A mobile terminal based on application lock state and a locking method thereof
By configuring a secure desktop in the Android system and configuring the application list of the mobile terminal according to user permissions, the problem of not being able to adjust the secure desktop in the existing technology is solved, realizing dedicated use of the mobile terminal and improving security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- LIANXIN MOBEI SOFTWARE (BEIJING) CO LTD
- Filing Date
- 2022-04-11
- Publication Date
- 2026-05-29
AI Technical Summary
Existing Android system launchers cannot adjust the security desktop according to the user's actual work status, resulting in mobile terminals not being able to be used exclusively for work and thus having insufficient security.
The sending unit sends an identifier to the server, the receiving unit obtains an application list from the server, and the configuration unit configures a secure desktop based on permissions, allowing users to use only specified applications and presenting a password prompt to obtain permissions when a non-specified application is triggered.
It enables dedicated use of mobile terminals, preventing users from engaging in non-work-related activities, improving security and management permissions, and ensuring that mobile terminals are used only for work-related tasks.
Smart Images

Figure CN114780931B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of mobile communication technology, and in particular to a mobile terminal based on application lock status and its locking method. Background Technology
[0002] Android is one of the mainstream development platforms for mobile terminals (such as mobile phones, tablets, and laptops). The native Android system automatically runs a launcher called Launcher upon startup, entering a UI interface (usually called the "desktop") to await user interaction. In other words, as one of the main program components provided by default in the Android system, the launcher is used to launch the Android desktop. However, for users in enterprises and institutions, the Android system has not fully considered their specific security requirements. The launchers provided by existing Android systems do not differentiate between user access permissions, and this deficiency may prevent mobile terminals using the Android system from meeting users' security requirements. For example, mobile terminals issued to employees by enterprises for mobile office work are intended to improve work efficiency, but employees may use these terminals during work hours to connect to networks not permitted by their organization, or to watch videos or play online games. Since the operation of the mobile terminal depends entirely on the user's (such as the aforementioned employee's) own self-discipline, it cannot be guaranteed that the mobile terminal will only be used for work. Therefore, there is an urgent need for a new type of mobile terminal based on application lock status and its locking method.
[0003] For example, Chinese patent document CN103491082A discloses a method for presenting a secure desktop on a mobile terminal and a corresponding mobile terminal. The method includes the following steps: sending an identifier of the mobile terminal to a server, the identifier being associated with a user of the mobile terminal; receiving from the server an application list including one or more applications, the one or more applications being determined based on the user's permissions; configuring a secure desktop according to the application list, such that the user can only use the one or more applications in the application list on the secure desktop; and presenting the secure desktop to the user of the mobile terminal. However, this invention still has the following technical shortcomings: the secure desktop configured by the configuration unit of this invention can only be determined based on the user's permissions, that is, it cannot be adjusted based on the user's actual working state. Therefore, it is necessary to improve upon the shortcomings of the prior art.
[0004] Furthermore, on the one hand, there are differences in understanding among those skilled in the art; on the other hand, the applicant studied a large number of documents and patents when making this invention, but due to space limitations, not all details and contents were listed in detail. However, this does not mean that the present invention does not possess the features of these prior art. On the contrary, the present invention already possesses all the features of the prior art, and the applicant reserves the right to add relevant prior art to the background art. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this invention provides a mobile terminal based on application lock state. The mobile terminal includes at least a sending unit, a receiving unit, and a configuration unit.
[0006] The sending unit can send an identifier to the server. The identifier is associated with the user using the mobile terminal.
[0007] The receiving unit is configured to receive a list of applications, including one or more applications, from the server. The one or more applications are determined based on the user's permissions.
[0008] The configuration unit can configure a secure desktop based on an application list, allowing users to use only one or more applications from that desktop. This setting elevates the configuration unit's administrative privileges and locks specific applications to the secure desktop, ensuring the mobile device is dedicated to its intended use and effectively preventing users from using it for non-work-related tasks.
[0009] The configuration unit is configured to configure the secure desktop based on user permissions.
[0010] According to a preferred embodiment, a presentation unit is also included. The presentation unit is configured to at least present the secure desktop to a user using the mobile terminal.
[0011] According to a preferred embodiment, the presentation unit can also present a password prompt box to the user when a function other than one or more applications in the secure desktop is triggered, and present the interface of the function to the user when the user enters the correct password through the password prompt box.
[0012] According to a preferred embodiment, the functions in the secure desktop other than the one or more applications are system settings applications.
[0013] According to a preferred embodiment, the identifier is the International Mobile Equipment Identity (IMEI) of the mobile terminal.
[0014] The present invention also provides a locking method based on application lock status. The method includes: sending an identifier of the mobile terminal to a server, the identifier being associated with a user using the mobile terminal; and receiving from the server an application list including one or more applications, the one or more applications being determined based on the user's permissions.
[0015] According to a preferred embodiment, the method further includes: configuring a secure desktop based on the user's permissions and in conjunction with the application list, so that the user can only use one or more applications in the secure desktop; and presenting the secure desktop to the user using the mobile terminal.
[0016] According to a preferred embodiment, the method further includes: presenting a password prompt box to the user when a function other than one or more applications in the secure desktop is triggered, and presenting an interface of the function to the user when the user enters the correct password through the password prompt box.
[0017] According to a preferred embodiment, the functions in the secure desktop other than the one or more applications are system settings applications.
[0018] According to a preferred embodiment, the identifier is the International Mobile Equipment Identity (IMEI) of the mobile terminal. Attached Figure Description
[0019] Figure 1 This is a simplified schematic diagram of the module connection relationship of a preferred embodiment provided by the present invention.
[0020] List of reference numerals
[0021] 1: Transmitting unit; 2: Receiving unit; 3: Configuration unit. Detailed Implementation
[0022] The following is a detailed explanation with reference to the accompanying drawings.
[0023] Figure 1 A mobile terminal based on an application lock state is shown. The mobile terminal includes at least a sending unit 1, a receiving unit 2, and a configuration unit 3.
[0024] Sending unit 1 can send an identifier to the server. The identifier is associated with the user using the mobile terminal.
[0025] Receiving unit 2 is configured to receive a list of applications, including one or more applications, from the server. The one or more applications are determined based on the user's permissions.
[0026] Configuration unit 3 can configure a secure desktop based on an application list, allowing users to use only one or more applications from the secure desktop. Through this setting, configuration unit 3 can enhance its management privileges over applications and lock specified applications to the secure desktop, thus ensuring the mobile terminal is dedicated to its intended use and effectively preventing users from using the mobile terminal for non-work-related tasks.
[0027] Configuration unit 3 is configured to configure the secure desktop based on user permissions.
[0028] The mobile terminal may also include a presentation unit. The presentation unit is configured to present the secure desktop to at least a user using the mobile terminal.
[0029] Sending unit 1 is used to send the identifier of the mobile terminal to the server. This identifier is associated with the user of the mobile terminal.
[0030] For example, the identifier can be uniquely associated with a specific user of the mobile terminal through pre-configuration by the mobile terminal's super user or administrator. For instance, the identifier could be the mobile terminal's IMEI (International Mobile Equipment Identity).
[0031] Preferably, the transmitting unit 1 can be a central processing unit (CPU), digital signal processor (DSP), microprocessor, microcontroller, etc. of the mobile terminal. The transmitting unit 1 can cooperate with the transmitter and / or transceiver of the mobile terminal to send the identifier of the mobile terminal to the server.
[0032] Receiving unit 2 is used to receive a list of applications, including one or more applications, from the server. These one or more applications are determined based on the user's permissions.
[0033] For example, user permissions can be used to determine which applications a user is allowed to use.
[0034] Preferably, the receiving unit 2 can be a central processing unit (CPU), digital signal processor (DSP), microprocessor, microcontroller, etc. of the mobile terminal. The receiving unit 2 can be used in conjunction with the receiver and / or transceiver of the mobile terminal to receive an application list including one or more applications from the server.
[0035] Configuration unit 3 is used to configure the secure desktop according to the application list, so that users can only use one or more applications from the application list in the secure desktop.
[0036] Preferably, the configuration unit 3 can be a central processing unit (CPU), digital signal processor (DSP), microprocessor, microcontroller, etc. of the mobile terminal. The configuration unit 3 can be used in conjunction with the mobile terminal's storage device (such as a hard disk, floppy disk, optical disk, magnetic tape, etc.) to configure a secure desktop.
[0037] "Secure Desktop" is a term used in contrast to the traditional desktop that mobile terminals present to users after normal startup in existing technologies.
[0038] Mobile devices only allow users to use applications within the secure desktop.
[0039] Configuration unit 3 can be set up in the mobile terminal in the form of a security control procedure.
[0040] Configuration unit 3 or the security management program corresponding to configuration unit 3 can run on the mobile terminal as an administrator, so that the mobile terminal can automatically enter the security desktop configured by configuration unit 3 after powering on.
[0041] Configuration unit 3 has the highest management authority over the mobile terminal.
[0042] Users can authorize the corresponding management permissions for the mobile terminal through configuration unit 3.
[0043] Users can modify some system settings of the mobile terminal through Configuration Unit 3. For example, Configuration Unit 3 can use methods in the DevicePolicyManager class to fine-tune the configuration, security, and applications on the mobile terminal. Only one user can use a mobile terminal at a time.
[0044] Before configuring the secure desktop in configuration unit 3, the built-in device manager of the mobile terminal must be activated.
[0045] Configuration unit 3 activates the device manager of the mobile terminal through specific program code.
[0046] The specific program code can be Google's original official code.
[0047] Device Manager is a management tool inherent to mobile devices, enabling the control and management of mobile devices.
[0048] Configuration Unit 3 can manage and control mobile terminals using Device Manager.
[0049] For example, configuration unit 3 can use DeviceAdminReceiver (Android's official API) to activate the device manager of the mobile terminal.
[0050] Configuration unit 3 can also detect whether the device manager in the mobile terminal has been successfully activated.
[0051] When the device manager in the mobile terminal is successfully activated, configuration unit 3 can install the security management program corresponding to configuration unit 3 onto the mobile terminal.
[0052] Users can enable developer debugging mode on their mobile devices and connect them to their computers using a data cable to establish a data connection between the two devices.
[0053] Next, use the command prompt (cmd) to access the platform-tools utility scripts. The platform-tools utility scripts are files included with the Android development environment. They can be used as debugging tools for mobile devices on a computer.
[0054] Then, execute the following command via the command line: adb shell dpm set-device-owner+application package name / DeviceAdminReceiver class name.
[0055] Afterwards, the mobile terminal's display unit can show a prompt indicating whether the device manager has been successfully activated.
[0056] After the device manager built into the mobile terminal is activated, the user can log in to configuration unit 3 or the security management program corresponding to configuration unit 3 with an account / password. Then, configuration unit 3 or the security management program corresponding to configuration unit 3 will automatically execute a piece of program code, so that the mobile terminal displays the security desktop configured by configuration unit 3 after powering on.
[0057] After the security management program corresponding to configuration unit 3 is installed on the mobile terminal, configuration unit 3 or the security management program corresponding to configuration unit 3 can have the highest management authority to manage the mobile terminal.
[0058] Preferably, the configuration unit 3 or the security management program corresponding to the configuration unit 3 can invoke the hiding method. The hiding method is used to fix one or more applications to the secure desktop. In short, the configuration unit 3 completely locks or hides the original desktop of the mobile terminal, and displays the secure desktop configured by the configuration unit 3 through the presentation unit after the mobile terminal is powered on.
[0059] Preferably, when other applications not permitted by the secure desktop attempt to operate the mobile terminal, the mobile terminal will not respond to any operations by those other applications not permitted by the secure desktop.
[0060] With this configuration method, the secure desktop configured by configuration unit 3 can prevent the mobile terminal from returning to its original desktop when it is powered on or the back button is clicked. This fundamentally prevents users from using the mobile terminal for operations other than their intended work. In other words, the secure desktop configured by configuration unit 3 enables the mobile terminal to be used exclusively for its intended purpose.
[0061] The original desktop of a mobile terminal is the initial application desktop configured when the mobile terminal leaves the factory.
[0062] Preferably, the configuration unit 3 or the security management program corresponding to the configuration unit 3 can use different management strategies to manage the mobile terminal.
[0063] After the configuration unit 3 or the security management program corresponding to the configuration unit 3 completes the configuration of the secure desktop of the mobile terminal, the configuration unit 3 or the security management program corresponding to the configuration unit 3 can control the mobile terminal and prohibit the installation of applications not permitted by the configuration unit 3 or the security management program corresponding to the configuration unit 3.
[0064] After the configuration unit 3 or the security management program corresponding to the configuration unit 3 performs an escalation and locking operation on the mobile terminal, the user can only operate the applications in the secure desktop configured by the configuration unit 3, while the applications in the original desktop of the mobile terminal cannot be used by the user.
[0065] Users can install applications that are not currently available on the security desktop but are allowed to be installed by the security management program through the application store or backend management terminal built into the security management program corresponding to the configuration unit 3.
[0066] Other applications that have passed the security checks of configuration unit 3 or the security control program corresponding to configuration unit 3 can be uploaded to the aforementioned application store or backend management terminal.
[0067] Configuration unit 3 or the security control program corresponding to configuration unit 3 can lock all backdoors that allow data interaction between the mobile terminal and the external environment of the mobile terminal, so as to prevent users from performing unauthorized operations after the mobile terminal is connected to the computer (such as copying private apps from the mobile terminal to the computer).
[0068] The security management program corresponding to configuration unit 3 can be the Launcher in the Android system. However, the present invention is not limited to this; the security management program corresponding to configuration unit 3 can also be a desktop application in operating systems such as iOS, Windows Mobile, and Symbian.
[0069] The security control program corresponding to configuration unit 3 can be installed by the user in the form of software on the mobile terminal, or it can be installed by the terminal manufacturer in the form of hardware or firmware on the mobile terminal.
[0070] After the mobile terminal's system starts up (step S210), the mobile terminal sends its identifier to the server (step S220). This identifier is associated with the user of the mobile terminal.
[0071] Step S230: The server receives the identifier of the mobile terminal.
[0072] Step S240: The server determines the user of the mobile terminal based on the mobile terminal's identifier.
[0073] Step S250: The server determines an application list that includes one or more applications based on the user's permissions on the mobile terminal.
[0074] Step S260: The server sends the application list to the mobile terminal.
[0075] Step S270: The mobile terminal receives the application list from the server.
[0076] Step S280: The mobile terminal configures a secure desktop based on the application list, so that the user can only use one or more applications from the application list in the secure desktop.
[0077] Step S290: The mobile terminal presents a secure desktop to user A. User A can only use one or more applications from the application list on this secure desktop.
[0078] For example, in the mobile terminal applications used at a hospital nursing station, the server can determine the available applications for the user (e.g., a nurse) based on their permissions. For instance, it might send an application specifically designed for nurses to conduct ward rounds to the mobile terminal. The mobile terminal then configures and presents a secure desktop based on this ward rounds application, ensuring that the user can only use applications related to ward rounds and not other unrelated applications.
[0079] Preferably, users cannot delete or change the applications in the application list provided on the secure desktop.
[0080] When a user attempts to access functions not permitted by the secure desktop, the user can press the "Settings" button built into configuration unit 3, and the mobile terminal will enter a settings interface displaying a password prompt. The user can only access this settings interface after entering the correct password.
[0081] Preferably, if the user does not enter a password within a predetermined time, or enters the wrong password three times in a row, the mobile terminal will return to the secure desktop.
[0082] The password mentioned above can be preset by the mobile terminal's administrator, super user, or server, or it can be modified by the mobile terminal's administrator, super user, or server.
[0083] Such access restrictions ensure that only users who have been given the password can perform relevant settings operations on the mobile device, such as setting a WiFi password, erasing data, deleting applications, and restoring factory settings.
[0084] The presentation unit is used to present a secure desktop to the user.
[0085] Preferably, the presentation unit can also be used to: present a password prompt to the user when a function other than one or more applications in the secure desktop is triggered; and present the interface of the function to the user if the password is correct. This function can be a system settings application.
[0086] Preferably, the presentation unit can be a central processing unit (CPU), digital signal processor (DSP), microprocessor, microcontroller, etc. of the mobile terminal, which can cooperate with the mobile terminal's display (such as a liquid crystal display) and other output devices to present a secure desktop to the user.
[0087] Preferably, two or more different units in the mobile terminal can be logically or physically combined together. For example, transmitting unit 1 and receiving unit 2 can be combined into one unit.
[0088] Users of mobile devices can have permissions such as advanced administrative permissions and ordinary permissions.
[0089] The above embodiments implement the configuration of permissions for the user currently using the mobile terminal, allowing them to access the secure desktop of the mobile terminal. Only applications authorized by configuration unit 3 appear on the secure desktop, thus preventing the user from accessing applications outside their authorized scope. However, in many application scenarios, applications granted to the user do not provide unlimited access at all times, especially when some applications involve data association. Based on work requirements, mobile terminals often need to lock or unlock applications with or without user permissions based on application associations. For example, the secure desktop of user A's mobile terminal grants access to three applications: a, b, and c. Application a is an application that can access internal information data of user A's company; application b is an application that can translate and package the aforementioned information data; and application c is a chat or communication application that can communicate with the internet. In daily work, all three applications are open to user A. User A can normally use any one of these three applications. However, for the sake of protecting company information, once user A has collected company data using application a and then translated and packaged it using application b, it is necessary to restrict their continued use of application c, otherwise there will be a significant risk of data leakage.
[0090] In view of the above problems, the present invention provides a preferred embodiment, which includes at least the following steps:
[0091] S11: Record the running parameters of authorized and running applications;
[0092] S12: Calculate the attraction and / or repulsion parameters between an application that is running and an application that is not running or is unauthorized, based on the running parameters;
[0093] S13: Lock and / or unlock applications that are not running or are not authorized based on gravity and repulsion parameters.
[0094] The running parameters in step S11 reflect at least one operational parameter of an application that is currently running. For example, these running parameters could be the application's local time, runtime, frequency of execution, executed instructions, data transmission, etc. Furthermore, multiple running parameters of the same application or different applications are recorded in chronological order. The recording of these running parameters can display a list of events that generate at least one running parameter, where each point in time corresponds to the generation event of one or more running parameters from one or more applications.
[0095] In step S12, the attraction and repulsion parameters represent the cooperative or repulsive relationships between applications in a running state and those in a non-running or unauthorized state. These parameters can be represented by positive or negative values. The larger the absolute value of the attraction or repulsion parameter, the stronger the cooperative or repulsive relationship between the running and non-running / unauthorized applications. Preferably, step S13 can set multiple check values for the attraction and repulsion parameters. When a certain check value is reached, a corresponding subsequent action is performed. For example, a first check value and a second check value can be set for the attraction parameter. If the attraction parameter does not reach the first check value, no operation is performed; if the attraction parameter reaches or exceeds the first check value but is less than the second check value, applications in a non-running state that meet this condition are displayed in the application recommendation bar of the secure desktop, and can be arranged and displayed in descending order. When the gravitational force parameter reaches or exceeds the second checkpoint, applications that meet this condition but are not running will prompt the user with a pop-up recommendation asking if they want to launch them, and / or applications that meet this condition but are not authorized will be unlocked and displayed on the secure desktop. For example, a third and fourth checkpoint are set for the repulsion parameter. When the repulsion parameter does not reach the third checkpoint, no action is taken. When the repulsion parameter reaches or exceeds the third checkpoint but is less than the fourth checkpoint, applications that meet this condition but are authorized but not running will be opened, and the user will be required to provide reconfirmation information, which could be a re-entered username and password or re-authorization from an administrator. When the repulsion parameter reaches or exceeds the fourth checkpoint, applications that meet this condition and are running in the background will be forcibly closed from the background, and / or applications that are authorized but not in the background will be locked or hidden to prevent the user from accessing them.
[0096] A typical method for calculating attraction or repulsion parameters is integration. The mobile terminal's built-in program or dedicated controller is used to calculate the attraction and / or repulsion parameters between a specific application and applications that are already launched and / or running. The program or controller calculates the integral by referring to a preset correlation table and the currently recorded operating parameters. This integral represents the attraction and / or repulsion parameters of the current application. The integral can be positive or negative. For example, for application c, its correlation table pre-stores the following relationship: the runtime of application a is negatively correlated with the integral of application c. For example, for every 10 minutes that application a runs, the integral of application c increases by "-1"; if application c only has this relationship with application a, then if application a actually runs for 20 minutes, the integral of application c is -2. Based on the above description, application c possesses a repulsion parameter with a value of -2. For example, besides its relationship with application a, application c is also related to the runtime order of application b. For instance, if application b starts running after application a, the score of application c increases by -10. Furthermore, if application b is launched after application a is running, application c possesses a repulsion parameter with a value of at least -10. Combined with the aforementioned checkpoint settings, application c may have triggered the secondary repulsion protection mechanism (i.e., the situation described above where the fourth checkpoint is reached and exceeded) and is locked. The aforementioned correlation value table is actually a set of rules. Each rule can derive at least one integral item. The built-in program or dedicated controller of this mobile terminal obtains the attraction and / or repulsion parameters for an application by summarizing the integral items of various parallel rules. Preferably, when the same application possesses both attraction and repulsion parameters, the repulsion parameter protection mechanism is executed first to ensure the data security of this mobile terminal. The above-mentioned calculation schemes for gravitational and repulsive parameters can be upgraded. For example, a gravitational or repulsive model involving artificial intelligence can be constructed, and the calculation schemes for gravitational and repulsive parameters can be obtained by learning the correlation and repulsion instances between applications.
[0097] Therefore, this solution enables dynamic adjustment of the usage rights of one or more applications on a mobile terminal in running, authorized but not running, or unauthorized states based on user behavior data records. Furthermore, as applications run automatically, the solution can dynamically determine whether to unlock or lock applications based on the user's previous or current actions. In particular, it dynamically locks or unlocks other applications based on their sequential running records. This helps prevent specific events from occurring when a large number of applications are generally authorized, without affecting the user's normal use of the mobile terminal. Compared to existing secure desktops, this solution is more flexible and effectively reduces user restrictions (because in existing technologies, users may not have permission to do anything with a particular application, but in this solution, users can be granted general permissions to use the program).
[0098] It should be noted that the specific embodiments described above are exemplary. Those skilled in the art can devise various solutions inspired by the disclosure of this invention, and these solutions all fall within the scope of this invention and its protection. Those skilled in the art should understand that this specification and its accompanying drawings are illustrative and do not constitute a limitation on the claims. The scope of protection of this invention is defined by the claims and their equivalents. This specification contains multiple inventive concepts; terms such as "preferredly," "according to a preferred embodiment," or "optionally" indicate that the corresponding paragraph discloses an independent concept. The applicant reserves the right to file divisional applications based on each inventive concept. Throughout the text, features introduced by "preferredly" are merely optional and should not be construed as mandatory. Therefore, the applicant reserves the right to abandon or delete relevant preferred features at any time.
Claims
1. A mobile terminal based on application lock state, comprising: Configure the security desktop based on the application list so that users can only use the hives of one or more applications in the security desktop; Its features are, The mobile terminal dynamically adjusts the usage rights of one or more applications in a running, authorized but not running, or unauthorized state based on the user's behavioral data. Furthermore, as the application runs automatically, it dynamically determines whether to unlock or lock the application based on the user's previous or current actions. When the configuration unit obtains user permissions, the configuration unit is configured to record multiple running parameters of the same application or different applications that are authorized and in a running state in a time sequence based on user permissions. Based on the running parameters, the unit calculates the attraction and repulsion parameters between the running application and the application in a non-running or unauthorized state. The record of running parameters shows a list of events that generate at least one running parameter, where each point in time corresponds to the event that generates one or more running parameters of one or more applications. The system uses attraction and repulsion parameters to lock and unlock applications in a non-running or unauthorized state, thereby dynamically adjusting the secure desktop. The attraction and repulsion parameters represent the cooperative or repulsive relationships between running and non-running or unauthorized applications, respectively. A first and second checkpoint are set for the gravity parameter. When the gravity parameter does not reach the first checkpoint, no operation is performed. When the gravity parameter reaches or exceeds the first checkpoint but is less than the second checkpoint, applications that are not running are displayed in the application recommendation bar on the secure desktop. When the gravity parameter reaches or exceeds the second checkpoint, applications that are not running are prompted by a pop-up window to ask the user whether they need to be launched, and applications that are not authorized are unlocked and displayed on the secure desktop. A third and fourth checkpoint are set for the repulsion parameter. When the repulsion parameter does not reach the third checkpoint, no operation is performed. When the repulsion parameter reaches or exceeds the third checkpoint but is less than the fourth checkpoint, an authorized but not running application is opened, and the user is prompted to provide confirmation again. When the repulsion parameter reaches or exceeds the fourth checkpoint, applications already running in the background are forcibly closed, and authorized but not running applications are locked or hidden to prevent user access. The mobile terminal's built-in program or dedicated controller is used to calculate the attraction and repulsion parameters between an application and applications in the launched state and applications in the running state. The program or dedicated controller obtains the integral of the attraction and repulsion parameters of the current application by referring to the currently recorded working parameters according to the preset correlation value table.
2. The mobile terminal according to claim 1, characterized in that, It also includes a presentation unit, wherein the presentation unit is configured to at least present the secure desktop to a user using the mobile terminal.
3. The mobile terminal according to claim 2, characterized in that, The presentation unit can also present a password prompt box to the user when a function other than one or more applications in the secure desktop is triggered, and present the interface of the function to the user when the user enters the correct password through the password prompt box.
4. The mobile terminal according to claim 3, characterized in that, The functions in the secure desktop other than one or more applications are system settings applications.
5. The mobile terminal according to any one of claims 1 to 4, characterized in that, The identifier is the International Mobile Equipment Identity (IMEI) of the mobile terminal.
6. A locking method for a mobile terminal based on application lock state according to any one of claims 1 to 5, characterized in that, include: Send the identifier of the mobile terminal to the server, the identifier being associated with the user using the mobile terminal; Receiving a list of applications from a server, including one or more applications determined based on the user's permissions, wherein the step of dynamically adjusting the applications includes: Record the running parameters of authorized and running applications, calculate the attraction and repulsion parameters between running applications and applications that are not running or are not authorized based on the running parameters, and lock and unlock applications that are not running or are not authorized based on the attraction and repulsion parameters; the attraction and repulsion parameters are used to represent the cooperative or repulsive relationship between running applications and applications that are not running or are not authorized.
7. The method according to claim 6, characterized in that, Also includes: Based on the user's permissions and in conjunction with the application list, the security desktop is adjusted so that the user can only use one or more applications on the security desktop; The secure desktop is presented to the user using the mobile terminal.
8. The method according to claim 7, characterized in that, Also includes: When a function other than one or more applications in the secure desktop is triggered, a password prompt box is presented to the user, and the interface of the function is presented to the user if the user enters the correct password through the password prompt box.
9. The method according to claim 8, characterized in that, The functions in the secure desktop other than one or more applications are system settings applications.
10. The method according to any one of claims 6 to 9, characterized in that, The identifier is the International Mobile Equipment Identity (IMEI) of the mobile terminal.