WO2014206192A1 - 一种指示移动设备操作环境的方法和能够指示操作环境的移动设备 - Google Patents

一种指示移动设备操作环境的方法和能够指示操作环境的移动设备 Download PDF

Info

Publication number
WO2014206192A1
WO2014206192A1 PCT/CN2014/079328 CN2014079328W WO2014206192A1 WO 2014206192 A1 WO2014206192 A1 WO 2014206192A1 CN 2014079328 W CN2014079328 W CN 2014079328W WO 2014206192 A1 WO2014206192 A1 WO 2014206192A1
Authority
WO
WIPO (PCT)
Prior art keywords
application
mobile device
level
operating system
personalized information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2014/079328
Other languages
English (en)
French (fr)
Inventor
柴洪峰
鲁志军
何朔
郭伟
周钰
陈成钱
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Priority to EP14818064.9A priority Critical patent/EP3016015B1/en
Priority to US14/896,826 priority patent/US20160140342A1/en
Publication of WO2014206192A1 publication Critical patent/WO2014206192A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/74Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information operating in dual or compartmented mode, i.e. at least one secure mode
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • G06F21/84Protecting input, output or interconnection devices output devices, e.g. displays or monitors
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/03Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
    • G06F2221/034Test or assess a computer or a system

Definitions

  • the present invention relates to mobile device security, and more particularly to a method of indicating a mobile device operating environment and a mobile device capable of indicating an operating environment.
  • users may also leak user information by downloading and installing malicious programs (for example, Trojans, viruses).
  • malicious programs for example, Trojans, viruses.
  • the human interface of a mobile device eg, a smartphone
  • a screen, keyboard, etc. is the most important way for a user to interact with an application within a mobile device. Therefore, when users enter information using the display unit (for example, private information such as bank card accounts and passwords), this information may be obtained by malicious programs.
  • a secure operating system is a closed operating system that runs in secure mode, which provides a trusted execution environment for mobile devices and is independent of the operating system in non-secure mode.
  • the secure operating system can be, for example, a TEE solution based on ARM's Trust Zone technology.
  • TEE is a trusted execution environment platform in a secure mode where malicious programs cannot access data resources in the secure mode or steal data resources, such as user information, under the control of security code. For example, for a human machine interface, when in the mobile device security mode, the human machine interface is only operated in the security system, so the user can safely interact with the application through the human machine interface. In other words, in safe mode, the man-machine interface is credible.
  • the screen of a mobile device can be accessed and used as a public interface by all programs on the mobile device, and although the reliability of the screen can be guaranteed under the control of a secure operating system, security is still challenged.
  • a malicious program can emulate an operating environment under a secure operating system to confuse users and steal user information. Therefore, in order to further increase the security of the mobile device, a solution indicating the operating environment is required to prompt the user to operate the current mobile device, including whether the mobile device is currently in a secure mode, that is, whether the currently running operating system is a secure operating system. (For example, use reliable instructions to inform the user that the human-machine interface that is currently operating is indeed trusted).
  • the dynamic use of the application can also pose a potential threat to the user's information, and therefore the operating environment indicating that the user is currently mobile can preferably also indicate the level of security of the application currently being operated by the mobile device.
  • a method of indicating a mobile device operating environment comprising the steps of: generating personalized information, and storing the personalized information in a storage area accessible only by a secure operating system,
  • the personalized information is displayed in the display area of the mobile device to indicate to the user the currently running operating system.
  • the method further comprises the following steps:
  • the personalized information is generated based on user input, including text, images, or a combination of text and images.
  • the method further comprises the following steps:
  • the personalized information is generated when the mobile device is first launched.
  • the method further comprises the following steps:
  • the final trusted level of the currently operating application is further displayed in the display area of the mobile device to indicate to the user the security of the currently operating application.
  • the final trusted level of the application is generated based on the application trusted level and the carrier trusted level of the application, wherein the application trusted level is based on whether the application passes the authentication and/or application of the secure operating system.
  • the carrier wherein the carrier is a physical security carrier or a virtual security carrier, and the trusted level of the applied carrier is based on whether the carrier passes the authentication of the secure operating system.
  • the method further comprises the following steps:
  • a mobile device capable of indicating an operating environment
  • the mobile device comprising:
  • a personalized information module for generating personalized information and storing the personalized information in a storage area that can only be accessed by an indicator module in the secure operating system.
  • an indicator module configured to display the personalized information in the display area of the mobile device when the mobile device enters the security operating system to indicate to the user the currently running operating system.
  • the personalized information module generates the personalized information based on a user's input, the personalized information including a text, an image, or a combination of text and images.
  • the personalized information module generates the personalized message when the mobile device is started for the first time [0015]
  • the indicator module further displays the final trusted level of the currently operated application in the display area of the mobile device to indicate to the user the security of the currently operated application. .
  • the final trusted level of the application is generated based on the application trusted level and the carrier trusted level of the application, wherein
  • the application credibility level is based on whether the application passes the authentication and/or application of the secure operating system, wherein the carrier is a physical security carrier or a virtual security carrier.
  • the trusted level of the carrier of the application is based on whether the carrier is authenticated by the secure operating system.
  • the indicator module is further configured to store, in the trusted level list, the application trusted level, the application trusted level, and the application identifier.
  • the indicator module is configured to obtain a final level of trust for the current application based on the list of trusted levels.
  • FIG. 1 is a schematic diagram of a method of indicating a mobile device operating environment, in accordance with an embodiment of the present invention.
  • FIG. 2 is a schematic diagram of a mobile device capable of indicating an operating environment, in accordance with an embodiment of the present invention.
  • FIG. 1 is a schematic diagram of a method of indicating a mobile device operating environment, in accordance with an embodiment of the present invention. As shown in FIG. 1, the method for indicating the operating environment of the mobile device includes the following steps:
  • the first step Generate personalized information and store the personalized information in a storage area that can only be accessed by a secure operating system.
  • the second step when the mobile device enters the security operating system, the personalized information is displayed in the display area of the mobile device to indicate to the user the currently running operating system.
  • the personalized information in the storage area can only be accessed by the indicator module of the secure operating system. Q, this prevents malicious programs from getting personalized information.
  • the personalized information may be generated based on user input, the textual information including text, images, or a combination of text and images.
  • Personalized information is user-generated and unique, thus preventing malicious programs in non-secure mode from spoofing this information to trick users.
  • these personalized information may be graphics edited by the user, selected patterns, captured images, entered text (e.g., user favorite food, favorite animal).
  • the personalized information is generated when the mobile device is first launched.
  • the mobile device is trusted and secure because it has not been used yet, which ensures the security of the personalized personal information entered.
  • the display area may be a specific area set on a screen of a mobile device.
  • the final trusted level of the currently operating application is further displayed in the display area of the mobile device to indicate to the user the security of the currently operating application.
  • personalized information can be displayed on the left side of the display area, and the final trusted level of the application can be displayed on the right side of the display area.
  • the final trusted level of the application indicates the tamper resistance, anti-leakage, anti-counterfeiting, and anti-attack capabilities of the application. In this way, the user knows the security of the currently operating application, allowing the user to be vigilant when faced with a low-trust level application, and further confirm whether the application to be operated is the application of his or her choice.
  • the final level of trust of the application is generated based on the application trust level and the carrier trust level of the application.
  • the application credibility level is based on whether the application passes the authentication and/or application of the secure operating system, wherein the bearer is a physical security bearer or a virtual secure bearer. For example, for the same application, if the application is on a physical security carrier, it has a higher level of trust than the application in the virtual security carrier. This is because the physical security carrier also includes independent hardware, and such independent hardware is highly secure against physical attacks.
  • the specific classification mode of the application credential level may be divided according to the actual situation. As an example, the credibility level of the application may be classified into three levels: low, medium, and high, where the security carrier (SIM card, smart card, etc.) is located.
  • the application that has been authenticated by the secure operating system is a high-trust level, and the application that passes the secure operating system authentication on the virtual secure element (VSE) is a medium-trusted level, for those that are not compatible with the secure operating system.
  • the application for authentication is a low level of trust.
  • the trusted level of the applied carrier is based on whether the carrier passes the authentication of the secure operating system.
  • the present invention can be combined with the application trust level (the credibility of the application itself) and the carrier trust level of the application.
  • the actual trust level of the application ie the final trusted level of the application. For example, when a high-trust level application is running in a low-trust level environment, the actual trust level of the application can be Determined to be a medium trust level.
  • the application trusted level, the application trusted level, and the application identifier may be stored in a trusted level list, and when an application is selected to be started as the current application, according to the A list of trusted levels to obtain the final level of trust for the current application.
  • the final trusted level display of the current application may take the form of text (eg, the text "High” in the display area may represent a high level of trust, the "Medium” representative of a level of trust, and "Low” a low level of trust. ), image display, etc., can also be expressed by color.
  • the mobile device includes a personalized information module and an indicator module.
  • the personalization information module is configured to generate personalized information and store the personalized information in a storage area that can only be accessed by an indicator module in the secure operating system.
  • an indicator module configured to display the personalized information in the display area of the mobile device when the mobile device enters the secure operating system to indicate to the user the currently running operating system.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Mathematical Physics (AREA)
  • Telephone Function (AREA)
  • Storage Device Security (AREA)
  • User Interface Of Digital Computer (AREA)

Abstract

本发明公开一种指示移动设备操作环境的方法和能够指示操作环境的移动设备。该方法包括以下步骤:生成个人化信息,并将该个人化信息存储在仅能由安全操作系统访问的存储区,当该移动设备进入该安全操作系统运行时,在移动设备的显示区域显示个所述人化信息,以向用户指示当前运行的操作系统。

Description

一种指示移动设备操作环境的方法和能够指示操作环境的移 动设备 技术领域
[0001] 本发明涉及移动设备安全性, 并且尤其涉及指示移动设备操作环境的方法和能够指 示操作环境的移动设备。
背景技术
[0002] 当前移动设备的操作系统由于强大的功能, 复杂的代码和开放的平台, 会产生操作 系统漏洞, 这些漏洞会对操作系统的安全构成威胁。
[0003] 另一方面, 用户也可能因下载安装恶意程序 (例如, 木马、 病毒) 而泄漏用户信 息。 移动设备 (例如, 智能手机) 的人机界面 (诸如屏幕、 键盘等) 是用户与移动设备内的 应用进行交互的最重要途径。 因此, 用户在使用人机界面输入信息时 (例如, 银行卡账户和 密码等私密信息), 这些信息可能被恶意程序所获取。
[0004] 现有技术中, 通过运行安全操作系统来防止恶意程序对私密信息的窃取和篡改。 安 全操作系统指运行在安全模式下的一个封闭式操作系统, 其为移动设备提供可信执行环境, 并且独立于非安全模式下操作系统。 安全操作系统例如可以是基于 ARM公司的 Trust Zone 技术的 TEE方案。 TEE 是一种安全模式下的可信执行环境平台, 在该平台上, 在安全代码 的控制之下, 恶意程序无法访问该安全模式下的数据资源的或窃取数据资源, 例如用户信 息。 例如, 对人机界面来说, 当处于移动设备安全模式时, 该人机界面只被在安全系统操 控, 因此用户能够安全地通过该人机界面与应用交互。 换句话说, 在安全模式下, 该人机界 面是可信的。
[0005] 移动设备的屏幕作为一种公共接口可以被移动设备上所有程序进行访问和使用, 虽 然在安全操作系统控制下可以保证该屏幕的可靠性, 安全性仍然会受到挑战。 例如, 恶意程 序可以模拟安全操作系统下的操作环境来迷惑用户从而窃取用户信息。 因此, 为进一步增加 移动设备使用的安全性, 需要一种指示操作环境的方案来提示用户当前移动设备的操作环 境, 包括移动设备当前是否处于安全模式, 即当前运行的操作系统是否为安全操作系统 (例 如, 利用可靠的指示信息来告知用户当前正在操作的人机界面确实可信)。 另外, 由于存在 可插拔的载体, 应用动态使用也会对用户的信息构成潜在的威胁, 因此, 指示用户当前移动 设备的操作环境优选地还可以指示移动设备当前操作的应用的安全程度。
发明内容 [0006] 根据本发明的一个目的, 公开一种指示移动设备操作环境的方法, 包括以下步骤: 生成个人化信息, 并将该个人化信息存储在仅能由安全操作系统访问的存储区,
当该移动设备进入该安全操作系统运行时, 在移动设备的显示区域显示个所述人化信息, 以 向用户指示当前运行的操作系统。
[0007] 优选地, 该方法还包括以下步骤:
基于用户的输入来生成所述个人化信息, 所述个人化信息包括文字、 图像或者文字和图像的 组合。
[0008] 优选地, 该方法还包括以下步骤:
在所述移动设备第一次被启动时生成所述个人化信息。
[0009] 优选地, 该方法还包括以下步骤:
当该移动设备运行在安全操作系统时, 在移动设备的显示区域进一步显示当前操作的应用的 最终可信等级, 以向用户指示当前操作的应用的安全性。
[0010] 优选地, 应用的最终可信等级基于应用可信等级和应用的载体可信等级生成, 其 中, 所述应用可信等级基于应用是否经过所述安全操作系统的认证和 /或应用的载体, 其 中, 所述载体是物理安全载体或者虚拟安全载体, 所述应用的载体的可信等级基于该载体是 否经过所述安全操作系统的认证。
[0011] 优选地, 该方法还包括以下步骤:
将所述应用可信等级、 所述应用的载体可信等级、 应用标识存储在可信等级列表中, 当一个应用被选择启动作为当前应用时, 根据该可信等级列表来获得当前应用的最终可信等 级。
[0012] 根据本发明的另一个目的, 公开一种能够指示操作环境的移动设备, 该移动设备包 括:
个人化信息模块, 用于生成个人化信息, 并将该个人化信息存储在仅能由安全操作系统中的 指示器模块访问的存储区,
指示器模块, 用于当该移动设备进入该安全操作系统运行时, 在移动设备的显示区域显示个 所述人化信息, 以向用户指示当前运行的操作系统。
[0013] 优选地, 所述个人化信息模块基于用户的输入来生成所述个人化信息, 所述个人化 信息包括文字、 图像或者文字和图像的组合。
[0014] 优选地, 所述个人化信息模块在所述移动设备第一次被启动时生成所述个人化信 [0015] 优选地, 当该移动设备运行在安全操作系统时, 该指示器模块在移动设备的显示区 域进一步显示当前操作的应用的最终可信等级, 以向用户指示当前操作的应用的安全性。
[0016] 优选地, 应用的最终可信等级基于应用可信等级和应用的载体可信等级生成, 其 中,
所述应用可信等级基于应用是否经过所述安全操作系统的认证和 /或应用的载体, 其中, 所 述载体是物理安全载体或者虚拟安全载体,
所述应用的载体的可信等级基于该载体是否经过所述安全操作系统的认证。
[0017] 优选地, 该指示器模块还用于将所述应用可信等级、 所述应用的载体可信等级、 应 用标识存储在可信等级列表中,
当一个应用被选择启动作为当前应用时, 该指示器模块被配置成根据该可信等级列表来获得 当前应用的最终可信等级。
附图说明
[0018] 在参照附图阅读了本发明的具体实施方式以后, 本领域技术人员将会更清楚地了解 本发明的各个方面。 本领域技术人员应当理解的是, 这些附图仅仅用于配合具体实施方式说 明本发明的技术方案, 而并非意在对本发明的保护范围构成限制。 其中,
图 1是根据本发明实施例的指示移动设备操作环境的方法的示意图。
[0019] 图 2是根据本发明实施例的能够指示操作环境的移动设备的示意图。
具体实施方式
[0020] 下面参照附图, 对本发明的具体实施方式作进一步的详细描述。 在下面的描述中, 为了解释的目的, 陈述许多具体细节以便提供对实施例的一个或多个方面的透彻理解。 然 而, 对于本领域技术人员可以显而易见的是, 可以这些具体细节的较少程度来实践各实施例 的一个或多个方面。 因此下面的描述不被视为局限性的, 而是通过所附权利要求来限定保护 范围。
[0021] 图 1 是根据本发明实施例的指示移动设备操作环境的方法的示意图。 如图 1 所示, 指示移动设备操作环境的方法包括以下步骤:
第一个步骤: 生成个人化信息, 并将该个人化信息存储在仅能由安全操作系统访问的存储 区。
[0022] 第二个步骤: 当该移动设备进入该安全操作系统运行时, 在移动设备的显示区域显 示个所述人化信息, 以向用户指示当前运行的操作系统。
[0023] 在一个实施例中, 存储区中的个人化信息仅仅能由安全操作系统的指示器模块访 问, 如此能够防止恶意程序获取个人化信息。
[0024] 在一个实施例中, 可以基于用户的输入来生成所述个人化信息, 所述个人化信息包 括文字、 图像或者文字和图像的组合。 个人化信息通过用户生成, 具有特有性, 因而能够防 止非安全模式下的恶意程序仿冒这些信息来欺骗用户。 作为示例, 这些个人化信息可以是由 用户编辑的图形、 选择的图案、 拍摄的图像、 输入的文字 (例如, 用户最爱的食物, 最喜欢 的动物)。
[0025] 在一个实施例中, 在所述移动设备第一次被启动时生成所述个人化信息。 在移动设 备第一次启动时, 由于移动设备尚未被使用, 因此是可信的、 安全的, 这能够保证输入的个 人化信息的安全性。
[0026] 在一个实施例中, 所述显示区域可以是在移动设备屏幕上设置的特定区域。
[0027] 在一个实施例中, 当该移动设备运行在安全操作系统时, 在移动设备的显示区域进 一步显示当前操作的应用的最终可信等级, 以向用户指示当前操作的应用的安全性。 例如, 可以在显示区域的左边显示个人化信息, 在显示区域的右边显示应用的最终可信等级。 应用 的最终可信等级表示该应用防篡改、 防泄密、 防仿冒、 防攻击的能力。 这样, 用户就知道当 前操作的应用的安全性, 让用户在面对低可信等级的应用时, 提高警惕, 并进一步确认要操 作的应用是否是自己所要的应用。
[0028] 应用的最终可信等级基于应用可信等级和应用的载体可信等级生成。
[0029] 应用可信等级基于应用是否经过所述安全操作系统的认证和 /或应用的载体, 其中, 所述载体是物理安全载体或者虚拟安全载体。 举例来说, 对于同一个应用, 如果该应用处于 物理安全载体, 那么就比处于虚拟安全载体的该应用具有更高的可信等级。 这是因为物理安 全载体还包括了独立的硬件, 而这样的独立的硬件是具有高安全性, 可防御物理攻击的。 应 用可信等级的具体分级方式可根据实际情况的不同而有不同的划分, 作为示例, 可以对应用 的可信等级划分为低、 中、 高三种等级, 其中位于安全载体 (SIM卡、 智能卡等) 上的被安 全操作系统认证过的应用为高可信等级, 对于虚拟安全载体 (VSE, virtual secure element) 上的通过安全操作系统认证的应用为中可信等级, 对于那些未与安全操作系统进行认证的应 用为低可信等级。
[0030] 所述应用的载体的可信等级基于该载体是否经过所述安全操作系统的认证。
[0031] 由此, 本发明可以结合应用可信等级 (应用本身可信程度) 和应用的载体可信等级
(应用实际所运行环境的可信程度) 来确定应用的实际可信等级, 即应用的最终可信等级。 例如, 一个高可信等级的应用在低可信等级的环境中运行时, 该应用的实际可信等级可以被 确定为中可信等级。
[0032] 在一个实施例中, 可以将所述应用可信等级、 所述应用的载体可信等级、 应用标识 存储在可信等级列表中, 当一个应用被选择启动作为当前应用时, 根据该可信等级列表来获 得当前应用的最终可信等级。 作为示例, 当前应用的最终可信等级显示的形式可以采用文字 (如可在显示区域显示文字 "高"代表高可信等级、 "中"代表中可信等级、 "低"代表低可 信等级)、 图像显示等, 也可通过颜色来表示等级。
[0033] 图 2 是根据本发明实施例的能够指示操作环境的移动设备的示意图。 如图 2所示, 该移动设备包括个人化信息模块和指示器模块。 其中, 个人化信息模块, 用于生成个人化信 息, 并将该个人化信息存储在仅能由安全操作系统中的指示器模块访问的存储区。 指示器模 块, 用于当该移动设备进入该安全操作系统运行时, 在移动设备的显示区域显示个所述人化 信息, 以向用户指示当前运行的操作系统。
[0034] 应当理解的是, 所描述的各方面和 /或实施例仅仅是实例, 并且可采用其他方面和 /或 实施例, 且在不背离本公开的范围的情况下可做出结构的和功能的修改。 另外, 尽管可以仅 关于若干实施方式中的一个公开了实施例的特定特征或方面, 但可针对任何给定的或特定的 应用所期望和有利的那样, 这种特征或方面可与其他实施方式的一种或多个其他特征或方面 相组合。

Claims

权利要求
1. 一种指示移动设备操作环境的方法, 其特征在于, 包括以下步骤:
生成个人化信息, 并将该个人化信息存储在仅能由安全操作系统访问的存储区,
当该移动设备进入该安全操作系统运行时, 在移动设备的显示区域显示个所述人化信息, 以 向用户指示当前运行的操作系统。
2. 如权利要求 1所述的方法, 其特征在于, 还包括以下步骤:
基于用户的输入来生成所述个人化信息, 所述个人化信息包括文字、 图像或者文字和图像的 组合。
3. 如权利要求 2所述的方法, 其特征在于, 还包括以下步骤:
在所述移动设备第一次被启动时生成所述个人化信息。
4. 如权利要求 1所述的方法, 其特征在于, 还包括以下步骤:
当该移动设备运行在安全操作系统时, 在移动设备的显示区域进一步显示当前操作的应用的 最终可信等级, 以向用户指示当前操作的应用的安全性。
5. 如权利要求 4所述的方法, 其特征在于,
应用的最终可信等级基于应用可信等级和应用的载体可信等级生成, 其中,
所述应用可信等级基于应用是否经过所述安全操作系统的认证和 /或应用的载体, 其中, 所 述载体是物理安全载体或者虚拟安全载体,
所述应用的载体的可信等级基于该载体是否经过所述安全操作系统的认证。
6. 如权利要求 5所述的方法, 其特征在于, 还包括以下步骤:
将所述应用可信等级、 所述应用的载体可信等级、 应用标识存储在可信等级列表中, 当一个应用被选择启动作为当前应用时, 根据该可信等级列表来获得当前应用的最终可信等 级。
7. —种能够指示操作环境的移动设备, 其特征在于, 该移动设备包括:
个人化信息模块, 用于生成个人化信息, 并将该个人化信息存储在仅能由安全操作系统中的 指示器模块访问的存储区,
指示器模块, 用于当该移动设备进入该安全操作系统运行时, 在移动设备的显示区域显示个 所述人化信息, 以向用户指示当前运行的操作系统。
8. 如权利要求 7所述的移动设备, 其特征在于,
所述个人化信息模块基于用户的输入来生成所述个人化信息, 所述个人化信息包括文字、 图 像或者文字和图像的组合。
9. 如权利要求 8所述的移动设备, 其特征在于,
所述个人化信息模块在所述移动设备第一次被启动时生成所述个人化信息。
10. 如权利要求 7所述的移动设备, 其特征在于,
当该移动设备运行在安全操作系统时, 该指示器模块在移动设备的显示区域进一步显示当前 操作的应用的最终可信等级, 以向用户指示当前操作的应用的安全性。
11. 如权利要求 10所述的移动设备, 其特征在于,
应用的最终可信等级基于应用可信等级和应用的载体可信等级生成, 其中,
所述应用可信等级基于应用是否经过所述安全操作系统的认证和 /或应用的载体, 其中, 所 述载体是物理安全载体或者虚拟安全载体,
所述应用的载体的可信等级基于该载体是否经过所述安全操作系统的认证。
12. 如权利要求 11所述的移动设备, 其特征在于,
该指示器模块还用于将所述应用可信等级、 所述应用的载体可信等级、 应用标识存储在可信 等级列表中,
当一个应用被选择启动作为当前应用时, 该指示器模块被配置成根据该可信等级列表来获得 当前应用的最终可信等级。
PCT/CN2014/079328 2013-06-25 2014-06-06 一种指示移动设备操作环境的方法和能够指示操作环境的移动设备 Ceased WO2014206192A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP14818064.9A EP3016015B1 (en) 2013-06-25 2014-06-06 Method for indicating operating environment of mobile device and mobile device capable of indicating operating environment
US14/896,826 US20160140342A1 (en) 2013-06-25 2014-06-06 Method for indicating operating environment of mobile device and mobile device capable of indicating operating environment

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310255179.0 2013-06-25
CN201310255179.0A CN104252597B (zh) 2013-06-25 2013-06-25 一种指示移动设备操作环境的方法和能够指示操作环境的移动设备

Publications (1)

Publication Number Publication Date
WO2014206192A1 true WO2014206192A1 (zh) 2014-12-31

Family

ID=52141016

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/079328 Ceased WO2014206192A1 (zh) 2013-06-25 2014-06-06 一种指示移动设备操作环境的方法和能够指示操作环境的移动设备

Country Status (5)

Country Link
US (1) US20160140342A1 (zh)
EP (1) EP3016015B1 (zh)
CN (1) CN104252597B (zh)
TW (1) TWI628558B (zh)
WO (1) WO2014206192A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104598189B (zh) * 2015-01-26 2019-01-15 联想(北京)有限公司 一种信息处理方法及电子设备
JP6911920B2 (ja) * 2017-07-12 2021-07-28 日本電気株式会社 真正性検証システム、真正性検証方法および真正性検証プログラム

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1609809A (zh) * 2003-10-23 2005-04-27 微软公司 向系统中的图形用户接口提供高确保度执行环境
CN101529366A (zh) * 2006-10-18 2009-09-09 微软公司 可信用户界面对象的标识和可视化
CN102087687A (zh) * 2009-12-04 2011-06-08 株式会社Ntt都科摩 状态通知装置以及状态通知方法

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
SE516779C2 (sv) * 1999-10-01 2002-02-26 Ericsson Telefon Ab L M Bärbar kommunikationsapparat med ett användargränssnitt samt en arbetsmetod för densamma
US8020001B2 (en) * 2006-02-23 2011-09-13 Qualcomm Incorporated Trusted code groups
CN101030238A (zh) * 2007-04-11 2007-09-05 北京飞天诚信科技有限公司 一种智能密钥装置的信息安全输入方法
JP2009169896A (ja) * 2008-01-21 2009-07-30 Sharp Corp サーバ、システム、及びコンテンツ表示制御方法
US8793786B2 (en) * 2008-02-08 2014-07-29 Microsoft Corporation User indicator signifying a secure mode
US9317851B2 (en) * 2008-06-19 2016-04-19 Bank Of America Corporation Secure transaction personal computer
US9166797B2 (en) * 2008-10-24 2015-10-20 Microsoft Technology Licensing, Llc Secured compartment for transactions

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1609809A (zh) * 2003-10-23 2005-04-27 微软公司 向系统中的图形用户接口提供高确保度执行环境
CN101529366A (zh) * 2006-10-18 2009-09-09 微软公司 可信用户界面对象的标识和可视化
CN102087687A (zh) * 2009-12-04 2011-06-08 株式会社Ntt都科摩 状态通知装置以及状态通知方法

Also Published As

Publication number Publication date
CN104252597B (zh) 2017-05-31
US20160140342A1 (en) 2016-05-19
TW201523329A (zh) 2015-06-16
CN104252597A (zh) 2014-12-31
TWI628558B (zh) 2018-07-01
EP3016015A1 (en) 2016-05-04
EP3016015A4 (en) 2017-03-01
HK1205577A1 (zh) 2015-12-18
EP3016015B1 (en) 2020-10-07

Similar Documents

Publication Publication Date Title
US11228449B2 (en) Secure interface for invoking privileged operations
US10574692B2 (en) Mutual authentication security system with detection and mitigation of active man-in-the-middle browser attacks, phishing, and malware and other security improvements
KR102504519B1 (ko) 네트워킹된 장치들을 갖는 컴퓨터 구동 시스템의 반가상 보안 위협 보호
Liu et al. Veriui: Attested login for mobile devices
US10788984B2 (en) Method, device, and system for displaying user interface
Petracca et al. {AWare}: Preventing Abuse of {Privacy-Sensitive} Sensors via Operation Bindings
KR102076878B1 (ko) 안티 멀웨어 프로세스를 보호하는 기법
US20130263277A1 (en) Secure computing system
US20150302201A1 (en) Device and method for processing transaction request in processing environment of trust zone
JP6835851B2 (ja) マルチユーザ厳密認証トークン
WO2009154705A1 (en) Interconnectable personal computer architectures that provide secure, portable and persistent computing environments
CN103843005B (zh) 用于安全交易的安全显示器
CN106899571A (zh) 信息交互方法及装置
CN105282117A (zh) 访问控制方法及装置
Kim et al. Anti-reversible dynamic tamper detection scheme using distributed image steganography for IoT applications
Fernandes et al. Tivos: Trusted visual i/o paths for android
JP2023500980A (ja) セキュア通信のためのデバイス及び方法
TWI628558B (zh) a method of indicating a mobile device operating environment and a mobile device capable of indicating an operating environment
Mannan et al. Unicorn: Two-factor attestation for data security
US10372905B1 (en) Preventing unauthorized software execution
Dar et al. Enhancing security of Android & IOS by implementing need-based security (NBS)
CN115544586B (zh) 用户数据的安全存储方法、电子设备及存储介质
CN111046440B (zh) 一种安全区域内容的篡改验证方法及系统
WO2015043444A1 (zh) 安全模式提示方法和实现该方法的移动设备
EP3190762B1 (en) Dynamic instruction processing method, dynamic instruction processing apparatus, and terminal

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14818064

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 14896826

Country of ref document: US

WWE Wipo information: entry into national phase

Ref document number: 2014818064

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE