Data protection method and electronic device
By uniformly managing the lock screen status in the device group, the problem of data unavailability in the lock screen state in the existing technology is solved, and the normal use and security protection of data in the distributed collaborative scenario are achieved.
Patent Information
- Application Number
- CN202010890450.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-29
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2040-08-29
AI Technical Summary
In a distributed collaboration scenario, existing technologies bind the availability of local sensitive data to whether the device is in a locked screen state, resulting in data unavailability in the locked screen state, making cross-device collaboration impossible and affecting the normal operation of collaborative services.
By setting the first data to unavailable when the lock screen status of all electronic devices in the device group is locked, and setting the data to available only when the lock screen status of any electronic device is unlocked, and utilizing the lock screen status judgment and update mechanism of the virtual terminal, the normal use of data in a distributed collaborative scenario can be achieved.
It enables the normal use of protected data in distributed collaborative scenarios, improves the efficiency and accuracy of lock screen status judgment, and ensures data security and the convenience of cross-device collaboration.
Smart Images

Figure CN114117367B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of terminals and communication technologies, and in particular to a data protection method and electronic device. Background Art
[0002] In the field of sensitive data protection, to prevent unauthorized users from accessing the contents of electronic devices through physical attacks (such as directly reading data from flash memory) after the electronic device is lost, resulting in user data leakage, the industry has developed a data encryption protection method for user file systems: file-based encryption (FBE).
[0003] Currently, the mainstream FBE implementation method is to bind the availability of local sensitive data to the state of the device's lock screen, and discard / load the encryption key that protects sensitive data after the device is locked / unlocked. This makes the data unavailable when the screen is locked and available after unlocking.
[0004] However, with the continuous development of the communications industry, computer networks have realized distributed collaboration among multiple electronic devices, and the demand for file protection in distributed collaboration scenarios is increasing day by day. Users need to protect data in distributed collaboration scenarios, and at the same time, they also need to increase the utilization rate of files and use protected data to complete business collaboration.
[0005] The availability of local sensitive data is tied to the lock screen status of the device. When the electronic device is locked, the data becomes unavailable, resulting in other electronic devices being unable to use the protected data in distributed collaboration scenarios. When other electronic devices access the protected data on this electronic device across devices, if the electronic device is unlocked, the protected data can be used collaboratively; however, if the electronic device is locked, the protected data is unavailable, making it impossible to achieve cross-device data collaboration and affecting the normal operation of collaborative services. Summary of the Invention
[0006] The present application provides a data protection method and electronic device, which can realize the normal use of protected data in a distributed collaborative scenario while ensuring the security of the data.
[0007] In a first aspect, the present application provides a data protection method, which includes: when it is determined that the lock screen status of all electronic devices in a device group is locked, the first electronic device sets first data to be unavailable, and the first data is protected data in the first electronic device; when it is determined that the lock screen status of any electronic device in the device group is unlocked, the first electronic device sets the first data to be available.
[0008] In the above embodiment, whether the protected first data in each electronic device in the device group is available is associated with the lock screen status of all electronic devices. When the lock screen status of all electronic devices is locked, the first data is unavailable and the first data is protected. As long as the lock screen status of any electronic device is unlocked, the electronic device will set the first data to be available, and the electronic devices can collaborate and access the protected first data in each electronic device. Under the condition of data security protection, the normal use of protected data in a distributed collaborative scenario is realized.
[0009] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: when the first electronic device determines that the lock screen status of all electronic devices recorded in the device lock screen information within the group of the first electronic device are in a locked state, the first electronic device determines that the lock screen status of all electronic devices in the device group are in a locked state; the device lock screen information within the group records the correspondence between the identification of the electronic devices in the device group and the lock screen status; when the first electronic device determines that the lock screen status of any electronic device recorded in the device lock screen information within the group is an unlocked state, the first electronic device determines that the lock screen status of any electronic device in the device group is an unlocked state.
[0010] In the above embodiment, the lock screen status of each electronic device in the device group is determined by using the information recorded in the lock screen information of the device in the group in the first electronic device, thereby improving the efficiency of determining the lock screen status of each electronic device.
[0011] In combination with some embodiments of the first aspect, in some embodiments, when it is determined that the lock screen status of all electronic devices in the device group is locked, the first electronic device sets the first data to unavailable, specifically including: when it is determined that the lock screen status of the virtual terminal is locked, the first electronic device sets the first data to unavailable; the lock screen status of the virtual terminal is determined according to the lock screen status of all electronic devices in the device group; when it is determined that the lock screen status of any electronic device in the device group is unlocked, the first electronic device sets the first data to available, specifically including: when it is determined that the lock screen status of the virtual terminal is unlocked, the first electronic device sets the first data to available.
[0012] In the above embodiment, all electronic devices in the device group may be regarded as a virtual terminal, and the first data is determined to be available based on the lock screen status of the virtual terminal, thereby improving the efficiency and accuracy of the judgment.
[0013] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: when the first electronic device determines that the lock screen status of all electronic devices recorded in the lock screen information of devices in the group are locked, the first electronic device determines that the lock screen status of the virtual terminal is locked; when the first electronic device determines that the lock screen status of any electronic device recorded in the lock screen information of devices in the group is unlocked, the first electronic device determines that the lock screen status of the virtual terminal is unlocked.
[0014] In the above embodiment, a strategy for determining the lock screen status of a virtual terminal is provided, so that when data is securely protected in a distributed collaborative scenario, the protected data can be used normally and more conveniently.
[0015] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: when the lock screen status of the first electronic device is a locked state, in response to the user's unlocking operation, the first electronic device updates the lock screen status of the first electronic device recorded in the lock screen information of the devices in the group to an unlocked state.
[0016] In the above embodiment, the first electronic device can update the lock screen status of the first electronic device recorded in the lock screen information of the devices in the group according to the user operation, thereby improving the accuracy of the recorded lock screen status of the electronic device.
[0017] In combination with some embodiments of the first aspect, in some embodiments, after the first electronic device updates the lock screen status of the first electronic device recorded in the lock screen information of the devices in the group to an unlocked state, the method also includes: the first electronic device sends the information that the lock screen status of the first electronic device is updated to an unlocked state to a second electronic device, and the second electronic device is any electronic device in the device group that is different from the first electronic device.
[0018] In the above embodiment, after the lock screen status of the first electronic device changes, it can be sent to other electronic devices in the device group, so that the other electronic devices synchronously update the lock screen status of the first electronic device.
[0019] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: when the lock screen status of the first electronic device is unlocked, in response to the user's lock screen operation, the first electronic device updates the lock screen status of the first electronic device recorded in the lock screen information of the devices in the group to a locked state.
[0020] In the above embodiment, the first electronic device can update the lock screen status of the first electronic device recorded in the lock screen information of the devices in the group according to the user operation, thereby improving the accuracy of the recorded lock screen status of the electronic device.
[0021] In combination with some embodiments of the first aspect, in some embodiments, after the first electronic device updates the lock screen status of the first electronic device recorded in the lock screen information of the devices in the group to a locked state, the method also includes: the first electronic device sends information that the lock screen status of the first electronic device is updated to a locked state to the second electronic device.
[0022] In the above embodiment, after the lock screen status of the first electronic device changes, it can be sent to other electronic devices in the device group, so that the other electronic devices synchronously update the lock screen status of the first electronic device.
[0023] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: the first electronic device receives information sent by the third electronic device that the lock screen status of the third electronic device is updated to the unlocked state; the third electronic device is any electronic device in the device group that is different from the first electronic device; the first electronic device updates the lock screen status of the third electronic device to the unlocked state according to the device lock screen information in the group.
[0024] In the above embodiment, the first electronic device can receive changes in the lock screen status of other electronic devices and update the lock screen information of devices in the group in real time, thereby ensuring the accuracy of the recorded lock screen status of each electronic device.
[0025] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: the first electronic device receives information sent by the third electronic device that the lock screen status of the third electronic device is updated to a locked state; the first electronic device updates the lock screen status of the third electronic device to a locked state based on the device lock screen information within the group.
[0026] In the above embodiment, the first electronic device can receive changes in the lock screen status of other electronic devices and update the lock screen information of devices in the group in real time, thereby ensuring the accuracy of the recorded lock screen status of each electronic device.
[0027] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: when the first electronic device determines that the fourth electronic device is connected to the device group, or when the first electronic device is connected to the device group where the fourth electronic device is located, the first electronic device adds an entry recording the lock screen status of the fourth electronic device to the device lock screen information in the group, and the fourth electronic device is any electronic device in the device group that is different from the first electronic device.
[0028] In the above embodiment, when other electronic devices come online or access the device group, the first electronic device can add a record entry to the lock screen information of the devices in the group, thereby ensuring that the lock screen status of all electronic devices in the device group can be recorded.
[0029] In combination with some embodiments of the first aspect, in some embodiments, the first electronic device adds an entry recording the lock screen status of the fourth electronic device in the lock screen information of devices in the group, specifically including: the first electronic device adds an initialization entry recording the lock screen status of the fourth electronic device in the lock screen information of devices in the group, and sets the lock screen status of the fourth electronic device to a locked state in the initialization entry.
[0030] In the above embodiment, the lock screen state of the electronic device can be added to the initialization entry of the lock screen state of the electronic device, and the lock screen state of the electronic device can be set to the locked state by default, thereby improving the security of the first data.
[0031] In combination with some embodiments of the first aspect, in some embodiments, after the first electronic device adds an initialization entry recording the lock screen status of the fourth electronic device in the lock screen information of devices in the group, the method also includes: the first electronic device receives information sent by the fourth electronic device that the lock screen status of the fourth electronic device is unlocked; the first electronic device updates the lock screen status of the fourth electronic device in the lock screen information of devices in the group to unlocked.
[0032] In the above embodiment, after adding the initialization entry in the lock screen information of the group device, the lock screen status of the electronic device can be synchronously updated, thereby improving the accuracy of the lock screen status of the electronic device recorded in the lock screen information of the group device.
[0033] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: when the first electronic device determines that the fifth electronic device has exited the device group, the first electronic device deletes the entry recording the lock screen status of the fifth electronic device in the device lock screen information within the group, and the fifth electronic device is any electronic device in the device group that is different from the first electronic device.
[0034] In the above embodiment, if an electronic device goes offline, the entry corresponding to the electronic device is deleted in the lock screen information of the group devices, which reduces the storage space demand of the lock screen information of the group devices and improves the efficiency of searching for data in the lock screen information of the group devices.
[0035] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: when the first electronic device exits the device group, the first electronic device deletes all entries in the device group that record the lock screen status of other electronic devices in the device lock screen information within the group.
[0036] In the above embodiment, when the electronic device goes offline, all entries recording the lock screen status of other electronic devices in the lock screen information of the group devices are deleted, which improves the efficiency of searching for data in the lock screen information of the group devices and ensures the accuracy of the data in the lock screen information of the group devices.
[0037] In combination with some embodiments of the first aspect, in some embodiments, the first electronic device sets the first data to be unavailable, specifically including: the first electronic device discards the class key, encrypts the first data, and makes the first data unavailable; the class key is used to decrypt the first data; the first electronic device sets the first data to be available, specifically including: the first electronic device loads the class key, decrypts the first data, and makes the first data available.
[0038] In the above embodiment, the first data is made available by loading the class key, and the first data is made unavailable by discarding the class key, thereby ensuring the security of the data.
[0039] In combination with some embodiments of the first aspect, in some embodiments, after the first electronic device sets the first data to be unavailable, the method also includes: the first electronic device denies access to the first data by a sixth electronic device, and the sixth electronic device is any electronic device in the device group that is different from the first electronic device.
[0040] In the above embodiment, data cannot be accessed when it is unavailable, which further ensures the security of the data.
[0041] In combination with some embodiments of the first aspect, in some embodiments, after the first electronic device makes the first data available, the method also includes: the first electronic device accepts access to the first data by a seventh electronic device, and the seventh electronic device is any electronic device in the device group that is different from the first electronic device.
[0042] In the above embodiment, the data can be accessed by other electronic devices in the device group when it is available, thereby ensuring the normal use of protected data in a distributed collaborative scenario.
[0043] In a second aspect, an embodiment of the present application provides a first electronic device, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the first electronic device to execute: when it is determined that the lock screen status of all electronic devices in a device group is locked, setting first data to unavailable, and the first data is protected data in the first electronic device; when it is determined that the lock screen status of any electronic device in the device group is unlocked, setting the first data to available.
[0044] In the above embodiment, whether the protected first data in each electronic device in the device group is available is associated with the lock screen status of all electronic devices. When the lock screen status of all electronic devices is locked, the first data is unavailable and the first data is protected. As long as the lock screen status of any electronic device is unlocked, the electronic device will set the first data to be available, and the electronic devices can collaborate and access the protected first data in each electronic device. Under the condition of data security protection, the normal use of protected data in a distributed collaborative scenario is realized.
[0045] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: when it is determined that the lock screen status of all electronic devices recorded in the device lock screen information within the group of the first electronic device are in a locked state, determine that the lock screen status of all electronic devices in the device group are in a locked state; the correspondence between the identification of the electronic devices in the device group and the lock screen status is recorded in the device lock screen information within the group; when it is determined that the lock screen status of any electronic device recorded in the device lock screen information within the group is in an unlocked state, determine that the lock screen status of any electronic device in the device group is in an unlocked state.
[0046] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are specifically used to call the computer instructions to enable the first electronic device to execute: when it is determined that the lock screen status of the virtual terminal is a locked state, the first data is set to unavailable; the lock screen status of the virtual terminal is determined based on the lock screen status of all electronic devices in the device group; when it is determined that the lock screen status of the virtual terminal is an unlocked state, the first data is set to available.
[0047] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: when it is determined that the lock screen status of all electronic devices recorded in the lock screen information of the devices in the group are all locked, determine that the lock screen status of the virtual terminal is locked; when it is determined that the lock screen status of any electronic device recorded in the lock screen information of the devices in the group is unlocked, determine that the lock screen status of the virtual terminal is unlocked.
[0048] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: when the lock screen state of the first electronic device is a locked state, in response to the user's unlocking operation, the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group is updated to an unlocked state.
[0049] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: sending information that updates the lock screen status of the first electronic device to an unlocked state to a second electronic device, and the second electronic device is any electronic device in the device group that is different from the first electronic device.
[0050] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: when the lock screen state of the first electronic device is unlocked, in response to the user's lock screen operation, the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group is updated to a locked state.
[0051] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instruction to enable the first electronic device to execute: sending information that updates the lock screen status of the first electronic device to a locked state to the second electronic device.
[0052] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: receiving information sent by a third electronic device that the lock screen status of the third electronic device is updated to an unlocked state; the third electronic device is any electronic device in the device group that is different from the first electronic device; and updating the lock screen status of the third electronic device to an unlocked state in the lock screen information of the devices in the group.
[0053] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: receiving information sent by the third electronic device that the lock screen status of the third electronic device is updated to a locked state; updating the lock screen status of the third electronic device to a locked state in the lock screen information of the devices in the group.
[0054] In the above embodiment, the first electronic device can receive changes in the lock screen status of other electronic devices and update the lock screen information of devices in the group in real time, thereby ensuring the accuracy of the recorded lock screen status of each electronic device.
[0055] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: when it is determined that the fourth electronic device is connected to the device group, or when it is connected to the device group where the fourth electronic device is located, an entry recording the lock screen status of the fourth electronic device is added to the device lock screen information in the group, and the fourth electronic device is any electronic device in the device group that is different from the first electronic device.
[0056] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are specifically used to call the computer instructions to enable the first electronic device to execute: add an initialization entry recording the lock screen status of the fourth electronic device in the lock screen information of the devices in the group, and set the lock screen status of the fourth electronic device to a locked state in the initialization entry.
[0057] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: receiving information sent by the fourth electronic device that the lock screen status of the fourth electronic device is unlocked; and updating the lock screen status of the fourth electronic device in the lock screen information of the devices in the group to unlocked.
[0058] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: when it is determined that the fifth electronic device has exited the device group, deleting the entry recording the lock screen status of the fifth electronic device in the device lock screen information within the group, and the fifth electronic device is any electronic device in the device group that is different from the first electronic device.
[0059] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to cause the first electronic device to execute: when exiting the device group, delete all entries in the device group that record the lock screen status of other electronic devices in the device group from the device lock screen information in the group.
[0060] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are specifically used to call the computer instructions to enable the first electronic device to execute: when it is determined that the lock screen status of all electronic devices in the device group is locked, discard the class key and encrypt the first data to make the first data unavailable; the class key is used to decrypt the first data; when it is determined that the lock screen status of any electronic device in the device group is unlocked, load the class key and decrypt the first data to make the first data available.
[0061] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to cause the first electronic device to execute: when the first data is unavailable, deny a sixth electronic device access to the first data, and the sixth electronic device is any electronic device in the device group that is different from the first electronic device.
[0062] In combination with some embodiments of the second aspect, in some embodiments, the one or more processors are also used to call the computer instructions to enable the first electronic device to execute: when the first data is available, accept access to the first data by a seventh electronic device, and the seventh electronic device is any electronic device in the device group that is different from the first electronic device.
[0063] In some embodiments, the third electronic device, the fourth electronic device, the fifth electronic device, the sixth electronic device, and the seventh electronic device may be the same electronic device as the second electronic device or may be different electronic devices, which is not limited here.
[0064] In a third aspect, an embodiment of the present application provides a chip system, which is applied to a first electronic device, and the chip system includes one or more processors, which are used to call computer instructions to enable the first electronic device to execute the method described in the first aspect and any possible implementation method of the first aspect.
[0065] In a fourth aspect, an embodiment of the present application provides a computer program product comprising instructions, which, when the computer program product is run on a first electronic device, enables the first electronic device to execute the method described in the first aspect and any possible implementation of the first aspect.
[0066] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium comprising instructions, which, when executed on a first electronic device, enables the first electronic device to execute the method described in the first aspect and any possible implementation of the first aspect.
[0067] It is understandable that the first electronic device provided in the second aspect, the chip system provided in the third aspect, the computer program product provided in the fourth aspect, and the computer storage medium provided in the fifth aspect are all used to execute the methods provided in the embodiments of the present application. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects of the corresponding methods and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] Figure 1 This is a schematic diagram of an exemplary user interface in the locked screen state in an embodiment of the present application;
[0069] Figure 2 This is a schematic diagram of an exemplary scenario of forming a device group in an embodiment of the present application;
[0070] Figure 3 This is a schematic diagram of an exemplary scenario in which locking / unlocking and logging on / offline of electronic devices in a device group affect the state of a virtual terminal in an embodiment of the present application;
[0071] Figure 4This is a schematic diagram of a scenario of a data protection method in the prior art;
[0072] Figure 5 This is a schematic diagram of an exemplary scenario of the data protection method in an embodiment of the present application;
[0073] Figure 6 This is a set of exemplary user interfaces for electronic devices to start a multi-device collaboration function in an embodiment of the present application;
[0074] Figures 7 to 12 This is a set of exemplary user interfaces for electronic devices to perform data collaboration in the embodiments of the present application;
[0075] Figure 13 is a schematic diagram of an exemplary structure of an electronic device 100 provided in an embodiment of the present application;
[0076] Figure 14 is an exemplary software structure block diagram of the electronic device 100 provided in an embodiment of the present application;
[0077] Figure 15 This is an exemplary information flow diagram in an embodiment of the present application;
[0078] Figure 16 This is a signaling interaction diagram of the data protection method in an embodiment of the present application;
[0079] Figure 17 This is another signaling interaction diagram of the data protection method in an embodiment of the present application;
[0080] Figure 18 This is another signaling interaction diagram of the data protection method in an embodiment of the present application;
[0081] Figure 19 This is another signaling interaction diagram of the data protection method in an embodiment of the present application;
[0082] Figure 20 This is a two-machine interaction information flow diagram in an embodiment of the present application;
[0083] Figure 21 This is another signaling interaction diagram of the data protection method in an embodiment of the present application;
[0084] Figure 22 This is another signaling interaction diagram of the data protection method in an embodiment of the present application;
[0085] Figure 23 This is another two-machine interaction information flow diagram in the embodiment of the present application;
[0086] Figure 24 This is another signaling interaction diagram of the data protection method in an embodiment of the present application;
[0087] Figure 25 This is a flow chart of a data protection method in an embodiment of the present application;
[0088] Figure 26 This is another flowchart of the data protection method in the embodiment of the present application. DETAILED DESCRIPTION
[0089] The terms used in the following examples of the present application are for the purpose of describing specific embodiments only and are not intended to limit the present application. As used in the specification and appended claims of the present application, the singular expressions "a," "an," "said," "above," "the," and "this" are intended to include plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in the present application refers to and encompasses any or all possible combinations of one or more of the listed items.
[0090] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of the technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.
[0091] To facilitate understanding, the following first introduces the relevant terms and concepts involved in the embodiments of this application.
[0092] (1) Lock screen status:
[0093] In the embodiment of the present application, the lock screen state of the electronic device includes two states: locked state and unlocked state.
[0094] In the locked state, users can only use some functions of the electronic device. The electronic device can display the lock screen interface. If a lock screen password is set, the user needs to enter the password or unlock it by other means before entering the unlocked state.
[0095] In the unlocked state, the user can use all functions of the electronic device.
[0096] For example, Figure 1 This is a schematic diagram of an exemplary user interface in the lock screen state in an embodiment of the present application.
[0097] Figure 1 (a) in FIG. 1 shows an exemplary user interface in which the lock screen state of the electronic device is locked. Figure 1As shown in (a) of FIG, the electronic device is in the locked state. The electronic device displays a lock screen interface, which prompts the user to unlock the device. In this locked state, the user can only use some functions of the electronic device, such as answering calls, turning on the flashlight, and making emergency calls.
[0098] like Figure 1 As shown in (b) of FIG, in response to the user's unlocking operation, the electronic device can display an unlocking interface. If the unlocking method of the electronic device is password unlocking, after the user enters the correct password, the lock screen state of the electronic device changes from locked state to unlocked state. The electronic device can display the following Figure 1 The user interface shown in (c) in FIG.
[0099] Figure 1 (c) in FIG. 1 shows an exemplary user interface in which the lock screen state of the electronic device is unlocked. Figure 1 As shown in (c), the lock screen state of the electronic device is unlocked. The electronic device can display the applications installed in the electronic device, and the user can use all the functions of the electronic device, such as opening applications and setting functions.
[0100] (2) Device Group:
[0101] In the embodiment of the present application, multiple devices are connected via a network to form a device group, forming a distributed collaborative scenario. The electronic devices in the device group can be protected by the data protection method in the embodiment of the present application.
[0102] In the embodiments of the present application, there are many ways to form a device group:
[0103] In some embodiments, multiple electronic devices logged into the same network account can be set to form the device group;
[0104] In some embodiments, multiple electronic devices in the same local area network may be configured to form the device group;
[0105] In some embodiments, multiple electronic devices with the same specific identification may be set to form the device group;
[0106] In some embodiments, the above-mentioned methods of forming device groups may be combined to obtain a device group.
[0107] It is understandable that there may be other ways to form device groups, which are not limited here.
[0108] Optionally, in some embodiments, multiple electronic devices within a device group may form a trusted communication network. The trusted communication network may meet the following requirements:
[0109] 1. Multiple electronic devices authenticate each other;
[0110] There are many possible ways to authenticate, such as through a preset trusted authentication certificate, account number, device number, etc., which are not limited here.
[0111] 2. After authentication is completed, a communication session link is established when multiple electronic devices communicate with each other, ensuring session security.
[0112] For example, Figure 2 As shown in FIG, it is a schematic diagram of an exemplary scenario of forming a device group in an embodiment of the present application. Figure 2 As shown, the device group includes electronic devices such as mobile phones, tablets, and computers. These electronic devices are connected to form a device group through the network, forming a distributed collaborative scenario and enabling mutual data access.
[0113] (3) First data:
[0114] In the embodiment of the present application, the first data is sensitive data that needs to be encrypted in the electronic device.
[0115] In some embodiments, the electronic device may set all stored data as sensitive data that needs to be encrypted.
[0116] In some embodiments, the electronic device may set data related to user privacy as sensitive data that needs to be encrypted.
[0117] In some embodiments, the electronic device may set data related to electronic device security information as sensitive data that needs to be encrypted.
[0118] It is understandable that the sensitive data to be encrypted in the electronic device may also be set as a combination of the above data, or other data, which is not limited here.
[0119] For example, email data, health data, etc. in an electronic device can be set as sensitive data that needs to be encrypted.
[0120] Exemplarily, files in the user file system of the electronic device may be set as sensitive data that needs to be encrypted.
[0121] (4) Encryption and decryption of data in electronic devices:
[0122] In the embodiment of the present application, the first data is protected by encrypting the first data using a key in the electronic device.
[0123] When the first data is encrypted, the first data cannot be accessed, which is simply referred to as the first data being unavailable.
[0124] After the first data is decrypted using the key, the first data can be accessed, which is simply referred to as the first data being available.
[0125] Optionally, the key may be stored in a secure area of the electronic device or in a secure chip of the electronic device, which is not limited here.
[0126] It can be understood that in the embodiment of the present application, the electronic device has encrypted the first data using a key by default.
[0127] When the electronic device needs to decrypt the first data, the electronic device loads the key and uses the key to decrypt the first data, so that the first data is available.
[0128] When the electronic device needs to encrypt and protect the first data, the electronic device can discard the key loaded in the memory or application layer. At this time, the first data will be restored to the encrypted state and the first data will be unavailable.
[0129] In the embodiment of the present application, the keys for encrypting and decrypting the first data in the electronic devices constituting the device group may be collectively referred to as class keys.
[0130] (5) Online and offline actions of electronic equipment:
[0131] In the embodiment of the present application, each electronic device in a device group can determine the online action and offline action of other electronic devices.
[0132] Optionally, an electronic device may determine online actions and offline actions of other electronic devices in various ways:
[0133] For example, when electronic device A in a device group goes online, it can send an online notification to other electronic devices in the device group. After receiving the online notification, the other electronic devices can determine that electronic device A has gone online. When electronic device A goes offline, it can send a offline notification to other electronic devices in the device group. After receiving the offline notification, the other electronic devices can determine that electronic device A has gone offline.
[0134] For example, each electronic device in a device group can periodically send a heartbeat detection signal to all other devices in the connected device group, and determine the online and offline actions of other electronic devices by determining whether a response to the heartbeat detection signal is received from the other electronic devices. When electronic device A first receives a response from electronic device B to the heartbeat detection signal, electronic device A can determine that electronic device B has executed the online action; when electronic device A does not receive a response from electronic device B to the heartbeat detection signal within a period of time, electronic device A can determine that electronic device B has executed the offline action.
[0135] For example, each electronic device in a device group can determine the online and offline actions of other electronic devices by judging the status of the communication link with other electronic devices in the device group. When electronic device A establishes a communication link with electronic device B, electronic device A can determine that electronic device B has performed an online action; when electronic device A determines that the communication link with electronic device B is disconnected, electronic device A can determine that electronic device B has performed an offline action.
[0136] It is understandable that there are many other different ways for an electronic device to determine the online actions and offline actions of other electronic devices in a device group, which are not limited here.
[0137] It should be noted that, after the electronic device performs an online action, it can enter the online state. After the electronic device performs an offline action, it can enter the offline state.
[0138] Optionally, after electronic device A enters the online state, electronic device A may be displayed as online on other electronic devices. After electronic device A enters the offline state, electronic device A may be displayed as offline on other electronic devices.
[0139] (6) Virtual Terminal:
[0140] In the embodiment of the present application, a virtual terminal refers to the collection of all devices in a device group. When an electronic device goes online, it joins the device group and is in the virtual terminal. When an electronic device goes offline, it exits the device group and is no longer in the virtual terminal.
[0141] The lock screen state of the virtual terminal also includes two states: locked state and unlocked state:
[0142] When the lock screen states of all electronic devices in the virtual terminal are locked, the lock screen state of the virtual terminal is also locked. When the lock screen state of the virtual terminal is locked, the first data in all electronic devices in the virtual terminal are unavailable.
[0143] When the lock screen state of one or more electronic devices in the virtual terminal is unlocked, the lock screen state of the virtual terminal is unlocked. When the lock screen state of the virtual terminal is unlocked, the first data in all electronic devices in the virtual terminal is available.
[0144] For example, Figure 3 This is a schematic diagram of an exemplary scenario in which locking / unlocking and logging on / offline of electronic devices in a device group affect the state of a virtual terminal in an embodiment of the present application.
[0145] like Figure 3As shown in (a), a device group consisting of electronic device A and electronic device B constitutes a distributed collaborative scenario. Therefore, the virtual terminal of the device group includes electronic device A and electronic device B. Since the lock screen status of electronic device A and electronic device B are both locked, the lock screen status of the virtual terminal of the device group is also locked at this time. The first data in electronic device A and electronic device B are both unavailable. Neither electronic device A nor electronic device B can access the first data stored in another electronic device in the device group in this distributed collaborative scenario.
[0146] like Figure 3 As shown in (b), if electronic device C comes online at this time, it joins the device group. Therefore, the virtual terminal of the device group includes electronic device A, electronic device B and electronic device C. Although the lock screen status of electronic device A and electronic device B are still locked, the lock screen status of electronic device C is unlocked. Therefore, at this time, the lock screen status of the virtual terminal of the device group is changed to unlocked. Electronic device A and electronic device B in the device group load the key to decrypt the first data in the electronic device, so that the first data in the electronic device is changed to available. At this time, any electronic device in the device group can access the first data stored in any electronic device in the device group in the distributed collaborative scenario.
[0147] Figure 3 As shown in (c), if electronic device B goes offline at this time, the device will be infringed. Therefore, the virtual terminal of the device group includes electronic device A and electronic device C. Since the lock screen state of electronic device A is locked and the lock screen state of electronic device C is unlocked, the lock screen state of the virtual terminal of the device group is still maintained in unlocked state. Electronic device A and electronic device C will not discard the key and make the first data in the electronic device unavailable. At this time, electronic device A or electronic device C in the device group can still continue to access the first data stored in another electronic device in the device group in the distributed collaborative scenario.
[0148] (7) Lock screen information of devices in the group:
[0149] In the embodiment of the present application, the in-group device lock screen information is used to indicate the corresponding relationship between the identification of the electronic devices in the device group and the lock screen status. The in-group device lock screen information can be stored in the memory of the electronic device.
[0150] The identifier of the electronic device is used to uniquely identify an electronic device in the device group.
[0151] Optionally, the identifier of the electronic device may be one or a combination of a device name, a device physical address, a mobile equipment identifier (MEID), an international mobile equipment identity (IMEI), etc., which is not limited here.
[0152] For example, taking IMEI as the identifier of an electronic device, the following Table 1 is an example of the lock screen information of the devices in the group in an embodiment of the present application:
[0153] Electronic equipment identification Lock screen status IMEI of device 1 Locked state IMEI of device 2 Unlocked IMEI of device 3 Unlocked
[0154] Table 1
[0155] The electronic devices in the device group can determine from the lock screen information of the devices in the group shown in Table 1 that: the lock screen status of device 1 is locked; and the lock screen status of devices 2 and 3 are unlocked.
[0156] In some embodiments, the group lock screen information stored in an electronic device may not include the lock screen status information of the electronic device itself. In some embodiments, an electronic device includes the lock screen status information of the electronic device itself. This is not limited here.
[0157] It is understandable that Table 1 is only an exemplary illustration of the lock screen information of devices in the group. In actual applications, the lock screen information of devices in the group can be stored in many other different forms, such as arrays, matrices, databases, etc., which are not limited here.
[0158] In the distributed collaborative scenario of the prior art, whether the first data in an electronic device is available is bound to the attribute state of whether the electronic device is locked. When the lock screen state of the electronic device is locked, the key for encrypting the first data is discarded, making the first data of the electronic device unavailable. When the lock screen state of the electronic device is unlocked, the key for encrypting the first data is loaded, making the first data of the electronic device available. When the lock screen state of the electronic device is locked, since the first data of the electronic device is unavailable, other electronic devices in the distributed collaborative scenario cannot read the first data in the electronic device, resulting in the inability to achieve cross-device collaboration of data, affecting the normal operation of the collaborative business.
[0159] For example, Figure 4 The figure is a schematic diagram of a scenario of a data protection method in the prior art.
[0160] like Figure 4As shown in (a) and (c), in a distributed collaborative scenario consisting of electronic device A, electronic device B, electronic device C and electronic device D, the lock screen state of electronic device A is locked. At this time, the key for encrypting the first data in electronic device A is discarded, and the first data in electronic device A is encrypted and protected and is in an unavailable state. The lock screen state of electronic device B, which is a collaborative electronic device of electronic device A, is locked, the lock screen state of electronic device C is locked, and the lock screen state of electronic device D is unlocked. Since the first data of electronic device A is unavailable, electronic device B, electronic device C and electronic device D cannot access the encrypted and protected first data in electronic device A, such as email data or health data.
[0161] like Figure 4 As shown in (b) and (c) above, the lock screen state of electronic device A changes to the unlocked state. At this point, electronic device A loads the key to decrypt the encrypted first data, making the first data in electronic device A available. Only then can electronic devices B, C, and D, acting as collaborative devices, access the first data in electronic device A, such as email data or health data.
[0162] However, in practical applications of distributed collaboration scenarios, the screen of the electronic device whose data needs to be accessed is often locked. Therefore, it is common for data on the target device to be unavailable due to the screen being locked. Therefore, existing FBE implementations are not well suited to distributed collaboration scenarios, preventing many collaborative services in these scenarios from operating normally.
[0163] By adopting the data protection method provided in the embodiment of the present application, as long as the lock screen status of any electronic device in the device group constituting the distributed collaborative scenario is unlocked, each electronic device in the device group will use the key to decrypt the encrypted first data, making the first data in its own electronic device available and accessible to other electronic devices in the device group, thereby ensuring the normal operation of the collaborative business in the distributed collaborative scenario. Only when the lock screen status of all electronic devices in the device group is locked will each electronic device in the device group discard the loaded key and the first data will be restored to the encrypted state, thereby achieving security protection of the first data without affecting the normal operation of the collaborative business in the distributed collaborative scenario.
[0164] Figure 5 This is a schematic diagram of an exemplary scenario of the data protection method in an embodiment of the present application.
[0165] like Figure 5As shown in (a), electronic device A, electronic device B, and electronic device C form a device group. Although the lock screen status of electronic device A and electronic device B are both locked, the lock screen status of electronic device C is unlocked. Therefore, in the distributed collaborative scenario formed by the device group, the first data in electronic device A, electronic device B, and electronic device C are all decrypted and become usable. For example, the first data can be sensitive data such as email data or health data. Although the lock screen status of electronic device A and electronic device B is locked, electronic device B and electronic device C can access each other's first data.
[0166] like Figure 5 As shown in (b) of the figure, when the lock screen status of electronic device C changes to locked, the lock screen status of electronic devices A, B, and C, which make up the device group, are all locked. At this point, electronic devices A, B, and C all discard the key, causing the first data in their respective electronic devices to return to an encrypted and unavailable state. Consequently, electronic devices A, B, and C cannot access each other's first data.
[0167] Therefore, by adopting the data protection method in the embodiment of the present application, the normal use of protected data in a distributed collaborative scenario is achieved while the data is securely protected.
[0168] The following uses a set of exemplary user interfaces (UIs) as an example to illustrate the data protection method in the embodiments of the present application:
[0169] It is understood that in some embodiments, if an electronic device needs to form a device group with other electronic devices and access data from each other in a distributed collaborative scenario, the electronic device can first activate the multi-device collaboration function in the device before the electronic device executes the data protection method in the embodiment of the present application. In some embodiments, the electronic device can activate the multi-device collaboration function by default, or the electronic device can execute the data protection method in the embodiment of the present application without activating the multi-device collaboration function, which is not limited here.
[0170] The following describes an example of a user needing to activate the multi-device collaboration function of an electronic device:
[0171] Figure 6 A set of exemplary user interfaces for enabling multi-device collaboration functions by electronic devices in an embodiment of the present application.
[0172] The term "user interface" as used in the specification, claims, and drawings of this application refers to the media interface for interaction and information exchange between an application or operating system and a user. It enables the conversion between the internal form of information and a form acceptable to the user. A common form of user interface is a graphical user interface (GUI), which refers to a user interface related to computer operations that is displayed graphically. It can be an interface element such as an icon, window, or control displayed on the display screen of an electronic device, where a control can include visual interface elements such as icons, buttons, menus, tabs, text boxes, dialog boxes, status bars, navigation bars, and widgets.
[0173] Figure 6 (a) in FIG. 1 exemplarily shows an exemplary user interface 61 on an electronic device for displaying applications installed on the electronic device.
[0174] The user interface 61 may include: a status bar 601, a calendar indicator 602, a tray 603 with common application icons, and other application icons.
[0175] The status bar 601 may include: one or more signal strength indicators 601A of mobile communication signals (also known as cellular signals), one or more signal strength indicators 601B of wireless fidelity (Wi-Fi) signals, a battery status indicator 601C, and a time indicator 601D.
[0176] The calendar indicator 602 may be used to indicate the current time, such as date, day of the week, hour and minute information, etc.
[0177] The tray 603 with commonly used application icons may display: a phone icon 603A, a contact icon 603B, a text message icon 603C, and a camera icon 603D.
[0178] Other application icons may include, for example, a mailbox icon 611, a memo icon 612, a gallery icon 613, and a settings icon 614. User interface 61 may also include a page indicator 615. Other application icons may be distributed across multiple pages, and page indicator 615 may be used to indicate which page of applications the user is currently browsing. The user may swipe left or right on the area containing the other application icons to browse application icons on other pages.
[0179] In some embodiments, Figure 6 The user interface 61 shown in (a) can be a main interface (Home screen).
[0180] In some other embodiments, the electronic device may further include a physical home screen key. The home screen key may be used to receive a user's instruction to return the currently displayed UI to the main interface, so that the user can conveniently view the home screen at any time. The above instruction may specifically be an operation instruction for the user to press the home screen key once, or an operation instruction for the user to press the home screen key twice in a short period of time, or an operation instruction for the user to long press the home screen key within a predetermined time. In some other embodiments of the present application, the home screen key may also be integrated with a fingerprint identifier so that fingerprint collection and identification can be performed when the home screen key is pressed.
[0181] It is understandable that Figure 6 (a) is merely an illustrative example of a user interface on an electronic device and should not constitute a limitation on the embodiments of the present application.
[0182] In response to the user Figure 6 The electronic device may display an operation (such as a click operation) on the setting icon 614 in the user interface 61 shown in (a) of FIG. Figure 6 The user interface 62 shown in (b) in FIG.
[0183] Figure 6 The user interface 62 exemplarily shown in (b) may be provided by a "settings" application. The "settings" application is an application installed on an electronic device for setting various functions of the electronic device. The present embodiment of the application does not limit the name of the application.
[0184] like Figure 6 As shown in (b) in FIG. 5 , the user interface 62 may include: a title bar 621 , a search bar 622 , and an area 623 including one or more setting items.
[0185] The title bar 621 may include a current page indicator 621A, which may be used to indicate the current page. For example, the text message "settings" may be used to indicate that the current page is used to display one or more setting items. The current page indicator 722A is not limited to text information and may also be an icon.
[0186] The search bar 622 may include a search indicator 622A. The search indicator 622A can be used to search for setting items contained in the current page. For example, if you enter "Bluetooth", the "Bluetooth" setting item will appear in the current interface. It is not limited to text information. The search indicator 622A can also be an icon.
[0187] Area 623 includes one or more setting items, which may include: user setting items, WIFI setting items, Bluetooth setting items, mobile network setting items, more connection setting items 623A, desktop and wallpaper setting items, display and brightness setting items, etc. The presentation form of each setting item may include icons and / or text, which is not limited in this application. Each setting item can be used to monitor an operation (such as a touch operation) that triggers the display of the setting content of the corresponding setting item. In response to the operation, the electronic device can open a user interface for displaying the setting content of the corresponding setting item.
[0188] In response to the user Figure 6 In the case of an operation (such as a click operation) on the more connection setting item 623A in the user interface 62 shown in (b) in FIG, the electronic device may display the following Figure 6 The user interface 63 shown in (c) in FIG.
[0189] like Figure 6 As shown in (c) of FIG. 5 , the user interface 63 is used to display the corresponding content of more connection management setting items. The user interface 63 may include: a title bar 631 and a more connection management area 632 .
[0190] The title bar 631 may include: a return key 631A and a current page indicator 631B. The return key 631A is an APP-level return key that can be used to return to the previous level of the menu. The previous level page of the user interface 63 can be as follows: Figure 6 The user interface 62 shown in (b) of FIG. The current page indicator 631B can be used to indicate the current page. For example, the text message "More Connection Management" can be used to indicate that the current page is used to display the corresponding content of more connection setting items. The current page indicator 632B is not limited to text information and can also be an icon.
[0191] The more connection management area 632 includes one or more management items, which may include: a multi-device collaboration management item 632A, a mobile phone sharing management item, a mobile phone screen projection management item, a printing management item, a VPN management item, an encrypted DNS management item, etc. The presentation of each management item may include an icon and / or text, which is not limited in this application. Each management item can be used to monitor an operation (such as a touch operation) that triggers the display of the management content of the corresponding management item. In response to the operation, the electronic device can open a user interface for displaying the management content of the corresponding management item.
[0192] In response to the user Figure 6By performing an operation (e.g., a slide or click) on the multi-device collaborative management item in the user interface 63 shown in (c) of FIG, the electronic device can change the switch state of the multi-device collaborative management item 632A from OFF to ON. The electronic device then activates the multi-device collaborative function. The data protection method of the embodiment of the present application can continue to be executed.
[0193] Combine Figure 6 The user interface shown is as follows. Taking the electronic device with the multi-device collaboration function enabled and other electronic devices forming a device group to perform data collaboration as an example, the relevant user interface is described exemplarily:
[0194] Figures 7 to 12 A set of exemplary user interfaces for electronic devices to perform data collaboration in the embodiments of the present application.
[0195] It is understandable that Figures 7 to 12 This is only an exemplary scenario for data collaboration among electronic devices that make up a device group. In actual applications, there can be many other different scenarios for data collaboration and related user interfaces. As long as the electronic devices that make up the device group can access each other's first data, there is no limitation here.
[0196] like Figure 7 As shown in (a), after the multi-device collaboration function of electronic device A is turned on, the online status of electronic devices that can form a device group with electronic device A can be displayed in the user interface 71A of electronic device A.
[0197] For example, when electronic device A detects that electronic device B, which has logged into the same network account, is online, a connection prompt box 701 may be displayed in the user interface 70A. The connection prompt box may include a connection confirmation control 701a for accepting user operation to confirm whether to form a device group with electronic device B. For example, electronic device B may be a tablet computer.
[0198] Electronic device A can also display a status prompt box 702 in the user interface 70A after detecting that the smart screen logged in to the same network account is in an offline state, and indicate in the status prompt box 702 that the smart screen is in an offline state.
[0199] Electronic device A may also display a status prompt box 703 in the user interface 70A after detecting that the laptop computer logged in with the same network account is in an offline state, and indicate in the status prompt box 703 that the laptop computer is in an offline state.
[0200] In response to the user clicking the connection confirmation control 701a in the user interface 70A, electronic device A and electronic device B may form a device group.
[0201] like Figure 7 As shown in (b), a connection prompt box 711 may be displayed in the user interface 71B of electronic device B. The connection prompt box 711 may include a connection indicator 711a. The connection indicator 711a may be used to indicate that electronic device B and electronic device A are connecting to form a device group.
[0202] After electronic device A and electronic device B form a device group, electronic device A can display Figure 8 The user interface 80A shown in (a) of FIG. 80A may include a mail icon 801 .
[0203] Electronic device B can display Figure 8 The user interface 81B shown in (b) of FIG. The user interface 81B may display the mapping screen 811 of the electronic device A, and the content displayed in the mapping screen 811 may be the same as the user interface 80A of the electronic device A.
[0204] In response to the user Figure 8 By operating on the mail icon 801 in the user interface 80A shown in (a), the electronic device A may display the following Figure 9 The user interface 90A shown in (a) in FIG. The user interface 90A may include an email information display area 901 , in which a plurality of email messages may be displayed.
[0205] Correspondingly, such as Figure 9 As shown in (b) of FIG. 8 , the content displayed on the mapping screen 811 displayed in the user interface 81B of the electronic device B may be refreshed to be the same as that of the user interface 90A of the electronic device A.
[0206] In response to the user Figure 9 As shown in (b) of FIG, the operation (such as dragging) of the mail information 9011 in the mapping screen 811 can be performed by electronic device B to read the data corresponding to the mail information 9011 in electronic device A and save it in electronic device B. Then, the following can be displayed: Figure 10 The user interface 101B shown in (b) in FIG. 1 may include an email editing area 1011 , and the email editing area 1011 may display information in the email message 9011 .
[0207] At this time, electronic device A can continue to display Figure 10 User interface 90A shown in (a) in FIG.
[0208] In response to the user Figure 10 The lock screen operation of the lock screen button 1001 shown in (a) of FIG. 1 may display the following information: Figure 11 The user interface 110A shown in (a) is the lock screen interface of the electronic device A, and the lock screen state of the electronic device A is changed from the unlocked state to the locked state.
[0209] At this time, if Figure 11 As shown in (b) of FIG, electronic device B may display a lock screen prompt 1111 on user interface 101B, which prompts the user that electronic device A, which forms a device group with electronic device B, has been locked. However, the connection with electronic device A is not disconnected, and electronic device B may continue to access the email data of electronic device A, for example, by dragging other email information on electronic device A from mapping screen 811.
[0210] After electronic device B also locks the screen, electronic device A can continue to display Figure 12 User interface 110A shown in (a) in FIG.
[0211] Electronic device B can display Figure 12 1B. In this user interface 1201B, electronic device B can no longer display the data in electronic device A, and may display a prompt message 1211 in the area of the original mapping screen 811. This prompt message 1211 may be used to indicate to the user that the lock screen of an electronic device in the device group must be unlocked before the electronic devices in the device group can access each other's encrypted data.
[0212] It can be seen that using the data protection method in the embodiments of the present application, in a distributed collaborative scenario, even if the lock screen status of an electronic device is locked, as long as the lock screen status of an electronic device in the device group is unlocked, other electronic devices in the device group can also access the first data in the electronic device with the locked lock screen. When the lock screen status of all electronic devices is locked, each electronic device will encrypt the first data, making it no longer accessible at will, thereby ensuring data security.
[0213] The following first introduces an exemplary electronic device 100 provided in an embodiment of the present application.
[0214] Figure 13 1 is a schematic structural diagram of an electronic device 100 provided in an embodiment of the present application.
[0215] The following embodiments are described in detail using electronic device 100 as an example. It should be understood that electronic device 100 may have more or fewer components than shown in the figure, may combine two or more components, or may have a different component configuration. The various components shown in the figure may be implemented in hardware, including one or more signal processing and / or application-specific integrated circuits, software, or a combination of hardware and software.
[0216] The electronic device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0217] It should be understood that the structure illustrated in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0218] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.
[0219] The controller may be the nerve center and command center of the electronic device 100. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0220] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.
[0221] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.
[0222] The I2C interface is a bidirectional synchronous serial bus that includes a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 may include multiple I2C bus lines. The processor 110 may be coupled to the touch sensor 180K, the charger, the flash, the camera 193, and the like via different I2C bus interfaces. For example, the processor 110 may be coupled to the touch sensor 180K via the I2C interface, enabling communication between the processor 110 and the touch sensor 180K via the I2C bus interface, thereby implementing the touch function of the electronic device 100.
[0223] The I2S interface can be used for audio communication. In some embodiments, the processor 110 can include multiple I2S buses. The processor 110 can be coupled to the audio module 170 via the I2S bus to enable communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the I2S interface, enabling the function of answering calls through a Bluetooth headset.
[0224] The PCM interface can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled via a PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 via the PCM interface, enabling the function of answering calls via a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.
[0225] The UART interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. It converts the data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is typically used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 via the UART interface to implement Bluetooth functionality. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the UART interface, enabling the function of playing music through Bluetooth headphones.
[0226] The MIPI interface can be used to connect the processor 110 to peripheral devices such as the display 194 and the camera 193. MIPI interfaces include the camera serial interface (CSI) and the display serial interface (DSI). In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to implement the camera function of the electronic device 100. The processor 110 and the display 194 communicate via the DSI interface to implement the display function of the electronic device 100.
[0227] The GPIO interface can be configured via software. The GPIO interface can be configured as either a control signal or a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 to the camera 193, display 194, wireless communication module 160, audio module 170, sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.
[0228] The SIM interface can be used to communicate with the SIM card interface 195 to implement the function of transmitting data to the SIM card or reading data in the SIM card.
[0229] The USB interface 130 is an interface that complies with USB standards and may be a Mini USB interface, a Micro USB interface, a USB Type-C interface, or the like. The USB interface 130 can be used to connect a charger to charge the electronic device 100, or to transfer data between the electronic device 100 and peripheral devices. It can also be used to connect headphones to play audio. This interface can also be used to connect other electronic devices, such as augmented reality devices.
[0230] It is understood that the interface connection relationship between the modules illustrated in the embodiment of the present invention is merely an illustrative illustration and does not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods from the above embodiments, or a combination of multiple interface connection methods.
[0231] The charging management module 140 is configured to receive charging input from a charger, which may be a wireless charger or a wired charger.
[0232] The power management module 141 is used to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140 to provide power to the processor 110, the internal memory 121, the external memory, the display 194, the camera 193, and the wireless communication module 160.
[0233] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor.
[0234] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.
[0235] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to the electronic device 100. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.
[0236] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the receiver 170B, etc.) or displays an image or video through the display screen 194. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be set in the same device as the mobile communication module 150 or other functional modules.
[0237] The wireless communication module 160 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., which are applied to the electronic device 100. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.
[0238] In some embodiments, the antenna 1 of the electronic device 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the electronic device 100 can communicate with the network and other devices through wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).
[0239] Electronic device 100 implements display functionality through a GPU, display screen 194, and an application processor. A GPU is a microprocessor for image processing that connects display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs that execute program instructions to generate or modify display information.
[0240] Display screen 194 is used to display images, videos, and the like. Display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-oLed, or a quantum dot light-emitting diode (QLED). In some embodiments, electronic device 100 may include one or N display screens 194, where N is a positive integer greater than one.
[0241] The electronic device 100 can implement a shooting function through an ISP, a camera 193, a video codec, a GPU, a display screen 194, and an application processor.
[0242] The ISP processes data fed back by camera 193. For example, when taking a photo, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, which is then passed to the ISP for processing and converted into a visible image. The ISP can also perform algorithmic optimization on image noise, brightness, and skin tone. It can also optimize parameters such as exposure and color temperature of the captured scene. In some embodiments, the ISP can be located within camera 193.
[0243] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then passes the electrical signal to the ISP for conversion into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the electronic device 100 may include 1 or N cameras 193, where N is a positive integer greater than 1.
[0244] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy.
[0245] Video codecs are used to compress or decompress digital video. Electronic device 100 may support one or more video codecs. This allows electronic device 100 to play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, and MPEG4.
[0246] The NPU is a neural network (NN) computing processor. Drawing on the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it rapidly processes input information and can continuously self-learn. The NPU can enable intelligent cognitive applications in electronic device 100, such as image recognition, face recognition, speech recognition, and text comprehension.
[0247] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 via the external memory interface 120 to implement data storage functions. For example, files such as music and videos can be stored on the external memory card.
[0248] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, applications required for at least one function (such as face recognition function, fingerprint recognition function, mobile payment function, etc.), etc. The data storage area can store data created during the use of the electronic device 100 (such as face information template data, fingerprint information template, etc.), etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0249] In an embodiment of the present application, the internal memory 121 may store lock screen information for devices within the group. The lock screen information for devices within the group stores a correspondence between the identifiers of the electronic devices in the device group and their lock screen states. The device group may be formed using networking technology via the mobile communication module 150 or the wireless communication module 160.
[0250] Optionally, the internal memory 121 may also store key information for encrypting the first data, etc., which is not limited here.
[0251] The electronic device 100 can implement audio functions such as music playback and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor.
[0252] The audio module 170 is used to convert digital audio information into analog audio signal output, and is also used to convert analog audio input into digital audio signals. The audio module 170 can also be used to encode and decode audio signals. In some embodiments, the audio module 170 can be provided in the processor 110, or some functional modules of the audio module 170 can be provided in the processor 110.
[0253] The speaker 170A, also called a "speaker", is used to convert audio electrical signals into sound signals. The electronic device 100 can listen to music or listen to hands-free calls through the speaker 170A.
[0254] The receiver 170B, also called a "handset", is used to convert audio electrical signals into sound signals. When the electronic device 100 receives a call or a voice message, the user can place the receiver 170B close to the ear to hear the voice.
[0255] Microphone 170C, also known as "microphone" or "microphone", is used to convert sound signals into electrical signals. When making a call or sending a voice message, the user can speak by putting their mouth close to the microphone 170C to input the sound signal into the microphone 170C. The electronic device 100 can be provided with at least one microphone 170C. In other embodiments, the electronic device 100 can be provided with two microphones 170C, which can not only collect sound signals but also realize noise reduction function. In other embodiments, the electronic device 100 can also be provided with three, four or more microphones 170C to collect sound signals, reduce noise, identify the source of sound, realize directional recording function, etc.
[0256] The headphone jack 170D is used to connect a wired headphone and can be the USB interface 130 or a 3.5mm open mobile terminal platform (OMTP) standard interface or a cellular telecommunications industry association of the USA (CTIA) standard interface.
[0257] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be located on display screen 194. There are many types of pressure sensors 180A, such as resistive, inductive, and capacitive. A capacitive pressure sensor can include at least two parallel plates made of conductive material. When force acts on pressure sensor 180A, the capacitance between the electrodes changes. Electronic device 100 determines the intensity of the pressure based on this change in capacitance. When a touch operation is applied to display screen 194, electronic device 100 detects the touch intensity based on pressure sensor 180A. Electronic device 100 can also calculate the touch location based on the detection signal from pressure sensor 180A. In some embodiments, touch operations applied to the same touch location but with different touch intensities can correspond to different operation instructions. For example, when a touch operation with an intensity less than a first pressure threshold is applied to a short message application icon, a command to view short messages is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to a short message application icon, a command to create a new short message is executed.
[0258] The gyroscope sensor 180B can be used to determine the motion posture of the electronic device 100. In some embodiments, the angular velocity of the electronic device 100 around three axes (i.e., x, y, and z axes) can be determined by the gyroscope sensor 180B. The gyroscope sensor 180B can be used for anti-shake shooting. For example, when the shutter is pressed, the gyroscope sensor 180B detects the angle of the electronic device 100 shaking, calculates the distance that the lens module needs to compensate based on the angle, and allows the lens to offset the shaking of the electronic device 100 through reverse movement to achieve anti-shake. The gyroscope sensor 180B can also be used for navigation and somatosensory game scenes.
[0259] The air pressure sensor 180C is used to measure air pressure. In some embodiments, the electronic device 100 calculates the altitude using the air pressure value measured by the air pressure sensor 180C to assist in positioning and navigation.
[0260] The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can use the magnetic sensor 180D to detect the opening and closing of the flip case. In some embodiments, when the electronic device 100 is a flip phone, the electronic device 100 can detect the opening and closing of the flip cover based on the magnetic sensor 180D. Based on the detected opening and closing status of the case or flip cover, features such as automatic unlocking of the flip cover can be configured.
[0261] Accelerometer 180E can detect the magnitude of acceleration of electronic device 100 in all directions (generally three axes). It can also detect the magnitude and direction of gravity when electronic device 100 is stationary. It can also be used to identify the electronic device's posture, enabling applications such as switching between landscape and portrait modes and pedometers.
[0262] The distance sensor 180F is used to measure distance. The electronic device 100 can measure distance using infrared or laser. In some embodiments, when shooting a scene, the electronic device 100 can use the distance sensor 180F to measure distance to achieve fast focusing.
[0263] The proximity light sensor 180G may include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The light emitting diode may be an infrared light emitting diode. The electronic device 100 emits infrared light outward through the light emitting diode. The electronic device 100 uses a photodiode to detect infrared reflected light from nearby objects. When sufficient reflected light is detected, it can be determined that there is an object near the electronic device 100. When insufficient reflected light is detected, the electronic device 100 can determine that there is no object near the electronic device 100. The electronic device 100 can use the proximity light sensor 180G to detect that the user is holding the electronic device 100 close to the ear to talk, so as to automatically turn off the screen to save power. The proximity light sensor 180G can also be used in leather case mode and pocket mode to automatically unlock and lock the screen.
[0264] Ambient light sensor 180L is used to sense ambient light brightness. Electronic device 100 can adaptively adjust the brightness of display screen 194 based on the perceived ambient light. Ambient light sensor 180L can also be used to automatically adjust white balance when taking photos. Ambient light sensor 180L can also work with proximity light sensor 180G to detect whether electronic device 100 is in a pocket to prevent accidental touches.
[0265] The fingerprint sensor 180H is used to collect fingerprints. The electronic device 100 can use the collected fingerprint characteristics to implement fingerprint unlocking, access application locks, fingerprint photography, fingerprint call answering, etc.
[0266] In some embodiments, the fingerprint characteristics collected by the fingerprint sensor 180H can realize fingerprint unlocking and enable the electronic device to enter the unlocked state from the locked state.
[0267] The temperature sensor 180J is used to detect temperature. In some embodiments, the electronic device 100 uses the temperature detected by the temperature sensor 180J to execute a temperature processing strategy. For example, when the temperature reported by the temperature sensor 180J exceeds a threshold, the electronic device 100 reduces the performance of the processor located near the temperature sensor 180J to reduce power consumption and implement thermal protection. In other embodiments, when the temperature is lower than another threshold, the electronic device 100 heats the battery 142 to prevent the electronic device 100 from shutting down abnormally due to low temperature. In other embodiments, when the temperature is lower than another threshold, the electronic device 100 boosts the output voltage of the battery 142 to prevent abnormal shutdown due to low temperature.
[0268] The touch sensor 180K is also called a "touch panel." The touch sensor 180K can be disposed on the display screen 194. The touch sensor 180K and the display screen 194 form a touch screen, also called a "touch screen." The touch sensor 180K is used to detect touch operations applied thereto or in the vicinity thereof. The touch sensor can transmit the detected touch operations to the application processor to determine the type of touch event. Visual output related to the touch operations can be provided via the display screen 194. In other embodiments, the touch sensor 180K can also be disposed on the surface of the electronic device 100, in a location different from that of the display screen 194.
[0269] The buttons 190 include a power button, a volume button, and the like. The buttons 190 may be mechanical buttons or touch buttons. The electronic device 100 may receive key inputs and generate key signal inputs related to user settings and function control of the electronic device 100.
[0270] Motor 191 can generate vibration prompts. Motor 191 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, audio playback, etc.) can correspond to different vibration feedback effects. For touch operations acting on different areas of the display screen 194, motor 191 can also correspond to different vibration feedback effects. Different application scenarios (for example: time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.
[0271] The indicator 192 may be an indicator light, which may be used to indicate the charging status, power level changes, messages, missed calls, notifications, etc.
[0272] The SIM card interface 195 is used to connect a SIM card. The SIM card can be connected to and disconnected from the electronic device 100 by inserting it into or removing it from the SIM card interface 195. The electronic device 100 can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 195 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 195 can also be compatible with different types of SIM cards. The SIM card interface 195 can also be compatible with external memory cards. The electronic device 100 interacts with the network through the SIM card to implement functions such as calls and data communications.
[0273] Figure 14 It is a software structure block diagram of the electronic device 100 according to an embodiment of the present application.
[0274] A layered architecture divides software into several layers, each with distinct roles and responsibilities. Layers communicate with each other via software interfaces. In some embodiments, the system is divided into four layers: application layer, application framework layer, runtime and system libraries, and kernel layer.
[0275] The application layer can include a series of application packages.
[0276] like Figure 14 As shown, the application package may include camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, short message and other applications (also referred to as applications).
[0277] In an embodiment of the present application, the application layer may also include a local lock screen / unlock module, which is used to detect and respond to the lock screen / unlock event of the electronic device, and notify the lock screen status of the electronic device to the following virtual terminal lock status management module and / or lock screen status synchronization / receiving module.
[0278] The application framework layer provides an application programming interface (API) and programming framework for the applications in the application layer. The application framework layer includes some predefined functions.
[0279] like Figure 14 As shown, the application framework layer may include a window manager, a content provider, a view system, a phone manager, a resource manager, a notification manager, and the like.
[0280] The window manager is used to manage window programs. The window manager can obtain the display size, determine whether there is a status bar, lock the screen, take screenshots, etc.
[0281] Content providers are used to store and retrieve data and make it accessible to applications. The data may include videos, images, audio, calls made and received, browsing history and bookmarks, phone books, etc.
[0282] The view system includes visual controls, such as those for displaying text and images. The view system is used to build applications. A display interface can consist of one or more views. For example, a display interface containing a text notification icon might include a view for displaying text and a view for displaying images.
[0283] The phone manager is used to provide communication functions of the electronic device 100, such as management of call status (including answering, hanging up, etc.).
[0284] The resource manager provides various resources for applications, such as localized strings, icons, images, layout files, video files, and so on.
[0285] The Notification Manager allows applications to display notifications in the status bar. These messages can be displayed briefly and then disappear automatically, without requiring user interaction. For example, the Notification Manager can be used to notify users of completed downloads, message reminders, and so on. The Notification Manager can also display notifications in the top status bar of the system as icons or scrolling text, such as notifications from background applications, or as dialog interfaces on the screen. Examples include text messages in the status bar, beeps, vibrations on electronic devices, and flashing indicator lights.
[0286] In the embodiment of the present application, the application framework layer may further include a user management module, a lock screen status synchronization / receiving module, a virtual terminal lock status management module, and a group key management module.
[0287] Among them, the user management module is used to provide users with services such as changing the unlock password, verifying the unlock password, and first unlocking.
[0288] The lock screen status synchronization / receiving module is used to receive the lock screen status of electronic devices in the device group, and update the lock screen status to the lock screen information of the devices in the group. It can also be used to synchronize the lock screen status of the electronic device to other electronic devices in the device group.
[0289] In some embodiments, the lock screen status synchronization / receiving module can also trigger the operation of other modules in the electronic device by sending information to other modules in the electronic device, which is not limited here.
[0290] The virtual terminal lock status management module is used to store the lock screen information of the devices in the group and the determination strategy of the virtual terminal lock screen status. It can judge and update the lock screen status of the virtual terminal based on the lock screen status information of all electronic devices in the device group stored in the lock screen information of the devices in the group, combined with the determination strategy of the virtual terminal lock screen status.
[0291] In some embodiments, the virtual terminal lock state management module may also notify other modules in the electronic device of the lock screen state of the virtual terminal, which is not limited here.
[0292] The group class key management module is configured to manage a class key for the first data based on the lock screen state of the virtual terminal. When the lock screen state of the virtual terminal is unlocked, the class key is loaded into the kernel file system to make the first data available. When the lock screen state of the virtual terminal is locked, the class key in the kernel file system is discarded to make the first data unavailable.
[0293] The runtime includes the core library and the virtual machine. The runtime is responsible for the scheduling and management of the system.
[0294] The core library consists of two parts: one part is the function that the programming language (for example, Java language) needs to call, and the other part is the core library of the system.
[0295] The application layer and application framework layer run in a virtual machine. The virtual machine executes the application layer and application framework layer programming files (for example, Java files) as binary files. The virtual machine performs functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.
[0296] The system library can include multiple functional modules, such as surface manager, media library, 3D graphics processing library (such as OpenGL ES), 2D graphics engine (such as SGL), etc.
[0297] The surface manager is used to manage the display subsystem and provide the fusion of two-dimensional (2D) and three-dimensional (3D) layers for multiple applications.
[0298] The media library supports playback and recording of a variety of common audio and video formats, as well as static image files. The media library can support a variety of audio and video encoding formats, such as: MPEG4, H.264, MP3, AAC, AMR, JPG, PNG, etc.
[0299] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.
[0300] A 2D graphics engine is a drawing engine for 2D drawings.
[0301] The kernel layer is the layer between hardware and software. The kernel layer includes at least display driver, camera driver, audio driver, sensor driver, and virtual card driver.
[0302] In an embodiment of the present application, the kernel layer may also include a communication and networking management module and a kernel file system.
[0303] The communication and networking management module is used to implement electronic device networking and communication between electronic devices in the networked device group. For example, it can provide notification of lock screen status and online and offline notifications between electronic devices in the device group, which are not limited here.
[0304] The kernel file system, used to manage the file system of the electronic device, can decrypt first data using the class key after the group class key management module controls loading the class key, making the first data available. After the group class key management module controls discarding the class key, the kernel file system can encrypt the first data, making the first data unavailable. Data can also be sent to other electronic devices in the device group via the communication and networking management module, although this is not limited here.
[0305] Combine Figure 14 As shown in the software architecture diagram, in some embodiments of the present application, the above-mentioned lock screen status synchronization / receiving module may include an intra-group lock screen event receiving module and an intra-group lock screen event synchronization module.
[0306] The intra-group lock screen event receiving module can be used to receive the lock screen status of each electronic device in the device group, and update the lock screen status to the intra-group device lock screen information stored in the virtual terminal lock status management module.
[0307] The intra-group lock screen event synchronization module can be used for the lock screen status of each electronic device, and can also be used to synchronize the online / offline status of each electronic device in the device group, which is not limited here.
[0308] In the embodiment of the present application, the virtual terminal lock state management module may include a group lock screen state storage module, a virtual terminal lock state determination module, and a policy management module.
[0309] The group lock screen status storage module can be used to store and update the lock screen information of devices in the group;
[0310] The policy management module can be used to set a virtual terminal lock screen state determination policy. In some embodiments of the present application, the virtual terminal lock screen state determination policy is that if all devices in the device group are locked, the virtual terminal is locked; if any device in the device group is unlocked, the virtual terminal is unlocked.
[0311] The virtual terminal lock status judgment module is used to judge and update the lock screen status of the virtual terminal based on the lock screen status of all electronic devices in the device group in the group device lock screen information stored in the group lock screen status storage module, combined with the virtual terminal lock screen status judgment policy set in the policy management module.
[0312] For example, combined Figure 14 The software architecture diagram shown in Figure 15 This is a schematic diagram of an exemplary information flow in an embodiment of the present application.
[0313] Figure 15 The diagram shows an exemplary information flow in which a first electronic device in a device group loads a class key to decrypt first data after detecting an unlocking event triggered by a user when a virtual terminal is in a locked state.
[0314] It is understandable that Figure 15 What is shown in the figure are only some software modules in the electronic device and should not limit the software architecture of the electronic device.
[0315] The user management module 1507 of the first electronic device in the device group may receive the unlock password set by the user.
[0316] In response to the user's unlocking operation, the local lock screen / unlock module 1501 in the first electronic device unlocks the first electronic device.
[0317] The lock screen state of the first electronic device changes from the locked state to the unlocked state, and the local lock screen / unlock module 1501 notifies the group lock screen event receiving module 1502A in the lock screen state synchronization / receiving module 1502 that the lock screen state of the first electronic device changes to the unlocked state.
[0318] After receiving the information that the lock screen state of the first electronic device is changed to the unlocked state, the intra-group lock screen event receiving module 1502A sends the information to the intra-group lock screen event synchronization module 1502B in the lock screen state synchronization / receiving module 1502.
[0319] After receiving the information, the intra-group lock screen event synchronization module 1502B can send the information that the lock screen state of the first electronic device is changed to the unlocked state to other electronic devices in the device group through the communication and networking management module 1504.
[0320] In some embodiments, the intra-group lock screen event receiving module 1502A may send information that the lock screen state of the first electronic device is changed to the unlocked state to the intra-group lock screen state storage module 1503A in the virtual terminal lock state management module 1503 .
[0321] In some embodiments, when the local lock screen / unlock module 1501 notifies the in-group lock screen event receiving module 1502A that the lock screen state of the first electronic device has changed to the unlocked state, the information that the lock screen state of the first electronic device has changed to the unlocked state can be directly sent to the in-group lock screen state storage module 1503A at the same time. It is not necessary for the in-group lock screen event receiving module 1502A to send the change information of the lock screen state of the electronic device to the in-group lock screen state storage module 1503A. The in-group lock screen event receiving module 1502A can only send the change information of the lock screen state of other electronic devices in the group to the in-group lock screen state storage module 1503A, which is not limited here.
[0322] After receiving the information that the lock screen state of the first electronic device has changed to the unlocked state, the in-group lock screen state storage module 1503A can update the stored in-group device lock screen information. After the lock screen state of an electronic device in the in-group device lock screen information stored in the in-group lock screen state storage module 1503A has been reversed, the virtual terminal lock state determination module 1503B in the virtual terminal lock state management module 1503 can be triggered.
[0323] Then, the virtual terminal lock status judgment module 1503B can determine whether the lock screen status of the virtual terminal is changed to the unlocked state based on the lock screen status of all electronic devices in the device lock screen information in the group at this time, and the virtual terminal lock screen status judgment policy stored in the policy management module 1503C in the virtual terminal lock status management module 1503.
[0324] After the virtual terminal lock state determination module 1503B updates the lock screen state of the virtual terminal from the locked state to the unlocked state, it can trigger the group key management module 1505 to load the key of the first data into the kernel file system 1506 .
[0325] After receiving the key for the first data loaded by the group key management module 1505 , the kernel file system 1506 may decrypt the first data in the user file system of the first electronic device, making the first data in the first electronic device available.
[0326] It can be understood that after the kernel file system 1506 decrypts the first data, the data can be sent to other electronic devices in the device group through the communication and networking management module 1504; the first electronic device can also obtain data from other electronic devices in the device group to the kernel file system 1506 through the communication and networking management module 1504, which is not limited here.
[0327] The data protection method in the embodiment of the present application is described below in conjunction with the software and hardware architecture of the electronic device 100.
[0328] The data protection method in the embodiment of the present application includes three stages. The first stage is the stage of forming a device group, the second stage is the stage of lock screen status update synchronization, and the third stage is the stage of virtual terminal status linkage key.
[0329] Phase 1: Establishing a device group. In this phase, one or more electronic devices are connected via a network to form a device group. The group can be considered a virtual terminal, and the electronic devices in the device group can form a distributed collaborative scenario. The electronic devices in the device group can be protected using the data protection method in the embodiments of this application.
[0330] There are many ways to form a device group with multiple devices. Please refer to the description of (2) device group in the above term introduction, and will not be repeated here.
[0331] The second stage is the lock screen status update synchronization stage. This stage is the process in which the electronic devices in the device group update the lock screen information stored in the local device based on the local device and other electronic devices in the device group.
[0332] In some embodiments, the operation of updating the lock screen information of devices in the group in the electronic device can be triggered by the unlocking / locking action of the electronic device.
[0333] In other embodiments, the operation of updating the lock screen information of devices in the group in the electronic device can be triggered by the online / offline action of the electronic device.
[0334] The third stage: the lock screen status linkage class key management stage. In this stage, the electronic device manages the class key of the first data in a linkage manner according to the lock screen status of all online electronic devices in the group recorded in the lock screen information of the group devices.
[0335] In the third stage, if the lock screen status of all online electronic devices in the device group is locked, the class key of the first data is discarded and the first data is unavailable. If the lock screen status of any electronic device among all online electronic devices in the device group is unlocked, the class key of the first data is loaded and the first data is available.
[0336] The following describes in detail the three stages of implementing the data protection method in this application, taking different specific scenarios as examples:
[0337] (1) Establishing device groups:
[0338] Application scenario 1: There is no device group at the beginning, and a new device group is created with one or more electronic devices.
[0339] Figure 16 This is a signaling interaction diagram of the data protection method in an embodiment of the present application.
[0340] like Figure 16 As shown, the first electronic device and the second electronic device establish a device group via a network connection. This process may include steps S1601 to S1603.
[0341] S1601: The first electronic device responds to a user operation and logs into a first network account;
[0342] S1602: The second electronic device responds to the user operation and logs into the first network account;
[0343] S1603: The first electronic device and the second electronic device establish a device group;
[0344] After the first electronic device and the second electronic device log in to the same network account, the first electronic device and the second electronic device perform authentication.
[0345] After the authentication is completed, the first electronic device and the second electronic device establish a device group. When the devices in the device group communicate with each other, a communication session link is established to ensure session security.
[0346] It is understandable that there is no particular order in which S1601 and S1602 may be performed simultaneously, and this is not limited here.
[0347] Application scenario 2: Initially, there is an existing device group, and other electronic devices join the device group through a network connection.
[0348] Figure 17 This is another signaling interaction diagram of the data protection method in an embodiment of the present application.
[0349] like Figure 17 As shown, the third electronic device establishes a group relationship with the first electronic device and the second electronic device through a network connection. The process includes steps S1701 to S1703.
[0350] S1701: The first electronic device and the second electronic device establish a device group;
[0351] The process of establishing a device group between the first electronic device and the second electronic device can refer to Figure 11 The description of the figure will not be repeated here.
[0352] S1702: The third electronic device responds to the user's operation and logs into the first network account;
[0353] The first network account is the same as the first network account of the first electronic device and the second electronic device.
[0354] S1703: A third electronic device joins the device group.
[0355] After the third electronic device logs into the same network account as the first electronic device and the second electronic device, it can authenticate with the first electronic device and the second electronic device respectively.
[0356] After completing the authentication, the first electronic device, the second electronic device, and the third electronic device establish a device group. When the devices in the device group communicate with each other, a communication session link is established to ensure session security.
[0357] It is understandable that the process of an electronic device joining a device group may also be referred to as the electronic device going online.
[0358] Application scenario 3: There is an existing device group, and other electronic devices exit the device group by disconnecting from the network.
[0359] Figure 18 This is another signaling interaction diagram of the data protection method in an embodiment of the present application.
[0360] like Figure 18 As shown, the second electronic device exits the original device group by logging out of the first network account. The process includes steps S1801 to S1803.
[0361] S1801: A first electronic device, a second electronic device, and a third electronic device form a device group;
[0362] The first electronic device, the second electronic device, and the third electronic device form a device group. Figure 12 The description of the figure will not be repeated here.
[0363] S1802: The third electronic device responds to the user operation and logs out of the first network account;
[0364] In some implementations, the electronic device may also exit the device group by disconnecting from the network, which is not limited here.
[0365] The first network account is the same as the first network account of the first electronic device and the second electronic device.
[0366] S1803: The first electronic device and the second electronic device form a device group.
[0367] In some embodiments, when the second electronic device exits the device group, it may send an offline notification to the first electronic device and the third electronic device, which is not limited here.
[0368] In the above three application scenarios, electronic devices are grouped together by logging into the same network account. In some embodiments, other ways of forming device groups may also be adopted, which are not limited here.
[0369] It is understandable that the process of an electronic device exiting a device group may also be referred to as the electronic device going offline.
[0370] Optionally, in some embodiments, the plurality of electronic devices constituting the device group may be considered as a virtual terminal as a whole.
[0371] (2) Lock screen status update synchronization phase:
[0372] Application scenario 1: Locking the screen of an electronic device causes synchronization of the lock screen status.
[0373] For example, a device group includes a first electronic device and a second electronic device, both of which are in a locked state. At this time, the first electronic device is unlocked and synchronizes its lock screen state to the second electronic device.
[0374] Figure 19 This is another signaling interaction diagram of the data protection method in an embodiment of the present application.
[0375] The lock screen status update and synchronization process is as follows Figure 19 As shown, the process includes steps S1901 to S1904. Figure 20 The two-machine interaction information flow diagram shown in FIG. 1 specifically describes steps S1901 to S1904.
[0376] S1901: The first electronic device responds to a user operation and unlocks.
[0377] The local lock screen / unlock module 1501 of the first electronic device unlocks the first electronic device in response to the user's unlocking operation.
[0378] S1902: After the first electronic device is unlocked, the lock screen status of the device in the group is updated to unlocked.
[0379] like Figure 20 As shown, after the first electronic device is unlocked, the lock screen / unlock module 1501 of the first electronic device can notify the intra-group lock screen event receiving module 1502A in the lock screen state synchronization / receiving module 1502 that the lock screen state of the first electronic device has changed to the unlocked state. After the intra-group lock screen event receiving module 1502A receives the information that the lock screen state of the first electronic device has changed to the unlocked state, it can update the lock screen state of the first electronic device to the unlocked state in the intra-group device lock screen information stored in the intra-group lock screen state storage module 1503A in the virtual terminal lock state management module 1503.
[0380] For example, in one implementation, if the Mobile Equipment Identifier (MEID) is used as the unique identifier of an electronic device in the group device lock screen information to record the corresponding relationship with the lock screen status of the electronic device, assuming that the locked state of the electronic device is identified by binary code 1 and the unlocked state is identified by binary code 0, and the MEID of the first electronic device is A00000B42381FD. Then, after the first electronic device enters the unlocked state, the first electronic device can update the entry recording the lock screen status of the first electronic device in the group lock screen information to [A00000B42381FD, 0].
[0381] S1903: The first electronic device notifies the second electronic device that it has been unlocked.
[0382] like Figure 20 As shown, after the lock screen event receiving module 1502A of the first electronic device receives the information that the lock screen state of the first electronic device has changed to the unlocked state, it can also send the information that the lock screen state of the first electronic device has changed to the unlocked state to the intra-group lock screen event synchronization module 1502B in the lock screen state synchronization / receiving module 1502. After receiving the information, the intra-group lock screen event synchronization module 1502B can pass the information that the lock screen state of the first electronic device has changed to the unlocked state to the communication and networking management module 1504 of the first electronic device. The communication and networking management module 1504 can send the information to the communication and networking management module 1904 of the second electronic device. As a result, the second electronic device receives the information sent by the first electronic device that the device has been unlocked.
[0383] S1904: The second electronic device updates the lock screen status of the first electronic device in the device lock screen information to an unlocked state;
[0384] like Figure 20 As shown, in the second electronic device, the communication and networking management module 1504 can send the information that the lock screen state of the first electronic device is changed to the unlocked state to the intra-group lock screen event synchronization module 1902B in the lock screen state synchronization / receiving module 1902 of the second electronic device. The intra-group lock screen event synchronization module 1902B can send the information to the intra-group lock screen event receiving module 1902A, and the intra-group lock screen event receiving module 1902A will then update and store the information that the lock screen state of the first electronic device is changed to the unlocked state in the intra-group lock screen state storage module 1903A in the second electronic device.
[0385] It can be understood that the storage method of the lock screen information of the device in the group of the second electronic device, the correspondence between the unique identifier of the electronic device and the lock screen status of the electronic device are not affected by the first electronic device, and can be the same as the first electronic device or different, and is not limited here.
[0386] For example, in one implementation, if the second electronic device also uses the MEID as the unique identifier of the electronic device in the in-group device lock screen information, the locked state is identified by a binary code 1, and the unlocked state is identified by a binary code 0. Then, after the in-group lock screen state storage module 1903A receives the information that the lock screen state of the first electronic device has changed to the unlocked state, the entry recording the lock screen state of the first electronic device in the in-group device lock screen information can be updated in the in-group lock screen state storage module 1903A to [A00000B42381FD, 0].
[0387] Application scenario 2: Unlocking an electronic device causes synchronization of the lock screen state.
[0388] For example, a device group includes a first electronic device and a second electronic device, the first electronic device is unlocked, and the second electronic device is locked. At this time, the first electronic device locks its screen, and the first and second electronic devices update the lock screen information of the devices in the group, indicating that the lock screen status of the first electronic device is locked.
[0389] Figure 21 This is another signaling interaction diagram of the data protection method in an embodiment of the present application.
[0390] S2101: The first electronic device locks the screen in response to a user operation;
[0391] S2102: After the first electronic device locks its screen, the lock screen status of the device in the group is updated to the locked state;
[0392] S2103: The first electronic device notifies the second electronic device that the screen is locked.
[0393] S2104: The second electronic device updates the lock screen status of the first electronic device in the lock screen information of the devices in the group to a locked state.
[0394] It is understandable that during the execution of steps S2101 to S2104, the information flow between the modules in the first electronic device and the second electronic device is the same as that in FIG. Figure 20 The information flow shown is similar, see Figure 20 The description is that the information transmitted between modules is changed from the information that the lock screen state of the first electronic device is changed to the unlocked state to the information that the lock screen state of the first electronic device is changed to the locked state, which will not be repeated here.
[0395] For example, in one implementation, if the second electronic device and the second electronic device also use the MEID as the unique identifier of the electronic device in the intra-group device lock screen information, the locked state is identified by the binary code 1, and the unlocked state is identified by the binary code 0. Then, after the intra-group lock screen state storage module 1503A of the first electronic device or the intra-group lock screen state storage module 1903A of the second electronic device receives the information that the lock screen state of the first electronic device has been changed to the locked state, the entry recording the lock screen state of the first electronic device in the intra-group device lock screen information can be updated to [A00000B42381FD, 1].
[0396] Application scenario 3: The electronic device goes online, causing the lock screen state to be synchronized.
[0397] For example, a device group includes a first electronic device and a second electronic device. A third electronic device comes online and joins the device group. The first and second electronic devices add an entry to the group's device lock screen information recording the third electronic device's lock screen status. The third electronic device adds an entry to the group's device lock screen information recording the first and second electronic devices' lock screen status.
[0398] Figure 22 This is another signaling interaction diagram of the data protection method in an embodiment of the present application.
[0399] The lock screen status update and synchronization process is as follows Figure 22 As shown, the process includes steps S2201 to S2206. Figure 23 The two-machine interaction information flow diagram shown in FIG. 1 specifically describes steps S2201 to S2206.
[0400] It is understandable that Figure 22 and Figure 23 Only the information flow between the first electronic device and the third electronic device is shown. Similar information flow may also exist between the second electronic device and the third electronic device, which is not limited here.
[0401] S2201: A third electronic device joins a device group consisting of a first electronic device and a second electronic device.
[0402] like Figure 23 As shown, when a third electronic device joins a device group consisting of a first electronic device and a second electronic device, the communication and networking management module 1504 of the first electronic device may determine that the third electronic device in the device group is online.
[0403] Specifically, the manner in which the first electronic device determines whether the third electronic device goes online can be referred to the description of the online action and offline action of the electronic device in the above term introduction, which will not be repeated here.
[0404] S2202: The first electronic device adds an initialization entry of the lock screen status of the third electronic device to the lock screen information of the devices in the group;
[0405] like Figure 23 As shown, after the communication and networking management module 1504 of the first electronic device determines that the third electronic device is online, it can notify the intra-group lock screen event receiving module 1502A of the third electronic device's online status through the intra-group lock screen event synchronization module 1502B. The intra-group lock screen event receiving module 1502A can add an initialization entry recording the lock screen status of the third electronic device to the intra-group device lock screen information stored in the intra-group lock screen status storage module 1503A.
[0406] In some embodiments, the lock screen state in the initialization entry of the lock screen state of the electronic device is a locked state.
[0407] For example, as shown in Table 2 below, it is an illustrative example of the lock screen information of the devices in the group in the first electronic device when the third electronic device is offline:
[0408] Electronic equipment identification Lock screen status Identification of the first electronic device Locked state Identification of the second electronic device Unlocked
[0409] Table 2
[0410] For example, as shown in Table 3 below, after the third electronic device comes online, the first electronic device adds an initialization entry recording the lock screen status of the third electronic device to the lock screen information of the devices in the group:
[0411] Electronic equipment identification Lock screen status Identification of the first electronic device Locked state Identification of the second electronic device Unlocked Identification of third electronic device Locked state
[0412] Table 3
[0413] S2203: The third electronic device adds the initialization entries of the lock screen states of the first electronic device and the second electronic device to the lock screen information of the devices in the group;
[0414] like Figure 23 As shown, after the third electronic device joins the device group consisting of the first electronic device and the second electronic device through the communication and networking management module 2304, the lock screen event synchronization module 2302B in the lock screen status synchronization / receiving module 2302 of the third electronic device can notify the in-group lock screen event receiving module 2302A that the first electronic device and the second electronic device are online in the device group. The in-group lock screen event receiving module 2302A can add an initialization entry recording the lock screen status of the first electronic device and the second electronic device to the in-group device lock screen information stored in the in-group lock screen status storage module 2302A of the third electronic device.
[0415] For example, as shown in Table 4 below, it is an illustrative example of the lock screen information of the devices in the group in the third electronic device when the third electronic device is not online:
[0416] Electronic equipment identification Lock screen status Identification of third electronic device Unlocked
[0417] Table 4
[0418] For example, as shown in Table 5 below, after the third electronic device goes online, the third electronic device adds an initialization entry recording the lock screen status of the first electronic device and the second electronic device to the lock screen information of the devices in the group:
[0419] Electronic equipment identification Lock screen status Identification of third electronic device Unlocked Identification of the first electronic device Locked state Identification of the second electronic device Locked state
[0420] Table 5
[0421] S2204, synchronizing lock screen status among electronic devices in the device group;
[0422] The electronic devices in the device group can synchronize the current lock screen status of each electronic device through the communication and networking management module, the intra-group lock screen time synchronization module and the intra-group lock screen event receiving module.
[0423] S2205: The first electronic device updates the lock screen status of the third electronic device in the lock screen information of the devices in the group;
[0424] S2206: The third electronic device records the lock screen status of the first electronic device and the second electronic device in the lock screen information of the devices in the group.
[0425] The intra-group lock screen event receiving module of each electronic device in the device group can update the current lock screen status of each electronic device to the intra-group device lock screen information stored in the intra-group lock screen status storage module of each electronic device.
[0426] The specific process of synchronizing the lock screen status between device groups in S2204 to S2206 can be found in the description of the above steps S1901 to S1904 and S2101 to S2104, and will not be repeated here.
[0427] For example, if the first electronic device is in a locked state, the second electronic device is in an unlocked state, and the third electronic device is in an unlocked state, the following Table 6 shows an illustrative example of the lock screen information of the first electronic device, the second electronic device, and the third electronic device in the group after executing steps S2204 to S2206:
[0428] Electronic equipment identification Lock screen status Identification of the first electronic device Locked state Identification of the second electronic device Unlocked Identification of third electronic device Unlocked
[0429] Table 6
[0430] Application scenario 4: The electronic device goes offline, causing the lock screen state to be synchronized.
[0431] For example, a device group includes a first electronic device, a second electronic device, and a third electronic device. When the third electronic device goes offline, the first electronic device and the second electronic device delete the entry recording the lock screen status of the third electronic device in their group device lock screen information.
[0432] Figure 24 This is another signaling interaction diagram of the data protection method in an embodiment of the present application;
[0433] The lock screen status update and synchronization process is as follows Figure 24 As shown, the process includes steps S2401 to S2403. Figure 23 The two-machine interaction information flow diagram shown in FIG. 1 specifically describes steps S2401 to S2403.
[0434] It is understandable that Figure 24 Only the information flow between the first electronic device and the third electronic device is shown. Similar information flow may also exist between the second electronic device and the third electronic device, which is not limited here.
[0435] S2401: The third electronic device exits the device group;
[0436] When the third electronic device exits the device group, the communication and networking management module 1504 of the first electronic device may determine that the third electronic device is offline.
[0437] S2402: The first electronic device deletes the entry recording the lock screen status of the third electronic device from the lock screen information of the devices in the group;
[0438] like Figure 23 As shown, after the communication and networking management module 1504 of the first electronic device determines that the third electronic device is online, it can notify the group lock screen event receiving module 1502A through the group lock screen event synchronization module 1502B that the third electronic device is offline. The group lock screen event receiving module 1502A can delete the entry recording the lock screen status of the third electronic device from the group device lock screen information stored in the group lock screen status storage module 1503A.
[0439] For example, Table 6 above is an illustrative example of the lock screen information of the group devices in the first electronic device when the third electronic device is not offline. Table 7 below is an illustrative example of the first electronic device deleting the entry recording the lock screen status of the third electronic device in the lock screen information of the group devices after the third electronic device goes offline:
[0440] Electronic equipment identification Lock screen status Identification of the first electronic device Locked state Identification of the second electronic device Unlocked
[0441] Table 7
[0442] S2403: The second electronic device deletes the entry recording the lock screen status of the first electronic device and the second electronic device from the lock screen information of devices in the group.
[0443] like Figure 23 As shown, after the third electronic device goes offline, the lock screen event synchronization module 2302B in the lock screen status synchronization / receiving module 2302 of the third electronic device can notify the group lock screen event receiving module 2302A that the device has gone offline. The group lock screen event receiving module 2302A can delete the entries of all electronic devices except the device from the group lock screen information stored in the group lock screen status storage module 2302A of the third electronic device.
[0444] Table 6 above is an illustrative example of the group device lock screen information in the first electronic device when the third electronic device is not offline. Table 8 below is an illustrative example of the third electronic device deleting the entries recording the lock screen status of the first and second electronic devices in the group device lock screen information after the third electronic device goes offline:
[0445] Electronic equipment identification Lock screen status Identification of third electronic device Unlocked
[0446] Table 8
[0447] (3) Lock screen state linkage key management stage:
[0448] Application scenario 1: When all electronic devices in the group's device lock screen information are in locked state, the class key loading is caused by the lock screen state of one electronic device being flipped to unlocked.
[0449] For example, in a device group consisting of a first electronic device and a second electronic device, the lock screen status of all electronic devices in the device lock screen information of the first electronic device and the second electronic device is locked. At this time, the lock screen status of the first electronic device is flipped to unlocked, causing the first and second electronic devices to load the class key, decrypt the first data in the first and second electronic devices, and make the first data available.
[0450] Figure 25 This is a flow chart of the data protection method in an embodiment of the present application.
[0451] The lock screen state linkage key management process is as follows Figure 25 As shown, the process includes steps S2501 to S2503. Figure 15 The information flow diagram shown in FIG. 1 specifically describes steps S2501 to S2503.
[0452] It is understandable that each electronic device in the device group can perform the following steps:
[0453] S2501: When the lock screen status of all electronic devices in the device lock screen information within the group is locked, update the lock screen status of the first electronic device to unlocked;
[0454] The process of the first electronic device and the second electronic device updating the lock screen information of the devices in the group so that the lock screen status of the first electronic device is unlocked can be referred to the description in the above (2) lock screen status update synchronization stage, which will not be repeated here.
[0455] S2502: Determine whether the lock screen status of an electronic device in the lock screen information of the device in the group is unlocked;
[0456] like Figure 15As shown, the virtual terminal lock status determination module 1503B in the first electronic device can monitor the reversal of the lock screen status of each electronic device in the group device lock screen information stored in the group lock screen status storage module 1503A, or when the lock screen status of an electronic device is reversed in the group device lock screen information, the group lock screen status storage module 1503A can notify the virtual terminal lock status determination module 1503B.
[0457] It can be understood that flipping the lock screen state of an electronic device means that the lock screen state of the electronic device is changed from a locked state to an unlocked state, or from an unlocked state to a locked state.
[0458] In some embodiments, when it is determined that the lock screen state of an electronic device has been flipped, the virtual terminal lock state determination module 1503B can be triggered to determine whether the lock screen state of any electronic device in the group device lock screen information is unlocked. When it is determined that the lock screen state of any electronic device is unlocked, step S2503 can be executed.
[0459] For example, when the lock screen state of the first electronic device is updated to unlocked state, the virtual terminal lock state determination module 1503B can determine that the lock screen state of an electronic device in the group device lock screen information is unlocked, and step S2503 can be executed.
[0460] In some embodiments, when it is determined that the lock screen state of an electronic device has been flipped, the virtual terminal lock state determination module 1503B can be triggered to determine the lock screen state of the virtual terminal in combination with the virtual terminal lock screen state determination policy stored in the policy management module 1503C. When it is determined that the lock screen state of the virtual terminal is unlocked, step S2503 can be executed.
[0461] For example, the virtual terminal lock screen status determination policy stored in the policy management module 1503C is that when the lock screen status of all electronic devices in the device group is locked, the virtual terminal is locked; when the lock screen status of any electronic device is unlocked, the virtual terminal is unlocked. If it is determined that the lock screen status of an electronic device in the group is unlocked in the lock screen information, the virtual terminal lock status determination module 1503B can determine that the lock screen status of the virtual terminal is unlocked and can execute step S2503.
[0462] In some embodiments, in addition to the lock screen status of an electronic device being flipped in the lock screen information of the devices in the group, an electronic device going online or offline in the device group can also trigger the virtual terminal lock status determination module 1503B to re-determine the lock screen status of the virtual terminal, which is not limited here.
[0463] It is understandable that in some embodiments, the strategy for determining the lock screen status of the virtual terminal may also be other strategies. For example, when more than a preset percentage of electronic devices are in a locked state, the virtual terminal is in a locked state; when less than a preset percentage of electronic devices are in a locked state, the virtual terminal is in an unlocked state, etc., which is not limited here.
[0464] It is understandable that the second electronic device may have a similar information flow, which is not limited here.
[0465] S2503: Load the class key and decrypt the first data of the local machine.
[0466] like Figure 15 As shown, when the virtual terminal lock status determination module 1503B determines that the lock screen state of an electronic device is unlocked, or the lock screen state of the virtual terminal is unlocked, it can trigger the group class key management module 1505 to load the class key of the first data into the kernel file system 1506. After the class key is loaded into the kernel file system 1506, the first data can be decrypted, making the first data available. In this way, even if the device is locked, the first data can be accessed by other electronic devices in the device group.
[0467] It is understandable that the second electronic device may have a similar information flow, which is not limited here.
[0468] Application scenario 2: When the lock screen status of one electronic device in the group device lock screen information is flipped to the locked state, causing all electronic devices to be locked, the class key is discarded.
[0469] For example, in a device group consisting of a first electronic device and a second electronic device, in the device lock screen information within the group, the lock screen status of the first electronic device is unlocked, and the lock screen status of the second electronic device is locked. At this time, the lock screen status of the first electronic device is flipped to locked, causing the first and second electronic devices to discard the class key, encrypting the first data in the first and second electronic devices, making the first data unavailable.
[0470] Figure 26 This is another flowchart of the data protection method implemented in this application;
[0471] The lock screen state linkage key management process is as follows Figure 26 As shown, the process includes steps S2601 to S2603. Figure 15 The information flow diagram shown in FIG. 1 specifically describes steps S2601 to S2603.
[0472] It is understandable that each electronic device in the device group can perform the following steps:
[0473] S2601: Update the lock screen status of the first electronic device in the lock screen information of the devices in the group to the locked state, so that the lock screen status of all electronic devices is the locked state;
[0474] The process of the first electronic device and the second electronic device updating the lock screen information of the devices in the group so that the lock screen status of the first electronic device is locked can be referred to the description in the above (2) lock screen status update synchronization stage, which will not be repeated here.
[0475] S2602: Determine that the lock screen status of all electronic devices in the device lock screen information within the group is locked;
[0476] like Figure 15 As shown, the virtual terminal lock status determination module 1503B in the first electronic device can monitor the reversal of the lock screen status of each electronic device in the group device lock screen information stored in the group lock screen status storage module 1503A, or when the lock screen status of an electronic device is reversed in the group device lock screen information, the group lock screen status storage module 1503A can notify the virtual terminal lock status determination module 1503B.
[0477] It can be understood that flipping the lock screen state of an electronic device means that the lock screen state of the electronic device is changed from a locked state to an unlocked state, or from an unlocked state to a locked state.
[0478] In some embodiments, when it is determined that the lock screen status of an electronic device has been flipped, the virtual terminal lock status determination module 1503B may be triggered to determine whether the lock screen status of any electronic device in the group device lock screen information is unlocked. If it is determined that the lock screen status of no electronic device is unlocked, that is, the lock screen status of all electronic devices in the group device lock screen information is locked, step S2603 may be executed.
[0479] For example, when the lock screen status of the first electronic device is updated to the locked state, the virtual terminal lock state determination module 1503B can determine that the lock screen status of all electronic devices in the device lock screen information in the group are locked, and step S2603 can be executed.
[0480] In some embodiments, when it is determined that the lock screen state of an electronic device has been flipped, the virtual terminal lock state determination module 1503B may be triggered to determine the lock screen state of the virtual terminal in combination with the virtual terminal lock screen state determination policy stored in the policy management module 1503C. When it is determined that the lock screen state of the virtual terminal is unlocked, step S2603 may be executed.
[0481] For example, the virtual terminal lock screen status determination policy stored in the policy management module 1503C is that when the lock screen status of all electronic devices in the device group is locked, the virtual terminal is locked; when the lock screen status of any electronic device is unlocked, the virtual terminal is unlocked. If it is determined that no electronic device in the group lock screen information has an unlocked lock screen, the virtual terminal lock status determination module 1503B can determine that the lock screen status of the virtual terminal is locked and can execute step S2603.
[0482] In some embodiments, in addition to the lock screen status of an electronic device being flipped in the lock screen information of the devices in the group, an electronic device going online or offline in the device group can also trigger the virtual terminal lock status determination module 1503B to re-determine the lock screen status of the virtual terminal, which is not limited here.
[0483] It is understandable that in some embodiments, the strategy for determining the lock screen status of the virtual terminal may also be other strategies. For example, when more than a preset percentage of electronic devices are in a locked state, the virtual terminal is in a locked state; when less than a preset percentage of electronic devices are in a locked state, the virtual terminal is in an unlocked state, etc., which is not limited here.
[0484] It is understandable that the second electronic device may have a similar information flow, which is not limited here.
[0485] S2603. Discard the class key and encrypt the first data of the local machine.
[0486] like Figure 15 As shown, when the virtual terminal lock status determination module 1503B determines that no electronic device's lock screen is unlocked, or the virtual terminal's lock screen is locked, it can trigger the group class key management module 1505 to instruct the kernel file system 1506 to use the class key for the first data. After the kernel file system 1506 discards the class key, it can restore the encryption of the first data, making the first data unavailable. In this way, the first data can no longer be accessed by other electronic devices in the device group.
[0487] It is understandable that the second electronic device may have a similar information flow, which is not limited here.
[0488] It should be noted that, although only two or three electronic devices form a device group in the above examples, in actual applications, more electronic devices may form a device group, which is not limited here.
[0489] It can be understood that, based on the scenario examples, some steps in the above embodiments are performed by the first electronic device, some steps are performed by the second electronic device, and some steps are performed by the third electronic device, but each electronic device that makes up the device group has the ability to perform all the above steps, which is not limited here.
[0490] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
[0491] As used in the above embodiments, the term “when…” may be interpreted to mean “if…” or “after…” or “in response to determining…” or “in response to detecting…”, depending on the context. Similarly, the phrases “upon determining…” or “if (stated condition or event) is detected” may be interpreted to mean “if determining…” or “in response to determining…” or “upon detecting (stated condition or event)” or “in response to detecting (stated condition or event)”, depending on the context.
[0492] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk).
[0493] Those skilled in the art will appreciate that all or part of the process steps in the above-described method embodiments can be implemented by a computer program instructing the relevant hardware. The program can be stored in a computer-readable storage medium, and when executed, the program can include the process steps in the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A data protection method, characterized in that: include: When it is determined that the lock screen states of all electronic devices in the device group are locked, the first electronic device sets first data to be unavailable, where the first data is protected data in the first electronic device; the device group includes a plurality of electronic devices, the plurality of electronic devices are connected to each other via a network to form a trusted communication network, and the plurality of electronic devices include the first electronic device; When it is determined that the lock screen state of any electronic device in the device group is unlocked, the first electronic device sets the first data to be available.
2. The method according to claim 1, characterized in that The method further comprises: When the first electronic device determines that the lock screen states of all electronic devices recorded in the in-group device lock screen information of the first electronic device are all locked, the first electronic device determines that the lock screen states of all electronic devices in the device group are all locked; the in-group device lock screen information records the correspondence between the identifiers of the electronic devices in the device group and the lock screen states; When the first electronic device determines that the lock screen state of any electronic device recorded in the device lock screen information in the group is unlocked, the first electronic device determines that the lock screen state of any electronic device in the device group is unlocked.
3. The method according to claim 1, characterized in that When it is determined that the lock screen states of all electronic devices in the device group are locked, the first electronic device setting the first data to be unavailable specifically includes: When it is determined that the lock screen state of the virtual terminal is locked, the first electronic device sets the first data to be unavailable; the lock screen state of the virtual terminal is determined according to the lock screen states of all electronic devices in the device group; When it is determined that the lock screen state of any electronic device in the device group is unlocked, the first electronic device setting the first data to be available specifically includes: When it is determined that the lock screen state of the virtual terminal is the unlocked state, the first electronic device sets the first data to be available.
4. The method according to claim 2, characterized in that When it is determined that the lock screen states of all electronic devices in the device group are locked, the first electronic device setting the first data to be unavailable specifically includes: When it is determined that the lock screen state of the virtual terminal is locked, the first electronic device sets the first data to be unavailable; the lock screen state of the virtual terminal is determined according to the lock screen states of all electronic devices in the device group; When it is determined that the lock screen state of any electronic device in the device group is unlocked, the first electronic device setting the first data to be available specifically includes: When it is determined that the lock screen state of the virtual terminal is the unlocked state, the first electronic device sets the first data to be available.
5. The method according to claim 3, characterized in that The method further comprises: When the first electronic device determines that the lock screen states of all electronic devices recorded in the lock screen information of the devices in the group are locked, the first electronic device determines that the lock screen state of the virtual terminal is locked; When the first electronic device determines that the lock screen state of any electronic device recorded in the lock screen information of devices in the group is unlocked, the first electronic device determines that the lock screen state of the virtual terminal is unlocked.
6. The method according to claim 4, characterized in that The method further comprises: When the first electronic device determines that the lock screen states of all electronic devices recorded in the lock screen information of the devices in the group are locked, the first electronic device determines that the lock screen state of the virtual terminal is locked; When the first electronic device determines that the lock screen state of any electronic device recorded in the lock screen information of devices in the group is unlocked, the first electronic device determines that the lock screen state of the virtual terminal is unlocked.
7. The method according to claim 2, characterized in that The method further comprises: When the lock screen state of the first electronic device is locked, in response to an unlocking operation by the user, the first electronic device updates the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group to unlocked; The first electronic device sends information that the locked screen state of the first electronic device is updated to the unlocked state to a second electronic device, where the second electronic device is any electronic device in the device group that is different from the first electronic device.
8. The method according to claim 4, characterized in that The method further comprises: When the lock screen state of the first electronic device is locked, in response to an unlocking operation by the user, the first electronic device updates the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group to unlocked; The first electronic device sends information that the locked screen state of the first electronic device is updated to the unlocked state to a second electronic device, where the second electronic device is any electronic device in the device group that is different from the first electronic device.
9. The method according to claim 6, characterized in that The method further comprises: When the lock screen state of the first electronic device is locked, in response to an unlocking operation by the user, the first electronic device updates the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group to unlocked; The first electronic device sends information that the locked screen state of the first electronic device is updated to the unlocked state to a second electronic device, where the second electronic device is any electronic device in the device group that is different from the first electronic device.
10. The method according to claim 2, characterized in that The method further comprises: When the lock screen state of the first electronic device is unlocked, in response to a lock screen operation by the user, the first electronic device updates the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group to a locked state; The first electronic device sends information that the lock screen state of the first electronic device is updated to a locked state to the second electronic device.
11. The method according to claim 4, characterized in that The method further comprises: When the lock screen state of the first electronic device is unlocked, in response to a lock screen operation by the user, the first electronic device updates the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group to a locked state; The first electronic device sends information that updates the lock screen state of the first electronic device to a locked state to the second electronic device.
12. The method according to claim 6, characterized in that The method further comprises: When the lock screen state of the first electronic device is unlocked, in response to a lock screen operation by the user, the first electronic device updates the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group to a locked state; The first electronic device sends information that updates the lock screen state of the first electronic device to a locked state to the second electronic device.
13. The method according to claim 7, characterized in that The method further comprises: When the lock screen state of the first electronic device is unlocked, in response to a lock screen operation by the user, the first electronic device updates the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group to a locked state; The first electronic device sends information that updates the lock screen state of the first electronic device to a locked state to the second electronic device.
14. The method according to claim 8, characterized in that The method further comprises: When the lock screen state of the first electronic device is unlocked, in response to a lock screen operation by the user, the first electronic device updates the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group to a locked state; The first electronic device sends information that updates the lock screen state of the first electronic device to a locked state to the second electronic device.
15. The method according to claim 9, characterized in that The method further comprises: When the lock screen state of the first electronic device is unlocked, in response to a lock screen operation by the user, the first electronic device updates the lock screen state of the first electronic device recorded in the lock screen information of the devices in the group to a locked state; The first electronic device sends information that updates the lock screen state of the first electronic device to a locked state to the second electronic device.
16. The method according to claim 2, characterized in that The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
17. The method according to claim 4, characterized in that The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
18. The method according to claim 6, characterized in that The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
19. The method according to claim 7, characterized in that The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
20. The method according to claim 8, characterized in that The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
21. The method according to claim 9, wherein The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
22. The method according to claim 10, wherein The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
23. The method according to claim 11, wherein The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
24. The method according to claim 12, wherein The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
25. The method according to claim 13, wherein The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
26. The method according to claim 14, wherein The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
27. The method according to claim 15, wherein The method further comprises: When the first electronic device receives information sent by a third electronic device indicating that the lock screen state of the third electronic device has been updated to an unlocked state, the first electronic device updates the lock screen state of the third electronic device to an unlocked state in the lock screen information of the devices in the group; the third electronic device is any electronic device in the device group that is different from the first electronic device; When the first electronic device receives information from the third electronic device that the lock screen status of the third electronic device is updated to the locked state, the first electronic device updates the lock screen status of the third electronic device to the locked state in the lock screen information of the devices in the group.
28. The method according to any one of claims 2, 4, 6 to 27, characterized in that The method further comprises: When the first electronic device determines that the fourth electronic device is connected to the device group, or when the first electronic device is connected to the device group where the fourth electronic device is located, the first electronic device adds an entry recording the lock screen status of the fourth electronic device in the device lock screen information within the group. The fourth electronic device is any electronic device in the device group that is different from the first electronic device.
29. The method according to claim 28, characterized in that The first electronic device adds an entry recording the lock screen status of the fourth electronic device to the lock screen information of the devices in the group, specifically including: The first electronic device adds an initialization entry recording the lock screen status of the fourth electronic device to the lock screen information of the devices in the group, and sets the lock screen status of the fourth electronic device to the locked state in the initialization entry.
30. The method according to claim 29, wherein After the step of adding, by the first electronic device, an initialization entry recording the lock screen state of the fourth electronic device to the in-group device lock screen information, the method further includes: The first electronic device receives information sent by the fourth electronic device indicating that the lock screen state of the fourth electronic device is unlocked; The first electronic device updates the lock screen state of the fourth electronic device in the lock screen information of the devices in the group to an unlocked state.
31. The method according to any one of claims 2, 4, 6 to 27, characterized in that The method further comprises: When the first electronic device determines that the fifth electronic device has exited the device group, the first electronic device deletes the entry recording the lock screen status of the fifth electronic device in the lock screen information of devices in the group. The fifth electronic device is any electronic device in the device group that is different from the first electronic device.
32. The method according to claim 28, wherein The method further comprises: When the first electronic device determines that the fifth electronic device has exited the device group, the first electronic device deletes the entry recording the lock screen status of the fifth electronic device in the lock screen information of devices in the group. The fifth electronic device is any electronic device in the device group that is different from the first electronic device.
33. The method according to claim 29, wherein The method further comprises: When the first electronic device determines that the fifth electronic device has exited the device group, the first electronic device deletes the entry recording the lock screen status of the fifth electronic device in the lock screen information of devices in the group. The fifth electronic device is any electronic device in the device group that is different from the first electronic device.
34. The method according to claim 30, wherein The method further comprises: When the first electronic device determines that the fifth electronic device has exited the device group, the first electronic device deletes the entry recording the lock screen status of the fifth electronic device in the lock screen information of devices in the group. The fifth electronic device is any electronic device in the device group that is different from the first electronic device.
35. The method according to any one of claims 2, 4, 6 to 27, characterized in that The method further comprises: When the first electronic device exits the device group, the first electronic device deletes all entries recording the lock screen status of other electronic devices in the device group from the lock screen information of devices in the group.
36. The method according to claim 28, wherein The method further comprises: When the first electronic device exits the device group, the first electronic device deletes all entries recording the lock screen status of other electronic devices in the device group from the lock screen information of devices in the group.
37. The method according to claim 29, wherein The method further comprises: When the first electronic device exits the device group, the first electronic device deletes all entries recording the lock screen status of other electronic devices in the device group from the lock screen information of devices in the group.
38. The method according to claim 30, wherein The method further comprises: When the first electronic device exits the device group, the first electronic device deletes all entries recording the lock screen status of other electronic devices in the device group from the lock screen information of devices in the group.
39. The method according to claim 31, wherein The method further comprises: When the first electronic device exits the device group, the first electronic device deletes all entries recording the lock screen status of other electronic devices in the device group from the lock screen information of devices in the group.
40. The method according to claim 32, wherein The method further comprises: When the first electronic device exits the device group, the first electronic device deletes all entries recording the lock screen status of other electronic devices in the device group from the lock screen information of devices in the group.
41. The method according to claim 33, wherein The method further comprises: When the first electronic device exits the device group, the first electronic device deletes all entries recording the lock screen status of other electronic devices in the device group from the lock screen information of devices in the group.
42. The method according to claim 34, wherein The method further comprises: When the first electronic device exits the device group, the first electronic device deletes all entries recording the lock screen status of other electronic devices in the device group from the lock screen information of devices in the group.
43. The method according to any one of claims 2, 4, 6 to 27, characterized in that The first electronic device setting the first data to be unavailable specifically includes: The first electronic device discards the class key and encrypts the first data, making the first data unusable; the class key is used to decrypt the first data; The first electronic device setting the first data to be available specifically includes: The first electronic device loads the class key and decrypts the first data to make the first data available.
44. The method according to claim 28, wherein The first electronic device setting the first data to be unavailable specifically includes: The first electronic device discards the class key and encrypts the first data, making the first data unusable; the class key is used to decrypt the first data; The first electronic device setting the first data to be available specifically includes: The first electronic device loads the class key and decrypts the first data to make the first data available.
45. The method according to claim 31, wherein The first electronic device setting the first data to be unavailable specifically includes: The first electronic device discards the class key and encrypts the first data, making the first data unusable; the class key is used to decrypt the first data; The first electronic device setting the first data to be available specifically includes: The first electronic device loads the class key and decrypts the first data to make the first data available.
46. The method according to claim 35, wherein The first electronic device setting the first data to be unavailable specifically includes: The first electronic device discards the class key and encrypts the first data, making the first data unusable; the class key is used to decrypt the first data; The first electronic device setting the first data to be available specifically includes: The first electronic device loads the class key and decrypts the first data to make the first data available.
47. The method according to claim 43, wherein The first electronic device setting the first data to be unavailable specifically includes: The first electronic device discards the class key and encrypts the first data, making the first data unusable; the class key is used to decrypt the first data; The first electronic device setting the first data to be available specifically includes: The first electronic device loads the class key and decrypts the first data to make the first data available.
48. The method according to any one of claims 29-30, 32-34, 36-42, characterized in that The first electronic device setting the first data to be unavailable specifically includes: The first electronic device discards the class key and encrypts the first data, making the first data unusable; the class key is used to decrypt the first data; The first electronic device setting the first data to be available specifically includes: The first electronic device loads the class key and decrypts the first data to make the first data available.
49. An electronic device, characterized in that The electronic device includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, and the computer program code is executed by the processor to implement the method according to any one of claims 1-48.
50. A chip system comprising one or more processors, wherein the processors implement the method according to any one of claims 1 to 48 when running computer program code.
51. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 48 is implemented.
52. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 48 is implemented.
Citation Information
Patent Citations
Data processing method, device and mobile terminal
CN105678171A
Auto-user registration and unlocking of a computing device
CN106233796A