WO2022247639A1 - 保存密文的方法和装置 - Google Patents
保存密文的方法和装置 Download PDFInfo
- Publication number
- WO2022247639A1 WO2022247639A1 PCT/CN2022/092296 CN2022092296W WO2022247639A1 WO 2022247639 A1 WO2022247639 A1 WO 2022247639A1 CN 2022092296 W CN2022092296 W CN 2022092296W WO 2022247639 A1 WO2022247639 A1 WO 2022247639A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- ciphertext
- key
- partition
- erasable
- account
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
- G06F21/79—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/602—Providing cryptographic facilities or services
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6209—Protecting access to data via a platform, e.g. using keys or access control rules to a single file or object, e.g. in a secure envelope, encrypted and accessed using a key, or with access control rules appended to the object itself
Definitions
- the present application relates to the field of terminals, in particular to a method and device for storing ciphertext.
- An external memory such as a secure digital (SD) card
- SD secure digital
- the key of the external memory is encrypted by the lock screen password and stored in the erasable partition of the electronic device.
- the encrypted key in the erasable partition ie , ciphertext
- the encrypted key in the erasable partition will be deleted before being saved in time, so that the data in the external memory cannot be decrypted.
- the present application provides a method and device for storing ciphertext, which can solve the problem that the data in the external memory cannot be decrypted after the electronic device is reset at the factory level.
- a method for storing ciphertext including: obtaining an encryption instruction indicating to encrypt a file in an external memory; obtaining a characteristic value of a first account ID according to the encryption instruction; using the The characteristic value of the first account identifier encrypts the first key to generate the first ciphertext, wherein the first key is used to encrypt the second key, and the second key is used to encrypt the the first file; encrypting the feature value of the first account ID to generate a second ciphertext; storing the first ciphertext and the second ciphertext in a non-erasable partition.
- the encryption instruction is an instruction triggered when the user encrypts the external memory on the encryption setting interface. After the electronic device obtains the encryption instruction, it generates the first ciphertext and the second ciphertext, and stores the first ciphertext and the second ciphertext in the electronic device.
- the electronic device before the user performs a factory-level reset on the electronic device, the electronic device has completed the safe storage of the first ciphertext and the second ciphertext; after the electronic device completes the factory-level reset, it can be accessed from The non-erasable partition restores the first key, and then uses the first key to decrypt the second key in the external storage, and uses the second key to decrypt the files in the external storage, thus solving the problem of external storage after factory reset.
- the problem that the files in the device storage cannot be decrypted.
- the method further includes: obtaining instruction information for switching accounts; verifying the first account ID according to the instruction information; after the verification of the first account ID is passed, obtaining the characteristic value of the second account ID ; Updating the first ciphertext and the second ciphertext according to the characteristic value of the second account identifier.
- the user can switch the currently logged-in account identifier (for example, the first account identifier) on the account login interface.
- the electronic device can require the user to enter the password corresponding to the first account identifier. , to verify the first account ID.
- the electronic device can obtain the second account ID input by the user, and calculate the hash value of the second account ID (an example of a characteristic value), and then The first ciphertext and the second ciphertext are updated using the hash value identified by the second account, wherein the electronic device can first decrypt the first key, and then use the hash value identified by the second account to generate an updated The first ciphertext, and then encrypt the hash value of the second account ID to generate an updated second ciphertext.
- the electronic device can first decrypt the first key, and then use the hash value identified by the second account to generate an updated The first ciphertext, and then encrypt the hash value of the second account ID to generate an updated second ciphertext.
- the first ciphertext and the second ciphertext are updated using the current user's account ID (second account ID), and the encryption corresponding to the first account ID is released. And the authority to decrypt the external memory, thus ensuring the security of the data in the external memory.
- the method further includes: after the factory reset is completed, verifying the first account ID; when the verification of the first account ID succeeds, decrypting the first ciphertext and the second Two ciphertexts to generate the first key.
- the account verification mechanism After the electronic device is reset at the factory level, the account verification mechanism will be activated. This mechanism requires that the electronic device can be used normally only after the account verification is successful. Verifying the last logged-in account ID (for example, the first account ID) before the factory-level reset can ensure that the user after the electronic device performs the factory-level reset is a legitimate user, thereby ensuring the security of data in the external memory.
- the verifying the first account ID includes:
- the method further includes: encrypting the first key with a default value to generate a third ciphertext; encrypting the default value to generate a fourth ciphertext; combining the third ciphertext and the first ciphertext Four ciphertexts are stored in the non-erasable partition.
- the electronic device can use the default value after decrypting the first key. Encryption saves the first key, thereby ensuring the security of data in the external memory.
- the method further includes: copying the third ciphertext and the fourth ciphertext from the non-erasable partition to an erasable partition;
- the third ciphertext and the fourth ciphertext generate the first key; decrypt the encrypted first file in the external memory according to the first key.
- the method before verifying the first account ID, further includes: acquiring a factory-level reset command triggered by a recovery interface; formatting data in the erasable partition according to the factory-level reset command .
- the encrypting the first key by using the feature value identified by the first account includes: calling the key management module keymaster TA to perform: encrypting the first key by using the feature value identified by the first account
- the encrypting the feature value of the first account ID includes: calling the keymaster TA to perform: encrypting the feature value of the first account ID.
- the storing the first ciphertext and the second ciphertext in the non-erasable partition includes: calling a trusted execution environment application program interface to execute: storing the first ciphertext and the second ciphertext The second ciphertext is stored in the non-erasable partition.
- the first key is also used to encrypt a third key
- the third key is used to encrypt the encrypted second file in the external memory.
- the method further includes: acquiring a feature value of the lock screen password according to the encryption instruction; encrypting the first key by using the feature value of the lock screen password to generate a fifth ciphertext; encrypting the lock screen password
- the feature value of the screen password is used to generate a sixth ciphertext; and the fifth ciphertext and the sixth ciphertext are stored in an erasable partition.
- the encrypting the first key using the feature value of the lock screen password includes: calling keymaster TA to execute: encrypting the first key using the feature value of the lock screen password;
- the feature value of the lock screen password includes: calling the keymaster TA to execute: encrypting the feature value of the lock screen password.
- the method further includes: acquiring a user-level reset instruction triggered by a setting interface; backing up the fifth ciphertext and the sixth ciphertext to the non-erasable partition.
- the backing up the fifth ciphertext and the sixth ciphertext to the non-erasable partition according to the user-level reset instruction includes: according to the user-level reset instruction, from the decrypting the first key from the fifth ciphertext and the sixth ciphertext; encrypting the first key with a default value to generate a seventh ciphertext; encrypting the default value to generate an eighth ciphertext;
- the seventh ciphertext and the eighth ciphertext are stored in the non-erasable partition.
- the method further includes: after the user-level reset is completed, copying the seventh ciphertext and the eighth ciphertext from the non-erasable partition to the erasable partition; Decrypt the first key from the seventh ciphertext and the eighth ciphertext in the erasable partition; decrypt the encrypted first file in the external memory according to the first key .
- the erasable partition is a data partition
- the feature value of the lock screen password is a hash value of the lock screen password
- the non-erasable partition is a sec_storage partition
- the characteristic value of the first account identifier is a hash value of the first account identifier
- another method for storing ciphertext including: displaying an encryption setting interface of an external memory; receiving a first operation performed by a user on the encryption setting interface; responding to the first operation , encrypting the files in the external memory; receiving the user’s second operation; in response to the second operation, displaying the factory-level reset setting interface; receiving the user’s operation on the factory-level reset setting interface
- the third operation in response to the third operation, perform a factory-level reset; display the account verification interface; receive the verification information input by the user on the account verification interface; when the verification information is verified When passing through, and when receiving the operation of accessing the files in the external storage by the user, the encrypted files in the external storage are decrypted.
- the encryption instruction is an instruction triggered when the user encrypts the external memory on the encryption setting interface. After the electronic device obtains the encryption instruction, it generates the first ciphertext and the second ciphertext, and stores the first ciphertext and the second ciphertext in the electronic device.
- the electronic device Before the user implements factory-level reset on the electronic device, the electronic device has completed the safe storage of the first ciphertext and the second ciphertext; after the electronic device completes the factory-level reset, it can Recover the first key from the non-erasable partition, then use the first key to decrypt the second key in the external storage, and use the second key to decrypt the files in the external storage, thus solving the problem after factory reset The problem that the files in the external storage cannot be decrypted.
- a device for storing ciphertext including a unit for executing any method in the first aspect or the second aspect.
- the device may be a terminal device, or a chip in the terminal device.
- the device may comprise an input unit and a processing unit.
- the processing unit may be a processor, and the input unit may be a communication interface; the terminal device may also include a memory, which is used to store computer program codes, and when the processor executes the When the computer program code is used, the terminal device is made to execute any method in the first aspect or the second aspect.
- the processing unit may be a processing unit inside the chip, and the input unit may be an output interface, a pin or a circuit, etc.; the chip may also include a memory, and the memory may be a memory (for example, registers, cache, etc.), can also be located outside the chip memory (for example, read-only memory, random access memory, etc.); the memory is used to store computer program code, when the processor executes the memory The stored computer program code causes the chip to execute any method in the first aspect or the second aspect.
- a computer-readable storage medium stores computer program code, and when the computer program code is run by a device storing ciphertext, the device executes the first aspect or Either method of the second aspect.
- Fig. 1 is a schematic diagram of a hardware system applicable to the device of the present application
- Fig. 2 is a schematic diagram of a software system applicable to the device of the present application
- Fig. 4 is a schematic diagram of an encryption confirmation interface provided by the present application.
- Fig. 6 is a schematic diagram of a method for storing keys provided by the present application.
- FIG. 7 is a schematic diagram of an encryption process provided by the present application.
- FIG. 8 is a schematic diagram of a method for backing up and restoring keys in a user-level reset scenario provided by the present application
- FIG. 10 is a schematic diagram of a method for backing up keys in a factory-level reset scenario provided by the present application.
- FIG. 11 is a schematic diagram of an account login interface provided by this application.
- FIG. 15 is a schematic diagram of a factory-level reset process interface provided by the present application.
- FIG. 16 is a schematic diagram of a method for recovering keys in a factory-level reset scenario provided by the present application.
- FIG. 18 is a schematic diagram of changes in ciphertext storage in a storage area in a factory-level reset scenario provided by the present application.
- the device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (universal serial bus, USB) interface 130, a charge management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, Mobile communication module 150, wireless communication module 160, audio module 170, speaker 170A, receiver 170B, microphone 170C, earphone jack 170D, sensor module 180, button 190, motor 191, indicator 192, camera 193, display screen 194, and user An identification module (subscriber identification module, SIM) card interface 195 and the like.
- SIM subscriber identification module
- Processor 110 may include one or more processing units.
- the processor 110 may include at least one of the following processing units: an application processor (application processor, AP), a modem processor, a graphics processing unit (graphics processing unit, GPU), an image signal processor (image signal processor) , ISP), controller, video codec, digital signal processor (digital signal processor, DSP), baseband processor, neural network processor (neural-network processing unit, NPU).
- an application processor application processor, AP
- modem processor graphics processing unit
- graphics processing unit graphics processing unit
- image signal processor image signal processor
- ISP image signal processor
- controller video codec
- digital signal processor digital signal processor
- DSP digital signal processor
- baseband processor baseband processor
- neural network processor neural-network processing unit
- a memory may also be provided in the processor 110 for storing instructions and data.
- the memory in processor 110 is a cache memory.
- the memory may hold instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instruction or data again, it can be called directly from the memory. Repeated access is avoided, and the waiting time of the processor 110 is reduced, thus improving the efficiency of the system.
- processor 110 may include one or more interfaces.
- the processor 110 may include at least one of the following interfaces: an inter-integrated circuit (inter-integrated circuit, I2C) interface, an inter-integrated circuit sound (inter-integrated circuit sound, I2S) interface, a pulse code modulation (pulse code modulation, PCM) interface, universal asynchronous receiver/transmitter (UART) interface, mobile industry processor interface (MIPI), general-purpose input/output (GPIO) interface, SIM interface, USB interface.
- I2C inter-integrated circuit
- I2S inter-integrated circuit sound
- PCM pulse code modulation
- UART universal asynchronous receiver/transmitter
- MIPI mobile industry processor interface
- GPIO general-purpose input/output
- the GPIO interface can be configured by software.
- the GPIO interface can be configured as a control signal interface or as a data signal interface.
- the GPIO interface can be used to connect the processor 110 with the camera 193 , the display screen 194 , the wireless communication module 160 , the audio module 170 and the sensor module 180 .
- the GPIO interface can also be configured as an I2C interface, I2S interface, UART interface or MIPI interface.
- the USB interface 130 is an interface conforming to the USB standard specification, for example, it can be a mini (Mini) USB interface, a micro (Micro) USB interface or a C-type USB (USB Type C) interface.
- the USB interface 130 can be used to connect a charger to charge the device 100 , can also be used to transmit data between the device 100 and peripheral devices, and can also be used to connect an earphone to play audio through the earphone.
- the USB interface 130 can also be used to connect other devices 100, such as AR equipment.
- the power management module 141 is used for connecting the battery 142 , the charging management module 140 and the processor 110 .
- the power management module 141 receives the input from the battery 142 and/or the charging management module 140 to provide power for the processor 110 , the internal memory 121 , the display screen 194 , the camera 193 , and the wireless communication module 160 .
- the power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle times, and battery health status (eg, leakage, impedance).
- the power management module 141 may be set in the processor 110, or the power management module 141 and the charge management module 140 may be set in the same device.
- Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals.
- Each antenna in device 100 may be used to cover single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization of the antennas.
- Antenna 1 can be multiplexed as a diversity antenna of a wireless local area network.
- the antenna may be used in conjunction with a tuning switch.
- the wireless communication module 160 can also provide a wireless communication solution applied to the device 100, such as at least one of the following solutions: wireless local area networks (wireless local area networks, WLAN), bluetooth (bluetooth, BT) , Bluetooth low energy (bluetooth low energy, BLE), ultra wide band (ultra wide band, UWB), global navigation satellite system (global navigation satellite system, GNSS), frequency modulation (frequency modulation, FM), near field communication (near field communication) communication, NFC), infrared (infrared, IR) technology.
- the wireless communication module 160 may be one or more devices integrating at least one communication processing module.
- the GNSS may include at least one of the following positioning technologies: global positioning system (global positioning system, GPS), global navigation satellite system (global navigation satellite system, GLONASS), Beidou satellite navigation system (beidou navigation satellite system, BDS), Quasi-zenith satellite system (QZSS), satellite based augmentation systems (SBAS).
- global positioning system global positioning system
- GLONASS global navigation satellite system
- Beidou satellite navigation system beidou navigation satellite system, BDS
- QZSS Quasi-zenith satellite system
- SBAS satellite based augmentation systems
- the ISP is used for processing the data fed back by the camera 193 .
- the light is transmitted to the photosensitive element of the camera through the lens, and the light signal is converted into an electrical signal, and the photosensitive element of the camera transmits the electrical signal to the ISP for processing, and converts it into an image visible to the naked eye.
- ISP can optimize the algorithm of image noise, brightness and color, and ISP can also optimize parameters such as exposure and color temperature of the shooting scene.
- the ISP may be located in the camera 193 .
- the internal memory 121 may be used to store computer-executable program codes including instructions.
- the internal memory 121 may include an area for storing programs and an area for storing data.
- the storage program area can store an operating system and an application program required by at least one function (for example, a sound playing function and an image playing function).
- the data storage area can store data created during use of the device 100 (for example, audio data and phonebook).
- the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, for example: at least one magnetic disk storage device, flash memory device, and universal flash storage (universal flash storage, UFS), etc.
- the processor 110 executes various processing methods of the device 100 by executing instructions stored in the internal memory 121 and/or instructions stored in a memory provided in the processor.
- Speaker 170A also known as a horn, is used to convert audio electrical signals into sound signals.
- Device 100 may listen to music or make hands-free calls through speaker 170A.
- Receiver 170B also known as an earpiece, is used to convert audio electrical signals into audio signals.
- the user uses the device 100 to answer calls or voice messages, he can listen to the voice by putting the receiver 170B close to the ear.
- Microphone 170C also known as microphone or microphone, is used to convert sound signals into electrical signals. When the user makes a call or sends a voice message, a sound signal may be input into the microphone 170C by uttering a sound close to the microphone 170C.
- the device 100 may be provided with at least one microphone 170C. In other embodiments, the device 100 may be provided with two microphones 170C to implement the noise reduction function. In some other embodiments, the device 100 may also be provided with three, four or more microphones 170C to realize functions such as identifying sound sources and directional recording.
- the processor 110 can process the electrical signal output by the microphone 170C. For example, the audio module 170 and the wireless communication module 160 can be coupled through a PCM interface. The electrical signal is transmitted to the processor 110; the processor 110 performs volume analysis and frequency analysis on the electrical signal to determine the volume and frequency of the ambient sound.
- the earphone interface 170D is used for connecting wired earphones.
- the earphone interface 170D may be a USB interface 130, or a 3.5mm open mobile terminal platform (OMTP) standard interface, or a cellular telecommunications industry association of the USA (CTIA) standard interface.
- OMTP open mobile terminal platform
- CTIA cellular telecommunications industry association of the USA
- the pressure sensor 180A is used to sense the pressure signal and convert the pressure signal into an electrical signal.
- pressure sensor 180A may be disposed on display screen 194 .
- pressure sensor 180A may be a resistive pressure sensor, an inductive pressure sensor or a capacitive pressure sensor.
- the capacitive pressure sensor may include at least two parallel plates with conductive materials.
- touch operations acting on the same touch position but with different touch operation intensities may correspond to different operation instructions. For example: when the touch operation whose touch operation intensity is less than the first pressure threshold acts on the short message application icon, execute the instruction of viewing the short message; when the touch operation whose touch operation intensity is greater than or equal to the first pressure threshold acts on the short message application icon , to execute the instruction of creating a new short message.
- the magnetic sensor 180D includes a Hall sensor.
- Device 100 may utilize magnetic sensor 180D to detect opening and closing of the flip holster.
- the device 100 can detect the opening and closing of the flip according to the magnetic sensor 180D.
- the device 100 can set features such as automatic unlocking of the flip cover according to the detected opening and closing state of the leather case or the opening and closing state of the flip cover.
- the acceleration sensor 180E can detect the acceleration of the device 100 in various directions (generally x-axis, y-axis and z-axis). The magnitude and direction of gravity can be detected when the device 100 is stationary. The acceleration sensor 180E can also be used to recognize the posture of the device 100 as an input parameter for application programs such as landscape and portrait screen switching and pedometer.
- the distance sensor 180F is used to measure distance.
- the device 100 can measure the distance by infrared or laser. In some embodiments, for example, in a shooting scene, the device 100 can use the distance sensor 180F for distance measurement to achieve fast focusing.
- the proximity light sensor 180G may include, for example, a light-emitting diode (LED) and a light detector, such as a photodiode.
- the LEDs may be infrared LEDs.
- the device 100 emits infrared light through the LED.
- Device 100 uses photodiodes to detect infrared reflected light from nearby objects. When the reflected light is detected, the device 100 may determine that there is an object nearby. When no reflected light is detected, the device 100 may determine that there is no object nearby.
- the device 100 can use the proximity light sensor 180G to detect whether the user is holding the device 100 close to the ear to make a call, so as to automatically turn off the screen to save power.
- the proximity light sensor 180G can also be used for automatic unlocking and automatic screen locking in leather case mode or pocket mode.
- the fingerprint sensor 180H is used to collect fingerprints.
- the device 100 can use the characteristics of the collected fingerprints to implement functions such as unlocking, accessing application locks, taking pictures, and answering incoming calls.
- the temperature sensor 180J is used to detect temperature.
- the device 100 implements a temperature treatment strategy using the temperature detected by the temperature sensor 180J. For example, when the temperature reported by the temperature sensor 180J exceeds a threshold, the device 100 may reduce the performance of a processor located near the temperature sensor 180J, so as to reduce power consumption and implement thermal protection.
- the device 100 when the temperature is lower than another threshold, the device 100 heats the battery 142 to avoid abnormal shutdown of the device 100 due to low temperature.
- the device 100 boosts the output voltage of the battery 142 to avoid abnormal shutdown caused by low temperature.
- the touch sensor 180K is also referred to as a touch device.
- the touch sensor 180K may be disposed on the display screen 194, and the touch sensor 180K and the display screen 194 form a touch screen, which is also called a touch screen.
- the touch sensor 180K is used to detect a touch operation on or near it.
- the touch sensor 180K may transmit the detected touch operation to the application processor to determine the touch event type.
- Visual output related to the touch operation can be provided through the display screen 194 .
- the touch sensor 180K may also be disposed on the surface of the device 100 and disposed at a different position from the display screen 194 .
- Keys 190 include a power key and a volume key.
- the key 190 can be a mechanical key or a touch key.
- the device 100 can receive key input signals and implement functions related to case input signals.
- the motor 191 can generate vibrations.
- the motor 191 can be used for notification of incoming calls, and can also be used for touch feedback.
- the motor 191 can generate different vibration feedback effects for touch operations on different application programs. For touch operations acting on different areas of the display screen 194, the motor 191 can also generate different vibration feedback effects. Different application scenarios (for example, time reminder, receiving information, alarm clock and games) may correspond to different vibration feedback effects.
- the touch vibration feedback effect can also support customization.
- the indicator 192 can be an indicator light, which can be used to indicate the charging status and the change of the battery capacity, and can also be used to indicate messages, missed calls and notifications.
- the hardware system of the device 100 is described in detail above, and the software system of the device 100 is introduced below.
- the software system may adopt a layered architecture, an event-driven architecture, a micro-kernel architecture, a micro-service architecture, or a cloud architecture.
- the embodiment of the present application uses a layered architecture as an example to describe the software system of the device 100 as an example.
- a software system adopting a layered architecture is divided into several layers, and each layer has a clear role and division of labor. Layers communicate through software interfaces.
- the software system can be divided into four layers, which are application program layer, application program framework layer, Android Runtime (Android Runtime) and system library, and kernel layer respectively from top to bottom.
- the application layer can include applications such as camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, and short message.
- the application framework layer provides an application programming interface (application programming interface, API) and a programming framework for applications in the application layer.
- the application framework layer can include some predefined functions.
- a window manager is used to manage window programs.
- the window manager can get the size of the display, determine whether there is a status bar, lock the screen, and capture the screen.
- Content providers are used to store and retrieve data and make it accessible to applications.
- the data may include video, images, audio, calls made and received, browsing history and bookmarks, and phonebook.
- the view system includes visual controls, such as those that display text and those that display pictures.
- the view system can be used to build applications.
- the display interface may be composed of one or more views, for example, a display interface including an SMS notification icon may include a view for displaying text and a view for displaying pictures.
- the phone manager is used to provide communication functions of the device 100, such as management of call status (connected or hung up).
- the resource manager provides various resources to the application, such as localized strings, icons, pictures, layout files, and video files.
- the notification manager enables the application to display notification information in the status bar, which can be used to convey notification-type messages, and can automatically disappear after a short stay without user interaction.
- the notification manager is used for download completion notifications and message reminders.
- the notification manager can also manage notifications that appear in the status bar at the top of the system in the form of charts or scrolling text, such as notifications from applications running in the background.
- the notification manager can also manage notifications that appear on the screen in the form of dialog windows, such as prompting text messages in the status bar, making alert sounds, vibrating electronic devices, and blinking lights.
- the Android Runtime includes core library and virtual machine. The Android runtime is responsible for the scheduling and management of the Android system.
- the application layer and the application framework layer run in virtual machines.
- the virtual machine executes the java files of the application program layer and the application program framework layer as binary files.
- the virtual machine is used to perform functions such as object life cycle management, stack management, thread management, security and exception management, and garbage collection.
- the system library can include multiple functional modules, such as: surface manager (surface manager), media library (Media Libraries), three-dimensional graphics processing library (for example: open graphics library for embedded systems (open graphics library for embedded systems, OpenGL ES) and 2D graphics engine (for example: skia graphics library (skia graphics library, SGL)).
- surface manager surface manager
- media library Media Libraries
- three-dimensional graphics processing library for example: open graphics library for embedded systems (open graphics library for embedded systems, OpenGL ES)
- 2D graphics engine for example: skia graphics library (skia graphics library, SGL)
- the surface manager is used to manage the display subsystem and provides the fusion of 2D layers and 3D layers for multiple applications.
- the 3D graphics processing library can be used to implement 3D graphics drawing, image rendering, compositing and layer processing.
- the 2D graphics engine is a drawing engine for 2D drawing.
- the kernel layer is the layer between hardware and software.
- the kernel layer may include driver modules such as display driver, camera driver, audio driver and sensor driver.
- a corresponding hardware interrupt is sent to the kernel layer, and the kernel layer processes the touch operation into an original input event.
- the original input event includes information such as touch coordinates and a time stamp of the touch operation.
- the original input event is stored in the kernel layer, and the application framework layer obtains the original input event from the kernel layer, identifies the control corresponding to the original input event, and notifies the corresponding application (application, APP) of the control.
- the above-mentioned touch operation is a single-click operation
- the APP corresponding to the above-mentioned control is a camera APP. After the camera APP is awakened by the single-click operation, it can call the camera driver of the kernel layer through the API, and control the camera 193 to take pictures through the camera driver.
- the following uses the device 100 as an example to introduce the method for storing ciphertext provided by this application.
- the files in the external memory can be encrypted and stored in the external memory, and the key for decrypting these files is stored in the internal memory of the device 100. In this way, the content in the external memory can only be It can be read as plaintext in the device 100.
- the external memory is connected to other electronic devices, since other electronic devices do not store keys, the content in the external memory cannot be decrypted by other electronic devices, thus ensuring the security of the external memory. Security of files in .
- the external storage can be an SD card, a USB flash drive or other types of storage.
- the external storage can establish a data connection with the device 100 through insertion, or establish a data connection with the device 100 through wired or wireless methods.
- This application There is no limitation on the specific type of the external memory and the connection method between the external memory and the device 100 .
- the user can trigger the encryption process of the SD card on the encryption setting interface shown in Figure 3.
- the user can click "Encrypted Memory Card” in Figure 3 to enter the encryption setting confirmation interface shown in Figure 4.
- the user can click "Encrypted Memory Card” in Figure 4 to confirm the encryption of the files in the SD card.
- the encryption process The interface is shown in Figure 5. This application does not limit the encryption algorithm used in the encryption process.
- file encryption key file encryption key, FEK
- a method of storing FEK is to encrypt FEK multiple times and then store it in an erasable partition, as shown in Figure 6.
- the SD card encryption setting module After the user triggers the encryption process of the SD card on the encryption setting interface shown in Figure 3, the SD card encryption setting module generates an encryption command. Based on the setting of the lock screen password, there are two situations for the module called by the encryption command.
- Case 1 The lock screen password is not set.
- the SD card encryption module calls the encryption management module (Vold) to encrypt the FEK through this encryption command. If the user does not set a lock screen password, the default value (empty auth) can be used to encrypt the FEK key (file encryption key) encryption key, FEKEK) for encryption, and the process of encrypting FEK will be described in detail below.
- the SD card encryption module calls the lock screen service (LockSettingsService) to obtain the password hash value through the encryption command, and then the lock screen service transmits the password hash value to the encryption management module (Vold), so that the subsequent use of the password hash value to encrypt FEK key for encryption.
- the password hash value above is based on the information generated by the lock screen password. For example, the lock screen service performs hash calculation on the lock screen password when the user sets the lock screen password to generate a password hash value. After the user triggers the encryption of the SD card, the previous Save the password hash value and transmit the password hash value to the encryption management module.
- Vold is responsible for the realization of the core function of encryption and decryption. Vold triggers the encryption logic or decryption logic for the SD card by calling the encryption library or decryption library.
- the file system When the file system (such as eCryptfs) creates files in the SD card, the file system generates a random number for each file. For example, when eCryptfs creates a new file, it uses the random function provided by the kernel to create a random number. The random number The number is FEK. FEK is used to encrypt files in the SD card and to decrypt encrypted files in the SD card.
- eCryptfs uses an open pretty good privacy (OpenPGP) file format to store encrypted files
- encrypted files can be divided into multiple logical blocks (extent), and the size of each logical block is adjustable, but The size of each logical block is usually not larger than the size of a physical page.
- OpenPGP open pretty good privacy
- the FEK needs to be encrypted and saved. Vold unmounts the file system when the user sets SD card encryption, and remounts the file system. At this time, a random number is generated, which is FEKEK (an example of the first key).
- the FEKEK is used to encrypt the FEK (an example of the second key), wherein the FEKEK is set by Vold to the keyring (keyring) of the kernel, and the file system obtains the FEKEK from the keyring when encrypting the FEK.
- the encrypted FEK is stored in the metadata of the encrypted file.
- FEKEK After FEK is encrypted, FEKEK also needs to be stored encrypted. Since Vold is a module in the rich execution environment (rich execution environment, REE), the security does not meet the requirements, and FEKEK cannot be encrypted. Vold can invoke the trusted execution environment (trust execution environment) through the client application (client application, CA).
- the key management module in the TEE that is, the keymaster trusted application (trust application, TA), completes the encryption of the FEKEK by the keymaster TA.
- the keymaster TA can encrypt FEKEK with the password hash and according to the advanced encryption standard (AES), generating ciphertext 1 (an example of a fifth ciphertext). Subsequently, the keymaster TA can use the hardware unique key (HUK) and encrypt the password hash value according to AES to generate keymaster_key_blob (an example of the sixth ciphertext). keymaster TA stores ciphertext 1 and keymaster_key_blob in the erasable partition (/data path).
- AES advanced encryption standard
- UK hardware unique key
- keymaster TA stores ciphertext 1 and keymaster_key_blob in the erasable partition (/data path).
- file system If there are two files to be encrypted (file 1 and file 2) in the current SD card, the file system generates two random numbers for these two files, namely, FEK1 and FEK2; subsequently, the file system uses FEK1 to encrypt file 1, and uses FEK2 encrypted file 2.
- the file system After file 1 and file 2 are encrypted, the file system obtains FEKEK from the keyring, and uses FEKEK to encrypt FEK1 and FEK2 respectively.
- the encrypted FEK1 is stored in the metadata of file 1
- the encrypted FEK2 is stored in file 2. in metadata.
- Vold calls the keymaster TA through the CA, and the keymaster TA uses the password hash value to encrypt FEKEK; then, the keymaster TA uses the hardware HUK to encrypt the password hash value.
- the device 100 When it is necessary to decrypt the encrypted file in the SD card, the device 100 performs the reverse process of the encryption process shown in Figure 7. For example, Vold calls the keymaster TA through the CA to perform the following decryption steps: the keymaster TA obtains the keymaster_key_blob and the key from the erasable partition. In document 1, first use HUK to decrypt keymaster_key_blob to obtain the password hash value, and then use the password hash value to decrypt ciphertext 1 to obtain FEKEK.
- eCryptfs when eCryptfs opens an encrypted file, it reads the metadata of the encrypted file header through the underlying file system, and hands the metadata to the Keystore module (including the module of keymaster TA); the Keystore module obtains FEKEK from the keyring, and uses FEKEK to The encrypted FEK in the metadata is decrypted to generate the FEK; then, eCryptfs uses the FEK to decrypt the encrypted file.
- each logical block (extent) of the encrypted file is read into the cache page (page cache) and decrypted through the Kernel Crypto API.
- the device 100 When the device 100 performs the first type of reset (also known as "user-level reset", that is, the user resets the device 100 from the system setting menu), the data in the erasable area will be cleared. At this time, the device 100 can back up ciphertext 1 and keymaster_key_blob, so as to prevent the files in the SD card from being unable to be decrypted due to ciphertext 1 and keymaster_key_blob being deleted.
- the backup process of user-level reset is shown in Figure 8.
- the user controls the device 100 to restore the factory settings through the setting interface.
- the device 100 verifies the lock screen password input by the user. For example, the device 100 calculates the lock screen password input by the user to obtain a password hash value, and then compares the calculated password hash value with the saved password hash value, If the hash values of the two passwords are the same, it is determined that the verification is passed.
- the application program framework layer (framework) sends a broadcast message for restoring factory settings. Vold starts the backup key process after receiving the broadcast message, calls the keymaster TA through the CA to decrypt the FEKEK from the erasable partition, then encrypts the FEKEK with the default value (empty auth), and encrypts the default value with HUK, and the encrypted FEKEK and default values (an example of the seventh ciphertext and the eighth ciphertext) are saved in the non-erasable partition.
- the non-erasable partition refers to the data that will not be erased during the second type of reset (also known as "factory reset", that is, the user does not reset the device 100 through the system setting menu)
- the non-erasable partition can be /sec_storage, or other secure storage areas in TEE, such as replay protected memory block (RPMB).
- RPMB replay protected memory block
- the device 100 After the user instructs the device 100 to perform a user-level reset, the device 100 is triggered to perform key backup.
- the ciphertext 1 and keymaster_key_blob are stored in the erasable partition.
- the ciphertext 1 and keymaster_key_blob are stored in the non-erasable partition in the form of "default encrypted FEKEK and HUK encrypted default value”. partition.
- the device 100 After the key backup is completed, the device 100 enters into the formatting stage. In the formatting stage, the data in the erasable partition is cleared, and the data in the non-erasable partition is retained.
- the device 100 After the formatting is completed, the device 100 enters the key recovery stage.
- the ciphertext in the non-erasable partition (the default value encrypted by FEKEK and the default value encrypted by HUK) is copied to the erasable partition, thus completing the key recovery.
- the user needs to format the device 100 through the system setting menu, and the device 100 has the opportunity to back up the ciphertext (encrypted FEKEK) in the erasable partition, so that the files in the SD card are stored in the device 100 It can still be decrypted after formatting.
- the ciphertext in the erasable partition will be deleted without being copied to the non-erasable partition , so that the files in the SD card cannot be decrypted after the device 100 is formatted.
- the following introduces another embodiment of the method for storing ciphertext provided by the present application, which enables the files in the SD card to be decrypted after the device 100 is reset at the factory level.
- This embodiment can be applied to the device 100 together with the "user-level reset" embodiment described above, or can be applied to the device 100 alone.
- the device 100 executes the key backup process shown in FIG. 10 .
- the SD card encryption setting module calls the account login module through encryption instructions for subsequent processing. Based on the account login situation, the account login module has the following two processing methods.
- the account login module displays the account login interface shown in Figure 11, prompting the user to log in to the account (such as the Honor account). After the account login is successful, the account login module calculates the hash value of the account identifier (identifier, ID), and then transmits the hash value of the account ID to Vold.
- the device 100 can back up FEKEK at any time before performing the factory reset. Even if the subsequent device 100 performs the factory reset, it can Restore FEKEK after restart, thus solving the problem that files in SD card cannot be decrypted after factory reset.
- the following describes the process of decrypting files in the SD card after the device 100 performs a factory reset.
- the user first locks the screen of the device 100 (or shuts it down), and then presses a key combination (for example, "volume key” + “power key”) to make the device 100 enter the recovery mode, and the factory-level reset setting interface shown in FIG. 13 is displayed. . Subsequently, after the user clicks "restore factory settings", the device 100 displays the confirmation interface shown in FIG. 14 . After the user clicks "restore factory settings” on the interface shown in FIG. 13 , the device 100 executes factory reset, and displays the factory reset interface shown in FIG. 15 .
- a key combination for example, "volume key” + “power key”
- the device 100 restarts after completing the factory reset, runs the boot wizard program, and executes the key recovery process shown in FIG. 16 .
- the boot wizard program calls the mobile phone retrieval module to determine whether the factory reset protection (factory reset protection, FRP) state has been triggered.
- the mobile phone retrieval module calls the anti-theft TA through the anti-theft CA to determine whether the FRP status has been triggered. If the FRP status has been triggered, the mobile phone retrieval module displays the account verification interface shown in Figure 17.
- the account verified on the account verification interface is The account associated with the FRP status (that is, the last login account of the device 100 before performing the factory reset). After the user enters the correct password on this interface, the mobile phone recovery module notifies Vold that the verification of the account is successful. Then, Vold calls the keymaster TA through the CA to perform the following key recovery steps.
- keymaster TA obtains keymaster_key_blob_bak and ciphertext 2 from the non-erasable partition, first uses HUK to decrypt keymaster_key_blob_bak to obtain the hash value of the account ID, and then uses the hash value of the account ID to decrypt ciphertext 2 to obtain FEKEK.
- keymaster TA re-encrypts FEKEK with the default value (empty auth) to generate the third ciphertext, and encrypts the default value with HUK to generate the fourth ciphertext.
- the encrypted FEKEK and the default value are stored in the non-erasable partition (/sec_storage path) as the backup key.
- keymaster TA copies the encrypted FEKEK and default values to the erasable partition (/data path) for use when encrypting or decrypting files in the SD card.
- the old lock screen password is cleared. The above embodiment enables the device 100 to use the default value as the key to decrypt the SD card without setting a new lock screen password.
- the keymaster TA can not use the default value to encrypt FEKEK, and directly copy keymaster_key_blob_bak and ciphertext 2 from the non-erasable partition to the erasable partition, in this case, the device 100 can prompt the user to set a new lock screen password , in order to encrypt FEKEK with the new lock screen password.
- keymaster TA decrypts the FEKEK from the erasable partition, and transmits the FEKEK to the key ring through Vold.
- the file system uses FEK to encrypt files in the SD card, it obtains FEKEK from the key ring, uses FEKEK to encrypt FEK, and the encrypted FEK is stored in the metadata of the file.
- keymaster TA decrypts the FEKEK from the erasable partition, and transmits the FEKEK to the key ring through Vold.
- the file system uses FEKEK to decrypt the FEK from the metadata of the file on the SD card, and then uses the FEK to decrypt the file.
- ciphertext 1 and keymaster_key_blob are stored in the erasable partition
- ciphertext 2 and keymaster_key_blob_bak are stored in the non-erasable partition.
- ciphertext 1 is FEKEK encrypted with the password hash value
- keymaster_key_blob is stored using The password hash value encrypted by HUK
- ciphertext 2 is FEKEK encrypted with the hash value of the account ID
- keymaster_key_blob_bak is the hash value of the account ID encrypted with HUK.
- the device 100 After the formatting is completed, the device 100 enters the key recovery stage.
- the ciphertext (ciphertext 2 and keymaster_key_blob_bak) in the non-erasable partition is decrypted and encrypted, and copied to the erasable partition in the form of "default value encrypted FEKEK and HUK encrypted default value", Key recovery is thus completed.
- the corresponding device includes a corresponding hardware structure and/or software module for performing each function.
- the present application can be implemented in the form of hardware or a combination of hardware and computer software in combination with the units and algorithm steps of each example described in the embodiments disclosed herein. Whether a certain function is executed by hardware or computer software drives hardware depends on the specific application and design constraints of the technical solution. Skilled artisans may use different methods to implement the described functions for each specific application, but such implementation should not be regarded as exceeding the scope of the present application.
- the present application may divide the device for storing ciphertext into functional units according to the above method example, for example, each function may be divided into each functional unit, or two or more functions may be integrated into one unit.
- the above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units. It should be noted that the division of units in this application is schematic, and is only a logical function division, and there may be other division methods in actual implementation.
- Fig. 19 is a schematic structural diagram of a device for storing ciphertext provided by the present application.
- the device 1900 includes a processing unit 1910 and an input unit 1920 .
- the input unit 1920 is used to: obtain an encryption instruction, the encryption instruction indicates to encrypt files in the external memory;
- the processing unit 1910 is configured to: obtain the characteristic value of the first account identifier according to the encryption instruction; use the characteristic value of the first account identifier to encrypt the first key to generate a first ciphertext, wherein the first key is used to encrypt a second key, and the second key is used to encrypt the first file in the external memory; encrypt the characteristic value of the first account identifier to generate a second ciphertext; convert the first The ciphertext and the second ciphertext are stored in the non-erasable partition.
- the input unit 1920 is further configured to: acquire instruction information for switching accounts;
- the processing unit 1910 is further configured to: verify the first account ID according to the instruction information; obtain the feature value of the second account ID after the verification of the first account ID is passed; A value updates the first ciphertext and the second ciphertext.
- the processing unit 1910 is further configured to: determine whether the FRP state has been triggered; when the FRP state has been triggered, verify the first account ID; when the verification of the first account ID is successful, Decrypt the first ciphertext and the second ciphertext to generate the first key.
- the processing unit 1910 is further configured to: use a default value to encrypt the first key to generate a third ciphertext; encrypt the default value to generate a fourth ciphertext; combine the third ciphertext and the The fourth ciphertext is stored in the non-erasable partition.
- the processing unit 1910 is further configured to: copy the third ciphertext and the fourth ciphertext from the non-erasable partition to the erasable partition; according to the The third ciphertext and the fourth ciphertext generate the first key; and decrypt the file in the external memory according to the first key.
- the device 1900 executes the method for storing ciphertext and the beneficial effects produced, refer to the relevant description in the method embodiments.
- FIG. 20 shows a schematic structural diagram of an electronic device provided by the present application.
- the dashed line in Figure 20 indicates that the unit or the module is optional.
- the device 2000 may be used to implement the methods described in the foregoing method embodiments.
- the device 2000 includes one or more processors 2001, and the one or more processors 2001 can support the device 2000 to implement the method in the method embodiment.
- the processor 2001 may be a general purpose processor or a special purpose processor.
- the processor 2001 may be a central processing unit (central processing unit, CPU), a digital signal processor (digital signal processor, DSP), an application specific integrated circuit (ASIC), a field programmable gate array (field programmable gate array, FPGA) or other programmable logic devices such as discrete gates, transistor logic devices, or discrete hardware components.
- the processor 2001 may be used to control the device 2000, execute software programs, and process data of the software programs.
- the device 2000 may also include a communication unit 2005, configured to implement signal input (reception) and output (transmission).
- the device 2000 may be a chip
- the communication unit 2005 may be an input and/or output circuit of the chip, or the communication unit 2005 may be a communication interface of the chip, and the chip may serve as a component of a terminal device or other electronic devices.
- the device 2000 may be a terminal device, and the communication unit 2005 may be a transceiver of the terminal device, or the communication unit 2005 may be a transceiver circuit of the terminal device.
- the device 2000 may include one or more memories 2002, on which a program 2004 is stored, and the program 2004 may be run by the processor 2001 to generate instructions 2003, so that the processor 2001 executes the methods described in the above method embodiments according to the instructions 2003.
- data may also be stored in the memory 2002 .
- the processor 2001 can also read the data stored in the memory 2002 (such as the first ciphertext and the second ciphertext), the data can be stored in the same storage address as the program 2004, and the data can also be stored in the same storage address as the program 2004. 2004 is stored at a different memory address.
- the processor 2001 and the memory 2002 may be set separately, or may be integrated together, for example, integrated on a system-on-chip (system on chip, SOC) of a terminal device.
- SOC system on chip
- the present application also provides a computer program product, which implements the method described in any method embodiment in the present application when the computer program product is executed by the processor 2001 .
- the computer program product can be stored in the memory 2002, such as program 2004, and the program 2004 is finally converted into an executable target file that can be executed by the processor 2001 through processes such as preprocessing, compiling, assembling and linking.
- the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a computer, the method described in any method embodiment in the present application is implemented.
- the computer program may be a high-level language program or an executable object program.
- the computer-readable storage medium is, for example, the memory 2002 .
- the memory 2002 may be a volatile memory or a nonvolatile memory, or, the memory 2002 may include both a volatile memory and a nonvolatile memory.
- the non-volatile memory can be read-only memory (read-only memory, ROM), programmable read-only memory (programmable ROM, PROM), erasable programmable read-only memory (erasable PROM, EPROM), electrically programmable Erases programmable read-only memory (electrically EPROM, EEPROM) or flash memory.
- Volatile memory can be random access memory (RAM), which acts as external cache memory.
- RAM random access memory
- SRAM static random access memory
- DRAM dynamic random access memory
- DRAM synchronous dynamic random access memory
- SDRAM double data rate synchronous dynamic random access memory
- double data rate SDRAM double data rate SDRAM
- DDR SDRAM enhanced synchronous dynamic random access memory
- ESDRAM enhanced synchronous dynamic random access memory
- serial link DRAM SLDRAM
- direct memory bus random access memory direct rambus RAM, DR RAM
- the disclosed systems, devices and methods may be implemented in other ways. For example, some features of the method embodiments described above may be omitted, or not implemented.
- the device embodiments described above are only illustrative, and the division of units is only a logical function division. In actual implementation, there may be other division methods, and multiple units or components may be combined or integrated into another system.
- the coupling between the various units or the coupling between the various components may be direct coupling or indirect coupling, and the above coupling includes electrical, mechanical or other forms of connection.
- serial numbers of the processes do not mean the order of execution, and the execution order of the processes should be determined by their functions and internal logic, rather than by the embodiments of the present application.
- the implementation process constitutes any limitation.
- system and “network” are often used herein interchangeably.
- the term “and/or” in this article is just an association relationship describing associated objects, which means that there can be three relationships, for example, A and/or B, which can mean: A exists alone, A and B exist simultaneously, and A and B exist alone. There are three cases of B.
- the character "/" in this article generally indicates that the contextual objects are an "or” relationship.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Telephone Function (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (39)
- 一种保存密文的方法,其特征在于,包括:获取加密指令,所述加密指令指示加密外置存储器中的文件;根据所述加密指令获取第一账号标识的特征值;使用所述第一账号标识的特征值加密第一密钥,生成第一密文,其中,所述第一密钥用于加密第二密钥,所述第二密钥用于加密所述外置存储器中的第一文件;加密所述第一账号标识的特征值,生成第二密文;将所述第一密文和所述第二密文存储于不可擦除分区。
- 根据权利要求1所述的方法,其特征在于,所述方法还包括:获取切换账号的指示信息;根据所述指示信息校验所述第一账号标识;所述第一账号标识校验通过后,获取第二账号标识的特征值;根据所述第二账号标识的特征值更新所述第一密文和所述第二密文。
- 根据权利要求1所述的方法,其特征在于,所述方法还包括:在工厂级重置完成后,校验所述第一账号标识;当所述第一账号标识校验成功时,解密所述第一密文和所述第二密文,生成所述第一密钥。
- 根据权利要求3所述的方法,其特征在于,所述校验所述第一账号标识,包括:当工厂级重置保护FRP状态已被触发时,校验所述第一账号标识。
- 根据权利要求3或4所述的方法,其特征在于,所述方法还包括:使用默认值加密所述第一密钥,生成第三密文;加密所述默认值,生成第四密文;将所述第三密文和所述第四密文存储于所述不可擦除分区。
- 根据权利要求5所述的方法,其特征在于,所述方法还包括:将所述第三密文和所述第四密文从所述不可擦除分区拷贝至可擦除分区;根据所述可擦除分区中的所述第三密文和所述第四密文生成所述第一密钥;根据所述第一密钥解密所述外置存储器中加密的所述第一文件。
- 根据权利要求3至6中任一项所述的方法,其特征在于,所述校验所述第一账号标识之前,所述方法还包括:获取recovery界面触发的工厂级重置指令;根据所述工厂级重置指令格式化可擦除分区中的数据。
- 根据权利要求1至7中任一项所述的方法,其特征在于,所述使用所述第一账号标识的特征值加密第一密钥,包括:调用密钥管理模块keymaster TA执行:使用所述第一账号标识的特征值加密所述第一密钥;所述加密所述第一账号标识的特征值,包括:调用所述keymaster TA执行:加密所述第一账号标识的特征值。
- 根据权利要求1至8中任一项所述的方法,其特征在于,所述将所述第一密文和所述第二密文存储于不可擦除分区,包括:调用可信执行环境应用程序接口TEE API执行:将所述第一密文和所述第二密文存储于所述不可擦除分区。
- 根据权利要求1至9中任一项所述的方法,其特征在于,所述第一密钥还用于加密第三密钥,所述第三密钥用于加密所述外置存储器中加密的第二文件。
- 根据权利要求1至10中任一项所述的方法,其特征在于,所述方法还包括:根据所述加密指令获取锁屏口令的特征值;使用所述锁屏口令的特征值加密所述第一密钥,生成第五密文;加密所述锁屏口令的特征值,生成第六密文;将所述第五密文和所述第六密文存储于可擦除分区。
- 根据权利要求11所述的方法,其特征在于,所述使用所述锁屏口令的特征值加密所述第一密钥,包括:调用keymaster TA执行:使用所述锁屏口令的特征值加密所述第一密钥;所述加密所述锁屏口令的特征值,包括:调用所述keymaster TA执行:加密所述锁屏口令的特征值。
- 根据权利要求11或12所述的方法,其特征在于,所述方法还包括:获取设置界面触发的用户级重置指令;根据所述用户级重置指令将所述第五密文和所述第六密文备份至所述不可擦除分区。
- 根据权利要求13所述的方法,其特征在于,所述根据所述用户级重置指令将所述第五密文和所述第六密文备份至所述不可擦除分区,包括:根据所述用户级重置指令从所述第五密文和所述第六密文中解密出所述第一密钥;使用默认值加密所述第一密钥,生成第七密文;加密所述默认值,生成第八密文;将所述第七密文和所述第八密文存储在所述不可擦除分区中。
- 根据权利要求14所述的方法,其特征在于,所述方法还包括:在用户级重置完成后,将所述第七密文和所述第八密文从所述不可擦除分区拷贝至所述可擦除分区;从所述可擦除分区中的所述第七密文和所述第八密文中解密出所述第一密钥;根据所述第一密钥解密所述外置存储器中加密的所述第一文件。
- 根据权利要求11至15中任一项所述的方法,其特征在于,所述可擦除分区为data分区,所述锁屏口令的特征值为所述锁屏口令的哈希值。
- 根据权利要求1至16中任一项所述的方法,其特征在于,所述不可擦除分区为sec_storage分区,所述第一账号标识的特征值为所述第一账号标识的哈希值。
- 一种保存密文的方法,其特征在于,包括:显示外置存储器的加密设置界面;接收用户在所述加密设置界面上进行的第一操作;响应于所述第一操作,加密所述外置存储器中的文件;接收所述用户的第二操作;响应于所述第二操作,显示工厂级重置设置界面;接收所述用户在所述工厂级重置设置界面进行的第三操作;响应于所述第三操作,进行工厂级重置;显示账号校验界面;接收所述用户在所述账号校验界面输入的校验信息;当所述校验信息校验通过时,并且,当接收到用户访问所述外置存储器中的文件的操作时,解密所述外置存储器中加密的文件。
- 根据权利要求18所述的方法,其特征在于,所述方法还包括:接收所述用户在所述加密设置界面上进行的第四操作;响应于所述第四操作,加密所述外置存储器中的文件;接收所述用户的第五操作;响应于所述第五操作,显示用户级重置设置界面;接收所述用户在所述用户级重置设置界面进行的第六操作;响应于所述第六操作,进行用户级重置;显示锁屏口令校验界面;接收所述用户在所述锁屏口令界面输入的锁屏口令;当所述锁屏口令校验通过时,并且,当接收到用户访问所述外置存储器中的文件的操作时,解密所述外置存储器中加密的文件。
- 根据权利要求18或19所述的方法,其特征在于,所述接收用户在所述加密设置界面上进行的第一操作,包括获取加密指令,所述加密指令指示加密外置存储器中的文件;所述方法还包括:根据所述加密指令获取第一账号标识的特征值;使用所述第一账号标识的特征值加密第一密钥,生成第一密文,其中,所述第一密钥用于加密第二密钥,所述第二密钥用于加密所述外置存储器中的第一文件;加密所述第一账号标识的特征值,生成第二密文;将所述第一密文和所述第二密文存储于不可擦除分区。
- 根据权利要求20所述的方法,其特征在于,所述方法还包括:获取切换账号的指示信息;根据所述指示信息校验所述第一账号标识;所述第一账号标识校验通过后,获取第二账号标识的特征值;根据所述第二账号标识的特征值更新所述第一密文和所述第二密文。
- 根据权利要求20所述的方法,其特征在于,所述解密所述外置存储器中加密的文件之前,所述方法还包括:在所述工厂级重置完成后,根据所述校验信息校验所述第一账号标识;当所述第一账号标识校验成功时,解密所述第一密文和所述第二密文,生成所述第一密钥。
- 根据权利要求22所述的方法,其特征在于,所述根据所述校验信息校验所述第一账号标识,包括:当工厂级重置保护FRP状态已被触发时,根据所述校验信息校验所述第一账号标 识。
- 根据权利要求22或23所述的方法,其特征在于,所述方法还包括:使用默认值加密所述第一密钥,生成第三密文;加密所述默认值,生成第四密文;将所述第三密文和所述第四密文存储于所述不可擦除分区。
- 根据权利要求24所述的方法,其特征在于,所述方法还包括:将所述第三密文和所述第四密文从所述不可擦除分区拷贝至可擦除分区;根据所述可擦除分区中的所述第三密文和所述第四密文生成所述第一密钥;根据所述第一密钥解密所述外置存储器中加密的所述第一文件。
- 根据权利要求20至25中任一项所述的方法,其特征在于,所述响应于所述第三操作,进行工厂级重置,包括:获取所述第三操作在所述工厂级重置设置界面触发的工厂级重置指令;根据所述工厂级重置指令格式化可擦除分区中的数据。
- 根据权利要求20至26中任一项所述的方法,其特征在于,所述使用所述第一账号标识的特征值加密第一密钥,包括:调用密钥管理模块执行:使用所述第一账号标识的特征值加密所述第一密钥;所述加密所述第一账号标识的特征值,包括:调用所述密钥管理模块执行:加密所述第一账号标识的特征值。
- 根据权利要求20至27中任一项所述的方法,其特征在于,所述将所述第一密文和所述第二密文存储于不可擦除分区,包括:调用可信执行环境应用程序接口执行:将所述第一密文和所述第二密文存储于所述不可擦除分区。
- 根据权利要求20至28中任一项所述的方法,其特征在于,所述第一密钥还用于加密第三密钥,所述第三密钥用于加密所述外置存储器中加密的第二文件。
- 根据权利要求20至29中任一项所述的方法,其特征在于,所述方法还包括:根据所述加密指令获取锁屏口令的特征值;使用所述锁屏口令的特征值加密所述第一密钥,生成第五密文;加密所述锁屏口令的特征值,生成第六密文;将所述第五密文和所述第六密文存储于可擦除分区。
- 根据权利要求30所述的方法,其特征在于,所述使用所述锁屏口令的特征值加密所述第一密钥,包括:调用密钥管理模块执行:使用所述锁屏口令的特征值加密所述第一密钥;所述加密所述锁屏口令的特征值,包括:调用所述密钥管理模块执行:加密所述锁屏口令的特征值。
- 根据权利要求30或31所述的方法,其特征在于,所述方法还包括:获取设置界面触发的用户级重置指令;根据所述用户级重置指令将所述第五密文和所述第六密文备份至所述不可擦除分区。
- 根据权利要求32所述的方法,其特征在于,所述根据所述用户级重置指令将 所述第五密文和所述第六密文备份至所述不可擦除分区,包括:根据所述用户级重置指令从所述第五密文和所述第六密文中解密出所述第一密钥;使用默认值加密所述第一密钥,生成第七密文;加密所述默认值,生成第八密文;将所述第七密文和所述第八密文存储在所述不可擦除分区中。
- 根据权利要求33所述的方法,其特征在于,所述方法还包括:在用户级重置完成后,将所述第七密文和所述第八密文从所述不可擦除分区拷贝至所述可擦除分区;从所述可擦除分区中的所述第七密文和所述第八密文中解密出所述第一密钥;根据所述第一密钥解密所述外置存储器中加密的所述第一文件。
- 根据权利要求30至34中任一项所述的方法,其特征在于,所述可擦除分区为数据分区,所述锁屏口令的特征值为所述锁屏口令的哈希值。
- 根据权利要求20至35中任一项所述的方法,其特征在于,所述不可擦除分区为安全存储分区,所述第一账号标识的特征值为所述第一账号标识的哈希值。
- 一种保存密文的装置,其特征在于,所述装置包括处理器和存储器,所述存储器用于存储计算机程序,所述处理器用于从所述存储器中调用并运行所述计算机程序,使得所述装置执行权利要求1至17中任一项所述的方法,或者,使得所述装置执行权利要求18至36中任一项所述的方法。
- 一种芯片,其特征在于,包括处理器,当所述处理器执行指令时,所述处理器执行如权利要求1至17中任一项所述的方法,或者,使得所述处理器执行权利要求18至36中任一项所述的方法。
- 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质存储了计算机程序,当所述计算机程序被处理器执行时,使得所述处理器执行权利要求1至17中任一项所述的方法,或者,使得所述处理器执行权利要求18至36中任一项所述的方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP22810366.9A EP4152198B1 (en) | 2021-05-24 | 2022-05-11 | Method and apparatus for storing ciphertext |
| US18/003,265 US12526137B2 (en) | 2021-05-24 | 2022-05-11 | Method for saving ciphertext and apparatus |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202110566480.8 | 2021-05-24 | ||
| CN202110566480.8A CN113408016B (zh) | 2021-05-24 | 2021-05-24 | 保存密文的方法和装置 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022247639A1 true WO2022247639A1 (zh) | 2022-12-01 |
Family
ID=77674679
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/092296 Ceased WO2022247639A1 (zh) | 2021-05-24 | 2022-05-11 | 保存密文的方法和装置 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US12526137B2 (zh) |
| EP (1) | EP4152198B1 (zh) |
| CN (2) | CN115391849A (zh) |
| WO (1) | WO2022247639A1 (zh) |
Families Citing this family (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114168160B (zh) | 2020-09-10 | 2026-04-21 | 荣耀终端股份有限公司 | 应用模块启动方法和电子设备 |
| CN115391849A (zh) * | 2021-05-24 | 2022-11-25 | 荣耀终端有限公司 | 保存密文的方法和装置 |
| US12585759B2 (en) * | 2021-06-30 | 2026-03-24 | Ivanti, Inc. | Application integrity verification |
| CN114662157B (zh) * | 2022-05-25 | 2022-08-26 | 湖南工商大学 | 社交文本数据流的块压缩感知不可区分性保护方法及装置 |
| CN115562573B (zh) * | 2022-08-30 | 2024-10-29 | 荣耀终端有限公司 | 一种存储数据的方法、通信系统、电子设备及存储介质 |
| CN116484431B (zh) * | 2023-06-21 | 2024-05-17 | 荣耀终端有限公司 | 一种数据保护方法、电子设备及存储介质 |
| CN118568736A (zh) * | 2024-08-01 | 2024-08-30 | 上海艾拉比智能科技有限公司 | 一种基于frp的设备防盗方法及系统 |
| CN119513877B (zh) * | 2024-11-15 | 2025-10-03 | 南方电网科学研究院有限责任公司 | 可搜索加密方法、计算机设备、存储介质和计算机程序产品 |
Citations (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20120185759A1 (en) * | 2011-01-13 | 2012-07-19 | Helen Balinsky | System and method for collaboratively editing a composite document |
| CN105809045A (zh) * | 2016-03-15 | 2016-07-27 | 青岛海信移动通信技术股份有限公司 | 一种设备系统在数据重置时的处理方法和装置 |
| US10164955B1 (en) * | 2016-05-25 | 2018-12-25 | Google Llc | Volatile encryption keys |
| US20200151356A1 (en) * | 2017-08-11 | 2020-05-14 | Duality Technologies, Inc. | System and method for fast and efficient searching of encrypted ciphertexts |
| CN111614698A (zh) * | 2017-04-28 | 2020-09-01 | 李丽萍 | 擦除终端数据的方法及装置 |
| CN111966373A (zh) * | 2020-08-11 | 2020-11-20 | Oppo(重庆)智能科技有限公司 | Apn的重置方法、终端设备及存储介质 |
| CN112262548A (zh) * | 2019-02-28 | 2021-01-22 | 华为技术有限公司 | 一种文件处理方法及终端设备 |
| CN113408016A (zh) * | 2021-05-24 | 2021-09-17 | 荣耀终端有限公司 | 保存密文的方法和装置 |
Family Cites Families (20)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7729690B1 (en) | 2006-02-15 | 2010-06-01 | Trend Micro, Inc. | Backup and restore of user data for mobile telephone |
| CN101075874B (zh) | 2007-06-28 | 2010-06-02 | 腾讯科技(深圳)有限公司 | 认证方法和认证系统 |
| CN201518127U (zh) * | 2009-10-13 | 2010-06-30 | 航天信息股份有限公司 | 基于口令认证的加密型移动存储器 |
| US8700895B1 (en) * | 2010-06-30 | 2014-04-15 | Google Inc. | System and method for operating a computing device in a secure mode |
| US20140373184A1 (en) * | 2013-06-12 | 2014-12-18 | Lookout, Inc. | Mobile device persistent security mechanism |
| US20180091301A1 (en) * | 2016-05-06 | 2018-03-29 | ZeroDB, Inc. | Method and system for switching public keys in ciphertexts |
| US20170337390A1 (en) * | 2016-05-18 | 2017-11-23 | Qualcomm Incorporated | Data protection at factory reset |
| US10678924B2 (en) | 2016-08-10 | 2020-06-09 | Qualcomm Incorporated | Hardware-based software-resilient user privacy exploiting ephemeral data retention of volatile memory |
| CN106952094B (zh) * | 2017-03-10 | 2018-09-04 | 腾讯科技(深圳)有限公司 | 电子票据管理方法及装置 |
| US10476858B2 (en) * | 2017-05-08 | 2019-11-12 | Dell Products L.P. | System and method to remotely secure a compromised information handling system |
| CN111566989B (zh) * | 2018-06-14 | 2022-06-07 | 华为技术有限公司 | 一种密钥处理方法及装置 |
| KR102794916B1 (ko) * | 2018-07-31 | 2025-04-15 | 삼성전자주식회사 | 팩토리 데이터 리셋 기능에 의해 제거된 어플리케이션을 복원하는 장치 및 방법 |
| US11163908B2 (en) * | 2019-03-08 | 2021-11-02 | Microsoft Technology Licensing, Llc | Device state driven encryption key management |
| CN110059499A (zh) * | 2019-03-22 | 2019-07-26 | 华为技术有限公司 | 一种文件访问权限认证方法及电子设备 |
| CN110377250B (zh) * | 2019-06-05 | 2021-07-16 | 华为技术有限公司 | 一种投屏场景下的触控方法及电子设备 |
| EP4036775A4 (en) * | 2019-11-08 | 2022-09-14 | Huawei Technologies Co., Ltd. | DATA PROCESSING METHOD AND DEVICE AND SYSTEM CHIP |
| KR102325986B1 (ko) * | 2020-01-22 | 2021-11-12 | 네이버클라우드 주식회사 | 스토리지 암호화의 동적 적용을 위한 방법 및 시스템 |
| CN111935138B (zh) * | 2020-08-07 | 2022-03-18 | 珠海海鹦安全科技有限公司 | 安全登录的防护方法、装置及电子设备 |
| CN112560058B (zh) * | 2020-12-17 | 2022-12-30 | 山东华芯半导体有限公司 | 基于智能密码钥匙的ssd分区加密存储系统及其实现方法 |
| CN112632593B (zh) * | 2021-03-09 | 2021-05-25 | 冷杉云(北京)科技股份有限公司 | 数据存储方法、数据处理方法、设备以及存储介质 |
-
2021
- 2021-05-24 CN CN202210499853.9A patent/CN115391849A/zh active Pending
- 2021-05-24 CN CN202110566480.8A patent/CN113408016B/zh active Active
-
2022
- 2022-05-11 WO PCT/CN2022/092296 patent/WO2022247639A1/zh not_active Ceased
- 2022-05-11 EP EP22810366.9A patent/EP4152198B1/en active Active
- 2022-05-11 US US18/003,265 patent/US12526137B2/en active Active
Patent Citations (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20120185759A1 (en) * | 2011-01-13 | 2012-07-19 | Helen Balinsky | System and method for collaboratively editing a composite document |
| CN105809045A (zh) * | 2016-03-15 | 2016-07-27 | 青岛海信移动通信技术股份有限公司 | 一种设备系统在数据重置时的处理方法和装置 |
| US10164955B1 (en) * | 2016-05-25 | 2018-12-25 | Google Llc | Volatile encryption keys |
| CN111614698A (zh) * | 2017-04-28 | 2020-09-01 | 李丽萍 | 擦除终端数据的方法及装置 |
| US20200151356A1 (en) * | 2017-08-11 | 2020-05-14 | Duality Technologies, Inc. | System and method for fast and efficient searching of encrypted ciphertexts |
| CN112262548A (zh) * | 2019-02-28 | 2021-01-22 | 华为技术有限公司 | 一种文件处理方法及终端设备 |
| CN111966373A (zh) * | 2020-08-11 | 2020-11-20 | Oppo(重庆)智能科技有限公司 | Apn的重置方法、终端设备及存储介质 |
| CN113408016A (zh) * | 2021-05-24 | 2021-09-17 | 荣耀终端有限公司 | 保存密文的方法和装置 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP4152198A4 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN113408016A (zh) | 2021-09-17 |
| EP4152198B1 (en) | 2025-10-15 |
| CN113408016B (zh) | 2022-07-05 |
| EP4152198A4 (en) | 2024-01-17 |
| US12526137B2 (en) | 2026-01-13 |
| EP4152198A1 (en) | 2023-03-22 |
| CN115391849A (zh) | 2022-11-25 |
| US20230254143A1 (en) | 2023-08-10 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN113408016B (zh) | 保存密文的方法和装置 | |
| CN113609498B (zh) | 数据保护方法及电子设备 | |
| CN110752929B (zh) | 应用程序的处理方法及相关产品 | |
| EP4063203A1 (en) | Authentication method and medium and electronic apparatus thereof | |
| CN114553814B (zh) | 处理推送消息的方法和装置 | |
| CN113168461A (zh) | 一种删除安全业务的方法及电子设备 | |
| CN112930533B (zh) | 一种电子设备的控制方法及电子设备 | |
| WO2020010584A1 (zh) | 一种终端恢复出厂设置时的数据恢复方法及终端 | |
| WO2020015259A1 (zh) | 一种数据备份方法及终端 | |
| CN115904282B (zh) | 一种投屏方法、设备、存储介质及计算机程序产品 | |
| CN114546969A (zh) | 一种文件共享方法、装置及电子设备 | |
| CN116339510A (zh) | 眼动追踪方法、装置、电子设备及计算机可读存储介质 | |
| CN112966297B (zh) | 数据保护方法、系统、介质及电子设备 | |
| CN116484431B (zh) | 一种数据保护方法、电子设备及存储介质 | |
| CN114254334B (zh) | 数据处理方法、装置、设备及存储介质 | |
| CN116669020B (zh) | 一种密码管理方法、系统和电子设备 | |
| CN114692119A (zh) | 校验应用的方法和电子设备 | |
| CN115017227B (zh) | 数据同步方法及相关设备 | |
| US12524388B2 (en) | Picture storage method and apparatus, and terminal device | |
| CN116414500B (zh) | 电子设备操作引导信息录制方法、获取方法和终端设备 | |
| RU2809740C2 (ru) | Способ обработки файла, хранящегося во внешней памяти | |
| WO2023071985A1 (zh) | 一种远程支付方法、电子设备及系统 | |
| CN116991345A (zh) | 投屏方法和电子设备 | |
| HK40076905A (zh) | 保存密文的方法和装置 | |
| CN120428885B (zh) | 应用窗口切换方法、电子设备及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| ENP | Entry into the national phase |
Ref document number: 2022810366 Country of ref document: EP Effective date: 20221216 |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22810366 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWG | Wipo information: grant in national office |
Ref document number: 2022810366 Country of ref document: EP |
|
| WWG | Wipo information: grant in national office |
Ref document number: 18003265 Country of ref document: US |