Mobile terminal operation and maintenance system

Through Bluetooth communication between the Bluetooth USB Key and the mobile operation and maintenance terminal, combined with national encryption algorithms and biometric recognition, the problem that traditional PCs or laptops cannot conveniently perform on-site operation and maintenance of mobile terminals is solved, and the secure startup and data protection of mobile operation and maintenance operations are realized.

CN120751378APending Publication Date: 2025-10-03BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510904337.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-01
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

Traditional operation and maintenance operations use PCs or laptops for terminal device communication, which cannot conveniently perform on-site operation and maintenance operations on mobile terminals, and cannot guarantee the safe startup of mobile terminal operation and maintenance operations.

Method used

A Bluetooth USB Key is used to establish a connection with the mobile operation and maintenance terminal, identity authentication and data encryption and decryption are performed through Bluetooth communication, the national secret algorithm is used to ensure communication security, and the baseline value of the mobile operation and maintenance application is stored in the Bluetooth USB Key for trusted startup.

Benefits of technology

It realizes convenient on-site operation and maintenance of mobile operation and maintenance terminals, ensures the communication security of the operation and maintenance process and the trusted startup of applications, prevents illegal operations and data leakage, and improves the work efficiency and security of operation and maintenance operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751378A_ABST
    Figure CN120751378A_ABST
Patent Text Reader

Abstract

The invention provides a mobile terminal operation and maintenance system, and belongs to the technical field of system operation and maintenance and information security. The mobile terminal operation and maintenance system comprises a target terminal, a mobile operation and maintenance operation terminal and a Bluetooth USB Key deployed in the mobile operation and maintenance operation terminal, and the mobile operation and maintenance operation terminal establishes a Bluetooth communication link with the target terminal through the Bluetooth USB Key; the Bluetooth USB Key comprises a main control chip, a Bluetooth module and an operation and maintenance service security chip; the mobile operation and maintenance job terminal is configured with a mobile operation and maintenance job application program file, and a reference value of the mobile operation and maintenance job application program file is stored in the Bluetooth USB Key; and the Bluetooth USB Key calculates an abstract value according to the obtained basic information of the mobile operation and maintenance job application program file, compares the abstract value with a stored reference value, and determines whether to start the mobile operation and maintenance job application program according to a comparison result. According to the method, the mobile operation and maintenance operation terminal can conveniently carry out field operation and maintenance operation, and credible starting of the mobile operation and maintenance operation application program is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of system operation and maintenance and information security technology, and in particular to a mobile terminal operation and maintenance system. Background Art

[0002] Traditional operation and maintenance applications use PCs or laptops, communicating with terminal devices via serial ports. With the increasing prevalence of mobile devices, a growing number of industrial sectors are using them for operation and maintenance and processing sensitive data. Therefore, leveraging existing cryptographic technologies to provide unified security for users in complex application scenarios has become increasingly important.

[0003] USB Key products store users' private keys and digital certificates, and utilize security chips with built-in symmetric and asymmetric algorithms to verify user identities and encrypt and decrypt key information. As an important carrier for identity authentication, they have been widely used in many industries such as financial transactions, electricity, and industrial control.

[0004] Existing operation and maintenance operations usually use traditional PCs or laptops, which are equipped with USB keys to communicate with terminals. Serial ports are usually used for data exchange, terminal certificate management, and key updates. However, this method is not convenient for on-site operation and maintenance operations on mobile terminals such as laptops, and cannot guarantee the secure startup of operation and maintenance applications on mobile terminals. Summary of the Invention

[0005] In order to solve the above technical defects, the present invention provides a mobile terminal operation and maintenance system to facilitate mobile operation and maintenance terminals to perform on-site operation and maintenance operations and ensure the trusted startup of mobile operation and maintenance application programs.

[0006] The mobile terminal operation and maintenance system provided by the present invention includes: a target terminal, a mobile operation and maintenance operation terminal, and a Bluetooth USB key deployed in the mobile operation and maintenance operation terminal. The Bluetooth USB key establishes a physical connection with the mobile operation and maintenance operation terminal, and the mobile operation and maintenance operation terminal establishes a Bluetooth communication link with the target terminal through the Bluetooth USB key; The Bluetooth USB Key includes: a main control chip, a Bluetooth module, and an operation and maintenance business security chip. Both the Bluetooth module and the operation and maintenance business security chip are connected to the main control chip; The mobile operation and maintenance operation terminal is configured with a mobile operation and maintenance operation application file, and the reference value of the mobile operation and maintenance operation application file is stored in the Bluetooth USB Key; The Bluetooth USB Key calculates a summary value based on the basic information of the obtained mobile operation and maintenance application file, compares the calculated summary value with the stored reference value to obtain a comparison result, and determines whether to start the mobile operation and maintenance application based on the comparison result.

[0007] In an embodiment of the present invention, the Bluetooth USB Key calculates a summary value based on the basic information of the obtained mobile operation and maintenance application file, including: Based on the basic information of the mobile operation and maintenance application file, the summary value is calculated using the national secret SM3 hash algorithm.

[0008] In an embodiment of the present invention, the Bluetooth USB Key compares the calculated summary value with the stored reference value to obtain a comparison result, and determines whether to start the mobile operation and maintenance application according to the comparison result, including: If the comparison result shows that the summary value is consistent with the reference value, the cryptographic algorithm resources of the operation and maintenance business security chip are enabled and the mobile operation and maintenance application is started; If the comparison result shows that the summary value is inconsistent with the benchmark value, exit the mobile operation and maintenance application.

[0009] In the embodiment of the present invention, after starting the mobile operation and maintenance application, the mobile operation and maintenance terminal identifies the user through biometric recognition; After the user's identity is successfully identified, the PIN code entered by the user is securely authenticated through the operation and maintenance business security chip of the Bluetooth USB Key.

[0010] In the embodiment of the present invention, after the security authentication is successful, the Bluetooth USB Key deployed in the mobile operation and maintenance terminal is paired with the target terminal via Bluetooth.

[0011] In an embodiment of the present invention, the Bluetooth USB Key deployed in the mobile operation and maintenance terminal is paired with the target terminal via Bluetooth, including: After the Bluetooth module of the Bluetooth USB Key scans and identifies the Bluetooth module of the target terminal, it initiates a pairing request to the Bluetooth module of the target terminal; The Bluetooth module of the target terminal obtains the random number R as the PIN code, and uses the random number R1 to encrypt the random number R to obtain the encrypted random number R En , the random number R1 and the encrypted random number R are transmitted over the air interface. En Broadcast it out; The Bluetooth module of the Bluetooth USB Key receives the random number R1 broadcast by the target terminal and the encrypted random number R En Afterwards, the encrypted random number R En Decryption and verification are performed. If the verification is successful, the Bluetooth pairing is successful.

[0012] In an embodiment of the present invention, after the Bluetooth USB Key deployed in the mobile operation and maintenance operation terminal is successfully paired with the Bluetooth of the target terminal, the mobile operation and maintenance operation terminal calls the operation and maintenance business security chip through the Bluetooth USB Key to realize encrypted business data interaction between the mobile operation and maintenance operation terminal and the target terminal.

[0013] In the embodiment of the present invention, the business data interaction between the mobile operation and maintenance terminal and the target terminal adopts a symmetric encryption method, and the fixed key is stored in the operation and maintenance business security chip of the Bluetooth USB Key.

[0014] The mobile operation and maintenance terminal uses the operation and maintenance business security chip to adopt the national secret SM1 algorithm and a fixed key to encrypt the operation and maintenance return business data.

[0015] The mobile operation and maintenance terminal determines the storage location of the operation and maintenance return copy business data according to the size of the operation and maintenance return copy business data, and stores the encrypted operation and maintenance return copy business data in the storage module of the mobile operation and maintenance terminal, the large-capacity storage area of ​​the Bluetooth USB Key, or the operation and maintenance business security chip of the Bluetooth USB Key.

[0016] In the embodiment of the present invention, the Bluetooth USB Key establishes a physical connection with the mobile operation and maintenance terminal via a USB-OTG mode.

[0017] The mobile operation and maintenance terminal directly obtains the USB interface permission of the Bluetooth USB Key through the Android USBManager class; uses the UsbDeviceConnection class and UsbRequest class to build a non-blocking communication channel and establish a communication connection between the mobile operation and maintenance terminal and the Bluetooth USB Key.

[0018] During data transmission between the Bluetooth USB Key and the mobile operation and maintenance terminal, secure data transmission is achieved through middleware based on national encryption standards.

[0019] The command encapsulation method of the middleware based on the national secret standard is: taking the batch transmission command as the payload, adding the security command of the national secret standard to the batch transmission command to form an encrypted transmission data packet.

[0020] In the embodiment of the present invention, data exchange is performed between the middleware based on the national encryption standard and the Bluetooth USB Key through the extended SCSI Command private protocol.

[0021] The middleware based on national encryption standards uses a lightweight communication protocol designed based on the Android sandbox permission model to implement three-level permission verification between the Bluetooth USB key and the mobile operation and maintenance application. The three-level permission verification includes: basic command verification, operation command verification and security command verification.

[0022] In the embodiment of the present invention, the Bluetooth module is connected to the main control chip through a serial port, and the operation and maintenance service security chip is connected to the main control chip through an SPI interface.

[0023] The present invention deploys a Bluetooth USB Key on a mobile operation and maintenance terminal to facilitate on-site operation and maintenance operations by the mobile operation and maintenance terminal. By integrating an operation and maintenance business security chip on the Bluetooth USB Key, communication security during the operation and maintenance operation is guaranteed, the security reinforcement of mobile applications is effectively achieved, and the work efficiency of operation and maintenance operations is greatly improved. By storing the benchmark value of the mobile operation and maintenance application file in the Bluetooth USB Key, the trusted startup of the mobile operation and maintenance application is achieved based on the comparison result of the calculated summary value and the stored benchmark value, thereby further ensuring the security of the mobile application itself.

[0024] Other features and advantages of the technical solution of the present invention will be described in detail in the specific implementation section below. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings: Figure 1 is a block diagram of a mobile terminal operation and maintenance system provided by an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a Bluetooth USB Key provided by an embodiment of the present invention; Figure 3 Schematic diagram of data interaction between a Bluetooth USB Key and a mobile operation and maintenance terminal via middleware in an embodiment of the present invention; Figure 4 1 is a schematic diagram of a verification process for starting a mobile operation and maintenance application program according to an embodiment of the present invention; Figure 5 It is a schematic diagram of the business data interaction process between the mobile operation and maintenance terminal and the target terminal in an embodiment of the present invention. DETAILED DESCRIPTION

[0026] To make the technical solutions and advantages of the embodiments of the present invention more clearly understood, exemplary embodiments of the present invention are further described in detail below with reference to the accompanying drawings. It should be noted that the embodiments described are only a portion of the embodiments of the present invention, and are not an exhaustive list of all embodiments. It should be noted that the embodiments of the present invention and the features thereof may be combined with each other unless they conflict.

[0027] In the description of the present invention, unless otherwise expressly specified or limited, terms such as "connected," "connect," and "link" should be understood in a broad sense. For example, they may refer to fixed or detachable connections, or integration; mechanical or electrical connections, or communication; direct or indirect connections through an intermediate medium; and internal communication between two components or interaction between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0028] Figure 1 This is a block diagram of a mobile terminal operation and maintenance system provided by an embodiment of the present invention. Figure 1 As shown, the mobile terminal operation and maintenance system provided in this embodiment includes a target terminal and a mobile operation and maintenance operation terminal. The mobile operation and maintenance operation terminal is deployed with a Bluetooth USB key, and the target terminal is deployed with a Bluetooth module. The Bluetooth USB key and the mobile operation and maintenance operation terminal are physically connected, and the mobile operation and maintenance operation terminal establishes a Bluetooth communication link with the Bluetooth module of the target terminal via the Bluetooth USB key.

[0029] In order to facilitate the connection of business and improve the application scenarios of products, the present invention adopts a Bluetooth USBKey with security protection function. Figure 2 As shown, the Bluetooth USB Key includes: a main control chip, a Bluetooth module, and an operation and maintenance business security chip. Both the Bluetooth module and the operation and maintenance business security chip are connected to the main control chip. The Bluetooth module is connected to the main control chip via a serial port, and the operation and maintenance business security chip is connected to the main control chip via an SPI interface. The Bluetooth USB Key also includes: a USB interface, a large-capacity storage area, and peripheral circuits such as a power supply and a crystal oscillator ( Figure 2 not shown).

[0030] The Bluetooth USB Key of the present invention utilizes an independent Bluetooth module and an operation and maintenance service security chip. The Bluetooth module is used for pairing and establishing a Bluetooth link, while the operation and maintenance service security chip provides algorithm support during data communication, achieving data encryption protection. Application of this Bluetooth USB Key to mobile operation and maintenance terminals can effectively strengthen the security of mobile applications while significantly improving the efficiency of operation and maintenance operations.

[0031] like Figure 3As shown, the Bluetooth USB key establishes a physical connection with the mobile operation and maintenance terminal via USB-OTG, detecting and responding to SCSI command codes received from USB Transfer. USB-OTG utilizes the USB On-The-Go (OTG) standard, which is fully compatible with USB 2.0 and adds power management capabilities, allowing the device to operate as both a host and a peripheral, a process known as dual-use OTG. After establishing a physical connection, the mobile operation and maintenance terminal directly obtains USB interface permissions for the Bluetooth USB key through the Android USBManager class. Using the UsbDeviceConnection and UsbRequest classes, the terminal establishes a non-blocking communication channel between the two devices.

[0032] During data transmission between a Bluetooth USB key and a mobile operation and maintenance terminal, a secure transmission channel is established by embedding middleware compliant with the national cryptographic standard "Smart IC Card and Smart Password Key Cryptographic Application Interface Specification" within the batch transmission command, enabling secure data transmission and integrity protection for operation and maintenance applications. The command encapsulation structure of the national cryptographic standard-based middleware consists of designing a specific command frame format, using the original batch transmission command as the payload, and adding the national cryptographic standard security command (APDU command) to the batch transmission command to form a complete encrypted transmission data packet.

[0033] The middleware and the Bluetooth USB Key exchange data via an extended SCSI Command private protocol, processing data exchanged with the Bluetooth module and security chip. The extended protocol command codes include: (1) 0xFA command: secure Bluetooth module sends; (2) 0xFB command: secure Bluetooth module reads; (3) 0xFD command: business security chip sends; (4) 0xFE command: business security chip reads.

[0034] The middleware utilizes a lightweight communication protocol designed based on the Android sandbox permission model to implement three-level permission verification based on command type between the Bluetooth USB key and the mobile operation and maintenance application. These three levels of permission verification include basic command verification, operational command verification, and secure command verification. Basic command verification requires no authentication, operational command verification requires user PIN verification, and secure command verification requires authentication based on a security algorithm.

[0035] The mobile operation and maintenance terminal is equipped with a mobile operation and maintenance application (APP). Its application file (APK) is a specialized application installation package format for the Android operating system and contains all the components required to run Android applications. The middleware called by the mobile operation and maintenance application reuses existing security service code in the form of a .so library. At the JNI (Java Native Interface) layer, the CallStaticIntMethod function is used to call static methods in Java classes. The method ID (unique identifier) ​​is specified to pass parameters to the application method at the application layer.

[0036] The baseline value of the mobile operation and maintenance application file (APK) is stored in the operation and maintenance service security chip of the Bluetooth USB key. Based on the basic information obtained from the mobile operation and maintenance application file (APK), the Bluetooth USB key uses the national encryption SM3 hashing algorithm to calculate a digest value. The calculated digest value is compared with the stored baseline value to obtain a comparison result. Based on the comparison result, a decision is made as to whether to launch the mobile operation and maintenance application (APP). If the comparison result shows that the digest value matches the baseline value, the cryptographic algorithm resources of the operation and maintenance service security chip are enabled, and the mobile operation and maintenance application (APP) is launched. If the comparison result shows that the digest value does not match the baseline value, the mobile operation and maintenance application (APP) is exited.

[0037] The basic information of the mobile operation and maintenance application file includes but is not limited to: file identification information (name), file path, version number, issuer information, signature information, permission list, key code, etc.

[0038] After starting the mobile operation and maintenance application, the mobile operation and maintenance terminal identifies the user through biometric recognition. After the user's identity is successfully identified, the PIN code entered by the user is forced to be authenticated through the operation and maintenance business security chip of the Bluetooth USB Key.

[0039] After the security authentication is successful, the Bluetooth USB Key deployed on the mobile operation and maintenance terminal is paired with the target terminal via Bluetooth. Specifically, after the Bluetooth module of the Bluetooth USB Key scans and identifies the Bluetooth module of the target terminal, it initiates a pairing request to the Bluetooth module of the target terminal; the Bluetooth module of the target terminal obtains the random number R as the PIN code, and uses the random number R1 to encrypt the random number R to obtain the encrypted random number R En , the random number R1 and the encrypted random number R are transmitted over the air interface. En Broadcast out; the Bluetooth module of the Bluetooth USB Key receives the random number R1 broadcast by the target terminal and the encrypted random number R En Afterwards, the encrypted random number REn Decryption and verification are performed. If the verification is successful, the Bluetooth pairing is successful.

[0040] After the Bluetooth USB Key deployed on the mobile operation and maintenance terminal is successfully paired with the Bluetooth of the target terminal, the mobile operation and maintenance terminal calls the operation and maintenance business security chip through the Bluetooth USB Key to realize encrypted business data interaction between the mobile operation and maintenance terminal and the target terminal.

[0041] Symmetric encryption is used for business data exchange between the mobile operation and maintenance terminal and the target terminal. A fixed key is stored in the operation and maintenance service security chip of the Bluetooth USB key. The mobile operation and maintenance terminal uses the national SM1 algorithm and a fixed key to encrypt the operation and maintenance feedback data using the operation and maintenance service security chip. The mobile operation and maintenance terminal determines the storage location of the operation and maintenance feedback data based on its size and stores the encrypted data in the mobile operation and maintenance terminal's storage module, the Bluetooth USB key's mass storage area, or the Bluetooth USB key's operation and maintenance service security chip.

[0042] In a specific embodiment, the mobile operation and maintenance process based on the above mobile terminal operation and maintenance system is as follows: (1) Application startup: The mobile operation and maintenance application (APP) is connected to the Bluetooth USB Key through the OTG conversion device. After the user clicks to open the application, the national secret SM3 hash algorithm is used to perform integrity verification on the mobile operation and maintenance application file (APK). Figure 4 As shown, the APK's baseline value is stored in the Bluetooth USB key's operation and maintenance service security chip. After the Android operating system obtains the APK baseline value (i.e., the basic information of the mobile operation and maintenance application file), it sends the relevant data to the Bluetooth USB key, which performs an SM3 hash calculation to obtain a digest value (SM3 hash value) and compares it with the baseline value. If the comparison is consistent, the mobile operation and maintenance application (app) is launched and the Bluetooth USB key cryptographic algorithm identifier is enabled. If the comparison is inconsistent, the app is exited (closing the app prompts uninstallation), and subsequent algorithm-related functions cannot be performed. This method, which uses Bluetooth USB key-based trusted integrity verification, can effectively prevent attacks such as repackaging of the mobile operation and maintenance application (app) and malicious code injection.

[0043] (2) Identity authentication: After launching the mobile operation and maintenance application (APP), the user's identity is first identified through biometric recognition technology, and then the user is prompted to enter the PIN code to complete the mandatory security authentication of the Bluetooth USB Key. The PIN code is not just a string of numbers, but is encrypted by the issuing manufacturer and pre-set in the security area of ​​the Bluetooth USB Key. Only when the input is consistent with the pre-set one can the authentication be passed. If the above authentication is not completed or the authentication is incorrect, subsequent operations cannot be performed.

[0044] (3) Bluetooth pairing: The mobile operation and maintenance application (APP) opens the Bluetooth USB key, scans and identifies the Bluetooth module of the target terminal, initiates a pairing request, and uses the national secret SM1 algorithm to perform Bluetooth secure pairing. Taking the power distribution terminal as an example, the establishment process is as follows: The random number R of the Bluetooth module of the power distribution terminal is used as the PIN code, and the random number R is dispersed and encrypted with the random number R1 to obtain the encrypted random number R En , the random number R1 and the encrypted random number R are transmitted over the air interface. En Broadcast it out; After the Bluetooth USB Key of the mobile operation and maintenance terminal selects the power distribution terminal to be connected, it receives the random number R1 broadcast by the power distribution terminal and the encrypted random number R En Afterwards, the encrypted random number R En Decryption and verification are performed. If the verification is successful, the Bluetooth pairing is successful.

[0045] (4) Data interaction: After the mobile operation and maintenance terminal is connected to the Bluetooth module of the target terminal via the Bluetooth USB Key, the business interaction data is called through the Bluetooth USB Key to the operation and maintenance business security chip to achieve encryption of the interaction data. Figure 5 As shown, the process is as follows: The mobile operation and maintenance terminal processes the business data and sends the processed plaintext data or ciphertext data to the Bluetooth USB Key. The main control chip of the Bluetooth USB Key calls the operation and maintenance business security chip to encrypt the data, passes the encrypted data to the Bluetooth module, and sends the encrypted data to the target terminal through the Bluetooth module.

[0046] (5) Data storage: Operation and maintenance operations involve a large amount of personal data, key locations, and sensitive data such as collection and control. Traditional mobile operation terminals usually use physical isolation and implicit storage, which cannot solve the fundamental risk of data leakage. The Bluetooth Key-based security application reinforcement of the present invention adopts symmetric encryption, uses the fixed key stored in the operation and maintenance business security chip of the Bluetooth USB Key, and adopts the national secret SM1 algorithm to achieve local data encryption storage. Depending on the size of the operation and maintenance copy data content, the encrypted data is stored in the mobile operation and maintenance operation terminal, the large-capacity storage area of ​​the Bluetooth USB Key (i.e., USB flash drive), or the operation and maintenance business security chip of the Bluetooth USB Key.

[0047] The mobile terminal operation and maintenance system of the present invention has the following advantages: 1) By deploying a Bluetooth USB Key on a mobile terminal, it is convenient for the mobile terminal to perform on-site operation and maintenance; 2) By integrating an operation and maintenance security chip into the Bluetooth USB Key, cryptographic technology is used to ensure communication security during operation and maintenance operations; 3) By storing the baseline value of the mobile operation and maintenance application file in the Bluetooth USB key, the application can be trusted to start based on the comparison result of the calculated summary value with the stored baseline value, thereby ensuring the security of the mobile application itself; 4) Identity authentication is completed through biometric technology and PIN code technology on mobile operation and maintenance terminals and Bluetooth USB keys, effectively preventing illegal operations; 5) Use cryptographic technology to achieve communication pairing between the Bluetooth USB Key of the mobile terminal and the Bluetooth module of the target terminal to ensure the security of the Bluetooth link; 6) Use encryption technology to store business data in ciphertext on mobile terminals or secure Bluetooth KEYs to prevent data leakage; 7) The mobile terminal platform implements secure Bluetooth calls in the form of JNI+so, and implements application security reinforcement by encapsulating middleware developed based on national encryption algorithm standards in mobile applications.

[0048] In general, the present invention is oriented towards mobile terminals, making it convenient for operation and maintenance personnel to carry equipment for on-site operations, thereby improving business convenience; it adopts a secure Bluetooth protocol to support long-distance communication, which is convenient for terminal data to be copied back and control commands to be issued. The security protection measures of the present invention fully consider the complex environment and uncontrollable factors of mobile application use, and the protection measures cover the entire life cycle of mobile application use. USB Key chip technology is used to ensure that key information is not read out, and its cryptographic operations are all completed by hardware algorithms, which solves the compliance of key carriers and key storage. The present invention effectively completes user identity verification by implementing cross-authentication of biometric identification and user PIN, effectively preventing illegal operations; the verification of the integrity of the mobile application APK effectively prevents illegal attacks on the APP; at the communication and data storage level, for encrypted ciphertext data and publicly available information, even if the attacker intercepts the communication data, he cannot crack and obtain valid data because he does not have the private key in the USB Key device; Currently, a mature and feasible security protection mechanism has been established for terminal devices, PCs, and server peripherals. This invention effectively draws on the mature application of USB Key technology, fully utilizing existing resources to achieve unified permission management for mobile terminal users and PC users. It has a low cost to modify existing equipment and provides a good user experience.

[0049] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk drives, CD-ROMs, optical storage devices, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention may be implemented using various computer languages, such as the object-oriented programming language Java and the interpreted scripting language JavaScript.

[0050] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0051] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0052] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0053] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they are aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the invention. Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the invention. Thus, the present invention is intended to include such changes and modifications as fall within the scope of the claims and their equivalents.

Claims

1. A mobile terminal operation and maintenance system, characterized in that: include: The target terminal, the mobile operation and maintenance operation terminal, and the Bluetooth USB Key deployed on the mobile operation and maintenance operation terminal establish a physical connection with the Bluetooth USB Key and the mobile operation and maintenance operation terminal, and the mobile operation and maintenance operation terminal establishes a Bluetooth communication link with the target terminal through the Bluetooth USB Key; The Bluetooth USB Key includes: a main control chip, a Bluetooth module, and an operation and maintenance business security chip. Both the Bluetooth module and the operation and maintenance business security chip are connected to the main control chip; The mobile operation and maintenance operation terminal is configured with a mobile operation and maintenance operation application file, and the reference value of the mobile operation and maintenance operation application file is stored in the Bluetooth USB Key; The Bluetooth USB Key calculates a summary value based on the basic information of the obtained mobile operation and maintenance application file, compares the calculated summary value with the stored reference value to obtain a comparison result, and determines whether to start the mobile operation and maintenance application based on the comparison result.

2. The mobile terminal operation and maintenance system according to claim 1, characterized in that: The Bluetooth USB Key calculates a summary value based on the basic information of the obtained mobile operation and maintenance application file, including: Based on the basic information of the mobile operation and maintenance application file, the summary value is calculated using the national secret SM3 hash algorithm.

3. The mobile terminal operation and maintenance system according to claim 1, characterized in that: The Bluetooth USB Key compares the calculated summary value with the stored reference value to obtain a comparison result, and determines whether to start the mobile operation and maintenance application based on the comparison result, including: If the comparison result shows that the summary value is consistent with the reference value, the cryptographic algorithm resources of the operation and maintenance business security chip are enabled and the mobile operation and maintenance application is started; If the comparison result shows that the summary value is inconsistent with the benchmark value, exit the mobile operation and maintenance application.

4. The mobile terminal operation and maintenance system according to claim 1, characterized in that: After launching the mobile operation and maintenance application, the mobile operation and maintenance terminal identifies the user through biometric recognition; After the user's identity is successfully identified, the PIN code entered by the user is securely authenticated through the operation and maintenance business security chip of the Bluetooth USB Key.

5. The mobile terminal operation and maintenance system according to claim 4, characterized in that: After the security authentication is successful, the Bluetooth USB Key deployed on the mobile operation and maintenance terminal is paired with the target terminal via Bluetooth.

6. The mobile terminal operation and maintenance system according to claim 5, characterized in that: The Bluetooth USB Key deployed on the mobile operation and maintenance terminal is paired with the target terminal via Bluetooth, including: After the Bluetooth module of the Bluetooth USB Key scans and identifies the Bluetooth module of the target terminal, it initiates a pairing request to the Bluetooth module of the target terminal; The Bluetooth module of the target terminal obtains the random number R as the PIN code, and uses the random number R1 to encrypt the random number R to obtain the encrypted random number R En , the random number R1 and the encrypted random number R are transmitted over the air interface. En Broadcast it out; The Bluetooth module of the Bluetooth USB Key receives the random number R1 broadcast by the target terminal and the encrypted random number R En Afterwards, the encrypted random number R En Decryption and verification are performed. If the verification is successful, the Bluetooth pairing is successful.

7. The mobile terminal operation and maintenance system according to claim 5, characterized in that: After the Bluetooth USB Key deployed on the mobile operation and maintenance terminal is successfully paired with the Bluetooth of the target terminal, the mobile operation and maintenance terminal calls the operation and maintenance business security chip through the Bluetooth USB Key to realize encrypted business data interaction between the mobile operation and maintenance terminal and the target terminal.

8. The mobile terminal operation and maintenance system according to claim 1, characterized in that: The business data interaction between the mobile operation and maintenance terminal and the target terminal adopts symmetric encryption, and the fixed key is stored in the operation and maintenance business security chip of the Bluetooth USB Key.

9. The mobile terminal operation and maintenance system according to claim 8, characterized in that: The mobile operation and maintenance terminal uses the operation and maintenance business security chip to adopt the national secret SM1 algorithm and a fixed key to encrypt the operation and maintenance return business data.

10. The mobile terminal operation and maintenance system according to claim 9, characterized in that: The mobile operation and maintenance terminal determines the storage location of the operation and maintenance return copy business data according to the size of the operation and maintenance return copy business data, and stores the encrypted operation and maintenance return copy business data in the storage module of the mobile operation and maintenance terminal, the large-capacity storage area of ​​the Bluetooth USB Key, or the operation and maintenance business security chip of the Bluetooth USB Key.

11. The mobile terminal operation and maintenance system according to claim 1, characterized in that: The Bluetooth USB Key establishes a physical connection with the mobile operation and maintenance terminal through USB-OTG.

12. The mobile terminal operation and maintenance system according to claim 11, characterized in that: The mobile operation and maintenance terminal directly obtains the USB interface permission of the Bluetooth USB Key through the Android USBManager class; uses the UsbDeviceConnection class and UsbRequest class to build a non-blocking communication channel and establish a communication connection between the mobile operation and maintenance terminal and the Bluetooth USB Key.

13. The mobile terminal operation and maintenance system according to claim 11, characterized in that: During data transmission between the Bluetooth USB Key and the mobile operation and maintenance terminal, secure data transmission is achieved through middleware based on national encryption standards.

14. The mobile terminal operation and maintenance system according to claim 13, characterized in that: The command encapsulation method of the middleware based on the national secret standard is: taking the batch transmission command as the payload, adding the security command of the national secret standard into the batch transmission command to form an encrypted transmission data packet.

15. The mobile terminal operation and maintenance system according to claim 13, characterized in that: The middleware based on national encryption standards and the Bluetooth USB Key exchange data via the extended SCSI Command private protocol.

16. The mobile terminal operation and maintenance system according to claim 13, characterized in that: The middleware based on national encryption standards uses a lightweight communication protocol designed based on the Android sandbox permission model to implement three-level permission verification between the Bluetooth USB key and the mobile operation and maintenance application; The three-level permission verification includes: basic command verification, operation command verification and security command verification.

17. The mobile terminal operation and maintenance system according to claim 1, characterized in that: The Bluetooth module is connected to the main control chip via a serial port, and the operation and maintenance service security chip is connected to the main control chip via an SPI interface.