File secret key storage method, system and device, electronic equipment and storage medium
By storing the secret keys generated by the smartphone into external security devices, especially using RTOS systems or dual-operating systems, the hardware-level secure isolated storage of the secret keys is realized, solving the problem that the smartphone operating system is prone to stealing, and improving the security and reliability of the secret keys.
Patent Information
- Application Number
- CN202510257532.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2020-02-27
- Publication Date
- 2025-07-29
AI Technical Summary
The openness of the smartphone operating system makes its code logic and encryption solutions easy to be stolen, and the security of the secret keys stored in terminal devices is difficult to guarantee.
The key is generated and stored in an external security device, using independent storage hardware and hardware-level security isolation, such as wearable devices connected through Bluetooth or USB interfaces, such as smartwatches, and securely stored using independent storage space of RTOS systems or dual operating systems.
Improves the storage security of the secret key, prevents theft, and ensures the accurate search and decryption process of the corresponding relationship between the target file and the secret key.
Smart Images

Figure CN120387183A_ABST
Abstract
Description
[0001] This divisional application of a Chinese invention patent application has an application date of February 27, 2020, an application number of 202010124455X, and a title of "File Secret Key Storage Method, System, Device, Electronic Device, and Storage Medium". Technical Field
[0002] This application relates to the field of computer technology, and particularly to a file secret key storage method, system, device, electronic device, and storage medium. Background Art
[0003] With the progress of technology, terminal devices have become increasingly popular. In the process of using a smart phone, a lot of relevant files will be stored in the terminal device, including those actively uploaded by users and those automatically generated during the use of application programs, etc.
[0004] Taking a smart phone as an example, generally, some files with relatively high privacy (hereinafter referred to as private files) will be encrypted and stored in the smart phone. Therefore, all encryption schemes for private files are based on the operating system of the smart phone. However, some operating systems currently used in smart phones have natural openness. For example, the Android system, which may lead to its code logic and schemes being easily known.
[0005] Therefore, when the system-level permissions of the terminal device are stolen, the security of the secret key stored in the operating system of the terminal device is difficult to guarantee. Summary of the Invention
[0006] Embodiments of this application provide a file secret key storage method, system, device, electronic device, and storage medium, which can store the secret key more securely.
[0007] A file secret key storage method, the method includes:
[0008] Receiving an encryption request for a target file;
[0009] Generating a secret key for the target file according to the encryption request;
[0010] Sending a secret key storage request to an external security device; the secret key storage request is used to request the external security device to store the correspondence between the identifier of the target file and the secret key.
[0011] A file decryption method, the method includes:
[0012] Receiving a decryption request for a target file;
[0013] Send a key acquisition request to an external security device according to the decryption request; the key acquisition request carries the identifier of the target file; the key acquisition request is used to request the external security device for the key corresponding to the identifier of the target file.
[0014] Receive the key returned by the external security device, and decrypt the target file according to the key.
[0015] A file key storage system, the system includes: a terminal and an external security device;
[0016] The terminal is used to receive the encryption request of the target file, generate the key of the target file according to the encryption request, and then send a key storage request to the external security device.
[0017] The external security device is used to receive the key storage request sent by the terminal and store the corresponding relationship between the identifier of the target file and the key according to the key storage request.
[0018] A file key storage device, the device includes:
[0019] A receiving module, configured to receive the encryption request of the target file;
[0020] A generating module, configured to generate the key of the target file according to the encryption request;
[0021] A sending module, configured to send a key storage request to the external security device; the key storage request is used to request the external security device to store the corresponding relationship between the identifier of the target file and the key.
[0022] An electronic device includes a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor executes the steps of the above file key storage method.
[0023] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above file key storage method are implemented.
[0024] For the above file key storage method, system, device, electronic device and storage medium, after the terminal receives the encryption request of the target file, it generates the key of the target file according to the encryption request and sends a key storage request to the external security device; to request the external security device to store the corresponding relationship between the identifier of the target file and the key. In this embodiment, since the terminal generates the key for the target file and stores the key in the external security device, it is equivalent to storing the key using an independent storage hardware and hardware-level security isolation. In this way, the key is not easily stolen, greatly improving the security of key storage. And what is stored in the external security device is the corresponding relationship between the identifier of the target file and the key, and the key of the target file can be accurately located through this corresponding relationship. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0026] Figure 1 It is an application environment diagram of the file secret key storage method in an embodiment;
[0027] Figure 2 It is a schematic internal structure diagram of a terminal in an embodiment;
[0028] Figure 3 It is a flowchart of the file secret key storage method in an embodiment;
[0029] Figure 4 It is a schematic diagram of a dual-system of a smart watch in an embodiment;
[0030] Figure 5 It is a flowchart of the file secret key storage method in another embodiment;
[0031] Figure 6 It is a schematic diagram of file encryption and decryption in an embodiment;
[0032] Figure 7 It is a structural block diagram of a file secret key storage device in an embodiment;
[0033] Figure 8 It is a structural block diagram of a file secret key storage device in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0034] In order to make the objectives, technical solutions and advantages of the present application clearer, the following further describes the present application in detail with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0035] Figure 1 It is a schematic application environment diagram of the file secret key storage method in an embodiment. As Figure 1As shown, the application environment includes a terminal 110 and an external security device 120. Among them, the terminal 110 includes, but is not limited to, electronic devices such as smartphones, personal computers, laptops, desktop computers, media players, smart TVs, and tablets. Among them, the external security device 120 can be a portable wearable device. For example, the portable wearable device can be a smart watch, a smart necklace, a smart helmet, etc. Among them, the external security device and the terminal can be connected by means such as Bluetooth, infrared, wifi, and USB interfaces.
[0036] Among them, the schematic internal structure diagram of the terminal 110 can be referred to Figure 2 As shown, the schematic internal structure diagram of the terminal is shown, including a processor and a memory connected by a system bus. Among them, the processor is used to provide computing and control capabilities to support the operation of the entire terminal. The memory may include a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The computer program can be executed by the processor to implement a file secret key storage method provided by each of the following embodiments. The internal memory provides a cache operating environment for the operating system computer program in the non-volatile storage medium.
[0037] Next, the technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail through embodiments and in conjunction with the accompanying drawings. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. It should be noted that a file secret key storage method provided by the present application Figures 3 - 6 The execution subject is the terminal, among which, Figures 3 - 6 The execution subject can also be a file secret key storage device, where the device can be implemented as part or all of the terminal in a software, hardware, or software-hardware combination manner.
[0038] Figure 3 It is a flowchart of the file secret key storage method in an embodiment. The file secret key storage method in this embodiment is described by taking the terminal running in Figure 1 as an example. As Figure 3 shown, the file secret key storage method includes steps 302 to 306.
[0039] Step 302, receiving an encryption request for a target file.
[0040] The target file represents the file to be encrypted in the current terminal. For example, in practical applications, when users store some relatively private files, they will encrypt these private files to ensure privacy. Among them, the file to be encrypted can be a picture. For example, the encrypted pattern of a payment software, including images of user face unlocking or payment; the file to be encrypted can also be a document, such as a document actively edited or uploaded to the terminal by the user; the file to be encrypted can also be of other types, such as the accounts and passwords of various application programs, unlocking passwords, etc.; this embodiment does not limit the type, quantity, etc. of the target file.
[0041] The encryption request for the target file represents the request triggered when the current user needs to encrypt the target file. For example, the user triggers the request to encrypt the target file on the terminal display screen, and the terminal receives the encryption request for the target file. Among them, the way the user triggers the encryption request for the target file can be a voice method, a touch method, through an external input device, etc., and this embodiment does not limit this.
[0042] In some scenarios, the encryption method can be carried in the encryption request. For example, it is encrypted by password, verification code, pattern, etc.
[0043] Step 304, generate a secret key for the target file according to the encryption request.
[0044] After the terminal receives the encryption request, it encrypts the target file to generate the secret key of the target file. The secret key can also be called a key, which refers to a secret information used to complete cryptographic applications such as encryption, decryption, and integrity verification.
[0045] Among them, the method for the terminal to generate the secret key of the target file is not limited. For example, after the terminal receives the encryption request, it can encrypt the target file through a built-in encryption algorithm, and generate the secret key of the target file after encryption. Of course, the encryption algorithm can be the Data Encryption Algorithm (DEA), the Data Encryption Standard (DES), the hash algorithm, etc., and this embodiment does not limit the encryption algorithm either.
[0046] Step 306, send a secret key storage request to an external security device; the secret key storage request is used to request the external security device to store the correspondence between the identifier of the target file and the secret key.
[0047] The external security device refers to an external device used to store the secret key of the target file. For example, this external device can be a device connected to the terminal through a UEB interface, such as a USB flash drive; it can also be a device connected to the terminal wirelessly, such as a wearable device that can be connected via Bluetooth or wifi, and the type of this external security device is not limited.
[0048] Based on the key of the target file generated by the terminal, the terminal sends the corresponding relationship between the target file and the key to an external security device for storage. That is, the terminal sends a key storage request to the external security device, and this key storage request is used to request the external security device to store the corresponding relationship between the identifier of the target file and the key. Among them, the identifier of the target file can be in the form of text, numbers, letters, or a combination thereof, and there is no limitation on this.
[0049] In the file key storage method of this embodiment, after the terminal receives an encryption request for a target file, according to the encryption request, it generates a key for the target file and sends a key storage request to an external security device; to request the external security device to store the corresponding relationship between the identifier of the target file and the key. In this embodiment, since the terminal stores the key in the external security device after generating the key for the target file, it is equivalent to using an independent storage hardware for the key and performing hardware-level security isolation for storage. In this way, the key is not easily stolen, greatly improving the security of key storage. And what is stored in the external security device is the corresponding relationship between the identifier of the target file and the key, and the key of the target file can be accurately located through this corresponding relationship.
[0050] For the above-mentioned external security device, taking the external security device as a wearable device as an example, the process of the terminal sending a key storage request to the external security device and the external security device storing the key will be described.
[0051] In one embodiment, the external security device is a wearable device; then the above-mentioned sending a key storage request to the external security device includes: sending a key storage request to the wearable device. Optionally, the wearable device includes an RTOS system; sending a key storage request to the wearable device includes: sending a key storage request to the wearable device; the key storage request is used to request the wearable device to store the corresponding relationship between the identifier of the target file and the key in the RTOS system.
[0052] In this embodiment, if the external security device is a wearable device, the terminal pre-establishes a connection with the wearable device, and then sends a key storage request to the wearable device, requesting the wearable device to store the corresponding relationship between the identifier of the target file and the key of the target file.
[0053] In a scenario, if the wearable device includes an RTOS system, where the RTOS system is the Real-time Operating System (RTOS), it will run and manage system resources in a sorted manner and provide a consistent basis for developing application programs. Compared with general operating systems, the biggest feature of the RTOS system is "real-time performance". If a task needs to be executed, the real-time operating system will execute the task immediately (within a short time) without long delays. This feature ensures the timely execution of each task. Based on these features of the RTOS system, if the wearable device includes an RTOS system, after the terminal sends a secret key storage request to the wearable device, the wearable device will store the correspondence between the identifier of the target file and the secret key in the RTOS system. In this way, when actually applying the file secret key storage method provided in this application, the file secret key storage process can be completed quickly and in real time.
[0054] In another scenario, if the wearable device includes two operating systems, and the power consumption of one operating system is higher than that of the other. For example, the operating system with higher power consumption is the commonly used operating system of the wearable device, and the operating system with lower power consumption is the backup operating system of the wearable device. For this scenario, an embodiment is provided to illustrate the process of the terminal sending a secret key storage request to an external security device and the external security device storing the secret key.
[0055] In an embodiment, the wearable device includes a first operating system and a second operating system, and the storage spaces of the first operating system and the second operating system are independent of each other; then the above-mentioned sending a secret key storage request to the wearable device includes: sending a secret key storage request to the first operating system of the wearable device, and the secret key storage request is used to instruct the first operating system to store the correspondence between the identifier of the target file and the secret key in the second operating system. Optionally, the power consumption of the first operating system is greater than that of the second operating system. Optionally, the first operating system and the second operating system use different chips.
[0056] In this embodiment, the wearable device includes a first operating system and a second operating system, and the storage spaces of the first operating system and the second operating system are independent of each other. The power consumption of the first operating system in the wearable device is greater than that of the second operating system. Using the second operating system with lower power consumption to store the correspondence between the identifiers of the target files and the secret keys can reduce the power consumption of the wearable device. Moreover, the first operating system and the second operating system use different chips. Even in the wearable device, chip-level physical isolation is adopted to improve the security of the correspondence between the identifiers of the target files and the secret keys. In this way, when the terminal device sends a secret key storage request to the wearable device, the secret key storage request first reaches the first operating system. After the first operating system receives the secret key storage request, it stores the correspondence between the identifiers of the target files and the secret keys in the second operating system. Since the storage spaces of the two operating systems are independent, and the second operating system is not the common system of the wearable device, storing the secret key in the second operating system can ensure the security of the secret key storage.
[0057] In one embodiment, the first operating system is the Android system, and the second operating system is the RTOS system; optionally, the wearable device is a smart watch.
[0058] Taking the smart watch including the Android system and the RTOS system as an example for illustration, that is, the smart watch has a dual-system and dual-mode, as Figure 4 shown, is a schematic diagram of the same sports APP with respect to the two operating systems. The big core of the smart watch uses the Android system, and the small core uses the RTOS system. The two use different chips, and the storage spaces are independent of each other. Among them, the user can freely switch between the two systems of the Android system and the RTOS system. The Android system provides relatively complete functions, and the RTOS system provides ultra-long standby with low power consumption and security reinforcement capabilities. The power consumption of the Android system is greater than that of the RTOS system.
[0059] When the smart watch uses the Android system of the big core, because its functions are relatively complete, it corresponds to the normal mode of the smart watch. When the smart watch uses the RTOS system of the small core, since the RTOS system is the mode switched during ultra-long standby with low power consumption, it corresponds to the bracelet mode of the smart watch.
[0060] For example, after the terminal generates the key of the target file, it sends a key storage request carrying the correspondence between the target file identifier and the key to the big-core Android system of the smartwatch. After receiving the key storage request, the big-core Android system of the smartwatch continues to forward it to the small-core RTOS system of the smartwatch, that is, stores the correspondence between the identifier of the target file and the key. In this way, the key is stored using an independent storage hardware and hardware-level security isolation, and the key is not easily stolen, greatly improving the security of key storage.
[0061] In this embodiment, the terminal stores the key of the target file in the bracelet mode of the smartwatch. When the target file needs to be decrypted, the terminal is connected to the bracelet, and the target file can be opened with the key stored in the bracelet mode, ensuring the security when the target file is used.
[0062] In addition to the process of encrypting the target file and storing the key involved in the above embodiment, in actual applications, when the target file needs to be applied, the key needs to be obtained to open the target file. Therefore, for the decryption process of the target file, an embodiment is provided for illustration, as Figure 5 shown, in one embodiment, after sending a key storage request to an external security device, the method includes:
[0063] Step S502, receive a decryption request for the target file.
[0064] The target file can be referred to the description in step S302 above and will not be elaborated here. Among them, the decryption request refers to a request triggered when the user wants to decrypt the target file. For example, the user can trigger the decryption request on the display screen of the terminal.
[0065] Step S504, according to the decryption request, send a key acquisition request to the external security device; the key acquisition request carries the identifier of the target file; the key acquisition request is used to request the key corresponding to the identifier of the target file from the external security device.
[0066] Similarly, the external security device can be referred to the description in the previous embodiment and will not be elaborated here.
[0067] In this step, after the terminal receives the decryption request, it sends a key acquisition request to the external security device. In order to accurately obtain the key of the target file, the key acquisition request sent by the terminal to the external security device carries the identifier of the target file. After the external security device receives the key acquisition request, it can locate the key corresponding to the target file according to the identifier of the target file and send the key back to the terminal.
[0068] Step S506, receive the key returned by the external security device and decrypt the target file according to the key.
[0069] After the terminal receives the secret key returned by the external security device, the terminal can decrypt the target file according to the secret key. Since the secret key is stored in an independent storage hardware and with hardware-level security isolation, the storage security is relatively high. When using the secret key to unlock the target file and apply the target file, the security of the target file is also greatly guaranteed.
[0070] In one embodiment, if the external security device is a wearable device and the wearable device includes an RTOS system, then in one embodiment, the above-mentioned terminal sends a secret key acquisition request to the external security device, including: sending a secret key acquisition request to the wearable device; the secret key acquisition request is used to request the secret key corresponding to the identifier of the target file from the RTOS system of the wearable device.
[0071] If the external security device is a wearable device, then the terminal has previously stored the file secret key in the wearable device. In the case where the wearable device includes an RTOS system, the file secret key is stored in the RTOS system of the wearable device. Then, when the terminal sends a secret key acquisition request to the external security device, it is to request the secret key of the file from the RTOS system of the wearable device. Based on the introduction of the characteristics of the RTOS system in the previous embodiment, after receiving the secret key acquisition request, the RTOS system of the wearable device will respond immediately and send the secret key corresponding to the target file identifier to the terminal. In this way, by requesting the secret key of the file from the RTOS system of the wearable device, the file secret key can be obtained quickly and in real time to complete the subsequent file decryption process.
[0072] In another embodiment, if the external security device is a wearable device, the wearable device includes a first operating system and a second operating system, and the storage spaces of the first operating system and the second operating system are independent of each other; then the above-mentioned sending a secret key acquisition request to the external security device includes: sending a secret key acquisition request to the first operating system of the wearable device, and the secret key acquisition request is used to instruct the first operating system to obtain the secret key corresponding to the identifier of the target file from the second operating system.
[0073] In this embodiment, for the first operating system and the second operating system of the wearable device, reference can be made to the introduction in the previous embodiment, and this embodiment will not be elaborated again here.
[0074] In the case where the wearable device includes a first operating system and a second operating system, the terminal previously stores the file secret key in the second operating system of the wearable device. Then, when the terminal sends a secret key acquisition request to the external security device, it is to request the secret key of the file from the second operating system of the wearable device.
[0075] Optionally, the first operating system and the second operating system use different chips, and the power consumption of the first operating system in the wearable device is greater than that of the second operating system. Then, the terminal stores the file key in the second operating system with lower power consumption of the wearable device in advance, and uses the second operating system with smaller power consumption to store the correspondence between the identifier of the target file and the key, which can reduce the power consumption of the wearable device. Moreover, since the first operating system and the second operating system use different chips, even in the wearable device, chip-level physical isolation is adopted to improve the security of the target file key.
[0076] For example, the wearable device is a smart watch, the first operating system is the Android system, and the second operating system is the RTOS system. When the terminal device sends a key acquisition request to the wearable device, the key acquisition request first reaches the first operating system. After the first operating system receives the key acquisition request, it continues to request the key corresponding to the identifier of the target file from the second operating system. That is, the terminal device first sends the key acquisition request to the Android system, and after the Android system receives it, it sends it to the RTOS system. In this way, after the RTOS system receives the key acquisition request, it will respond immediately and send the key corresponding to the target file identifier to the Android system, so that the Android system will continue to send it to the terminal, realizing the fast and real-time acquisition of the file key to complete the decryption of the target file.
[0077] As Figure 6 shown, taking the wearable device as the above-mentioned dual-system and dual-mode smart watch and the terminal as a mobile phone as an example, an embodiment of storing an encrypted file key and acquiring an encrypted file key is provided. This embodiment includes:
[0078] File encryption steps:
[0079] S11, the user operates on the mobile phone to encrypt the file.
[0080] S12, the mobile phone creates an encrypted file and generates a corresponding key.
[0081] S13, the mobile phone sends the key to the big core of the smart watch.
[0082] S14, the big core of the smart watch sends the key to the small core of the smart watch.
[0083] S15, the small core of the smart watch stores the key in the independent storage space of the small core.
[0084] File decryption steps:
[0085] S21, view the encrypted file.
[0086] S22, the mobile phone obtains the key from the smart watch.
[0087] S23, The large core of the smartwatch obtains the secret key from the small core of the smartwatch.
[0088] S24, The small core of the smartwatch returns the secret key to the large core of the smartwatch.
[0089] S25, The large core of the smartwatch returns the secret key to the mobile phone.
[0090] S26, The mobile phone uses the secret key to decrypt the file.
[0091] This example provides a combined file encryption processing strategy for a mobile phone and a smartwatch with a dual-core and dual-system architecture. Since the file secret key is stored in the small core of the smartwatch, and the small core of the smartwatch uses the RTOS system with independent storage space, it can improve the security of file secret key storage, making it difficult for intruders to obtain the file secret key, thereby effectively increasing the security of mobile phone files.
[0092] It should be understood that although Figures 3 - 6 the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, there is no strict order limit for the execution of these steps, and these steps can be executed in other orders. Moreover, Figures 3 - 6 at least a part of the steps in
[0093] can include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps. Figure 1 In addition, the embodiment of the present application also provides a file secret key storage system, as shown in the above
[0094] This system includes: a terminal and an external security device; wherein, the terminal is used to receive an encryption request for a target file, generate a secret key for the target file according to the encryption request, and then send a secret key storage request to the external security device; wherein, the external security device is used to receive the secret key storage request sent by the terminal and store the corresponding relationship between the identifier of the target file and the secret key according to the secret key storage request.
[0095] In one embodiment, the external security device is a wearable device.
[0096] In one embodiment, the wearable device includes a first operating system and a second operating system, and the storage spaces of the first operating system and the second operating system are independent of each other; the first operating system of the wearable device is configured to receive a secret key storage request and store the correspondence between the identifier of the target file and the secret key in the second operating system according to the secret key storage request.
[0097] In one embodiment, the power consumption of the first operating system is greater than that of the second operating system.
[0098] In one embodiment, the first operating system and the second operating system use different chips.
[0099] In one embodiment, the first operating system is an Android system and the second operating system is an RTOS system.
[0100] In one embodiment, the wearable device is a smart watch.
[0101] In one embodiment, the terminal is further configured to receive a decryption request for the target file, and according to the decryption request, send a secret key acquisition request to an external security device; and receive the secret key returned by the external security device and decrypt the target file according to the secret key; the external security device is further configured to receive the secret key acquisition request sent by the terminal and send the secret key corresponding to the identifier of the target file to the terminal according to the secret key acquisition request.
[0102] For the file secret key storage system provided in the above embodiment, its implementation principle and technical effects are similar to those of the above file secret key storage method embodiment, and will not be elaborated here.
[0103] In addition, a virtual device corresponding to the above file secret key storage method is also provided. In one embodiment, Figure 7 It is a structural block diagram of a file secret key storage device provided for an embodiment. As Figure 7 shown, the device includes: an encryption request receiving module 10, a generating module 11, and a sending module 12, where
[0104] The encryption request receiving module 10 is configured to receive an encryption request for the target file;
[0105] The generating module 11 is configured to generate a secret key for the target file according to the encryption request;
[0106] The sending module 12 is configured to send a secret key storage request to an external security device; the secret key storage request is used to request the external security device to store the correspondence between the identifier of the target file and the secret key.
[0107] In one embodiment, the above sending module 12 is specifically configured to send a secret key storage request to the wearable device.
[0108] In one embodiment, the above-mentioned sending module 12 is further specifically configured to send a key storage request to the wearable device; the key storage request is used to request the wearable device to store the correspondence between the identifier of the target file and the key in the RTOS system.
[0109] In one embodiment, the above-mentioned sending module 12 is further specifically configured to send a key storage request to the first operating system of the wearable device, and the key storage request is used to instruct the first operating system to store the correspondence between the identifier of the target file and the key in the second operating system.
[0110] In one embodiment, the power consumption of the first operating system is greater than that of the second operating system.
[0111] In one embodiment, the first operating system and the second operating system use different chips.
[0112] In one embodiment, the first operating system is the Android system, and the second operating system is the RTOS system.
[0113] In one embodiment, the wearable device is a smart watch.
[0114] In one embodiment, a file key storage device is provided, as Figure 8 shown. The device includes: a decryption request receiving module 13, an obtaining module 14, and a decryption module 15, where
[0115] The decryption request receiving module 13 is configured to receive a decryption request for the target file;
[0116] The obtaining module 14 is configured to send a key obtaining request to an external security device according to the decryption request; the key obtaining request carries the identifier of the target file; the key obtaining request is used to request the external security device for the key corresponding to the identifier of the target file;
[0117] The decryption module 15 is configured to receive the key returned by the external security device and decrypt the target file according to the key.
[0118] In one embodiment, the above-mentioned obtaining module 14 is specifically configured to send a key obtaining request to the wearable device; the key obtaining request is used to request the RTOS system of the wearable device for the key corresponding to the identifier of the target file.
[0119] In one embodiment, the above-mentioned obtaining module 14 is further specifically configured to send a key obtaining request to the first operating system of the wearable device, and the key obtaining request is used to instruct the first operating system to obtain the key corresponding to the identifier of the target file from the second operating system.
[0120] All the file secret key storage devices provided in the above embodiments have the same implementation principles and technical effects as those in the above embodiments of the file secret key storage method, and will not be elaborated here.
[0121] The division of each module in the above file secret key storage device is only for illustrative purposes. In other embodiments, the file secret key storage device can be divided into different modules as needed to complete all or part of the functions of the above file secret key storage.
[0122] For the specific limitations of the file secret key storage device, reference can be made to the limitations on the file secret key storage method in the above text, and will not be elaborated here. Each module in the above file secret key storage device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0123] In one embodiment, an electronic device is provided. The internal structure diagram of the electronic device can be referred to the internal structure diagram of the terminal as described above Figure 2 shown. The electronic device includes a processor and a memory connected by a system bus. Among them, the processor is used to provide computing and control capabilities to support the operation of the entire electronic device. The memory may include a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The computer program can be executed by the processor to implement a file secret key storage method provided in each of the following embodiments. The internal memory provides a high-speed cache operating environment for the operating system computer program in the non-volatile storage medium. The electronic device can be any terminal device such as a mobile phone, a tablet computer, a PDA (Personal Digital Assistant), a POS (Point of Sales), a vehicle-mounted computer, a wearable device, etc.
[0124] In the embodiments of the present application, each module in the provided file secret key storage device can be in the form of a computer program. The computer program can run on a terminal or a server. The program modules formed by the computer program can be stored in the memory of the electronic device. When the computer program is executed by the processor, the steps of the method described in the embodiments of the present application are implemented.
[0125] The embodiments of the present application also provide a computer-readable storage medium. One or more non-volatile computer-readable storage media containing computer-executable instructions, when the computer-executable instructions are executed by one or more processors, cause the processors to execute the steps of the file secret key storage method.
[0126] A computer program product containing instructions, which when run on a computer, causes the computer to execute a file key storage method.
[0127] Any reference to memory, storage, database, or other media used in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM), which serves as an external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0128] The above-described embodiments merely represent several implementation manners of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of the patent of this application shall be subject to the appended claims.
Claims
1. A method for storing file keys, characterized in that, Applied to a wearable device, the wearable device includes a first processor and a second processor. The first processor is used to run a first operating system, and the second processor is used to run a second operating system. The method includes: The first operating system receives a key storage request. The key storage request includes the correspondence between the identifier of the target file and the key of the target file. In response to the key storage request, the first operating system stores the correspondence between the identifier of the target file and the key of the target file.
2. The method according to claim 1, wherein In response to the key storage request, the first operating system stores the correspondence between the identifier of the target file and the key of the target file, including: In response to the key storage request, the first operating system sends the correspondence between the identifier of the target file and the key of the target file to the second operating system. The second operating system stores the correspondence between the identifier of the target file and the key of the target file.
3. The method according to claim 1 or 2, characterized in that The method further includes: The first operating system receives a key acquisition request. The key acquisition request carries the identifier of the target file. The first operating system sends the key acquisition request to the second operating system. In response to the key acquisition request, the second operating system acquires the key corresponding to the identifier of the target file and sends the key corresponding to the identifier of the target file to the first operating system.
4. The method according to claim 1 or 2, characterized in that, The method further includes: The wearable device receives a key acquisition request sent by a terminal. The key acquisition request carries the identifier of the target file. In response to the key acquisition request, the second system sends the key corresponding to the identifier of the target file to the terminal. The second system is an RTOS system.
5. The method according to claim 1, wherein The power consumption of the first operating system is greater than that of the second operating system.
6. The method according to claim 1, characterized in that, The storage spaces of the first operating system and the second operating system are independent of each other.
7. The method according to claim 1, wherein The first operating system and the second operating system use different chips.
8. A file decryption method, characterized in that, Applied to a wearable device, the wearable device includes a first processor and a second processor. The first processor is used to run a first operating system, and the second processor is used to run a second operating system. The method includes: The wearable device receives a key acquisition request sent by a terminal. The key acquisition request carries the identifier of the target file. In response to the key acquisition request, the second system sends the key corresponding to the identifier of the target file to the terminal.
9. The method according to claim 8, wherein The wearable device receives a key acquisition request sent by a terminal. In response to the key acquisition request, the second system sends the key corresponding to the identifier of the target file to the terminal, including: The first operating system receives the key acquisition request sent by the terminal. In response to the key acquisition request, the first operating system acquires the key corresponding to the identifier of the target file from the second operating system, and the first operating system sends the key to the terminal; or, The first operating system receives the key acquisition request sent by the terminal, and the first operating system sends the key acquisition request to the second operating system. The second operating system sends the key corresponding to the file identifier to the terminal in response to the key acquisition request.
10. A file key storage system, characterized in that, The system includes: a terminal and a wearable device; the wearable device includes a first processor and a second processor. The first processor is used to run a first operating system, and the second processor is used to run a second operating system; The terminal is configured to receive an encryption request for a target file, generate a key for the target file according to the encryption request, and then send a key storage request to the external security device; the key storage request includes the correspondence between the identifier of the target file and the key of the target file; The first operating system of the wearable device is configured to receive the key storage request sent by the terminal and store the correspondence between the identifier of the target file and the key of the target file in response to the key storage request.
11. A wearable device, comprising a first processor and a second processor, the first processor being used to run a first system, and the second processor being used to run a second system; The first system is configured to execute the steps performed by the first system in the method according to any one of claims 1 to 9; The second system is configured to execute the steps performed by the second system in the method according to any one of claims 1 to 9.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the file key storage method according to any one of claims 1 to 9.