Unlocking method and device, electronic equipment and readable storage medium

This technology uses a verification code provided by a trusted contact to generate a key for unlocking electronic devices, solving the problem of unlocking devices when users forget their lock screen password. It enables secure and convenient user data recovery and reduces the risk of data leakage.

CN115333733BActive Publication Date: 2025-12-30VIVO MOBILE COMM CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210969910.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-12
Publication Date
2025-12-30
Estimated Expiration
2042-08-12

AI Technical Summary

Technical Problem

When users forget their electronic device lock screen password, existing technologies cannot securely and conveniently unlock the device and recover user data, resulting in the user data becoming unusable and posing security risks.

Method used

By generating a second key corresponding to the first key from P verification codes provided by M trusted contacts, the second key is used to decrypt the encrypted lock screen password, thereby unlocking the electronic device and avoiding the synchronization of user data and complex cloud service operations.

Benefits of technology

It enables secure and convenient unlocking of electronic devices when the lock screen password is forgotten, ensuring that user data remains available, reducing the risk of data leakage, and avoiding the need to restore factory settings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115333733B_ABST
    Figure CN115333733B_ABST
Patent Text Reader

Abstract

The application discloses an unlocking method and device, electronic equipment and a readable storage medium, and belongs to the technical field of communication. The method comprises the following steps: in the case that a user forgets a lock screen password of the electronic equipment, the electronic equipment receives a first input of M first verification codes input by the user, the M first verification codes are provided by preset M trusted contacts, P first verification codes are the same as P target verification codes, the P target verification codes are verification codes used when a first key for generating a first lock screen password is generated, the first lock screen password is a current lock screen password of the electronic equipment, M and P are positive integers, and P is less than or equal to M; the electronic equipment generates a second key corresponding to the first key based on the P first verification codes in response to the first input; the electronic equipment decrypts first encrypted data by using the second key to obtain the first lock screen password, the first encrypted data is data obtained by encrypting the first lock screen password by using the first key; and the electronic equipment is unlocked by using the first lock screen password.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of communication technology, and specifically relates to an unlocking method, device, electronic device, and readable storage medium. Background Technology

[0002] With the development of terminal technology, electronic devices are being used more and more widely. Typically, electronic devices can encrypt user data by setting a password on the lock screen, thus protecting user privacy.

[0003] If a password is set for the lock screen and the user forgets it, they can reset the device by triggering a factory reset, allowing them to continue using the device. However, the user's original data on the device will become unusable because it is stored encrypted with the lock screen password. Since the user has forgotten the lock screen password, the encrypted data cannot be decrypted correctly. Summary of the Invention

[0004] The purpose of this application is to provide an unlocking method, device, electronic device, and readable storage medium that enables users to unlock electronic devices even if they forget their lock screen password and continue to use their user data without resetting the electronic device.

[0005] In a first aspect, embodiments of this application provide an unlocking method, comprising: when a user forgets the lock screen password of an electronic device, the electronic device receives a first input from the user, the first input being used to input M first verification codes, the M first verification codes being provided by M preset trusted contacts (the contact information of the trusted contacts can be a mobile phone number, email address, etc.), P of the M first verification codes being the same as P target verification codes, the P target verification codes being verification codes used when generating the first key of the first lock screen password, the first lock screen password being the current lock screen password of the electronic device, M and P being positive integers, and P being less than or equal to M; the electronic device responding to the first input generating a second key corresponding to the first key based on the P first verification codes; the electronic device using the second key to decrypt first encrypted data to obtain the first lock screen password, the first encrypted data being data encrypted with the first key using the first lock screen password; and the electronic device using the first lock screen password to unlock the electronic device.

[0006] Secondly, embodiments of this application provide an unlocking device, which may include: a receiving module and a processing module; the receiving module is configured to receive a first input from a user when the user forgets the lock screen password of the electronic device, the first input being used to input M first verification codes, the M first verification codes being provided by M preset trusted contacts, P of the M first verification codes being the same as P target verification codes, the P target verification codes being verification codes used when generating the first key of the first lock screen password, the first lock screen password being the current lock screen password of the electronic device, M and P being positive integers, and P being less than or equal to M; the processing module is configured to, in response to the first input received by the receiving module, generate a second key corresponding to the first key based on the P first verification codes; decrypt first encrypted data using the second key to obtain the first lock screen password, the first encrypted data being data encrypted with the first key using the first lock screen password; and unlock the electronic device using the first lock screen password; wherein, the first encrypted data is data encrypted with the first key using the first key.

[0007] Thirdly, embodiments of this application provide an electronic device including a processor and a memory, wherein the memory stores programs or instructions executable on the processor, and the programs or instructions, when executed by the processor, implement the steps of the method described in the first aspect.

[0008] Fourthly, embodiments of this application provide a readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect.

[0009] Fifthly, embodiments of this application provide a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run programs or instructions to implement the method as described in the first aspect.

[0010] In a sixth aspect, embodiments of this application provide a computer program product stored in a storage medium, which is executed by at least one processor to implement the method described in the first aspect.

[0011] In this embodiment, when a user forgets the lock screen password of their electronic device, the device can generate a second key corresponding to the first key by using P first verification codes from M pre-set trusted contacts (the user inputs the first verification codes). The second key is then used to decrypt the first encrypted data encrypted by the first key to obtain the current lock screen password, which can then be used to unlock the device. In other words, the device can be unlocked using the verification codes provided by trusted contacts, thus correctly decrypting the user data and ensuring its continued usability, without requiring the device to undergo a factory reset. Attached Figure Description

[0012] Figure 1 This is a flowchart illustrating the unlocking method provided in an embodiment of this application;

[0013] Figure 2 This is a schematic diagram of the communication between the electronic device and the management server in an embodiment of this application;

[0014] Figure 3 This is a schematic diagram of the unlocking device provided in the embodiments of this application;

[0015] Figure 4 This is one of the structural schematic diagrams of the electronic device provided in the embodiments of this application;

[0016] Figure 5 This is the second schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0017] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0018] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0019] The following section will first explain some of the terms or terms used in the claims and description of this application.

[0020] Personal Identification Number (PIN): Also known as a lock screen password. It is a security measure for electronic devices used to protect the data stored on them.

[0021] If an electronic device is enabled with a PIN code, a PIN code is required each time the device is powered on to unlock the screen.

[0022] Currently, electronic devices (such as mobile phones) can be unlocked using methods including screen lock passwords or PIN codes, fingerprint recognition, and facial recognition. Generally, screen lock passwords / PIN codes offer higher security than fingerprint and facial recognition. Therefore, after a restart, if the screen lock password / PIN code is not used within a preset time interval (e.g., 72 hours) after the device has been powered on, or if fingerprint or facial recognition fails multiple times (e.g., 5 times), a screen lock password / PIN code must be used to unlock the device to ensure the security of the data stored on it.

[0023] It is understandable that, in order to ensure the security of data in electronic devices and protect user privacy, in scenarios where unlocking electronic devices requires a lock screen password or PIN code, if the user forgets the lock screen password or PIN code, even if fingerprint or facial recognition is successful, the phone cannot be unlocked.

[0024] Trusted Execution Environment (TEE): A TEE is an independent and secure operating environment located within an electronic device. This environment is logically isolated from the Rich Execution Environment (REE), and the two can only interact through authorized Application Programming Interfaces (APIs). The TEE provides a secure execution environment for trusted applications (TAs), while also ensuring the confidentiality, integrity, and access rights of the TA's resources and data.

[0025] REE: is a general operating environment for electronic devices. A general operating system (OS) runs in the REE, such as Android or iOS.

[0026] Lock screen state: refers to the state in which the screen of an electronic device is lit up and displays the lock screen interface; that is, the state of the electronic device when the screen is lit up but not unlocked.

[0027] Lock screen: refers to the interface displayed on an electronic device when the screen is on and the device is not unlocked.

[0028] The following is an exemplary description of a solution to the problem of users forgetting their lock screen password in related technologies.

[0029] Solution 1:

[0030] Remotely reset your phone by logging into your cloud service account. If you need to recover user data from your phone, you must first sync the data to the cloud or your computer. However, if you choose to sync the data to the cloud, you may have concerns about data security; if you choose to sync the data to your computer, it is not convenient enough, because mobile phone users (especially elderly users) may not have their own independent computer.

[0031] Furthermore, remotely resetting a phone requires users to log in to a cloud service account. However, ordinary users, especially elderly users, may not necessarily register a cloud account, and the password for the cloud account is more difficult, making it harder for the elderly to remember.

[0032] Solution 2:

[0033] By restoring factory settings. Specifically, if a user forgets their lock screen password, they can reset their phone and use it again. However, the data originally stored on the electronic device will no longer be usable because it was encrypted with the lock screen password. Since the password has been forgotten, the encrypted data cannot be decrypted correctly, causing inconvenience to the user.

[0034] Solution 3:

[0035] The remote unlocking scheme includes the following steps 1 and 2:

[0036] Step 1, Remote unlocking preparation stage.

[0037] Step 1.1: Register the cloud service corresponding to your mobile phone and log in to the cloud service on your mobile phone;

[0038] Step 1.2: In your cloud service account, find the "My Phone" entry and manually enable the remote unlock function.

[0039] Step 2: Remote unlocking.

[0040] Step 2.1: When a user forgets their lock screen password, the user can trigger a successful login to the cloud service using their mobile phone.

[0041] Step 2.2: Verify the remote unlock password via cloud service. Specifically:

[0042] a) Users can remotely unlock their phones by clicking "Remote Unlock" on the cloud service website and re-entering their cloud service account password. If the phone is connected to the internet at this time, the cloud service can instruct the phone to revert to a state without a lock screen password, allowing the user to use the phone normally and continue using their original data.

[0043] b) If a user forgets their cloud service account password, the user can trigger the cloud service to send an SMS verification code to the Subscriber Identity Module (SIM) card bound to the cloud service account, usually the SIM card installed in the phone, to retrieve the cloud service account password; then, the user can use the above method a) to remotely unlock the phone.

[0044] While Solution 3 allows for remote unlocking, it also presents a serious security vulnerability. Specifically, when a phone is stolen or lost, an attacker could remove the SIM card, place it in another phone, and obtain the remote unlock password via SMS verification. This would allow them to remotely unlock the stolen / lost phone and access the user data stored on it.

[0045] Based on the above analysis, it can be seen that the operation of restoring user data in the mobile phone using Solution 1 is quite difficult; the factory reset of Solution 2 allows the electronic device to be used again, but the data originally stored in the electronic device cannot be used; and Solution 3 poses a significant security risk because when the mobile phone is lost, attackers may be able to remotely unlock the phone by forgetting the remote unlock password.

[0046] Based on the above discussion, the purpose of this application is to provide an unlocking method that allows users to conveniently and securely reset the lock screen password of their electronic devices while continuing to use the data stored on the devices normally. Specifically:

[0047] The electronic device generates P target verification codes (P being a positive integer less than or equal to M) based on the contact information of M trusted contacts within the TEE (Trusted Entities Environment). A first key is generated based on these P target verification codes, and the lock screen password of the electronic device is encrypted using the first key. The electronic device then stores the encrypted lock screen password, the P target verification codes, and the M contact information within the TEE, specifically in a storage area associated with the TEE. The electronic device can pre-send M verification codes (e.g., M second verification codes in this embodiment) to the M trusted contacts, and these M verification codes include the P target verification codes. Each of the M verification codes corresponds one-to-one with one of the M trusted contacts. In scenarios requiring a lock screen password to unlock the electronic device, such as when a user forgets their lock screen password, the electronic device can also prompt the user to obtain the corresponding verification code from the relevant trusted contact, for example, by displaying the name of the trusted contact. Thus, the user can quickly and accurately obtain the corresponding verification code from the relevant trusted contact based on the prompts from the electronic device and input it into the electronic device. After the electronic device receives M first verification codes provided by M trusted contacts from the user, the electronic device can generate a second key corresponding to the first key based on the P first verification codes that are the same as the P target verification codes among the M first verification codes; and unlock the encrypted lock screen password (e.g., the first lock screen password) with the second key to obtain the lock screen password; and use the lock screen password to unlock the electronic device.

[0048] Thus, since the electronic device can be unlocked based on the M initial verification codes entered by the user and the P target verification codes stored in the electronic device, there is no need for the user to back up their data to other devices in advance or remember related passwords (such as the password for a cloud service account). This allows for secure and convenient unlocking of the electronic device even if the lock screen password is forgotten, while ensuring that the user can continue to use the user data stored in the electronic device.

[0049] Optionally, to further enhance the security of unlocking the electronic device, the electronic device can store a portion of the target verification codes from P target verification codes (e.g., (PQ) target verification codes in this embodiment) and a portion of the contact information of trusted contacts from M trusted contacts (e.g., (MN) contact information in this embodiment) in the management server corresponding to the electronic device, and store the remaining target verification codes from P target verification codes and the remaining contact information from M contact information in the TEE. Thus, in scenarios requiring a lock screen password to unlock the electronic device, the electronic device can send a verification code (which can be a target verification code or a distractor code) to the trusted contact indicated by the contact information stored in the TEE, and send a notification message to the management server to notify the management server to send a second verification code (e.g., a target verification code stored in the management server or a distractor code sent by the electronic device) to each trusted contact indicated by the contact information stored in the management server. This allows the user to obtain the relevant verification code from the relevant trusted contact.

[0050] It should be noted that the interference code is generated in real time by the electronic device.

[0051] It is understood that the unlocking method provided in this application embodiment has at least the following beneficial effects:

[0052] 1. Users do not need to register for cloud services in advance; 2. Users do not need to synchronize user data from their electronic devices to the cloud or computer in advance. User data is always stored in the electronic device and never leaves the electronic device; 3. The electronic device unlock verification code is provided by at least two trusted (emergency) contacts, reducing the risk of user data leakage when the electronic device is stolen or lost.

[0053] The unlocking method provided in this application will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.

[0054] This application provides an unlocking method. Figure 1 A schematic diagram of a possible process for the unlocking method provided in an embodiment of this application is shown. Figure 1 As shown, the call capability monitoring method provided in this application embodiment may include steps 101 to 104 as described below. The following description uses an electronic device executing the method as an example.

[0055] Step 101: If the user forgets the lock screen password of the electronic device, the electronic device receives the user's first input.

[0056] The first input is used to input M first verification codes, which are provided by M pre-set trusted contacts. Among the M first verification codes, P first verification codes are the same as P target verification codes. The P target verification codes are the verification codes used by the electronic device when generating the first key of the first lock screen password. The first lock screen password is the current lock screen password of the electronic device. M and P are positive integers, and P is less than or equal to M.

[0057] It should be noted that electronic devices can receive the user's first input in scenarios where a lock screen password is required to unlock the device, and where the user has forgotten the lock screen password.

[0058] In this embodiment of the application, "the scenario where a lock screen password is required to unlock an electronic device" can be understood as: a scenario where a lock screen password must be entered to unlock the screen of an electronic device.

[0059] Optionally, "scenarios requiring a lock screen password to unlock electronic devices" may include at least one of the following: the first unlock after the electronic device is restarted, the electronic device has not been unlocked within a preset time interval (e.g., 72 hours) after being powered on, or multiple consecutive (e.g., 5) fingerprint or face recognition failures, etc. The specific scenario can be determined according to actual usage needs.

[0060] It is understandable that in scenarios where a lock screen password is required to unlock an electronic device, the electronic device is in a locked state.

[0061] Optionally, if the user forgets the electronic device's lock screen password, the electronic device is in a locked state, and the electronic device has its unlock function enabled, the electronic device can display an input box for entering M first verification codes, so that the user can enter M first verification codes in the input box (i.e., the electronic device receives the user's first input).

[0062] Optionally, the electronic device can enable the unlock function after the authentication conditions for enabling the unlock function are met. This ensures that only authorized users or the owner of the electronic device can enable this function.

[0063] The authentication conditions for enabling the unlock function can include: successful fingerprint recognition, successful facial recognition, or successful iris recognition, or any other authentication condition that can identify the authorized user or owner of the electronic device.

[0064] For example, if a user forgets their lock screen password, the electronic device can be triggered to perform facial recognition, and the device can then unlock itself after successful facial recognition.

[0065] It is understood that in this embodiment of the application, the electronic device can first generate a first key through P target verification codes, encrypt the first lock screen password of the electronic device based on the first key, and store the encrypted first lock screen password (i.e., the first encrypted data below).

[0066] It is understandable that storing the encrypted first lock screen password on an electronic device includes: the electronic device storing the encrypted first lock screen password in the TEE of the electronic device.

[0067] Step 102: The electronic device responds to the first input and generates a second key corresponding to the first key based on P first verification codes.

[0068] It should be noted that the first key and the second key can be a key pair.

[0069] For example, the first key can be a public key (Pub_Key), and the second key can be the corresponding private key (Pri_Key); or, the first key can be a public key, and the second key can be the corresponding private key.

[0070] Optionally, in this embodiment of the application, the electronic device can generate first data T based on P first verification codes and a first encryption algorithm, such as the scrypt algorithm, and then calculate a second key corresponding to the first key based on the data T according to an asymmetric encryption algorithm, such as the Ellipse Curve Ctyptography (ECC) algorithm.

[0071] In this embodiment of the application, if none of the M first verification codes entered by the user match the P target verification codes, or if the number of first verification codes that match the P target verification codes among the M first verification codes is less than P, then the electronic device cannot correctly generate the second key corresponding to the first key.

[0072] Optionally, in order to improve the success rate of decrypting the first encrypted data, step 102 above can be implemented through step 102a below.

[0073] Step 102a: If the number of verified codes that have passed trusted verification among the M first verification codes is greater than or equal to the target number, generate a second key based on the P first verification codes.

[0074] The target quantity refers to the number of target verification codes sent by the electronic device before receiving the first input.

[0075] In this embodiment of the application, "the number of verification codes that pass trusted verification among the M first verification codes is greater than or equal to the target number" means that the overlap between the M first verification codes entered by the user and the P target verification codes is relatively high. In other words, if the number of verification codes that pass trusted verification among the M first verification codes is less than the target number, it means that the electronic device cannot successfully unlock the screen of the electronic device based on the received M first verification codes.

[0076] Optionally, based on the target verification code stored in the electronic device, trusted verification can be performed on M first verification codes, meaning that the interference codes (such as the L interference codes described below) in the M first verification codes do not participate in trusted verification. In this case, when the number of verification codes that pass trusted verification among the M first verification codes equals the target number, the electronic device can generate a second key based on P first verification codes. Alternatively, trusted verification can be performed on the M first verification codes based on the target verification code and temporarily stored interference codes stored in the electronic device, meaning that the interference codes (such as the L interference codes described below) in the M first verification codes participate in trusted verification. In this case, when the number of verification codes that pass trusted verification among the M first verification codes is greater than the target number, the electronic device can generate a second key based on P first verification codes.

[0077] Optionally, when the M first verification codes include interference codes, the electronic device can discard the interference codes. For example, it can compare the M first verification codes with the interference codes stored in the electronic device, and discard the first verification codes that match successfully as interference codes. Then, the electronic device can use the remaining first verification codes as the P first verification codes. Of course, in actual implementation, the electronic device can also select the P first verification codes based on other methods.

[0078] It's understandable that, among the M initial verification codes, the remaining P codes are considered interference codes and do not participate in subsequent calculations. The purpose of these interference codes is to increase the security of the unlocking process and reduce the risk of attacks.

[0079] Thus, since the electronic device only generates the second key based on the P first verification codes when the number of verification codes that have passed trusted verification out of the M first verification codes is greater than or equal to the target number, it can avoid generating the key based on the received verification codes when the number of verification codes that have passed trusted verification out of the M first verification codes is less than the target number, thereby saving the power consumption of the electronic device.

[0080] Step 103: The electronic device uses the second key to decrypt the first encrypted data to obtain the first lock screen password.

[0081] The first encrypted data is the data encrypted with the first lock screen password using the first key.

[0082] Step 104: Unlock the electronic device using the first lock screen password.

[0083] It can be understood that unlocking an electronic device using a first lock screen password includes: unlocking the screen of the electronic device using the first lock screen password, and decrypting the file system of the electronic device based on the first lock screen password. That is, after unlocking the electronic device, the file system of the electronic device is in a plaintext state. This file system includes user data.

[0084] Thus, if a user forgets their electronic device's lock screen password, the device can generate a second key corresponding to the first key using P of the M first verification codes provided by the user's pre-set trusted contacts (which, along with the P target verification codes used when generating the first key for the first lock screen password). This second key is then used to decrypt the first encrypted data encrypted by the first key, yielding the current lock screen password. This password can then be used to unlock the electronic device. In other words, the device can be unlocked using the verification codes provided by trusted contacts, allowing the user's original data to remain usable without requiring a factory reset.

[0085] Optionally, prior to step 101 above, the unlocking method provided in this application embodiment may further include step 105 below.

[0086] Step 105: If the user forgets the lock screen password of the electronic device, the electronic device performs the first operation.

[0087] In this embodiment of the application, the first operation may include any one of the following operations 1 and 2:

[0088] Operation 1: The electronic device sends M encrypted second verification codes to M trusted contacts, wherein the M second verification codes include P target verification codes.

[0089] Operation 2: The electronic device sends N encrypted second verification codes to N trusted contacts respectively, and sends a notification message to the management server based on a secure transmission protocol. Among the N second verification codes, there may be Q target verification codes. The notification message is used to notify the management server to send (MN) encrypted second verification codes to (MN) trusted contacts respectively, where Q is a positive integer less than or equal to P, N is a positive integer less than M, and N is greater than or equal to Q.

[0090] It is understood that in operation 2, the management server stores at least the contact information of (MN) authorized contacts.

[0091] Optionally, if a user forgets the lock screen password of an electronic device, the electronic device can perform the first operation if it detects that the unlock function is enabled.

[0092] It should be noted that after the electronic device performs the first operation, each of the M trusted contacts can receive a second verification code. Then, the user can use a specific communication method, such as a call through another device, to speak with the M trusted contacts and obtain a first verification code from each contact. It can be understood that when a trusted contact receives a second verification code, and the user can obtain a second verification code from each trusted contact, the M second verification codes are identical to the M first verification codes.

[0093] Optionally, the secure transport protocol may include any of the following: Transport Layer Security (TLS), Internet Protocol Security (IPSec), Hyper Text Transfer Protocol over Secure Socket Layer (HTTPS), etc.

[0094] Optionally, in operation 2 above, when N equals P, it means that all P target verification codes can be contained in N second verification codes. That is, the verification code issued by the server is an interference code that does not participate in key generation. Alternatively, when N is less than P, the verification code issued by the server may include (PN) target verification codes. The specific details can be determined according to actual usage requirements, and this application embodiment does not impose any limitations.

[0095] Optionally, before step 105 above, the unlocking method provided in this application embodiment may further include step 106 below.

[0096] Step 106: The electronic device randomly generates L interference codes.

[0097] Among them, the M second verification codes include L interference codes and P target verification codes, M = P + L, where L is a positive integer.

[0098] It is understood that the interference codes in the embodiments of this application are all emitted from electronic devices. In other words, the management server does not store interference codes.

[0099] In this embodiment of the application, since the interference code in the M second verification codes is generated in real time by the electronic device, the risk of verification code leakage due to attack on the electronic device can be reduced, and the security of the process of unlocking the electronic device based on the verification code can be further improved.

[0100] Optionally, prior to step 101 above, the unlocking method provided in this application embodiment may further include steps 107 to 110 below.

[0101] Step 107: With the electronic device in an unlocked state, the electronic device receives a second input from the user.

[0102] The second input can be used to enter the first lock screen password and the contact information of M authorized contacts.

[0103] Optionally, the electronic device may receive a second input from the user while the electronic device is in an unlocked state.

[0104] For example, when the electronic device is unlocked and the aforementioned unlocking function is enabled, a prompt message is displayed asking the user to enter the first lock screen password and the contact information of M authorized contacts. Then, the user can enter the first lock screen password and the contact information of the M authorized contacts based on the prompt message and the unlocking requirements.

[0105] Optionally, the contact information of the credit contact person may include: telephone number, instant messaging account, email address, nickname, or any other information that can uniquely identify the credit contact person.

[0106] For example, a user can add the mobile phone numbers of M authorized contacts through a second input, such as A1, A2, ..., Am.

[0107] Step 108: The electronic device responds to the second input and generates P target verification codes based on the M contact information.

[0108] It should be noted that the M contact information refers to the contact information of the aforementioned M credit contacts, and there is a one-to-one correspondence between the M contact information and the M credit contacts.

[0109] It is understandable that P target CAPTCHAs can also be called P random factors.

[0110] For example, an electronic device can generate M-1 random factors, namely R1, R2, ..., Rm-1, based on M contact information added by the user. These M-1 (i.e., P = M-1) random factors will subsequently be called unlock verification codes, i.e., the P target verification codes mentioned above. When the user enables the unlock function, these unlock verification codes will be sent to the mobile phones of the authorized contacts via SMS. Of course, these unlock verification codes can be encrypted before sending the SMS to prevent them from being leaked.

[0111] In this embodiment of the application, each target verification code is associated with the contact information of one of the M trusted contacts.

[0112] Step 109: The electronic device generates a second key based on P target verification codes, and processes the second key to obtain the first key.

[0113] Optionally, in this embodiment, the electronic device can generate first data T based on P target verification codes and a first encryption algorithm, such as the scrypt algorithm, and then calculate a second key based on data T using an asymmetric encryption algorithm, such as the ECC algorithm. Thus, the electronic device can further calculate a first key corresponding to the second key based on the second key and using an asymmetric encryption algorithm, such as the ECC algorithm.

[0114] It can be seen that the method used by the electronic device to generate the second key based on P first verification codes is the same as the method used to generate the second key based on P target verification codes.

[0115] Step 110: The electronic device discards the second key and uses the first key to encrypt the first lock screen password to obtain the first encrypted data.

[0116] For example, the electronic device discards the private key (i.e., the second key) and uses the public key (i.e., the first key) to encrypt the first lock screen password, thus obtaining the ciphertext of the password / PIN code, which is the aforementioned first encrypted data.

[0117] Thus, when a user enters the initial lock screen password and M contact details, the electronic device can generate P target verification codes based on the M contact details, and then generate a key pair based on the P target verification codes. One key from the key pair is used to encrypt the initial lock screen password, yielding the first encrypted data. The other key is discarded. Therefore, even if the user forgets the initial lock screen password, the first encrypted data can be decrypted using the M initial verification codes entered by the user, yielding the initial lock screen password, which can then be used to unlock the electronic device. Furthermore, since the electronic device does not store the initial key, the risk of the initial encrypted data being cracked is reduced, thereby improving the security of the data within the electronic device.

[0118] Optionally, after step 110, the unlocking method provided in this application embodiment may further include the following step 111.

[0119] Step 111: The electronic device stores the first key, the first encrypted data, M contact information and P target verification codes.

[0120] In this embodiment of the application, since the electronic device can store a first key, first encrypted data, M contact information and P target verification codes, on the one hand, the risk of the first key, first encrypted data, M contact information and P target verification codes being stolen can be reduced, and on the other hand, it can facilitate users to securely unlock the electronic device if they forget their lock screen password.

[0121] Optionally, step 111 above can be implemented through steps 111a or 111b below.

[0122] Step 111a: The electronic device stores the first key, the first encrypted data, M contact information and P target verification codes in the electronic device.

[0123] For example, it is stored in the TEE of an electronic device.

[0124] In this embodiment of the application, step 111a corresponds to operation 1 described above. That is, after the electronic device executes step 111a, when the user forgets the lock screen password of the electronic device, the electronic device can send M second verification codes to M trusted contacts through operation 1 described above.

[0125] Step 111b: The electronic device stores the first key, the first encrypted data, N contact information entries, and Q target verification codes in its own device, and stores the encrypted (MN) contact information entries and the encrypted (PQ) target verification codes in the management server; where N is a positive integer less than M, Q is a positive integer less than or equal to P, and N is greater than or equal to Q.

[0126] In this embodiment of the application, the above-mentioned M credit contacts may include N credit contacts and (MN) credit contacts, where N and K are positive integers, and N+K=M.

[0127] Optionally, the electronic device stores the encrypted (MN) contact information and the encrypted (PQ) target verification codes in the management server by sending the encrypted (MN) contact information and the encrypted (PQ) target verification codes to the management server.

[0128] Optionally, in step 111b above, after the electronic device sends the encrypted (MN) contact information and the encrypted (PQ) target verification codes to the management server, the management server can store the encrypted (MN) contact information and the encrypted (PQ) target verification codes.

[0129] For example, the management server can store (MN) encrypted contact information and (PQ) encrypted target verification codes in the Trusted Application Manager (TAM) environment of the management server. Specifically, the management server can store (MN) encrypted contact information and (PQ) encrypted target verification codes in the TAM's area for storing unlocking information (TAM-unlock).

[0130] In this embodiment, step 111b corresponds to operation 2. That is, after the electronic device executes step 111a, when the user forgets the lock screen password of the electronic device, the electronic device can execute step 111a to make M trusted contacts receive M second verification codes. Thus, the user can obtain M first verification codes from the M trusted contacts through a specific communication method (such as voice communication).

[0131] Optionally, the first key can be used to encrypt the updated lock screen password when it is updated, forming third encrypted data, which is then used to update the first encrypted data. Specifically, after the user enters a new lock screen password, the electronic device can call the trusted unlocking application in the background, encrypt the new lock screen password using the first key, and use the ciphertext of the new lock screen password (i.e., the third encrypted data) to replace the ciphertext of the previous lock screen password (i.e., the first encrypted data) stored in the TEE. This implementation requires enhancement to the existing lock screen password update process. Thus, since the electronic device can encrypt the updated lock screen password using the first key when it detects a lock screen password update, it can ensure that the electronic device can obtain the most recently updated lock screen password based on the user-input verification code. This ensures that the electronic device can successfully unlock itself based on the user-input verification code, improving the reliability of unlocking the electronic device based on the verification code.

[0132] Optionally, after step 104 above, the unlocking method provided in this application embodiment may further include steps 112 and 113 as described below.

[0133] Step 112: The electronic device outputs a prompt message.

[0134] The aforementioned prompt message can be used to remind the user to reset the lock screen password.

[0135] Step 113: When the electronic device detects that the lock screen password has been updated to the second lock screen password, it uses the first key to encrypt the second lock screen password to obtain the second encrypted data, and then updates the first encrypted data to the second encrypted data.

[0136] Understandably, the purpose of the first key is to encrypt the lock screen password. Therefore, if the lock screen password is changed, the first key will encrypt the changed lock screen password.

[0137] Thus, since the electronic device can prompt the user to change the unlock password after unlocking the device based on the verification code entered by the user, the risk of the unlock password being leaked and stolen can be reduced, thereby improving the security of user data in the electronic device.

[0138] To better understand the unlocking method provided in the embodiments of this application, the specific process of the unlocking method provided in the embodiments of this application will be described in detail below.

[0139] For example, such as Figure 2 As shown, a new trusted application unlocking function, TA_unlock, is added to the TEE of the electronic device, and an API for unlocking trusted applications, namely the client call interface TA_unlockClient API, is added to the REE of the electronic device. A TAM unlocking function, TAM_unlock, is added to the TAM of the management server. Thus, by using TA_unlock, the TA_unlock Client API, and TAM_unlock, the electronic device can be unlocked when a user forgets their lock screen password or PIN code, ensuring the user can continue to use the user data on the electronic device, and allowing the user to reset their lock screen password or PIN code.

[0140] Understandable. Figure 2 The dashed arrows in the diagram represent communication between TA_unlock and TAM_unlock. Figure 2 The dashed lines in the diagram indicate that the REE and TEE of the electronic device are isolated from each other.

[0141] I. Unlocking Preparation Phase

[0142] For example, the unlocking preparation phase is implemented through steps 41 to 49 below.

[0143] Step 41: The electronic device receives the first lock screen password entered by the user.

[0144] It is understandable that users can enter a first lock screen password when the electronic device is unlocked, and the electronic device can then unlock itself after the user enters the first lock screen password.

[0145] Step 42: The electronic device receives the phone numbers (i.e., contact information) of M authorized contacts entered by the user. Specifically, assume the user has added M (M≥2) mobile phone numbers of authorized contacts, such as H1, H2, ..., Hm.

[0146] As can be seen, step 107 above can be specifically implemented through steps 41 and 42.

[0147] Step 43: The TA_unlock function in the electronic device generates P random factors (i.e., P target verification codes) based on the mobile phone numbers of the M trusted contacts added by the user, namely R1, R2, ..., Rp, where P is a positive integer less than or equal to M. It can be seen that step 108 above can be specifically implemented through step 43.

[0148] These P random factors will be referred to as unlock verification codes. When the user activates the unlock function, they will be sent to the authorized emergency contacts via SMS. Of course, when sending the SMS, other security methods such as encryption are required to ensure the security of the SMS transmission.

[0149] Step 44: TA_unlock generates data T using the first encryption algorithm, such as scrypt, based on P target verification codes, R1, R2, ..., Rn-1 (a total of P codes); and TA_unlock further calculates the second key (e.g., Pri_Key) using an asymmetric encryption algorithm, such as the ECC algorithm.

[0150] Step 45: TA_unlock calculates the first key (e.g., Pub_Key) corresponding to the second key based on the second key and using an asymmetric encryption algorithm, such as ECC.

[0151] As can be seen, step 109 above can be specifically implemented through steps 44 and 45.

[0152] Step 46: TA_unlock discards the second key.

[0153] Step 47: TA_unlock uses the first key to encrypt the first lock screen password, obtaining the ciphertext of the first lock screen password, which is the first encrypted data.

[0154] As can be seen, step 110 above can be implemented through steps 46 and 47.

[0155] Step 48: TA_unlock stores the first key and the first encrypted data in the TEE and performs the second operation.

[0156] Specifically, in one approach, TA_unlock stores the phone numbers of M trusted contacts and P target verification codes in the TEE. In another approach, TA_unlock stores the phone numbers of N trusted contacts and Q target verification codes in the TEE; and the electronic device calls TA_unlock via the TA_unlock Client API to send encrypted (MN) trusted contact phone numbers and encrypted (PQ) target verification codes to the management server, where Q is a positive integer less than or equal to P, N is a positive integer less than M, and N is greater than or equal to Q. The management server can then receive and store the encrypted (MN) trusted contact phone numbers and encrypted (PQ) target verification codes. For example, in another approach, the electronic device sends one target verification code (e.g., R1) and a user-added mobile phone number (e.g., H1) from R1, R2, ..., Rn-1 to the management server. Furthermore, to ensure the secure transmission of R1 and H1, a transport security mechanism, such as TLS, is required for transmitting R1 and H1.

[0157] The above step 111 can be specifically implemented through step 48.

[0158] Step 49: After TAM_unlock receives the encrypted (MN) phone numbers of the authorized contacts and the encrypted (PQ) target verification codes, such as R1 and H1, it can store the (MN) phone numbers of the authorized contacts and the encrypted (PQ) target verification codes.

[0159] II. Unlocking Phase

[0160] For example, the unlocking preparation phase is implemented through steps 51 to 63 described below.

[0161] Step 51: When the electronic device is locked, the user can trigger the device to unlock. It's understood that unlocking the electronic device requires fingerprint or facial recognition authentication to prevent unauthorized users from using this function.

[0162] Step 52: TA_unlock generates L interference codes.

[0163] It is understandable that when P is less than M, TA_unlock can generate L interference codes in an instant to ensure that each authorized contact corresponds to a verification code.

[0164] As can be seen, step 106 above can be specifically implemented through step 52.

[0165] Step 53: TA_unlock calls the SMS application running on the REE of the electronic device through the TA_unlock Client API, and notifies the SMS application to send N second verification codes, such as R2, ..., Rm-1 and Rm, to N trusted contacts in the form of SMS messages.

[0166] Step 54: The SMS application sends R2, ..., Rm-1 and Rm to N trusted contacts via SMS.

[0167] To prevent SMS messages containing target verification codes from being hijacked or eavesdropped on by fake base stations, encryption is used when sending SMS messages. Specifically, TA_unlock can encrypt each verification code that needs to be sent.

[0168] Step 55: TA_unlock sends a notification message to the management server, instructing TAM_unlock on the management server to send (MN) second verification codes to the (MN) trusted contacts corresponding to the K contact information in TAM_unlock. It should be noted that if TAM_unlock stores the target verification code, then the (MN) second verification codes include the target verification code in TAM_unlock; if TAM_unlock does not store the target verification code, then all (MN) second verification codes are interference codes.

[0169] In this embodiment of the application, TA_unlock and TAM_unlock communicate via a secure transport protocol.

[0170] Step 56: TAM_unlock sends (MN) second verification codes to (MN) trusted contacts. For example, TAM_unlock sends R1 (the target verification code stored in TAM_unlock) to the trusted contact corresponding to H1 (i.e., K=1) via SMS. To prevent SMS messages containing H1 from being hijacked or eavesdropped on by fake base stations, TAM_unlock can encrypt the sent SMS messages.

[0171] It is understood that steps 53 to 56 above are illustrated using the example of the management server participating in the unlocking process, that is, the first operation above includes operation 2 as an example. In actual implementation, when the first operation includes operation 1, TA_unlock can call the SMS application running in the REE of the electronic device through the TA_unlock Client API, notifying the SMS application to send M encrypted second verification codes to M trusted contacts in the form of SMS messages. These M second verification codes include L interference codes and P target verification codes. Thus, the SMS application can send the M second verification codes to the M trusted contacts in the form of SMS messages.

[0172] It can be seen that when the first operation includes operation 2, the above step 105 can be specifically implemented through steps 53 to 56.

[0173] Step 57: Users can obtain M first verification codes (e.g., the same as M second verification codes) from M authorized contacts by phone or other means, such as R1, R2, ..., Rm-1 and Rm.

[0174] It is understandable that after the electronic device calls the SMS application in TA_unlock, it can output a prompt message to ask the user to enter a verification code.

[0175] Step 58: The user inputs the M first verification codes obtained, such as R1, R2, ..., Rm-1 and Rm; that is, the electronic device receives the user's first input.

[0176] Step 59: TA_unlock performs trusted verification on the M first verification codes.

[0177] Step 60: If the number of verified codes that have passed trusted verification among the M first verification codes is greater than or equal to the target number, TA_unlock will perform an unlocking operation, as follows:

[0178] a) TA_unlock uses P of the received M first verification codes and a first encryption algorithm, such as scrypt, to generate data T. Then, TA_unlock uses an asymmetric encryption algorithm, such as ECC, to calculate the second key.

[0179] b) TA_unlock uses the second key to decrypt the first encrypted data and obtain the first lock screen password.

[0180] c) TA_unlock uses the first lock screen password to unlock the electronic device's screen and decrypts the file system. At this point, the file system exists in plaintext. It can be understood that the file system stores data encrypted by the first lock screen password from the electronic device.

[0181] It can be seen that step 102 can be implemented by a), step 103 by b), and step 104 by c).

[0182] Step 61: The electronic device outputs a prompt message to remind the user to reset a new lock screen password.

[0183] Step 62: The user enters a new lock screen password / PIN code, such as a second lock screen password.

[0184] Step 63: The electronic device uses the second lock screen password to encrypt the electronic device's file system, and calls TA_unlock via the TA_unlockClient API to encrypt the second lock screen password using the public key first key, and stores the encrypted second lock screen password (i.e., the second encrypted data). It is understood that the user is unaware of step 63.

[0185] In practice, after detecting an update to the lock screen password, the electronic device directly encrypts the updated key using the first key and stores the encrypted data in the TEE.

[0186] The unlocking method of this application embodiment enables users to securely and conveniently unlock their electronic devices even after forgetting their lock screen password, and to continue using the user data originally stored in the electronic devices. This can bring great convenience to users, especially elderly users.

[0187] It should be noted that the unlocking method provided in this application embodiment can be executed by an unlocking device or a control module within that unlocking device for executing the unlocking method. This application embodiment uses the example of an unlocking device executing the unlocking method to illustrate the unlocking device provided in this application embodiment.

[0188] This application provides an unlocking device. Figure 3 This paper illustrates a possible structural diagram of the unlocking device provided in an embodiment of this application, as shown below. Figure 3 As shown, the unlocking device 30 may include a receiving module 31 and a processing module 32. The receiving module 31 can receive a first input from the user when the user forgets the lock screen password of the electronic device. The first input may be M first verification codes, each provided by one of M pre-set trusted contacts. P of these first verification codes are identical to P target verification codes, which are the verification codes used when generating the first key for the first lock screen password. The first lock screen password is the current lock screen password of the electronic device. M and P are positive integers, and P is less than or equal to M. The processing module 32 can respond to the first input received by the receiving module 31 by generating a second key corresponding to the first key based on the P first verification codes; decrypting first encrypted data using the second key to obtain the first lock screen password; and unlocking the electronic device using the first lock screen password. The first encrypted data is the data encrypted with the first key using the first key.

[0189] In one possible implementation, the unlocking device may further include a sending module. The sending module can be used to perform a first operation before the receiving module 31 receives the user's first input. The first operation may include: the sending module sending M encrypted second verification codes to the M trusted contacts respectively, wherein the M second verification codes may include the P target verification codes; or, the sending module sending N encrypted second verification codes to N trusted contacts respectively, and sending a notification message to the management server based on a secure transmission protocol, wherein the N second verification codes may include Q target verification codes, and the notification message can be used to notify the management server to send (MN) encrypted second verification codes to (MN) trusted contacts respectively, where Q is a positive integer less than or equal to P, N is a positive integer less than M, and N is greater than or equal to Q.

[0190] In one possible implementation, the processing module 32 can also be used to randomly generate L interference codes before the sending module performs the first operation. The M second verification codes may include the L interference codes and the P target verification codes, where M = P + L, and L is a positive integer.

[0191] In one possible implementation, the processing module 32 can be used to generate a second key based on the P first verification codes when the number of verification codes that have passed trusted verification among the M first verification codes is greater than or equal to the target number; wherein, the target number is the number of target verification codes sent by the electronic device before receiving the first input.

[0192] In one possible implementation, the receiving module 31 can also be used to receive a second input from the user when the electronic device is in an unlocked state. The second input can be used to input a first lock screen password and contact information of the M authorized contacts. The processing module 32 can also be used to respond to the second input received by the receiving module 31, generate the P target verification codes based on the M contact information, generate a second key based on the P target verification codes, process the second key to obtain a first key, discard the second key, and encrypt the first lock screen password using the first key to obtain the first encrypted data.

[0193] In one possible implementation, the processing module 32 can also be used to store the first key, the first encrypted data, the M contact information and the P target verification codes after encrypting the first lock screen password with the first key and obtaining the first encrypted data.

[0194] In one possible implementation, processing module 32 can be used to store the first key, the first encrypted data, M contact information entries, and the P target verification codes in an electronic device; or, processing module 32 can be used to store the first key, the first encrypted data, N contact information entries, and Q target verification codes in an electronic device, and store the encrypted (MN) contact information entries and the encrypted (PQ) target verification codes in a management server. Here, N is a positive integer less than M, Q is a positive integer less than or equal to P, and N is greater than or equal to Q.

[0195] In one possible implementation, the first key can be used to encrypt the updated lock screen password when the lock screen password is updated, forming third encrypted data, so as to update the first encrypted data with the third encrypted data.

[0196] In one possible implementation, the unlocking device may further include an output module. The output module may be used to output a prompt message after the processing module 32 unlocks the electronic device using the first lock screen password. The prompt message may be used to prompt the user to reset the lock screen password. The processing module 32 may also be used to, upon detecting that the lock screen password has been updated to a second lock screen password, encrypt the second lock screen password using a first key to obtain second encrypted data, and update the first encrypted data to the second encrypted data.

[0197] Thus, if a user forgets their electronic device's lock screen password, a second key corresponding to the first key can be generated from P first verification codes (used in conjunction with the P target verification codes used when generating the first key for the first lock screen password) provided by the user's input and M pre-set trusted contacts. This second key is then used to decrypt the first encrypted data encrypted by the first key, yielding the current lock screen password. This password can then be used to unlock the electronic device. In other words, the electronic device can be unlocked using the verification codes provided by trusted contacts, allowing the user's original data to remain usable without requiring a factory reset.

[0198] The unlocking device in this application embodiment can be an electronic device or a component within an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices besides a terminal. For example, the electronic device can be a mobile phone, tablet computer, laptop computer, PDA, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc., network attached storage (NAS), personal computer (PC), television set (TV), ATM, or self-service machine, etc. This application embodiment does not specifically limit the specific device.

[0199] The unlocking device in this application embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit it.

[0200] The unlocking device provided in this application embodiment can achieve... Figure 1 and Figure 2 The various processes implemented in the method implementation examples will not be described again here to avoid repetition.

[0201] Optionally, such as Figure 4 As shown, this application embodiment also provides an electronic device 4000, including a processor 4001 and a memory 4002. The memory 4002 stores a program or instructions that can run on the processor 4001. When the program or instructions are executed by the processor 4001, they implement the various steps of the above-described electronic device-side method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.

[0202] It should be noted that the electronic devices in the embodiments of this application include the mobile electronic devices and non-mobile electronic devices described above.

[0203] Figure 5 A schematic diagram of the hardware structure of an electronic device to implement an embodiment of this application.

[0204] The terminal 7000 includes, but is not limited to, at least some of the following components: radio frequency unit 7001, network module 7002, audio output unit 7003, input unit 7004, sensor 7005, display unit 7006, user input unit 7007, interface unit 7008, memory 7009, and processor 7010.

[0205] Those skilled in the art will understand that the terminal 7000 may also include a power supply (such as a battery) for supplying power to various components. The power supply may be logically connected to the processor 7010 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system. Figure 5 The terminal structure shown does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0206] The user input unit 7007 can receive a first input from the user when the user forgets the lock screen password of the electronic device. The first input can be used to input M first verification codes, which are provided by M pre-set trusted contacts. P of the M first verification codes are the same as P target verification codes, which are the verification codes used when generating the first key of the first lock screen password. The first lock screen password is the current lock screen password of the electronic device. M and P are positive integers, and P is less than or equal to M. The processor 7010 can respond to the first input received by the user input unit 7007, generate a second key corresponding to the first key based on the P first verification codes; decrypt the first encrypted data using the second key to obtain the first lock screen password, where the first encrypted data is the data encrypted with the first key using the first lock screen password; and unlock the electronic device using the first lock screen password.

[0207] In one possible implementation, the radio frequency unit 7001 can be used to perform a first operation before the user input unit 7007 receives the user's first input. The first operation may include: the radio frequency unit 7001 sending M encrypted second verification codes to the M trusted contacts respectively, wherein the M second verification codes may include the P target verification codes; or, the radio frequency unit 7001 sending N encrypted second verification codes to N trusted contacts respectively, and sending a notification message to the management server based on a secure transmission protocol, wherein the N second verification codes may include Q target verification codes, and the notification message may be used to notify the management server to send (MN) encrypted second verification codes to (MN) trusted contacts respectively, where Q is a positive integer less than or equal to P, N is a positive integer less than M, and N is greater than or equal to Q.

[0208] In one possible implementation, the processor 7010 can also be used to randomly generate L interference codes before the radio frequency unit 7001 performs the first operation. The M second verification codes may include the L interference codes and the P target verification codes, where M = P + L, and L is a positive integer.

[0209] In one possible implementation, the processor 7010 can be used to generate a second key based on the P first verification codes when the number of verification codes that have passed trusted verification among the M first verification codes is greater than or equal to a target number; wherein the target number is the number of target verification codes sent by the electronic device before receiving the first input.

[0210] In one possible implementation, the user input unit 7007 can also be used to receive a second input from the user when the electronic device is in an unlocked state. The second input can be used to input a first lock screen password and contact information of the M trusted contacts. The processor 7010 can also be used to respond to the second input received by the user input unit 7007, generate the P target verification codes based on the M contact information, generate a second key based on the P target verification codes, process the second key to obtain a first key, discard the second key, and encrypt the first lock screen password using the first key to obtain the first encrypted data.

[0211] In one possible implementation, the processor 7010 can also be used to store the first key, the first encrypted data, the M contact information and the P target verification codes after encrypting the first lock screen password with the first key to obtain the first encrypted data.

[0212] In one possible implementation, processor 7010 can be used to store the first key, the first encrypted data, the M contact information entries, and the P target verification codes in an electronic device; or, processor 7010 can be used to store the first key, the first encrypted data, the N contact information entries, and the Q target verification codes in an electronic device, and store the encrypted (MN) contact information entries and the encrypted (PQ) target verification codes in a management server. Here, N is a positive integer less than M, Q is a positive integer less than or equal to P, and N is greater than or equal to Q.

[0213] In one possible implementation, the first key can be used to encrypt the updated lock screen password if the lock screen password is updated.

[0214] In one possible implementation, the display unit 7006 or the audio output unit 7003 can be used to output a prompt message after the processor 7010 unlocks the electronic device using the first lock screen password. The prompt message can be used to prompt the user to reset the lock screen password. The processor 7010 can also be used to encrypt the second lock screen password using the first key to obtain the second encrypted data when it detects that the lock screen password has been updated to the second lock screen password, and update the first encrypted data to the second encrypted data.

[0215] Thus, if a user forgets their electronic device's lock screen password, a second key corresponding to the first key can be generated from P first verification codes (used in conjunction with the P target verification codes used when generating the first key for the first lock screen password) provided by the user's input and M pre-set trusted contacts. This second key is then used to decrypt the first encrypted data encrypted by the first key, yielding the current lock screen password. This password can then be used to unlock the electronic device and correctly decrypt the user's data. In other words, the electronic device can be unlocked using the verification codes provided by trusted contacts, allowing the user to continue using the data stored on the device without requiring a factory reset.

[0216] It should be understood that, in this embodiment, the input unit 7004 may include a graphics processing unit (GPU) 7041 and a microphone 7042. The GPU 7041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 7006 may include a display panel 7061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 7007 includes at least one of a touch panel 7071 and other input devices 7072. The touch panel 7071 is also called a touch screen. The touch panel 7071 may include a touch detection device and a touch controller. Other input devices 7072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described in detail here.

[0217] The memory 7009 can be used to store software programs and various data. The memory 7009 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 7009 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 7009 in the embodiments of this application includes, but is not limited to, these and any other suitable types of memory.

[0218] Processor 7010 may include one or more processing units; optionally, processor 7010 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 7010.

[0219] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described unlocking method embodiments and achieve the same technical effect. To avoid repetition, they will not be described again here.

[0220] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0221] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described unlocking method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0222] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0223] This application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the unlocking method embodiments described above, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0224] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0225] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software (program) plus necessary general-purpose hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer program product. This computer software (program) product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0226] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. An unlocking method, characterized by, The method comprises: In the case that the user forgets the lock screen password of the electronic device, the electronic device receives a first input of the user, the first input is used for inputting M first verification codes, the M first verification codes are respectively provided by preset M trusted contacts, P first verification codes in the M first verification codes are the same as P target verification codes, the verification codes other than the P first verification codes in the M first verification codes are interference codes, the interference codes are interference codes randomly generated by the electronic device and provided to the trusted contacts, the P target verification codes are verification codes used when a first key of a first lock screen password is generated, the first lock screen password is a current lock screen password of the electronic device, M and P are positive integers, and P is less than M; The electronic device discards the interference codes in the M first verification codes in response to the first input, and generates a second key corresponding to the first key based on the P first verification codes; The electronic device decrypts first encrypted data by using the second key to obtain the first lock screen password, the first encrypted data is data encrypted by using the first key on the first lock screen password; The electronic device unlocks the electronic device by using the first lock screen password.

2. The method of claim 1, wherein, Before the receiving the first input of the user, the method further comprises: The electronic device performs a first operation; The first operation comprises: The electronic device sends encrypted M second verification codes to the M trusted contacts respectively, wherein the P target verification codes are included in the M second verification codes; Or, the electronic device sends encrypted N second verification codes to N trusted contacts respectively, and sends a notification message to a management server based on a secure transmission protocol, wherein Q target verification codes are included in the N second verification codes, the notification message is used to notify the management server to send encrypted (M-N) second verification codes to (M-N) trusted contacts respectively, Q is a positive integer less than or equal to P, N is a positive integer less than M, and N is greater than or equal to Q.

3. The method of claim 2, wherein, Before the electronic device performs the first operation, the method further comprises: The electronic device randomly generates L interference codes; The L interference codes and the P target verification codes are included in the M second verification codes, and M=P+L, L is a positive integer.

4. The method according to any one of claims 1 to 3, characterized in that, The generating of the second key corresponding to the first key based on the P first verification codes comprises: In the case that the number of verification codes verified by trusted verification in the M first verification codes is greater than or equal to a target number, the second key is generated based on the P first verification codes; The target number is the number of target verification codes sent by the electronic device before receiving the first input.

5. The method of claim 1, wherein, The method further comprises: In the case that the electronic device is in an unlocked state, the electronic device receives a second input of the user, the second input is used for inputting the first lock screen password and contact information of the M trusted contacts; The electronic device generates the P target verification codes according to M contact information in response to the second input; The electronic device generates the second key based on the P target verification codes, and processes the second key to obtain the first key; The electronic device discards the second key, and encrypts the first lock screen password by using the first key to obtain the first encrypted data.

6. The method of claim 5, wherein, After the step of encrypting the first lock screen password by using the first key to obtain the first encrypted data, the method further comprises: The electronic device stores the first key, the first encrypted data, the M contact information, and the P target verification codes.

7. The method of claim 6, wherein, The electronic device stores the first key, the first encrypted data, the M contact information, and the P target verification codes, comprising: The electronic device stores the first key, the first encrypted data, the M contact information, and the P target verification codes in the electronic device; or, The electronic device stores the first key, the first encrypted data, N contact information, and Q target verification codes in the electronic device, and stores the encrypted (M-N) contact information and the encrypted (P-Q) target verification codes in a management server; Wherein, N is a positive integer less than M, Q is a positive integer less than or equal to P, and N is greater than or equal to Q.

8. The method according to claim 6 or 7, characterized in that, The first key is used to encrypt the updated lock screen password to form third encrypted data when the lock screen password is updated, so as to update the first encrypted data to the third encrypted data.

9. The method of claim 1, wherein, After the step of unlocking the electronic device by using the first lock screen password, the method further comprises: The electronic device outputs prompt information, and the prompt information is used to prompt the user to reset the lock screen password; The electronic device encrypts the second lock screen password by using the first key to obtain second encrypted data when detecting that the lock screen password is updated to a second lock screen password, and updates the first encrypted data to the second encrypted data.

10. An unlocking device characterized by comprising: The device comprises a receiving module and a processing module; The receiving module is configured to receive a first input of a user in a case where the user forgets a lock screen password of an electronic device, the first input being used to input M first verification codes, the M first verification codes being provided by M preset trusted contacts respectively, P first verification codes in the M first verification codes being the same as P target verification codes, and verification codes in the M first verification codes other than the P first verification codes being interference codes, the interference codes being interference codes randomly generated by the electronic device and provided to the trusted contacts, the P target verification codes being verification codes used when a first key of a first lock screen password is generated, the first lock screen password being a current lock screen password of the electronic device, M and P being positive integers, and P being less than M. The processing module is configured to, in response to the first input received by the receiving module, discard the interference codes in the M first verification codes, generate a second key corresponding to the first key based on the P first verification codes, decrypt first encrypted data by using the second key to obtain the first lock screen password, and use the first lock screen password to unlock the electronic device, wherein the first encrypted data is data obtained by encrypting the first lock screen password by using the first key. The first encrypted data is data obtained by encrypting the first lock screen password by using the first key.

11. The apparatus of claim 10, wherein, The apparatus further includes a sending module. The sending module is configured to perform a first operation before the receiving module receives the first input of the user. The first operation includes that the sending module sends encrypted M second verification codes to the M trusted contacts respectively, wherein the P target verification codes are included in the M second verification codes. Alternatively, the sending module sends encrypted N second verification codes to N trusted contacts respectively, and sends a notification message to a management server based on a secure transmission protocol, wherein Q target verification codes are included in the N second verification codes, the notification message is used to notify the management server to send encrypted (M-N) second verification codes to (M-N) trusted contacts, Q is a positive integer less than or equal to P, N is a positive integer less than M, and N is greater than or equal to Q.

12. The apparatus of claim 11, wherein, The processing module is further configured to randomly generate L interference codes before the sending module performs the first operation. The M second verification codes include the L interference codes and the P target verification codes, and M = P + L, wherein L is a positive integer.

13. The apparatus of any one of claims 10 to 12, wherein The processing module is specifically configured to generate the second key based on the P first verification codes in a case where a number of first verification codes that pass the trusted verification in the M first verification codes is greater than or equal to a target number. The target number is a number of target verification codes sent by the electronic device before the first input is received.

14. The apparatus of claim 10, wherein, The receiving module is further configured to receive a second input of the user in a case where the electronic device is in an unlocked state, wherein the second input is used to input the first lock screen password and contact information of the M trusted contacts. The processing module is further configured to, in response to the second input received by the receiving module, generate the P target verification codes according to the M contact information, generate the second key based on the P target verification codes, and process the second key to obtain the first key. The processing module is further configured to, in response to the second input received by the receiving module, generate the P target verification codes according to the M contact information, generate the second key based on the P target verification codes, and process the second key to obtain the first key.

15. The apparatus of claim 14, wherein, The processing module is further configured to, after encrypting the first lock screen password by using the first key to obtain the first encrypted data, store the first key, the first encrypted data, the M contact information, and the P target verification codes.

16. The apparatus of claim 15, wherein, The processing module is specifically configured to store the first key, the first encrypted data, the M contact information and the P target verification code in the electronic device; or, The processing module is specifically configured to store the first key, the first encrypted data, N contact information and Q target verification code in the electronic device, and store encrypted (M-N) contact information and encrypted (P-Q) target verification code in a management server. N is a positive integer less than M, Q is a positive integer less than or equal to P, and N is greater than or equal to Q.

17. The apparatus of claim 15 or 16, wherein, The first key is used to encrypt the updated lock screen password to form third encrypted data when the lock screen password is updated, so as to update the first encrypted data to the third encrypted data.

18. The apparatus of claim 10, wherein, The device further comprises an output module. The output module is configured to output a prompt information after the processing module uses the first lock screen password to unlock the electronic device, and the prompt information is used to prompt the user to reset the lock screen password. The processing module is further configured to, when detecting that the lock screen password is updated to a second lock screen password, encrypt the second lock screen password by using the first key to obtain second encrypted data, and update the first encrypted data to the second encrypted data.

19. An electronic device, comprising: The device comprises a processor and a memory, the memory stores programs or instructions executable on the processor, and the programs or instructions are executed by the processor to implement the steps of the unlocking method according to any one of claims 1 to 9.

20. A readable storage medium, characterized by, The readable storage medium stores programs or instructions, and the programs or instructions are executed by the processor to implement the steps of the unlocking method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Terminal security protection method and system

    CN103338443A

  • Password acquiring method and electronic equipment

    CN106845181A