Equipment life cycle safety management method and terminal

By receiving terminal state transition requests and judging the request type, the security link and TLS protocol are used to ensure the security management of the terminal in different life cycle states, solving the problem that existing systems cannot meet high security requirements, and achieving flexible security control and rapid response.

CN120337221APending Publication Date: 2025-07-18FUJIAN WISBO DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410103189.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-24
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing Android and OpenHarmony systems lack security management in multiple states in the terminal life cycle, and cannot meet the high security requirements of industry-type terminals under different life cycle states.

Method used

By receiving the terminal state transition request, the request type is determined. If it is from high security to low security, it is converted through a preset security link. If it is from low security to high security, it is converted directly, and the TLS protocol and session key are introduced into the security link to ensure security.

Benefits of technology

It realizes specific verification when reducing safety, ensures system security, quickly responds to emergencies when improving safety, and adapts to safety control in different usage environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337221A_ABST
    Figure CN120337221A_ABST
Patent Text Reader

Abstract

The invention provides an equipment life cycle safety management method and a terminal, and the method comprises the steps: receiving a terminal state conversion request, and carrying out the conversion operation through a preset safety link if the terminal state conversion request is converted from a high-safety state to a low-safety state; and if the terminal state conversion request is converted from the low-security state to the high-security state, directly carrying out conversion operation. According to the method and the device, the operation can be carried out only through specific verification when the safety degree is reduced, so that the safety of the system is ensured, too complicated verification is not needed when the safety degree is improved, the safety degree of the system can be rapidly improved to protect the system when an emergency occurs, and the safety of the system is improved. And the security management and control of the terminal in different use environments are realized by adjusting the security degree state of the terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of device security, and particularly to a device life cycle security management method and a terminal. Background Art

[0002] With the development of devices in industries such as financial digital services, government affairs, and policing, more and more intelligent systems such as Android and OpenHarmony are used in industrial terminals. For the original Android and OpenHarmony systems of these types, in each life cycle of the terminal, such as in the device life cycle from device manufacturing, factory shipment, maintenance, etc., there is no concept of multiple states. However, in the above-mentioned industrial terminals, there are often higher security requirements and different processing in different life cycle states of the terminal, and the existing original systems cannot meet such requirements. Summary of the Invention

[0003] The technical problem to be solved by the present invention is: to provide a device life cycle security management method and a terminal, which realize different security controls in different stages of device development.

[0004] To solve the above technical problem, a technical solution adopted by the present invention is:

[0005] A device life cycle security management method includes the steps of:

[0006] Receiving a terminal state conversion request. If the terminal state conversion request is from a high security level state to a low security level state, then perform a conversion operation through a preset security link;

[0007] If the terminal state conversion request is from a low security level state to a high security level state, then directly perform a conversion operation.

[0008] To solve the above technical problem, another technical solution adopted by the present invention is:

[0009] A device life cycle security management terminal includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:

[0010] Receiving a terminal state conversion request. If the terminal state conversion request is from a high security level state to a low security level state, then perform a conversion operation through a preset security link;

[0011] If the terminal state conversion request is from a low security level state to a high security level state, then directly perform a conversion operation.

[0012] The beneficial effects of the present invention are as follows: When a terminal state conversion request is received, the type of the conversion request is judged. If it is a conversion from a low security level state to a high security level state, the conversion operation is directly performed. However, if it is a conversion from a high security level state to a low security level state, the conversion operation needs to be carried out through a preset security link. In this way, it is ensured that a specific verification is required for the operation of reducing the security level, thus guaranteeing the security of the system. When increasing the security level, overly complex verification is not required, and the system security level can be quickly increased to protect the system in case of emergencies. The security control of the terminal in different usage environments is realized by adjusting the security level state of the terminal. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 It is a step flow chart of a device life cycle security management method according to an embodiment of the present invention;

[0014] Figure 2 It is a flow schematic diagram of the second terminal state conversion according to an embodiment of the present invention;

[0015] Figure 3 It is a timing diagram of establishing a security link according to an embodiment of the present invention;

[0016] Figure 4 It is a timing diagram of terminal state conversion through a security link according to an embodiment of the present invention;

[0017] Figure 5 It is a structural schematic diagram of a device life cycle security management terminal according to an embodiment of the present invention;

[0018] Label description:

[0019] 1. A device life cycle security management terminal; 2. A processor; 3. A memory. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] To describe in detail the technical content, the achieved objectives and the effects of the present invention, the following is described in conjunction with the embodiments and with reference to the drawings.

[0021] Please refer to Figure 1 , a device life cycle security management method, including the steps:

[0022] Receive a terminal state conversion request. If the terminal state conversion request is a conversion from a high security level state to a low security level state, perform the conversion operation through a preset security link;

[0023] If the terminal state conversion request is a conversion from a low security level state to a high security level state, directly perform the conversion operation.

[0024] As can be seen from the above description, the beneficial effects of the present invention are as follows: when a terminal state conversion request is received, the type of the conversion request is judged. If it is a conversion from a low security level state to a high security level state, the conversion operation is directly performed. However, if it is a conversion from a high security level state to a low security level state, the conversion operation needs to be performed through a preset security link. This ensures that a specific verification is required for the operation when reducing the security level, thereby guaranteeing the security of the system. When increasing the security level, overly complex verification is not required, and the system security level can be quickly increased to protect the system in case of emergencies. The security control of the terminal in different usage environments is realized by adjusting the security level state of the terminal.

[0025] Further, the conversion operation through the preset security link includes:

[0026] Receive a user operation request, and verify whether the user identity is legal according to the user operation request;

[0027] If so, obtain the terminal identifier of the terminal, and register a task instruction in the server according to the terminal identifier;

[0028] If the server also verifies that the user identity is legal, add the task instruction to the instruction pool;

[0029] Create transparent transmission channels with the terminal and the server respectively, so that after the terminal and the server complete the TLS handshake and negotiate the session key, a security link is established through the session key and the TLS protocol;

[0030] Perform the conversion operation through the instruction pool and the security link.

[0031] As can be seen from the above description, after receiving the user operation request, verify whether the user identity is legal according to the user operation request. After the verification is passed, obtain the terminal identifier and register the corresponding task instruction in the server and add it to the instruction pool. Then, the execution authority of the corresponding terminal is restricted according to the terminal, and the security of the transparent transmission channel is ensured by introducing the TLS protocol and the session key after establishing the transparent transmission channel, completing the construction of the security link. Finally, the corresponding instruction in the instruction pool is called according to the request in the security link for operation, ensuring the security of the instruction execution process.

[0032] Further, the conversion operation through the instruction pool and the security link includes:

[0033] Obtain the random number generated by the terminal, and combine the random number with the received mode switching instruction and parameters to obtain combined data;

[0034] Send the combined data to the server so that the server signs the combined data to obtain signature data;

[0035] Forward the signature data and the corresponding signature certificate to the terminal so that the terminal verifies the signature data according to the signature certificate, and executes the mode switching instruction according to the parameters in the signature data after the signature verification passes.

[0036] As can be seen from the above description, after establishing a secure channel, the terminal also generates a random number, combines the random number, the mode switching instruction, and the parameters to obtain combined data and sends it to the server. The server then signs the combined data. The terminal will only execute the mode switching instruction that passes the signature verification, that is, not only the instruction needs to be sent through the secure link, but also it needs to pass the signature verification to be executed by the terminal to switch from a high security level to a low security level, further ensuring the security of the terminal device when exiting the high security state.

[0037] Furthermore, the terminal states from low security level to high security level include a normal state, a maintenance state, and a protection state.

[0038] As can be seen from the above description, setting the normal state, the maintenance state, and the protection state to control the terminal state, and the security levels of different states are different, so it is possible to switch between different terminal states according to different production stages, realizing the full-cycle management of the terminal usage.

[0039] Furthermore, the terminal state is stored in a secure chip.

[0040] As can be seen from the above description, storing the terminal state in a secure chip reduces the possibility of being tampered with. Further improving the security of the system.

[0041] A terminal for device lifecycle security management includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:

[0042] Receive a terminal state conversion request. If the terminal state conversion request is from a high security level state to a low security level state, perform a conversion operation through a preset secure link;

[0043] If the terminal state conversion request is from a low security level state to a high security level state, directly perform a conversion operation.

[0044] The beneficial effects of the present invention are as follows: When a terminal state conversion request is received, the type of the conversion request is judged. If it is a conversion from a low security level state to a high security level state, the conversion operation is directly performed. However, if it is a conversion from a high security level state to a low security level state, the conversion operation needs to be carried out through a preset security link. In this way, it is ensured that a specific verification is required for the operation when reducing the security level, thus guaranteeing the security of the system. When increasing the security level, overly complex verification is not required, and the system security level can be quickly increased to protect the system in case of emergencies. The security control of the terminal in different usage environments is achieved by adjusting the security level state of the terminal.

[0045] Further, the conversion operation through the preset security link includes:

[0046] Receive a user operation request, and verify whether the user identity is legal according to the user operation request;

[0047] If so, obtain the terminal identifier of the terminal, and register a task instruction in the server according to the terminal identifier;

[0048] If the server also verifies that the user identity is legal, add the task instruction to the instruction pool;

[0049] Create transparent transmission channels with the terminal and the server respectively, so that after the terminal and the server complete the TLS handshake and negotiate the session key, a security link is established through the session key and the TLS protocol;

[0050] Perform the conversion operation through the instruction pool and the security link.

[0051] As can be seen from the above description, after receiving the user operation request, verify whether the user identity is legal according to the user operation request. After passing the verification, obtain the terminal identifier and register the corresponding task instruction in the server and add it to the instruction pool. Then, the execution permission of the corresponding terminal is restricted according to the terminal, and the security of the transparent transmission channel is ensured by introducing the TLS protocol and the session key after establishing the transparent transmission channel, completing the construction of the security link. Finally, the corresponding instruction in the instruction pool is called according to the request in the security link for operation, ensuring the security of the instruction execution process.

[0052] Further, the conversion operation through the instruction pool and the security link includes:

[0053] Obtain a random number generated by the terminal, and combine the random number with the received mode switching instruction and parameters to obtain combined data;

[0054] Send the combined data to the server so that the server signs the combined data to obtain signed data;

[0055] Forward the signature data and the corresponding signature certificate to the terminal, so that the terminal verifies the signature data according to the signature certificate, and executes the mode switching instruction according to the parameters in the signature data after the signature verification passes.

[0056] As can be seen from the above description, after establishing a secure channel, the terminal also generates a random number, combines the random number, the mode switching instruction, and the parameters to obtain combined data and sends it to the server. The server then signs the combined data. The terminal will only execute the mode switching instruction that passes the signature verification, that is, not only the instruction needs to be sent through the secure link, but also it needs to pass the signature verification to be executed by the terminal to switch from a high security level to a low security level, further ensuring the security of the terminal device when exiting the high security state.

[0057] Further, the terminal states from low security level to high security level include a normal state, a maintenance state, and a protection state.

[0058] As can be seen from the above description, setting the normal state, the maintenance state, and the protection state to control the terminal state, and the security levels of different states are different, so the switching between different terminal states can be performed according to different production stages, realizing the full-cycle management of the terminal usage.

[0059] Further, the terminal state is stored in a secure chip.

[0060] As can be seen from the above description, storing the terminal state in a secure chip reduces the possibility of being tampered with. Further improving the security of the system.

[0061] The above device life cycle security management method and terminal of the present invention can be applied to scenarios where different permission scopes need to be controlled for devices in different scenarios, especially in the financial payment scenario where multiple intelligent payment collection devices need to perform cross-terminal payment, printing and other related services; the following is described through specific embodiments.

[0062] Please refer to Figure 1 , the first embodiment of the present invention is:

[0063] A device life cycle security management method specifically includes:

[0064] S1. Receive a terminal state conversion request. If the terminal state conversion request is from a high security level state to a low security level state, then execute S2;

[0065] In an optional embodiment, the terminal states from low security level to high security level include a normal state, a maintenance state, and a protection state; and the terminal state is stored in a secure chip (SE); the terminal also includes a general system (AP);

[0066] In an alternative embodiment, the terminal state stored in the SE is denoted as the first terminal state, and there is also a second terminal state stored in the general system. The second terminal state includes, from a low security level to a high security level, an operating state, a manufacturing / maintenance state, and an attack state. Referring to Table 1 below, the permission settings in each state are described.

[0067] Table 1

[0068]

[0069]

[0070] In Table 1, the key management functions include key download, key usage, and PIN input.

[0071] In an alternative embodiment, both the second terminal state and the attack flag are stored in the SFS file system in the TEE (Trusted Execution Environment). The SFS achieves data anti-leakage, anti-tampering, and anti-replay through the TEE security mechanism and the RPMB of the EMMC.

[0072] Specifically, during the production process, after the blank board is burned with the underlying software, it enters the manufacturing state. After the board is assembled into a terminal and the terminal is activated after a full machine test, it enters the operating state. In addition, at the repair center, if the terminal is re-flashed, it will also enter the manufacturing state, and the production and repair processes are carried out in a controlled environment. If the terminal or the board is in the manufacturing state, the user is prompted on the terminal desktop that the device cannot be used for normal transactions. For example, the prompt is "Terminal in manufacturing stage, do not use for transactions!"; at this time, the SE is in the maintenance state, and the PINPAD function on the SE is disabled, including key download, key usage, and PIN input.

[0073] When there is no attack source on the terminal and it is activated during the production or repair stage, it enters the operating state. In the operating state, all functions of the terminal can be used normally, and at this time, the SE is in the normal state.

[0074] If an attack occurs in the operating state, the terminal sets an attack flag; the attacks include cover removal, high temperature, illegal frequency, firmware exception, etc., and attack detection can be achieved through sensors. After the sensors detect external disassembly and other behaviors, they send corresponding signals to the terminal; the response processing for the attack is as follows: after the attack occurs, the state of the second terminal is adjusted to the attack state, the sensitive data in the SE is automatically cleared and the SE enters the protection state, all card functions (magnetic card, IC card, and contactless) and all PINPAD functions (key download, key use, and PIN input) are disabled, and the SE notifies the general system AP that an attack has occurred; after rebooting, there is always a watermark on the status screen indicating that the terminal cannot be used for sensitive services; after an attack occurs in the operating state, the terminal can only enter the maintenance state after performing a networked attack clearing operation (i.e., it needs to be switched from a high security state to a low security state through step S2) in a controlled environment (customer service maintenance).

[0075] The general system AP and the SE are independent of each other and communicate through a serial port.

[0076] After an attack occurs on the terminal, it enters the maintenance state after networked attack clearing; in the maintenance state, after the terminal completes relevant repairs, it enters the operating state after being reactivated and can be used normally; in addition, through online operations in a controlled environment, the terminal in the operating state can be switched to the maintenance state for terminal repair, rectification, etc. operations; when the terminal is in the maintenance state: there is a watermark on the screen to prompt the user that the terminal cannot be used for sensitive services; the PINPAD function on the SE is disabled, including key download, key use, and PIN input.

[0077] Refer to Figure 3 S2. Perform conversion operations through a preset secure link, including:

[0078] S21. Receive a user operation request and verify whether the user's identity is legal according to the user operation request.

[0079] In an optional implementation manner, the user performs Ukey login in the PC tool, and uses the public and private keys preset in the Ukey to implement Https mutual authentication with the account system of the server.

[0080] S22. If so, obtain the terminal identifier of the terminal, and register a task instruction on the server according to the terminal identifier.

[0081] In an optional implementation manner, the PC tool establishes a connection with the operation and maintenance module in the terminal through Socket and obtains the terminal identifier (serial number SN, CPU - built - in identifier information cpuID); among them, the terminal uploads the terminal identifier to the PC tool through its own secure link TA.

[0082] The PC tool registers the task instructions that need to be operated with the server. The registration information includes the task instructions (tagList) and parameters: the terminal identifier and the PC tool identifier (PCMac);

[0083] S23. If the server also verifies that the user identity is legal, that is, the registration information is sent to the server in a preset manner, so that the server performs identity verification on the registration information according to the preset manner. If the user identity is verified to be legal, the task instructions are added to the instruction pool;

[0084] In an optional implementation manner, the verification process includes: the PC tool and the server establish a connection and communication through standard Https two-way authentication. After the server receives the terminal serial number, cpuID, operator account information, PCmac, and operation instructions sent by the PC tool, it first checks whether the operator has the permission for the corresponding operation instructions, whether the PCMac used for the operation is authorized, and then checks whether the operated terminal (SN or cpuID) matches the information already entered. If all are met, the verification is passed;

[0085] In an optional implementation manner, after receiving the registration information, the instruction management module of the server requests the user operation authorization management module of the server to perform verification on the legality of the instruction operator. If the verification is passed, the instruction is cached in the instruction pool waiting for the execution terminal to request a connection, and the verification result is returned to the PC tool, and the PC tool notifies the security link TA of the terminal to start;

[0086] S24. Create a transparent transmission channel with the terminal and the server respectively, so that after the terminal and the server complete the TLS handshake and negotiate the session key, a secure link is established through the session key and the TLS protocol, including:

[0087] S241. The security routing module of the terminal creates a Socket server according to the specified IP and port, and establishes a transparent transmission channel with the terminal using the PC tool as the Sockect client;

[0088] S242. The PC tool side is used as the client, and the server is used as the sever to create a transparent transmission channel through socket(ip, post);

[0089] S243. The terminal performs a TLS handshake with the server through the transparent transmission channel and completes the negotiation of the session key; among them, the superior CA of the certificate responded by the server is preset in the terminal, and the identity of the server is verified through the superior CA to complete the TLS handshake;

[0090] S244. After the handshake is completed, the terminal sends the first service frame, which is encrypted and transmitted through the TLS protocol using the previously negotiated session key. After receiving the service frame, the link module of the server sends the terminal identifier and the terminal capabilities to the instruction management module in the server and notifies that the secure link is successfully established;

[0091] Please refer to Figure 4 , S25. Perform conversion operations through the instruction pool and the secure link, including:

[0092] S251. Obtain the random number generated by the terminal, and combine the random number with the received mode switching instruction and parameters to obtain combined data;

[0093] In an optional implementation, the lifecycle module of the server requests the terminal to generate a SE random number through the secure link. After the secure link TA of the terminal resolves the request to generate the SE random number through the session key, it requests the lifecycle TA of the terminal through the lifecycle service in the REE to obtain the SE random number. The lifecycle TA communicates with the SE and sends an instruction to obtain the SE random number. After the SE generates the random number, it returns to the lifecycle module of the server through the relevant services and the secure link within the terminal;

[0094] S252. Send the combined data to the server so that the server signs the combined data to obtain signature data;

[0095] In an optional implementation, the lifecycle management module of the server combines the obtained random number with the specific mode switching instruction (obtained from the instruction pool according to the received mode switching instruction) and parameters (such as activation / clear attack, etc.), and requests the signature module to sign the combined data to obtain signature data;

[0096] S253. Forward the signature data and the corresponding signature certificate to the terminal so that the terminal verifies the signature data according to the signature certificate, and executes the mode switching instruction according to the parameters in the signature data after the verification passes;

[0097] In an alternative embodiment, it includes: (1) The server forwards the signature data to the secure link TA of the terminal through a secure link. After the secure link TA decrypts and parses it using the session key, it is then transmitted all the way to the SE through the life cycle service in the terminal, etc.; (2) The SE verifies the signature, parses the instruction, and then performs the switching operation (activating / changing the attack state) on the SE side; for example, changing from the protected state to the maintenance state, that is, an attack mark is stored when under attack, and the second terminal state is the attack state. At this time, the switching operation is: clearing the attack flag register and the keys (SK / EK). Since it has been attacked at this time, new keys need to be regenerated to prevent the keys after the attack from being stolen or tampered with; finally, change the SE state to the maintenance state and allow card functions; change from the maintenance state to the normal state; change the activation mode identifier on the SE side, change the SE state to the normal state and enable relevant sensitive functions; The normal use of the application is implemented by calling various service interfaces provided by the system. When various service interfaces are called, the sensitive functions will detect the terminal state identifier, and only when the identifier is in the normal state will the corresponding operation be allowed; for example, when the application calls the printing function, the printing service will call all the way to the printing interface provided by the SE side. The key interfaces on the terminal AP side and the printing execution interfaces on the SE side will both detect the current terminal state identifier. When the identifier is not in the normal state, the process will abort and return the result to the application; (3) After the conversion operation is completed, the execution result is returned to the PC tool side, and the PC tool side returns it to the server;

[0098] S3. If the terminal state conversion request is from a low security level state to a high security level state, directly perform the conversion operation;

[0099] In an alternative embodiment, the attack flag is set through the manufacturer software in the REE, that is, without going through the security verification in the TEE or the security status verification of networking, the terminal state can be switched when under attack, improving the timeliness of protecting the terminal;

[0100] That is, for the manufacturer software in the REE, the life cycle state in the SE is stored in the SE; only the following SE state switches can be performed: normal state -> protected state, normal state -> maintenance state, and maintenance state -> protected state; for other state switches, they can only be based on the secure link;

[0101] In an alternative embodiment, if the original state and the target state in the terminal state conversion request are not adjacent in sorting, the terminal state conversion request is rejected; state conversions across security levels are not allowed, and only adjacent terminal states are allowed to be converted, avoiding vulnerabilities caused by a large difference in security levels during the terminal state conversion process;

[0102] In an alternative embodiment, the conditions of S1 and S3 are burned into the SE firmware to restrict the terminal state switching.

[0103] Please refer to Figure 5 , the second embodiment of the present invention is as follows:

[0104] A device life cycle security management terminal 1 includes a processor 2, a memory 3, and a computer program stored on the memory 3 and executable on the processor 2. When the processor 2 executes the computer program, each step in the first embodiment is implemented.

[0105] In summary, the present invention provides a device life cycle security management method and terminal. The state of the terminal is switched according to different environments, and the operable items in each state are different. And when re-entering the normal use state, it needs to be verified in a secure environment to enter, thus ensuring the use safety of the terminal; further, during the state switching process, if it is necessary to switch from a high security state to a low security state, it needs to be carried out through a dedicated security link, thereby ensuring the use safety of the terminal, and the terminal can switch between different states according to the environment it is in to provide different service scopes, ensuring the use safety of the terminal. Further, when switching from a low security state to a high security state, the restrictions are reduced, so that when the terminal detects an attack, it can quickly provide protection to avoid data leakage.

[0106] The above are only the embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent transformation made by using the specification and drawings of the present invention, or directly or indirectly applied in related technical fields, shall be equally included in the patent protection scope of the present invention.

Claims

1. A method for device life cycle security management, characterized in that Including the steps: Receiving a terminal state conversion request. If the terminal state conversion request is from a high security level state to a low security level state, perform a conversion operation through a preset secure link; If the terminal state conversion request is from a low security level state to a high security level state, directly perform a conversion operation.

2. The method for lifecycle safety management of a device according to claim 1, wherein The performing a conversion operation through a preset secure link includes: Receiving a user operation request, and verifying whether the user identity is legal according to the user operation request; If so, obtaining the terminal identifier of the terminal, and registering a task instruction in the server according to the terminal identifier; If the server also verifies that the user identity is legal, adding the task instruction to the instruction pool; Respectively creating a pass-through channel with the terminal and with the server, so that after the terminal and the server complete the TLS handshake and negotiate a session key, establish a secure link through the session key and the TLS protocol; Performing a conversion operation through the instruction pool and the secure link.

3. The method for lifecycle safety management of a device according to claim 2, wherein The performing a conversion operation through the instruction pool and the secure link includes: Obtaining a random number generated by the terminal, and combining the random number with the received mode switching instruction and parameters to obtain combined data; Sending the combined data to the server, so that the server signs the combined data to obtain signature data; Forwarding the signature data and the corresponding signature certificate to the terminal, so that the terminal verifies the signature data according to the signature certificate, and executes the mode switching instruction according to the parameters in the signature data after the signature verification passes.

4. A method for lifecycle safety management of a device according to claim 1, characterized in that, The terminal state from low security level to high security level includes a normal state, a maintenance state, and a protection state.

5. A method for lifecycle safety management of a device according to claim 1 or 4, characterized in that, The terminal state is stored in a secure chip.

6. A device life cycle security management terminal, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the following steps are implemented: Receiving a terminal state conversion request. If the terminal state conversion request is from a high security level state to a low security level state, perform a conversion operation through a preset secure link; If the terminal state conversion request is from a low security level state to a high security level state, directly perform a conversion operation.

7. An equipment life cycle safety management terminal according to claim 6, characterized in that, The performing a conversion operation through a preset secure link includes: Receiving a user operation request, and verifying whether the user identity is legal according to the user operation request; If so, obtaining the terminal identifier of the terminal, and registering a task instruction in the server according to the terminal identifier; If the server also verifies that the user identity is legal, adding the task instruction to the instruction pool; Respectively creating a pass-through channel with the terminal and with the server, so that after the terminal and the server complete the TLS handshake and negotiate a session key, establish a secure link through the session key and the TLS protocol; Performing a conversion operation through the instruction pool and the secure link.

8. An equipment life cycle safety management terminal according to claim 7, characterized in that, The performing a conversion operation through the instruction pool and the secure link includes: Obtaining a random number generated by the terminal, and combining the random number with the received mode switching instruction and parameters to obtain combined data; Sending the combined data to the server, so that the server signs the combined data to obtain signature data; Forward the signature data and the corresponding signature certificate to the terminal, so that the terminal verifies the signature data according to the signature certificate, and executes the mode switching instruction according to the parameters in the signature data after the signature verification passes.

9. An equipment life cycle safety management terminal according to claim 6, characterized in that, The terminal states from low security level to high security level include the normal state, the maintenance state, and the protection state.

10. An equipment life cycle safety management terminal according to claim 6 or 9, characterized in that, The terminal state is stored in the security chip.