A method and system for switching operation modes of an intelligent terminal
By evaluating the security factor of the security project of the smart terminal and pre-configuring multiple security modes, combining location, network, operation and environmental data to dynamically switch the security mode, the problem that existing smart terminal security measures cannot fully cover multiple potential threats is solved, and efficient, flexible and precise security protection of smart terminals is achieved.
Patent Information
- Application Number
- CN202510187636.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-20
AI Technical Summary
The security measures of existing smart terminals cannot fully cover multiple potential security threats, and most security policies are static and cannot adapt to changing usage environments and potential threats.
By evaluating the security factors of security items involving financial and privacy in smart terminals, pre-configuring multiple security modes, and dynamically switching the security modes based on location data, network data, operation data and environmental data, and implementing corresponding security measures.
It significantly improves the security of smart terminals, can effectively prevent unauthorized access and malicious behavior, provides flexible and accurate security protection, and ensures that the device can obtain the best security guarantee in various application scenarios.
Smart Images

Figure CN119670103B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of intelligent terminal security protection. Specifically, it relates to a method and system for switching the operating mode of an intelligent terminal. Background Art
[0002] With the rapid development of information technology, intelligent terminals have become an indispensable part of people's daily life and work. Whether it is a smart phone, a tablet computer or a laptop, these devices carry a large amount of personal data, including but not limited to financial information, privacy data, health records, and social network accounts. However, with the increasing power of these devices and the diversification of usage scenarios, security threats have become more and more complex and difficult to prevent. Now, intelligent terminals such as mobile phones are usually bound to various bank cards. Once the user is controlled by others, financial information and privacy data can be easily obtained through such intelligent terminals, and the user's personal wealth security and privacy security face great risks.
[0003] Existing security measures usually focus on a single level, such as password protection or simple firewall settings, and cannot comprehensively cover various potential security threats. Traditional security measures mainly rely on simple authentication methods such as password protection, fingerprint recognition or face recognition. Although these methods have improved security to a certain extent, they often can only prevent unauthorized physical access. Moreover, most of the existing security policies are static, that is, once set, they are not easy to change and cannot adapt to the changing usage environment and potential threats. Summary of the Invention
[0004] Based on the problems existing in the prior art, this application provides a method and system for switching the operating mode of an intelligent terminal. The specific solutions are as follows:
[0005] A method for switching the operating mode of an intelligent terminal includes the following:
[0006] Evaluate the security coefficient of the intelligent terminal in the normal mode according to the security items related to finance and privacy in the intelligent terminal, and pre-configure one or more security modes with higher security coefficients for the intelligent terminal, and each security mode is provided with exclusive active activation conditions, passive activation conditions and security measures;
[0007] Obtain first information including location data and network data of the intelligent terminal, and judge whether the intelligent terminal meets the active activation condition of any security mode based on the first information:
[0008] If so, switch the intelligent terminal to the security mode corresponding to the active activation condition; if not, monitor the unlocking process of the intelligent terminal in real time, and when any passive activation condition is matched during the unlocking process, switch the intelligent terminal to the security mode corresponding to the passive activation condition;
[0009] When the smart terminal is in any security mode, obtain second information of the smart terminal including operation data and environmental data, and execute security measures corresponding to the security mode based on the second information.
[0010] In some specific embodiments, obtain security items related to finance and privacy in the smart terminal, and determine access permissions for each security item;
[0011] Construct an evaluation system for evaluating the security level of the smart terminal based on the accessible quantity and access permissions of the security items; determine the normal mode of the smart terminal, and evaluate the security coefficient of the smart terminal in the normal mode according to the evaluation system to obtain a first security coefficient;
[0012] Determine access permissions for each security item, and divide all involved access permissions into permission levels; divide the item types according to whether the security item involves privacy or finance;
[0013] Construct multiple security modes based on the permission level, item type, and accessible quantity of the security items, and the security coefficient of each security mode is higher than the first security coefficient.
[0014] In some specific embodiments, the active activation conditions include: being connected to a preset network and being located at a preset position;
[0015] The passive activation conditions include: detecting multiple unlocking attempts within a preset time, restarting or shutting down multiple times within a preset time, unlocking with a preset non - habitual password, and pressing a preset button in a preset pressing manner.
[0016] In some specific embodiments, when unlocking with a preset non - habitual password, it specifically includes:
[0017] The smart terminal is preset with multiple locking modes, and each locking mode corresponds to a non - habitual password and a security mode;
[0018] During the unlocking process, when it is recognized that the smart terminal is unlocked with a non - habitual password, judge the locking mode corresponding to the non - habitual password to obtain a first locking mode;
[0019] After confirmation, switch the smart terminal to the security mode corresponding to the first locking mode.
[0020] In some specific embodiments, it further includes:
[0021] Obtain the historical operation data of the same user on the smart terminal, and analyze the user's operation habits from the historical operation data. The operation habits include data input methods and input speeds, access frequencies and access habits of security items, and holding postures of the smart terminal.
[0022] When the smart terminal is in any security mode, obtain the operation data of the user on the smart terminal, and analyze whether the operation data conforms to the user's operation habits: if not, execute the security measures corresponding to the security mode.
[0023] In some specific embodiments, it further includes:
[0024] When the smart terminal is in any security mode, regard the security items allowed to be accessed in this security mode as non-restricted access items, and regard the security items not allowed to be accessed as restricted access items.
[0025] Obtain the operation data of the current user on the smart terminal, and evaluate the access intentions of the current user for financial and privacy security items respectively by analyzing the access times of each restricted access item and non-restricted access item in the operation data to obtain a first access intention and a second access intention.
[0026] Judge whether to incorporate the non-restricted access items of the financial category in this security mode into the restricted access items according to the first access intention, and judge whether to incorporate the non-restricted access items of the privacy category in this security mode into the restricted access items according to the second access intention.
[0027] In some specific embodiments, regard the total access times of each restricted access item in the operation data as the first total number, and regard the total access times of each non-restricted access item in the operation data as the second total number.
[0028] Calculate the proportion of the access times of the restricted access items of the financial category in the operation data to the first total number to obtain a financial restriction ratio, calculate the proportion of the access times of the non-restricted access items of the financial category in the operation data to the second total number to obtain a financial non-restriction ratio, and evaluate the first access intention according to the financial restriction ratio and the financial non-restriction ratio.
[0029] Calculate the proportion of the access times of the restricted access items of the privacy category in the operation data to the first total number to obtain a privacy restriction ratio, calculate the proportion of the access times of the non-restricted access items of the privacy category in the operation data to the second total number to obtain a privacy non-restriction ratio, and evaluate the second access intention according to the privacy restriction ratio and the privacy non-restriction ratio.
[0030] In some specific embodiments, if the difference between the financial restriction ratio and the financial non - restriction ratio in the first access intention is greater than a preset difference, the non - restricted access items of the financial category in this security mode are incorporated into the restricted access items;
[0031] If the difference between the privacy restriction ratio and the privacy non - restriction ratio in the second access intention is greater than a preset difference, the non - restricted access items of the privacy category in this security mode are incorporated into the restricted access items.
[0032] In some specific embodiments, the operation data includes the operation behavior of the user on the intelligent terminal;
[0033] The environmental data includes the geographical location and residence time where the intelligent terminal is currently located, the image information and sound information around the intelligent terminal, and the weather information of the location where it is located.
[0034] An operation mode switching system for an intelligent terminal includes the following:
[0035] A pre - configuration unit for evaluating the security coefficient of the intelligent terminal in the normal mode according to the security items related to the financial category and the privacy category, and pre - configuring one or more security modes with higher security coefficients for the intelligent terminal. Each security mode is provided with exclusive active activation conditions, passive activation conditions, and security measures;
[0036] A mode switching unit for obtaining first information of the intelligent terminal including location data and network data, and judging whether the intelligent terminal meets the active activation condition of any security mode based on the first information:
[0037] If so, the intelligent terminal is switched to the security mode corresponding to the active activation condition; if not, the unlocking process of the intelligent terminal is monitored in real time, and when any passive activation condition is matched during the unlocking process, the intelligent terminal is switched to the security mode corresponding to the passive activation condition;
[0038] A security mode unit for obtaining second information of the intelligent terminal including operation data and environmental data when the intelligent terminal is in any security mode, and executing the security measures corresponding to this security mode based on the second information.
[0039] Beneficial effects: The present application proposes a method and system for switching the operating mode of an intelligent terminal. Through multi-level security mode configuration, dynamic adjustment mechanism, personalized protection, and comprehensive environmental perception ability, the security and user experience of the intelligent terminal are significantly improved. It can not only effectively prevent unauthorized access and malicious behaviors, but also provide flexible and accurate security protection according to the actual needs of users, ensuring that the device can obtain the best security guarantee in various application scenarios. By evaluating the security factor of the intelligent terminal in the normal mode and pre-configuring multiple security modes with higher security factors, multi-level security protection is provided. Different security modes correspond to different active activation conditions, passive activation conditions, and security measures to ensure that the device can obtain appropriate protection in various situations. It can monitor the user's operation data and environmental data in real time, identify abnormal behaviors, and automatically switch to the corresponding security mode. For example, when multiple unlocking attempts are detected or a preset non-customary password is used for unlocking, the system will immediately take more stringent measures to prevent unauthorized access. By analyzing the user's historical operation data, extracting the user's operation habits, and automatically executing corresponding security measures when the current operation data does not conform to the user's habits, this personalized protection mechanism can better adapt to the actual usage scenarios of users and provide accurate security protection. According to the user's access intention, the system can dynamically adjust the access permissions of financial and privacy security items. By constructing a security evaluation system based on the accessible quantity and access permissions of security items, the system can quantitatively evaluate the security factor of the intelligent terminal in different modes. This provides a scientific basis for subsequent security mode configuration and adjustment, ensuring the reliability and effectiveness of the system. The system can dynamically adjust the preset difference and other key parameters by continuously collecting user feedback and the latest statistical data to achieve continuous optimization. This data-driven decision support mechanism enables the system to continuously improve with changes in usage conditions and always maintain the best security performance.
[0040] To make the above objects, features, and advantages of the present application more obvious and understandable, the following specifically enumerates preferred embodiments and, in conjunction with the accompanying drawings, makes the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0042] Figure 1 It is a schematic flowchart of the method for switching the operating mode of the present application;
[0043] Figure 2It is a schematic diagram of the principle of the operation mode switching method of this application;
[0044] Figure 3 It is a schematic diagram of the principle of the first access intention of this application;
[0045] Figure 4 It is a schematic diagram of the principle of the first access intention of this application;
[0046] Figure 5 It is a schematic diagram of the system module for operation mode switching of this application.
[0047] Reference numerals: 1 - Pre - configuration unit; 2 - Mode switching unit; 3 - Security mode unit. Detailed implementation manners
[0048] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of this application.
[0049] This application proposes an operation mode switching method for an intelligent terminal. By comprehensively evaluating the security items related to finance and privacy in the intelligent terminal and pre - configuring multiple security modes with higher security coefficients based on this, the security of the intelligent terminal when processing sensitive information is significantly improved. The flow schematic diagram of the operation mode switching method of the intelligent terminal is as shown in the appendix Figure 1 as shown, and the principle is as shown in the appendix Figure 2 as shown. The specific solutions are as follows:
[0050] An operation mode switching method for an intelligent terminal includes the following:
[0051] 101. Evaluate the security coefficient of the intelligent terminal in the normal mode according to the security items related to finance and privacy in the intelligent terminal, and pre - configure one or more security modes with higher security coefficients for the intelligent terminal. Each security mode is provided with exclusive active activation conditions, passive activation conditions, and security measures;
[0052] 102. Obtain the first information of the intelligent terminal including location data and network data, and judge whether the intelligent terminal meets the active activation condition of any security mode based on the first information: if so, switch the intelligent terminal to the security mode corresponding to the active activation condition; if not, monitor the unlocking process of the intelligent terminal in real - time, and when any passive activation condition is matched during the unlocking process, switch the intelligent terminal to the security mode corresponding to the passive activation condition;
[0053] 103. When the smart terminal is in any security mode, obtain second information of the smart terminal including operation data and environmental data, and execute security measures corresponding to the security mode based on the second information.
[0054] This application provides a method for switching the operating mode of a smart terminal, mainly used to enhance the security of the smart terminal when processing financial and privacy information. This method is achieved by evaluating the security factor of the smart terminal in the normal mode and pre-configuring one or more security modes with higher security factors based on this. These security modes are automatically switched according to different active activation conditions or passive activation conditions. Among them, the smart terminal includes portable terminal devices such as wearable devices, mobile phones, tablet computers, and laptop computers, and such devices involve user personal privacy and some property information.
[0055] In this application, the security mode is based on security items. The security items can be specific software or relevant information in the software, such as favorite information, browsing information, etc. When entering the security mode, the smart terminal will only display information such as software allowed to be accessed in this mode, so as to achieve the purpose of privacy protection and property protection. For example, in a high-level security mode, security items such as the bank APP on the smart phone are not displayed or not allowed to be accessed, and security items containing privacy information such as the photo album and social software are not displayed or not allowed to be accessed.
[0056] Step 101 is the basis of the entire method for switching the operating mode of the smart terminal. Its core lies in evaluating the security factor of the smart terminal in the normal mode and pre-configuring one or more security modes with higher security factors.
[0057] In this application, the smart terminal needs to have certain capabilities, including:
[0058] Network connection ability: Connect to the Internet through Wi-Fi, cellular network, etc.
[0059] Multitasking: Be able to run multiple applications simultaneously and process different types of tasks.
[0060] User interface: Provide a graphical user interface (GUI) for easy user operation.
[0061] Sensor integration: Built-in multiple sensors (such as GPS, accelerometer, gyroscope, etc.) for obtaining environmental information.
[0062] Microphone and camera: Used to obtain audio and video data around the terminal.
[0063] First, the system needs to identify and evaluate security items on the smart terminal that involve finance (such as banking applications, payment platforms, etc.) and privacy (such as address books, text messages, photos, etc.). These items usually contain the most sensitive information of users, so their security needs to be particularly concerned. By clarifying which items belong to the finance and privacy categories, the system can specifically apply more stringent security protection to these high-risk items.
[0064] Among them, security items refer to the types of data stored or processed on the smart terminal and their related access control mechanisms. These items usually involve users' financial information and personal privacy, so special security protection measures are required. Specifically, security items can be classified into the following categories:
[0065] I. Finance-related security items
[0066] Banking applications: such as Alipay, WeChat Pay, and the official apps of major banks.
[0067] Investment and financial management platforms: such as stock trading software and fund trading platforms.
[0068] Electronic wallets: such as Apple Pay and Google Wallet.
[0069] II. Privacy-related security items
[0070] Address book: contains information such as contact names, phone numbers, and email addresses.
[0071] Text messages and instant messaging records: such as text messages, WhatsApp, and WeChat chat records.
[0072] Personal photos and videos: private pictures and videos stored in the photo album.
[0073] Health data: such as the number of steps and heart rate recorded by fitness trackers.
[0074] To protect these security items, the system usually sets access permissions to restrict which applications or users can access this data under what conditions. For example: Password protection, requiring the input of a password or fingerprint to access certain sensitive applications. Encrypted storage, using encryption algorithms such as AES to encrypt and store sensitive data. Permission management, allocating different access permissions according to the needs of the application, such as read-only permissions or full access permissions.
[0075] Based on the above-identified security items, the system will evaluate the overall security factor of the smart terminal in the normal mode. This includes, but is not limited to, aspects such as access permission settings, encryption measures, network connection security, etc. The evaluated security factor can help determine the security level of the current smart terminal under normal use, providing a basis for further enhancing the security level. According to the evaluated security factor, the system pre-configures one or more security modes with higher security factors for the smart terminal.
[0076] Among them, the security mode is an operating state of the smart terminal, which improves the security of the smart terminal by enabling specific security measures. Each security mode has exclusive active activation conditions, passive activation conditions, and corresponding security measures to deal with different levels of security threats. The smart terminal, security items, and security modes are an interrelated whole. The smart terminal, as the carrier, bears various security items; while the security mode is a security strategy dynamically adjusted according to different usage scenarios and potential threats. This design not only improves the security of the smart terminal but also effectively responds to various potential security threats without affecting the user experience.
[0077] Each security mode has specific security measures and activation conditions. Pre-configuring multiple security modes enables the smart terminal to automatically adjust to the most suitable security level according to different usage scenarios and potential threats, thereby enhancing the overall security. Each security mode has exclusive active activation conditions, which are usually triggered based on the user's operation behavior or environmental changes. For example, when the smart terminal connects to a risky network, the high-security mode is automatically activated; when the smart terminal connects to the home network, the security mode is turned off or a security mode with a lower security factor is started. Similarly, by detecting the location where the smart terminal is located, the security mode is automatically switched. For example, when the smart terminal is at home, the medium-security mode is activated; while in a public place, the high-security mode is activated. By setting clear active activation conditions, the system can quickly switch to the corresponding security mode when detecting a specific environment or behavior, and timely respond to potential threats.
[0078] In addition to the active activation conditions, the system also sets some passive activation conditions for automatically switching to a higher-level security mode when detecting abnormal behaviors. For example, if the password is entered incorrectly three times in a row, the high-security mode is automatically activated. If the smart terminal restarts or shuts down multiple times within a short period, the high-security mode is activated. The passive activation conditions can take immediate measures when detecting abnormal operations to prevent unauthorized access or malicious attacks. By setting the active and passive activation conditions, a dynamic response mechanism is achieved, enhancing the adaptability and response speed of the system.
[0079] Each security mode is equipped with exclusive security measures designed to further enhance the security of intelligent terminals. Specific security measures can provide effective protection means for different levels of security requirements, ensuring that user data can be fully protected in various situations.
[0080] Regarding the evaluation of the security coefficient and the construction of security modes. In some specific embodiments, security items related to finance and privacy in the intelligent terminal are obtained, and the access permissions for each security item are determined; an evaluation system for evaluating the security level of the intelligent terminal is constructed based on the accessible quantity and access permissions of the security items; the normal mode of the intelligent terminal is determined, and the security coefficient of the intelligent terminal in the normal mode is evaluated according to the evaluation system to obtain the first security coefficient; the access permissions for all security items are determined, and the access permissions are divided into different permission levels; the security items are divided into different item types according to whether they involve privacy or finance; multiple security modes are constructed based on the permission level, item type, and accessible quantity of the security items, and the security coefficient of each security mode is higher than the first security coefficient.
[0081] First, it is necessary to identify all data or applications related to finance and privacy on the intelligent terminal, and set specific access permissions for each security item, such as read, write, modify, delete, etc. By scanning the application programs and the data they store on the intelligent terminal, mark which ones belong to security items related to finance or privacy. For example, it can be achieved through API calls or file system scanning. Configure these permissions in the settings interface of the intelligent terminal, or manage them dynamically through the application programming interface (API).
[0082] Construct an evaluation system and evaluate the security coefficient in the normal mode. Based on the accessible quantity and access permissions of the security items, construct an evaluation system to quantify the security level of the intelligent terminal. Use this evaluation system to evaluate the overall security coefficient of the intelligent terminal in the normal mode to obtain the first security coefficient. Define the scoring criteria and score according to the access permissions of each security item. For example, use a 10 - point scale, and each item is scored according to the security of its permissions. Aggregate the scores of all items, calculate the total score, and divide by the full score to obtain the security coefficient. For example, if the total score is 35 points and the full score is 50 points, the security coefficient is 70%.
[0083] All items involving access permissions are divided into different levels according to their security levels. For example, they are divided into three levels: low, medium, and high. Items that require two - factor authentication are of high level, items that only require password verification are of medium level, and items that do not require verification are of low level. According to the item content, classify them as finance - related or privacy - related. For example, banking applications and payment platforms are finance - related, and address books and photo albums are privacy - related.
[0084] Exemplarily, regarding the security mode as follows:
[0085] High Security Mode:
[0086] Permission Level: Two-factor authentication is required for all security items.
[0087] Project Type: The highest level of protection is enabled for all financial and privacy-related projects.
[0088] Security Coefficient: Assume it is 85%.
[0089] Active Activation Conditions: Connected to the company's internal network and located in the office.
[0090] Passive Activation Conditions: Multiple failed unlock attempts, frequent restarts or shutdowns.
[0091] Security Measures: Enable two-factor authentication, restrict external device connections, and enforce encryption for all communications.
[0092] Medium Security Mode:
[0093] Permission Level: Fingerprint or facial recognition is required for some projects, and password verification is required for other projects.
[0094] Project Type: Higher protection is enabled for financial projects, and medium protection is enabled for privacy projects.
[0095] Security Coefficient: Assume it is 80%.
[0096] Active Activation Conditions: Connected to the home Wi-Fi network and located at home.
[0097] Passive Activation Conditions: Detection of abnormal behavior (such as frequent switching between applications in a short period of time).
[0098] Security Measures: Enable fingerprint recognition, restrict background activities of certain applications, and perform regular data backups.
[0099] Low Security Mode:
[0100] Permission Level: Most projects only require password verification, and some projects do not require verification.
[0101] Project Type: Basic protection is enabled for financial projects, and lower protection is enabled for privacy projects.
[0102] Security Coefficient: Assume it is 75%.
[0103] Active Activation Conditions: Connected to a public Wi-Fi network and located in a public place.
[0104] Passive Activation Conditions: The device has not been used for a long time (such as no operation for more than 30 minutes).
[0105] Security measures: Enable password protection, automatic screen locking, and prompt users to pay attention to network security.
[0106] Step 102 is a key part of the entire intelligent terminal operation mode switching method, mainly involving obtaining the first information of the intelligent terminal (such as location data and network data), and judging whether it meets the active activation conditions of any security mode based on this information. If the conditions are met, switch to the corresponding security mode; otherwise, monitor the unlocking process in real time and perform mode switching when the passive activation conditions are matched.
[0107] The first information refers to various data related to the current state of the intelligent terminal, mainly including location data and network data. Location data can be location information provided by GPS coordinates, Wi-Fi positioning, or Bluetooth beacons, etc. Network data includes the current connected network type (such as Wi-Fi, 4G / 5G) and its specific SSID (Service Set Identifier), etc.
[0108] The active activation condition refers to the condition for automatically activating the corresponding security mode when the intelligent terminal is in certain specific environments or connected to certain specific networks. For example, automatically activate the high-security mode when connected to the company's internal network. Compare the obtained first information with the active activation conditions of each security mode to judge whether any condition is met. If the active activation condition of a certain security mode is met, immediately switch to that security mode. For example, when the intelligent terminal is connected to the Wi-Fi network named "company" and the location data shows that the user is located in the company's office, the system will automatically activate the high-security mode. After the system detects that a certain security mode's active activation condition is met, it triggers mode switching. During the switching process, the system will load all configurations and security measures in this security mode and apply them to the intelligent terminal. At the same time, the system may prompt the user that the current has switched to the new security mode.
[0109] The passive activation condition refers to the condition for automatically activating the corresponding security mode when certain abnormal behaviors or operations are detected during the use of the intelligent terminal. For example, multiple failed unlocking attempts, frequent restarts or shutdowns, etc. When the intelligent terminal does not meet any active activation conditions, the system will continue to monitor the user's operation behavior, especially the unlocking process. The monitored content can include the number of unlocking times, the unlocking time interval, the number of times of entering the wrong password, etc. If it is found during the monitoring process that the user's behavior meets the passive activation condition of a certain security mode, immediately switch to that security mode. For example, if the user enters the wrong password three times in a row, the high-security mode will be automatically activated, and the user will be required to perform additional identity verification (such as fingerprint recognition or facial recognition).
[0110] Step 103 is a key link in the intelligent terminal operation mode switching method, mainly involving obtaining second information including operation data and environmental data when the intelligent terminal is in a certain security mode, and performing corresponding security measures based on this information. Dynamically adjust the security measures in the current security mode according to the operation data and environmental data obtained in real time to ensure that the intelligent terminal is always in the optimal security state. Automatically adjust the security level without affecting the normal use of users, enhance the security of the intelligent terminal, and reduce potential security threats. Provide personalized security protection strategies according to the behavior habits and usage scenarios of different users. Timely respond to potential security threats through real-time monitoring and dynamic adjustment to protect users' financial and privacy data. Enable or disable certain security measures according to actual needs to avoid unnecessary resource consumption and improve the overall performance of the intelligent terminal.
[0111] Among them, the second information refers to various data related to the current operation behavior and environment of the intelligent terminal, mainly including operation data and environmental data. In some specific embodiments, the operation data includes the operation behavior of the user on the intelligent terminal, such as the number of unlock attempts, the number of incorrect password inputs, the timestamps of application startup and shutdown, the situation of the user frequently switching applications, the restart frequency of the intelligent terminal, and the shutdown frequency. In practical applications, the API interface provided by the operating system is used to capture the operation behavior of the user, record the results of each unlock attempt, the timestamps of application startup and shutdown, the number of incorrect passwords entered by the user, etc. The environmental data includes the geographical location where the intelligent terminal is currently located and the residence time, the image information and sound information around the intelligent terminal, and the weather information of the geographical location. The current position coordinates are obtained through the GPS module, and the residence time of the intelligent terminal at this position is recorded. The image information around the intelligent terminal is captured through the camera, and computer vision technology is used to analyze these images to identify potential security threats (such as whether there are unauthorized people approaching the intelligent terminal). The environmental sound around the intelligent terminal is captured through the microphone, and audio analysis technology can be used to detect abnormal sounds (such as alarm sounds, noisy sounds). The weather information (such as temperature, humidity, weather conditions) of the location where the intelligent terminal is located is obtained through a network request.
[0112] Each security mode has corresponding security measures to deal with different security threats. For example, the high-security mode may require two-factor authentication, restrict external smart terminal connections, enforce encryption for all communications, etc.; the medium-security mode may enable fingerprint recognition, restrict background activities of certain applications, etc. The system matches the second information obtained with the security measures of the current security mode to determine whether to enable or adjust certain security measures. If potential security threats are detected (such as multiple failed unlock attempts or abnormal sounds in the vicinity), the corresponding advanced security measures (such as two-factor authentication or locking the screen) will be immediately enabled. Based on the data obtained in real time, the system can dynamically adjust the security measures in the current security mode. For example, in the low-security mode, if abnormal sounds are detected around the smart terminal, the system can temporarily upgrade to the medium-security mode and enable more security measures.
[0113] For example:
[0114] High-security mode: When it is detected that the user enters the wrong password three times in a row, the system will automatically enable two-factor authentication and prompt the user for additional identity verification (such as fingerprint recognition or facial recognition). If there are abnormal sounds in the vicinity, the system will also temporarily lock the screen and send a notification to the administrator.
[0115] Medium-security mode: When it is detected that the user frequently switches applications within a short period of time, the system will temporarily restrict the background activities of certain applications and enable the fingerprint recognition function. If the surrounding images show a stranger approaching the smart terminal, the system will prompt the user to pay attention to security and temporarily lock the screen.
[0116] Low-security mode: When it is detected that the smart terminal has not been used for a long time (such as not being operated for more than 30 minutes), the system will automatically lock the screen and prompt the user to pay attention to network security. If the surrounding sounds are abnormal (such as an alarm sound), the system will temporarily upgrade to the medium-security mode and enable more security measures.
[0117] The core of step 103 lies in dynamically adjusting the security measures in the current security mode by obtaining the operation data and environmental data (i.e., the second information) of the smart terminal in real time, ensuring that the smart terminal is always in an optimal security state. This method not only improves the security of the smart terminal but also effectively responds to various potential security threats without affecting the user experience. Each security mode has clear security measures and a dynamic adjustment mechanism to ensure appropriate protection measures in different situations. This method realizes dynamic adaptability and multi-level protection, significantly enhancing the overall security of the smart terminal.
[0118] In some specific embodiments, the active activation conditions include: being connected to a preset network and being located at a preset location; the passive activation conditions include: detecting multiple unlocking attempts within a preset time, restarting or shutting down multiple times within a preset time, unlocking with a preset non-conventional password, and pressing a preset button in a preset pressing manner.
[0119] The preset network is user-defined and can be a secure network or an insecure network. In practical applications, the preset network can be a strange and unauthenticated external network, such as a public place network, which may pose a risk of reading user data. When it is detected that the intelligent terminal accesses such a network with relatively low security, it can be switched to a security mode with a higher security factor. In addition, the preset network can also be maintained by a trusted organization or individual and has relatively high security. For example, an internal company network may be equipped with security facilities such as firewalls and intrusion detection systems, which can effectively prevent external attacks. In the preset network environment, the intelligent terminal can more easily access enterprise resources and services, and at the same time, it can also better control the behavior and permissions of the intelligent terminal. Similarly, the preset location is also user-defined and can be a specific place, such as a company, a home, a public place, etc.
[0120] The passive activation condition refers to that during the use of the intelligent terminal, by real-time monitoring of the user's operation behavior and environmental data, when certain abnormal behaviors or potential security threats are detected, it automatically switches to the corresponding security mode. In some embodiments, when the passive activation condition and / or the active activation condition are met, the intelligent terminal enters the security mode without any prompt. The passive activation condition is a way for the user to imply the intelligent terminal to enter the security mode with a special password or a special operation form, and different fingerprints, different passwords, different expressions, pressing a specific button in a specific manner, etc. can be used. For example, pressing the power key and the volume key once, multiple times, or for a long time to control the intelligent terminal to enter the security mode.
[0121] The non-conventional password refers to a password or an uncommon password combination that the user does not often use. Usually, the user will set a common password for daily unlocking of the intelligent terminal. A set of non-conventional passwords pre-configured by the user, when these passwords are used to unlock the intelligent terminal, the system considers that there may be a security threat. If the user uses an infrequently used password to unlock, it may indicate that the intelligent terminal has been stolen or there are other security risks. In this application, the password form of the non-conventional password includes character passwords, graphic passwords, or biometric passwords.
[0122] Under normal circumstances, users can conveniently unlock the smart terminal with a commonly used password and enjoy a convenient operation experience. Only when abnormal behavior (such as using a non-customary password) is detected will the system automatically take more stringent measures to ensure the security of the smart terminal. In some specific embodiments, when unlocking with a preset non-customary password, it specifically includes: multiple locking modes are preset in the smart terminal, and each locking mode corresponds to a non-customary password and a security mode; during the unlocking process, when it is recognized that the smart terminal is unlocked with a non-customary password, the locking mode corresponding to the non-customary password is judged to obtain the first locking mode; after confirmation, the smart terminal is switched to the security mode corresponding to the first locking mode. Each locking mode has one or more pre-configured non-customary passwords, which are different from the user's commonly used password. When the user unlocks the smart terminal with a non-customary password, the system can recognize the password and automatically switch to the corresponding security mode according to its corresponding locking mode. Unlocking with a non-customary password usually means that the smart terminal may be in an abnormal state (such as being stolen or used by an unauthorized person), so higher security measures are needed to protect the smart terminal and data. Different locking modes can provide different levels of security protection to adapt to different usage scenarios and potential threats. Among them, the confirmation method can be set according to the actual situation, which can be a prompt box prompt or entering the same or different password again.
[0123] By presetting multiple locking modes, each mode corresponding to different security measures and security levels, the system can provide appropriate protection according to the specific situation. For example, the high-security mode may include two-factor authentication, restricting external smart terminal connections, forcing encryption of all communications, etc.; the medium-security mode may enable fingerprint recognition, restricting background activities of certain applications, etc.; the low-security mode may only enable basic password protection and automatic screen locking functions. Users can preset different locking modes and non-customary passwords according to their own needs and usage scenarios. For example, use the commonly used password to unlock the smart terminal at home, and use the preset non-customary password to unlock the smart terminal in the company office or when going out. This can flexibly respond to various potential security threats in different environments. Each locking mode has specific security measures, and users can choose the appropriate locking mode according to actual needs. For example, when users expect that the smart terminal may face higher security risks (such as using it in public places), they can choose to use a non-customary password to trigger a higher level of security protection.
[0124] In some specific embodiments, it further includes: obtaining the historical operation data of the same user on the smart terminal, analyzing the user's operation habits from the historical operation data, where the operation habits include data input methods and input speeds, access frequencies and access habits of security items, and the holding postures of the smart terminal; when the smart terminal is in any security mode, obtaining the operation data of the user on the smart terminal and parsing whether the operation data conforms to the user's operation habits: if not, executing the security measures corresponding to the security mode. By analyzing the user's operation habits, the system can automatically execute corresponding security measures when detecting abnormal operations, preventing unauthorized access or malicious behaviors. According to the user's actual operation habits, the system can provide more precise security protection, adapting to different usage scenarios and potential threats.
[0125] The system extracts the user's operation habits, such as data input methods and input speeds, access frequencies and access habits of security items, and the holding postures of the smart terminal, by obtaining and analyzing the historical operation data of the same user on the smart terminal. Data input methods and input speeds, such as typing speed, touch screen click frequency; access frequencies and access habits of security items, such as the access frequency of the banking App, login time; the holding postures of the smart terminal, such as the holding method reflected by sensor data. The user's operation habits are extracted. For example: the user usually enters passwords at a relatively fast speed, the user accesses financial applications at a fixed time every day, and the user is used to operating the smart terminal with one hand using the left hand. The system stores these operation habits as a habit model for subsequent comparison and anomaly detection.
[0126] When the smart terminal is in any security mode, the system will obtain the user's operation data in real time and compare it with the operation habits analyzed previously. If the current operation data does not conform to the user's operation habits, the system will judge it as an abnormal behavior and automatically execute the security measures corresponding to the security mode. In some cases, the system may require the user to perform additional identity verification (such as fingerprint recognition or facial recognition) to confirm the identity. When the system detects that the current operation does not conform to the user's habits, it will automatically enable a higher security level to prevent the smart terminal from being accessed by unauthorized personnel. For example, the user's smart terminal is suddenly lost, and the person who picks up the smart terminal tries to unlock it. Since their operation methods (such as slower input speed, inconsistent holding posture) do not match the user's habits, the system detects this abnormal behavior, immediately activates the high-security mode, requires additional identity verification (such as fingerprint recognition or facial recognition), and enables other advanced security measures (such as restricting external smart terminal connections, forcing encryption of all communications).
[0127] In some specific embodiments, it further includes: when the intelligent terminal is in any security mode, taking the security items allowed to be accessed in this security mode as unrestricted access items, and taking the security items not allowed to be accessed as restricted access items; obtaining the operation data of the current user on the intelligent terminal, and evaluating the access intentions of the current user for financial and privacy security items respectively by analyzing the access times of each restricted access item and unrestricted access item in the operation data, so as to obtain a first access intention and a second access intention; judging whether to include the unrestricted access items of the financial category in the security mode into the restricted access items according to the first access intention, and judging whether to include the unrestricted access items of the privacy category in the security mode into the restricted access items according to the second access intention. By analyzing the operation data of the user, the system can evaluate the access intention of the user in real time and dynamically adjust the access permissions of financial and privacy security items according to these intentions. In this way, a more flexible user experience can be provided while ensuring security. According to the actual access behavior of the user, the system can more accurately judge which items need to further restrict access, so as to provide personalized security protection. When an abnormal access intention is detected, the system will automatically take measures to include some unrestricted access items into the restricted access items to ensure the security of the intelligent terminal. This not only enhances the security protection ability of the intelligent terminal, but also can provide personalized security measures according to actual needs to adapt to different usage scenarios and potential threats.
[0128] The system sets clear financial and privacy security items for each security mode and classifies them into restricted access items and unrestricted access items. The security items allowed to be accessed are taken as unrestricted access items, and the security items not allowed to be accessed are taken as restricted access items. Unrestricted access items: Security items that users can freely access, such as viewing weather information, browsing news, etc. Restricted access items: Security items that users need additional verification or cannot access, such as bank account information, personal information, etc. When entering a certain security mode, the system initializes the restricted access items and unrestricted access items according to preset rules.
[0129] The system collects the user's operation data in real time, including but not limited to: the number of times of accessing financial security items, the number of times of accessing privacy security items, the user's operation time and frequency, etc. Compare the current operation data with the previously set restricted access items and unrestricted access items, and count the number of times the user accesses each item. The system evaluates the access intentions of the current user for financial and privacy security items respectively. The first access intention: the user's access intention for financial security items. For example, frequently accessing bank account information may indicate that the user has strong financial needs. The second access intention: the user's access intention for privacy security items. For example, frequently accessing personal information may indicate that the user has strong privacy needs. Thresholds or other criteria can be preset to determine whether the user's access intention is abnormal. For example, if the user frequently accesses multiple financial security items in a short period of time, it may indicate a potential security threat.
[0130] Based on the evaluated first access intention and second access intention, the system decides whether to include some unrestricted access items in the restricted access items. If the system detects that the user's access intention for financial security items is abnormal (such as frequent access), it will include some originally allowed financial items in the restricted access items. If the system detects that the user's access intention for privacy security items is abnormal (such as frequent access), it will include some originally allowed privacy items in the restricted access items. After confirmation, the system updates the list of restricted access items and unrestricted access items in the current security mode and notifies the user of the corresponding changes. When the system detects that the user's access intention is abnormal, it will automatically include some unrestricted access items in the restricted access items to prevent the smart terminal from being accessed by unauthorized personnel for sensitive information. For example, when the user is working in the company office, the smart terminal is suddenly lost. The person who picks up the smart terminal tries to frequently access multiple financial security items (such as bank account information). The system detects this abnormal behavior and immediately removes these financial items from the unrestricted access items and changes them to restricted access items, requiring additional authentication (such as fingerprint recognition or facial recognition) to access.
[0131] In some specific embodiments, the total number of accesses to each restricted access item in the operation data is used as the first total number, and the total number of accesses to each non-restricted access item in the operation data is used as the second total number; calculate the proportion of the number of accesses to the restricted access items in the financial category in the operation data to the first total number to obtain the financial restriction ratio, calculate the proportion of the number of accesses to the non-restricted access items in the financial category in the operation data to the second total number to obtain the financial non-restriction ratio, and evaluate the first access intention based on the financial restriction ratio and the financial non-restriction ratio; calculate the proportion of the number of accesses to the restricted access items in the privacy category in the operation data to the first total number to obtain the privacy restriction ratio, calculate the proportion of the number of accesses to the non-restricted access items in the privacy category in the operation data to the second total number to obtain the privacy non-restriction ratio, and evaluate the second access intention based on the privacy restriction ratio and the privacy non-restriction ratio. The principle of the first access intention is as shown in Appendix Figure 3 as shown, and the principle of the second access intention is as shown in Appendix Figure 4 as shown.
[0132] The system classifies the user's operation data into the number of accesses to restricted access items and non-restricted access items, and further subdivides them into security items in the financial category and the privacy category. By calculating the proportion of the number of accesses to restricted access items and non-restricted access items in the financial category and the privacy category to the total number of accesses, the system evaluates the user's access intention. Based on the calculated access intentions (the first access intention and the second access intention), the system decides whether to adjust the access permissions of certain items to enhance security. When the system detects that the user's access intention is abnormal, it will automatically include some non-restricted access items in the restricted access items to prevent the smart terminal from being accessed by unauthorized personnel for sensitive information.
[0133] In some specific embodiments, if the difference between the financial restriction ratio and the financial non-restriction ratio in the first access intention is greater than the preset difference, then the non-restricted access items in the financial category in this security mode are included in the restricted access items; if the difference between the privacy restriction ratio and the privacy non-restriction ratio in the second access intention is greater than the preset difference, then the non-restricted access items in the privacy category in this security mode are included in the restricted access items. The preset difference is a key threshold used by the system to determine whether the user's access intention is abnormal. It determines in what circumstances the system will adjust some non-restricted access items to restricted access items.
[0134] Classification of operation data: The total number of accesses to each restricted access item in the operation data is used as the first total number. The total number of accesses to each non-restricted access item in the operation data is used as the second total number.
[0135] Ratio calculation:
[0136] Finance category: Calculate the proportion of the number of accesses to finance-restricted access items in the first total number of accesses to obtain the finance restriction ratio. Calculate the proportion of the number of accesses to finance-unrestricted access items in the second total number of accesses to obtain the finance non-restriction ratio.
[0137] Privacy category: Calculate the proportion of the number of accesses to privacy-restricted access items in the first total number of accesses to obtain the privacy restriction ratio. Calculate the proportion of the number of accesses to privacy-unrestricted access items in the second total number of accesses to obtain the privacy non-restriction ratio.
[0138] Access intention assessment: Based on the finance restriction ratio and the finance non-restriction ratio, assess the user's access intention to finance security items (the first access intention). Based on the privacy restriction ratio and the privacy non-restriction ratio, assess the user's access intention to privacy security items (the second access intention).
[0139] Dynamic access permission adjustment: Based on the first access intention, determine whether to include some finance-unrestricted access items in the restricted access items. Based on the second access intention, determine whether to include some privacy-unrestricted access items in the restricted access items.
[0140] Exemplarily, when the user is working in the company office, the smart terminal is suddenly lost. The person who picks up the smart terminal tries to access multiple finance security items (such as bank account information) frequently.
[0141] Operation data:
[0142] The first total number of accesses: The total number of accesses to all restricted access items is 50 times.
[0143] The second total number of accesses: The total number of accesses to all unrestricted access items is 100 times.
[0144] The number of accesses to finance-restricted access items: 30 times.
[0145] The number of accesses to finance-unrestricted access items: 70 times.
[0146] Calculation of the ratio:
[0147] Finance restriction ratio = 30 / 50 = 60%
[0148] Finance non-restriction ratio = 70 / 100 = 70%
[0149] Assessment of access intention:
[0150] The first access intention: Since the finance restriction ratio is relatively high (60%), it indicates that the user has strong financial needs and frequently accesses restricted items, and security measures may need to be strengthened.
[0151] The system detected that the user frequently accessed multiple financial security items and determined it as an abnormal behavior. The system automatically activates the high-security mode, requires the user to perform additional authentication (such as fingerprint recognition or facial recognition), and removes these financial items from the non-restricted access items and changes them to restricted access items to ensure the security of sensitive information.
[0152] The access permission scheme for security items based on access intent adjusts the access permissions by real-time monitoring of the user's operation data, calculating the access frequency ratios of financial and privacy restricted access items and non-restricted access items, evaluating the user's access intent, and dynamically adjusting the access permissions according to these intents. This method not only enhances the security protection ability of the smart terminal but also provides personalized security measures according to actual needs to adapt to different usage scenarios and potential threats.
[0153] The setting of the preset difference needs to consider multiple factors, including security requirements, user experience, historical data, and statistical analysis.
[0154] Based on historical data analysis: Collect a large amount of the user's operation data, including access behaviors under normal circumstances and abnormal circumstances. By analyzing this data, find the differences between normal and abnormal access behaviors. Conduct statistical analysis on the historical data, calculate the access frequency ratios and their differences of financial and privacy restricted access items and non-restricted access items. Find a reasonable difference range so that most normal access behaviors will not trigger permission adjustments, while abnormal access behaviors can be effectively identified. According to the statistical results, select a suitable difference as the preset difference. This difference should be able to minimize false alarms (i.e., normal access behaviors are wrongly determined as abnormal) while ensuring security. If the statistical results show that the difference between the financial restricted ratio and the financial non-restricted ratio of normal users usually does not exceed 5%, then the preset difference can be set to 5% or slightly higher (such as 6%) to leave a certain margin of error.
[0155] Based on risk assessment: Divide different risk levels according to different application scenarios and user groups. For example, the smart terminals of enterprise users may face higher security risks, while those of individual users are relatively lower. Set different preset differences for different risk levels. For high-risk scenarios, a lower preset difference can be set to more sensitively detect potential security threats; for low-risk scenarios, a higher preset difference can be set to reduce unnecessary permission adjustments. Example: High-risk scenario (such as enterprise users): The preset difference can be set to 3%. Low-risk scenario (such as ordinary individual users): The preset difference can be set to 8%.
[0156] In practical applications, a relatively conservative preset difference (such as 5%-10%) can be set first to ensure the stability and security of the system. This can avoid excessive false alarms or missed alarms caused by unreasonable initial settings. As the system runs for a longer time, more user data and feedback information are gradually accumulated, and the preset difference is dynamically adjusted to make it more in line with the actual usage situation, improving the accuracy of the system and the user experience. In addition to simply relying on the difference, other indicators (such as the user's geographical location, operation habits, etc.) can be combined for multi-dimensional comprehensive evaluation to improve the overall judgment ability of the system and reduce the risk of misjudgment caused by a single indicator.
[0157] This application provides a running mode switching system for an intelligent terminal, as Figure 5 shown, the system includes the following modules:
[0158] A pre-configuration unit 1, configured to evaluate the security factor of the intelligent terminal in the normal mode according to the security items related to finance and privacy in the intelligent terminal, and pre-configure one or more security modes with higher security factors for the intelligent terminal, and each security mode is provided with exclusive active activation conditions, passive activation conditions, and security measures;
[0159] A mode switching unit 2, configured to obtain first information including location data and network data of the intelligent terminal, and determine whether the intelligent terminal meets the active activation condition of any security mode based on the first information:
[0160] If so, switch the intelligent terminal to the security mode corresponding to the active activation condition; if not, monitor the unlocking process of the intelligent terminal in real time, and when any passive activation condition is matched during the unlocking process, switch the intelligent terminal to the security mode corresponding to the passive activation condition;
[0161] A security mode unit 3, configured to obtain second information including operation data and environmental data of the intelligent terminal when the intelligent terminal is in any security mode, and execute the security measures corresponding to the security mode based on the second information.
[0162] This application provides a computer program product, which includes computer instructions stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes a running mode switching method for an intelligent terminal. Applying a running mode switching method for an intelligent terminal to a computer program product is convenient for execution.
[0163] This application also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the steps of a running mode switching method for an intelligent terminal as described above.
[0164] The computer storage medium of the present application can adopt any combination of one or more computer-readable media. The computer-readable media can be computer-readable signal media or computer-readable storage media. The computer-readable storage media can be, for example, but not limited to: electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage media include: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this document, the computer-readable storage media can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, device, or component. The present application applies a method for switching the operating mode of an intelligent terminal to a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the steps of the clothing simulation method provided by the present application, which is simple, fast, easy to store, and not easily lost.
[0165] The present application proposes a method and system for switching the operating mode of an intelligent terminal. Through multi-level security mode configuration, dynamic adjustment mechanism, personalized protection, and comprehensive environmental perception ability, the security and user experience of the intelligent terminal are significantly improved. It can not only effectively prevent unauthorized access and malicious behaviors, but also provide flexible and accurate security protection according to the actual needs of users, ensuring that the device can obtain the best security guarantee in various application scenarios.
[0166] Those of ordinary skill in the art should understand that the above-mentioned modules of the present application can be implemented by a general-purpose computing system. They can be concentrated on a single computing system or distributed on a network composed of multiple computing systems. Optionally, they can be implemented with program codes executable by a computer system, so that they can be stored in a storage system and executed by the computing system, or they can be separately made into individual integrated circuit modules, or multiple modules or steps among them can be made into a single integrated circuit module to implement. In this way, the present application is not limited to any specific combination of hardware and software.
[0167] Note that the above is only a preferred embodiment of the present application and the applied technical principles. Those skilled in the art will understand that the present application is not limited to the specific embodiments here, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments only. Without departing from the concept of the present application, more other equivalent embodiments can be included, and the scope of the present application is determined by the scope of the appended claims.
[0168] The above discloses only several specific implementation scenarios of the present application. However, the present application is not limited thereto, and any changes that can be thought of by those skilled in the art should fall within the protection scope of the present application.
Claims
1. A method for switching an operation mode of an intelligent terminal, characterized in that: These include: Evaluate the security factor of the smart terminal in normal mode based on the financial and privacy security items in the smart terminal, and pre-configure one or more security modes with higher security factors for the smart terminal. Each security mode has its own active activation conditions, passive activation conditions and security measures. Acquire first information including location data and network data of the smart terminal, and determine whether the smart terminal meets the active activation condition of any security mode based on the first information: If yes, the smart terminal is switched to the security mode corresponding to the active activation condition; if no, the unlocking process of the smart terminal is monitored in real time, and when any passive activation condition is matched during the unlocking process, the smart terminal is switched to the security mode corresponding to the passive activation condition; When the smart terminal is in any security mode, obtaining second information of the smart terminal including operation data and environment data, and executing security measures corresponding to the security mode based on the second information; Wherein, when the smart terminal is in any security mode, the security items that are allowed to be accessed in the security mode are regarded as non-restricted access items, and the security items that are not allowed to be accessed are regarded as restricted access items; the operation data of the current user on the smart terminal are obtained, and the access intentions of the current user to financial and privacy security items are evaluated by parsing the number of accesses to each restricted access item and non-restricted access item in the operation data, so as to obtain a first access intention and a second access intention; according to the first access intention, it is determined whether to include the non-restricted access items of the financial category in the security mode into the restricted access items, and according to the second access intention, it is determined whether to include the non-restricted access items of the privacy category in the security mode into the restricted access items; Among them, the total number of visits to each restricted access item in the operation data is taken as the first total number, and the total number of visits to each unrestricted access item in the operation data is taken as the second total number; the proportion of the number of visits to financial restricted access items in the operation data to the first total number is calculated to obtain the financial restriction ratio, the proportion of the number of visits to financial unrestricted access items in the operation data to the second total number is calculated to obtain the financial unrestricted ratio, and the first access intention is obtained by evaluating the financial restriction ratio and the financial unrestricted ratio; the proportion of the number of visits to privacy restricted access items in the operation data to the first total number is calculated to obtain the privacy restriction ratio, the proportion of the number of visits to privacy unrestricted access items in the operation data to the second total number is calculated to obtain the privacy unrestricted ratio, and the second access intention is obtained by evaluating the privacy restriction ratio and the privacy unrestricted ratio.
2. The operation mode switching method according to claim 1, characterized in that: Obtain financial and privacy-related security items in smart terminals and determine access rights for each security item; An evaluation system for evaluating the security level of the smart terminal is established based on the accessible number and access rights of security items; Determining a normal mode of the smart terminal, and evaluating a safety factor of the smart terminal in the normal mode according to the evaluation system to obtain a first safety factor; Determine the access rights for each security project and classify all access rights into different levels; classify security projects into different types based on whether they involve privacy or finance; Multiple security modes are constructed based on the permission level, project type and the accessible number of security projects, and the safety factor of each security mode is higher than the first safety factor.
3. The operation mode switching method according to claim 1, characterized in that: The active activation conditions include: being connected to a preset network and being located at a preset location; The passive activation conditions include: detecting multiple unlocking attempts within a preset time, multiple restarts or shutdowns within a preset time, unlocking using a preset non-usual password, pressing a preset button in a preset pressing method, and pressing a preset button in a preset pressing method.
4. The operation mode switching method according to claim 3, characterized in that: When a preset non-common password is used to unlock, it includes: The smart terminal is preset with multiple lock modes, each lock mode corresponds to a non-conventional password and a security mode, and the non-conventional password includes a character password, a graphic password or a biometric password; During the unlocking process, when it is recognized that the smart terminal is unlocked with a non-usual password, the lock mode corresponding to the non-usual password is determined to obtain a first lock mode; After confirmation, the smart terminal is switched to a security mode corresponding to the first locking mode.
5. The operation mode switching method according to claim 1, characterized in that: Also includes: Acquire historical operation data of the same user on the smart terminal, and analyze the user's operation habits from the historical operation data, wherein the operation habits include data input method and input speed, access frequency and access habits of security items, and holding posture of the smart terminal; When the smart terminal is in any security mode, the operation data of the user on the smart terminal is obtained, and the operation data is analyzed to see whether it conforms to the user's operation habits. If not, the security measures corresponding to the security mode are executed.
6. The operation mode switching method according to claim 1, characterized in that: If the difference between the financial restriction ratio and the financial non-restriction ratio in the first access intention is greater than a preset difference, then incorporating the financial non-restricted access items in the security mode into the restricted access items; If the difference between the privacy restriction ratio and the privacy non-restriction ratio in the second access intention is greater than a preset difference, the non-restricted access items of the privacy class in the security mode are included in the restricted access items.
7. The operation mode switching method according to claim 1, characterized in that: The operation data includes the user's operation behavior on the smart terminal; The environmental data includes the current geographical location and residence time of the smart terminal, image information and sound information around the smart terminal, and weather information of the geographical location.
8. An operation mode switching system for an intelligent terminal, characterized in that: These include: A pre-configuration unit, used to evaluate the security factor of the smart terminal in a normal mode according to the security items related to finance and privacy in the smart terminal, and pre-configure one or more security modes with higher security factors for the smart terminal, and each security mode has exclusive active activation conditions, passive activation conditions and security measures; A mode switching unit is used to obtain first information including location data and network data of the smart terminal, and determine whether the smart terminal meets the active activation conditions of any security mode based on the first information: If yes, the smart terminal is switched to the security mode corresponding to the active activation condition; if no, the unlocking process of the smart terminal is monitored in real time, and when any passive activation condition is matched during the unlocking process, the smart terminal is switched to the security mode corresponding to the passive activation condition; A security mode unit, configured to obtain second information including operation data and environment data of the smart terminal when the smart terminal is in any security mode, and execute security measures corresponding to the security mode based on the second information; Wherein, when the smart terminal is in any security mode, the security items that are allowed to be accessed in the security mode are regarded as non-restricted access items, and the security items that are not allowed to be accessed are regarded as restricted access items; the operation data of the current user on the smart terminal are obtained, and the access intentions of the current user to financial and privacy security items are evaluated by parsing the number of accesses to each restricted access item and non-restricted access item in the operation data, so as to obtain a first access intention and a second access intention; according to the first access intention, it is determined whether to include the non-restricted access items of the financial category in the security mode into the restricted access items, and according to the second access intention, it is determined whether to include the non-restricted access items of the privacy category in the security mode into the restricted access items; Among them, the total number of visits to each restricted access item in the operation data is taken as the first total number, and the total number of visits to each unrestricted access item in the operation data is taken as the second total number; the proportion of the number of visits to financial restricted access items in the operation data to the first total number is calculated to obtain the financial restriction ratio, the proportion of the number of visits to financial unrestricted access items in the operation data to the second total number is calculated to obtain the financial unrestricted ratio, and the first access intention is obtained by evaluating the financial restriction ratio and the financial unrestricted ratio; the proportion of the number of visits to privacy restricted access items in the operation data to the first total number is calculated to obtain the privacy restriction ratio, the proportion of the number of visits to privacy unrestricted access items in the operation data to the second total number is calculated to obtain the privacy unrestricted ratio, and the second access intention is obtained by evaluating the privacy restriction ratio and the privacy unrestricted ratio.
Citation Information
Patent Citations
Mobile terminal and method entering different user modes in different unlocking ways
CN104008350A
Privacy protection method and device and storage medium
CN111949957A
Leveraging mobile devices to enforce restricted area security
US20160286034A1