Data processing terminal and associated method for locking, intermediate and unlocking modes

CN115659362BActive Publication Date: 2026-09-22郑在落 +2
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
CN202211232577.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2016-08-25
Filing Date
2017-08-23
Publication Date
2026-09-22
Estimated Expiration
2037-08-23

AI Technical Summary

Technical Problem

但不能为了提供更高的安全、更高的完整性、加强的个人信息保护而牺牲数据处理终端的便利性

Benefits of technology

[0023]要解决的技术问题

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115659362B_ABST
    Figure CN115659362B_ABST
Patent Text Reader

Abstract

The present specification relates to a data processing apparatus capable of being driven in a plurality of modes endowed with a plurality of access rights capable of accessing a plurality of hardware elements or software elements. In particular, the terminal includes a lock system driven in a lock mode and a main system driven in an unlock mode. Also, in the case where the terminal moves from the lock mode with narrow access rights to the unlock mode with wide access rights, a part or all of a product obtained by executing a lock job in the lock mode can be erased. In the case where, as above, before moving to the unlock mode, malicious computer codes that can have infiltrated into the product are erased, the terminal can not only enhance security, integrity, etc., but also prevent important data stored in the terminal from being lost or disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of Chinese patent application No. 2017800660075, filed on August 23, 2017, entitled "Data Processing Terminal and Related Method Thereof in Locked, Intermediate and Unlocked Modes". Technical Field

[0002] This specification relates to various data processing terminals capable of being driven by more than one hierarchy across multiple operating modes, wherein the terminals can grant different access permissions to users in different operating modes. When the terminal receives appropriate user input (or specific input), it can move the user from the current mode to a new mode.

[0003] The aforementioned "current mode" includes "powered-off state" (i.e., the terminal cannot communicate and the imaging unit is also off), "off-state" (for example, the terminal is in a "powered-on state" that can communicate, but the imaging unit is off), and one of multiple modes defined by a specific layer (for example, a "powered-on state" mode where the imaging unit is lit up).

[0004] Examples of the "new mode" include a power-off state, a closed state, an open state, and one of the multiple modes defined by the hierarchy. Furthermore, this specification relates to various units, hardware elements, and software elements of the terminal, which may allow or deny the user from moving from the current mode to a new mode. This specification also relates to various configurations of the units, hardware elements, and software elements used to implement and enforce mode movement.

[0005] Furthermore, this specification relates to various methods for providing a data processing terminal capable of being driven in multiple (operating) modes, various methods for driving the terminal in multiple modes, various methods for moving from a current mode to a new mode, and methods for granting a user one of a variety of access permissions to enable the user to move from a current mode to a new mode or to enable the user to drive specific hardware or software elements in a specific mode.

[0006] This specification relates to methods for constructing multiple hierarchical structures that define different operating modes, methods for arranging said modes in a specific hierarchy, and methods for assigning the same, similar, different, or comparable access permissions to each mode. This specification relates to methods for allowing (or denying) a user to move from a current mode to a specific mode, methods for allowing (or denying) a user to move from one mode in a specific hierarchy to other modes in the same hierarchy, methods for allowing (or denying) access to or driving specific hardware or software elements based on the access permissions attached to each mode, and methods for constructing multiple hierarchical structures that define multiple modes, etc.

[0007] Therefore, this specification relates to multiple data processing terminals that include not only one or more "main systems" but also one or more "lock systems" or "intermediate systems," thereby providing users with enhanced security, integrity, and personal information protection. The main system typically includes various hardware or software elements that enable users to run multiple unlocking operations in unlock mode. Conversely, the lock (or intermediate) system typically includes one or more hardware or software elements that are physically or operationally isolated from the main system.

[0008] Therefore, the terminal can prevent the products generated by driving the hardware or software elements of the main system in lock mode from negatively impacting the hardware or software elements of the main system. Through this physical or operational isolation, the terminal allows users to run multiple tasks in lock (or intermediate) mode without worrying about potential adverse effects on the security, integrity, or personal information protection of the main system.

[0009] Therefore, this specification describes various configurations including the main system and the locking system, such as various data processing terminals, various units of the main system and the locking system, hardware elements and software elements; various methods for physically or operationally isolating the locking or intermediate (or main) system from the main (or locking, intermediate) system; and various configurations for completely (or partially) isolating the locking or intermediate (or main) system from the main (or locking, intermediate) system. This specification also describes methods for ensuring physical or operational isolation between the main system and the locking (or intermediate) system, and various methods for "erasing" or "semi-erasing" potential hazards or unnecessary consequences remaining in the locking (or intermediate) system before, during, or after a user moves from the locking (or intermediate) mode to the unlocking mode.

[0010] The following description not only illustrates exemplary aspects, embodiments, and specific examples of various data processing terminals described herein, but also explains various methods related to them in conjunction with the accompanying drawings.

[0011] [Cross-reference to related applications]

[0012] This invention claims priority to Provisional Patent Application No. 62 / 379559, filed August 25, 2016, the entire contents of which are incorporated herein by reference. In the event of any discrepancy between this application and the aforementioned Provisional Application, this application shall prevail. Furthermore, any content provided in the Provisional Application but not included in this application shall be deemed not to be included in this application and shall not be part of this application. Background Technology

[0013] With smartphones, mobile phones, tablets, PDAs, and connected devices now equipped with significantly more powerful processors and larger storage capacities than ever before, users are becoming increasingly reliant on and addicted to them. Furthermore, these devices often include calling capabilities, leading users to replace existing telephones and even desktop and laptop computers with them. Given the convenience these devices offer, it's not surprising that users store their important personal data on them.

[0014] With the development of wireless communication hardware and software technologies, many hackers are planting malicious viruses in seemingly secure online software applications or content, hoping to infiltrate the main system of unsuspecting users' data processing devices. Once a malicious virus infiltrates a user's data processing device, hackers can steal important personal or financial data from the user's device.

[0015] Therefore, whenever a user unknowingly downloads malicious applications or content to their data processing device, their important financial data stored on the device's main system may be leaked or lost, personal data or data they do not wish to disclose may be accidentally leaked, and the device may also malfunction or suffer other damage. This damage is especially likely to occur when a malicious virus infiltrates the user's data processing device's main system. Some hackers may even plant ransomware on a user's data processing device, preventing the user from accessing the data stored on their device unless they pay compensation to the hacker.

[0016] Conservative or cautious users of data processing devices may also face this situation. For example, in some cases, users may need to visit unfamiliar websites or download applications or content from such websites. The safest approach is to avoid visiting these websites or downloading the content or applications. However, in situations where there are no other options or in emergency situations, users may be forced to visit unfamiliar websites or download applications or content.

[0017] Because of these security concerns, conservative or cautious users cannot make the most of their data processing devices. For example, even if a user discovers attractive content on a new website, they may refrain from using the application or downloading the content due to the risk of hackers stealing important data stored on their device.

[0018] Users of data processing devices have other reasons for needing to protect the main system of their devices. Firstly, the main system (for example, the main memory unit) stores the highest-level personal data that users do not wish to disclose or share with others. While users can use existing authentication procedures to prevent their personal data from being disclosed, they may face situations where they are forced to use their data processing devices in public environments even if the information stored in the main memory unit of the main system is at risk of being leaked.

[0019] Furthermore, users can use existing antivirus programs to check whether downloaded applications and content contain malicious viruses. However, many malicious viruses are designed to evade existing antivirus programs. In most cases, even if a user confirms that a downloaded application contains a malicious virus, it is already too late to take appropriate countermeasures. This is because the malicious virus has already successfully infiltrated the user's data processing device's main system.

[0020] In other words, even if a highly secure method is developed and installed on a data processing device to protect its users, hackers will inevitably develop new mechanisms or sophisticated algorithms to effectively counter it. In fact, given that data processing devices operate in digital environments, it is not surprising that hackers, given enough time, can catch up with any security method.

[0021] Therefore, the best or optimal way for users to protect the data stored on their data processing devices is to avoid visiting suspicious websites or downloading any malicious applications or content. This is because, while this method is not very effective, there is no reliable protocol that can know in advance which websites are malicious or which content contains malicious viruses.

[0022] As mentioned above, data processing terminals need to provide users with enhanced security, integrity, and personal information protection. However, convenience should not be sacrificed for the sake of providing enhanced security, integrity, and personal information protection. In particular, users will experience convenience when enhanced security, integrity, and personal information protection are guaranteed, and multiple tasks can be run seamlessly without requiring them to spend a lot of time or provide a large amount of additional user input. Summary of the Invention

[0023] Technical problems to be solved

[0024] The purpose of the various data processing terminals described in this specification is to provide users with higher security, higher integrity, and enhanced personal information protection while maintaining or improving "seamless" operational convenience. In particular, the terminals utilize at least "four characteristics" to maintain or improve the "seamless characteristic." The four characteristics may be independent of each other or dependent on each other, and the four characteristics may be [1] based on the characteristics of the terminal's structure or operation, or [2] based on the characteristics of the hardware or software elements of the terminal's main system.

[0025] The "first characteristic" of the four characteristics is defining "more than two modes" in which a user can run a job, allowing the user to have different access permissions to drive the hardware or software elements of the host system in each mode. As a result, the user drives the terminal in an unlocked mode when processing credible data, and in a locked mode when processing suspicious data.

[0026] The second characteristic of the four characteristics is to "isolate" the master (or lock) system from the lock (or master) system in terms of physical or operational operation.

[0027] The "third characteristic" among the four characteristics is "erasure (or partial erasure) operation." Before the products obtained by the user driving the locking system in lock mode to run various locking operations affect the hardware or software elements of the terminal's main system, the terminal can erase all (or part) of the products. Therefore, the terminal can run the erasure (or partial erasure) operation at several points in time.

[0028] The last of the four features, the "fourth feature," is that the terminal includes a "mode movement input unit." Therefore, users who want to move from the current mode to a new mode do not need to turn off and then on the terminal's image unit as in the past. They can easily move modes by simply providing the terminal with user input that includes one or more specific mode movement (user) inputs.

[0029] The following describes the various purposes, advantages, benefits, and methods of manufacturing and using the various data processing terminals described in this specification. To this end, the terms and phrases used in this specification are first defined below. Attached Figure Description

[0030] Figure 1A This is an example diagram that uses access permission lines to represent operation modes defined at multiple levels;

[0031] Figure 1B (A) to (D) are illustrative diagrams illustrating various levels of operational modes defined using multiple circles;

[0032] Figure 1C (A) to (D) are illustrations of overlapping access permissions, partially overlapping access permissions, and non-overlapping access permissions;

[0033] Figure 1D (A) to (D) are further examples of overlapping access permissions, partially overlapping access permissions, and non-overlapping access permissions;

[0034] Figures 2A to 2B It is a diagram showing the patterns defined by multiple hierarchical levels along the access permission line;

[0035] Figures 2C to 2D This is another diagram showing the pattern of multiple hierarchical levels defined on the access permission line;

[0036] Figures 2E to 2F This is another diagram showing the pattern of multiple hierarchical levels defined on the access permission line;

[0037] Figures 2G to 2H This is yet another diagram showing the pattern of multiple hierarchical levels defined on the access permission line.

[0038] Figure 3 It is an example diagram that shows the jobs or steps running simultaneously according to the clock cycle of the terminal's processor;

[0039] Figure 4 It is an example diagram that takes into account the characteristics of user input and marks the jobs or steps running simultaneously according to the clock cycle of the terminal's processor;

[0040] Figure 5A It is a block diagram of an exemplary data processing terminal, including a lock viewer as the first component;

[0041] Figure 5B It is about Figure 5A A simplified block diagram of the main system;

[0042] Figure 5C It is about Figure 5A and Figure 5BA block diagram of an exemplary locking system for a data processing terminal;

[0043] Figure 6A and Figure 6B It is a diagrammatic chart illustrating a specific level of an exemplary path;

[0044] Figures 7A to 7D The image above shows an example of a mobile input unit that is manufactured in the form of a hard button or hardware element and installed in various locations on a terminal.

[0045] Figure 7E and Figure 7F The image above shows an exemplary mode mobile input unit manufactured as a soft key or software element and installed in various locations on a terminal.

[0046] Figures 8A to 8E The above diagram illustrates a mobile input unit that is installed as various hardware or software elements in various parts of a terminal.

[0047] Figures 9A to 9D The diagram above shows various notification units that generate notification signals;

[0048] Figure 10A and Figure 10B This is a block diagram of an exemplary data processing terminal of the second configuration in this specification;

[0049] Figure 11 This is a block diagram of a data processing system with a built-in configuration, representing a third exemplary aspect of this specification.

[0050] Figure 12 This is a block diagram of an exemplary data processing terminal, which is the fourth component of this specification, and is a hybrid configuration.

[0051] Figures 13A to 13D The image above shows an example terminal driven by a seamless job execution sequence. Detailed Implementation

[0052] 1. Definition

[0053] As described above, the various data processing terminals described in this specification can be operated in multiple different, similar, or identical operating modes, and the terminals can assign different, similar, or identical access permissions to each mode. Furthermore, the terminals provide enhanced security, improved integrity, and enhanced personal information protection, and enable movement from the current mode to a new mode.

[0054] In this specification, when a number is placed between "[" and "]", i.e., [1] or [2], it indicates that they are alternatives to each other. Therefore, the statement "examples of the device include [1] a plate, [2] a cup, etc." indicates that the device is a plate or a cup or their equivalents.

[0055] 1-1. Accessible hardware or software elements

[0056] A data processing terminal comprises multiple hardware and software components. When a user is unable to directly or indirectly drive or modify a specific hardware or software component due to operational or security reasons, that component is referred to as an "inaccessible" hardware or software component. Examples of inaccessible components include microprocessors, wireless transmitters, wireless receivers, firmware, and kernels. Furthermore, software components stored in the kernel space (a protected area of ​​the terminal) rather than in the user space are also considered inaccessible software components.

[0057] However, terminal manufacturers can enable users to directly drive specific hardware or software elements by providing user input; these elements are referred to as "accessible" hardware or software elements of the terminal's main system. For example, input units, memory units, software applications (hereinafter referred to as "applications"), operating systems (O / S), and other user-driven elements that can run various tasks are examples of accessible hardware or software elements.

[0058] Furthermore, the terminal can provide users with various interfaces such as graphical user interface (GUI), text-based interface, or other user interfaces. Users can access hardware or software elements driven by the interface.

[0059] From this perspective, when a data processing terminal grants a user specific access permissions under a specific operating mode, the user [1] may access all accessible hardware and software elements or [2] may not be able to access all accessible hardware or software elements but may only access a portion of them. In the case of [1] or [2] above, the terminal may enable the user [3] to drive "all parts" of a specific accessible hardware or software element, or [4] to drive only "limited parts" of a specific accessible hardware or software element. In the case of [4] above, the user can only drive the specific accessible hardware or software element to a "limited degree," resulting in the user being able to drive only limited parts of the element rather than all of them, or only with limited options rather than all available options.

[0060] When the terminal receives appropriate user input, it accordingly allows the user to move from the current mode to a new mode. Then, depending on the access permissions granted to the user by the terminal in the new mode, the terminal may [1] allow the user to access more than one accessible hardware or software element, or [2] allow the driving of the element, or [3] allow the running of a specific job by driving the element, or [4] allow the execution of a specific function by driving the element.

[0061] Conversely, [5] if the terminal does not authenticate user input, the terminal may prevent the user from moving from the current mode to the new mode. In this case, [5-1] the user may remain in the current mode, or [5-2] the terminal may move to the off state or power-off state. In the case of [5-1] above, the terminal may allow the user to continue driving hardware or software elements that can be driven in the current mode, but prevents the user from driving hardware or software elements that can only be driven in the new state.

[0062] Limited by the terminal's specific access permissions granted in a particular mode, a user may "access" or "drive" more than one accessible hardware or software element. However, the user cannot access or drive hardware or software elements that are inaccessible in that mode. From this perspective, when indicating that a terminal or user can access or drive a specific hardware or software element, unless otherwise specified, that hardware or software element is considered an accessible hardware or software element.

[0063] Furthermore, the statement "drives a specific element" has the same meaning as the statement "drives more than one accessible hardware element or software element." And both "drives more than one accessible hardware element" and "runs more than one accessible software element" are collectively referred to as the statement "drives a specific element."

[0064] 1-2. Main System and Locking System

[0065] The data processing terminal described in this specification includes one or more main systems and one or more locking systems. The terminal may also include one or more intermediate systems. The terminal typically grants users driving the main system in unlocked mode the maximum (or most) access permissions, but grants users driving the locking system in locked mode the minimum access permissions. Furthermore, the terminal grants users driving the intermediate system in intermediate mode intermediate access permissions, which are less than the access permissions granted to the main system but more extensive than the access permissions granted to the locking system.

[0066] In this specification, "main system" refers to the system driven by the user for using the terminal in the unlock (operation) mode actually defined by the user in the hierarchy built on the terminal. Typically, the user uses the main system when driving the terminal in the unlock mode described below. From this perspective, the main system is the system granted the widest access permissions within a particular hierarchy. The main system includes more than one accessible hardware element or more than one accessible software element.

[0067] When a user drives the main system in unlocked mode, the terminal grants the widest (or maximum) access permissions, allowing the user to drive the most (or all) accessible hardware elements or the most (or all) accessible software elements of the main system. From this perspective, "main system" is used in this specification to mean the same thing as "unlocked system." The main system or unlocked system operates at a specific level defined in the terminal's architecture, where the terminal grants the maximum access permissions at that level.

[0068] Conversely, a "locked system" refers to a system driven by a user to use a data processing terminal in a locked (operating) mode actually defined by the hierarchy. A locked system is generally equivalent to a system used by a user to drive a terminal in the following "locked mode." From this perspective, a locked system is a system to which the hierarchy with the locked mode typically grants the minimum access permissions. A terminal can include more than one hardware or software element in the locked system, but depending on the circumstances, it can exclude any hardware or software element. A terminal can grant or deny permissions to the locked system to drive more than one accessible hardware or software element of the main system.

[0069] Locking systems can be physically or operationally isolated from the main system for various reasons, including security, integrity, and personal information protection. For ease of explanation, "physical isolation" or "operational isolation" can be collectively referred to as "isolation".

[0070] Therefore, in the case of the first specific example, when a user uses the locking system in locked mode, the terminal can utilize the isolation to deny the user's access to multiple elements of the main system. Thus, the user cannot access or drive any accessible hardware or software elements of the main system in locked mode. Since the user cannot drive any accessible hardware or software elements of the main system in locked mode, the locking system can include more than one hardware or software element accessible in locked mode, which the user accesses or drives to run various tasks. From this perspective, the locking system can be viewed as a system granted the minimum access permissions to accessible hardware or software elements of the main system.

[0071] In the case of the second specific example, when a user is driving the locking system in lock mode, the terminal can grant the user minimal access to the main system so that the user can only drive a minimum number of accessible hardware or software elements of the main system during the lock mode period.

[0072] Even if the terminal allows a user to use more than one accessible hardware or software element of the host system in locked mode (for example, access, drivers, etc.), the terminal may [1] completely disable the user from storing any results or partially disable the host system, or [2] completely disable the user from changing any element of the host system or partially disable the host system through said isolation. That is, the terminal can prevent (or minimize) the adverse effects or functional degradation of the host system from the locked system.

[0073] As stated above, in locked mode, users can only use a minimum number of the accessible hardware or software elements of the host system. Therefore, the locked system may [1] include more than one hardware or software element for running multiple locked jobs, or [2] exclude any accessible elements so that the host system can run the locked jobs. From this perspective, the locked system can be considered to have only partial (not full) access to the accessible hardware or software elements of the host system.

[0074] In the case of the third specific example, when a user uses the locking system in locked mode, the terminal grants the user all access rights to the main system, enabling the user to drive all accessible hardware or software elements of the main system using the locking system in locked mode. However, the terminal can also [1] prevent the user or the locking system from storing any results on the main system, or [2] prevent the user or the locking system from changing elements of the main system through the isolation. Thus, the terminal can prevent the locking system from adversely affecting or degrading the main system.

[0075] In lock mode, the user drives the locking system and can drive all accessible hardware and software elements of the main system. Therefore, the locking system may include more than one hardware or software element, or may not include any element that allows the main system to perform locking operations in lock mode. From this perspective, the locking system can be considered similar to or (very) identical to the main system.

[0076] 1-3. Access Permissions

[0077] In this specification, "access permission" refers to the permissions granted by the terminal to a user using a specific system driver terminal in a specific mode. Specifically, "access permission" refers to the terminal granting a user permission to access only a specific number of accessible hardware or software elements of the main system. For example, the terminal may grant a user permission to access all (or some) accessible elements of the main system or grant no permission at all.

[0078] When a terminal grants a user the right to access specific accessible hardware or software elements of the main system, the user is deemed to have [1] the right to "drive" the element, [2] the right to drive the element to "run" a specific job, or [3] the right to run the job to "perform" a specific function. Furthermore, depending on the nature of the access permission, a user may [1] have access to drive the main system in unlocked mode to drive specific elements of the main system, or [2] have access to drive the locked (or intermediate) system in locked (or intermediate) mode to drive specific elements of the main system. In this specification, access permission to hardware or software elements of a locked system refers to [1] the right to drive the locked (or intermediate) system in locked (or intermediate) mode to access the elements of the locked system, or [2] the right to drive the main system in unlocked mode to access the elements of the locked system.

[0079] Therefore, unless otherwise specified, “access rights” in this specification means [1] that a user can “access” one or more accessible hardware or software elements of the main system during the process of driving the main system in unlock mode or during the process of driving the locked (or intermediate) system in lock (or intermediate) mode, or [2] that a user can drive the hardware or software elements during the process of “driving” the system in the mode, or [3] that a user can “run” one or more jobs by driving the elements during the process of driving the system in the mode, or [4] that a user can perform a specific “function” by driving the system in the mode to run the jobs.

[0080] In this specification, the use of the term "access rights" to more than one hardware or software element of a locking system is limited to the case where such access rights refer to [1] a user's ability to access more than one accessible locking element of the locking system during the process of driving the locking (or intermediate) system in a locked (or intermediate) mode or during the process of driving the main system in an unlocked mode, or [2] the ability to drive the element during the process of driving the system in the mode, or [3] the ability to drive the system in the mode to run more than one job, or [4] the ability to perform a specific function by running the job during the process of driving the system in the mode.

[0081] 1-4. (Operation) Modes and Access Permissions

[0082] In this specification, "(Operating) Mode" or simply "Mode" refers to the operating state of the data processing terminal, in which the user can access a specific number of accessible hardware or software elements of the terminal's main system. The terminal can move to a new mode accordingly based on appropriate user input provided by the user to the input unit: [1] from the power-off state (i.e., the power is off, communication is impossible, and the image unit is also off) or [2] from the off state (the power is on, communication is possible, but the image unit is off) or [3] from the current mode in the on state (the power is on, communication is possible, and the image unit is also on) or [4] from the current mode in the on state to the off state or [5] from the current mode in the on state to the power-off state. For ease of explanation, "(Operating) Mode Switch" or "Mode Switching" refers to one of the above [1] to [5].

[0083] The terminal may prevent the user from accessing any accessible hardware or software elements of the host system in locked mode or the highest restricted mode described below. However, the terminal may allow the user to access all accessible hardware and software elements of the host system in unlocked mode or the highest unrestricted mode described below.

[0084] In this specification, the "off state" is referred to as the "inactive state," and conversely, the "on state" is referred to as the "active state." Specifically, in both the inactive and active states, the terminal's power supply is not completely disconnected, and communication is possible. Alternatively, if the terminal's power supply is disconnected and communication is impossible, this state is referred to as the "power-off state." Clearly, in the power-off state, the terminal's imaging unit is off.

[0085] In the case of a user driving a specific accessible hardware element of the terminal, the user [1] is considered to be able to drive the electronic, optical, mechanical, or magnetic "parts" of the element, or the user [2] is considered to be able to drive only a specific number of "parts" of the element, not all "parts". Similarly, in the case of a user driving a specific accessible software element of the terminal, the user [1] is considered to be able to use all "options" of the element, or the user [2] is considered to be able to use only a specific number of "options" of the element, not all "options".

[0086] In this specification, "restricted (operating) mode" or simply "restricted mode" is a general term for operating modes in which the terminal is unable to drive all accessible hardware or software elements contained in the host system. Therefore, various operating modes that are granted fewer access permissions than those that can drive all accessible hardware and software elements of the host system are collectively referred to as "restricted modes".

[0087] In this specification, "more restrictive (operating) mode," or simply "more restrictive mode," refers to an operating mode in which the user cannot drive all accessible hardware or software elements of the terminal's main system; the user can only drive a fewer number of elements than in the aforementioned "restrictive mode." From this perspective, when using "restrictive mode" as a benchmark, "more restrictive mode" can be referred to as "fewer unrestrictive mode." Furthermore, compared to "unrestrictive mode," "more restrictive mode" can be considered one of several "restrictive modes."

[0088] The term "highest restricted (operating) mode" or simply "highest restricted mode" in this specification refers to an operating mode in which a user can drive fewer (or "0") accessible hardware or software elements compared to the various restricted modes defined in the hierarchy. Therefore, when compared to "restricted modes," the "highest restricted mode" can be referred to as the "lowest unrestricted mode." Thus, in a specific highest restricted mode, the user will be unable to drive any of the accessible hardware or software elements. Furthermore, compared to "unrestricted operating modes," the "highest restricted mode" can be considered one of several "restricted modes."

[0089] In this specification, "unrestricted (operating) mode" or simply "unrestricted mode" refers to an operating mode in which the user cannot drive all accessible hardware or software elements of the terminal's main system, or a mode in which the user can drive a greater number of accessible elements compared to a restricted mode. In other words, "unrestricted mode" refers to multiple modes that are granted fewer access permissions than those that can drive all accessible hardware or software elements of the main system, and modes that are granted wider access permissions than a certain restricted mode.

[0090] Furthermore, "more unrestricted (operational) modes," or simply "more unrestricted modes," refers to modes where, although the user cannot drive all accessible hardware or software elements of the terminal's main system, they can drive a greater number of accessible hardware or software elements than in the restricted and unrestricted modes. Therefore, "more unrestricted modes," compared to the restricted or unrestricted modes, can be referred to as "less restricted (operational) modes." The "more unrestricted modes" can also be considered as one of several unrestricted modes.

[0091] Furthermore, the "highest non-restrictive (operating) mode," or simply the "highest non-restrictive mode," refers to the operating mode in which the user can drive the maximum number (or all) of the accessible hardware or software elements of the terminal's main system compared to the aforementioned baseline mode and other modes. Therefore, the "highest non-restrictive mode," when compared to a specific level of baseline mode or other modes, can be referred to as the "lowest restrictive mode." In particular, the user can also drive all accessible hardware or software elements in this mode. Of course, the "highest non-restrictive mode" can also be considered as one of several non-restrictive modes.

[0092] The [1] highest restrictive mode, [2] more restrictive modes, [3] restrictive mode, [4] non-restrictive mode, [5] more non-restrictive mode, or [6] highest non-restrictive mode can all be defined from a relative perspective. Therefore, when each of the aforementioned modes is marked on a "line of access authority" defined as an access permission increasing from left to right, the highest restrictive mode is located at the left end of the line, the highest non-restrictive mode is located at the right end of the line, and the more restrictive modes to more non-restrictive modes are located between the left end and the right end in the direction from left to right.

[0093] Figure 1A This is an example diagram illustrating multi-level defined work modes. Especially... Figure 1A The various restrictive and non-restrictive modes described above are illustrated on the access permission line, and the position of each mode on the access permission line indicates the scope or width of the access permission granted to each mode. Figure 1A For each layer illustrated in (A) to (D), the terminal defines a first mode MD1 and a second mode MD2, and drives either MD1 or MD2. The terminal grants wider access permissions to users in MD2, which is located to the right of the access permission line, than to users in MD1, which is located to the left of the access permission line.

[0094] like Figure 1A As shown, the terminal can define an unlimited number of different modes on the access permission line. However, the terminal "actually" only defines two modes, MD1 and MD2. Therefore, the terminal enables the user to [1] move from the off state to MD1 or MD2 or [2] move from one of the modes, MD1 and MD2, to another mode. That is, the terminal can define hundreds of the same or different modes on the access permission line, but "actually" only defines two modes.

[0095] Figure 1AIn (A), the terminal operates in MD1 and MD2, and can move from one mode to the other according to appropriate user input. Furthermore, in (A), the terminal "actually" defines MD1 at the right end of the access permission line (equivalent to the "hierarchy" of the terminal's actual operation). Therefore, MD1 corresponds to the highest unrestricted (or lowest restricted) mode of the hierarchy. The terminal "actually" defines MD2 at the left end of the access permission line (or hierarchy), and therefore MD2 corresponds to the highest restricted (or lowest unrestricted) mode of the hierarchy. The terminal grants the user wider access permissions in MD1 than in MD2, thus allowing the user to access a greater number of hardware or software elements in MD1 than in MD2.

[0096] Figure 1A In (B), the terminal defines MD1 and MD2, and like in (A), MD2 is defined at the left end of the access permission line. Therefore, MD2 is equivalent to the highest restricted mode of the hierarchy. Although the terminal defines MD1 to the right of MD2 on the same access permission line, MD1 is not located at the right end of the line but to its left. Therefore, the terminal does not define MD1 as the highest unrestricted mode of the hierarchy. As a result, compared to the highest unrestricted mode, the user of MD1 cannot drive all accessible hardware or software elements. Conversely, the terminal grants the user of MD1 more permissions than the user of MD2, but fewer permissions than the user of the highest unrestricted mode. From this perspective, MD1 can be considered a more unrestricted mode than the highest unrestricted mode.

[0097] Figure 1A In (C), the terminal defines MD1 and MD2, and like in (A), defines MD1 at the right end of the access permission line. Therefore, MD1 corresponds to the highest unrestricted mode of the hierarchy. Although the terminal defines MD2 to the left of MD1 on the same access permission line, MD2 is not located at the left end of the access permission line but to its right. Therefore, the terminal does not define MD2 as the highest restricted mode of the hierarchy. As a result, the user of MD2 can drive accessible hardware or software elements with a wider access permission than the highest restricted mode granted by the terminal. From this perspective, MD2 can be considered a more restricted mode rather than the highest restricted mode.

[0098] Figure 1AIn (D), the terminal defines MD1 and MD2. Similar to (B), MD1 is defined at a predetermined distance from the right end of the access permission line, and similar to (C), MD2 is defined at a predetermined distance from the left end of the same line. Therefore, MD1 can be considered as more unrestricted modes rather than the highest unrestricted mode, and MD2 can be considered as more restricted modes rather than the highest restricted mode.

[0099] As mentioned above, a terminal can theoretically define a large number of operating modes along the access permission line. For example, a terminal can define modes ranging from the mode with the least access permission (i.e., the most restrictive mode) to the mode with the highest access permission (i.e., the highest unrestricted mode), and can also define an unlimited number of intermediate modes in between. However, for various security, integrity, and personal information protection reasons, the terminal, manufacturer, or user may not define the highest unrestricted mode or the highest restrictive mode at a specific level. Figure 1A Examples of this hierarchy are (B) and (D), where the terminal does not define the highest unrestricted mode at the right end of the access permission line. Furthermore, the terminals in (C) and (D) do not define the highest restricted mode at the left end of the line.

[0100] In this case, each level cannot cover the entire range of the access permission line, and therefore cannot include the entire length from the left end to the right end of the line. Conversely, each level only includes a portion of the access permission line, and may not include the highest non-restrictive mode or the highest restrictive mode. From this perspective, the unlock mode and lock mode in this specification may be equivalent to or not equivalent to the aforementioned highest non-restrictive mode or highest restrictive mode, depending on whether the terminal actually defines the mode at the left end and the right end of the access permission line.

[0101] In this manual, "locked (operation) mode," or simply "locked mode," refers to the operation mode that the terminal "actually" defines as being on the far left of the access permission line. Therefore, as... Figure 1A As shown in (A) and (B), when the terminal "actually" defines a locking mode on the left side of the access permission line, the locking mode is consistent with the highest restrictive mode of the hierarchy. Therefore, among the hierarchical modes that the terminal "actually" provides to the user in (A) and (B), the mode with the fewest access permissions is the locking mode that is consistent with the highest restrictive mode of the hierarchy.

[0102] Conversely, the terminal can be like Figure 1AAs shown in (C) and (D), locking modes are defined at predetermined distances from the left end of the access permission line, where each locking mode corresponds to more unrestricted or restricted modes rather than the highest restricted mode. Therefore, the mode with the fewest access permissions among the modes actually provided to the user by the hierarchically driven terminal in (C) and (D) is the locking mode that is granted wider access permissions than the highest restricted mode of the hierarchy. As a result, a user operating a terminal in the "actually" defined locking modes of the hierarchies in (C) and (D) can access a greater number of accessible hardware or software elements than a user operating a terminal in the "actually" defined locking modes of the hierarchies in (A) and (B).

[0103] Similarly, the "unlock (operating) mode" or simply "unlock mode" in this specification corresponds to the operating mode "actually" defined by the terminal at the far right of the access permission line. Therefore, in the case where the unlock mode is defined at the right end of the access permission line as shown in (A) and (C), the unlock mode corresponds to the highest non-restrictive mode of the hierarchy. Thus, the unlock mode, which grants the widest access permission to the terminal driven by the hierarchy in (A) and (C), corresponds to the highest non-restrictive mode of the same hierarchy.

[0104] On the other hand, such as Figure 1A As shown in (B) and (D), when the terminal defines an unlocking mode at a predetermined distance from the right end of the access permission line, the unlocking mode is equivalent to more unrestricted modes or unrestricted modes of the hierarchy, rather than the highest unrestricted mode. That is, the mode that grants the widest access permission to the terminal driven by the hierarchy in (B) and (D) is yet another unlocking mode, which grants less access permission than the aforementioned highest unrestricted mode. As a result, a user of a terminal driven by an unlocking mode in hierarchy (B) or (D) can only drive a smaller number of accessible hardware or software elements compared to a user of a terminal driven by an unlocking mode in hierarchy (A) or (C).

[0105] Figure 1A The illustrated modes are assigned different access permissions that can overlap, and the different ranges of access permissions for each mode can be specified by the position of each mode on the access permission line. However, the overlapping range of multiple modes can be represented in different ways.

[0106] Figure 1B (A) to (D) are illustrations of operation modes defined by multiple levels. Each mode is represented by a circle, and the scope or width of access permissions for each mode is represented by the radius, diameter, area, etc. of the circle. Figure 1BThe outermost circle in (A) to (D) (hereinafter referred to as the "outermost circle") represents the "highest unrestricted mode" that the terminal can define, and conversely, the innermost circle (hereinafter referred to as the "innermost circle") represents the "highest restricted mode" that the terminal can define. Furthermore, circles represented by solid lines represent modes that the terminal "actually" defines at a specific level, and that the user can "actually" drive the terminal in these modes. Conversely, circles represented by dashed lines represent modes that, although they can be defined by the terminal, are not "actually" defined at that level by the terminal due to various security, integrity, and personal information protection considerations.

[0107] As an example, Figure 1B Terminal (A) defines two modes at the exemplary level: MD1 as the unlock mode and MD4 as the lock mode. The terminal defines MD1 using the outermost circle, thus the unlock mode MD1 is equivalent to the "highest unrestricted mode". Therefore, the terminal grants the widest access permission to MD1, resulting in the largest number of accessible hardware or software elements in the user-driven host system of the terminal driven by MD1.

[0108] and Figure 1B The terminal of (A) uses the innermost circle as the MD4 for the locking mode. Therefore Figure 1B The (A) level's locking mode is equivalent to a "maximum restriction mode." Therefore, the terminal grants minimal access to MD4, ensuring that users on the MD4-driven terminal can only drive a minimum number (including "0") of accessible hardware or software elements. From this perspective... Figure 1B The class of (A) and Figure 1A The social class of (A) is the same. Furthermore, Figure 1B The MD1 in (A) contains MD4 internally. In other words, the user of the MD1 driver terminal can access all accessible hardware or software elements of the MD4 driver in the MD1 driver.

[0109] Figure 1B In case (B), the terminal defines two modes: MD2 and MD4. However, MD4 and... Figure 1B The MD4 of (A) is the same, therefore MD4 is the locking mode equivalent to the "highest restricted mode" of the hierarchy. Conversely, the terminal uses the largest solid circle of the hierarchy to "actually" define MD2 instead of actually defining MD1 (therefore represented by a dashed line). Therefore, MD2 is equivalent to "more unrestricted modes" or "unrestricted modes" rather than "highest unrestricted mode". As a result, the user can only drive (not all) of the accessible hardware or software elements that can be driven by MD1 in MD2. From this point of view, Figure 1B (B) class and Figure 1A The social class of (B) is the same. And... Figure 1BIn (B), MD2 internally contains MD4. That is, a user on the MD2-driven terminal can drive all accessible hardware or software elements that a user on the same terminal can drive.

[0110] Figure 1B In case (C), the terminal defines two modes: MD1 and MD3. Figure 1B The MD1 of (A) is the same. Therefore, MD1 is the unlocking mode equivalent to the "highest unrestricted mode" of the hierarchy. Conversely, the terminal does not actually define MD4, but instead defines MD3 using the smallest circle of the hierarchy with solid lines. That is, MD3 is not equivalent to the "highest restricted mode", but rather to "more restricted modes" or "restricted modes". As a result, the user can only drive some (not all) of the accessible hardware or software elements that can be driven by MD1 in MD3. Furthermore, the user can drive all accessible hardware or software elements that can be driven by MD4 in MD3. From this perspective, Figure 1B The (C) class and Figure 1A The social class of (C) is the same. And... Figure 1B MD1 of (C) contains MD3.

[0111] Figure 1B The terminal definition (D) specifies the lock mode MD3 and the unlock mode MD2, MD3 and Figure 1B The MD3 of (C) is the same, the reverse, and the MD2 is the same. Figure 1B (B) has the same MD2. That is, unlock mode MD2 is equivalent to "more unrestricted mode" or "restricted mode" but not "maximum unrestricted mode", and lock mode MD3 is equivalent to "more restricted mode" or "restricted mode" but not "maximum restricted mode". In other words, the terminal grants the user fewer access permissions in MD2 than in MD1, but more access permissions than in MD3. Similarly, the terminal grants more access permissions in MD3 than in MD4 but fewer than in MD2. Figure 1B As can be seen from (D), MD2 contains MD3 internally. Therefore, users on the MD2-driven terminal can drive all accessible hardware or software elements that users on the MD3-driven terminal can drive.

[0112] Figures 1A to 1BThe exemplary terminal defines only two modes with different access permissions, but the terminal can define more modes at a specific level. For example, the terminal can define three modes: MD3 is the actual locked mode defined by the terminal, which can be the mode with the least access permissions granted in that level; MD1 is the actual unlocked mode defined by the terminal in that level, which is the mode with the widest access permissions granted; conversely, MD2 is the actual intermediate mode defined by the terminal, which can be the mode with less access permissions than MD1 but wider than MD3.

[0113] From this perspective, "intermediate (operating) mode" or simply "intermediate mode" is equivalent to the mode that the terminal "actually" defines between the locked mode and the unlocked mode on the access permission line of a specific level. The terminal can (1) grant less access permission to the intermediate mode than the access permission actually granted to the unlocked mode of the same level, and (2) grant more access permission than the access permission actually granted to the locked mode of the same level.

[0114] A terminal can define one or any number of intermediate modes on the access permission line. In particular, when a terminal defines multiple intermediate modes, the intermediate modes can be referred to as "half-unlocked mode", "less unlocked mode", "half-locked mode", "less locked mode", etc. The "half-unlocked mode" or "less unlocked mode" is a mode in which the terminal grants access permissions that are narrower than the unlocked mode. Conversely, the "half-locked mode" or "less locked mode" is a mode in which the terminal grants access permissions that are wider than the locked mode.

[0115] Multiple intermediate modes can be defined from a relative perspective. Therefore, a terminal can be defined as "more unlock modes" or "more lock modes". However, for ease of explanation, this specification defines intermediate modes as "half-unlock mode" (or "less unlock mode") and "half-lock mode" (or "less lock mode"), which are hereby considered to be granting narrower access permissions to "half-lock mode (or less lock mode)" than granting access permissions to "half-unlock mode (or less unlock mode)".

[0116] As mentioned above, Figures 1A-1B The multiple modes have overlapping access permissions, i.e., the characteristic of "overlapping access permissions". That is, the terminal grants different access permissions to the user in unlock mode and lock mode, so (1) the user in the unlock mode of the tier can not only drive all accessible hardware or software elements that can be driven in the lock mode of the tier, (2) but also drive at least one or more hardware or software elements that cannot be driven in the lock mode due to insufficient access permissions. As above, when the terminal defines multiple modes with overlapping access permissions, the mode is called "overlapping mode".

[0117] The terminal constructs a specific hierarchy, and can such that (1) a portion of the access permissions granted to the locking mode of the hierarchy are also granted to the unlocking mode of the same hierarchy, and (2) other portions of the access permissions granted to the locking mode are not granted to the unlocking mode of the same hierarchy. That is, a user of the terminal driven by the unlocking mode of the hierarchy can drive one or more (not all) of the accessible hardware or software elements that can be driven by the locking mode of the same hierarchy. In this specification, each of the aforementioned modes is referred to as a "partially overlapping mode", and the access permissions granted to the modes are referred to as "partially overlapping access permissions".

[0118] Conversely, the terminal can be structured to assign different access permissions to multiple modes, with each access permission being completely non-overlapping. That is, a user in the unlocked mode of a given tier cannot drive any hardware or software elements that can be driven in the locked mode of the same tier. This specification refers to these modes as "non-overlapping modes" and the access permissions granted to these modes as "non-overlapping access permissions." Despite this characteristic, a user can drive a greater number of accessible hardware or software elements in the unlocked mode than in the locked mode of the same tier.

[0119] The following will explain in detail, but the terminal (or user) can construct a specific hierarchy using overlapping modes, partially overlapping modes, or non-overlapping modes for various reasons. As an example, if the terminal defines multiple overlapping modes and assigns different access permissions to each mode, the user can drive a small number of accessible hardware or software elements when driving the terminal in locked mode, but can drive a larger number of the aforementioned elements in unlocked mode (by providing an additional password or specific user input for authentication if necessary).

[0120] An example of an overlapping mode is that it restricts access to all accessible hardware or software elements for personal use in unlocked mode, while only a portion of those elements can be accessed in locked mode. This prevents unauthorized access to personal information stored on the terminal's main system. Therefore, the terminal can maintain the security and integrity of the main system and protect personal information.

[0121] Conversely, in the case of multiple users sharing a terminal, each user constructs a specific hierarchy, and each user can define their own pattern that does not overlap with the patterns defined by other users. Therefore, a user cannot drive the terminal using other user-defined patterns, but can prevent other users from driving the terminal using their own user-defined patterns. That is, each user can independently drive only their own accessible elements within their own limited pattern, while simultaneously preventing other users from driving user-driven elements. The following explains variations of the aforementioned overlapping, partially overlapping, or non-overlapping patterns.

[0122] Figure 1CDiagrams (A) to (D) are illustrative diagrams regarding the overlapping access permissions, partially overlapping access permissions, and non-overlapping access permissions, representing the case where the terminal "actually" only defines unlock mode MD1 and lock mode MD2, and only MD1 and MD2 are activated. The overlap characteristics of MD1 and MD2 are represented by the horizontal position of the modes on the access permission line. As an example, it is stipulated that the closer each mode is to or near the center of the line, the more overlapping the access permissions of the modes; conversely, the farther each mode is from the center of the line in the opposite direction, the less overlapping the access permissions of the modes. The height of the quadrilateral representing each mode represents the range of access permissions granted to each mode by the terminal.

[0123] right Figure 1C In case (A), the terminal "actually" defines MD1 and MD2, indicating that the quadrilaterals of each mode have the same or similar heights. Therefore, it can be considered that the terminal grants MD1 and MD2 the same or similar level of access rights, allowing the user to drive the same or similar number of accessible hardware or software elements in both MD1 and MD2. Furthermore, MD1 and MD2 are roughly located in the center of the access rights line, and the modes overlap, thus constituting an overlapping mode.

[0124] right Figure 1C In case (B), the terminal's "actual" definition is used in conjunction with Figure 1C The quadrilateral representations of MD1 and MD2 in (A) suggest that the terminal grants MD1 and MD2 the same or similar level of access rights. However, MD1 and MD2 are not located in the center of the access rights line, but are slightly separated from each other. Therefore, MD1 and MD2 can be considered as partially overlapping modes where the terminal grants partially overlapping access rights. That is, the user can drive at least one overlapping accessible hardware or software element in either MD1 or MD2. However, as an example, the terminal may allow the user to drive the camera in MD1 but not in MD2, or allow the user to perform schedule management in MD2 but not in MD1.

[0125] Figure 1C Terminal (C) "actually" defines MD1 and MD2, where the height of the quadrilateral representing MD1 is greater than the height of the quadrilateral representing MD2. Therefore, it can be seen that the terminal grants wider access permissions to MD1 than to MD2. Furthermore, MD1 and MD2 are not located in the center of the access permission line, but are configured slightly apart in the opposite direction. Therefore, MD1 and MD2 are in a partially overlapping mode.

[0126] Figure 1CIn case (D), the terminal "actually" defines MD1 and MD2, and the access permissions of each mode do not overlap. Therefore, regardless of which hardware or software elements the user drives in MD1 (or MD2), the user cannot drive those elements in MD2 (or MD1). Therefore, the modes are non-overlapping modes.

[0127] Figure 1D (A) through (D) are yet another example of overlapping, partially overlapping, and non-overlapping access permissions. Figure 1D The exemplary circles (A) to (D) represent modes that can be defined at a specific level, and the radius, diameter or area of ​​each circle represents the range of access permissions granted to the mode by the terminal.

[0128] and Figure 1B (A) through (D) are the same, (1) Figure 1D The outermost circles of (A) to (D) are the "highest unrestricted mode" that the terminal can define, conversely, (2) Figure 1D The innermost circle of (A) to (D) is the "highest restrictive mode" that the terminal can define, (3) Figure 1D In (A) to (D), the circles represented by solid lines correspond to the modes that the terminal "actually" defines at a specific level, and (4) the circles represented by dashed lines represent modes that the terminal can define but are not "actually" defined at that level due to reasons such as security, integrity, and personal information protection. Therefore, the outermost circle (or the circle with the largest area) represented by solid lines is the unlocking mode at a specific level, and conversely, the innermost circle (or the circle with the smallest area) represented by solid lines represents the locking mode at the same level. Figure 1D The positions of the circles in (A) to (D) represent the accessible hardware or software elements that the user can access in the mode represented by the circle.

[0129] From this perspective, Figure 1D Terminal (A) defines two modes, MD5 and MD6. For each mode, one mode can overlap with other modes or be extremely similar to each other, and the access permissions of the modes can also be extremely similar. Therefore, MD5 and MD6 as overlapping modes are equivalent to Figure 1C MD1 and MD2 of (A), and [1] MD5 and MD6 correspond to locked mode and unlocked mode (or vice versa), respectively, or [2] MD5 and MD6 can both be locked (or unlocked). And the terminal can grant MD5 and MD6 access permissions that are less than the access permissions that can be granted to the "highest unrestricted mode" (i.e., the outermost circle indicated by the dashed line).

[0130] Figure 1DTerminal (B) also defines two modes, MD5 and MD6, but these modes only partially overlap. Therefore, the modes include not only a common "common part" but also a "non-common part" that is included only in one mode but not in the other. Thus, MD5 and MD6 are equivalent to partially overlapping modes, equivalent to... Figure 1C MD1 and MD2 of (B). Figure 1D Like (A), MD5 and MD6[1] can be unlock mode and lock mode (or vice versa), or[2] MD5 and MD6 both represent unlock (or lock) mode. And regardless of MD5 or MD6, the terminal can grant the user fewer permissions than the "highest unrestricted mode (i.e., the outermost circle of the dashed line)".

[0131] Figure 1D The (C) terminal is also like Figure 1D (B) defines two modes, MD5 and MD6, but the terminal assigns different access permissions to these modes. Therefore, MD5 and MD6 are like... Figure 1C MD1 and MD2 of (C) are equivalent to partially overlapping modes. And since the circle representing MD5 is larger than the circle representing MD6, MD5 can be considered as the unlock mode, and conversely, MD6 as the lock mode.

[0132] Figure 1D Terminal (D) also defines MD5 and MD6, but these modes do not overlap, therefore there are no shared access permissions between them. That is, MD5 and MD6 are equivalent to non-overlapping modes, equivalent to... Figure 1C MD1 and MD2 of (D). And MD5 and MD6 have extremely similar diameters or areas, so the user can drive extremely similar numbers of accessible hardware or software elements in each mode. However, the elements that the user can drive in MD5 are different from the elements that can be driven in MD6.

[0133] As mentioned above, the terminal can operate in a hierarchical manner with two modes, where the mode granted more access is equivalent to unlock mode, and the mode granted less access is equivalent to lock mode. And as... Figure 1D (A), (B), and Figure 1D As shown in (D), if the terminal grants two modes extremely similar access permissions or defines the modes as non-overlapping modes, one of the modes can be regarded as a locked mode and the other as an unlocked mode.

[0134] The terminal may "actually" define more than three modes at a specific level. In this case, the mode to which the terminal grants the least access permissions may be considered the "locked mode", the mode to which the terminal grants the widest access permissions may be considered the "unlocked mode", and the mode to which the terminal grants intermediate access permissions may be considered the "intermediate mode". As mentioned above, the locked mode may be [1] the "highest restrictive mode" or [2] (if the terminal "actually" defines the "highest restrictive mode" at that level) a "more restrictive mode" or "restricted mode" that is granted wider permissions than the "highest restrictive mode". Similarly, the unlocked mode may be [1] the "highest unrestricted mode" or [2] (if the terminal "actually" defines the "highest unrestricted mode" at that level) a "more unrestricted mode" or "unrestricted mode" that is granted narrower permissions than the "highest unrestricted mode".

[0135] The terminal can [1] define multiple unlock modes, one lock mode and selectively define intermediate modes, or [2] define multiple lock modes, one unlock mode and selectively define intermediate modes, or [3] define multiple lock modes and one or more unlock modes but not define intermediate modes, or [4] define multiple unlock modes and one or more lock modes but not define intermediate modes. The following describes the “hierarchy” and its various forms.

[0136] 1-5. Social classes and categories

[0137] As described above, a "(operation) mode," or simply "mode," represents the operational state of a data processing terminal. Users can access a specific number of operable hardware or software elements of the terminal's main system within a specific mode. From this perspective, a "(operation) hierarchy," or simply "hierarchy," represents a group comprising two or more modes "actually" defined by the terminal along its operational line (or within an access permission domain). Here, the terminal can assign predetermined access permissions to each mode, enabling access to various accessible hardware or software elements of the main system.

[0138] As an example, a terminal (or user) may [1] define more than one unlock mode and more than one lock mode at the first level, [2] define more than two unlock modes but no lock mode at the second level, [3] define more than two lock modes but no unlock mode at the third level, or [4] define more than one unlock mode, more than one intermediate mode and more than one lock mode at the fourth level. The terminal may assign the same or very similar access permissions to more than two unlock modes, resulting in complete overlap of the unlock modes and their access permissions. Alternatively, more than two unlock modes may have partially overlapping or non-overlapping access permissions. This configuration may also be applicable to situations where the terminal defines more than two lock modes or more than two intermediate modes.

[0139] Once a terminal or user constructs a specific hierarchy and defines a specific mode within that hierarchy, the terminal can [1] move from a power-off state or a shutdown state to the specific mode defined by the hierarchy, or [2] move from the current mode defined by the hierarchy to a new mode defined by the hierarchy, or [3] move from the current mode defined by the hierarchy to a power-off state or a shutdown state. Therefore, the terminal or user can construct multiple hierarchies as needed, and can define multiple modes within each hierarchy. The following describes various types of hierarchies.

[0140] In this specification, "sequential hierarchy" refers to (1) a hierarchy in which multiple operating modes are arranged sequentially, and (2) the terminal can move from a specific mode to an adjacent mode when it receives user input from the user. The following figure illustrates a sequential hierarchy in which the terminal defines two or more modes, and the terminal grants a wider access permission to the mode located to the right of the hierarchy (i.e., "forward direction" or "upstream") than to the mode located to the left of the hierarchy (i.e., "rear direction" or "downstream").

[0141] Figures 2A to 2H This is an example of multiple hierarchical levels that define multiple modes on an access permission line (not shown), granting wider access permissions to modes in the forward direction than to modes in the backward direction. For clarity, "forward direction" or "upstream" refers to the right-hand direction in the diagram, and conversely, "backward direction" or "downstream" refers to the left-hand direction in the diagram.

[0142] right Figure 2A In this case, the terminal build defines three modes MD LK MD IN MD UL The levels are respectively equivalent to locked mode, intermediate mode, and unlocked mode. Figure 2A The terminals are arranged in the aforementioned patterns sequentially. Therefore, when a user provides the first user input to a terminal in the off state, the terminal accordingly causes the user to move from the off state to MD. LK When the user provides a second user input, the terminal allows the user to input from the MD. LK Move to (the direction indicated by the arrow pointing to the right in the image, i.e., the forward direction) MD IN When a third user provides input, the terminal allows the user to input from the MD. IN Move to (the direction of the arrow pointing to the right in the image, i.e., the forward direction) MD UL Even if the user provides further input afterward, the terminal remains in MD mode. UL The reason is that the layer constructed by the terminal does not allow users to access the MD. UL Move to another mode.

[0143] When the user turns off the terminal's image unit, the terminal moves to the off state. Subsequently, if the user provides the first user input to the terminal, the terminal repeats the above process to move the user to a specific mode, and can then move to a new mode based on the second user input provided by the user.

[0144] right Figure 2B In this case, the terminal build defines five modes MD LK MD IN1 MD IN2 MD IN3 MD UL The hierarchy of terminals grants wider access permissions in that order. In this MD... IN1 MD IN2 MD IN3 These are intermediate modes, and each intermediate mode has a higher degree of compatibility than MD. LK It has broad access permissions, but with more permissions than MD. UL The permissions are narrow. The five modes are arranged sequentially, therefore in Figure 2B The terminal of the hierarchical work can be arranged according to... Figure 2A The terminals run various jobs in a similar sequence.

[0145] Figure 2A and Figure 2B The terminal user can provide multiple methods for moving modes. As an example, the terminal moves from the current mode to an adjacent mode located ahead in the hierarchy, i.e., along the direction of the arrow connecting the adjacent modes. Therefore, whenever user input is received, the terminal can move from the MD... LK Move to MD IN1 Then from MD IN1 Move to MD IN2 Then from MD IN2 Move to MD IN3 Then from MD IN3 Move to MD UL In this specification, the mode movement method is referred to as "sequential switching." Conversely, the terminal moves from the current mode to a new mode based on user input, and the new mode does not necessarily have to be adjacent to the current mode. Hereafter, this mode movement method is referred to as "selective switching." Regardless of whether the terminal is driven by sequential switching or selective switching, it is considered that the terminal can move modes along the lines and arrows defined by the hierarchy.

[0146] Figure 2A and Figure 2BIn this case, patterns defined at the left and right ends of the hierarchy are connected to an adjacent pattern; conversely, intermediate patterns between opposite sides (i.e., the left and right ends) of the hierarchy are connected to a pair of adjacent patterns in the left and right directions. Therefore, any pattern in a sequential hierarchy may not be connected to more than three adjacent patterns. Furthermore, no pattern in a sequential hierarchy can "bifurcate" into multiple patterns, and no pattern can "merge" into a single pattern.

[0147] In contrast to the sequential hierarchy described above, the "parallel hierarchy" in this specification refers to (1) a hierarchy in which multiple operating modes are arranged side by side (i.e., one or more modes branch into multiple modes or two or more modes merge into one), and (2) a hierarchy in which the terminal can move from a specific mode to a new mode when it receives appropriate user input. The following figures illustrate a parallel hierarchy, which are considered as the terminal granting wider access rights to modes located in the forward direction than to modes located in the backward direction of the hierarchy.

[0148] right Figure 2C In this case, the terminal defines two unlock modes MD UL1 and MD UL2 With an intermediate mode MD IN A locked mode MD LK There are four modes in total, built on MD LK This includes a hierarchy with a "bifurcation" point. (And...) Figure 2A and Figure 2B Similarly, the terminal moves from the off state to the MD state according to the first user input provided by the user. LK In the case where the user provides a second user input, the terminal driven by the parallel hierarchy is accessed from the MD. LK Move to MD UL1 MD IN MD UL2 One of these three modes is a new mode, which may depend on the second user input, and in particular on the mode movement (user) specific input (UI) contained in the second user input. SWI Even if the user provides third-party input, the terminal may not run the mode-shifting job accordingly because of MD. UL1 MD IN and MD UL2 Neither the forward nor backward direction is connected to any pattern by an arrow.

[0149] right Figure 2D In this case, the terminal defines a locking mode MD LK Three intermediate modes MD IN1 MD IN2and MD IN3 Two unlock modes MD UL1 and MD UL2 Six patterns were defined, and an MD (Multi-Level Design) system with two branching points was constructed. LK With MD IN2 The hierarchy. The terminal receives information including the UI at each branch point. SWI User input can be based on the UI SWI Determine the new pattern and move it. Figure 2D Other tasks on the terminal and Figure 2C Other tasks on the terminal are similar.

[0150] exist Figures 2A to 2H In this hierarchy, each mode in a sequential order is connected to one or more adjacent modes in the forward or backward direction via arrows, but can be directly connected to non-adjacent modes without arrows. Therefore, given appropriate user input, the terminal can move from the current mode to a new adjacent mode accordingly. Furthermore, the sequential order does not include branching points where a mode is connected side-by-side to two or more adjacent modes in the forward or backward direction, nor does it include "merger points" where two or more modes are merged into an adjacent mode.

[0151] Unlike this, the branching point of a parallel hierarchy branches a pattern into multiple patterns. Therefore, more than one pattern defined by a parallel hierarchy can be connected to multiple adjacent patterns via forward or backward arrows. And two or more patterns in a parallel hierarchy can be merged into an adjacent pattern in the forward or backward direction via arrows. Thus, the terminal can define multiple parallel paths from more than one pattern to the forward or backward direction, and can move from one pattern to one of multiple adjacent patterns according to user input. As a result, a parallel hierarchy [1] may include a start pattern and multiple end patterns or [2] may include multiple start patterns and one end pattern or [3] may include multiple start patterns and multiple end patterns, and may also include intermediate patterns located between the start pattern and the end pattern.

[0152] Figures 2A to 2D The illustrated hierarchical structure exhibits the characteristic of moving from a mode with limited access permissions to a mode with wider access permissions. Therefore, the user arrives at... Figures 2A to 2D Unlock mode or reach Figure 2C and Figure 2DIn the intermediate mode, the user cannot move to a forward-facing mode. In this case, the user turns off the image unit, and the terminal can move from the on state to the off state (for example, "sleep mode"). Afterwards, if the user provides additional user input to the off-facing terminal (for example, "wake up" the terminal), the terminal can move to the locked mode. From this point of view, the "non-cyclic layer" in this specification can be referred to as (1) a layer in which the terminal is always allowed to move in the forward direction (i.e., from the mode with less access to the mode with more access) and (2) is not allowed to move in the reverse direction (i.e., from the mode with more access to the mode with less access) to the mode with more access, and a layer in which the terminal is not allowed to move in the reverse direction (i.e., from the mode with more access to the mode with less access) to the mode with less access. And the non-cyclic layer can be a sequential non-cyclic layer or a parallel non-cyclic layer.

[0153] The aforementioned illustrative hierarchies are based on the assumption that a user starts driving the terminal in a locked (or intermediate) mode with limited access permissions and wishes to move to an unlocked mode with wider access permissions. However, it is possible that other users start driving the terminal in an unlocked mode with wider access permissions and wish to move to a locked (or intermediate) mode with limited access permissions. For the latter, in this specification, a "non-cyclic hierarchy" can be a hierarchy in which the terminal, whether sequential or parallel, (1) allows the user to move backward, (2) but does not allow movement in the opposite forward direction. However, for ease of explanation, unless otherwise specified in the various examples in this specification, it is assumed that the user starts driving the terminal in a locked mode and wishes to move to an unlocked mode, and if necessary, wishes to move from the locked mode to an intermediate mode and then to the unlocked mode.

[0154] Unlike the non-cyclic hierarchy described herein, the "cyclic hierarchy" in this specification refers to a hierarchy in which the terminal, regardless of whether the hierarchy is sequential or parallel[1], allows the user to move forward (i.e., from a mode with fewer access permissions to a mode with more access permissions)[2] and allows the user to move backward (i.e., from a mode with more access permissions to a mode with fewer access permissions). Furthermore, depending on the characteristics of the path that allows movement in the backward direction, the cyclic hierarchy can be divided into "fully cyclic hierarchy" and "partially cyclic hierarchy," etc. The following figures are various examples of cyclic hierarchies, and in the following figures, the mode located in the forward direction is also considered to have wider access permissions than the mode located in the backward direction.

[0155] Figure 2E The terminal build defines a locking mode MD LK MD intermediate mode IN and unlock mode MD UL The terminal can move in a forward direction, therefore... Figure 2E social class and Figure 2A Their social classes are similar. However, they are different. Figure 2A , Figure 2E When the terminal receives appropriate user input, for example, it can retrieve data from the MD... UL Move to MD IN And can be obtained from MD IN Move to MD LK It can also move backward. This... Figure 2E The class that is in this class is called the "completely cyclical class".

[0156] Figure 2F The terminal also constructs and defines an MD LK MD IN and MD UL It can move forward. And when it receives appropriate user input, the terminal does not need to go through MD... IN , can be found in MD UL Move directly to MD IN That is, moving directly backward. This... Figure 2F The class that is in this class is called the "partially cyclical class".

[0157] Unlike the sequential and parallel hierarchies mentioned above, some hierarchies can be considered as a mixture of the sequential and parallel hierarchies. In this specification, a "mixed hierarchy" is an arrangement of multiple patterns, meaning (1) two or more patterns connected to form a sequential hierarchical structure, and (2) a hierarchy including one or more branching or merging points of parallel hierarchies. The following figures illustrate mixed hierarchies, and in these figures, patterns in the forward direction are also considered to have wider access than patterns in the backward direction.

[0158] Figure 2G In this case, the terminal builds a definition MD LK MD IN1 MD IN2 MD UL There are four modes in total. Within these modes, users can access MD... LK Move to MD IN1 (or MD) IN2 After that, move to MD UL Therefore, the hierarchy can be considered as a sequential hierarchy. However, the MD of the hierarchy LK Forked to MD IN1 and MD IN2 On the other hand, MD IN1 With MD IN2 Merge into MD UL That is, the hierarchy can be viewed as a non-cyclic hybrid hierarchy that prevents the user from moving backward.

[0159] Figure 2H Terminal like Figure 2G The same four modes are defined to build and Figure 2G The same connected hierarchical structure. But Figure 2 can be used as an example. Figure 2H The hierarchy is considered to also include the terminal's ability to access MD. IN2 Move to MD LK The path is a hybrid hierarchy. And the hierarchy is equivalent to the terminal being able to access the MD... IN2 Move to MD LK The cyclic hierarchy that the terminal can move backward.

[0160] Furthermore, the terminal can construct more complex sequential, parallel, or mixed hierarchical structures than those illustrated above. The terminal can also construct these hierarchical structures as cyclic or non-cyclic. The following figures illustrate the specific configuration of the main system and the locking system, as well as each of the described hierarchical structures.

[0161] Users can utilize the various hierarchies for a variety of purposes. As an example, a user can define multiple modes after constructing a hierarchy. Examples of such modes include [1] an unlocking mode MD that allows the user to drive the locking system and access all accessible hardware and software elements of the main system. UL [2] A user-driven locking system including a lock viewer and optionally a lock memory unit or a lock CPU unit, comprising a locking mode MD. LK Or [3] a user-driven intermediate system that can only drive some elements of the main system or lock the system, rather than all of them, in one or more intermediate modes (MD). IN wait.

[0162] The terminal may, according to the user's needs, not define any MD at a specific level[1]. IN Or [2] define multiple MDs that are given the same or different access permissions. UL Or [3] define multiple MDs that are given the same or different access permissions. LK .

[0163] In addition to defining the various modes mentioned above, the terminal can also physically or operationally isolate various units of the main system from the locking system [1] or completely or partially isolate them [2]. The terminal can also perform erase (or partial erase) operations at various times. Therefore, the terminal can correspondingly [1] improve the security of the main system or [2] improve the integrity of the main system or [3] more securely protect the personal information stored in the main system in response to the locking system.

[0164] A user can utilize multiple operating modes defined by the hierarchy for various purposes. As an example, a user can drive the terminal in each mode according to different purposes. For example of the purposes, [1] the user accesses all data stored in the main system of the terminal or drives all accessible hardware or software elements of the main system in the unlocked mode for personal business, or [2] the user accesses only the minimum amount of data stored in the main system of the terminal or drives only the minimum elements of accessible hardware or software elements of the main system in the locked mode for business, or [3] the user can access only a portion of the data stored in the main system or drive only some elements of the main system in the intermediate mode for semi-personal and semi-business intermediate events.

[0165] A user can apply multiple operating modes defined by hierarchy to various operating modes. For example, a user can physically or operationally combine their terminal with other electronic devices and operate the devices using their own terminal. Especially when a user shares the device with others, there is a risk of malicious viruses infiltrating the user's terminal, leading to a decrease in terminal security or integrity, or the theft of personal data, financial data, etc., stored on the terminal's main system. When the terminal is connected to the device, and the user is driving the terminal in locked mode while performing erase (or partial erase) operations at multiple erase points, the user can erase malicious viruses that have successfully infiltrated their terminal before they infiltrate the unlocked terminal. The following are several examples of driving the terminal in this situation.

[0166] According to the first embodiment utilizing the erasure (or partial erasure) operation, a user can physically or operationally attach their terminal to a vehicle and perform operations such as guiding the vehicle to its destination through the terminal. As an example, to operate the vehicle, the user can utilize the hardware or software elements of the terminal's main (or locked) system, or provide data from the terminal to the vehicle's computer system. Examples of vehicles include cars, motorcycles, bicycles, airplanes, helicopters, drones, speedboats, and ships of various shapes and sizes.

[0167] In the first specific example, when a user operates multiple elements of the terminal's master (or locked) system or uses data stored in the master (or locked) system to operate their own vehicle, the user can operate the terminal in unlocked mode. This is because, unless the user is extremely careless, the risk of potential malicious viruses on the user's own vehicle's computer is low. Therefore, provided that the terminal's master system and the vehicle's computer system are partially or completely isolated, the operation of connecting the terminal to the vehicle and operating it in unlocked mode can generally be considered safe.

[0168] In the second specific example, when a user shares a vehicle with their family or colleagues, a malicious virus may infiltrate the vehicle's computer system as the careless child or colleague downloads suspicious files from a website with low credibility. As the vehicle is used, the risk of the terminal becoming infected with the malicious virus increases. In the case of a user sharing a vehicle with someone they know but do not fully trust, the user may drive the terminal in an intermediate mode and [1] drive only (not all) elements of the terminal's main (or locked) system, operate the vehicle using only (not all) of the data stored on the terminal, or [2] drive the hardware or software elements of the intermediate system to operate the vehicle.

[0169] In the third specific example, when a user wants to operate a vehicle shared with someone they don't know, the risk of a malicious virus that has already infiltrated the vehicle's computer system infiltrating their own terminal is higher. This risk is particularly high when the vehicle is a rental vehicle, a shared vehicle, or a publicly used vehicle. In this case, the user can operate the vehicle in locked mode by driving the hardware or software elements of the locking system, or by simply utilizing the data stored in the locking system. Simultaneously, the terminal can isolate its main system from the vehicle's computer system to prevent any adverse effects that a malicious virus infiltrating the vehicle's computer system might have on the terminal's main system.

[0170] In the second embodiment utilizing the erasure (or partial erasure) operation, the user can physically or operationally connect the terminal to the computer and operate the computer with their own terminal to obtain the desired result. For example, the user can operate the computer by driving the hardware or software elements of the terminal's main (or locked) system or by providing data from the terminal to the computer. Examples of such computers include computers shared with others in public PC stations, bars, school PC labs, etc. Various configurations and methods of the first embodiment described above can also be applied in this case.

[0171] In its first specific example, a user can operate their terminal in unlocked mode to control their computer. This allows them to control various elements of the main (or locked) system or provide all data stored on the terminal to the computer. However, unless the user is particularly careful, the risk of a virus on their computer is not high. Therefore, the user can completely or partially isolate the terminal's main system from the computer, connecting their terminal to their computer and operating it in unlocked mode.

[0172] A second specific example is the situation where a user shares a computer with family members or colleagues, where the risks may be higher than those described above. Therefore, a user can drive the terminal and control the computer only in intermediate mode. For this purpose, the user can drive only some elements of the main (or locked) system, rather than all elements, and access only some data stored in the system, rather than all data, or drive the hardware or software elements of the intermediate mode.

[0173] A third specific example is a situation where a user wants to control a computer shared with someone they don't know using their own terminal, in which case the computer is highly likely to be infected with a malicious virus. Therefore, the user can drive specific hardware or software elements of the locked system, or operate the computer in locked mode using only specific data stored in the locked system. Furthermore, the terminal isolates the main system from the computer, thus preventing any adverse effects that a malicious virus invading the computer might have on the user's main system.

[0174] Configurations identical or similar to those described in the two embodiments above can also be applied to different situations. According to yet another embodiment, when a user connects their terminal to a control panel in a public video game center, public sports bar, etc., the user can operate the terminal only in locked (or intermediate) mode. Alternatively, when a user connects their terminal to the control panel for video games, virtual sports, etc., the user can operate the terminal in locked, intermediate, or unlocked mode depending on the potential risks posed by the control panel.

[0175] Therefore, whenever a user connects their terminal to an external electronic device or network for physical or operational purposes, or whenever a user does not fully trust the security of the device or network, the user can drive the terminal in locked mode or other restricted mode, and then perform an erase (or partial erase) operation before moving to unlocked mode.

[0176] As mentioned above, different tiers can offer users various benefits, such as user convenience or terminal security. However, advantages like user convenience and seamless operation can also increase the risk of potentially compromising terminal security or integrity. For example, a circular tier can offer benefits to some users.

[0177] As an example, when a user is using an unlocked terminal, they might hesitate to download files from unfamiliar websites due to concerns about malicious viruses. However, in locked mode, the terminal's main system and the locking system are isolated. Therefore, the user can move backward—from unlocked mode to an intermediate mode, then from an intermediate mode back to locked mode—and then download files from unfamiliar websites in locked mode without worrying about potential adverse effects from the downloaded files or content.

[0178] As explained above, the cyclic hierarchy provides a means for users to move to a mode with fewer access permissions from the unlocked mode without having to turn off the imaging unit (i.e., move to the off state) and then turn it back on (i.e., move to the lock mode, which is the basic setting mode that is on). Terminals operating according to the cyclic hierarchy can offer flexibility in moving modes.

[0179] However, this doesn't mean that acyclic layers offer no benefits to the user. In fact, acyclic layers inherently prevent users from moving from unlocked mode to locked (or intermediate) mode, thus providing additional stability to the device. Of course, this added stability of acyclic layers might be disliked due to the inconvenience associated with moving backwards between modes.

[0180] Therefore, a terminal can be constructed with multiple tiers that define various modes to optimize security and integrity, protect personal data stored on the main system, and allow users to comfortably use the terminal. The construction and definition of these multiple tiers are typically related to the choices made by technical personnel in the relevant fields; therefore, a more detailed explanation is omitted.

[0181] 1-6. Deletion and Erase

[0182] When a terminal (more specifically, the terminal's CPU or operating system) drives multiple hardware or software elements, various traces of data, files, folders, etc., remain on the terminal. In this manual, "products" refers to the data, files, or folders left behind by the terminal's locking (or intermediate) system during or after the locking (or intermediate) mode operation.

[0183] In this specification, "delete" refers to the deletion of a direct pointer to a data sector containing or with remnants of "products" (that the user wishes to delete). However, these "products" may remain as remnants after deletion due to data remanence. Furthermore, these "products" may be recoverable after simple deletion. In other words, when a terminal runs a locking operation using the locking system in locked mode, some "products" may remain in the locking system. Therefore, even after the terminal "deletes" the "products" from the locking system and moves from locked mode to unlocked mode, some "products" may still remain on the terminal. If these residual "products" contain malicious viruses, the viruses can infiltrate the main system when the user uses the terminal in unlocked mode, potentially causing negative impacts on the main system.

[0184] As mentioned above, even if the user "deletes" the "products" obtained by running a locking operation through the locking system in locked (or intermediate) mode, some of them may still remain in the locking system. Therefore, simply "deleting" them is not enough to prevent the residual "products" from having a negative impact on the terminal's main system or various accessible hardware or software elements of the main system.

[0185] In contrast to the term "delete," in this specification, "erase" refers to the operation of erasing the "products" stored or remaining in the memory cell without affecting the operation of the memory cell. That is, "erase" can erase not only the aforementioned direct pointers but also the "products" stored or remaining in the memory cell or memory sector. Furthermore, the "products" erased as described above cannot be recovered by others. Even if a skilled technician were able to recover the erased "products," the process would be extremely difficult. Therefore, "erase operations" may be necessary to enhance security for one of the various purposes of the data processing terminal described in this specification.

[0186] Therefore, the various data processing terminals described in this specification enable users to erase all or part of the "products (for example, text, images, files, etc.)" obtained by running a locking (or intermediate) operation using a locking (or intermediate) system in locked (or intermediate) mode. The locking system may include one or more locking memory units capable of temporarily or permanently storing the "products". The locking memory unit may be [1] a memory unit or memory sector that is part of the locking system, or [2] a memory unit or memory sector contained in the main system but that the locking system can use in modes other than unlocked mode.

[0187] Compared to the term "erase," in this specification, "semi-erase" refers to erasing a portion, rather than all, of the "product" obtained by performing a locking (or intermediate) operation using a locking (or intermediate) system in locked (or intermediate) mode, which may be stored or remain in the locked memory cell. "Semi-erase" only erases a portion of the "product," therefore the remaining portion of the "product" does not affect the operation of the locked memory cell and can be stored in the locked memory cell or locked memory sector. In other words, "semi-erase" erases only a portion of the "product (including residual portions)" obtained by performing a locking (or intermediate) operation using a locking (or intermediate) system in locked (or intermediate) mode, and may or may not perform an active storage operation to leave the remaining portion intact in the memory cell.

[0188] The terminal (for example, the main system, intermediate system, or locking system) can perform the "erase" operation on various hardware or software elements of the system. For example, the terminal can perform an "erase operation or partial erase operation" on the main memory unit of the main system, the intermediate memory unit of the intermediate system, or the locking memory unit of the locking system. The terminal can also perform an "erase (or partial erase) operation" on temporary memory sectors of the main, intermediate, or locking systems, such as the data buffer, cache, clipboard, and recycle bin of the main system, intermediate system, or locking system.

[0189] In this specification, “erased products” refers to the “products” of the terminal “erased” when the terminal allows the user[1] to move from a locked mode (or the current mode different from the locked mode) to a new mode or[2] to move from an on state to a off state. “Erased products” refers to erased text, erased images, erased files, erased folders, erased applications, or other erased results. “Erased products” is a general term for[1] the results obtained by the locked (or intermediate) system running a locked (or intermediate) operation in the locked (or intermediate) mode or[2] the results remaining in the locked (or intermediate) system.

[0190] In this specification, whenever the statement "protect the main system against erased products" is used, it does not mean that the terminal protects the main system against the products after erasing them. Rather, the statement indicates that if the terminal does not erase the "erased products," it cannot protect the main system against the "erased products," but the terminal protects the main system by erasing the "erased products." Similarly, in this specification, "planned erased products" refers to products currently mixed with "planned storage products" but which will be erased later; otherwise, they can be the same as the "erased products" mentioned above.

[0191] In this specification, "stored products" refers to products that are not erased from the terminal but stored in the locking system or main system. In other words, "stored products" refers to all products obtained by running a locking (or intermediate) operation in locked (or intermediate) mode, excluding "erased products". Similarly, in this specification, "planned storage products" refers to products currently mixed with "planned erasing products" but which will be stored later, otherwise they may be the same as the "stored products" described above.

[0192] The terminal can change the above "erase" or "partial erase" to "formatting", "reformatting", or "initializing" of specific hardware elements. The terminal can run the formatting or initialization operation under specific circumstances, such as [1] when a predetermined time has passed since the last formatting or initialization, [2] when the terminal finds suspicious data, code, files, etc. that may contain malicious viruses from memory units, temporary memory sectors, etc., or [3] when the terminal finds hardware or software elements that are malfunctioning.

[0193] The formatting and initialization described above are special cases of erasure and partial erasure. Therefore, the terminal can run formatting or initialization operations at various "erasure time points." Similar to the erasure and partial erasure cases, the terminal can completely format or initialize specific hardware elements, or only format or initialize a portion of them.

[0194] When a terminal formats or initializes a specific hardware element, all software elements installed on that element may also be deleted. Therefore, when formatting or initializing a locking system, the terminal can determine which data or code from various types of data or computer code in the locking system should be deleted.

[0195] As an example, a terminal can partially format or partially initialize only the data stored or remaining in a locked memory cell or a temporary locked memory sector. Here, the terminal can exclude the locked operating system or locked (software) application from the partial formatting and partial initialization. To this end, the terminal can [1] store the locked operating system, locked application, etc. in a location that is safe to perform the partial formatting or partial initialization, such as a locked basic input output system (i.e., BIOS), or other storage locations, or [2] explicitly specify the memory sectors to be partially formatted or partially initialized while excluding the other sectors from partial formatting or partial initialization. However, since the locked system includes a runnable locked operating system or locked application, the terminal can immediately operate in locked mode after partial formatting or partial initialization.

[0196] In another specific example, the terminal can delete all data or computer code stored or existing in the locked system through (complete) formatting or (complete) initialization. Therefore, the terminal can erase not only the locked operating system and locked applications, but also the locked viewer. Consequently, the erased locked system does not contain a runnable locked operating system or locked applications, and therefore the terminal will not immediately run in locked mode after formatting or initialization. Therefore, the terminal needs to reinstall the locked operating system, locked applications, etc., into the locked system.

[0197] In other specific cases, where the locking system includes a locking application but not a locking operating system, the locking system cannot drive the application itself. Therefore, the main operating system or main CPU unit can drive the application instead of the locking system. Thus, if the application remains in the locking system after the terminal performs a partial formatting or initialization operation, the main system can use the main CPU unit or main operating system to drive the application immediately after the formatting or initialization operation.

[0198] However, if the terminal completely formats or initializes the locking system, the main system can assist the locking system in performing locking operations after the application is reinstalled onto the locking system. The situation where the locking system includes the locking application and the driver that drives the application is similar to the situation where the locking system includes the locking CPU unit; therefore, a detailed description of this is omitted.

[0199] 1-7. Image Units and Image Screens

[0200] The data processing terminal of this specification includes one or more (main) image units that define an image screen capable of displaying images. Examples of images may include still images such as photographs, moving images such as videos, etc. The images may be black and white, color, or a combination thereof. Therefore, the image unit can [1] display one or more still images of text, words, text, pictures, photographs, other things or people on the image screen, or [2] display video games, videos, or moving images (of text, words, text, pictures, comics, other things or people) on the image screen.

[0201] The terminal can [1] store multiple static or dynamic images and represent them one by one, or [2] display the images after receiving them from external sources such as disassembly devices, portable devices, other terminals, and websites. Regarding [2], the terminal can display the images either after acquiring them or at the same time as acquiring them. The image display primarily represents a portion of the image unit, which is one of the hardware elements of the terminal's main system. In particular, if a user wants to display a specific static or dynamic image, they need to drive the image unit; therefore, the image unit can be considered one of the accessible hardware elements of the main system.

[0202] An image frame can be defined as a segment, in which case the image frame becomes identical to the segment. However, when an image frame is defined as multiple segments, image units can display the same or different images simultaneously or sequentially in different segments.

[0203] Similarly, a terminal may include multiple image units, each having the same shape or size and performing the same function. Alternatively, the multiple image units may have different shapes, sizes, or perform different functions, or be installed in different parts of the terminal. In the latter case, one image unit performs the function of a main image unit, while other image units may perform the function of a sub-(or auxiliary) image unit. Furthermore, each image unit includes an image frame, the shape and size of which may be the same or different.

[0204] As described below, the various "notification units" in this specification can also be used as one of the multiple image units. Furthermore, when the terminal includes multiple notification units, each notification unit may have the same, similar, or different functions capable of displaying static or dynamic images at a specific resolution and color. The notification unit is responsible for providing visual notification signals to the user; therefore, the notification unit may be smaller than the image unit, or may display simpler static or dynamic images compared to the image unit. Alternatively, an image unit may use a portion of an image frame as a notification unit.

[0205] When a terminal includes multiple image units, the terminal can drive each image unit simultaneously, sequentially, or independently in time. For example, the terminal can [1] turn on the first image unit whenever the second image unit is turned on, or [2] turn off the first image unit whenever the second image unit is turned on, or [3] turn on (or off) two or more image units in a specific order, or [4] turn each image unit on or off independently. As explained below, the terminal can make the image units continuously display daily data such as time and date. Furthermore, the terminal can drive multiple image units through the same software element or drive each image unit through different software elements.

[0206] Unlike the examples above that include more than one imaging unit, a terminal may not include an imaging unit. The terminal may be configured to be detachably combined with an external imaging device, which is a device independent of the terminal. This allows the terminal to be configured with a smaller shape and size. Of course, a terminal including an imaging unit can also assist the main system's imaging unit by combining with an external imaging device.

[0207] 1-8.Screen

[0208] In this specification, "screen" refers to the image displayed on the image unit of the terminal. The screen can be [1] black and white or color or [2] two-dimensional (2-D) or three-dimensional (3-D) or [3] a 2-D image, a 3-D image or a holographic image. The screen can be a static screen that does not change over time or a dynamic screen that changes over time. From this point of view, the screen may include one or more windows, in which case the user can drive various software elements of the main system in each window.

[0209] When the image unit is turned on (i.e., the terminal is in the on state), a screen is displayed on the image screen of the image unit, and the user can see the screen. Therefore, any image displayed on the image screen can be called a screen, and examples of screens include [1] static images of one or more characters, words, text, pictures, photos, objects or people, [2] dynamic images such as video games, or [3] videos or dynamic images of objects or people. Furthermore, from the viewpoint of content, the screen may include one or more advertisements, content, warnings, instructions, etc. Furthermore, the screen may be an "unlock screen (or home screen)" displayed in unlock mode, a "lock screen" displayed in lock mode, and a "middle screen" displayed in intermediate mode, etc.

[0210] In this specification, an image unit that displays only images related to "daily data" is considered to be in an "off" state, and therefore the terminal is considered to be in a closed state. Furthermore, when the terminal includes a main image unit and a sub-image unit, and the main image unit is in an off state while the sub-image unit only displays daily data, the image unit is considered to be in an "off" state and the terminal is considered to be in a closed state. Also, when the terminal includes only one image unit with a main block and a sub-block, and the main element is in an off state while the sub-element only displays daily data, the image unit is considered to be in an off state as well.

[0211] Typically, routine data refers to data that a terminal can obtain without running tasks based on user input.

[0212] "Daily data" typically relates to information such as time or date, clock or stopwatch, remaining battery level, temperature, weather, wireless communication connection status, alarms, new emails, new messages, received calls, and calendar notifications. Furthermore, if the terminal displays the daily data or other information on the image unit, but approximately 80% or more of the pixels of the image unit are off, this specification considers the image unit to be in an "off" state, and the terminal to be in a "power-off" state.

[0213] 1-9. Simultaneously or sequentially

[0214] In this specification, "simultaneously" means that multiple tasks or steps occur or exist at the same time. It is defined as the user providing multiple user inputs to one or more input units at the same time. Specifically, when a user "simultaneously provides multiple user inputs to the terminal," it is considered that the user has provided the multiple user inputs simultaneously if there is more than one common clock cycle in the terminal's processor clock cycle where multiple user inputs are provided. That is, this is a situation where multiple user inputs are not completely separated by time gaps, but rather overlap in time with each other in the common clock cycle.

[0215] Similarly, when a terminal runs multiple jobs (or steps) at the same time, it is considered that the terminal is running multiple jobs (or steps) "simultaneously". Therefore, when a terminal runs multiple jobs or steps simultaneously, it is considered that the terminal is running multiple jobs or steps in more than one common clock cycle of the processor. This is a case where multiple jobs or steps are not completely separated from each other by time gaps, but overlap with each other in the common clock cycle.

[0216] Figure 3 It is an example diagram that marks the jobs or steps running simultaneously along the clock cycle of the processor in the data processing terminal. Figure 3 In case (A), the terminal's processor (hereinafter referred to as the "terminal") runs job (or step) A1 from clock cycles 003 to 010 (a total of 8 clock cycles). The terminal also runs job (or step) A2 from clock cycles 009 to 019 (a total of 11 clock cycles). Since jobs (or steps) A1 and A2 overlap during clock cycles 009 and 010, they can be considered as the terminal executing jobs (or steps) A1 and A2 "simultaneously" according to the above definition.

[0217] Figure 3 In case (B), the terminal runs job (or step) B1 from clock cycle 003 to 002 (a total of 18 clock cycles) and job (or step) B2 from clock cycle 020 to 030 (a total of 11 clock cycles). Jobs (or steps) B1 and B2 overlap in one clock cycle 020, therefore, according to the above definition, the terminal can be considered to execute jobs (or steps) B1 and B2 "simultaneously".

[0218] Figure 3Terminal (C) runs job (or step) C1 for one clock cycle 023 (1 clock cycle in total), and runs job (or step) C2 from clock cycle 003 to 090 (88 clock cycles in total). Although job (or step) C1 is one tenth the length of job (or step) C2, the jobs (or steps) overlap with each other in a common clock cycle 23. Therefore, according to the above definition, the terminal can be regarded as executing job (or step) C1 and C2 "simultaneously".

[0219] Figure 3 Terminal (D) runs job (or step) D1 from clock cycle 005 to 014 (10 clock cycles), job (or step) D2 from clock cycle 012 to 022 (11 clock cycles), and job (or step) D3 from clock cycle 016 to 1015 (1000 clock cycles). Jobs (or steps) D1 and D2 overlap from clock cycle 012 to 014, so they can be considered as the terminal running jobs (or steps) D1 and D2 "simultaneously". Similarly, jobs (or steps) D2 and D3 overlap from clock cycle 016 to 022, so they can also be considered as the terminal running jobs (or steps) D2 and D3 "simultaneously". However, jobs (or steps) D1 and D3 do not overlap in any clock cycle, so they are considered as the terminal not running jobs (or steps) D1 and D3 simultaneously. Instead, jobs (or steps) D1 and D3 are separated by a time gap of clock cycle 15.

[0220] Regarding the simultaneity of the execution of three or more jobs or steps in this specification, it is defined as the terminal "simultaneously" executing three or more jobs or steps, provided there is no time gap between the start clock cycle of the first job (or step) to start and the end clock cycle of the last job (or step) to end. Based on this definition, it can be considered as... Figure 3 The terminal of (D) runs jobs or steps D1, D2 and D3 "simultaneously". The reason is that the three jobs (or steps) of the terminal start from D1 and end at D3, and there is no clock cycle in between in which the terminal does not run any of the jobs (or steps) of D1, D2 and D3.

[0221] In this specification, "sequentially" refers to a specific arrangement in which the terminal runs one job (or step) at a time or sequentially. "Sequentially" means that the terminal runs one of multiple jobs (or steps) at time intervals according to a specific arrangement. Furthermore, "sequentially" and "run one at a time" have the same meaning. Therefore, it can be considered as... Figure 3 When the terminal of (D) runs job (or step) D1 and D3, they run sequentially with a time gap between them.

[0222] 1-10. User Input

[0223] In this specification, “user input” means input provided by a user to the input unit by directly or indirectly operating one or more parts of the terminal’s input unit. The user may provide user input using their own body parts or (non-user) objects such as styluses or pens. For ease of explanation, the phrase “providing user input” to one or more input units of the terminal is referred to as [1] the user providing user input using one or more parts of their own body or [2] the user providing user input using one or more objects that the terminal’s input unit can recognize or [3] the terminal acquiring the user’s biometric information or [4] the terminal acquiring electromagnetic waves or sound waves related to the user.

[0224] In the case of the first embodiment associated therewith, the user can "directly operate" one or more parts of the input unit of the terminal. As an example, the user can use their own body parts or objects to move one or more movable parts of the input unit or contact one or more parts of the input unit to directly provide user input. When moving the movable part, the user can move the part for a specific duration or for a duration of their choice. When contacting the part, the user can [1] maintain the contact between their own body parts or objects and the part of the input unit for a predetermined duration or [2] maintain the contact while moving their own body parts or objects to change the position of the contact.

[0225] In the case of the second embodiment, the user can indirectly provide user input by providing various waves to the input unit without directly manipulating the input unit. In the case of the first embodiment, the user can provide electromagnetic waves or sound waves to the input unit, including information related to the user input. The information provided by the electromagnetic waves is the user image or characteristics of the waves (for example, amplitude, frequency, phase angle, phase delay, etc.), and the information provided by the sound waves includes the user's voice, sounds produced by the user's body parts, etc. Therefore, when the input unit acquires user images such as the user's face, iris, and retina for authentication, the image can be considered as user input. Similarly, when the input unit acquires user voice for user authentication, the voice can also be considered as user input.

[0226] The user input includes more than one specific input. Therefore, when a user provides user input to the input unit, the input unit "receives" the user input, and a sensor installed on the input unit "acquires" the specific user input from the user input. Therefore, when the user input includes one specific input, the user input can be equivalent to the specific user input.

[0227] Alternatively, if the user input includes multiple specific inputs, one or more input units receive the user input, and one or more sensors of the input units acquire the specific inputs from the user input. For ease of explanation, unless otherwise specified in this specification, "user input" and "specific input" can be collectively referred to as "user input." Furthermore, "specific input" can be simply referred to as "specific input."

[0228] Depending on the structure or operational characteristics of the input unit, the user can provide various types of user input. For example, the user can provide several user inputs by directly operating the input unit, and provide the remaining user inputs indirectly instead of directly operating them.

[0229] In this specification, user input can be classified as follows based on its type and nature. As an example, “first type of user input” is “mechanical user input” provided by the user directly operating one or more parts of the input unit. Examples of first type of user input include [1] “activation” of one or more parts of the input unit (for example, pressing, pushing, pulling, lateral pushing, rotating, rotating around the central axis or by other methods), [2] “contact (or touch)” with said part, or [3] a combination of said activity and contact.

[0230] Other examples of the first type of user input are the user's "mechanical biometric information." Examples of this type of user input include blood pressure or heart pulse measured from a specific part of the user's body, blood flow rate measured at a specific location, other information about the cardiovascular system, respiratory rate and flow rate during rest or exercise, other respirator information, and muscle or skeletal biometric information. As mentioned above, the mechanical user input includes specific mechanical (user) input.

[0231] The first type of user input can also be related to the static or dynamic characteristics of mechanical user input. Examples of this first type of user input include [1] a (scalar or vector) force related to the movement of the part of the input unit or contact with the part, [2] the (scalar or vector) velocity of the movement, [3] the (scalar or vector) acceleration of the movement, [4] the (scalar or vector) displacement based on the movement, [5] the direction of the force, velocity acceleration or movement, [6] the direction of the contact, [7] the duration of [1] to [6] above, [8] the number of [1] to [6] above, [9] the time overlap between [1] to [6] above,

[10] the time gap between [1] to [6] above, etc. The first type of user input also includes the "mechanical characteristics" of the body parts of the user or the object to which the input is provided to the part of the input unit. Examples of this type of user input include elasticity, roughness, various moduli, etc. The magnitude or frequency of the force applied to the sensor of the input unit is also an example of this type of input.

[0232] In this specification, "second type of user input" refers to "electronic user input." Second type of user input is equivalent to providing electronic signals to one or more parts of an input unit capable of receiving and obtaining specific electronic (user) input. For example, a user may provide DC or AC electronic signals to the input unit using a specific pen or wearable device, other mobile device, or other terminals. Users may provide electronic biometric information from body parts as second type of user input, examples of which include electrocardiograms (ECG), electromyograms (EMG), electroencephalograms (EEG), and other electronic signals measured from specific body parts.

[0233] The second type of user input can also relate to the static or dynamic characteristics of electronic user input. Examples of this type of user input include current, voltage, its magnitude (or amplitude), phase angle, phase delay, frequency, wavelength, and (scalar or vector) flux. The second type of user input can also include providing the "electronic characteristics" of the user's body part or object to an appropriate location on the input unit. Examples of this type of user input include the resistance, conductivity, capacitance, permittivity, thermoelectricity, and dielectric properties of the said part or object, which can be determined from a static (or dynamic) electric or magnetic field. As an example, user fingerprints measured using a capacitive sensor in a capacitive input unit also fall under the category of the second type of user input.

[0234] In this specification, "third type user input" refers to "magnetic user input." Third type user input is equivalent to providing a magnetic signal to one or more parts of an input unit capable of receiving and obtaining specific magnetic (user) input. For example, a user may provide a DC or AC magnetic signal to the input unit using a specific pen, wearable device, or other mobile device, or provide a magnetic signal using other terminals. Users may provide magnetic biometric information from body parts as third type user input. Examples of such biometric information include magnetocardiogram (MCG), magnetomyogram (MMG), magnetoencephalogram (MEG), and other magnetic signals measured from specific body parts.

[0235] The third type of user input can also be related to the static or dynamic characteristics of magnetic user input. Examples of this third type of user input include the magnitude or direction of the B-magnetic field or H-magnetic field, the number of magnetic poles, phase angle, phase delay, frequency, wavelength, and (scalar or vector) flow. The third type of user input also includes the "magnetic properties" of the body part or object to which the user provides input to one or more parts of the input unit. Examples of such magnetic properties include the magnetic polarity, permeability, and susceptibility of the body part or object, which can be determined from a static (or dynamic) magnetic field (or electric field).

[0236] In this specification, "fourth type of user input" refers to "electromagnetic user input." Fourth type of user input is equivalent to electromagnetic waves provided to one or more parts of an input unit capable of receiving this fourth type of user input and obtaining specific electromagnetic (user) input from it. For example, a user may provide electromagnetic waves to the input unit using a specific pen, wearable device (i.e., a clock, ring, necklace, bracelet, contact lens, glasses, etc.), other mobile device, or other terminals.

[0237] Furthermore, users can provide the input unit with images of "body parts" such as the face, iris, retina, or other body parts, or images of "non-user objects," via electromagnetic waves in the visible light region, UV, IR, or other frequencies. These images can be still images, videos, or combinations thereof. In the case of providing a fourth type of user input via electromagnetic waves in the visible light region, the input can be equivalent to "optical user input."

[0238] The fourth type of user input can be related to the static or dynamic characteristics of electromagnetic user input. Examples of this fourth type of user input include the amplitude, phase angle, phase delay, wavelength, frequency, and (scalar or vector) flow of electromagnetic waves. When the fourth type of user input is an image, it can include the image's color (for example, hue, color value, intensity, etc.), size, color contrast, content contained in the image, and the image's arrangement or orientation. As described above, electromagnetic fourth type of user input can include more than one specific electromagnetic (user) input.

[0239] In this specification, "Fifth Type User Input" refers to "Audio User Input." Fifth Type User Input is equivalent to providing acoustic waves to one or more parts of an input unit capable of receiving and obtaining specific acoustic (user) input. For example, a user may provide acoustic waves to the input unit using a specific pen, wearable device (i.e., clock, belt, ring, necklace, bracelet, earring, contact lens, artificial nails, gloves, helmet, hat, belt, goggles, glasses, shoes, etc.), or other wearable devices, or by using other terminals. Furthermore, a user may provide their own voice or sounds generated by their own body parts to the input unit (for example, clapping, snapping fingers, etc.). A user may also provide sounds unrelated to their own body parts to the input unit; these sounds may be sound waves within audible frequencies, ultrasound, or other specific frequency bands.

[0240] The fifth type of user input can also be related to the static or dynamic characteristics of acoustic user input. Examples of this fifth type of user input include the amplitude, phase angle, phase delay, wavelength, frequency, and flow of sound waves. When the fifth type of user input is a sound emitted by the user's voice or body part, it can include the duration, tone, envelope, and location of the source of the voice or sound. Furthermore, the fifth type of user input can include more than one acoustic (user) specific input.

[0241] User input can be any of the aforementioned variations over time. For example, changes in the activity or the magnitude of the force applied to the input unit over time are examples of user input. User input can also be spatial variations of the aforementioned variations. For example, changes in the position of the user's body part in contact with the input unit or changes in the distribution of the force applied by the user to a specific part of the input unit are examples of user input.

[0242] 1-11. A user input

[0243] With in chapter 1-9 Similar to the definition of "simultaneous," unless otherwise specified, "a simultaneous effort (or action)" is simply referred to as "an effort (or action)" or "an effort," etc. For example, it refers to [1] one effort (or action) performed by the user or [2] multiple efforts (or actions) of the same or different performed by the user simultaneously. Therefore, for multiple "efforts or actions" (hereinafter referred to as "efforts") to occur simultaneously, there must be one or more common clock cycles in the clock cycle of the terminal's processor where the user is simultaneously performing multiple efforts. That is, multiple efforts must overlap in one or more common clock cycles. And when the user performs more than three efforts (or actions), it can be determined according to the chapter. 1-9 and[ Figure 3 The definition of "simultaneous" in the description determines whether the effort (or action) is "simultaneous".

[0244] Unless otherwise specified, in this specification, "user input" has the same meaning as "a user input". Therefore, "user input" or "a user input" refers to user input provided by the user to more than one part of the input unit, as described in the section. 1-10 The description indicates that the first type of user input is provided to one or more input units of the fifth type of user input through direct operation, indirect operation, or other operation. That is, when a user provides multiple user inputs simultaneously through one effort, the user input can be regarded as a single user input. However, when a user provides multiple user inputs sequentially rather than simultaneously through multiple efforts, the user input can be regarded as a single user input.

[0245] Therefore, a first-type user input or a third-type user input can each be considered as a single user input provided to the input unit by the user's simultaneous effort. Furthermore, if the user provides two first-type user inputs to the input unit by the user's simultaneous effort, that user input can also be considered as a single user input. Similarly, if the user provides three fifth-type user inputs to the input unit by the user's simultaneous effort, that user input can also be considered as a single user input. Finally, if the user provides one first-type user input and three fourth-type user inputs to the input unit by the user's simultaneous effort, that user input can also be considered as a single user input.

[0246] In the case of the first embodiment associated therewith, a user can press a finger on the first input unit and move the finger on the first input unit. If the user continues to press the first input unit while moving the finger (i.e., without removing the finger from the first input unit), the pressing and the moving can be considered as a simultaneous effort by the user. This is because, from the perspective of the terminal's processor clock cycle, the user performs the pressing and moving in more than one common clock cycle.

[0247] However, if the user removes their finger from the first input unit and then presses it again after moving their finger, there is a time gap between the pressing and the movement. Therefore, the pressing and the movement generally do not equate to a (simultaneous) user input. But as described in the following sections... 1-12 If the time gap is shorter than, for example, 1.5 seconds, 1.0 seconds, 0.5 seconds, or 0.3 seconds, the press and the movement can be regarded as a (simultaneous) user input.

[0248] In the related second embodiment, the user provides their facial image to the third input unit by gazing at a camera or similar device while touching the second input unit. If the user provides the image during this contact, the contact and image provision can be considered a single (simultaneous) effort as long as there is one or more common clock cycles within the processor clock cycle where the user's contact and image provision occur simultaneously. That is, there is no time gap between the contact and image provision, thus it can be considered equivalent to a single (simultaneous) effort.

[0249] In the case of the related third embodiment, the user presses the first input unit with a first finger and touches the fourth input unit with a second finger. Therefore, as long as there is a common clock cycle on the processor clock cycle where the user simultaneously performs the pressing and touching, or there is no time gap between the pressing and touching, the pressing and touching can be regarded as a (simultaneous) effort.

[0250] However, users live in a world defined by seconds, hours, days, weeks, years, etc., while the terminal's processor works in a world defined by nanoseconds or picoseconds. Therefore, the definitions of "simultaneously" or "sequentially" related to the tasks (or steps) run by the terminal's processor can be modified based on the characteristics of user input associated with the task (or step) and the user's effort requiring a predetermined time to complete. For example, a user cannot provide input instantaneously (for example, within one clock cycle or 5-6 clock cycles), but rather provides user input or specific input over a predetermined time equivalent to 0.1 seconds or 1 second, or millions of clock cycles of the processor.

[0251] Explaining this characteristic Figure 4 It is an example diagram that marks the jobs (or steps) running simultaneously according to the clock cycle of the processor of the data processing terminal based on user input. Figure 4 In case (A), the terminal or processor (hereinafter referred to as the "terminal") runs job (or step) A1 during clock cycles 004–013 and job (or step) A2 during clock cycles 009–019. According to the definition, the terminal runs jobs (or steps) A1 and A2 simultaneously. This is because A1 and A2 overlap over five clock cycles 009–013. Furthermore, the user provides user input U1 during clock cycles 003–1,000,003. The duration of this U1 provision includes the clock cycles for running A1 and A2; therefore, from the viewpoint of user input U1, it can be considered that the terminal is running jobs (or steps) A1 and A2 simultaneously.

[0252] Figure 4 In case (B), the terminal runs job (or step) B1 in clock cycle 023 and job (or step) B2 in clock cycles 014-029. Therefore, the terminal can be considered to execute job (or step) B1 and B2 simultaneously. Furthermore, if the user provides user input UI2 in clock cycles 003-100003, the clock cycle of UI2 includes the clock cycles for running B1 and B2. Therefore, when considering user input UI2, the terminal can be considered to run B1 and B2 simultaneously.

[0253] Figure 4 In case (C), the terminal runs job (or step) C1 during clock cycles 006–014, job (or step) C2 during clock cycles 014–022, and other job (or step) C3 during clock cycles 020–032. Therefore, it can be considered that the terminal executes jobs (or steps) C1 and C2 simultaneously, and also runs jobs (or steps) C2 and C3 simultaneously. However, the terminal runs jobs (or steps) C1 and C3 sequentially because C1 and C3 do not overlap in any clock cycle.

[0254] When the user provides user input UI3 during clock cycles 003 to 1,000,003, the clock cycles provided by UI3 include the clock cycles for running jobs (or steps) C1, C2, and C3. Therefore, considering user input UI3, it can be considered that the terminal simultaneously runs jobs (or steps) C1 and C2, simultaneously runs jobs (or steps) C2 and C3, simultaneously runs jobs (or steps) C3 and C1, and simultaneously runs jobs (or steps) C1, C2, and C3.

[0255] A user can make an effort in a variety of ways. In the case of the first embodiment associated therewith, a user can make an "active effort" by performing an active or spontaneous action when providing user input to the input unit. Examples of such an active effort include [1] an effort by which the user actively operates one or more parts of the input unit in a mechanical, electronic, magnetic or optical manner, or [2] an effort by which the user provides a specific image or voice to the input unit through an active action (for example, the user spontaneously gazing at the camera or speaking into the microphone).

[0256] In the case of the related second embodiment, the user may passively or involuntarily make a "passive effort, an inactive effort" to provide user input to the input unit. For example, even if the user does not actively or spontaneously take action, the terminal can still obtain more than one specific input from a received user input. Therefore, if the terminal acquires an image of a user's eyes that are not spontaneously gazing at the camera and processes that image as user input, it can be considered that the user has performed a passive effort to provide user input to the terminal.

[0257] Furthermore, if the terminal acquires the voice of a user speaking to another person and uses that voice as user input even if the user is unaware of it, it can be considered that the user has also performed an inactive effort. Also, if the terminal acquires the sound emitted by the surrounding environment and uses it as user input, even though the user is not required to record such sounds, it can be considered that the user has also performed a passive effort. It is specified that "an effort" in this specification includes not only "an active effort" but also "a passive effort".

[0258] 1-12. Multiple repeated efforts

[0259] As in the chapter 1-11 The description states that "user input" or "a single user input" refers to input provided by a user to more than one input unit through an "effort." However, a user may make multiple rapid and repeated efforts to provide a specific user input (i.e., called "repeated efforts"). Examples of such repeated efforts include rapid double clicks, rapid double taps, triple clicks or taps, etc. Since each click (or tap) in a multiple click (or tap) is separated from other clicks (or taps) by time intervals, such repeated efforts can be considered as not constituting a single user input.

[0260] However, in reality, the user provides a specific user input to the terminal by performing multiple rapid clicks (or taps), and the terminal also recognizes the rapid, repetitive effort as a specific user input. For example, when the terminal receives a single tap, it considers it to have received the first user input and runs the first task; conversely, receiving a double tap can be considered as receiving the second user input and running the second task. This specification, in conjunction with the above, considers a user's rapid execution of multiple efforts within 1.5 seconds, 1.0 seconds, 0.5 seconds, or 0.3 seconds as a "user input" or "user input." Furthermore, the terminal can, according to control settings, also consider a user's repetitive effort performed within 1.7 seconds, 2.0 seconds, or 3.0 seconds as a user input; in this case, the repetitive effort can also be considered "a user input."

[0261] Unlike repeated, rapid clicks or taps that involve the same effort repeatedly, "repeated effort" can also include different efforts made by the user. In particular, users can use different body parts or different objects to provide user input, or provide different user inputs to different input units simultaneously.

[0262] In its first specific example, a user can simultaneously perform an operation (or touch) on a portion of the first input unit (for example, a button) and provide voice to the second input unit (for example, a microphone). If this touch and voice generation overlap for more than one clock cycle, these can be considered as a single user input. Even if the user touches the portion of the first input unit and provides voice to the second input unit after a predetermined duration, the touch and voice generation can be considered as a single user input as long as the time gap is shorter than 1.5, 1.0, 0.5, or 0.3 seconds.

[0263] In a related second specific example, if a user presses a portion of a third input unit (e.g., a touchscreen) with a pointer or stylus while simultaneously gazing at a fourth input unit (e.g., a camera), the press and the gaze can be considered a single user input. Even if the user presses a portion of the third input unit and gazes at the fourth input unit after a predetermined time (i.e., a time gap exists), the press and gaze can be considered a single user input as long as the time gap between the press and the gaze is shorter than 1.5, 1.0, 0.5, or 0.3 seconds.

[0264] In a related third specific example, a user can perform "repeated efforts" by repeatedly making the same effort, manipulating the static or dynamic characteristics of the effort. Examples of these characteristics include the duration, intensity or degree, direction, time gap between two efforts, temporal overlap between two efforts, number of efforts, and order of efforts. For example, a user can press a portion of the input unit harder, change the direction of pressing the portion, or repeatedly press the portion without removing their hand, to perform different "repeated efforts" that can be recognized by the terminal as different user inputs.

[0265] 1-13. (User) Specific Input

[0266] In this specification, "(user) specific input" or simply "specific input" refers to the user input element that enables the input unit to generate control signals. Therefore, "(user) specific input" or "specific input" is a fundamental element of user input. To acquire the "specific input," the input unit includes one or more sensor elements (or sensors), the structural features or operational characteristics of which may depend on the characteristics of the "specific input" that the sensor should acquire.

[0267] Therefore, when the first input unit receives mechanical, first-type user input, the first input unit may include a mechanical sensor capable of acquiring the specific mechanical (user) input contained in the user input. And when the second input unit receives acoustic, fifth-type user input, the second input unit may include an acoustic sensor capable of acquiring the specific acoustic (user) input contained in the user input.

[0268] The user input in this specification includes more than one specific input among multiple (user) specific inputs. Examples of such specific inputs include [1] mode-moving (user) specific input UI. SWI [2] Activation using (user) specific input UI ACT [3] Authentication (User) Specific Input UI THEN [4] Assist (User) Specific Input (UI) AUX From this perspective, when the input unit receives user input, it is considered that the appropriate sensors of the input unit have obtained more than one specific (user) input from the user.

[0269] In particular, when a user provides user input to move from the off state to another mode or from the current mode to a new mode, the user input is considered to include UI. SWI And selectively include UI. ACT UI THEN or UI AUXOne or more of other specific inputs. Therefore, the received input includes UI elements. SWI In the case of user input, the terminal obtains the UI from the user input. SWI The terminal then performs a mode-shifting operation to move to the new mode. Here, the terminal selects the new mode from a group of multiple modes "actually" defined by the terminal while belonging to a specific tier. As explained below, when the mode-shifting operation (i.e., mode switching) is run based on the result of different operations such as authentication or activation, the terminal receives a UI-free input... SWI The user can also move to a different mode after inputting their own input.

[0270] A user can include a specific number of specific inputs in a user input. As a result, the terminal can run various jobs accordingly based on the received user input or the acquired specific inputs. For example, a terminal that receives user input including a first number of specific inputs can run a second number of jobs accordingly.

[0271] However, the first quantity and the second quantity may be different. As an example, the terminal acquires the UI... SWI (That is, the authentication job is automatically run accordingly during the acquisition, or the terminal acquires the UI.) SWI Accordingly (i.e., with the acquisition) when the image unit is opened, the user input does not need to include the UI. THEN UI ACT Therefore, the first quantity can be less than the second quantity. Alternatively, the first quantity can be greater than the second quantity. As an example, when the terminal receives a user input, the terminal obtains the UI from it. ACT UI THEN and UI SWI The terminal opens the imaging unit and moves to the new mode only if the user authentication process is successful. If the user authentication process fails, the terminal does not run any tasks but remains in the off state or the current mode. In this case, the terminal that obtains three (user) specific inputs actually only runs one task. As mentioned above, the first number can be greater than the second number.

[0272] Therefore, the first quantity can be greater than or less than the second quantity, and the first quantity and the second quantity can also be the same. Furthermore, even if the first quantity and the second quantity are the same, the job actually executed by the terminal may not correspond to each specific input contained in one or more user inputs.

[0273] 1-13-1. Activation using (user) specific input (UI) ACT )

[0274] The first of the various (user) specific inputs in this manual is "Activation (User) Specific Input," or simply UI. ACT The terminal receives the UI as it progresses.ACT User input or obtaining UI ACT The activation process is then executed accordingly, opening the image unit. This corresponds to the UI. ACT Activate the terminal. For ease of explanation, the input unit that acquires the specific input from the user for activation is called the activation input unit, and the sensor of the activation input unit is called the activation sensor.

[0275] When the terminal includes multiple image units, the UI ACT This allows the terminal to open one or more image units. That is, the terminal accesses the UI as needed. ACT Accordingly, one or more of the unrun or remaining steps of the operation to open the image unit are performed (or started), therefore there is no UI. ACT In such cases, the terminal (i.e., CPU unit, operating system, or software application) may be unable to run activation tasks or tasks that open the image unit, etc.

[0276] The activation input unit includes generating a UI that can be recognized by the terminal. ACT The control signal and the existing activation sensor that enables the terminal to perform activation operations based on the control signal. Therefore, the activation input unit is based on the UI. ACT Accordingly, it is driven by mechanical, electronic, optical, or electromagnetic means, and the activation sensor generates mechanical, electronic, optical, or electromagnetic control signals. However, if the operation of the activation task is conditional on the result of other tasks, the terminal may not display the UI. ACT This is a necessary condition for running activation tasks or opening image units. For example, the terminal can do so regardless of whether it receives a UI. ACT Once the user authentication process is successful, the image unit will be opened.

[0277] Users can provide UI at multiple points in time. ACT Examples of the time points mentioned include [1] providing a UI. SWI UI THEN and UI AUX [2] To provide a single point in time for a specific input, to operate an input unit or to operate multiple input units simultaneously to provide a single point in time for a user input, [3] to operate different parts of an input unit sequentially or to operate multiple input units sequentially to provide multiple points in time for a user input, etc. The user can operate an input unit, multiple input units or two or more parts of an input unit simultaneously to provide a single point in time for a user input. SWI UI ACT or UI ACT Provide UI for one or more at the same time ACT .

[0278] 1-13-2. Authentication (User) Specific Input UI THEN

[0279] In this manual, the second of the various (user) input methods is "Authentication (User) Input," "Authentication Input," or simply UI. THEN The terminal receives a UI. THEN User input or obtaining UI THEN Accordingly, one or more authentication jobs are run to authenticate the user. However, for ease of explanation, the input unit that obtains the specific input for authentication (user) is called the authentication input unit, and the sensor of the authentication input unit is called the authentication sensor.

[0280] When the terminal includes multiple input units specialized for user authentication, the UI... THEN This allows the terminal to drive one or more input units. The terminal receives the UI. THEN In this case, the terminal runs (or begins running) more than one of the unrun (or remaining) steps of the authentication job. Therefore, there is no UI. THEN At this time, the terminal (i.e., CPU unit, operating system, or software application) cannot run any authentication jobs.

[0281] The input unit for authentication may include generating a UI that can be recognized by the terminal. THEN The existing authentication sensor provides control signals and enables the terminal to perform more than one authentication operation. Therefore, the authentication input unit is driven mechanically, electronically, optically, or magnetically, and the authentication sensor is based on the UI. THEN Correspondingly, mechanical, electronic, optical, or magnetic control signals are generated.

[0282] However, when the authentication job depends on the results of other jobs, the terminal does not always need to display the UI. THEN This is a prerequisite for running the authentication job. For example, the terminal will not receive a UI if it does not receive a UI. THEN User authentication jobs can also be run when the user inputs are received. Examples of such cases include [1] whenever the terminal obtains UI input. SWI The authentication job is run when the user moves to a new mode that grants the user more access rights than the current mode, or the authentication job is run when the terminal runs the authentication job according to the specific running order of the operating system or software application.

[0283] The terminal can use various types of information, both user-related and user-unrelated, as the UI. THEN As an example, the UI... THENIt can be the user's biological information, relative to biological information, or containing biological information. Examples of the biological information include fingerprints, hands, palms, wrists, eyes, irises, retina, ears, noses, faces, other body parts, blood vessels, blood vessel distribution patterns, blood flow rate, blood flow patterns, and other body parts or images of said body parts, [2] electronic signals such as resistance, conductivity, or capacitance related to the user's biological information, [3] optical or magnetic signals such as the user's biological information or related to it, [4] user-related sounds such as voice, snapping fingers, clapping, etc., or sounds related to the biological information, or [5] various physiological characteristics such as body temperature, blood pressure, electrocardiogram (ECG), heart pulse, other cardiac circulatory system characteristics, respiratory rate or sound, other respiratory system characteristics, other digestive system characteristics related to stomach or intestinal motility, electromyography (EMG), electroencephalogram (EEG), and other muscle and skeletal characteristics.

[0284] And UI THEN It can be dynamic biological information, or equivalent to dynamic biological information, or contain dynamic biological information. Examples of the dynamic biological information include the activity or displacement of a body part, the velocity or acceleration of the activity or displacement, the (2-D or 3-D) position of the part, the posture of the part, etc.

[0285] Users can also use non-biological information as UI elements. THEN This UI THEN It can be equivalent to or contain non-biological information, such as passwords or passwords, images unrelated to the user (i.e., non-user), non-user sounds, non-user light or non-user sound waves or non-user electromagnetic waves, etc.

[0286] Terminals can use their static or dynamic characteristics as the UI. THEN As an example, a terminal can measure the activity of a specific part of itself, the speed or acceleration of the activity, the displacement or position caused by the activity, the number or sequence of the activity, the duration or orientation of the activity (for example, facing upwards, facing downwards, tilting at a specific angle, etc.), or other related information, and use it as a UI. THEN The authentication process is executed. Therefore, as long as a protocol exists between the terminal and the user, any type of information can be used by the terminal as a UI. THEN .

[0287] Users can provide the aforementioned UI to the terminal through various operations. THENExamples of the operations include [1] an operation on one part of an authentication input unit, [2] an operation on multiple parts of an authentication input unit, or [3] an operation on two or more parts of two or more authentication input units. In particular, the user may perform the above operations [2] or [3] simultaneously, sequentially, or in combination.

[0288] Users can provide the UI to the terminal at multiple points in time. THEN Examples of the time points mentioned include [1] providing a UI. SWI or UI ACT At the same time point in one of them, [2] the UI is provided. SWI and UI ACT At the same time point or [3] provide UI SWI UI ACT and UI AUX At the same time point, etc. For this purpose, the user can [1] include all of the multiple specific inputs in one user input and provide it to one input unit, or [2] include multiple specific inputs in multiple user inputs and provide them to one input unit simultaneously or sequentially, or [3] include multiple specific inputs in multiple user inputs and provide them to multiple input units simultaneously or sequentially.

[0289] User-defined actions can be performed to provide a UI to the input unit. THEN The spontaneous action is “an active effort”, examples of which include [1] to provide fingerprint-related UI. THEN The action of touching the finger on the authentication input unit, [2] in order to provide fingerprint-related UI THEN According to the actions of the input unit used for authentication, [3] in order to provide UI images of the face, iris, retina, etc. THEN The act of staring at the camera or [4] is to provide a UI for one's own voice. THEN Actions such as speaking into a microphone are also included. Furthermore, users can perform actions that provide the UI. THEN "Spontaneous repetitive effort" refers to multiple spontaneous actions.

[0290] Conversely, the terminal can proactively obtain one or more UI elements without requiring users to perform spontaneous actions. THEN Therefore, [1] even if the user does not spontaneously gaze at the camera, or [2] even if the user speaks to someone but does not spontaneously speak into the microphone, the terminal can still receive images of the user's eyes, the user's voice, or sounds of the surrounding environment and obtain the UI from them. THEN In this specification, this situation is considered as the user performing an action to provide the UI to the input unit. THEN A passive effort to perform an involuntary action.

[0291] Once the terminal's input unit receives user input from the user, the input unit's sensors acquire UI information from the user input. THEN With the UI obtained THEN The terminal (i.e., software application, processor, or operating system) then begins running the program code for the authentication job to determine whether the current user's authentication can be successful. More specifically, the terminal (1) runs a comparison UI. THEN (1) A "comparison step" of the authentication job (with the user's biometric information stored on the terminal), and (2) a "determination step" of the authentication job (of the authentication job) to determine whether the current user's authentication job is successful or not.

[0292] 1-13-3. Pattern Movement (User) Specific Input (UI) SWI )

[0293] The third user input in this manual is "Mode Movement (User) Specific Input" or "Mode Movement Specific Input," which is simply represented as UI. SWI The terminal [1] receives the UI as it receives the UI. SWI The user input is correspondingly or [2] obtained from the UI. THEN Accordingly, a mode-shifting operation is performed to enable the terminal [1] to move from one mode to another mode or [2] from the current mode to a new mode in a power-off or shutdown state. The terminal may perform mode-shifting at the "mode-shifting time points" described below. However, the terminal (i.e., the software application, processor, or operating system) obtains the UI before the operation begins. SWI The system will run (or start running) one or more unrun (or remaining) steps of the move job in the corresponding mode, so if there is no UI... SWI The terminal may be unable to run any mode of mobile work.

[0294] This manual will receive the UI. SWI The input unit is called a "pattern movement input unit," which includes a "pattern movement sensor." And related to the chapter... 1-4 As defined in the manual, “mode switching” or “mode movement” refers to [1] moving from a power-off state to a specific mode, [2] moving from a closed state to a specific mode, [3] moving from the current mode to a new mode while maintaining the open state (i.e., the power is not completely disconnected, the terminal can communicate and the image unit is open), [4] moving from a specific mode in the open state to the closed state, or [5] moving from a specific mode in the open state to the power-off state.

[0295] In mobile mode, the terminal refers to a "matching list" and selects a new mode based on UISWI. The "matching list" refers to multiple (operational) modes defined by the terminal or user within a specific tier, each corresponding to a different UI. SWIA list that matches (or corresponds to). However, multiple UI elements... S WI Multiple (job) patterns are already included in the matching list, therefore, according to the UI... SWI The process of selecting a new mode is simply to accurately find the entry corresponding to a specific item from the matching list (user-provided UI). SWI Other entries (among multiple predefined patterns corresponding to the UI obtained by the terminal) SWI The steps (of the pattern) are different. Therefore, the steps for selecting the exact entry from the matching list may differ from those for comparing UI elements. THEN The "determining steps" of the authentication job based on pre-stored authentication information. This is due to the user-provided UI. THEN It may be inaccurate or incorrect, or may not correspond to the authentication information pre-stored on the terminal.

[0296] Users can provide various UIs through multiple methods. SWI As an example, the UI can be [1] operated by the user in a first activity involving one or more active parts of the mode operation input unit, [2] operated by the user in a second activity involving the user moving the body parts on the input unit while maintaining contact with one or more body parts in a mechanical, electronic, magnetic, or optical manner, [3] operated by the user moving the body parts on the input unit while maintaining contact with one or more parts of the input unit while maintaining contact with the non-user object, or [4] operated by the user moving the body parts or objects relative to the input unit while maintaining contact with one or more parts of the input unit at a predetermined distance from one or more user parts (or non-user objects). SWI Provided to the terminal.

[0297] Furthermore, the terminal can [1] change with the type, nature, or pattern of the first to fourth activities mentioned above, [2] change with the degree, size, or amplitude of the first to fourth activities, [3] change with the direction of the first to fourth activities, [4] change with the sequence of at least two or more activities in the first to fourth activities (but the two or more activities can be repeated identical activities or different activities), or [5] change with the static or dynamic characteristics of the first to fourth activities to obtain different UIs. SWI .

[0298] Users can move to the mode and provide a user input using the input unit to provide UI functionality. SWI The user input described herein may include other specific inputs. Alternatively, the user may provide multiple user inputs to one or more parts of the mode-moving input unit to provide a UI. SWIHere, one or more user inputs may include UI. SWI Alternatively, users can provide multiple user inputs to multiple input units to provide UI functionality. SWI Here, one of the multiple input units functions as a mode-shifting input unit, and one of the multiple user inputs may include the UI. SWI .

[0299] When a user provides multiple inputs simultaneously, the UI... SWI It may not matter which user input is included. This is because the terminal obtains more than just the UI. SWI It can also obtain other specific inputs. However, when the user provides multiple user inputs sequentially, especially when the user wants to open the imaging unit or is in a seamless mobile mode running user authentication, the user can change the UI. SWI Included in the first user input.

[0300] Terminal obtains UI SWI Simultaneously or subsequently, the input unit's pattern movement sensor generates a control signal and transmits it to other units of the terminal. The terminal can then execute unexecuted (or remaining) steps based on the steps selected from the matching list, or execute (or begin executing) the remaining steps of the "pattern movement job".

[0301] As mentioned above, users interact with the UI by manipulating a body part (or a non-user object). SWI It is included in user input and provided to the terminal. The terminal obtains the UI through the various methods mentioned above. SWI The user interacts with two or more body parts (or non-user objects) to change the UI. SWI When a user input is included, the terminal can obtain the UI through the various methods mentioned above. SWI .

[0302] When a user input is received (for example, when the user performs one effort), the terminal can simultaneously acquire multiple specific inputs. Alternatively, when the terminal receives multiple simultaneous user inputs (for example, when the user performs multiple repeated efforts simultaneously), it can simultaneously acquire multiple specific inputs contained within the user input. Furthermore, when the user provides multiple sequential user inputs, the terminal can simultaneously acquire multiple specific inputs contained within the multiple user inputs. This will be explained in detail below.

[0303] In the case of the first embodiment, the user can [1] press, push, rotate, or otherwise manipulate one or more movable parts of the input unit, or [2] touch or contact one or more movable or fixed parts of the input unit using a part of the user's body or a non-user object. The input unit can accordingly receive a user input and simultaneously or sequentially obtain one or more (user) specific inputs. This configuration, along with the various methods described below, is also applicable to other specific inputs in this specification.

[0304] In other words, a user input is the result of an effort by the user to perform one or more actions, such as [1] when the user approaches one or more sensors of the input unit with their finger or other body part, [2] when the user provides fingerprint, iris or other biometric information to activate the authentication sensor of the authentication input unit, [3] when the user touches or presses a moving (or fixed) part of the input unit, or [4] when the user activates the tactile sensor or other activation sensor of the input unit to wake up the terminal (i.e., turn on the imaging unit). That is, even if the user actively performs multiple actions, from a minute time unit perspective, the multiple actions can occur sequentially.

[0305] As an example, the user presses the first part of the input unit to provide the UI. SWI Simultaneous contact with the second part of different input units to provide UI THEN Afterwards, the user can re-contact (i.e., a second contact) the same second part or a different third part of the same input unit after removing their finger from the second part [1] to provide UI. AUX Or [2] re-contact (i.e., a second contact) a specific part of a different input unit to provide a UI. AUX In this case, [1] if the user continues to press while removing their finger and making a second contact, or [2] if there is a time overlap between the press and the second contact, the multiple efforts and multiple user inputs are still equivalent to "one user input".

[0306] In the second embodiment, the terminal may receive multiple user inputs sequentially and without time overlap. However, the terminal may simultaneously acquire multiple (user) specific inputs. As an example, [1] during the operation of the first embodiment, the user leaves (or moves) all body parts or all non-user objects from one or more parts of the input unit, or [2] before the operation ends, the terminal receives multiple sequential user inputs. Even when the terminal receives sequential user inputs as described above, [1] the terminal begins to acquire multiple specific inputs after receiving all sequential user inputs, or [2] the terminal acquires other (user) specific inputs on the condition of receiving a specific (user) specific input, the terminal may simultaneously acquire the multiple specific inputs.

[0307] That is, the user will use the UI SWI When a specific user input is included, and multiple user inputs are simultaneously provided to more than one input unit, the terminal can receive UI inputs according to the various methods described above. SWI As an example, after operating the first input unit, a user can operate the same or different input units after a predetermined time interval, thus allowing the user to provide multiple non-overlapping user inputs sequentially. However, the terminal may not begin acquiring specific inputs until the user has provided all user inputs. When the terminal then begins acquiring specific inputs, it can acquire multiple specific inputs simultaneously.

[0308] In another instance, the user touches the first part of the input unit and then moves their body part away from the first part (as an example, providing UI). THEN Then, in the case of the second part of the same or different input unit (as an example, providing UI), ACT The user can provide multiple user inputs through such multiple efforts. In this case, the terminal can acquire the first specific input before the user moves the body part away from the input unit, and can acquire the second specific input after the user presses the input unit. However, [1] if the user presses the second part of the input unit within 1.5 seconds, 1.0 seconds or 0.5 seconds, or [2] if the acquisition time of the specific input overlaps with more than one clock cycle of the terminal's clock cycle, the terminal can acquire the specific input simultaneously.

[0309] Typically, providing multiple user inputs or acquiring multiple specific inputs simultaneously can be very important because receiving multiple user inputs or acquiring multiple specific inputs at the same time helps the terminal run multiple jobs seamlessly.

[0310] Conversely, the same applies: a terminal can acquire multiple (user) inputs sequentially, even if it can acquire them simultaneously. This is because, for example, if the execution of a second task based on a second (user) input depends on the result of the execution of a first task based on a first (user) input, acquiring both the first and second inputs simultaneously is not essential for the terminal to maintain its seamless characteristic. Therefore, the terminal can acquire the first and second inputs sequentially without compromising its seamless characteristic.

[0311] 1-14. Input Unit

[0312] In this specification, "input unit" refers to the hardware element of the terminal's main system, which functions to receive one or more of the first to fifth types of user inputs mentioned above. Furthermore, provided that existing mechanical, electronic, magnetic, or optical devices include [1] existing sensors capable of receiving one or more of multiple user inputs or [2] existing sensors capable of acquiring one or more specific (user) inputs contained within the user inputs, the terminal can use these existing devices as input units.

[0313] A specific input unit is designated to receive UI input. ACT In this context, the input unit is referred to as an "activation input unit," and the input unit includes one or more activation sensors. A specific input unit is designated to receive UI inputs. THEN In this context, the input unit is referred to as an "authentication input unit," and the input unit includes one or more authentication sensors. Furthermore, a specific input unit is designated to receive UI input. SWI In this case, the input unit is referred to as a "pattern movement input unit," which includes one or more pattern movement sensors. The terminal may include an additional input unit capable of receiving user input, including specific input for performing tasks other than the aforementioned activation task, authentication task, or pattern movement task; this type of input unit is referred to as an "auxiliary input unit," which includes components for acquiring auxiliary (user) specific input (UI). AUX (One or more auxiliary sensors)

[0314] The input unit can directly receive user input, directly acquire specific input, or extract one or more specific inputs from the user input to acquire specific input. That is, the terminal can acquire specific input while receiving user input or acquire specific input sequentially after receiving user input, depending on whether there is a time gap between the user input receiving time point and the specific input acquisition time point. Alternatively, the second input unit can extract specific input from the input to acquire specific input when the first input unit receives user input.

[0315] The sensors of the input unit acquire more than one specific input from one or more user inputs, so the input unit can typically include the same number of sensors as the number of specific inputs included in the user inputs. Of course, the input unit can include only a smaller number of sensors than the number of specific inputs included in the user inputs, in cases such as [1] the terminal acquires a specific input and runs multiple jobs accordingly or [2] the terminal runs a second job based on the result of the first job, etc.

[0316] When a terminal acquires multiple specific inputs using multiple input units, each input unit may include one or more sensors. Alternatively, the terminal may acquire one specific input (i.e., 1:1) using one input unit, acquire n specific inputs (i.e., 1:n) using one input unit, acquire one specific input (i.e., m:1) using m input units, or acquire n specific inputs (i.e., m:n) using m input units, where m and n are natural numbers, and m may be greater than, less than, or the same as n.

[0317] Depending on the type and attributes of the input unit or the number of user inputs required for the terminal to perform its operation, the input unit can receive user input when the user directly or indirectly operates one or more parts of the unit. For example, the terminal includes an input unit that can [1] receive multiple user inputs of the same or similar type, [2] receive multiple user inputs of different types, or [3] receive user inputs in a combination of [1] and [2]. Conversely, the terminal includes multiple input units of different or the same type, receiving different types of user inputs, or simultaneously or sequentially acquiring different types of specific inputs using different input units.

[0318] Furthermore, any hardware element of the terminal capable of receiving one or more of the first to fifth types of user input can be used as an input unit, and such hardware element is also considered as an input unit in this specification. That is, when the terminal includes hardware elements such as a touch screen, gyroscope, force transducer, etc., these elements can be used as other input units. As an example, [1] the terminal can use the touch screen to obtain the UI. THEN [2] Use a gyroscope to sense the user's position, activity, posture, etc., and obtain the UI from them. SWI Alternatively [3] the force applied to the input unit can be measured using a force transducer, and the UI can be obtained from it. ACT Alternatively, the sensor may acquire specific input through methods other than those described above, or from measurements of the position, activity, or force.

[0319] The terminal can utilize various existing input units, including U.S. Patent No. 5,463,388 belonging to AT&T, U.S. Patents Nos. 7,479,949, 8,392,340, and 8,542,206 belonging to Apple, U.S. Patent No. 8,279,182 belonging to Samsung Electronics, and U.S. Patent No. 8,554,275 belonging to LG Electronics. Other existing input units can also be installed in various terminals described in this specification.

[0320] 1-15. (Software) Application (or application)

[0321] In this specification, the term "software element" of the terminal's main system refers to the main operating system, main (software) applications, etc. "Software element" has the same meaning as "accessible software element," and specifically refers to a group of computer instructions or computer programs. In this specification, "(software) application," or simply "application," is one of the terminal's software elements, representing a group of computer instruction systems (or computer programs) designed to run a specific task or perform a specific function. A (software) application can be driven by the CPU unit, operating system, or other applications to run a specific task or perform a specific function. Furthermore, when driving a (software) application, more than one hardware element may also be driven.

[0322] In this specification, the term "(software) application" or "application" does not include an operating system, and is therefore defined as an application distinct from an operating system. Terminal manufacturers or distributors may install more than one application on the terminal before it is sold. Alternatively, users may download more than one application after purchasing the terminal. Furthermore, applications already installed on the operating system or terminal can also download new "applications" from external storage devices or websites, etc.

[0323] The application provides users with a variety of "options," allowing them to choose different options to run different jobs or perform different functions. Therefore, when a terminal grants a user access permissions to drive a specific application, the terminal can allow the user to use all options or only the limited options, depending on the user's current driving mode (i.e., the current mode) or the access permissions granted for that mode.

[0324] 1-16. Operation

[0325] In this specification, (1) the terminal is the subject that "drives" various hardware or software elements of the main system, and (2) the terminal is also the subject that "runs" various jobs using the main (or locked) system. In particular, when the terminal drives the operating system, more than one application, CPU unit, etc., the terminal can run multiple jobs. For ease of explanation, the term "terminal" in this specification is defined as a general term for its own operating system, (software) application, or CPU. Therefore, the terminal drives more than one part of the CPU, operating system, or application to run jobs. For ease of explanation, the phrase "running a job" is considered to have the same meaning as "running more than one job" or "running more than one predetermined job".

[0326] The aforementioned “operation job” includes one or more steps among multiple steps, examples of which include [1] retrieving data stored in the terminal (one or more steps), [2] setting up the system related to the operation job or retrieving user preferences (one or more steps), [3] performing an erase operation on volatile or non-volatile memory cells, performing an erase operation on at least a portion of the “product” obtained from the operation lock operation, [4] preparing one or more hardware elements for a specific operation such as starting a power supply device (one or more steps), [5] supplying power to the hardware elements (one or more steps), [6] driving hardware elements or software elements such as operating computer instructions for hardware elements or running software elements to perform specific functions (one or more steps), [7] storing data obtained by driving the elements (one or more steps), or [8] storing, utilizing, or erasing the product obtained by the driving (one or more steps), etc.

[0327] For this purpose, the terminal can be made of various configurations. For example, the terminal can [1] retrieve specific data (or "products") from the memory cells of the main (or locked) system, [2] erase the memory cells of the main (or locked) system before driving hardware or software elements, [3] supply power to one or more hardware elements to prepare them for operation, [4] execute computer instruction sets to drive one or more software elements, and [5] divide computer instructions into two or more parts and execute the parts simultaneously, sequentially, or in combination to drive one or more software elements. Despite these differences, the operation can be considered to be in an "aborted" state as long as the terminal does not perform the unrun (or remaining) steps of the (software) application required to run the operation.

[0328] When the terminal receives user input, it accordingly drives (or begins driving) one or more hardware or software elements to run (or begins running) one or more jobs. Alternatively, the terminal may drive a first hardware or software element upon receiving first user input, and automatically (or proactively) run a second job even if no second user input for running a second job is received. As an example, the terminal may drive a second element to run a second job only if a specific result is obtained when running a first job by driving a first element. In this specification, this configuration is referred to as driving a second element to run a second job "conditionally" by driving a first job by driving a first element.

[0329] In this specification, the terminal may drive hardware or software elements accordingly (i.e., simultaneously with the receipt of user input) or (i.e., simultaneously with the acquisition) when [1] receiving user input or [2] acquiring more than one specific input. As an example, the terminal may [1] drive hardware or software elements according to the UI. ACT The activation job is run accordingly, [2] based on the UI. THEN Accordingly, run an authentication job or [3] according to the UI. S WI The operation mode moves accordingly. And a user input may include multiple specific inputs, so the terminal can drive multiple elements or run multiple jobs when it receives a user input, where the multiple elements or jobs may be the same or different.

[0330] 1-17. A screen and mode movement operation

[0331] In this specification, "running more than one mode movement operation" or "running a mode movement operation" is considered to have the same meaning as the abbreviation "mode movement" or "mode switching". As mentioned above, mode movement refers to the operation of moving from the current mode actually defined by the hierarchy to a new mode actually defined by the same hierarchy. Therefore, the current or new mode includes not only all modes actually defined by the same hierarchy, but also the off state and the power-off state. The current or new mode also includes the on state because the locked mode, intermediate mode, and unlocked mode are all on. Furthermore, the current or new mode also includes the power-on state because the locked mode, intermediate mode, and unlocked mode are all power-on.

[0332] The “pattern move” or “run a pattern move job” may include a number of steps, such as [1] the step of starting a pattern move job, [2] selecting the corresponding UI from a matching list that includes multiple patterns defined in a specific hierarchy. SWI More than one new mode of steps, [3] UI SWISteps to perform a specific action when none of the multiple patterns in the matching list correspond, [4] steps to move from the current pattern to a new pattern, or [5] steps to end the running pattern movement job, etc.

[0333] Terminals can typically run multiple modes of mobile operations in various ways. For ease of explanation, multiple modes of mobile operations can be classified into several types based on the following factors. Examples of these factors include [1] whether the terminal is in a powered-off state or a powered-on state before the mode is moved, [2] whether the terminal's image unit is off (i.e., closed) or on (i.e., open) before the mode is moved, or [3] whether the terminal runs user authentication operations in conjunction with the mode is moved (i.e., before, after, or simultaneously with the mode is moved).

[0334] In the case of the first embodiment associated therewith, when a terminal in a closed state receives user input including UISWI, the terminal can move to a new mode accordingly based on the UISWI. Here, the matching list maps all UISWIs defined by the terminal to all modes defined at a specific level, and the new mode is the mode corresponding to the UISWI in the matching list. In this specification, this mode movement is referred to as "first type mode movement".

[0335] However, when the terminal performs user authentication, the terminal can move to different modes depending on the authentication result. For example, if the user authentication is successful, the terminal can move to the unlock mode and display the unlock (or home) screen on the image unit. However, if the user authentication fails, the terminal [1] can move to the lock mode or a different basic settings mode and display the lock (or basic settings) screen, or [2] the image unit does not display any screen and remains in the off state.

[0336] Here, the terminal can first obtain the UI from user input. THEN And only retrieve the UI if user authentication is successful. SWI Alternatively, the terminal can obtain the UI regardless of whether user authentication is successful. THEN and UI SWI .

[0337] In other embodiments, when the terminal receives user input including UISWI while in the enabled state, the terminal can accordingly select a new mode corresponding to UISWI from the matching list and move from the current mode to the new mode. In this specification, this mode movement is referred to as "second type mode movement".

[0338] When user authentication is imported into the terminal, the terminal can move to various new modes based on the authentication result. For example, if user authentication is successful, the terminal can move to the unlock mode and display the unlock screen or the home screen on the image unit. However, if user authentication fails, the terminal can [1] move to the lock mode or a different basic settings mode and display the lock screen or a different basic settings screen, or [2] display the lock screen and remain in the lock mode if the current mode is the lock mode, or [3] turn off the image unit and move to the off state. Conversely, the terminal can first obtain the UI from the user input. THEN And only retrieve the UI if user authentication is successful. SWI Alternatively, the terminal can obtain the UI regardless of whether user authentication is successful. THEN and UI SWI .

[0339] 1-18. Multiple screen and mode movement operations

[0340] chapter 1-17 Multiple-mode mobile operations are essentially equivalent to a terminal driving a single image unit to display a single screen or window. Therefore, the terminal can allow the user to run multiple tasks while remaining in one mode, regardless of the number of modes defined at a specific level. Consequently, when a user moves from the current mode to a new mode, they cannot run tasks that can only be run in the current mode in the new mode. However, when the terminal displays multiple screens or windows on one or more image units, the terminal can allow the user to access different screens or windows simultaneously. 1-17 The method drives the terminal.

[0341] The terminal of the first embodiment associated therewith provides two or more screens that a user can drive, so that the user can make the first screen run a task in a locked (or intermediate) mode, and the second screen run the same or different tasks in an unlocked mode. This type of terminal can realize the various mode movements described above and below. Therefore, the user can provide a UI to the mode movement input unit. SWI The user can move from a first screen driven by a first mode to a second screen driven by a second mode. Alternatively, the user can move body parts on an existing touchscreen-type imaging unit, or select a new mode by operating the cursor if the imaging unit is not touchscreen-type.

[0342] In other words, users can move from one screen to another on the terminal to perform multiple tasks, much like using a mouse on a computer to move from one window to another. This configuration allows the terminal to completely or partially isolate the locking (or intermediate) system from the main system, thus improving the security and integrity of the main system. This prevents "products" stored or remaining in the locking (or intermediate) system from contaminating or adversely affecting the main system. However, despite this configuration, situations still arise where personal data stored on the main system cannot be protected because unauthenticated users, after intruding into the locked (or restricted) mode, can peek at the same content displayed on other screens—that is, the content displayed on a specific screen driven by the unlocked (or unrestricted) mode.

[0343] Therefore, the terminal can perform an erase (or partial erase) operation at multiple points in time. For example, the terminal can perform an erase (or partial erase) operation each time the user moves from a first screen (driven in a first mode and granted first access permissions) to a second screen (driven in a second mode and granted second access permissions wider than the first access permissions). Conversely, an erase (or partial erase) operation may not be performed when moving from the second screen to the first screen. Alternatively, the terminal can perform an erase (or partial erase) operation whenever the user moves between modes, regardless of the access permissions granted to each mode. Alternatively, the terminal can perform an erase (or partial erase) operation when the user closes the screen or ends the window during the process of driving a locked (or intermediate) mode.

[0344] The terminal may request or ask the user for confirmation before running an erase (or partial erase) operation. Furthermore, the terminal may synchronize the erase (or partial erase) operation with other operations, in situations where synchronization is easily achieved by the terminal or where it is easy for the user to execute the erase (or partial erase) operation.

[0345] Terminals displaying multiple screens can perform user authentication when the user moves the screen. In particular, when moving from a locked (or intermediate) mode to an unlocked mode, the terminal can perform authentication to verify whether the user has the necessary access rights to move to the unlocked mode.

[0346] Furthermore, if one or more screens displayed on the image unit are screens driven by the locked (or intermediate) mode, or if the screen is a screen selected by the user who wants to perform a locked (or intermediate) operation in the locked (or intermediate) mode, the terminal can allow the user to temporarily minimize the screen. In this configuration, the terminal can perform the erase (or partial erase) at multiple erase time points.

[0347] Users may minimize one of multiple screens while running a locked (or intermediate) job for various reasons. For example, if a user minimizes the screen in locked (or intermediate) mode but later wishes to rerun the job in that locked (or intermediate) mode, the terminal may not run an erase (or partial erase) job. Alternatively, if the user maximizes the screen, the terminal may run an additional user authentication job. Conversely, if a user wishes to reuse a specific artifact in the next job or step, the terminal may request the user to store the (planned storage) artifact before minimizing the screen.

[0348] The above-described synchronization of erase (or partial erase) operations with screen movement operations also applies when the screen is unlocked. That is, this is because even if the user driving the terminal in unlocked mode is an authenticated user, the synchronization of screen movement and erase (or partial erase) operations can further enhance the security and integrity of the terminal's main system, and also strengthen the protection of personal information stored in the main system.

[0349] 1-19. Certification Assignment

[0350] In this specification, the phrases "run more than one authentication job" or "run authentication job" have the same meaning as "(perform) user authentication" or "(perform) authentication". Furthermore, in this specification, "authentication job" refers to a job in which the terminal confirms [1] whether the (current) user is an authenticated user, [2] whether the (current) user has access rights to specific hardware or software elements of the main system driving the terminal, [3] whether the (current) user can run a specific job, or [4] whether the (current) user can drive specific hardware or software elements to use specific options, etc. For this purpose, the terminal can compare the UI obtained from the (current) user. THEN The authentication information already stored on the terminal (for example, the already stored UI) THEN ).

[0351] The authentication process includes one or more of the following steps, examples of which include: [1] preparing one or more steps for driving the authentication input unit and the authentication sensor; [2] receiving user input using the authentication input unit; and [3] acquiring the UI from the user input using the authentication sensor. THEN One or more steps, [4] compare the obtained UI THE N With the UI pre-stored in the terminal THEN One or more steps to obtain other authentication information, [5] one or more steps to determine whether the user authentication job is successful (i.e., passed) or failed (i.e., failed), or [6] one or more steps to end the authentication job, etc.

[0352] Furthermore, the authentication process may include one or more steps of temporarily or permanently storing the “planned storage artifacts” related to [1] to [6] above into memory cells (or sectors). As an example, the terminal may store the UI obtained in [1]. THEN [2] UI obtained THEN With pre-stored UI THEN The differences between them or the results of the certification process, such as success or failure [3]. The above [1] to [3] can take the form of text, file, folder, etc., and the above [1] to [3] can be collectively referred to as "products".

[0353] The terminal may run only one authentication job, or run multiple authentication jobs simultaneously or sequentially. Alternatively, the terminal may include multiple authentication sensors to run fingerprint authentication, facial authentication, hand (or palm) authentication, iris (or retina) authentication, voice authentication, vascular pattern authentication, or authentication using other biometric information.

[0354] To perform the authentication process, the terminal may also include configurations different from those described above. For example, the terminal may prepare to drive one or more authentication sensors simultaneously with the image unit being turned on (or starting to turn on), or the terminal may prepare to drive the authentication sensors while the image unit remains off. The terminal can obtain the UI... THEN Simultaneously with other specific inputs (i.e., along with the acquisition of the corresponding input), prepare the driver for the authentication sensor. Alternatively, the terminal can also acquire the UI... THEN The sensor will be used for driver authentication in the future. The terminal will then be able to utilize the UI. THEN Alternatively, it can extract other authentication information from user input and perform authentication tasks.

[0355] Regardless of this structural difference, [1] the terminal obtains the UI until it receives user input, [2] and so on. THEN [3] Until the terminal receives other (user) specific input or [4] as long as the image unit is in an off state, the "authentication operation" is considered to be in a suspended state in this specification. In other words, [1] until the terminal receives user input or obtains UI. THEN [2] As long as the image unit is in an off state, it is considered that more than one unrun (or remaining) step of the authentication operation has not been run. Therefore, the terminal receives the UI THEN The authentication process is considered to be suspended until (or other specific input) is received or as long as the image unit is in a extinguished state.

[0356] Once the terminal obtains the UI THENThe terminal can then execute (or begin executing) one or more of the previously suspended (or remaining) steps of the authentication job, allowing it to run a user authentication job that was originally in a suspended state. Therefore, by running the previously suspended or remaining steps, the terminal can perform the specific functions assigned to the authentication job.

[0357] The terminal can use various biological or non-biological information as the UI. THEN Examples of the biometric information include user body parts (such as fingerprints, hands, palms, wrists, irises, retina, eyes, ears, noses, faces, other body parts, blood vessels, blood vessel distribution patterns, etc.) or their images that can be acquired using the image acquisition unit of a terminal such as a camera or scanner. Additional examples of the biometric information include the conductivity of the body part, which is an electronic or magnetic property of the user body part; details regarding this are as described above.

[0358] Another example of biometric information is the user's (or another person's) voice or the user's (or another person's) physiological characteristics, such as [1] characteristics of the circulatory system (for example, average blood pressure, blood pressure at a specific location, heart pulse, etc.), [2] characteristics of the respiratory system (for example, respiratory rate, breathing sounds, etc.), [3] characteristics of the digestive system (for example, the activity of the stomach or internal organs) or [4] other physiological characteristics, states, etc. For this purpose, the terminal can use existing pressure sensors, flow sensors, thermometers, etc., to measure the biometric information.

[0359] Another example of biometric information includes the user's dynamic biometric information such as the movement or displacement of body parts, the speed or acceleration of the movement, position in 2D or 3D space, and posture. Existing non-biometric information, unlike these, can also be used for user authentication, examples of which include passwords, PINs, gestures, and moving patterns.

[0360] 1-20. Activation Operation

[0361] In this specification, "activation operation" refers to the operation of moving (starting to move) the terminal from the off state to the on state. The off state is the state in which the terminal is powered on and can communicate, but the image unit is off. The on state is the state in which the terminal is powered on and can communicate, and the image unit is also on. Therefore, the activation operation is the operation of moving (starting to move) the image unit from the off state to the on state, which is the same as [1] the operation of turning on the image unit when the image unit is off or [2] the operation of moving the image unit from the off state to the on state.

[0362] Therefore, "running the activation job" is the same as "running the job to open the image unit while the image unit is off". In other words, "running the activation job" has the same meaning as "opening the image unit".

[0363] The “activation job” or “opening image unit job” includes one or more of the following steps, examples of which include [1] obtaining specific input (UI) for activation (user). ACT [2] The step of turning off the power switch of the image unit or the step of waiting in order to turn on the image unit, [3] The step of supplying current to the image unit, [4] The step of selecting the basic settings screen to be displayed in the unit when the image unit is turned on from the off state, or [5] The step of covering the current screen with a new screen or replacing the current screen with a new screen in the case of terminal mobile mode, etc.

[0364] The terminal can also open the image unit through other means. As an example, the terminal can [1] prepare in advance the image screen to be displayed when the image unit is opened while the image unit is in a state of being off, so that the image screen can be displayed at the same time as the image unit is opened, [2] (as) obtain the UI. ACT Then select the screen to be displayed in the image unit, [3] receive the screen to be displayed in the image unit from external sources such as websites or clouds, or external devices, or [4] display the pre-selected screen in the image unit randomly or in a specific order.

[0365] Regardless of any differences in the specific configuration described in this specification, the "activation operation" is considered to be in a suspended state as long as the image unit is off. That is, as long as the image unit is off, more than one unexecuted (or remaining) step of the activation operation will not be executed. Therefore, as long as the image unit is off, the activation operation or the operation of opening the image unit is considered to be in a suspended state.

[0366] The terminal can synchronize the time point of opening the image unit with the time points related to the execution of other tasks. In this specification, "activation time point" refers to the time point of opening the image unit. The activation task of opening the image unit run by the terminal can be received by the UI [1]. ACT Running while receiving user input, [2] receiving data excluding UI input. ACT [3] Run simultaneously with different user inputs, [4] run immediately after receiving user inputs from [1] or [2] above, [5] run after receiving user inputs from [1] or [2] above but before the user provides the next user input, [6] run while running the user authentication job (for example, run accordingly while determining whether the user authentication job is successful), or [7] run immediately after the authentication job finishes running.

[0367] 1-21. Types of Mode Movement (Switching)

[0368] The terminal allows users to move from the current mode (or off state) to a new mode in various ways. For example, the terminal could allow the user to move one of several hierarchically defined modes at a time, in a hierarchical order, or it could allow movement based on the UI. SWI Skip the intermediate modes and move to any mode within the defined hierarchy.

[0369] In this specification, "sequential switching" refers to a configuration that moves the terminal from the current mode to adjacent modes among multiple modes defined by the hierarchy. That is, during the sequential switching, the terminal switches modes whenever it receives user input or whenever it acquires UI information. SWI It can be moved in a mobile mode. Figure 2B The hierarchy is an example of sequential switching, where multiple UI elements are presented to the user one by one. SWI The terminal is from MD LK Move to MD IN1 Then move to MD IN2 Then move to MD IN3 Then move to MD UL .and Figure 2B The hierarchy is a non-cyclic hierarchy, therefore once the terminal moves to MD... UL Therefore, even if the user provides further input, the terminal will still remain in MD mode. UL .

[0370] Figure 2F The hierarchy is also an example of sequential switching of layers, as users provide multiple UI elements one by one. SWI The terminal can be accessed from MD LK Move to MD IN Then move to MD UL .and Figure 2F The hierarchy is a cyclic hierarchy, therefore users in MD UL The driver terminal further provides a UI SWI In this case, the terminal can be moved back to MD. LK .

[0371] Therefore, regarding sequential movement, one thing a user needs to do is provide multiple UI elements one by one. SWI The terminal moves forward one mode at a time, and if the hierarchy is a cyclic hierarchy, the terminal can move backward. Therefore, if the user wants to move three spaces (or three modes) forward along the hierarchy, the user is provided with three UI elements one at a time. SWI From this perspective, if a user on a terminal that switches drivers sequentially wants to move between modes, they only need to confirm whether they want to move forward or backward, and determine how many UI elements need to be provided. SWI That's all.

[0372] As described above, as terminals switch jobs sequentially, they always move towards adjacent modes, thus eliminating the need to refer to a matching list to determine the new mode. Furthermore, regardless of the user-provided UI, terminals switch jobs sequentially... SWI In all cases, movement is only allowed within the specified hierarchy towards adjacent patterns, thus allowing users to access multiple identical UI elements for pattern movement. SWI .

[0373] Especially when switching between non-cyclic movement modes sequentially, the terminal allows the user to move only in the forward direction. In this case, a user who has reached the unlocked mode may no longer be able to move. If the user wants to move from the unlocked mode back to the locked mode (i.e., backward), they can turn off the camera unit to move to the off state and then turn the camera unit back on to move to the locked mode.

[0374] However, by sequentially switching the movement cycle mode, the terminal allows the user to re-move into the locked mode along the direction defined by the cycle. Therefore, the terminal can enable the user to move only forward, only backward, or in both directions.

[0375] Unlike the previously mentioned "sequential switching," the "selective switching" in this specification refers to the user's ability to move from the current mode to a new mode in a forward or backward direction within the terminal's driving hierarchy. In other words, with "selective switching," the terminal can acquire the UI accordingly. SWI And based on the obtained UI SWI The types of mobile modes. As an example, the terminal in Figure 2(B) enables six modes defined by hierarchy with six UIs. SWI Each match (i.e., corresponding) is performed, and the matches or correspondences are stored in the match list. The user then provides six UI elements. SWI One example (UI) SWI-3 In the case of ), the terminal refers to the matching list and selects the corresponding pattern (for example, MD). IN2 Therefore, regardless of how many grids (or modes) the user-selected mode is separated from the current mode, the terminal can move to the MD. IN2 .

[0376] In particular, in a cyclically driven terminal, the user can move from almost all current modes to almost all new modes regardless of [1] how far the new mode is from the current mode in the hierarchy or [2] whether the new mode is upstream or downstream of the current mode. Therefore, in the case of selective switching, the user only needs to confirm a UI from the matching list corresponding to the new mode they want to move to. SWI The UI will be provided later. SWI .

[0377] Furthermore, in this specification, "adaptive switching" refers to a configuration in which the terminal adaptively moves to a new mode based on a pre-selected baseline. Examples of such baselines include jobs that the user is running (or has run) in the current (or previous) mode, the results of those jobs, specific events that occur in the current mode, statistics on users of the terminal, or statistics on users in locked (or intermediate) or unlocked modes.

[0378] To enable adaptive switching, the terminal can sense predetermined benchmarks, such as [1] hardware or software elements driven (or driven) by the user in the current mode, [2] external websites or links accessed by the user in the current mode, [3] data downloaded by the user from the websites or links in the current mode, [4] the type of data processed by the user in the current mode, [5] the content contained in or linked to the data, [6] the duration the user stays in the current mode, or [7] whether there is a schedule for running specific tasks in the current mode. The terminal can determine whether it should move from the current mode to a new mode and which new mode to move to based on the benchmarks. For this purpose, the terminal can use various existing algorithms commonly used in big data, artificial intelligence, and other fields.

[0379] Conversely, the terminal can operate on adaptive switching based on benchmarks related to the user's past activities rather than current activities, or based on benchmarks related to the user's past statistics rather than current statistics. The benchmarks related to the past include [1] the hardware or software elements driven (most or least) by the user in previous modes rather than in the current mode, [2] the websites or external links visited (most or least) by the user in previous modes, [3] the external websites or external links where the user spent the most time in previous modes, [4] the data and its types downloaded by the user in the last session, last week, or last month, [5] the data obtained by the user (most or least) in previous modes, or [6] the content and types contained in said data. For this purpose, the terminal can use a variety of existing algorithms used in the field of big data artificial intelligence.

[0380] Adaptive switching varies depending on whether the hierarchy is cyclic or non-cyclic. In other words, in a non-cyclic hierarchy, once the device is moved to unlock mode, it cannot move to other modes even if the AI ​​algorithm suggests any new modes. Conversely, in a cyclic hierarchy, the device can move from unlock mode to any mode defined in the hierarchy.

[0381] Alternatively, if the terminal senses different benchmarks, it can move from the current mode to a new mode. Examples of these different benchmarks include [1] the occurrence or end of a specific event, [2] the running or ending of a specific job (or the job starting to run or starting to end), [3] the running or ending of a specific (software) application (or the application starting to run or starting to end), or [4] obtaining the "product" obtained through the job or application. Therefore, the terminal does not need to wait to receive user input or obtain the UI. SWI The movement can be based on the reference movement mode, which can be pre-selected by the terminal manufacturer, terminal, user, etc.

[0382] The terminal can move from the current mode to a new mode at various "mode move points" based on events related to activation time points, erase time points, start time points, or storage time points. In particular, mode move points refer to various time points between mode movement and other operations running on the terminal. Examples of mode move points include [1] receiving UI. SWI While receiving user input, [2] receiving data excluding UI input. SWI [3] At the same time as the user input, [4] after receiving the user input mentioned in [1] or [2] above, [5] after receiving the user input mentioned in [1] or [2] above but before the user provides further user input, [6] at the same time as the authentication job ends, [7] after the authentication job is run, [8] at the same time as (or after) the erase (or partial erase) job is run, [9] before, at the same time as or after the image unit is turned on,

[10] before, at the same time as or after the power of the terminal is turned off (or on),

[11] before, at the same time as or after the main system, intermediate system or locking system is turned on,

[12] at the same time as or after the “product” obtained from the operation of the lock (or intermediate) mode is stored, or

[13] after the storage mentioned above.

[0383] 2. Purpose

[0384] The following are the objectives to be achieved through various data processing terminals described in this specification. However, these objectives are merely illustrative and therefore do not limit the scope or applicability of the terminals described. 2 The focus of the data processing terminal, the unit of the terminal, hardware elements, software elements and other characteristics is to protect the main system of the terminal for the "product" obtained by driving the locking system to run the locking operation in the locking mode. However, the terminal can also protect the main (or intermediate) system of the terminal for the "product" obtained by driving the intermediate (or locking) system to run the intermediate (or locking) operation in the intermediate (or locking) mode.

[0385] 2-1. Run a locking operation via the locking system in locked mode.

[0386] The first exemplary aspect of the data processing terminal and related methods in this specification, namely the first objective, is to restrict all or part of the (accessible) hardware or software elements of the main system of the terminal to be inaccessible when the user drives the terminal in a locked mode. Therefore, it is possible to prevent the user of the terminal in a locked mode from [1] driving more than one hardware or software element of the main system or [2] accessing and driving said hardware or software element without utilizing all options.

[0387] Therefore, one or more parts of the terminal's main system can be physically or operationally isolated from the terminal's locking system. Furthermore, the terminal can prevent users driving it in locked mode from driving all (or some) of the main system's hardware or software components. Through this isolation, the "products" of locking operations performed through the locking system in locked mode cannot adversely affect the main system of the same terminal.

[0388] For ease of explanation, "(in locked mode) run more than one job through the locked system" is considered to have the same meaning as "run more than one locked job", "run a locked job", or "run multiple locked jobs". Furthermore, "(in intermediate mode) run more than one job through the intermediate system" is considered to have the same meaning as "run more than one intermediate job", "run an intermediate job", or "run multiple intermediate jobs".

[0389] The terminal of the first embodiment of the first objective can [1] directly based on the UI. SWI [2] Based on the UI used during operation THEN The authentication results are obtained at equal intervals based on user input or [3] based on the terminal settings selected by the user or terminal and moved from the current mode to a new mode.

[0390] In the second embodiment of the first objective, the user can run a job (i.e., run a locking job) in a locked mode by a locking system while all (or part of) the hardware or software elements of the main system of the undriven terminal are accessible. In particular [1] while the user is running a locking job in a locked mode, [2] while the user is driving the terminal in a locked mode, or [3] before the terminal moves to a new mode that is granted wider access permissions, the terminal can prevent the user from storing unauthenticated or untrusted "products" into the main memory unit of the main system.

[0391] As described above, the locking system is physically or operationally isolated from the main system of the terminal. Therefore, by [1] prohibiting the user from performing unauthorized modifications to the main system during the locking operation through the locking system in the locking mode, [2] prohibiting the terminal from performing the aforementioned [1] modifications after moving to the unlock mode, or [3] prohibiting intrusion into the main system, the terminal can improve the security of the main system.

[0392] Therefore, unless the terminal performs an erase (or partial erase) operation, the terminal can [1] prevent the user from modifying or altering the main system during or after the lock operation, or [2] prevent such modification or alteration even after the terminal moves to unlock mode. Thus, the terminal can improve the integrity of the main system. Furthermore, by preventing [1] unauthenticated users from accessing personal information stored in the main memory unit of the main system in lock mode, or [2] users from retrieving data stored in the main system in an unauthenticated state during or after the user drives the terminal in lock mode.

[0393] Furthermore, the "products" obtained from running the locking job cannot drive or modify the main system in the locking mode. Therefore, the user[1] does not need to worry about adverse effects on the security or integrity of the main system or[2] does not need to worry about contaminating the main system. The user can run any locking job. Therefore, regardless of the knowledge or trustworthiness of the website accessed in the locking mode, the user can permanently or temporarily store the "products" obtained from running the locking job in the locking memory unit of the locking system.

[0394] The terminal may include one or more locking systems capable of performing locking operations in a locking mode. In the case of a terminal including multiple locking systems, the terminal may grant different access permissions to two or more locking systems. Furthermore, two or more (or all) locking systems may be physically or operationally isolated from one or more parts of the main system. Therefore, it is possible to prevent [1] the locking system from adversely affecting the main system, or [2] to prevent the "products" obtained from performing locking operations from adversely affecting the main system. That is, as long as it does not adversely affect the security, integrity, or personal information security of the main system, the terminal may allow users to access data stored in the main system, but may prohibit users from modifying, replacing, or otherwise altering elements or units of the main system.

[0395] Taking advantage of this, multiple users can use a terminal in a variety of ways. For example, multiple users can drive the terminal in a shared lock mode, a shared intermediate mode, or a shared unlock mode. Alternatively, the terminal can enable users to drive only the lock system, intermediate system, or main system they use. In particular, the terminal can prevent [1] users from driving other users' systems, [2] users from moving back and forth to other users' modes, or [3] the "products" of a particular user's lock operation from adversely affecting other users' lock, intermediate, or main systems. Therefore, the terminal can maintain the security, integrity, or personal information protection of each user's main system or a shared main system for multiple users.

[0396] 2-2. Erase the "products" obtained by running a locking operation in locked mode.

[0397] A second exemplary aspect of the data processing terminal and related methods in this specification, namely the second objective, is to be able to erase all or part of the "products" obtained by the user in lock mode through a lock system performing a lock operation.

[0398] The terminal of the first embodiment of the second objective can perform an erase operation that erases all or part of the "product" obtained by the locking operation driven by the locking system in locked mode. Alternatively, the terminal can perform a partial erase operation that erases only a specific portion of the "product" instead of all of it. (Due to the section...) 1-6 The erasure operation or partial erasure operation has been explained in detail, so it will not be repeated here.

[0399] In the second embodiment of the second objective, the terminal can synchronize the aforementioned erase (or partial erase) operation with multiple points in time (especially when or after the user moves from the current mode to a new mode). For example, the terminal can run the erase (or partial erase) operation when moving from a mode with fewer (or wider) access permissions to a mode with wider (or fewer) access permissions. Alternatively, the terminal can run the erase (or partial erase) operation each time a mode is moved. The terminal can run the erase (or partial erase) operation when moving from a closed state to an open state (or vice versa). This configuration prevents the "products" obtained from running the operation in the first mode from automatically moving to the second mode, thus preventing the "products" from adversely affecting the hardware or software elements of the terminal's main system.

[0400] The terminal can synchronize the timing of an erase (or partial erase) operation with the timing of other operations performed by the terminal. In particular, in this specification, "erasure timing" refers to the timing related to the execution of an erase (or partial erase) operation and a mode-shift operation, examples of which include [1] simultaneous with the execution of a mode-shift operation (i.e., when one or more steps of an erase (or partial erase) operation overlap with one or more steps of a mode-shift operation in one or more common clock cycles), [2] after the execution of a mode-shift operation, or [3] after the execution of a mode-shift operation but before the user provides further user input, etc.

[0401] The “erasure time point” may include different time points related to various operations running on the main (or locked) system of the terminal, such as [1] at the same time as the authentication operation (for example, confirming whether the user authentication is successful or failed), [2] after the authentication operation, [3] before, at the same time or after the image unit is turned on, [4] before, at the same time or after the power of the terminal is turned off (on), or [5] at the same time or after receiving user input related to the erasure (or partial erasure) operation.

[0402] Therefore, the terminal can provide users with seamless functionality and the resulting convenience. Users can also ensure that temporary or permanent storage or residual "products" in the locking system, such as locked memory cells or locked memory sectors, will not adversely affect any unit or element of the main system. Furthermore, users can easily erase records of their operations performed in locked mode through the locking system.

[0403] From a clock cycle perspective, the terminal can perform erase (or partial erase) jobs in several ways. Firstly, the terminal can perform erase (or partial erase) jobs in real-time. Alternatively, the terminal can perform erase (or partial erase) jobs each time the user runs a lock job, thus erasing (or partially erasing) data, files, or folders one by one whenever they are generated. This is referred to in this specification as a subsequent "real-time erase (or partial erase) job."

[0404] Alternatively, the terminal may run a "potential erase (or partial erase) job," in which the terminal may [1] run an erase (or partial erase) job at a specific (time) interval, [2] at a user-defined interval, or [3] whenever the size of the "product" obtained from running a lock job exceeds a specific size. Conversely, the terminal may run a "post-erasure erase (or partial erase) job," in which the terminal runs an erase (or partial erase) job after the user has finished running a lock job in lock mode.

[0405] The terminal of the third embodiment of the second objective can perform an erasure (or partial erasure) operation to erase all or part of the "products" obtained from operations running in multiple modes. The locking system of its first specific example can perform the erasure (or partial erasure) operation in a locked mode. That is, the locking system starts the erasure (or partial erasure) operation in the locked mode, and the operation of the erasure (or partial erasure) operation can end before or after the terminal moves to a new mode (such as an intermediate or unlocked mode).

[0406] In a second specific example, the intermediate system can perform an erase (or partial erase) operation in an intermediate mode. That is, the intermediate system begins the erase (or partial erase) operation in the intermediate mode, and the terminal can end the erase (or partial erase) operation before moving to a new mode such as an unlock mode or after the mode is moved. In a third specific example, the main system can perform an erase (or partial erase) operation in an unlock mode, and the terminal can end the erase (or partial erase) operation after moving to a new mode such as an intermediate mode or a locked mode.

[0407] In the first and second specific examples above, the terminal can perform an erase (or partial erase) operation when moving from a mode with fewer access permissions to a mode with more access permissions. Therefore, this configuration not only improves the security and integrity of the terminal's main system but also strengthens the protection of personal information stored on the main system.

[0408] Conversely, in the third embodiment, the terminal can perform an erase (or partial erase) operation while moving from a current mode with wide access permissions to a mode with fewer access permissions. However, the terminal performing the erase (or partial erase) operation is still secure even if it does not perform the operation, because the potential threat posed by the unlocked mode-driven main system is low in this case.

[0409] However, when the user moves in the mode described in the third specific example, they can also run an erase (or partial erase) operation to erase the products obtained from running multiple unlock operations in the unlock mode. As a result, the user can effectively prevent third parties from tracking [1] the unlock operations they ran, [2] the websites they visited, [3] the content they downloaded from external sources, or [4] their communication content in the future. From this point of view, whether it is the lock system or the main system, as long as the user is concerned about the personal information contained in the data stored or remaining therein, the terminal can run an erase (or partial erase) operation every time the user moves in the mode.

[0410] 2-3. Store the "products" obtained by running a locking job in locked mode.

[0411] A third exemplary aspect of the data processing terminal and related methods in this specification is that the third objective is to store a portion, but not all, of the "product" obtained by the user driving the locking system to run a locking operation in the locking mode, and to prevent the stored "product" from adversely affecting the main system or from hindering the main system from running an unlocking operation in the unlocking mode.

[0412] In the first embodiment of the third objective, the locking system includes a locking memory unit, thus allowing at least a portion of the "products" obtained from performing locking operations while the locking system is running in locking mode to be temporarily or permanently stored in the locking memory unit. In particular, the locking memory unit can be physically or operationally isolated from the main system's main memory (or other) units. As a result, the terminal can protect the main system's main memory (or other) units from contamination or interference by the "products" stored in the locking memory unit. That is, by physically or operationally isolating the locking memory unit from the main system, the terminal can not only prevent the "products" from contaminating or damaging the main system, but also enable the user to fully utilize both the locking system and the main system.

[0413] The locking system of the second embodiment of the third objective does not include a locking memory unit, but the terminal can cause the locking system (1) to invoke at least a portion of the main memory unit of the main system, and (2) to temporarily or permanently store at least a portion of the "product" obtained by driving the locking system in the locking mode to run a locking operation in the main memory unit. In this case, the terminal physically or operationally isolates the portion of the main memory unit invoked (or driven) by the locking system from the rest of the main memory unit, thereby preventing data stored or remaining in the portion of the main memory unit from contaminating the rest of the unit. From this viewpoint, the portion of the main memory unit driven by the locking system can be regarded as a unit of the locking system rather than a unit of the main system.

[0414] The terminals described in various embodiments of this section can perform erase (or partial erase) operations on a portion of the main memory unit that is locked to the system drive at multiple erase points in time, thereby erasing all or part of the "products" stored or remaining in that portion of the main memory unit. Thus, the terminal can completely erase viruses or malware contained in the "products" to ensure that the main system cannot be contaminated.

[0415] In the described embodiment, the terminal allows a user to store at least a portion of the "products" stored or remaining in the locked system, and then access the stored "products" when running a job through the main system in unlocked mode. Here, the terminal prevents the "products" from altering units of the main system or being stored in the main system. Furthermore, the terminal allows the user to subsequently retrieve the portion of the "products" stored in the main system's main memory unit and store it in the main memory unit. In this case, it is necessary to verify whether the stored products contain malicious viruses.

[0416] 2-4. Install the locking system and main system

[0417] The fourth illustrative aspect, or fourth objective, of the data processing terminal and related methods described in this specification is to enable the terminal to have various hardware or software configurations and run various operations to achieve the various objectives described herein. To this end, the terminal includes one or more main systems and one or more locking systems, which can physically or operationally isolate the latter from at least a portion of the former. Furthermore, when the terminal includes one or more intermediate systems, the locking system can physically or operationally isolate at least a portion of the intermediate (or main) system from the intermediate (or main) system. However, the characteristics of the locking system in the following various embodiments driven in locking mode can also be applied to the intermediate system driven in intermediate mode.

[0418] The data processing terminal of the first embodiment of the fourth objective includes one or more main systems and one or more locking systems. The main system includes one or more (1) main CPU units, (2) main memory units, (3) main input units, (4) main output units, etc., and may optionally include other units typically included in other existing data processing devices. The locking system includes one or more locking (application) viewers (for example, existing file viewers, etc.), and may optionally include one or more locking hardware elements (for example, locking memory units, locking CPU units, locking image units, etc.) and one or more locking software elements (for example, locking software applications, etc.).

[0419] In particular, the elements of the locking system in the described embodiment can be isolated from the elements of the main system in terms of operation, so the terminal can prevent the locking system from driving any element of the main system. Furthermore, the elements of the locking system in the described embodiment can be physically isolated from all elements of the main system; therefore, the terminal can configure the elements of the locking system in locations that are not physically adjacent to the elements of the main system.

[0420] As an example, a terminal may include one or more main systems and locking systems with various structures. In this first specific example, the locking system may be installed completely independently (hereinafter referred to as "completely isolated") from the main system, so that the locking system is physically or operationally isolated from all units or elements of the main system. As a result, if the locking system includes locking hardware elements or locking software elements, the locking elements may be physically or operationally completely isolated from all units or elements of the main system. Thus, the terminal can [1] completely prevent any "products" stored or remaining in the locking system from adversely affecting any unit or element of the main system, or [2] completely prevent any locking unit or locking element from adversely affecting any main unit or main element of the main system.

[0421] In the second specific example, the locking system may be physically or operationally partially isolated from all units or elements of the main system (hereinafter referred to as "partial isolation"). Thus, when the locking system includes locking hardware elements or locking software elements, [1] the locking element may be physically or operationally isolated from one or more units or elements of the main system, but not all units or elements, or [2] the locking element may be partially isolated from one or more units or elements of the main system, although not from all units or elements. As a result, the terminal may ensure that "products" stored or remaining in the isolated units of the locking system cannot adversely affect any unit of the main system.

[0422] The data processing terminal of the second embodiment of the fourth objective includes one or more main systems and one or more locking systems similar to the first embodiment of the fourth objective. Furthermore, the locking elements of the locking system are physically isolated from all elements of the main system (i.e., installed in different locations), but the locking system and the main system are not completely isolated in terms of operation. That is, the terminal can cause [1] the locking system to drive one or more elements of the main system or [2] the locking system to call (i.e., drive) at least one but not all elements of the main system in locking mode. From this perspective, the locking system and one or more (but not all) elements of the main system can be said to "partially interact in terms of operation." Conversely, if the locking system can access all elements of the main system in locking mode, the locking system can be said to "fully interact in terms of operation."

[0423] In this embodiment, the locking system is physically isolated from the main system, so it can be installed in a location far removed from all elements of the main system. In other specific examples, the locking system can drive at least a portion (not all) of the main memory unit, temporarily or permanently storing all or part of the "products" obtained from performing a locking operation in locking mode in said portion of the main memory unit. The locking system can then retrieve the stored "products" from said portion of the main memory unit. In other specific examples, the locking system can drive at least a portion (not all) of the main CPU unit to perform a locking operation in locking mode. In other specific examples, the locking system can drive at least a portion (not all) of the main image unit while simultaneously displaying multiple "products" obtained from performing a locking operation in locking mode in said portion of the main image unit.

[0424] As described above, when the terminal locks certain elements of the main system, it can [1] prevent the locking system from deleting data already stored in the main memory unit, or [2] prevent the main system from changing its unit configuration. Therefore, the terminal can improve the security and integrity of the main system and strengthen the protection of personal information.

[0425] The data processing terminal of the third embodiment of the fourth objective includes one or more main systems and locking systems similar to those in the first embodiment of the fourth objective. However, the units or elements of the locking system can be "completely isolated in operation" (i.e., do not interact) from the units or elements of the main system. Therefore, as long as the user drives the terminal in locked mode, the locking system may not be able to drive any element of the main system.

[0426] However, one or more elements of the locking system can [1] be installed close to one or more elements of the main system in the vertical or horizontal direction, or [2] constitute an object with one or more elements of the main system. Therefore, even if the locking system and the main system are completely or partially isolated in operation, the locking system can still "physically interact" with (not all) one or more elements of the main system.

[0427] The locking system of the described embodiment is isolated from the main system in operation, therefore the locking system may not be able to drive (i.e., invoke) any element of the main system. However, in this first specific example, the locking memory unit of the locking system can be installed near the main memory unit of the main system or the locking memory unit and the main memory unit can be manufactured into one object. However, the locking system cannot drive any part of the main memory unit, and the main system may also be unable to drive any part of the locking memory unit. In yet another specific example, the locking CPU unit of the locking system can be installed near the main CPU unit of the main system or the locking CPU unit and the main CPU unit can be constructed into one object. However, the locking system cannot drive any part of the main CPU unit, and the main system cannot drive any part of the locking CPU unit.

[0428] The data processing terminal of the fourth embodiment of the fourth objective includes one or more main systems and locking systems similar to those in the first embodiment of the fourth objective. However, the main system is capable of "interacting with one or more elements of the locking system in operation". Therefore, as long as the user drives the terminal in unlocked mode, the main system can drive the part of the locking system that interacts with the main system, regardless of whether [1] the locking system is capable of "interacting with one or more elements of the main system in operation", and therefore regardless of whether the locking system can drive the elements of the main system in locked mode, or regardless of whether [2] the locking system and all parts of the main system are "isolated in operation", and therefore regardless of whether the locking system can drive the parts of the main system in locked mode. In this case, the locking system can be physically isolated from the main system or physically interact with one or more parts of the main system.

[0429] As described above, the terminal can grant different access permissions to the locking system and the main system in locked and unlocked modes, respectively. Therefore, in the fifth embodiment of the fourth objective, the terminal can completely restrict any hardware or software elements of the main system that prevent the locking system from driving in locked mode. Alternatively, the terminal can allow the locking system to drive specific hardware or software elements of the main system in locked (or intermediate) mode.

[0430] Therefore, by adjusting the degree of physical isolation or operational isolation between the main system and the locking system, users can easily run locking operations through various methods such as [1] driving the locking system only in locking mode, [2] driving the locking system in both locking and unlocking modes, or [3] driving the main system in unlocking mode together with [1] or [2] above. However, the terminal can prevent or minimize accidents that could adversely affect the main system from the locking system, and can prevent confusion between the locking (or main) system and the main system during operation in locking (or main) mode, so that the "products" obtained from running the locking (or main) operation in locking (or main) mode do not reduce the security, integrity, or personal information protection of the main (or locking) system.

[0431] Terminals incorporating the aforementioned locking system may require more than one additional locking hardware or software element, and may need additional space within the terminal for installing these additional elements. However, the benefits offered, such as seamless operational flexibility, enhanced security and integrity, minimized risk of unauthorized user intrusion, and strengthened protection of personal information stored on the terminal, outweigh the costs or effort associated with the additional elements or additional space. Alternatively, by physically or operationally isolating the main system from the locking system and using the main CPU unit or main operating system as the locking system or main system, the terminal can provide the aforementioned benefits without the additional elements or space.

[0432] 2-5. System installation in locked and unlocked modes.

[0433] The fifth illustrative aspect, namely the fifth objective, concerning the data processing terminal and related methods of this specification relates to a system that can be driven as both a master system and a locking system, and is a terminal capable of being driven in both unlocked and locked modes. That is, such a terminal is a system that is driven as a master system only in unlocked mode and can be driven as a locking system in locked mode. Therefore, the system can be considered as [1] a system driven as a master system in unlocked mode or a system that can be driven as a locking system in locked mode, or [2] a system that is driven as a locking system in locked mode and can be driven as a master system in unlocked mode. For ease of explanation, the following description is equivalent to [1] above. However, various embodiments of this section are also equivalent to [2] above. Generally, various embodiments of this fifth objective can be implemented using a terminal with the following third configuration.

[0434] The data processing terminal of the first embodiment of the fifth objective includes a system. In a locked mode, the terminal drives the system as a locking system, which drives specific hardware or software elements of the terminal, but may prevent [1] other hardware or software elements of the terminal from being driven, [2] other hardware or software elements from being changed, [3] data stored in the elements from being erased, [4] the structure or job execution order of the elements from being changed, [5] the "products" obtained from running a locking operation in the locked mode from being stored in the elements, [6] the elements from being updated or rearranged, or [7] data stored in the system from being sent to other elements of the locking system, other terminals, or third parties. Alternatively, the terminal may drive the system as the main system and drive other elements in an unlocked mode. The system may also be driven in multiple locked or unlocked modes. Furthermore, when the terminal moves from a locked mode to another locked or unlocked mode (or from an unlocked mode to a locked mode) or receives specific user input, the terminal may perform an erase (or partial erase) operation.

[0435] In other words, such a system can be viewed as a pool of multiple hardware or software elements. In this case, the terminal can be seen as assigning specific elements to the locked system, and conversely, assigning the remaining elements to the main system. Furthermore, to enhance security, improve integrity, and protect personal information, the terminal can physically or operationally isolate the hardware or software elements driven by the system in locked mode from the remaining elements driven by the system in unlocked mode. Conversely, the terminal can partially isolate elements driven by locked mode from those driven by unlocked mode.

[0436] The data processing terminal of the second embodiment of the fifth objective also includes only one system. In locked mode, the terminal drives the system as a locking system, which drives specific hardware or software elements of the terminal, but may prevent other elements of the terminal from being driven or prevent the operation of [1] to [7] of the first embodiment of the fifth objective from running. Furthermore, in unlocked mode, the terminal drives the system as the main system while running multiple operations. Therefore, the difference between the terminals of the first and second embodiments is that one or more elements of the latter terminal can be driven not only by the locking system but also by the main system.

[0437] From this perspective, the system of this embodiment can be regarded as a pool of multiple hardware or software elements. In this case, it can be regarded as the terminal [1] allocating the first group of elements to the locking system, [2] allocating the second group of elements to the main system, and [3] allocating the third group of elements to both the locking system and the main system. In order to enhance security, improve integrity, and highly protect personal information, the elements of the first group and the elements of the second group can be completely isolated physically or in operation. At the same time, the terminal can enable the elements of the third group to [1] run the same operation in both the locking and unlocking modes, [2] run more operations in the unlocking mode than in the locking mode, [3] access and use the same data in both the locking and unlocking modes, or [4] access more data in the unlocking mode than in the locking mode.

[0438] The system in this embodiment can function as both a main system and a locking system, thus making the manufacture of terminals including such systems relatively easy. For example, the terminal can assign different access permissions to the locking system and the main system, or display different graphical user interfaces (GUIs) on the lock and unlock screens. Furthermore, since the locking system and the main system can use the same hardware or software elements, the terminal does not need to include identical units in both systems, resulting in the ability to manufacture such terminals as small devices. Moreover, by isolating the locking system from the main system, the terminal enhances security, prevents intrusion, improves integrity, and protects personal information. The terminal also provides users with operational flexibility, such as assigning different access permissions to different modes while using only one system.

[0439] 2-6. Multiple modes and access permissions

[0440] The sixth exemplary aspect of the data processing terminal and related methods in this specification, namely the sixth objective, is to provide a terminal driven in one or more locked modes and one or more unlocked modes, and selectively in one or more intermediate modes (for example, a semi-locked mode, a less locked mode, a semi-unlocked mode, a less unlocked mode, etc.), with different access permissions granted. As stated above, "access permission" means [1] the permission to access a specific number (including '0') of the accessible hardware or software elements of the terminal's main system without mentioning a locking (or intermediate) system, [2] the permission to drive the elements, [3] the permission to run a specific job by driving the elements, or [4] the permission to perform a specific function by driving the elements or running the job. However, the characteristics of the locking system described in this section regarding the driving in locked mode can also be applied to intermediate systems driven in intermediate modes.

[0441] The terminal of the first embodiment of the sixth objective [1] may grant the widest access permission to the unlock mode, [2] the narrowest access permission to the lock mode, or [3] grant access permission to intermediate modes (for example, a half-lock mode, a half-unlock mode, etc.) that is wider than the access permission granted to the lock mode but less than the access permission granted to the unlock mode. When there are multiple unlock modes with overlapping access permissions defined by the hierarchy, the terminal may [1] grant the same access permission to each unlock mode, [2] grant the unlock mode a wider access permission than other unlock modes, or [3] grant the unlock mode a narrower access permission than other unlock modes.

[0442] In the case of multiple non-overlapping unlock modes with non-overlapping access permissions defined in a hierarchy, the terminal may assign different non-overlapping access permissions to each unlock mode. In particular, since the access permissions do not overlap, it may not be easy to determine which unlock mode has wider access permissions. However, from a quantitative point of view, it can be stated that an unlock mode can drive more hardware or software elements or [2] run more jobs compared to other unlock modes [1]. The above and following descriptions of the characteristics associated with multiple unlock modes can also be applied to a hierarchy that defines multiple locking (or intermediate) modes.

[0443] The terminal of the second embodiment of the sixth objective defines multiple completely non-overlapping modes at a specific level, (1) the modes do not completely overlap with each other, and (2) the terminal can assign different access permissions to each mode. As an example, such as Figure 1C (D) and Figure 1D As shown in (D), different systems driven by non-overlapping modes can be more easily isolated.

[0444] This non-overlapping characteristic can also be applied to specific hardware or software elements. For example, it can enable the main system to drive the main memory unit in unlock mode, and conversely, prevent the locking system from driving the main memory unit in lock mode. This non-overlapping characteristic can also be applied to multiple parts of a specific hardware or software element. For example, the terminal can enable both the locking system and the main system to drive the main memory unit. However, the terminal can enable the locking system (1) to access the locking data stored in the main memory unit after performing a locking operation in lock mode using the locking system, and (2) to not access the unlocking data obtained by performing an unlocking operation in unlock mode. Furthermore, the terminal can enable (1) the main system to access all unlocking data and (2) to not access the locking data.

[0445] The aforementioned non-overlapping characteristics can also be applied to the software elements of the main system. As an example, the terminal can enable the main system and the locking system to drive software applications that execute financial transactions. However, in this case, the terminal can enable (1) the locking system to run operations that send limited information to a third party, (2) but cannot directly execute financial transactions. At the same time, the terminal can enable (1) the main system to run financial transactions or personal information retrieval operations, (2) but cannot send data to or receive data from a third party.

[0446] The data processing terminal of the third embodiment of the sixth objective can define multiple partially overlapping modes at a specific level such that (1) the access permissions of each mode only partially (not entirely) overlap with the access permissions of other modes, and therefore (2) it is possible for two or more modes to have common access permissions to one or more hardware or software elements. As an example, it is possible for a first system driven by a first mode to drive one or more elements of a first hardware or software element (or parts or options of these elements), and conversely, for a second system driven by a second mode to drive one or more elements of the element (or parts or options of these elements). Of course, it is also possible for the second system to be unable to drive all of the first hardware or software elements.

[0447] The terminal of the fourth embodiment of the sixth objective can grant different access permissions to specific hardware or software elements allocated to the main system through multiple user interfaces. The terminal can operate the interface based on various factors, such as [1] the user's current terminal driving mode, [2] the currently granted access permissions to the user, and [3] whether the user authentication process was successful. Therefore, the terminal can restrict access to hardware or software elements of the main system by operating the interface.

[0448] In a first specific example of the fourth embodiment, the terminal can operate a "DUI" (i.e., direct manipulation user interface) assigned to a specific hardware or software element. As an example, the terminal can operate a DUI that [1] completely or partially restricts the normal function of the DUI in locked mode or [2] allows the normal function of the DUI in unlocked mode but completely or partially restricts the function of the DUI in locked mode. Therefore, the user cannot operate the specific DUI in locked mode, and thus cannot operate the hardware or software elements displayed by the DUI.

[0449] In a second specific example of the fourth embodiment, the terminal can directly operate a "GUI" (Graphical User Interface or GUI-based interface) assigned to specific hardware or software elements in a specific mode. For example, when the user is driving the terminal in locked mode, the terminal may not display an object-oriented GUI, application-oriented GUI, etc., on the image unit. Therefore, the terminal can effectively prevent the user from driving hardware or software elements of a GUI not displayed on the locked screen while in locked mode. However, once the terminal moves to unlocked mode, the terminal can display the GUI on the screen to provide the user with tools to access the elements assigned to the GUI.

[0450] In this configuration, the terminal can use various GUIs, such as [1] a GUI corresponding to a specific hardware or software element, [2] a GUI corresponding to a specific part of a specific hardware or software element, or [3] a GUI indicating a specific access permission. Therefore, in a specific mode, the user can confirm the hardware or software elements that they can drive in that mode simply by seeing the GUI displayed on the image unit. At the same time, the terminal can easily operate the access permissions granted to that mode.

[0451] In the third specific example of the fourth embodiment, the terminal can display the GUI on the lock screen in either locked or unlocked mode, while in a specific mode, some functions of the GUI can be restricted (i.e., the GUI is restricted). Therefore, the user can see the restricted GUI on a specific (for example, locked) screen, but as long as the user drives the terminal in the specific (for example, locked) mode, the hardware or software elements corresponding to the restricted GUI cannot be driven.

[0452] As an example, the terminal displays a restricted GUI regarding the main memory unit in both locked and unlocked modes. In unlocked mode, the restricted GUI is displayed in a relatively dark color (i.e., an unrestricted GUI), allowing the user to input data into the GUI and drive the corresponding hardware or software elements. However, in locked mode, the terminal can display the GUI in a relatively light color (i.e., a restricted GUI), preventing the user from driving the corresponding elements even if they input data. Therefore, in a specific mode, the user can easily distinguish which hardware or software elements they can drive simply by checking the color of the GUI displayed on the image unit.

[0453] The terminal can display the same GUI in different modes with different colors or shapes, in different positions on the screen, in different directions, blurred, or displayed directly without such blurring. Given that users can easily determine which GUI elements are operable and which hardware or software elements can be operated in a specific mode, the terminal can display the GUI through various methods.

[0454] In the fourth specific example of the fourth embodiment, the terminal can operate a "TUI" (i.e., touch user interface), which is a special form of GUI displayed on a touchscreen-type image unit. Therefore, the terminal may not display a TUI corresponding to a hardware or software element with restricted access on the touchscreen. Alternatively, the terminal may display a TUI corresponding to a restricted element on the touchscreen, but prevent the user from selecting or driving the element. Here, when displaying a TUI for a restricted element, the terminal may [1] display it with a shape, size, or color different from that of a TUI for an unrestricted element, [2] display it at a location different from the location of the TUI for an unrestricted element, or [3] display it vaguely. The above description of TUI can also be applied to object-oriented GUIs or application-oriented GUIs, etc.

[0455] The terminal of the fifth embodiment of the sixth objective can use different existing user interfaces (UIs) other than those described in this section, as described herein. Examples of these different existing interfaces include web-based UIs, command-line UIs, hardware (or firmware) UIs, attentive UIs, batch UIs, conversational UIs, crossing-based UIs, gesture UIs, holographic UIs, motion-tracking UIs, multi-screen UIs, and reflective UIs. Furthermore, the various embodiments described in this section are applicable not only to locked and unlocked modes but also to intermediate modes that are granted wider access permissions than locked modes but cannot drive all hardware or software elements.

[0456] In the sixth embodiment of the sixth objective, the operating system or application of the data processing terminal can allow or deny access to specific hardware or software elements based on the terminal's driving mode. In a first specific example, if the current driving mode is confirmed, the terminal references a database of hardware or software elements that the user can drive in that specific mode. Therefore, whenever user input is received, the terminal can determine whether the user has access rights to drive the specific hardware or software element. If the user has the required permissions, the terminal drives the element accordingly based on the user input. However, if the user does not have the required permissions, the terminal may take no action or prompt the user that the element cannot be driven.

[0457] In a second specific example, the terminal confirms the current mode and refers to the database to confirm a list of hardware or software elements that the user can drive in that mode. The terminal can then provide the user with a GUI via mechanical, electronic, or visual means. In a third specific example, the terminal can utilize existing technology that assigns different access permissions to different hardware or software elements based on the type of the current mode or the type of new mode the user wants to move to. Various examples of this existing technology will be specifically described in sections 4-11-6 below.

[0458] In the seventh embodiment of the sixth objective, the terminal assigns specific access permissions to various modes defined in a specific layer, and then provides information about the access permissions to the user using visual, auditory, or tactile notification signals. Various notification units, main image units, or main speakers can generate the notification signals. The user can confirm, based on the notification signals, [1] the type of access permissions assigned to the user in the current mode, [2] the type of access permissions assigned to the user when the terminal moves to a new mode, [3] the hardware or software elements that the user can drive in the current mode or the new mode, [4] the hardware or software elements that the user can drive after moving to the new mode, or [5] the hardware or software elements that the user can no longer use after moving to the new mode, etc.

[0459] In the first specific example, the terminal can assign different visual characteristics to each mode to display different images in different modes. In particular, the terminal can assign unique colors, shapes, images, orientations, sizes, and patterns to each mode. Therefore, users can easily identify the mode they are driving the terminal through these visual characteristics. In the second specific example, the terminal can assign the above-mentioned visual characteristics to the notification unit, which will be explained in detail below.

[0460] In the third specific example, the terminal may display the same or similar background screen in two or more modes, may display different GUI groups on the screen, and may display a blurred or no GUI about restricted (and therefore not driven in the mode) elements.

[0461] In the fourth specific example, the terminal displays the same GUI in all modes, but the GUI is restricted to displaying different shapes, sizes, orientations, positions, colors, or patterns on the image unit or notification unit in specific modes. That is, as long as the terminal can prompt the user about the specific mode it is operating in, the terminal can use not only the visual method, but also auditory methods such as sound or beeping, and tactile methods such as vibration. Therefore, the user can easily confirm the current operating mode of the terminal, the new mode to be moved to, etc. If the user realizes that they are operating the terminal in the wrong mode, the user can take corrective actions such as providing specific input to move to the correct mode.

[0462] In the fifth specific example, the terminal can assign different access permissions to accessible hardware and software elements in various modes defined within a specific layer. The specific descriptions of other components or operational procedures in this specific example are the same or similar to the corresponding descriptions of the other specific examples, and therefore will not be repeated here.

[0463] 2-7. Easy movement between different modes and states

[0464] The seventh exemplary aspect of this specification regarding the data processing terminal and related methods, namely the seventh objective, is to provide a terminal including hardware or software elements that enable the user to easily move modes, examples of which include [1] moving from a power-off state to a new mode defined by a hierarchy, [2] moving from a power-on, off state to a specific mode, [3] moving from the current mode to a new mode, [4] moving from a specific mode to a power-off state, [5] moving from the current mode to a power-off state, etc. Therefore, the user does not need to perform a process of turning off and on the image unit in order to move from the current mode to a new mode, or, does not need to perform an authentication process.

[0465] In the first embodiment of the seventh objective, the terminal may include a UI developed to receive specific input from a modal mobile user. SWI The input unit is a mobile input unit for one or more user input modes. The input unit can be manufactured as a "soft key" (e.g., a GUI displayed on the image unit) or a "hard key" (e.g., installed in an appropriate location on the terminal). The terminal can use various existing input units as the aforementioned hard keys.

[0466] The terminal of the first embodiment of the first specific example can provide the same or different UI with the input unit whenever the user moves to a mode.SWI When the terminal moves from a first mode (with less or more access than the first mode) to a second mode (with less access than the second mode), the terminal may request authentication from the user if necessary. A second specific example of the terminal allows it to request authentication from the user whenever the user provides a UI... SWI and UI THEN This allows for user movement mode. Therefore, regardless of the terminal's architecture, the user does not need to temporarily turn off and then back on the image unit; they only need to provide the UI to the mode movement input unit. SWI You can easily switch modes.

[0467] As described above, when a user moves from a first mode with fewer access permissions to a second mode with more access permissions, the terminal can request the user to provide a UI. THEN The authentication can protect the terminal's main system against the "products" obtained by the user running a job in the first mode. Furthermore, the terminal can also request UI authentication when the user moves from a second mode with wider access permissions to a first mode with fewer permissions. THEN If the user authentication process has been successful and the terminal is in a specific mode driving state, the terminal can allow the user to move from the first mode to the second mode without performing the authentication process. Alternatively, the user may have provided the terminal with a first UI in order to move the terminal from a closed state to an open state. THEN In this case, the terminal can allow the user to only provide the terminal with a different UI than the first one. THEN Second UI THEN Only then can one move from the first mode to the second mode.

[0468] In the second embodiment of the seventh objective, the terminal may include a device specifically configured to receive a UI. SWI The input unit is used for moving user input patterns. The terminal is constructed with a specific hierarchy that defines multiple patterns, and the input unit can move patterns when it receives appropriate user input. Alternatively, the terminal [1] can move patterns in the order of multiple patterns defined in the hierarchy (for example, switching sequentially) or [2] according to a "pattern movement path" between different patterns (for example, selectively switching from one pattern to another non-adjacent pattern based on UISWI). For this purpose, the terminal can use the above-mentioned parallel hierarchy, sequential hierarchy, or mixed hierarchy.

[0469] As an example, the terminal can provide a UI whenever the user provides one. SWI The user moves from the current mode to the next mode along the hierarchy. The terminal can move modes sequentially one by one according to the order defined in a cyclic hierarchy. However, in the case of a non-cyclic hierarchy, when the user reaches the left or right end of the hierarchy, they cannot move the mode further downstream or upstream, respectively.

[0470] The terminal of the third embodiment of the seventh objective includes a device configured to receive a UI. SWI The user-input mode movement input unit can display specific information about the hierarchy in the image (or notification) unit. Examples of such specific information include the composition or configuration of the hierarchy, the mode movement path defined by the hierarchy using selective switching, etc. The terminal can display [1] the current mode currently driven by the user, [2] the new mode the terminal wants to move to, [3] the hardware or software elements that can be driven in the current (or new) mode, or [4] the jobs that the user can run in the current (or new) mode, etc., using names, icons, symbols, or text. Therefore, the user can confirm the mode movement when they provide an incorrect UI. SWI Corrective actions can be taken at that time.

[0471] The terminal can display the specific information related to each mode on the imaging unit or on a specific part of the unit. Alternatively, the terminal includes a notification unit independent of the imaging unit, which can display the specific information to help the user easily confirm the current mode or a new mode. As described above, the notification unit can provide the user with visual, auditory, or tactile notification signals.

[0472] The notification unit can be installed in various parts of the terminal. For example, the terminal can install the notification unit around or near the main input unit or mode-shifting input unit so that the user can easily confirm the current mode or the new mode to be switched to. In another specific example, the notification unit can be installed away from the main input unit or mode-shifting input unit, but the user can easily confirm the location of the notification signal. When the notification unit generates an audible or tactile notification signal, and the user can easily hear or feel the signal, the exact location of the notification unit may not be very important.

[0473] In the case of the fourth embodiment of the seventh objective, the terminal allows the user to move modes only after a specific mode has been started. As an example, when the user drives the terminal in locked mode, the user can move to different locked modes, intermediate modes, or unlocked modes according to the type of modes defined by the hierarchy and the arrangement of the modes. When the user drives the terminal in unlocked mode, [1] the user can move to a different unlocked mode that is granted wider access rights, or [2] the terminal moves to an intermediate mode or locked mode in the case of cyclic hierarchical driving, or [3] the terminal does not move modes in the case of non-cyclic hierarchical driving.

[0474] 2-8. Multiple Applicable Examples

[0475] The eighth exemplary aspect, or eighth objective, of this specification is to provide a data processing terminal that not only possesses various features related to mobile mode but is also capable of being driven according to various job execution sequences or arrangements. Typically, the various terminals described in this specification are manufactured in forms that are portable to users, such as existing smartphones, mobile phones, and tablets.

[0476] In the first example of the eighth objective, the data processing terminal can be manufactured according to various aspects, embodiments, specific examples, etc. disclosed in this specification.

[0477] In the second example of the eighth objective, the hardware or software elements of existing data processing devices are modified according to various aspects, embodiments, and specific examples of the data processing terminal described in this specification to transform the existing devices into the terminal of this specification. Therefore, the terminal of this specification can be manufactured by modifying various existing data processing devices or data management devices, such as [1] existing desktop data processors, [2] existing devices including the processor mentioned above [1], [3] existing portable data processors, [4] existing devices including the processor mentioned above [3], and [5] existing devices capable of performing various data processing operations such as data storage operations, data editing or rearrangement operations, data storage operations, or data erasure or purification operations. Therefore, various data processing terminals of this specification can be manufactured to have the same or similar [1] shape, [2] size, or [3] design as the various existing devices mentioned in this paragraph.

[0478] In the third example of the eighth objective, the various features regarding mode mobility described in this specification are applicable to existing computers installed in [1] desktop computers, [2] laptops, [3] mobile pads, or [4] other electronic devices such as automobiles and robots, and capable of running the various data processing tasks described above. Therefore, the various data processing terminals of this specification can be manufactured to have the same or similar shape, size, or form as the existing computers described above.

[0479] In the fourth example of the eighth objective, the various characteristics of mode mobility described in this specification are applicable to a variety of existing wireless communication devices. Therefore, the data processing terminal of this specification is applicable to existing wireless communication devices such as [1] smartphones, [2] mobile phones, [3] mobile pads, [4] personal digital assistants, [5] networking devices, [6] other wireless communication devices, or [7] other data processing devices. As a result, the various data processing terminals of this specification can be manufactured to have the same or similar shape, size, or form as existing wireless communication devices.

[0480] In the fifth example of the eighth objective, the various data processing terminals of this specification may have various existing characteristics related to the Internet of Things (IoT), big data, or artificial intelligence. In the first specific example related thereto, the data processing terminal may include one or more hardware or software elements capable of connecting to an existing electronic device that can connect to or is connected to the IoT. Thus, the terminal may also operate the IoT or operate the electronic device. Alternatively, the terminal may operate the electronic device by performing a mode-shifting operation after connecting to an electronic device belonging to the IoT. Conversely, an electronic device belonging to the IoT may be connected to the terminal, and the terminal may be moved to a new mode when [1] the electronic device starts or ends a specific operation or [2] the electronic device senses a specific event (for example, a fire, an emergency, other events, etc.). The terminal may also utilize the characteristics of the IoT related to various applicable cases currently applicable to existing IoT.

[0481] In a related second specific example, the data processing terminal may include hardware or software elements capable of connecting to a big data storage unit and storing data to or retrieving data from the storage unit. Alternatively, the terminal may include existing algorithms or existing computer code capable of analyzing big data and using big data in conjunction with various tasks on the terminal. As an example, the terminal may perform pattern shifts based on specific results obtained through big data analysis, or the terminal may operate on data stored in the big data storage unit according to the pattern shifts.

[0482] In a related third specific example, the data processing terminal may include one or more hardware or software elements capable of installing existing intelligent agents such as artificial intelligence, or capable of collaborating with said intelligent agents, to analyze the terminal's intended use, usage methods, user preferences, user habits, or the agent's environment, and based on this, assist the user or the terminal. Therefore, the intelligent agent can provide the terminal with reasoning abilities, knowledge, planning capabilities, or natural language processing capabilities, similar to what existing artificial intelligence performs.

[0483] As an example, a terminal can utilize existing intelligent agents for various purposes, such as [1] controlling the hardware or software elements of the terminal, [2] self-diagnosing the main system or locking system, [3] repairing the system when defects are found, or [4] diagnosing the physical or operational isolation between the locking system and the main system. Furthermore, the terminal can utilize existing intelligent agents to assist the user in various ways, such as [1] recording and analyzing various tasks performed by the user, [2] recording and analyzing various functions executed by the user, and [3] recording and analyzing the sequence of various modes driven by the user on the terminal. Based on this, the existing intelligent agent can suggest to the user which task to run, which function to perform, whether the user should remain in the current mode, or which new mode to move to.

[0484] The terminal can operate mode-shifting operations according to the guidance of the intelligent agent. As an example, the intelligent agent can move the terminal (or the terminal) from the current mode to a new mode according to user actions. Examples of such user actions include [1] situations where it would be advantageous to move the mode based on the output obtained by the user in the locked (or unlocked) mode, [2] situations where user statistics show that the user has a tendency to move the mode at a specific time or under a specific condition, or [3] situations where the mode should be moved according to user preferences, etc.

[0485] In other cases, the intelligent agent can move the terminal (or, change the terminal) from its current mode to a new mode based on external environment or events, such as [1] the occurrence of an emergency or a specific event, [2] the probability of an emergency or a specific event exceeding a specific threshold, [3] the approach of a specific agreed-upon time, or [4] the receipt of a specific phone call, message, or email. The terminal can utilize the characteristics of the intelligent agent in relation to various applicable scenarios currently used by the existing intelligent agent.

[0486] Furthermore, in the sixth example of the eighth objective, the user can apply the various features of the various terminals described above and below to manufacture various portable data processing terminals, and also to manufacture various non-portable data processing terminals (or devices). For example, the various features described above and below can be applied to existing desktop computers or other existing data processing devices to improve the security, integrity, and protection of personal information stored on the non-portable terminal. In other specific examples, the features described above and below regarding the data processing terminal of this specification can be applied to various transport vehicles or drones, such as cars, trains, motorcycles, bicycles, airplanes, and helicopters. Therefore, the terminal can protect various operations of the vehicle or drone, while preventing unauthorized users from using the vehicle or drone for improper purposes.

[0487] 2-9. Multiple users

[0488] The ninth exemplary aspect, or ninth objective, of the data processing terminal and related methods described in this specification is to define multiple modes at a specific level, assign specific access permissions to each mode, and apply the level and modes to the terminal so that one or more users can drive a terminal in multiple modes. To this end, the terminal includes multiple systems that can be driven by the modes defined at the level. Therefore, the terminal can provide one or more users with the flexibility to use more than two different systems in more than two different modes.

[0489] In the first embodiment of the ninth objective, multiple authenticated users use a single terminal. Therefore, the terminal can enable multiple users to drive the terminal according to one or more hierarchical levels. The terminal can define the same one or more modes for all users [1], [2] define different modes for different users, or [3] define multiple modes in a combination of [1] and [2]. Thus, the terminal can provide each user with the same or different number of lock (or unlock) modes or grant the same, similar, or different access permissions to each user driving the terminal in each mode.

[0490] As an example, the terminal defines a locking mode MD LK and three unlock modes MD UL1 MD UL2 and MD UL3 Hierarchical drive, the first user in a locked mode MD LK With an unlock mode MD UL1 The driver terminal, while the second user can operate in the same locking mode MD. LK With two different unlock modes MD UL2 and MD UL3Driving the terminal. As another example, the terminal includes more than one locking system and more than one master system. Each user can drive the same master (or locking) system or different master (or locking) systems in various unlock (or lock) modes. In yet another example, the terminal can grant multiple access permissions to multiple authenticated users. Thus, the terminal can grant the first user access to move to other modes without running user authentication operations, and conversely, it can restrict the 103rd user to access only their assigned first and second modes, but not the modes of other users.

[0491] Therefore, each user can drive a terminal with different access permissions, resulting in: [1] each user can access the same mode defined by the tier with different mode movement permissions, or [2] each user can access different modes defined by the tier. Thus, the first user can move to any mode defined in the first tier, but cannot move to any mode in the second tier used by the second user. Thus, each user can have different access permissions to the hardware or software elements of the main system that can drive the terminal. That is, each user can [1] drive the same or different locking systems in one or more locking modes, or [2] drive the same or different main systems in one or more unlocking modes, or [3] drive the same or different hardware or software elements in more than one mode. Thus, the number of modes defined in a particular tier does not necessarily equal the number of certified users who can drive the same terminal.

[0492] In the second embodiment of the ninth objective, the terminal is driven by only one user, who can drive the terminal in multiple modes defined within a hierarchy. Therefore, the user can drive the terminal not only in locked and unlocked modes, but also in any number of intermediate modes if necessary. As an example, the hierarchy defines a locked mode MD. LK With three identical, similar or different unlock modes MD UL1 MD UL2 and MD UL3 In this case, the user can put MD UL1 For general use, MD UL2 Used for family relationships purposes, MD UL3 For personal use only.

[0493] In cases where a specific layer defines multiple lock (or unlock) modes, the terminal can also grant the same, similar, or different access permissions to each lock (or unlock) mode according to the user's requirements or external conditions. Examples of such external conditions include [1] a situation where driving a specific hardware or software element is restricted in the first mode, but driving the element is allowed in the second mode; [2] a situation where using a portion or specific option of a specific hardware or software element is restricted in the first mode, but such use is allowed in the second mode; or [3] a situation where access to data stored in a memory unit is restricted in the first mode, but such access is allowed in the second mode, etc. In this case, the terminal can send a request to the MD... UL3 Give more than MD UL1 and MD UL2 Wider access permissions. Or, the user biasedly uses MD UL1 Used for work purposes, on the contrary, in MD UL3 With only minimal functionality (i.e., a Word processor, Photoshop, or image gallery), the terminal can process MD files. UL1 Give more than MD UL3 Wider access permissions.

[0494] The terminal in the second embodiment may include a locking system and a main system, driving the locking system in locked mode and the main system in unlocked mode. Alternatively, the terminal may include only one system driven by the locking system in locked mode and by the main system in unlocked mode. Alternatively, the terminal may include multiple systems, and the user may [1] drive the locking system in locked mode and drive the main system in unlocked mode, or [2] in MD LK1 Drive the first locking system and in MD LK2 Then drive the second locking system, in MD UL1 and MD UL2 It can also drive the main system. That is, the exact number of modes defined at a specific level does not need to be the same as the total number of systems included in the terminal (i.e., locking system, main system, etc.).

[0495] The terminal enables users to drive the same hardware or software elements in two or more modes, but specific restrictions can be imposed on each mode. Examples of such restrictions include [1] allowing access to specific data sectors of a memory cell in the second mode but prohibiting access in the first mode, or [2] allowing the use of specific options when driving software elements in the second mode but prohibiting access in the first mode.

[0496] The terminal may include a locking system and a master system, or may include multiple locking systems and multiple master systems, in the latter case the user can drive different master (or locking) systems in different unlock (or lock) modes. Thus a user can use multiple modes, such as driving the locking system in a lock mode and driving the master system in one or more unlock modes, etc. Here, the terminal may allow the user to drive specific hardware or software elements or [2] drive specific parts of said elements or [3] use specific options associated with said elements with different access permissions in each mode.

[0497] In the case of the third embodiment of the ninth objective, the various terminals described in this specification can be used in conjunction with existing devices for operation during the driving process, and can be separated from the devices for operation after driving. In particular, users can operate the existing devices by combining their own terminals with the devices and then operating the terminals. That is, users [1] can physically combine their own terminals with the devices and use the terminals as a portable console to operate various tasks of the existing devices, or [2] can use the terminals as a portable remote controller capable of operating various tasks of the existing devices even without physically combining the terminals with the existing devices. Typically, the terminals can communicate with the existing devices via wired or wireless communication.

[0498] Therefore, in the first specific example of the third embodiment, the various characteristics of the data processing terminal of this specification are applicable to existing [1] portable or mobile data processing devices, [2] non-portable data processing devices, or [3] non-mobile data processing devices, etc. The aforementioned existing data processing devices may be devices included in existing vehicles (for example, cars, trains, motorcycles, bicycles, airplanes, helicopters, etc.), existing drones, etc. Therefore, when the terminal drives the vehicle or drone, security can be enhanced, and unauthorized users can be prevented from using the vehicle, drone, etc. for improper purposes.

[0499] 2-10. User convenience

[0500] The tenth exemplary aspect, namely the tenth objective, of the data processing terminal and related methods described in this specification is to provide a terminal that offers enhanced security, higher integrity, and strengthened protection of personal information to users.

[0501] In the first embodiment of the tenth objective, the terminal provides the user with multiple hierarchical levels defining multiple modes, each of which can be assigned the same, similar, or different access permissions. The terminal can erase all or part of the "product" obtained by performing multiple locking (or unlocking) operations in a locked (or unlocked) mode at multiple erase time points. The terminal can perform an erase (or partial erase) operation when moving from a mode with fewer access permissions to a mode with wider (similar or non-overlapping) access permissions.

[0502] Therefore, regardless of whether the previous mode was granted fewer (or more) access permissions than the new mode, the terminal driven by the new mode is protected from the potential threat of malicious programs downloaded or infiltrated from the "products" obtained in the previous mode. As described above, users can completely or partially isolate each mode from the rest of the hierarchy without worrying about potential contamination or damage from malicious programs, and can easily drive the terminal in each mode defined in the hierarchy. As a result, users can obtain benefits such as high security, high integrity, and enhanced personal information.

[0503] In the second embodiment of the tenth objective, the terminal allows users to easily construct a hierarchy defining one or more lock (or intermediate) modes and one or more unlock modes. Furthermore, the terminal can assign specific access permissions to each mode according to the user's needs, thereby allowing some users to drive only a portion, rather than all, of the accessible hardware or software elements of the main system, while allowing other users to drive (almost) all accessible hardware and software elements of the main system.

[0504] As described above, multiple users can [1] share a terminal, or [2] connect multiple terminals with their own environments in a network to share the hardware or software elements of the network. Furthermore, the terminal can erase all or part of the "products". Therefore, each user does not need to worry about their own activity content stored in their own mode being accidentally leaked to other users, nor do they need to worry about the network being contaminated or damaged by activities performed in their own mode, and can effectively use the terminal.

[0505] In the case of the third embodiment of the tenth objective, the terminal can perform an erase (or partial erase) operation and allow the user to easily move between multiple modes defined by a specific hierarchy or from one mode to another. When a user or terminal constructs a hierarchy defining multiple modes, a user who starts driving the terminal in a specific locked (or intermediate) mode or a user who wants to move from a specific locked (or intermediate) mode to another mode [1] can construct the hierarchy as an unlocked mode that cannot be moved to the hierarchy or [2] construct the hierarchy as a specific hardware or software element that cannot drive the main system. For this purpose, the terminal can construct the following including Figure 2C and Figure 2D The example of a "skip mode" is a "path-specific hierarchy".

[0506] The terminal can be easily used as an additional security measure to prevent critical main systems from being contaminated, damaged, or destroyed by intruders. This is because the terminal can prevent users (i.e., intruders) from driving certain hardware or software elements of the main system if they are not operating in the predetermined mode.

[0507] As described above, the various terminals described in this specification can prevent malicious viruses from infiltrating the terminal during a user's or unauthenticated user's operation of a locking process, and from causing contamination, damage, or malfunction to the main system when the user moves from locked mode to unlocked mode. To this end, the terminal provides a security device that can perform an erasure (or partial erasure) operation on the "products" obtained from the locking (or intermediate) operation in the locked (or intermediate) mode before moving from the locked mode to the unlocked (or other) mode, which grants wider access permissions. As a result, the various terminals described in this specification can effectively prevent intrusion by suspicious websites accessed by the user due to mistaken access during the locked (or intermediate) mode, or by accidentally downloaded contaminated files.

[0508] As described above, the various terminals described in this specification can effectively save the user's personal information stored in the main memory unit and details of the user's activities in locked, intermediate, or unlocked modes. In particular, by carefully constructing the aforementioned hierarchy, the terminal can prevent unauthorized users from reclaiming data in the main memory unit or writing corrupted data to the main memory unit. Furthermore, the terminal's user can prevent unauthorized users from obtaining details of the user's activities performed in weaker protection modes such as locked or intermediate modes.

[0509] In the fourth embodiment of the tenth objective, the terminal enables the use of various vehicles or drones in an environment with enhanced security, higher integrity, and greater protection of personal information. For example, when a user uses a shared vehicle, the user can connect to the vehicle by inserting their terminal into the vehicle's port or by wirelessly synchronizing their terminal with the vehicle, and drive the vehicle as needed. Here, the terminal can protect the main system from malicious viruses or code that have already infiltrated the vehicle due to other users, and by running the erasure (or partial erasure) operation, it can prevent others from accessing the user's driving records or data.

[0510] The advantages also apply to users being able to run tasks via wirelessly connected shared electronic devices. These advantages further apply to situations where users share their terminals with others, such as public networks or third-party networks, while running tasks via wireless connectivity. Here, by driving the terminal in locked (or intermediate) mode, partially or completely isolating the main system of their terminal, and preventing third-party access to the main system or driving system of their terminal, users can ensure security, integrity, and protection of personal information.

[0511] 2-11. Improvements and enhancements to existing data processing equipment

[0512] The various data processing terminals, units, hardware elements, and software elements described in this specification can also be driven in different modes disclosed in various existing documents. Examples of such existing documents include U.S. Patent No. 8,782,775, owned by Apple Inc., which may be particularly referenced. Figure 3 Figure 5, rows 27-39 of column 7, and rows 15 to 17 of column 9, etc. Other examples of the aforementioned prior art include U.S. Patent Application No. 2012 / 0009896, belonging to Microsoft Corporation, which is of particular interest. Figure 3 A, Figure 3 B Figure 4 A and Figure 4 B. Paragraphs 70-72 and 75-76, etc. Another example of the aforementioned prior art is U.S. Patent No. 8,943,580, owned by Apple Inc., which is of particular interest. Figure 1B (B) and Figure 5C Column 7, rows 27-39; column 8, rows 15 to Column 9, rows 17, etc.

[0513] However, the various terminals described in this specification can grant access permissions to the various operating modes disclosed in the existing documents that are different from the access permissions disclosed in the existing documents. Furthermore, the various terminals described in this specification can include the modes disclosed in the existing documents in a hierarchy different from the hierarchy disclosed in the documents. Moreover, the various terminals described in this specification can use a combination of the modes described in this specification and the modes disclosed in the documents.

[0514] 3. Additional Purpose

[0515] This specification relates to various data processing terminals driven by different modes in multiple modes. The terminals described herein can erase all or part of the "products" obtained, stored, or remaining in the locked (or intermediate) system driven by the locked (or intermediate) mode, resulting from running various locked (or intermediate) operations. Therefore, even if a user runs locked (or intermediate) operations through the locked (or intermediate) system in locked (or intermediate) mode and visits a website with low credibility, accesses suspicious links, or downloads files or content infected with malicious viruses, the terminal can erase all (or specific) portions of the "products" at various erasure points. Therefore, even if the terminal moves to unlocked mode, malicious viruses cannot adversely affect the terminal's main system because they have already been erased.

[0516] In addition to the aforementioned erasure or partial erasure, various terminals described in this specification can completely or partially, physically or operationally, isolate the main (or locked) system from the locked (or main) system. As a result, even if a malicious virus successfully infiltrates the locked system, it cannot infiltrate the main system due to the aforementioned physical or operational isolation.

[0517] Therefore, the terminal described in this manual can protect itself from suspicious websites, potentially harmful downloaded content, viruses contained in such content, links, etc. At the same time, the terminal described in this manual allows users to seamlessly switch from one mode to another without worrying about contamination or damage to the terminal caused by activity in restricted modes such as locked mode.

[0518] Therefore, another exemplary data processing terminal of this specification may include an image unit that operates in both unlocked and locked modes, and a main system that drives the image unit while operating in unlocked mode. The terminal also includes a lock viewer capable of displaying data on the image unit in locked mode.

[0519] In the first embodiment of the stated objective, a terminal driven in locked mode can erase at least a portion of the product before (about to) move to unlock mode, simultaneously with, immediately after, or within a predetermined time after the move. As a result, the terminal can fully or partially prevent the portion of the "product" from affecting the main system. In the second embodiment of the stated objective, the terminal includes a lock viewer that can be physically or partially physically or operationally isolated from the main system in locked mode. Therefore, the terminal can prevent the "product" and the lock viewer from causing adverse effects on the main system.

[0520] Another illustrative purpose of this specification is a data processing terminal that operates in both unlocked and locked modes and may include multiple hardware or software elements. The terminal may include an image unit, a main system, a locking system, etc. The main system can drive the image unit in unlocked mode while simultaneously driving the elements to perform various tasks. Conversely, the locking system includes a locking viewer, which displays data on the image unit in locked mode by driving both the image unit and the locking viewer. Furthermore, the terminal operating in locked mode can erase at least a portion of the "products" remaining in the locking system before (about to) move from locked mode to unlocked mode, simultaneously with the move, immediately after the move, or within a predetermined time after the move.

[0521] The terminal of the first embodiment of the stated objective can fully or partially prevent a portion of the "prod...

Claims

1. A mobile data processing terminal operating in locked mode and unlocked mode, comprising: Image unit; A locking system in which the terminal operates in the locked mode and displays a locked screen on the image unit in the locked mode; as well as The main system, wherein the terminal operates in the unlocked mode and displays the home screen on the image unit in the unlocked mode; The locking system includes a first number of locking elements, one of which is a locking website browser application capable of performing a first function: accessing an external source containing at least one piece of content infected with a malicious virus. The main system includes a second number of key elements, one of which is a main website browser application capable of performing the first function of accessing the external source. The second quantity is greater than the first quantity. Specifically, when the terminal receives first user input from the user while the image unit is off but the terminal is powered on, the terminal turns on the image unit, switches to the locked mode, displays the locked screen on the image unit, and displays the first graphical user interface of the locked website browser application on the locked screen. Specifically, when the terminal receives second user input from the user provided to the first graphical user interface, the terminal allows the user to access the external source using the locked website browser application and download a first product including infected content, while preventing the infected content from accessing the main system in the locked mode. Specifically, after the first product is generated, when the terminal receives input from the user in the locked mode, it moves to the unlocked mode at a mode movement time point related to either a first time point of receiving the third user input or a second time point of moving from the locked mode to the unlocked mode, while erasing a specific portion of the first product. Therefore, the terminal can prevent the infected content from infecting the main website browser application of the main system in the locked mode, even when the locked website browser application is infected by the malicious virus in the locked mode. The terminal performs one of the initialization and formatting of the locking system in at least one of several situations, such that the terminal removes the locking website browser application from the locking system and then reloads the locking website browser application into the locking system. The scenarios described include a first scenario and a second scenario. In the first scenario, a predetermined time has elapsed since either the previous initialization or the previous formatting. In the second scenario, the terminal discovers the virus-infected content in one of the first artifacts, the locked website browser application, and the locked system. The specific portion is not the entirety of the first product, such that the terminal erases the specific portion but not the remainder of the first product.

2. The terminal according to claim 1, wherein the mode movement time point is one of a third time point after receiving the second user input but before moving to the unlock mode, a fourth time point that occurs simultaneously with the movement, and a fifth time point after the movement.

3. The terminal according to claim 1, wherein the locking system includes the locking website browser application and the second locking element, and The terminal displays the first graphical user interface of the locked website browser application and the second graphical user interface of the second locked element on the locked screen.

4. The terminal according to claim 1, wherein the first product is one of data, file, folder, and content.

5. The terminal according to claim 1, wherein when the system detects the infected content in the locking system, the terminal removes the locked website browser application from the locking system.

6. The terminal according to claim 5, wherein, After the terminal removes the locked website browser application from the locking system, the terminal allows the user to reload the locked website browser application onto the locking system.

7. The terminal according to claim 1, wherein the first product comprises at least one of the following: The first piece of information is related to the address of the website accessed by the browser application that is locked on the website; The second piece of information is related to the website mentioned; and The third piece of information was downloaded from the website in question.

8. The terminal according to claim 1, further comprising a locked memory unit, wherein the locked memory unit includes at least one of a data buffer, a cache, a clipboard, a recycle bin, a non-volatile memory element, and a volatile memory element.

9. The terminal of claim 8, wherein the terminal allows the user to access the locked memory unit in the locked mode.

10. The terminal of claim 8, wherein the terminal allows the user to access the locked memory unit in the unlock mode.

11. The terminal of claim 1, wherein the terminal performs an authentication operation in response to at least a portion of the third user input, and The third user input includes information associated with at least one of the user's fingerprint, the user's iris, the user's retina, the user's voice, and the user's face.

12. The terminal of claim 11, wherein when the user completes the authentication process, the terminal moves to the unlock mode.

13. The terminal of claim 11, wherein when the user fails the authentication process, the terminal remains in the locked mode instead of moving to the unlocked mode.

14. A mobile data processing terminal operating in locked mode and unlocked mode, comprising: Image unit; A locking system in which the terminal operates in the locked mode and displays a locked screen on the image unit in the locked mode; as well as The main system, wherein the terminal operates in the unlocked mode and displays the home screen on the image unit in the unlocked mode; The locking system includes a browser application capable of performing a first function: locking a website to access an external source containing at least one piece of content infected with a malicious virus. The main system includes a main website browser application capable of performing the first function of accessing the external source, and also includes at least one additional application that is not the main website browser application and is not included in the locking system. The terminal displays a first graphical user interface of the locked website browser application on the locked screen in the locked mode. Specifically, when the terminal receives first user input from the user provided to the first graphical user interface, the terminal allows the user to access the external source using the locked website browser application and download a first product including infected content, while preventing the infected content from accessing the main system in the locked mode. Specifically, after the first product is generated, when a second user input is received from the user in the locked mode, the terminal performs a movement from the locked mode to the unlocked mode and erases a specific portion of the first product from the locking system. Therefore, the terminal can prevent the infected content from infecting the main website browser application of the main system in the locked mode, even when the locked website browser application is infected by the malicious virus in the locked mode. The terminal performs one of the initialization and formatting of the locking system in at least one of several situations, such that the terminal removes the locking website browser application from the locking system and then reloads the locking website browser application into the locking system. The scenarios described include a first scenario and a second scenario. In the first scenario, a predetermined time has elapsed since either the previous initialization or the previous formatting. In the second scenario, the terminal discovers the virus-infected content in one of the first artifacts, the locked website browser application, and the locked system. The specific portion is not the entirety of the first product, such that the terminal erases the specific portion but not the remainder of the first product.

15. The terminal of claim 14, wherein the terminal prevents the locked website browser application from accessing the main system in the locked mode.

16. The terminal of claim 14, wherein the terminal prevents the locking system from accessing the main system in the locking mode.

17. The terminal of claim 14, wherein the terminal performs one of the following: The erasure and the subsequent movement; The erasure and the simultaneous movement; and The movement and the subsequent erasure.

18. The terminal according to claim 14, wherein the main website browser application is capable of performing not only the first function but also the second function, and The locked website browser application can perform the first function, but not the second function.

19. The terminal according to claim 14, wherein the main website browser application is not only capable of performing the first function, but also capable of performing a second number of additional functions. The locked website browser application is not only capable of performing the first function, but also of performing a third number of additional functions, and The second quantity is not less than the third quantity.

20. The terminal of claim 14, wherein when the system detects the infected content in the locking system, the terminal removes the locked website browser application from the locking system.

21. The terminal according to claim 20, wherein, After the terminal removes the locked website browser application from the locking system, the terminal allows the user to reload the locked website browser application onto the locking system.

22. The terminal according to claim 14, wherein the first product is one of data, file, folder, and content.

23. The terminal of claim 14, wherein the first product comprises at least one of the following: The first piece of information is related to the address of the website accessed by the browser application that is locked on the website; The second piece of information is related to the website in question; The third piece of information was downloaded from the website in question.

24. The terminal of claim 14, further comprising a locked memory unit, wherein the locked memory unit includes at least one of a data buffer, a cache, a clipboard, a recycle bin, a non-volatile memory element, and a volatile memory element, and The locking system stores at least a portion of the remaining portion of the first product in the locking memory unit.

25. The terminal of claim 24, wherein the terminal allows the user to access the locked memory unit in the locked mode.

26. The terminal of claim 24, wherein the terminal allows the user to access the locked memory unit in the unlock mode.

27. The terminal of claim 14, wherein the terminal performs an authentication operation in response to at least a portion of the second user input, and The second user input includes information related to at least one of the user's fingerprint, the user's iris, the user's retina, the user's voice, and the user's face.

28. The terminal of claim 27, wherein the terminal moves to the unlock mode when the user completes the authentication process.

29. The terminal of claim 27, wherein when the user fails the authentication process, the terminal remains in the locked mode instead of moving to the unlocked mode.

30. A mobile data processing terminal operating in locked mode and unlocked mode, comprising: Image unit; A locking system in which the terminal operates in the locked mode and displays a locked screen on the image unit in the locked mode; as well as The main system, wherein the terminal operates in the unlocked mode and displays the home screen on the image unit in the unlocked mode; The locking system includes a locking element capable of performing a first function: accessing an external source containing at least one piece of content infected with a malicious virus. The main system includes key elements capable of performing the first function of accessing the external source. Wherein, when the locking element is one of the following: locking a web browser application, locking an IoT application, locking an ad viewer application, locking a messaging application, and locking an email application, the main element is one of the following: the main web browser application, the main IoT application, the main ad viewer application, the main messaging application, and the main email application. The terminal displays a first graphical user interface of the locking elements on the locking screen in the locking mode; Specifically, when the terminal receives first user input from the user, which is provided to the first graphical user interface, the terminal allows the user to access the external source using the locking element and download a first product including infected content, while preventing the infected content from accessing the main system in the locked mode. Wherein, after the first product is generated, when a second user input is received from the user in the locked mode, the terminal performs a movement from the locked mode to the unlocked mode, and erases a specific portion of the first product from the locking system, and Therefore, the terminal can prevent the infected content from infecting the main elements of the host system in the locked mode, even when the locked elements are infected by the malicious virus in the locked mode. The terminal performs one of the initialization and formatting of the locking system in at least one of several scenarios, such that the terminal removes the locking element from the locking system and then reloads the locking element back into the locking system. The scenarios described include a first scenario and a second scenario. In the first scenario, a predetermined time has elapsed since either the previous initialization or the previous formatting. In the second scenario, the terminal discovers the virus-infected content in one of the first product, the locking element, and the locking system. The specific portion is not the entirety of the first product, such that the terminal erases the specific portion but not the remainder of the first product.

31. The terminal of claim 30, wherein the terminal prevents the locking element from accessing the main system in the locking mode.

32. The terminal of claim 30, wherein the terminal prevents the locking system from accessing the main system in the locking mode.

33. The terminal of claim 30, wherein the terminal performs one of the following: The erasure and the subsequent movement; The erasure and the simultaneous movement; and The movement and the subsequent erasure.

34. The terminal according to claim 30, wherein the main element is capable of performing not only the first function but also the second function, and The locking element is capable of performing the first function, but not the second function.

35. The terminal according to claim 30, wherein the main element is not only capable of performing the first function, but also capable of performing a second number of additional functions. The locking element is capable not only of performing the first function, but also of performing a third number of additional functions, and The second quantity is not less than the third quantity.

36. The terminal of claim 30, wherein when the system detects the infected content in the locking system, the terminal removes the locking element from the locking system.

37. The terminal according to claim 36, wherein, After the terminal removes the locking element from the locking system, the terminal allows the user to reload the locking element back onto the locking system.

38. The terminal according to claim 30, wherein the first product is one of data, file, folder, and content.

39. The terminal of claim 30, wherein the first product comprises at least one of the following: The first piece of information is related to the address of the external source accessed by the locked element; The second piece of information is downloaded from the external source.

40. The terminal of claim 30, further comprising a locked memory unit, wherein the locked memory unit includes at least one of a data buffer, a cache, a clipboard, a recycle bin, a non-volatile memory element, and a volatile memory element, and The locking system stores at least a portion of the remaining portion of the first product in the locking memory unit.

41. The terminal of claim 40, wherein the terminal allows the user to access the locked memory unit in the locked mode.

42. The terminal of claim 40, wherein the terminal allows the user to access the locked memory unit in the unlock mode.

43. The terminal of claim 30, wherein the terminal performs an authentication operation in response to at least a portion of the second user input, and The second user input includes information related to at least one of the user's fingerprint, the user's iris, the user's retina, the user's voice, and the user's face.

44. The terminal of claim 43, wherein the terminal switches to the unlock mode when the user completes the authentication process.

45. The terminal of claim 43, wherein when the user fails the authentication process, the terminal remains in the locked mode instead of moving to the unlocked mode.

Citation Information

Patent Citations

  • Above-lock camera access

    US20120009896A1

  • Computer mouse or keyboard input device utilizing capacitive sensors

    US5463388A

  • Touch screen device, method, and graphical user interface for determining commands by applying heuristics

    US7479949B2

  • User input device and method using fingerprint recognition sensor

    US8279182B2

  • Method and apparatus for detecting conditions of a peripheral device including motion, and determining / predicting temperature(S) wherein at least one temperature is weighted based on detected conditions

    US8392340B2