domain, so that the trusted service manager forwards the information to the communication terminal; the network interface 16012 may be further configured to obtain a second forwarding sent by the trusted service manager.
  • the response message, the second forwarding response message may include a sub-security domain deletion success status message, and an identifier of the deleted sub-security domain.
  • the processor 16012 may be further configured to: delete the sub-security domain deletion success status information and the deleted sub-security domain identifier obtained by the network interface 16012, and delete the mobile network operator configuration file.
  • the identity of the child security domain is obtained by the server, and obtaining the issuer security domain profile identifier of the mobile network operator profile and the state of the mobile network operator profile. And sending a configuration request message to the communication terminal to obtain a configuration response message, where the status of the mobile network operator profile is an activation request message, where the configuration request message may include the issuer security domain profile identifier And configuration information of the first service, where the configuration should The answer message may include the identifier of the child security domain.
  • the identifier of the child security domain is recorded in the mobile network operator configuration file corresponding to the issuer security domain profile identifier. Therefore, when the user newly subscribes to the service, the configuration information and the security domain of the new subscription service are added to the mobile network operator configuration file of the communication terminal, and the security domain that can be used to store the first service configuration information is managed.
  • the embodiment of the present invention provides a contract management security route, which can be applied to the communication field, and can be applied to the security domain management system shown in FIG. 1. As shown in FIG. 17, the subscription management security route can be embedded or itself is micro-processing.
  • a portable device such as a general-purpose computer, a custom machine, a mobile terminal or a tablet, the subscription management secure route 1701 may include: at least one network interface 1701 1, a processor 17012, a memory 17013, and a bus 17014, the at least one network The interface 1701 1.
  • the processor 17012 and the memory 17013 are connected by a bus 17014 and complete communication with each other.
  • the bus 17014 may be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component) bus, or an EISA (Extended Industry Standard Architecture) bus.
  • the bus 17014 can be divided into an address bus, a data bus, a control bus, and the like.
  • the memory 17013 can be used to store executable program code, which can include computer operating instructions.
  • the memory 17013 may include a high speed RAM memory, and may also include a non-volatile memory such as at least one disk memory.
  • the processor 17012 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more configured to implement the embodiments of the present invention. integrated circuit.
  • the network interface 1701 1 may be configured to obtain a query request message sent by the server, where the query request message may include the identifier of the subscription management secure route and The identifier of the embedded integrated circuit card; the network interface 1701 1 is further configured to obtain, according to the identifier of the subscription management security route acquired by the network interface 1701, the identifier corresponding to the identifier of the embedded integrated circuit card.
  • the issuer security domain profile identifier of the mobile network operator profile and the state of the mobile network operator profile; the network interface 1701 1 may be used to send a query response message to the server, where the query response message may
  • the issuer security domain profile identifier of the mobile network operator profile obtained by the network interface 1701 1 and the state of the mobile network operator profile are included, so that the server performs secure domain management.
  • the network interface 1701 1 is further configured to: when the first service is newly signed, obtain the first update request message sent by the server, where the first update request message may include the mobile network.
  • the configuration information of the operator profile may be used to update the configuration information of the mobile network operator profile according to the first update request message acquired by the network interface 1701 1 to enable the signing Managing the secure routing, the server and the mobile network operator profile synchronization in the communication terminal, the configuration information of the mobile network operator profile may include the type, version and sub-security domain information of the mobile network operator profile.
  • the network interface 1701 1 is further configured to acquire, when the first service is terminated, a second update request message sent by the server, where the second update request message may include the deleted Configuration information of the mobile network operator profile identified by the child security domain;
  • the processor 17012 is further configured to: update, according to the second update request message acquired by the network interface 1701, configuration information of the mobile network operator configuration file, to enable the subscription management security route, the server Synchronizing with a mobile network operator profile in the communication terminal.
  • the query request message sent by the server is obtained by signing the management security route; and the issuer security domain profile identifier of the mobile network operator profile and the state of the mobile network operator profile are obtained according to the query request message. And sending a query response message to the server, where the query response message may include an issuer security domain profile identifier of the mobile network operator profile and a status of the mobile network operator profile, so that the server Perform security domain management.
  • An embodiment of the present invention provides a trusted service manager, which can be applied to the field of communications, and can be applied to the security domain management system shown in FIG. 1.
  • the trusted service manager can be embedded or itself A microprocessor, such as a general-purpose computer, a custom machine, a mobile terminal, or a tablet, the trusted service manager 1801 can include: at least one network interface 1801 1, a processor 18012, a memory 18013, and a bus 18014. At least one network interface 1801 1, processor 18012, and memory 18013 are connected by bus 18014 and complete communication with each other.
  • the bus 18014 may be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component) bus, or an EISA (Extended Industry Standard Architecture) bus.
  • the bus 18014 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 18, but it does not mean that there is only one bus or one type of bus. among them:
  • the memory 18013 can be used to store executable program code, which can include computer operating instructions.
  • the memory 18013 may include a high speed RAM memory, and may also include a non-volatile memory such as at least one disk memory.
  • the processor 18012 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more configured to implement the embodiments of the present invention. integrated circuit.
  • CPU central processing unit
  • ASIC application specific integrated circuit
  • the network interface 18011 may be configured to acquire a first forwarding request message sent by the server when the first service is newly contracted, where the first forwarding request message may include the issuer security domain profile identifier, an integrated circuit card identifier.
  • the integrated circuit card ID (ICCID) and the configuration information of the first service where the configuration information of the first service may include application information and data of the first service, and the network interface 18011 may be configured to send to the communication terminal.
  • a first connection request message where the first connection request message may include an integrated circuit card identifier acquired by the network interface 18011;
  • the network interface 18011 may be further configured to acquire a first connection response message sent by the communication terminal, where the network interface 18011 is further configured to: when the network interface 18011 obtains the first connection response message, Sending a first service request message, where the first service request message may include an issuer security domain profile identifier of the mobile network operator profile and configuration information of the first service, and configuration information of the first service
  • the application and data of the first service may be included, so that the communication terminal configures a security domain for the first service;
  • the network interface 18011 may be further configured to obtain a first service response message sent by the communication terminal, where the first service response message may include an identifier of a sub-security domain.
  • the network interface 18011 may be further configured to send a first forwarding response message to the server, where the first forwarding response message may include an identifier of the sub-security domain acquired by the network interface 18011.
  • the network interface 18011 is further configured to acquire, when the first service is terminated, a second forwarding request message sent by the server, where the second forwarding request message may include the issuer security domain configuration. a file identifier, an integrated circuit card identifier, and an identifier of the sub-security domain;
  • the network interface 18011 may be further configured to send a second connection to the communication terminal.
  • a request message, the second connection request message may include an integrated circuit card identifier acquired by the network interface 1801 1; the network interface 1801 1 may be further configured to acquire a second connection response message sent by the communication terminal;
  • the network interface 1801 1 may be further configured to: when the network interface 1801 1 obtains the second connection response message, send a second service request message to the communication terminal, where the second service request message may include The issuer security domain configuration file identifier and the identifier of the child security domain, so that the communication terminal deletes the security domain; the network interface 1801 1 may be further configured to acquire the second service response message sent by the communication terminal,
  • the second service response message may include sub-security domain deletion success status information and an identifier of the sub-security domain deleted by the configuration unit.
  • the network interface 1801 1 may be further configured to send a second forwarding response message to the server, where the second forwarding response message may include the sub-security domain deletion success status information acquired by the network interface 1801 1 and deleted.
  • An identifier of the child security domain such that the server updates the mobile network operator profile according to the second forwarding response message.
  • the trusted service manager forwards the communication message between the server and the communication terminal, and the auxiliary server and the communication terminal perform the security domain that can be used to store the first service configuration information in the mobile network operator configuration file. management.
  • Computer readable media can comprise both computer storage media and communication media, where the communication media can comprise any medium that facilitates transfer of the computer program from one location to another.
  • a storage medium may be any available media that can be accessed by a computer.
  • the computer readable medium may include RAM (Random Access Memory), ROM (Read Only Memory), and EEPROM (Electrically Erasable Programmable Read Only Memory).
  • any connection may suitably be a computer readable medium.
  • coaxial cable, fiber optic cable, twisted pair, DSL (Digital Subscriber Line), or wireless technologies such as infrared, radio, and microwave can include CD (Compact Disc), laser disc, CD, DVD disc (Digital Versatile Disc) , floppy disks and Blu-ray discs, where the discs are usually magnetically replicated, while the discs use lasers to optically replicate data. Combinations of the above should also be included within the scope of the computer readable media.
  • the embodiment of the present invention provides a security domain management method, which can be applied to the communication field, and can be applied to the communication terminal in the security domain management system shown in FIG. 1, where the mobile terminal operator configuration can be pre-configured.
  • the file, as shown in Figure 19, can include the following steps:
  • the management request message may include a configuration request message, where the management sub-security domain may include creating a sub-security domain, where the configuration request message may further include configuration information of the first service, when the first service is newly signed.
  • the configuration information of the first service may be stored in the sub-security domain; optionally, the management request message may include a deletion request message, and the management sub-security domain may include deleting a sub-security domain, and the deleting The request message can contain the sub-an
  • the global identifier may be deleted according to the identifier of the sub-security domain when the first service is terminated.
  • the communication terminal provided by the embodiment of the present invention can obtain the management request message sent by the server through the communication terminal, where the management request message can include the issuer security domain profile identifier, and then the communication terminal is in the release
  • the party security domain profile identifies the managed child security domain in the corresponding mobile network operator profile.
  • An embodiment of the present invention provides a security domain management method, which can be applied to a communication domain, and can be applied to a server in the security domain management system shown in FIG. 1, where the mobile network operator configuration file can be pre-configured. Referring to Figure 20, the following steps can be included:
  • the query request message may include an identifier of the subscription management security route and an identifier of an embedded integrated circuit card;
  • the query response message sent by the subscription management security route is obtained, where the query response message may include an issuer security domain profile identifier of the mobile network operator profile and a state of the mobile network operator profile.
  • a management request message may be sent to the communication terminal, so that the communication terminal manages the child security domain according to the management request message.
  • the configuration request message may include the issuer security domain configuration file identifier, and the sub-security domain may be used to store configuration information of the first service.
  • the management request message may include a configuration request message, and the management sub-security The domain may include a child security domain, and the configuration request message may further include configuration information of the first service, where the configuration information of the first service may be stored in the child security domain when the first service is newly signed.
  • the management request message may include a deletion request message
  • the management sub-security domain may include deleting a sub-security domain
  • the deletion request message may include an identifier of the sub-security domain
  • the first service is At the end of the process, the deletion of the sub-security domain may be implemented according to the identifier of the sub-security domain.
  • the server provided by the embodiment of the present invention can send a management request message to the communication terminal by using the server, where the management request message can include the issuer security domain configuration file identifier, and then the communication terminal is secure on the issuer.
  • the domain profile identifies the managed child security domain in the corresponding mobile network operator profile.
  • the security domain that can be used to store the first service configuration information can be managed according to the service status of the user's subscription service.
  • an embodiment of the present invention provides a security domain management method, which can be applied to a communication domain, and can be applied to a communication terminal in the security domain management system shown in FIG.
  • the communication terminal may be pre-configured with a mobile network operator configuration file.
  • the management request message may include a configuration request message
  • Managing a child security domain may include creating a child security domain
  • the configuration request message is obtained, where the configuration request message may include an issuer security domain profile identifier of the mobile network operator profile and configuration information of the first service
  • the configuration information of the first service may include the application and data of the first service.
  • the configuration request message sent by the server may be acquired.
  • This step is one of specific implementation manners of the following content: acquiring a management request
  • the message, the management request message may include an issuer security domain profile identifier. 2102. Create a sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain configuration file identifier, where the sub-security domain may be used to store configuration information of the first service.
  • the step is one of the specific implementations of the following: managing the sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier, where the sub-security domain may be used to store the first service Configuration information.
  • the sub-security domain may also be managed according to the identifier of the sub-security domain.
  • the configuration response message may include an identifier of the sub-security domain, so that the server manages the sub-security domain according to the configuration response message.
  • a configuration response message may be sent to the server.
  • the management request message may include a deletion request message, where the management sub-security domain may include deleting a sub-security domain;
  • deletion request message may include the issuer security domain configuration file identifier and the identifier of the child security domain;
  • the method may be: acquiring the deletion request message sent by the server; the step is one of the specific implementation manners of: acquiring the management request message, where the management request message may include an issuer security domain configuration file identifier.
  • Send a save request message where the save request message may include the requirement The saved application and the data; specifically, the save request message may be sent to the server, so that the server saves the application and data that need to be saved according to the save request message.
  • the save request message may include the requirement The saved application and the data; specifically, the save request message may be sent to the server, so that the server saves the application and data that need to be saved according to the save request message.
  • this step is one of the specific implementation manners of the following: deleting the issuer security domain configuration file according to the issuer security domain profile identifier and the identifier of the child security domain included in the delete request message. Identifying the sub-security domain in the corresponding mobile network operator configuration file.
  • the sub-security domain Specifically, the step is to manage the sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain configuration file identifier, where the sub-security domain can be used to store the configuration information of the first service.
  • the sub-security domain can be used to store the configuration information of the first service.
  • the delete response message may include a sub-security domain deletion success status information and an identifier of the sub-security domain.
  • the deletion response message may be sent to the server.
  • the method may further include:
  • Al obtaining an activation request message; specifically, obtaining an activation request message sent by the server; A2. Acquire a user instruction according to the activation request message.
  • the activation response message is sent, where the activation response message may include a status of the mobile network operator profile. Specifically, the activation response message may be sent to the server.
  • the communication terminal provided by the embodiment of the present invention can obtain the management request message sent by the server through the communication terminal, where the management request message can include the issuer security domain profile identifier, and then the communication terminal is in the release
  • the party security domain profile identifies the managed child security domain in the corresponding mobile network operator profile.
  • the management request message may include a configuration request message, and the management sub-security domain may include creating a sub-security domain, where the configuration request message may further include configuration information of the first service, where the first service may be newly signed.
  • the configuration information of the first service is stored in the sub-security domain; the management request message may include a deletion request message, the management sub-security domain may include deleting a sub-security domain, and the deletion request message may include the sub-security
  • the identifier of the domain when the first service is terminated, the deletion of the sub-security domain may be implemented according to the identifier of the sub-security domain. Therefore, the security domain that can be used to store the first service configuration information can be managed according to the service status of the user's subscription service.
  • an embodiment of the present invention provides a security domain management method, which can be applied to a communication field, and can be applied to a server in the security domain management system shown in FIG.
  • the mobile network operator configuration file may be pre-configured.
  • the management request message may include a configuration request message, where the management sub-security domain may be configured. Including creating a child security domain; see Figure 23:
  • the query request message may include the identifier of the subscription management security route. And the identification of the embedded integrated circuit card;
  • the query response message may include an issuer security domain profile identifier of the mobile network operator profile and a state of the mobile network operator profile.
  • the configuration request message may be sent to the communication terminal, so that the communication terminal manages the sub-security domain according to the management request message.
  • This step is one of the specific implementations of the following: sending a management request message when the status of the mobile network operator profile included in the query response message is an active state, where the configuration request message may include the The issuer security domain profile identifier, where the child security domain can be used to store configuration information of the first service.
  • the configuration response message sent by the communication terminal may be acquired.
  • the first update request message may include configuration information of the mobile network operator configuration file, so that the subscription management security route is cancelled according to the first update request, and the mobile network operator configuration file is updated. Configuration information.
  • the configuration information of the device may include the type, version, and sub-security domain information of the mobile network operator profile.
  • the management request message may include a deletion request message, where the management sub-security domain may include deleting a sub-security domain, as shown in FIG. 24:
  • the first service when the first service is terminated, sending a query request message to the subscription management security route, where the query request message may include the identifier of the subscription management security route and an identifier of the embedded integrated circuit card;
  • the query response message sent by the subscription management security route is obtained, where the query response message may include an issuer security domain profile identifier of the mobile network operator profile and a state of the mobile network operator profile.
  • the server may obtain the identifier of the sub-security domain from the data stored by the server, or obtain the identifier of the sub-security domain, for example, obtain the known sub-security domain from the communication terminal. The logo, and then select the one that needs to be removed.
  • the delete request message may include the issuer security domain profile identifier and the child security The identity of the domain.
  • the deletion request message may be sent to the communication terminal, so that the communication terminal manages the sub-security domain according to the management request message.
  • the server sends a management request message to the communication terminal when the state of the mobile network operator profile included in the query response message is an active state, where The configuration request message may include the issuer security domain profile identifier, and the child security domain may be used to store configuration information of the first service.
  • the save request message may include a save request
  • the application and the data may be obtained by acquiring the save request message sent by the communication terminal.
  • the application and data that need to be saved may also be saved according to the save request message.
  • deletion response message may include a sub-security domain deletion success status message, and an identifier of the deleted sub-security domain.
  • the deletion response message sent by the communication terminal may be acquired.
  • the method may further include:
  • an activation request message is sent to the communication terminal
  • the activation response message may include a status of the mobile network operator configuration file; specifically, acquiring an activation response message sent by the communication terminal; B3. Check a status of the mobile network operator profile included in the activation response message.
  • the deletion request message may be sent to the communication terminal.
  • the server provided by the embodiment of the present invention can send a management request message to the communication terminal by using the server, where the management request message can include the issuer security domain configuration file identifier, and then, in the issuer security domain configuration file identifier.
  • the child security domain is managed in the corresponding mobile network operator profile.
  • the management request message may include a configuration request message, and the management sub-security domain may include creating a sub-security domain, where the configuration request message may further include configuration information of the first service, where the first service may be newly signed.
  • the configuration information of the first service is stored in the sub-security domain; the management request message may include a deletion request message, the management sub-security domain may include deleting a sub-security domain, and the deletion request message may include the sub-security
  • the identifier of the domain when the first service is terminated, the deletion of the sub-security domain may be implemented according to the identifier of the sub-security domain. Therefore, the security domain that can be used to store the first service configuration information can be managed according to the service status of the user's subscription service.
  • the embodiment of the present invention provides a security domain management method, which can be applied to the communication field, and can be applied to the contract management security route in the security domain management system shown in FIG. 1. Referring to FIG. 25, the following steps can be included:
  • the query request message may include an identifier of the subscription management secure route and an identifier of the embedded integrated circuit card.
  • a query response message sent to the server may include an issuer security domain profile identifier and a location of the mobile network operator profile.
  • the security domain management method may further include the following steps:
  • the subscription management security route, the server and the mobile network operator profile in the communication terminal are synchronized, and the configuration information of the mobile network operator profile may include the type of the mobile network operator profile. , version, and sub-security domain information.
  • the security domain management method provided by the embodiment of the present invention obtains the query request message sent by the server by signing the management security route, and obtains the issuer security domain profile identifier of the mobile network operator profile according to the query request message and the mobile network.
  • the embodiment of the present invention provides a security domain management method, which can be applied to the communication field, and can be applied to the trusted service manager in the security domain management system shown in FIG. 1. Referring to FIG. 26, the following steps can be included:
  • the server may include the issuer security domain profile identifier, an integrated circuit card identifier, and configuration information of the first service.
  • the configuration information of the first service may include application information and data of the first service.
  • Send a first connection request message to the communication terminal where the first connection request message may include the integrated circuit card identifier.
  • the acquiring unit acquires the first connection response message, send a first service request message.
  • the first service request message may include an issuer security domain profile identifier of the mobile network operator profile and configuration information of the first service, where the configuration information of the first service may include the first An application and data of a service, so that the communication terminal configures a security domain for the first service;
  • the security domain management method provided by the embodiment of the present invention, the present invention actually forwards the communication message between the server and the communication terminal through the trusted service manager, and the auxiliary server and the communication terminal are in the mobile network operator configuration file. It can be used to manage the security domain that stores the first service configuration information.
  • the embodiment of the present invention provides a security domain management method, which can be used in the communication field, and can be used in the security domain management system shown in FIG. 1 , and can be specifically combined with the devices provided in the foregoing embodiments.
  • the application may be used to add a security domain that can be used to store configuration information of the first service in a mobile network operator configuration file of the communication terminal when the user newly subscribes to the first service, where the first service may include
  • the mobile payment service as shown in FIG. 27, needs to refer to FIG. 28, FIG. 29 or FIG. 30 in some steps of the embodiment. The specific steps are as follows:
  • the server sends a query request message to the subscription management security route when the first service is newly signed.
  • the query request message may include the identifier of the subscription management security route and the identifier of the embedded integrated circuit card.
  • the contract management security route acquires an issuer security domain configuration of the mobile network operator configuration file corresponding to the identifier of the embedded integrated circuit card according to the identifier of the subscription management security route included in the query request message.
  • the file identification and the status of the mobile network operator profile are included in the query request message.
  • the subscription management security route sends a query response message to the server, where the query response message may include an issuer security domain configuration file identifier of the mobile network operator configuration file and a status of the mobile network operator configuration file.
  • the reason for this is to allow the server to perform secure domain management.
  • the server checks a status of the mobile network operator profile included in the query response message.
  • the server sends a configuration request message to the communication terminal, where the configuration request message may include the issuer security.
  • the configuration information of the first service may include application information and data of the first service.
  • the communication terminal creates a sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier.
  • the sub-security domain may be used to store configuration information of the first service.
  • the communication terminal allocates an identifier for the sub-security domain.
  • the communication terminal sends a configuration response message to the server, where the configuration response message may include an identifier of the sub-security domain.
  • the server acquires the configuration response message sent by the communication terminal:
  • the server records the identifier of the sub-security domain in the mobile network operator configuration file corresponding to the issuer security domain profile identifier.
  • the server sends a first update request message to the subscription management security route, where the first update request message may include configuration information of the mobile network operator configuration file.
  • the purpose of this is to enable the subscription management security route to update the configuration information of the mobile network operator profile according to the first update request message, so that the subscription management secure route, the server, and the communication terminal
  • the mobile network operator profile synchronization in the mobile network operator profile may include the type, version, and sub-security domain information of the mobile network operator profile.
  • the subscription management security route obtains the first update request message sent by the server:
  • the subscription management security route updates the configuration information of the mobile network operator configuration file according to the first update request message.
  • the subscription management secure route, the server and the mobile network operator profile in the communication terminal are synchronized.
  • step 2705 is not executable, and is replaced by the following steps 2705a to 2705f:
  • the server sends an activation request message to the communication terminal;
  • the communication terminal After the communication terminal acquires the activation request message sent by the server: 2705b, the communication terminal acquires a user instruction according to the activation request message; 2705c, when the user instruction is an activation instruction, the communication terminal Move Change the status of the network operator profile to the active state;
  • the communication terminal sends the activation response message to the server, where the activation response message may include a status of the mobile network operator profile.
  • the server acquires the activation response message sent by the communication terminal:
  • the server checks a status of the mobile network operator profile included in the activation response message.
  • the server sends a configuration request message to the communication terminal.
  • the security domain management system can include a trusted service manager, referring to FIG. 28, the steps are as follows:
  • the server sends a query request message to the subscription management security route, where the query request message may include the identifier of the subscription management security route and the identifier of the embedded integrated circuit card.
  • the subscription management security route obtains, according to the identifier of the subscription management security route carried in the query request, an issuer security domain configuration file of the mobile network operator configuration file corresponding to the identifier of the embedded integrated circuit card. Identify and status of the mobile network operator profile.
  • the subscription management security route sends a query response message to the server, where the query response message may include an issuer security domain configuration file identifier of the mobile network operator configuration file and a status of the mobile network operator configuration file.
  • the reason for this is to allow the server to perform secure domain management.
  • the server checks, by the query response message, the mobile network The status of the business profile.
  • the server sends a first forwarding request message to the trusted service manager, where the status of the mobile network operator profile included in the query response message is an active state, where the first forwarding request message may include The issuer security domain profile identifier, the integrated circuit card identifier, and the configuration information of the first service.
  • the configuration information of the first service may include application information and data of the first service.
  • the trusted service manager sends a first connection request message to the communication terminal, where the first connection request message may include the integrated circuit card identifier.
  • the communication terminal sends a first connection response message when the first connection request message may include that the integrated circuit card identifier matches the communication terminal itself; acquiring, by the trusted service manager, the first connection sent by the communication terminal After replying to the message, that is, after establishing a connection between the trusted service manager and the communication terminal:
  • the trusted service manager sends a first service request message to the embedded integrated circuit card, where the first service request message may include an issuer security domain profile identifier of the mobile network operator configuration file. Configuration information of the first service.
  • the communication terminal creates a sub-security domain under the mobile network operator configuration file corresponding to the issuer security domain profile identifier included in the first service request message.
  • the sub-security domain may be used to store configuration information of the first service.
  • the communication terminal allocates an identifier to the sub-security domain.
  • the communication terminal sends a first service response message to the trusted service manager, where the first service response message may include an identifier of the child security domain.
  • the trusted service manager obtains the first service response message sent by the communication terminal:
  • the trusted service manager sends a first forwarding response message to the server, where the first forwarding response message may include an identifier of a child security domain. After the server obtains the first forwarding response message sent by the trusted service manager:
  • the server records the identifier of the sub-security domain in the mobile network operator configuration file corresponding to the issuer security domain profile identifier.
  • the server sends a first update request message to the subscription management security route, where the first update request message may include configuration information of the mobile network operator configuration file.
  • the purpose of this is to enable the subscription management security route to update the configuration information of the mobile network operator profile according to the first update request message, so that the subscription management secure route, the server, and the communication terminal
  • the mobile network operator profile synchronization in the mobile network operator profile may include the type, version, and sub-security domain information of the mobile network operator profile.
  • the subscription management security route obtains the first update request message sent by the server:
  • the subscription management security route updates the configuration information of the mobile network operator configuration file according to the first update request message. Then, the subscription management security route, the server and the mobile network operator profile in the communication terminal are synchronized.
  • the mobile network operator configuration file included in the query response message The step 2805 can also be replaced by the step 2705a to the step 2705f, except that the content of the step 2705f needs to be changed to: the activation response message is included in the activation response message.
  • the server sends a first forwarding request message to the trusted service manager, where the first forwarding request message may include the issuer security domain configuration file.
  • the identification, the integrated circuit card identifier, and the configuration information of the first service may further include the following steps:
  • the server sends a query request message to the subscription management security route when the first service ends, where the query request message may include an identifier of the subscription management security route and an identifier of the embedded integrated circuit card. .
  • the contract management security route obtains the query request message sent by the server:
  • the subscription management security route acquires, according to the identifier of the subscription management security route included in the query request message, an issuer security domain configuration of the mobile network operator configuration file corresponding to the identifier of the embedded integrated circuit card.
  • the file identification and the status of the mobile network operator profile are included in the query request message.
  • the subscription management security route sends a query response message to the server, where the query response message may include the issuer security domain profile identifier and the state of the mobile network operator profile.
  • the server obtains the query response message sent by the subscription management security route:
  • the server checks a status of the mobile network operator profile included in the query response message.
  • the server sends a delete request message to the communication terminal, where the delete request message may include the issuer security.
  • Domain profile identifier and location The identity of the child security domain.
  • the communication terminal detects, according to the issuer security domain configuration file identifier and the identifier of the sub-security domain, an application and data to be saved in the sub-security domain.
  • the detecting standard of the application and the data to be saved in the sub-security domain may be preset in combination with the service content of different services in the actual application; or, the instruction input by the user in actual application may be used to determine the need. Test criteria for saved applications and data.
  • the present invention does not limit the specific content of the application and data that needs to be saved, and does not limit the specific method for detecting the application and data that needs to be saved in the sub-security domain, as long as the application and data that need to be saved can be detected. can.
  • the communication terminal sends a save request message to the server, where the save request message may include the application and data that need to be saved.
  • the server acquires the save request message sent by the communication terminal:
  • the server saves the application and data that need to be saved.
  • the server After saving the application and data that need to be saved, the server sends a save response message to the communication terminal.
  • the communication terminal deletes the transfer and data corresponding to the issuer security domain profile identifier according to the issuer security domain profile identifier and the identifier of the child security domain.
  • the communication terminal After the deletion of the sub-security domain, the communication terminal sends a deletion response message to the server, where the deletion response message may include a sub-security domain deletion success status information and an identifier of the sub-security domain.
  • the server After the server acquires the delete response message sent by the communication terminal:
  • the server deletes success status information according to the sub-security domain and the The ID of the deleted sub-security domain, and the ID of the sub-security domain in the mobile network operator profile is deleted.
  • the method may further include:
  • the server After the server deletes the identifier of the sub-security domain in the mobile network operator configuration file, the server sends a second update request message to the subscription management security route, where the second update request message may include The configuration information of the mobile network operator profile of the identifier of the sub-security domain is deleted.
  • the purpose of this is to enable the subscription management security route to update the configuration information of the mobile network operator profile according to the second update request message, so that the subscription management security route, the server, and the communication terminal The mobile network operator profile synchronization in .
  • the contract management security route obtains the second update request message sent by the server:
  • the subscription management security route updates the configuration information of the mobile network operator configuration file according to the second update request message.
  • the subscription management secure route, the server and the mobile network operator profile in the communication terminal are synchronized.
  • the step 2905 may be replaced by the following steps 2905a to 2905f:
  • the server sends an activation request message to the communication terminal.
  • the communication terminal acquires a user instruction according to the activation request message.
  • the communication terminal changes the state of the mobile network operator profile to an active state when the user command is an activation command.
  • the communication terminal sends the activation response message to the server, where The activation response message may contain the status of the mobile network operator profile.
  • the activation response message may contain the status of the mobile network operator profile.
  • the server checks a status of the mobile network operator profile included in the activation response message.
  • the server sends a deletion request message to the communication terminal.
  • the embodiment can also be completed by the following steps:
  • the server sends a query request message to the subscription management security route, where the query request message may include an identifier of the subscription management security route and an identifier of the embedded integrated circuit card.
  • the contract management security route obtains the query request message sent by the server:
  • the contract management security route sends a query response message to the server, where the query response message may include the issuer security domain profile identifier and the state of the mobile network operator profile.
  • the server obtains the query response message sent by the subscription management security route:
  • the server checks a status of the mobile network operator profile included in the query response message.
  • the second forwarding request message is sent to the trusted service manager, where the second forwarding request message may include the issuer security domain profile identifier, the integrated circuit card identifier, and the sub-security The identity of the domain.
  • the trusted service manager obtains the second forwarding request message sent by the server:
  • the trusted service manager and the communication terminal establish a connection by using the integrated circuit card identifier. Specifically, the trusted service manager sends a second connection request message to the communication terminal, where the second connection request message may include the integrated circuit card identifier, and the trusted terminal acquires the trusted After the second connection request message sent by the service manager: the communication terminal sends a second connection response message when the second connection request message may include that the integrated circuit card identifier matches the communication terminal itself. After the trusted service manager obtains the second connection response message sent by the communication terminal, that is, after the trusted service manager and the communication terminal establish a connection:
  • the trusted service manager sends a second service request message to the communication terminal, where the second service request message may include the issuer security domain profile identifier and the identifier of the child security domain. After the communication terminal acquires the second service request message sent by the trusted service manager:
  • the communication terminal detects, according to the issuer security domain configuration file identifier and the identifier of the sub-security domain, an application and data to be saved in the sub-security domain.
  • the communication terminal sends a save request message to the server, where the save request message may include the application and data that need to be saved.
  • the server acquires the save request message sent by the communication terminal:
  • the server saves the application and data that need to be saved. 301 1. After saving the application and data that need to be saved, the server sends a save response message to the communication terminal.
  • the communication terminal deletes the mobile network corresponding to the issuer security domain profile identifier according to the issuer security domain profile identifier and the identifier of the child security domain included in the second service request message.
  • the sub-security domain in the carrier profile is not limited to the issuer security domain profile identifier.
  • the communication terminal deletes the issuer security domain configuration file identifier according to the issuer security domain configuration file identifier and the identifier of the child security domain.
  • the communication terminal After the deletion of the sub-security domain, the communication terminal sends a second service response message to the trusted service manager, where the second service response message may include a sub-security domain deletion success status information and a deleted location. The identity of the child security domain. After the trusted service manager obtains the second service response message sent by the communication terminal:
  • the trusted service manager sends a second forwarding response cancellation and an identifier of the deleted sub-security domain to the server. After the server obtains the second forwarding response message sent by the trusted service manager:
  • the server deletes the identifier of the sub-security domain in the mobile network operator configuration file according to the obtained sub-security domain deletion success status information and the deleted sub-security domain identifier.
  • the method may further include:
  • the server After deleting the identifier of the sub-security domain in the mobile network operator configuration file, the server sends a second update request to the subscription management security route.
  • the second update request message may include configuration information of the mobile network operator profile in which the identifier of the sub-security domain is deleted. The purpose of this is to enable the subscription management security route to update the configuration information of the mobile network operator profile according to the second update request message, so that the subscription management security route, the server, and the communication terminal The mobile network operator profile synchronization in .
  • the subscription management security route updates configuration information of the mobile network operator configuration file according to the second update request message.
  • the subscription management secure route, the server and the mobile network operator profile in the communication terminal are synchronized.
  • the step 3005 may be replaced by step 2905a to step 2905f, except that it is noted here that The content of the step 2905f needs to be changed to:
  • the server sends a second forwarding request message to the trusted service manager, where the second forwarding request message may include The issuer security domain profile identifier, the integrated circuit card identifier, and the identifier of the sub-security domain.
  • the communication terminal provided by the embodiment of the present invention can obtain the management request message sent by the server by using the communication terminal, where the management request message The issuer security domain profile identifier may be included, and then the communication terminal manages the child security domain in the mobile network operator profile corresponding to the issuer security domain profile identifier.
  • the management request message may include a configuration request message, and the management sub-security domain may include creating a sub-security domain, where the configuration request message may further include configuration information of the first service, where the communication terminal newly signs the first service.
  • the configuration information of the first service may be stored in the
  • the management request message may include a deletion request message, the management sub-security domain may include deleting the sub-security domain, and the deletion request message may include an identifier of the sub-security domain, where the communication terminal is When the first service is terminated, the deletion of the sub-security domain may be implemented according to the identifier of the sub-security domain. Therefore, the security domain that can be used to store the first service configuration information can be managed according to the service status of the user's subscription service.
  • the security domain management method provided by the embodiment of the present invention can be used to delete the configured security domain by using a process similar to the configuration security domain. Therefore, the security domain management method provided by the embodiment of the present invention can be used in the communication terminal.
  • the configuration information and the security domain of the new subscription service are added to the mobile network operator profile, and the related security domain and configuration information are deleted when the new subscription service is terminated, and the security domain that can be used to store the first service configuration information is performed. management. It can be seen that the security domain management method provided by the embodiment of the present invention does not require the user to replace the universal integrated circuit card.
  • the security domain can be flexibly managed according to whether the user subscribes to the mobile service.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明提供了一种安全域管理方法、装置及***,涉及通信领域,能够根据用户签约业务的业务状态,对用于存储业务配置信息的安全域进行管理。具体方案为:通信终端获取服务器发送的管理请求消息,所述管理请求消息包含发行方安全域配置文件标识;所述通信终端在所述发行方安全域配置文件标识对应的移动网络运营商配置文件下管理子安全域,所述子安全域用于存储第一业务的配置信息。本发明用于安全域管理。

Description

一种安全域管理方法、 装置及*** 技术领域 本发明涉及通信领域, 尤其涉及一种安全域管理方法、 装置及系 统。 背景技术
移动通信***多使用智能卡来存储用户身份、 用户认证参数(密 钥等)和算法、 用户的电话簿和短信数据、运营商的定制参数等信息, 以方便实现用户身份和用户数据的可包含性以及运营商间的差异化 定制, 所述智能卡包括 SIM ( Subscriber Identity Module , 客户识别 模块) 卡、 USIM ( Universal Subscriber Identity Module , 全球用户识 别卡) 卡和 RUIM ( Removable User Identity Module , 可移动用户识 别 ) 卡等。
在实际应用中, 用户会向移动网络运营商定制业务, 其中就有移 动支付业务, 移动支付业务需要安全芯片来存储和管理对安全性要求 很高的支付应用和数据(例如用户 ID、 密钥、 属性参数和相关应用 )。 安全芯片可以放到手机主板上、 近场通信芯片上、 安全数码卡中, 常 见的是将所述安全芯片集成到通用集成电路卡 ( Universal Integrated Circuit Card , UICC ) 这类智能卡中, 并与通用集成电路卡中的一个 独立的安全域匹配, 专门用来存储和管理与支付等有关的高安全要求 的应用和数据。 其中通用集成电路卡又包含嵌入式通用集成电路卡 ( embedded Universal Integrated Circuit Card , eUICC )。 为了让智能 卡能满足一些应用场景和使用环境下对终端尺寸、价格和物理特性或 电气特性等所提出的特殊要求, 运营商主导的 GSMA ( Global System for Mobile communication Association 全求移动通信***十办会 ) 提出 了对嵌入式通用集成电路卡的需求。 对 eUICC 的需求至少包括: 能 在嵌入式通用 集成电路卡上创建一个移动网络运营商 ( Mobile Network Operator , MNO ) 的订购数据, 并且能在嵌入式通用集成电 路卡的移动网络运营商的订购数据中增加关于业务的配置信息和安 全域, 以对用于存储第一业务配置信息的安全域进行管理。
在欧洲电信标准化协会嵌入式通用集成电路卡的文档中,公开了 在嵌入式通用集成电路卡上创建一个在移动网络运营商 ( Mobile Network Operator , MNO ) 的订购数据的方法, 具体做法是在嵌入式 通用集成电路卡上为该移动网络运营商创建一个配置文件。 但是, 该 技术公开部分却没有涉及在用户新签约业务时, 如何在嵌入式通用集 成电路卡的移动网络运营商配置文件中增加关于新签约业务的配置 信息和安全域, 也未言明如何在用户签约的业务终结时, 如何从嵌入 式通用集成电路卡的移动网络运营商配置文件中删除关于到期业务 的配置信息和安全域。 这样, 就无法获知安全域的管理方法, 也就无法根据用户签约业 务的业务状态, 对用于存储业务配置信息的安全域进行管理。 发明内容
本发明的实施例提供一种安全域管理方法、 装置及***, 能够根 据用户签约业务的业务状态, 对用于存储业务配置信息的安全域进行 管理。
为达到上述目的, 本发明的实施例采用如下技术方案: 第一方面, 提供一种通信终端, 所述通信终端中可以预配置有移 动网络运营商配置文件, 所述通信终端包括: 获取单元, 用于获取管理请求消息, 所述管理请求消息包含发行 方安全域配置文件标识;
管理单元,用于在所述获取单元获取的所述配置请求消息包含的 所述发行方安全域配置文件标识对应的移动网络运营商配置文件下 管理子安全域, 所述子安全域用于存储第一业务的配置信息。 结合第一方面, 在第一种可能的实现方式中, 所述管理请求消息 包括配置请求消息, 所述管理子安全域包括创建子安全域; 所述获取单元,具体用于在所述第一业务新签约时获取配置请求 消息, 所述配置请求消息包含所述发行方安全域配置文件标识和所述 第一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的 应用和数据;
所述管理单元,具体用于在所述获取单元获取的所述配置请求消 息包含的所述发行方安全域配置文件标识对应的所述移动网络运营 商配置文件下创建子安全域, 并将所述第一业务的配置信息存储于所 述子安全域; 所述通信终端, 还包括:
分配单元, 用于为所述管理单元创建的所述子安全域分配标识; 所述管理单元,还用于根据所述分配单元分配的所述子安全域的 标识管理所述子安全域。 结合第一方面中第一种可能的实现方式,在第二种可能的实现方 式中, 所述通信终端还包括: 第一发送单元, 用于发送配置应答消息, 所述配置应答消息包含 所述分配单元分配的所述子安全域的标识, 以便服务器根据所述配置 应答消息管理所述子安全域。 结合第一方面, 在第三种可能的实现方式中, 所述管理请求消息 包括删除请求消息, 所述管理子安全域包括删除子安全域; 所述获取单元,具体用于在所述第一业务终结时获取删除请求消 息, 所述删除请求消息包含所述发行方安全域配置文件标识和所述子 安全域的标识; 所述管理单元,具体用于根据所述获取单元获取的所述删除请求 消息包含的所述发行方安全域配置文件标识和所述子安全域的标识, 删除所述发行方安全域配置文件标识对应的所述移动网络运营商配 置文件中的所述子安全域。 结合第一方面中第三种可能的实现方式,在第四种可能的实现方 式中, 所述通信终端还包括: 检测单元,用于根据所述获取单元获取的所述删除请求消息包含 的所述发行方安全域配置文件标识和所述子安全域的标识, 检测所述 子安全域中需要保存的应用和数据; 第二发送单元, 用于发送保存请求消息, 所述保存请求消息包含 所述检测单元检测的所述需要保存的应用和数据, 以便服务器根据所 述保存请求消息保存所述需要保存的应用和数据; 所述管理单元,具体用于在所述第二发送单元发送所述保存请求 消息后, 根据所述获取单元获取的所述发行方安全域配置文件标识和 所述子安全域的标识, 删除所述发行方安全域配置文件标识对应的所 的应用和数据。 结合第一方面中第三种或第四种可能的实现方式,在第五种可能 的实现方式中, 所述通信终端还包括: 第三发送单元, 用于在所述管理单元删除所述子安全域后, 发送 删除应答消息, 所述删除应答消息包含子安全域删除成功状态信息和 所述管理单元删除的所述子安全域的标识。 结合第一方面或第一种至第五种可能的实现方式中的任一种,在 第六二种可能的实现方式中, 所述获取单元, 还用于获取激活请求消 息;
所述获取单元,还用于根据所述获取单元获取的所述激活请求消 息获取用户指令; 所述通信终端, 还包括: 变更单元,用于在所述获取单元获取的所述用户指令为激活指令 时, 将所述移动网络运营商配置文件的状态变更为激活状态; 第四发送单元, 用于发送所述激活应答消息, 所述激活应答消息 包含所述变更单元变更的所述移动网络运营商配置文件的状态。 第二方面, 提供一种服务器, 所述服务器中可以预配置有移动网 络运营商配置文件, 所述服务器包括: 发送单元, 用于向签约管理安全路由发送查询请求消息, 所述查 询请求消息包含所述签约管理安全路由的标识和嵌入式集成电路卡 的标识; 获取单元, 用于获取所述签约管理安全路由发送的查询应答消 息, 所述查询应答消息包含移动网络运营商配置文件的发行方安全域 配置文件标识和所述移动网络运营商配置文件的状态; 检查单元,用于检查所述获取单元获取的所述查询应答消息包含 的所述移动网络运营商配置文件的状态; 所述发送单元,还用于在所述检查单元检查的所述查询应答消息 包含的所述移动网络运营商配置文件的状态是激活状态时发送管理 请求消息,以便通信终端根据所述管理请求消息管理子安全域,其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息。
结合第二方面, 在第一种可能的实现方式中, 所述管理请求消息 包括配置请求消息, 所述管理子安全域包括创建子安全域;
所述发送单元,还用于在所述检查单元检查的所述查询应答消息 包含的所述移动网络运营商配置文件的状态是激活状态时发送管理 请求消息,以便通信终端根据所述管理请求消息管理子安全域,其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息, 具体包括:
在所述第一业务新签约并且所述检查单元检查的所述查询应答 消息包含的所述移动网络运营商配置文件的状态是激活状态时发送 配置请求消息, 以便通信终端根据所述管理请求消息创建子安全域, 其中, 所述配置请求消息包含所述发行方安全域配置文件标识和所述 第一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的 应用信息和数据。 结合第二方面中第一种可能的实现方式,在第二种可能的实现方 式中, 所述获取单元, 还用于获取配置应答消息, 所述配置应答消息 包含子安全域的标识; 所述服务器还包括: 配置单元,用于将所述获取单元获取的所述子安全域的标识记录 在所述发行方安全域配置文件标识对应的所述移动网络运营商配置 文件中。
结合第二方面中第二种可能的实现方式,在第三种可能的实现方 式中, 所述发送单元, 还用于在所述配置单元将所述子安全域的标识 记录在所述发行方安全域配置文件标识对应的所述移动网络运营商 配置文件中之后, 向所述签约管理安全路由发送第一更新请求消息; 其中,所述第一更新请求消息中包含所述移动网络运营商配置文 件的配置信息, 以便所述签约管理安全路由按照所述第一更新请求消 息更新所述移动网络运营商配置文件的配置信息, 所述移动网络运营 商配置文件的配置信息包含移动网络运营商配置文件的类型、 版本和 子安全域信息。 结合第二方面, 在第四种可能的实现方式中, 所述管理请求消息 包括删除请求消息, 所述管理子安全域包括删除子安全域; 所述获取单元,还用于在所述第一业务终结时获取子安全域的标 识;
所述发送单元,还用于在所述检查单元检查的所述查询应答消息 包含的所述移动网络运营商配置文件的状态是激活状态时发送管理 请求消息,以便通信终端根据所述管理请求消息管理子安全域,其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息, 具体包括:
在所述检查单元检查的所述查询应答消息包含的所述移动网络 运营商配置文件的状态是激活状态时发送删除请求消息, 以便通信终 端根据所述管理请求消息删除子安全域, 其中, 所述删除请求消息包 含所述发行方安全域配置文件标识和所述子安全域的标识。
结合第二方面中第四种可能的实现方式,在第五种可能的实现方 式中, 所述获取单元, 还用于获取保存请求消息, 所述保存请求消息 包含需要保存的应用和数据;
所述服务器还包括: 保存单元,用于根据所述获取单元获取的所述保存请求消息保存 所述需要保存的应用和数据。
结合第二方面中第四种或第五种可能的实现方式,在第六种可能 的实现方式中, 所述获取单元, 还用于获取删除应答消息, 所述删除 应答消息包含子安全域删除成功状态信息和被删除的子安全域的标 识; 所述服务器还包括: 配置单元,用于根据所述获取单元获取的所述子安全域删除成功 状态信 , I,和所述被删除的子安全域的标识, 删除所述移动网络运营商 配置文件中的子安全域的标识。 结合第二方面中第六种可能的实现方式,在第七种可能的实现方 式中, 所述发送单元, 还用于在所述配置单元删除了所述移动网络运 营商配置文件中的子安全域的标识之后, 向所述签约管理安全路由发 送第二更新请求消息; 其中,所述第二更新请求消息中包含被所述配置单元删除了所述 子安全域的标识的所述移动网络运营商配置文件的配置信息, 以便所 述签约管理安全路由按照所述第二更新请求消息更新所述移动网络 运营商配置文件的配置信息。
结合第二方面或第一种至第七种可能的实现方式,在第八种可能 的实现方式中, 所述发送单元, 还用于在所述检查单元检查的所述查 询应答消息包含的所述移动网络运营商配置文件的状态是未激活状 态时发送激活请求消息; 所述获取单元, 还用于获取激活应答消息, 所述激活应答消息包 含所述移动网络运营商配置文件的状态; 所述检查单元,还用于检查所述获取单元获取的所述激活应答消 息包含的所述移动网络运营商配置文件的状态; 所述发送单元,还用于在所述检查单元检查的所述激活应答消息 包含的所述移动网络运营商配置文件的状态是激活状态时发送管理 请求消息。
第三方面, 提供一种通信终端, 所述通信终端包括: 网络接口、 处理器及总线, 其中, 所述网络接口、 所述处理器通过所述总线相互 连接,
其中, 所述网络接口, 用于获取管理请求消息, 所述管理请求消 息包含发行方安全域配置文件标识; 所述处理器,用于在所述网络接口获取的所述配置请求消息包含 的所述发行方安全域配置文件标识对应的移动网络运营商配置文件 下管理子安全域, 所述子安全域用于存储第一业务的配置信息。 结合第三方面, 在第一种可能的实现方式中, 所述管理请求消息 包括配置请求消息, 所述管理子安全域包括创建子安全域;
所述网络接口,具体用于在所述第一业务新签约时获取配置请求 消息, 所述配置请求消息包含所述发行方安全域配置文件标识和所述 第一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的 应用和数据;
所述处理器,具体用于在所述网络接口获取的所述配置请求消息 包含的所述发行方安全域配置文件标识对应的所述移动网络运营商 配置文件下创建子安全域, 并将所述第一业务的配置信息存储于所述 子安全域;
所述处理器, 还用于为所述处理器创建的所述子安全域分配标 识;
所述处理器,还用于根据所述处理器分配的所述子安全域的标识 管理所述子安全域。 结合第三方面中第一种可能的实现方式,在第二种可能的实现方 式中, 所述网络接口, 还用于发送配置应答消息, 所述配置应答消息 包含所述处理器分配的所述子安全域的标识, 以便服务器根据所述配 置应答消息管理所述子安全域。 结合第三方面, 在第三种可能的实现方式中, 所述管理请求消息 包括删除请求消息, 所述管理子安全域包括删除子安全域; 所述网络接口,具体用于在所述第一业务终结时获取删除请求消 息, 所述删除请求消息包含所述发行方安全域配置文件标识和所述子 安全域的标识; 所述处理器,具体用于根据所述网络接口获取的所述删除请求消 息包含的所述发行方安全域配置文件标识和所述子安全域的标识, 删 除所述发行方安全域配置文件标识对应的所述移动网络运营商配置 文件中的所述子安全域。 结合第三方面中第三种可能的实现方式,在第四种可能的实现方 式中, 所述处理器, 还用于根据所述网络接口获取的所述删除请求消 息包含的所述发行方安全域配置文件标识和所述子安全域的标识,检 测所述子安全域中需要保存的应用和数据; 所述网络接口, 还用于发送保存请求消息, 所述保存请求消息包 含所述处理器检测的所述需要保存的应用和数据, 以便服务器根据所 述保存请求消息保存所述需要保存的应用和数据; 所述处理器, 具体用于在所述网络接口发送所述保存请求消息 后, 根据所述网络接口获取的所述发行方安全域配置文件标识和所述 子安全域的标识, 删除所述发行方安全域配置文件标识对应的所述移 用和数据。 结合第三方面中第三种或第四种可能的实现方式,在第五种可能 的实现方式中, 所述网络接口, 还用于在所述处理器删除所述子安全 域后, 发送删除应答消息, 所述删除应答消息包含子安全域删除成功 状态信息和所述处理器删除的所述子安全域的标识。 结合第三方面或第一种至第五种可能的实现方式中的任一种,在 第六二种可能的实现方式中, 所述网络接口, 还用于获取激活请求消 息;
所述网络接口,还用于根据所述网络接口获取的所述激活请求消 息获取用户指令; 所述处理器,还用于在所述网络接口获取的所述用户指令为激活 指令时, 将所述移动网络运营商配置文件的状态变更为激活状态; 所述网络接口, 还用于发送所述激活应答消息, 所述激活应答消 息包含所述处理器变更的所述移动网络运营商配置文件的状态。 第四方面, 提供一种服务器, 所述服务器包括: 网络接口、 处理 器及总线, 其中, 所述网络接口、 所述处理器通过所述总线相互连接, 其中, 所述网络接口, 用于向签约管理安全路由发送查询请求消 息, 所述查询请求消息包含所述签约管理安全路由的标识和嵌入式集 成电路卡的标识; 所述网络接口,还用于获取所述签约管理安全路由发送的查询应 答消息, 所述查询应答消息包含移动网络运营商配置文件的发行方安 全域配置文件标识和所述移动网络运营商配置文件的状态; 所述处理器,用于检查所述网络接口获取的所述查询应答消息包 含的所述移动网络运营商配置文件的状态; 所述网络接口,还用于在所述处理器检查的所述查询应答消息包 含的所述移动网络运营商配置文件的状态是激活状态时发送管理请 求消息, 以便通信终端根据所述管理请求消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息。 结合第四方面, 在第一种可能的实现方式中, 所述管理请求消息 包括配置请求消息, 所述管理子安全域包括创建子安全域;
所述网络接口 ,还用于在所述处理器检查的所述查询应答消息包 含的所述移动网络运营商配置文件的状态是激活状态时发送管理请 求消息, 以便通信终端根据所述管理请求消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息, 具体包括:
在所述第一业务新签约并且所述处理器检查的所述查询应答消 息包含的所述移动网络运营商配置文件的状态是激活状态时发送配 置请求消息, 以便通信终端根据所述管理请求消息创建子安全域, 其 中, 所述配置请求消息包含所述发行方安全域配置文件标识和所述第 一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的应 用信息和数据。 结合第四方面中第一种可能的实现方式,在第二种可能的实现方 式中, 所述网络接口, 还用于获取配置应答消息, 所述配置应答消息 包含子安全域的标识; 所述处理器,还用于将所述网络接口获取的所述子安全域的标识 记录在所述发行方安全域配置文件标识对应的所述移动网络运营商 配置文件中。 结合第四方面中第二种可能的实现方式,在第三种可能的实现方 式中, 所述网络接口, 还用于在所述处理器将所述子安全域的标识记 录在所述发行方安全域配置文件标识对应的所述移动网络运营商配 置文件中之后, 向所述签约管理安全路由发送第一更新请求消息; 其中,所述第一更新请求消息中包含所述移动网络运营商配置文 件的配置信息, 以便所述签约管理安全路由按照所述第一更新请求消 息更新所述移动网络运营商配置文件的配置信息, 所述移动网络运营 商配置文件的配置信息包含移动网络运营商配置文件的类型、 版本和 子安全域信息。 结合第四方面, 在第四种可能的实现方式中, 所述管理请求消息 包括删除请求消息, 所述管理子安全域包括删除子安全域; 所述网络接口,还用于在所述第一业务终结时获取子安全域的标 识;
所述网络接口,还用于在所述处理器检查的所述查询应答消息包 含的所述移动网络运营商配置文件的状态是激活状态时发送管理请 求消息, 以便通信终端根据所述管理请求消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息, 具体包括: 在所述处理器检查的所述查询应答消息包含的所述移动网络运 营商配置文件的状态是激活状态时发送删除请求消息, 以便通信终端 根据所述管理请求消息删除子安全域, 其中, 所述删除请求消息包含 所述发行方安全域配置文件标识和所述子安全域的标识。
结合第四方面中第四种可能的实现方式,在第五种可能的实现方 式中, 所述网络接口, 还用于获取保存请求消息, 所述保存请求消息 包含需要保存的应用和数据;
所述服务器还包括: 存储器, 所述存储器通过所述总线与所述网 络接口、 所述处理器相互连接; 所述存储器,用于根据所述网络接口获取的所述保存请求消息保 存所述需要保存的应用和数据。 结合第四方面中第四种或第五种可能的实现方式,在第六种可能 的实现方式中, 所述网络接口, 还用于获取删除应答消息, 所述删除 应答消息包含子安全域删除成功状态信息和被删除的子安全域的标 识;
所述处理器,还用于根据所述网络接口获取的所述子安全域删除 成功状态信, IT和所述被删除的子安全域的标识, 删除所述移动网络运 营商配置文件中的子安全域的标识。 结合第四方面中第六种可能的实现方式,在第七种可能的实现方 式中, 所述网络接口, 还用于在所述处理器删除了所述移动网络运营 商配置文件中的子安全域的标识之后, 向所述签约管理安全路由发送 第二更新请求消息; 其中,所述第二更新请求消息中包含被所述处理器删除了所述子 安全域的标识的所述移动网络运营商配置文件的配置信息, 以便所述 签约管理安全路由按照所述第二更新请求消息更新所述移动网络运 营商配置文件的配置信息。 结合第四方面或第一种至第七种可能的实现方式,在第八种可能 的实现方式中, 所述网络接口, 还用于在所述处理器检查的所述查询 应答消息包含的所述移动网络运营商配置文件的状态是未激活状态 时发送激活请求消息;
所述网络接口, 还用于获取激活应答消息, 所述激活应答消息包 含所述移动网络运营商配置文件的状态; 所述处理器,还用于检查所述网络接口获取的所述激活应答消息 包含的所述移动网络运营商配置文件的状态; 所述网络接口,还用于在所述处理器检查的所述激活应答消息包 含的所述移动网络运营商配置文件的状态是激活状态时发送管理请 求消息。
第五方面, 提供一种安全域管理方法, 中可以预配置有移动网络 运营商配置文件, 所述安全域管理方法包括: 获取管理请求消息,所述管理请求消息包含发行方安全域配置文 件标识; 在所述发行方安全域配置文件标识对应的移动网络运营商配置 文件下管理子安全域, 所述子安全域用于存储所述第一业务的配置信 息。 结合第五方面, 在第一种可能的实现方式中, 所述管理请求消息 包括配置请求消息, 所述管理子安全域包括创建子安全域; 在所述第一业务新签约时获取管理请求消息,所述管理请求消 , 包含发行方安全域配置文件标识, 具体包括:
获取配置请求消息,所述配置请求消息包含所述移动网络运营商 配置文件的发行方安全域配置文件标识和所述第一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的应用和数据; 在所述发行方安全域配置文件标识对应的移动网络运营商配置 文件下管理子安全域, 所述子安全域用于存储所述第一业务的配置信 息, 具体包括:
在所述发行方安全域配置文件标识对应的所述移动网络运营商 配置文件下创建子安全域, 所述子安全域用于存储所述第一业务的配 置信息;
所述安全域管理方法还包括: 为所述子安全域分配标识; 根据所述子安全域的标识管理所述子安全域。
结合第五方面中第一种可能的实现方式,在第二种可能的实现方 式中, 为所述子安全域分配标识之后, 所述安全域管理方法还包括: 发送配置应答消息, 所述配置应答消息包含所述子安全域的标 识, 以便服务器根据所述配置应答消息管理所述子安全域。 结合第五方面, 在第三种可能的实现方式中, 所述管理请求消息 包括删除请求消息, 所述管理子安全域包括删除子安全域; 在所述第一业务终结时获取管理请求消息,所述管理请求消 , 包 含发行方安全域配置文件标识, 具体包括:
获取删除请求消息,所述删除请求消息包含所述发行方安全域配 置文件标识和所述子安全域的标识; 在所述发行方安全域配置文件标识对应的移动网络运营商配置 文件下管理子安全域, 所述子安全域用于存储所述第一业务的配置信 息, 具体包括: 根据所述删除请求消息包含的所述发行方安全域配置文件标识 和所述子安全域的标识, 删除所述发行方安全域配置文件标识对应的 所述移动网络运营商配置文件中的所述子安全域。 结合第五方面中第三种可能的实现方式,在第四种可能的实现方 式中, 根据所述删除请求消息包含的所述发行方安全域配置文件标识 和所述子安全域的标识, 删除所述发行方安全域配置文件标识对应的 所述移动网络运营商配置文件中的所述子安全域之前, 所述方法还包 括: 根据所述删除请求消息包含的所述发行方安全域配置文件标识 和所述子安全域的标识, 检测所述子安全域中需要保存的应用和数 据; 发送保存请求消息,所述保存请求消息包含所述需要保存的应用 和数据, 以便服务器根据所述保存请求消息保存所述需要保存的应用 和数据; 根据所述删除请求消息包含的所述发行方安全域配置文件标识 和所述子安全域的标识, 删除所述发行方安全域配置文件标识对应的 所述移动网络运营商配置文件中的所述子安全域, 具体包括: 在发送所述保存请求消息后,根据所述删除请求消息包含的所述 发行方安全域配置文件标识和所述子安全域的标识, 删除所述发行方 安全域配置文件标识对应的所述移动网络运营商配置文件中的所述
结合第五方面中第三种或第四种可能的实现方式,在第五种可能 的实现方式中, 所述方法还包括: 在删除所述子安全域后, 发送删除应答消息, 所述删除应答消息 包含子安全域删除成功状态信息和所述子安全域的标识。 结合第五方面或第一种至第五种可能的实现方式中的任一种,在 第六二种可能的实现方式中, 获取管理请求消息之前所述方法还包 括: 获取激活请求消息; 根据所述激活请求消息获取用户指令; 在所述用户指令为激活指令时,将所述移动网络运营商配置文件 的状态变更为激活状态; 发送所述激活应答消息,所述激活应答消息包含所述移动网络运 营商配置文件的状态。 第六方面, 提供一种安全域管理方法, 中可以预配置有移动网络 运营商配置文件, 所述方法包括: 向签约管理安全路由发送查询请求消息,所述查询请求消息包含 所述签约管理安全路由的标识和嵌入式集成电路卡的标识; 获取所述签约管理安全路由发送的查询应答消息,所述查询应答 消息包含移动网络运营商配置文件的发行方安全域配置文件标识和 所述移动网络运营商配置文件的状态; 检查所述查询应答消息包含的所述移动网络运营商配置文件的 状态;
在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送管理请求消息, 以便通信终端根据所述管理请求 消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域 配置文件标识, 所述子安全域用于存储第一业务的配置信息。 结合第六方面, 在第一种可能的实现方式中, 所述管理请求消息 包括配置请求消息, 所述管理子安全域包括创建子安全域; 在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送管理请求消息, 以便通信终端根据所述管理请求 消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域 配置文件标识, 所述子安全域用于存储第一业务的配置信息, 具体包 括:
在所述第一业务新签约并且所述查询应答消息包含的所述移动 网络运营商配置文件的状态是激活状态时发送配置请求消息, 以便通 信终端根据所述管理请求消息管理子安全域, 其中, 所述配置请求消 息包含所述发行方安全域配置文件标识和所述第一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的应用信息和数据。
结合第六方面中第一种可能的实现方式,在第二种可能的实现方 式中, 所述方法包括:
获取配置应答消息, 所述配置应答消息包含子安全域的标识; 将所述子安全域的标识记录在所述发行方安全域配置文件标识 对应的所述移动网络运营商配置文件中。 结合第六方面中第二种可能的实现方式,在第三种可能的实现方 式中, 将所述子安全域的标识记录在所述发行方安全域配置文件标识 对应的所述移动网络运营商配置文件中之后, 所述方法还包括:
向所述签约管理安全路由发送第一更新请求消息; 其中,所述第一更新请求消息中包含所述移动网络运营商配置文 件的配置信息, 以便所述签约管理安全路由按照所述第一更新请求消 息更新所述移动网络运营商配置文件的配置信息, 所述移动网络运营 商配置文件的配置信息包含移动网络运营商配置文件的类型、 版本和 子安全域信息。
结合第六方面, 在第四种可能的实现方式中, 所述管理请求消息 包括删除请求消息, 所述管理子安全域包括删除子安全域;
在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送管理请求消息, 以便通信终端根据所述管理请求 消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域 配置文件标识, 所述子安全域用于存储第一业务的配置信息之前, 所 述方法还包括: 在所述第一业务终结时获取子安全域的标识;
在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送管理请求消息, 以便通信终端根据所述管理请求 消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域 配置文件标识, 所述子安全域用于存储第一业务的配置信息, 具体包 括:
在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送删除请求消息, 以便通信终端根据所述管理请求 消息删除子安全域, 所述删除请求消息包含所述发行方安全域配置文 件标识和所述子安全域的标识。 结合第六方面中第四种可能的实现方式,在第五种可能的实现方 式中, 所述方法还包括:
获取保存请求消息,所述保存请求消息包含需要保存的应用和数 据;
根据所述保存请求消息保存所述需要保存的应用和数据。
结合第六方面中第四种或第五种可能的实现方式,在第六种可能 的实现方式中, 所述方法还包括: 获取删除应答消息,所述删除应答消息包含子安全域删除成功状 态信 , 和被删除的子安全域的标识; 根据所述子安全域删除成功状态信息和所述被删除的子安全域 的标识, 删除所述移动网络运营商配置文件中的子安全域的标识。 结合第六方面中第六种可能的实现方式,在第七种可能的实现方 式中, 根据所述子安全域删除成功状态信息和所述被删除的子安全域 的标识, 删除所述移动网络运营商配置文件中的子安全域的标识之 后, 所述方法还包括: 在删除了所述移动网络运营商配置文件中的子安全域的标识之 后, 向所述签约管理安全路由发送第二更新请求消息; 其中,所述第二更新请求消息中包含被删除了所述子安全域的标 识的所述移动网络运营商配置文件的配置信息, 以便所述签约管理安 全路由按照所述第二更新请求消息更新所述移动网络运营商配置文 件的配置信息。 结合第六方面或第一种至第七种可能的实现方式,在第八种可能 的实现方式中, 获取管理应答消息之前, 所述方法还包括:
如果所述查询应答消息包含的所述移动网络运营商配置文件的 状态是未激活状态, 则发送激活请求消息; 获取激活应答消息,所述激活应答消息包含所述移动网络运营商 配置文件的状态; 检查所述激活应答消息包含的所述移动网络运营商配置文件的 状态;
在所述激活应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送删除请求消 , 。 本发明提供的安全域管理方法、 装置及***, 能通过通信终端获 取管理请求消息, 其中, 所述管理请求消息包含所述发行方安全域配 置文件标识, 然后, 所述通信终端在所述发行方安全域配置文件标识 对应的移动网络运营商配置文件中管理子安全域。 所述管理请求消息 包括配置请求消息, 管理子安全域包括创建子安全域, 所述配置请求 消息还包含第一业务的配置信息, 在所述第一业务新签约时, 可以将 所述第一业务的配置信息存储于所述子安全域中; 所述管理请求消息 包括删除请求消息, 管理子安全域包括删除子安全域, 并且所述删除 请求消息包含所述子安全域的标识, 在所述第一业务终结时, 可以根 据所述子安全域的标识实现对所述子安全域的删除。 所以本发明提供 的安全域管理方法、 装置及***能够根据用户签约业务的业务状态, 对用于存储第一业务配置信息的安全域进行管理。 附图说明 为了更清楚地说明本发明实施例或现有技术中的技术方案,下面 将对实施例或现有技术描述中所需要使用的附图作简单地介绍, 显而 易见地, 下面描述中的附图仅仅是本发明的一些实施例, 对于本领域 普通技术人员来讲, 在不付出创造性劳动的前提下, 还可以根据这些 附图获得其他的附图。
图 1 为本发明的实施例提供的一种安全域管理***的***示意 图;
图 2为本发明的实施例提供的一种通信终端的结构示意图; 图 3为本发明的实施例提供的又一种通信终端的结构示意图; 图 4为本发明的实施例提供的另一种通信终端的结构示意图; 图 5为本发明的实施例提供的再一种通信终端的结构示意图; 图 6为本发明的实施例提供的还有一种通信终端的结构示意图; 图 7为本发明的实施例提供的再有一种通信终端的结构示意图; 图 8为本发明的实施例提供的又有一种通信终端的结构示意图; 图 9为本发明的实施例提供的一种服务器的结构示意图; 图 10为本发明的实施例提供的又一种服务器的结构示意图; 图 1 1为本发明的实施例提供的另一种服务器的结构示意图; 图 12为本发明的实施例提供的一种签约管理安全路由的结构示 意图;
图 13 为本发明的实施例提供的又一种签约管理安全路由的结构 示意图; 图 14为本发明的实施例提供的一种可信服务管理器的结构示意 图;
图 15 为本发明的又一实施例提供的一种通信终端的结构示意 图;
图 16为本发明的又一实施例提供的一种服务器的结构示意图; 图 17为本发明的又一实施例提供的一种签约管理安全路由的结 构示意图; 图 18为本发明的又一实施例提供的一种可信服务管理器的结构 示意图; 图 19为本发明的实施例提供的一种安全域管理方法的流程示意 图; 图 20为本发明的又一实施例提供的一种安全域管理方法的流程 一 _思 图 21 为本发明的另一实施例提供的一种安全域管理方法的流程 一 _思 图 22为本发明的另一实施例提供的又一种安全域管理方法的流 程示思图; 图 23 为本发明的再一实施例提供的一种安全域管理方法的流程 一 _思 图 24为本发明的再一实施例提供的又一种安全域管理方法的流 程示思图;
25为本发明的实施例提供的一种安全域管理方法的流程示意 图;
图 26为本发明的实施例提供的一种安全域管理方法的流程示意 图;
图 27为本发明的实施例提供的一种安全域管理方法的数据交互 示意图; 图 28为本发明的实施例提供的又一种安全域管理方法的数据交 互示意图; 图 29为本发明的实施例提供的另一种安全域管理方法的数据交 互示意图;
图 30为本发明的实施例提供的再一种安全域管理方法的数据交 互示意图。 具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方 案进行清楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部 分实施例, 而不是全部的实施例。 基于本发明中的实施例, 本领域普 通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例, 都属于本发明保护的范围。
参照图 1所示, 本发明的实施例提供一种安全域管理***, 所述 安全域管理***可以包含可以相互通信的服务器、 通信终端以及签约 管理安全路由 ( Subscription Manager Secure Routing , SM-SR )。 其中, 所述服务器, 可以用于承载移动网络运营商 ( Mobile Network Operator , ΜΝΟ ) 的月良务, 具体可以用于发出消息, 以通知 所述通信终端管理预配置于所述通信终端自身的移动网络运营商配 置文件中的安全域, 所述安全域可以用于存储第一业务的配置信息, 参考图中以 ΜΝΟ表示所述服务器; 所述第一业务可以是移动支付业 务, 或者其他支付类业务, 或者其他需要使用安全域存储业务配置信 息的业务。 所述通信终端, 可以是嵌入式通用 集成电路卡 ( embedded Universal Integrated Circuit Card , eUICC ) 本身, 也可以是承载所述 嵌入式通用集成电路卡的装置, 所述通信终端可以用于根据所述服务 器发出的消息, 管理所述通信终端自身的移动网络运营商配置文件中 的安全域, 以 eUICC为例在附图中表示所述通信终端。 因为移动支付业务需要安全芯片来存储和管理对安全性要求很 高的支付应用和数据 (例如用户 ID、 密钥、 属性参数和相关应用 )。 所述安全芯片可以放到手机主板上、近场通信芯片上、安全数码卡中, 或者集成到通用集成电路卡中, 并与通用集成电路卡中的一个独立的 安全域匹配, 专门用来存储和管理与支付等有关的高安全要求的应用 和数据, 其中所述通用集成电路卡可以包含所述嵌入式通用集成电路 卡。 因此, 能够承载所述安全芯片的通信终端, 也可为本发明实施例 提供的安全域管理***中的所述通信终端可以包含。
具体的, 所述通信终端中可以预配置有嵌入式通用集成电路卡; 其中, 所述通信终端可以用于实现所述嵌入式通用集成电路卡与其他 设备的数据通信, 所述数据通信可以包括获取数据信息和发送数据信 息中的至少一种; 还可以用于实现为所述嵌入式通用集成电路卡计算 所需要的数据。 其中, 所述嵌入式通用集成电路卡可以通过承载自身 的通信终端完成信息处理、 信息通信等功能, 仅仅只根据承载所述嵌 入式通用集成电路卡的通信终端获得的各种数据, 实现对所述安全域 的管理, 还可以存储有所述移动网络运营商配置文件。 所述签约管理安全路由,可以用于存储所述移动网络运营商配置 文件相关信息, 例如所述移动网络运营商配置文件的发行方安全域配 置文件标识; 并可以存储所述移动网络运营商配置文件中的安全域的 相关信息, 例如所述安全域的标识。 可选的, 所述安全域管理***还可以包含可信服务管理器。 所述 可信服务管理器可以用 于实现可信服务管理 ( Trusted Sercive Management , TSM ) , 同样可与所述安全域管理***中的其他装置进 行通信。 所述可信服务管理器可以用于在所述服务器不直接与所述通 信终端进行通信时, 在所述服务器与所述通信终端之间传递两者进行 通信的通信数据, 参考图中以 TSM表示所述可信服务管理器。 其中, 在所述安全域管理***不可以包含所述可信服务管理器 时, 服务器可以 自行管理需要可信服务管理器管理的内容, 直接与所 述通信终端进行通信。 所述安全域管理***可以应用于通信领域,可以应用于在用户新 签约第一业务时, 在通信终端的移动网络运营商配置文件 ( Mobile Network Operator Profile , MNO Profile ) 中创建可以用于存储所述第 一业务的配置信息的安全域。 可选的, 所述安全域管理***还可以应用于所述第一业务终结 (如到期或用户解约) 时的场景, 此时, 可以在所述嵌入式通用集成 电路卡侧装置的移动网络运营商配置文件中删除可以用于存储所述 第一业务的配置信息的安全域。 本发明实施例提供的安全域管理***,能通过通信终端获取发送 的管理请求消息, 其中, 所述管理请求消息可以包含所述发行方安全 域配置文件标识, 然后, 所述通信终端在所述发行方安全域配置文件 标识对应的移动网络运营商配置文件中管理子安全域。 在所述第一业 务新签约时, 所述管理请求消息可以包括配置请求消息, 管理子安全 域可以包括创建子安全域, 所述配置请求消息还可以包含第一业务的 配置信息, 所述通信终端可以将所述第一业务的配置信息存储于所述 子安全域中; 在所述第一业务终结时, 所述管理请求消息可以包括删 除请求消息, 管理子安全域可以包括删除子安全域, 并且所述删除请 求消息可以包含所述子安全域的标识, 所述通信终端可以根据所述子 安全域的标识实现对所述子安全域的删除。 所以本发明提供的安全域 管理***能够根据用户签约业务的业务状态, 对可以用于存储第一业 务配置信息的安全域进行管理。 参照图 2所示, 本发明的实施例提供一种通信终端, 可以应用于 通信领域, 可以应用于图 1所示的安全域管理***, 所述通信终端中 可以预配置有移动网络运营商配置文件, 所述通信终端可以包括: 获取单元 201 , 可以用于获取所述服务器发送的管理请求消息, 所述管理请求消息可以包含发行方安全域配置文件 ( Issuer Security Domain Profile , ISD-P ) 标识 ( Application ID , AID ); 管理单元 202 , 可以用于在所述获取单元 201获取的所述配置请 求消息包含的所述发行方安全域配置文件标识对应的移动网络运营 商配置文件下管理子安全域, 所述子安全域可以用于存储第一业务的 配置信息。
可选的, 所述管理请求消息可以包括配置请求消息, 所述管理子 安全域可以包括创建子安全域; 所述获取单元 201 , 具体可以用于在所述第一业务新签约时获取 配置请求消息, 例如获取所述服务器发送的配置请求消息, 所述配置 请求消息可以包含所述发行方安全域配置文件标识和所述第一业务 的配置信息, 所述第一业务的配置信息可以包含所述第一业务的应用 和数据;
所述管理单元 202 , 具体可以用于在所述获取单元 201获取的所 述配置请求消息包含的所述发行方安全域配置文件标识对应的所述 移动网络运营商配置文件下创建子安全域, 并将所述第一业务的配置 信息存储于所述子安全域;
此时, 参照图 3所示, 所述通信终端, 还可以包括: 分配单元 203 , 可以用于为所述管理单元 202创建的所述子安全 i或分配标识; 所述管理单元,还可以用于根据所述分配单元分配的所述子安全 域的标识管理所述子安全域。 此时, 可选的, 参照图 4所示, 所述通信终端还可以包括: 第一发送单元 204 , 可以用于发送配置应答消息, 例如向所述服 务器发送配置应答消息, 所述配置应答消息可以包含所述分配单元 203分配的所述子安全域的标识, 以便所述服务器根据所述配置应答 消息管理所述子安全域。
可选的, 所述管理请求消息可以包括删除请求消息, 所述管理子 安全域可以包括删除子安全域; 所述获取单元 201 , 具体可以用于在所述第一业务终结时获取删 除请求消息, 例如获取所述服务器发送的删除请求消息, 所述删除请 求消息可以包含所述发行方安全域配置文件标识和所述子安全域的 标识;
所述管理单元 202 , 具体可以用于根据所述获取单元 201获取的 所述删除请求消息包含的所述发行方安全域配置文件标识和所述子 安全域的标识, 删除所述发行方安全域配置文件标识对应的所述移动 网络运营商配置文件中的所述子安全域。
此时可选的, 参照图 5所示, 所述通信终端还可以包括: 检测单元 205 , 可以用于根据所述获取单元 201获取的所述删除 请求消息包含的所述发行方安全域配置文件标识和所述子安全域的 标识, 检测所述子安全域中需要保存的应用和数据; 第二发送单元 206 , 可以用于发送保存请求消息, 例如向所述服 务器发送保存请求消息, 所述保存请求消息可以包含所述检测单元 205检测的所述需要保存的应用和数据, 以便所述服务器根据所述保 存请求消息保存所述需要保存的应用和数据;
所述管理单元 202 , 具体可以用于在所述第二发送单元 206发送 所述保存请求消息后, 根据所述获取单元 201获取的所述发行方安全 域配置文件标识和所述子安全域的标识, 删除所述发行方安全域配置 文件标识对应的所述移动网络运营商配置文件中的所述子安全域以 及所述子安全域中的应用和数据。
可选的, 参照图 6所示, 所述通信终端还可以包括: 第三发送单元 207 , 可以用于在所述管理单元 202删除所述子安 全域后, 发送删除应答消息, 例如向所述服务器发送删除应答消息, 所述删除应答消息可以包含子安全域删除成功状态信息和所述管理 单元 202删除的所述子安全域的标识。 可选的, 所述获取单元 201 , 还可以用于获取激活请求消息, 例 如获取所述服务器发送的激活请求消息; 所述获取单元 201 , 还可以用于根据所述获取单元 201获取的所 述激活请求消息获取用户指令;
此时, 参照图 7所示, 所述通信终端, 还可以包括: 变更单元 208 , 可以用于在所述获取单元 201获取的所述用户指 令为激活指令时, 将所述移动网络运营商配置文件的状态变更为激活 状态;
第四发送单元 209 , 可以用于发送激活应答消息, 例如向所述服 务器发送所述激活应答消息, 所述激活应答消息可以包含所述变更单 元 208变更的所述移动网络运营商配置文件的状态。 可选的, 所述安全域管理***可以包含可信服务管理器时: 此时, 所述获取单元 201 , 可以用于在第一业务新签约时获取所 述可信服务管理器发送的第一连接请求消息, 所述第一连接请求消息 携带集成电路卡标识;
此时, 参照图 8所示, 所述通信终端还可以包括: 第五发送单元 210 , 可以用于在所述获取单元 201获取的所述第 一连接请求消息携带集成电路卡标识与通信终端自身匹配时, 发送第 一连接应答消息; 所述获取单元 201 , 可以用于获取所述可信服务管理器发送的第 一服务请求消息, 所述第一服务请求消息可以包含所述移动网络运营 商配置文件的发行方安全域配置文件标识和所述第一业务的配置信 息, 所述第一业务的配置信息可以包含所述第一业务的应用和数据; 所述管理单元 202 , 可以用于在所述获取单元 201获取的所述第 一服务请求消息携带的所述发行方安全域配置文件标识表征的所述 发行方安全域配置文件下创建子安全域, 所述子安全域可以用于存储 所述第一业务的配置信息; 所述分配单元 203 , 可以用于为所述管理单元 202创建的所述子 安全域分配标识, 所述子安全域可以用于存储所述第一业务的配置信 息;
所述第五发送单元 210 , 可以用于向所述可信服务管理器发送第 一服务应答消息, 所述第一服务应答消息携带所述分配单元 203分配 的所述子安全域的标识。 此时, 所述管理单元 202 , 可以用于将所述获取单元 201获取的 所述子安全域的标识记录在所述移动网络运营商配置文件中。 可选的, 当所述第一业务终结, 所述安全域管理***可以包含可 信服务管理器时: 此时, 所述获取单元 201 , 可以用于获取所述可信服务管理器发 送的第二连接请求消息, 所述第二连接请求消息携带集成电路卡标 识;
所述第五发送单元 210 , 可以用于在所述获取单元 201获取的所 述第二连接请求消息携带集成电路卡标识与通信终端自身匹配时, 发 送第二连接应答消息; 所述获取单元 201 , 还可以用于获取所述可信服务管理器发送的 第二服务请求消息, 所述第二服务请求消息携带所述发行方安全域配 置文件标识和所述子安全域的标识; 此时, 所述管理单元 202 , 还可以用于根据所述获取单元 201获 取的所述第二服务请求消息携带的所述发行方安全域配置文件标识 和所述子安全域的标识, 删除所述发行方安全域配置文件中的所述子 安全域; 本发明实施例提供的通信终端,能通过通信终端获取服务器发送 的管理请求消息, 其中, 所述管理请求消息可以包含所述发行方安全 域配置文件标识, 然后, 所述通信终端在所述发行方安全域配置文件 标识对应的移动网络运营商配置文件中管理子安全域。 在所述第一业 务新签约时, 所述管理请求消息可以包括配置请求消息, 管理子安全 域可以包括创建子安全域, 所述配置请求消息还可以包含第一业务的 配置信息, 所述通信终端可以将所述第一业务的配置信息存储于所述 子安全域中; 在所述第一业务终结时, 所述管理请求消息可以包括删 除请求消息, 管理子安全域可以包括删除子安全域, 并且所述删除请 求消息可以包含所述子安全域的标识, 所述通信终端可以根据所述子 安全域的标识实现对所述子安全域的删除。 所以能够根据用户签约业 务的业务状态, 对可以用于存储第一业务配置信息的安全域进行管 理。 参照图 9所示, 本发明的实施例提供一种服务器, 可以应用于通 信领域, 可以应用于图 1所示的安全域管理***, 所述服务器中可以 预配置有移动网络运营商配置文件, 所述服务器可以包括: 发送单元 901 , 可以用于向签约管理安全路由发送查询请求消 息, 所述查询请求消息可以包含所述签约管理安全路由的标识( ID of the relevant SM-SR , SRID )和嵌入式集成电路卡的标识( eUICC-ID , EID ); 获取单元 902 , 可以用于获取所述签约管理安全路由发送的查询 应答消息, 所述查询应答消息可以包含所述移动网络运营商配置文件 的发行方安全或配置文件 ( Issuer Security Domain Profile , ISD-P ) 标识( Application ID , AID )和所述移动网络运营商配置文件的状态; 检查单元 903 , 可以用于检查所述获取单元 902获取的所述查询 应答消息包含的所述移动网络运营商配置文件的状态; 所述发送单元 901 , 还可以用于在所述检查单元 903检查的所述 查询应答消息包含的所述移动网络运营商配置文件的状态是激活状 态 ( Enabled ) 时, 发送管理请求消息, 例如向所述通信终端发送管 理请求消息, 以便所述通信终端根据所述管理请求消息管理子安全 域, 其中, 所述配置请求消息可以包含所述发行方安全域配置文件标 识, 所述子安全域可以用于存储第一业务的配置信息。 可选的, 所述管理请求消息可以包括配置请求消息, 所述管理子 安全域可以包括创建子安全域; 所述发送单元 901 , 还可以用于在所述检查单元 903检查的所述 查询应答消息包含的所述移动网络运营商配置文件的状态是激活状 态 ( Enabled ) 时, 发送管理请求消息, 例如向所述通信终端发送管 理请求消息, 以便所述通信终端根据所述管理请求消息管理子安全 域, 其中, 所述配置请求消息可以包含所述发行方安全域配置文件标 识,所述子安全域可以用于存储第一业务的配置信息,具体可以包括: 所述发送单元 901 , 可以用于在所述第一业务新签约并且所述检 查单元 903 检查的所述查询应答消息包含的所述移动网络运营商配 置文件的状态是激活状态时发送配置请求消息, 例如向所述通信终端 发送配置请求消息, 以便所述通信终端根据所述管理请求消息创建子 安全域, 其中, 所述配置请求消息可以包含所述发行方安全域配置文 件标识和所述第一业务的配置信息, 所述第一业务的配置信息可以包 含所述第一业务的应用信息和数据。 进一步可选的, 所述获取单元 902 , 还可以用于获取所述通信终 端发送的配置应答消息, 所述配置应答消息可以包含子安全域的标 识;
此时, 参照图 10所示, 所述服务器还可以包括: 配置单元 904 , 可以用于将所述获取单元 902获取的所述子安全 域的标识记录在所述发行方安全域配置文件标识对应的所述移动网 络运营商配置文件中。
更进一步, 可选的, 所述发送单元 901 , 还可以用于在所述配置 单元 904 将所述子安全域的标识记录在所述发行方安全域配置文件 标识对应的所述移动网络运营商配置文件中之后, 向所述签约管理安 全路由发送第一更新请求消息; 其中,所述第一更新请求消息中可以包含所述移动网络运营商配 置文件的配置信息, 以便所述签约管理安全路由按照所述第一更新请 求消息更新所述移动网络运营商配置文件的配置信息, 可以使所述签 约管理安全路由、 所述服务器和所述通信终端中的移动网络运营商配 置文件同步, 所述移动网络运营商配置文件的配置信息可以包含移动 网络运营商配置文件的类型、 版本和子安全域信息。 可选的, 所述管理请求消息可以包括删除请求消息, 所述管理子 安全域可以包括删除子安全域; 所述获取单元 902 , 还可以用于在所述第一业务终结时获取子安 全域的标识; 所述发送单元 901 , 还可以用于在所述检查单元 903检查的所述 查询应答消息包含的所述移动网络运营商配置文件的状态是激活状 态 ( Enabled ) 时, 发送管理请求消息, 例如向所述通信终端发送管 理请求消息, 以便所述通信终端根据所述管理请求消息管理子安全 域, 其中, 所述配置请求消息可以包含所述发行方安全域配置文件标 识,所述子安全域可以用于存储第一业务的配置信息,具体可以包括: 所述发送单元 901 , 可以用于在所述检查单元 903检查的所述查 询应答消息包含的所述移动网络运营商配置文件的状态是激活状态 时发送删除请求消息, 例如向所述通信终端发送删除请求消息, 以便 所述通信终端根据所述管理请求消息删除子安全域, 其中, 所述删除 请求消息可以包含所述发行方安全域配置文件标识和所述子安全域 的标识。 进一步可选的, 所述获取单元 902 , 还可以用于获取所述通信终 端发送的保存请求消息, 所述保存请求消息可以包含需要保存的应用 和数据; 此时可选的, 参照图 1 1所示, 所述服务器还可以包括: 保存单元 905 , 可以用于根据所述获取单元 902获取的所述保存 请求消息保存所述需要保存的应用和数据。 更进一步可选的, 所述获取单元 902 , 还可以用于获取删除应答 消息, 例如获取所述通信终端发送的删除应答消息, 所述删除应答消 息可以包含子安全域删除成功状态信息和被删除的子安全域的标识; 此时, 同样参照图 10所示, 所述服务器还可以包括: 配置单元 904 , 可以用于根据所述获取单元 902获取的所述子安 全域删除成功状态信 , 和所述被删除的子安全域的标识,删除所述移 动网络运营商配置文件中的子安全域的标识。
再进一步可选的, 所述发送单元 901 , 还可以用于在所述配置单 元 904 删除了所述移动网络运营商配置文件中的子安全域的标识之 后, 向所述签约管理安全路由发送第二更新请求消息; 其中, 所述第二更新请求消息中可以包含被所述配置单元 904 删除了所述子安全域的标识的所述移动网络运营商配置文件的配置 信息, 以便所述签约管理安全路由按照所述第二更新请求消息更新所 述移动网络运营商配置文件的配置信息, 可以使所述签约管理安全路 由、 所述服务器和所述通信终端中的移动网络运营商配置文件同步。 可选的, 所述发送单元 901 , 还可以用于在所述检查单元 903检 查的所述查询应答消息包含的所述移动网络运营商配置文件的状态 是未激活状态时发送激活请求消息, 例如向所述通信终端发送激活请 求消息;
所述获取单元 902 , 还可以用于获取激活应答消息, 例如获取所 述通信终端发送的激活应答消息, 所述激活应答消息可以包含所述移 动网络运营商配置文件的状态; 所述检查单元 903 , 还可以用于检查所述获取单元 902获取的所 述激活应答消息包含的所述移动网络运营商配置文件的状态; 所述发送单元 901 , 还可以用于在所述检查单元 903检查的所述 激活应答消息包含的所述移动网络运营商配置文件的状态是激活状 态时发送管理请求消息, 例如向所述通信终端发送管理请求消 , 。 可选的, 所述安全域管理***可以包含可信服务管理器时: 此时, 所述发送单元 901 , 还可以用于在第一业务新签约并且所 述检查单元 903 检查的所述查询应答消息包含的所述移动网络运营 商配置文件的状态是激活状态时, 向所述可信服务管理器发送第一转 发请求消息, 其中, 所述第一转发请求消息可以包含所述发行方安全 域配置文件标识、集成电路卡标识( Integrated Circuit Card ID , ICCID ) 和所述第一业务的配置信息, 所述第一业务的配置信息可以包含所述 第一业务的应用信息和数据, 以便所述可信服务管理器向所述通信终 端转发;
此时, 所述获取单元 902 , 还可以用于获取所述可信服务管理器 发送的第一转发应答消息, 所述第一转发应答消息可以包含子安全域 的标识。 进一步, 可选的, 当第一业务终结, 所述安全域管理***可以包 含可信服务管理器时;
所述发送单元 901 , 还可以用于所述检查单元 903检查的所述查 询应答消息携带的所述移动网络运营商配置文件的状态是激活状态 时, 向所述可信服务管理器发送第二转发请求消息, 所述第二转发请 求消息携带所述发行方安全域配置文件标识、 集成电路卡标识和所述 子安全域的标识, 以便所述可信服务管理器向所述通信终端转发; 所述获取单元 902 , 还可以用于获取所述可信服务管理器发送的 第二转发应答消息, 所述第二转发应答消息携带子安全域删除成功状 态信 , 和被删除的子安全域的标识。 此时, 所述配置单元 904 , 还可以用于根据所述获取单元 902获 取的所述子安全域删除成功状态信息和所述被删除的子安全域的标 识, 删除所述移动网络运营商配置文件中的子安全域的标识。 本发明实施例提供的服务器,能通过服务器向通信终端发送管理 请求消息, 其中, 所述管理请求消息可以包含所述发行方安全域配置 文件标识, 然后, 所述通信终端在所述发行方安全域配置文件标识对 应的移动网络运营商配置文件中管理子安全域。 在所述第一业务新签 约时, 所述管理请求消息可以包括配置请求消息, 管理子安全域可以 包括创建子安全域, 所述配置请求消息还可以包含第一业务的配置信 息, 所述通信终端可以将所述第一业务的配置信息存储于所述子安全 域中; 在所述第一业务终结时, 所述管理请求消息可以包括删除请求 消息, 管理子安全域可以包括删除子安全域, 并且所述删除请求消息 可以包含所述子安全域的标识, 所述通信终端可以根据所述子安全域 的标识实现对所述子安全域的删除。 所以能够根据用户签约业务的业 务状态, 对可以用于存储第一业务配置信息的安全域进行管理。
参照图 12所示, 本发明实施例提供一种签约管理安全路由, 可 以应用于通信领域, 可以应用于图 1所示的安全域管理***, 所述签 约管理安全路由可以包括: 获取单元 1201 , 可以用于获取服务器发送的查询请求消息, 所 述查询请求消息可以包含所述签约管理安全路由的标识和嵌入式集 成电路卡的标识; 所述获取单元 1201 , 还可以用于根据所述获取单元 1201获取的 所述签约管理安全路由的标识, 获取与所述嵌入式集成电路卡的标识 对应的所述移动网络运营商配置文件的发行方安全域配置文件标识 和所述移动网络运营商配置文件的状态; 发送单元 1202 , 可以用于向服务器发送的查询应答消息, 所述 查询应答消息可以包含所述获取单元 1201 获取的所述移动网络运营 商配置文件的发行方安全域配置文件标识和所述移动网络运营商配 置文件的状态, 以便所述服务器进行安全域管理。 参照图 13 所示, 可选的, 所述签约管理安全路由还可以包括: 保存单元 1203 ; 所述获取单元 1201 , 还可以用于在所述第一业务新签约时获取 所述服务器发送的第一更新请求消息, 所述第一更新请求消息中可以 包含所述移动网络运营商配置文件的配置信息; 所述保存单元 1203 , 可以用于按照所述获取单元 1201获取的所 述第一更新请求消息更新所述移动网络运营商配置文件的配置信息, 使所述签约管理安全路由、 所述服务器和所述通信终端中的移动网络 运营商配置文件同步, 所述移动网络运营商配置文件的配置信息可以 包含移动网络运营商配置文件的类型、 版本和子安全域信息。 可选的, 同样参照图 13所示: 所述获取单元 1201 , 还可以用于在所述第一业务终结时获取所 述服务器发送的第二更新请求消息, 所述第二更新请求消息中可以包 含被删除了所述子安全域的标识的所述移动网络运营商配置文件的 配置信息; 所述保存单元 1203 , 还可以用于按照所述获取单元 1201获取的 所述第二更新请求消息更新所述移动网络运营商配置文件的配置信 息, 使所述签约管理安全路由、 所述服务器和所述通信终端中的移动 网络运营商配置文件同步。 本发明实施例,通过签约管理安全路由获取服务器发送的查询请 求消息; 根据所述查询请求消息获取移动网络运营商配置文件的发行 方安全域配置文件标识和所述移动网络运营商配置文件的状态, 并向 所述服务器发送查询应答消息, 所述查询应答消息可以包含所述移动 网络运营商配置文件的发行方安全域配置文件标识和所述移动网络 运营商配置文件的状态, 以便所述服务器进行安全域管理。 参照图 14所示, 本发明的实施例提供一种可信服务管理器, 可 以应用于通信领域, 可以应用于图 1所示的安全域管理***, 所述签 约管理安全路由可以包括: 获取单元 1401 可以用于在所述第一业务新签约时获取服务器发 送的第一转发请求消息, 其中, 所述第一转发请求消息可以包含所述 发行方安全域配置文件标识、集成电路卡标识( Integrated Circuit Card ID , ICCID ) 和所述第一业务的配置信息, 所述第一业务的配置信息 可以包含所述第一业务的应用信息和数据; 发送单元 1402 , 可以用于向通信终端发送第一连接请求消息, 所述第一连接请求消息可以包含所述获取单元 1401 获取的集成电路 卡标识;
所述获取单元 1401 , 还可以用于获取所述通信终端发送的第一 连接应答消息; 所述发送单元 1402 , 还可以用于在所述获取单元 1401获取到所 述第一连接应答消息时, 发送第一服务请求消息, 所述第一服务请求 消息可以包含所述移动网络运营商配置文件的发行方安全域配置文 件标识和所述第一业务的配置信息, 所述第一业务的配置信息可以包 含所述第一业务的应用和数据, 以便所述通信终端为所述第一业务配 置安全域;
所述获取单元 1401 , 还可以用于获取所述通信终端发送的第一 服务应答消息, 所述第一服务应答消息可以包含子安全域的标识。 所述发送单元 1402 , 还可以用于向所述服务器发送第一转发应 答消息, 所述第一转发应答消息可以包含所述获取单元 1401 获取的 子安全域的标识。
可选的: 所述获取单元 1401 , 还可以用于在所述第一业务终结 时获取所述服务器发送的第二转发请求消息, 所述第二转发请求消息 可以包含所述发行方安全域配置文件标识、 集成电路卡标识和所述子 安全域的标识; 所述发送单元 1402 , 还可以用于向所述通信终端发送第二连接 请求消息, 所述第二连接请求消息可以包含所述获取单元 1401 获取 的集成电路卡标识; 所述获取单元 1401 , 还可以用于获取所述通信终端发送的第二 连接应答消息; 所述发送单元 1402 , 还可以用于在所述获取单元 1401获取到所 述第二连接应答消息时, 向所述通信终端发送第二服务请求消息, 所 述第二服务请求消息可以包含所述发行方安全域配置文件标识和所 述子安全域的标识, 以便所述通信终端删除安全域; 所述获取单元 1401 , 还可以用于获取所述通信终端发送的第二 服务应答消息, 所述第二服务应答消息可以包含子安全域删除成功状 态信息和所述配置单元删除的所述子安全域的标识。 所述发送单元 1402 , 还可以用于向所述服务器发送第二转发应 答消息, 所述第二转发应答消息可以包含所述获取单元 1401 获取的 子安全域删除成功状态信息和被删除的子安全域的标识, 以便所述服 务器根据所述第二转发应答消息更新移动网络运营商配置文件。 本发明实施例,通过可信服务管理器转发服务器和通信终端之间 的通信消息, 辅佐服务器和通信终端, 在移动网络运营商配置文件中 对可以用于存储第一业务配置信息的安全域进行管理。
本发明的实施例提供一种通信终端, 可以应用于通信领域, 可以 应用于图 1所示的安全域管理***, 所述通信终端中可以预配置有移 动网络运营商配置文件, 参照图 15 所示, 该通信终端可以嵌入或本 身就是微处理计算机, 比如: 通用计算机、 客户定制机、 手机终端或 平板机等便携设备, 该通信终端 1501 可以包括: 至少一个网络接口 1501 1、 处理器 15012 和总线 15014 , 还可以包括至少一个存储器 15013 , 该至少一个网络接口 1501 1、 处理器 15012 和存储器 15013 通过总线 15014连接并完成相互间的通信。 该总线 15014可以是 ISA ( Industry Standard Architecture , 工业 标准体系结构) 总线、 PCI ( Peripheral Component , 外部设备互连 ) 总线或 EISA ( Extended Industry Standard Architecture , 扩展工业标准 体系结构) 总线等。 该总线 15014可以分为地址总线、 数据总线、 控 制总线等。 为便于表示, 图 15 中仅用一条粗线表示, 但并不表示仅 有一根总线或一种类型的总线。 其中: 存储器 15013可以用于存储可执行程序代码,该程序代码可以包 括计算机操作指令。 存储器 15013可能可以包括高速 RAM存储器, 也可能还可以包括非易失性存储器( non- volatile memory ) , 例如至少 一个磁盘存储器。 处理器 15012可能是一个中央处理器 ( Central Processing Unit , 简称为 CPU ) , 或者是特定集成电路 ( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个或 多个集成电路。
其中, 所述网络接口 1501 1 , 可以用于获取管理请求消息, 例如 获取所述服务器发送的管理请求消息, 所述管理请求消息可以包含发 行方安全 i或配置文件标识;
所述处理器 15012 , 可以用于在所述网络接口 1501 1获取的所述 配置请求消息包含的所述发行方安全域配置文件标识对应的移动网 络运营商配置文件下管理子安全域, 所述子安全域可以用于存储第一 业务的配置信息。 可选的, 所述管理请求消息可以包括配置请求消息, 所述管理子 安全域可以包括创建子安全域; 所述网络接口 1501 1 , 具体可以用于在所述第一业务新签约时获 取配置请求消息, 例如获取所述服务器发送的配置请求消息, 所述配 置请求消息可以包含所述发行方安全域配置文件标识和所述第一业 务的配置信息, 所述第一业务的配置信息可以包含所述第一业务的应 用和数据;
所述处理器 15012 , 具体可以用于在所述网络接口 1501 1获取的 所述配置请求消息包含的所述发行方安全域配置文件标识对应的所 述移动网络运营商配置文件下创建子安全域, 并将所述第一业务的配 置信息存储于所述子安全域;
所述处理器 15012 , 还可以用于为所述处理器 15012创建的所述 子安全域分配标识; 所述处理器 15012 , 还可以用于根据所述处理器 15012 自身分配 的所述子安全域的标识管理所述子安全域。 进一步可选的, 所述网络接口 1501 1 , 还可以用于向所述服务器 发送配置应答消息, 所述配置应答消息可以包含所述处理器 15012分 配的所述子安全域的标识, 以便所述服务器根据所述配置应答消息管 理所述子安全域。 可选的, 所述管理请求消息可以包括删除请求消息, 所述管理子 安全域可以包括删除子安全域; 所述网络接口 1501 1 , 具体可以用于在所述第一业务终结时获取 删除请求消息, 例如获取所述服务器发送的删除请求消息, 所述删除 请求消息可以包含所述发行方安全域配置文件标识和所述子安全域 的标识; 所述处理器 15012 , 具体可以用于根据所述网络接口 1501 1获取 的所述删除请求消息包含的所述发行方安全域配置文件标识和所述 子安全域的标识, 删除所述发行方安全域配置文件标识对应的所述移 动网络运营商配置文件中的所述子安全域。 更进一步可选的, 所述处理器 15012 , 还可以用于根据所述网络 接口 1501 1获取的所述删除请求消息包含的所述发行方安全域配置文 件标识和所述子安全域的标识,检测所述子安全域中需要保存的应用 和数据; 所述网络接口 1501 1 , 还可以用于发送保存请求消息, 例如向所 述服务器发送保存请求消息, 所述保存请求消息可以包含所述处理器 15012检测的所述需要保存的应用和数据, 以便所述服务器根据所述 保存请求消息保存所述需要保存的应用和数据; 所述处理器 15012 , 具体可以用于在所述网络接口 1501 1发送所 述保存请求消息后, 根据所述网络接口 1501 1获取的所述发行方安全 域配置文件标识和所述子安全域的标识, 删除所述发行方安全域配置 文件标识对应的所述移动网络运营商配置文件中的所述子安全域以 及所述子安全域中的应用和数据。 进一步可选的, 所述网络接口 15011, 还可以用于在所述处理器 15012删除所述子安全域后, 发送删除应答消息, 例如向所述服务器 发送删除应答消息, 所述删除应答消息可以包含子安全域删除成功状 态信息和所述处理器 15012删除的所述子安全域的标识。 可选的, 所述网络接口 15011, 还可以用于获取所述服务器发送 的激活请求消息;
所述网络接口 15011, 还可以用于根据所述网络接口 15011获取 的所述激活请求消息获取用户指令; 所述处理器 15012, 还可以用于在所述网络接口 15011获取的所 述用户指令为激活指令时, 将所述移动网络运营商配置文件的状态变 更为激活状态; 所述网络接口 15011, 还可以用于向所述服务器发送所述激活应 答消息, 所述激活应答消息可以包含所述处理器 15012变更的所述移 动网络运营商配置文件的状态。 可选的, 所述安全域管理***可以包含可信服务管理器时: 此时, 所述网络接口 15011, 可以用于在第一业务新签约时获取 所述可信服务管理器发送的第一连接请求消息, 所述第一连接请求消 息可以包含集成电路卡标识; 所述网络接口 15011在所述网络接口 15011获取的所述第一连接 请求消息可以包含集成电路卡标识与通信终端自身匹配时, 发送第一 连接应答消息; 所述网络接口 15011, 可以用于获取所述可信服务管理器发送的 第一服务请求消息, 所述第一服务请求消息可以包含所述移动网络运 营商配置文件的发行方安全域配置文件标识和所述第一业务的配置 信息, 所述第一业务的配置信息可以包含所述第一业务的应用和数 据;
所述处理器 15012 , 可以用于在所述网络接口 1501 1获取的所述 第一服务请求消息包含的所述发行方安全域配置文件标识对应的所 述移动网络运营商配置文件下创建子安全域, 所述子安全域可以用于 存储所述第一业务的配置信息; 所述处理器 15012 , 可以用于为所述处理器 15012创建的所述子 安全域分配标识, 所述子安全域可以用于存储所述第一业务的配置信 息;
所述网络接口 1501 1 , 可以用于向所述可信服务管理器发送第一 服务应答消息, 所述第一服务应答消息可以包含所述处理器 15012分 配的所述子安全域的标识。 可选的, 所述安全域管理***可以包含可信服务管理器时: 此时, 所述网络接口 1501 1 , 可以用于在第一业务终结时获取所 述可信服务管理器发送的第二连接请求消息, 所述第二连接请求消息 可以包含集成电路卡标识;
所述网络接口 1501 1在所述网络接口 1501 1获取的所述第二连接 请求消息可以包含集成电路卡标识与通信终端自身匹配时, 发送第二 连接应答消息; 所述网络接口 1501 1 , 还可以用于获取所述可信服务管理器发送 的第二服务请求消息, 所述第二服务请求消息可以包含所述发行方安 全域配置文件标识和所述子安全域的标识; 所述处理器 15012 , 还可以用于根据所述网络接口 1501 1获取的 所述第二服务请求消息包含的所述发行方安全域配置文件标识和所 述子安全域的标识, 删除所述发行方安全域配置文件标识对应的所述 移动网络运营商配置文件中的所述子安全域; 所述网络接口 1501 1 , 还可以用于在所述处理器 15012删除所述 子安全域后, 向所述可信服务管理器发送第二服务应答消息, 所述第 二服务应答消息可以包含子安全域删除成功状态信息和所述处理器
15012删除的所述子安全域的标识。 本发明实施例提供的通信终端,能通过通信终端获取服务器发送 的管理请求消息, 其中, 所述管理请求消息可以包含所述发行方安全 域配置文件标识, 然后, 所述通信终端在所述发行方安全域配置文件 标识对应的移动网络运营商配置文件中管理子安全域。 在所述第一业 务新签约时, 所述管理请求消息可以包括配置请求消息, 管理子安全 域可以包括创建子安全域, 所述配置请求消息还可以包含第一业务的 配置信息, 所述通信终端可以将所述第一业务的配置信息存储于所述 子安全域中; 在所述第一业务终结时, 所述管理请求消息可以包括删 除请求消息, 管理子安全域可以包括删除子安全域, 并且所述删除请 求消息可以包含所述子安全域的标识, 所述通信终端可以根据所述子 安全域的标识实现对所述子安全域的删除。 所以本发明提供的安全域 管理方法、 装置及***能够根据用户签约业务的业务状态, 对可以用 于存储第一业务配置信息的安全域进行管理。 本发明的实施例提供一种服务器, 可以应用于通信领域, 可以应 用于图 1所示的安全域管理***, 所述服务器中可以预配置有移动网 络运营商配置文件, 参照图 16 所示, 该服务器可以嵌入或本身就是 微处理计算机, 比如: 通用计算机、 客户定制机、 手机终端或平板机 等便携设备, 该服务器 1601 可以包括: 至少一个网络接口 1601 1、 处 理器 16012和总线 16014 , 还可以包括至少一个存储器 16013 , 该至 少一个网络接口 1601 1、处理器 16012和存储器 16013通过总线 16014 连接并完成相互间的通信。 该总线 16014可以是 ISA ( Industry Standard Architecture , 工业 标准体系结构) 总线、 PCI ( Peripheral Component , 外部设备互连 ) 总线或 EISA ( Extended Industry Standard Architecture , 扩展工业标准 体系结构) 总线等。 该总线 16014可以分为地址总线、 数据总线、 控 制总线等。 为便于表示, 图 16 中仅用一条粗线表示, 但并不表示仅 有一根总线或一种类型的总线。 其中:
存储器 16013可以用于存储可执行程序代码,该程序代码可以包 括计算机操作指令。 存储器 16013可能可以包括高速 RAM存储器, 也可能还可以包括非易失性存储器( non- volatile memory ) , 例如至少 一个磁盘存储器。 处理器 16012可能是一个中央处理器 ( Central Processing Unit , 简称为 CPU ) , 或者是特定集成电路 ( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个或 多个集成电路。 其中, 所述网络接口 1601 1 , 可以用于向签约管理安全路由发送 查询请求消息, 所述查询请求消息可以包含所述签约管理安全路由的 标识和嵌入式集成电路卡的标识; 所述网络接口 1601 1 , 还可以用于获取所述签约管理安全路由发 送的查询应答消息, 所述查询应答消息可以包含所述移动网络运营商 配置文件的发行方安全域配置文件标识和所述移动网络运营商配置 文件的状态; 所述处理器 16012 , 可以用于检查所述网络接口 1601 1获取的所 述查询应答消息包含的所述移动网络运营商配置文件的状态; 所述网络接口 1601 1 , 还可以用于在所述处理器 16012检查的所 述查询应答消息包含的所述移动网络运营商配置文件的状态是激活 状态时发送管理请求消息, 例如向所述通信终端发送管理请求消 , , 以便所述通信终端根据所述管理请求消息管理子安全域, 其中, 所述 配置请求消息可以包含所述发行方安全域配置文件标识, 所述子安全 域可以用于存储第一业务的配置信息。 可选的, 所述管理请求消息可以包括配置请求消息, 所述管理子 安全域可以包括创建子安全域; 所述网络接口 1601 1 , 还可以用于在所述处理器 16012检查的所 述查询应答消息包含的所述移动网络运营商配置文件的状态是激活 状态时发送管理请求消息, 例如向所述通信终端发送管理请求消 , , 以便所述通信终端根据所述管理请求消息管理子安全域, 其中, 所述 配置请求消息可以包含所述发行方安全域配置文件标识, 所述子安全 域可以用于存储第一业务的配置信息, 具体可以包括: 所述网络接口 1601 1 , 可以用于在所述第一业务新签约并且所述 处理器 16012 检查的所述查询应答消息包含的所述移动网络运营商 配置文件的状态是激活状态时发送配置请求消息, 例如向所述通信终 端发送配置请求消息, 以便所述通信终端根据所述管理请求消息创建 子安全域, 其中, 所述配置请求消息可以包含所述发行方安全域配置 文件标识和所述第一业务的配置信息, 所述第一业务的配置信息可以 包含所述第一业务的应用信息和数据。 进一步可选的, 所述网络接口 1601 1 , 还可以用于获取配置应答 消息, 例如获取所述通信终端发送的配置应答消息, 所述配置应答消 息可以包含子安全域的标识; 所述处理器 16012 , 还可以用于将所述网络接口 1601 1获取的所 述子安全域的标识记录在所述发行方安全域配置文件标识对应的所 述移动网络运营商配置文件中。 更进一步可选的, 所述网络接口 1601 1 , 还可以用于在所述处理 器 16012 将所述子安全域的标识记录在所述发行方安全域配置文件 标识对应的所述移动网络运营商配置文件中之后, 向所述签约管理安 全路由发送第一更新请求消息; 其中,所述第一更新请求消息中可以包含所述移动网络运营商配 置文件的配置信息, 以便所述签约管理安全路由按照所述第一更新请 求消息更新所述移动网络运营商配置文件的配置信息, 可以使所述签 约管理安全路由、 所述服务器和所述通信终端中的移动网络运营商配 置文件同步, 所述移动网络运营商配置文件的配置信息可以包含移动 网络运营商配置文件的类型、 版本和子安全域信息。 可选的, 在第四种可能的实现方式中, 所述管理请求消息可以包 括删除请求消息, 所述管理子安全域可以包括删除子安全域; 所述网络接口 1601 1 , 还可以用于在所述第一业务终结时获取子 安全域的标识; 所述网络接口 1601 1 , 还可以用于在所述处理器 16012检查的所 述查询应答消息包含的所述移动网络运营商配置文件的状态是激活 状态时发送管理请求消息, 例如向所述通信终端发送管理请求消 , , 以便所述通信终端根据所述管理请求消息管理子安全域, 其中, 所述 配置请求消息可以包含所述发行方安全域配置文件标识, 所述子安全 域可以用于存储第一业务的配置信息, 具体可以包括: 所述网络接口 1601 1 , 可以用于在所述处理器 16012检查的所述 查询应答消息包含的所述移动网络运营商配置文件的状态是激活状 态时发送删除请求消息, 例如向所述通信终端发送删除请求消息, 以 便所述通信终端根据所述管理请求消息删除子安全域, 其中, 所述删 除请求消息可以包含所述发行方安全域配置文件标识和所述子安全 域的标识。 进一步可选的, 所述网络接口 1601 1 , 还可以用于获取所述通信 终端发送的保存请求消息, 所述保存请求消息可以包含需要保存的应 用和数据; 所述存储器 16013 , 还可以用于根据所述网络接口获取的所述保 存请求消息保存所述需要保存的应用和数据。
更进一步可选的, 所述网络接口 1601 1 , 还可以用于获取删除应 答消息, 例如获取所述通信终端发送的删除应答消息, 所述删除应答 消息可以包含子安全域删除成功状态信息和被删除的子安全域的标 识;
所述处理器 16012 , 还可以用于根据所述网络接口 1601 1获取的 所述子安全域删除成功状态信息和所述被删除的子安全域的标识, 删 除所述移动网络运营商配置文件中的子安全域的标识。 再进一步可选的, 所述网络接口 1601 1 , 还可以用于在所述处理 器 16012 删除了所述移动网络运营商配置文件中的子安全域的标识 之后, 向所述签约管理安全路由发送第二更新请求消息; 其中, 所述第二更新请求消息中可以包含被所述处理器 16012 删除了所述子安全域的标识的所述移动网络运营商配置文件的配置 信息, 以便所述签约管理安全路由按照所述第二更新请求消息更新所 述移动网络运营商配置文件的配置信息, 可以使所述签约管理安全路 由、 所述服务器和所述通信终端中的移动网络运营商配置文件同步。 可选的, 所述网络接口 1601 1 , 还可以用于在所述处理器 16012 检查的所述查询应答消息包含的所述移动网络运营商配置文件的状 态是未激活状态时, 向所述通信终端发送激活请求消 , ί、 ; 所述网络接口 1601 1 , 还可以用于获取所述通信终端发送的激活 应答消息, 所述激活应答消息可以包含所述移动网络运营商配置文件 的状态;
所述处理器 16012 , 还可以用于检查所述网络接口 1601 1获取的 所述激活应答消息包含的所述移动网络运营商配置文件的状态; 所述网络接口 1601 1 , 还可以用于在所述处理器 16012检查的所 述激活应答消息包含的所述移动网络运营商配置文件的状态是激活 状态时, 向所述通信终端发送管理请求消息。
可选的, 所述安全域管理***可以包含可信服务管理器时: 此时, 所述网络接口 16012 , 还可以用于在第一业务新签约并且 所述检查单元检查的所述查询应答消息包含的所述移动网络运营商 配置文件的状态是激活状态时, 向所述可信服务管理器发送第一转发 请求消息, 其中, 所述第一转发请求消息可以包含所述发行方安全域 配置文件标识、 集成电路卡标识 ( Integrated Circuit Card ID , ICCID ) 和所述第一业务的配置信息, 所述第一业务的配置信息可以包含所述 第一业务的应用信息和数据, 以便所述可信服务管理器向所述通信终 端转发;
此时, 所述网络接口 16012 , 还可以用于获取所述可信服务管理 器发送的第一转发应答消息, 所述第一转发应答消息可以包含子安全 域的标识。 所述处理器 16012 , 可以用于将所述网络接口 16012获取的所述 子安全域的标识记录在所述发行方安全域配置文件标识对应的所述 移动网络运营商配置文件中。 可选的, 所述安全域管理***可以包含可信服务管理器时; 所述网络接口 16012 , 还可以用于在所述第一业务终结并且所述 检查单元检查的所述查询应答消息包含的所述移动网络运营商配置 文件的状态是激活状态时, 向所述可信服务管理器发送第二转发请求 消息, 所述第二转发请求消息可以包含所述发行方安全域配置文件标 识、 集成电路卡标识和所述子安全域的标识, 以便所述可信服务管理 器向所述通信终端转发; 所述网络接口 16012 , 还可以用于获取所述可信服务管理器发送 的第二转发应答消息, 所述第二转发应答消息可以包含子安全域删除 成功状态信, ¾和被删除的子安全域的标识。
所述处理器 16012 , 还可以用于根据所述网络接口 16012获取的 所述子安全域删除成功状态信息和所述被删除的子安全域的标识, 删 除所述移动网络运营商配置文件中的子安全域的标识。 本发明实施例,通过所述服务器向签约管理安全路由发送查询请 求消息的方式, 获取所述移动网络运营商配置文件的发行方安全域配 置文件标识和所述移动网络运营商配置文件的状态; 并在所述移动网 络运营商配置文件的状态是激活状态时, 向所述通信终端发送配置请 求消息来获取配置应答消息, 其中, 所述配置请求消息可以包含所述 发行方安全域配置文件标识和所述第一业务的配置信息, 所述配置应 答消息可以包含子安全域的标识; 最后, 将所述子安全域的标识记录 在所述发行方安全域配置文件标识对应的所述移动网络运营商配置 文件中。 所以能够在用户新签约业务时, 在通信终端的移动网络运营 商配置文件中增加关于新签约业务的配置信息和安全域, 对可以用于 存储第一业务配置信息的安全域进行管理。 本发明的实施例提供一种签约管理安全路由,可以应用于通信领 域, 可以应用于图 1 所示的安全域管理***, 照图 17所示, 该签约 管理安全路由可以嵌入或本身就是微处理计算机,比如:通用计算机、 客户定制机、 手机终端或平板机等便携设备, 该签约管理安全路由 1701可以包括:至少一个网络接口 1701 1、处理器 17012、存储器 17013 和总线 17014 , 该至少一个网络接口 1701 1、 处理器 17012和存储器 17013通过总线 17014连接并完成相互间的通信。 该总线 17014可以是 ISA ( Industry Standard Architecture , 工业 标准体系结构) 总线、 PCI ( Peripheral Component , 外部设备互连 ) 总线或 EISA ( Extended Industry Standard Architecture , 扩展工业标准 体系结构) 总线等。 该总线 17014可以分为地址总线、 数据总线、 控 制总线等。 为便于表示, 图 17 中仅用一条粗线表示, 但并不表示仅 有一根总线或一种类型的总线。 其中: 存储器 17013可以用于存储可执行程序代码,该程序代码可以包 括计算机操作指令。 存储器 17013可能可以包括高速 RAM存储器, 也可能还可以包括非易失性存储器( non- volatile memory ) , 例如至少 一个磁盘存储器。 处理器 17012可能是一个中央处理器 ( Central Processing Unit , 简称为 CPU ) , 或者是特定集成电路 ( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个或 多个集成电路。 其中, 所述网络接口 1701 1 , 可以用于获取服务器发送的查询请 求消息, 所述查询请求消息可以包含所述签约管理安全路由的标识和 嵌入式集成电路卡的标识; 所述网络接口 1701 1 , 还可以用于根据所述网络接口 1701 1获取 的所述签约管理安全路由的标识, 获取与所述嵌入式集成电路卡的标 识对应的所述移动网络运营商配置文件的发行方安全域配置文件标 识和所述移动网络运营商配置文件的状态; 网络接口 1701 1 , 可以用于向服务器发送的查询应答消息, 所述 查询应答消息可以包含所述网络接口 1701 1获取的所述移动网络运营 商配置文件的发行方安全域配置文件标识和所述移动网络运营商配 置文件的状态, 以便所述服务器进行安全域管理。 可选的: 所述网络接口 1701 1 , 还可以用于在所述第一业务新签约时获取 所述服务器发送的第一更新请求消息, 所述第一更新请求消息中可以 包含所述移动网络运营商配置文件的配置信息; 所述处理器 17012 , 可以用于按照所述网络接口 1701 1获取的所 述第一更新请求消息更新所述移动网络运营商配置文件的配置信息, 使所述签约管理安全路由、 所述服务器和所述通信终端中的移动网络 运营商配置文件同步, 所述移动网络运营商配置文件的配置信息可以 包含移动网络运营商配置文件的类型、 版本和子安全域信息。 可选的: 所述网络接口 1701 1 , 还可以用于在所述第一业务终结时获取所 述服务器发送的第二更新请求消息, 所述第二更新请求消息中可以包 含被删除了所述子安全域的标识的所述移动网络运营商配置文件的 配置信息;
所述处理器 17012 , 还可以用于按照所述网络接口 1701 1获取的 所述第二更新请求消息更新所述移动网络运营商配置文件的配置信 息, 使所述签约管理安全路由、 所述服务器和所述通信终端中的移动 网络运营商配置文件同步。 本发明实施例,通过签约管理安全路由获取服务器发送的查询请 求消息; 根据所述查询请求消息获取移动网络运营商配置文件的发行 方安全域配置文件标识和所述移动网络运营商配置文件的状态, 并向 所述服务器发送查询应答消息, 所述查询应答消息可以包含所述移动 网络运营商配置文件的发行方安全域配置文件标识和所述移动网络 运营商配置文件的状态, 以便所述服务器进行安全域管理。 本发明的实施例提供一种可信服务管理器, 可以应用于通信领 域, 可以应用于图 1 所示的安全域管理***, 参照图 18所示, 该可 信服务管理器可以嵌入或本身就是微处理计算机,比如:通用计算机、 客户定制机、 手机终端或平板机等便携设备, 该可信服务管理器 1801 可以包括: 至少一个网络接口 1801 1、 处理器 18012、 存储器 18013 和总线 18014 , 该至少一个网络接口 1801 1、 处理器 18012和存储器 18013通过总线 18014连接并完成相互间的通信。 该总线 18014可以是 ISA ( Industry Standard Architecture , 工业 标准体系结构) 总线、 PCI ( Peripheral Component , 外部设备互连 ) 总线或 EISA ( Extended Industry Standard Architecture , 扩展工业标准 体系结构) 总线等。 该总线 18014可以分为地址总线、 数据总线、 控 制总线等。 为便于表示, 图 18 中仅用一条粗线表示, 但并不表示仅 有一根总线或一种类型的总线。 其中:
存储器 18013可以用于存储可执行程序代码,该程序代码可以包 括计算机操作指令。 存储器 18013可能可以包括高速 RAM存储器, 也可能还可以包括非易失性存储器( non- volatile memory ) , 例如至少 一个磁盘存储器。 处理器 18012可能是一个中央处理器 ( Central Processing Unit , 简称为 CPU ) , 或者是特定集成电路 ( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个或 多个集成电路。 其中, 可选的: 所述网络接口 18011 可以用于在所述第一业务新签约时获取服 务器发送的第一转发请求消息, 所述第一转发请求消息可以包含所述 发行方安全域配置文件标识、集成电路卡标识( Integrated Circuit Card ID, ICCID ) 和所述第一业务的配置信息, 所述第一业务的配置信息 可以包含所述第一业务的应用信息和数据; 网络接口 18011, 可以用于向通信终端发送第一连接请求消息, 所述第一连接请求消息可以包含所述网络接口 18011获取的集成电路 卡标识;
所述网络接口 18011, 还可以用于获取所述通信终端发送的第一 连接应答消息; 所述网络接口 18011, 还可以用于在所述网络接口 18011获取到 所述第一连接应答消息时, 发送第一服务请求消息, 所述第一服务请 求消息可以包含所述移动网络运营商配置文件的发行方安全域配置 文件标识和所述第一业务的配置信息, 所述第一业务的配置信息可以 包含所述第一业务的应用和数据, 以便所述通信终端为所述第一业务 配置安全域;
所述网络接口 18011, 还可以用于获取所述通信终端发送的第一 服务应答消息, 所述第一服务应答消息可以包含子安全域的标识。 所述网络接口 18011, 还可以用于向所述服务器发送第一转发应 答消息, 所述第一转发应答消息可以包含所述网络接口 18011获取的 子安全域的标识。
可选的: 所述网络接口 18011, 还可以用于在所述第一业务终结时获取所 述服务器发送的第二转发请求消息, 所述第二转发请求消息可以包含 所述发行方安全域配置文件标识、 集成电路卡标识和所述子安全域的 标识;
所述网络接口 18011, 还可以用于向所述通信终端发送第二连接 请求消息, 所述第二连接请求消息可以包含所述网络接口 1801 1获取 的集成电路卡标识; 所述网络接口 1801 1 , 还可以用于获取所述通信终端发送的第二 连接应答消息; 所述网络接口 1801 1 , 还可以用于在所述网络接口 1801 1获取到 所述第二连接应答消息时, 向所述通信终端发送第二服务请求消息, 所述第二服务请求消息可以包含所述发行方安全域配置文件标识和 所述子安全域的标识, 以便所述通信终端删除安全域; 所述网络接口 1801 1 , 还可以用于获取所述通信终端发送的第二 服务应答消息, 所述第二服务应答消息可以包含子安全域删除成功状 态信息和所述配置单元删除的所述子安全域的标识。 所述网络接口 1801 1 , 还可以用于向所述服务器发送第二转发应 答消息, 所述第二转发应答消息可以包含所述网络接口 1801 1获取的 子安全域删除成功状态信息和被删除的子安全域的标识, 以便所述服 务器根据所述第二转发应答消息更新移动网络运营商配置文件。 本发明实施例,通过可信服务管理器转发服务器和通信终端之间 的通信消息, 辅佐服务器和通信终端, 在移动网络运营商配置文件中 对可以用于存储第一业务配置信息的安全域进行管理。
通过以上的实施方式的描述,所属领域的技术人员可以清楚地了 解到本发明可以用硬件实现,或固件实现,或它们的组合方式来实现。 当使用软件实现时, 可以将上述功能存储在计算机可读介质中或作为 计算机可读介质上的一个或多个指令或代码进行传输。 计算机可读介 质可以包括计算机存储介质和通信介质, 其中通信介质可以包括便于 从一个地方向另一个地方传送计算机程序的任何介质。 存储介质可以 是计算机能够存取的任何可用介质。 以此为例但不限于: 计算机可读 介质可以包括 RAM ( Random Access Memory , 随机存储器)、 ROM ( Read Only Memory , 只读内存)、 EEPROM ( Electrically Erasable Programmable Read Only Memory , 电可擦可编程只读存储器 )、 CD-ROM ( Compact Disc Read Only Memory , 即只读光盘) 或其他光 盘存储、 磁盘存储介质或者其他磁存储设备、 或者能够可以用于可以 包含或存储具有指令或数据结构形式的期望的程序代码并能够由计 算机存取的任何其他介质。 此外, 任何连接可以适当的成为计算机可 读介质。 例如, 如果软件是使用同轴电缆、 光纤光缆、 双绞线、 DSL ( Digital Subscriber Line , 数字用户专线) 或者诸如红外线、 无线电 和微波之类的无线技术从网站、 服务器或者其他远程源传输的, 那么 同轴电缆、 光纤光缆、 双绞线、 DSL或者诸如红外线、 无线和微波之 和碟可以包括 CD ( Compact Disc , 压缩光碟)、 激光碟、 光碟、 DVD 碟 ( Digital Versatile Disc , 数字通用光)、 软盘和蓝光光碟, 其中盘 通常磁性的复制数据, 而碟则用激光来光学的复制数据。 上面的组合 也应当可以包括在计算机可读介质的保护范围之内。 本发明的实施例提供一种安全域管理方法, 可以应用于通信领 域, 可以应用于图 1所示的安全域管理***中的通信终端, 所述通信 终端中可以预配置有移动网络运营商配置文件, 参照图 19 所示, 可 以包括以下步骤:
1901、 获取管理请求消息, 所述管理请求消息可以包含发行方安 全域配置文件标识。
1902、在所述发行方安全域配置文件标识对应的移动网络运营商 配置文件下管理子安全域, 所述子安全域可以用于存储所述第一业务 的配置信息。 可选的, 所述管理请求消息可以包括配置请求消息, 管理子安全 域可以包括创建子安全域, 所述配置请求消息还可以包含第一业务的 配置信息, 在所述第一业务新签约时, 可以将所述第一业务的配置信 息存储于所述子安全域中; 可选的, 所述管理请求消息可以包括删除请求消息, 管理子安全 域可以包括删除子安全域, 并且所述删除请求消息可以包含所述子安 全域的标识, 在所述第一业务终结时, 可以根据所述子安全域的标识 实现对所述子安全域的删除。 本发明实施例提供的通信终端,能通过通信终端获取服务器发送 的管理请求消息, 其中, 所述管理请求消息可以包含所述发行方安全 域配置文件标识, 然后, 所述通信终端在所述发行方安全域配置文件 标识对应的移动网络运营商配置文件中管理子安全域。 所以能够根据 用户签约业务的业务状态, 对可以用于存储第一业务配置信息的安全 域进行管理。 本发明的实施例提供一种安全域管理方法, 可以应用于通信领 域, 可以应用于图 1所示的安全域管理***中的服务器, 所述服务器 中可以预配置有移动网络运营商配置文件, 参照图 20 所示, 可以包 括以下步骤:
2001、 向签约管理安全路由发送查询请求消息。 其中,所述查询请求消息可以包含所述签约管理安全路由的标识 和嵌入式集成电路卡的标识;
2002、 获取所述签约管理安全路由发送的查询应答消息, 所述查 询应答消息可以包含所述移动网络运营商配置文件的发行方安全域 配置文件标识和所述移动网络运营商配置文件的状态;
2003、检查所述查询应答消息包含的所述移动网络运营商配置文 件的状态;
2004、在所述查询应答消息包含的所述移动网络运营商配置文件 的状态是激活状态时发送管理请求消 , 。 具体的, 可以向所述通信终端发送管理请求消息, 以便所述通信 终端根据所述管理请求消息管理子安全域。 其中,所述配置请求消息可以包含所述发行方安全域配置文件标 识, 所述子安全域可以用于存储第一业务的配置信息。 可选的, 所述管理请求消息可以包括配置请求消息, 管理子安全 域可以包括创建子安全域, 所述配置请求消息还可以包含第一业务的 配置信息, 在所述第一业务新签约时, 可以将所述第一业务的配置信 息存储于所述子安全域中; 可选的, 所述管理请求消息可以包括删除请求消息, 管理子安全 域可以包括删除子安全域, 并且所述删除请求消息可以包含所述子安 全域的标识, 在所述第一业务终结时, 可以根据所述子安全域的标识 实现对所述子安全域的删除。 本发明实施例提供的服务器,能通过服务器向通信终端发送管理 请求消息, 其中, 所述管理请求消息可以包含所述发行方安全域配置 文件标识, 然后, 所述通信终端在所述发行方安全域配置文件标识对 应的移动网络运营商配置文件中管理子安全域。 所以能够根据用户签 约业务的业务状态, 对可以用于存储第一业务配置信息的安全域进行 管理。 在图 19所示的实施例的基础上, 本发明的实施例提供一种安全 域管理方法, 可以应用于通信领域, 可以应用于图 1所示的安全域管 理***中的通信终端, 所述通信终端中可以预配置有移动网络运营商 配置文件, 参照图 21所示和图 22所示, 可以包括以下步骤: 首先参照图 21所示: 所述管理请求消息可以包括配置请求消息,所述管理子安全域可 以包括创建子安全域;
2101、 在所述第一业务新签约时, 获取配置请求消息, 所述配置 请求消息可以包含所述移动网络运营商配置文件的发行方安全域配 置文件标识和所述第一业务的配置信息, 所述第一业务的配置信息可 以包含所述第一业务的应用和数据; 具体的, 可以是获取所述服务器发送的配置请求消息; 本步为以下内容的具体实现方式之一: 获取管理请求消息, 所述 管理请求消息可以包含发行方安全域配置文件标识。 2102、在所述发行方安全域配置文件标识对应的所述移动网络运 营商配置文件下创建子安全域, 所述子安全域可以用于存储所述第一 业务的配置信息; 具体的, 本步为以下内容的具体实现方式之一: 在所述发行方安 全域配置文件标识对应的移动网络运营商配置文件下管理子安全域, 所述子安全域可以用于存储所述第一业务的配置信息。
2103、 为所述子安全域分配标识。 可选的, 在所述步骤 2103之后还可以根据所述子安全域的标识 管理所述子安全域。
2104、 发送配置应答消息, 所述配置应答消息可以包含所述子安 全域的标识, 以便所述服务器根据所述配置应答消息管理所述子安全 域。 具体的, 可以向所述服务器发送配置应答消息。 可选的, 参照图 22所示: 所述管理请求消息可以包括删除请求消息,所述管理子安全域可 以包括删除子安全域;
2201、 在所述第一业务终结时, 获取删除请求消息, 所述删除请 求消息可以包含所述发行方安全域配置文件标识和所述子安全域的 标识;
具体的, 可以是获取所述服务器发送的删除请求消息; 本步为以下内容的具体实现方式之一: 获取所述管理请求消息, 所述管理请求消息可以包含发行方安全域配置文件标识。
2202、根据所述删除请求消息包含的所述发行方安全域配置文件 标识和所述子安全域的标识, 检测所述子安全域中需要保存的应用和 数据;
2203、 发送保存请求消息, 所述保存请求消息可以包含所述需要 保存的应用和数据; 具体的, 可以是向所述服务器发送保存请求消息, 以便所述服务 器根据所述保存请求消息保存所述需要保存的应用和数据。 在发送所述保存请求消息后:
2204、根据所述删除请求消息包含的所述发行方安全域配置文件 标识和所述子安全域的标识, 删除所述发行方安全域配置文件标识对 应的所述移动网络运营商配置文件中的所述子安全域以及所述子安 全域中的应用和数据。 具体的, 本步为以下内容的具体实现方式之一: 根据所述删除请 求消息包含的所述发行方安全域配置文件标识和所述子安全域的标 识, 删除所述发行方安全域配置文件标识对应的所述移动网络运营商 配置文件中的所述子安全域。
2205、根据所述删除请求消息包含的所述发行方安全域配置文件 标识和所述子安全域的标识, 删除所述发行方安全域配置文件标识对 应的所述移动网络运营商配置文件中的所述子安全域。 具体的,本步为在所述发行方安全域配置文件标识对应的移动网 络运营商配置文件下管理子安全域, 所述子安全域可以用于存储所述 第一业务的配置信息的具体实现形式之一。 在删除所述子安全域后:
2206、 发送删除应答消息, 所述删除应答消息可以包含子安全域 删除成功状态信息和所述子安全域的标识。 具体的, 可以是向所述服务器发送删除应答消息。 可选的, 对于本实施例的以上步骤, 在获取管理请求消息之前, 所述方法还可以包括:
Al、 获取激活请求消息; 具体的, 可以是获取所述服务器发送的激活请求消息; A2、 根据所述激活请求消息获取用户指令;
A3、 在所述用户指令为激活指令时, 将所述移动网络运营商配 置文件的状态变更为激活状态;
A4、 发送所述激活应答消息, 所述激活应答消息可以包含所述 移动网络运营商配置文件的状态; 具体的, 可以是向所述服务器发送所述激活应答消息。 本发明实施例提供的通信终端,能通过通信终端获取服务器发送 的管理请求消息, 其中, 所述管理请求消息可以包含所述发行方安全 域配置文件标识, 然后, 所述通信终端在所述发行方安全域配置文件 标识对应的移动网络运营商配置文件中管理子安全域。 所述管理请求 消息可以包括配置请求消息, 管理子安全域可以包括创建子安全域, 所述配置请求消息还可以包含第一业务的配置信息, 在所述第一业务 新签约时, 可以将所述第一业务的配置信息存储于所述子安全域中; 所述管理请求消息可以包括删除请求消息, 管理子安全域可以包括删 除子安全域, 并且所述删除请求消息可以包含所述子安全域的标识, 在所述第一业务终结时, 可以根据所述子安全域的标识实现对所述子 安全域的删除。 所以能够根据用户签约业务的业务状态, 对可以用于 存储第一业务配置信息的安全域进行管理。 在图 20所示的实施例的基础上, 本发明的实施例提供一种安全 域管理方法, 可以应用于通信领域, 可以应用于图 1所示的安全域管 理***中的服务器, 所述服务器中可以预配置有移动网络运营商配置 文件, 参照图 23所示和图 24所示, 可以包括以下步骤: 可选的, 所述管理请求消息可以包括配置请求消息, 所述管理子 安全域可以包括创建子安全域; 参照图 23所示:
2301、 在所述第一业务新签约时, 向签约管理安全路由发送查询 请求消息。 其中,所述查询请求消息可以包含所述签约管理安全路由的标识 和嵌入式集成电路卡的标识;
2302、 获取所述签约管理安全路由发送的查询应答消息, 所述查 询应答消息可以包含所述移动网络运营商配置文件的发行方安全域 配置文件标识和所述移动网络运营商配置文件的状态;
2303、检查所述查询应答消息包含的所述移动网络运营商配置文 件的状态;
2304、在所述查询应答消息包含的所述移动网络运营商配置文件 的状态是激活状态时发送配置请求消息, 其中, 所述配置请求消息可 以包含所述发行方安全域配置文件标识和所述第一业务的配置信息, 所述第一业务的配置信息可以包含所述第一业务的应用信息和数据。 具体的, 可以是向所述通信终端发送配置请求消息, 以便所述通 信终端根据所述管理请求消息管理子安全域。 本步为以下内容的具体实现方式之一:在所述查询应答消息包含 的所述移动网络运营商配置文件的状态是激活状态时发送管理请求 消息, 其中, 所述配置请求消息可以包含所述发行方安全域配置文件 标识, 所述子安全域可以用于存储第一业务的配置信息。
2305、 获取配置应答消息, 所述配置应答消息可以包含子安全域 的标识;
具体的, 可以是获取所述通信终端发送的配置应答消息。
2306、将所述子安全域的标识记录在所述发行方安全域配置文件 标识对应的所述移动网络运营商配置文件中。
2307、 向所述签约管理安全路由发送第一更新请求消息。 其中, 所述第一更新请求消息中可以包含所述移动网络运营商配置文件的 配置信息, 以便所述签约管理安全路由按照所述第一更新请求消 , 更 新所述移动网络运营商配置文件的配置信息。
这样做, 可以使所述签约管理安全路由、 所述服务器和所述通信 终端中的移动网络运营商配置文件同步, 所述移动网络运营商配置文 件的配置信息可以包含移动网络运营商配置文件的类型、版本和子安 全域信息。
可选的, 所述管理请求消息可以包括删除请求消息, 所述管理子 安全域可以包括删除子安全域, 参照图 24所示:
2401、 在所述第一业务终结时, 向签约管理安全路由发送查询请 求消息, 所述查询请求消息可以包含所述签约管理安全路由的标识和 嵌入式集成电路卡的标识;
2402、 获取所述签约管理安全路由发送的查询应答消息, 所述查 询应答消息可以包含所述移动网络运营商配置文件的发行方安全域 配置文件标识和所述移动网络运营商配置文件的状态;
2403、检查所述查询应答消息包含的所述移动网络运营商配置文 件的状态;
2404、 获取子安全域的标识; 具体的,所述服务器可以从自身存储的数据中获取子安全域的标 识, 也可以从第三方获取, 例如从所述通信终端先获取已知的子安全 域的标识, 然后从中选取需要删除的。
2405、在所述查询应答消息包含的所述移动网络运营商配置文件 的状态是激活状态时发送删除请求消息, 所述删除请求消息可以包含 所述发行方安全域配置文件标识和所述子安全域的标识。 具体的, 可以是向所述通信终端发送删除请求消息, 以便所述通 信终端根据所述管理请求消息管理子安全域。 本步为以下内容的具体实现方式之一:所述服务器在所述查询应 答消息包含的所述移动网络运营商配置文件的状态是激活状态时, 向 所述通信终端发送管理请求消息, 其中, 所述配置请求消息可以包含 所述发行方安全域配置文件标识, 所述子安全域可以用于存储第一业 务的配置信息。
2406、 获取保存请求消息, 所述保存请求消息可以包含需要保存 的应用和数据; 具体的, 可以是获取所述通信终端发送的保存请求消息。 可选的, 在所述步骤 2406之后, 还可以根据所述保存请求消息 保存所述需要保存的应用和数据。
2407、 获取删除应答消息, 所述删除应答消息可以包含子安全域 删除成功状态信 , 和被删除的子安全域的标识; 具体的, 可以是获取所述通信终端发送的删除应答消息。
2408、根据所述子安全域删除成功状态信息和所述被删除的子安 全域的标识, 删除所述移动网络运营商配置文件中的子安全域的标 识。
在删除了所述移动网络运营商配置文件中的子安全域的标识之 后:
2409、 向所述签约管理安全路由发送第二更新请求消息; 其中,所述第二更新请求消息中可以包含被删除了所述子安全域 的标识的所述移动网络运营商配置文件的配置信息, 以便所述签约管 理安全路由按照所述第二更新请求消息更新所述移动网络运营商配 置文件的配置信息, 使所述签约管理安全路由、 所述服务器和所述通 信终端中的移动网络运营商配置文件同步。 可选的, 对于本实施例的以上步骤, 获取管理应答消息之前, 所 述方法还可以包括:
B 1、 如果所述查询应答消息包含的所述移动网络运营商配置文 件的状态是未激活状态, 则发送激活请求消 , ;
具体的, 可以是向所述通信终端发送激活请求消息;
B2、 获取激活应答消息, 所述激活应答消息可以包含所述移动 网络运营商配置文件的状态; 具体的, 可以是获取所述通信终端发送的激活应答消息; B3、 检查所述激活应答消息包含的所述移动网络运营商配置文 件的状态;
B4、 在所述激活应答消息包含的所述移动网络运营商配置文件 的状态是激活状态时发送删除请求消 , ; 具体的, 可以是向所述通信终端发送删除请求消息。 本发明实施例提供的服务器,能通过服务器向通信终端发送管理 请求消息, 其中, 所述管理请求消息可以包含所述发行方安全域配置 文件标识, 然后, 在所述发行方安全域配置文件标识对应的移动网络 运营商配置文件中管理子安全域。 所述管理请求消息可以包括配置请 求消息, 管理子安全域可以包括创建子安全域, 所述配置请求消息还 可以包含第一业务的配置信息, 在所述第一业务新签约时, 可以将所 述第一业务的配置信息存储于所述子安全域中; 所述管理请求消息可 以包括删除请求消息, 管理子安全域可以包括删除子安全域, 并且所 述删除请求消息可以包含所述子安全域的标识, 在所述第一业务终结 时, 可以根据所述子安全域的标识实现对所述子安全域的删除。 所以 能够根据用户签约业务的业务状态, 对可以用于存储第一业务配置信 息的安全域进行管理。 本发明实施例提供一种安全域管理方法, 可以应用于通信领域, 可以应用于图 1所示的安全域管理***中的签约管理安全路由, 参照 图 25所示, 可以包括以下步骤:
2501、 获取服务器发送的查询请求消息, 所述查询请求消息可以 包含所述签约管理安全路由的标识和嵌入式集成电路卡的标识。
2502、 根据所述签约管理安全路由的标识, 获取与所述嵌入式集 成电路卡的标识对应的所述移动网络运营商配置文件的发行方安全 域配置文件标识和所述移动网络运营商配置文件的状态。
2503、 向服务器发送的查询应答消息, 所述查询应答消息可以包 含所述移动网络运营商配置文件的发行方安全域配置文件标识和所 述移动网络运营商配置文件的状态, 以便所述服务器进行安全域管 理。 可选的, 所述步骤 2503之后, 所述安全域管理方法还可以包括 以下步骤:
2504、 获取所述服务器发送的第一更新请求消息, 所述第一更新 请求消息中可以包含所述移动网络运营商配置文件的配置信息。
2505、按照所述第一更新请求消息更新所述移动网络运营商配置 文件的配置信息。 这样就能使所述签约管理安全路由、所述服务器和所述通信终端 中的移动网络运营商配置文件同步, 所述移动网络运营商配置文件的 配置信息可以包含移动网络运营商配置文件的类型、 版本和子安全域 信息。 本发明实施例提供的安全域管理方法,通过签约管理安全路由获 取服务器发送的查询请求消息; 根据所述查询请求消息获取移动网络 运营商配置文件的发行方安全域配置文件标识和所述移动网络运营 商配置文件的状态, 并向所述服务器发送查询应答消息, 所述查询应 答消息可以包含所述移动网络运营商配置文件的发行方安全域配置 文件标识和所述移动网络运营商配置文件的状态, 以便所述服务器进 行安全域管理。 本发明的实施例提供一种安全域管理方法, 可以应用于通信领 域, 可以应用于图 1所示的安全域管理***中的可信服务管理器, 参 照图 26所示, 可以包括以下步骤:
2601、 获取服务器发送的第一转发请求消息, 所述第一转发请求 消息可以包含所述发行方安全域配置文件标识、 集成电路卡标识和所 述第一业务的配置信息。 其中,所述第一业务的配置信息可以包含所述第一业务的应用信 息和数据。 2602、 向通信终端发送第一连接请求消息, 所述第一连接请求消 息可以包含所述集成电路卡标识。
2603、 获取所述通信终端发送的第一连接应答消息。
2604、 在所述获取单元获取到所述第一连接应答消息时, 发送第 一服务请求消息。 其中,所述第一服务请求消息可以包含所述移动网络运营商配置 文件的发行方安全域配置文件标识和所述第一业务的配置信息, 所述 第一业务的配置信息可以包含所述第一业务的应用和数据, 以便所述 通信终端为所述第一业务配置安全域;
2605、 获取所述通信终端发送的第一服务应答消息, 所述第一服 务应答消息可以包含子安全域的标识。
2606、 向所述服务器发送第一转发应答消息, 所述第一转发应答 消息可以包含所述子安全域的标识。 本发明实施例本发明实施例提供的安全域管理方法,本发明实通 过可信服务管理器转发服务器和通信终端之间的通信消息, 辅佐服务 器和通信终端, 在移动网络运营商配置文件中对可以用于存储第一业 务配置信息的安全域进行管理。 在上述各实施例的基础上,本发明实施例提供一种安全域管理方 法, 可以用于通信领域, 可以用于图 1所示的安全域管理***, 具体 可以结合上述各实施例提供的设备进行适用, 可以用于在用户新签约 第一业务时, 在通信终端的移动网络运营商配置文件中增加可以用于 存储所述第一业务的配置信息的安全域, 所述第一业务可以包括移动 支付业务, 参照图 27所示, 在实施例的一些步骤中还需要参照图 28、 图 29或图 30所示, 具体步骤如下:
2701、服务器在第一业务新签约时向签约管理安全路由发送查询 请求消息, 所述查询请求消息可以包含所述签约管理安全路由的标识 和嵌入式集成电路卡的标识。 在签约管理安全路由获取服务器发送的查询请求消息后:
2702、签约管理安全路由根据所述查询请求消息包含的所述签约 管理安全路由的标识, 获取与所述嵌入式集成电路卡的标识对应的所 述移动网络运营商配置文件的发行方安全域配置文件标识和所述移 动网络运营商配置文件的状态。
2703、 签约管理安全路由向服务器发送查询应答消息, 所述查询 应答消息可以包含所述移动网络运营商配置文件的发行方安全域配 置文件标识和所述移动网络运营商配置文件的状态。 这样做的原因是, 以便所述服务器进行安全域管理。 在所述服务器获取所述签约管理安全路由发送的查询应答消息 后:
2704、所述服务器检查所述查询应答消息包含的所述移动网络运 营商配置文件的状态。
2705、如果所述查询应答消息包含的所述移动网络运营商配置文 件的状态是激活状态, 则所述服务器向所述通信终端发送配置请求消 息, 所述配置请求消息可以包含所述发行方安全域配置文件标识和所 述第一业务的配置信息。 其中,所述第一业务的配置信息可以包含所述第一业务的应用信 息和数据。
在所述通信终端获取所述服务器发送的配置请求消息后:
2706、所述通信终端在所述发行方安全域配置文件标识对应的所 述移动网络运营商配置文件下创建子安全域。 其中, 所述子安全域可以用于存储所述第一业务的配置信息。
2707、 所述通信终端为所述子安全域分配标识。
2708、 所述通信终端向所述服务器发送配置应答消息, 所述配置 应答消息可以包含所述子安全域的标识。 在所述服务器获取所述通信终端发送的配置应答消息后:
2709、所述服务器将所述子安全域的标识记录在所述发行方安全 域配置文件标识对应的所述移动网络运营商配置文件中。
2710、所述服务器向所述签约管理安全路由发送第一更新请求消 息, 所述第一更新请求消息中可以包含所述移动网络运营商配置文件 的配置信息。
这样做的目的是,以便所述签约管理安全路由按照所述第一更新 请求消息更新所述移动网络运营商配置文件的配置信息, 使所述签约 管理安全路由、 所述服务器和所述通信终端中的移动网络运营商配置 文件同步, 所述移动网络运营商配置文件的配置信息可以包含移动网 络运营商配置文件的类型、 版本和子安全域信息。
可选的,在签约管理安全路由获取所述服务器发送的第一更新请 求消息后:
271 1、签约管理安全路由按照所述第一更新请求消息更新所述移 动网络运营商配置文件的配置信息。
于是, 所述签约管理安全路由、 所述服务器和所述通信终端中的 移动网络运营商配置文件同步。
可选的,如果所述查询应答消息包含的所述移动网络运营商配置 文件的状态是未激活状态, 则所述步骤 2705 不可执行, 由以下步骤 2705a至步骤 2705f代替:
2705a , 如果所述查询应答消息包含的所述移动网络运营商配置 文件的状态是未激活状态, 则所述服务器向所述通信终端发送激活请 求消息;
在所述通信终端获取所述服务器发送的激活请求消息后: 2705b , 所述通信终端根据所述激活请求消息获取用户指令; 2705c , 所述通信终端在所述用户指令为激活指令时, 将所述移 动网络运营商配置文件的状态变更为激活状态;
2705d、 所述通信终端向所述服务器发送所述激活应答消息, 所 述激活应答消息可以包含所述移动网络运营商配置文件的状态。 在所述服务器获取所述通信终端发送的激活应答消息后:
2705e、 所述服务器检查所述激活应答消息包含的所述移动网络 运营商配置文件的状态;
2705f、 在所述激活应答消息包含的所述移动网络运营商配置文 件的状态是激活状态时, 所述服务器向所述通信终端发送配置请求消 息。 进一步, 可选的, 当所述安全域管理***可以包含可信服务管理 器时, 参照图 28所示, 步骤如下:
2801、 服务器向签约管理安全路由发送查询请求消息, 所述查询 请求消息可以包含所述签约管理安全路由的标识和嵌入式集成电路 卡的标识。
在签约管理安全路由获取服务器发送的查询请求消息后:
2802、签约管理安全路由根据所述查询请求携带的所述签约管理 安全路由的标识, 获取与所述嵌入式集成电路卡的标识对应的所述移 动网络运营商配置文件的发行方安全域配置文件标识和所述移动网 络运营商配置文件的状态。
2803、 签约管理安全路由向服务器发送查询应答消息, 所述查询 应答消息可以包含所述移动网络运营商配置文件的发行方安全域配 置文件标识和所述移动网络运营商配置文件的状态。 这样做的原因是, 以便所述服务器进行安全域管理。 在所述服务器获取所述签约管理安全路由发送的查询应答消息 后:
2804、所述服务器检查所述查询应答消息包含的所述移动网络运 营商配置文件的状态。
2805、服务器在所述查询应答消息包含的所述移动网络运营商配 置文件的状态是激活状态时, 向所述可信服务管理器发送第一转发请 求消息, 所述第一转发请求消息可以包含所述发行方安全域配置文件 标识、 集成电路卡标识和所述第一业务的配置信息。 其中,所述第一业务的配置信息可以包含所述第一业务的应用信 息和数据。
在所述可信服务管理器获取服务器发送的第一转发请求消息后:
2806、所述可信服务管理器和所述通信终端之间利用所述集成电 路卡标识建立连接。
具体可选的,所述可信服务管理器向通信终端发送第一连接请求 消息, 所述第一连接请求消息可以包含所述集成电路卡标识。
在所述通信终端获取所述可信服务管理器发送的第一连接请求 消息后:
所述通信终端在所述第一连接请求消息可以包含集成电路卡标 识与通信终端自身匹配时, 发送第一连接应答消息; 在所述可信服务管理器获取所述通信终端发送的第一连接应答 消息后, 即在所述可信服务管理器和所述通信终端之间建立连接后:
2807、所述可信服务管理器向所述嵌入式集成电路卡发送第一服 务请求消息, 所述第一服务请求消息可以包含所述移动网络运营商配 置文件的发行方安全域配置文件标识和所述第一业务的配置信息。
在所述通信终端获取所述可信服务管理器发送的第一服务请求 消息后:
2808、所述通信终端在所述第一服务请求消息包含的所述发行方 安全域配置文件标识对应的所述移动网络运营商配置文件下创建子 安全域。 其中, 所述子安全域可以用于存储所述第一业务的配置信息。
2809、 所述通信终端为所述子安全域分配标识。
2810、所述通信终端向所述可信服务管理器发送第一服务应答消 息, 所述第一服务应答消息可以包含所述子安全域的标识。 在所述可信服务管理器获取所述通信终端发送的第一服务应答 消息后:
281 1、 所述可信服务管理器向所述服务器发送第一转发应答消 息, 所述第一转发应答消息可以包含子安全域的标识。 在服务器获取所述可信服务管理器发送的第一转发应答消息后:
2812、所述服务器将所述子安全域的标识记录在所述发行方安全 域配置文件标识对应的所述移动网络运营商配置文件中。
2813、所述服务器向所述签约管理安全路由发送第一更新请求消 息, 所述第一更新请求消息中可以包含所述移动网络运营商配置文件 的配置信息。
这样做的目的是,以便所述签约管理安全路由按照所述第一更新 请求消息更新所述移动网络运营商配置文件的配置信息, 使所述签约 管理安全路由、 所述服务器和所述通信终端中的移动网络运营商配置 文件同步, 所述移动网络运营商配置文件的配置信息可以包含移动网 络运营商配置文件的类型、 版本和子安全域信息。
可选的,在签约管理安全路由获取所述服务器发送的第一更新请 求消息后:
2814、签约管理安全路由按照所述第一更新请求消息更新所述移 动网络运营商配置文件的配置信息。 于是, 所述签约管理安全路由、 所述服务器和所述通信终端中的 移动网络运营商配置文件同步。 可选的,在所述查询应答消息包含的所述移动网络运营商配置文 件的状态是未激活状态时, 所述步骤 2805 同样可以由步骤 2705a至 步骤 2705f代替, 只是这里需要注意的是, 此时, 所述步骤 2705f 内 容需要变更为: 在所述激活应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时, 所述服务器向所述可信服务管理器发送第一转发请 求消息, 所述第一转发请求消息可以包含所述发行方安全域配置文件 标识、 集成电路卡标识和所述第一业务的配置信息。 可选的, 在本实施例的上述步骤的基础上, 在所述第一业务终结 时, 参照图 29所示, 所述安全域管理方法还可以包括以下步骤:
2901、所述服务器在所述第一业务终结时向所述签约管理安全路 由发送查询请求消息, 所述查询请求消息可以包含所述签约管理安全 路由的标识和所述嵌入式集成电路卡的标识。 在签约管理安全路由获取所述服务器发送的查询请求消息后:
2902、签约管理安全路由根据所述查询请求消息包含的所述签约 管理安全路由的标识, 获取与所述嵌入式集成电路卡的标识对应的所 述移动网络运营商配置文件的发行方安全域配置文件标识和所述移 动网络运营商配置文件的状态。
2903、 签约管理安全路由向所述服务器发送查询应答消息, 所述 查询应答消息可以包含所述发行方安全域配置文件标识和所述移动 网络运营商配置文件的状态。 在所述服务器获取所述签约管理安全路由发送的查询应答消息 后:
2904、所述服务器检查所述查询应答消息包含的所述移动网络运 营商配置文件的状态。
2905、如果所述查询应答消息包含的所述移动网络运营商配置文 件的状态是激活状态, 则所述服务器向所述通信终端发送删除请求消 息, 所述删除请求消息可以包含所述发行方安全域配置文件标识和所 述子安全域的标识。
在所述通信终端获取所述服务器发送的删除请求消息后:
2906、所述通信终端根据所述发行方安全域配置文件标识和所述 子安全域的标识, 检测所述子安全域中需要保存的应用和数据。 其中,检测所述子安全域中所述需要保存的应用和数据的检测标 准, 可以结合实际运用中不同业务的业务内容来预先设定; 或者, 可 以结合实际运用中用户输入的指令来决定需要保存的应用和数据的 检测标准。 本发明并不限定所述需要保存的应用和数据的具体内容, 也不限定检测所述子安全域中需要保存的应用和数据的具体方法, 只 要能检测出所述需要保存的应用和数据即可。
2907、 所述通信终端向所述服务器发送保存请求消息, 所述保存 请求消息可以包含所述需要保存的应用和数据。 在所述服务器获取所述通信终端发送的保存请求消息后:
2908、 所述服务器保存所述需要保存的应用和数据。
2909、 在保存所述需要保存的应用和数据后, 所述服务器向所述 通信终端发送保存应答消息。
在所述通信终端获取所述服务器发送的保存应答消息后:
2910、所述通信终端根据所述发行方安全域配置文件标识和所述 子安全域的标识, 删除所述发行方安全域配置文件标识对应的所述移 用和数据。
291 1、 所述通信终端在删除所述子安全域后, 向所述服务器发送 删除应答消息, 所述删除应答消息可以包含子安全域删除成功状态信 息和所述子安全域的标识。 在所述服务器获取所述通信终端发送的删除应答消息后:
2912、所述服务器根据所述子安全域删除成功状态信息和所述被 删除的子安全域的标识, 删除所述移动网络运营商配置文件中的子安 全域的标识。 可选的, 所述方法还可以包括:
2913、所述服务器在删除了所述移动网络运营商配置文件中的子 安全域的标识之后, 向所述签约管理安全路由发送第二更新请求消 息, 所述第二更新请求消息中可以包含被删除了所述子安全域的标识 的所述移动网络运营商配置文件的配置信息。 这样做的目的是,以便所述签约管理安全路由按照所述第二更新 请求消息更新所述移动网络运营商配置文件的配置信息, 使所述签约 管理安全路由、 所述服务器和所述通信终端中的移动网络运营商配置 文件同步。 在签约管理安全路由获取所述服务器发送的第二更新请求消息 后:
2914、签约管理安全路由按照所述第二更新请求消息更新所述移 动网络运营商配置文件的配置信息。 于是, 所述签约管理安全路由、 所述服务器和所述通信终端中的 移动网络运营商配置文件同步。 进一步, 可选的, 如果所述查询应答消息包含的所述移动网络运 营商配置文件的状态是未激活状态, 则所述步骤 2905 可由以下步骤 2905a至步骤 2905f代替:
2905a , 所述服务器向所述通信终端发送激活请求消息。
在所述通信终端获取所述服务器发送的激活请求消息后:
2905b , 所述通信终端根据所述激活请求消息获取用户指令。
2905c , 所述通信终端在所述用户指令为激活指令时, 将所述移 动网络运营商配置文件的状态变更为激活状态。
2905d、 所述通信终端向所述服务器发送所述激活应答消息, 所 述激活应答消息可以包含所述移动网络运营商配置文件的状态。 在所述服务器获取所述通信终端发送的激活应答消息后:
2905e、 所述服务器检查所述激活应答消息包含的所述移动网络 运营商配置文件的状态。
2905f、 在所述激活应答消息包含的所述移动网络运营商配置文 件的状态是激活状态时, 所述服务器向所述通信终端发送删除请求消 息。
进一步可选的, 在本实施例的上述步骤的基础上, 当所述安全域 管理***可以包含可信服务管理器时, 参照图 30 所示, 本实施例还 可以由下述步骤完成:
3001、 所述服务器向所述签约管理安全路由发送查询请求消息 , 所述查询请求消息可以包含所述签约管理安全路由的标识和所述嵌 入式集成电路卡的标识。 在签约管理安全路由获取所述服务器发送的查询请求消息后:
3002、签约管理安全路由根据所述查询请求消息包含的所述签约 管理安全路由的标识, 获取与所述嵌入式集成电路卡的标识对应的所 述移动网络运营商配置文件的发行方安全域配置文件标识和所述移 动网络运营商配置文件的状态。
3003、 签约管理安全路由向所述服务器发送查询应答消息, 所述 查询应答消息可以包含所述发行方安全域配置文件标识和所述移动 网络运营商配置文件的状态。 在所述服务器获取所述签约管理安全路由发送的查询应答消息 后:
3004、所述服务器检查所述查询应答消息包含的所述移动网络运 营商配置文件的状态。
3005、如果所述查询应答消息包含的所述移动网络运营商配置文 件的状态是激活状态, 向所述可信服务管理器发送第二转发请求消 息, 所述第二转发请求消息可以包含所述发行方安全域配置文件标 识、 集成电路卡标识和所述子安全域的标识。 在所述可信服务管理器获取所述服务器发送的第二转发请求消 息后:
3006、所述可信服务管理器和所述通信终端利用所述集成电路卡 标识建立连接。 具体可选的,所述可信服务管理器向所述通信终端发送第二连接 请求消息, 所述第二连接请求消息可以包含所述集成电路卡标识; 在所述通信终端获取所述可信服务管理器发送的第二连接请求 消息后: 所述通信终端在所述第二连接请求消息可以包含集成电路卡标 识与通信终端自身匹配时, 发送第二连接应答消息。 在所述可信服务管理器获取所述通信终端发送的第二连接应答 消息后, 即所述可信服务管理器和所述通信终端建立连接后:
3007、所述可信服务管理器向所述通信终端发送第二服务请求消 息, 所述第二服务请求消息可以包含所述发行方安全域配置文件标识 和所述子安全域的标识。 在所述通信终端获取所述可信服务管理器发送的第二服务请求 消息后:
3008、所述通信终端根据所述发行方安全域配置文件标识和所述 子安全域的标识, 检测所述子安全域中需要保存的应用和数据。
3009、 所述通信终端向所述服务器发送保存请求消息, 所述保存 请求消息可以包含所述需要保存的应用和数据。 在所述服务器获取所述通信终端发送的保存请求消息后:
3010、 所述服务器保存所述需要保存的应用和数据。 301 1、 在保存所述需要保存的应用和数据后, 所述服务器向所述 通信终端发送保存应答消息。
在所述通信终端获取所述服务器发送的保存应答消息后:
3012、所述通信终端根据所述第二服务请求消息包含的所述发行 方安全域配置文件标识和所述子安全域的标识, 删除所述发行方安全 域配置文件标识对应的所述移动网络运营商配置文件中的所述子安 全域。
具体的, 所述通信终端在获取所述保存应答消息后, 所述通信终 端根据所述发行方安全域配置文件标识和所述子安全域的标识, 删除 所述发行方安全域配置文件标识对应的所述移动网络运营商配置文
3013、 所述通信终端在删除所述子安全域后, 向所述可信服务管 理器发送第二服务应答消息, 所述第二服务应答消息可以包含子安全 域删除成功状态信息和删除的所述子安全域的标识。 在所述可信服务管理器获取所述通信终端发送的第二服务应答 消息后:
3014、 所述可信服务管理器向所述服务器发送第二转发应答消 和被删除的子安全域的标识。 在所述服务器获取所述可信服务管理器发送的第二转发应答消 息后:
3015、所述服务器根据获取的所述子安全域删除成功状态信息和 所述被删除的子安全域的标识, 删除所述移动网络运营商配置文件中 的子安全域的标识。 可选的, 所述方法还可以包括:
3016、所述服务器在删除了所述移动网络运营商配置文件中的子 安全域的标识之后, 向所述签约管理安全路由发送第二更新请求消 息, 所述第二更新请求消息中可以包含被删除了所述子安全域的标识 的所述移动网络运营商配置文件的配置信息。 这样做的目的是,以便所述签约管理安全路由按照所述第二更新 请求消息更新所述移动网络运营商配置文件的配置信息, 使所述签约 管理安全路由、 所述服务器和所述通信终端中的移动网络运营商配置 文件同步。
在所述签约管理安全路由获取所述服务器发送的第二更新请求 消息后:
3017、 所述签约管理安全路由按照所述第二更新请求消息, 更新 所述移动网络运营商配置文件的配置信息。 于是, 所述签约管理安全路由、 所述服务器和所述通信终端中的 移动网络运营商配置文件同步。 可选的,在所述查询应答消息包含的所述移动网络运营商配置文 件的状态是未激活状态时, 所述步骤 3005 同样可以由步骤 2905a至 步骤 2905f代替, 只是这里需要注意的是, 此时, 所述步骤 2905f 内 容需要变更为:
在所述激活应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时, 所述服务器向所述可信服务管理器发送第二转发请 求消息, 所述第二转发请求消息可以包含所述发行方安全域配置文件 标识、 集成电路卡标识和所述子安全域的标识 本发明实施例提供的通信终端,能通过通信终端获取服务器发送 的管理请求消息, 其中, 所述管理请求消息可以包含所述发行方安全 域配置文件标识, 然后, 所述通信终端在所述发行方安全域配置文件 标识对应的移动网络运营商配置文件中管理子安全域。 所述管理请求 消息可以包括配置请求消息, 管理子安全域可以包括创建子安全域, 所述配置请求消息还可以包含第一业务的配置信息, 所述通信终端在 所述第一业务新签约时, 可以将所述第一业务的配置信息存储于所述 子安全域中; 所述管理请求消息可以包括删除请求消息, 管理子安全 域可以包括删除子安全域, 并且所述删除请求消息可以包含所述子安 全域的标识, 所述通信终端在所述第一业务终结时, 可以根据所述子 安全域的标识实现对所述子安全域的删除。 所以能够根据用户签约业 务的业务状态, 对可以用于存储第一业务配置信息的安全域进行管 理。 同时, 由本发明实施例提供的安全域管理方法可知, 还可以通过 与配置安全域类似的流程, 对已经配置的安全域进行删除, 所以本发 明实施例提供的安全域管理方法能够在通信终端的移动网络运营商 配置文件中增加关于新签约业务的配置信息和安全域, 并且在该新签 约业务终止时删除相关的安全域和配置信息, 对可以用于存储第一业 务配置信息的安全域进行管理。 由上可知, 本发明实施例提供的安全域管理方法, 不需要用户更 换通用集成电路卡, 在通信终端的形态下, 可以根据用户是否签约移 动业务来灵活地管理安全域。 以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围并 不局限于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范 围内, 可轻易想到变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护范围应以权利要求的保护范围为准。

Claims

权 利 要 求 书
1、 一种通信终端, 其特征在于, 所述通信终端包括:
获取单元, 用于获取管理请求消息, 所述管理请求消息包含发行 方安全域配置文件标识;
管理单元,用于在所述获取单元获取的所述配置请求消息包含的 所述发行方安全域配置文件标识对应的移动网络运营商配置文件下 管理子安全域, 所述子安全域用于存储第一业务的配置信息。
2、 根据权利要求 1 所述的通信终端, 其特征在于, 所述管理请 求消息包括配置请求消息, 所述管理子安全域包括创建子安全域; 所述获取单元,具体用于在所述第一业务新签约时获取配置请求 消息, 所述配置请求消息包含所述发行方安全域配置文件标识和所述 第一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的 应用和数据;
所述管理单元,具体用于在所述获取单元获取的所述配置请求消 息包含的所述发行方安全域配置文件标识对应的所述移动网络运营 商配置文件下创建子安全域, 并将所述第一业务的配置信息存储于所 述子安全域;
所述通信终端, 还包括:
分配单元, 用于为所述管理单元创建的所述子安全域分配标识; 所述管理单元,还用于根据所述分配单元分配的所述子安全域的 标识管理所述子安全域。
3、 根据权利要求 2所述的通信终端, 其特征在于, 所述通信终 端还包括:
第一发送单元, 用于发送配置应答消息, 所述配置应答消息包含 所述分配单元分配的所述子安全域的标识, 以便服务器根据所述配置 应答消息管理所述子安全域。
4、 根据权利要求 1 所述的通信终端, 其特征在于, 所述管理请 求消息包括删除请求消息, 所述管理子安全域包括删除子安全域; 所述获取单元,具体用于在所述第一业务终结时获取删除请求消 息, 所述删除请求消息包含所述发行方安全域配置文件标识和所述子 安全域的标识;
所述管理单元,具体用于根据所述获取单元获取的所述删除请求 消息包含的所述发行方安全域配置文件标识和所述子安全域的标识, 删除所述发行方安全域配置文件标识对应的所述移动网络运营商配 置文件中的所述子安全域。
5、 根据权利要求 4所述的通信终端, 其特征在于, 所述通信终 端还包括:
检测单元,用于根据所述获取单元获取的所述删除请求消息包含 的所述发行方安全域配置文件标识和所述子安全域的标识, 检测所述 子安全域中需要保存的应用和数据;
第二发送单元, 用于发送保存请求消息, 所述保存请求消息包含 所述检测单元检测的所述需要保存的应用和数据, 以便服务器根据所 述保存请求消息保存所述需要保存的应用和数据;
所述管理单元,具体用于在所述第二发送单元发送所述保存请求 消息后, 根据所述获取单元获取的所述发行方安全域配置文件标识和 所述子安全域的标识, 删除所述发行方安全域配置文件标识对应的所 的应用和数据。
6、 根据权利要求 4或 5所述的通信终端, 其特征在于, 所述通 信终端还包括:
第三发送单元, 用于在所述管理单元删除所述子安全域后, 发送 删除应答消息, 所述删除应答消息包含子安全域删除成功状态信息和 所述管理单元删除的所述子安全域的标识。
7、 根据权利要求 1 -6任一项所述的通信终端, 其特征在于, 所 述获取单元, 还用于获取激活请求消息;
所述获取单元,还用于根据所述获取单元获取的所述激活请求消 息获取用户指令;
所述通信终端, 还包括: 变更单元,用于在所述获取单元获取的所述用户指令为激活指令 时, 将所述移动网络运营商配置文件的状态变更为激活状态;
第四发送单元, 用于发送所述激活应答消息, 所述激活应答消息 包含所述变更单元变更的所述移动网络运营商配置文件的状态。
8、 一种服务器, 其特征在于, 所述服务器包括:
发送单元, 用于向签约管理安全路由发送查询请求消息, 所述查 询请求消息包含所述签约管理安全路由的标识和嵌入式集成电路卡 的标识;
获取单元, 用于获取所述签约管理安全路由发送的查询应答消 息, 所述查询应答消息包含移动网络运营商配置文件的发行方安全域 配置文件标识和所述移动网络运营商配置文件的状态;
检查单元,用于检查所述获取单元获取的所述查询应答消息包含 的所述移动网络运营商配置文件的状态;
所述发送单元,还用于在所述检查单元检查的所述查询应答消息 包含的所述移动网络运营商配置文件的状态是激活状态时发送管理 请求消息,以便通信终端根据所述管理请求消息管理子安全域,其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息。
9、 根据权利要求 8所述的服务器, 其特征在于, 所述管理请求 消息包括配置请求消息, 所述管理子安全域包括创建子安全域;
所述发送单元,还用于在所述检查单元检查的所述查询应答消息 包含的所述移动网络运营商配置文件的状态是激活状态时发送管理 请求消息,以便通信终端根据所述管理请求消息管理子安全域,其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息, 具体包括:
在所述第一业务新签约并且所述检查单元检查的所述查询应答 消息包含的所述移动网络运营商配置文件的状态是激活状态时发送 配置请求消息, 以便通信终端根据所述管理请求消息创建子安全域, 其中, 所述配置请求消息包含所述发行方安全域配置文件标识和所述 第一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的 应用信息和数据。
10、根据权利要求 9所述的服务器, 其特征在于, 所述获取单元, 还用于获取配置应答消息, 所述配置应答消息包含子安全域的标识; 所述服务器还包括:
配置单元,用于将所述获取单元获取的所述子安全域的标识记录 在所述发行方安全域配置文件标识对应的所述移动网络运营商配置 文件中。
1 1、 根据权利要求 10所述的服务器, 其特征在于, 所述发送单 元, 还用于在所述配置单元将所述子安全域的标识记录在所述发行方 安全域配置文件标识对应的所述移动网络运营商配置文件中之后, 向 所述签约管理安全路由发送第一更新请求消息;
其中,所述第一更新请求消息中包含所述移动网络运营商配置文 件的配置信息, 以便所述签约管理安全路由按照所述第一更新请求消 息更新所述移动网络运营商配置文件的配置信息, 所述移动网络运营 商配置文件的配置信息包含移动网络运营商配置文件的类型、 版本和 子安全域信息。
12、 根据权利要求 8所述的服务器, 其特征在于, 所述管理请求 消息包括删除请求消息, 所述管理子安全域包括删除子安全域;
所述获取单元,还用于在所述第一业务终结时获取子安全域的标 识;
所述发送单元,还用于在所述检查单元检查的所述查询应答消息 包含的所述移动网络运营商配置文件的状态是激活状态时发送管理 请求消息,以便通信终端根据所述管理请求消息管理子安全域,其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息, 具体包括:
在所述检查单元检查的所述查询应答消息包含的所述移动网络 运营商配置文件的状态是激活状态时发送删除请求消息, 以便通信终 端根据所述管理请求消息删除子安全域, 其中, 所述删除请求消息包 含所述发行方安全域配置文件标识和所述子安全域的标识。
13、 根据权利要求 12所述的服务器, 其特征在于, 所述获取单 元, 还用于获取保存请求消息, 所述保存请求消息包含需要保存的应 用和数据;
所述服务器还包括:
保存单元,用于根据所述获取单元获取的所述保存请求消息保存 所述需要保存的应用和数据。
14、 根据权利要求 12或 13所述的服务器, 其特征在于, 所述获 取单元, 还用于获取删除应答消息, 所述删除应答消息包含子安全域 删除成功状态信息和被删除的子安全域的标识;
所述服务器还包括:
配置单元,用于根据所述获取单元获取的所述子安全域删除成功 状态信 , I,和所述被删除的子安全域的标识, 删除所述移动网络运营商 配置文件中的子安全域的标识。
15、 根据权利要求 14所述的服务器, 其特征在于, 所述发送单 元, 还用于在所述配置单元删除了所述移动网络运营商配置文件中的 子安全域的标识之后, 向所述签约管理安全路由发送第二更新请求消 息;
其中,所述第二更新请求消息中包含被所述配置单元删除了所述 子安全域的标识的所述移动网络运营商配置文件的配置信息, 以便所 述签约管理安全路由按照所述第二更新请求消息更新所述移动网络 运营商配置文件的配置信息。
16、 根据权利要求 8- 15 任一项所述的服务器, 其特征在于, 所 述发送单元, 还用于在所述检查单元检查的所述查询应答消息包含的 所述移动网络运营商配置文件的状态是未激活状态时发送激活请求 消息;
所述获取单元, 还用于获取激活应答消息, 所述激活应答消息包 含所述移动网络运营商配置文件的状态;
所述检查单元,还用于检查所述获取单元获取的所述激活应答消 息包含的所述移动网络运营商配置文件的状态;
所述发送单元,还用于在所述检查单元检查的所述激活应答消息 包含的所述移动网络运营商配置文件的状态是激活状态时发送管理 请求消息。
17、 一种通信终端, 其特征在于, 所述通信终端包括: 网络接口、 处理器及总线, 其中, 所述网络接口、 所述处理器通过所述总线相互 连接,
其中, 所述网络接口, 用于获取管理请求消息, 所述管理请求消 息包含发行方安全域配置文件标识;
所述处理器,用于在所述网络接口获取的所述配置请求消息包含 的所述发行方安全域配置文件标识对应的移动网络运营商配置文件 下管理子安全域, 所述子安全域用于存储第一业务的配置信息。
18、 根据权利要求 17所述的通信终端, 其特征在于, 所述管理 请求消息包括配置请求消息, 所述管理子安全域包括创建子安全域; 所述网络接口, 具体用于在所述第一业务新签约时, 获取配置请 求消息, 所述配置请求消息包含所述发行方安全域配置文件标识和所 述第一业务的配置信息, 所述第一业务的配置信息包含所述第一业务 的应用和数据;
所述处理器,具体用于在所述网络接口获取的所述配置请求消息 包含的所述发行方安全域配置文件标识对应的所述移动网络运营商 配置文件下创建子安全域, 并将所述第一业务的配置信息存储于所述 子安全域;
所述处理器, 还用于为所述处理器创建的所述子安全域分配标 识;
所述处理器,还用于根据所述处理器分配的所述子安全域的标识 管理所述子安全域。
19、 根据权利要求 18所述的通信终端, 其特征在于, 所述网络 接口, 还用于发送配置应答消息, 所述配置应答消息包含所述处理器 分配的所述子安全域的标识, 以便服务器根据所述配置应答消息管理 所述子安全域。
20、 根据权利要求 17所述的通信终端, 其特征在于, 所述管理 请求消息包括删除请求消息, 所述管理子安全域包括删除子安全域; 所述网络接口, 具体用于在所述第一业务终结时, 获取删除请求 消息, 所述删除请求消息包含所述发行方安全域配置文件标识和所述 子安全域的标识;
所述处理器,具体用于根据所述网络接口获取的所述删除请求消 息包含的所述发行方安全域配置文件标识和所述子安全域的标识, 删 除所述发行方安全域配置文件标识对应的所述移动网络运营商配置 文件中的所述子安全域。
21、 根据权利要求 20所述的通信终端, 其特征在于, 所述处理 器, 还用于根据所述网络接口获取的所述删除请求消息包含的所述发 行方安全域配置文件标识和所述子安全域的标识, 检测所述子安全域 中需要保存的应用和数据;
所述网络接口, 还用于发送保存请求消息, 所述保存请求消息包 含所述处理器检测的所述需要保存的应用和数据, 以便服务器根据所 述保存请求消息保存所述需要保存的应用和数据;
所述处理器, 具体用于在所述网络接口发送所述保存请求消息 后, 根据所述网络接口获取的所述发行方安全域配置文件标识和所述 子安全域的标识, 删除所述发行方安全域配置文件标识对应的所述移 用和数据。
22、 根据权利要求 20或 21所述的通信终端, 其特征在于, 所述 网络接口, 还用于在所述处理器删除所述子安全域后, 发送删除应答 消息, 所述删除应答消息包含子安全域删除成功状态信息和所述处理 器删除的所述子安全域的标识。
23、 根据权利要求 17-22任一项所述的通信终端, 其特征在于, 所述网络接口, 还用于获取激活请求消息;
所述网络接口,还用于根据所述网络接口获取的所述激活请求消 息获取用户指令;
所述处理器,还用于在所述网络接口获取的所述用户指令为激活 指令时, 将所述移动网络运营商配置文件的状态变更为激活状态; 所述网络接口, 还用于发送所述激活应答消息, 所述激活应答消 息包含所述处理器变更的所述移动网络运营商配置文件的状态。
24、 一种服务器, 其特征在于, 所述服务器包括: 网络接口、 处 理器及总线, 其中, 所述网络接口、 所述处理器通过所述总线相互连 接,
其中, 所述网络接口, 用于向签约管理安全路由发送查询请求消 息, 所述查询请求消息包含所述签约管理安全路由的标识和嵌入式集 成电路卡的标识;
所述网络接口 ,还用于获取所述签约管理安全路由发送的查询应 答消息, 所述查询应答消息包含移动网络运营商配置文件的发行方安 全域配置文件标识和所述移动网络运营商配置文件的状态;
所述处理器,用于检查所述网络接口获取的所述查询应答消息包 含的所述移动网络运营商配置文件的状态;
所述网络接口 ,还用于在所述处理器检查的所述查询应答消息包 含的所述移动网络运营商配置文件的状态是激活状态时发送管理请 求消息, 以便通信终端根据所述管理请求消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息。
25、 根据权利要求 24所述的服务器, 其特征在于, 所述管理请 求消息包括配置请求消息, 所述管理子安全域包括创建子安全域; 所述网络接口 ,还用于在所述处理器检查的所述查询应答消息包 含的所述移动网络运营商配置文件的状态是激活状态时发送管理请 求消息, 以便通信终端根据所述管理请求消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息, 具体包括:
在所述第一业务新签约并且所述处理器检查的所述查询应答消 息包含的所述移动网络运营商配置文件的状态是激活状态时发送配 置请求消息, 以便通信终端根据所述管理请求消息创建子安全域, 其 中, 所述配置请求消息包含所述发行方安全域配置文件标识和所述第 一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的应 用信息和数据。
26、 根据权利要求 25所述的服务器, 其特征在于, 所述网络接 口, 还用于获取配置应答消息, 所述配置应答消息包含子安全域的标 识;
所述处理器,还用于将所述网络接口获取的所述子安全域的标识 记录在所述发行方安全域配置文件标识对应的所述移动网络运营商 配置文件中。
27、 根据权利要求 26所述的服务器, 其特征在于, 所述网络接 口, 还用于在所述处理器将所述子安全域的标识记录在所述发行方安 全域配置文件标识对应的所述移动网络运营商配置文件中之后, 向所 述签约管理安全路由发送第一更新请求消息;
其中,所述第一更新请求消息中包含所述移动网络运营商配置文 件的配置信息, 以便所述签约管理安全路由按照所述第一更新请求消 息更新所述移动网络运营商配置文件的配置信息, 所述移动网络运营 商配置文件的配置信息包含移动网络运营商配置文件的类型、 版本和 子安全域信息。
28、 根据权利要求 24所述的服务器, 其特征在于, 所述管理请 求消息包括删除请求消息, 所述管理子安全域包括删除子安全域; 所述网络接口 ,还用于在所述第一业务终结时获取子安全域的标 识;
所述网络接口 ,还用于在所述处理器检查的所述查询应答消息包 含的所述移动网络运营商配置文件的状态是激活状态时发送管理请 求消息, 以便通信终端根据所述管理请求消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域配置文件标识, 所述子安全 域用于存储第一业务的配置信息, 具体包括: 在所述处理器检查的所述查询应答消息包含的所述移动网络运 营商配置文件的状态是激活状态时发送删除请求消息, 以便通信终端 根据所述管理请求消息删除子安全域, 其中, 所述删除请求消息包含 所述发行方安全域配置文件标识和所述子安全域的标识。
29、 根据权利要求 28所述的服务器, 其特征在于, 所述网络接 口, 还用于获取保存请求消息, 所述保存请求消息包含需要保存的应 用和数据;
所述服务器还包括: 存储器, 所述存储器通过所述总线与所述网 络接口、 所述处理器相互连接;
所述存储器,用于根据所述网络接口获取的所述保存请求消息保 存所述需要保存的应用和数据。
30、 根据权利要求 28或 29所述的服务器, 其特征在于, 所述网 络接口, 还用于获取删除应答消息, 所述删除应答消息包含子安全域 删除成功状态信息和被删除的子安全域的标识;
所述处理器,还用于根据所述网络接口获取的所述子安全域删除 成功状态信, ¾和所述被删除的子安全域的标识, 删除所述移动网络运 营商配置文件中的子安全域的标识。
3 1、 根据权利要求 30所述的服务器, 其特征在于, 所述网络接 口, 还用于在所述处理器删除了所述移动网络运营商配置文件中的子 安全域的标识之后, 向所述签约管理安全路由发送第二更新请求消 息;
其中,所述第二更新请求消息中包含被所述处理器删除了所述子 安全域的标识的所述移动网络运营商配置文件的配置信息, 以便所述 签约管理安全路由按照所述第二更新请求消息更新所述移动网络运 营商配置文件的配置信息。
32、 根据权利要求 24-3 1任一项所述的服务器, 其特征在于, 所 述网络接口, 还用于在所述处理器检查的所述查询应答消息包含的所 述移动网络运营商配置文件的状态是未激活状态时发送激活请求消 息; 所述网络接口, 还用于获取激活应答消息, 所述激活应答消息包 含所述移动网络运营商配置文件的状态;
所述处理器,还用于检查所述网络接口获取的所述激活应答消息 包含的所述移动网络运营商配置文件的状态;
所述网络接口,还用于在所述处理器检查的所述激活应答消息包 含的所述移动网络运营商配置文件的状态是激活状态时发送管理请 求消息。
33、 一种安全域管理方法, 其特征在于, 包括:
获取管理请求消息,所述管理请求消息包含发行方安全域配置文 件标识;
在所述发行方安全域配置文件标识对应的移动网络运营商配置 文件下管理子安全域, 所述子安全域用于存储所述第一业务的配置信 息。
34、 根据权利要求 33 所述的安全域管理方法, 其特征在于, 所 述管理请求消息包括配置请求消息, 所述管理子安全域包括创建子安 全域;
获取管理请求消息,所述管理请求消息包含发行方安全域配置文 件标识, 具体包括:
在所述第一业务新签约时获取配置请求消息,所述配置请求消息 包含所述移动网络运营商配置文件的发行方安全域配置文件标识和 所述第一业务的配置信息, 所述第一业务的配置信息包含所述第一业 务的应用和数据;
在所述发行方安全域配置文件标识对应的移动网络运营商配置 文件下管理子安全域, 所述子安全域用于存储所述第一业务的配置信 息, 具体包括:
在所述发行方安全域配置文件标识对应的所述移动网络运营商 配置文件下创建子安全域, 所述子安全域用于存储所述第一业务的配 置信息;
所述安全域管理方法还包括: 为所述子安全域分配标识;
根据所述子安全域的标识管理所述子安全域。
35、 根据权利要求 34所述的方法, 其特征在于, 为所述子安全 域分配标识之后, 所述安全域管理方法还包括:
发送配置应答消息, 所述配置应答消息包含所述子安全域的标 识, 以便服务器根据所述配置应答消息管理所述子安全域。
36、 根据权利要求 33 所述的方法, 其特征在于, 所述管理请求 消息包括删除请求消息, 所述管理子安全域包括删除子安全域; 获取管理请求消息,所述管理请求消息包含发行方安全域配置文 件标识, 具体包括:
在所述第一业务终结时获取删除请求消息,所述删除请求消息包 含所述发行方安全域配置文件标识和所述子安全域的标识;
在所述发行方安全域配置文件标识对应的移动网络运营商配置 文件下管理子安全域, 所述子安全域用于存储所述第一业务的配置信 息, 具体包括:
根据所述删除请求消息包含的所述发行方安全域配置文件标识 和所述子安全域的标识, 删除所述发行方安全域配置文件标识对应的 所述移动网络运营商配置文件中的所述子安全域。
37、 根据权利要求 36所述的方法, 其特征在于, 根据所述删除 请求消息包含的所述发行方安全域配置文件标识和所述子安全域的 标识, 删除所述发行方安全域配置文件标识对应的所述移动网络运营 商配置文件中的所述子安全域之前, 所述方法还包括:
根据所述删除请求消息包含的所述发行方安全域配置文件标识 和所述子安全域的标识, 检测所述子安全域中需要保存的应用和数 据;
发送保存请求消息,所述保存请求消息包含所述需要保存的应用 和数据, 以便服务器根据所述保存请求消息保存所述需要保存的应用 和数据;
根据所述删除请求消息包含的所述发行方安全域配置文件标识 和所述子安全域的标识, 删除所述发行方安全域配置文件标识对应的 所述移动网络运营商配置文件中的所述子安全域, 具体包括:
在发送所述保存请求消息后,根据所述删除请求消息包含的所述 发行方安全域配置文件标识和所述子安全域的标识, 删除所述发行方 安全域配置文件标识对应的所述移动网络运营商配置文件中的所述
38、 根据权利要求 36或 37所述的方法, 其特征在于, 所述方法 还包括:
在删除所述子安全域后, 发送删除应答消息, 所述删除应答消息 包含子安全域删除成功状态信息和所述子安全域的标识。
39、 根据权利要求 33 -38任一项所述的方法, 其特征在于, 获取 管理请求消息之前, 所述方法还包括:
获取激活请求消息;
根据所述激活请求消息获取用户指令;
在所述用户指令为激活指令时,将所述移动网络运营商配置文件 的状态变更为激活状态;
发送所述激活应答消息,所述激活应答消息包含所述移动网络运 营商配置文件的状态。
40、 一种安全域管理方法, 其特征在于, 包括:
向签约管理安全路由发送查询请求消息,所述查询请求消息包含 所述签约管理安全路由的标识和嵌入式集成电路卡的标识;
获取所述签约管理安全路由发送的查询应答消息,所述查询应答 消息包含移动网络运营商配置文件的发行方安全域配置文件标识和 所述移动网络运营商配置文件的状态;
检查所述查询应答消息包含的所述移动网络运营商配置文件的 状态;
在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送管理请求消息, 以便通信终端根据所述管理请求 消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域 配置文件标识, 所述子安全域用于存储第一业务的配置信息。
41、 根据权利要求 40所述的安全域管理方法, 其特征在于, 所 述管理请求消息包括配置请求消息, 所述管理子安全域包括创建子安 全域;
在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送管理请求消息, 以便通信终端根据所述管理请求 消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域 配置文件标识, 所述子安全域用于存储第一业务的配置信息, 具体包 括:
在所述第一业务新签约并且所述查询应答消息包含的所述移动 网络运营商配置文件的状态是激活状态时发送配置请求消息, 以便通 信终端根据所述管理请求消息管理子安全域, 其中, 所述配置请求消 息包含所述发行方安全域配置文件标识和所述第一业务的配置信息, 所述第一业务的配置信息包含所述第一业务的应用信息和数据。
42、 根据权利要求 41 所述的安全域管理方法, 其特征在于, 所 述方法包括:
获取配置应答消息, 所述配置应答消息包含子安全域的标识; 将所述子安全域的标识记录在所述发行方安全域配置文件标识 对应的所述移动网络运营商配置文件中。
43、 根据权利要求 42所述的安全域管理方法, 其特征在于, 将 所述子安全域的标识记录在所述发行方安全域配置文件标识对应的 所述移动网络运营商配置文件中之后, 所述方法还包括:
向所述签约管理安全路由发送第一更新请求消息;
其中,所述第一更新请求消息中包含所述移动网络运营商配置文 件的配置信息, 以便所述签约管理安全路由按照所述第一更新请求消 息更新所述移动网络运营商配置文件的配置信息, 所述移动网络运营 商配置文件的配置信息包含移动网络运营商配置文件的类型、 版本和 子安全域信息。
44、 根据权利要求 40所述的安全域管理方法, 其特征在于, 所 述管理请求消息包括删除请求消息, 所述管理子安全域包括删除子安 全域;
在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送管理请求消息, 以便通信终端根据所述管理请求 消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域 配置文件标识, 所述子安全域用于存储第一业务的配置信息之前, 所 述方法还包括:
在所述第一业务终结时获取子安全域的标识;
在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送管理请求消息, 以便通信终端根据所述管理请求 消息管理子安全域, 其中, 所述配置请求消息包含所述发行方安全域 配置文件标识, 所述子安全域用于存储第一业务的配置信息, 具体包 括:
在所述查询应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送删除请求消息, 以便通信终端根据所述管理请求 消息删除子安全域, 所述删除请求消息包含所述发行方安全域配置文 件标识和所述子安全域的标识。
45、 根据权利要求 44所述的方法, 其特征在于, 所述方法还包 括:
获取保存请求消息,所述保存请求消息包含需要保存的应用和数 据;
根据所述保存请求消息保存所述需要保存的应用和数据。
46、 根据权利要求 44或 45所述的方法, 其特征在于, 所述方法 还包括:
获取删除应答消息,所述删除应答消息包含子安全域删除成功状 态信 , 和被删除的子安全域的标识;
根据所述子安全域删除成功状态信息和所述被删除的子安全域 的标识, 删除所述移动网络运营商配置文件中的子安全域的标识。
47、 根据权利要求 46所述的方法, 其特征在于, 根据所述子安 全域删除成功状态信 , 和所述被删除的子安全域的标识,删除所述移 动网络运营商配置文件中的子安全域的标识之后, 所述方法还包括: 在删除了所述移动网络运营商配置文件中的子安全域的标识之 后, 向所述签约管理安全路由发送第二更新请求消息;
其中,所述第二更新请求消息中包含被删除了所述子安全域的标 识的所述移动网络运营商配置文件的配置信息, 以便所述签约管理安 全路由按照所述第二更新请求消息更新所述移动网络运营商配置文 件的配置信息。
48、 根据权利要求 40-47所述的方法, 其特征在于, 获取管理应 答消息之前, 所述方法还包括:
如果所述查询应答消息包含的所述移动网络运营商配置文件的 状态是未激活状态, 则发送激活请求消息;
获取激活应答消息,所述激活应答消息包含所述移动网络运营商 配置文件的状态;
检查所述激活应答消息包含的所述移动网络运营商配置文件的 状态;
在所述激活应答消息包含的所述移动网络运营商配置文件的状 态是激活状态时发送删除请求消 , 。
PCT/CN2014/084307 2014-08-13 2014-08-13 一种安全域管理方法、装置及*** WO2016023199A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
EP14899640.8A EP3171566B1 (en) 2014-08-13 2014-08-13 Method, device and system for security domain management
CN201480075787.6A CN106031119B (zh) 2014-08-13 2014-08-13 一种安全域管理方法、装置及***
US15/503,317 US10270811B2 (en) 2014-08-13 2014-08-13 Security domain management method, apparatus, and system
PCT/CN2014/084307 WO2016023199A1 (zh) 2014-08-13 2014-08-13 一种安全域管理方法、装置及***

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2014/084307 WO2016023199A1 (zh) 2014-08-13 2014-08-13 一种安全域管理方法、装置及***

Publications (1)

Publication Number Publication Date
WO2016023199A1 true WO2016023199A1 (zh) 2016-02-18

Family

ID=55303801

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/084307 WO2016023199A1 (zh) 2014-08-13 2014-08-13 一种安全域管理方法、装置及***

Country Status (4)

Country Link
US (1) US10270811B2 (zh)
EP (1) EP3171566B1 (zh)
CN (1) CN106031119B (zh)
WO (1) WO2016023199A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111417109A (zh) * 2020-03-17 2020-07-14 江苏恒宝智能***技术有限公司 一种eSIM卡及其运营商文件管理方法和管理***
US11057760B2 (en) 2016-06-23 2021-07-06 Telefonaktiebolaget Lm Ericsson (Publ) Methods and entities for ending a subscription
WO2023216035A1 (zh) * 2022-05-07 2023-11-16 Oppo广东移动通信有限公司 安全域管理方法、装置、设备、存储介质及程序产品

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE102015012943A1 (de) * 2015-10-07 2017-04-13 Giesecke & Devrient Gmbh Verwalten eines Subskriptions-Profils
KR102545897B1 (ko) 2015-12-22 2023-06-22 삼성전자 주식회사 프로파일 제공 방법 및 장치
US10346147B2 (en) * 2015-12-22 2019-07-09 Samsung Electronics Co., Ltd. Method and apparatus for providing a profile
US10887102B2 (en) * 2016-12-15 2021-01-05 Nutanix, Inc. Intent framework
CN109474650B (zh) * 2017-09-08 2021-04-20 ***通信有限公司研究院 一种配置文件下载方法及终端
US10891384B2 (en) * 2017-10-19 2021-01-12 Koninklijke Kpn N.V. Blockchain transaction device and method
CN111191213B (zh) * 2018-11-14 2023-11-10 华为终端有限公司 一种删除安全业务的方法及电子设备
WO2021142849A1 (zh) * 2020-01-19 2021-07-22 Oppo广东移动通信有限公司 安全域的配置、发现和加入方法及装置、电子设备
CN113490211B (zh) * 2021-06-17 2023-03-24 中国联合网络通信集团有限公司 一种辅助安全域的创建方法、sm-sr及***

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102668501A (zh) * 2009-10-15 2012-09-12 交互数字专利控股公司 用于接入基于订阅的服务的注册和凭证转出
FR2994622A1 (fr) * 2012-08-20 2014-02-21 France Telecom Procede d'activation d'un nouveau profil dans un element de securite
CN103605939A (zh) * 2013-12-04 2014-02-26 东信和平科技股份有限公司 金融ic卡的个人化数据写入方法、装置及***

Family Cites Families (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6772157B2 (en) * 2000-10-19 2004-08-03 General Electric Company Delegated administration of information in a database directory
US6782379B2 (en) * 2000-12-22 2004-08-24 Oblix, Inc. Preparing output XML based on selected programs and XML templates
US7185359B2 (en) * 2001-12-21 2007-02-27 Microsoft Corporation Authentication and authorization across autonomous network systems
US7469417B2 (en) * 2003-06-17 2008-12-23 Electronic Data Systems Corporation Infrastructure method and system for authenticated dynamic security domain boundary extension
US7680935B2 (en) * 2004-09-30 2010-03-16 Microsoft Corporation Entity domains
US8930331B2 (en) * 2007-02-21 2015-01-06 Palantir Technologies Providing unique views of data based on changes or rules
CN101370248B (zh) * 2007-08-15 2011-12-07 ***通信集团公司 密钥更新方法、第三方服务器及激活第三方应用的***
AR073125A1 (es) * 2008-08-25 2010-10-13 Interdigital Patent Holdings Tarjeta de circuito integrada universal que tiene una funcion de modulo de identificacion virtual de usuario.
US9131008B2 (en) 2008-09-30 2015-09-08 Lenovo Enterprise Solutions (Singapore) Pte. Ltd. Discovery profile based unified credential processing for disparate security domains
EP2630764A1 (en) * 2010-10-20 2013-08-28 Markus Lobmaier Secure element for mobile network services
CN102118385A (zh) * 2010-12-14 2011-07-06 北京握奇数据***有限公司 安全域的管理方法和装置
US8881236B2 (en) 2011-02-04 2014-11-04 Futurewei Technologies, Inc. Method and apparatus for a control plane to manage domain-based security and mobility in an information centric network
KR20130012243A (ko) * 2011-07-08 2013-02-01 주식회사 케이티 특수 권한 기반의 내장 sim의 mno 변경방법 및 그를 위한 내장 sim과 기록매체
US9578014B2 (en) * 2011-09-29 2017-02-21 Oracle International Corporation Service profile-specific token attributes and resource server token attribute overriding
KR101903061B1 (ko) * 2011-11-01 2018-10-01 구글 엘엘씨 다수의 서비스 제공자 신뢰된 서비스 관리자 및 보안 요소와 인터페이싱하기 위한 시스템, 방법 및 컴퓨터 프로그램 제품
KR101716743B1 (ko) 2012-02-14 2017-03-15 애플 인크. 복수의 액세스 제어 클라이언트를 지원하는 모바일 장치, 및 대응 방법들
US8959331B2 (en) * 2012-11-19 2015-02-17 At&T Intellectual Property I, Lp Systems for provisioning universal integrated circuit cards
US20140189880A1 (en) * 2012-12-31 2014-07-03 Gemalto Sa System and method for administrating access control rules on a secure element
US9713006B2 (en) * 2014-05-01 2017-07-18 At&T Intellectual Property I, Lp Apparatus and method for managing security domains for a universal integrated circuit card
US10164953B2 (en) * 2014-10-06 2018-12-25 Stmicroelectronics, Inc. Client accessible secure area in a mobile device security module
KR102331695B1 (ko) * 2014-10-27 2021-11-26 삼성전자 주식회사 식별 모듈을 활용한 프로파일 변경 방법 및 이를 구현한 전자장치

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102668501A (zh) * 2009-10-15 2012-09-12 交互数字专利控股公司 用于接入基于订阅的服务的注册和凭证转出
FR2994622A1 (fr) * 2012-08-20 2014-02-21 France Telecom Procede d'activation d'un nouveau profil dans un element de securite
CN103605939A (zh) * 2013-12-04 2014-02-26 东信和平科技股份有限公司 金融ic卡的个人化数据写入方法、装置及***

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3171566A4 *

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11057760B2 (en) 2016-06-23 2021-07-06 Telefonaktiebolaget Lm Ericsson (Publ) Methods and entities for ending a subscription
EP3476142B1 (en) * 2016-06-23 2023-04-26 Telefonaktiebolaget LM Ericsson (PUBL) Methods and entities for ending a subscription
US11963260B2 (en) 2016-06-23 2024-04-16 Telefonaktiebolaget Lm Ericsson (Publ) Methods and entities for ending a subscription
CN111417109A (zh) * 2020-03-17 2020-07-14 江苏恒宝智能***技术有限公司 一种eSIM卡及其运营商文件管理方法和管理***
CN111417109B (zh) * 2020-03-17 2023-05-23 恒宝股份有限公司 一种eSIM卡及其运营商文件管理方法和管理***
WO2023216035A1 (zh) * 2022-05-07 2023-11-16 Oppo广东移动通信有限公司 安全域管理方法、装置、设备、存储介质及程序产品

Also Published As

Publication number Publication date
US10270811B2 (en) 2019-04-23
EP3171566B1 (en) 2019-10-09
EP3171566A1 (en) 2017-05-24
CN106031119B (zh) 2019-06-21
US20180054463A1 (en) 2018-02-22
CN106031119A (zh) 2016-10-12
EP3171566A4 (en) 2017-06-14

Similar Documents

Publication Publication Date Title
WO2016023199A1 (zh) 一种安全域管理方法、装置及***
US11617073B2 (en) Method enabling migration of a subscription
JP6370912B2 (ja) ユーザデータを送信及び受信するための方法及び端末デバイス
CN111480350B (zh) 嵌入式sim卡的数据访问的方法和设备
CN106162517B (zh) 一种虚拟sim卡的管理方法及***
US9603189B2 (en) Method and apparatus for multisim devices with embedded SIM functionality
WO2016045478A1 (zh) Sim卡读写方法及终端
WO2015021875A1 (zh) 应用的托管方法及***、移动终端、服务器
US20200053534A1 (en) Electronic device, external electronic device, and method of managing embedded subscriber identity modules of external electronic device
JP6923582B2 (ja) 情報処理装置、情報処理方法、およびプログラム
US20220117008A1 (en) Just in time connection configuration stored in sim profile
US20210044961A1 (en) Electronic device for managing embedded subscriber identification module and method for same
KR102538663B1 (ko) 전자 장치, 외부 전자 장치 및 외부 전자 장치의 eSIM 관리 방법
CN102510391B (zh) 应用管理方法、装置及智能卡
JP2015043231A (ja) データ保護方法、回路カード、及び移動無線通信装置
US8326933B2 (en) Appearance package management method, system and device
CN105025482A (zh) 一种通信信息处理方法及其设备
US20230336970A1 (en) Electronic device performing verification using embedded sim and operating method therefor
CN107040904A (zh) 控制短信息的菜单项显示撤回的方法和装置
CN106685889B (zh) 基于用户身份的业务实现方法和装置
CN115835179A (zh) 一种增值业务权益终端间迁移方法和***
CN112702728A (zh) 用户配置文件下载方法、管理方法、装置、智能卡及介质
JP2016035686A (ja) サービスアプリケーション発行装置、インストーラ、サービスアプリケーション発行システム、サービスアプリケーション発行方法及びインストール方法
JP2016012779A (ja) サービスアプリケーション発行装置、サービスアプリケーション発行方法及びサービスアプリケーション発行システム

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14899640

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 15503317

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

REEP Request for entry into the european phase

Ref document number: 2014899640

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2014899640

Country of ref document: EP