Privacy protection method and operating system

By loading the second operating system on the virtual machine in the first operating system of the electronic device for privacy password verification, the security issues caused by malicious attacks or system vulnerabilities in the privacy space are solved, and higher privacy protection and security are achieved.

CN120408714APending Publication Date: 2025-08-01VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510551802.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

In the prior art, the privacy space of electronic devices may be reduced in privacy protection due to malicious attacks or system vulnerabilities, and cannot effectively prevent the privacy space from being started without verification.

Method used

In the first operating system of the electronic device, the second operating system is loaded through a virtual machine, and a communication channel is established for privacy password verification. The privacy space is only activated after the verification is passed to ensure safe isolation.

Benefits of technology

It improves the security of starting the privacy space, reduces the risk of starting the privacy space directly caused by malicious attacks or system vulnerabilities, and enhances the security of privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408714A_ABST
    Figure CN120408714A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy protection method and an operating system, and belongs to the technical field of communication. The privacy protection method is applied to a first operating system running in the electronic equipment, the first system comprises a privacy space, and the privacy protection method can comprise the following steps: responding to a first input used for starting the privacy space, displaying a verification window, and establishing a communication channel between the privacy space and a second operating system running on a virtual machine; in response to a second input for the verification window, obtaining a to-be-verified privacy password, and sending the to-be-verified privacy password to a second operating system through the communication channel, so that the second operating system verifies the to-be-verified privacy password; obtaining a verification result returned by the second operating system through the communication channel; and under the condition that the verification result indicates that the verification is passed, starting the privacy space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of communication technologies, and particularly relates to a privacy protection method and an operating system. Background Art

[0002] Due to the need for users to use files privately, an electronic device usually sets up a private space. The user can control the startup of this private space by setting a private password for storing private files. To protect the security of the data stored in the private space, files are usually protected by encryption. If the private space is not started, the files are in an encrypted state and cannot be read or used. If the private space is started, the files will be automatically decrypted and can be read and used.

[0003] However, currently, the startup of the private space mainly intercepts the startup request through the operating system of the electronic device, jumps to the verification interface to verify the private password entered by the user, and starts the private space after the verification passes. There may be a risk that the operating system of the electronic device fails to intercept in a timely manner due to malicious attacks or system vulnerabilities, and the private space can be started without verifying the private password, resulting in a reduction in the security of privacy protection. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide a privacy protection method and an operating system, which can improve the security of privacy protection.

[0005] In a first aspect, the embodiments of this application provide a privacy protection method, which is applied to a first operating system running on an electronic device. The first system includes a private space. The method includes:

[0006] In response to a first input for starting the private space, display a verification window and establish a communication channel between the private space and a second operating system running on a virtual machine;

[0007] In response to a second input to the verification window, obtain the private password to be verified, and send the private password to be verified to the second operating system through the communication channel, so that the second operating system verifies the private password to be verified;

[0008] Obtain the verification result returned by the second operating system through the communication channel;

[0009] When the verification result indicates that the verification passes, start the private space.

[0010] In a second aspect, the embodiments of this application provide a privacy protection method, which is applied to a second operating system running on a virtual machine. The method includes:

[0011] Obtain the privacy password to be verified sent by the first operating system through the communication channel with the second operating system; the first operating system is the operating system running on the electronic device, and the first operating system includes a privacy space. The privacy password to be verified is obtained by the first operating system in response to a second input to the verification window, and the verification window is displayed in response to a first input for starting the privacy space;

[0012] Verify the privacy password to be verified;

[0013] Return the verification result to the first operating system through the communication channel, so that the first operating system starts the privacy space when the verification is passed.

[0014] In a third aspect, an embodiment of the present application provides a first operating system running on an electronic device and including a privacy space; the first operating system includes:

[0015] A privacy space startup module, configured to receive a first input for starting the privacy space and call a first privacy password module in the privacy space;

[0016] The first privacy password module is configured to display a verification window in response to a first input for starting the privacy space and call a virtual machine management module in the privacy space;

[0017] The virtual machine management module is configured to establish a communication channel between the privacy space and the second operating system running on the virtual machine;

[0018] The first privacy password module is further configured to:

[0019] In response to a second input to the verification window, obtain the privacy password to be verified and send the privacy password to be verified to the second operating system through the communication channel, so that the second operating system verifies the privacy password to be verified;

[0020] Obtain the verification result returned by the second operating system through the communication channel;

[0021] Start the privacy space when the verification result indicates that the verification is passed.

[0022] In a fourth aspect, an embodiment of the present application provides a second operating system running on a virtual machine; the second operating system includes a second privacy password module, configured to:

[0023] Obtain the privacy password to be verified sent by the first operating system through the communication channel between the privacy space and the second operating system; the first operating system is the operating system running on the electronic device, and the first operating system includes a privacy space. The privacy password to be verified is obtained by the first operating system in response to a second input to the verification window, and the verification window is displayed in response to a first input for starting the privacy space;

[0024] Verify the privacy password to be verified;

[0025] Return the verification result to the first operating system through the communication channel, so that the first operating system can start the privacy space when the verification is passed.

[0026] In a fifth aspect, an embodiment of the present application provides an electronic device, which includes a processor and a memory. The memory stores a program or instruction that can run on the processor. When the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented.

[0027] In a sixth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented.

[0028] In a seventh aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the method described in the first aspect.

[0029] In an eighth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method described in the first aspect.

[0030] In the embodiment of the present application, when starting the privacy space in the first operating system of the electronic device, the second operating system running on the virtual machine can be called to perform the verification process of the privacy password, so that the privacy space can be started only when the verification is passed. In this way, compared with the first operating system installed with many application programs, the second operating system is securely isolated from the first operating system, is not easily interfered by other application programs, and the probability of being maliciously attacked or having system vulnerabilities is greatly reduced, thereby reducing the risk of directly starting the privacy space by bypassing the privacy password verification and improving the security of privacy protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 is a schematic structural diagram of the privacy protection system provided by the embodiment of the present application;

[0032] Figure 2 is one of the flow diagrams of the privacy protection method provided by the embodiment of the present application;

[0033] Figure 3 is another flow diagram of the privacy protection method provided by the embodiment of the present application;

[0034] Figure 4 is one of the flow diagrams of the scenario embodiment of the privacy protection method provided by the embodiment of the present application;

[0035] Figure 5 It is the second flowchart of the scenario embodiment of the privacy protection method provided by the embodiments of the present application;

[0036] Figure 6 It is the third flowchart of the scenario embodiment of the privacy protection method provided by the embodiments of the present application;

[0037] Figure 7 It is the fourth flowchart of the scenario embodiment of the privacy protection method provided by the embodiments of the present application;

[0038] Figure 8 It is the structural schematic diagram of the electronic device provided by the embodiments of the present application;

[0039] Figure 9 It is the hardware structural schematic diagram of the electronic device provided by the embodiments of the present application. Detailed implementation manners

[0040] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.

[0041] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. generally belong to the same category, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the associated objects before and after.

[0042] Next, the privacy protection method provided by the embodiments of the present application will be described in detail in conjunction with the accompanying drawings, through specific embodiments and their application scenarios.

[0043] As Figure 1 shown, the privacy protection system may include a first operating system 110 running on an electronic device and a second operating system 120 running on a virtual machine. The first operating system 110 may include a privacy space 130. The privacy space 130 is a space provided on the first operating system 110 for users to privately store and use personal files, and can be implemented based on a multi-threaded manner or a multi-user manner, and no specific limitation is made here.

[0044] The first operating system 110 may include a first file management module 111 outside the privacy space 130 and a module 112 for starting the privacy space 130. The first file management module 111 may be responsible for managing files in the first operating system 110 except for the privacy space 130. The module 112 for starting the privacy space 130 may be responsible for starting the privacy space 130.

[0045] The first operating system 110 may further include a virtual machine management module 113, a second file management module 114, and a first privacy password module 115 within the privacy space 130. The virtual machine management module 113 is responsible for managing the second operating system 120 including but not limited to starting, connecting, shutting down, destroying, etc., and establishing a communication channel with the second operating system 120. The second file management module 114 is responsible for managing files in the privacy space 130. The first privacy password module 115 is responsible for setting and verifying privacy passwords.

[0046] The second operating system 120 is an operating system independent of the first operating system 110 loaded through a virtual machine, and only establishes a communication channel with the privacy space 130, and has a certain secure storage capability, that is, the second operating system 120 may include a storage area 140 for storing various data.

[0047] The second operating system 120 may include a third file management module 121, a second privacy password module 122, a key management module 123, and an encryption / decryption module 124C1. The third file management module 121 is responsible for file management in the second operating system 120. The second privacy password module 122 is responsible for setting and verifying privacy passwords. The key management module 123 is responsible for creating, storing, using, destroying, etc. keys in the second operating system 120. The encryption / decryption module 124 is responsible for encrypting and decrypting file data.

[0048] Figure 2 It is a schematic flowchart of the privacy protection method provided by an embodiment of the present application. The privacy protection method is applied to the first operating system running on an electronic device. The first operating system includes a privacy space. The privacy protection method may include:

[0049] Step 201, in response to a first input for starting the privacy space, display a verification window, and establish a communication channel between the privacy space and the second operating system running on the virtual machine.

[0050] In step 201, the electronic device may receive a first input from the user to start the privacy space. The first operating system starts the privacy space by activating the privacy space module, and calls the first privacy password module in the privacy space to display a verification window. At the same time, the first privacy password module calls the virtual machine management module, which starts a second operating system in a virtual machine and establishes a communication channel between the privacy space and the second operating system.

[0051] In step 202, in response to a second input to the verification window, obtain the privacy password to be verified, and send the privacy password to be verified to the second operating system through the communication channel, so that the second operating system verifies the privacy password to be verified.

[0052] In step 202, after the verification window is displayed, a second input from the user to the verification window can be received, and the privacy password to be verified entered by the user in the verification window can be obtained. The first privacy password module may transmit the privacy password to be verified to the second privacy password module of the second operating system through the communication channel, so that the second operating system verifies the privacy password to be verified.

[0053] Exemplarily, the second privacy password module may compare the privacy password set by the user pre-stored in the second operating system with the privacy password to be verified. If they are the same, the verification passes; if they are different, the verification fails. The second privacy password module may also obtain a random number pre-stored in the second operating system, perform key derivation based on the random number and the privacy password to be verified to obtain the privacy key to be verified, and obtain the privacy key obtained by performing key derivation based on the random number and the user-set privacy password. Compare the privacy key to be verified with the privacy key. If they are the same, the verification passes; if they are different, the verification fails. The second privacy password module may also perform a message authentication code operation on the privacy key to be verified to obtain the verification credential to be verified, and obtain the verification credential obtained by performing a message authentication code operation based on the privacy key pre-stored in the second operating system. Compare the verification credential to be verified with this verification credential. If they are the same, the verification passes; if they are different, the verification fails.

[0054] In step 203, obtain the verification result returned by the second operating system through the communication channel.

[0055] In step 203, after the second privacy password module verifies the privacy password to be verified, it may inform the first privacy password module of the verification result through the communication channel. In other words, the first privacy password module of the first operating system may obtain the verification result returned by the second privacy password module of the second operating system through the communication channel.

[0056] In step 204, when the verification result indicates that the verification passes, start the privacy space.

[0057] In step 204, if the verification result indicates that the verification is passed, it means that the privacy password to be verified is consistent with the privacy password set by the user. At this time, the user who wants to start the privacy space can be considered as the user himself / herself of the privacy space, and the privacy space can be started at this time.

[0058] In the embodiment of the present application, when starting the privacy space in the first operating system of the electronic device, the privacy protection method can call the second operating system running on the virtual machine to perform the verification process of the privacy password, so that the privacy space can be started only when the verification is passed. In this way, compared with the first operating system installed with many application programs, the second operating system is securely isolated from the first operating system, is not easily interfered by other application programs, and the probability of being maliciously attacked or having system vulnerabilities is greatly reduced, thereby reducing the risk of directly starting the privacy space by bypassing the privacy password verification and improving the security of privacy protection.

[0059] In some embodiments, after starting the privacy space, the method may further include:

[0060] Receiving a third input for a first file outside the privacy space;

[0061] In response to the third input, saving preview information of the first file in the privacy space, and sending the first file to the second operating system through a communication channel, so that the second operating system encrypts the first file based on a file key randomly generated for the first file to obtain a file ciphertext of the first file, and stores the file ciphertext of the first file.

[0062] In this embodiment, after starting the privacy space, the user can migrate files with high privacy outside the privacy space into the privacy space for storage and use, so as to avoid the files being discovered by others in the first operating system.

[0063] It is possible to receive a third input for a first file outside the privacy space, and the third input may indicate migrating the first file into the privacy space for storage.

[0064] In response to the third input, the first file is moved into the second file management module in the privacy space through the first file management module. The second file management module only retains preview information of the first file, such as file name, file type, etc., for the user to preview in the privacy space.

[0065] The second file management module can send the first file to the third file management module of the second operating system through a communication channel, so that the second operating system can encrypt the first file based on a file key randomly generated for the first file to obtain a file ciphertext of the first file, and store the file ciphertext of the first file.

[0066] In this way, only the preview information of the file can be saved in the privacy space, while the detailed content of the file is encrypted and saved in a securely isolated second operating system, reducing the risk of the file in the privacy space being cracked and leaked, and further improving the security of privacy protection.

[0067] In some embodiments, after the privacy space is launched, the method may further include:

[0068] Receiving a fourth input for the preview information of a second file, where the preview information of the second file is the preview information of any file saved in the privacy space;

[0069] In response to the fourth input, sending a request to the second operating system through a communication channel, so that in response to the request, the second operating system decrypts the file ciphertext of the pre-stored second file based on the file key corresponding to the second file to obtain the decrypted second file;

[0070] Obtaining the second file sent by the second operating system through the communication channel;

[0071] Performing an operation corresponding to the fourth input; where the operation corresponding to the fourth input includes at least one of the following:

[0072] Displaying the second file in the privacy space;

[0073] Deleting the preview information of the second file in the privacy space.

[0074] In this embodiment, when the privacy space is launched, the preview information of some files in the privacy space will be displayed to the user, and the user can select to view the file or move the file out of the privacy space according to the preview information of the file.

[0075] It is possible to receive a fourth input for the preview information of a second file. The preview information of the second file can be the preview information of any file saved in the privacy space, and the fourth input can indicate viewing the second file or moving the second file out of the privacy space.

[0076] In response to the fourth input, the second file management module can send a request to the third file management module of the second operating system through a communication channel, so that in response to the request, the second operating system decrypts the file ciphertext of the pre-stored second file based on the file key corresponding to the second file to obtain the decrypted second file.

[0077] The second file management module can obtain the second file sent by the third file management module of the second operating system through the communication channel and perform the operation corresponding to the fourth input. For example, the second file can be displayed in the privacy space.

[0078] The second file management module can also delete the preview information of the second file in the private space, and the second file management module transfers the second file to the first file management module in the first operating system for storage.

[0079] In this way, when using or moving out a file in the private space, in response to relevant input for the preview information of the file saved in the private space, after obtaining the decrypted file from the securely isolated second operating system, corresponding operations can be performed, which can reduce the risk of the files in the private space being cracked and leaked without reason, and further improve the security of privacy protection.

[0080] In some embodiments, when the operation corresponding to the fourth input includes deleting the preview information of the second file in the private space, the method may further include:

[0081] Sending a deletion instruction to the second operating system through the communication channel, so that the second operating system deletes the file ciphertext of the second file in response to the deletion instruction.

[0082] In this embodiment, if the operation corresponding to the fourth input includes deleting the preview information of the second file in the private space, it can be indicated that the user wants to move the second file out of the private space. At this time, the second file management module can send a deletion instruction to the second operating system through the communication channel, informing the third file management module to delete the corresponding file ciphertext, that is, the file ciphertext of the second file.

[0083] In some examples, the corresponding file key ciphertext can also be deleted, that is, the file key ciphertext corresponding to the second file obtained after encryption of the file key corresponding to the second file and stored in the second operating system.

[0084] In this way, after the file in the private space is moved out, the data corresponding to the file in the second operating system can be deleted, thereby releasing the storage memory of the second operating system and saving resources.

[0085] Figure 3 It is a schematic flowchart of the privacy protection method provided by the embodiments of the present application. The privacy protection method is applied to the second operating system running on a virtual machine. The privacy protection method may include:

[0086] Step 301, obtaining the privacy password to be verified sent by the first operating system through the communication channel between the private space and the second operating system; the first operating system is the operating system running on the electronic device, and the first operating system includes a private space. The privacy password to be verified is obtained by the first operating system in response to the second input to the verification window, and the verification window is displayed in response to the first input for starting the private space.

[0087] In step 301, the electronic device may receive a first input from the user to start the privacy space. The first operating system starts the privacy space by activating the privacy space module, and invokes the first privacy password module in the privacy space to display a verification window. Meanwhile, the first privacy password module invokes the virtual machine management module, which starts the second operating system in the virtual machine and establishes a communication channel between the privacy space and the second operating system.

[0088] After the verification window is displayed, the second input from the user to the verification window can be received, and the privacy password to be verified entered by the user within the verification window can be obtained. The first privacy password module may transmit the privacy password to be verified through the communication channel to the second privacy password module of the second operating system.

[0089] In other words, the second privacy password module may obtain the privacy password to be verified sent by the first privacy password module through the communication channel between the privacy space and the second operating system.

[0090] Step 302: Verify the privacy password to be verified.

[0091] In step 302, the second privacy password module may verify the privacy password to be verified. For example, the second privacy password module may compare the privacy password to be verified with the privacy password set by the user pre-stored in the second operating system. If they are the same, the verification passes; if not, the verification fails. The second privacy password module may also obtain a random number pre-stored in the second operating system, perform key derivation based on the random number and the privacy password to be verified to obtain the privacy key to be verified, and obtain the privacy key derived from the random number and the user-set privacy password. Then compare the privacy key to be verified with the privacy key. If they are the same, the verification passes; if not, the verification fails. The second privacy password module may further perform a message authentication code operation on the privacy key to be verified to obtain the verification credential to be verified, and obtain the verification credential obtained by performing a message authentication code operation on the privacy key pre-stored in the second operating system. Then compare the verification credential to be verified with this verification credential. If they are the same, the verification passes; if not, the verification fails.

[0092] Step 303: Return the verification result to the first operating system through the communication channel so that the first operating system starts the privacy space when the verification passes.

[0093] In step 303, after the second privacy password module verifies the privacy password to be verified, it may inform the first privacy password module of the verification result through the communication channel so that the first operating system starts the privacy space when the verification passes.

[0094] In an embodiment of the present application, when the privacy protection method starts the privacy space in the first operating system of the electronic device, it can call the second operating system running on the virtual machine to perform the verification process of the privacy password, so that the privacy space can be started only when the verification is passed. Thus, compared with the first operating system installed with numerous application programs, the second operating system is securely isolated from the first operating system, is not easily interfered by other application programs, and the probability of being maliciously attacked or having system vulnerabilities is greatly reduced, thereby reducing the risk of directly starting the privacy space by bypassing the privacy password verification and improving the security of privacy protection.

[0095] In some embodiments, verifying the privacy password to be verified may include:

[0096] Deriving a first privacy key based on a pre-stored random number and the privacy password to be verified;

[0097] Verifying the first privacy key based on a second privacy key, where the second privacy key is derived based on the privacy password set by the user and the random number.

[0098] In this embodiment, the second privacy password module can obtain the random number rand stored when the user sets the privacy password from the storage area of the second operating system, and derive a first privacy key based on the privacy password privacy_password1 to be verified and the random number rand.

[0099] Among them, key derivation can be implemented by algorithms such as KEYDERIVATION algorithm, Password-Based Key Derivation Function 2 (PBKDF2) algorithm, and memory-intensive key derivation function (Scrypt) algorithm, and specific limitations are not made here.

[0100] Taking the KEYDERIVATION algorithm as an example, the expression of the first privacy key can be: privacy_key1 = KEYDERIVATION(privacy_password2, rand).

[0101] When the user sets the privacy password, a second privacy key can also be generated, and the second privacy key privacy_key2 can be derived based on the privacy password privacy_password2 set by the user and the random number rand.

[0102] If the privacy password to be verified, privacy_password1, is consistent with the privacy password set by the user, privacy_password2, then the first privacy key derived from the key, privacy_key1, is also consistent with the second privacy key, privacy_key1. In this way, the first privacy key can be verified based on the second privacy key to obtain a verification result.

[0103] In this way, the verification of the privacy password can be performed based on the privacy key after key derivation, reducing the risk of privacy password leakage caused by directly storing the privacy password set by the user in the second operating system for verification, and further improving the security of privacy protection.

[0104] In some embodiments, verifying the first privacy key based on the second privacy key may include:

[0105] Performing a message authentication code operation on the first privacy key to obtain a first verification credential;

[0106] Obtaining a pre-stored second verification credential, where the second verification credential is obtained by performing a message authentication code operation on the second privacy key;

[0107] Determining that the verification is passed when the first verification credential is consistent with the second verification credential.

[0108] In this embodiment, the second privacy password module may also perform a message authentication code operation on itself using the first privacy key, privacy_key1, to obtain a first verification credential, mac1.

[0109] Among them, the message authentication code operation can be implemented by algorithms such as the Hash-based Message Authentication Code (HMAC) algorithm, the HMAC-SHA256 algorithm based on a 256-bit hash encryption function, and the HMAC-SHA384 algorithm based on a 384-bit hash encryption function.

[0110] Taking the HMAC algorithm as an example, the expression of the first verification credential can be mac1 = HMAC(privacy_key1, privacy_key1).

[0111] When the user sets the privacy password, a second verification credential, mac2, can also be obtained by performing a message authentication code operation based on the second privacy key, privacy_key2, and stored in the storage area of the second operating system.

[0112] The second verification credential mac2 stored in the storage area can be retrieved and compared with the first verification credential mac1. If the privacy password to be verified privacy_password1 is consistent with the privacy password privacy_password2 set by the user, then the first verification credential mac1 is also consistent with the second verification credential mac2. In this way, verification can be determined to pass when the first verification credential is consistent with the second verification credential.

[0113] In this way, a message authentication code operation can be performed on the privacy key derived from the key to obtain a verification credential for verifying the privacy password. On the one hand, the verification credential has fewer characters, enabling fast verification and saving computing power resources. On the other hand, it is difficult to reverse-deduce the privacy password from the verification credential pre-stored in the second operating system, further reducing the risk of privacy password leakage.

[0114] In the embodiments of the present application, as Figure 4 shown, the scenario embodiments of starting the verification process of the privacy space in the privacy protection method may include:

[0115] Step 401, the first operating system starts the privacy space, the privacy space starts a virtual machine, loads the second operating system on the virtual machine, and establishes a communication channel between the privacy space and the second operating system;

[0116] Step 402, input the privacy password to be verified in the first operating system and transmit it to the second operating system through the communication channel;

[0117] Step 403, use the verification credential to verify the privacy password to be verified in the second operating system;

[0118] Step 404, if the verification passes, the second operating system notifies the privacy space that the verification passes to start the privacy space;

[0119] Step 405, if the verification fails, the second operating system notifies the privacy space that the verification fails and the privacy space fails to start.

[0120] In some embodiments, before obtaining the privacy password to be verified sent through the communication channel between the privacy space and the second operating system, the method may further include:

[0121] Obtain the privacy password set by the user sent by the first operating system through the communication channel between the privacy space and the second operating system;

[0122] Derive a second privacy key based on a randomly generated random number and the privacy password set by the user, and store the random number;

[0123] Perform a message authentication code operation on the second privacy key to obtain a second verification credential, and store the second verification credential.

[0124] In this embodiment, when the user first starts the privacy space, a privacy password needs to be set to protect the files stored in the privacy space.

[0125] The first operating system starts the privacy space by starting the privacy space module, calls the first privacy password module in the privacy space, displays a password setting window, and at the same time the first privacy password module calls the virtual machine management module, which starts the second operating system in the virtual machine and establishes a communication channel between the privacy space and the second operating system.

[0126] The user can enter the privacy password privacy_password2 in the password setting window popped up by the first privacy password module. Subsequently, the first privacy password module transmits the privacy password privacy_password2 set by the user to the second privacy password module of the second operating system through the communication channel.

[0127] In other words, the second privacy password module can obtain the privacy password privacy_password2 set by the user sent by the first operating system through the communication channel between the privacy space and the second operating system.

[0128] The second privacy password module can generate a random number rand, and perform key derivation based on the privacy password privacy_password2 set by the user and the random number rand to obtain a second privacy key. For example, the second privacy key can be: privacy_key2 = KEYDERIVATION(privacy_password2, rand). Subsequently, the second privacy password module saves the random number rand in the storage area of the second operating system.

[0129] The second privacy password module can also perform a message authentication code operation on itself using the second privacy key privacy_key2 to obtain a second verification credential.

[0130] For example, the second verification credential can be: mac2 = HMAC(privacy_key2, privacy_key2). The second privacy password module can save the second verification credential mac2 in the storage area of the second operating system.

[0131] In this way, during privacy password setting, key derivation and message authentication code operation can be performed based on the privacy password set by the user to obtain and store the second verification credential, so that the privacy password can be verified based on the second verification credential subsequently. On the one hand, the verification credential has fewer characters, which can achieve fast verification and save computing power resources. On the other hand, it is difficult to reverse-derive the privacy password from the verification credential, further reducing the risk of privacy password leakage.

[0132] In some embodiments, after deriving a second privacy key based on a randomly generated random number and a privacy password set by a user, the method may further include:

[0133] Encrypting a randomly generated root key according to the second privacy key to obtain a ciphertext of the root key, and storing the ciphertext of the root key;

[0134] After verifying a privacy password to be verified, the method further includes:

[0135] In the case of successful verification, decrypting the ciphertext of the root key using a first privacy key to obtain the root key; the first privacy key is derived based on the privacy password to be verified and the random number.

[0136] In this embodiment, when setting the privacy password, after obtaining the second privacy key, the second privacy password module may pass the generated second privacy key privacy_key2 to the key management module. Subsequently, the key management module may randomly generate a root key root_key, and encrypt the root key root_key using the second privacy key privacy_key2 to obtain a ciphertext of the root key root_key_cipher = ENC(privacy_key1, root_key). The key management module may save the ciphertext of the root key root_key_cipher in the storage area of the second operating system.

[0137] Among them, the encryption algorithm may be a symmetric encryption algorithm or an asymmetric encryption algorithm, and no specific limitation is made here.

[0138] After verifying the privacy password to be verified, if the verification is successful, then at this time the first privacy key privacy_key1 is the same as the second privacy key privacy_key2, and at this time the ciphertext of the root key may be decrypted using the first privacy key to obtain the root key.

[0139] In this way, the randomly generated root key can be encrypted by the privacy key, and the ciphertext of the root key can be saved, so that the file key can be encrypted according to the root key subsequently, protecting the root key from being leaked, further protecting the file key from being leaked, and further improving the security of privacy protection.

[0140] In the embodiments of the present application, as Figure 5 shown, the scenario embodiments of the privacy password setting process in the privacy protection method may include:

[0141] Step 501, the first operating system starts the privacy space, the privacy space starts the virtual machine, loads the second operating system on the virtual machine, and establishes a communication channel between the privacy space and the second operating system;

[0142] Step 502: Input the privacy password set by the user in the first operating system, transmit it to the second operating system through the communication channel, and generate a second privacy key in the second operating system.

[0143] Step 503: Randomly generate a root key in the second operating system, encrypt the root key using the second privacy key to obtain a ciphertext of the root key, and save it.

[0144] Step 504: Generate a second verification credential based on the privacy password set by the user in the second operating system and save it.

[0145] In some embodiments, after returning the verification result to the first operating system when the verification result indicates that the verification is passed, the method may further include:

[0146] When the preview information of the first file is saved in the privacy space, obtain the first file sent by the first operating system through the communication channel.

[0147] Encrypt the first file using a randomly generated file key corresponding to the first file to obtain a ciphertext of the first file and store it.

[0148] Encrypt the file key corresponding to the first file using the root key to obtain a ciphertext of the file key corresponding to the first file and store it.

[0149] In this embodiment, after the privacy space is started, the user can migrate highly private files outside the privacy space into the privacy space for storage and use, avoiding the files being discovered by others in the first operating system.

[0150] In response to a third input to the first file outside the privacy space, the first file is moved into the second file management module in the privacy space through the first file management module. The second file management module only retains the preview information of the first file, such as the file name, file type, etc., for the user to preview within the privacy space. At this time, the second file management module can send the first file to the third file management module of the second operating system through the communication channel.

[0151] In other words, the third file management module can obtain the first file file sent by the first operating system through the communication channel. The third file management module requests the encryption storage of the first file file from the encryption and decryption module. After receiving the encryption storage request, the encryption and decryption module requests the file key corresponding to the first file from the key management module.

[0152] After the key management module receives a file key request, it randomly generates a file key file_key as the file key corresponding to the first file. At the same time, the key management module encrypts the file key file_key corresponding to the first file using the root key root_key to obtain the ciphertext of the file key file_key_cipher = ENC(root_key, file_key) corresponding to the first file, and saves the ciphertext of the file key file_key_cipher corresponding to the first file in the storage area. After successful storage, the file key file_key corresponding to the first file is passed to the encryption / decryption module.

[0153] After the encryption / decryption module receives the file key file_key corresponding to the first file, it encrypts the first file file to obtain the ciphertext of the first file file_cipher = ENC(file_key, file), and saves the ciphertext of the first file file_cipher in the storage area.

[0154] In this way, only the preview information of the file can be saved in the privacy space, while the detailed content of the file is encrypted and saved in the second operating system with security isolation, and the encryption of the file can be coupled with the privacy password, effectively preventing the file from being cracked by other users who do not know the privacy password, and further improving the security of privacy protection.

[0155] In the embodiments of the present application, as Figure 6 shown, the scenario embodiments of the file protection process in the privacy protection method may include:

[0156] Step 601, move the file in the first file management module to the third file management module by the second file management module through the communication channel between the privacy space and the second operating system;

[0157] Step 602, the third file management module requests file encryption storage from the encryption / decryption module;

[0158] Step 603, the encryption / decryption module requests a file key from the key management module;

[0159] Step 604, the key management module generates a file key, encrypts the file key using the root key to obtain the file key cipher and saves it, and passes the file key to the encryption / decryption module;

[0160] Step 605, the encryption / decryption module encrypts the file using the file key to obtain the file ciphertext and saves it.

[0161] In some embodiments, when the verification result indicates that the verification is passed, after returning the verification result to the privacy space, the method may further include:

[0162] Obtain a request sent by the first operating system through a communication channel. The request is generated by the first operating system in response to a fourth input for the preview information of a second file, and the preview information of the second file is the preview information of any file stored in the privacy space;

[0163] In response to the request, obtain the file key ciphertext corresponding to the second file and the file ciphertext of the second file that are pre-stored;

[0164] Decrypt the file key ciphertext corresponding to the second file according to the root key to obtain the file key corresponding to the second file;

[0165] Decrypt the file ciphertext of the second file according to the file key corresponding to the second file to obtain the decrypted second file;

[0166] Send the second file to the first operating system through the communication channel so that the first operating system performs the operation corresponding to the fourth input; wherein, the operation corresponding to the fourth input includes at least one of the following:

[0167] Display the second file in the privacy space;

[0168] Delete the preview information of the second file in the privacy space.

[0169] In this embodiment, when the privacy space is started, the preview information of some files in the privacy space will be displayed to the user, and the user can select to view the file or move the file out of the privacy space according to the preview information of the file.

[0170] In response to a fourth input for the preview information of a second file, the preview information of the second file can be the preview information of any file stored in the privacy space. The second file management module can send a request to the third file management module of the second operating system through the communication channel, and the request can be a file reading request or a file moving out request.

[0171] After receiving the request, the third file management module can locate and obtain the file ciphertext file_cihper of the second file from the storage area and request decryption from the encryption and decryption module.

[0172] After receiving the decryption request, the encryption and decryption module requests the file key file_key corresponding to the second file from the key management module.

[0173] After the key management module receives the request for the file key corresponding to the second file, it obtains the file key ciphertext file_key_cipher corresponding to the second file from the storage area, and uses the root key root_key to decrypt the file key ciphertext file_key_cipher corresponding to the second file, obtaining the file key corresponding to the second file file_key = DEC(root_key, file_key_cipher), and transmits the file key corresponding to the second file to the encryption and decryption module.

[0174] After the encryption and decryption module obtains the file key file_key corresponding to the second file, it uses the file key file_key corresponding to the second file to decrypt the file ciphertext file_cipher of the second file, obtains the second file file=DEC(file_key,file_cipher), and returns the second file to the third file management module.

[0175] The third file management module may transmit the received second file to the second file management module through the communication channel, so that the second file management module may perform an operation corresponding to the fourth input on the second file.

[0176] For example, the second file management module can display the second file in the private space. The second file management module can also delete the preview information of the second file in the private space, and transfer the second file to the first file management module in the first operating system for storage.

[0177] In this way, when using or moving files in the privacy space, you can respond to the relevant input of preview information of the files saved in the privacy space, obtain the decrypted files from the securely isolated second operating system, and then perform the corresponding operations. The decryption of the file can be coupled with the privacy password, effectively preventing the file from being cracked and used by other users who do not know the privacy password, further improving the security of privacy protection.

[0178] In the embodiments of this application, Figure 7 As shown, a scenario embodiment of the file display process in the privacy protection method may include:

[0179] Step 701: The PrivateSpace initiates a request (e.g., a file read request) to the second operating system.

[0180] Step 702: The third file management module initiates a file decryption request;

[0181] Step 703: The encryption / decryption module initiates a file key request to the key management module;

[0182] Step 704: The key management module processes the file key request, decrypts the file key to obtain the corresponding file key, and returns it to the encryption / decryption module.

[0183] Step 705: The encryption / decryption module decrypts the corresponding file ciphertext using the file key and returns the decrypted file to the second file management module of the privacy space.

[0184] Step 706: The second file management module displays the decrypted file in the private space.

[0185] In some embodiments, when the operation corresponding to the fourth input includes deleting the preview information of the second file in the privatespace, the method may further include:

[0186] Obtaining a deletion instruction sent by the first operating system through the communication channel;

[0187] In response to the deletion instruction, the file key ciphertext corresponding to the second file and the file ciphertext of the second file are deleted.

[0188] In this embodiment, if the operation corresponding to the fourth input includes deleting the preview information of the second file in the private space, it may indicate that the user wants to move the second file out of the private space. At this time, the second file management module can send a deletion instruction to the second operating system through the communication channel.

[0189] In other words, the third file management module can obtain the deletion instruction sent by the first operating system through the communication channel, and in response to the deletion instruction, delete the corresponding file key ciphertext and file ciphertext, that is, the file key ciphertext corresponding to the second file and the file ciphertext of the second file.

[0190] In this way, after the file in the privacy space is moved out, the data corresponding to the file in the second operating system can be deleted, thereby freeing up the storage memory of the second operating system and saving resources.

[0191] In the embodiments of this application, Figure 7 As shown, the scenario embodiment of the file removal process in the privacy protection method may include:

[0192] Step 701: The PrivateSpace initiates a request (e.g., a file removal request) to the second operating system.

[0193] Step 702: The third file management module initiates a file decryption request;

[0194] Step 703: The encryption / decryption module initiates a file key request to the key management module;

[0195] Step 704: The key management module processes the file key request, decrypts the file key to obtain the corresponding file key, and returns it to the encryption / decryption module.

[0196] Step 705: The encryption / decryption module decrypts the corresponding file ciphertext using the file key and returns the decrypted file to the second file management module in the private space.

[0197] Step 707: The second file management module moves the decrypted file to the first file management module and deletes the preview information of the corresponding file in the private space.

[0198] Step 708: The second operating system deletes the ciphertext data related to the file (file ciphertext and file key ciphertext).

[0199] In the privacy protection method provided by the embodiments of the present application, the execution entity can be an operating system. In the embodiments of the present application, the method of the operating system implementing privacy protection is taken as an example to illustrate the first operating system and the second operating system provided by the embodiments of the present application.

[0200] As Figure 1 shown, the first operating system runs on the electronic device and includes a private space 130; the first operating system may include:

[0201] A private space startup module 112, which is used to receive a first input for starting the private space 130 and call the first privacy password module 115 in the private space 130;

[0202] The first privacy password module 115 is used to display a verification window in response to the first input for starting the private space 130 and call the virtual machine management module 113 in the private space 130;

[0203] The virtual machine management module 113 is used to establish a communication channel between the private space 130 and the second operating system 120 running on the virtual machine; [[ID=X]]

[0204] The first privacy password module 115 is further used for:

[0205] In response to a second input to the verification window, obtaining a privacy password to be verified and sending the privacy password to be verified to the second operating system 120 through the communication channel, so that the second operating system 120 verifies the privacy password to be verified;

[0206] Obtaining the verification result returned by the second operating system 120 through the communication channel;

[0207] When the verification result indicates that the verification is passed, starting the private space 130.

[0208] In this way, when starting the privacy space in the first operating system of the electronic device, the second operating system running on the virtual machine is called to perform the verification process of the privacy password, so that the privacy space can be started only when the verification is passed. In this way, compared with the first operating system installed with numerous application programs, the second operating system is securely isolated from the first operating system, is not easily interfered by other application programs, and the probability of being maliciously attacked or having system vulnerabilities is greatly reduced, thereby reducing the risk of directly starting the privacy space by bypassing the privacy password verification and improving the security of privacy protection.

[0209] In some embodiments, the first operating system 110 may further include:

[0210] A first file management module 111, configured to receive a third input for a first file outside the privacy space 130;

[0211] A second file management module 114, configured to, in response to the third input, save the preview information of the first file in the privacy space 130, and send the first file to the second operating system 120 through a communication channel, so that the second operating system 120 encrypts the first file based on a randomly generated file key corresponding to the first file to obtain a file ciphertext of the first file, and stores the file ciphertext of the first file.

[0212] In this way, only the preview information of the file can be saved in the privacy space, while the detailed content of the file is encrypted and saved in the securely isolated second operating system, reducing the risk of the file in the privacy space being cracked and leaked, and further improving the security of privacy protection.

[0213] In some embodiments, the first operating system 110 may further include a second file management module 114, configured to:

[0214] Receive a fourth input for the preview information of a second file, where the preview information of the second file is the preview information of any file saved in the privacy space 130;

[0215] In response to the fourth input, send a request to the second operating system 120 through a communication channel, so that the second operating system 120 decrypts the pre-stored file ciphertext of the second file based on the file key corresponding to the second file in response to the request to obtain the decrypted second file;

[0216] Obtain the second file sent by the second operating system 120 through the communication channel;

[0217] Execute the operation corresponding to the fourth input; where the operation corresponding to the fourth input includes at least one of the following:

[0218] Display the second file in the privacy space 130;

[0219] Delete the preview information of the second file in the private space 130.

[0220] In this way, when using or moving out a file in the private space, in response to relevant input of the preview information of the file saved in the private space, after obtaining the decrypted file from the second operating system with secure isolation, corresponding operations can be performed, which can reduce the risk of the file in the private space being cracked and leaked without reason, and further improve the security of privacy protection.

[0221] As Figure 1 shown, the second operating system 120 runs on a virtual machine. The second operating system 120 includes a second privacy password module 122, which is used for:

[0222] Obtain the privacy password to be verified sent by the first operating system 110 through the communication channel between the private space 130 and the second operating system 120; the first operating system 110 is the operating system running on the electronic device, and the first operating system 110 includes the private space 130. The privacy password to be verified is obtained by the first operating system 110 in response to the second input to the verification window, and the verification window is displayed in response to the first input for starting the private space 130;

[0223] Verify the privacy password to be verified;

[0224] Return the verification result to the first operating system 110 through the communication channel, so that the first operating system 110 starts the private space 130 when the verification is passed.

[0225] In this way, when starting the private space in the first operating system of the electronic device, the second operating system running on the virtual machine is called to perform the privacy password verification process, so that the private space will be started only when the verification is passed. In this way, compared with the first operating system installed with many application programs, the second operating system is securely isolated from the first operating system, is not easily interfered by other application programs, and the probability of being maliciously attacked or having system vulnerabilities is greatly reduced, thereby reducing the risk of directly starting the private space by bypassing the privacy password verification and improving the security of privacy protection.

[0226] In some embodiments, the second privacy password module 122 can also be used for:

[0227] Derive a first privacy key based on a pre-stored random number and the privacy password to be verified;

[0228] Verify the first privacy key based on a second privacy key, where the second privacy key is derived based on the privacy password set by the user and the random number.

[0229] In this way, the privacy password can be verified based on the privacy key derived from the key, reducing the risk of privacy password leakage caused by directly storing the user-set privacy password in the second operating system for verification, and further improving the security of privacy protection.

[0230] In some embodiments, the second privacy password module 122 can also be used for:

[0231] Performing a message authentication code operation on the first privacy key to obtain a first verification credential;

[0232] Obtaining a pre-stored second verification credential, where the second verification credential is obtained by performing a message authentication code operation on the second privacy key;

[0233] Determining that the verification is passed when the first verification credential is consistent with the second verification credential.

[0234] In this way, a message authentication code operation can be performed on the privacy key derived from the key to obtain a verification credential for verifying the privacy password. On the one hand, the verification credential has fewer characters, enabling fast verification and saving computing power resources. On the other hand, it is difficult to reverse-deduce the privacy password from the verification credential stored in advance by the second operating system, further reducing the risk of privacy password leakage.

[0235] In some embodiments, the second operating system 120 may further include a storage area 140; the second privacy password module 122 can also be used for:

[0236] Obtaining the user-set privacy password sent by the first operating system 110 through the communication channel between the privacy space 130 and the second operating system 120;

[0237] Deriving a second privacy key based on a randomly generated random number and the user-set privacy password, and storing the random number in the storage area 140;

[0238] Performing a message authentication code operation on the second privacy key to obtain a second verification credential, and storing the second verification credential in the storage area 140.

[0239] In this way, when setting the privacy password, key derivation and message authentication code operation can be performed based on the user-set privacy password to obtain and store the second verification credential, so that the privacy password can be verified based on the second verification credential subsequently. On the one hand, the verification credential has fewer characters, enabling fast verification and saving computing power resources. On the other hand, it is difficult to reverse-deduce the privacy password from the verification credential, further reducing the risk of privacy password leakage.

[0240] In some embodiments, the second operating system 120 may further include a key management module 123 for:

[0241] Encrypt the randomly generated root key according to the second privacy key to obtain the ciphertext of the root key, and store the ciphertext of the root key in the storage area 140;

[0242] In the case of successful verification, decrypt the ciphertext of the root key using the first privacy key to obtain the root key; the first privacy key is derived based on the privacy password to be verified and a random number.

[0243] In this way, the randomly generated root key can be encrypted by the privacy key, and the ciphertext of the root key can be saved, so that the file key can be encrypted according to the root key subsequently, protecting the root key from being leaked, further protecting the file key from being leaked, and further improving the security of privacy protection.

[0244] In some embodiments, the second operating system 120 may further include:

[0245] A third file management module 121, configured to obtain the first file sent by the first operating system 110 through the communication channel when the preview information of the first file is saved in the privacy space 130;

[0246] An encryption and decryption module 124, configured to encrypt the first file based on the randomly generated file key corresponding to the first file to obtain the file ciphertext of the first file and store it;

[0247] The key management module 123 is further configured to: encrypt the file key corresponding to the first file according to the root key to obtain the file key ciphertext corresponding to the first file and store it in the storage area 140.

[0248] In this way, only the preview information of the file can be saved in the privacy space, while the detailed content of the file is encrypted and saved in the securely isolated second operating system, and the encryption of the file can be coupled with the privacy password, effectively preventing the file from being cracked by other users who do not know the privacy password, and further improving the security of privacy protection.

[0249] In some embodiments, the second operating system 120 may further include:

[0250] A third file management module 121, configured to obtain a request sent by the first operating system 110 through the communication channel, where the request is generated by the first operating system 110 in response to a fourth input to the preview information of the second file, and the preview information of the second file is the preview information of any file saved in the privacy space 130; in response to the request, obtain the file key ciphertext corresponding to the second file and the file ciphertext of the second file stored in advance;

[0251] The key management module 123 is further configured to decrypt the file key ciphertext corresponding to the second file according to the root key to obtain the file key corresponding to the second file;

[0252] An encryption / decryption module 124, configured to decrypt the file ciphertext of the second file according to the file key corresponding to the second file to obtain the decrypted second file;

[0253] The third file management module 121 is further configured to send the second file to the first operating system 110 through a communication channel, so that the first operating system 110 executes an operation corresponding to a fourth input; wherein, the operation corresponding to the fourth input includes at least one of the following:

[0254] Display the second file in the privacy space 130;

[0255] Delete the preview information of the second file in the privacy space 130.

[0256] In this way, when using or moving out a file in the privacy space, in response to a relevant input of the preview information of the file saved in the privacy space, the decrypted file can be obtained from the securely isolated second operating system and then the corresponding operation can be performed, and the decryption of the file can be coupled with the privacy password, effectively preventing the file from being cracked and used by other users who do not know the privacy password, and further improving the security of privacy protection.

[0257] The operating system in the embodiments of the present application may be an electronic device or a component in an electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal or other devices other than a terminal. Exemplarily, the electronic device may be a mobile phone, a tablet computer, a laptop computer, a handheld computer, a vehicle-mounted electronic device, a Mobile Internet Device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc., and may also be a server, a Network Attached Storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiments of the present application do not make specific limitations.

[0258] The privacy protection device in the embodiments of the present application may be a device with an operating system. The operating system may be an Android operating system, an IOS operating system, or other possible operating systems. The embodiments of the present application do not make specific limitations.

[0259] The privacy protection device provided in the embodiment of the present application can implement Figures 2 to 7 each process implemented by the method embodiment. To avoid repetition, it will not be elaborated here.

[0260] Optionally, as Figure 8 shown, the embodiment of the present application further provides an electronic device 800, including a processor 801 and a memory 802. A program or instruction that can run on the processor 801 is stored on the memory 802. When the program or instruction is executed by the processor 801, it implements each step of the above privacy protection method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0261] It should be noted that the electronic device in the embodiment of the present application includes the above-mentioned mobile electronic device and non-mobile electronic device.

[0262] Figure 9 is a schematic hardware structure diagram of the electronic device provided by the embodiment of the present application.

[0263] The electronic device 900 includes but is not limited to: a radio frequency unit 901, a network module 902, an audio output unit 903, an input unit 904, a sensor 905, a display unit 906, a user input unit 907, an interface unit 908, a memory 909, and a processor 910 and other components.

[0264] Those skilled in the art can understand that the electronic device 900 may further include a power supply (such as a battery) for supplying power to each component. The power supply can be logically connected to the processor 910 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption management through the power management system. Figure 9 The electronic device structure shown in does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0265] Among them, the display unit 906 can be used to: in response to a first input for starting a privacy space, display a verification window;

[0266] The processor 910 can be used to:

[0267] Establish a communication channel between the privacy space and a second operating system running on a virtual machine;

[0268] In response to a second input to the verification window, obtain a privacy password to be verified, and send the privacy password to be verified to the second operating system through the communication channel, so that the second operating system verifies the privacy password to be verified;

[0269] Obtain the verification result returned by the second operating system through the communication channel;

[0270] When the verification result indicates that the verification is passed, the privacy space is started.

[0271] In this way, when starting the privacy space in the first operating system of the electronic device, the second operating system running on the virtual machine is called to perform the verification process of the privacy password, so that the privacy space will be started only when the verification is passed. In this way, compared with the first operating system installed with many application programs, the second operating system is securely isolated from the first operating system, is not easily interfered by other application programs, and the probability of being maliciously attacked or having system vulnerabilities is greatly reduced, thereby reducing the risk of directly starting the privacy space by bypassing the privacy password verification and improving the security of privacy protection.

[0272] In some embodiments, the user input unit 907 can be used for:

[0273] Receiving a third input for a first file outside the privacy space;

[0274] The processor 910 can also be used for:

[0275] In response to the third input, saving the preview information of the first file in the privacy space, and sending the first file to the second operating system through the communication channel, so that the second operating system encrypts the first file based on the file key corresponding to the randomly generated first file to obtain the file ciphertext of the first file, and stores the file ciphertext of the first file.

[0276] In this way, only the preview information of the file can be saved in the privacy space, while the detailed content of the file is encrypted and saved in the securely isolated second operating system, reducing the risk of the file in the privacy space being cracked and leaked, and further improving the security of privacy protection.

[0277] In some embodiments, the user input unit 907 can be used for:

[0278] Receiving a fourth input for the preview information of a second file, where the preview information of the second file is the preview information of any file saved in the privacy space;

[0279] The processor 910 can also be used for:

[0280] In response to the fourth input, sending a request to the second operating system through the communication channel, so that the second operating system decrypts the pre-stored file ciphertext of the second file based on the file key corresponding to the second file in response to the request to obtain the decrypted second file;

[0281] Obtaining the second file sent by the second operating system through the communication channel;

[0282] Perform the operation corresponding to the fourth input; wherein, the operation corresponding to the fourth input includes at least one of the following:

[0283] Display the second file in the privacy space;

[0284] Delete the preview information of the second file in the privacy space.

[0285] In this way, when using or moving out a file in the privacy space, in response to the relevant input of the preview information of the file saved in the privacy space, after obtaining the decrypted file from the securely isolated second operating system, the corresponding operation can be performed, which can reduce the risk of the file in the privacy space being cracked and leaked without reason, and further improve the security of privacy protection.

[0286] Wherein, the processor 910 can be used for:

[0287] Obtain the privacy password to be verified sent by the first operating system through the communication channel between the privacy space and the second operating system; the first operating system is the operating system running on the electronic device, and the first operating system includes a privacy space, and the privacy password to be verified is obtained by the first operating system in response to the second input to the verification window, and the verification window is displayed in response to the first input for starting the privacy space.

[0288] Verify the privacy password to be verified.

[0289] Return the verification result to the first operating system through the communication channel, so that the first operating system starts the privacy space when the verification is passed.

[0290] In this way, when starting the privacy space in the first operating system of the electronic device, the second operating system running on the virtual machine is called to perform the privacy password verification process, so that the privacy space will be started only when the verification is passed. In this way, compared with the first operating system installed with many application programs, the second operating system is securely isolated from the first operating system, is not easily interfered by other application programs, and the probability of being maliciously attacked or having system vulnerabilities is greatly reduced, thereby reducing the risk of directly starting the privacy space by bypassing the privacy password verification and improving the security of privacy protection.

[0291] In some embodiments, the processor 910 can also be used for:

[0292] Derive a first privacy key based on a pre-stored random number and the privacy password to be verified;

[0293] Verify the first privacy key based on a second privacy key, wherein the second privacy key is derived based on the privacy password set by the user and the random number.

[0294] In this way, the privacy password can be verified based on the privacy key derived from the secret key, reducing the risk of privacy password leakage caused by directly storing the user-set privacy password in the second operating system for verification, and further improving the security of privacy protection.

[0295] In some embodiments, the processor 910 may further be configured to:

[0296] Perform a message authentication code operation on the first privacy key to obtain a first verification credential;

[0297] Obtain a pre-stored second verification credential, where the second verification credential is obtained by performing a message authentication code operation on the second privacy key;

[0298] Determine that the verification is passed when the first verification credential is consistent with the second verification credential.

[0299] In this way, a message authentication code operation can be performed on the privacy key derived from the secret key to obtain a verification credential for verifying the privacy password. On the one hand, the verification credential has fewer characters, enabling fast verification and saving computing power resources. On the other hand, it is difficult to reverse-deduce the privacy password from the verification credential pre-stored in the second operating system, further reducing the risk of privacy password leakage.

[0300] In some embodiments, the processor 910 may further be configured to:

[0301] Obtain the user-set privacy password sent by the first operating system through the communication channel between the privacy space and the second operating system;

[0302] Derive a second privacy key based on a randomly generated random number and the user-set privacy password, and store the random number;

[0303] Perform a message authentication code operation on the second privacy key to obtain a second verification credential, and store the second verification credential.

[0304] In this way, when setting the privacy password, key derivation and message authentication code operation can be performed based on the user-set privacy password to obtain and store the second verification credential, so that the privacy password can be verified based on the second verification credential later. On the one hand, the verification credential has fewer characters, enabling fast verification and saving computing power resources. On the other hand, it is difficult to reverse-deduce the privacy password from the verification credential, further reducing the risk of privacy password leakage.

[0305] In some embodiments, the processor 910 may further be configured to:

[0306] Encrypt the randomly generated root key according to the second privacy key to obtain a root key ciphertext, and store the root key ciphertext;

[0307] After verifying the privacy password to be verified, the method further includes:

[0308] In the case of successful verification, use the first privacy key to decrypt the root key ciphertext to obtain the root key; the first privacy key is derived based on the privacy password to be verified and a random number.

[0309] In this way, the randomly generated root key can be encrypted with the privacy key, and the root key ciphertext can be saved, so that the file key can be encrypted according to the root key subsequently, protecting the root key from being leaked, further protecting the file key from being leaked, and further improving the security of privacy protection.

[0310] In some embodiments, the processor 910 can also be used for:

[0311] When the preview information of the first file is saved in the privacy space, obtain the first file sent by the first operating system through the communication channel;

[0312] Encrypt the first file based on the randomly generated file key corresponding to the first file to obtain the file ciphertext of the first file and store it;

[0313] Encrypt the file key corresponding to the first file with the root key to obtain the file key ciphertext corresponding to the first file and store it.

[0314] In this way, only the preview information of the file can be saved in the privacy space, while the detailed content of the file is encrypted and saved in the securely isolated second operating system, and the encryption of the file can be coupled with the privacy password, effectively preventing the file from being cracked by other users who do not know the privacy password, and further improving the security of privacy protection.

[0315] In some embodiments, the processor 910 can also be used for:

[0316] Obtain a request sent by the first operating system through the communication channel, where the request is generated by the first operating system in response to a fourth input to the preview information of the second file, and the preview information of the second file is the preview information of any file saved in the privacy space;

[0317] In response to the request, obtain the file key ciphertext corresponding to the second file and the file ciphertext of the second file stored in advance;

[0318] Decrypt the file key ciphertext corresponding to the second file with the root key to obtain the file key corresponding to the second file;

[0319] Decrypt the file ciphertext of the second file with the file key corresponding to the second file to obtain the decrypted second file;

[0320] Send a second file to the first operating system via a communication channel so that the first operating system performs an operation corresponding to a fourth input; wherein, the operation corresponding to the fourth input includes at least one of the following:

[0321] Display the second file in the privacy space;

[0322] Delete the preview information of the second file in the privacy space.

[0323] In this way, when using or moving out a file in the privacy space, in response to a relevant input to the preview information of the file saved in the privacy space, after obtaining the decrypted file from the second operating system with security isolation, the corresponding operation can be performed, and the decryption of the file can be coupled with the privacy password, effectively preventing the file from being cracked and used by other users who do not know the privacy password, and further improving the security of privacy protection.

[0324] It should be understood that in the embodiments of the present application, the input unit 904 may include a Graphics Processing Unit (GPU) 9041 and a microphone 9042. The graphics processor 9041 processes the image data of static pictures or videos obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 906 may include a display panel 9061, and the display panel 9061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 907 includes at least one of a touch panel 9071 and other input devices 9072. The touch panel 9071 is also called a touch screen. The touch panel 9071 may include two parts: a touch detection device and a touch controller. The other input devices 9072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be elaborated here.

[0325] The memory 909 can be used to store software programs and various data. The memory 909 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area may store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 909 may include a volatile memory or a non-volatile memory, or the memory 909 may include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synch link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM). The memory 909 in the embodiments of the present application includes but is not limited to these and any other suitable types of memories.

[0326] The processor 910 may include one or more processing units; optionally, the processor 910 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor may not be integrated into the processor 910 either.

[0327] The embodiments of the present application also provide a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements each process of the above-mentioned embodiment of the privacy protection method and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0328] Among them, the processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media such as computer read-only memory ROM, random access memory RAM, magnetic disks, or optical discs.

[0329] Another embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement each process of the above-mentioned embodiment of the privacy protection method and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0330] It should be understood that the chip mentioned in the embodiments of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip.

[0331] The embodiments of the present application provide a computer program product. The program product is stored in a storage medium and is executed by at least one processor to implement each process of the above-mentioned embodiment of the privacy protection method and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0332] It should be noted that in this article, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article, or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, the features described with reference to certain examples may be combined in other examples.

[0333] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described example methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0334] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

Claims

1. A privacy protection method, characterized in that, Applied to a first operating system running on an electronic device, the first operating system including a privacy space; the method includes: In response to a first input for starting the privacy space, display a verification window and establish a communication channel between the privacy space and a second operating system running on a virtual machine; In response to a second input to the verification window, obtain a privacy password to be verified and send the privacy password to be verified to the second operating system through the communication channel, so that the second operating system verifies the privacy password to be verified; Obtain the verification result returned by the second operating system through the communication channel; When the verification result indicates verification passed, start the privacy space.

2. The method according to claim 1, characterized in that, After starting the privacy space, the method further includes: Receive a third input for a first file outside the privacy space; In response to the third input, save preview information of the first file in the privacy space and send the first file to the second operating system through the communication channel, so that the second operating system encrypts the first file based on a file key randomly generated for the first file to obtain a file ciphertext of the first file and stores the file ciphertext of the first file.

3. The method according to claim 1, wherein After starting the privacy space, the method further includes: ​ ​ ​ ​ ​ ​ 4. A privacy protection method, characterized in that, ​ ​ ​ ​ 5. The method according to claim 4, characterized in that ​ ​ Verify the first private key based on the second private key, where the second private key is derived based on a privacy password set by a user and the random number.

6. The method according to claim 5, wherein The verifying the first private key based on the second private key includes: Performing a message authentication code operation on the first private key to obtain a first verification credential; Obtaining a pre-stored second verification credential, where the second verification credential is obtained by performing a message authentication code operation on the second private key; Determining that the verification is passed when the first verification credential is consistent with the second verification credential.

7. The method according to any one of claims 4 to 6, characterized in that Before obtaining the privacy password to be verified sent through a communication channel between the privacy space and the second operating system, the method further includes: Obtaining the privacy password set by the user sent by the first operating system through the communication channel between the privacy space and the second operating system; Deriving a second private key based on a randomly generated random number and the privacy password set by the user, and storing the random number; Performing a message authentication code operation on the second private key to obtain a second verification credential, and storing the second verification credential.

8. The method according to claim 7, wherein After deriving the second private key based on the randomly generated random number and the privacy password set by the user, the method further includes: Encrypting a randomly generated root key according to the second private key to obtain a root key ciphertext, and storing the root key ciphertext; After verifying the privacy password to be verified, the method further includes: When the verification is passed, decrypting the root key ciphertext using the first private key to obtain the root key; the first private key is derived based on the privacy password to be verified and the random number.

9. The method according to claim 8, wherein When the verification result indicates that the verification is passed, after returning the verification result to the first operating system, the method further includes: When preview information of a first file is saved in the privacy space, obtaining the first file sent by the first operating system through the communication channel; Encrypting the first file based on a randomly generated file key corresponding to the first file to obtain a file ciphertext of the first file and storing it; Encrypting the file key corresponding to the first file according to the root key to obtain a file key ciphertext corresponding to the first file and storing it.

10. The method according to claim 8, characterized in that, When the verification result indicates that the verification is passed, after returning the verification result to the privacy space, the method further includes: Obtaining a request sent by the first operating system through the communication channel, where the request is generated by the first operating system in response to a fourth input to preview information of a second file, and the preview information of the second file is preview information of any file saved in the privacy space; In response to the request, obtaining the file key ciphertext corresponding to the second file and the file ciphertext of the second file pre-stored; Decrypting the file key ciphertext corresponding to the second file according to the root key to obtain the file key corresponding to the second file; Decrypt the file ciphertext of the second file according to the file key corresponding to the second file to obtain the decrypted second file; Send the second file to the first operating system through the communication channel so that the first operating system performs the operation corresponding to the fourth input; wherein, the operation corresponding to the fourth input includes at least one of the following: Display the second file in the privacy space; Delete the preview information of the second file in the privacy space.

11. A first operating system, characterized in that, Runs on an electronic device and includes a privacy space; the first operating system includes: A privacy space startup module for receiving a first input for starting the privacy space and invoking a first privacy password module in the privacy space; The first privacy password module for displaying a verification window in response to the first input for starting the privacy space and invoking a virtual machine management module in the privacy space; The virtual machine management module for establishing a communication channel between the privacy space and a second operating system running on a virtual machine; The first privacy password module is further used for: In response to a second input to the verification window, obtain a privacy password to be verified and send the privacy password to be verified to the second operating system through the communication channel so that the second operating system verifies the privacy password to be verified; Obtain the verification result returned by the second operating system through the communication channel; Start the privacy space when the verification result indicates that the verification is passed.

12. A second operating system, characterized in that, Runs on a virtual machine; the second operating system includes a second privacy password module for: Obtain the privacy password to be verified sent by the first operating system through the communication channel between the privacy space and the second operating system; the first operating system is the operating system running on the electronic device, and the first operating system includes the privacy space, the privacy password to be verified is obtained by the first operating system in response to a second input to the verification window, and the verification window is displayed in response to the first input for starting the privacy space; Verify the privacy password to be verified; Return the verification result to the first operating system through the communication channel so that the first operating system starts the privacy space when the verification is passed.