基于GlobalPlatform SIM卡的OTA Load命令SMS传输故障排查
Let's break down your issue and walk through the most likely causes and actionable fixes:
Core Issue Recap
You've confirmed critical working paths:
Install_for_loadsucceeds over SMS- USB-based app loading + SMS
Install_for_installworks perfectly - SMS-based app deletion functions as expected
The failure point is your first Load command, which returns an RP-ERROR (TP-FCS 0xd5: (U)SIM data download error) with TP-User-Data 00:60:00. Let's unpack that response first:
- The
6000is a GlobalPlatform status code meaning "Command completed successfully"—this contradiction suggests either a truncated SIM response (the full status got cut off mid-transmission) or misinterpretation by Osmo-NITB. The leading00is an invalid length indicator, pointing directly to a problem with the incoming Load command's structure or size.
Likely Root Causes & Fixes
1. Load Command Exceeds GSM SMS TP-UD Length Limit
GSM SMS with 8-bit encoding (data_coding=0xF6) has a hard maximum TP-UD length of 140 bytes. Your first Load command's TP-UD (including the leading length byte 02 and full GP APDU) totals 146 bytes—way over this limit. Even with concatenated SMS, each chunk's TP-UD (including concat metadata in the UDHI) can't exceed 140 bytes.
Fix:
- Adjust the load block size in
shadysim.pyto fit within the limit. For concatenated SMS, reserve ~4 bytes for the concat UDHI (IEI 0x00, length 0x03, reference number, total blocks, block number), leaving ~135 bytes for the actual GP Load command data. - Use
shadysim.py's--load-block-sizeparameter (if available) to set a smaller block size (e.g., 128 bytes) to ensure each Load command's TP-UD stays within valid bounds.
2. Missing/Incorrect Concatenated SMS UDHI
You set esm_class=0x40 (which enables UDHI), but if shadysim.py isn't generating the required concat metadata in the UDHI, the SIM won't recognize fragmented Load commands as part of a single sequence.
Fix:
- Verify the Load command's UDHI in your abis interface capture. A valid concat UDHI looks like:
00 03 RR TT NN(whereRRis a unique reference number,TTis total blocks,NNis current block number). - If
shadysim.pyisn't adding this metadata, modify the script to include it or use an SMPP client that automatically appends correct concat UDHI for multi-part SMS.
3. Load Command Block Numbering or Encryption Mismatch
While USB loading works, SMS OTA uses distinct encryption keys and requires strict block sequencing:
- Key Usage:
Install_for_loadusesKic, but Load commands must useKid. Ensureshadysim.pyencrypts Load commands with the correctKidkey. - Block Sequencing: Load blocks must be sent in order, starting from block 1, with no gaps. Check that your Load command sequence has correctly incrementing block numbers (look for the 2-byte block number field after the
0x15load block tag in the GP APDU data section).
4. Osmo-NITB SMSC Configuration Quirks
Double-check your SMSC settings to ensure it handles concatenated 8-bit SMS correctly:
- Confirm
allow-concat-smsis enabled in your Osmo-NITB config. - Verify that SMPP parameters (
data_coding=0xF6,protocol_id=0x7F,esm_class=0x40) are correctly propagated to outgoing SMS in your abis capture. If any parameter is missing or altered, the SIM will reject the command.
Additional Debugging Steps
- Capture the full Load command SMS from the abis interface and verify its total length. If it's over 140 bytes, this is definitively the issue.
- Test sending a manually truncated Load command (within the 140-byte limit) to confirm if length is the primary problem.
内容的提问来源于stack exchange,提问作者PavelS

