The invention relates to a method and
system for encrypting and isolating storage data of a credential mobile terminal, and belongs to the technical field of information. The method comprises the following steps: encrypting and partitioning the whole
storage area, and setting an access strategy according to user permission; when a user requests to access, executing multi-factor
authentication containing a
password and an external hardware
certificate, and adding biological characteristic
authentication; after the
authentication is passed, an
encryption key is taken from the domestic security
chip; and encrypting and decrypting data by using the secret key, and opening corresponding partition access according to authority. The
system comprises a storage partition module, an identity authentication module, a
key management module, an
encryption and decryption module and an
authority control module and is used for executing the method. The method also comprises the steps of equipment startup trusted boot and
firmware upgrade verification, is based on a custom curing
system, and is compatible with Android 10 +. The problems of poor hardware
controllability and positioning security risk of the creative mobile terminal are solved, and full-
link data security protection is realized.