R-UIM mode work normally, is commonly known as CDMA direct plug-in card. We know that water products can not be directly inserted into the CDMA card, since the release of the telecommunications industry, compare it with the water products in the R-UIM model, can help us find out the direction of the problem, to find an accurate solution.
There is a post from the prompt to insert the uimcard or SIM card angle for comparison, but this is only a problem of interface display, in fact, whether the R-UIM works depends on the underlying SFI file and Its configuration data. Therefore, it is necessary to conduct a more accurate comparison test. So what aspects should we compare to find the answer to the question? Whether the Ruim mode actually works can be determined at three levels.
The first layer is whether the iccid can be correctly read. This layer is mainly subject to the operating voltage, frequency, and clock enabling mode of the card. This layer depends mainly on the card. It helps us find a compatible card, which is useless.
The second layer is whether the imsi data in the card can be correctly read and replaced with the imsi data of the fuselage. In the hand-compiled data, we can view the results. If your licensed mobile phone clicks the sprint Rom downloaded from the official website, you can use the imsi to replace the fuselage imsi. This proves that the RoM does not set any obstacles on this layer, but is completely controlled by the configuration data. In the test, you can flash the machine in two steps. The first step is to use CFP-u load XXXX on the licensed machine with the licensed Rom installed. SFI fl, where XXXX. SFI is the corresponding file in sprint Rom. Then, check whether imsi is replaced by data in the card. Step 2 Use javaloader or other tools to fl all the cod files of the sprint Rom. Then, check whether imsi is replaced by the data in the card. In this way, you can accurately exclude or prove that Rom has set obstacles at this layer. If you have set obstacles, you can determine whether it is in SFI or cod.
The third layer is whether the TIA-95B authentication command can be correctly issued to the card. If the digits digit of the 0x88 command is called as the last 6 digits, it is correct. This test must monitor the communication between the mobile phone and the uimcard. If there is no condition, you can call out a phone number in the area not closed for authentication. It is correct to make a call. During the test, only a few phone calls are not allowed. The call should be made at intervals of over 30 seconds, because the fault tolerance settings in some regions are relatively plentiful, and one or more phone calls that fail to be authenticated are allowed. Like the second layer, by flushing the sprint ROM and dialing out the phone in the second step on the line, you can determine that the authentication command in R-UIM mode is controlled by the configuration data, there is still SFI or cod to control.
If the test result is controlled by the configuration data, you need to rewrite the configuration data. Common configuration data includes Qualcomm NV data and blackberry VSM files. If you get the licensed VSM file, you can use vsmtools to analyze the content. If you find an id like flag_ruim or a suspicious unknown ID, it is likely to be controlled independently. 9530 it is easier to rewrite the configuration data. 9630 currently, no public software tools are available to switch out or write configuration data. However, there is no way at all. There are at least two ways to import the configuration data of the goods to the goods. One is to remove the licensed flash chip and copy a flash chip that replaces the commodities. The other is to use the JTAG to read the flash of the goods online and then write the flash of the goods. If you can accurately locate the position of the configuration switch, it will be easier to directly rewrite it with JTAG. JTAG pin definitions can be provided by Qualcomm datasheet or by skilled maintenance personnel through measurement.