Locking control method, terminal device, storage medium and program product

By locking the system interface of the terminal device, setting the one-time programmable memory chip, and locking the user identification module, combined with prompt information, the problem of malicious user default is solved, achieving fast and reliable terminal device management and reducing losses for manufacturers.

CN122152472APending Publication Date: 2026-06-05SPREADTRUM COMMUNICATION (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SPREADTRUM COMMUNICATION (SHANGHAI) CO LTD
Filing Date
2026-03-10
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

In the current technology, under the buy-now-pay-later strategy for consumer electronics products, malicious default by users can lead to losses for manufacturers or guarantor companies. Furthermore, existing manual control is inefficient and cannot quickly and effectively restrict the unauthorized use of user terminal devices.

Method used

By acquiring the lock command, the system interface of the terminal device is locked, the lock flag of the one-time programmable memory chip is set, and the user identification module is locked. Combined with the display prompt information, multi-dimensional locking and state solidification are achieved to ensure that the terminal device is in a locked state.

Benefits of technology

It enables rapid and reliable control of terminal devices, restricts basic user operations, makes the hardware-level lock state irreversible, strengthens communication function restrictions, clearly informs users of the reasons for the lock, and reduces losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122152472A_ABST
    Figure CN122152472A_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a locking control method, a terminal device, a storage medium and a program product. The method comprises: when a first instruction is acquired, locking a system interface of the terminal device based on the first instruction, the first instruction being used to indicate locking the terminal device, the first instruction comprising first prompt information, the first prompt information being used to prompt a user of the terminal device to standardize a behavior; setting a lock flag bit of a one-time programmable storage chip of the terminal device to a first value based on the first instruction, the first value being used to indicate that the terminal device is in a locked state; locking a user identification module of the terminal device based on the first instruction; and when the system interface of the terminal device is locked, the lock flag bit is the first value, and the user identification module is locked, displaying the first prompt information. The method is used to improve the efficiency of managing and controlling the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to a locking control method, terminal device, storage medium, and program product. Background Technology

[0002] The "buy now, pay later" strategy is widely used in consumer electronics products. While it can be convenient for users and increase sales for manufacturers, malicious defaults by users can cause losses to manufacturers or guarantor companies. Reliable technical means are urgently needed to reduce these losses.

[0003] Existing technologies primarily employ manual control for the aforementioned breaches of contract. Upon discovering a user's malicious breach of contract, manual verification of information and contact with the user are conducted to urge them to fulfill their obligations. If the user refuses to fulfill their obligations, manual on-site investigation is carried out.

[0004] The core technical problem with existing manual control methods is their low efficiency. Manual operation is time-consuming and cannot quickly control the terminal devices of users who violate regulations. Summary of the Invention

[0005] The locking control method, terminal device, storage medium, and program product provided in this application are used to improve the efficiency of managing and controlling terminal devices.

[0006] In a first aspect, embodiments of this application provide a locking control method, including:

[0007] When the first instruction is received, the system interface of the terminal device is locked based on the first instruction. The first instruction is used to instruct the terminal device to be locked. The first instruction includes a first prompt message, which is used to prompt the user of the terminal device to use the terminal device in a standardized manner.

[0008] Based on the first instruction, the lock flag bit of the one-time programmable memory chip of the terminal device is set to a first value, which is used to indicate that the terminal device is in a locked state;

[0009] Based on the first instruction, the user identification module of the terminal device is locked;

[0010] When the system interface of the terminal device is locked, the lock flag is set to the first value, and the user identification module is locked, the first prompt message is displayed.

[0011] Secondly, embodiments of this application provide a locking control device, comprising:

[0012] The locking module is used to lock the system interface of the terminal device based on the first instruction when a first instruction is received. The first instruction is used to instruct the terminal device to be locked. The first instruction includes a first prompt message, which is used to prompt the user of the terminal device to use the device in a standardized manner.

[0013] The locking module is also used to set the locking flag of the one-time programmable memory chip of the terminal device to a first value based on the first instruction. The first value is used to indicate that the terminal device is in a locked state.

[0014] The locking module is also used to lock the user identification module of the terminal device based on the first instruction;

[0015] The display module is used to display a first prompt message when the system interface of the terminal device is locked, the lock flag is set to the first value, and the user identification module is locked.

[0016] Thirdly, embodiments of this application provide a terminal device, including: a memory and a processor;

[0017] The memory stores the instructions that the computer executes;

[0018] The processor executes computer execution instructions stored in memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0019] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0020] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0021] The locking control method, terminal device, storage medium, and program product provided in this application can directly restrict users' basic operations on the terminal by acquiring a locking command and locking the system interface of the terminal device, quickly blocking users from using the device illegally. By setting the locking flag bit of the one-time programmable storage chip to a first value, the locking state can be solidified at the hardware level, preventing users from unlocking the device through software means and improving the reliability of the locking. By locking the user identification module of the terminal device, the communication function of the terminal can be further restricted, strengthening the control. Furthermore, when all three locking conditions are met, a prompt message is displayed, clearly informing the user of the reason for the locking and the performance requirements, achieving rapid, accurate, and reliable control over the terminal devices of maliciously defaulting users. Attached Figure Description

[0022] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0023] Figure 1This is a schematic diagram of the system architecture of the locking control terminal device provided in the embodiments of this application;

[0024] Figure 2 Flowchart of the locking control method provided in the embodiments of this application Figure 1 ;

[0025] Figure 3 Flowchart of the locking control method provided in the embodiments of this application Figure 2 ;

[0026] Figure 4 This is a schematic diagram of the locking control device provided in the embodiments of this application;

[0027] Figure 5 This is a schematic diagram of the structure of the terminal device provided in the embodiments of this application.

[0028] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0029] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0030] To address the aforementioned technical issues, the following technical concept is proposed: By responding to a lock command containing prompt information, a multi-dimensional lock operation is performed on the terminal device, and the lock state of the terminal device is solidified. At the same time, a prompt information is output when all multi-dimensional lock conditions are met. Through the design that combines multi-dimensional lock with state solidification and prompt functions, rapid and reliable control of the terminal device can be achieved, thereby solving related control problems and reducing losses.

[0031] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0032] Figure 1 This is a schematic diagram of the system architecture of the locking control terminal device provided in an embodiment of this application. As shown in the figure, it includes:

[0033] A rich execution environment (REE) refers to the general operating environment of a terminal device, which carries applications and services that are not of a high security level (such as telephone services, system interfaces, and conventional lock-up applications). It is the core carrier for terminal user interaction and basic business operations.

[0034] A Trusted Execution Environment (TEE) is a high-security operating environment isolated from the REE. It has independent resources and security mechanisms, and only hosts trusted applications. It is used to perform core security operations such as hardware-level hardening, key management, and security verification in terminal locking.

[0035] One-time programmable memory chips (OTPs) are hardware carriers used to permanently store lock flags. Once data is written to them, the lock flags cannot be erased, ensuring that the lock state cannot be tampered with by software. They are the core components of hardware-level locking.

[0036] A Replay Protected Memory Block (RPMB) embedded multimedia card refers to a storage module with replay attack protection capabilities. It is used to store critical security data locked by the terminal (such as lock command verification information) to prevent data from being tampered with or replayed.

[0037] A modem is the core communication module of a terminal, responsible for the modulation and demodulation of wireless signals and the management of the communication functions of the user identification module.

[0038] The Subscriber Identity Module Lock (SIM Lock) is used to lock the terminal's communication functions. It belongs to the Modem and, once locked, prevents the terminal from authenticating and communicating with the SIM.

[0039] The Lock Trusted Application (LTA) is a core trusted application within the TEE, responsible for executing the core security logic for terminal locking and coordinating locking operations at both the hardware and software levels.

[0040] The Production Deployment Trusted Application (TA) is responsible for the initial deployment of security parameters and keys when the terminal leaves the factory, providing basic security support for the locking function.

[0041] Key Master TA (Key Master Trusted Application) is responsible for key generation, management, and verification during the terminal locking process, ensuring the security of locking commands and data.

[0042] The Gatekeeper Trusted Application (GTA) is responsible for verifying the identity and permissions of terminal locking operations and managing access permissions for hardware and software modules.

[0043] The Lock App is the front-end application of the REE layer, responsible for interacting with the server to obtain locking commands and sending the commands to the Lock System Service.

[0044] The Lock System Service is the core service of the REE layer. It receives instructions from the lock application, coordinates the various modules of the REE layer (such as the system interface and device mapping verification) to perform the initial locking operation, and initiates a security lock request to the TEE layer.

[0045] The Lock Security Agent is a proxy module that connects the REE and TEE, responsible for secure data transmission and command interaction across environments, ensuring that locking commands are securely transmitted from the REE to the TEE.

[0046] The Gatekeeper Certificate Authority (Gatekeeper CA) is responsible for issuing security certificates for the Gatekeeper modules, enabling identity authentication between modules and ensuring the legitimacy of locking operations.

[0047] The server points to the locking application: indicating the path where the locking command is issued. After the server detects a user's malicious breach of contract, it generates a locking command containing prompt information and transmits it over the network to the locking application in the terminal's rich execution environment layer.

[0048] The lock application points to the lock system service, indicating the hierarchical transmission of instructions. After receiving instructions from the server, the lock application parses them and forwards them to the lock system service in the rich execution environment layer.

[0049] The lock system service points to the system interface: indicating the flow of control commands for locking the system interface. The lock system service sends a lock command to the system interface module, controlling the terminal system interface to enter a locked state, restricting basic user operations.

[0050] The device locking system service points to device mapping verification and system attributes: representing the security verification before locking. The device locking system service retrieves device information and system status, verifies the terminal's identity and current status, and ensures that the locking operation is performed on the target terminal.

[0051] The lock-up system service points to the lock-up security agent, indicating the initiation of a cross-environment security request. After the rich execution environment layer completes the initial software lock, it initiates a hardware-level lock request to the trusted execution environment layer through the lock-up security agent.

[0052] The lock security agent points to the lock trusted application, indicating the secure entry of core lock commands. Verified lock commands are passed to the lock trusted application in the trusted execution environment layer via the security agent, triggering hardware-level lock logic.

[0053] The trusted application for the lock-up system refers to the trusted application deployed on the production line, the trusted application for key management, and the trusted application for gate control: representing the collaborative interaction within the trusted execution environment. The trusted application for the lock-up system invokes the security capabilities of each trusted application to complete parameter configuration, data verification, and permission auditing.

[0054] The trusted application for the lock-on device points to a one-time programmable memory chip interface. The one-time programmable memory chip represents the solidification of the hardware lock state. The trusted application sends instructions to the one-time programmable memory chip through a dedicated interface, writing the lock flag into the hardware and ensuring it remains unalterable.

[0055] Locking the machine for trusted applications refers to input / output control and inter-process communication, as well as secure storage: it means locking the secure storage of critical data to prevent data leakage or tampering.

[0056] Rich Execution Environment Layer Input / Output Control and Inter-Process Communication Points to Replay Protection Memory Block Embedded Multimedia Card: This indicates that the relevant data is securely stored to prevent it from being tampered with by replay attacks.

[0057] The lock system service points to the communication interface, universal serial bus, universal asynchronous transceiver, and modem: indicating the direction of the command flow for locking the communication function.

[0058] The modem points to the instruction set command, protocol stack, and user identification module lock: this indicates the execution of the user identification module lock, which ultimately completes the locking of the terminal's communication functions.

[0059] The user identification module lock pointer is a non-volatile parameter: representing the local storage of the communication lock state, ensuring that the lock state remains effective after the terminal restarts.

[0060] Implicit correlation between the system interface and multiple locking states: When the system interface is locked, the one-time programmable memory chip lock flag is active, and the user identification module lock is completed, the system interface displays a prompt message, forming a complete lock control closed loop.

[0061] Figure 2 Flowchart of the locking control method provided in the embodiments of this application Figure 1 The method described above in this application embodiment can be applied to any terminal device. For example... Figure 2 As shown, the method includes:

[0062] S201. When the first instruction is obtained, the system interface of the terminal device is locked based on the first instruction. The first instruction is used to instruct the terminal device to be locked. The first instruction includes a first prompt message, which is used to prompt the user of the terminal device to use the device in a standardized manner.

[0063] The first instruction is the core signal that triggers the terminal device to perform a locking operation. It is generated and issued by the terminal device's management end (such as the manufacturer's server or the company's management platform). Its sole purpose is to instruct the terminal device to perform locking-related operations.

[0064] The system interface serves as the user interaction entry point for terminal devices. It is a visual interface for users to operate terminal devices and use various functions of the terminal devices (such as the mobile phone's desktop, unlock screen, application operation interface, etc.).

[0065] The first prompt message, which includes text / pop-up information in the first instruction, is primarily intended to inform users of the reason for the device being locked, the relevant obligations or operational requirements, and guide users to use the device correctly and handle related matters promptly. It covers multiple locking scenarios; specifically, it may include performance reminders in scenarios of malicious breach of contract such as "buy now, pay later," retrieval reminders in scenarios of lost devices, and correct usage reminders in scenarios of improper use of devices. This ensures that users can clearly understand the reason for the lock and the subsequent handling methods in different locking scenarios.

[0066] Specifically, the terminal device receives the first instruction from the control terminal via network communication (such as 4G, 5G, or WiFi), completes the reception, parsing, and verification of the instruction to ensure its legitimacy and lack of tampering. Based on the first instruction, the terminal device executes subsequent system interface locking operations according to the preset locking rules within the instruction, ensuring that the operation complies with the control terminal's requirements. The terminal device's system interface is restricted, preventing it from responding normally to user operations (such as being unable to unlock, open applications, or access operating system settings), retaining only the function of displaying prompt information, thus achieving initial software-level control.

[0067] S202. Based on the first instruction, the lock flag bit of the one-time programmable memory chip of the terminal device is set to a first value, which is used to indicate that the terminal device is in a locked state.

[0068] The first value is a preset value (such as the number "1") used to indicate that the terminal device is in a locked state, which is different from the second value (such as the number "0") for the "unlocked state". It cannot be modified after being written into the one-time programmable memory chip.

[0069] Specifically, the terminal device, based on the first instruction, executes the setting operation of the lock flag bit to ensure that the setting behavior complies with the requirements of the control terminal instruction. Modifying the lock flag bit in the one-time programmable memory chip from the initial "unlocked" value to the "locked" value (the first value) is essentially writing a lock status identifier to the hardware chip, and this writing is irreversible.

[0070] S203. Based on the first instruction, lock the user identification module of the terminal device.

[0071] Specifically, based on the first instruction, the terminal device ensures that the locking operation of the user identification module complies with the requirements of the control end, restricts the normal function of the user identification module, prevents it from completing identity authentication and accessing the network, and thus prevents the terminal device from realizing communication functions such as making calls, sending text messages, and using mobile data. This strengthens the control of the terminal and makes up for the shortcomings of the system interface locking (preventing users from continuing to use communication functions after unlocking by changing the system).

[0072] S204. When the system interface of the terminal device is locked, the lock flag is set to the first value, and the user identification module is locked, the first prompt message is displayed.

[0073] Specifically, the terminal device monitors the completion status of the three locking operations in real time. Only when all three operations are completed and the preset locking conditions are met will the subsequent prompt information display operation be triggered, avoiding the accidental display of prompt information when a single locking operation is incomplete. The first prompt information contained in the first instruction is displayed on the terminal device's system interface in the form of a pop-up window, fixed text, etc., ensuring that the user can clearly see the prompt content, understand the reason for locking and the fulfillment requirements, and achieve collaborative management of "locking + prompt".

[0074] The locking control method provided in this application can directly restrict users' basic operations on the terminal by acquiring a locking command and locking the system interface of the terminal device, quickly blocking users from using the device illegally. By setting the locking flag bit of the one-time programmable memory chip to a first value, the locking state can be solidified at the hardware level, preventing users from unlocking the device through software means and improving the reliability of the locking. By locking the user identification module of the terminal device, the communication function of the terminal can be further restricted, strengthening the control. When all three locking conditions are met, a prompt message is displayed, which can clearly inform the user of the reason for the locking and the performance requirements, realizing rapid, accurate and reliable control over the terminal devices of malicious defaulting users.

[0075] Figure 3 Flowchart of the locking control method provided in the embodiments of this application Figure 2 .like Figure 3 As shown, the method includes:

[0076] S301. When the first instruction is obtained, the system interface of the terminal device is locked based on the first instruction. The first instruction is used to instruct the terminal device to be locked. The first instruction includes a first prompt message, which is used to prompt the user of the terminal device to use the device in a standardized manner.

[0077] S302. Based on the first instruction, the lock flag bit of the one-time programmable memory chip of the terminal device is set to a first value, which is used to indicate that the terminal device is in a locked state.

[0078] In one possible implementation, based on the first instruction, a third instruction is determined, the third instruction being used to instruct the locking flag bit of the one-time programmable memory chip of the terminal device to be set to a first value; the third instruction is sent to the lock-machine trusted application, the lock-machine trusted application being used to execute the instruction in the trusted execution environment of the terminal device; the third instruction is executed through the lock-machine trusted application to make the locking flag bit set to the first value.

[0079] The third instruction is a sub-instruction derived from the first instruction. Its core purpose is to specifically instruct the terminal device to perform the operation of setting the lock flag of the one-time programmable memory chip to the first value. It is a refined execution instruction of the first instruction.

[0080] Specifically, the locking application on the terminal device receives the first instruction from the control terminal, parses and breaks it down to extract the specific requirement of "setting the lock flag of the one-time programmable memory chip," and then generates a corresponding third instruction to ensure that the third instruction is consistent with the locking requirements of the first instruction. The locking application then transmits the generated third instruction to the trusted application running on the trusted execution environment side through the locking security proxy (a secure transmission channel between the rich execution environment and the trusted execution environment). After receiving the third instruction, the trusted application performs the bit-setting operation of the one-time programmable memory chip according to the instruction requirements. It interacts with the one-time programmable memory chip through a dedicated interface to modify the value of the reserved lock flag in the chip to the first value, completing the hardware-level permanent lock, and the operation is irreversible.

[0081] In one possible implementation, based on the first instruction, a fourth instruction and first data are determined. The fourth instruction is used to instruct the storage of the first data in a secure storage environment within a trusted execution environment. The first data is used to implement secure authentication of the terminal device and verification of the device lock operation permission. The fourth instruction and the first data are sent to a trusted device lock application. The trusted device lock application executes the fourth instruction to store the first data in a secure storage environment within the trusted execution environment.

[0082] The fourth instruction is another sub-instruction derived from the first instruction. Its core purpose is to instruct the trusted application of the lock to store the first data in the secure storage on the trusted execution environment side. It is executed in parallel with the third instruction to help realize the locking security of the terminal device, corresponding to the operation of "storing the key and confidential data in the secure storage".

[0083] The first data is the core security data in the terminal device locking process, including the terminal device identity identifier, locking operation permission parameters, security authentication key, and the verification code of the first instruction. It is used for subsequent terminal device security authentication (such as identity verification during unlocking) and locking operation permission verification (such as determining whether the operation performed by the trusted application is legal).

[0084] Secure storage is a dedicated storage module located within a trusted execution environment. It features high security, tamper-proof, and leak-proof characteristics. It is specifically used to store confidential information such as primary data and public keys for production line deployment, and is not accessible to other modules (such as ordinary applications) on the trusted execution environment side.

[0085] Specifically, the lock-on application uses the first instruction as a basis to parse the requirement of "storing secure data," and then determines the fourth instruction and the first data (including keys, terminal identity identifiers, etc.). The lock-on application sends the fourth instruction and the first data together to the lock-on trusted application through the lock-on security proxy (a secure transmission channel between the rich execution environment and the trusted execution environment). After receiving the fourth instruction and the first data, the lock-on trusted application writes the first data into the secure storage on the trusted execution environment side according to the instruction requirements, thus completing the secure storage of the data. At the same time, the first data works in conjunction with the public key information deployed on the production line to provide support for subsequent security authentication and permission verification. Moreover, this data can only be accessed by the lock-on trusted application and cannot be tampered with.

[0086] S303. Based on the first instruction, lock the user identification module of the terminal device.

[0087] In one possible implementation, based on the first instruction, a fifth instruction is determined, which instructs the modem of the terminal device to shut down the protocol stack to lock the user identification module of the terminal device; the fifth instruction is sent to the modem; and the fifth instruction is executed through the modem to lock the user identification module of the terminal device.

[0088] The fifth instruction is a sub-instruction derived from the first instruction. Its core purpose is to specifically instruct the modem of the terminal device to shut down the protocol stack, thereby locking the user identification module. It is a detailed execution instruction of the "lock user identification module" operation in the first instruction, corresponding to the relevant operation of the modem.

[0089] The protocol stack is the core software component inside the modem used to implement communication functions. It is responsible for handling the communication protocols (such as call and data transmission protocols) between the user identification module and the operator's network. When the protocol stack is turned off, the user identification module cannot establish a connection with the network and cannot perform communication functions.

[0090] Specifically, after receiving the first instruction from the control terminal, the lock-on application parses the specific requirement of "locking the user identification module," clarifying that this operation must be achieved by "shutting down the modem protocol stack." It then generates a fifth instruction to control the modem. The lock-on application sends this fifth instruction to the terminal device's modem via the telephone's remote interface. Upon receiving the fifth instruction, the modem shuts down its internal protocol stack. Simultaneously, the user identification module lock-on module verifies the server parameters transmitted by the lock-on application, stores the legitimate encrypted data in the modem's non-volatile memory, and closes the parameter access interface to the protocol stack. After the protocol stack is shut down, the user identification module cannot establish a connection with the operator's network and cannot perform communication functions, thus completing the locking of the user identification module.

[0091] S304. When the system interface of the terminal device is locked, the lock flag is set to the first value, and the user identification module is locked, the first prompt message is displayed.

[0092] In one possible implementation, when the second instruction is obtained, the device mapping verification result and network access verification result of the terminal device are obtained. The device mapping verification result is used to indicate whether the system partition data of the terminal device has been tampered with, and the network access verification result is used to indicate whether the network access of the terminal device has been tampered with. The second instruction includes one of the terminal device performing power-on verification, screen lock verification, or requesting a security key. When the device mapping verification result indicates that the system partition data of the terminal device has been tampered with, or the network access verification result indicates that the network access of the terminal device has been tampered with, the terminal device is set to an unavailable state.

[0093] The second instruction is generated by the terminal device itself and includes three scenarios: power-on, screen lock verification, and security key application. It is used to instruct the terminal device to perform device mapping verification and network access verification operations.

[0094] The device mapping verification result is the result obtained by the terminal device after verifying its own system partition data. It is achieved by reading the device mapping verification result from the rich execution environment side (reading attribute values, etc.) and is used to determine whether the system partition data has been tampered with (such as flashing the device, modifying system files related to the device lock, etc.). It is divided into two states: "untampered" and "tampered".

[0095] System partition data contains core data required for the operation of terminal device systems, including lock module configuration, lock application running parameters, system user interface locking logic, etc. It is the basis for the normal operation of the terminal device's lock function, and tampering with it may cause the lock function to fail.

[0096] The network access verification result is the result obtained by the terminal device after verifying its own network access function. It is used to determine whether the network access link and network configuration of the terminal device have been tampered with (such as modifying network parameters, bypassing the network verification of the control terminal, etc.) to ensure that the communication between the terminal device and the control terminal is normal. It is divided into two states: "untampered" and "tampered".

[0097] The security key is the key required for unlocking the terminal device and performing lock / unlock related security operations. It is applied for through the key storage / key management module and is used to verify the user's identity or operation permissions to ensure the legality of the operation.

[0098] The unavailable state is an extreme control state for terminal devices, which is more stringent than the "locked state". It is specifically achieved by triggering the crash of trusted applications, abnormalities in the trusted execution environment system, device crashes or frequent restarts, etc. The terminal device cannot perform any normal operations, completely eliminating the possibility of malicious use.

[0099] Specifically, after the terminal device completes the initial prompt display and enters the locked state, this double verification operation will be executed every time one of the three operations—power-on, screen lock verification, or security key application—is triggered, continuously ensuring the normal functioning of the locking solution. When the terminal device's trusted application detects that the terminal device is performing operations such as power-on, gate module password verification, or key storage / key management module key application, it automatically captures and receives the second instruction corresponding to the operation, triggering the subsequent verification process. The trusted application reads the device mapping verification result from the rich execution environment side (reads relevant attribute values), performs integrity verification on the terminal device's system partition data, generates and reads the device mapping verification result, and determines whether the system partition data has been tampered with. The trusted application for device locking checks the network access link and network configuration of the terminal device, verifies whether the communication between the terminal device and the control terminal is normal and whether the network parameters have been tampered with, generates network access verification results and reads them. When the trusted application for device locking identifies any verification result as "tampered with" (system partition data has been tampered with or network access has been tampered with), it will immediately trigger the terminal device to enter an unavailable state. Setting it to an unavailable state means that the trusted application for device locking triggers a trusted application crash, a trusted execution environment system malfunction, or sends instructions to the modem or system user interface to cause the terminal device to freeze, frequently restart, or fail to boot, shutting down all core functions and retaining only basic security verification, thus completely preventing malicious tampering from bypassing the locking control.

[0100] S305. When the terminal device is powered on, obtain the lock flag bit of the one-time programmable memory chip of the terminal device.

[0101] Specifically, during the startup process of the terminal device, after the system completes the initial loading, it reads the value of the lock flag stored in the one-time programmable memory chip, completes the reading and recognition of the value, and confirms the current lock status of the terminal device.

[0102] S306. When the lock flag is the first value, lock the system interface and user identification module of the terminal device and display the first prompt message.

[0103] Specifically, after the terminal device recognizes that the value of the lock flag is the first value (locked state), it sends an instruction to the lock service on the rich execution environment side through the lock security agent to lock the system interface; on the other hand, it sends an instruction to the modem's user identification module lock module through the remote interface of the telephone to lock the user identification module, and at the same time triggers the display of the first prompt information.

[0104] By acquiring the lock flag of the one-time programmable memory chip when the terminal device is powered on, and locking the system interface and user identification module and displaying prompt information when the lock flag is at the first value, a rapid lock verification is achieved during the terminal device's power-on phase. This can promptly block unauthorized user operations and inform the user of the lock status and reason through clear prompt information. This not only ensures the hardware security of the terminal device but also improves the user experience and effectively prevents the terminal device from being illegally operated or stolen.

[0105] After the terminal device displays a lockout message, by obtaining a second instruction and simultaneously verifying the device mapping and network access status, it can accurately identify abnormal situations such as system partition data tampering and network access tampering. When tampering is detected, the terminal device is set to an unavailable state, which further enhances the security protection level of the terminal device, effectively preventing malicious users from unlocking the device by tampering with data or bypassing network verification, ensuring the security of confidential information within the terminal device, and reducing the risk of the device being illegally controlled.

[0106] Based on the first instruction, the third instruction is determined and sent to the lock-up trusted application. The lock-up trusted application then executes the setting operation of the lock flag bit of the one-time programmable memory chip, realizing the standardized and secure execution of the lock-up instruction. Relying on the high security of the trusted execution environment, it ensures that the setting operation is not tampered with or intercepted. At the same time, the data of the one-time programmable memory chip is non-erasable, which enables permanent locking of the terminal device. This ensures the stability and reliability of the lock-up operation from the hardware level and prevents the lock-up state from being illegally released.

[0107] Based on the first instruction, the fourth instruction and the first data are determined and sent to the trusted application for locking, which stores them in the secure storage of the trusted execution environment. This achieves secure storage of terminal device security authentication data and locking permission data. Relying on the anti-tampering and anti-leakage characteristics of secure storage, it ensures that the relevant data is not illegally accessed or tampered with, providing reliable data support for subsequent terminal device unlocking verification and permission verification. This further improves the terminal device's locking security system and enhances the security and standardization of locking operations.

[0108] Based on the first instruction, the fifth instruction is determined and sent to the modem. The modem then performs the operation of shutting down the protocol stack to lock the user identification module, thereby achieving precise control over the communication functions of the terminal device. By shutting down the protocol stack, the connection between the user identification module and the operator's network is blocked. This not only prevents unauthorized users from controlling the device through the communication function, but also avoids the terminal device from being illegally accessed by the network. This further broadens the lock protection dimension of the terminal device, improves the overall security protection capability of the device, and adapts to the security management needs of terminal devices in multiple scenarios.

[0109] Figure 4 This is a schematic diagram of the locking control device provided in the embodiments of this application, such as... Figure 4 As shown, the locking control device 40 provided in this embodiment includes a locking module 401 and a display module 402.

[0110] The locking module 401 is used to lock the system interface of the terminal device based on the first instruction when the first instruction is obtained. The first instruction is used to instruct the terminal device to be locked. The first instruction includes a first prompt message, which is used to prompt the user of the terminal device to use the terminal device in a standardized manner.

[0111] The locking module 401 is also used to set the locking flag bit of the one-time programmable memory chip of the terminal device to a first value based on the first instruction. The first value is used to indicate that the terminal device is in a locked state.

[0112] The locking module 401 is also used to lock the user identification module of the terminal device based on the first instruction;

[0113] The display module 402 is used to display a first prompt message when the system interface of the terminal device is locked, the lock flag is set to the first value, and the user identification module is locked.

[0114] In one possible implementation, the locking module 401 is further configured to:

[0115] When the terminal device is powered on, the lock flag bit of the terminal device's one-time programmable memory chip is obtained;

[0116] When the lock flag is at the first value, the system interface and user identification module of the terminal device are locked, and the first prompt message is displayed.

[0117] In one possible implementation, the locking module 401 is further configured to:

[0118] When the second instruction is obtained, the device mapping verification result and network access verification result of the terminal device are obtained. The device mapping verification result is used to indicate whether the system partition data of the terminal device has been tampered with, and the network access verification result is used to indicate whether the network access of the terminal device has been tampered with. The second instruction includes one of the following: the terminal device performs power-on verification, screen lock verification, or requests a security key.

[0119] When the device mapping verification result indicates that the system partition data of the terminal device has been tampered with, or the network access verification result indicates that the network access of the terminal device has been tampered with, the terminal device is set to an unavailable state.

[0120] In one possible implementation, the locking module 401 is specifically used for:

[0121] Based on the first instruction, a third instruction is determined, which is used to instruct the locking flag bit of the one-time programmable memory chip of the terminal device to be set to the first value;

[0122] The third instruction is sent to the lock-up trusted application, which is used to execute the instruction in the trusted execution environment of the terminal device.

[0123] The third instruction is executed through the lock-on trusted application to set the lock flag to the first value.

[0124] In one possible implementation, the locking module 401 is further configured to:

[0125] Based on the first instruction, a fourth instruction and first data are determined. The fourth instruction is used to instruct the storage of the first data in a secure storage in a trusted execution environment. The first data is used to implement the security authentication and lock operation permission verification of the terminal device.

[0126] Send the fourth instruction and the first data to the lock-up trusted application;

[0127] By using a locked trusted application, a fourth instruction is executed to store the first data in secure storage within a trusted execution environment.

[0128] In one possible implementation, the locking module 401 is specifically used for:

[0129] Based on the first instruction, a fifth instruction is determined. The fifth instruction is used to instruct the modem of the terminal device to shut down the protocol stack in order to lock the user identification module of the terminal device.

[0130] Send the fifth instruction to the modem;

[0131] The fifth instruction is executed via the modem to lock the user identification module of the terminal device.

[0132] The locking control device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0133] Figure 5 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application. Figure 5 As shown, the terminal device 50 provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus.

[0134] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.

[0135] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0136] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0137] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0138] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0139] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0140] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0141] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0142] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0143] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0144] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0145] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0146] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0147] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0148] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A locking control method, characterized in that, Applied to terminal devices, including: When a first instruction is received, the system interface of the terminal device is locked based on the first instruction. The first instruction is used to instruct the terminal device to be locked. The first instruction includes a first prompt message, which is used to prompt the user of the terminal device to use the device in a proper manner. Based on the first instruction, the lock flag bit of the one-time programmable memory chip of the terminal device is set to a first value, which is used to indicate that the terminal device is in a locked state; Based on the first instruction, the user identification module of the terminal device is locked; When the system interface of the terminal device is locked, the lock flag is set to a first value, and the user identification module is locked, the first prompt message is displayed.

2. The method according to claim 1, characterized in that, Also includes: When the terminal device is powered on, the lock flag bit of the one-time programmable memory chip of the terminal device is obtained; When the lock flag is the first value, the system interface and the user identification module of the terminal device are locked, and the first prompt information is displayed.

3. The method according to claim 1, characterized in that, After displaying the first prompt message, the method further includes: When the second instruction is obtained, the device mapping verification result and network access verification result of the terminal device are obtained. The device mapping verification result is used to indicate whether the system partition data of the terminal device has been tampered with, and the network access verification result is used to indicate whether the network access of the terminal device has been tampered with. The second instruction includes one of the terminal device performing power-on, screen lock verification, or applying for a security key. When the device mapping verification result indicates that the system partition data of the terminal device has been tampered with, or when the network access verification result indicates that the network access of the terminal device has been tampered with, the terminal device shall be set to an unavailable state.

4. The method according to claim 1, characterized in that, The step of setting the lock flag of the one-time programmable memory chip of the terminal device to a first value based on the first instruction includes: Based on the first instruction, a third instruction is determined, wherein the third instruction is used to instruct the locking flag bit of the one-time programmable memory chip of the terminal device to be set to a first value; The third instruction is sent to the lock-up trusted application, which is used to execute the instruction in the trusted execution environment of the terminal device. The third instruction is executed through the trusted lock application to set the lock flag to the first value.

5. The method according to claim 4, characterized in that, Also includes: Based on the first instruction, a fourth instruction and first data are determined. The fourth instruction is used to instruct the storage of the first data in the secure storage of the trusted execution environment. The first data is used to implement the security authentication and lock operation permission verification of the terminal device. The fourth instruction and the first data are sent to the lock trusted application; The fourth instruction is executed through the trusted application of the lock-up mechanism to store the first data in secure storage within the trusted execution environment.

6. The method according to claim 1, characterized in that, The step of locking the user identification module of the terminal device based on the first instruction includes: Based on the first instruction, a fifth instruction is determined, which is used to instruct the modem of the terminal device to shut down the protocol stack in order to lock the user identification module of the terminal device; Send the fifth instruction to the modem; The fifth instruction is executed via the modem to lock the user identification module of the terminal device.

7. A locking control device, characterized in that, include: A locking module is used to lock the system interface of the terminal device based on the first instruction when a first instruction is received. The first instruction is used to instruct the terminal device to be locked. The first instruction includes a first prompt message, which is used to prompt the user of the terminal device to use the device in a standardized manner. The locking module is further configured to set the locking flag bit of the one-time programmable memory chip of the terminal device to a first value based on the first instruction, wherein the first value is used to indicate that the terminal device is in a locked state; The locking module is further configured to lock the user identification module of the terminal device based on the first instruction; The display module is used to display the first prompt information when the system interface of the terminal device is locked, the lock flag is a first value, and the user identification module is locked.

8. A terminal device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-6.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-6.