Data protection method and electronic device

By generating lock screen authentication parameters and encryption master keys on the terminal electronic device, the problem of user data security depending on account security is solved, achieving high-security and real-time data protection, and enhancing the self-proof of innocence on the cloud side.

CN116405202BActive Publication Date: 2026-04-10HONOR DEVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HONOR DEVICE CO LTD
Filing Date
2021-11-19
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

In existing technologies, the security of user data depends on account security. Cloud servers cannot prove their innocence, leading to data leakage when accounts are attacked, thus failing to meet high security requirements.

Method used

By generating a lock screen code as an authentication parameter on the terminal electronic device, a master key is generated after identity authentication. The master key is encrypted using the lock screen code and transmitted through the cloud side to ensure that the cloud side cannot decrypt the master key. Combined with the user's unique information, the master key is encrypted to improve security.

Benefits of technology

It achieves real-time and highly secure user data protection, avoids the risk of cloud-side decryption of master keys, and enhances data security and user convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116405202B_ABST
    Figure CN116405202B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a data protection method and an electronic device. In the method, a first electronic device has logged in a first account and enabled a password safe synchronization function corresponding to the first account, and synchronizes first service information to the password safe. When a user logs in the first account on a second electronic device, the first electronic device generates a verification code and displays the verification code after receiving an instruction allowing the second electronic device to log in. After the user inputs the verification code on the second electronic device, the second electronic device displays a lock screen password input interface, and enables the password safe synchronization function corresponding to the first account after the user inputs a lock screen password. When the user uses the first service on the second electronic device, the second electronic device can obtain the first service information from the password safe and automatically fill in the first service information. In this way, electronic devices logging in the same account can share service information in the corresponding password safe, and the user does not need to remember extra information.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present application is a divisional application, the original application is named data protection method and electronic device, the original application has an application number of 202111408374.3, an original application date of November 19, 2021, and the entire contents of the original application are incorporated herein by reference. TECHNICAL FIELD

[0002] Embodiments of the present application relate to the field of terminal devices, and in particular to a data protection method and an electronic device. BACKGROUND

[0003] Currently, a terminal device can save user data in the cloud to allow the user to upload and download the data in real time. The user data usually corresponds to a specific user account. However, the security of the user data completely depends on the security of the account. As long as the device can pass the account verification, the data can be obtained from the cloud side. If either the account or the server on the cloud side is attacked, the user data will be leaked. Moreover, the cloud side server also has the possibility of decrypting the user data, and the cloud side cannot prove its innocence. Therefore, the known solution has low security and cannot provide support for user data protection with higher security requirements. SUMMARY

[0004] The present application provides a data protection method and an electronic device. The electronic device generates an authentication parameter based on a lock screen code of a peer electronic device, transmits the authentication parameter to the peer electronic device through the cloud, and returns an encapsulated master key to the electronic device after the peer electronic device performs identity authentication on the second electronic device based on the authentication parameter. The electronic device decrypts the encapsulated master key to obtain the master key, and then adds a ring based on the master key and the local lock screen code. On the one hand, the secret used to confirm the identity of the electronic device, such as a verification code, is not stored in any device in advance, which is instant. On the other hand, the secret is not issued to the device by the cloud side. Therefore, when the encrypted master key based on the secret is transmitted through the cloud side, the cloud side cannot decrypt the master key, and the cloud side can prove its innocence. 3. The secret is friendly to user memory and does not require additional memory

[0005] In a first aspect, the embodiments of the present application provide a data protection method applied to a second electronic device, the method comprising: receiving, by the second electronic device, a verification code displayed by a first electronic device input by a user, wherein the first electronic device has logged in a first account, and the first electronic device is an in-ring device of a first trust ring corresponding to the first account; the verification code is generated by the first electronic device after receiving an instruction allowing the second electronic device to log in to the first account; generating an authentication parameter based on the verification code; then, transmitting the authentication parameter to the first electronic device through a first server, so that the first electronic device performs identity authentication on the second electronic device based on the authentication parameter; in the case that the identity authentication of the second electronic device is passed, obtaining a master key from the first electronic device; receiving a second lock screen code of the second electronic device input by the user; after the second lock screen code is verified, encrypting the master key based on the second lock screen code to generate a second master key ciphertext of the second electronic device, and generating a second authentication parameter based on the second lock screen code; sending an add-ring request to the first server, so that the first server adds the second master key ciphertext and the second authentication parameter to trust ring data of the first trust ring.

[0006] The data protection method, the add-ring device generates an authentication parameter according to the verification code randomly generated by the registered device, transmits the authentication parameter to the device A (i.e. the first electronic device) through the cloud side, the device A performs identity authentication on the device B based on the authentication parameter, and after the identity authentication of the device B and the second electronic device is passed, the device A generates a negotiation parameter, double-encrypts the master key MK based on the negotiation parameter, and transmits the double-encrypted MK and the negotiation parameter to the device B through the cloud side. The device B decrypts the double-encrypted MK based on the negotiation parameter to obtain the MK. In this add-ring process, a certain user secret (non-lock screen code) is verified between the device A and the device B, so as to confirm the identity of the account and the device B. On the one hand, the secret used to confirm the identity of the device B is not stored in any device in advance, and has instantaneity. On the second hand, the secret is not issued to the device by the cloud side. Therefore, when the master key encrypted based on the negotiation parameter is transmitted through the cloud side, the cloud side cannot decrypt the master key, and the cloud side can prove its innocence. 3. The secret is friendly to the user's memory, and does not need to be memorized additionally.

[0007] The lock screen code in the application can also be replaced by other user information, for example, the user information can be the user's birthday, the user's name, the birthday of the user's parents or friends, the name, and the like. The information is unique to the user, only the user knows, and the information is different for different users. The user information is easy for the user to remember, and is unknown to the cloud side. When the master key is encrypted based on the user information, the cloud side cannot decrypt, so the cloud side can prove its innocence. Except for the user himself, it is difficult for others to know which user information the user uses to encrypt the master key, which greatly increases the difficulty of cracking the master key ciphertext, improves the security of the master key, and thus can improve the security of the user data protected by the derived key using the master key. At the same time, when the second device and the second and subsequent devices in the trust ring are registered, the identity of the registered device can be verified based on the user information, without the need to interact with the registered device, providing convenience for the user.

[0008] According to the first aspect, before the master key is encrypted based on the second lock screen code to generate the second master key ciphertext of the second electronic device, the method further includes: comparing, by the second electronic device, the second lock screen code with the locally saved lock screen code of the second electronic device; and determining that the second lock screen code passes the verification when the second lock screen code is consistent with the locally saved lock screen code of the second electronic device. By verifying the lock screen code of the device, malicious triggering of the ring adding process by others can be avoided.

[0009] According to the first aspect, or any one of the implementation manners of the first aspect, the second electronic device encrypts the master key based on the second lock screen code to generate the second master key ciphertext of the second electronic device, including: generating, by the second electronic device, a third derived key according to the second lock screen code; generating a fourth derived key according to the third derived key; and encrypting the master key according to the fourth derived key to obtain the second master key ciphertext of the second electronic device. In this way, the master key is encrypted according to the user personalized information such as the lock screen code, so that the cloud side that does not know the user personalized information cannot decrypt the master key, the user data encrypted by the derived key using the master key is protected, and the security of the user data is improved.

[0010] According to the first aspect, or any one of the implementation manners of the first aspect, the second electronic device generates the second authentication parameter based on the second lock screen code, including: generating, by the second electronic device, a third derived key according to the second lock screen code; generating a second shared value according to the third derived key; and encrypting the second shared value according to the HSM public key generated by the first server side to obtain the second authentication parameter. In this way, the authentication parameter is generated according to the user personalized information such as the lock screen code, so that the authentication parameter cannot be forged, and the security of the authentication is ensured.

[0011] According to a first aspect, or any possible implementation mode of the first aspect, the method further comprises: deriving, by the second electronic device, the first service key based on the master key, encrypting the first service data using the first service key to obtain first service data ciphertext, and sending the first service data ciphertext to the second server to enable the second server to save the first service data ciphertext. This kind of synchronization of the encrypted service data ciphertext based on the service key derived from the master key to the cloud has the advantage that the master key is cloud-agnostic, and thus the service data ciphertext synchronized to the cloud is also cloud-agnostic, which can ensure the security of the service data and enable the cloud to be self-vindicating.

[0012] According to the first aspect, or any possible implementation mode of the first aspect, the method further comprises: obtaining, by the second electronic device, second service data ciphertext from the second server, deriving the first service key based on the master key, and decrypting the second service data ciphertext using the first service key to obtain second service data. This kind of decryption of the service data ciphertext obtained from the cloud on the electronic device has the advantage that even if the service data ciphertext transmitted between the cloud and the electronic device is intercepted, the intercepted data cannot be decrypted to obtain the service data because the master key and the rule of deriving the first service key from the master key cannot be obtained by the interceptor, which can improve the security of the service data.

[0013] In a second aspect, an electronic device is provided, which can serve as a second electronic device and comprises a memory and a processor, the processor being coupled to the memory, and the memory storing program instructions which, when executed by the processor, cause the electronic device to perform the following steps:

[0014] The second electronic device receives a verification code displayed by a first electronic device input by a user, wherein the first electronic device has logged in a first account, and the first electronic device is an in-ring device of a first trust ring corresponding to the first account; the verification code is generated by the first electronic device after receiving an instruction allowing the second electronic device to log in the first account; an authentication parameter is generated based on the verification code; the authentication parameter is transparently transmitted to the first electronic device by a first server, to enable the first electronic device to perform identity authentication on the second electronic device based on the authentication parameter; in a case where the identity authentication of the second electronic device is passed, a master key from the first electronic device is obtained; a second lock screen code of the second electronic device input by the user is received; after the second lock screen code is verified, the master key is encrypted based on the second lock screen code to generate second master key ciphertext of the second electronic device, and a second authentication parameter is generated based on the second lock screen code; a ring addition request is sent to the first server, to enable the first server to add the second master key ciphertext and the second authentication parameter to trust ring data of the first trust ring.

[0015] According to a second aspect, when the program instructions are executed by the processor, the electronic device is further caused to perform the following steps: comparing the second lock screen code with the locally stored lock screen code of the second electronic device; and determining that the second lock screen code is verified when the second lock screen code is consistent with the locally stored lock screen code of the second electronic device.

[0016] According to the second aspect, or any possible implementation of the second aspect, when the program instructions are executed by the processor, the electronic device is further caused to perform the following steps: generating a third derived key according to the second lock screen code; generating a fourth derived key according to the third derived key; and encrypting the master key according to the fourth derived key to obtain the second master key ciphertext of the second electronic device.

[0017] According to the second aspect, or any possible implementation of the second aspect, when the program instructions are executed by the processor, the electronic device is further caused to perform the following steps: generating a third derived key according to the second lock screen code; generating a second shared value according to the third derived key; and encrypting the second shared value according to the first server-side generated HSM public key to obtain the second authentication parameter.

[0018] According to the second aspect, or any possible implementation of the second aspect, when the program instructions are executed by the processor, the electronic device is further caused to perform the following steps: deriving a first service key based on the master key, encrypting the first service data using the first service key to obtain first service data ciphertext; and sending the first service data ciphertext to the second server, so that the second server stores the first service data ciphertext.

[0019] According to the second aspect, or any possible implementation of the second aspect, when the program instructions are executed by the processor, the electronic device is further caused to perform the following steps: obtaining the second service data ciphertext from the second server; deriving a first service key based on the master key; and decrypting the second service data ciphertext using the first service key to obtain the second service data.

[0020] The second aspect and any possible implementation of the second aspect correspond to the first aspect and any possible implementation of the first aspect respectively. The technical effects of the second aspect and any possible implementation of the second aspect can refer to the technical effects of the first aspect and any possible implementation of the first aspect, which will not be described here.

[0021] In a third aspect, the present application provides a computer readable medium for storing a computer program, the computer program comprising instructions for executing the method in the first aspect or any possible implementation of the first aspect.

[0022] In a fourth aspect, the present application provides a computer program comprising instructions for performing the method of the first aspect or any possible implementation mode of the first aspect. BRIEF DESCRIPTION OF DRAWINGS

[0023] Figure 1 Structure schematic diagram of the electronic device 100 shown for example;

[0024] Figure 2 Software structure block diagram of the electronic device 100 of the embodiment of the present application shown for example;

[0025] Figure 3 Information interaction schematic diagram in the process of creating a trust circle shown for example;

[0026] Figure 4 Interaction schematic diagram between the device and the cloud side in the process of creating a trust circle shown for example;

[0027] Figure 5A Interface schematic diagram of entering the "My Device" application in the case of a logged-in account shown for example;

[0028] Figure 5B Interface schematic diagram of entering the "My Device" application in the case of a non-logged-in account shown for example;

[0029] Figure 6 Interface schematic diagram of entering the "Password Vault Synchronization" application from the "My Device" application in the device A shown for example;

[0030] Figure 7A Process schematic diagram of entering the "Password Vault" interface in the case that the device A has set a lock screen code shown for example;

[0031] Figure 7B Process schematic diagram of entering the "Password Vault" interface in the case that the device A has not set a lock screen code shown for example;

[0032] Figure 8 Process schematic diagram of turning on the "Password Vault Synchronization" switch in the scenario of creating a trust circle shown for example;

[0033] Figure 9 Process schematic diagram of turning on the "Synchronize to Honor Account" switch in the scenario of creating a trust circle shown for example;

[0034] Figure 10 Flow schematic diagram of creating a trust circle shown for example;

[0035] Figure 11 Schematic diagram of synchronizing the business data ciphertext of the device A to the account management server after creating a trust circle shown for example;

[0036] Figure 12 A module interaction diagram for synchronizing service data ciphertext is shown as an example;

[0037] Figure 13 An interface diagram for synchronizing service data ciphertext to an account management server is shown as an example;

[0038] Figure 14 An information interaction diagram for device B joining a trust ring is shown as an example;

[0039] Figure 15 An interaction interface diagram for device B and device A during device B joining a signal is shown as an example;

[0040] Figure 16 A flow diagram for device B joining a trust ring is shown as an example;

[0041] Figure 17 A diagram for device B synchronizing service data ciphertext from an account management server after device B joins a trust ring is shown as an example;

[0042] Figure 18 An interface diagram for synchronizing service data ciphertext from an account management server is shown as an example. DETAILED DESCRIPTION

[0043] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0044] The term “and / or” in the present application is only used to describe the association relationship of the associated objects, and means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone.

[0045] The terms “first” and “second” and the like in the specification and claims of the embodiments of the present application are used to distinguish different objects, and are not used to describe a specific order of the objects. For example, the first target object and the second target object are used to distinguish different target objects, and are not used to describe a specific order of the target objects.

[0046] In the embodiments of the present application, the word "exemplary" or "for example" is used to mean serving as an example, instance, or illustration. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the embodied words are used to present concepts in a particular, concrete form that is easier to understand.

[0047] In the description of the embodiments of the present application, the meaning of "a plurality of" is two or more unless otherwise specified. For example, a plurality of processing units means two or more processing units; a plurality of systems means two or more systems.

[0048] Figure 1 The structural schematic diagram of the electronic device 100 is shown as an example. It should be understood that, Figure 1 The electronic device 100 shown is only one example of an electronic device, and the electronic device 100 can have more or fewer components than shown in the figure, can combine two or more components, or can have a different component configuration. Figure 1 The various components shown in the figure can be implemented in hardware, software, or a combination of hardware and software including one or more signal processing and / or application specific integrated circuits.

[0049] Among them, the electronic device 100 can be a mobile phone, a tablet, etc.

[0050] The electronic device 100 can include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charge management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 can include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0051] The software system of the electronic device 100 can employ a layered architecture, an event-driven architecture, a microkernel architecture, a microservices architecture, or a cloud architecture. Embodiments of the present application take an Android system with a layered architecture as an example to illustrate the software structure of the electronic device 100.

[0052] The layered architecture of the electronic device 100 divides software into several layers, each of which has a clear role and division of labor. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into three layers, from top to bottom, the application layer, the application framework layer, and the kernel layer.

[0053] The application layer can include a series of application packages.

[0054] As shown in Figure 2 , the application packages can include sensor (which can also be referred to as desktop and wallpaper), HMS core, trust circle, password vault, and the like. By way of example, the sensor can monitor user operations such as swiping and pressing the screen, the HMS core provides a collection of electronic device-side and cloud open capabilities. The trust circle application is used to create and manage a trust circle for an account, where the management of the trust circle includes but is not limited to adding devices to the trust circle, deleting devices from the trust circle, deleting the trust circle, freezing the trust circle, updating the master key ciphertext under the trust circle, and the like. The password vault is used to manage business data synchronized by the user to the account management server, for example, the login account and password of a certain business.

[0055] The application framework layer provides application programming interfaces (APIs) and programming frameworks for the applications of the application layer. The application framework layer includes some pre-defined functions.

[0056] As shown in Figure 2 , the application framework layer can include a window manager, a view system, an F interface, and a resource manager, and the like.

[0057] The window manager is used to manage window programs. The window manager can obtain the size of the display screen, determine whether there is a status bar, lock the screen, take a screenshot, send interface information display instructions to the view system, and the like.

[0058] The view system includes visual controls, such as controls that display text, controls that display pictures, and the like. The view system can be used to build an application. A display interface can be composed of one or more views. For example, a display interface that includes a short message notification icon can include a view that displays text and a view that displays a picture.

[0059] The resource manager provides various resources for the application program, such as localized strings, icons, pictures, layout files, video files, and the like.

[0060] The F interface is an external service interface of the trust circle.

[0061] The application program layer and the application program framework layer run in the virtual machine. The virtual machine executes the java files of the application program layer and the application program framework layer into binary files. The virtual machine is used to perform the management of the object life cycle, the management of the stack, the management of the thread, the management of the security and the exception, and the garbage collection, and the like.

[0062] The system library can include a plurality of functional modules. For example: a two-dimensional graphics engine (for example: SGL), a key asset trust circle CA, a surface manager, and the like.

[0063] The surface manager is used to manage the display subsystem, and provides the fusion of the 2D and 3D layers for a plurality of application programs. The two-dimensional graphics engine is a drawing engine of the two-dimensional image.

[0064] The key asset trust circle CA can also be referred to as a trust circle service module, and is mainly used for the message transparent transmission between the upper trust circle application and the lower key asset trust circle TA.

[0065] The kernel layer is a layer between the hardware and the software. The kernel layer at least includes a display driver, a sensor driver, a Wi-Fi driver, and a key asset trust circle TA. The display driver is used to drive the display screen 194, the Wi-Fi driver is used to drive the wireless communication module 160, and the sensor driver is used to drive the sensor module 180.

[0066] The key asset trust circle TA can also be referred to as a trust circle module, and is used to implement the core security logic, to provide a trusted execution environment, and to generate a master key, to encrypt the master key to generate a master key ciphertext, and the like in the trusted execution environment. For the specific functions of the key asset trust circle CA and the key asset trust circle TA, refer to the related descriptions in the following process descriptions of the trust circle, the encryption, the deletion, the violence prevention, the device offline in the trust circle, the update of the master key, the update of the master key ciphertext, and the like.

[0067] It can be understood that, Figure 2 The components included in the system framework layer and the runtime layer shown do not constitute a specific limitation on the electronic device 100. In some other embodiments of the present application, the electronic device 100 can include more or fewer components than those shown, or combine certain components, or split certain components, or different arrangement of components.

[0068] When using an electronic device, a user often needs to remember a lot of password data, such as the password of a mailbox account, the password of a network disk account, the password of smart home control right, and the like. When there are too much of such password data, if the user independently records the password data of each service, it will cause great difficulty for the user to remember. Therefore, the user hopes to upload such password data to the cloud side for storage through a data synchronization function, and directly obtain the password data from the cloud side when using, without the user himself remembering.

[0069] However, for such password data, the user has different security requirements from general data to be synchronized, such as pictures, address books, short messages, and the like. Once such password data is leaked, it will cause great loss to the user. Therefore, the user has a high security requirement for such password data. At this time, the disadvantage of the cloud side being unable to prove its innocence will greatly reduce the security of the data synchronized to the cloud side, and cannot meet the high security requirement of such password data.

[0070] The present application provides a data protection method for enabling the cloud side to prove its innocence, which can support data synchronization of service data such as password data with high security requirements.

[0071] The data protection method of the present application will be described in detail below with reference to the accompanying drawings.

[0072] First, create a trust ring

[0073] Figure 3 The information interaction schematic diagram in the process of creating a trust ring is exemplarily shown. Figure 4 The interaction schematic diagram between the device and the cloud side in the process of creating a trust ring is exemplarily shown. Figure 10 The flowchart of creating a trust ring is exemplarily shown.

[0074] The process of creating a trust ring of the embodiment of the present application will be described in detail below with reference to Figure 3 , Figure 4 and Figure 10 .

[0075] In the embodiment of the present application, it is assumed that the honor account of device A is account 1, and the process of creating a trust ring is described by taking device A as an example of first initiating registration to the trust ring cloud and creating trust ring 1 of account 1. The application that can trigger the creation of a trust ring process can be any application under the honor account, and in this paper, the creation of a trust ring process is described by taking the "password safe synchronization" application under the honor account as an example.

[0076] In this document, "registration" refers to the process of adding a device to a trust circle. In this document, the process of registering the first device is referred to as creating a trust circle, because the trust circle does not exist under the account yet, and the device needs to be added to the trust circle after the trust circle is created. The process of registering a non-first device is referred to as joining a trust circle, because the device only needs to be added to an existing trust circle.

[0077] In this document, it is assumed that account 1 includes three devices, namely, Honor V40 (device A), Honor V30 (device B), and Honor V50 (device C).

[0078] It should be noted that the actions performed by various clouds in this document should be understood as actions performed by servers in the corresponding clouds. For example, the actions performed by the account management server are performed by the account management server server, and the actions performed by the trust circle cloud are performed by the trust circle cloud server.

[0079] See Figure 3 In the process of creating a trust circle, device A sends a request to log in to account 1 to the account management server. After the account management server verifies the request to log in to account 1, the account management server returns a verification pass message to device A. After receiving the verification pass message, device A generates a device A master key ciphertext EMK11 and a device A authentication parameter PAKE11, and sends EMK11 and PAKE11 to the trust circle cloud. After receiving EMK11 and PAKE11 sent by device A, the trust circle cloud creates trust circle 1 for account 1 and adds device A to trust circle 1.

[0080] See Figure 10 In the embodiments of this application, the process of creating a trust circle by device A can include the following steps:

[0081] Step S1: Device A logs in to account 1.

[0082] In this document, device A is taken as an example of an Honor V40 mobile phone. It should be understood that device A can be any electronic device that has installed the trust circle creation function in this application, and this application does not limit device A.

[0083] Device A needs to be logged in to an account before it can initiate registration with the trust circle cloud to create a trust circle. If device A has not logged in to an account, device A needs to log in to an account first.

[0084] Figure 5A An example of an interface diagram of entering the "My Devices" application when logged in to an account. Figure 5B An example of an interface diagram of entering the "My Devices" application when not logged in to an account. Figure 6This is an example illustration of the interface for accessing the "Password Vault Sync" application from the "My Device" application on device A.

[0085] Please see Figure 5A and Figure 6 If device A is already logged into account 1 (assuming account 1 is 1581991××××), the user can click the "Settings" application icon on the main interface of device A (e.g., ...). Figure 5A As shown in Figure (a), enter Figure 5A The “Settings” interface is shown in Figure (b). In the “Settings” interface, the user clicks on account 1 (i.e., 1581991××××) to enter… Figure 5A The “Account Center” interface is shown in Figure (b). In the “Account Center” interface, the user clicks “My Device” to enter… Figure 6 The "My Devices" interface is shown in Figure (b). In the "My Devices" interface, locate the current device, i.e., Honor V40, and tap on Honor V40 to enter... Figure 6 The "Device Information" interface is shown in Figure (c). On the "Device Information" interface, the user can access the "Password Vault Sync" application by clicking on it. In the "Password Vault" interface, after enabling the "Password Vault Sync" switch, clicking the "Sync to Honor Account" switch triggers the process of creating a trust ring. The processes of accessing the "Password Vault" interface, enabling the "Password Vault Sync" switch, and enabling the "Sync to Honor Account" switch will be explained later.

[0086] It should be noted that if account 1 already has a trust ring, devices added to the trust ring will be displayed as "Trusted Devices" on the "My Devices" interface. Devices marked as "Trusted Devices" are those already added to the trust ring, i.e., registered devices. Please refer to subsequent sections for more details. Figure 15 The interface shown in Figure (b). If there is no trust loop under account 1, for example in Figure 6 In Figure (b), on the "My Devices" interface of device A, none of the three Honor devices are trusted devices, indicating that there is no trust ring under the current account 1.

[0087] Please see Figure 5A , Figure 5B and Figure 6 If user A is not logged into account 1 on device A, and the user clicks the "Settings" application icon on the main interface of device A (e.g., ... Figure 5A After (as shown in Figure (a)), proceed to... Figure 5B The "Settings" interface is shown in Figure (a). In the "Settings" interface, the user clicks "Log in to Honor account" to enter... Figure 5BFigure (b) shows the Honor account login interface. On the Honor account login interface, the user enters account 1 (1581991××××) and login password (assumed to be key1). Device A sends a login request for account 1 to the account management server, carrying account 1 (1581991××××) and login password key1 in the request.

[0088] Please see Figure 4 Users can send a login request for account 1 to the account management server through the account management module of the application layer of device A to log in to account 1.

[0089] After device A successfully logs in to account 1, it triggers the trust ring creation process according to the aforementioned process for an already logged-in account. Please refer to [link to relevant documentation]. Figure 5A Figures (c), (d), and Figure 6 As shown, it will not be elaborated further here.

[0090] Step S2: The account management server returns a verification successful message.

[0091] The account management server pre-stores information about account 1, including its login password. Let's assume the password stored for account 1 is key0. When the account management server receives a login request for account 1 from device A, it verifies the request based on the information stored locally. If the password key1 in the login request matches the password key0 stored locally on the account management server, the login verification for account 1 is successful. At this point, the account management server returns a verification success message to device A.

[0092] If the password key1 for account 1 carried in the login request does not match the password key0 for account 1 stored locally on the account management server, the account management server determines that login verification for account 1 has failed. In this case, the account management server returns a verification failure message to device A. At this point, the user needs to... Figure 5B (b) Re-enter your account and login password.

[0093] Please see Figure 4 and Figure 10 Device A receives verification success or verification failure messages through the account management module.

[0094] S3: Send a registration activation notification.

[0095] Please see Figure 4 and Figure 10In the case that the account management module of the device A receives the verification pass message returned by the account management server, the account management module in the device A sends a registration start notification to the trust circle service module of the application framework layer. The registration start notification is used to instruct the trust circle service module to start the registration process.

[0096] Here, the process in which the device A enters the "password safe" interface and starts the "password safe synchronization" switch in the process of creating a trust circle is described.

[0097] Figure 7A is a schematic diagram of the process in which the device A enters the "password safe" interface in the case that the device A has set a lock screen code. Please refer to Figure 7A In the case that the user of the device A has set a lock screen code (also referred to as a lock screen password) of the device A, when the user clicks the "password safe synchronization" application in the "device information" interface (please refer to Figure 7A (a) of FIG. 8), the device A pops up an "enter lock screen password" interface (please refer to Figure 7A (b) of FIG. 8). If the user inputs a lock screen code in the "enter lock screen password" interface and the lock screen password is correct, the screen of the device A enters the "password safe" interface (please refer to Figure 7A (c) of FIG. 8). At this time, the "password safe synchronization" switch and the "synchronize to honor account" switch on the "password safe" interface are both in the off state.

[0098] Figure 7B is a schematic diagram of the process in which the device A enters the "password safe" interface in the case that the device A has not set a lock screen code. Please refer to Figure 7B In the case that the user of the device A has not set a lock screen code of the device A, when the user clicks the "password safe synchronization" application in the "device information" interface (please refer to Figure 7B (a) of FIG. 9), the device A pops up a "set digital lock screen password" interface (please refer to Figure 7B (b) of FIG. 9). After the user inputs a lock screen code in the "set digital lock screen password" interface shown in Figure 7B (b) of FIG. 9, the device A pops up an interface for confirming the password of the "set digital lock screen password" (please refer to Figure 7B (c) of FIG. 9). The user inputs a lock screen code again on the interface shown in Figure 7B (c) of FIG. 9. If the lock screen code inputted again is consistent with the lock screen code inputted by the user on the interface shown in Figure 7B (b) of FIG. 9, the screen of the device A enters the "password safe" interface shown in Figure 7B (d) of FIG. 9, which is the same as the interface shown in Figure 7A (c) of FIG. 8.

[0099] Figure 8The process of turning on the "password safe synchronization" switch in the scenario of creating a trust circle is shown in the following figures. Please refer to Figure 8 When the user clicks the "password safe synchronization" switch on the "password safe" interface (please refer to (a) of Figure 8 , the prompt interface shown in (b) of Figure 8 pops up on the screen of device A, which is used to remind the user whether to agree to turn on the password safe synchronization service. When the user clicks the "agree" button on the prompt interface (please refer to (b) of Figure 8 , the "password safe synchronization" switch on the "password safe" interface is turned on (please refer to (c) of Figure 8 ).

[0100] When the trust circle service module receives the registration opening notification, it cannot determine whether to start the process of creating a trust circle or the process of joining a trust circle, and needs to determine it by detecting the registration state.

[0101] S4: The trust circle service module in device A detects the registration state of device A.

[0102] The registration state includes two states: unregistered and registered. The unregistered state is used to indicate that the device is currently not registered to the trust circle, and the registered state is used to indicate that the device is currently registered to the trust circle.

[0103] S5: When it is detected that the registration state of device A is unregistered, device A sends a registration state comparison request to the trust circle cloud.

[0104] The registration state comparison request is used to indicate the comparison result of the registration state of device A detected by the trust circle service module and the registration state of device A stored in the trust circle cloud.

[0105] The registration state comparison request includes the UID (device identifier) of device A and the UDID (account identifier) of the account to which device A belongs.

[0106] S6: The trust circle cloud returns a first registration state confirmation message to the trust circle service module in device A.

[0107] The first registration state confirmation message is used to indicate that there is no trust circle under account 1.

[0108] After receiving the registration state comparison request of device A, the trust circle cloud first compares whether there is a trust circle under account 1, and then compares whether device A is in the trust circle if there is a trust circle under account 1. When there is no trust circle under account 1, the trust circle cloud generates a first registration state confirmation message and sends it to device A.

[0109] Based on the first registration status confirmation message returned by the Trust Ring Cloud, Device A determines that it will execute the Trust Ring Creation process during this registration.

[0110] S7: The trust ring service module in device A receives the user's input screen lock code pw11 for device A.

[0111] This section explains the process of enabling the "Sync to Honor Account" switch during the creation of a trust ring.

[0112] Figure 9 This is a schematic diagram illustrating the process of enabling the "Sync to Honor Account" switch in a scenario where a trust ring is created. Please refer to [link / reference]. Figure 9 When a user clicks the "Sync to Honor Account" switch on the "Password Vault Sync" interface where the "Password Vault Sync" switch is enabled (see [link]), Figure 9 (See Figure (a)). On device A's screen, a "Enter lock screen password" interface pops up (see Figure (a)). Figure 9 (See Figure (b)). If the user enters the lock screen code of device A on the "Enter Lock Screen Password" screen, the trust ring service module in device A will receive the user's lock screen code. If the user's lock screen code for device A is correct, after device A completes the trust ring creation process, it will enter the "Password Vault" screen where both the "Password Vault Synchronization" and "Synchronize to Honor Account" switches are turned on (see Figure (b)). Figure 9 (Figure (c)).

[0113] It should be noted that users in Figure 9 The operation of clicking the "Sync to Honor Account" switch on the interface shown in Figure (a) (see also) Figure 9 (a) Figure triggers device A to execute Figure 10 Step S3 and the subsequent steps in the trust ring creation process.

[0114] The lock screen code of device A is a user secret of device A, and it is unknown to the cloud side.

[0115] S8: The trust ring service module of device A verifies the lock screen code pw11 of device A.

[0116] The process of verifying the lock screen code of device A can be as follows: device A compares the lock screen code entered by the user with the lock screen code pre-stored in device A. If the two match, the verification is successful; otherwise, the verification fails.

[0117] Here, the trust ring service module provides users with... Figure 9 The device lock screen code entered on the interface shown in Figure (b) is re-verified. Only after successful verification can the subsequent step S9 be executed. If verification fails, device A will return to... Figure 9the interface shown in (b) of FIG. 1, and prompts input of the lock screen code at the interface.

[0118] S9: The trust circle service module derives PWUA TH11 based on the lock screen code of device A.

[0119] Assuming that the lock screen code input by the user this time is pw11, the trust circle service module derives PWUA TH11 based on pw11.

[0120] Since pw11 belongs to the user secret of device A, the cloud side cannot obtain pw11, and thus the cloud side cannot obtain PWUA TH11 derived based on pw11.

[0121] Since PWUA TH11 is generated based on the user secret pw11 unknown to the cloud side, PWUA TH11 is unknown to the cloud side.

[0122] S10: The trust circle service module of device A sends PWAUTH11 to the trust circle module in the trusted execution environment of device A.

[0123] Subsequently, the trust circle module generates a master key ciphertext EMK11 and a parameter PAKE11 based on PWAUTH11, and the generation manner of EMK11 and PAKE11 is detailed in steps S11 to S14 of Figure 10 .

[0124] S11: The trust circle module generates MK.

[0125] Device A generates MK, i.e., a master key, through the trust circle module, and MK is saved in the trusted execution environment of device A. Even if device A is attacked, MK will not be stolen, and thus the security is very high.

[0126] S12: The trust circle module encrypts MK based on PWAUTH11 to generate EMK11.

[0127] EMK11 is a first master key ciphertext. The trust circle module derives a key KEK11 based on PWAUTH11, and encrypts MK based on the key KEK11 to generate EMK11.

[0128] S13: The trust circle module of device A sends EMK11 to the trust circle service module of device A.

[0129] After the trust circle module generates EMK11, the trust circle module sends EMK11 to the trust circle service module, and sends salt_enc11 to the trust circle service module at the same time.

[0130] S14: The trust circle service module in device A generates a parameter PAKE11 based on PWAUTH11.

[0131] S15: Device A sends a ring creation request carrying EMK11, parameter PAKE11 to the trust circle cloud through the trust circle service module.

[0132] Device A sends a ring creation request to the trust circle cloud through the trust circle service module, by which the PAKE11 parameter registration and EMK11 hosting can be completed.

[0133] In order to improve the security of EMK11, the trust circle service module can perform secondary encryption on EMK11 based on the public key of the trust circle cloud HSM obtained during login before sending EMK11, to obtain a two-layer ciphertext of the master key.

[0134] S16: The trust circle cloud creates trust circle 1 of account 1 and adds device A to trust circle 1 in response to the ring creation request.

[0135] The trust circle cloud creates trust circle 1 of account 1 in response to the ring creation request sent by device A, and when other devices such as device B and device C under account 1 send a registration state comparison request to the trust circle cloud, the trust circle cloud will return a confirmation message that trust circle 1 exists but device B and device C are not in the trust circle. Device B and device C perform the process of joining the trust circle, and the specific process of joining the trust circle can be referred to subsequent related descriptions.

[0136] After the creation of trust circle 1 is completed, the trust circle 1 data managed in the trust circle cloud is as shown in Table 1:

[0137] Table 1

[0138] UID UDID Parameter PAKE Master Key Cipher Account 1 Device A PAKE 11 EMK 11

[0139] S17: The trust circle cloud returns a ring creation success message to the trust circle service module of device A.

[0140] After the trust circle cloud creates trust circle 1 of account 1 and adds device A to trust circle 1, it returns a ring creation success message to device A. After device A receives the ring creation success message, it turns on the "synchronize to honor account" switch in the password safe interface, as shown in (c) of FIG. Figure 9 After the "synchronize to honor account" switch is turned on, the user can perceive that device A has successfully joined the trust circle, and the business data in the password safe can be synchronized to the account management server, so that other devices under account 1 in trust circle 1 can share the business data.

[0141] At this point, the process of creating a trust circle is completed, and device A completes registration.

[0142] After device A completes registration, the trust circle service module of device A modifies the registration state of device A to registered.

[0143] As can be seen from the process of creating the trust circle, the embodiments of the present application protect the account-level master key MK based on the user secret. Since the user secret is unknown to the cloud side, the cloud side cannot decrypt the ciphertext of the hosted master key, thereby reducing the risk of master key leakage and improving the security of the master key MK, while enabling the cloud side to prove its innocence.

[0144] It should be noted that the above process is an illustrative example of the process of creating a trust circle in the present application and does not limit the present application.

[0145] Figure 11 A schematic diagram of synchronizing the ciphertext of the business data of device A to the account management server after creating the trust circle is shown by way of example. Figure 12 A schematic diagram of the module interaction for synchronizing the ciphertext of the business data is shown by way of example. Figure 13 A schematic diagram of the interface for synchronizing the ciphertext of the business data to the account management server is shown by way of example. Please refer to Figure 11 、 Figure 12 and Figure 13 In the case where the trust circle 1 of the account 1 has been created and the device A has been added to the trust circle 1, the device A can encrypt the sensitive business data using the MK to obtain the ciphertext of the business data and upload the ciphertext of the business data to the account management server.

[0146] The process of synchronizing the ciphertext of the business data of device A to the account management server after creating the trust circle is as follows:

[0147] Please refer to Figure 12 The password safe of the application layer in the device A reads the plaintext of the business data, and then stores the plaintext of the business data in the business data storage service module of the application framework layer. The business data storage service module sends the plaintext of the business data to the key management module in the trusted execution environment. The trust circle module generates the business key dkey based on the MK. The key management module reads the business key dkey from the trust circle module, encrypts the business data data using the dkey to obtain the ciphertext of the business data Edata. The key management module returns the ciphertext of the business data Edata to the business data storage service module. The business data storage service module uploads the ciphertext of the business data Edata to the account management server through the business data synchronization service module and the account management server synchronization framework of the application layer.

[0148] It should be noted that the business keys dkey corresponding to different businesses are different, and the device A can generate the business keys of different businesses based on the MK.

[0149] For example, please refer to Figure 13 When the user uses the business 1 on the device A, the user needs to input the account and password of the business 1, such as Figure 13Fig. 1 (a). After inputting the account and password of service 1, device A pops up information prompting whether to synchronize the account and password of service 1 to the password safe, as shown in Fig. 1 (b). If the user agrees, device A uploads the ciphertext Edata1 of data1 of service 1 to the account management server as the service data data1 of service 1 according to the synchronization process of the service data data described above. Figure 13 Fig. 1 (b). If the user agrees, device A uploads the ciphertext Edata1 of data1 of service 1 to the account management server as the service data data1 of service 1 according to the synchronization process of the service data data described above.

[0150] As can be seen from the above, in the embodiment of the present application, the ciphertext of the service data in the account management server does not completely depend on the security of the account, but also depends on the security of the MK, so that even if the account is stolen, the security of the data on the cloud is not affected.

[0151] Based on the high-security master key, the service data of the user is encrypted, and then the ciphertext of the service data is synchronized to the account management server, thereby reducing the risk of leakage of the ciphertext of the service data and improving the security of data synchronization backup.

[0152] Joining a trust ring

[0153] On the basis that device A has created the trust ring 1 of account 1, device B under the account 1 can be joined into the trust ring 1 according to the joining process of the trust ring in the following embodiments. Taking the case that there is only one in-ring device A in the trust ring 1 before device B joins the trust ring 1 as an example.

[0154] In the joining method of the trust ring provided by the embodiment of the present application, when device B joins the trust ring, a device A in the trust ring 1 and online and near the user is needed, a random verification code is generated by device A, the user inputs the verification code on device B, a series of authentication parameters are generated through a cryptographic algorithm, the authentication parameters are sent to device A through the trust ring cloud, the authentication parameters sent by device B are checked by device A, after the check is passed, device A encrypts the master key MK to obtain EMK12, and EMK12 and the negotiation parameters are sent to device B through the trust ring cloud, device B negotiates the key with the negotiation parameters sent by device A to decrypt EMK12 to obtain MK, and device B is joined into the trust ring 1 based on the obtained MK.

[0155] Figure 14 An information interaction schematic diagram in the process of joining the trust ring of device B is shown for example. Figure 16 A flowchart of the process of joining the trust ring of device B is shown for example.

[0156] The process of joining the trust ring of the embodiment of the present application will be described in detail below. Figure 14 and Figure 16 The process of joining the trust ring of the embodiment of the present application will be described in detail below.

[0157] Please refer to Figure 14After device A registers as the first device, the creation of the trust circle process is completed, and device A has uploaded the master key ciphertext EMK11 of device A and the authentication parameter PAKE11 of device A to the trust circle cloud. Thereafter, other devices, such as device B, register by joining the trust circle process. In the process of device B joining the trust circle 1, device B logs in an account, sends login information to the account management server, the account management server verifies the login account of device B, and sends a login information verification pass notification to the trust circle cloud after verification. The trust circle cloud sends a preparation check notification to device A. Device A randomly generates a verification code, the user inputs the verification code generated by device A on device B, device B sends the authentication parameter generated based on the verification code to the trust circle cloud, the trust circle cloud transmits the authentication parameter, device A checks the authentication parameter, generates negotiation parameters after verification, and encapsulates the MK based on the negotiation parameters to generate EMK12. The trust circle cloud transmits the negotiation parameters and EMK12 to device B, device B negotiates the session key based on the negotiation parameters, decrypts EMK12 based on the session key to obtain MK, and encrypts MK based on the lock screen code of device B to generate the master key ciphertext EMK21 of device B and the authentication parameter PAKE21 of device B, and sends EMK21 and PAKE21 to the trust circle cloud.

[0158] See Figure 16 In the embodiments of the present application, the process of device B joining the trust circle can include the following steps:

[0159] S1: Device B logs in account 1.

[0160] Like device A, device B logs in account 1 by sending a request for logging in account 1 to the account management server. The detailed process of device B logging in account 1 can be found in the foregoing process of device A logging in account 1, which will not be repeated here.

[0161] S2: The account management server returns a verification pass message to device B.

[0162] The process of the account management server processing the request of device B logging in account 1 can be found in the foregoing process of the account management server processing the request of device A logging in account 1, which will not be repeated here.

[0163] S3: The account management server sends a login information verification pass message to the trust circle cloud.

[0164] After the account management server verifies the login information of device B, the account management server sends a login information verification pass message to the trust circle cloud. After the trust circle cloud receives the login information verification pass message of device B, the trust circle cloud determines the devices that have joined the trust circle 1 under account 1, sends a preparation check notification to each device in the trust circle 1, and returns a verification pass message to device B.

[0165] S4: Pull up the service, send the waiting verification code message.

[0166] Figure 15 As shown in (a) of FIG. 1, the user inputs the account 1 "1581991xxxx" and the login password on the device B to request login of the honor account, i.e., the account 1. After the account management module of the device B receives the verification pass message returned by the account management server, the waiting verification code message is sent.

[0167] S5: The trust ring cloud notifies the in-ring device A to prepare for verification.

[0168] The trust ring cloud determines all devices under the trust ring 1 managed by it, and notifies all devices under the trust ring 1 to prepare for verification. Since the device A is the only in-ring device in the trust ring 1, the preparation for verification notification is sent to the device A only.

[0169] It should be noted that if the trust ring 1 further includes other devices such as the device C and the device D in addition to the device A, the preparation for verification notification is sent to the device A, the device C, and the device D respectively.

[0170] S6: The device B pops up a verification code input interface.

[0171] After the account management module of the device B sends the waiting verification code message, the device B pops up a verification code input interface. The verification code input interface of the device B is shown in (d) of FIG. 1. Figure 15 As shown in (d) of FIG. 1, the verification code input interface includes a security verification prompt box, which includes a verification code input area, a cancel button, and a confirm button.

[0172] S7: The device A pops up a request pop-up window for allowing login.

[0173] After the device A in the trust ring 1 receives the preparation for verification notification, a request pop-up window for allowing login is popped up. A schematic diagram of the request pop-up window for allowing login is shown in (b) of FIG. 1. Figure 15 As shown in (b) of FIG. 1, the request pop-up window for allowing login includes inquiry information "whether to allow … to log in on …", a do not allow button, and an allow button.

[0174] S8: After the device A receives the user login instruction, a verification code is generated and displayed.

[0175] The user clicks the "allow" button. In response to the operation of the user clicking the "allow" button, the device A determines that the user login instruction is received, randomly generates a verification code, and cancels the display of the request pop-up window for allowing login, and displays the honor account security verification code prompt box in the interface, as shown in (c) of FIG. 1. Figure 15As shown in (c) of FIG. 1, the honor account security verification code prompt box includes the random verification code generated by the device A and a "I know" button. After the user views the security verification code displayed by the device A, the user can click the "I know" button to trigger the device A to cancel displaying the honor account security verification code prompt box.

[0176] The honor account security verification code prompt box is not limited to being canceled after the user clicks the "I know" button. The honor account security verification code prompt box can also automatically disappear after being displayed for a preset time length or automatically disappear after the user clicks an area outside the honor account security verification code prompt box. The present application does not make a specific limitation in this regard.

[0177] The preset time length can be set to 3 seconds, 2 seconds, 5 seconds, etc. The value of the preset time length can be flexibly set by those skilled in the art, and the present application does not make a specific limitation in this regard.

[0178] It should be noted that if the trust ring 1 also includes devices C and D, the devices C and D will also pop up the request window for allowing login, and the display interface is the same as that after the device A pops up the request window for allowing login. After the user clicks the "allow" button of the device A, the request window for allowing login of the devices C and D disappears.

[0179] S9: The device B receives the verification code displayed by the device A input by the user.

[0180] Continuing to refer to (c) of FIG. 1, after the verification code is displayed on the device A, the user can input the verification code displayed on the device A into the verification code input interface of the device B as shown in (d) of FIG. 1. Figure 15 Figure 15 The trust ring service module of the device B receives the verification code displayed by the device A input by the user.

[0181] S10: The device B generates an authentication parameter based on the verification code.

[0182] In this step, the trust ring service module and the trust ring module interact to generate an authentication parameter. The process of generating the authentication parameter is as follows:

[0183] The trust ring service module receives the PinCodeA generated by the device A, i.e., the verification code, input by the user.

[0184] The trust ring module generates an elliptic curve public-private key pair ecc_keypair_B and sends the elliptic curve public key NewDevPk of the device B to the trust ring service module.

[0185] The trust ring service module generates a hash value CodeIndex of the PinCode, a PAKE parameter (password authentication key exchange parameter) PakeX, and an authentication parameter UpdatePkAuth.

[0186] ​The generated authentication parameter can include CodeIndex, PakeX, NewDevPk, UpdatePkAuth, other device information, and a challenge value challenge for anti-replay attack.

[0187] S11: Device B sends the authentication parameter to the trust circle cloud.

[0188] The trust circle service module of device B sends the authentication parameter to the trust circle cloud to pass the authentication parameter to device A through the trust circle cloud.

[0189] S12: The trust circle cloud passes the authentication parameter to device A.

[0190] S13: Device A generates negotiation parameters and encapsulates the master key MK.

[0191] The trust circle service module of device A interacts with the trust circle module to generate negotiation parameters and encapsulate the master key MK. The specific process of generating negotiation parameters and encapsulating MK is as follows:

[0192] The trust circle service module generates the hash value of PinCodeA and compares whether it is consistent with CodeIndex in the authentication parameter. It generates HMAC and compares whether it is consistent with UpdatePkAuth in the authentication parameter. If both comparison results are consistent, it sends a verification pass notification to the trust circle module. The trust circle module generates negotiation parameters. The process of the trust circle module generating negotiation parameters can be as follows:

[0193] Generate the elliptic curve public-private key pair ecc_keypair_A of device A and UpdatePk;

[0194] Generate the message authentication code UpdatePkMac of the public key of device A

[0195] Negotiate the session key of the elliptic curve of device A: ecc_seesionkey

[0196] Encrypt the master key using the negotiated session key of the elliptic curve of device A to obtain EMK12

[0197] The trust circle module sends the negotiated session key ecc_seesionkey and EMK12 to the trust circle service module, and the trust circle service module executes the following algorithm logic:

[0198] Generate PAKE parameter PakeY

[0199] Generate PAKE session key pake_sessionKey

[0200] PAKE session key encrypts EMK12 to obtain encapsulated MKE.

[0201] The encapsulated MK is generated by encrypting the MK twice, first encrypting the MK using the negotiated session key of the elliptic curve of device A, ecc_sessionkey, to generate EMK12, and then encrypting EMK12 using the PAKE session key to obtain the encapsulated MK.

[0202] The trust circle service module sends the negotiation parameters and the encapsulated MK to the trust circle cloud. The negotiation parameters can include:

[0203] UpdatePk (the public key of the elliptic curve of device A), UpdatePkMac, PakeY, CipherDevDataSignature, other additional information, and the encapsulated MK can be represented as EEMK12.

[0204] S14: Device A sends the negotiation parameters and the encapsulated MK to the trust circle cloud.

[0205] S15: The trust circle cloud transmits the negotiation parameters and the encapsulated MK to the trust circle service module of device B.

[0206] S16: The trust circle service module of device B decapsulates the encapsulated MK to obtain EMK12.

[0207] After receiving the negotiation parameters and the encapsulated MK transmitted by the trust circle cloud, the trust circle service module of device B decapsulates the encapsulated MK to obtain EMK12. The process of decapsulating the encapsulated MK can be as follows:

[0208] Calculate pake_sessionKey, and decrypt EEMK12 based on pake_sessionKey to obtain EMK12

[0209] Compare the challenge values. If they are consistent, send EMK12 to the trust circle module of device B.

[0210] S17: The trust circle service module of device B sends EMK12 to the trust circle module of device B.

[0211] S18: The trust circle module of device B negotiates a session key and decrypts EMK12 based on the session key to obtain MK.

[0212] The trust circle module performs the following process:

[0213] Negotiate ECC session key ecc_sessionkey, and decrypt EMK12 based on the ECC session key to obtain MK.

[0214] The generated message authentication code HMac(MK, UpdatePK) is compared with the UpdatePK in the negotiation parameter transmitted by device A. If they are consistent, it is determined that the security verification is passed.

[0215] S19: The trust circle module of device B pulls up the lock screen.

[0216] After the trust circle module of device B successfully decrypts MK, the lock screen is pulled up.

[0217] S9 to S19 are the process of performing security verification on device B based on the authentication code of device A, and obtaining MK from device A after the security verification of device B is passed.

[0218] S20: Device B pops up the lock screen code input interface.

[0219] Continuing to refer to Figure 15 (d) of the drawings, after the user inputs the authentication code of device A in the authentication code input interface of device B to complete the security verification, as shown in Figure 15 (e) of the drawings, the local lock screen code input interface is displayed in device B.

[0220] S21: Device B receives the lock screen code pw21 of device B input by the user.

[0221] In this example, the trust circle service module of device B receives the lock screen code input by the user, and in the actual implementation process, the lock screen service module can also be set to receive the lock screen code input by the user.

[0222] S22: The trust circle service module of device B verifies the lock screen code pw21 of device B, and after the verification is passed, derives the parameter PAKE21 based on pw21.

[0223] The process of deriving the parameter PAKE21 based on the lock screen password pw21 of device B can refer to the process of deriving the parameter PAKE11 based on the lock screen password pw11 of device A in the creation of the trust circle shown in Figure 10 , which will not be repeated here.

[0224] S23: The trust circle module of device B encrypts MK based on the key derived based on pw21 to obtain EMK21.

[0225] The process of encrypting MK based on the key derived based on the lock screen password pw21 of device B can refer to the process of encrypting MK based on the key derived based on the lock screen password pw11 of device A in the creation of the trust circle shown in Figure 10 , which will not be repeated here.

[0226] S24: The trust ring module of device B sends EMK21 to the trust ring service module of device B.

[0227] S25: The trust ring service module of device B sends a ring addition request carrying PAKE21 and EMK21 to the trust ring cloud.

[0228] S26: The trust ring cloud adds device B to trust ring 1 of account 1 in response to the ring addition request.

[0229] After device B joins trust ring 1, the trust ring 1 data managed in the trust ring cloud is as shown in Table 2:

[0230] Table 2

[0231] UID UDID Parameter PAKE Master Key Cipher Account 1 Device A PAKE 11 EMK 11 Account 1 Device B PAKE 21 EMK 21

[0232] Wherein, PAKE11 can also be referred to as pakeParameter ciphertext A, PAKE21 can also be referred to as pakeParameter ciphertext B, EMK11 can also be referred to as escrowMsg ciphertext A, and EMK21 can also be referred to as escrowMsg ciphertext B.

[0233] S27: The trust ring cloud returns a ring addition success notification to the trust ring service module of device B.

[0234] S28: The trust ring service module sends a ring addition success notification to the account management module.

[0235] S29: Return to the cloud space interface.

[0236] After the trust ring cloud adds device B to trust ring 1, a ring addition success message is returned to device B, and device B returns to the cloud space interface after receiving the ring addition success message, as shown in (f) of FIG. 1. Figure 15 The "cloud backup" button in the cloud space interface is turned on, and the user can perceive that device B has successfully joined the trust ring, and the business data managed in the cloud space can be synchronized to the account management server, so that other devices under account 1 in trust ring 1 can share the business data.

[0237] At this point, the process of device B joining trust ring 1 is completed, and device B completes registration.

[0238] After device B completes ring addition, the trust ring service module of device B modifies the registration state of device B to registered.

[0239] As can be seen by adding the trust ring process, in the embodiment of the application, the ring adding device generates authentication parameters according to the verification code randomly generated by the registered device, transmits the authentication parameters to device A through the cloud side, device A verifies the identity of device B based on the authentication parameters, and after the identity of device B is verified, device A generates negotiation parameters, double-encrypts the master key MK based on the negotiation parameters, and transmits the double-encrypted MK and negotiation parameters to device B through the cloud side. Device B decrypts the double-encrypted MK based on the negotiation parameters to obtain MK. The ring adding process, by verifying a certain user secret (non-lock screen code) between device A and device B, achieves the purpose of confirming the identity of the account and device B. On the one hand, the secret used to confirm the identity of device B is not stored in any device in advance, which is instant. On the second hand, the secret is not issued to the device by the cloud side, therefore, when the master key encrypted by the negotiation parameter based on the secret is transmitted through the cloud side, the cloud side cannot decrypt the master key, and the cloud side can prove its innocence. 3. The secret is friendly to user memory, and does not need to be memorized additionally.

[0240] Figure 17 A schematic diagram of device B synchronizing business data ciphertext from the account management server after joining the trust ring is shown by way of example. Figure 18 A schematic diagram of the interface for synchronizing business data ciphertext from the account management server is shown by way of example. Please refer to Figure 17 Figure 12 and Figure 18 In the case where the trust ring 1 of the account 1 has been created, the device A has been added to the trust ring 1, and the device A has uploaded the business data ciphertext Edata to the account management server, the device B can synchronize the business data ciphertext Edata from the account management server to the device B, and decrypt the business data ciphertext Edata with MK locally to obtain the business data plaintext data.

[0241] The process of device B synchronizing business data ciphertext from the account management server after joining the trust ring is as follows:

[0242] Please refer to Figure 12 ​The service data synchronization service module in the device B synchronizes the service data ciphertext Edata from the account management server through the account management server synchronization framework of the application layer. Then, the service data synchronization service module in the device B sends the service data ciphertext Edata to the service data storage service module in the device B, and the service data storage service module sends the service data ciphertext Edata to the key management module in the trusted execution environment of the device B. The trust ring module generates the service key dkey according to the master key, the key management module reads the master key dkey from the trust ring module, decrypts the service data ciphertext Edata using dkey, and obtains the service data plaintext data. Then, the key management module returns the service data plaintext data to the service data storage service module, and the service data storage service module stores the service data plaintext data.

[0243] For example, please refer to Figure 18 When the user uses the service 1 on the device B, the user needs to input the account and password of the service 1. In the input interface of the account and password of the service 1, as shown in FIG. 8(a), the device B pops up information prompting whether to use the account and password of the service 1 synchronized by the password safe. If the user agrees, the device B automatically fills the account and password of the service 1 synchronized by the password safe into the interface shown in FIG. 8(a), and after filling, as shown in FIG. 8(b). In this way, the user does not need to record the password independently for each service, and the user experience is improved. Figure 18 Figure 18 Figure 18 Figure 18 It should be noted that after the device B joins the trust ring 1, the device B can also synchronize the service data in the device B to the account management server by encrypting the service data in the device B using the master key MK, and the synchronization process can refer to the foregoing description of the synchronization of the service data of the device A to the account management server, which will not be described herein again.

[0244] It should be noted that after the device B joins the trust ring 1, the device B can also synchronize the service data in the device B to the account management server by encrypting the service data in the device B using the master key MK, and the synchronization process can refer to the foregoing description of the synchronization of the service data of the device A to the account management server, which will not be described herein again.

[0245] The electronic device, the computer storage medium, the computer program product or the chip provided in the embodiment can achieve the beneficial effects of the corresponding method provided in the foregoing description, which will not be described herein again.

[0246] Through the description of the above embodiments, those skilled in the art can understand that, for the convenience and brevity of description, only the division of the above functional modules is taken as an example for illustration, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0247] ​​In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented by other manners. For example, the apparatus embodiments described above are merely illustrative, for example, the division of the modules or units is merely a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another apparatus, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, apparatuses or units, and can be electrical, mechanical or other forms.

[0248] The units described as separate components can or can not be physically separate, and the components shown as units can be one physical unit or a plurality of physical units, that is, can be located in one place, or can be distributed to a plurality of different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0249] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0250] Any content of each embodiment of the present application, and any content of the same embodiment, can be freely combined. Any combination of the above is within the scope of the present application.

[0251] If the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for making an apparatus (which can be a single-chip microcomputer, a chip, etc.) or a processor execute all or part of the steps of the method of the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.

[0252] The embodiments of the present application are described above with reference to the accompanying drawings, but the present application is not limited to the specific embodiments described above, and the specific embodiments described above are merely illustrative, but not restrictive, and a person of ordinary skill in the art can make many forms under the inspiration of the present application without departing from the purpose of the present application and the scope protected by the claims.

Claims

1. A data protection method, characterized in that, include: The second electronic device displays a first interface, which includes a first account entered by the user; wherein the first electronic device is logged into the first account, and the synchronization function of the password safe corresponding to the first account is enabled in the first electronic device, and the password safe stores the account password information of the first service synchronized by the first electronic device; In response to the login operation of the first account, the second electronic device displays a second interface; the second interface includes a first prompt box, which is used to input a verification code; In response to the operation of entering the target verification code in the first prompt box, the second electronic device displays a third interface; wherein the target verification code is displayed on the first electronic device; The second electronic device responds to the user's operation of entering a lock screen password on the third interface by activating the synchronization function of the password safe corresponding to the first account; In response to the operation of activating the first service, the second electronic device displays a fourth interface; the fourth interface includes an account password input box for the first service and a second prompt box, the second prompt box being used to prompt whether to use the account password information of the first service stored in the password safe. In response to the user's confirmation operation in the second prompt box, the second electronic device fills the account password of the first service into the account password input box of the first service; wherein, the account password of the first service is obtained from the password safe corresponding to the first account.

2. The method according to claim 1, characterized in that, After the second electronic device enables the synchronization function of the password safe corresponding to the first account, it also includes: In response to the received first operation, the second electronic device displays a fifth interface; the fifth interface includes the account and password for the second service entered by the user. In response to the login operation of the second service, the second electronic device displays a third prompt box, which prompts whether to synchronize the account and password of the second service to the password safe. In response to the confirmation operation entered by the user in the third prompt box, the second electronic device synchronizes the account and password of the second service to the password safe corresponding to the first account.

3. The method according to claim 1, characterized in that, Before the second electronic device displays the first interface, it also includes: The first electronic device displays a sixth interface, which includes a first control; The first electronic device displays a seventh interface in response to the operation of the first control; The first electronic device responds to the operation of entering a lock screen password on the seventh interface and enables the synchronization function of the password safe corresponding to the first account; In response to the received second operation, the first electronic device displays an eighth interface; the eighth interface includes the account password for the first service entered by the user. In response to the login operation of the first service, the first electronic device displays a fourth prompt box, which prompts whether to synchronize the account password of the first service to the password safe. In response to the confirmation operation entered by the user in the fourth prompt box, the first electronic device synchronizes the account and password of the first service to the password safe corresponding to the first account.

4. The method according to claim 1, characterized in that, In response to the operation of entering the target verification code in the first prompt box, the second electronic device displays a third interface, including: The second electronic device generates first authentication parameters based on the target verification code; The second electronic device transmits the first authentication parameters to the first electronic device through the first server, so that the first electronic device can authenticate the identity of the second electronic device based on the first authentication parameters; If the second electronic device successfully authenticates its identity, the second electronic device obtains the master key from the first electronic device and displays the third interface; The second electronic device, in response to the user entering a lock screen password on the third interface, activates the synchronization function of the password safe corresponding to the first account, including: The second electronic device receives the lock screen password entered by the user. After the lock screen password verification is successful, the second electronic device encrypts the master key based on the lock screen password to generate the master key ciphertext of the second electronic device, and generates the second authentication parameters based on the lock screen password; The second electronic device sends a ring-adding request to the first server. The request includes the master key ciphertext and the second authentication parameters. The ring-adding request is used to request joining the trust ring corresponding to the first account. When the second electronic device receives a success indication from the first server in response to the ring request, it activates the synchronization function of the password safe corresponding to the first account.

5. The method according to claim 4, characterized in that, The second electronic device sends a ring-on request to the first server, including: The second electronic device sends a ring-adding request to the first server, so that the first server adds the master key ciphertext and the second authentication parameters to the trust ring data of the trust ring corresponding to the first account.

6. The method according to claim 4, characterized in that, Before the second electronic device encrypts the master key based on the lock screen password to generate the master key ciphertext of the second electronic device, the following steps are also included: The second electronic device compares the lock screen password with the lock screen code of the second electronic device stored locally; When the lock screen password matches the lock screen code stored locally by the second electronic device, the second electronic device determines that the lock screen password verification is successful.

7. The method according to claim 4, characterized in that, The second electronic device encrypts the master key based on the lock screen password to generate the master key ciphertext of the second electronic device, including: The second electronic device generates a third derived key based on the lock screen password; The second electronic device generates a fourth derived key based on the third derived key; The second electronic device encrypts the master key according to the fourth derived key to obtain the master key ciphertext of the second electronic device.

8. The method according to claim 4, characterized in that, The second electronic device generates second authentication parameters based on the lock screen password, including: The second electronic device generates a third derived key based on the lock screen password; The second electronic device generates a second shared value based on the third derived key; The second electronic device encrypts the second shared value based on the HSM public key generated by the first server to obtain the second authentication parameter.

9. The method according to claim 2, characterized in that, The second electronic device synchronizes the account and password for the second service to the password safe corresponding to the first account, including: The second electronic device derives a second service key based on the master key, and uses the second service key to encrypt the account and password of the second service to obtain the ciphertext of the second service data; The second electronic device sends the encrypted second service data to the second server so that the second server can save the encrypted second service data.

10. The method according to claim 1, characterized in that, The second electronic device retrieves the account password information for the first service from the password safe corresponding to the first account, including: The second electronic device obtains the first business data ciphertext from the second server; The second electronic device derives the first service key based on the master key; The second electronic device uses the first service key to decrypt the encrypted first service data to obtain the account password information for the first service.

11. A second electronic device, characterized in that, include: Memory and processor; The processor is coupled to the memory; The memory stores program instructions that, when executed by the processor, cause the second electronic device to perform the following steps: The second electronic device displays a first interface, which includes a first account entered by the user; wherein the first electronic device is logged into the first account, and the synchronization function of the password safe corresponding to the first account is enabled in the first electronic device, and the password safe stores the account password information of the first service synchronized by the first electronic device; In response to the login operation of the first account, the second electronic device displays a second interface; the second interface includes a first prompt box, which is used to input a verification code; In response to the operation of entering the target verification code in the first prompt box, the second electronic device displays a third interface; wherein the target verification code is displayed on the first electronic device; The second electronic device responds to the user's operation of entering a lock screen password on the third interface by activating the synchronization function of the password safe corresponding to the first account; In response to the operation of activating the first service, the second electronic device displays a fourth interface; the fourth interface includes an account password input box for the first service and a second prompt box, the second prompt box being used to prompt whether to use the account password information of the first service stored in the password safe. In response to the user's confirmation operation in the second prompt box, the second electronic device fills the account password of the first service into the account password input box of the first service; wherein, the account password of the first service is obtained from the password safe corresponding to the first account.

12. The second electronic device according to claim 11, characterized in that, When the program instructions are executed by the processor, the second electronic device also performs the following steps: In response to the received first operation, the second electronic device displays a fifth interface; the fifth interface includes the account and password for the second service entered by the user. In response to the login operation of the second service, the second electronic device displays a third prompt box, which prompts whether to synchronize the account and password of the second service to the password safe. In response to the confirmation operation entered by the user in the third prompt box, the second electronic device synchronizes the account and password of the second service to the password safe corresponding to the first account.

13. The second electronic device according to claim 11, characterized in that, When the program instructions are executed by the processor, the second electronic device also performs the following steps: The second electronic device generates first authentication parameters based on the target verification code; The second electronic device transmits the first authentication parameters to the first electronic device through the first server, so that the first electronic device can authenticate the identity of the second electronic device based on the first authentication parameters; If the second electronic device successfully authenticates its identity, the second electronic device obtains the master key from the first electronic device and displays the third interface; The second electronic device receives the lock screen password entered by the user. After the lock screen password verification is successful, the second electronic device encrypts the master key based on the lock screen password to generate the master key ciphertext of the second electronic device, and generates the second authentication parameters based on the lock screen password; The second electronic device sends a ring-adding request to the first server. The request includes the master key ciphertext and the second authentication parameters. The ring-adding request is used to request joining the trust ring corresponding to the first account. When the second electronic device receives a success indication from the first server in response to the ring request, it activates the synchronization function of the password safe corresponding to the first account.

14. The second electronic device according to claim 13, characterized in that, When the program instructions are executed by the processor, the second electronic device also performs the following steps: The second electronic device sends a ring-adding request to the first server, so that the first server adds the master key ciphertext and the second authentication parameters to the trust ring data of the trust ring corresponding to the first account.

15. The second electronic device according to claim 13, characterized in that, When the program instructions are executed by the processor, the second electronic device also performs the following steps: The second electronic device compares the lock screen password with the lock screen code of the second electronic device stored locally; When the lock screen password matches the lock screen code stored locally by the second electronic device, the second electronic device determines that the lock screen password verification is successful.

16. The second electronic device according to claim 13, characterized in that, When the program instructions are executed by the processor, the second electronic device also performs the following steps: The second electronic device generates a third derived key based on the lock screen password; The second electronic device generates a fourth derived key based on the third derived key; The second electronic device encrypts the master key according to the fourth derived key to obtain the master key ciphertext of the second electronic device.

17. The second electronic device according to claim 13, characterized in that, When the program instructions are executed by the processor, the second electronic device also performs the following steps: The second electronic device generates a third derived key based on the lock screen password; The second electronic device generates a second shared value based on the third derived key; The second electronic device encrypts the second shared value based on the HSM public key generated by the first server to obtain the second authentication parameter.

18. The second electronic device according to claim 12, characterized in that, When the program instructions are executed by the processor, the second electronic device also performs the following steps: The second electronic device derives a second service key based on the master key, and uses the second service key to encrypt the account and password of the second service to obtain the ciphertext of the second service data; The second electronic device sends the encrypted second service data to the second server so that the second server can save the encrypted second service data.

19. The second electronic device according to claim 11, characterized in that, When the program instructions are executed by the processor, the second electronic device also performs the following steps: The second electronic device obtains the first business data ciphertext from the second server; The second electronic device derives the first service key based on the master key; The second electronic device uses the first service key to decrypt the encrypted first service data to obtain the account password information for the first service.

20. A computer-readable storage medium comprising a computer program, characterized in that, When the computer program is run on the electronic device, it causes the second electronic device to perform the data protection method as described in any one of claims 1-10.

Citation Information

Patent Citations

  • Data protection method and electronic equipment

    CN113609498A

  • Combined Authorization Process

    US20170012959A1