WO2017157192A1 - 一种数据输入方法、装置及用户设备 - Google Patents

一种数据输入方法、装置及用户设备 Download PDF

Info

Publication number
WO2017157192A1
WO2017157192A1 PCT/CN2017/075643 CN2017075643W WO2017157192A1 WO 2017157192 A1 WO2017157192 A1 WO 2017157192A1 CN 2017075643 W CN2017075643 W CN 2017075643W WO 2017157192 A1 WO2017157192 A1 WO 2017157192A1
Authority
WO
WIPO (PCT)
Prior art keywords
user
event
operating environment
environment
display area
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2017/075643
Other languages
English (en)
French (fr)
Inventor
张朋
王季
李辉
谢红亮
王小璞
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to BR112018068582-8A priority Critical patent/BR112018068582B1/pt
Priority to EP17765734.3A priority patent/EP3418934B1/en
Publication of WO2017157192A1 publication Critical patent/WO2017157192A1/zh
Priority to US16/131,548 priority patent/US10831905B2/en
Anticipated expiration legal-status Critical
Priority to US17/085,539 priority patent/US11574064B2/en
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • G06F21/83Protecting input, output or interconnection devices input devices, e.g. keyboards, mice or controllers thereof
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/74Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information operating in dual or compartmented mode, i.e. at least one secure mode
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/03Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
    • G06F2221/034Test or assess a computer or a system
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2105Dual mode as a secondary aspect

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a data input method, apparatus, and user equipment.
  • UE user equipment
  • the industry proposes the Trust Zone technology.
  • the technology proposes to divide the hardware components of the user equipment into a secure world and a normal world, and the security world can only transmit data through a monitor.
  • the operating system running the user equipment in the non-secure world the program running in the security world has higher security level than the program running in the non-secure world
  • the security world is isolated from the non-secure world by hardware, and the security world has access to the non-secure world. All the data in the security world, but not vice versa.
  • the user device starts up, it will first enter the security world, and then the program in the security world is responsible for switching to the non-secure world and starting the operating system of the user device.
  • Trust Zone technology proposes the concept of a secure world and a non-secure world to solve the problem of data input security in user devices.
  • users can operate in the provided data input environment.
  • Input events such as account numbers and passwords, but usually, when the data input environment running in the security world displays and inputs related content, the displayed content generally covers the entire display area of the user device, when the user needs to perform other
  • a short message popup window appears, and the user needs to view the short message.
  • the system needs to exit the data input environment under the instruction of the user to view the short message, causing the event that has been operated before. Lost.
  • the Trust Zone technology does not fully address the security of events generated by users running programs in the non-secure world of user devices, nor does it directly operate on events that run in a non-secure world.
  • the invention provides a data input method, device and user equipment, which can better improve the security of an event generated when a user runs a program running in a non-secure world of a user equipment, and realizes direct operation in a non-secure world.
  • the event in the operation can better improve the security of an event generated when a user runs a program running in a non-secure world of a user equipment, and realizes direct operation in a non-secure world. The event in the operation.
  • a data input method including: determining that a user is not in a preset display area When the UE performs the operation, the event corresponding to the operation is distributed to the first running environment for processing; wherein the preset display area is running in the second running environment of the UE, the second running environment
  • the security level is higher than the first running environment, and the security of the event generated when the user runs the program running in the non-secure world of the user device is better, and the event directly running in the non-secure world is realized. Take action.
  • the method further includes: receiving, by the user, an operation in an input area that is displayed by the display unit for the user, generating an event corresponding to the operation; determining that the user is Whether the event generated by the operation in the input area is a security input event; if the judgment result is yes, the preset display area is activated, and the preset display area is presented to the user through the display unit.
  • the starting the preset display area includes: backing up an event in the current first running environment; triggering the second running The interruption in the environment, through the interruption in the second operating environment, starts the preset display area.
  • the security of the generated event is
  • the preset display area and the input area presented simultaneously on the screen of the user device.
  • the event corresponding to the operation is distributed to the first running environment for processing, including: storing an event corresponding to the operation to the sharing a storage area, wherein the shared storage area is a storage area commonly used by the first running environment and the second running environment; storing the shared storage area by triggering an interruption in the first running environment The event is distributed to the first runtime environment for processing.
  • the foregoing stored in the shared storage area is triggered by triggering an interruption in the first operating environment
  • Distributing the event to the first execution environment for processing includes: triggering an interrupt in the first execution environment, and calling a daemon thread in the first security environment to pass the daemon thread into the shared storage area
  • the stored events are distributed to the first runtime environment for processing.
  • the method further includes: displaying, when the event corresponding to the operation is a security input event, displaying the preset display area, so that the user is in the preset display area An operation is performed wherein the secure input event is a data input event having a rights verification attribute.
  • the event corresponding to the operation is distributed to After processing in the first running environment, the method further includes: hiding the preset display area. Can increase the flexibility of user operations.
  • the preset display area includes Formatted input edit box.
  • the input edit box of the set format includes at least one of the following: a set input type It can be an input type such as a nine-keyboard numeric type, a nine-keyboard Chinese type, a nine-keyboard letter type, and a digital Chinese mix. Can improve the convenience of user operations.
  • a data input device having a function of implementing terminal behavior in a method design of any of the first to eighth possible implementations of the first aspect and the first aspect described above.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more modules corresponding to the functions described above.
  • a user terminal having a function for implementing terminal behavior in a method design of any of the first to eighth possible implementations of the first aspect and the first aspect.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more modules corresponding to the functions described above.
  • the structure of the terminal includes a memory and a processor, wherein the memory is configured to store a set of programs, and the processor is configured to invoke the memory storage
  • a computer storage medium for storing computer software instructions for use as a data input device, comprising a program designed to perform the above aspects.
  • the event corresponding to the operation is distributed to the first running environment for processing, so that the user is in the non-secure world of the user equipment.
  • the program running in the operation is operated, even if other non-security events need to be processed, the security of the event generated when the user runs the program running in the non-secure world of the user device can be guaranteed to be directly operated in the non-secure world. The event is handled.
  • FIG. 1 is a schematic diagram of a logical structure of a computing node applied by a method for data input according to an embodiment of the present invention
  • FIG. 2 is a schematic structural diagram of a user equipment according to an embodiment of the present invention.
  • FIG. 3 is a schematic structural diagram of a user equipment according to an embodiment of the present invention.
  • FIG. 4 is a schematic diagram of hardware components of a security world of a data input system according to an embodiment of the present invention.
  • FIG. 5 is a flowchart of a data input method according to an embodiment of the present invention.
  • FIG. 6 is a schematic diagram of an input edit box according to an embodiment of the present invention.
  • FIG. 7 is a schematic diagram of a preset display area and an input area according to an embodiment of the present invention.
  • FIG. 8 is a schematic diagram of input types set according to an embodiment of the present invention.
  • FIG. 9 is a flowchart of a data input method according to an embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of a data input device according to an embodiment of the present invention.
  • the present invention proposes In the technical solution, when it is determined that the user does not perform an operation on the UE in the preset display area, The corresponding event is distributed to the first operating environment for processing, wherein the preset display area is operated in the second operating environment of the UE, and the security level of the second operating environment is higher than the first operating environment, thereby It can better improve the security of events generated when a user runs a program running in a non-secure world of the user device, and directly operates an event running in a non-secure world.
  • the computing node may be a user equipment, and the user equipment may specifically be a desktop computer, a notebook computer, a smart phone or a tablet computer.
  • the hardware layer of the user equipment includes a central processing unit (CPU), a graphics processing unit (GPU), and the like, and may further include a memory and an input/output device (Input Device).
  • the input device may include a keyboard, a mouse, a touch screen, etc.
  • the output device may include a display device such as a liquid crystal display (LCD), a cathode ray tube (CRT), a holographic image (Holographic), Projector, etc.
  • LCD liquid crystal display
  • CRT cathode ray tube
  • Holographic holographic image
  • Projector Projector
  • the core library layer is the core part of the operating system, including input/output services, core services, graphics device interfaces, and graphics engine (Graphics Engine) for CPU and GPU graphics processing.
  • the graphics engine may include a 2D engine, a 3D engine, a composition, a frame buffer, and the like.
  • the core library layer also includes input method services. Among them, the input method service includes the input method service provided by the terminal.
  • the input method service further includes a data input method proposed by the embodiment of the present invention.
  • the terminal further includes a driving layer, a frame layer, and an application layer.
  • the driver layer may include a CPU driver, a GPU driver, a display controller driver, a Trust Zone Driver, and the like.
  • the framework layer may include a graphic service (Graphic Service), a system service (System service), a web service (Web Service), and a customer service (Customer Service); and the graphic service may include, for example, a widget (widget) or a canvas (Canvas). , Views, Render Script, etc.
  • the application layer may include a desktop, a media player, a browser, and the like.
  • the hardware and program instructions of the user equipment can include two operating environments at run time, which are a safe operating environment and a non-secure operating environment, and a non-secure operating environment, which can also be called a non-secure world.
  • the first operating environment and the safe operating environment, which are proposed by the embodiments of the present invention, may also be referred to as a security world, corresponding to the second operating environment proposed by the embodiments of the present invention.
  • the program running in a secure operating environment and the security of the hardware of the user device are higher than the programs running in the non-secure operating environment and the security level of the hardware of the user device.
  • the security world may also be a virtual running environment isolated from the operating system of the user equipment.
  • the user equipment 200 includes at least one processor 201, at least one network interface 204 or other user interface 203, and a memory 205, at least one communication.
  • Communication bus 202 is used to implement connection communication between these components.
  • the user device 200 optionally includes a user interface 203, including a display (such as the LCD, CRT, Holographic or Projector shown in FIG. 1), a keyboard or a pointing device (eg, a mouse, a trackball ( Trackball), touchpad or touch screen, etc.).
  • a display such as the LCD, CRT, Holographic or Projector shown in FIG. 1
  • a keyboard or a pointing device eg, a mouse, a trackball ( Trackball), touchpad or touch screen, etc.
  • the memory 205 may include read only memory and random access memory, and provides the processor 201 with program instructions and data stored in the memory 205.
  • a portion of the memory 205 may also include non-volatile random access memory (NVRAM).
  • NVRAM non-volatile random access memory
  • the memory 205 stores the following elements, executable modules or data structures, or Their subset, or their extension set:
  • the operating system 2051 includes various system program instructions that can be run, for example, at the framework layer, core library layer, driver layer, etc. shown in FIG. 1, for implementing various basic services and for processing hardware-based tasks.
  • the operating system not only looks to run in the first running environment, but also the operating system can be run in the second operating environment with the security level higher than the first operating environment.
  • the application 2052 includes various applications, such as a desktop, a media player, a browser, and an input method application, as shown in FIG. 1, for implementing various application services.
  • the various applications in the application 2052 can be applied in the first operating environment or in the second operating environment.
  • the implemented data is stored in the application 2052.
  • the memory 205 may also be referred to as a storage area, a program for storing a data input method, and a storage operating system.
  • the processor 201 is configured to execute the program instructions stored in the memory 205, and the processor 201 is configured to execute according to the obtained program instructions: when it is determined that the user does not perform an operation on the UE in the preset display area, the event corresponding to the operation is distributed to Processing is performed in the first operating environment.
  • the processor 201 is further configured to: when determining that the event corresponding to the operation is a security input event, displaying a preset display area, so that the user operates in the preset display area,
  • the security input event is a data input event with a permission verification attribute.
  • the processor 201 is specifically configured to: store an event corresponding to the operation into the shared storage area, where the shared storage area is a storage area commonly used by the first running environment and the second running environment;
  • the user equipment also includes an interrupt in the first operating environment (not shown in FIG. 2), the processor 201 triggers an interrupt in the first operating environment, and the interrupt in the first operating environment distributes the event stored in the shared storage area to Processing is performed in the first operating environment. Further, the processor 201 is specifically configured to: trigger an interrupt in the first running environment, and invoke a daemon thread in the first security environment to distribute the event stored in the shared storage area to the first running environment by using the daemon thread. deal with.
  • the processor 201 is specifically configured to: hide a preset display area.
  • the user equipment to which the data input method is applied is proposed by the embodiment of the present invention.
  • the user equipment may be a mobile phone, a tablet computer, a personal digital assistant (PDA), or the like.
  • PDA personal digital assistant
  • FIG. 3 it is a schematic diagram of one of the structural components of the user equipment 300.
  • the user equipment 300 mainly includes a memory 320, a processor 360, and an input unit 330, and the input unit 330 is configured to receive a generated event when the user performs an operation on the terminal.
  • the memory 320 is used to store program instructions for the operating system and various applications.
  • the memory 320 can be divided into a secure memory (also referred to as a secure storage area) and a non-secure memory (also Can be called non-secure storage area) and shared storage (also called shared storage area).
  • the non-secure memory is set in the first operating environment
  • the secure memory is set in the second operating environment
  • the second operating environment has a higher security level than the first operating environment.
  • a processor or interrupt set in the first operating environment cannot directly access the secure memory in the second operating environment.
  • a processor or interrupt in the second operating environment can access the non-secure processor set in the first operating environment and access the non-secure storage area.
  • the data stored in the shared memory is data that can be accessed by the processor or interrupt in the first operating environment and the second operating environment, that is, the first operating environment and the second
  • the processor in the operating environment, or an interrupt can access the shared memory to obtain the data in the shared memory.
  • processor 360 can be referred to the detailed description of the processor 201 described above, and details are not described herein.
  • the memory 320 may be a memory of the user equipment 300, and the memory may be divided into three storage spaces, corresponding to the security memory set in the first running environment, the non-secure memory set in the second environment, and the first operating environment and the first
  • the shared memory that can be accessed by applications or hardware in the running environment.
  • the space division of secure memory, non-secure memory, and shared memory can be divided into the same size, or can be divided into different sizes according to different storage data input events.
  • the input unit 330 in the user device can be used to receive numeric or character information input by the user, as well as to generate signal inputs related to user settings and function control of the user device 300.
  • the input unit 330 may include a touch panel 331.
  • the touch panel 331 can collect operations of the user (such as the user using a finger, a stylus, or the like on the touch panel 331), and drive and touch the panel according to preset program instructions. 331 corresponding connection device.
  • the touch panel 331 can include two parts: a touch detection device and a touch controller.
  • the touch detection device detects the touch orientation of the user, and detects a signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts the touch information into contact coordinates, and sends the touch information.
  • the processor 360 is provided and can receive commands from the processor 360 and execute them.
  • the touch panel 331 can be implemented in various types such as resistive, capacitive, infrared, and surface acoustic waves.
  • the input unit 330 may further include other input devices 332, which may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, switch buttons, etc.), trackballs, mice, joysticks, and the like. One or more of them.
  • the user device 300 can also include a display unit 340 that can be used to display information entered by the user or information provided to the user and various menu interfaces of the user device 300.
  • the display unit 340 can include a display panel 341.
  • the display panel 341 can be configured in the form of a liquid crystal display (LCD) or an organic light-emitting diode (OLED).
  • the touch panel 331 covers the display panel 341 to form a touch display screen, and the touch display screen provides a preset display area to the user.
  • the touch display screen 7 detects a touch operation thereon or nearby, it is transmitted to the processor 360 to determine the type of touch event, and then the processor 360 provides a corresponding visual output on the touch display screen according to the type of touch event.
  • the touch display screen comprises different display areas.
  • Each display area may contain interface elements such as at least one application icon and/or widget desktop control.
  • the processor 360 is a control center of the user device 300 that connects various portions of the entire handset using various interfaces and lines, and executes various types of the user device 300 by running or executing software programs and/or modules stored in the memory 320.
  • the user equipment 300 is monitored as a whole by functioning and processing the data.
  • the initialization setting includes initialization of the monitoring mode.
  • all memory (secure memory, non-secure memory, and shared memory) in the operating system of the user device is in the second operating environment. Then load the operating system image that needs to run in the first running environment into non-secure memory, and then go to the system image running the first running environment.
  • the user equipment 300 may further include an RF circuit 310 for providing a wirelessly connected WIFI module 380. And a power supply 390 and an audio circuit 370 for providing sound input and output.
  • the operating environment of the data input method is divided into a non-secure world (first operating environment) and a security world (second Operating environment).
  • first operating environment first operating environment
  • second Operating environment second Operating environment
  • the security of the entire system is obtained by dividing the hardware resources and software resources of the System on Chip (SoC) into two worlds.
  • SoC System on Chip
  • the SoC system includes a processor (Core) 401.
  • processor Core
  • each physical processor core provides two virtual cores, one is non-secure core (NS) and the other is security core (Secure), switching between non-secure core and security core.
  • the mechanism is called the monitor mode.
  • a non-secure core can only access system resources of the NS, and the security core can access all resources in the user equipment.
  • DMA direct memory access
  • Secure RAM Secure Random Access Memory
  • Secure Boot Secure Boot Read Only Memory
  • ROM read only memory
  • the SoC also includes a Trust Zone Address Space Controller (TZASC) 407 for supporting security interrupts, a Trust Zone Protection Space Controller (TZPC) 408, and a Dynamic Memory Controller (Dynamic Memory). Controller, DMC) 409, dynamic RAM (Dynamic RAM) 410, and the like.
  • the TZPC is used to set the security properties of the peripheral device. For example, it can set the display unit properties to be safe so that operations in the first runtime environment cannot access these devices that are set to be secure.
  • TZASC is used to control the security attribute partitioning of DRAM. It can set a part of DRAM to be secure, and the rest is set to be non-secure. If the processor in the first running environment initiates an access request to secure memory, the access request is made. Will be rejected. Access to the secure memory by the DMA in the first operating environment is denied, thus ensuring that the secure memory is not accessed by any operating system or hardware in the first operating environment.
  • the GIC is responsible for controlling all interrupt information. It can set certain interrupts to be safe and some interrupts to normal.
  • the SoC components are connected to each other through an Advanced eXtensible Interactive (AXI) 411.
  • the SoC and the peripheral device communicate through the Advanced eXtensible Interactive to Advanced Peripheral Bus Bridge (AXI2APB) bridge 412, and the AXI2APB can sense the security attribute of the event currently accessing the peripheral device.
  • AXI2APB rejects the access.
  • the secure RAM and the secure ROM are isolated by a hardware and software mechanism for storing the operating system running in the second operating environment.
  • the SoC system is initialized after power-on, and when the system starts, the system first enters the second running environment, and the initial setting is performed in the second running environment.
  • the initialization settings include initialization of the operating system in the second runtime environment.
  • all memory in the operating system of the user device is in the second operating environment.
  • the operating system image that needs to be run in the first running environment is loaded into the memory, and part of the memory is allocated to the first running environment, and the security attribute of the part of the memory allocated for the first running environment is set to be non-secure, and then Run the system image in the first runtime environment.
  • Step 1 The display unit presents an input area to the user, and the user operates in the input area to generate an event corresponding to the operation.
  • a numeric type of payment password is input in the input area presented by the display unit as an example for detailed description.
  • the display unit may include a touch panel having a touch property.
  • the user inputs a payment account in the input area by touching the touch panel, and continues to input the payment password after inputting the payment account.
  • the processor receives an event generated by the user operating the touch panel. Specifically, it may be a non-secure core in the first operating environment, and receive an event generated by the user operating the touch panel.
  • Step 2 The processor determines whether the event generated by the operation of the user in the input area is a security input event. If it is determined that it is not a secure input event, the user continues to operate in the input area, generating an event corresponding to the operation, and the processor continues to process the event.
  • a security input event is an event that requires the user to enter a password generated with a rights verification attribute. For example, for a certain payment application, after the user inputs the user name, the user is required to continue to input the payment password corresponding to the user name, and after the payment password and the user name match, the payment is completed. Then, the user continues to input an event corresponding to the operation of the payment password corresponding to the user name, that is, a security input event.
  • the security attribute of the input area presented by the display unit may be edited in advance.
  • the input area is set to a non-secure display area running in the first running environment and a secure display area running in the second running environment.
  • the input area in the first running environment may be an input edit box having a fixed shape and size, and the input edit box may be any shape, as shown in FIG. Take a square as an example for illustration.
  • the security attribute is set to a numeric attribute, that is, when the received event that the user operates in the input edit box is a trigger digital input, it is determined that the event is a secure input event.
  • the payment password of the user input numeric type is 12345678
  • the user payment password is 12345678
  • the user triggers a number it is determined that the data input event operated by the user is a secure input event.
  • Step 3 The processor triggers the TZ driver when it is determined that the data input event of the user operation is a security input event.
  • the TZ driver triggers a monitor mode used to switch between the first operating environment and the second operating environment, and the processor enters the second operating environment through the monitor.
  • Step 4 The processor backs up events in the current first running environment in the monitor mode.
  • the processor triggers an interrupt in the first operating environment, and saves the currently determined security input event to be shared in the storage area.
  • the interrupt in the second operating environment is triggered in the monitor mode, and the processor in the second operating environment, that is, the security core, is triggered by the interrupt in the second operating environment.
  • Step 5 The safety core (ie, the processor in the second operating environment) triggers an interrupt, starts a preset display area, and presents the preset display area to the user through the display unit. The operation after the user will operate in the preset display area.
  • the safety core ie, the processor in the second operating environment
  • the preset display area runs in the second running environment, and the preset display area may be a part of the user equipment screen, and the user may perform an input operation in the preset display area.
  • the preset display area may be an input edit box having a fixed shape and size, and having security attributes.
  • FIG. 7 a preset display area is started, and the preset display area and the input area can be simultaneously presented in the screen of the user equipment.
  • the preset display area can cover part of the input area and is superimposed on part of the input area.
  • the preset display area can include the set input type.
  • the input type set may be an input type of nine keyboard digital type, nine keyboard Chinese type (not shown in FIG. 8), nine keyboard letter type, digital Chinese mixture, etc. (not shown in FIG. 8). .
  • the preset display area is activated, assuming that the set input type is a display area of a nine-keyboard type, in the display unit, the display area of the nine-keyboard type is displayed to the user, and the user is preset in the nine-keyboard type. Enter the payment password in the display area.
  • step 6 the processor transfers the event to the second operating environment for processing.
  • the corresponding event generated by the user operating in the input area in the first running environment is determined to determine whether the event is a security input event, and when the determination result is yes, the first operating environment is performed.
  • the switching to the second operating environment is to display the preset display area for the user, so that the user can switch to the second operating environment for processing during the security input time generated by the operation of the user equipment, so that the user can be better protected.
  • step 7 the user operates in a preset display area of the user equipment.
  • Step 8 The processor in the second operating environment obtains an event corresponding to the operation.
  • step 5 For a detailed description of the preset display area, please refer to the detailed explanation in step 5 above, and no further details are provided.
  • the payment password of the user input type is also taken as an example.
  • the payment password is entered in the display area preset by the user.
  • Step 9 The processor determines whether the user operates the UE in the preset display area. If the determination result is yes, step 10 is performed; otherwise, step 12 is performed.
  • the user operates in a preset display area of the display unit, and may also operate outside the preset display area.
  • the event corresponding to the operation generated by the user is transmitted to the security core, and the security core determines whether the event corresponds to the operation falling in the preset display area.
  • the user presets the display area, inputs a payment password, and the security core determines whether the user's touch point is in the preset display area.
  • the user is operating, for example, when the user triggers the input of the account category (ie, operates in the input area), it is determined that the user does not operate in the preset display area, and vice versa, the user is determined to be in the preset display area. In the middle of the operation.
  • the user inputs the payment password 12345678 through the preset display area, and the user inputs 123.
  • the user equipment receives the short message display or the call display, the user clicks on the short message to display, and the user operates the user equipment at this time. Falling in the short message display box, in this case, it is determined that the user does not perform an operation on the UE in the preset display area.
  • Step 10 Continue to receive an event generated by the user performing an operation on the user equipment in the preset display area.
  • Step 11 After determining that the user ends the operation, the processor performs verification processing on the received event, and transfers to the first running environment, and feeds back the verification processing result to the user.
  • the received payment password is verified, and the verification result is fed back to the user.
  • Step 12 When the processor determines that the user does not perform an operation on the user equipment in the preset display area, the processor distributes the event corresponding to the operation to the first running environment for processing.
  • the event corresponding to the operation is distributed to the first running environment for processing, and the implementation manner thereof may include the following two methods:
  • the first way by triggering an interrupt, the event corresponding to the operation is distributed to the first running environment for processing.
  • the processor may trigger an interrupt in the second running environment, and store an event corresponding to the user's operation into the shared storage area by using the interrupt in the second running environment.
  • the processor is in monitor mode, The events stored in the shared storage area are distributed to the first running environment for processing by triggering an interruption in the first running environment.
  • the processor triggers a Fast Interrupt Reques (FIQ), stores an event corresponding to the user's operation in the shared storage area, and then the processor triggers an interrupt in the first running environment in the monitor mode, in the sharing The stored event is obtained in the storage area, and the interrupt in the first running environment distributes the obtained event to the first running environment for processing.
  • FIQ Fast Interrupt Reques
  • the second way is to distribute the event corresponding to the operation to the first running environment for processing by the daemon thread.
  • the daemon process is a long-lived process, usually independent of the user equipment and periodically performing certain tasks or waiting to process certain events.
  • the daemon is typically started when the system boots into the mount and terminates when the system is shut down.
  • the processor may store an event corresponding to the user's operation in the shared storage area by triggering an interrupt in the second running environment, and then trigger the first running environment in the monitor mode.
  • the interrupt triggers the daemon thread in the first running environment through the interrupt in the first running environment, the daemon thread obtains the stored event in the shared storage area, and the daemon thread sends the obtained event to the first running environment for processing.
  • the current event needs to be saved to the shared storage area before the event is distributed.
  • the interrupt in the second running environment stores the event in the shared storage area through the interrupt running in the second environment. It is also possible that the display unit driver transmits the event to the upper layer application, and stores the event in the shared storage area through the upper layer application.
  • the method further includes: hiding the preset display area.
  • the embodiment of the present invention further provides a data input method, as shown in FIG. 9, the specific processing flow is as follows:
  • step 91 the user operates in a preset display area of the user equipment.
  • Step 92 The processor in the second operating environment obtains an event corresponding to the operation.
  • step 5 For a detailed description of the preset display area, please refer to the detailed explanation in step 5 above, and details are not described here.
  • the payment password of the user input type is also taken as an example.
  • the user enters a payment password in a preset display area.
  • Step 93 The processor determines whether the user operates the UE in the preset display area. If the determination result is yes, step 94 is performed; otherwise, step 96 is performed.
  • Step 94 continuing to receive an event generated by the user performing an operation on the user equipment in the preset display area.
  • Step 95 After determining that the user ends the operation, the processor performs verification processing on the received event, and transfers the result to the first running environment, and feeds back the verification processing result to the user.
  • the received payment password is verified, and the verification result is fed back to the user.
  • Step 96 The processor distributes an event corresponding to the operation to the first running environment for processing when it is determined that the user does not perform an operation on the user equipment in the preset display area.
  • the event corresponding to the operation is distributed to the first running environment for processing, and the implementation manner thereof may include Two ways:
  • the first way by triggering an interrupt, the event corresponding to the operation is distributed to the first running environment for processing.
  • the processor may trigger an interrupt in the second running environment, and store an event corresponding to the user's operation into the shared storage area by using the interrupt in the second running environment.
  • the processor distributes the events stored in the shared storage area to the first running environment for processing by triggering the interrupt in the first running environment.
  • the processor triggers a Fast Interrupt Reques (FIQ), stores an event corresponding to the user's operation in the shared storage area, and then the processor triggers an interrupt in the first running environment in the monitor mode, in the sharing The stored event is obtained in the storage area, and the interrupt in the first running environment distributes the obtained event to the first running environment for processing.
  • FIQ Fast Interrupt Reques
  • the second way is to distribute the event corresponding to the operation to the first running environment for processing by the daemon thread.
  • the daemon process is a long-lived process, usually independent of the user equipment and periodically performing certain tasks or waiting to process certain events.
  • the daemon is typically started when the system boots into the mount and terminates when the system is shut down.
  • the processor may store an event corresponding to the user's operation in the shared storage area by triggering an interrupt in the second running environment, and then trigger the first running environment in the monitor mode.
  • the interrupt triggers the daemon thread in the first running environment through the interrupt in the first running environment, the daemon thread obtains the stored event in the shared storage area, and the daemon thread sends the obtained event to the first running environment for processing.
  • the current event needs to be saved to the shared storage area before the event is distributed.
  • the interrupt in the second running environment stores the event in the shared storage area through the interrupt running in the second environment. It is also possible that the display unit driver transmits the event to the upper layer application, and stores the event in the shared storage area through the upper layer application.
  • the method further includes: hiding the preset display area.
  • an embodiment of the present invention further provides a data input device, as shown in FIG. 10, the structural components thereof include:
  • the receiving unit 1001 is configured to receive an event generated by the user performing an operation on the UE in a preset display area.
  • the determining unit 1002 is configured to determine whether the user performs an operation in the preset display area.
  • the executing unit 1003 is configured to, when it is determined that the user does not perform an operation on the UE in the preset display area, distribute the event corresponding to the operation to the first running environment for processing.
  • the preset display area runs in the second running environment of the UE, and the security level of the second running environment is higher than the first running environment.
  • the executing unit 1003 is specifically configured to store an event corresponding to the operation into a shared storage area, where the shared storage area is the first operating environment and the second a storage area commonly used by the operating environment; the event stored in the shared storage area is distributed to the first operating environment for processing by triggering an interruption in the first operating environment.
  • the executing unit 1003 is specifically configured to trigger an interrupt in the first running environment, and invoke the A daemon thread in the first security environment to distribute the event stored in the shared storage area to the first execution environment for processing by the daemon thread.
  • the executing unit 1003 is further configured to: when it is determined that the event corresponding to the operation is a security input event, display the preset display area, so that the user performs in the preset display area.
  • the operation, wherein the secure input event is a data input event having a rights verification attribute.
  • the executing unit 1003 is further configured to hide the preset display area after the event corresponding to the operation is distributed to the first running environment for processing.
  • the preset display area includes an input edit box having a security attribute.
  • the present invention also provides a computer storage medium for storing computer software instructions for use with the data input device of the above aspect, comprising a program designed to perform the above aspects.
  • embodiments of the present invention can be provided as a method, apparatus (device), or computer program product. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or a combination of software and hardware. Moreover, the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, read-only optical disks, optical storage, etc.) including computer usable program code.
  • computer-usable storage media including but not limited to disk storage, read-only optical disks, optical storage, etc.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Automation & Control Theory (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • User Interface Of Digital Computer (AREA)
  • Storage Device Security (AREA)

Abstract

一种数据输入方法、装置及用户设备,该方法包括:在确定出用户未在预设的显示区域中对用户设备UE执行操作时,将与操作对应的事件分发至第一运行环境中进行处理;其中,预设的显示区域运行在UE的第二运行环境中,第二运行环境的安全级别高于第一运行环境。能够较好地提高用户在用户设备的非安全世界中运行的程序进行操作时生成的事件的安全性,实现直接对运行在非安全世界中的事件进行操作。

Description

一种数据输入方法、装置及用户设备
本申请要求在2016年3月15日提交中国专利局、申请号为201610145990.7、发明名称为“一种数据输入方法、装置及用户设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及通信技术领域,尤其是涉及一种数据输入方法、装置及用户设备。
背景技术
随着通信技术的不断发展,用户设备(user equipment,UE)能够提供的应用功能也越来与强大,个人财产、隐私等数据也就越来越多的存储在用户设备中。
用户设备的不断发展,其系统功能也不断增加,随着系统功能的增加,用户设备的系统中不可避免地出现安全漏洞,不法分子可以利用这些安全漏洞入侵用户设备的系统,获得用户设备中存储的数据,用户输入操作与终端显示的的安全性就无法得到保证。以用户通过用户设备实现费用支付为例,用户在通过用户设备提供的界面输入数据的过程中,不法分子可以通过截获用户的输入事件以及用户设备的显示内容获取该用户的输入数据,再通过分析用于费用支付的应用所对应的已经存储的历史数据,就可以得知用户的账号,进而加上获取的用户在用户设备中输入的口令,用户的资金就存在严重的风险。基于此,业界提出信任区域(Trust Zone)技术。该技术提出将用户设备的硬件组成分为安全世界(secure world)与非安全世界(normal world),且安全世界只有通过监视器(monitor)才可以传输数据。其中,在非安全世界中运行用户设备的操作系统,在安全世界中运行的程序的安全级别高于非安全世界中运行的程序,安全世界通过硬件与非安全世界隔离,安全世界有权访问非安全世界中的全部数据,但反之不行。用户设备启动时,会首先进入安全世界,然后由安全世界中的程序负责切换到非安全世界,启动用户设备的操作系统。Trust Zone技术提出了安全世界和非安全世界的概念,用于解决用户设备中数据输入安全的问题,通过提供运行在安全世界中的数据输入环境,用户可以在提供的数据输入环境中进行操作,输入账号、口令等事件,但是通常情况下,在安全世界中运行的数据输入环境在显示和输入相关的内容时,这些显示出的内容一般会覆盖用户设备的整个显示区域,当用户需要进行其它事件的操作时,例如用户正在输入用户名和密码时出现短消息弹窗,用户需要查看该短消息,此时在用户查看短消息的指令下系统需要退出数据输入环境,造成之前已经进行操作的事件丢失。因此,Trust Zone技术无法完全解决用户在用户设备的非安全世界中运行的程序进行操作时生成的事件的安全性,也无法直接对运行在非安全世界中的事件进行操作。
发明内容
本发明提供了一种数据输入方法、装置及用户设备,能够较好地提高用户在用户设备的非安全世界中运行的程序进行操作时生成的事件的安全性,实现直接对运行在非安全世界中的事件进行操作。
第一方面,提供了一种数据输入方法,包括:在确定出用户未在预设的显示区域中对 UE执行操作时,将与所述操作对应的事件分发至第一运行环境中进行处理;其中,所述预设的显示区域运行在所述UE的第二运行环境中,所述第二运行环境的安全级别高于所述第一运行环境,能够较好地提高用户在用户设备的非安全世界中运行的程序进行操作时生成的事件的安全性,实现直接对运行在非安全世界中的事件进行操作。
结合第一方面,在第一方面的第一种可能的实现方式中,该方法还包括:接收用户在显示单元为用户呈现的输入区域中进行操作,生成与操作对应的事件;判断该用户在输入区域中操作生成的事件是否是安全输入事件;如果判断结果为是,启动预设的显示区域,通过显示单元将预设的显示区域呈现给用户。
结合第一方面的第一种可能的实现方式,在第一方面的第二种可能的实现方式中,启动预设的显示区域,包括:备份当前第一运行环境中的事件;触发第二运行环境中的中断,通过第二运行环境中的中断,启动预设的显示区域。
对用户在运行在第一运行环境中的输入区域进行操作生成的对应的事件进行判断,确定该事件是否是安全输入事件,在判断结果为是时,进行第一运行环境到第二运行环境的切换,即为用户展示预设的显示区域,以使用户在对用户设备进行操作生成的安全输入时间可以切换到第二运行环境中进行处理,这样,能够较好地保障用户在用户设备中操作时生成的事件的安全性。
结合第一方面至第一面方面的第二种可能的实现方式中的任一一种可能的实现方式,在第一面的第三种可能的实现方式中,预设的显示区域和输入区域,同时呈现在用户设备的屏幕中。
结合第一方面,在第一方面的第四种可能的实现方式中,将与所述操作对应的事件分发至第一运行环境中进行处理,包括:将与所述操作对应的事件存储至共享存储区中,其中所述共享存储区是所述第一运行环境和所述第二运行环境共同使用的存储区;通过触发所述第一运行环境中的中断,将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
结合第一方面的第四种可能的实现方式,在第一方面的第五种可能的实现方式中,通过触发所述第一运行环境中的中断,将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理,包括:触发所述第一运行环境中的中断,并调用所述第一安全环境中的守护线程,以通过所述守护线程将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
结合第一方面至第一方面的第五种可能实现的方式中的任一一种可能实现方式,在第一方面的第六种可能的实现方式中,在确定出用户未在预设的显示区域中对用户设备UE执行操作之前,还包括:在确定出与所述操作对应的事件是安全输入事件时,显示所述预设的显示区域,以使用户在所述预设的显示区域中进行操作,其中所述安全输入事件是具有权限验证属性的数据输入事件。
结合第一方面至第一方面的第六种可能实现的方式中的任一一种可能实现方式,在第一方面的第七种可能的实现方式中,将与所述操作对应的事件分发至第一运行环境中进行处理之后,还包括:隐藏所述预设的显示区域。能够提高用户操作的灵活性。
结合第一方面至第一方面的第六种可能实现的方式中的任一一种可能的实现方式,在第一方面的第八种可能的实现方式中,所述预设的显示区域包含设定格式的输入编辑框。
结合第一方面的第八种可能的实现方式,在第一方面的第九种可能的实现方式中,所述设定格式的输入编辑框包含下述中的至少一种:设定的输入类型可以是九键盘数字类型、九键盘中文类型、九键盘字母类型、数字中文混合等输入类型。可以提高用户操作的便利性。
第二方面,提供一种数据输入装置,该数据输入装置具有实现上述第一方面和第一方面的第一种至第八种可能的实现方式中的任一种方法设计中终端行为的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。
第三方面,提供了一种用户终端,该用户终端具有实现上述第一方面和第一方面的第一种至第八种可能的实现方式中的任一种方法设计中终端行为的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。
结合第三方面,在第三方面的第一种可能的实现方式中,终端的结构包括存储器和处理器,其中,所述存储器用于存储一组程序,所述处理器用于调用所述存储器存储的程序以执行如上述第一方面和第一方面的第一种至第八种可能的实现方式中的任一种所述的方法。
第四方面,提供了一种计算机存储介质,用于储存为数据输入装置所用的计算机软件指令,其包含用于执行上述方面所设计的程序。
通过采用上述技术方案,在确定出用户未在预设的显示区域中对UE执行操作时,将与操作对应的事件分发至第一运行环境中进行处理,这样,用户在用户设备的非安全世界中运行的程序进行操作时,即使需要处理其它非安全事件,也能够保证用户在用户设备的非安全世界中运行的程序进行操作时生成的事件的安全性,实现直接对运行在非安全世界中的事件进行操作。
附图说明
图1本发明实施例提供的数据输入的方法应用的计算节点的逻辑结构示意图;
图2为本发明实施例提出的用户设备结构组成示意图;
图3为本发明实施例提出的用户设备结构组成示意图;
图4为本发明实施例提供的数据输入系统的安全世界硬件组成示意图;
图5为本发明实施例提出的数据输入方法流程图;
图6为本发明实施例提出的输入编辑框示意图;
图7为本发明实施例提出的预设的显示区域和输入区域示意图;
图8为本发明实施例提出的设定的输入类型示意图;
图9为本发明实施例提出的数据输入方法流程图;
图10为本发明实施例提出的数据输入装置结构组成示意图。
具体实施方式
针对Trust Zone技术无法完全解决用户在用户设备的非安全世界中运行的程序进行操作时生成的事件的安全性,也无法直接对运行在非安全世界中的事件进行操作的问题,本发明提出的技术方案中,在确定出用户未在预设的显示区域中对UE执行操作时,将与操 作对应的事件分发至第一运行环境中进行处理,其中,预设的显示区域运行在所述UE的第二运行环境中,第二运行环境的安全级别高于所述第一运行环境,从而能够较好地提高用户在用户设备的非安全世界中运行的程序进行操作时生成的事件的安全性,实现直接对运行在非安全世界中的事件进行操作。
下面将结合各个附图对本发明实施例技术方案的主要实现原理、具体实施方式及其对应能够达到的有益效果进行详细地阐述。
本发明实施例提出的技术方案中,以图1为例介绍本发明实施例提供的数据输入的方法应用的计算节点的逻辑结构。该计算节点可以是用户设备,该用户设备具体可以为桌面计算机、笔记本电脑、智能手机或平板电脑等。如图1所示,该用户设备的硬件层包括中央处理器(Center Processing Unit,CPU)、图形处理器(Graphic Processing Unit,GPU)等,当然还可以包括存储器、输入/输出设备(Input Device)、网络接口等,输入设备可包括键盘、鼠标、触摸屏等,输出设备可包括显示设备如液晶显示器(Liquid Crystal Display,LCD)、阴极射线管(Cathode Ray Tube,CRT)、全息成像(Holographic)、投影(Projector)等。在硬件层之上可运行有操作系统(如Android等)以及一些应用程序。核心库层是操作系统的核心部分,包括输入/输出服务、核心服务、图形设备接口以及实现CPU、GPU图形处理的图形引擎(Graphics Engine)等。图形引擎可包括2D引擎、3D引擎、合成器(Composition)、帧缓冲区(Frame Buffer)等。核心库层还包括输入法服务。其中,输入法服务包括终端自带的输入法服务。输入法服务还包含本发明实施例提出的数据输入方法。除此之外,该终端还包括驱动层、框架层和应用层。驱动层可包括CPU驱动(driver)、GPU驱动、显示控制器驱动、安全区域驱动(Trust Zone Driver)等。框架层可包括图形服务(Graphic Service)、系统服务(System service)、网页服务(Web Service)和用户服务(Customer Service)等;图形服务中,可包括如微件(Widget)、画布(Canvas)、视图(Views)、Render Script等。应用层可包括桌面(launcher)、媒体播放器(Media Player)、浏览器(Browser)等。
在Trust Zone技术中,用户设备的硬件和程序指令在运行时,可包含两个运行环境,分别是安全运行环境和非安全运行环境,非安全运行环境,也可以称之为非安全世界,对应本发明实施例提出的第一运行环境,安全运行环境,也可以称之为安全世界,对应本发明实施例提出的第二运行环境。在安全运行环境中运行的程序以及用户设备的硬件的安全级别要高于非安全运行环境中运行的程序以及用户设备的硬件的安全级别。其中,安全世界也可以是用户设备的操作系统中隔离出来的虚拟运行环境。
本发明实施例提出的数据输入方法所应用的用户设备,如图2所示,该用户设备200包括:至少一个处理器201,至少一个网络接口204或者其他用户接口203,存储器205,至少一个通信总线202。通信总线202用于实现这些组件之间的连接通信。该用户设备200可选的包含用户接口203,包括显示器(例如图1所示的LCD、CRT、全息成像(Holographic)或者投影(Projector)等),键盘或者点击设备(例如,鼠标,轨迹球(trackball),触感板或者触摸屏等)。
存储器205可以包括只读存储器和随机存取存储器,并向处理器201提供存储器205中存储的程序指令和数据。存储器205的一部分还可以包括非易失性随机存取存储器(NVRAM)。
在一些实施方式中,存储器205存储了如下的元素,可执行模块或者数据结构,或者 他们的子集,或者他们的扩展集:
操作系统2051,包含各种系统程序指令,该程序指令可运行在例如图1所示的框架层、核心库层、驱动层等,用于实现各种基础业务以及处理基于硬件的任务。
其中,在本发明实施例提出的技术方案中,操作系统不仅看运行在第一运行环境中,操作系统还可运行在安全级别高于第一运行环境的第二运行环境中。
应用程序2052,包含各种应用程序,例如图1所示的桌面(launcher)、媒体播放器(Media Player)、浏览器(Browser)以及输入法应用等,用于实现各种应用业务。
应用程序2052中的各种应用程序,可以应用在第一运行环境中,也可以运行在第二运行环境中,在本发明实施例上述提出的技术方案中,应用程序2052中,存储的实现数据输入方法的程序指令,该程序指令运行在第二运行环境中。
在本发明实施例中,存储器205也可以称之为存储区域,用于存储数据输入方法的程序,以及存储操作系统。
处理器201通过调用存储器205存储的程序指令,处理器201用于按照获得的程序指令执行:在确定出用户未在预设的显示区域中对UE执行操作时,将与操作对应的事件分发至第一运行环境中进行处理。
可选地,作为一个实施例,处理器201还用于:在确定出与操作对应的事件是安全输入事件时,显示预设的显示区域,以使用户在预设的显示区域中进行操作,其中安全输入事件是具有权限验证属性的数据输入事件。
进一步地,处理器201具体用于:将与操作对应的事件存储至共享存储区中,其中共享存储区是第一运行环境和第二运行环境共同使用的存储区;
该用户设备还包括第一运行环境中的中断(图2中未示出),处理器201触发第一运行环境中的中断,第一运行环境中的中断将共享存储区中存储的事件分发至第一运行环境中进行处理。进一步地,处理器201具体用于:触发第一运行环境中的中断,并调用第一安全环境中的守护线程,以通过守护线程将共享存储区中存储的事件分发至第一运行环境中进行处理。
进一步地,处理器201具体用于:隐藏预设的显示区域。
本发明实施例提出的提出数据输入方法所应用的用户设备,该用户设备可以为手机、平板电脑、个人数字助理(Personal Digital Assistant,PDA)等。参考图3所示,为用户设备300的其中一种结构组成示意图。
该用户设备300主要包括,存储器320、处理器360及输入单元330,该输入单元330用于接收用户在终端上进行操作时的生成的事件。该存储器320用于存储操作系统和各种应用程序的程序指令。
其中,本发明实施例提出的技术方案中,提出了第一运行环境和第二运行环境,相应地,存储器320可以划分为安全存储器(也可以称之为安全存储区)、非安全存储器(也可以称之为非安全存储区)和共享存储器(也可以称之为共享存储区)。非安全存储器设置在第一运行环境中,安全存储器设置在第二运行环境中,第二运行环境的安全级别高于第一运行环境。设置在第一运行环境中的处理器或中断,不能够直接访问第二运行环境中的安全存储器。在第二运行环境中的处理器或中断,可以访问设置在第一运行环境中的非安全处理器,以及访问非安全存储区。对于共享存储器,共享存储器中存储的数据,是第一运行环境和第二运行环境中的处理器或中断都可以访问的数据,即第一运行环境和第二 运行环境中的处理器,或中断,可以通过访问共享存储器,获得共享存储器中的数据。
可以理解的,处理器360的具体实现功能可参见上述处理器201的详细阐述,不再赘述。
存储器320可以是用户设备300的内存,该内存可以划分为三个存储空间,分别对应设置在第一运行环境中的安全内存、设置在第二环境中的非安全内存以及第一运行环境和第二运行环境中的应用程序或者硬件都可以访问的共享内存。安全内存、非安全内存以及共享内存的空间划分,可以划分相同的大小,也可以根据存储数据输入事件的不同,划分不同的大小。
用户设备中的输入单元330可用于接收用户输入的数字或字符信息,以及产生与用户设备300的用户设置以及功能控制有关的信号输入。具体地,本发明实施例中,该输入单元330可以包括触控面板331。触控面板331,可收集用户在其上(比如用户使用手指、触笔等任何适合的物体或附件在触控面板331上)的操作,并根据预先设定的程序指令,驱动与触控面板331相应的连接装置。可选的,触控面板331可包括触摸检测装置和触摸控制器两个部分。其中,触摸检测装置检测用户的触摸方位,并检测触摸操作带来的信号,将信号传送给触摸控制器;触摸控制器从触摸检测装置上接收触摸信息,并将它转换成触点坐标,再送给该处理器360,并能接收处理器360发来的命令并加以执行。此外,可以采用电阻式、电容式、红外线以及表面声波等多种类型实现触控面板331。除了触控面板331,输入单元330还可以包括其他输入设备332,其他输入设备332可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆等中的一种或多种。
该用户设备300还可以包括显示单元340,该显示单元340可用于显示由用户输入的信息或提供给用户的信息以及用户设备300的各种菜单界面。该显示单元340可包括显示面板341,可选的,可以采用液晶显示器(Liquid Crystal Display,LCD)或有机发光二极管(Organic Light-Emitting Diode,OLED)等形式来配置显示面板341。
请参考图3所示,本发明实施例中,该触控面板331覆盖该显示面板341,形成触摸显示屏,触摸显示屏提供给用户预设的显示区域。当该触摸显示屏7检测到在其上或附近的触摸操作后,传送给处理器360以确定触摸事件的类型,随后处理器360根据触摸事件的类型在触摸显示屏上提供相应的视觉输出。
本发明实施例中,该触摸显示屏包括不同的显示区域。每一个显示区域可以包含至少一个应用程序的图标和/或widget桌面控件等界面元素。
该处理器360是用户设备300的控制中心,利用各种接口和线路连接整个手机的各个部分,通过运行或执行存储在该存储器320内的软件程序和/或模块,执行用户设备300的各种功能和处理数据,从而对用户设备300进行整体监控。
可以理解的,该处理器360初始化时,首先进入第二运行环境,在第二运行环境中进行操作系统的初始化设置,以保证操作系统的安全性。
其中,初始化设置包括监控模式的初始化。在系统初始化过程中,用户设备的操作系统中的所有内存(安全内存、非安全内存以及共享内存)处于第二运行环境中。然后将需要在第一运行环境中运行的操作系统镜像加载到非安全内存中,再转至运行第一运行环境中的系统镜像。
可选的该用户设备300还可以包括RF电路310,用于提供无线连接的WIFI模块380, 以及电源390和用于提供声音输入输出的音频电路370。
基于图3所示的带有触摸显示屏的用户设备300,本发明实施例提出的技术方案中,将数据输入方法的运行环境划分为非安全世界(第一运行环境)和安全世界(第二运行环境)。在硬件组成上,一个用户设备中的只有一套硬件结构。但是,该些硬件中,部分硬件是的安全属性是可以进行动态设置的,而其他硬件的安全属性是固定不变的。整个系统的安全是通过将片上系统(System on Chip,SoC)的硬件资源和软件资源划分到两个世界获得的。安全世界和非安全世界是安全子系统对应的安全世界,以及其他子系统对应的非安全世界。
如图4所示,SoC系统包括处理器(Core)401。在处理器架构上,每个物理的处理器核提供两个虚拟核,一个是非安全核(Non-secure,NS),另一个是安全核(Secure),在非安全核和安全核之间切换的机制称之为监控(monitor)模式。非安全核只能访问NS的系统资源,而安全核能够访问用户设备中的所有资源。在SoC中,还包括直接内存访问(Direct Memory Access,DMA)402、安全的随机存储器(Secure Random Access Memory,Secure RAM)403、用于启动的安全只读存储器(Secure Boot Read Only Memory,Secure Boot ROM)404、集成Trust Zone支持的可在第一运行环境与第二运行环境下工作的中断控制器(Generic Interrupt Controller,GIC)405,在实现上可能会单独实现一个Trust Zone中断控制器(Trust Zone Interrupt Controller,TZIC)406。SoC还包括用于支持安全中断的信任区域地址空间控制器(Trust Zone Address Space Controller,TZASC)407、信任区域地址空间保护控制器(Trust Zone Protection Controller,TZPC)408、动态内存控制器(Dynamic Memory Controller,DMC)409、动态RAM(Dynamic RAM)410等。TZPC用于设置外围设备的安全属性,例如,它可设置显示单元属性为安全的,这样在第一运行环境中的操作就无法访问这些设置为安全的设备。TZASC用于控制对DRAM的安全属性划分,它可将一部分DRAM设置为安全的,其余部分设为非安全的,如果处于第一运行环境中的处理器对安全的内存发起访问请求时该访问请求会被拒绝。第一运行环境中的DMA对安全内存的访问会被拒绝,这样保证了安全内存不被第一运行环境下的任何操作系统或硬件访问。GIC负责控制所有中断信息,它可将某些中断设置为安全的,某些中断设置为普通的。
SoC组件之间通过高速可拓展接口(Advanced eXtensible Interactive,AXI)411相互连接。SoC与外围设备是通过高速可拓展接口先进的可扩展的外围总线桥(Advanced eXtensible Interactive to Advanced Peripheral Bus Bridge,AXI2APB)桥412进行通信,AXI2APB可感知当前访问外围设备的事件的安全属性,当第一运行环境中的事件访问一个属性被设为安全的外围设备时,AXI2APB会拒绝该访问。安全RAM与安全ROM利用软硬件机制进行隔离,它们用于存储第二运行环境中运行的操作系统。
本发明实施例提出的数据输入方法中,SoC系统在上电后进行初始化,系统在启动时,首先进入第二运行环境,在第二运行环境中进行初始化设置。初始化设置包括第二运行环境中的操作系统的初始化。在系统初始化过程中,用户设备的操作系统中的所有内存处于第二运行环境中。然后将需要在第一运行环境中运行的操作系统镜像加载到内存,并给第一运行环境分配部分内存,为第一运行环境分配的部分内存的安全属性被设置为非安全的,再转至运行第一运行环境中的系统镜像。
下面详细阐述本发明实例提出的数据输入方法的处理流程,首先阐述将第一运行环境中的事件转入到第二运行环境中处理的具体实施过程,如图5所示:
步骤1,显示单元为用户呈现输入区域,用户在该输入区域中进行操作,生成与操作对应的事件。
以用户在显示单元呈现的输入区域中输入数字类型的支付口令为例进行详细阐述。显示单元可以包含具有触摸性质的触控面板。用户通过触摸触控面板,在输入区域中输入支付账号,在输入支付账号后,继续输入支付口令。处理器接收用户操作触控面板生成的事件。具体地,可以是第一运行环境中的非安全核,接收用户操作触控面板生成的事件。
步骤2,处理器判断该用户在输入区域中操作生成的事件是否是安全输入事件。如果确定出不是安全输入事件,用户继续在输入区域中进行操作,生成与操作对应的事件,处理器继续处理该事件。
安全输入事件,是指需要用户输入具有权限验证属性的口令生成的事件。例如,某一支付应用,在用户输入用户名之后,需要用户继续输入与该用户名对应的支付口令,在支付口令和用户名匹配之后,完成支付。则用户继续输入与该用户名对应的支付口令的操作对应的事件,即为安全输入事件。
其中,可以预先对显示单元呈现的输入区域的安全属性进行编辑。将输入区域设置为运行在第一运行环境中的非安全显示区域和运行在第二运行环境中的安全显示区域。例如,在具体实施过程中,如图6所示,第一运行环境中的输入区域可以是一个具有固定形状和大小的输入编辑框,输入编辑框可以是任何形状,如图6所示,仅以方形为例进行示意。在进行设置时,可以对该输入编辑框增加一个安全属性,并对安全属性进行设置。例如,安全属性设置为数字属性,即当接收到的用户在该输入编辑框中操作的事件是触发数字输入时,判断该事件是安全输入事件。
后文将继续以用户输入数字类型的支付口令为例进行详细阐述。在用户将要输入数字类型的支付口令时,例如用户支付口令为12345678,用户触发数字时,确定用户操作的数据输入事件是安全输入事件。
步骤3,处理器在确定出用户操作的数据输入事件是安全输入事件时,触发TZ driver。TZ driver触发第一运行环境和第二运行环境之间进行切换所使用的监控(monitor)模式,处理器将通过monitor,进入到第二运行环境。
步骤4,处理器在monitor模式中备份当前第一运行环境中的事件。处理器触发第一运行环境中的中断,将当前确定出的安全输入事件保存才共享存储区中。在安全输入事件存储完毕之后,monitor模式下触发第二运行环境中的中断,通过第二运行环境中的中断,触发第二运行环境中的处理器,即安全核。
步骤5,安全核(即第二运行环境中的处理器)触发中断,启动预设的显示区域,通过显示单元将预设的显示区域呈现给用户。用户之后的操作,将在预设的显示区域中进行操作。
预设的显示区域,运行在第二运行环境中,该预设的显示区域可以是用户设备屏幕中的一部分,用户可以在该预设的显示区域中进行输入操作。相应地,该预设的显示区域可以是具有固定形状和大小,以及具备安全属性的输入编辑框。如图7所示,启动预设的显示区域,该预设的显示区域和输入区域,可以同时呈现在用户设备的屏幕中。预设的显示区域可以覆盖部分输入区域,叠加在部分输入区域之上。预设的显示区域,可以包括设定的输入类型。如图8所示,设定的输入类型可以是九键盘数字类型、九键盘中文类型(图8中未示出)、九键盘字母类型、数字中文混合等输入类型(图8中未示出)。
例如,启动预设的显示区域,假设设定的输入类型是九键盘数字类型的显示区域,在显示单元中,将九键盘数字类型的显示区域展示给用户,用户在九键盘数字类型的预设的显示区域中输入支付口令。
步骤6,处理器将事件转入到第二运行环境中进行处理。
通过采用上述技术方案,对用户在运行在第一运行环境中的输入区域进行操作生成的对应的事件进行判断,确定该事件是否是安全输入事件,在判断结果为是时,进行第一运行环境到第二运行环境的切换,即为用户展示预设的显示区域,以使用户在对用户设备进行操作生成的安全输入时间可以切换到第二运行环境中进行处理,这样,能够较好地保障用户在用户设备中操作时生成的事件的安全性。
其次阐述将第二运行环境中的事件分发到第一运行环境中处理的具体实施过程,如图5所示:
步骤7,用户在用户设备的预设的显示区域中进行操作。
步骤8,第二运行环境中的处理器获得与该操作对应的事件。
预设的显示区域的详细阐述请参见上述步骤5中的详细阐述,不再赘述。
同样以用户输入数字类型的支付口令为例进行阐述。在步骤8中,用户预设的显示区域中输入支付口令。
步骤9,处理器判断用户是否在预设的显示区域中对UE进行操作,如果判断结果为是,执行步骤10,反之,执行步骤12。
具体地,用户在显示单元的预设的显示区域中进行操作,也可以在预设的显示区域之外进行操作。与用户的操作生成的对应的事件,传输到安全核中,安全核判断该事件是否对应落入在预设的显示区域中的操作。例如用户预设的显示区域,输入支付口令,安全核确定用户的触摸点是否在预设的显示区域中。用户在操作时,如用户又触发输入账号类目时(即在输入区域中操作),则确定该用户未在预设的显示区域中进行操作,反之,确定该用户是在预设的显示区域中进行操作。例如,用户通过预设的显示区域输入支付口令12345678,用户输入了123,此时,用户设备接收到短消息展示、或者来电展示时,用户点击该短消息展示,此时用户对用户设备的操作落在短消息展示框中,该种情况下即确定用户未在预设的显示区域中对UE执行操作。
步骤10,继续接收用户在预设的显示区域中对用户设备执行操作生成的事件。
步骤11,处理器在确定出用户结束操作时,对接收到的事件进行验证处理,并转入到第一运行环境中,将验证处理结果反馈给用户。
例如,当用户结束输入支付口令时,在第二运行环境中,对接收到的支付口令进行验证,将验证结果反馈给用户。
步骤12,处理器在确定出用户未在预设的显示区域中对用户设备执行操作时,将与该操作对应的事件分发至第一运行环境中进行处理。
其中,将与操作对应的事件分发至第一运行环境中进行处理,其实施方式可以包含下述两种方式:
第一种方式:可以通过触发中断,实现将与操作对应的事件分发至第一运行环境中进行处理。
上述第一种方式中,处理器可以触发第二运行环境中的中断,通过第二运行环境中的中断,将与用户的操作对应的事件存储至共享存储区中。此时,处理器在monitor模式中, 通过触发第一运行环境中的中断,将共享存储区中存储的事件分发至第一运行环境中进行处理。
例如,处理器触发快速中断请求(Fast Interrupt Reques,FIQ),将与用户的操作对应的事件存储至共享存储区中,然后处理器在monitor模式中,触发第一运行环境中的中断,在共享存储区中获得存储的事件,第一运行环境中的中断将获得的事件分发至第一运行环境中进行处理。
第二种方式:通过守护线程实现将与操作对应的事件分发至第一运行环境中进行处理。
上述第二种方式中,守护进程,是一个生存期较长的进程,通常独立于用户设备并且周期性地执行某种任务或等待处理某些发生的事件。守护进程一般在系统引导装入时启动,在系统关闭时终止。在上述第二种方式中,处理器可以通过触发第二运行环境中的中断,将与用户的操作对应的事件存储至共享存储区中,然后在monitor模式中,通过触发第一运行环境中的中断,通过第一运行环境中的中断,触发第一运行环境中的守护线程,守护线程在共享存储区中获得存储的事件,守护线程将获得的事件发送给第一运行环境中进行处理。
在上述两种将与操作对应的事件分发至第一运行环境中进行处理的具体实施方式中,在将事件进行分发之前,需要将当前事件保存到共享存储区中,此时,可以通过触发第二运行环境中的中断,通过第二环境中运行的中断,将事件存储在共享存储区中。也可以是显示单元驱动将事件传输给上层应用,通过上层应用将事件存储在共享存储区中。
可选地,在将与操作对应的事件分发至第一运行环境中进行处理之后,还包括:隐藏预设的显示区域。
例如,用户在输入12345678之后,不需要再进行任何输入,此时处理器隐藏预设的显示区域。
相应地,本发明实施例还提出一种数据输入方法,如图9所示,其具体处理流程如下述:
步骤91,用户在用户设备的预设的显示区域中进行操作。
步骤92,第二运行环境中的处理器获得与该操作对应的事件。
预设的显示区域的详细阐述请参见上述步骤5中的详细阐述,这里不再赘述。
同样以用户输入数字类型的支付口令为例进行阐述。用户在预设的显示区域中输入支付口令。
步骤93,处理器判断用户是否在预设的显示区域中对UE进行操作,如果判断结果为是,执行步骤94,反之,执行步骤96。
步骤94,继续接收用户在预设的显示区域中对用户设备执行操作生成的事件。
步骤95,处理器在确定出用户结束操作时,对接收到的事件进行验证处理,并转入到第一运行环境中,将验证处理结果反馈给用户。
例如,当用户结束输入支付口令时,在第二运行环境中,对接收到的支付口令进行验证,将验证结果反馈给用户。
步骤96,处理器在确定出用户未在预设的显示区域中对用户设备执行操作时,将与该操作对应的事件分发至第一运行环境中进行处理。
其中,将与操作对应的事件分发至第一运行环境中进行处理,其实施方式可以包含下 述两种方式:
第一种方式:可以通过触发中断,实现将与操作对应的事件分发至第一运行环境中进行处理。
上述第一种方式中,处理器可以触发第二运行环境中的中断,通过第二运行环境中的中断,将与用户的操作对应的事件存储至共享存储区中。此时,处理器在monitor模式中,通过触发第一运行环境中的中断,将共享存储区中存储的事件分发至第一运行环境中进行处理。
例如,处理器触发快速中断请求(Fast Interrupt Reques,FIQ),将与用户的操作对应的事件存储至共享存储区中,然后处理器在monitor模式中,触发第一运行环境中的中断,在共享存储区中获得存储的事件,第一运行环境中的中断将获得的事件分发至第一运行环境中进行处理。
第二种方式:通过守护线程实现将与操作对应的事件分发至第一运行环境中进行处理。
上述第二种方式中,守护进程,是一个生存期较长的进程,通常独立于用户设备并且周期性地执行某种任务或等待处理某些发生的事件。守护进程一般在系统引导装入时启动,在系统关闭时终止。在上述第二种方式中,处理器可以通过触发第二运行环境中的中断,将与用户的操作对应的事件存储至共享存储区中,然后在monitor模式中,通过触发第一运行环境中的中断,通过第一运行环境中的中断,触发第一运行环境中的守护线程,守护线程在共享存储区中获得存储的事件,守护线程将获得的事件发送给第一运行环境中进行处理。
在上述两种将与操作对应的事件分发至第一运行环境中进行处理的具体实施方式中,在将事件进行分发之前,需要将当前事件保存到共享存储区中,此时,可以通过触发第二运行环境中的中断,通过第二环境中运行的中断,将事件存储在共享存储区中。也可以是显示单元驱动将事件传输给上层应用,通过上层应用将事件存储在共享存储区中。
可选地,在将与操作对应的事件分发至第一运行环境中进行处理之后,还包括:隐藏预设的显示区域。
例如,用户在输入12345678之后,不需要再进行任何输入,此时处理器隐藏预设的显示区域。
相应地,本发明实施例还提出一种数据输入装置,如图10所示,其结构组成包括:
接收单元1001,用于接收用户在预设的显示区域中对UE执行操作生成的事件。
判断单元1002,用于确定用户是否在预设的显示区域中UE执行操作。
执行单元1003,用于在确定出用户未在预设的显示区域中对UE执行操作时,将与操作对应的事件分发至第一运行环境中进行处理。
其中,预设的显示区域运行在UE的第二运行环境中,第二运行环境的安全级别高于第一运行环境。
可选地,上述装置中,所述执行单元1003,具体用于将与所述操作对应的事件存储至共享存储区中,其中所述共享存储区是所述第一运行环境和所述第二运行环境共同使用的存储区;通过触发所述第一运行环境中的中断,将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
具体地,所述执行单元1003,具体用于触发所述第一运行环境中的中断,并调用所述 第一安全环境中的守护线程,以通过所述守护线程将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
具体地,所述执行单元1003,还用于在确定出与所述操作对应的事件是安全输入事件时,显示所述预设的显示区域,以使用户在所述预设的显示区域中进行操作,其中所述安全输入事件是具有权限验证属性的数据输入事件。
具体地,所述执行单元1003,还用于将与所述操作对应的事件分发至第一运行环境中进行处理之后,隐藏所述预设的显示区域。
具体地,上述预设的显示区域包含具有安全属性的输入编辑框。
本发明还提供了一种计算机存储介质,用于储存为上述方面所述的数据输入装置所用的计算机软件指令,其包含用于执行上述方面所设计的程序。
本领域的技术人员应明白,本发明的实施例可提供为方法、装置(设备)、或计算机程序产品。因此,本发明可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、只读光盘、光学存储器等)上实施的计算机程序产品的形式。
本发明是参照根据本发明实施例的方法、装置(设备)和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
尽管已描述了本发明的优选实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例作出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本发明范围的所有变更和修改。
显然,本领域的技术人员可以对本发明进行各种改动和变型而不脱离本发明的精神和范围。这样,倘若本发明的这些修改和变型属于本发明权利要求及其等同技术的范围之内,则本发明也意图包含这些改动和变型在内。

Claims (16)

  1. 一种数据输入方法,其特征在于,包括:
    在确定出用户未在预设的显示区域中对用户设备UE执行操作时,将与所述操作对应的事件分发至第一运行环境中进行处理;
    其中,所述预设的显示区域运行在所述UE的第二运行环境中,所述第二运行环境的安全级别高于所述第一运行环境。
  2. 如权利要求1所述的方法,其特征在于,将与所述操作对应的事件分发至第一运行环境中进行处理,包括:
    将与所述操作对应的事件存储至共享存储区中,其中所述共享存储区是所述第一运行环境和所述第二运行环境共同使用的存储区;
    通过触发所述第一运行环境中的中断,将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
  3. 如权利要求2所述的方法,其特征在于,通过触发所述第一运行环境中的中断,将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理,包括:
    触发所述第一运行环境中的中断,并调用所述第一安全环境中的守护线程,以通过所述守护线程将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
  4. 如权利要求1~3任一所述的方法,其特征在于,在确定出用户未在预设的显示区域中对用户设备UE执行操作之前,还包括:
    在确定出与所述操作对应的事件是安全输入事件时,显示所述预设的显示区域,以使用户在所述预设的显示区域中进行操作,其中所述安全输入事件是具有权限验证属性的数据输入事件。
  5. 如权利要求1~3任一所述的方法,其特征在于,将与所述操作对应的事件分发至第一运行环境中进行处理之后,还包括:
    隐藏所述预设的显示区域。
  6. 如权利要求1~5任一所述的方法,其特征在于,所述预设的显示区域包含设定格式的输入编辑框。
  7. 一种数据输入装置,其特征在于,包括:
    接收单元,用于接收用户在预设的显示区域中对UE执行操作生成的事件;
    判断单元,用于确定用户是否在预设的显示区域中UE执行操作;
    执行单元,用于在所述判断单元确定出用户未在预设的显示区域中对用户设备UE执行操作时,将与所述操作对应的事件分发至第一运行环境中进行处理;其中,所述预设的显示区域运行在所述UE的第二运行环境中,所述第二运行环境的安全级别高于所述第一运行环境。
  8. 如权利要求7所述的装置,其特征在于,所述执行单元,具体用于将与所述操作对应的事件存储至共享存储区中,其中所述共享存储区是所述第一运行环境和所述第二运行环境共同使用的存储区;通过触发所述第一运行环境中的中断,将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
  9. 如权利要求8所述的装置,其特征在于,所述执行单元,具体用于触发所述第一运行环境中的中断,并调用所述第一安全环境中的守护线程,以通过所述守护线程将所述 共享存储区中存储的所述事件分发至第一运行环境中进行处理。
  10. 如权利要求7~9任一所述的装置,其特征在于,所述执行单元,还用于在确定出与所述操作对应的事件是安全输入事件时,显示所述预设的显示区域,以使用户在所述预设的显示区域中进行操作,其中所述安全输入事件是具有权限验证属性的数据输入事件。
  11. 如权利要求7~9任一所述的装置,其特征在于,所述执行单元,还用于隐藏所述预设的显示区域。
  12. 一种用户设备,其特征在于,包括:
    存储器,用于存储程序指令;
    处理器,用于在所述存储器中获得存储的程序指令,按照获得的程序执行:在确定出用户未在预设的显示区域中对用户设备UE执行操作时,将与所述操作对应的事件分发至第一运行环境中进行处理;
    其中,所述预设的显示区域运行在所述UE的第二运行环境中,所述第二运行环境的安全级别高于所述第一运行环境。
  13. 如权利要求12所述的用户设备,其特征在于,所述处理器,具体用于将与所述操作对应的事件存储至共享存储区中,其中所述共享存储区是所述第一运行环境和所述第二运行环境共同使用的存储区;
    所述用户设备还包括第一运行环境中的中断;
    所述处理器,具体用于触发所述第一运行环境中的中断;
    所述第一运行环境中的中断,用于将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
  14. 如权利要求13所述的用户设备,其特征在于,所述处理器,具体用于触发所述第一运行环境中的中断,并调用所述第一安全环境中的守护线程,以通过所述守护线程将所述共享存储区中存储的所述事件分发至第一运行环境中进行处理。
  15. 如权利要求12~14任一所述的用户设备,其特征在于,所述处理器,还用于在确定出与所述操作对应的事件是安全输入事件时,显示所述预设的显示区域,以使用户在所述预设的显示区域中进行操作,其中所述安全输入事件是具有权限验证属性的数据输入事件。
  16. 如权利要求12~14任一所述的用户设备,其特征在于,所述处理器,还用于隐藏所述预设的显示区域。
PCT/CN2017/075643 2016-03-15 2017-03-03 一种数据输入方法、装置及用户设备 Ceased WO2017157192A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
BR112018068582-8A BR112018068582B1 (pt) 2016-03-15 2017-03-03 Método de entrada de dados, aparelho, e equipamento de usuário
EP17765734.3A EP3418934B1 (en) 2016-03-15 2017-03-03 Data input method, device and user equipment
US16/131,548 US10831905B2 (en) 2016-03-15 2018-09-14 Data input method and apparatus and user equipment
US17/085,539 US11574064B2 (en) 2016-03-15 2020-10-30 Data input method and apparatus and user equipment

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610145990.7A CN105825128B (zh) 2016-03-15 2016-03-15 一种数据输入方法、装置及用户设备
CN201610145990.7 2016-03-15

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US16/131,548 Continuation US10831905B2 (en) 2016-03-15 2018-09-14 Data input method and apparatus and user equipment

Publications (1)

Publication Number Publication Date
WO2017157192A1 true WO2017157192A1 (zh) 2017-09-21

Family

ID=56987835

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/075643 Ceased WO2017157192A1 (zh) 2016-03-15 2017-03-03 一种数据输入方法、装置及用户设备

Country Status (4)

Country Link
US (2) US10831905B2 (zh)
EP (1) EP3418934B1 (zh)
CN (1) CN105825128B (zh)
WO (1) WO2017157192A1 (zh)

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105825128B (zh) 2016-03-15 2020-05-19 华为技术有限公司 一种数据输入方法、装置及用户设备
CN107168747B (zh) * 2017-05-27 2020-12-29 努比亚技术有限公司 移动终端配置的区分方法、装置及计算机可读存储介质
CN109426355B (zh) * 2017-08-31 2022-12-30 华为终端有限公司 一种电子设备的输入方法、输入装置及电子设备
CN110059489B (zh) * 2018-01-19 2021-08-17 旭景科技股份有限公司 安全电子设备
GB201806465D0 (en) 2018-04-20 2018-06-06 Nordic Semiconductor Asa Memory-access controll
GB201810662D0 (en) 2018-06-28 2018-08-15 Nordic Semiconductor Asa Peripheral Access On A Secure-Aware Bus System
GB201810653D0 (en) * 2018-06-28 2018-08-15 Nordic Semiconductor Asa Secure peripheral interconnect
GB201810659D0 (en) 2018-06-28 2018-08-15 Nordic Semiconductor Asa Secure-Aware Bus System
FR3135334B1 (fr) 2022-05-05 2025-07-18 St Microelectronics Rousset Systeme sur puce integrant un circuit d’acces direct en memoire et procede correspondant

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103714276A (zh) * 2012-10-01 2014-04-09 Nxp股份有限公司 相连的设备架构、移动平台和用于安全的用户认证的系统
US20140101755A1 (en) * 2012-10-10 2014-04-10 Research In Motion Limited Mobile wireless communications device providing security features based upon wearable near field communication (nfc) device and related methods
CN104115152A (zh) * 2012-02-16 2014-10-22 三星电子株式会社 用于使用装置认证来保护数字内容的方法和设备
CN104239783A (zh) * 2014-09-19 2014-12-24 东软集团股份有限公司 一种特定信息安全输入系统及方法
CN104933361A (zh) * 2015-06-05 2015-09-23 浪潮电子信息产业股份有限公司 一种登录密码的保护装置及方法
CN105825128A (zh) * 2016-03-15 2016-08-03 华为技术有限公司 一种数据输入方法、装置及用户设备

Family Cites Families (32)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6321337B1 (en) * 1997-09-09 2001-11-20 Sanctum Ltd. Method and system for protecting operations of trusted internal networks
US20040226041A1 (en) * 2000-02-18 2004-11-11 Xsides Corporation System and method for parallel data display of multiple executing environments
AU4595501A (en) * 2000-03-22 2001-10-03 Sony Electronics Inc. Data entry user interface
US7266490B2 (en) * 2000-12-28 2007-09-04 Robert Marc Zeidman Apparatus and method for connecting hardware to a circuit simulation
US7062466B2 (en) * 2000-12-06 2006-06-13 The Belo Company Method and system for operating online classified advertisements
WO2004046916A2 (en) * 2002-11-18 2004-06-03 Arm Limited Exception types within a secure processing system
JP4439187B2 (ja) * 2003-02-10 2010-03-24 シャープ株式会社 データ処理装置
US20070266444A1 (en) * 2004-12-03 2007-11-15 Moshe Segal Method and System for Securing Data Stored in a Storage Device
US20080275992A1 (en) * 2005-02-09 2008-11-06 Access Systems Americas, Inc. System and method of managing connections between a computing system and an available network using a connection manager
US7954064B2 (en) * 2005-10-27 2011-05-31 Apple Inc. Multiple dashboards
CN100428164C (zh) * 2006-01-23 2008-10-22 联想(北京)有限公司 一种虚拟机系统及其设备访问方法
US8261064B2 (en) * 2007-02-27 2012-09-04 L-3 Communications Corporation Integrated secure and non-secure display for a handheld communications device
US20130145475A1 (en) 2011-12-02 2013-06-06 Samsung Electronics Co., Ltd. Method and apparatus for securing touch input
US8812873B2 (en) * 2012-09-26 2014-08-19 Intel Corporation Secure execution of a computer program using binary translators
US9886595B2 (en) 2012-12-07 2018-02-06 Samsung Electronics Co., Ltd. Priority-based application execution method and apparatus of data processing device
US20140281560A1 (en) * 2013-03-15 2014-09-18 Ologn Technologies Ag Secure zone on a virtual machine for digital communications
WO2014141206A1 (en) * 2013-03-15 2014-09-18 Ologn Technologies Ag Secure zone on a virtual machine for digital communications
JP6067449B2 (ja) * 2013-03-26 2017-01-25 株式会社東芝 情報処理装置、情報処理プログラム
CN105900108A (zh) * 2013-11-15 2016-08-24 Ctpg运营有限责任公司 用于印刷隐藏式安全条形码的系统和方法
KR20150077774A (ko) * 2013-12-30 2015-07-08 삼성전자주식회사 화면 전환 방법 및 그 장치
KR101442539B1 (ko) * 2013-12-31 2014-09-26 권용구 보안저장장치를 구비하는 저장 시스템 및 그 관리 방법
JP2015215687A (ja) * 2014-05-08 2015-12-03 パナソニックIpマネジメント株式会社 可搬型決済端末装置
CN105335672B (zh) * 2014-06-16 2020-12-04 华为技术有限公司 一种安全模式提示方法及装置
CN104318182B (zh) * 2014-10-29 2017-09-12 中国科学院信息工程研究所 一种基于处理器安全扩展的智能终端隔离系统及方法
US10754967B1 (en) * 2014-12-15 2020-08-25 Marvell Asia Pte, Ltd. Secure interrupt handling between security zones
US20160239649A1 (en) * 2015-02-13 2016-08-18 Qualcomm Incorporated Continuous authentication
US20160253651A1 (en) * 2015-02-27 2016-09-01 Samsung Electronics Co., Ltd. Electronic device including electronic payment system and operating method thereof
CN104820573A (zh) * 2015-05-27 2015-08-05 南京芯度电子科技有限公司 一种安全人机交互接口的系统及其实现方法
CN105224403B (zh) * 2015-09-17 2018-09-28 华为技术有限公司 一种中断处理方法及装置
CN105447406B (zh) * 2015-11-10 2018-10-19 华为技术有限公司 一种用于访问存储空间的方法与装置
CN110059500A (zh) * 2015-11-30 2019-07-26 华为技术有限公司 用户界面切换方法和终端
US10740496B2 (en) * 2017-02-13 2020-08-11 Samsung Electronics Co., Ltd. Method and apparatus for operating multi-processor system in electronic device

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104115152A (zh) * 2012-02-16 2014-10-22 三星电子株式会社 用于使用装置认证来保护数字内容的方法和设备
CN103714276A (zh) * 2012-10-01 2014-04-09 Nxp股份有限公司 相连的设备架构、移动平台和用于安全的用户认证的系统
US20140101755A1 (en) * 2012-10-10 2014-04-10 Research In Motion Limited Mobile wireless communications device providing security features based upon wearable near field communication (nfc) device and related methods
CN104239783A (zh) * 2014-09-19 2014-12-24 东软集团股份有限公司 一种特定信息安全输入系统及方法
CN104933361A (zh) * 2015-06-05 2015-09-23 浪潮电子信息产业股份有限公司 一种登录密码的保护装置及方法
CN105825128A (zh) * 2016-03-15 2016-08-03 华为技术有限公司 一种数据输入方法、装置及用户设备

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3418934A4 *

Also Published As

Publication number Publication date
BR112018068582A2 (pt) 2019-02-12
US20190018969A1 (en) 2019-01-17
US11574064B2 (en) 2023-02-07
CN105825128B (zh) 2020-05-19
US10831905B2 (en) 2020-11-10
EP3418934B1 (en) 2025-02-19
US20210049286A1 (en) 2021-02-18
EP3418934A4 (en) 2018-12-26
EP3418934A1 (en) 2018-12-26
CN105825128A (zh) 2016-08-03

Similar Documents

Publication Publication Date Title
US11574064B2 (en) Data input method and apparatus and user equipment
US11874903B2 (en) User interface switching method and terminal
RU2635224C2 (ru) Способ и аппарат для безопасного сенсорного ввода
US10528252B2 (en) Key combinations toolbar
US9654603B1 (en) Client-side rendering for virtual mobile infrastructure
US20100132015A1 (en) Apparatus and method for providing security information in virtual environment
EP3255578B1 (en) Interface display method of terminal and terminal
CN103914646A (zh) 触摸事件处理方法和实现所述方法的便携式设备
CN103136488A (zh) 保护触摸输入的方法和装置
EP3210159B1 (en) Technologies for secure input and display of virtual touch user interfaces
US9444912B1 (en) Virtual mobile infrastructure for mobile devices
WO2020151518A1 (zh) 应用开启方法、装置、终端及存储介质
WO2021077882A1 (zh) 一种图像显示方法与电子设备
US12566829B2 (en) Device access control
KR20130058621A (ko) 터치 신호를 처리하는 방법 및 그 계산 장치
CN116484438A (zh) 信息处理方法和装置
CN106919361A (zh) 一种语音提醒方法及装置
JP7176067B1 (ja) 情報処理装置、及び制御方法
BR112018068582B1 (pt) Método de entrada de dados, aparelho, e equipamento de usuário
TW201439882A (zh) 觸控事件處理方法和實現該方法的可攜式裝置
JP5831948B2 (ja) 情報端末、情報入力用画像の表示方法、及びプログラム
HK1249308B (zh) 终端的控制方法、装置和存储介质
TW201717090A (zh) 安全獨佔式平台

Legal Events

Date Code Title Description
NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2017765734

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2017765734

Country of ref document: EP

Effective date: 20180919

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112018068582

Country of ref document: BR

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17765734

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 112018068582

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20180913