Equipment anti-theft method, electronic equipment and storage medium
By setting authorized modification of anti-theft mark information in the communication device, illegal operations are prohibited, and the problem of unattended equipment is easily theft is solved, and the low-cost protection of equipment security and network stability is achieved.
Patent Information
- Application Number
- CN202410139682.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-30
- Publication Date
- 2025-08-01
AI Technical Summary
Unattended communication equipment computer rooms are easily targeted for stealing. The existing physical anti-theft measures are poor and costly, which affects the normal operation of the communication network.
The anti-theft identification information modified according to the authorization is set in the storage space of the target device, and the identification information is read in response to the power-on of the device, and the target operation is prohibited when the anti-theft protection function is turned on, including configuration changes, version changes and hardware unit replacement.
Effectively prevent the thief from disguising the stolen equipment as legal equipment for secondary sales, ensuring the security of communication equipment and the normal operation of the communication network, with a low cost.
Smart Images

Figure CN120408735A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of communication technologies, and in particular, to a method for device anti-theft, an electronic device, and a storage medium. Background Art
[0002] In the field of communication, unmanned communication equipment machine rooms are easily targeted by thieves because they are located in remote areas and unattended. After thieves usually steal small and medium-sized equipment (such as routers, switches, or power equipment) in unmanned machine rooms, they resell it for profit.
[0003] When an unmanned machine room is stolen, on the one hand, it will cause losses to the operator's fixed assets, and on the other hand, it will also cause communication failures, affecting the normal operation of the communication network and the user experience. In the prior art, a special anti-theft structure or device is usually designed to prevent theft by increasing the difficulty for thieves to steal communication equipment, but the effect of this physical anti-theft is poor and it will further increase costs. Summary of the Invention
[0004] The purpose of the embodiments of the present disclosure is to provide a method for device anti-theft, an electronic device, and a storage medium.
[0005] To solve the above technical problems, the embodiments of the present disclosure are implemented through the following aspects.
[0006] According to the first aspect of the embodiments of the present disclosure, a method for device anti-theft is provided, which is applied to a target device. The storage space of the target device includes anti-theft identification information modified according to authorization. The method includes: in response to the power-on of the target device, reading the anti-theft identification information, where the anti-theft identification information is used to represent whether the target device enables the anti-theft protection function; and in the case where the anti-theft identification information represents that the target device enables the anti-theft protection function, prohibiting the execution of a target operation on the target device.
[0007] According to the second aspect of the embodiments of the present disclosure, an electronic device is provided, including: a memory, a processor, and computer-executable instructions stored on the memory and executable on the processor. When the computer-executable instructions are executed by the processor, the method for device anti-theft in the first aspect is implemented.
[0008] According to the third aspect of the embodiments of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, the method for device anti-theft in the first aspect is implemented.
[0009] With the above technical solution, anti-theft identification information that can be modified according to authorization is set in the storage space of the target device. In response to the power-on of the target device, the anti-theft identification information is read. When the anti-theft identification information indicates that the anti-theft protection function of the target device is enabled, the execution of the target operation on the target device is prohibited, so as to prevent thieves from disguising the stolen target device as a legal device for secondary sales at a relatively low cost, and ensure the safety of communication devices and the normal operation of communication networks.
[0010] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure.
[0011] Other features and advantages of the present disclosure will be described in detail in the following specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0013] Figure 1 A schematic flowchart showing a method for anti-theft of a device provided by an embodiment of the present disclosure;
[0014] Figure 2 A schematic flowchart showing the startup process of a target device provided by an embodiment of the present disclosure;
[0015] Figure 3 Another schematic flowchart showing a method for anti-theft of a device provided by an embodiment of the present disclosure;
[0016] Figure 4 Another schematic flowchart showing a method for anti-theft of a device provided by an embodiment of the present disclosure;
[0017] Figure 5 Another schematic flowchart showing a method for anti-theft of a device provided by an embodiment of the present disclosure;
[0018] Figure 6 A schematic interaction flowchart showing a method for anti-theft of a device provided by an embodiment of the present disclosure;
[0019] Figure 7 Another schematic interaction flowchart showing a method for anti-theft of a device provided by an embodiment of the present disclosure;
[0020] Figure 8 A schematic hardware structure diagram of an electronic device for executing the method for anti-theft of a device provided by an embodiment of the present disclosure. Detailed implementation manners
[0021] In order to enable those skilled in the art of the present technology to better understand the technical solutions in the present disclosure, the following will clearly and completely describe the technical solutions in the embodiments of the present disclosure with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present disclosure.
[0022] It should be noted that although the present disclosure describes the above method for preventing equipment theft by taking an unattended computer room as an example, it can be understood that the above method for preventing equipment theft is equally applicable to target equipment in other similar application scenarios, such as public equipment (such as power equipment) set in public areas. The present disclosure does not limit this.
[0023] Figure 1 A flowchart showing a method for preventing equipment theft provided by an embodiment of the present disclosure. This method is applied to a target equipment, such as Figure 1 As shown, the method may include the following steps:
[0024] In step S101, in response to the power-on of the target equipment, anti-theft identification information is read.
[0025] Among them, the storage space of the target equipment includes anti-theft identification information modified according to authorization, and the anti-theft identification information is used to represent whether the anti-theft protection function of the target equipment is enabled.
[0026] In some possible implementation manners, the storage space of the target equipment is a storage space modified according to authorization. For example, it needs to be authenticated and authorized by the network management system of the target equipment to be modified. The value in the storage space will not change due to the power-off and restart of the target equipment. Exemplarily, the anti-theft identification information may be a 1-bit register Flag in the storage space. When the value is 1, it represents that the anti-theft protection function of the target equipment is enabled, and when the value is 0, it represents that the anti-theft protection function of the target equipment is disabled. It can be understood that, based on the need for anti-theft protection, a more flexible setting manner of anti-theft identification information may be adopted. For example, the anti-theft identification information may be a register Flag of multiple bits, respectively representing the enabling of multiple different levels of anti-theft protection functions. The present disclosure does not limit this.
[0027] In some embodiments, the storage space may be set in the security module of the target device, and the security module is a hardware module that drives the target device to start and run. Important information of the device, such as the target device identifier, digital certificate, Hash function, encryption algorithm, encryption key, and the first piece of code for the device to start and run, may be stored in the security module. Since the security module is a hardware module that drives the target device to start and run, in the case of being violently removed or damaged, the target device will not be able to start and run. Setting the storage space in the security module of the target device can further improve the reliability of the anti-theft protection of the target device.
[0028] In step S102, when the anti-theft identification information indicates that the target device enables the anti-theft protection function, the target operation on the target device is prohibited.
[0029] In some embodiments, the target operation includes at least one of the following:
[0030] Configuration change of the target device;
[0031] Version change of the target device;
[0032] Starting the target device in a manner other than the preset startup method;
[0033] Replacing the hardware unit of the target device.
[0034] Among them, the configuration change includes at least one of configuration modification, configuration deletion, configuration addition, and restoring to factory settings, and the version change includes at least one of version upgrade, version downgrade, and version patching.
[0035] Exemplarily, the preset startup method may be, for example, hard disk startup. When the anti-theft identification information indicates that the target device enables the anti-theft protection function, starting the target device in a manner other than the hard disk startup method will be prohibited. For example, a thief cannot attempt to start the target device through methods such as network startup or mobile device startup (such as USB flash drive, external hard drive, or optical disc).
[0036] A thief may also disassemble the stolen target device and resell the hardware unit in the target device (such as the board in a router) for profit. In some embodiments, when the anti-theft identification information indicates that the target device enables the anti-theft protection function, replacing the hardware unit of the target device may also be prohibited to prevent reselling the hardware unit in the target device (such as the board in a router) for profit. In some possible implementation manners, the target device may save the identifier of the current hardware unit in the storage space. When the anti-theft identification information indicates that the target device enables the anti-theft protection function and at least one hardware unit of the target device is removed, replaced, or a new hardware unit is added, the startup or normal operation of the target device is blocked.
[0037] Figure 2 Schematic diagram showing the process of starting the target device provided by the embodiments of the present disclosure, as Figure 2 shown, the process includes the following steps:
[0038] Step 201, power on the target device.
[0039] Step 202, when the anti-theft protection function is enabled, prohibit starting methods other than the preset starting method.
[0040] In some embodiments, the preset starting method may be, for example, hard disk startup. After the target device is powered on, it first reads the anti-theft identification information. When the anti-theft identification information indicates that the anti-theft protection function of the target device is enabled, starting the target device by methods other than hard disk startup is prohibited, for example, starting the target device by network startup or mobile device startup (such as USB flash drive, external hard disk, or optical disc) is prohibited.
[0041] Step 203, normally start the operating system through the preset starting method.
[0042] In some embodiments, the preset starting method may be, for example, hard disk startup, and the operating system can be normally started through the hard disk drive.
[0043] Step 204, when the anti-theft protection function is disabled, by default, start the operating system normally through the preset starting method.
[0044] When the anti-theft protection function is disabled, the target device can also be started by other starting methods such as network startup or mobile device startup.
[0045] Step 205, in response to the enable instruction, enable the anti-theft protection function.
[0046] It can be understood that after the anti-theft protection function of the target device is enabled, when the target device is restarted, starting methods other than the preset starting method will be prohibited.
[0047] Step 206, when the anti-theft protection function is enabled, prohibit at least one of the following target operations: configuration change of the target device; version change of the target device; replacement of the hardware unit of the target device. [[ID=۳۷]]
[0048] With the above technical solutions, when the anti-theft identification information indicates that the anti-theft protection function of the target device is enabled, performing target operations on the target device is prohibited, which can prevent thieves from disguising the stolen target device as a legitimate device for secondary sales at a relatively low cost, and ensure the security of communication devices and the normal operation of communication networks.
[0049] Figure 3Another schematic flowchart showing the method for anti-theft of a device provided by an embodiment of the present disclosure. As Figure 3 shown, the method may further include the following steps:
[0050] In step S103, in response to an update instruction of anti-theft identification information, security authentication is performed through a network management system.
[0051] The legal owner of the target device (such as an operator) may also perform legal target operations during daily device management of the target device, such as modifying configurations, adding single boards, or upgrading versions. During daily device management, security authentication can be performed through the network management system to update the anti-theft identification information to temporarily turn off the anti-theft protection function. After the daily device management work is completed, the anti-theft protection function is restarted.
[0052] In step S104, when the authentication result of the security authentication passes, the update of the anti-theft identification information is executed. In step S105, when the authentication result of the security authentication times out or the authentication result of the security authentication fails, the update of the anti-theft identification information is refused to be executed.
[0053] It can be understood that the update operation of the anti-theft identification information can either modify the anti-theft identification information to turn on the anti-theft protection function or modify the anti-theft identification information to turn off the anti-theft protection function. The present disclosure does not limit this.
[0054] By adopting the above technical solution, it is possible to, according to the authentication result of the security authentication with the network management system, execute the update operation of the anti-theft identification information when the authentication result of the security authentication passes, and refuse to execute the update operation of the anti-theft identification information when the authentication signature information acquisition times out or the authentication result fails, thereby realizing the authorized modification of the anti-theft identification information, being able to prevent thieves from disguising the stolen target device as a legal device for secondary sales at a relatively low cost, while ensuring the normal device management of the legal owner of the target device for the target device.
[0055] Figure 4 Another schematic flowchart showing the method for anti-theft of a device provided by an embodiment of the present disclosure. As Figure 4 shown, step S103 may include the following steps:
[0056] In step S1031, authentication information is sent to the network management system.
[0057] In some possible implementation manners, the authentication information may be, for example, a random number randomly generated by the target device. To avoid possible brute-force cracking by thieves, a first timer may be started. When the first timer times out, a new random number may be generated. It can be understood that the authentication information may further include digest information generated by the target device according to device information (such as the device identifier, version, etc. of the target device) through a preset algorithm (such as a hash function). The present disclosure places no limitation thereon.
[0058] In some embodiments, a first key may be obtained from a network management system first. Among them, the first key may be, for example, the public key in an asymmetric key generated by the network management system according to a key generation algorithm.
[0059] After obtaining the first key, the authentication information is encrypted using the first key, and the encrypted authentication information is sent to the network management system.
[0060] In some possible implementation manners, the target device may encrypt the authentication information (such as a random number) using the first key, and send the encrypted authentication information (such as a random number) to the network management system, so that the network management system decrypts the encrypted authentication information (such as a random number) using the private key in the saved asymmetric key to obtain the decrypted authentication information (such as a random number), and when it is determined that the update instruction is a legal operation in response, sign the authentication information to generate authentication signature information. When it is determined that the update instruction is an illegal operation, the network management system may not send the authentication signature information.
[0061] In step S1032, receive the authentication signature information feedback by the network management system for the authentication information.
[0062] In step S1033, verify the authentication signature information, and determine the verification result of the verification as the authentication result of the security authentication.
[0063] In some possible implementation manners, the authentication signature information may be obtained by the network management system encrypting and signing the received authentication information (such as a random number) using the private key in the asymmetric key. The target device may decrypt the authentication signature information using the first key, and determine the verification result according to the decrypted authentication signature information.
[0064] Exemplarily, when the authentication information (such as a random number) included in the decrypted authentication signature information is the same as the current authentication information (such as a random number) of the target device, it can be determined that the authentication result of the security authentication passes; when the authentication information (such as a random number) included in the decrypted authentication signature information is different from the current authentication information (such as a random number) of the target device, it can be determined that the authentication result of the security authentication fails. When the acquisition of the authentication signature information times out (for example, the authentication signature information is not received when the first timer times out), it is confirmed that the acquisition of the authentication result of the security authentication times out, and the update of the anti-theft identification information can be refused to be executed.
[0065] By adopting the above technical solution, the authorized modification of the anti-theft identification information is realized, and the authentication with the network management system is completed through encryption, which can further improve the reliability of the device management and anti-theft protection of the target device.
[0066] Figure 5 Another process schematic diagram showing the method for device anti-theft provided by the embodiments of the present disclosure is as follows. As Figure 5 shown, step S103 may further include the following steps:
[0067] In step S1034, the mutual trust authentication with the network management system is completed through the certification authority.
[0068] To further ensure the reliability of the target device to obtain the first key from the network management system, the target device may also complete the mutual trust authentication with the network management system through a certification authority (CA).
[0069] Exemplarily, the target device may perform the mutual trust authentication of the network management system through the second key publicly disclosed by the certification authority CA, where the second key is the publicly disclosed public key in the asymmetric keys owned by the certification authority CA.
[0070] In some possible implementation manners, the network management system may use the authentication certificate of the certification authority to perform CA signature on the first key. After receiving the first key with the CA signature, the target device decrypts the CA signature through the second key. In the case of successful decryption, the CA identity authentication is completed. Further, the target device may also obtain the first certificate digest in the CA signature, and use the same preset algorithm (such as a hash function) to obtain the second certificate digest. In the case where the first certificate digest matches the second certificate digest, the integrity verification is completed, that is, it is determined whether the certificate has been tampered with. Further, the target device may also compare the information in the certificate with the preset information of the network management system, so as to complete the mutual trust authentication with the network management system.
[0071] By adopting the above technical solution, mutual trust authentication with the network management system can be completed through the certification center, ensuring the authenticity and reliability of the first public key obtained from the network management system (it cannot be forged or tampered with), and further improving the reliability of device management and anti-theft protection for the target device.
[0072] Figure 6 FIG. shows an interaction process diagram of a method for device anti-theft provided by an embodiment of the present disclosure. As Figure 6 shown, the method includes the following steps:
[0073] Step 301: Complete the business activation of the target device and enable the anti-theft protection function of the target device.
[0074] Exemplarily, the legal owner of the target device (such as an operator) normally completes the business activation of the target device. After the business is activated and goes online, the anti-theft protection function of the target device can be enabled by modifying the anti-theft identification information of the target device.
[0075] Step 302: Complete the mutual trust authentication between the target device and the network management system.
[0076] The mutual trust authentication between the target device and the network management system is completed through the certification center. For the specific steps, reference can be made to the description of step S1034, which will not be elaborated here.
[0077] Step 303: The network management system sends a first key to the target device.
[0078] In some possible implementation manners, the network management system can generate an asymmetric key through a key generation algorithm. The first key can be the public key in the asymmetric key, and the network management system saves the private key of the asymmetric key.
[0079] It can be understood that the network management system can also generate other types of keys through a key generation algorithm, such as symmetric keys in related technologies. The present disclosure does not limit the type of generated keys.
[0080] Step 304: The target device saves the first key.
[0081] After receiving the first key, the target device can save the first key so that when responding to the update instruction of the anti-theft identification information, it can send the authentication information encrypted with the first key to the network management system.
[0082] It can be understood that the present disclosure does not limit the order of the steps of service activation and enabling the anti-theft protection function in step 301 and the steps of steps 302 - 304. For example, in the case of first enabling the anti-theft protection function of the target device after service activation, the anti-theft protection function can be enabled without performing security authentication. Then, the steps of mutual trust authentication and obtaining the first key in steps 302 - 304 can be carried out. It is also possible to first complete the steps of mutual trust authentication and obtaining the first key in steps 302 - 304, and then perform service activation of the target device and enable the anti-theft protection function of the target device on the basis of security authentication.
[0083] Step 305: In response to the update instruction of the anti-theft identification information, the target device encrypts the authentication information with the first key and sends the encrypted authentication information to the network management system.
[0084] Exemplarily, after a thief steals the target device and attempts to update the anti-theft identification information to perform a target operation on the target device (such as rolling back the initialization configuration). Then, in response to the update instruction of the anti-theft identification information, the target device encrypts the authentication information with the first key and sends the encrypted authentication information to the network management system. Among them, the authentication information can be, for example, a random number randomly generated by the target device. After sending the encrypted authentication information, the target device can also start the first timer.
[0085] Step 306: When the network management system responds to the confirmation that the update instruction is an illegal operation, it does not generate authentication signature information.
[0086] In some embodiments, after receiving the encrypted authentication information, the network management system can decrypt the authenticated encrypted information through the saved private key to obtain the decrypted authentication information.
[0087] In some possible implementation manners, the authentication information may further include the identification information of the target device. The network management system can display the identification information of the target device to the user. In response to the user's confirmation operation that the update instruction is an illegal operation, it does not generate authentication signature information and can generate an alarm information indicating that the target device is suspected of being stolen.
[0088] In another possible implementation manner, a legally preset target operation schedule table can also be preset in the network management system, so that it can be determined that the update instruction is an illegal operation according to the time when the authentication information is received, the identification information of the target device, and the preset legally target operation schedule table, without generating authentication signature information, and can generate an alarm information indicating that the target device is suspected of being stolen.
[0089] It is understandable that since the authentication information is encrypted with the first key, even if a thief receives the encrypted authentication information using a forged network management system, without the corresponding private key, they cannot decrypt the authentication information properly, let alone generate authentication signature information for the authentication information.
[0090] Step 307: When the target device times out while receiving the authentication signature information, it refuses to execute the operation of updating the anti-theft identification information.
[0091] Exemplarily, since the network management system does not generate and send the authentication signature information, and the authentication signature information of the network management system is still not received after the first timer times out, the target device can refuse to execute the operation of updating the anti-theft identification information. Further, the target device can also generate new authentication information (such as a new random number) to prevent the thief from brute-forcing the target device (such as randomly generating forged authentication signature information to attempt to crack it).
[0092] Step 308: When the anti-theft protection function is enabled, the target operation on the target device is prohibited.
[0093] Adopting the above technical solution, when the anti-theft identification information indicates that the anti-theft protection function of the target device is enabled, prohibiting the execution of the target operation on the target device can prevent a thief from disguising the stolen target device as a legitimate device for secondary sales at a relatively low cost, thereby eliminating the thief's motivation to steal the target device and ensuring the security of the communication device and the normal operation of the communication network.
[0094] Figure 7 Another interaction process schematic diagram showing the device anti-theft method provided by the embodiments of the present disclosure is as Figure 7 shown, and the method includes the following steps:
[0095] Step 401: Complete the business activation of the target device and enable the anti-theft protection function of the target device.
[0096] Step 402: Complete the mutual trust authentication between the target device and the network management system.
[0097] Step 403: The network management system sends the first key to the target device.
[0098] Step 404: The target device saves the first key.
[0099] The above steps are similar to steps 301 - 304, and will not be elaborated here.
[0100] Step 405: In response to the update instruction of the anti-theft identification information, encrypt the authentication information with the first key and send the encrypted authentication information to the network management system.
[0101] The legitimate owner of the target device (such as an operator) can update the anti-theft identification information to temporarily turn off the anti-theft identification information when performing normal target operations. The target device can encrypt the authentication information using the first key in response to the update instruction of the anti-theft identification information, and send the encrypted authentication information to the network management system. The authentication information can be a random number randomly generated by the target device. After sending the encrypted authentication information, the target device can also start the first timer.
[0102] Step 406: Generate authentication signature information for the authentication information in the case of confirming that the update instruction is a legitimate operation.
[0103] In some possible implementation manners, the authentication information may further include the identification information of the target device. The network management system can display the identification information of the target device to the user, and generate authentication signature information for the authentication information in response to the user's confirmation operation that the update instruction is a legitimate operation.
[0104] In another possible implementation manner, a legitimate target operation schedule table can be preset in the network management system, so that it can be determined that the update instruction is a legitimate operation according to the time when the authentication information is received, the identification information of the target device, and the preset legitimate target operation schedule table, and generate authentication signature information for the authentication information.
[0105] The network management system can decrypt the encrypted authentication information using the saved private key to obtain the decrypted authentication information (such as a random number), and then encrypt and sign the received authentication information (such as a random number) using the private key in the asymmetric key to obtain the authentication signature information.
[0106] Step 407: Send the authentication signature information to the target device.
[0107] Step 408: Decrypt the authentication signature information using the first key, and determine the authentication result of the security authentication according to the decrypted authentication signature information.
[0108] Step 409: In the case where the authentication result of the security authentication is passed, perform the update operation on the anti-theft identification information.
[0109] The legitimate owner of the target device can perform the update operation on the anti-theft identification information to temporarily turn off the anti-theft protection function. After completing the target operation on the target device, the anti-theft protection function can also be restarted.
[0110] With the above technical solution, when the anti-theft identification information indicates that the target device has enabled the anti-theft protection function, the target operation on the target device is prohibited, which can prevent thieves from disguising the stolen target device as a legal device for secondary sales at a relatively low cost, ensure the security of communication devices and the normal operation of communication networks. At the same time, the anti-theft protection function can be temporarily turned off after completing the security authentication to facilitate the completion of legal target operations.
[0111] Figure 8 The following shows a schematic diagram of the hardware structure of the electronic device provided by the embodiments of the present disclosure. As Figure 8 shown, at the hardware level, the electronic device includes at least one processor. Optionally, it includes an internal bus, a network interface, and a memory. Among them, the memory may include internal memory, such as high-speed random access memory (RAM), and may also include non-volatile memory, such as at least one disk memory, etc. Of course, the electronic device may also include other hardware required for other services.
[0112] The processor, network interface, and memory can be interconnected through the internal bus. The internal bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity, only a bidirectional arrow is used in this figure to represent it, but it does not mean that there is only one bus or one type of bus.
[0113] The memory stores programs. Specifically, the program may include program code, and the program code includes at least one computer operation instruction. The memory may include internal memory and non-volatile memory, and provide instructions and data to the processor.
[0114] At least one processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs it, forming a device for locating the target user at the logical level. At least one processor executes the program stored in the memory and specifically executes: Figures 1-7 The methods disclosed in the illustrated embodiments implement the functions and beneficial effects of the various methods described in the foregoing method embodiments, and will not be elaborated here.
[0115] The above is as described in the present disclosure Figures 1-7The method disclosed in the illustrated embodiment can be applied to at least one processor or implemented by at least one processor. The processor may be an integrated circuit chip with the ability to process signals. During implementation, the steps of the above method can be completed by the integrated logic circuit of the hardware in at least one processor or instructions in the form of software. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present disclosure. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present disclosure can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.
[0116] The electronic device can also execute the various methods described in the foregoing method embodiments and achieve the functions and beneficial effects of the various methods described in the foregoing method embodiments, which will not be elaborated herein.
[0117] Of course, in addition to the software implementation, the electronic device of the present disclosure does not exclude other implementation manners, such as a logic device or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, and may also be hardware or a logic device.
[0118] The embodiments of the present disclosure also propose a computer-readable storage medium, where the computer-readable medium stores one or more programs, and when the one or more programs are executed by at least one processor, they implement Figures 1-7 the method disclosed in the illustrated embodiment and achieve the functions and beneficial effects of the various methods described in the foregoing method embodiments, which will not be elaborated herein.
[0119] Among them, the computer-readable storage medium includes a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disc, etc.
[0120] Furthermore, an embodiment of the present disclosure also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the following process is implemented: Figures 1-7 The method disclosed in the illustrated embodiment realizes the functions and beneficial effects of the various methods described in the foregoing method embodiments, and will not be elaborated herein.
[0121] In summary, the above are only the preferred embodiments of the present disclosure, and do not limit the protection scope of the present disclosure. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.
[0122] The systems, modules or units illustrated in the above embodiments may be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0123] Computer-readable media includes both permanent and non-permanent, removable and non-removable media and may be implemented by any method or technology for storing information. The information may be computer-readable instructions, data structures, modules of a program, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVDs) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can store information accessible by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0124] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising said element.
[0125] Each embodiment in this specification is described in a progressive manner. For the identical and similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and reference can be made to the relevant part of the method embodiment for the relevant content.
Claims
1. A method for device anti-theft, which is applied to a target device. The storage space of the target device includes anti-theft identification information modified according to authorization. The method includes: In response to the power-on of the target device, read the anti-theft identification information, where the anti-theft identification information is used to indicate whether the anti-theft protection function of the target device is enabled; When the anti-theft identification information indicates that the anti-theft protection function of the target device is enabled, prohibit performing a target operation on the target device.
2. The method according to claim 1, where the target operation includes at least one of the following: Configuration change of the target device; Version change of the target device; Starting the target device in a manner other than the preset startup method; Replacing the hardware unit of the target device.
3. The method according to claim 1, the method further includes: In response to an update instruction of the anti-theft identification information, perform security authentication through a network management system; When the authentication result of the security authentication is passed, perform the update of the anti-theft identification information.
4. The method according to claim 3, after performing the security authentication through the network management system, the method further includes: When the authentication result is timed out or the authentication result is not passed, reject the update of the anti-theft identification information.
5. The method according to claim 3 or 4, the security authentication through the network management system includes: Send authentication information to the network management system; Receive the authentication signature information feedback by the network management system for the authentication information; Verify the authentication signature information, and determine the verification result of the verification as the authentication result of the security authentication.
6. The method according to claim 5, characterized in that The sending the authentication information to the network management system includes: Encrypt the authentication information with a first key, and send the encrypted authentication information to the network management system, where the first key is obtained from the network management system; The verifying the authentication signature information includes: Decrypt the authentication signature information with the first key, and determine the verification result according to the decrypted authentication signature information.
7. The method according to claim 6, wherein Before obtaining the first key from the network management system, the method further includes: Complete the mutual trust authentication with the network management system through an authentication center.
8. The method according to claim 1, the storage space is set in the security module of the target device, and the security module is a hardware module that drives the target device to start and run.
9. An electronic device, including: At least one processor; And A memory configured to store at least one computer executable instruction, and when the at least one executable instruction is executed, use the at least one processor to execute the device anti-theft method according to any one of claims 1-8.
10. A computer-readable storage medium, the computer-readable storage medium stores at least one computer program, and when the at least one program is executed by at least one processor, it implements the device anti-theft method according to any one of claims 1-8.