A management method, device and terminal for terminal security risks

By detecting the connection status of the mobile terminal's back cover attachment device and the hardware debugging point, monitoring the security status in real time and reminding users of security risks, the security problem of malicious use of terminal hardware debugging points is solved, achieving more accurate security risk judgment and stronger security protection.

CN114022029BActive Publication Date: 2025-05-27ONTIM TECH LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111386915.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-22
Publication Date
2025-05-27
Estimated Expiration
2041-11-22

AI Technical Summary

Technical Problem

The hardware debugging points of mobile terminals are easily exploited by malicious users for attack and analysis, resulting in the threat of terminal security. These debugging points are exposed during the maintenance process, increasing security risks.

Method used

By detecting the connection status of the terminal's back cover attached device and hardware debugging point, the security status is monitored in real time, and the security risk warning level is determined based on the operation behavior, users are reminded and security assessment and vulnerability remediation are carried out through cloud servers.

Benefits of technology

Effectively manage the security risks of terminals, improve users' security awareness, increase business security warning functions, improve user experience, and provide terminal manufacturers with stronger security protection channels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114022029B_ABST
    Figure CN114022029B_ABST
Patent Text Reader

Abstract

The present invention relates to a method, apparatus, and terminal for managing terminal security risks. The method includes the following steps: when it is detected that the hardware debugging point of the terminal is in a risk state, obtain the operation behavior of the hardware debugging point in the connected state; determine the security risk warning level according to the operation behavior; when it is detected that the hardware debugging point of the terminal is in a safe state, remind the security risk warning level. This application determines the security risk warning level of the terminal by real-time monitoring of the operation behavior of the hardware debugging point in the connected state, and after determining that the hardware debugging point is in a safe state, reminds the security risk warning level, enabling the user to timely know whether there are security risks in the terminal, adding a business security warning function, and improving the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method, an apparatus, and a terminal for managing terminal security risks. Background Art

[0002] Mobile terminals have entered the 5G era. People have been exploring and continuously updating and iterating on the innovation of terminals. Along with the development of technologies, the requirements for the business security of terminals are getting higher and higher. Therefore, people have been trying to explore business security in aspects such as business access, attack prevention, data security, and warning reminders.

[0003] During the development of a terminal, there are usually hardware debugging points (such as URAT debugging points, JTAG debugging points, forced download points, etc.) on the terminal PCB board for functions such as debugging and measurement of the terminal. Exactly these function debugging points of the hardware are often exploited by malicious users for malicious attacks and analysis, and may discover vulnerabilities in the terminal's software and hardware, thus causing risks to the terminal's security. And when the terminal is repaired after a failure, the back cover will be removed, and these debugging points are completely exposed. For example, if the mobile phone is attacked or a malicious program is implanted, it is impossible to know whether it has been attacked after it is returned to the user. When a malicious event occurs one day, the user has no idea when they have fallen into a security risk.

[0004] The hardware debugging points on the terminal hardware PCB board are covered and shielded by painting a paint coating before leaving the factory. However, these debugging points are usually very easy to identify. By scraping off the coating, the connection to the debugging point can be completed for debugging or attacking, and the security risk is extremely high. Summary of the Invention

[0005] Based on this, the present invention provides a method, an apparatus, and a terminal for managing terminal security risks, which monitor the security status by detecting the components attached to the back cover of the terminal and the hardware debugging points. The business security warning function is added to improve the user experience.

[0006] According to a first aspect of some embodiments of the present application, there is provided a method for managing terminal security risks, the method including the following steps:

[0007] When it is detected that the hardware debugging point of the terminal is in a risk state, obtain the operation behavior of the hardware debugging point in a connected state;

[0008] Determine the security risk warning level according to the operation behavior;

[0009] When it is detected that the hardware debugging point of the terminal is in a safe state, remind the security risk warning level.

[0010] Further, the operation behavior includes at least one of the following: target data of the operation, operation type, number of accesses, access duration;

[0011] Among them, the target data includes at least one of the following: ordinary data, sensitive data, confidential data;

[0012] The operation type includes at least one of the following: read, add, modify, delete.

[0013] Further, according to the operation behavior, determine the security risk warning level, including: determining a first risk parameter according to the target data; determining a second risk parameter according to the operation type; determining a third risk parameter according to the number of accesses; determining a fourth risk parameter according to the access duration; determining the security risk warning level according to the first risk parameter, the second risk parameter, the third risk parameter and the fourth risk parameter.

[0014] Further, determining the security risk warning level according to the first risk parameter, the second risk parameter, the third risk parameter and the fourth risk parameter includes:

[0015] Determining the security risk warning level according to the weighted sum of the first risk parameter, the second risk parameter, the third risk parameter and the fourth risk parameter.

[0016] Further, it also includes the following steps: obtaining the connection state of the back cover attachment device of the terminal; when the back cover attachment device is in an unconnected state, obtaining the connection state of the hardware debugging point of the terminal; if the hardware debugging point is in a connected state, determining that the hardware debugging point of the terminal is in a risk state.

[0017] Further, after determining that the hardware debugging point of the terminal is in a risk state, it also includes:

[0018] When it is detected that the back cover attachment device is in a connected state, determining that the hardware debugging point of the terminal is in a safe state;

[0019] Sending the stored operation records to the cloud server for security evaluation analysis and vulnerability remediation.

[0020] Further, the terminal includes an electrochromic film, and reminding the security risk warning level includes: controlling the electrochromic film to display the color corresponding to the security risk warning level.

[0021] Further, the back cover attachment device includes at least one of the following: NFC antenna, fingerprint module, electrochromic film; the hardware debugging point includes at least one of the following: URAT debugging point, JTAG debugging point, forced download point.

[0022] According to a second aspect of some embodiments of the present application, there is provided an apparatus for managing terminal security risks, including:

[0023] An operation behavior acquisition module, configured to acquire the operation behavior of the hardware debugging point in a connected state when it is detected that the hardware debugging point of the terminal is in a risk state;

[0024] A warning level determination module, configured to determine a security risk warning level according to the operation behavior;

[0025] A warning level reminder module, configured to remind the security risk warning level when it is detected that the hardware debugging point of the terminal is in a safe state.

[0026] According to a third aspect of some embodiments of the present application, there is provided a terminal, including: at least one memory and at least one processor;

[0027] The memory is configured to store one or more programs;

[0028] When the one or more programs are executed by the at least one processor, the at least one processor implements the steps of a method for managing terminal security risks as described in the first aspect of some embodiments of the present application.

[0029] A method, an apparatus, and a terminal for managing terminal security risks provided by the present application. The present application determines the security risk warning level of the terminal by real-time monitoring of the operation behavior of the hardware debugging point in a connected state. After determining that the hardware debugging point is in a safe state, the security risk warning level is reminded, which can enable the user to timely know whether there is a security risk in the terminal, increase the business security warning function, and improve the user experience. Secondly, the present application determines the risk state and safe state of the terminal by the connection state between the rear cover attaching device and the hardware debugging point, evaluates the risk of the terminal through the cloud server, and remedies the possible security vulnerabilities. This solution can provide a powerful way for terminal manufacturers to protect the security of mobile terminals while increasing the business security warning function, making the judgment of terminal security risks more accurate.

[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. Description of the Drawings

[0031] Figure 1Schematic diagram of an application scenario of a method for managing terminal security risks provided by the present invention;

[0032] Figure 2 Schematic diagram of the steps of a method for managing terminal security risks provided by the present invention;

[0033] Figure 3 Schematic diagram of the modules of a device for managing terminal security risks provided by the present invention. Detailed implementation manners

[0034] To make the objectives, technical solutions and advantages of the present application clearer, the following will further describe in detail the embodiments of the present application with reference to the accompanying drawings.

[0035] It should be clear that the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by the embodiments of the present application.

[0036] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the embodiments of the present application. The singular forms "a", "the" and "said" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0037] When the following description relates to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all the embodiments consistent with the present application. On the contrary, they are only examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims. In the description of the present application, it should be understood that the terms "first", "second", "third", etc. are only used to distinguish similar entities, and do not have to be used to describe a specific order or sequence, nor can they be understood as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific circumstances.

[0038] In addition, in the description of the present application, unless otherwise specified, "a plurality of" means two or more. "And / or" describes the association relationship of associated entities, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the front and back associated entities.

[0039] In view of the technical problems in the background art, an embodiment of the present application provides a method for managing terminal security risks, and this method is applied to a terminal. For example, Figure 1 as shown, in an example, the terminal 100 is a smart phone. The terminal 100 has a processor 101, a back cover attachment device 102, a hardware debugging point 103, and an electrochromic film 104.

[0040] In other examples, the terminal may also be other mobile terminals with 4G or 5G communication capabilities (such as a tablet computer), wearable devices (such as a smart watch, a sports bracelet, smart glasses), intelligent vehicle-mounted devices, etc.

[0041] Among them, the processor 101, as the central processing unit of the terminal 100, is used to connect to the back cover attachment device 102, the hardware debugging point 103, and the electrochromic film 104. The processor 101 is used to obtain the connection signals of the back cover attachment device 102 and the hardware debugging point 103, and apply different voltages to the electrochromic film 104. In other examples, the processor 101 may also be a specially set processing chip for executing the method steps of the embodiment of the present application.

[0042] Currently, the hardware debugging points on the hardware PCB board of mobile phone terminals are covered and shielded by painting a paint coating before leaving the factory. However, these debugging points are usually very easy to identify. Scratching off the coating can complete the connection to the debugging point for debugging or attack, resulting in extremely high security risks.

[0043] To solve the above problems. Please refer to Figure 2 In a specific example, Figure 2 is a schematic diagram of the steps of a method for managing terminal security risks provided by the present invention. This method may be executed by the processor 102 in Figure 1 .

[0044] In step S201, when it is detected that the hardware debugging point of the terminal is in a risk state, obtain the operation behavior of the hardware debugging point in the connected state.

[0045] A hardware debugging point refers to a debugging point exposed on the hardware PCB board. Optionally, the hardware debugging point includes at least one of the following: JTAG debugging point, URAT debugging point, forced download point. JTAG technology is an embedded debugging technology mainly used for internal chip testing. It encapsulates a dedicated test circuit TAP (Test Access Port) inside the chip, and tests internal nodes by setting JTAG debugging points on the surface of the PCB at the terminal. UART (Universal Asynchronous Receiver / Transmitter) is usually called a universal asynchronous transceiver. It converts the data to be transmitted between serial communication and parallel communication. As a chip that converts parallel input signals into serial output signals, the URAT debugging point refers to the point where the UART is integrated into the connection of other communication interfaces. The forced download point is set on the surface of the PCB of the terminal and is used to trigger the application processor to enter the forced download mode.

[0046] The hardware debugging point is in a risk state, which is used to indicate that the terminal has a risk of being damaged. This risk mainly targets the exposure risk of the hardware debugging point on the back cover of the terminal. For example, the exposed hardware debugging point is maliciously connected by other users for forced download or data transmission, leaking the user's private data. This risk state can detect whether the terminal has been invaded or attacked through the operating system of the terminal.

[0047] When the terminal is in a connected state, it has signal transmission with the terminal processor, obtains the signal transmission data, and stores the data determined to be operation behavior.

[0048] In step S202, according to the operation behavior, determine the security risk warning level.

[0049] This operation behavior indicates the behavior data of other users connecting to, accessing, attacking, or downloading and analyzing the terminal through the hardware debugging point.

[0050] The above operation behavior includes at least one of the following: target data of the operation, operation type, number of accesses, access duration. Among them, the target data includes at least one of the following: ordinary data, sensitive data, confidential data; the operation type includes at least one of the following: read, add, modify, delete.

[0051] The security risk warning level can be preset with corresponding security risk warning levels according to different operation behaviors. The security risk warning level is used to indicate the level of the security risk state of the terminal caused by the above risk situation. A high security risk warning level indicates that the hardware debugging point of the terminal is in a relatively dangerous state, and a low security risk warning level indicates that the terminal is in a relatively safe state. For example, when the operation behavior includes reading confidential data more than 10 times and the duration reaches more than 10 minutes, it indicates that the security risk state of the terminal is relatively high, and the security risk warning level is higher.

[0052] In step S203, when it is detected that the hardware debugging point of the terminal is in a safe state, the security risk warning level is reminded.

[0053] This safe state is used to indicate that there is no exposed risk at the hardware debugging point of the terminal. For example, when the device attached to the back cover of the terminal is in a connected state, it indicates that the back cover of the terminal has not been opened, and the hardware debugging point on the PCB board will not be exposed.

[0054] The reminder of the security risk warning level can be achieved by setting a warning ringtone, warning vibration, warning message, or warning color on the terminal, and corresponding to prompt the security risk warning level of the risk.

[0055] This application determines the security risk warning level of the terminal by real-time monitoring of the operation behaviors of the hardware debugging points in the connected state. After determining that the hardware debugging point is in a safe state, the security risk warning level is reminded, which can enable the user to timely know whether there is a security risk in the terminal and the level of the security risk, increase the business security warning function, and improve the user experience.

[0056] In a preferred embodiment, in order to ensure accurate judgment of the risk state of the terminal, in step S201, when it is detected that the hardware debugging point of the terminal is in a risk state, the following steps are further included:

[0057] Obtain the connection state of the device attached to the back cover of the terminal.

[0058] The rear cover attaching device refers to a device attached to the rear cover of a terminal. Optionally, the rear cover attaching device includes at least one of the following: NFC antenna, fingerprint module, electrochromic film, etc. Among them, the NFC antenna, that is, near field communication technology, is a short-distance and high-frequency radio technology that can identify and exchange data with compatible devices within a short distance. The NFC technology is mainly integrated into mobile terminals to achieve its corresponding functions; the fingerprint module is used for a device supporting fingerprint recognition to collect the fingerprint images of users through the fingerprint module; the electrochromic film is a material with electrochromic properties, and under the action of an external electric field, it undergoes a stable and reversible color change phenomenon, which appears as a reversible change in color and transparency in appearance. The electrochromic film is applied to the outer shell of the terminal, specifically, it can be a position such as the rear cover of the terminal where users can directly observe the color change.

[0059] The connection state of the rear cover attaching device is used to characterize whether the rear cover attaching device is connected to or not connected to the processor of the terminal. For example, when the rear cover attaching device is a fingerprint module, when there is signal transmission between the processor and the fingerprint module, it indicates that the fingerprint module and the processor are in a connected state; when there is no signal transmission between the processor and the fingerprint module, it indicates that the electrochromic film and the processor are in an unconnected state. When the rear cover attaching device is in a connected state, it indicates that the rear cover is not opened and the terminal is not in a security risk state; if the rear cover attaching device is in an unconnected state, it indicates that the rear cover of the terminal is opened and there is a risk of exposure of the hardware debugging point. The same applies to the rear cover attaching devices such as NFC antenna and electrochromic film. By detecting the signal transmission between the rear cover attaching device and the terminal processor in real time, the connection state of the rear cover attaching device is obtained, so as to determine whether the rear cover of the terminal is opened and whether the hardware debugging point has the risk of exposure.

[0060] When the rear cover attaching device is in an unconnected state, obtain the connection state of the hardware debugging point of the terminal.

[0061] The connection state of the hardware debugging point is used to indicate whether the terminal is accessed for terminal data through the hardware debugging point. For example, when the rear cover attaching device is in an unconnected state and the signal transmission between the forced download point of the terminal and the terminal processor is receiving external access, it indicates that the hardware debugging point is in a connected state; when the rear cover attaching device is in an unconnected state and the forced download point does not receive external access, it indicates that the hardware debugging point is in an unconnected state. By detecting the signal transmission between the hardware debugging point and the terminal processor in real time, the connection state of the hardware debugging point is obtained, so as to determine whether the hardware debugging point is maliciously connected or attacked by other users.

[0062] If the hardware debugging point is in a connected state, it is considered that the terminal has a security risk of malicious attack and analysis through the hardware debugging point. At this time, the hardware debugging point is in a risk state. Since the operation behavior includes multiple different types of judgment bases, in order to clarify the security risk warning level corresponding to each type, in a specific embodiment, in step S202, according to the operation behavior, determining the security risk warning level includes:

[0063] Determine a first risk parameter according to the target data.

[0064] Determine a second risk parameter according to the operation type.

[0065] Determine a third risk parameter according to the number of accesses.

[0066] Determine a fourth risk parameter according to the access duration.

[0067] Determine the security risk warning level according to the first risk parameter, the second risk parameter, the third risk parameter and the fourth risk parameter.

[0068] The first risk parameter corresponds to ordinary data, sensitive data, and confidential data in ascending order; the second risk parameter corresponds to read, add, modify, and delete in ascending order; the third risk parameter corresponds to the number of accesses from few to many in ascending order; the fourth risk parameter corresponds to the access duration from short to long in ascending order.

[0069] The security risk warning level can be determined by equal weight or weighted according to the magnitudes of the first risk parameter, the second risk parameter, the third risk parameter and the fourth risk parameter. For example, when the first risk parameter, the second risk parameter, the third risk parameter and the fourth risk parameter are all the highest, the risk level can be determined to be the highest.

[0070] Since the types of judgment bases included in the operation behavior are numerous and the grade divisions of the types are also different, in order to be able to remind the security risk warning level more efficiently and comprehensively. In a preferred embodiment, determining the security risk warning level according to the first risk parameter, the second risk parameter, the third risk parameter and the fourth risk parameter includes:

[0071] Determine the security risk warning level according to the weighted sum of the first risk parameter, the second risk parameter, the third risk parameter and the fourth risk parameter.

[0072] According to the security guarantee requirements for the terminal, the user preset the weights of the first risk parameter, the second risk parameter, the third risk parameter, and the fourth risk parameter in advance, and then determined the security risk warning level according to the level corresponding to each risk parameter. For example, if the preset weight of the first risk parameter is 40%, the weight of the second risk parameter is 30%, the weight of the third risk parameter is 20%, and the weight of the fourth risk parameter is 10%, when the weighted sum of the above four risk parameters is greater than 80%, it is determined that the security risk warning level is high risk; when the weighted sum is less than 80% and greater than 50%, it is determined that the security risk warning level is medium risk; when the weighted sum is less than 50%, it is determined that the security risk warning level is low risk.

[0073] Specifically, for example, when the operation behavior includes reading ordinary data within 5 times in ten minutes, it can be judged that the security risk warning level is low risk; when the operation behavior includes modifying sensitive data within 5 times in ten minutes, it can be judged that the security risk warning level is medium risk; when the operation behavior includes deleting confidential data within 5 times in ten minutes, it can be judged that the security risk warning level is high risk.

[0074] In a preferred embodiment, in order to enable the user to quickly and clearly know the terminal security risk, the terminal can remind the user through a warning color. The terminal includes an electrochromic film. In step S203, the reminder of the security risk warning level includes:

[0075] Controlling the electrochromic film to display the color corresponding to the security risk warning level.

[0076] The terminal presets corresponding voltage values according to the security risk warning level, and applies the corresponding voltage values to the electrochromic film electrode plate that controls the electrochromic film, so that the electrochromic film presents the color corresponding to the security risk warning level. Different colors correspond to different security risk warning levels. For example, red corresponds to the high danger level, yellow corresponds to the medium danger level, and green corresponds to the low danger level.

[0077] The storage resources of the terminal are limited. If the operation behavior is stored in the terminal device, it will cause problems such as mutual interference in accessing the data system and low access efficiency. Moreover, directly storing the data in the device will also lead to low security and low data access flexibility. Therefore, in order to improve the efficiency and security of storing and reading data by the terminal, in another embodiment, after step S203, the following steps are further included:

[0078] After determining that the hardware debugging point of the terminal is in a risk state, it further includes:

[0079] When it is detected that the rear cover attachment device is in a connected state, it is determined that the hardware debugging point of the terminal is in a safe state;

[0080] Send the stored operation records to the cloud server for security evaluation analysis and vulnerability remediation.

[0081] Among them, the security risk warning level standard of the cloud server can be the same as that of the terminal, and the cloud server can specify the rules and standards for the security risk warning level and send the rules and standards to the terminal, and the terminal executes them using the same rules and standards. Transmitting the operation records to the cloud server for security analysis and vulnerability remediation can, while adding the business security warning function, improve the protection of the mobile terminal security by the terminal manufacturer and enhance the user experience.

[0082] Corresponding to the above method for managing terminal security risks, an embodiment of the present application further provides a device, as Figure 3 shown Figure 3 is a schematic diagram of modules of a device for managing terminal security risks provided by the present invention. The device 300 includes:

[0083] An operation behavior acquisition module 301, configured to acquire the operation behavior of the hardware debugging point in the connected state when it is detected that the hardware debugging point of the terminal is in a risk state.

[0084] In an optional embodiment, the behavior acquisition module 301 further includes:

[0085] A first state acquisition unit, configured to acquire the connection state of the back cover attachment device of the terminal.

[0086] A second state acquisition unit, configured to acquire the connection state of the hardware debugging point of the terminal when the back cover attachment device is in a disconnected state.

[0087] A risk state determination unit, configured to determine that the hardware debugging point of the terminal is in a risk state if the hardware debugging point is in a connected state.

[0088] A warning level determination module 302, configured to determine the security risk warning level according to the operation behavior.

[0089] In an optional embodiment, the level determination module 302 further includes:

[0090] A first parameter unit, configured to determine a first risk parameter according to the target data;

[0091] A second parameter unit, configured to determine a second risk parameter according to the operation type;

[0092] A third parameter unit, configured to determine a third risk parameter according to the access times;

[0093] A fourth parameter unit, configured to determine a fourth risk parameter according to the access duration;

[0094] A level determination unit, configured to determine the security risk warning level according to the first risk parameter, the second risk parameter, the third risk parameter, and the fourth risk parameter.

[0095] In an optional embodiment, the level determination unit further includes:

[0096] A level determination component, configured to determine the security risk warning level according to the weighted sum of the first risk parameter, the second risk parameter, the third risk parameter, and the fourth risk parameter.

[0097] A warning level reminder module 303, configured to remind the security risk warning level when it is detected that the hardware debug point of the terminal is in a safe state.

[0098] In an optional embodiment, the terminal includes an electrochromic film, and the reminder module 303 further includes:

[0099] A reminder unit, configured to control the electrochromic film to display the color corresponding to the security risk warning level.

[0100] In an optional embodiment, after it is determined that the hardware debug point of the terminal is in a risk state, the device 300 further includes:

[0101] A security state determination module, configured to determine that the hardware debug point of the terminal is in a safe state when it is detected that the rear cover attachment device is in a connected state;

[0102] A vulnerability remediation module, configured to send the stored operation records to a cloud server for security evaluation analysis and vulnerability remediation.

[0103] In an optional embodiment, the rear cover attachment device includes at least one of the following:

[0104] NFC antenna, fingerprint module, electrochromic film.

[0105] In an optional embodiment, the hardware debug point includes at least one of the following:

[0106] URAT debug point, JTAG debug point, forced download point.

[0107] Corresponding to the above method for detecting the security risk of a terminal to trigger a security warning, an embodiment of the present application further provides a terminal, including:

[0108] At least one memory and at least one processor;

[0109] The memory is used to store one or more programs;

[0110] When the one or more programs are executed by the at least one processor, the at least one processor implements the steps of a method for detecting terminal security risks to trigger a security warning as described in any one of the above embodiments.

[0111] Specifically, the terminal can be a mobile terminal (such as a tablet computer) with 4G or 5G communication capabilities, a wearable device (such as a smart watch, a sports bracelet, smart glasses), a smart vehicle-mounted device, etc.

[0112] A method, device and terminal for managing terminal security risks provided by the present application. The present application determines the security risk warning level of the terminal by real-time monitoring of the operation behaviors of the hardware debugging points in the connected state. After determining that the hardware debugging points are in a safe state, the security risk warning level is reminded, which enables the user to timely know whether there are security risks in the terminal, increases the business security warning function, and improves the user experience. Secondly, the present application determines the risk state and security state of the terminal through the connection state between the back cover attaching device and the hardware debugging points, evaluates the risks of the terminal through the cloud server, and remedies the possible security vulnerabilities. This solution can, while increasing the business security warning function, provide a powerful way for terminal manufacturers to protect the security of mobile phone terminals, making the judgment of terminal security risks more accurate.

[0113] It should be understood that the embodiments of the present application are not limited to the exact structures already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the embodiments of the present application is only limited by the appended claims. The above-described embodiments only express several implementation manners of the embodiments of the present application, and their descriptions are relatively specific and detailed, but should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the embodiments of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the embodiments of the present application.

Claims

1. A method for managing terminal security risks, characterized in that, the method comprises the following steps: When it is detected that the hardware debugging point of the terminal is in a risk state, obtain the operation behavior of the connected hardware debugging point; Determine the security risk warning level according to the operation behavior; wherein, the operation behavior includes: The target data of the operation, the operation type, the access times, and the access duration; Determine the first risk parameter according to the target data, and the target data includes at least one of the following: Ordinary data, sensitive data, confidential data; Determine the second risk parameter according to the operation type, and the operation type includes at least one of the following: Read, add, modify, delete; Determine the third risk parameter according to the access times; Determine the fourth risk parameter according to the access duration; Determine the security risk warning level according to the weighted sum of the first risk parameter, the second risk parameter, the third risk parameter, and the fourth risk parameter; When it is detected that the hardware debugging point of the terminal is in a safe state, remind the security risk warning level; Wherein, the methods for determining the risk state and the safe state are: Obtain the connection state of the back cover attachment device of the terminal; When the back cover attachment device is in a disconnected state, obtain the connection state of the hardware debugging point of the terminal; If the hardware debugging point is in a connected state, determine that the hardware debugging point of the terminal is in a risk state; after determining that the hardware debugging point of the terminal is in a risk state, it further includes: When it is detected that the back cover attachment device is in a connected state, determine that the hardware debugging point of the terminal is in a safe state.

2. The method for managing terminal security risks according to claim 1, characterized in that, After determining that the hardware debugging point of the terminal is in a safe state, it further includes: Send the stored operation records to the cloud server for security evaluation analysis and vulnerability remediation.

3. The method for managing terminal security risks according to claim 1, characterized in that, The terminal includes an electrochromic film, and the reminding of the security risk warning level includes: Controlling the electrochromic film to display the color corresponding to the security risk warning level.

4. The method for managing terminal security risks according to claim 1, characterized in that: The back cover attachment device includes at least one of the following: NFC antenna, fingerprint module, electrochromic film; The hardware debugging point includes at least one of the following: URAT debugging point, JTAG debugging point, forced download point.

5. A device for managing terminal security risks, characterized in that, comprises: An operation behavior acquisition module, configured to obtain the operation behavior of the connected hardware debugging point when it is detected that the hardware debugging point of the terminal is in a risk state; A warning level determination module, configured to determine the security risk warning level according to the operation behavior; wherein, the operation behavior includes: The target data of the operation, the operation type, the access times, and the access duration; Determine the first risk parameter according to the target data, and the target data includes at least one of the following: Ordinary data, sensitive data, confidential data; Determine a second risk parameter according to the operation type, where the operation type includes at least one of the following: Read, add, modify, delete; Determine a third risk parameter according to the number of accesses; Determine a fourth risk parameter according to the access duration; Determine the security risk warning level according to the weighted sum of the first risk parameter, the second risk parameter, the third risk parameter, and the fourth risk parameter; A warning level reminder module, configured to remind the security risk warning level when it is detected that the hardware debugging point of the terminal is in a safe state; wherein, the determination methods of the risk state and the safe state are: Obtain the connection state of the back cover attachment device of the terminal; When the back cover attachment device is in a disconnected state, obtain the connection state of the hardware debugging point of the terminal; If the hardware debugging point is in a connected state, determine that the hardware debugging point of the terminal is in a risk state; after determining that the hardware debugging point of the terminal is in a risk state, it further includes: When it is detected that the back cover attachment device is in a connected state, determine that the hardware debugging point of the terminal is in a safe state.

6. A terminal Characterized in that It includes: At least one memory and at least one processor; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the at least one processor implements the steps of a method for managing the security risk of a terminal according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Method for recording POS machine intrusion attack

    CN108470407A

  • Terminal security management method and device, terminal and storage medium

    CN113591086A