Data processing method and device, equipment and storage medium
By acquiring user characteristic-related data and managing data protection keys using context-aware rules, the problem of dependence on screen lock mechanisms is solved, and a method to effectively protect data on devices without or without screen lock mechanisms is realized, improving the security and flexibility of data access.
Patent Information
- Application Number
- CN202011023716.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-25
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2040-09-25
AI Technical Summary
In existing technologies, ECE and SECE data protection methods rely on screen lock mechanisms, which cause file encryption to fail on devices that do not have or have not enabled screen lock mechanisms, thus failing to effectively protect data.
By acquiring object data related to user characteristics, context-aware rules are used to determine whether to delete or restore the key for data protection methods, avoiding reliance on screen lock mechanisms and ensuring that designated users can encrypt or decrypt files, while non-designated users cannot access them.
It enables effective data protection on devices without or without a screen lock mechanism, ensuring that designated users can access files while non-designated users cannot, thus improving the security and flexibility of data protection.
Smart Images

Figure CN114254334B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of terminals, and in particular to a data processing method and device, equipment and a storage medium. BACKGROUND
[0002] File-level encryption refers to that different files can be encrypted using different file keys, and each file key can be protected using different data protection methods. Currently, data protection methods such as credential encryption (CE), device encryption (DE), enhanced credential encryption (ECE), and sub-enhanced credential encryption (SECE) can be used to encrypt file keys.
[0003] Currently, the effectiveness of the above-mentioned ECE and SECE data protection methods depends on the lock screen mechanism. Taking ECE as an example, after a device encrypts a file using a file key, the device can encrypt the file key using the ECE corresponding key and store the encrypted file key. After a lock screen event occurs, the device deletes the stored ECE corresponding key, at which time the file key cannot be decrypted, and therefore the file cannot be accessed; after an unlock event occurs, the device restores the ECE corresponding key, at which time the file key can be decrypted, and therefore the file can be accessed.
[0004] As can be seen, only when the device has and enables the lock screen mechanism, the ECE and SECE data protection methods are effective. Otherwise, if the device does not have or does not enable the lock screen mechanism, the files encrypted using the ECE and SECE data protection methods can always be accessed, that is, the data protection methods are ineffective, resulting in the ECE and SECE data protection methods being unsuitable for devices that do not have or do not enable the lock screen mechanism. SUMMARY
[0005] The present application provides a data processing method, device, equipment and storage medium, which can solve the problem that the data protection method in the prior art is not suitable for devices that do not have or do not enable the lock screen mechanism.
[0006] To achieve the above object, the present application adopts the following technical solutions:
[0007] In a first aspect, a data processing method is provided, applied to a first device, comprising:
[0008] Obtaining first object data, the first object data being data related to user characteristics, and the first object data not including a lock screen event and an unlock event;
[0009] If the first object data satisfies one data protection condition in the context-aware rule, it is determined, according to the context-aware rule, whether to delete or restore the key corresponding to the data protection mode, the context-aware rule being used to determine whether a file encrypted by using the data protection mode can be accessed.
[0010] The user feature can be used to indicate a user, and the first object data being related to the user feature means that the first object data can be used to determine the user indicated by the user feature to some extent. For example, the first object data can be used to determine whether the user indicated by the user feature is a specified user to some extent, and the specified user can be a user who has access to data in the first device, for example, the specified user can be the owner of the first device.
[0011] In this way, whether to delete or restore the key corresponding to the data protection mode can be determined according to the first object data and the context-aware rule, and the need to rely on the lock screen mechanism can be avoided, so that the effectiveness of the data protection mode can be ensured when the data protection mode is applied to a device that does not have or does not enable the lock screen mechanism. That is, the file encrypted by using the data protection mode on the device that does not have or does not enable the lock screen mechanism can be encrypted or decrypted by the specified user and cannot be encrypted or decrypted by a non-specified user, and the user himself / herself does not need additional complex authentication to access the file.
[0012] In a possible implementation of the present application, the context-aware rule includes a plurality of data protection conditions, and the determining, according to the context-aware rule, whether to delete or restore the key corresponding to the data protection mode includes:
[0013] The second object data associated with other data protection conditions in the plurality of data protection conditions except the one data protection condition is obtained, the second object data is data related to the user feature, and the second object data is different from the first object data;
[0014] In a case where the second object data satisfies the other data protection conditions in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode.
[0015] In some embodiments, it can be unsafe to determine whether the user indicated by the user feature can encrypt or decrypt the file based only on the first object data, and therefore, in a case where the first object data satisfies one data protection condition in the context-aware rule, the second object data can be obtained, so that whether to delete or restore the key corresponding to the data protection mode can be determined according to the second object data and the context-aware rule.
[0016] For example, if the second object data satisfies other data protection conditions in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode.
[0017] It is understandable that if the second object data does not satisfy other data protection conditions in the context-aware rule, it is determined that the key corresponding to the data protection mode does not need to be deleted or restored.
[0018] It is worth mentioning that it is first determined whether the first object data satisfies a data protection condition in the context-aware rule, and only if it is satisfied, the first device will further acquire the second object data and determine whether to delete or restore the key corresponding to the data protection mode according to the second object data and other data protection conditions in the context-aware rule, so as to save the power consumption of the first device.
[0019] In a possible implementation of the present application, the method further comprises:
[0020] acquiring second object data, the second object data being data related to a user feature, and the second object data being different from the first object data;
[0021] The context-aware rule comprises a plurality of data protection conditions, and if the first object data satisfies a data protection condition in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode according to the context-aware rule, comprising:
[0022] In a case where the first object data satisfies a data protection condition in the context-aware rule and the second object data satisfies other data protection conditions in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode.
[0023] In an embodiment, the second object data can comprise at least one of the following object data:
[0024] user biological feature data;
[0025] probe data detected by a sensor, the probe data being used to indicate a user behavior habit and / or a user behavior state;
[0026] state indication information of a second device in the same network as the first device, the state indication information being used to indicate that the second device has a screen locking event or an unlocking event.
[0027] Further, if the first device is provided with and enabled with the lock screen mechanism, the second object data can further include a lock screen event or an unlock event of the first device. That is, the method provided by the embodiments of the present application can also be applied to the device provided with and enabled with the lock screen mechanism.
[0028] Here, according to the first object data and the second object data, and in combination with the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode, thus increasing the condition of user authentication, and thus improving the security of file encryption and decryption.
[0029] In a possible implementation of the present application, the determining whether to delete or restore the key corresponding to the data protection mode includes:
[0030] According to the data protection result in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode.
[0031] For example, the data protection result can include encryption or decryption, different data protection results can correspond to different data protection conditions, and each data protection result can correspond to at least one data protection condition, or when the context-aware rule includes multiple data protection conditions, each data protection result can correspond to at least one group of data protection conditions.
[0032] In a possible implementation of the present application, the determining whether to delete or restore the key corresponding to the data protection mode includes:
[0033] The current state of the file encrypted by the data protection mode is obtained, and according to the file state, it is determined whether to delete or restore the key corresponding to the data protection mode, wherein the state includes an encryption state or a decryption state.
[0034] For example, if the file encrypted by the data protection mode is currently in an encryption state, it can be determined that the key corresponding to the data protection mode needs to be restored, and for another example, if the file encrypted by the data protection mode is currently in a decryption state, it can be determined that the key corresponding to the data protection mode needs to be deleted.
[0035] In a possible implementation of the present application, the first object data includes any one of the following object data:
[0036] User biological feature data;
[0037] Detection data detected by a sensor, the detection data being used to indicate user behavior habits and / or user behavior state;
[0038] State indication information of a second device in a same group as the first device, the state indication information indicating that the second device has a screen locking event or a screen unlocking event.
[0039] Exemplarily, the user biometric feature data can include, but is not limited to, user fingerprint feature data, user voiceprint feature data, and user face feature data.
[0040] Exemplarily, the detection data can include, but is not limited to, weight features, driving speed, and seat position information.
[0041] In a second aspect, a data processing apparatus is provided, configured in a first device, comprising:
[0042] The acquisition module is configured to acquire first object data, the first object data being data related to user features, and the first object data not including a screen locking event or a screen unlocking event.
[0043] The determination module is configured to, if the first object data satisfies one data protection condition in a context awareness rule, determine whether to delete or restore a key corresponding to a data protection mode according to the context awareness rule, the context awareness rule being used to determine whether a file encrypted by using the data protection mode can be accessed.
[0044] In a possible implementation of the present application, the context awareness rule includes a plurality of data protection conditions, and the determination module is configured to:
[0045] acquire second object data associated with other data protection conditions in the plurality of data protection conditions except the one data protection condition, the second object data being data related to user features, and the second object data being different from the first object data;
[0046] In a case where the second object data satisfies the other data protection conditions in the context awareness rule, determine whether to delete or restore the key corresponding to the data protection mode.
[0047] In a possible implementation of the present application, the determination module is further configured to:
[0048] acquire second object data, the second object data being data related to user features, and the second object data being different from the first object data;
[0049] In a case where the first object data satisfies one data protection condition in the context awareness rule and the second object data satisfies the other data protection conditions in the context awareness rule, determine whether to delete or restore the key corresponding to the data protection mode.
[0050] In a possible implementation of the present application, the determining module is configured to:
[0051] According to the data protection result in the context awareness rule, determine whether to delete or restore the key corresponding to the data protection mode; or
[0052] Obtain a current state of a file encrypted by the data protection mode, and determine whether to delete or restore the key corresponding to the data protection mode according to the file state, wherein the state includes an encryption state or a decryption state.
[0053] In a possible implementation of the present application, the first object data includes any one of the following object data:
[0054] User biological feature data;
[0055] Detection data detected by a sensor, the detection data being used to indicate a user behavior habit and / or a user behavior state;
[0056] State indication information of a second device in the same network group as the first device, the state indication information being used to indicate that the second device has a screen locking event or a screen unlocking event.
[0057] In a third aspect, an electronic device is provided, which includes a processor and a memory in its structure. The memory is configured to store a program supporting the electronic device to execute the data processing method of any one of the first aspect, and store data involved in the data processing method of any one of the first aspect. The processor is configured to execute the program stored in the memory. The electronic device can further include a communication bus configured to establish a connection between the processor and the memory.
[0058] In a fourth aspect, a computer readable storage medium is provided, which stores instructions. When the instructions are executed on a computer, the computer executes the method of any one of the first aspect.
[0059] In a fifth aspect, a computer program product including instructions is provided, which, when executed on a computer, causes the computer to execute the data processing method of the first aspect.
[0060] The technical effects obtained by the second aspect, the third aspect, the fourth aspect and the fifth aspect are similar to the technical effects obtained by the corresponding technical means in the first aspect, and thus are not described herein.
[0061] The technical solutions provided by the present application can at least bring the following beneficial effects:
[0062] The first object data related to the user feature is acquired, and the first object data does not include the lock screen event and the unlock event. If the first object data satisfies one data protection condition in the context-aware rule, it can be considered that the user corresponding to the user feature can encrypt or decrypt the file encrypted in the data protection mode, so whether to delete or restore the key corresponding to the data protection mode can be determined according to the context-aware rule. That is, the method avoids the need to rely on the lock screen mechanism of the device, and can enable the data protection mode to be applied to a device without or without a lock screen mechanism. BRIEF DESCRIPTION OF DRAWINGS
[0063] Figure 1 An architecture schematic diagram of an electronic device is provided for an embodiment of the present application.
[0064] Figure 2 A software structure block diagram of an electronic device is provided for an embodiment of the present application.
[0065] Figure 3 A functional module schematic diagram of an electronic device is provided for an embodiment of the present application.
[0066] Figure 4 A flowchart of a data processing method is provided for an embodiment of the present application.
[0067] Figure 5 A flowchart of another data processing method is provided for an embodiment of the present application.
[0068] Figure 6 A flowchart of another data processing method is provided for an embodiment of the present application.
[0069] Figure 7 A flowchart of another data processing method is provided for an embodiment of the present application.
[0070] Figure 8 A schematic diagram of a data processing method is provided for an embodiment of the present application.
[0071] Figure 9 A flowchart of another data processing method is provided for an embodiment of the present application.
[0072] Figure 10 A schematic diagram of another data processing method is provided for an embodiment of the present application.
[0073] Figure 11 A flowchart of another data processing method is provided for an embodiment of the present application.
[0074] Figure 12 A structure schematic diagram of a data processing apparatus is provided for an embodiment of the present application. DETAILED DESCRIPTION
[0075] For the purpose, technical solutions and advantages of the present application to be clearer, the embodiments of the present application will be further described in detail below with reference to the drawings.
[0076] It should be understood that the "multiple" mentioned in the present application refers to two or more. In the description of the present application, unless otherwise specified, " / " represents the meaning of or, for example, A / B can represent A or B; "and / or" in this article is only a description of the relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent: A exists alone, A and B exist together, and B exists alone. In addition, in order to clearly describe the technical solutions of the present application, the same items or similar items with basically the same function and role are distinguished by using "first", "second" and the like. Those skilled in the art can understand that "first", "second" and the like do not limit the quantity and execution order, and "first", "second" and the like do not necessarily mean different.
[0077] First, the execution subject involved in the embodiments of the present application is introduced, the data processing method provided by the embodiments of the present application can be executed by an electronic device. As an example, the electronic device can not have or not enable a lock screen mechanism. As another example, the electronic device can also have and enable a lock screen mechanism, in which case, the data processing method provided by the embodiments of the present application can be implemented in combination with a lock screen event or an unlock event. In one embodiment, the electronic device can include a car machine device, a smart home device, a terminal, etc. For example, the smart home device can include but is not limited to a smart speaker, a smart TV, a smart toilet, a smart washing machine, a smart air conditioner, the terminal can include but is not limited to a mobile phone, a tablet computer, a personal digital assistant (PDA), a notebook computer, a portable computer, and the present application does not limit this.
[0078] Please refer to Figure 1 , Figure 1 is a structural schematic diagram of an electronic device provided by the embodiments of the present application.
[0079] The electronic device 100 can include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headset interface 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 can include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0080] It can be understood that the structure shown in the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 can include more or fewer components than shown, or combine certain components, or split certain components, or different arrangement of components. The components shown can be implemented in hardware, software, or a combination of software and hardware.
[0081] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices, or can be integrated in one or more processors.
[0082] The controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of fetching instructions and executing instructions.
[0083] The processor 110 can also include a memory that stores instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The cache memory can hold instructions or data that the processor 110 has recently used or is likely to use again. If the processor 110 needs to use the instructions or data again, it can be retrieved directly from the cache memory. This avoids repeated accesses to the main memory, reducing the latency of the processor 110 and thus improving the efficiency of the system.
[0084] In some embodiments, the processor 110 can include one or more interfaces. The interfaces can include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0085] The I2C interface is a bidirectional synchronous serial bus that includes a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 can include multiple sets of I2C buses. The processor 110 can be coupled to the touch sensor 180K, the charger, the flash, the camera 193, etc. through different I2C bus interfaces. For example, the processor 110 can be coupled to the touch sensor 180K through an I2C interface, so that the processor 110 and the touch sensor 180K communicate through the I2C bus interface, realizing the touch function of the electronic device 100.
[0086] The I2S interface can be used for audio communication. In some embodiments, the processor 110 can include multiple sets of I2S buses. The processor 110 can be coupled to the audio module 170 through the I2S bus, realizing communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can deliver audio signals to the wireless communication module 160 through the I2S interface, realizing the function of answering the phone through the Bluetooth headset.
[0087] The PCM interface can also be used for audio communication, sampling, quantizing and encoding analog signals. In some embodiments, the audio module 170 can be coupled with the wireless communication module 160 through a PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 through the PCM interface, realizing the function of answering a phone call through a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.
[0088] The UART interface is a universal serial bus for asynchronous communication. The bus can be a bidirectional communication bus. It converts data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is usually used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 through the UART interface, realizing the Bluetooth function. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 through the UART interface, realizing the function of playing music through a Bluetooth headset.
[0089] The MIPI interface can be used to connect the processor 110 and peripheral devices such as the display screen 194 and the camera 193. The MIPI interface includes the camera serial interface (CSI), the display serial interface (DSI), etc. In some embodiments, the processor 110 and the camera 193 communicate through the CSI interface, realizing the shooting function of the electronic device 100. The processor 110 and the display screen 194 communicate through the DSI interface, realizing the display function of the electronic device 100.
[0090] The GPIO interface can be configured by software. The GPIO interface can be configured as a control signal or as a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 and the camera 193, the display screen 194, the wireless communication module 160, the audio module 170, the sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.
[0091] The USB interface 130 is an interface that meets the USB standard specification, which can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 can be used to connect a charger to charge the electronic device 100, or to transmit data between the electronic device 100 and peripheral devices. It can also be used to connect a headset to play audio through the headset. The interface can also be used to connect other electronic devices, such as AR devices, etc.
[0092] It can be understood that the interface connection relationship between the modules shown in the embodiments of the present application is only illustrative and does not constitute a limitation on the structure of the electronic device 100. In other embodiments of the present application, the electronic device 100 can also use different interface connection modes or a combination of multiple interface connection modes in the above embodiments.
[0093] The charging management module 140 is configured to receive charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 can receive charging input from a wired charger through the USB interface 130. In some wireless charging embodiments, the charging management module 140 can receive wireless charging input through a wireless charging coil of the electronic device 100. The charging management module 140 can charge the battery 142 and also supply power to the electronic device 100 through the power management module 141.
[0094] The power management module 141 is configured to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140 to supply power to the processor 110, the internal memory 121, the external memory, the display screen 194, the camera 193, and the wireless communication module 160. The power management module 141 can also be configured to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance). In other embodiments, the power management module 141 can also be arranged in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be arranged in the same device.
[0095] The wireless communication function of the electronic device 100 can be realized through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor, and the baseband processor.
[0096] The antenna 1 and the antenna 2 are configured to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example, the antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in combination with a tuning switch.
[0097] The mobile communication module 150 can provide a solution for wireless communication including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves by the antenna 1, and perform filtering, amplification, etc. on the received electromagnetic waves, and transfer to a modem processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modem processor, and radiate as electromagnetic waves through the antenna 1. In some embodiments, at least part of the function modules of the mobile communication module 150 can be disposed in the processor 110. In some embodiments, at least part of the function modules of the mobile communication module 150 can be disposed in the same device as at least part of the modules of the processor 110.
[0098] The modem processor can include a modulator and a demodulator. The modulator is configured to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is configured to demodulate a received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. The low-frequency baseband signal processed by the baseband processor is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the microphone 170B, etc.), or displays an image or a video through the display screen 194. In some embodiments, the modem processor can be a separate device. In other embodiments, the modem processor can be independent of the processor 110, and disposed in the same device as the mobile communication module 150 or other function modules.
[0099] The wireless communication module 160 can provide a solution for wireless communication, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc., which are applied on the electronic device 100. In the embodiments of the present application, the electronic device 100 and other devices can be in the same network through the wireless communication module 160. The wireless communication module 160 can be one or more devices integrated with at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive signals to be sent from the processor 110, perform frequency modulation and amplification, and convert them into electromagnetic wave radiation via the antenna 2.
[0100] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include a global positioning system (GPS), a global navigation satellite system (GLONASS), a beidu navigation satellite system (BDS), a quasi-zenith satellite system (QZSS), and / or a satellite based augmentation systems (SBAS).
[0101] The electronic device 100 implements a display function through a GPU, a display screen 194, and an application processor, etc. The GPU is a microprocessor for image processing, which is connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs, which execute program instructions to generate or change display information.
[0102] The display screen 194 is configured to display images, videos, and the like. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diode (QLED), or the like. In some embodiments, the electronic device 100 can include one or N display screens 194, where N is a positive integer greater than 1.
[0103] The electronic device 100 can implement a photographing function through an ISP, the camera 193, a video codec, a GPU, the display screen 194, and an application processor.
[0104] The ISP is configured to process data fed back by the camera 193. For example, when taking a photo, a shutter is opened, light is transmitted to a camera photosensitive element through a lens, and the light signal is converted into an electrical signal. The camera photosensitive element transmits the electrical signal to the ISP for processing, and converts the electrical signal into an image visible to the naked eye. The ISP can also perform algorithm optimization on noise, brightness, and skin color of the image. The ISP can also optimize exposure, color temperature, and other parameters of a shooting scene. In some embodiments, the ISP can be disposed in the camera 193.
[0105] The camera 193 is configured to capture a still image or a video. For example, in the embodiments of the present application, the electronic device 100 can collect a face image through the camera 193. An object generates an optical image through a lens and projects the optical image onto a photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then transmits the electrical signal to the ISP to convert the electrical signal into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV, or the like format. In some embodiments, the electronic device 100 can include one or N cameras 193, where N is a positive integer greater than 1.
[0106] The digital signal processor is used to process digital signals, in addition to being able to process digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.
[0107] The video codec is used to compress or decompress digital video. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record videos in multiple encoding formats, such as: moving picture experts group (MPEG) 1, MPEG 2, MPEG 3, MPEG 4, etc.
[0108] The NPU is a neural-network (NN) calculation processor, which can quickly process input information by drawing on the structure of a biological neural network, such as drawing on the transmission mode between human brain neurons, and can also constantly self-learn. Through the NPU, the electronic device 100 can realize intelligent cognition applications such as image recognition, face recognition, voice recognition, text understanding, etc.
[0109] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to realize data storage functions. For example, music, video, etc. Files are saved in the external memory card.
[0110] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various function applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program required by a function (such as a sound playing function, an image playing function, etc.), etc. The data storage area can store data created during the use of the electronic device 100 (such as audio data, a phonebook, etc.), etc. In addition, the internal memory 121 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0111] The electronic device 100 can realize audio functions through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the earphone interface 170D, and the application processor, etc. For example, music playing, recording, etc.
[0112] The audio module 170 is configured to convert digital audio information into an analog audio signal output, and to convert an analog audio input into a digital audio signal. The audio module 170 can also be configured to encode and decode audio signals. In some embodiments, the audio module 170 can be disposed in the processor 110, or some functional modules of the audio module 170 can be disposed in the processor 110.
[0113] The speaker 170A, also referred to as a "loudspeaker", is configured to convert an audio electrical signal into a sound signal. The electronic device 100 can listen to music or listen to a hands-free call through the speaker 170A.
[0114] The receiver 170B, also referred to as a "earpiece", is configured to convert an audio electrical signal into a sound signal. When the electronic device 100 receives a call or a voice message, the user can listen to the voice through the receiver 170B close to the ear.
[0115] The microphone 170C, also referred to as a "microphone", "sound transducer", is configured to convert a sound signal into an electrical signal. When making a call or sending a voice message, the user can make a sound through the mouth close to the microphone 170C, input the sound signal into the microphone 170C, such as in the embodiments of the present application, the electronic device 100 can collect the voice instruction of the user through the microphone, so as to obtain the audio data of the user from the voice instruction. The electronic device 100 can be provided with at least one microphone 170C. In other embodiments, the electronic device 100 can be provided with two microphones 170C, in addition to collecting sound signals, it can also realize the function of noise reduction. In other embodiments, the electronic device 100 can also be provided with three, four or more microphones 170C, to realize the collection of sound signals, noise reduction, and also to identify the source of the sound, to realize the function of directional recording, etc.
[0116] The earphone interface 170D is configured to connect a wired earphone. The earphone interface 170D can be a USB interface 130, or a 3.5mm open mobile terminal platform (OMTP) standard interface, a cellular telecommunications industry association of the USA (CTIA) standard interface.
[0117] The pressure sensor 180A is configured to sense a pressure signal and convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A can be disposed on the display screen 194. The pressure sensor 180A can be of various types, such as a resistive pressure sensor, an inductive pressure sensor, a capacitive pressure sensor, etc. The capacitive pressure sensor can include at least two parallel plates of conductive material. When a force is applied to the pressure sensor 180A, the capacitance between the electrodes changes. The electronic device 100 determines the intensity of the pressure according to the change in capacitance. When a touch operation is applied to the display screen 194, the electronic device 100 detects the intensity of the touch operation according to the pressure sensor 180A. The electronic device 100 can also calculate the position of the touch according to the detection signal of the pressure sensor 180A. In some embodiments, touch operations applied to the same touch position but with different touch operation intensities can correspond to different operation instructions. For example, when a touch operation with a touch operation intensity less than a first pressure threshold is applied to a short message application icon, an instruction to view a short message is executed. When a touch operation with a touch operation intensity greater than or equal to the first pressure threshold is applied to the short message application icon, an instruction to create a new short message is executed.
[0118] The gyroscope sensor 180B can be configured to determine the motion attitude of the electronic device 100. In some embodiments, the angular velocity of the electronic device 100 around three axes (i.e., x, y, and z axes) can be determined by the gyroscope sensor 180B. The gyroscope sensor 180B can be used for anti-shake photography. For example, when the shutter is pressed, the gyroscope sensor 180B detects the angle of shaking of the electronic device 100, calculates the distance that the lens module needs to compensate according to the angle, and lets the lens offset the shaking of the electronic device 100 by reverse movement to achieve anti-shake. The gyroscope sensor 180B can also be used for navigation and motion sensing game scenarios.
[0119] The barometric pressure sensor 180C is configured to measure air pressure. In some embodiments, the electronic device 100 calculates the altitude, assists positioning and navigation by using the air pressure value measured by the barometric pressure sensor 180C.
[0120] The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can detect the opening and closing of a flip cover by using the magnetic sensor 180D. In some embodiments, when the electronic device 100 is a flip phone, the electronic device 100 can detect the opening and closing of the flip cover according to the magnetic sensor 180D. Further, according to the detected opening and closing state of the cover or the flip cover, the electronic device 100 can set a feature such as automatic unlocking of the flip cover.
[0121] The acceleration sensor 180E can detect the magnitude of acceleration of the electronic device 100 in various directions (generally three axes). When the electronic device 100 is stationary, the acceleration sensor 180E can detect the magnitude and direction of gravity. The acceleration sensor 180E can also be used to identify the attitude of the electronic device 100 and applied to applications such as landscape / portrait screen switching and pedometers.
[0122] Distance sensor 180F is used to measure distance. Electronic device 100 can measure distance by infrared or laser. In some embodiments, electronic device 100 can take a picture of a scene and use distance sensor 180F to measure distance for fast focusing.
[0123] Proximity light sensor 180G can include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The light emitting diode can be an infrared light emitting diode. Electronic device 100 emits infrared light outwardly through the light emitting diode. Electronic device 100 detects infrared reflected light from nearby objects using the photodiode. When sufficient reflected light is detected, electronic device 100 can determine that there is an object near electronic device 100. When insufficient reflected light is detected, electronic device 100 can determine that there is no object near electronic device 100. Electronic device 100 can use proximity light sensor 180G to detect when a user is holding electronic device 100 close to the ear for a phone call, so that the screen can be automatically turned off for power saving purposes. Proximity light sensor 180G can also be used for automatic unlocking and locking of the screen in a holster mode or a pocket mode.
[0124] Ambient light sensor 180L is used to sense ambient light brightness. Electronic device 100 can adaptively adjust the brightness of display screen 194 according to the sensed ambient light brightness. Ambient light sensor 180L can also be used to automatically adjust white balance when taking a picture. Ambient light sensor 180L can also work with proximity light sensor 180G to detect whether electronic device 100 is in a pocket to prevent accidental touch.
[0125] Fingerprint sensor 180H is used to collect a fingerprint. Electronic device 100 can use the collected fingerprint characteristics to implement fingerprint unlocking, access application lock, fingerprint picture taking, fingerprint call answering, and the like. In one embodiment, when electronic device 100 does not have or does not enable a lock screen mechanism, a fingerprint can still be collected by fingerprint sensor, for example, electronic device 100 can display a fingerprint collection interface on display screen 194, so that a user can enter a fingerprint in the fingerprint collection interface, and electronic device 100 can collect the fingerprint through fingerprint sensor 180H.
[0126] The temperature sensor 180J is configured to detect temperature. In some embodiments, the electronic device 100 performs temperature handling strategies based on the temperature detected by the temperature sensor 180J. For example, when the temperature reported by the temperature sensor 180J exceeds a threshold, the electronic device 100 reduces the performance of a processor located near the temperature sensor 180J to reduce power consumption and implement thermal protection. In another example, when the temperature is lower than another threshold, the electronic device 100 heats the battery 142 to avoid abnormal shutdown of the electronic device 100 caused by low temperature. In yet another example, when the temperature is lower than yet another threshold, the electronic device 100 boosts the output voltage of the battery 142 to avoid abnormal shutdown caused by low temperature.
[0127] The touch sensor 180K, also referred to as a "touch panel". The touch sensor 180K can be disposed on the display screen 194, and the touch sensor 180K and the display screen 194 form a touch screen, also referred to as a "touch panel". The touch sensor 180K is configured to detect a touch operation applied thereto or in the vicinity thereof. The touch sensor 180K can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through the display screen 194. In another example, the touch sensor 180K can also be disposed on the surface of the electronic device 100, which is different from the position of the display screen 194. For example, the electronic device 100 can detect a user's trigger instruction through the touch sensor.
[0128] The bone conduction sensor 180M can obtain a vibration signal. In some embodiments, the bone conduction sensor 180M can obtain a vibration signal of a human body sound vibration bone block. The bone conduction sensor 180M can also contact the human body pulse to receive a blood pressure pulsation signal. In some embodiments, the bone conduction sensor 180M can also be disposed in a headset to form a bone conduction headset. The audio module 170 can analyze a voice signal based on the vibration signal of the sound vibration bone block obtained by the bone conduction sensor 180M to implement a voice function. The application processor can analyze heart rate information based on the blood pressure pulsation signal obtained by the bone conduction sensor 180M to implement a heart rate detection function.
[0129] The keys 190 include a power on key, a volume key, and the like. The keys 190 can be mechanical keys. Alternatively, the keys 190 can be touch keys. The electronic device 100 can receive a key input and generate a key signal input related to user settings and function control of the electronic device 100.
[0130] The motor 191 can generate a vibration prompt. The motor 191 can be used for incoming call vibration prompt, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, playing audio, etc.) can correspond to different vibration feedback effects. The motor 191 can also correspond to different vibration feedback effects for touch operations acting on different regions of the display screen 194. Different application scenarios (such as time reminders, received messages, alarms, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.
[0131] The indicator 192 can be an indicator light, which can be used to indicate the charging state, the power change, and can also be used to indicate messages, missed calls, notifications, etc.
[0132] The SIM card interface 195 is used to connect the SIM card. The SIM card can be inserted into or pulled out of the SIM card interface 195 to realize contact and separation with the electronic device 100. The electronic device 100 can support one or N SIM card interfaces, and N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, etc. The same SIM card interface 195 can simultaneously insert multiple cards. The types of the multiple cards can be the same or different. The SIM card interface 195 can also be compatible with different types of SIM cards. The SIM card interface 195 can also be compatible with external storage cards. The electronic device 100 interacts with the network through the SIM card to realize functions such as calling and data communication. In some embodiments, the electronic device 100 uses an eSIM, that is, an embedded SIM card. The eSIM card can be embedded in the electronic device 100 and cannot be separated from the electronic device 100.
[0133] Further, the software system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a microkernel architecture, a microservice architecture, or a cloud architecture. The embodiment of the application takes the Android system with a layered architecture as an example to exemplarily illustrate the software structure of the electronic device 100.
[0134] Figure 2 The figure is a software structure block diagram of the electronic device 100 of the embodiment of the application.
[0135] The layered architecture divides the software into several layers, and each layer has a clear role and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom, the application layer, the application framework layer, the Android runtime and the system library, and the kernel layer.
[0136] The application layer can include a series of application packages.
[0137] AsFigure 2 As shown, the application package can include camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, short message, etc. applications.
[0138] The application framework layer provides application programming interface (API) and programming framework for the applications of the application layer. The application framework layer includes some pre-defined functions.
[0139] As shown, the application framework layer can include window manager, content provider, view system, phone manager, resource manager, notification manager, etc. Figure 2
[0140] The window manager is used to manage window programs. The window manager can acquire the size of the display screen, determine whether there is a status bar, lock the screen, and intercept the screen, etc.
[0141] The content provider is used to store and acquire data, and make the data accessible by the applications. The data can include video, image, audio, dialed and received calls, browsing history and bookmarks, phonebook, etc.
[0142] The view system includes visual controls, such as controls for displaying text, controls for displaying pictures, etc. The view system can be used to build applications. A display interface can be composed of one or more views. For example, a display interface including a short message notification icon can include a view for displaying text and a view for displaying pictures.
[0143] The phone manager is used to provide the communication function of the electronic device 100. For example, management of call status (including call connection, call hang-up, etc.).
[0144] The resource manager provides various resources for the applications, such as localized strings, icons, pictures, layout files, video files, etc.
[0145] The notification manager makes the applications able to display notification information in the status bar, which can be used to convey messages of the notification type, which can automatically disappear after a short stay without user interaction. For example, the notification manager is used to inform the completion of download, message reminder, etc. The notification manager can also be a notification in the form of a chart or a scroll bar text appearing in the top status bar of the system, such as a notification of an application running in the background, or a notification in the form of a dialogue window appearing on the screen. For example, prompting text information in the status bar, issuing a prompt sound, the electronic device 100 vibrating, the indicator light flashing, etc.
[0146] The Android runtime includes the core library and the virtual machine. The Android runtime is responsible for the scheduling and management of the Android system.
[0147] The core library contains two parts: one part is the function function that the java language needs to call, and the other part is the core library of Android.
[0148] The application layer and the application framework layer run in the virtual machine. The virtual machine executes the java file of the application layer and the application framework layer into a binary file. The virtual machine is used to execute the management of the object life cycle, the management of the stack, the management of the thread, the management of the security and the exception, and the garbage collection and the like.
[0149] The system library can include a plurality of function modules. For example: surface manager, media library, three-dimensional graphics processing library (for example: OpenGL ES), 2D graphics engine (for example: SGL) and the like.
[0150] The surface manager is used to manage the display subsystem, and provides the fusion of 2D and 3D layers for a plurality of applications.
[0151] The media library supports a plurality of commonly used audio, video format playback and recording, and static image files and the like. The media library can support a plurality of audio and video coding formats, for example: MPEG4, H.264, MP3, AAC, AMR, JPG, PNG and the like.
[0152] The three-dimensional graphics processing library is used to realize three-dimensional graphics drawing, image rendering, synthesis, and layer processing and the like.
[0153] The 2D graphics engine is a drawing engine for 2D drawing.
[0154] The kernel layer is a layer between hardware and software. The kernel layer at least contains display driver, camera driver, audio driver, sensor driver.
[0155] The working flow of the software and the hardware of the electronic device 100 is exemplarily explained below by combining with capturing a face image.
[0156] When the touch sensor 180K receives a touch operation, a corresponding hardware interrupt is sent to the kernel layer. The kernel layer processes the touch operation into a raw input event (including touch coordinates, timestamp of the touch operation and the like). The raw input event is stored in the kernel layer. The application framework layer obtains the raw input event from the kernel layer, and identifies the control corresponding to the input event. Taking the touch operation as a touch single click operation, and the control corresponding to the single click operation as the control of the camera application icon as an example, the camera application calls the interface of the application framework layer, starts the camera application, and then starts the camera driver through the kernel layer, and captures the face image through the camera 193.
[0157] For the convenience of understanding and distinguishing, the following takes the application of the data processing method to the first device as an example for illustration, and the first device can be the electronic device 100 described above. Please refer to Figure 3 , the Figure 3 is a functional module schematic diagram of a first device according to an exemplary embodiment. The first device is deployed with a context awareness module and a virtual lock screen module. Further, the context awareness module can include but is not limited to a rule creation submodule and a query submodule, and the virtual lock screen module can include a plurality of management submodules, which can include but are not limited to a biometric feature management submodule, a networking device management submodule, a sensor management submodule, and a context management submodule.
[0158] The rule creation submodule can be used to create and update context awareness rules, and the query submodule can be used to query the plurality of management submodules to obtain object data managed by each of the plurality of management submodules. The plurality of management submodules can be used to obtain different object data, for example, the biometric feature management submodule can be used to obtain user biometric feature data, the networking device management submodule can be used to obtain state indication information of a second device in the same network as the first device, the state indication information can be used to indicate that the second device has a lock screen event or an unlock event, the sensor management submodule can be used to obtain detection data detected by a sensor, and the context management submodule can be used to trigger the context awareness module.
[0159] It should be noted that the above is only an example of a functional module schematic diagram of the first device, but this does not limit the functions of the first device, and the first device can also include other functional modules. For example, it can also include a file creation module, and further, the file creation module can include a file key generation submodule and a file encryption submodule, the file key generation submodule can be used to generate a file key, and the file encryption submodule can be used to encrypt a file. For another example, the virtual unlock module described above can also include a lock screen submodule and an unlock submodule, etc., which are not limited by the embodiments of the present application.
[0160] Based on the above Figures 1-3 embodiments of the first device, the specific implementation of the data processing method provided by the embodiments of the present application is introduced, please refer to Figure 4 , Figure 4 is a schematic flowchart of a data processing method provided by an embodiment of the present application, which can include the following parts or all of the contents:
[0161] Step 401: obtaining first object data, the first object data is data related to user features, and the first object data does not include a lock screen event and an unlock event.
[0162] The user feature can be used to indicate a user, and the first object data being related to the user feature means that the first object data can be used to determine the user indicated by the user feature to some extent. For example, the first object data can be used to determine whether the user indicated by the user feature is a specified user to some extent, and the specified user can be a user who has access to data in the first device, for example, the specified user can be the owner of the first device.
[0163] In an embodiment, the first object data can include user biometric feature data. For example, the first object data can include user fingerprint feature data, or the first object data can include user voiceprint feature data, or the first object data can include user face feature data.
[0164] In another embodiment, the first object data can also include detection data detected by a sensor, and the detection data can be used to indicate user behavior habits and / or user behavior states.
[0165] For example, the sensor can be a gravity sensor, a seat position sensor, a pose sensor, or a speed sensor. The sensor can be connected to the first device through an interface such as a USB (Universal Serial Bus), a serial port, or the like. The number of sensors can include one or more, and when the number of sensors is more than one, the types of the plurality of sensors can be different.
[0166] For example, if the first device is a car device, the sensor can include a gravity sensor, a seat position sensor, and a speed sensor, wherein the gravity sensor can be used to detect the weight feature of the driver, so as to determine whether the driver has left the driver seat, i.e., to determine the user behavior state; the seat position sensor can be used to detect the seat position information of the driver, and the speed sensor can be used to detect the driving speed, so as to determine the driving habits of the driver according to the seat position information and the driving speed, i.e., to determine the user behavior habits.
[0167] In yet another embodiment, the first object data can also include state indication information of a second device in the same network group as the first device, and the state indication information is used to indicate that the second device has a screen locking event or an unlocking event.
[0168] As an example, the second device can be referred to as a strong device, where the strong device refers to a device with identity authentication capability, i.e., a device capable of identifying the identity of a user, such as a device with a lock screen mechanism enabled. Further, the number of the second devices in the same network as the first device can be one or more, and if the second devices include multiple second devices, the types of the multiple second devices can be the same or different, such as the multiple second devices including, but not limited to, a smart watch, a mobile phone, and a smart television, and the embodiments of the present application do not limit the same.
[0169] According to different data contents of the first object data, the implementation manners of obtaining the first object data are different, and specifically:
[0170] In a possible implementation manner, in a case where the first object data includes user biometric feature data, the first device can obtain the first object data through a collector configured by the first device. For example, if the first object data includes user voiceprint feature data, the first device can obtain the first object data through a voice collector such as a microphone, and for another example, if the first object data includes user fingerprint feature data, the first device can obtain the first object data through a fingerprint collector.
[0171] In another possible implementation manner, in a case where the first object data includes detection data detected by a sensor, the first device can obtain the first object data through the sensor. For example, the first device can be connected with a gravity sensor, and the gravity sensor can be used to detect the weight feature of a driver, so as to obtain the first object data.
[0172] In another possible implementation manner, in a case where the first object data includes state indication information of a second device in the same network as the first device, as an example, if the second device has a lock screen event or an unlock event, the second device can send the state indication information to the first device, so that the first device obtains the first object data. As another example, the first device can also actively send an obtaining request to the second device, where the obtaining request is used to instruct the second device to feed back the state indication information, so that the second device can send the state indication information to the first device according to the current state of the second device.
[0173] Of course, it should be noted that the above is only an example in which the first object data includes any one of user biometric feature data, detection data detected by a sensor, and state indication information of a second device in the same network as the first device, and in another embodiment, the first object data can also include other object data associated with user features, and the embodiments of the present application do not limit the same.
[0174] Step 402: If the first object data satisfies one of the data protection conditions in the context-aware rule, it is determined according to the context-aware rule whether to delete or restore the key corresponding to the data protection mode, and the context-aware rule is used to determine whether the file encrypted by the data protection mode can be accessed.
[0175] As an example, the data protection mode herein can include ECE or SECE, wherein different data protection modes usually correspond to their own keys, which can be used to encrypt the file key to encrypt the file.
[0176] In a possible implementation, the context-aware rule can be created by the first device in the case of system initialization. As an example, the context-aware rule can be from the firmware of the first device, which is pre-set by the device manufacturer of the first device, wherein the firmware refers to the bottommost working software of the system of the first device; as another example, the context-aware rule can also be downloaded from a network resource, and the creation manner of the context-aware rule is not limited in the embodiments of the present application. In addition, the context-aware rule can exist in the form of a library, that is, the first device includes a context-aware rule library, and the existing form of the context-aware rule is not limited in the embodiments of the present application.
[0177] Further, the first device can update the context-aware rule, for example, the first device can obtain the latest context-aware rule from a network resource every certain period of time (for example, obtain the context-aware rule with the closest storage date to the current time point), or can obtain the updated context-aware rule from the upgraded firmware after the firmware is upgraded. Of course, the first device can also obtain the updated context-aware rule from other positions, for example, from other devices, and the embodiments of the present application are not limited thereto.
[0178] The context-aware rule can include one or more data protection conditions. As an example, the plurality of data protection conditions can include: 1, the user voiceprint feature data conforms to the specified voiceprint feature data, wherein the specified voiceprint feature data can be set according to actual needs; 2, the detection data detected by the sensor changes; 3, the second device in the same network with the first device has an unlocking event / lock screen event.
[0179] Further, the context-aware rule can further include a data protection result, the data protection result can include encryption or decryption, and different data protection results can correspond to different data protection conditions, and each data protection result can correspond to at least one set of data protection conditions. For example, if the data protection result includes encryption, the corresponding data protection conditions can include at least one of the following three: 1. The user's voiceprint feature data meets the specified voiceprint feature data, wherein the specified voiceprint feature data can be set according to actual needs; 2. The detection data detected by the sensor changes, and the change result indicates that the corresponding user behavior state is to leave the current environment; 3. A second device in the same network as the first device has a screen lock event. For another example, if the data protection result includes decryption, the corresponding data protection conditions can include: 1. The user's voiceprint feature data meets the specified voiceprint feature data; 2. A second device in the same network as the first device has an unlock event.
[0180] In one embodiment, if the first object data meets one of the data protection conditions in the context-aware rule, it can be considered that the user feature related to the first object data is consistent with the user feature of the specified user, so that it can be considered that the user related to the first object data can encrypt or decrypt the file in the first device, in this case, whether to delete or restore the key corresponding to the data protection mode can be determined according to the context-aware rule.
[0181] As an example, the context-aware rule further includes a data protection result, and the first device can determine whether to delete or restore the key corresponding to the data protection mode according to the data protection result corresponding to the data protection condition met by the first object data, such as if the data protection result corresponding to the data protection condition met by the first object data is encryption, it can be determined that the key corresponding to the data protection mode needs to be deleted, and for another example, if the data protection result corresponding to the data protection condition met by the first object data is decryption, it can be determined that the key corresponding to the data protection mode needs to be restored.
[0182] In one embodiment, the context-aware rule includes a plurality of data protection conditions, in which case the specific implementation of determining whether to delete or restore the key corresponding to the data protection mode according to the context-aware file can include: obtaining second object data associated with other data protection conditions in the plurality of data protection conditions except one data protection condition, the second object data is data related to the user feature, and the second object data is different from the first object data. In the case where the second object data meets the other data protection conditions in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode.
[0183] The second object data can be one or more, and the first object data can include user biometric data, and the second object data can include sensor detection data and second device state indication information.
[0184] In general, the first object data can be a weak determinant and can be easily imitated, so in order to ensure the security of the file, the first device can further obtain second object data related to the user feature to make further judgment in combination with the second object data when the first object data meets one of the data protection conditions in the context-aware rule.
[0185] For example, if the biometric management submodule in the first device detects that the first object data meets one of the data protection conditions in the context-aware rule, the context management submodule can be notified, and the context-aware module is triggered by the context management submodule. The context-aware module queries other management submodules through a query submodule to obtain second object data, such as sensor detection data and second device state indication information.
[0186] After the first device obtains the second object data, the first device can determine whether to delete or restore the key corresponding to the data protection mode according to the second object data and the context-aware rule. For example, if the second object data meets other data protection conditions in the context-aware rule, it can be considered that the user feature meets the user feature of the specified user, and at this time the first device can determine whether to delete or restore the key corresponding to the data protection mode.
[0187] It should be noted that if the number of second object data includes multiple, in one embodiment, when at least one of the multiple second object data meets other data protection conditions included in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode; in another embodiment, when all of the multiple second object data meet other data protection conditions included in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode.
[0188] It is worth mentioning that it is first determined whether the first object data meets one of the data protection conditions in the context-aware rule, and only when it is met, the first device will further obtain the second object data, and determine whether to delete or restore the key corresponding to the data protection mode according to the second object data and other data protection conditions in the context-aware rule, so as to save the power consumption of the first device.
[0189] In one embodiment, the specific implementation of determining whether to delete or restore the key corresponding to the data protection mode can include any one of the following two implementation manners:
[0190] The first implementation manner is that according to the data protection result in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection manner.
[0191] That is, the data protection result is included in the context-aware rule, and as described above, different data protection results correspond to different data protection conditions, so according to the data protection condition satisfied by the first object data and the data protection condition satisfied by the second object data, the data protection result can be determined, and thus according to the data protection result, it can be determined whether to delete or restore the key corresponding to the data protection manner.
[0192] It is worth mentioning that here, it can be directly determined according to the data protection result included in the context-aware rule whether to delete or restore the key corresponding to the data protection manner, thus improving the key management efficiency.
[0193] The second implementation manner is that a current state of a file encrypted by using the data protection manner is obtained, and according to the file state, it is determined whether to delete or restore the key corresponding to the data protection manner, wherein the state includes an encryption state or a decryption state.
[0194] In this implementation manner, the first device can determine whether to delete or restore the key corresponding to the data protection manner according to the state of the file encrypted by using the data protection manner. For example, if the file is currently in an encryption state, it indicates that the file needs to be decrypted, and thus the first device determines to restore the key corresponding to the data protection manner. If the file is currently in a decryption state, it indicates that the file needs to be encrypted, and thus the first device determines to delete the key corresponding to the data protection manner.
[0195] It should be noted that if the data protection manner is SECE, the key corresponding to the SECE includes a public key and a private key, and in the implementation process, the first device deletes or restores the private key corresponding to the SECE.
[0196] It should be further noted that the embodiments of the present application are described by taking the case that the first device does not have or does not enable the lock screen mechanism as an example. If the first device also has and enables the lock screen mechanism, the second object data can also include a lock screen event or an unlock event.
[0197] In the embodiments of the present application, the first object data related to the user feature is acquired, and the first object data does not include the lock screen event and the unlock event. If the first object data satisfies one data protection condition in the context awareness rule, it can be considered that the user corresponding to the user feature can encrypt or decrypt the file encrypted in the data protection manner, so whether to delete or restore the key corresponding to the data protection manner can be determined according to the context awareness rule. That is, the method avoids the need to rely on the lock screen mechanism of the device, and can enable the data protection manner to be applied to the device without or without the lock screen mechanism.
[0198] The above is described by taking the case that the second object data is acquired when the first object data satisfies one data protection condition in the context awareness rule, and whether to delete or restore the key corresponding to the data protection manner is determined according to the second object data and the context awareness rule. In another embodiment, the second object data can also be acquired directly without judging whether the first object data satisfies the context awareness rule, and then whether to delete or restore the key corresponding to the data protection manner is determined in combination with the context awareness rule. For details, reference can be made to Figure 5 , and Figure 5 A flowchart of a data processing method according to another exemplary embodiment is shown, which can be applied to a first device. The method can include the following or all contents:
[0199] Step 501: Acquire first object data, the first object data is data related to a user feature, and the first object data does not include a lock screen event and an unlock event.
[0200] The specific implementation of this step can refer to step 401 in the above-described Figure 4 embodiment, which will not be repeated here.
[0201] Step 502: Acquire second object data, the second object data is data related to a user feature, and the second object data is different from the first object data.
[0202] As an example, the second object data can include user biometric feature data; and / or, the second object data can include detection data detected by a sensor, which can be used to indicate user behavior habits and / or user behavior states; and / or, the second object data can also be state indication information of a second device in the same network as the first device, which is used to indicate that the second device has a lock screen event or an unlock event. For example, the first object data includes user voiceprint feature data, and the second object data can include detection data detected by a sensor and state indication information of a second device.
[0203] In one embodiment, the second object data is acquired in different manners according to different contents of the second object data, specifically:
[0204] In one possible implementation, when the second object data comprises user biometric data, the first device can acquire the second object data through a self-configured collector. For example, the second object data is user voiceprint feature data, and the first device can acquire the user voiceprint feature data through a voice collector such as a microphone.
[0205] In another possible implementation, when the second object data comprises detection data detected by a sensor, the first device can acquire the second object data through the sensor. For example, the first device can be connected with a gravity sensor, through which the weight feature of a driver can be detected to obtain the second object data.
[0206] In another possible implementation, when the second object data comprises state indication information of a second device in the same network group as the first device, as an example, if the second device has a screen locking event or an unlocking event, the second device can send the state indication information to the first device, and the first device acquires the state indication information to obtain the second object data. As another example, the first device can also actively send an acquisition request to the second device, the acquisition request being used to instruct the second device to feed back the state indication information, so that the second device can send the state indication information to the first device according to the current state thereof.
[0207] It should be noted that, here, only the second object data comprising at least one of user biometric data, detection data and state indication information is taken as an example for illustration, and in another embodiment, the second object data can also comprise other object data. For example, if the first device has and enables a screen locking mechanism, the second object data can also comprise a screen locking event or an unlocking event.
[0208] Step 503: determining whether to delete or restore the key corresponding to the data protection mode according to the first object data, the second object data and the context awareness rule.
[0209] Similarly to the above embodiment, the context awareness rule can be pre-created and updated according to actual needs, and the specific creation and updating manners can be referred to step 402 in the above embodiment. Figure 4
[0210] In one embodiment, the determining whether to delete or restore the key corresponding to the data protection mode according to the first object data, the second object data and the context-aware rule can comprise: determining whether to delete or restore the key corresponding to the data protection mode, in a case that the first object data satisfies one data protection condition in the context-aware rule and the second object data satisfies the other data protection condition in the context-aware rule.
[0211] In a case that the first object data satisfies one data protection condition in the context-aware rule and the second object data satisfies the other data protection condition in the context-aware rule, it can be considered that the user feature indicated user is consistent with the user feature of the specified user, and thus it can be considered that the user feature indicated user related to the first object data and the second object data is able to encrypt or decrypt the key corresponding to the data protection mode, and therefore the first device can determine whether to delete or restore the key corresponding to the data protection mode.
[0212] In one embodiment, if the number of the second object data comprises a plurality, in one embodiment, when it is determined according to the context-aware rule that the first object data is a strong determinant, if the first object data satisfies one data protection condition in the context-aware rule and at least one of the plurality of second object data satisfies the other data protection condition included in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode. In another embodiment, when the first object data satisfies one data protection condition in the context-aware rule and all of the plurality of second object data satisfy the other data protection condition included in the context-aware rule, it is determined whether to delete or restore the key corresponding to the data protection mode.
[0213] In one embodiment, the determining whether to delete or restore the key corresponding to the data protection mode can comprise any one of the following two implementations:
[0214] The first implementation: determining whether to delete or restore the key corresponding to the data protection mode according to the data protection result in the context-aware rule.
[0215] That is, the context-aware rule includes the data protection result, as described above, since different data protection results correspond to different data protection conditions, according to the data protection condition satisfied by the first object data and the data protection condition satisfied by the second object data, the data protection result can be determined, and thus according to the data protection result, it can be determined whether to delete or restore the key corresponding to the data protection mode.
[0216] It is worth mentioning that, here, the data protection result included in the context awareness rule can be directly used to determine whether to delete or restore the key corresponding to the data protection mode, thus improving the key management efficiency.
[0217] The second implementation manner: obtaining the current state of the file encrypted by the data protection mode, and determining whether to delete or restore the key corresponding to the data protection mode according to the file state, wherein the state includes an encryption state or a decryption state.
[0218] In this implementation manner, the first device can determine whether to delete or restore the key corresponding to the data protection mode according to the state of the file encrypted by the data protection mode. For example, if the file is currently in the encryption state, it means that the file needs to be decrypted, and therefore, the first device determines to restore the key corresponding to the data protection mode. If the file is currently in the decryption state, it means that the file needs to be encrypted, and therefore, the first device determines to delete the key corresponding to the data protection mode.
[0219] In the embodiments of the present application, the first object data related to the user feature is obtained, and the second object data related to the user feature is obtained, wherein the first object data does not include the lock screen event and the unlock event, and the second object data is different from the first object data. In the case that the first object data satisfies one data protection condition in the context awareness rule and the second object data satisfies the other data protection condition in the context awareness rule, it can be considered that the user corresponding to the user feature can encrypt or decrypt the file encrypted by the data protection mode, and therefore, it can be determined according to the context awareness rule whether to delete or restore the key corresponding to the data protection mode. That is, the method avoids the need to rely on the lock screen mechanism of the device, and can make the data protection mode applied to the device without or without the lock screen mechanism.
[0220] Moreover, here, the first object data and the second object data are used to determine whether to delete or restore the key corresponding to the data protection mode in combination with the context awareness rule, thus increasing the conditions for user authentication, thereby improving the security of file encryption and decryption.
[0221] It should be understood that the size of the serial number of each step in the above embodiments does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0222] Based on the above-provided data processing method, in order to facilitate understanding, the implementation process of the method will be described in detail in combination with specific examples. Here, the method is taken as an example applied to a car machine device, and the method can include the following parts or all the contents:
[0223] Firstly, the business scenario is introduced. The in-vehicle device can usually store some personal privacy data of the user, such as location information, address book and the like, and the personal privacy data can be file-level encrypted by using ECE or SECE. For example, refer to Figure 6 , the file creation and encryption process can include:
[0224] 601. The user creates a file and sets a data protection mode.
[0225] For example, the user navigates to location A through the navigation application in the in-vehicle device, and then the in-vehicle device can store a file, the content of which includes "location A is a frequently visited place".
[0226] 602. The in-vehicle device encrypts the file by using a file key.
[0227] As an example, the in-vehicle device includes a file creation module, by which a file key can be automatically generated. Suppose the file key is E file , the file can be encrypted by using the file key to obtain an encrypted file E file (text).
[0228] 603. The in-vehicle device encrypts the file key by using a data protection mode.
[0229] For example, the file creation module encrypts the file key E file by using ECE to obtain an encrypted file key E ECE (E file ).
[0230] 604. The in-vehicle device stores the encrypted data.
[0231] For example, the in-vehicle device stores the encrypted file E file (text), the type of data protection mode ECE and the encrypted file key E ECE (E file ) by using the file creation module. As an example, the in-vehicle device can store the above-mentioned encrypted data in the memory.
[0232] Since the in-vehicle device usually does not have a lock screen mechanism, in order to ensure the effectiveness of the data protection mode, the file can be encrypted and decrypted by using the following method:
[0233] The first decryption stage, refer to Figure 7 :
[0234] 701. The in-vehicle device obtains first object data.
[0235] For example, when a user wants to query a place that he / she visited last time, a navigation application in the vehicle device can be opened. The navigation application can provide a query interface, which can provide a voice collection option that can be triggered by the user. After detecting the triggering operation on the voice collection option, the vehicle module in the vehicle device can enable the microphone to collect voice, such as a voice instruction of the user, which includes "please query a place that he / she visited last time". The vehicle device obtains user voiceprint feature data from the voice instruction, and takes the user voiceprint feature data as first object data.
[0236] 702、The vehicle device verifies the first object data.
[0237] As an example, the vehicle device can compare the user voiceprint feature data with pre-stored specified voiceprint feature data, which can be voiceprint feature data of a specified user. If the similarity between the user voiceprint feature data and the specified voiceprint feature data is greater than a specified threshold, it means that the user can be the same user as the specified user, so it can be determined that the verification of the first object data is passed.
[0238] The specified voiceprint feature data can be pre-collected and stored in the vehicle device according to actual needs, and the specified user corresponding to the specified voiceprint feature data refers to a user who can access data in the vehicle device, for example, the specified user is the owner of the vehicle where the vehicle device is located.
[0239] The specified threshold can be set by the user according to actual needs, or it can also be set by default by the vehicle device, and the embodiments of the present application do not limit this.
[0240] 703、The first object data whether meets one data protection condition in the context awareness rule.
[0241] For example, in the case where the verification of the first object data is passed, the vehicle device determines that the first object data meets one data protection condition in the context awareness rule.
[0242] Of course, if the first object data does not meet the data protection condition in the context awareness rule, it means that the user associated with the first object data has not passed the verification, and the vehicle device determines that the first object data does not meet the data protection condition in the context awareness rule, at this time, no encryption or decryption operation is performed, that is, the process is ended.
[0243] 704、If the first object data meets one data protection condition in the context awareness rule, the vehicle device triggers the context awareness module to query other management sub-modules to obtain second object data.
[0244] The authentication capability of the biometric feature management submodule of the vehicle machine device is generally weak, and the user voiceprint feature data can be imitated. Based on this, the context awareness module can be triggered to query other management submodules to obtain other second object data in addition to the first object data, so as to verify the user identity in combination with the second object data.
[0245] In one embodiment, referring to Figure 8 The vehicle machine device can query the networking device management submodule to obtain state indication information of a second device in the same networking as the vehicle machine device, such as a smart watch and a mobile phone, and query the sensor management submodule to obtain detection data detected by a sensor, such as a body weight feature detected by a gravity sensor, position information of a driver's seat, and a driving speed of a vehicle. As an example, the body weight feature can be used to indicate a user behavior state, such as whether the user leaves the driver's seat. The position information of the driver's seat and the driving speed can be used to indicate a user behavior habit, such as a driving habit of the user.
[0246] 705. If the second object data satisfies other data protection conditions in the context awareness rule except for one data protection condition, it is determined whether to delete or restore the key corresponding to the ECE.
[0247] For example, according to the state indication information, it is determined that none of the second devices in the same networking as the vehicle machine device is in an unlocked state, and the detection data detected by the sensor indicates that the body weight feature of the user on the current driver's seat, the driving speed of the user in a period of time, and the position of the current driver's seat all match the specified user. The vehicle machine device determines that other data protection conditions in the context awareness rule are satisfied in this case, and thus it can be determined that the user is the specified user, that is, the user identity verification of the user is passed.
[0248] It should be noted that the above-mentioned second object data is only exemplary, and in another embodiment, the second object data can also include other object data, for example, referring to Figure 8 In the case where the plurality of management submodules further include a face recognition submodule, the second object data can further include user face feature data. Further, assuming that the vehicle machine device has and enables a lock screen mechanism, the second object data can include a lock screen event or an unlock event, such as an unlock notification. The embodiments of the present application are not limited in this regard.
[0249] 706. According to the data protection result of the context awareness rule, it is determined to restore the key corresponding to the ECE.
[0250] According to the context awareness rule, it can be determined that the data protection condition corresponds to a data protection result of recovering the key corresponding to the ECE, so the car machine device needs to delete the key corresponding to the ECE.
[0251] As an example, the car machine device can regenerate the key corresponding to the ECE based on the root key of the ECE, and store the key in the memory. Then, the file key E ECE file ) can be decrypted to obtain the file key E file , and then the file can be decrypted using the file key E file to obtain the decrypted file text, which can also be referred to as file plaintext.
[0252] Further, after obtaining the file plaintext, the car machine device can display the file plaintext to the user, or can also convert the file plaintext into voice data and play the voice data, so that the user obtains the information that he or she wants to query.
[0253] The first encryption stage, please refer to Figure 9 :
[0254] 901、After a period of time, the voice instruction times out.
[0255] It is not difficult to understand that in the case of voice instruction timeout, it means that the acquisition of user voiceprint feature data times out, at this time, the first object data can be considered to meet one of the data protection conditions in the context awareness rule, that is, the data protection condition is that the acquisition of user voiceprint feature data times out, at this time, the context awareness module is triggered.
[0256] 902、The context awareness module queries other management sub-modules to obtain second object data.
[0257] For example, please refer to Figure 10 , the context awareness module queries the networking device management sub-module to obtain the state indication information of the second device in the networking, such as the second device including a smart watch and a mobile phone, and queries the sensor management sub-module to obtain the detection data detected by the sensor, such as the detection data including the weight feature detected by the gravity sensor, the position information of the driver's seat and the driving speed of the vehicle.
[0258] 903、Determine whether the second object data meets other data protection conditions in the context awareness rule.
[0259] 904、If the second object data meets other data protection conditions in the context awareness module except one data protection condition, determine whether to delete or recover the key corresponding to the ECE.
[0260] For example, assuming that it is determined according to the state indication information that no second device in the networking is in an unlocked state, the detection data detected by the sensor indicates that the weight characteristics of the user currently on the driver seat, the driving speed of the user in a period of time, and the position of the current driver seat all conform to the specified user, and the second object data of the other management sub-module determined by the vehicle machine device satisfies the other data protection conditions in the context awareness rule, it can be determined that the user is the specified user, that is, the user identity verification of the user is passed.
[0261] It should be noted that the second object data is exemplary only, and in another embodiment, the second object data can also include other object data, for example, please refer to Figure 10 In the case where the plurality of management sub-modules further include a face recognition sub-module, the second object data can also include user face feature data. Further, assuming that the vehicle machine device has and enables a lock screen mechanism, the second object data can include a lock screen event or an unlock event, such as a lock screen notification, and the embodiments of the present application do not limit this.
[0262] 905. According to the data protection result of the context awareness rule, it is determined to delete the key corresponding to the ECE.
[0263] According to the context awareness rule, the data protection result corresponding to the data protection condition is to delete the key corresponding to the ECE, so the vehicle machine device needs to delete the key corresponding to the ECE, for example, the vehicle machine device deletes the key E ECE , so that the file encrypted by the ECE cannot be accessed.
[0264] Second decryption stage, please refer to Figure 11 :
[0265] 1101. Obtain state indication information, the state indication information being used to indicate that an intelligent watch in the same networking as the vehicle machine device has an unlock event.
[0266] For example, the user unlocks the intelligent watch and queries a message, and after the intelligent watch has the unlock event, it sends state indication information to other devices in the same networking, so that the vehicle machine device can receive the state indication information, for example, the vehicle machine device receives the state indication information through the networking device management sub-module. Further, the vehicle machine device determines that the state indication information satisfies one of the data protection conditions in the context awareness rule.
[0267] 1102. Trigger the context awareness module to query the other management sub-modules to obtain second object data.
[0268] For example, the biometric feature management submodule can be queried to obtain user voiceprint feature data, and the sensor management submodule can be queried to obtain detection data, such as body weight features detected by a gravity sensor, position information of a driver seat, and a driving speed of the vehicle.
[0269] 1103. Determine, according to the context awareness rule and the second object data, whether to delete or restore the key corresponding to the ECE.
[0270] For example, the user voiceprint feature data is obtained, and the detection data indicates that the body weight features of the user currently on the driver seat are consistent with the body weight features of the specified user, but there is a small difference between the driving habits of the user and the driving habits of the specified user. If the unlocking state of the second device is a strong determining factor according to the context awareness rule, it can be determined that the user unlocking the smart watch is the specified user when the smart watch is in the unlocked state, that is, although the driving habits of the user are slightly different from the driving habits of the specified user, it can be determined that the current user is the specified user, and it can be determined that the key E corresponding to the ECE needs to be restored. ECE .
[0271] It should be noted that the car machine device can determine the difference in driving habits according to certain rules. For example, when the position of the driver seat and the driving speed are used to indicate the driving habits of the user, certain weights can be set for these two elements, respectively, and then the scores corresponding to the driving habits are evaluated based on the weight values, so as to determine the size of the difference in driving habits according to the scores.
[0272] After the key E corresponding to the ECE is restored ECE , the car machine device uses the key E ECE to decrypt the encrypted file key E ECE (E file ), obtains the file key E file , so that the encrypted file E file (text) can be decrypted using the file key, so as to obtain the decrypted file text, that is, the file plaintext.
[0273] In the second encryption stage, please continue to refer to Figure 11 :
[0274] 1104. After a period of time, the detection data detected by the sensor changes.
[0275] For example, if the user gets off the driver seat, the detection data detected by the sensor for detecting the body weight features will change, and the car machine device determines that the change in the detection data satisfies a data protection condition of the context awareness rule.
[0276] 1105、The car machine device triggers the context awareness module to query other management sub-modules to obtain second object data.
[0277] For example, the context awareness module queries the biometric feature management sub-module to obtain user voiceprint feature data, and queries the networking device management sub-module to obtain state indication information of a second device in the same network as the car machine device, such as a smart watch.
[0278] 1106、The car machine device queries the context awareness rule, and determines whether to delete or restore the key corresponding to the data protection mode according to the second object data and the context awareness rule.
[0279] For example, if the smart watch in the same network as the car machine device has a screen locking event, it is determined that the second object data meets other data protection conditions in the context awareness rule. Further, the car machine device determines that the file needs to be encrypted according to the data protection result included in the context awareness rule, and the car machine device determines that the key corresponding to the ECE needs to be deleted.
[0280] It should be noted that the above determination method is only exemplary, and in another embodiment, other methods can also be used to determine whether the key corresponding to the data protection mode needs to be deleted or restored. For example, assuming that the car machine device determines that the user has left the driver's seat, but the number of second devices in the same network as the car machine device has not decreased, it can be considered that the user is still in the car, and therefore it can be determined that the lock is not needed, and the car machine device can not delete the key corresponding to the data protection mode, and the process can be ended. It is not difficult to understand that in this case the file can still be accessed.
[0281] Based on the above-provided data processing method, the implementation process of the method will be described in detail in combination with another specific example. Here, the method is applied to the car machine device as an example for illustration, and the method can include the following parts or all the contents:
[0282] First, the business scenario is introduced. The car machine device can usually store some personal privacy data of the user, such as the user's location information, address book, etc. These personal privacy data can be file-level encrypted using ECE or SECE. The file creation and encryption process can be referred to the above Figure 6 The embodiments are not repeated here.
[0283] Since the car machine device usually does not have a screen locking mechanism, in order to ensure the effectiveness of the data protection mode, the file can be encrypted and decrypted in the following way:
[0284] Decryption phase:
[0285] 1. The car machine device obtains first object data.
[0286] For example, when a user wants to query a place that he / she visited last time, a navigation application in the car machine device can be opened. The navigation application can provide a query interface, which can provide a voice collection option that can be triggered by the user. After detecting the triggering operation on the voice collection option, the car machine module in the car machine device can enable the microphone to collect voice, such as the voice instruction of the user, which includes "please query the place that was visited last time". The car machine device obtains the user voiceprint feature data from the voice instruction, and takes the user voiceprint feature data as the first object data.
[0287] 2. The car machine device obtains second object data.
[0288] The authentication capability of the biometric management submodule of the car machine device is generally weak, and the user voiceprint feature data can be imitated. Therefore, the context awareness module can be triggered to query other management submodules to obtain other second object data in addition to the first object data, so as to verify the user identity in combination with the second object data.
[0289] In an embodiment, the car machine device can query a networking device management submodule to obtain state indication information of a second device in the same networking as the car machine device, such as a smart watch and a mobile phone, and query a sensor management submodule to obtain detection data detected by a sensor, such as body weight features detected by a gravity sensor, position information of a driver's seat, and driving speed of a vehicle. As an example, the body weight features can be used to indicate the behavior state of the user, such as whether the user has left the driver's seat. The position information of the driver's seat and the driving speed can be used to indicate the behavior habit of the user, such as the driving habit of the user.
[0290] 3. The first object data and the second object data are verified.
[0291] As an example, the car machine device can compare the user voiceprint feature data with pre-stored specified voiceprint feature data, which can be voiceprint feature data of a specified user. If the similarity between the user voiceprint feature data and the specified voiceprint feature data is greater than a specified threshold, it means that the user can be the same user as the specified user, so it can be determined that the verification of the first object data is passed. In this case, it can be determined that the first object data satisfies one data protection condition in the context awareness rule.
[0292] The specified voiceprint feature data can be pre-collected and stored in the car machine device according to actual needs, and the specified user corresponding to the specified voiceprint feature data is a user who can access the data in the car machine device, for example, the specified user is the owner of the vehicle where the car machine device is located.
[0293] The specified threshold can be set by the user according to actual needs, or can also be set by default by the car machine device, and the embodiments of the application do not limit this.
[0294] According to the state indication information, it is determined that the second device in the same networking as the car machine device is not in the unlocked state, and the detection data detected by the sensor indicates that the weight characteristics of the user currently sitting in the driver's seat, the driving speed of the user in a period of time, and the position of the current driver's seat are all consistent with those of the specified user. At this time, the car machine device determines that the second object data of the other management sub-module satisfies the other data protection condition in the context awareness rule, and can determine that the user is the specified user, that is, the user identity verification of the user is passed.
[0295] It should be noted that the above-mentioned second object data is only exemplary, and in another embodiment, the second object data can also include other object data. In the case where the plurality of management sub-modules further include a face recognition sub-module, the second object data can also include user face feature data. Further, assuming that the car machine device has and enables the lock screen mechanism, the second object data can include a lock screen event or an unlock event, such as the second object data being an unlock notification, and the embodiments of the application do not limit this.
[0296] 4. Determine to restore the key corresponding to the ECE according to the data protection result of the context awareness rule.
[0297] According to the context awareness rule, it can be determined that the data protection result corresponding to the above-mentioned data protection condition is decryption, so the car machine device needs to restore the key corresponding to the ECE.
[0298] As an example, the car machine device can regenerate the key corresponding to the ECE based on the root key of the ECE, and store the key in the memory. Then, the file key E ECE (E file ) can be decrypted to obtain the file key E file , and then the file can be decrypted using the file key E file to obtain the decrypted file text, which can also be referred to as file plaintext.
[0299] Further, the car machine device can display the file plaintext to the user after obtaining the file plaintext, or can also convert the file plaintext into voice data and play the voice data, so that the user obtains the information to be inquired.
[0300] The encryption stage includes:
[0301] 1. Obtain the first object data.
[0302] For example, the first object data includes user voiceprint feature data.
[0303] 2. Obtain the second object data.
[0304] For example, the state indication information of the second device in the network is obtained, such as the second device including a smart watch and a mobile phone, and the detection data detected by the sensor is obtained, such as the detection data including the weight feature detected by the gravity sensor, the position information of the driver's seat, and the driving speed of the vehicle.
[0305] 3. If the user voiceprint feature data meets one data protection condition in the context awareness rule, and the second object data meets other data protection conditions in the context awareness rule except for the one data protection condition, it is determined whether to delete or restore the key corresponding to the ECE.
[0306] In the case of voice instruction timeout, it is considered that the first object data meets one data protection condition in the context awareness rule, i.e., the data protection condition is the timeout of obtaining the user voiceprint feature data. Assuming that it is determined according to the state indication information that there is no second device in the network in the unlocked state, and the detection data detected by the sensor indicates that the weight feature of the user on the driver's seat, the driving speed of the user in a period of time, and the position of the current driver's seat are consistent with those of the specified user, the car machine device determines that the second object data of the other management sub-module meets other data protection conditions in the context awareness rule, and it is determined that the user is the specified user, i.e., the user identity verification of the user is passed.
[0307] 4. According to the data protection result of the context awareness rule, it is determined to delete the key corresponding to the ECE.
[0308] According to the context awareness rule, it is determined that the data protection result corresponding to the above data protection condition is encryption, so the car machine device needs to delete the key corresponding to the ECE. For example, the car machine device deletes the key E ECE corresponding to the ECE from the memory. In this way, the file encrypted by the ECE cannot be accessed.
[0309] According to the data processing method described in the above embodiment, Figure 12FIG. 1 is a structural block diagram of a data processing apparatus provided by an embodiment of the present application. For ease of illustration, only parts related to the embodiments of the present application are shown.
[0310] With reference to Figure 12 The apparatus comprises:
[0311] The obtaining module 1210 is configured to obtain first object data, the first object data being data related to a user feature, and the first object data not including a lock screen event and an unlock event.
[0312] The determining module 1220 is configured to, if the first object data satisfies one data protection condition in a context awareness rule, determine whether to delete or restore a key corresponding to a data protection mode according to the context awareness rule, the context awareness rule being used to determine whether a file encrypted by using the data protection mode can be accessed.
[0313] In a possible implementation of the present application, the context awareness rule comprises a plurality of data protection conditions, and the determining module 1220 is configured to:
[0314] obtain second object data associated with other data protection conditions in the plurality of data protection conditions except for the one data protection condition, the second object data being data related to a user feature, and the second object data being different from the first object data;
[0315] determine whether to delete or restore the key corresponding to the data protection mode in a case where the second object data satisfies the other data protection conditions in the context awareness rule.
[0316] In a possible implementation of the present application, the determining module 1220 is further configured to:
[0317] obtain second object data, the second object data being data related to a user feature, and the second object data being different from the first object data;
[0318] determine whether to delete or restore the key corresponding to the data protection mode in a case where the first object data satisfies one data protection condition in the context awareness rule and the second object data satisfies the other data protection conditions in the context awareness rule.
[0319] In a possible implementation of the present application, the determining module 1220 is configured to:
[0320] determine whether to delete or restore the key corresponding to the data protection mode according to a data protection result in the context awareness rule; or
[0321] Acquire a current state of the file encrypted by the data protection mode, and determine whether to delete or restore the key corresponding to the data protection mode according to the file state, wherein the state includes an encryption state or a decryption state.
[0322] In a possible implementation of the application, the first object data includes any one of the following object data:
[0323] User biological feature data;
[0324] Detection data detected by a sensor, the detection data being used to indicate a user behavior habit and / or a user behavior state;
[0325] State indication information of a second device in the same network as the first device, the state indication information being used to indicate that the second device has a screen locking event or a screen unlocking event.
[0326] In the embodiment of the application, the first object data related to the user feature is acquired, and the first object data does not include the screen locking event and the screen unlocking event. If the first object data satisfies one data protection condition in the context awareness rule, it can be considered that the user corresponding to the user feature can encrypt or decrypt the file encrypted by the data protection mode, so whether to delete or restore the key corresponding to the data protection mode can be determined according to the context awareness rule. That is, the method avoids the need to rely on the screen locking mechanism of the device, and can enable the data protection mode to be applied to a device without or without the screen locking mechanism.
[0327] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is exemplified, and in actual application, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for easy distinction, and do not limit the protection scope of the application. The specific working process of the units and modules in the system can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0328] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described or recorded in a certain embodiment can be referred to the related description of other embodiments.
[0329] Those skilled in the art can understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0330] In the embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented by other ways. For example, the system embodiments described above are only schematic, for example, the division of the modules or units is only a logical function division, and there can be another division way in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual coupling or direct coupling or communication connection between the units can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.
[0331] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0332] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0333] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the present application can implement all or part of the processes in the above-mentioned embodiment methods through a computer program to instruct related hardware to complete, and the computer program can be stored in a computer readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be implemented. The computer program includes computer program code, which can be in the form of source code, object code, executable files or some intermediate forms. The computer readable medium at least includes any entity or device capable of carrying the computer program code to the electronic device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium. For example, U disk, mobile hard disk, magnetic disk or optical disk, etc. In some jurisdictions, according to legislation and patent practice, the computer readable medium can not be an electrical carrier signal and a telecommunication signal.
[0334] Finally, it should be noted that: the above is only a specific implementation of the present application, but the protection scope of the present application is not limited to this, any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A data processing method, characterized by, The method applied to a first device comprises: obtaining first object data, the first object data being data related to user features, and the first object data not including a lock screen event and an unlock event; if the first object data satisfies one data protection condition in a context-aware rule, determining whether to delete or restore a key corresponding to a data protection mode according to the context-aware rule, the context-aware rule being used to determine whether a file encrypted by the data protection mode can be accessed; the context-aware rule includes a plurality of data protection conditions, and the determining whether to delete or restore the key corresponding to the data protection mode according to the context-aware rule comprises: obtaining second object data associated with other data protection conditions in the plurality of data protection conditions except the one data protection condition, the second object data being data related to user features, and the number of the second object data being one or more; in a case where the second object data satisfies the other data protection conditions in the context-aware rule, determining whether to delete or restore the key corresponding to the data protection mode; wherein the first object data includes any one of the following object data, and the second object data includes at least one of the following object data: user biological feature data; detection data detected by a sensor, the detection data being used to indicate user behavior habits and / or user behavior states; state indication information of a second device in a same network group as the first device, the state indication information being used to indicate that the second device has a lock screen event or an unlock event; wherein the second object data is different from the first object data.
2. The method of claim 1, wherein, The method further comprises: obtaining second object data, the second object data being data related to user features, and the second object data being different from the first object data; the context-aware rule includes a plurality of data protection conditions, and the if the first object data satisfies one data protection condition in the context-aware rule, determining whether to delete or restore a key corresponding to a data protection mode according to the context-aware rule comprises: in a case where the first object data satisfies one data protection condition in the context-aware rule and the second object data satisfies other data protection conditions in the context-aware rule, determining whether to delete or restore the key corresponding to the data protection mode.
3. The method of claim 1 or 2, wherein, The determining whether to delete or restore the key corresponding to the data protection mode comprises: determining whether to delete or restore the key corresponding to the data protection mode according to a data protection result in the context-aware rule; or obtaining a current state of a file encrypted by the data protection mode, and determining whether to delete or restore the key corresponding to the data protection mode according to the file state, wherein the state includes an encryption state or a decryption state.
4. A data processing apparatus, characterized by, The apparatus configured in a first device comprises: The acquisition module is configured to acquire first object data, the first object data being data related to a user feature, and the first object data not including a lock screen event and an unlock event. The determination module is configured to, if the first object data satisfies one data protection condition in a context-aware rule, determine whether to delete or restore a key corresponding to a data protection mode according to the context-aware rule, the context-aware rule being used to determine whether a file encrypted by using the data protection mode can be accessed. The context-aware rule includes a plurality of data protection conditions, and the determination module is configured to: acquire second object data associated with other data protection conditions in the plurality of data protection conditions except for the one data protection condition, the second object data being data related to a user feature, and the number of the second object data being one or more; determine whether to delete or restore the key corresponding to the data protection mode in a case where the second object data satisfies the other data protection conditions in the context-aware rule. The first object data includes any one of the following object data, and the second object data includes at least one of the following object data: user biological feature data; detection data detected by a sensor, the detection data being used to indicate a user behavior habit and / or a user behavior state; state indication information of a second device in a same network group as the first device, the state indication information being used to indicate that the second device has a lock screen event or an unlock event; The second object data is different from the first object data.
5. The apparatus of claim 4, wherein, The determination module is further configured to: acquire second object data, the second object data being data related to a user feature, and the second object data being different from the first object data; determine whether to delete or restore the key corresponding to the data protection mode in a case where the first object data satisfies one data protection condition in the context-aware rule and the second object data satisfies other data protection conditions in the context-aware rule.
6. The apparatus of claim 4 or 5, wherein, The determination module is configured to: determine whether to delete or restore the key corresponding to the data protection mode according to a data protection result in the context-aware rule; or acquire a current state of a file encrypted by using the data protection mode, and determine whether to delete or restore the key corresponding to the data protection mode according to the file state, wherein the state includes an encryption state or a decryption state.
7. An electronic device, a structure of the electronic device including a processor and a memory, the memory being used to store a program supporting the electronic device to execute the data processing method in any one of claims 1-3, and store data involved in the data processing method in any one of claims 1-3; the processor is configured to execute the program stored in the memory; the electronic device can further include a communication bus, the communication bus being used to establish a connection between the processor and the memory.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores instructions which, when executed on a computer, cause the computer to perform the method of any one of claims 1-3.
Citation Information
Patent Citations
A biometrics-based safe printing method and system
CN109375883A
Identity authentication method and device
CN111199032A