WO2017157192A1 - 一种数据输入方法、装置及用户设备 - Google Patents
一种数据输入方法、装置及用户设备 Download PDFInfo
- Publication number
- WO2017157192A1 WO2017157192A1 PCT/CN2017/075643 CN2017075643W WO2017157192A1 WO 2017157192 A1 WO2017157192 A1 WO 2017157192A1 CN 2017075643 W CN2017075643 W CN 2017075643W WO 2017157192 A1 WO2017157192 A1 WO 2017157192A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- user
- event
- operating environment
- environment
- display area
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/82—Protecting input, output or interconnection devices
- G06F21/83—Protecting input, output or interconnection devices input devices, e.g. keyboards, mice or controllers thereof
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/604—Tools and structures for managing or administering access control systems
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/74—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information operating in dual or compartmented mode, i.e. at least one secure mode
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/034—Test or assess a computer or a system
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2105—Dual mode as a secondary aspect
Definitions
- the present invention relates to the field of communications technologies, and in particular, to a data input method, apparatus, and user equipment.
- UE user equipment
- the industry proposes the Trust Zone technology.
- the technology proposes to divide the hardware components of the user equipment into a secure world and a normal world, and the security world can only transmit data through a monitor.
- the operating system running the user equipment in the non-secure world the program running in the security world has higher security level than the program running in the non-secure world
- the security world is isolated from the non-secure world by hardware, and the security world has access to the non-secure world. All the data in the security world, but not vice versa.
- the user device starts up, it will first enter the security world, and then the program in the security world is responsible for switching to the non-secure world and starting the operating system of the user device.
- Trust Zone technology proposes the concept of a secure world and a non-secure world to solve the problem of data input security in user devices.
- users can operate in the provided data input environment.
- Input events such as account numbers and passwords, but usually, when the data input environment running in the security world displays and inputs related content, the displayed content generally covers the entire display area of the user device, when the user needs to perform other
- a short message popup window appears, and the user needs to view the short message.
- the system needs to exit the data input environment under the instruction of the user to view the short message, causing the event that has been operated before. Lost.
- the Trust Zone technology does not fully address the security of events generated by users running programs in the non-secure world of user devices, nor does it directly operate on events that run in a non-secure world.
- the invention provides a data input method, device and user equipment, which can better improve the security of an event generated when a user runs a program running in a non-secure world of a user equipment, and realizes direct operation in a non-secure world.
- the event in the operation can better improve the security of an event generated when a user runs a program running in a non-secure world of a user equipment, and realizes direct operation in a non-secure world. The event in the operation.
- a data input method including: determining that a user is not in a preset display area When the UE performs the operation, the event corresponding to the operation is distributed to the first running environment for processing; wherein the preset display area is running in the second running environment of the UE, the second running environment
- the security level is higher than the first running environment, and the security of the event generated when the user runs the program running in the non-secure world of the user device is better, and the event directly running in the non-secure world is realized. Take action.
- the method further includes: receiving, by the user, an operation in an input area that is displayed by the display unit for the user, generating an event corresponding to the operation; determining that the user is Whether the event generated by the operation in the input area is a security input event; if the judgment result is yes, the preset display area is activated, and the preset display area is presented to the user through the display unit.
- the starting the preset display area includes: backing up an event in the current first running environment; triggering the second running The interruption in the environment, through the interruption in the second operating environment, starts the preset display area.
- the security of the generated event is
- the preset display area and the input area presented simultaneously on the screen of the user device.
- the event corresponding to the operation is distributed to the first running environment for processing, including: storing an event corresponding to the operation to the sharing a storage area, wherein the shared storage area is a storage area commonly used by the first running environment and the second running environment; storing the shared storage area by triggering an interruption in the first running environment The event is distributed to the first runtime environment for processing.
- the foregoing stored in the shared storage area is triggered by triggering an interruption in the first operating environment
- Distributing the event to the first execution environment for processing includes: triggering an interrupt in the first execution environment, and calling a daemon thread in the first security environment to pass the daemon thread into the shared storage area
- the stored events are distributed to the first runtime environment for processing.
- the method further includes: displaying, when the event corresponding to the operation is a security input event, displaying the preset display area, so that the user is in the preset display area An operation is performed wherein the secure input event is a data input event having a rights verification attribute.
- the event corresponding to the operation is distributed to After processing in the first running environment, the method further includes: hiding the preset display area. Can increase the flexibility of user operations.
- the preset display area includes Formatted input edit box.
- the input edit box of the set format includes at least one of the following: a set input type It can be an input type such as a nine-keyboard numeric type, a nine-keyboard Chinese type, a nine-keyboard letter type, and a digital Chinese mix. Can improve the convenience of user operations.
- a data input device having a function of implementing terminal behavior in a method design of any of the first to eighth possible implementations of the first aspect and the first aspect described above.
- the functions may be implemented by hardware or by corresponding software implemented by hardware.
- the hardware or software includes one or more modules corresponding to the functions described above.
- a user terminal having a function for implementing terminal behavior in a method design of any of the first to eighth possible implementations of the first aspect and the first aspect.
- the functions may be implemented by hardware or by corresponding software implemented by hardware.
- the hardware or software includes one or more modules corresponding to the functions described above.
- the structure of the terminal includes a memory and a processor, wherein the memory is configured to store a set of programs, and the processor is configured to invoke the memory storage
- a computer storage medium for storing computer software instructions for use as a data input device, comprising a program designed to perform the above aspects.
- the event corresponding to the operation is distributed to the first running environment for processing, so that the user is in the non-secure world of the user equipment.
- the program running in the operation is operated, even if other non-security events need to be processed, the security of the event generated when the user runs the program running in the non-secure world of the user device can be guaranteed to be directly operated in the non-secure world. The event is handled.
- FIG. 1 is a schematic diagram of a logical structure of a computing node applied by a method for data input according to an embodiment of the present invention
- FIG. 2 is a schematic structural diagram of a user equipment according to an embodiment of the present invention.
- FIG. 3 is a schematic structural diagram of a user equipment according to an embodiment of the present invention.
- FIG. 4 is a schematic diagram of hardware components of a security world of a data input system according to an embodiment of the present invention.
- FIG. 5 is a flowchart of a data input method according to an embodiment of the present invention.
- FIG. 6 is a schematic diagram of an input edit box according to an embodiment of the present invention.
- FIG. 7 is a schematic diagram of a preset display area and an input area according to an embodiment of the present invention.
- FIG. 8 is a schematic diagram of input types set according to an embodiment of the present invention.
- FIG. 9 is a flowchart of a data input method according to an embodiment of the present invention.
- FIG. 10 is a schematic structural diagram of a data input device according to an embodiment of the present invention.
- the present invention proposes In the technical solution, when it is determined that the user does not perform an operation on the UE in the preset display area, The corresponding event is distributed to the first operating environment for processing, wherein the preset display area is operated in the second operating environment of the UE, and the security level of the second operating environment is higher than the first operating environment, thereby It can better improve the security of events generated when a user runs a program running in a non-secure world of the user device, and directly operates an event running in a non-secure world.
- the computing node may be a user equipment, and the user equipment may specifically be a desktop computer, a notebook computer, a smart phone or a tablet computer.
- the hardware layer of the user equipment includes a central processing unit (CPU), a graphics processing unit (GPU), and the like, and may further include a memory and an input/output device (Input Device).
- the input device may include a keyboard, a mouse, a touch screen, etc.
- the output device may include a display device such as a liquid crystal display (LCD), a cathode ray tube (CRT), a holographic image (Holographic), Projector, etc.
- LCD liquid crystal display
- CRT cathode ray tube
- Holographic holographic image
- Projector Projector
- the core library layer is the core part of the operating system, including input/output services, core services, graphics device interfaces, and graphics engine (Graphics Engine) for CPU and GPU graphics processing.
- the graphics engine may include a 2D engine, a 3D engine, a composition, a frame buffer, and the like.
- the core library layer also includes input method services. Among them, the input method service includes the input method service provided by the terminal.
- the input method service further includes a data input method proposed by the embodiment of the present invention.
- the terminal further includes a driving layer, a frame layer, and an application layer.
- the driver layer may include a CPU driver, a GPU driver, a display controller driver, a Trust Zone Driver, and the like.
- the framework layer may include a graphic service (Graphic Service), a system service (System service), a web service (Web Service), and a customer service (Customer Service); and the graphic service may include, for example, a widget (widget) or a canvas (Canvas). , Views, Render Script, etc.
- the application layer may include a desktop, a media player, a browser, and the like.
- the hardware and program instructions of the user equipment can include two operating environments at run time, which are a safe operating environment and a non-secure operating environment, and a non-secure operating environment, which can also be called a non-secure world.
- the first operating environment and the safe operating environment, which are proposed by the embodiments of the present invention, may also be referred to as a security world, corresponding to the second operating environment proposed by the embodiments of the present invention.
- the program running in a secure operating environment and the security of the hardware of the user device are higher than the programs running in the non-secure operating environment and the security level of the hardware of the user device.
- the security world may also be a virtual running environment isolated from the operating system of the user equipment.
- the user equipment 200 includes at least one processor 201, at least one network interface 204 or other user interface 203, and a memory 205, at least one communication.
- Communication bus 202 is used to implement connection communication between these components.
- the user device 200 optionally includes a user interface 203, including a display (such as the LCD, CRT, Holographic or Projector shown in FIG. 1), a keyboard or a pointing device (eg, a mouse, a trackball ( Trackball), touchpad or touch screen, etc.).
- a display such as the LCD, CRT, Holographic or Projector shown in FIG. 1
- a keyboard or a pointing device eg, a mouse, a trackball ( Trackball), touchpad or touch screen, etc.
- the memory 205 may include read only memory and random access memory, and provides the processor 201 with program instructions and data stored in the memory 205.
- a portion of the memory 205 may also include non-volatile random access memory (NVRAM).
- NVRAM non-volatile random access memory
- the memory 205 stores the following elements, executable modules or data structures, or Their subset, or their extension set:
- the operating system 2051 includes various system program instructions that can be run, for example, at the framework layer, core library layer, driver layer, etc. shown in FIG. 1, for implementing various basic services and for processing hardware-based tasks.
- the operating system not only looks to run in the first running environment, but also the operating system can be run in the second operating environment with the security level higher than the first operating environment.
- the application 2052 includes various applications, such as a desktop, a media player, a browser, and an input method application, as shown in FIG. 1, for implementing various application services.
- the various applications in the application 2052 can be applied in the first operating environment or in the second operating environment.
- the implemented data is stored in the application 2052.
- the memory 205 may also be referred to as a storage area, a program for storing a data input method, and a storage operating system.
- the processor 201 is configured to execute the program instructions stored in the memory 205, and the processor 201 is configured to execute according to the obtained program instructions: when it is determined that the user does not perform an operation on the UE in the preset display area, the event corresponding to the operation is distributed to Processing is performed in the first operating environment.
- the processor 201 is further configured to: when determining that the event corresponding to the operation is a security input event, displaying a preset display area, so that the user operates in the preset display area,
- the security input event is a data input event with a permission verification attribute.
- the processor 201 is specifically configured to: store an event corresponding to the operation into the shared storage area, where the shared storage area is a storage area commonly used by the first running environment and the second running environment;
- the user equipment also includes an interrupt in the first operating environment (not shown in FIG. 2), the processor 201 triggers an interrupt in the first operating environment, and the interrupt in the first operating environment distributes the event stored in the shared storage area to Processing is performed in the first operating environment. Further, the processor 201 is specifically configured to: trigger an interrupt in the first running environment, and invoke a daemon thread in the first security environment to distribute the event stored in the shared storage area to the first running environment by using the daemon thread. deal with.
- the processor 201 is specifically configured to: hide a preset display area.
- the user equipment to which the data input method is applied is proposed by the embodiment of the present invention.
- the user equipment may be a mobile phone, a tablet computer, a personal digital assistant (PDA), or the like.
- PDA personal digital assistant
- FIG. 3 it is a schematic diagram of one of the structural components of the user equipment 300.
- the user equipment 300 mainly includes a memory 320, a processor 360, and an input unit 330, and the input unit 330 is configured to receive a generated event when the user performs an operation on the terminal.
- the memory 320 is used to store program instructions for the operating system and various applications.
- the memory 320 can be divided into a secure memory (also referred to as a secure storage area) and a non-secure memory (also Can be called non-secure storage area) and shared storage (also called shared storage area).
- the non-secure memory is set in the first operating environment
- the secure memory is set in the second operating environment
- the second operating environment has a higher security level than the first operating environment.
- a processor or interrupt set in the first operating environment cannot directly access the secure memory in the second operating environment.
- a processor or interrupt in the second operating environment can access the non-secure processor set in the first operating environment and access the non-secure storage area.
- the data stored in the shared memory is data that can be accessed by the processor or interrupt in the first operating environment and the second operating environment, that is, the first operating environment and the second
- the processor in the operating environment, or an interrupt can access the shared memory to obtain the data in the shared memory.
- processor 360 can be referred to the detailed description of the processor 201 described above, and details are not described herein.
- the memory 320 may be a memory of the user equipment 300, and the memory may be divided into three storage spaces, corresponding to the security memory set in the first running environment, the non-secure memory set in the second environment, and the first operating environment and the first
- the shared memory that can be accessed by applications or hardware in the running environment.
- the space division of secure memory, non-secure memory, and shared memory can be divided into the same size, or can be divided into different sizes according to different storage data input events.
- the input unit 330 in the user device can be used to receive numeric or character information input by the user, as well as to generate signal inputs related to user settings and function control of the user device 300.
- the input unit 330 may include a touch panel 331.
- the touch panel 331 can collect operations of the user (such as the user using a finger, a stylus, or the like on the touch panel 331), and drive and touch the panel according to preset program instructions. 331 corresponding connection device.
- the touch panel 331 can include two parts: a touch detection device and a touch controller.
- the touch detection device detects the touch orientation of the user, and detects a signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts the touch information into contact coordinates, and sends the touch information.
- the processor 360 is provided and can receive commands from the processor 360 and execute them.
- the touch panel 331 can be implemented in various types such as resistive, capacitive, infrared, and surface acoustic waves.
- the input unit 330 may further include other input devices 332, which may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, switch buttons, etc.), trackballs, mice, joysticks, and the like. One or more of them.
- the user device 300 can also include a display unit 340 that can be used to display information entered by the user or information provided to the user and various menu interfaces of the user device 300.
- the display unit 340 can include a display panel 341.
- the display panel 341 can be configured in the form of a liquid crystal display (LCD) or an organic light-emitting diode (OLED).
- the touch panel 331 covers the display panel 341 to form a touch display screen, and the touch display screen provides a preset display area to the user.
- the touch display screen 7 detects a touch operation thereon or nearby, it is transmitted to the processor 360 to determine the type of touch event, and then the processor 360 provides a corresponding visual output on the touch display screen according to the type of touch event.
- the touch display screen comprises different display areas.
- Each display area may contain interface elements such as at least one application icon and/or widget desktop control.
- the processor 360 is a control center of the user device 300 that connects various portions of the entire handset using various interfaces and lines, and executes various types of the user device 300 by running or executing software programs and/or modules stored in the memory 320.
- the user equipment 300 is monitored as a whole by functioning and processing the data.
- the initialization setting includes initialization of the monitoring mode.
- all memory (secure memory, non-secure memory, and shared memory) in the operating system of the user device is in the second operating environment. Then load the operating system image that needs to run in the first running environment into non-secure memory, and then go to the system image running the first running environment.
- the user equipment 300 may further include an RF circuit 310 for providing a wirelessly connected WIFI module 380. And a power supply 390 and an audio circuit 370 for providing sound input and output.
- the operating environment of the data input method is divided into a non-secure world (first operating environment) and a security world (second Operating environment).
- first operating environment first operating environment
- second Operating environment second Operating environment
- the security of the entire system is obtained by dividing the hardware resources and software resources of the System on Chip (SoC) into two worlds.
- SoC System on Chip
- the SoC system includes a processor (Core) 401.
- processor Core
- each physical processor core provides two virtual cores, one is non-secure core (NS) and the other is security core (Secure), switching between non-secure core and security core.
- the mechanism is called the monitor mode.
- a non-secure core can only access system resources of the NS, and the security core can access all resources in the user equipment.
- DMA direct memory access
- Secure RAM Secure Random Access Memory
- Secure Boot Secure Boot Read Only Memory
- ROM read only memory
- the SoC also includes a Trust Zone Address Space Controller (TZASC) 407 for supporting security interrupts, a Trust Zone Protection Space Controller (TZPC) 408, and a Dynamic Memory Controller (Dynamic Memory). Controller, DMC) 409, dynamic RAM (Dynamic RAM) 410, and the like.
- the TZPC is used to set the security properties of the peripheral device. For example, it can set the display unit properties to be safe so that operations in the first runtime environment cannot access these devices that are set to be secure.
- TZASC is used to control the security attribute partitioning of DRAM. It can set a part of DRAM to be secure, and the rest is set to be non-secure. If the processor in the first running environment initiates an access request to secure memory, the access request is made. Will be rejected. Access to the secure memory by the DMA in the first operating environment is denied, thus ensuring that the secure memory is not accessed by any operating system or hardware in the first operating environment.
- the GIC is responsible for controlling all interrupt information. It can set certain interrupts to be safe and some interrupts to normal.
- the SoC components are connected to each other through an Advanced eXtensible Interactive (AXI) 411.
- the SoC and the peripheral device communicate through the Advanced eXtensible Interactive to Advanced Peripheral Bus Bridge (AXI2APB) bridge 412, and the AXI2APB can sense the security attribute of the event currently accessing the peripheral device.
- AXI2APB rejects the access.
- the secure RAM and the secure ROM are isolated by a hardware and software mechanism for storing the operating system running in the second operating environment.
- the SoC system is initialized after power-on, and when the system starts, the system first enters the second running environment, and the initial setting is performed in the second running environment.
- the initialization settings include initialization of the operating system in the second runtime environment.
- all memory in the operating system of the user device is in the second operating environment.
- the operating system image that needs to be run in the first running environment is loaded into the memory, and part of the memory is allocated to the first running environment, and the security attribute of the part of the memory allocated for the first running environment is set to be non-secure, and then Run the system image in the first runtime environment.
- Step 1 The display unit presents an input area to the user, and the user operates in the input area to generate an event corresponding to the operation.
- a numeric type of payment password is input in the input area presented by the display unit as an example for detailed description.
- the display unit may include a touch panel having a touch property.
- the user inputs a payment account in the input area by touching the touch panel, and continues to input the payment password after inputting the payment account.
- the processor receives an event generated by the user operating the touch panel. Specifically, it may be a non-secure core in the first operating environment, and receive an event generated by the user operating the touch panel.
- Step 2 The processor determines whether the event generated by the operation of the user in the input area is a security input event. If it is determined that it is not a secure input event, the user continues to operate in the input area, generating an event corresponding to the operation, and the processor continues to process the event.
- a security input event is an event that requires the user to enter a password generated with a rights verification attribute. For example, for a certain payment application, after the user inputs the user name, the user is required to continue to input the payment password corresponding to the user name, and after the payment password and the user name match, the payment is completed. Then, the user continues to input an event corresponding to the operation of the payment password corresponding to the user name, that is, a security input event.
- the security attribute of the input area presented by the display unit may be edited in advance.
- the input area is set to a non-secure display area running in the first running environment and a secure display area running in the second running environment.
- the input area in the first running environment may be an input edit box having a fixed shape and size, and the input edit box may be any shape, as shown in FIG. Take a square as an example for illustration.
- the security attribute is set to a numeric attribute, that is, when the received event that the user operates in the input edit box is a trigger digital input, it is determined that the event is a secure input event.
- the payment password of the user input numeric type is 12345678
- the user payment password is 12345678
- the user triggers a number it is determined that the data input event operated by the user is a secure input event.
- Step 3 The processor triggers the TZ driver when it is determined that the data input event of the user operation is a security input event.
- the TZ driver triggers a monitor mode used to switch between the first operating environment and the second operating environment, and the processor enters the second operating environment through the monitor.
- Step 4 The processor backs up events in the current first running environment in the monitor mode.
- the processor triggers an interrupt in the first operating environment, and saves the currently determined security input event to be shared in the storage area.
- the interrupt in the second operating environment is triggered in the monitor mode, and the processor in the second operating environment, that is, the security core, is triggered by the interrupt in the second operating environment.
- Step 5 The safety core (ie, the processor in the second operating environment) triggers an interrupt, starts a preset display area, and presents the preset display area to the user through the display unit. The operation after the user will operate in the preset display area.
- the safety core ie, the processor in the second operating environment
- the preset display area runs in the second running environment, and the preset display area may be a part of the user equipment screen, and the user may perform an input operation in the preset display area.
- the preset display area may be an input edit box having a fixed shape and size, and having security attributes.
- FIG. 7 a preset display area is started, and the preset display area and the input area can be simultaneously presented in the screen of the user equipment.
- the preset display area can cover part of the input area and is superimposed on part of the input area.
- the preset display area can include the set input type.
- the input type set may be an input type of nine keyboard digital type, nine keyboard Chinese type (not shown in FIG. 8), nine keyboard letter type, digital Chinese mixture, etc. (not shown in FIG. 8). .
- the preset display area is activated, assuming that the set input type is a display area of a nine-keyboard type, in the display unit, the display area of the nine-keyboard type is displayed to the user, and the user is preset in the nine-keyboard type. Enter the payment password in the display area.
- step 6 the processor transfers the event to the second operating environment for processing.
- the corresponding event generated by the user operating in the input area in the first running environment is determined to determine whether the event is a security input event, and when the determination result is yes, the first operating environment is performed.
- the switching to the second operating environment is to display the preset display area for the user, so that the user can switch to the second operating environment for processing during the security input time generated by the operation of the user equipment, so that the user can be better protected.
- step 7 the user operates in a preset display area of the user equipment.
- Step 8 The processor in the second operating environment obtains an event corresponding to the operation.
- step 5 For a detailed description of the preset display area, please refer to the detailed explanation in step 5 above, and no further details are provided.
- the payment password of the user input type is also taken as an example.
- the payment password is entered in the display area preset by the user.
- Step 9 The processor determines whether the user operates the UE in the preset display area. If the determination result is yes, step 10 is performed; otherwise, step 12 is performed.
- the user operates in a preset display area of the display unit, and may also operate outside the preset display area.
- the event corresponding to the operation generated by the user is transmitted to the security core, and the security core determines whether the event corresponds to the operation falling in the preset display area.
- the user presets the display area, inputs a payment password, and the security core determines whether the user's touch point is in the preset display area.
- the user is operating, for example, when the user triggers the input of the account category (ie, operates in the input area), it is determined that the user does not operate in the preset display area, and vice versa, the user is determined to be in the preset display area. In the middle of the operation.
- the user inputs the payment password 12345678 through the preset display area, and the user inputs 123.
- the user equipment receives the short message display or the call display, the user clicks on the short message to display, and the user operates the user equipment at this time. Falling in the short message display box, in this case, it is determined that the user does not perform an operation on the UE in the preset display area.
- Step 10 Continue to receive an event generated by the user performing an operation on the user equipment in the preset display area.
- Step 11 After determining that the user ends the operation, the processor performs verification processing on the received event, and transfers to the first running environment, and feeds back the verification processing result to the user.
- the received payment password is verified, and the verification result is fed back to the user.
- Step 12 When the processor determines that the user does not perform an operation on the user equipment in the preset display area, the processor distributes the event corresponding to the operation to the first running environment for processing.
- the event corresponding to the operation is distributed to the first running environment for processing, and the implementation manner thereof may include the following two methods:
- the first way by triggering an interrupt, the event corresponding to the operation is distributed to the first running environment for processing.
- the processor may trigger an interrupt in the second running environment, and store an event corresponding to the user's operation into the shared storage area by using the interrupt in the second running environment.
- the processor is in monitor mode, The events stored in the shared storage area are distributed to the first running environment for processing by triggering an interruption in the first running environment.
- the processor triggers a Fast Interrupt Reques (FIQ), stores an event corresponding to the user's operation in the shared storage area, and then the processor triggers an interrupt in the first running environment in the monitor mode, in the sharing The stored event is obtained in the storage area, and the interrupt in the first running environment distributes the obtained event to the first running environment for processing.
- FIQ Fast Interrupt Reques
- the second way is to distribute the event corresponding to the operation to the first running environment for processing by the daemon thread.
- the daemon process is a long-lived process, usually independent of the user equipment and periodically performing certain tasks or waiting to process certain events.
- the daemon is typically started when the system boots into the mount and terminates when the system is shut down.
- the processor may store an event corresponding to the user's operation in the shared storage area by triggering an interrupt in the second running environment, and then trigger the first running environment in the monitor mode.
- the interrupt triggers the daemon thread in the first running environment through the interrupt in the first running environment, the daemon thread obtains the stored event in the shared storage area, and the daemon thread sends the obtained event to the first running environment for processing.
- the current event needs to be saved to the shared storage area before the event is distributed.
- the interrupt in the second running environment stores the event in the shared storage area through the interrupt running in the second environment. It is also possible that the display unit driver transmits the event to the upper layer application, and stores the event in the shared storage area through the upper layer application.
- the method further includes: hiding the preset display area.
- the embodiment of the present invention further provides a data input method, as shown in FIG. 9, the specific processing flow is as follows:
- step 91 the user operates in a preset display area of the user equipment.
- Step 92 The processor in the second operating environment obtains an event corresponding to the operation.
- step 5 For a detailed description of the preset display area, please refer to the detailed explanation in step 5 above, and details are not described here.
- the payment password of the user input type is also taken as an example.
- the user enters a payment password in a preset display area.
- Step 93 The processor determines whether the user operates the UE in the preset display area. If the determination result is yes, step 94 is performed; otherwise, step 96 is performed.
- Step 94 continuing to receive an event generated by the user performing an operation on the user equipment in the preset display area.
- Step 95 After determining that the user ends the operation, the processor performs verification processing on the received event, and transfers the result to the first running environment, and feeds back the verification processing result to the user.
- the received payment password is verified, and the verification result is fed back to the user.
- Step 96 The processor distributes an event corresponding to the operation to the first running environment for processing when it is determined that the user does not perform an operation on the user equipment in the preset display area.
- the event corresponding to the operation is distributed to the first running environment for processing, and the implementation manner thereof may include Two ways:
- the first way by triggering an interrupt, the event corresponding to the operation is distributed to the first running environment for processing.
- the processor may trigger an interrupt in the second running environment, and store an event corresponding to the user's operation into the shared storage area by using the interrupt in the second running environment.
- the processor distributes the events stored in the shared storage area to the first running environment for processing by triggering the interrupt in the first running environment.
- the processor triggers a Fast Interrupt Reques (FIQ), stores an event corresponding to the user's operation in the shared storage area, and then the processor triggers an interrupt in the first running environment in the monitor mode, in the sharing The stored event is obtained in the storage area, and the interrupt in the first running environment distributes the obtained event to the first running environment for processing.
- FIQ Fast Interrupt Reques
- the second way is to distribute the event corresponding to the operation to the first running environment for processing by the daemon thread.
- the daemon process is a long-lived process, usually independent of the user equipment and periodically performing certain tasks or waiting to process certain events.
- the daemon is typically started when the system boots into the mount and terminates when the system is shut down.
- the processor may store an event corresponding to the user's operation in the shared storage area by triggering an interrupt in the second running environment, and then trigger the first running environment in the monitor mode.
- the interrupt triggers the daemon thread in the first running environment through the interrupt in the first running environment, the daemon thread obtains the stored event in the shared storage area, and the daemon thread sends the obtained event to the first running environment for processing.
- the current event needs to be saved to the shared storage area before the event is distributed.
- the interrupt in the second running environment stores the event in the shared storage area through the interrupt running in the second environment. It is also possible that the display unit driver transmits the event to the upper layer application, and stores the event in the shared storage area through the upper layer application.
- the method further includes: hiding the preset display area.
- an embodiment of the present invention further provides a data input device, as shown in FIG. 10, the structural components thereof include:
- the receiving unit 1001 is configured to receive an event generated by the user performing an operation on the UE in a preset display area.
- the determining unit 1002 is configured to determine whether the user performs an operation in the preset display area.
- the executing unit 1003 is configured to, when it is determined that the user does not perform an operation on the UE in the preset display area, distribute the event corresponding to the operation to the first running environment for processing.
- the preset display area runs in the second running environment of the UE, and the security level of the second running environment is higher than the first running environment.
- the executing unit 1003 is specifically configured to store an event corresponding to the operation into a shared storage area, where the shared storage area is the first operating environment and the second a storage area commonly used by the operating environment; the event stored in the shared storage area is distributed to the first operating environment for processing by triggering an interruption in the first operating environment.
- the executing unit 1003 is specifically configured to trigger an interrupt in the first running environment, and invoke the A daemon thread in the first security environment to distribute the event stored in the shared storage area to the first execution environment for processing by the daemon thread.
- the executing unit 1003 is further configured to: when it is determined that the event corresponding to the operation is a security input event, display the preset display area, so that the user performs in the preset display area.
- the operation, wherein the secure input event is a data input event having a rights verification attribute.
- the executing unit 1003 is further configured to hide the preset display area after the event corresponding to the operation is distributed to the first running environment for processing.
- the preset display area includes an input edit box having a security attribute.
- the present invention also provides a computer storage medium for storing computer software instructions for use with the data input device of the above aspect, comprising a program designed to perform the above aspects.
- embodiments of the present invention can be provided as a method, apparatus (device), or computer program product. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or a combination of software and hardware. Moreover, the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, read-only optical disks, optical storage, etc.) including computer usable program code.
- computer-usable storage media including but not limited to disk storage, read-only optical disks, optical storage, etc.
- the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
- the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
- These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
- the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Automation & Control Theory (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- User Interface Of Digital Computer (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (16)
- 一种数据输入方法,其特征在于,包括:在确定出用户未在预设的显示区域中对用户设备UE执行操作时,将与所述操作对应的事件分发至第一运行环境中进行处理;其中,所述预设的显示区域运行在所述UE的第二运行环境中,所述第二运行环境的安全级别高于所述第一运行环境。
- 如权利要求1所述的方法,其特征在于,将与所述操作对应的事件分发至第一运行环境中进行处理,包括:将与所述操作对应的事件存储至共享存储区中,其中所述共享存储区是所述第一运行环境和所述第二运行环境共同使用的存储区;通过触发所述第一运行环境中的中断,将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
- 如权利要求2所述的方法,其特征在于,通过触发所述第一运行环境中的中断,将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理,包括:触发所述第一运行环境中的中断,并调用所述第一安全环境中的守护线程,以通过所述守护线程将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
- 如权利要求1~3任一所述的方法,其特征在于,在确定出用户未在预设的显示区域中对用户设备UE执行操作之前,还包括:在确定出与所述操作对应的事件是安全输入事件时,显示所述预设的显示区域,以使用户在所述预设的显示区域中进行操作,其中所述安全输入事件是具有权限验证属性的数据输入事件。
- 如权利要求1~3任一所述的方法,其特征在于,将与所述操作对应的事件分发至第一运行环境中进行处理之后,还包括:隐藏所述预设的显示区域。
- 如权利要求1~5任一所述的方法,其特征在于,所述预设的显示区域包含设定格式的输入编辑框。
- 一种数据输入装置,其特征在于,包括:接收单元,用于接收用户在预设的显示区域中对UE执行操作生成的事件;判断单元,用于确定用户是否在预设的显示区域中UE执行操作;执行单元,用于在所述判断单元确定出用户未在预设的显示区域中对用户设备UE执行操作时,将与所述操作对应的事件分发至第一运行环境中进行处理;其中,所述预设的显示区域运行在所述UE的第二运行环境中,所述第二运行环境的安全级别高于所述第一运行环境。
- 如权利要求7所述的装置,其特征在于,所述执行单元,具体用于将与所述操作对应的事件存储至共享存储区中,其中所述共享存储区是所述第一运行环境和所述第二运行环境共同使用的存储区;通过触发所述第一运行环境中的中断,将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
- 如权利要求8所述的装置,其特征在于,所述执行单元,具体用于触发所述第一运行环境中的中断,并调用所述第一安全环境中的守护线程,以通过所述守护线程将所述 共享存储区中存储的所述事件分发至第一运行环境中进行处理。
- 如权利要求7~9任一所述的装置,其特征在于,所述执行单元,还用于在确定出与所述操作对应的事件是安全输入事件时,显示所述预设的显示区域,以使用户在所述预设的显示区域中进行操作,其中所述安全输入事件是具有权限验证属性的数据输入事件。
- 如权利要求7~9任一所述的装置,其特征在于,所述执行单元,还用于隐藏所述预设的显示区域。
- 一种用户设备,其特征在于,包括:存储器,用于存储程序指令;处理器,用于在所述存储器中获得存储的程序指令,按照获得的程序执行:在确定出用户未在预设的显示区域中对用户设备UE执行操作时,将与所述操作对应的事件分发至第一运行环境中进行处理;其中,所述预设的显示区域运行在所述UE的第二运行环境中,所述第二运行环境的安全级别高于所述第一运行环境。
- 如权利要求12所述的用户设备,其特征在于,所述处理器,具体用于将与所述操作对应的事件存储至共享存储区中,其中所述共享存储区是所述第一运行环境和所述第二运行环境共同使用的存储区;所述用户设备还包括第一运行环境中的中断;所述处理器,具体用于触发所述第一运行环境中的中断;所述第一运行环境中的中断,用于将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
- 如权利要求13所述的用户设备,其特征在于,所述处理器,具体用于触发所述第一运行环境中的中断,并调用所述第一安全环境中的守护线程,以通过所述守护线程将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
- 如权利要求12~14任一所述的用户设备,其特征在于,所述处理器,还用于在确定出与所述操作对应的事件是安全输入事件时,显示所述预设的显示区域,以使用户在所述预设的显示区域中进行操作,其中所述安全输入事件是具有权限验证属性的数据输入事件。
- 如权利要求12~14任一所述的用户设备,其特征在于,所述处理器,还用于隐藏所述预设的显示区域。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| BR112018068582-8A BR112018068582B1 (pt) | 2016-03-15 | 2017-03-03 | Método de entrada de dados, aparelho, e equipamento de usuário |
| EP17765734.3A EP3418934B1 (en) | 2016-03-15 | 2017-03-03 | Data input method, device and user equipment |
| US16/131,548 US10831905B2 (en) | 2016-03-15 | 2018-09-14 | Data input method and apparatus and user equipment |
| US17/085,539 US11574064B2 (en) | 2016-03-15 | 2020-10-30 | Data input method and apparatus and user equipment |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610145990.7A CN105825128B (zh) | 2016-03-15 | 2016-03-15 | 一种数据输入方法、装置及用户设备 |
| CN201610145990.7 | 2016-03-15 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US16/131,548 Continuation US10831905B2 (en) | 2016-03-15 | 2018-09-14 | Data input method and apparatus and user equipment |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017157192A1 true WO2017157192A1 (zh) | 2017-09-21 |
Family
ID=56987835
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2017/075643 Ceased WO2017157192A1 (zh) | 2016-03-15 | 2017-03-03 | 一种数据输入方法、装置及用户设备 |
Country Status (4)
| Country | Link |
|---|---|
| US (2) | US10831905B2 (zh) |
| EP (1) | EP3418934B1 (zh) |
| CN (1) | CN105825128B (zh) |
| WO (1) | WO2017157192A1 (zh) |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105825128B (zh) | 2016-03-15 | 2020-05-19 | 华为技术有限公司 | 一种数据输入方法、装置及用户设备 |
| CN107168747B (zh) * | 2017-05-27 | 2020-12-29 | 努比亚技术有限公司 | 移动终端配置的区分方法、装置及计算机可读存储介质 |
| CN109426355B (zh) * | 2017-08-31 | 2022-12-30 | 华为终端有限公司 | 一种电子设备的输入方法、输入装置及电子设备 |
| CN110059489B (zh) * | 2018-01-19 | 2021-08-17 | 旭景科技股份有限公司 | 安全电子设备 |
| GB201806465D0 (en) | 2018-04-20 | 2018-06-06 | Nordic Semiconductor Asa | Memory-access controll |
| GB201810662D0 (en) | 2018-06-28 | 2018-08-15 | Nordic Semiconductor Asa | Peripheral Access On A Secure-Aware Bus System |
| GB201810653D0 (en) * | 2018-06-28 | 2018-08-15 | Nordic Semiconductor Asa | Secure peripheral interconnect |
| GB201810659D0 (en) | 2018-06-28 | 2018-08-15 | Nordic Semiconductor Asa | Secure-Aware Bus System |
| FR3135334B1 (fr) | 2022-05-05 | 2025-07-18 | St Microelectronics Rousset | Systeme sur puce integrant un circuit d’acces direct en memoire et procede correspondant |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103714276A (zh) * | 2012-10-01 | 2014-04-09 | Nxp股份有限公司 | 相连的设备架构、移动平台和用于安全的用户认证的系统 |
| US20140101755A1 (en) * | 2012-10-10 | 2014-04-10 | Research In Motion Limited | Mobile wireless communications device providing security features based upon wearable near field communication (nfc) device and related methods |
| CN104115152A (zh) * | 2012-02-16 | 2014-10-22 | 三星电子株式会社 | 用于使用装置认证来保护数字内容的方法和设备 |
| CN104239783A (zh) * | 2014-09-19 | 2014-12-24 | 东软集团股份有限公司 | 一种特定信息安全输入系统及方法 |
| CN104933361A (zh) * | 2015-06-05 | 2015-09-23 | 浪潮电子信息产业股份有限公司 | 一种登录密码的保护装置及方法 |
| CN105825128A (zh) * | 2016-03-15 | 2016-08-03 | 华为技术有限公司 | 一种数据输入方法、装置及用户设备 |
Family Cites Families (32)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6321337B1 (en) * | 1997-09-09 | 2001-11-20 | Sanctum Ltd. | Method and system for protecting operations of trusted internal networks |
| US20040226041A1 (en) * | 2000-02-18 | 2004-11-11 | Xsides Corporation | System and method for parallel data display of multiple executing environments |
| AU4595501A (en) * | 2000-03-22 | 2001-10-03 | Sony Electronics Inc. | Data entry user interface |
| US7266490B2 (en) * | 2000-12-28 | 2007-09-04 | Robert Marc Zeidman | Apparatus and method for connecting hardware to a circuit simulation |
| US7062466B2 (en) * | 2000-12-06 | 2006-06-13 | The Belo Company | Method and system for operating online classified advertisements |
| WO2004046916A2 (en) * | 2002-11-18 | 2004-06-03 | Arm Limited | Exception types within a secure processing system |
| JP4439187B2 (ja) * | 2003-02-10 | 2010-03-24 | シャープ株式会社 | データ処理装置 |
| US20070266444A1 (en) * | 2004-12-03 | 2007-11-15 | Moshe Segal | Method and System for Securing Data Stored in a Storage Device |
| US20080275992A1 (en) * | 2005-02-09 | 2008-11-06 | Access Systems Americas, Inc. | System and method of managing connections between a computing system and an available network using a connection manager |
| US7954064B2 (en) * | 2005-10-27 | 2011-05-31 | Apple Inc. | Multiple dashboards |
| CN100428164C (zh) * | 2006-01-23 | 2008-10-22 | 联想(北京)有限公司 | 一种虚拟机系统及其设备访问方法 |
| US8261064B2 (en) * | 2007-02-27 | 2012-09-04 | L-3 Communications Corporation | Integrated secure and non-secure display for a handheld communications device |
| US20130145475A1 (en) | 2011-12-02 | 2013-06-06 | Samsung Electronics Co., Ltd. | Method and apparatus for securing touch input |
| US8812873B2 (en) * | 2012-09-26 | 2014-08-19 | Intel Corporation | Secure execution of a computer program using binary translators |
| US9886595B2 (en) | 2012-12-07 | 2018-02-06 | Samsung Electronics Co., Ltd. | Priority-based application execution method and apparatus of data processing device |
| US20140281560A1 (en) * | 2013-03-15 | 2014-09-18 | Ologn Technologies Ag | Secure zone on a virtual machine for digital communications |
| WO2014141206A1 (en) * | 2013-03-15 | 2014-09-18 | Ologn Technologies Ag | Secure zone on a virtual machine for digital communications |
| JP6067449B2 (ja) * | 2013-03-26 | 2017-01-25 | 株式会社東芝 | 情報処理装置、情報処理プログラム |
| CN105900108A (zh) * | 2013-11-15 | 2016-08-24 | Ctpg运营有限责任公司 | 用于印刷隐藏式安全条形码的系统和方法 |
| KR20150077774A (ko) * | 2013-12-30 | 2015-07-08 | 삼성전자주식회사 | 화면 전환 방법 및 그 장치 |
| KR101442539B1 (ko) * | 2013-12-31 | 2014-09-26 | 권용구 | 보안저장장치를 구비하는 저장 시스템 및 그 관리 방법 |
| JP2015215687A (ja) * | 2014-05-08 | 2015-12-03 | パナソニックIpマネジメント株式会社 | 可搬型決済端末装置 |
| CN105335672B (zh) * | 2014-06-16 | 2020-12-04 | 华为技术有限公司 | 一种安全模式提示方法及装置 |
| CN104318182B (zh) * | 2014-10-29 | 2017-09-12 | 中国科学院信息工程研究所 | 一种基于处理器安全扩展的智能终端隔离系统及方法 |
| US10754967B1 (en) * | 2014-12-15 | 2020-08-25 | Marvell Asia Pte, Ltd. | Secure interrupt handling between security zones |
| US20160239649A1 (en) * | 2015-02-13 | 2016-08-18 | Qualcomm Incorporated | Continuous authentication |
| US20160253651A1 (en) * | 2015-02-27 | 2016-09-01 | Samsung Electronics Co., Ltd. | Electronic device including electronic payment system and operating method thereof |
| CN104820573A (zh) * | 2015-05-27 | 2015-08-05 | 南京芯度电子科技有限公司 | 一种安全人机交互接口的系统及其实现方法 |
| CN105224403B (zh) * | 2015-09-17 | 2018-09-28 | 华为技术有限公司 | 一种中断处理方法及装置 |
| CN105447406B (zh) * | 2015-11-10 | 2018-10-19 | 华为技术有限公司 | 一种用于访问存储空间的方法与装置 |
| CN110059500A (zh) * | 2015-11-30 | 2019-07-26 | 华为技术有限公司 | 用户界面切换方法和终端 |
| US10740496B2 (en) * | 2017-02-13 | 2020-08-11 | Samsung Electronics Co., Ltd. | Method and apparatus for operating multi-processor system in electronic device |
-
2016
- 2016-03-15 CN CN201610145990.7A patent/CN105825128B/zh active Active
-
2017
- 2017-03-03 EP EP17765734.3A patent/EP3418934B1/en active Active
- 2017-03-03 WO PCT/CN2017/075643 patent/WO2017157192A1/zh not_active Ceased
-
2018
- 2018-09-14 US US16/131,548 patent/US10831905B2/en active Active
-
2020
- 2020-10-30 US US17/085,539 patent/US11574064B2/en active Active
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104115152A (zh) * | 2012-02-16 | 2014-10-22 | 三星电子株式会社 | 用于使用装置认证来保护数字内容的方法和设备 |
| CN103714276A (zh) * | 2012-10-01 | 2014-04-09 | Nxp股份有限公司 | 相连的设备架构、移动平台和用于安全的用户认证的系统 |
| US20140101755A1 (en) * | 2012-10-10 | 2014-04-10 | Research In Motion Limited | Mobile wireless communications device providing security features based upon wearable near field communication (nfc) device and related methods |
| CN104239783A (zh) * | 2014-09-19 | 2014-12-24 | 东软集团股份有限公司 | 一种特定信息安全输入系统及方法 |
| CN104933361A (zh) * | 2015-06-05 | 2015-09-23 | 浪潮电子信息产业股份有限公司 | 一种登录密码的保护装置及方法 |
| CN105825128A (zh) * | 2016-03-15 | 2016-08-03 | 华为技术有限公司 | 一种数据输入方法、装置及用户设备 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP3418934A4 * |
Also Published As
| Publication number | Publication date |
|---|---|
| BR112018068582A2 (pt) | 2019-02-12 |
| US20190018969A1 (en) | 2019-01-17 |
| US11574064B2 (en) | 2023-02-07 |
| CN105825128B (zh) | 2020-05-19 |
| US10831905B2 (en) | 2020-11-10 |
| EP3418934B1 (en) | 2025-02-19 |
| US20210049286A1 (en) | 2021-02-18 |
| EP3418934A4 (en) | 2018-12-26 |
| EP3418934A1 (en) | 2018-12-26 |
| CN105825128A (zh) | 2016-08-03 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11574064B2 (en) | Data input method and apparatus and user equipment | |
| US11874903B2 (en) | User interface switching method and terminal | |
| RU2635224C2 (ru) | Способ и аппарат для безопасного сенсорного ввода | |
| US10528252B2 (en) | Key combinations toolbar | |
| US9654603B1 (en) | Client-side rendering for virtual mobile infrastructure | |
| US20100132015A1 (en) | Apparatus and method for providing security information in virtual environment | |
| EP3255578B1 (en) | Interface display method of terminal and terminal | |
| CN103914646A (zh) | 触摸事件处理方法和实现所述方法的便携式设备 | |
| CN103136488A (zh) | 保护触摸输入的方法和装置 | |
| EP3210159B1 (en) | Technologies for secure input and display of virtual touch user interfaces | |
| US9444912B1 (en) | Virtual mobile infrastructure for mobile devices | |
| WO2020151518A1 (zh) | 应用开启方法、装置、终端及存储介质 | |
| WO2021077882A1 (zh) | 一种图像显示方法与电子设备 | |
| US12566829B2 (en) | Device access control | |
| KR20130058621A (ko) | 터치 신호를 처리하는 방법 및 그 계산 장치 | |
| CN116484438A (zh) | 信息处理方法和装置 | |
| CN106919361A (zh) | 一种语音提醒方法及装置 | |
| JP7176067B1 (ja) | 情報処理装置、及び制御方法 | |
| BR112018068582B1 (pt) | Método de entrada de dados, aparelho, e equipamento de usuário | |
| TW201439882A (zh) | 觸控事件處理方法和實現該方法的可攜式裝置 | |
| JP5831948B2 (ja) | 情報端末、情報入力用画像の表示方法、及びプログラム | |
| HK1249308B (zh) | 终端的控制方法、装置和存储介质 | |
| TW201717090A (zh) | 安全獨佔式平台 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2017765734 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 2017765734 Country of ref document: EP Effective date: 20180919 |
|
| REG | Reference to national code |
Ref country code: BR Ref legal event code: B01A Ref document number: 112018068582 Country of ref document: BR |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17765734 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 112018068582 Country of ref document: BR Kind code of ref document: A2 Effective date: 20180913 |