Key management method, storage medium and electronic equipment

By generating and storing the ciphertext of the recovery key, the problem of data encryption keys being unable to be decrypted due to the loss of hardware keys or passwords is solved, realizing reliable decryption and secure storage in the event of hardware failure, and expanding the ways to obtain data encryption keys.

CN121765740APending Publication Date: 2026-03-31HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

If the user password or hardware key cannot be obtained, the electronic device cannot decrypt the ciphertext of the data encryption key, resulting in the inability to access the content data.

Method used

A key management method is provided, which generates a recovery key to encrypt data encryption key, generates a first ciphertext and stores it in the unencrypted area of ​​non-volatile memory. The decryption process does not require hardware keys and user passwords, and the recovery key is stored on the server to bind account information, thereby reducing the risk of key leakage.

Benefits of technology

Even in the event of hardware failure or forgotten password, the data encryption key can still be decrypted, improving the reliability of data encryption key acquisition and storage security, and reducing key dependence and leakage risk.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121765740A_ABST
    Figure CN121765740A_ABST
Patent Text Reader

Abstract

The invention provides a key management method, a storage medium and electronic equipment, and relates to the technical field of computers.The key management method comprises the steps that in response to user operation, a recovery key is received; obtaining a first ciphertext of the data encryption key from a non-encryption storage area in the nonvolatile memory; the recovery key is used for decrypting the first ciphertext, a data encryption key is obtained, and the data encryption key is used for encrypting and / or decrypting the target content data in the nonvolatile memory. In this way, the dependence of the data encryption key and the hardware key can be reduced, and under the condition that the hardware key is lost, the first ciphertext in the non-encryption storage area can be decrypted through the recovery key to obtain the data encryption key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a key management method, storage medium, and electronic device. Background Technology

[0002] Full-disk encryption technology is used to encrypt content data with a data encryption key before electronic devices are locked or powered off, thereby improving the storage security of business data.

[0003] In related technologies, a user password and / or hardware key are used to encrypt and protect the data encryption key, generating ciphertext of the data encryption key. After the electronic device screen is unlocked or the device is powered on, the electronic device's security chip decrypts the ciphertext of the data encryption key using the user password and / or hardware key to obtain the data encryption key; and uses the data encryption key to decrypt the ciphertext of the target content data stored on the hard drive to obtain the target content data.

[0004] However, if the user password or hardware key cannot be obtained, the electronic device cannot decrypt the ciphertext of the data encryption key, resulting in the inability to access the content data. Summary of the Invention

[0005] To address the aforementioned technical problems, this application provides a key management method, a storage medium, and an electronic device. In the technical solution provided by this application, in response to a request to generate a recovery key, the recovery key is displayed; the recovery key is used to encrypt the data encryption key, obtaining a first ciphertext of the data encryption key; the first ciphertext is stored in the unencrypted storage area of ​​a non-volatile memory. Since the decryption process of the first ciphertext does not require obtaining a hardware key and / or user password, the electronic device can still decrypt the ciphertext of the data encryption key to obtain the data encryption key even if the user password or hardware key is unavailable. This allows the first ciphertext of the data encryption key to continue decryption without relying on a hardware key and / or user password, enabling the first ciphertext stored in the non-volatile memory to be decrypted using the recovery key even if the electronic device hardware is damaged, thus obtaining the data encryption key.

[0006] To achieve the above-mentioned technical objectives, this application provides the following technical solution:

[0007] In a first aspect, a key management method is provided, applied to a first electronic device. The method includes: displaying the recovery key in response to a request to generate a recovery key; encrypting a data encryption key using the recovery key to obtain a first ciphertext of the data encryption key; encrypting and / or decrypting target content data in a non-volatile memory using the data encryption key; and storing the first ciphertext in an unencrypted storage area of ​​the non-volatile memory.

[0008] The above method encrypts the data encryption key using the recovery key, generating the first ciphertext of the data encryption key. Compared to technologies that use the hardware key of an electronic device for decryption, the hardware key is often embedded in the motherboard. Damage or loss of the motherboard can lead to the loss of the hardware key, making the second ciphertext of the data encryption key difficult to decrypt, and ultimately preventing the data encryption key from being obtained.

[0009] In the solution provided in this embodiment, the recovery key is used to decrypt the first ciphertext of the data encryption key. This eliminates the need for a hardware key in the decryption process, reducing the dependence of the data encryption key on the hardware key in the electronic device. In the event of hardware damage to the electronic device, but with the non-volatile memory intact, the non-volatile memory can be connected to another electronic device, and this key management method can be executed in that other device. This approach helps improve the reliability of data encryption key acquisition and helps prevent data loss due to forgotten hardware keys or user passwords.

[0010] Furthermore, storing the first ciphertext of the data encryption key in the unencrypted area of ​​non-volatile memory reduces the difficulty for electronic devices to read it. Simultaneously, since the first ciphertext requires a recovery key for decryption, storing it in the unencrypted area will not lead to key leakage. This approach enhances the security of key storage even if the key is obtained, thereby improving the reliability of the key management method.

[0011] In one possible implementation, after generating the recovery key in response to the key generation operation, the method further includes: sending account information to the server in response to the account login operation; and sending a key binding request to the server in response to the key binding operation. The key binding request carries key data, which is an encrypted recovery key. The key binding request is used to request the binding of account information and recovery key.

[0012] Storing recovery keys on a server helps prevent users from forgetting their recovery keys, which could render the initial ciphertext of the data encryption key undecryptable.

[0013] In one possible implementation, before sending a key binding request to the server in response to the key binding operation, the method further includes: obtaining an end-cloud key, which is used to encrypt communication data between the first electronic device and the server; and encrypting a recovery key based on the public key in the end-cloud key to obtain key data.

[0014] This method helps prevent the recovery key from being leaked during communication between the electronic device and the server.

[0015] In one possible implementation, the recovery key includes a first subkey and a second subkey; in response to the operation of requesting to generate a recovery key, the recovery key is displayed, including: displaying the first subkey; the key data is the encrypted second subkey, and the key binding request is used to request binding account information and the second subkey.

[0016] Dividing the recovery key into a first subkey and a second subkey, and storing the subkeys in different ways, helps reduce the risk of recovery key leakage, improves the security of recovery key storage, and thus reduces the risk of data encryption key leakage.

[0017] In one possible implementation, the method further includes: obtaining a first credential based on the recovery key, the first credential being used to identify the recovery key; and storing the first credential in non-volatile memory.

[0018] This method helps verify the correctness of the recovery key provided by the user, thereby enhancing the security of data encryption keys obtained by decrypting based on the recovery key, or resetting user passwords based on the recovery key.

[0019] In one possible implementation, after storing the first ciphertext in the unencrypted storage area of ​​the non-volatile memory, the method further includes: receiving a recovery key in response to a user operation; reading the first ciphertext from the unencrypted storage area in the non-volatile memory; and decrypting the first ciphertext using the recovery key to obtain the data encryption key.

[0020] This allows users to provide a recovery key to decrypt the first ciphertext and obtain the data encryption key. It expands the methods for obtaining the data encryption key.

[0021] In one possible implementation, the boot area of ​​the non-volatile memory stores a second ciphertext of the data encryption key, which is obtained by encrypting the data encryption key using a preset first user password; after storing the first ciphertext in the unencrypted storage area of ​​the non-volatile memory, the method further includes: receiving a second user password provided by the user in response to an input user password; reading the second ciphertext from the boot area of ​​the non-volatile memory; and displaying a second interface if the second user password cannot decrypt the second ciphertext, wherein the second interface is used to receive a recovery key.

[0022] Thus, the key management method provided in this application can serve as an extension to the full-disk encryption algorithm, enabling the data encryption key to be obtained by decrypting both the first ciphertext and the second ciphertext. This increases the ways to obtain the data encryption key, helping to reduce the risk of the data encryption key being unobtainable. Provided that at least one of the recovery key or user password (and / or hardware key) is not lost, it can be guaranteed that after the electronic device is powered on or unlocked, the electronic device can successfully decrypt the ciphertext of the data encryption key to obtain the data encryption key.

[0023] In one possible implementation, the method further includes: displaying a third interface when the recovery key meets the verification conditions, the third interface being used to receive the operation of resetting the user password; in response to the third user password entered by the user on the third interface, replacing the first user password with the third user password, the first user password being used to encrypt the data encryption key and outputting the second ciphertext, and / or decrypting the second ciphertext and outputting the data encryption key, the second ciphertext being stored in the encrypted area of ​​a non-volatile memory.

[0024] Thus, triggering a password reset when the recovery key is correct helps improve the security of the password reset process.

[0025] In one possible implementation, if the recovery key meets the verification conditions, a third interface is displayed, including: obtaining a first credential based on the recovery key, the first credential being used to determine the correctness of the recovery key provided by the user; and displaying the third interface if the first credential is the same as a second credential stored in non-volatile memory.

[0026] By verifying whether the first and second credentials are consistent, it is possible to quickly verify whether the recovery key entered by the user is correct.

[0027] In one possible implementation, user actions are obtained from the lock screen, which is the display interface of the first electronic device when it is powered on, woken up, or requests to open the first application; or, user actions are obtained from the password reset interface.

[0028] In one possible implementation, the number of data bits in the recovery key is greater than or equal to the number of data bits in the data encryption key.

[0029] In a second aspect, a key management method is provided for use in a second electronic device. The method includes: receiving a recovery key in response to a user operation; obtaining a first ciphertext of a data encryption key from an unencrypted storage area in a non-volatile memory; decrypting the first ciphertext using the recovery key to obtain a data encryption key, wherein the data encryption key is used to encrypt and / or decrypt target content data in the non-volatile memory.

[0030] The above method encrypts the data encryption key using the recovery key, generating the first ciphertext of the data encryption key. Compared to technologies that use the hardware key of an electronic device for decryption, the hardware key is often embedded in the motherboard. Damage or loss of the motherboard can lead to the loss of the hardware key, making the second ciphertext of the data encryption key difficult to decrypt, and ultimately preventing the data encryption key from being obtained.

[0031] In the solution provided in this embodiment, the recovery key is used to decrypt the first ciphertext of the data encryption key. This eliminates the need for a hardware key in the decryption process, reducing the dependence of the data encryption key on the hardware key in the electronic device. In the event of hardware damage to the electronic device, but with the non-volatile memory intact, the non-volatile memory can be connected to another electronic device, and this key management method can be executed in that other device. This approach helps improve the reliability of data encryption key acquisition and helps prevent data loss due to forgotten hardware keys or user passwords.

[0032] Furthermore, storing the first ciphertext of the data encryption key in the unencrypted area of ​​non-volatile memory reduces the difficulty for electronic devices to read it. Simultaneously, since the first ciphertext requires a recovery key for decryption, storing it in the unencrypted area will not lead to key leakage. This approach enhances the security of key storage even if the key is obtained, thereby improving the reliability of the key management method.

[0033] In one possible implementation, receiving a recovery key in response to a user action includes: receiving a recovery key input by the user in response to an input of a recovery key.

[0034] In one possible implementation, receiving a recovery key in response to a user action includes: sending a key retrieval request to a server in response to a search for a recovery key; receiving key data sent by the server; and retrieving the recovery key based on the key data.

[0035] In one possible implementation, the recovery key includes a first subkey and a second subkey. Receiving the recovery key in response to a user operation includes receiving the first subkey in response to a user operation; the key data is the encrypted second subkey.

[0036] In one possible implementation, obtaining the recovery key based on the key data includes: decrypting the key data based on the private key in the end-cloud key to obtain the recovery key, wherein the end-cloud key is used to encrypt communication data between the second electronic device and the server.

[0037] In one possible implementation, before receiving key data bound to account information from the server in response to the operation of finding the recovery key, the method further includes: displaying a first interface for receiving account information input by the user.

[0038] In one possible implementation, obtaining the first ciphertext of the data encryption key from an unencrypted storage area in non-volatile memory includes: obtaining a first file directory corresponding to the unencrypted storage area according to a file management system for managing the non-volatile memory, wherein the file management system is used to divide the storage areas in the non-volatile memory, and the first file directory is used to index the data stored in the unencrypted storage area; and reading the first ciphertext from at least one file stored in the first file directory.

[0039] In one possible implementation, a second ciphertext of the data encryption key is stored in the non-volatile memory. The second ciphertext is obtained by encrypting the data encryption key using a preset first user password. Before receiving the recovery key in response to a user operation, the method further includes: receiving a second user password provided by the user in response to an input user password; retrieving the second ciphertext of the data encryption key from the startup area in the non-volatile memory; and displaying a second interface if the second user password cannot decrypt the second ciphertext. The second interface is used to receive the recovery key.

[0040] In one possible implementation, the non-volatile memory is a non-volatile memory installed in a second electronic device, or a non-volatile memory removed from another electronic device and having a data transmission path between it and the second electronic device.

[0041] In one possible implementation, after receiving the recovery key in response to a user operation, the method further includes: displaying a third interface if the recovery key meets the verification conditions; the third interface being used to receive the operation of resetting the user password; replacing the first user password with the third user password entered by the user on the third interface, the first user password being used to encrypt the data encryption key and outputting the second ciphertext; and / or decrypting the second ciphertext and outputting the data encryption key, the second ciphertext being stored in the encrypted area of ​​a non-volatile memory.

[0042] In one possible implementation, if the recovery key meets the verification conditions, a third interface is displayed, including: obtaining a first credential based on the recovery key, the first credential being used to determine the correctness of the recovery key provided by the user; and displaying the third interface if the first credential is the same as a second credential stored in non-volatile memory.

[0043] In one possible implementation, user actions are obtained from the lock screen, which is the display interface of the second electronic device when it is powered on, woken up, or requests to open the first application; or, user actions are obtained from the password reset interface.

[0044] Thirdly, a first electronic device is provided. The first electronic device includes at least one processor and a memory; the at least one processor is configured to execute instructions stored in the memory to cause the device to perform the methods described in the first aspect and any possible implementation thereof. In response to a request to generate a recovery key, the first electronic device displays the recovery key; encrypts a data encryption key using the recovery key to obtain a first ciphertext of the data encryption key; the data encryption key encrypts and / or decrypts target content data in non-volatile memory; and stores the first ciphertext in an unencrypted storage area of ​​the non-volatile memory.

[0045] In one possible implementation, when the processor reads computer instructions from memory, it also causes the first electronic device to perform: in response to an account login operation, sending account information to the server; in response to a key binding operation, sending a key binding request to the server, the key binding request carrying key data, the key data being an encrypted recovery key, the key binding request being used to request binding of account information and recovery key.

[0046] In one possible implementation, when the processor reads computer instructions from memory, it also causes the first electronic device to perform: obtaining an end-to-end cloud key, which is used to encrypt communication data between the first electronic device and the server; encrypting a recovery key based on the public key in the end-to-end cloud key, and obtaining key data.

[0047] In one possible implementation, the recovery key includes a first subkey and a second subkey; in response to the operation of requesting to generate a recovery key, the recovery key is displayed, including: displaying the first subkey; the key data is the encrypted second subkey, and the key binding request is used to request binding account information and the second subkey.

[0048] In one possible implementation, when the processor reads computer instructions from memory, it also causes the first electronic device to perform: obtaining a first credential based on the recovery key, the first credential being used to identify the recovery key; and storing the first credential in non-volatile memory.

[0049] In one possible implementation, when the processor reads computer instructions from memory, it also causes the first electronic device to perform: in response to a user operation, receive a recovery key; read the first ciphertext from an unencrypted storage area in non-volatile memory; and decrypt the first ciphertext using the recovery key to obtain the data encryption key.

[0050] In one possible implementation, the boot area of ​​the non-volatile memory stores a second ciphertext of the data encryption key, which is obtained by encrypting the data encryption key using a preset first user password; when the processor reads computer instructions from the memory, it also causes the first electronic device to perform: in response to the operation of inputting a user password, receiving a second user password provided by the user; reading the second ciphertext from the boot area of ​​the non-volatile memory; if the second user password cannot decrypt the second ciphertext, displaying a second interface, which is used to receive a recovery key.

[0051] In one possible implementation, when the processor reads computer instructions from memory, it also causes the first electronic device to perform: displaying a third interface if the recovery key meets the verification conditions, the third interface being used to receive the operation of resetting the user password; in response to the third user password entered by the user on the third interface, replacing the first user password with the third user password, the first user password being used to encrypt data encryption key and outputting a second ciphertext, and / or decrypting the second ciphertext and outputting a data encryption key, the second ciphertext being stored in the encrypted area of ​​non-volatile memory.

[0052] In one possible implementation, if the recovery key meets the verification conditions, a third interface is displayed, including: obtaining a first credential based on the recovery key, the first credential being used to determine the correctness of the recovery key provided by the user; and displaying the third interface if the first credential is the same as a second credential stored in non-volatile memory.

[0053] In one possible implementation, user actions are obtained from the lock screen, which is the display interface of the first electronic device when it is powered on, woken up, or requests to open the first application; or, user actions are obtained from the password reset interface.

[0054] In one possible implementation, the number of data bits in the recovery key is greater than or equal to the number of data bits in the data encryption key.

[0055] Fourthly, a second electronic device is provided. The second electronic device includes at least one processor and a memory; the at least one processor is configured to execute instructions stored in the memory to cause the second electronic device to perform the methods in any possible implementation of the second aspect and the second aspect described above. In response to a user operation, the second electronic device receives a recovery key; obtains a first ciphertext of a data encryption key from an unencrypted storage area in a non-volatile memory; and decrypts the first ciphertext using the recovery key to obtain a data encryption key, the data encryption key being used to encrypt and / or decrypt target content data in the non-volatile memory.

[0056] In one possible implementation, receiving a recovery key in response to a user action includes: receiving a recovery key input by the user in response to an input of a recovery key.

[0057] In one possible implementation, receiving a recovery key in response to a user action includes: sending a key retrieval request to a server in response to a search for a recovery key; receiving key data sent by the server; and retrieving the recovery key based on the key data.

[0058] In one possible implementation, the recovery key includes a first subkey and a second subkey. Receiving the recovery key in response to a user operation includes receiving the first subkey in response to a user operation; the key data is the encrypted second subkey.

[0059] In one possible implementation, obtaining the recovery key based on the key data includes: decrypting the key data based on the private key in the end-cloud key to obtain the recovery key, wherein the end-cloud key is used to encrypt communication data between the second electronic device and the server.

[0060] In one possible implementation, when the processor reads computer instructions from memory, it also causes the second device to: display a first interface for receiving account information input by the user.

[0061] In one possible implementation, obtaining the first ciphertext of the data encryption key from an unencrypted storage area in non-volatile memory includes: obtaining a first file directory corresponding to the unencrypted storage area according to a file management system for managing the non-volatile memory, wherein the file management system is used to divide the storage areas in the non-volatile memory, and the first file directory is used to index the data stored in the unencrypted storage area; and reading the first ciphertext from at least one file stored in the first file directory.

[0062] In one possible implementation, a second ciphertext of the data encryption key is stored in the non-volatile memory. The second ciphertext is obtained by encrypting the data encryption key using a preset first user password. When the processor reads computer instructions from the memory, it also causes the electronic device to perform the following actions: in response to the input of a user password, receiving a second user password provided by the user; retrieving the second ciphertext of the data encryption key from the boot area in the non-volatile memory; and, if the second user password cannot decrypt the second ciphertext, displaying a second interface for receiving a recovery key.

[0063] In one possible implementation, the non-volatile memory is a non-volatile memory installed in a second electronic device, or a non-volatile memory removed from another electronic device and having a data transmission path between it and the second electronic device.

[0064] In one possible implementation, when the processor reads computer instructions from memory, it also causes the second electronic device to perform: displaying a third interface if the recovery key meets the verification conditions, the third interface being used to receive the operation of resetting the user password; in response to the third user password entered by the user on the third interface, replacing the first user password with the third user password, the first user password being used to encrypt data encryption key and outputting second ciphertext; and / or decrypting the second ciphertext and outputting data encryption key, the second ciphertext being stored in the encrypted area of ​​non-volatile memory.

[0065] In one possible implementation, if the recovery key meets the verification conditions, a third interface is displayed, including: obtaining a first credential based on the recovery key, the first credential being used to determine the correctness of the recovery key provided by the user; and displaying the third interface if the first credential is the same as a second credential stored in non-volatile memory.

[0066] In one possible implementation, user actions are obtained from the lock screen, which is the display interface of the second electronic device when it is powered on, woken up, or requests to open the first application; or, user actions are obtained from the password reset interface.

[0067] Fifthly, a computer-readable storage medium is provided, on which computer program instructions are stored, which, when executed by a processing circuit, implement the method as described in any possible embodiment of the first aspect or the method as described in any possible embodiment of the second aspect.

[0068] In a sixth aspect, a chip system is provided, the chip system including a processing circuit and a storage medium storing computer program instructions; when the computer program instructions are executed by the processing circuit, they implement the method as described in any possible embodiment of the first aspect or the method as described in any possible embodiment of the second aspect.

[0069] In a seventh aspect, a computer program product comprising instructions is provided, which, when run on a computer, causes the computer to perform the method as described in any possible embodiment of the first aspect or the method as described in any possible embodiment of the second aspect.

[0070] The technical effects corresponding to any of the implementation methods in aspects three through seven can be found in the first aspect and the technical effects corresponding to any of the implementation methods in the first aspect, or in the second aspect and the technical effects corresponding to any of the implementation methods in the second aspect. They will not be repeated here. Attached Figure Description

[0071] Figure 1A schematic diagram of the communication system provided in the embodiments of this application;

[0072] Figure 2 The first electronic device and the second electronic device provided in the embodiments of this application are different electronic devices, but they share a non-volatile memory.

[0073] Figure 3 This application provides a schematic diagram of the structure of the first electronic device 100 or the second electronic device 300 for embodiments of the present application;

[0074] Figure 4 This is a schematic diagram of the structure of the server 200 provided in this application;

[0075] Figure 5A A schematic diagram of the functional modules provided in the embodiments of this application;

[0076] Figure 5B This is a schematic diagram of the layered software architecture provided in the embodiments of this application;

[0077] Figure 6 One of the flowcharts of the key management method provided in the embodiments of this application;

[0078] Figure 7 A schematic diagram illustrating the response key creation process provided in this application embodiment;

[0079] Figure 8 A flowchart illustrating the recovery key saving process provided in this application embodiment;

[0080] Figure 9 This is a schematic diagram illustrating the division of the recovery key as provided in an embodiment of this application;

[0081] Figure 10 A flowchart illustrating the credential generation process provided in this application embodiment;

[0082] Figure 11 A schematic diagram illustrating the interaction of functional modules during the data encryption key encryption process provided in this application embodiment;

[0083] Figure 12 A second schematic flowchart illustrating the key management method provided in this application embodiment;

[0084] Figure 13 A schematic diagram illustrating the interface switching process provided in an embodiment of this application;

[0085] Figure 14 A schematic diagram illustrating the interaction of functional modules during the execution of the key management method provided in this application embodiment;

[0086] Figure 15A flowchart illustrating the combination of the key management method and the full-disk encryption method provided in the embodiments of this application;

[0087] Figure 16 One of the scenario diagrams illustrating the key management method provided in the embodiments of this application;

[0088] Figure 17 A second schematic diagram illustrating a key management method provided in an embodiment of this application;

[0089] Figure 18 The third flowchart illustrating the key management method provided in this application embodiment;

[0090] Figure 19 The fourth flowchart illustrating the key management method provided in this application embodiment;

[0091] Figure 20 A schematic diagram illustrating a scenario of resetting a user password based on a recovery key, provided in an embodiment of this application;

[0092] Figure 21 A schematic diagram illustrating the interaction of functional modules during the password reset process provided in this application embodiment;

[0093] Figure 22 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0094] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0095] The terms "comprising" and "having," and any variations thereof, used in the description of the embodiments of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices.

[0096] Hereinafter, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature.

[0097] In this application, the terms "exemplarily" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplarily" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.

[0098] In the description of the embodiments in this application, unless otherwise stated, "multiple" means two or more. The term "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone.

[0099] With the development and widespread adoption of electronic devices, they are increasingly used in all aspects of users' lives. During the use of these devices, data is generated, and protecting the security of this data, both in its use and storage, remains a crucial and unavoidable aspect. Typically, data encryption algorithms are employed to protect this data and prevent leaks. For example, electronic devices may use full-disk encryption or password protection to safeguard data.

[0100] In one possible implementation, the electronic device's operating system includes a file vault, a built-in encryption function used to securely protect static data. For example, the file vault uses the AES-XTS data encryption algorithm to protect stored data on the electronic device. Optionally, the data encryption algorithm requires at least one of the following keys: a user password and a hardware key. The user password includes, but is not limited to, a user-set lock screen password and application password. The hardware key is information burned into the electronic device's hardware, such as information burned onto the motherboard.

[0101] When it is necessary to access the content data stored in the file vault, the user enters a user password; the security chip decrypts the ciphertext of the data encryption key based on the hardware key and / or the user password to obtain the data encryption key, and uses the data encryption key to decrypt the ciphertext of the content data stored in the file vault to obtain the decrypted content data.

[0102] Since decrypting the ciphertext of the data encryption key requires a hardware key and / or a user password, if the device motherboard is damaged and the hardware key cannot be obtained, or if the user password is forgotten, the ciphertext of the data encryption key will be undecryptable. This prevents the data encryption key from being obtained normally, thus making it impossible to decrypt the ciphertext of the content data in non-volatile memory, affecting the normal reading and use of the content data.

[0103] To address the aforementioned issues, this application provides a key management method that, in response to a request to generate a recovery key, displays the recovery key; uses the recovery key to encrypt a data encryption key to obtain a first ciphertext of the data encryption key; the data encryption key encrypts and / or decrypts target content data in a non-volatile memory; and stores the first ciphertext in the unencrypted storage area of ​​the non-volatile memory.

[0104] The above method encrypts the data encryption key using the recovery key, generating the first ciphertext of the data encryption key. Compared to technologies that use the hardware key of an electronic device for decryption, the hardware key is often embedded in the motherboard. Damage or loss of the motherboard can lead to the loss of the hardware key, making the second ciphertext of the data encryption key difficult to decrypt, and ultimately preventing the data encryption key from being obtained.

[0105] In the solution provided in this embodiment, the recovery key is used to decrypt the first ciphertext of the data encryption key. This eliminates the need for a hardware key in the decryption process, reducing the dependence of the data encryption key on the hardware key in the electronic device. In the event of hardware damage to the electronic device, but with the non-volatile memory intact, the non-volatile memory can be connected to another electronic device, and this key management method can be executed in that other device. This approach helps improve the reliability of data encryption key acquisition and helps prevent data loss due to forgotten hardware keys or user passwords.

[0106] Furthermore, storing the first ciphertext of the data encryption key in the unencrypted area of ​​non-volatile memory reduces the difficulty for electronic devices to read it. Simultaneously, since the first ciphertext requires a recovery key for decryption, storing it in the unencrypted area will not lead to key leakage. This approach enhances the security of key storage even if the key is obtained, thereby improving the reliability of the key management method.

[0107] In some embodiments, the key management scheme provided in this application can be implemented as a supplement to the full-disk encryption method. In some full-disk encryption methods, before the electronic device is powered off or the screen is locked, the content data needs to be encrypted using a data encryption key to obtain ciphertext of the content data, and the ciphertext of the content data is stored in non-volatile memory. Optionally, the electronic device encrypts the data encryption key using a hardware key and / or a user password to obtain a second ciphertext of the data encryption key. The second ciphertext is stored in the boot area of ​​the non-volatile memory. When the data encryption key needs to be obtained, the security chip in the electronic device decrypts the second ciphertext according to the hardware key and / or the user password to obtain the data encryption key.

[0108] As can be seen, the second key in the full-disk encryption method and the first key generated by the key management method provided in this application embodiment each have different decryption methods and storage areas. Therefore, supplementing the full-disk encryption method with this solution helps to expand the ways to obtain data encryption keys.

[0109] In one possible implementation, if the data encryption key cannot be obtained by decrypting the second ciphertext, the electronic device decrypts the first ciphertext of the data encryption key using this key management method to obtain the data encryption key. In other words, the key management method provided in this application can serve as an extension to the full-disk encryption algorithm, enabling the data encryption key to be obtained by decrypting both the first and second ciphertexts. This increases the ways to obtain the data encryption key, helping to reduce the risk of not being able to obtain it. Provided that at least one of the recovery key or user password (and / or hardware key) is not lost, it can be guaranteed that after the electronic device is powered on or unlocked, the electronic device can successfully decrypt the ciphertext of the data encryption key to obtain the data encryption key.

[0110] As can be seen, the solution provided in this embodiment helps to ensure the stability of obtaining the data encryption key in various usage environments, and helps to avoid the problem that the content data cannot be read due to the inability to obtain the data encryption key, which would affect the user experience.

[0111] The following describes the communication system to which the key management method provided in the embodiments of this application is applied. Figure 1 This is a schematic diagram of a communication system in which the key management method provided in this application is applied. Figure 1 As shown, the communication system includes a first electronic device 100.

[0112] In some embodiments, the first electronic device 100 is also referred to as at least one of the following: access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user equipment.

[0113] The first electronic device 100 in the embodiments of this application includes, but is not limited to: mobile phone, personal computer, tablet computer, computer with wireless transceiver function, virtual reality (VR) device, augmented reality (AR) device, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical care, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, vehicle terminal, roadside unit (RSU) with terminal function, etc.

[0114] Optionally, the operating system installed on the first electronic device 100 includes, but is not limited to, Or other operating systems.

[0115] like Figure 1 As shown, the communication system may also include at least one of the following: a server 200 and a second electronic device 300. The first electronic device 100 participates in the encryption process of the data encryption key; the second electronic device 300 participates in the decryption process of the data encryption key. The server 200 can provide users with a storage service for recovery keys used to encrypt and / or decrypt data encryption keys.

[0116] In some embodiments, server 200 is a device or server with computing capabilities, such as a cloud server or network server. The server can be a single server, a server cluster consisting of multiple servers, or a cloud computing data center. Server 200 can be the server for the operating system corresponding to the first electronic device 100 or the second electronic device 300, or it can be the backend server for third-party applications installed on the first electronic device 100 or the second electronic device 300. Optionally, third-party applications include, but are not limited to, cloud storage applications, social applications, etc.

[0117] In some embodiments, the second electronic device 300 includes the first electronic device 100. For example, the second electronic device 300 and the first electronic device 100 may be the same electronic device. Alternatively, the second electronic device 300 may be a different electronic device than the first electronic device 100. In this case, the first electronic device 100 and the second electronic device 300 perform corresponding operations based on the same non-volatile memory.

[0118] Figure 2 The first electronic device and the second electronic device provided in the embodiments of this application are different electronic devices, but they can share the same non-volatile memory. (See the schematic diagram.) Figure 2 As shown, a non-volatile memory 101 is installed in the first electronic device 100. In the event of damage to the motherboard or other hardware of the first electronic device 100, the non-volatile memory 101 can be removed from the first electronic device 100. Subsequently, the user connects the non-volatile memory 101 to the second electronic device 300, enabling the second electronic device 300 to read the data stored in the non-volatile memory 101, thereby realizing the key management method provided in this embodiment.

[0119] The structures of the first electronic device 100 and the second electronic device 300 are described below. For easier understanding, please refer to [link / reference needed]. Figure 3 , Figure 3 A schematic diagram of the structure of a first electronic device 100 or a second electronic device 300 is shown. Optionally, the first electronic device 100 and the second electronic device 300 have similar structures. The structure of the electronic device is described using the first electronic device 100 as an example. Figure 3 As shown, the first electronic device 100 includes a processor 110, a memory 120, a communication module 130, and a display screen 140.

[0120] Processor 110 may include one or more processing units. For example, processor 110 may include at least one of the following: application processor (AP), modem processor, graphics processing unit (GPU), image signal processor (ISP), controller, video codec, digital signal processor (DSP), baseband processor, and / or neural network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.

[0121] Memory 120 includes external memory and internal memory. The internal memory is used to store executable program code. The executable program code includes instructions. Processor 110 executes various functional applications and data processing of the first electronic device 100 by running the instructions stored in the internal memory. Exemplarily, the internal memory includes a program storage area and a data storage area. Memory 120 may be disposed in processor 110 for storing instructions and data. External memory refers to a memory card connected to the first electronic device 100 via an external memory interface.

[0122] Optionally, the memory 120 includes non-volatile memory, which is used to store user data generated during the user's use of the first electronic device 100, as well as the ciphertext of the data encryption key. Non-volatile memory refers to memory capable of storing data for a long period. The non-volatile memory ensures that the data stored within it is not lost after power is lost. Exemplarily, the type of non-volatile memory includes at least one of the following: flash memory, solid-state drive (SSD), hybrid hard drive (HHD), and hard disk drive (HDD). For example, the non-volatile memory is a removable solid-state drive in the first electronic device.

[0123] For example, the non-volatile memory is installed inside the first electronic device 100, and the non-volatile memory in the first electronic device 100 is removable. For example, the non-volatile memory is connected to a data read interface on the bus of the first electronic device 100 via a connection cable.

[0124] The communication module 130 is used to implement the communication function of the first electronic device 100. Optionally, the communication module 130 includes functional modules such as an antenna, a mobile communication module, a wireless communication module, a modem processor, and a baseband processor. Optionally, at least some of the functional modules of the mobile communication module can be housed within the processor. The wireless communication module is used to support the first electronic device 100 in wireless communication.

[0125] The first electronic device 100 implements display functions through functional modules such as a GPU and a display screen 140. The display screen 140 is used to display images, videos, etc. In some embodiments, the first electronic device 100 may include one or N display screens 140, where N is a positive integer greater than 1. The GPU and the display screens 140 can be used to support the first electronic device 100 in displaying system tools or applications.

[0126] For details regarding the structure of the second electronic device 300, please refer to the description of the structure of the first electronic device 100; it will not be repeated here. It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the first electronic device 100 or the second electronic device 300. In other embodiments of this application, the first electronic device 100 or the second electronic device 300 may include more or fewer components than illustrated, or combine certain components, or split certain components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0127] For example, Figure 4 This is a schematic diagram of the structure of the server 200 provided in this application. Figure 4 As shown, server 200 includes at least one processor 401, communication line 402, memory 403, and at least one communication interface 404. The memory 403 may also be included within the processor 401.

[0128] Processor 401 includes, but is not limited to: a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the present application.

[0129] Communication line 402 may include at least one path for transmitting information between the aforementioned components.

[0130] The memory 403 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. The memory 403 may exist independently or be connected to the processor 401 via communication line 402. The memory 403 may also be integrated with the processor 401.

[0131] The memory 403 stores computer execution instructions for implementing the scheme of this application, and its execution is controlled by the processor 401. The processor 401 executes the computer execution instructions stored in the memory 403, thereby implementing the key management method provided in the following embodiments of this application.

[0132] Communication interface 404 is used for communication with other devices. In this embodiment, communication interface 404 may be a module, circuit, bus, interface, transceiver, or other device capable of implementing communication functions. Optionally, when communication interface 404 is a transceiver, the transceiver may be a separately configured transmitter used to send information to other devices, or it may be a separately configured receiver used to receive information from other devices. The transceiver may also be a component that integrates sending and receiving information functions; this embodiment does not limit the specific implementation of the transceiver.

[0133] Optionally, the computer execution instructions in the embodiments of this application may also be referred to as application code, instructions, computer program or other names, and the embodiments of this application do not specifically limit them.

[0134] In a specific implementation, as one example, processor 401 may include one or more CPUs, for example... Figure 4 CPU0 and CPU1 in the example. In a specific implementation, as one embodiment, server 200 may include multiple processors, such as... Figure 4 Processors 401 and 407 are described herein. Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. A processor here may refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).

[0135] It is understood that the embodiments illustrated in this application are as follows: Figure 4 The structure does not constitute a specific limitation on the implementation of server 200. In other embodiments of this application, server 200 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0136] In one possible implementation, the key management method provided in this application is implemented by at least one functional module in a first electronic device 100 and / or a second electronic device 300. The types and functions of the functional modules are described below using the first electronic device 100 as an example. Figure 5A As shown, the software functional modules in the first electronic device 100 provided in this application embodiment include at least a recovery key management module and a file encryption module.

[0137] The file encryption module is used to provide protection services for content data generated during the operation of the first electronic device 100. Optionally, the file encryption module is used to encrypt content data according to a data encryption key when content data protection is required, thereby obtaining the ciphertext of the content data. The file encryption module is also used to decrypt the ciphertext of the content data according to the data encryption key, thereby obtaining the content data.

[0138] Optionally, the file encryption module is also used to generate a recovery key and use the recovery key to encrypt the data encryption key to obtain the first ciphertext of the data encryption key.

[0139] The recovery key management module provides management services for recovery keys. Optionally, the recovery key management module displays the recovery key in response to user actions. The recovery key management module also stores the first ciphertext of the data encryption key. The recovery key is used to protect the data encryption key.

[0140] In one example, during the recovery key generation process, the file encryption module generates a recovery key and a first ciphertext. The file encryption module then sends the recovery key to the recovery key management module, enabling the recovery key management module to display the recovery key to the user and store the first ciphertext in an unencrypted area of ​​non-volatile memory. Subsequently, the recovery key can be kept by the user or linked to the user's account information and stored on the server. When the recovery key is needed, the user provides it through user actions.

[0141] In one example, during the process of using the recovery key to decrypt and obtain the data encryption key, the recovery key management module receives the recovery key through user operation and reads the first ciphertext from the unencrypted area of ​​the non-volatile memory; the file encryption module obtains the first ciphertext and the recovery key through the recovery key management module; the file encryption module uses the recovery key to decrypt the first ciphertext and obtain the data encryption key.

[0142] Optionally, the functional modules in the first electronic device 100 may further include at least one of the following: a hardware key reading module, a password management module, and a key management module.

[0143] A hardware key reading module is used to read a hardware key from the hardware of the first electronic device 100. In some embodiments, the hardware key is burned onto the hardware of the electronic device, such as onto the motherboard of the first electronic device 100. Optionally, the hardware key reading module reads the hardware key from the motherboard and provides the hardware key to the key management module, so that the key management module can encrypt the data encryption key based on the hardware key.

[0144] The password management module is used to provide management services for user passwords. Optionally, user passwords include, but are not limited to, lock screen passwords and application passwords. The lock screen password is used to restore the first electronic device 100 from a locked state to a working state; the application password is used to unlock applications on the first electronic device so that the first electronic device 100 can display the application's user interface. For example, the password management module is used to generate authentication information based on the user password, and to determine whether the user can unlock the first electronic device 100 or unlock applications on the first electronic device using the authentication information.

[0145] Optionally, the password management module provides the key management module with a user password entered by the user, so that the key management module can encrypt the data encryption key based on the hardware key.

[0146] Optionally, the password management module is used to provide the user password to the key management module when the user password is confirmed to be correct, so as to trigger the key management module to use the user password to unlock the second ciphertext, or to trigger the key management module to use the user password to encrypt the data encryption key to obtain the second ciphertext.

[0147] The key management module is used to generate data encryption keys. In some examples, after obtaining the data encryption key, the key management module sends it to the file encryption module to trigger the file encryption module to encrypt the content data using the data encryption key. In other examples, after obtaining the data encryption key, the key management module sends it to the file encryption module to trigger the file encryption module to encrypt the data encryption key using the recovery key to output the first ciphertext. In still other examples, after obtaining the data encryption key, the key management module encrypts it using a user password and / or a hardware key to output the second ciphertext.

[0148] In this embodiment, a key management method is completed through the collaboration of multiple functional modules. The interaction logic between the various functional modules is described below.

[0149] In some embodiments, the file encryption module, recovery key management module, password management module, hardware key reading module, and key management module described above are disposed in the application framework layer of the software layered architecture of the first electronic device 100 and the second electronic device 300.

[0150] like Figure 5B As shown, the layered architecture divides the software into several layers, each with a clear role and function. Layers communicate with each other through software interfaces. In some embodiments, the operating system is divided into four layers, from top to bottom: the application layer, the application framework layer, the TS (arkts runtime) runtime and system libraries, and the kernel layer.

[0151] The application layer comprises a series of applications, such as telephone, SMS, photo album, and video player. The application framework layer provides application programming interfaces (APIs) and a programming framework for the applications in the application layer. The application framework layer includes some predefined functions.

[0152] The window manager is used to manage window applications. It can obtain the screen size, determine if a status bar is present, lock the screen, and capture screenshots, among other things.

[0153] System libraries can include multiple functional modules. For example: surface manager, media libraries, 3D graphics processing libraries (e.g., OpenGL ES), 2D graphics engines, etc.

[0154] The Surface Manager is used to manage the display subsystem and provides the fusion of two-dimensional (2D) and three-dimensional (3D) layers for multiple applications.

[0155] The media library supports playback and recording of various commonly used audio and video formats, as well as still image files. It supports multiple audio and video coding formats, such as: Moving Picture Experts Group 4 (MPEG4), Advanced Video Coding (H.264), Moving Picture Experts Group Audio Layer III (MP3), Advanced Audio Coding (AAC), Adaptive Multi Rate (AMR), Joint Photographic Experts Group (JPG), and Portable Network Graphics (PNG).

[0156] 3D graphics processing libraries are used to implement 3D graphics drawing, image rendering, compositing, and layer processing. 2D graphics engines are drawing engines for 2D graphics.

[0157] The key management method is described below through several embodiments. Optionally, the data encryption key encryption process and the data encryption key decryption process can be performed by the same electronic device or by different electronic devices. For clarity, in the embodiments below, a first electronic device is used as the execution subject of the data encryption key encryption process, and a second electronic device is used as the execution subject of the data encryption key decryption process.

[0158] The following is based on Figure 1 The first electronic device 100 shown is used as an execution entity to specifically illustrate the key management method. Optionally, the functional modules of the first electronic device 100 include a file encryption module and a recovery key management module. Exemplarily, the functional modules in the first electronic device 100 also include at least one of the following: a key management module, a hardware key reading module, and a password management module. Please refer to the relevant documentation. Figure 6 , Figure 6 This is one of the flowcharts illustrating the key management method provided in an embodiment of this application. Figure 6 As shown, the key management method provided in this application embodiment includes at least steps S610 to S630.

[0159] In step S610, the first electronic device responds to the request to generate a recovery key by displaying the recovery key.

[0160] Optionally, the recovery key is used to protect the data encryption key. The data encryption key is the key used to protect the content data in the first electronic device. The data encryption key is also called the encryption key.

[0161] In the key management method provided in this embodiment, the recovery key is generated by a first electronic device, and the user of the first electronic device decides how to store the recovery key. For example, the user decides how to store the recovery key.

[0162] Optionally, the data encryption key is generated by the first electronic device. Optionally, for different users using the same first electronic device, the data encryption keys corresponding to each user can be the same or different.

[0163] For example, when a user logs into the first electronic device for the first time using their device account, the first electronic device generates a data encryption key corresponding to the device account and uses this data encryption key to encrypt and store the content data generated by the user in the first electronic device. This embodiment focuses on an encryption key within the first electronic device as an example.

[0164] Optionally, the recovery key is the key used in a symmetric encryption algorithm. That is, both encryption and decryption of the data encryption key can be performed using the recovery key. For example, a first electronic device encrypts the data encryption key using the recovery key to obtain the first ciphertext of the data encryption key. The first ciphertext is the encrypted data after encryption with the data encryption key. As another example, the first electronic device decrypts the first ciphertext using the recovery key to obtain the data encryption key.

[0165] The operation of requesting the generation of a recovery key is used to request the first electronic device to generate a recovery key.

[0166] Optionally, the operation to request the generation of a recovery key is triggered by a user using the first electronic device. Exemplarily, the operation to request a recovery key includes, but is not limited to, at least one of the following: a click, a double-click, a long press, a swipe, a button press, a gesture, a voice command, etc. Exemplarily, the operation to request a recovery key is implemented as clicking a key generation button. If the first electronic device responds to clicking the recovery key generation button, it generates and displays a recovery key.

[0167] Figure 7 This is a schematic diagram illustrating a scenario of the recovery key creation process provided in an embodiment of this application. Figure 7 As shown, the user requests the generation of a recovery key; the first electronic device responds to the request by generating a recovery key. Optionally, the first electronic device may also display the recovery key in the key display interface 710.

[0168] In some embodiments, the first electronic device, in response to a request to generate a recovery key, randomly generates a recovery key. Optionally, the recovery key is a string of random numbers. For example, the first electronic device, in response to a request to generate a recovery key, randomly generates a 256-bit random number and uses that 256-bit random number as the recovery key.

[0169] In some embodiments, the number of bits in the recovery key is greater than or equal to the number of bits in the data encryption key. For example, the data encryption key is 128 bits and the recovery key is 256 bits. Another example is that both the data encryption key and the recovery key are 128 bits.

[0170] Optionally, during the generation of the recovery key, the first electronic device determines the number of data bits of the recovery key based on the number of data bits of the data encryption key.

[0171] For example, in response to a request to generate a recovery key, the first electronic device obtains a first value, where the first value is the number of data bits in the data encryption key. Based on the first value, the first electronic device determines a second value, where the second value is the number of data bits the recovery key should have. Subsequently, the first electronic device randomly generates a recovery key of the second value length.

[0172] By setting the number of data bits in the recovery key to be greater than or equal to the number of data bits in the data encryption key, it is easier to crack the first ciphertext obtained by encrypting the data encryption key with the recovery key, thereby helping to ensure the security of the first ciphertext.

[0173] In some embodiments, the first electronic device randomly generates a recovery key in a data sequence format, and displays the recovery key in this data sequence format. Optionally, the recovery key in the data sequence format is a string of random numbers.

[0174] In other embodiments, the first electronic device converts the recovery key to a first data format recovery key to facilitate user observation and / or input of the recovery key. The data format conversion process of the recovery key is described below through several embodiments.

[0175] In some embodiments, the first electronic device displays a recovery key in a first data format. Optionally, in response to a request to generate a recovery key, the first electronic device generates a recovery key in a data sequence format; the first electronic device converts the data sequence format recovery key into a data key in the first data format; and the electronic device displays the recovery key in the first data format.

[0176] The first data format is the data format obtained after data format conversion. Optionally, the recovery key in the first data format consists of at least one of the following elements: numbers, lowercase letters, uppercase letters, and punctuation marks. The punctuation marks include at least one of the following: +, =, / , etc.

[0177] For example, the recovery key in the first data format includes multiple sequence groups, each containing the same total number of elements, with adjacent sequence groups connected by a "-". For instance, a recovery key in a certain first data format is represented as: wf9+-x6ls-Fwn9-D6FW-Bsfs-ykHp-m8Kr-afz7-Dxxx-LhxC-4Tg=. Here, "wf9+" represents one sequence group, "x6ls" represents another sequence group, and so on.

[0178] In one example, after the first electronic device randomly generates a recovery key, it divides the numbers in the recovery key in the data sequence format into multiple number groups. For each number group, the first electronic device performs a base conversion to obtain a binary number group. The first electronic device divides the binary number group into multiple binary subgroups. For each binary subgroup, the first electronic device expands the number of bits included in the binary subgroup to obtain an expanded binary subgroup. The first electronic device determines the element corresponding to the expanded binary subgroup according to the format encoding table. The electronic device assembles the recovery key in the first data format based on the elements corresponding to each binary subgroup.

[0179] Here, "multiple" refers to two or more, and the recovery key in the data sequence format is a string of random numbers. For example, the format encoding table refers to the element corresponding to the binary subgroup. For example, the format encoding table includes the Base encoding table.

[0180] For example, if the recovery key in the data sequence format is [1, 2, 3, 4, ...], the first electronic device divides the recovery key in the data sequence format into multiple element groups. The following describes the data format conversion process using the first element group as an example.

[0181] Suppose the first element group contains the numbers 1, 2, and 3. Here, "1" is represented by 8 bits in American Standard Code for Information Interchange (ASCII), making the first element group 24 bits in total. The first electronic device then divides this element group into three subgroups, each 6 bits in length. For each subgroup, the first electronic device adds two 0s to its high-order bits, resulting in an expanded subgroup of 8 bits. The recovery key in the first data format includes the elements corresponding to each expanded subgroup.

[0182] For example, if the expanded binary subgroup represents 0 in ASCII encoding, and the element corresponding to 0 in the format encoding table is A, then the first electronic device determines that the element corresponding to the expanded binary subgroup is A.

[0183] In this embodiment, the recovery key's data format is first converted, and then the converted recovery key is displayed. Compared to a string of random numbers, the converted recovery key is easier for users to observe, remember, and input. By displaying the key in the first data format, this method helps reduce the difficulty for users to input the data encryption key subsequently, thereby improving the ease with which users can decrypt the data using the recovery key to obtain the encryption key and then decrypt the content data.

[0184] In some embodiments, during the display of the recovery key, the first electronic device generates key data in response to an instruction to save the recovery key. The key data is used to record the recovery key.

[0185] Optionally, the key data may be represented in at least one of the following formats: text, screenshot, file, etc. Subsequently, in response to the operation of storing the key data, the first electronic device stores the key data in itself. In response to the operation of sending the key data, the first electronic device sends the key data to other electronic devices or a server so that the other electronic devices can store the key data.

[0186] In other embodiments, the data saving function of the first electronic device is disabled during the display of the recovery key. That is, the first electronic device does not support copying the recovery key at the user's instruction, taking screenshots of the recovery key display interface, or generating a file containing the recovery key.

[0187] Optionally, in response to the instruction to save the recovery key, the first electronic device displays a save failure message. This message serves to remind the first electronic device that it does not support long-term storage of the recovery key. This method avoids storing the recovery key in the first electronic device, thus improving the security of the recovery key.

[0188] Optionally, the first electronic device does not store the recovery key permanently. For example, after displaying the recovery key, the first electronic device deletes the data associated with the recovery key in response to the operation of de-displaying the recovery key. This helps prevent the first ciphertext and the recovery key from being stored simultaneously in the first electronic device. This ensures that after the recovery key is displayed to the user, other users cannot obtain the recovery key from the first electronic device, helping to prevent the data encryption key from being leaked from the first electronic device and thus threatening the security of the content data stored in non-volatile memory.

[0189] In some embodiments, step S610 involves functional modules of the first electronic device including a file encryption module and a recovery key management module. Optionally, in response to an operation requesting a recovery key, the file encryption module generates a recovery key; subsequently, the file encryption module transmits the recovery key to the recovery key management module; and the recovery key management module displays the recovery key to the user.

[0190] Optionally, step S610 also involves a key management module. After generating the data encryption key, the key management module transmits the data encryption key to the file encryption module; the file encryption module determines the data length of the recovery key based on the data length of the data encryption key, and then generates the recovery key.

[0191] In one example, the recovery key generation process is triggered by the user. Exemplarily, the first electronic device displays the operating system's settings interface; in response to a request to switch interfaces detected in the settings interface, the first electronic device displays a key generation interface. This key generation interface is provided by the operating system of the first electronic device. Exemplarily, the key generation interface displays a first control for requesting the generation of a recovery key; in response to clicking the first control, the first electronic device displays the recovery key in the key generation interface.

[0192] Optionally, the first electronic device can also trigger the generation of a recovery key through various methods such as user voice operation or remote control operation. Optionally, the first electronic device can also provide users with access points other than the settings interface to obtain the recovery key.

[0193] The solution provided in this example supports users actively requesting recovery keys. Allowing the user to control when the first electronic device generates and displays the recovery key helps ensure that the user understands its purpose before being provided with it. This approach helps remind users to carefully safeguard their recovery keys, thereby reducing the likelihood of them being forgotten.

[0194] In another example, the recovery key generation process is automatically triggered by the first electronic device. For instance, in response to a login operation using a device account, the first electronic device retrieves the number of login attempts for that account; if it determines that the device account is logging in for the first time, the first electronic device displays the recovery key. In this case, after the user logs in to the first electronic device, the recovery key is automatically generated and displayed.

[0195] As described above, the first electronic device can generate and display a recovery key after receiving a request for a recovery key. The recovery key can be stored in several ways: either by the user personally, or by binding the recovery key and user account and storing it on another device (such as a server).

[0196] In one possible implementation, the recovery key is kept personally by the user, including recording it by hand, photograph, or other means. The specific method of personal storage is determined by the user and is not limited here. Binding the recovery key to the user account means associating the recovery key with user credentials that can identify the user, so that the recovery key can be retrieved later using the user credentials.

[0197] In another possible implementation, the recovery key is stored by the server. Optionally, the user logs into their user account via a first electronic device and requests the server to establish a binding relationship between the user account and the recovery key. This method allows the server to store the recovery key. Several embodiments of this recovery key storage method are described below.

[0198] In some embodiments, the method further includes (attached) after step S610. Figure 6 (Not shown in the image), in step S613, the first electronic device sends a recovery key to the server so that the server can store the recovery key.

[0199] Figure 8 This is a flowchart illustrating the recovery key saving process provided in an embodiment of this application. Figure 8 As shown, the process of saving the recovery key includes the following steps, which are provided by... Figure 1 The first electronic device 100 and the server 200 work together to complete this task.

[0200] In step S810, the first electronic device responds to the account login operation and displays the first interface.

[0201] The account login function is used to log in to the user account of the user using the first electronic device. The first interface is used to log in to the user account.

[0202] Optionally, in response to the user account login operation, the first electronic device switches the key display interface used to display the recovery key to the first interface. This allows the user to log in to their account through the first interface and establish a binding relationship between the recovery key and the user account.

[0203] For example, step S810 is executed after generating the recovery key in response to the request in step S610. After the recovery key is generated, steps S810-S870 can establish a binding relationship between the recovery key and the user account, so that when the user needs to obtain the recovery key, the server can find the recovery key generated in step S610 based on the binding relationship between the recovery key and the user account.

[0204] In step S820, the first electronic device responds to the operation of entering account information and obtains the account information and login password.

[0205] Account information corresponds to credentials that identify a user, and different users have different account information. Optionally, the type of account information includes, but is not limited to, at least one of the following: third-party account information and native account information. Third-party account information refers to accounts registered by users in third-party applications. In this case, the server provides backend support for the third-party application. For example, third-party applications include, but are not limited to, social applications and cloud storage applications.

[0206] For example, the native account information is the user's account information under the operating system of the first electronic device. In this case, the server is a cloud platform used to support the operating system.

[0207] In step S830, the first electronic device responds to the account information verification operation by generating a login verification request.

[0208] The login verification request is used to verify whether the account information exists. For example, the login verification request carries the user account and login password.

[0209] Optionally, the account information verification operation can be implemented as at least one of the following: a click operation, a long press operation, a swipe operation, a gesture operation, a voice operation, etc. For example, the first interface displays a control for logging into a user account, and the first electronic device generates a login verification request in response to clicking the control.

[0210] In step S840, the first electronic device sends a login verification request to the server.

[0211] Optionally, the server verifies whether the account information exists based on the login verification request. For example, if the account information does not exist or the login password is incorrect, the server executes steps S850 and S860, and then stops executing other steps; if the account information exists and the login password is correct, the first electronic device executes step S870.

[0212] In step S850, if the account information does not exist, the server sends a verification failure notification to the first electronic device.

[0213] The verification failure notification indicates that the login key is incorrect or the account information does not exist.

[0214] In step S860, the first electronic device displays a verification failure message.

[0215] In step S870, if the account information is verified to exist, the first electronic device responds to the key binding operation by sending a key binding request to the server.

[0216] Optionally, the key binding request carries key data related to the recovery key. For example, the key data includes at least one of the following: the recovery key, and the ciphertext of the recovery key. The key data of the recovery key is obtained by encrypting the recovery key; that is, the key data is the encrypted recovery key. For example, the key binding request includes the ciphertext of the recovery key.

[0217] In one example, the first electronic device obtains the end-cloud key in response to the operation of binding the recovery key; the first electronic device encrypts the recovery key using the public key in the end-cloud key to obtain the key data of the recovery key; the first electronic device carries the recovery key data in the key binding request; and the first electronic device stores the private key in the end-cloud key.

[0218] The private key in the edge-cloud key is used to decrypt the ciphertext of the recovery key. Optionally, the edge-cloud key is generated by the first electronic device and is used to protect the communication data transmitted between the server and the first electronic device. For example, the edge-cloud key includes a public key and a private key, the public key being known to both the first electronic device and the server, and the private key being known to the first electronic device.

[0219] This method avoids directly carrying the recovery key during communication between the electronic device and the server, preventing the key binding request sent by the electronic device to the server from being intercepted and thus leading to the leakage of the recovery key. Furthermore, this embodiment eliminates the need to store the recovery key on the server, helping to ensure the security of the recovery key's storage on the server and preventing the recovery key from being stolen due to security attacks on the server.

[0220] In step S880, the server establishes a binding relationship between the recovery key and the account information based on the key binding request.

[0221] Optionally, the server stores the encrypted recovery key in the storage space corresponding to the user account according to the key binding request, so that the server can subsequently provide the first electronic device with the recovery key bound to the account information through the account information.

[0222] This method allows users to find the recovery key through their registered account. Storing the recovery key on the server helps prevent users from forgetting it, thereby improving the reliability of recovery key storage.

[0223] To further enhance the storage security of recovery keys and reduce the possibility of recovery key leakage, the following examples illustrate the methods for storing recovery keys.

[0224] In some embodiments, the recovery key includes a first subkey. The first electronic device generates and displays the first subkey in response to a request for a recovery key. Optionally, the recovery key also includes a second subkey. The first electronic device generates both the first and second subkeys in response to a request for a recovery key. Subsequently, the first electronic device displays the first subkey.

[0225] For example, in response to a request for a recovery key, the first electronic device generates a first subkey and a second subkey, including: the first electronic device generating a recovery key in response to the request for a recovery key; the first electronic device dividing the recovery key to obtain the first subkey and the second subkey. Subsequently, the first electronic device displays the first subkey.

[0226] In one example, the recovery key consists of 2n elements, where n is a positive integer. The first subkey contains the first n elements, and the second subkey contains the last n elements, or the second subkey contains the first n elements and the first subkey contains the last n elements.

[0227] In another example, the recovery key comprises p*q elements, where p and q are positive integers. The first electronic device divides the recovery key into p element groups, each containing q consecutive elements from the recovery key. For example, the first subkey includes elements in odd-numbered positions from the p element groups, and the second subkey includes elements in even-numbered positions from the p element groups. Alternatively, the first subkey may include elements in even-numbered positions from the p element groups, and the second subkey may include elements in odd-numbered positions from the p element groups.

[0228] Figure 9 This is a schematic diagram illustrating the division of the recovery key provided in an embodiment of this application. For example... Figure 9 As shown, the recovery key 900 comprises 32 elements. The first electronic device divides the recovery key 900 into 8 element groups, each containing 4 elements. The 8 element groups are: element group 1, element group 2, element group 3, element group 4, element group 5, element group 6, element group 7, and element group 8. The first electronic device uses element groups 1, 3, 5, and 7 to form the first subkey 910, and uses element groups 2, 4, 6, and 8 to form the second subkey 920.

[0229] Optionally, in addition to displaying the first subkey, the first electronic device also displays the second subkey. For example, the first electronic device displays both the first and second subkeys on the same interface. Optionally, the first electronic device does not display the second subkey.

[0230] For example, after displaying the recovery key, the first electronic device, in response to the instruction to bind the recovery key, requests the server to establish a binding relationship between the account information and the second sub-key. For instance, the first electronic device encrypts the second sub-key using the public key in the end-to-cloud key to obtain the ciphertext of the second sub-key; the first electronic device sends the ciphertext of the second sub-key to the server; the server stores the ciphertext of the second sub-key in the account space corresponding to the account information.

[0231] In some embodiments, when it is necessary to decrypt to obtain the data encryption key, a first electronic device or a second electronic device obtains a first sub-key from the user side and a second sub-key from the server using account information; the first electronic device or the second electronic device concatenates the first sub-key and the second sub-key to obtain a recovery key. The recovery key is then used to decrypt the first ciphertext of the data encryption key to obtain the data encryption key.

[0232] This embodiment helps reduce the risk of recovery key leakage and improves the security of recovery key storage by dividing the recovery key into at least two sub-keys and storing them in different ways.

[0233] To verify the correctness of the recovery key provided by the user during subsequent use, the method for verifying the correctness of the recovery key is described below. Optionally, after generating the recovery key, the first electronic device generates and stores a first credential of the recovery key, and verifies the accuracy of the recovery key subsequently entered by the user using the first credential.

[0234] like Figure 10 As shown, after step S610, the key management method further includes steps S616 and S617, which are performed by... Figure 1 The first electronic device 100 in the process is executed.

[0235] Step S616: The first electronic device obtains the second credential based on the recovery key.

[0236] The second credential is used to indicate the recovery key generated by the first electronic device. Optionally, the mapping relationship between the second credential and the recovery key is determined. That is, processing the same recovery key using the same encoding method yields a definite second credential; processing different recovery keys using the same encoding method results in different second credentials. For details on the usage of the second credential, please refer to the embodiment on the second electronic device side.

[0237] For example, there are strict execution timing constraints between each of steps S613, S616, and S620. For instance, S613, S616, and S620 are executed synchronously. Or, for another example, S613, S616, and S620 are executed sequentially.

[0238] In one example, the first electronic device maps the recovery key to obtain the second credential; the first electronic device stores the second credential in an encrypted area of ​​non-volatile memory.

[0239] Optionally, the first electronic device performs mapping processing on the recovery key to obtain the second credential, including: the first electronic device processes the recovery key through an encryption algorithm to obtain the second credential.

[0240] Step S617: The first electronic device stores the second credential.

[0241] Optionally, the first electronic device stores the second credential in non-volatile memory.

[0242] In some embodiments, steps S616 and S617 involve a functional module of the first electronic device including a recovery key management module. Optionally, after receiving a recovery key from the file encryption module, the recovery key management module encrypts the recovery key to obtain a first credential, and stores the first credential.

[0243] For example, in cases where user password reset is triggered by recovery key, the recovery key management module sends a first credential to the password management module, which then stores the first credential in non-volatile memory.

[0244] This embodiment generates a credential corresponding to the recovery key, enabling the verification of the authenticity of the obtained recovery key using the first credential when a user-provided recovery key is subsequently received. This method helps prevent invalid calculations by the electronic device due to incorrect recovery keys.

[0245] After the first electronic device generates the recovery key, it uses the recovery key to process the data encryption key in order to protect the data encryption key. This process is described below through step S620.

[0246] In step S620, the first electronic device uses the recovery key to encrypt the data encryption key, thereby obtaining the first ciphertext of the data encryption key.

[0247] For example, step S620 is executed after step S610 is completed. There is no strict execution sequence between step S620 and steps S613 and S616. For example, step S620 can be executed before step S613, or after step S613, or step S620 can be executed synchronously with step S613.

[0248] In some embodiments, the first ciphertext of the data encryption key is the ciphertext data obtained by encrypting the data encryption key with the recovery key. The data encryption key can be obtained by decrypting the first ciphertext with the recovery key.

[0249] Optionally, the first electronic device uses a data encryption key to encrypt the data encryption key based on a symmetric encryption algorithm to obtain the first ciphertext.

[0250] For example, symmetric encryption algorithms include at least one of the following: Advanced Encryption Standard (AES), Data Encryption Standard (DES), Triple Data Encryption Standard (3DES), and Stream Cipher (RC). The encryption process can also be aided by using Galois Counter Mode (GCM). For instance, a first electronic device uses the AES-GCM encryption algorithm and the recovery key to encrypt the data encryption key, obtaining the first ciphertext.

[0251] In some embodiments, step S620 involves a functional module of the first electronic device including a file encryption module. Optionally, after generating a recovery key, the file encryption module uses the recovery key to encrypt a data encryption key, generating a first ciphertext of the data encryption key.

[0252] In step S630, the first electronic device stores the first ciphertext in the unencrypted area of ​​the non-volatile memory.

[0253] Optionally, non-volatile memory refers to memory capable of storing data for a long period. Non-volatile memory ensures that the data stored within it is not lost after power is lost. Exemplarily, the types of non-volatile memory include at least one of the following: flash memory, solid-state drive (SSD), hybrid hard drive (HHD), and hard disk drive (HDD). For example, the non-volatile memory is a removable solid-state drive in a first electronic device.

[0254] In some embodiments, the non-volatile memory is used to store content data generated during the operation of the first electronic device. Optionally, when the first electronic device is in operation, the non-volatile memory stores unencrypted content data (excluding data for which the user performs encryption operations); when the first electronic device is in sleep or powered off state, the encrypted area of ​​the non-volatile memory stores ciphertext of the content data. The ciphertext of the content data is obtained by encrypting the content data with a data encryption key.

[0255] Optionally, the content data includes at least one of the following: operational data and business data. The operational data refers to data recording the usage process of the first electronic device. Optionally, the operational data includes at least one of the following: log files, temporary files, performance parameters, etc. For example, log files and temporary files are used to record events occurring during the operation of the first electronic device. Performance parameters are used to reflect performance changes during the operation of the first electronic device.

[0256] Business data refers to data related to users of the first electronic device. For example, business data includes documents, images, videos, audio files, binary files, etc., downloaded, edited, or viewed by the user on the first electronic device.

[0257] In some embodiments, the data storage area in a non-volatile memory is divided into an encrypted area and an unencrypted area. The unencrypted area is also called the unencrypted storage area, and the encrypted area is also called the encrypted storage area.

[0258] The unencrypted area is used to store data that does not require encryption. Electronic devices can read data from the unencrypted area and use that data. The electronic devices mentioned here include the first electronic device and other electronic devices. For example, if the connection between the first electronic device and the non-volatile memory is disconnected, and a second electronic device is connected to the non-volatile memory, the second electronic device can read the data stored in the unencrypted area of ​​the non-volatile memory.

[0259] Optionally, the first electronic device stores the first ciphertext of the data encryption key in an unencrypted area. For example, the first electronic device stores the first ciphertext in a first file directory within the unencrypted area. When the first ciphertext needs to be retrieved, it can be read from the first file directory in the unencrypted area. The electronic device mentioned herein includes the first electronic device.

[0260] In this embodiment, the electronic device generates a recovery key and stores the first ciphertext obtained by encrypting the data encryption key with the recovery key in the unencrypted area of ​​non-volatile memory. This facilitates subsequent decryption using the user-held recovery key and the first ciphertext stored in the unencrypted area to obtain the data encryption key. This method provides a relatively simple and quick way to obtain the data encryption key, reducing the difficulty of obtaining the data encryption key while ensuring its security.

[0261] The encrypted area is used to store data that needs to be encrypted. Optionally, for the aforementioned content data, the first electronic device encrypts the content data using a data encryption key to obtain ciphertext of the content data; the first electronic device then stores the ciphertext of the content data in the encrypted area.

[0262] The following section describes when to use a data encryption key to encrypt content data.

[0263] In some embodiments, upon receiving a data protection instruction, the first electronic device uses a data encryption key to encrypt content data, generating ciphertext of the content data.

[0264] Optionally, the data protection instruction is generated by the first electronic device. For example, before the first electronic device is powered off and its screen is locked, the first electronic device generates a data protection instruction, triggering the step of encrypting the content data using a data encryption key.

[0265] Since users may access business data at any time while the electronic device is in use, encrypting content data with a data encryption key when it is determined that the first electronic device is about to lock its screen or be powered off can ensure the security of content data storage while reducing the interference of content data encryption on the user experience.

[0266] For example, before the first application is closed, the first electronic device generates a data protection instruction, triggering the step of encrypting content data related to the first application using a data encryption key. Encrypting content data using a data encryption key before the first application is closed helps improve the storage security of content data related to the first application and reduces the risk of content data being stolen, misused, or modified by other applications.

[0267] The first application is the application installed in the first electronic device.

[0268] Optionally, the first electronic device encrypts a file containing content data using a data encryption key to obtain an encrypted file; the first electronic device then stores the encrypted file in an encrypted area. The encrypted file includes ciphertext of the content data.

[0269] In one example, the first electronic device generates a data protection instruction in response to an instruction to lock the screen; the first electronic device triggers the encryption of the content data using a data encryption key based on the data protection instruction to obtain the ciphertext of the content data; the first electronic device stores the ciphertext of the content data in an encrypted area.

[0270] The operations for locking the screen include, but are not limited to, tapping, double-tapping, long-pressing, swiping, and gesture operations.

[0271] In another example, when the standby time reaches a time threshold, the first electronic device automatically generates a data protection instruction; the first electronic device uses a data encryption key to encrypt the content data, obtaining the ciphertext of the content data; subsequently, the first electronic device enters a lock screen state.

[0272] In another example, the first electronic device, in response to a power-off instruction, generates a data protection command; based on the data protection command, the first electronic device triggers the encryption of the content data using a data encryption key, obtaining the ciphertext of the content data; the first electronic device stores the ciphertext of the content data in an encrypted area. Subsequently, the first electronic device powers off all devices, shutting down the system.

[0273] In some embodiments, step S630 involves a functional module of the first electronic device including a recovery key management module. Optionally, after generating the first ciphertext, the file encryption module stores the first ciphertext in an unencrypted area of ​​a non-volatile memory.

[0274] The following describes the interaction process of the various functional modules in the first electronic device during the data encryption key encryption process. This embodiment involves... Figure 5A The first electronic device includes a file encryption module and a recovery key management module. Optionally, this embodiment also relates to an interface display module in the first electronic device. The interface display module is used to control the first electronic device to display a key display interface to the user. Figure 11 As shown, this embodiment includes at least the following steps:

[0275] In step S1110, the file encryption module encrypts the data encryption key according to the first user password and obtains the second ciphertext of the data encryption key.

[0276] The second ciphertext is obtained by encrypting the data encryption key using the first user password and / or a hardware key by the file encryption module. Optionally, the second ciphertext is stored in the boot area of ​​non-volatile memory. The boot area is used to store resources required during the startup process of the electronic device. For example, during the startup or wake-up process of the first electronic device, the security chip in the first electronic device reads the second ciphertext from the boot area and decrypts the second ciphertext using the first user password and / or a hardware key to obtain the data encryption key.

[0277] The boot area refers to a storage region in non-volatile memory used to store system resources. Optionally, the boot area may be an encrypted region. For example, during the boot process of the first electronic device, the first electronic device reads the resource files required to boot the operating system from the boot area.

[0278] For example, in response to the operation of unlocking the first electronic device, the file encryption module obtains the data encryption key through the key management module, and the file encryption module encrypts the data encryption key according to the first user password to obtain the data encryption key.

[0279] The operation of unlocking the first electronic device is used to control the first electronic device to enter the operating state. Optionally, the operation of unlocking the first electronic device can be implemented by inputting a first user password into the first electronic device when the first electronic device is powered on or needs to be unlocked. Optionally, the first user password is a lock screen password or a power-on password set by the user.

[0280] Optionally, the file encryption module encrypts the data encryption key using a first user password and a hardware key to obtain a second ciphertext of the data encryption key. For example, the first user password is provided to the file encryption module by the password management module, and the hardware key is provided to the file encryption module by the hardware key reading module.

[0281] In one example, the file encryption key uses a user password to encrypt the data encryption key. In another example, the file encryption key uses a hardware key to encrypt the data encryption key. In yet another example, the file encryption key uses both a user password and a hardware key to encrypt the data encryption key.

[0282] Optionally, the file encryption module uses a user password and / or a hardware key to encrypt data. The specific method of encrypting the encryption key depends on the encryption algorithm used for full disk encryption. This application does not limit the encryption algorithm used in the second ciphertext generation process.

[0283] In step S1112, the file encryption module encrypts the content data according to the data encryption key to obtain the ciphertext of the content data.

[0284] Optionally, in response to locking the first electronic device, the file encryption module encrypts the content data according to the data encryption key to obtain the ciphertext of the content data. Locking the first electronic device controls it to enter a non-operating state such as power off or hibernation. Optionally, unlocking the first electronic device can be implemented by controlling it to power off or lock its screen.

[0285] To ensure the security of data stored in the non-volatile memory after the first electronic device is powered off or enters hibernation mode, the file encryption module encrypts the data using a data encryption key before entering the non-operating state, obtaining the ciphertext of the data. Optionally, the ciphertext of the data is stored in an encrypted area of ​​the non-volatile memory.

[0286] For example, after encrypting the content data, the file encryption module deletes the data encryption key. That is, after the first electronic device is powered off or put into sleep mode, the encrypted area of ​​the non-volatile memory stores the ciphertext of the content data, but not the content data itself. Optionally, this embodiment can also start execution from step S1112.

[0287] In step S1113, the file encryption module decrypts the second ciphertext of the lock data encryption key according to the first user password to obtain the data encryption key.

[0288] Optionally, the user wakes up the first electronic device, such as after the first electronic device is restarted or the screen is unlocked, and the file encryption module decrypts the second ciphertext using the first user password and / or hardware key to obtain the data encryption key.

[0289] In step S1114, the file encryption module responds to the operation of obtaining the first content data by decrypting the ciphertext of the first content data according to the data encryption key, and obtains the first content data.

[0290] The first content data can be any single piece of content data. For example, the first content data could be a file that the user has edited in the past. Optionally, the encrypted first content data can be stored in an encrypted area of ​​a non-volatile memory.

[0291] Optionally, after step S1113 is completed, the file encryption module uses the data encryption key to decrypt the ciphertext of all content data in the encrypted area. Optionally, after step S1113 is completed, if the first electronic device needs to use the first content data, the file encryption module reads the ciphertext of the first content data from the encrypted area of ​​the non-volatile memory; the file encryption module uses the data encryption key to decrypt the ciphertext of the first content data to obtain the first content data.

[0292] In step S1120, the interface display module sends a recovery key generation request to the recovery key management module. The recovery key generation request is used to request the generation of a recovery key.

[0293] Optionally, in response to the request to generate a recovery key, the interface display module sends a recovery key generation request to the recovery key management module. Optionally, the recovery key generation request carries a first user password. The first user password is the password for the device's user account. For example, if the first user password is correct, the first electronic device switches from a locked state to a running state.

[0294] By including the first user password in the recovery key generation request, it is possible to identify the user currently using the first electronic device.

[0295] Step S1121: The recovery key management module sends a recovery key generation request to the file encryption module.

[0296] Step S1130: The file encryption module generates a recovery key.

[0297] Optionally, after receiving a recovery key generation request, the file encryption model randomly generates a recovery key. For example, the file encryption module converts the recovery key to a first data format recovery key.

[0298] In step S1140, the file encryption module encrypts the data encryption key according to the recovery key and obtains the first ciphertext of the data encryption key.

[0299] In step S1141, the file encryption module sends the recovery key and the first ciphertext to the recovery key management module.

[0300] Optionally, the file encryption module sends a recovery key in a first data format to the recovery key.

[0301] In step S1150, the recovery key management module stores the first ciphertext in the unencrypted area of ​​the non-volatile memory.

[0302] Optionally, the recovery key management module stores the first ciphertext in a first file directory. The first file directory is the file directory corresponding to the unencrypted area in non-volatile memory.

[0303] Step S1160: The recovery key management module sends the recovery key to the interface display module.

[0304] Optionally, after receiving the recovery key, the interface display module displays the recovery key in the recovery key interface.

[0305] Optionally, after displaying the recovery key to the user through the interface display module, the first electronic device can also generate a first credential, so that after the user obtains the recovery key through subsequent operations, the first credential can be used to verify whether the recovery key is correct. The key management method can also optionally perform the following two steps.

[0306] Step S1170: The recovery key management module obtains the first credential based on the recovery key.

[0307] Optionally, the recovery key management module encodes the recovery key to obtain a first credential for the recovery key. For example, the recovery key management module encrypts the recovery key using a first encryption algorithm to generate the first credential for the recovery key. The first encryption algorithm is a symmetric encryption algorithm.

[0308] Step S1171: The recovery key management module stores the first credential.

[0309] Optionally, the recovery key management module sends a first credential to the password management module so that the password management module can verify the correctness of the recovery key provided by the user based on the first credential, and provide the function of resetting the user's password if the recovery key is correct.

[0310] For details not described in this embodiment, please refer to the embodiments above; they will not be repeated here.

[0311] This embodiment supports the generation of recovery keys for user-protected data encryption keys. These recovery keys enable the encryption and decryption of the data encryption keys. Since the recovery key is generated by the file encryption module's hardware key and stored by the user, the encryption and decryption processes of the data encryption keys do not depend on the hardware key. This method helps reduce the dependence on the hardware key during the ciphertext decryption process of the data encryption key, thereby avoiding the problem of hardware damage leading to the inability to obtain the data encryption key.

[0312] Furthermore, the first ciphertext is stored in an unencrypted area for easy retrieval. Even if other hardware in the electronic device is damaged, the data encryption key can be obtained by decrypting the first ciphertext and the recovery key using the non-volatile memory installed in another electronic device.

[0313] The following is based on Figure 1 The second electronic device 300 shown is used as the execution entity to specifically illustrate the key management method. Optionally, the functional modules of the second electronic device 300 include a recovery key management module. The functional modules in the second electronic device 300 may also include: a file encryption module, a key management module, a hardware key reading module, and a password management module. Please refer to the following references. Figure 12 , Figure 12 This is a second flowchart illustrating the key management method provided in the embodiments of this application. Figure 12 As shown, the key management method provided in this application embodiment includes at least steps S1210 to S1250.

[0314] In step S1210, the second electronic device receives the recovery key in response to the user's operation.

[0315] In some embodiments, the first electronic device and the second electronic device are the same device, or the second electronic device is a different device from the first electronic device. Optionally, in scenarios where the recovery key is used to decrypt the ciphertext of the content data, the first electronic device and the second electronic device are the same device, or the first electronic device and the second electronic device are different electronic devices. For example, if a user forgets their password, making it impossible to decrypt the second ciphertext of the data decryption key based on the user password, the recovery key can be used to decrypt the first ciphertext of the data decryption key to obtain the data encryption key. In this case, the first electronic device and the second electronic device are the same electronic device.

[0316] For example, in the event of hardware damage / replacement of the first electronic device, a non-volatile memory in the first electronic device is connected to a second electronic device. A recovery key is provided to the second electronic device to decrypt the first ciphertext of the data encryption key, thus obtaining the data encryption key. The second electronic device then uses the data encryption key to decrypt the ciphertext of the content data stored in the encrypted area of ​​the non-volatile memory, obtaining the content data generated by the user during use of the first electronic device. In this case, the first electronic device and the second electronic device are different electronic devices.

[0317] Optionally, in scenarios where a recovery key is used to change a user's password, the first electronic device and the second electronic device are the same device.

[0318] The user operation is used to provide a recovery key to the second electronic device. Optionally, the data format of the recovery key provided by the user operation to the second electronic device includes, but is not limited to: a recovery key in a first data format, and a recovery key in a data sequence format.

[0319] In some embodiments, user operations include at least one of the following: entering a recovery key and searching for a recovery key.

[0320] Optionally, the user provides a recovery key in a first data format to the second electronic device by inputting a recovery key; the second electronic device, in response to the input of the recovery key, obtains the recovery key in the first data format input by the user; the second electronic device converts the recovery key in the first data format into a data sequence format recovery key (such as obtaining a string of random numbers), so that the first ciphertext can be decrypted in subsequent steps using the data sequence format recovery key.

[0321] Optionally, the user operation is implemented by logging into the user account's account space through the operation of logging into the user account; and by searching for the recovery key, the recovery key bound to the account information is retrieved from the account space through the operation of searching for the recovery key.

[0322] For example, when the user account is a native account, the second electronic device supports logging into the user account's account space while the screen is locked. Figure 13 As shown, when the second electronic device is in a locked state, a login control 1310 is displayed on the lock screen interface 1300; in response to the operation of logging into a user account, the second electronic device displays the first interface 1320; in response to the operation of entering account information, the second electronic device obtains the account information and login password; in response to the operation of verifying account information, the second electronic device generates a login verification request; the second electronic device sends the login verification request to the server. If the verified account information exists, the second electronic device sends a key retrieval request to the server in response to the operation of finding a recovery key. After receiving the key binding request, the server finds the key data bound to the account information and sends the key data to the second electronic device.

[0323] The first interface is the user interface provided by the application or cloud platform to which the user account belongs. Optionally, the first interface displays a second control for finding the recovery key; the second electronic device responds to clicking the second control by requesting the server to find the recovery key bound to the account information. The display effect of the login control is as follows. Figure 13 The "Login" control in the first interface 1320.

[0324] In some embodiments, the key data includes a recovery key, or includes ciphertext of the recovery key.

[0325] Optionally, if the key data includes a recovery key, the second electronic device reads the recovery key from the key data. Optionally, if the key data includes ciphertext of the recovery key, the second electronic device decrypts the ciphertext of the recovery key using the private key in the end-cloud key to obtain the recovery key. For an introduction to the end-cloud key, please refer to the embodiment on the first electronic device side.

[0326] For example, if the user account belongs to a third-party application, the second electronic device may not support logging into the user account's account space while the screen is locked. In this case, the user can log into the user account through another electronic device, obtain a recovery key, and manually enter the recovery key into the second electronic device.

[0327] In some embodiments, user operations are obtained from the lock screen interface, which is the display interface of the first electronic device when it is powered on, woken up, or requests to open the first application; or, user operations are obtained from the password reset interface. That is, user operations are used to unlock the first electronic device using a recovery key, wake up the first electronic device, or trigger the launch of an application installed on the first electronic device. Exemplarily, user operations are also used to update the user password using a recovery key. The password reset interface is used to reset the user password, and the password reset interface includes the third interface described in the embodiments below. For details regarding the above implementation scenarios, please refer to the description of the embodiments below.

[0328] In step S1220, the second electronic device retrieves the first ciphertext of the data encryption key from the unencrypted storage area in the non-volatile memory.

[0329] For details regarding the first ciphertext and the non-volatile memory, please refer to the above embodiment.

[0330] Optionally, the second electronic device obtains the first ciphertext of the data encryption key from the unencrypted storage area in the non-volatile memory, including: the second electronic device determining the file management system corresponding to the non-volatile memory; determining the unencrypted storage area according to the file management system; and traversing at least one file stored in the unencrypted storage area to obtain the first ciphertext.

[0331] The file management system is used to allocate storage space in non-volatile memory. Different operating systems use different file management systems, and these different file management methods result in different ways of allocating storage space in non-volatile memory. For example, the file names corresponding to unencrypted areas may differ depending on the file management system used.

[0332] Optionally, if the first electronic device and the second electronic device are different, the second electronic device determines the file management system corresponding to the non-volatile memory through driver software; the second electronic device determines the first file directory corresponding to the unencrypted area in the non-volatile memory according to the file management system corresponding to the non-volatile memory; the second electronic device traverses at least one file stored in the unencrypted storage area according to the first file directory to obtain the first ciphertext.

[0333] The first file directory is the file directory corresponding to the unencrypted area, and the data stored in the unencrypted area is set in the first file directory. For example, the first file directory is the "data / " directory.

[0334] For example, the second electronic device traverses at least one file stored in the unencrypted storage area according to the first file directory to obtain the first ciphertext, including: the second electronic device determining the set of running files included in the first file according to the first file directory; the second electronic device traversing each file included in the set of running files to obtain the first ciphertext.

[0335] The runtime file set is used to store data generated by the first electronic device during its operation. The first ciphertext is generated during the operation of the first electronic device, therefore it can be stored in the runtime file set.

[0336] This method helps reduce the total number of files that electronic devices need to traverse in unencrypted areas, thereby increasing the speed at which electronic devices can retrieve recovery keys from non-volatile storage.

[0337] In step S1230, the second electronic device uses the recovery key to decrypt the first ciphertext and obtain the data encryption key.

[0338] The data encryption key is used to encrypt and / or decrypt target content data in the non-volatile memory. For a detailed description of the data encryption key, please refer to the embodiment on the first electronic device side.

[0339] In step S1240, the second electronic device retrieves the ciphertext of the target content data from the non-volatile memory.

[0340] In some embodiments, the ciphertext of the target content data is stored in an encrypted region of a non-volatile memory. Optionally, the target content data is any content data that needs to be decrypted from the encrypted region.

[0341] Optionally, the target content data may be all content data, or it may be a portion of the content data. Here, "all content data" refers to the content data corresponding to the ciphertext of each piece of content data within the encrypted area.

[0342] For example, the target content data is the content data that the second electronic device needs to use during operation; in response to the instruction to display the content data, the second electronic device uses the data encryption key to decrypt the ciphertext of the target content data to obtain the target content data.

[0343] The instruction to display content data is used to indicate the file identifier or file storage address of the target content data. The second electronic device reads the ciphertext of the target content data from the encrypted area based on the file identifier or file storage address.

[0344] Optionally, the instruction to display content data is generated by the second electronic device in response to an operation to view the target content data. The operation to view the target content data includes at least one of the following: triggering a display icon for the target content data, or instructing the opening of the target content data via program code.

[0345] In step S1250, the second electronic device decrypts the ciphertext of the target content data using the data encryption key to obtain the target content data.

[0346] Optionally, the encryption method used to protect the content data by the data encryption key is a symmetric encryption algorithm. For example, the first electronic device encrypts the target content data using the data encryption key based on the second encryption algorithm to obtain the ciphertext of the target content data; the second electronic device decrypts the ciphertext of the target content data using the data encryption key based on the second encryption algorithm to obtain the target content data.

[0347] The second encryption algorithm can be any type of symmetric encryption algorithm. For example, if the first and second electronic devices are equipped with the same application architecture layer, the second encryption method is known to the second electronic device. For instance, the second electronic device may have a file encryption module that includes the second encryption algorithm.

[0348] Subsequently, the second electronic device displays the target content data.

[0349] In one example, the target content data is a first document that the user has edited in the past. In response to the operation of displaying the first document, the second electronic device reads the ciphertext of the first document from the encrypted area; the second electronic device decrypts the ciphertext of the first document using the data encryption key to obtain the first document; the second electronic device displays the second document.

[0350] The following describes the interaction process between functional modules within the second electronic device during the execution of the key management method. This embodiment is provided by... Figure 5A The file encryption module and recovery key management module work together as shown. In this embodiment, the non-volatile memory is an SSD. This SSD is removed from the first electronic device. The SSD is connected to the second electronic device, which can read data from the SSD. Figure 14 As shown, this embodiment includes at least the following steps:

[0351] S1410, The recovery key management module receives the recovery key in response to the user's operation.

[0352] In one example, the recovery key management module receives a recovery key entered by the user. In another example, the recovery key management module reads the recovery key from a USB storage device.

[0353] In one example, the recovery key management module obtains the recovery key from the server. The server stores the binding relationship between account information and recovery keys. When the user enters account information and login password on the second electronic device, the recovery key management module requests the recovery key from the server.

[0354] S1420, the recovery key management module obtains the first ciphertext of the data encryption key from the unencrypted storage area in the non-volatile memory.

[0355] Optionally, the recovery key management module queries the first ciphertext in the unencrypted storage area of ​​the non-volatile memory. For example, the recovery key management module reads the first ciphertext from a first file directory in the unencrypted area.

[0356] S1430, the recovery key management module sends the recovery key and the first ciphertext to the file encryption module.

[0357] Optionally, if the recovery key management module obtains a recovery key in the first data format, it converts the recovery key in the first data format to obtain a recovery key in the data sequence format. The recovery key management module then sends the first ciphertext and the recovery key in the data sequence format to the file encryption module.

[0358] S1440, the file encryption module uses the recovery key to decrypt the first ciphertext and obtain the data encryption key.

[0359] S1450, the file encryption module uses the data encryption key to decrypt the ciphertext of the target content data and obtain the target content data.

[0360] Optionally, the target content data is all the content data. For example, when the second electronic device is powered on or unlocked from the lock screen, the file encryption module reads the ciphertext of the content data stored in the encryption area one by one.

[0361] Optionally, the file encryption module decrypts the ciphertext of the target content data using a second encryption algorithm and a data encryption key to obtain the target content data. For example, the decrypted target content data is stored in an encrypted area, and the second electronic device can read and directly use the target content data from the encrypted area. If the second electronic device is powered off, locked, or the application is closed, the second electronic device deletes the target content data stored in the encrypted area.

[0362] After the electronic device is powered on, unlocked, or the application is reopened, if the user needs to use the target content data, the second electronic device responds to the operation of finding the target content data, retrieves the target content data from the SSD, and displays the target content data to the user.

[0363] In the solution provided in this embodiment, the first ciphertext of the data encryption key is generated from the recovery key, so that the process of decrypting to obtain the data encryption key does not require the use of a hardware key, reducing the dependence of the data encryption key on the hardware key in the electronic device. In the event of hardware damage to the electronic device, but with the non-volatile memory intact, the non-volatile memory can be connected to another electronic device, and this key management method can be executed in that other electronic device. This helps improve the reliability of the data encryption key acquisition method and helps avoid data loss to the user due to forgotten hardware keys or user passwords.

[0364] The following examples illustrate this. Figure 1 Example of a scenario where the second electronic device 300 performs a key management method.

[0365] Example 1: A scenario combining recovery key management and full-disk encryption. In this embodiment, the second electronic device and the first electronic device are the same electronic device. Figure 15 As shown, this embodiment includes at least the following steps:

[0366] S1510, the second electronic device receives the second user password in response to the operation of inputting the user password.

[0367] The second user password is the password entered by the user. The second user password is used to attempt to unlock the second ciphertext and obtain the data encryption key.

[0368] For example, during the power-on or unlocking process of the second electronic device, the second electronic device displays a lock screen interface; the lock screen interface includes a password input field; the second electronic device receives a second user password in response to an input operation on the password input field.

[0369] S1520, the second electronic device retrieves the second ciphertext of the data encryption key from the boot area in the non-volatile memory.

[0370] After receiving the second user password, the second electronic device reads the second ciphertext and decrypts it using the second user password.

[0371] In some embodiments, a security chip in the second electronic device reads the second ciphertext from the boot area. Optionally, the second electronic device decrypts the second ciphertext using a first user password and / or a hardware key.

[0372] For example, if the second electronic device can obtain the data encryption key by decrypting the second ciphertext, it can directly execute step S1570 since the data encryption key has been obtained. If the second electronic device cannot obtain the data encryption key by decrypting the second ciphertext, it starts executing from step S1530.

[0373] S1530, if the second user password is different from the first user password, the second electronic device displays the second interface.

[0374] The second interface is used for users to provide recovery keys. For example, the second interface may display a key input field. Alternatively, the second interface may display an account login control, allowing the second electronic device to respond to the account login control by displaying the first interface and retrieving the recovery key from the server using account information.

[0375] In some embodiments, if the second user password is different from the first user password, the second electronic device cannot decrypt the second ciphertext using the second user password, indicating that the second user password entered by the user is incorrect. That is, the second user password entered by the user does not match the first user password set in the second electronic device. In other words, if the second user password cannot decrypt the second ciphertext, the second electronic device displays a second interface.

[0376] Optionally, the second electronic device stores first verification information used to characterize the first user password, and after receiving the second user password, the second electronic device generates second verification information for the second user password.

[0377] For example, a second electronic device encrypts a second user password using a third encryption algorithm to obtain second verification information. The third encryption algorithm is the same as the one used to encrypt the first user password to obtain the first verification information. The third encryption algorithm may be the same as the second encryption algorithm, or it may be unrelated to the second encryption algorithm.

[0378] Subsequently, the second electronic device compares the first verification information with the second verification information. If the first verification information and the second verification information are the same, it means that the second user password is the same as the first user password; if the first verification information and the second verification information are different, it means that the second user password is different from the first user password, and the second user password is incorrect.

[0379] For example, when the second user password differs from the first user password, the second electronic device records the number of password errors. In one example, if the number of errors is less than a first threshold, the second electronic device clears the password input field so that the first user can correct their password; if the number of errors is greater than or equal to the first threshold, the second electronic device displays a second interface, or the second electronic device displays a third control on the lock screen, and the second electronic device displays the second interface in response to the operation of triggering the third control.

[0380] The first threshold is preset, such as 1, 2, 3, etc. This application does not limit the value of the first threshold.

[0381] S1540, the second electronic device receives the recovery key in response to the user's operation.

[0382] S1550, the second electronic device retrieves the first ciphertext of the data encryption key from the unencrypted storage area in the non-volatile memory.

[0383] S1560, the second electronic device uses the recovery key to decrypt the first ciphertext and obtain the data encryption key.

[0384] S1570, the second electronic device uses the data encryption key to decrypt the ciphertext of the target data and obtain the target content data.

[0385] For a description of steps S1540-S1570, please refer to the above embodiment; they will not be repeated here.

[0386] The key management method provided in this application can be used as an extension to the full-disk encryption algorithm, enabling the data encryption key to be obtained by decrypting both the first ciphertext and the second ciphertext. This increases the ways to obtain the data encryption key, helping to reduce the risk of the data encryption key being unobtainable. Provided that at least one of the recovery key or user password (and / or hardware key) is not lost, it can be guaranteed that after the electronic device is powered on or unlocked, the ciphertext of the data encryption key can be successfully decrypted to obtain the data encryption key, thus improving the reliability of the key management method.

[0387] Example 2: A scenario where, after the hardware components of the first electronic device are replaced, data stored in non-volatile memory is retrieved using a recovery key. In this embodiment, Figure 1 The second electronic device 300 is obtained by replacing some electronic components of the first electronic device 100.

[0388] like Figure 16 As shown, the second electronic device is equipped with non-volatile memory. The user provides a recovery key to the second electronic device; the second electronic device can successfully decrypt the data encryption key based on the recovery key, so as to decrypt the ciphertext of the content data stored in the non-volatile memory. Subsequently, the second electronic device provides the content data for the user's use.

[0389] Example 3: Scenario of retrieving data stored in an external non-volatile memory using a recovery key. In this embodiment, the data is retrieved by... Figure 1 The second electronic device 300 performs the operation. In this embodiment, the second electronic device and the first electronic device are different electronic devices.

[0390] like Figure 17 As shown, the second electronic device is connected to a non-volatile memory removed from the first electronic device. The user provides a recovery key to the second electronic device; the second electronic device can then successfully decrypt the data encryption key using the recovery key, thereby decrypting the ciphertext of the content data stored in the non-volatile memory. Subsequently, the second electronic device provides the content data for the user's use.

[0391] Examples 2 and 3 demonstrate that in the key management method provided by this solution, the first ciphertext of the data encryption key relies on the recovery key for decryption, rather than the hardware key of the electronic device. Therefore, even if the hardware of the electronic device is replaced, or only the non-volatile memory remains intact, the first ciphertext can still be read from the non-volatile memory, and the data encryption key can be obtained using the user-provided recovery key and the first ciphertext. This approach enhances the adaptability of the key management method to different scenarios, making it more universally applicable.

[0392] In some embodiments, the recovery key is also used to trigger a change in the user password. In some embodiments, if the recovery key meets the verification conditions, a third interface is displayed, which is used to receive an operation to reset the user password; in response to the third user password entered by the user on the third interface, the first user password is replaced by the third user password, which is used to encrypt the data encryption key and output the second ciphertext, and / or, the second ciphertext is decrypted and the data encryption key is output, and the second ciphertext is stored in the encrypted area of ​​a non-volatile memory.

[0393] The verification condition is used to verify whether the recovery key provided by the user is correct. The verification condition is at least one of the following: the recovery key correctly decrypts the first ciphertext, and the first and second credentials are identical. For a description of the verification conditions, please refer to the example below.

[0394] Optionally, the third interface is used to reset the user password. The third user password is set by the user and is used to replace the first user password.

[0395] In some embodiments, the key management method further includes the following steps: the entity executing the following steps is... Figure 1 The second electronic device 300 is shown. In this example, the second electronic device and the first electronic device are the same electronic device. Optionally, the functional modules of the second electronic device 300 include a recovery key management module and a password management module. Please refer to [reference needed]. Figure 18 , Figure 18 This is the third flowchart illustrating the key management method provided in the embodiments of this application.

[0396] In step S1810, the second electronic device receives the recovery key in response to the user's operation.

[0397] For a detailed description of step S1810, please refer to the description of step S1210 above; it will not be repeated here.

[0398] In step S1820, if the recovery key correctly decrypts the first ciphertext, the second electronic device responds to the operation of resetting the user password and obtains the updated user password.

[0399] Optionally, if the recovery key decrypts the first ciphertext to obtain the data encryption key, it indicates that the recovery key entered by the user is correct, thus proving that the user is the user of the second electronic device. In this case, the second electronic device supports resetting the user password. If the recovery key cannot decrypt the first ciphertext to obtain the data encryption key, the second electronic device does not reset the user password.

[0400] In step S1830, the second electronic device replaces the first user password with the third user password.

[0401] After the replacement is completed, the user can unlock the second electronic device using a third user password.

[0402] In this example, the second electronic device and the first electronic device are the same electronic device. Optionally, the second electronic device 300 includes a password management module in its functional modules. Please refer to [reference needed]. Figure 19 , Figure 19 This is the fourth flowchart illustrating the key management method provided in the embodiments of this application.

[0403] In step S1910, the second electronic device receives the recovery key in response to the user's operation.

[0404] For a detailed description of step S1910, please refer to the description of step S1210 above, which will not be repeated here.

[0405] In step S1920, the second electronic device generates the first credential based on the recovery key.

[0406] The second credential is used to verify the correctness of the recovery key provided by the user.

[0407] Step S1930: If the first credential and the second credential stored in the non-volatile memory meet the verification conditions, the third interface is displayed.

[0408] Optionally, the verification condition is that the second credential and the first credential are identical. For example, if the second credential is the same as the first credential, the second electronic device obtains the second user password in response to the password reset operation; if the second credential is different from the first credential, the second electronic device displays a key error message. The key error message is used to remind the user that the provided recovery key is incorrect.

[0409] The first user password and the second user password are lock screen passwords used to switch the first electronic device from a locked state to an unlocked state. Optionally, the first user password and the second user password are used to encrypt and / or decrypt a second ciphertext of the data encryption key. The second ciphertext is stored in the boot area of ​​non-volatile memory.

[0410] In step S1940, the second electronic device responds to the third user password entered by the user on the third interface and replaces the first user password with the third user password.

[0411] After the replacement is completed, the user can unlock the second electronic device using a third user password.

[0412] This embodiment provides a new way to update user passwords. By resetting user passwords using a recovery key, the security of resetting user passwords can be improved.

[0413] Figure 20 This is a schematic diagram illustrating a scenario where a user password is reset based on a recovery key. For example... Figure 20 As shown, if a user forgets their first user password, a recovery key can be provided to a second electronic device to trigger the process of resetting the user password.

[0414] This embodiment triggers the user password reset process through the recovery key. Since the recovery key is known to the user using the second electronic device, resetting the recovery key through the recovery key helps to improve the security of resetting the user password.

[0415] The following describes the interaction process between functional modules within the second electronic device during the execution of the key management method. This embodiment is provided by... Figure 5A The file encryption module, recovery key management module, and password management module work together as shown. Figure 21 As shown, this embodiment includes at least the following steps:

[0416] In step S2110, the recovery key management module responds to the user's operation and obtains the recovery key.

[0417] Step S2120: The recovery key management module sends the recovery key to the password management module.

[0418] In step S2130, the password management module obtains the first credential based on the recovery key.

[0419] Optionally, the password management module uses a second encryption algorithm to encrypt the recovery key to obtain the first credential.

[0420] In step S2140, the password management module verifies whether the first credential and the second credential stored in the non-volatile memory are consistent.

[0421] Optionally, the first credential is stored in non-volatile memory, and the password management module reads the first credential from the non-volatile memory. The password management module compares whether the second credential and the first credential are the same.

[0422] For example, if the second credential is the same as the first credential, the password management module determines that the verification was successful. That is, the user-entered recovery key is correct, the password management module notifies the recovery key management module that the recovery key verification was successful, and the recovery key management module executes step S2150.

[0423] For example, if the second credential is different from the first credential, the password management module determines that the verification has failed, that is, the recovery key entered by the user is incorrect. The password management module notifies the recovery key management module that the recovery key verification has failed, and the process ends.

[0424] In step S2150, the recovery key management module, in response to the user password reset operation, obtains a third user password. The third user password is the user password that the user has reset.

[0425] Optionally, resetting the user password can be achieved by entering a third user password on a third interface.

[0426] Step S2160: The recovery key management module sends a third user password to the password management module.

[0427] In step S2170, the password management module replaces the first user password with a third user password. Optionally, after successful replacement, the password management module notifies the recovery key management module that the third user password registration was successful, so that the recovery key management module can confirm that the replacement of the first user password with the third user password is complete.

[0428] In step S2180, the recovery key management module sends a third user password to the file encryption module.

[0429] In step S2190, the file encryption module obtains the updated second ciphertext by encrypting the data using the encryption key based on the third user's password.

[0430] Optionally, after obtaining the second ciphertext, the file encryption module notifies the recovery key management module that the second ciphertext has been successfully generated. Subsequently, the file encryption module stores the second ciphertext in the encrypted area of ​​the non-volatile memory.

[0431] After the user password is reset, the user can unlock the second electronic device using a third user password.

[0432] This embodiment supports enabling users to reset their passwords using a recovery key after forgetting them. This helps to mitigate the inconvenience caused by users being unable to unlock their electronic devices due to forgotten passwords.

[0433] The above combination Figures 6 to 21 The key management method provided in the embodiments of this application is described in detail below. Figure 22 This invention provides a detailed description of the electronic device involved in this embodiment. All or part of any feature of any embodiment in this application can be freely combined. The resulting combined technical solutions also fall within the scope of this application.

[0434] In one possible design, Figure 22 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Optionally, electronic device 2200 represents... Figure 1 At least one of the first electronic device 100 and the second electronic device 300. For example... Figure 22 As shown, the electronic device 2200 may include a transceiver unit 2201 and a processing unit 2202. The electronic device 2200 can be used to implement the functions of the electronic device involved in the above method embodiments.

[0435] Optionally, the transceiver unit 2201 is used to support the second electronic device in performing... Figure 9 S922, S930, S940, and S970; and / or, for supporting the first electronic device to perform Figure 14 S1410 in the example, and / or, for supporting the first electronic device to perform Figure 15 S1510, S1530, and S1550, and / or, are used to support the first electronic device in performing... Figure 19 S1470 in the middle.

[0436] Optionally, the processing unit 2202 is configured to support the second electronic device in performing [operations]. Figure 9 S910, S950, S960; and / or, for supporting the first electronic device to perform Figure 14 S1420 and S1430, and / or, are used to support the first electronic device in performing... Figure 15 S1532-S1540 and S1550-S1554; and / or, for supporting the first electronic device to perform Figure 16S1440-S1460, and / or, are used to support the first electronic device in performing... Figure 17 S1710-S1740, and / or, are used to support the first electronic device in performing... Figure 18 S1810-S1870, and / or, are used to support the first electronic device in performing... Figure 19 S1480-S1490, and / or, are used to support the first electronic device in performing... Figure 22 S1495- and S1496 in the example.

[0437] The transceiver unit may include a receiving unit and a transmitting unit, and may be implemented by a transceiver or transceiver-related circuit components, and may be a transceiver or transceiver module. The operation and / or function of each unit in the electronic device 2200 are respectively to implement the corresponding process of the key management method described in the above method embodiments. All relevant content of each step involved in the above method embodiments can be referred to the functional description of the corresponding functional unit, and for the sake of brevity, it will not be repeated here.

[0438] Optionally, Figure 22 The illustrated electronic device 2200 may also include a storage unit ( Figure 22 (not shown in the image), this storage unit stores a program or instruction. When the transceiver unit 2201 and the processing unit 2202 execute the program or instruction, it causes... Figure 22 The electronic device 2200 shown can execute the key management method described in the above method embodiments.

[0439] Figure 22 The technical effects of the electronic device 2200 shown can be referred to the technical effects of the key management method described in the above method embodiments, and will not be repeated here.

[0440] In addition to being in the form of electronic device 2200, the technical solution provided in this application can also be a functional unit or chip in an electronic device, or a device used in conjunction with an electronic device.

[0441] Figure 22 The technical effects of the first electronic device 2200 shown can be referred to the technical effects of the key management method described in the above method embodiments, and will not be repeated here.

[0442] In addition to being in the form of the first electronic device 2200, the technical solutions provided in this application may also be functional units or chips in the first electronic device, or devices used in conjunction with the first electronic device.

[0443] This application also provides a chip system, including: a processor coupled to a memory, the memory being used to store programs or instructions, wherein when the program or instructions are executed by the processor, the chip system implements the methods in any of the above method embodiments.

[0444] This application also provides a chip system, including: a processor coupled to a memory, the memory being used to store programs or instructions, wherein when the program or instructions are executed by the processor, the chip system implements the methods in any of the above method embodiments.

[0445] Optionally, the chip system may contain one or more processors. These processors can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor, implemented by reading software code stored in memory.

[0446] Optionally, the chip system may contain one or more memories. The memory may be integrated with the processor or disposed separately from it; this application embodiment does not limit this. For example, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed separately on different chips. This application embodiment does not specifically limit the type of memory or the arrangement of the memory and processor.

[0447] For example, the chip system may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD), or other integrated chips.

[0448] It should be understood that each step in the above method embodiments can be completed by integrated logic circuits in the processor hardware or by instructions in software form. The method steps disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or being executed by a combination of hardware and software modules in the processor.

[0449] This application also provides a computer-readable storage medium storing a computer program. When the computer program is run on a computer, it causes the computer to perform the aforementioned steps to implement the key management method in the above embodiments.

[0450] This application also provides a computer program product that, when run on a computer, causes the computer to perform the aforementioned steps to implement the key management method described in the above embodiments.

[0451] In addition, this application also provides an apparatus. This apparatus may specifically be a component or module, and may include one or more processors and a memory connected together. The memory is used to store a computer program. When the computer program is executed by one or more processors, the apparatus performs the key management method described in the above method embodiments.

[0452] In this application, the computer-readable storage medium, computer program product, or chip provided in the embodiments are all used to execute the corresponding methods described above. Therefore, the beneficial effects they can achieve can be referred to in the beneficial effects of the corresponding methods described above, and will not be repeated here.

[0453] The steps of the methods or algorithms described in conjunction with the embodiments of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, optical discs, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can reside in an application-specific integrated circuit (ASIC).

[0454] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, the division of the above functional modules is only used as an example. In practical applications, the above functions can be assigned to different functional modules as needed; that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0455] In the several embodiments provided in this application, it should be understood that the disclosed methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of modules or units is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of modules or units may be electrical, mechanical or other forms.

[0456] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units. Computer-readable storage media include, but are not limited to, any of the following: USB flash drive, portable hard drive, read-only memory, random access memory, magnetic disk, or optical disk, and other media capable of storing program code.

[0457] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A key management method characterized by comprising: The method is performed by a first electronic device, and the method comprises: In response to a key generation operation, a recovery key is generated, and the recovery key is displayed; A data encryption key is encrypted using the recovery key to obtain first ciphertext of the data encryption key, the data encryption key being used to encrypt target content data in a non-volatile memory and / or to decrypt; The first ciphertext is stored in a non-encrypted storage area of the non-volatile memory.

2. The method of claim 1, wherein, After the recovery key is generated in response to the key generation operation, the method further comprises: In response to an account login operation, account information is sent to a server; In response to a key binding operation, a key binding request is sent to the server, the key binding request carrying key data, the key data being the encrypted recovery key, and the key binding request being used to request binding of the account information and the recovery key.

3. The method of claim 2, wherein, Before the key binding request is sent to the server in response to the key binding operation, the method further comprises: An end-to-cloud key is obtained, the end-to-cloud key being used to encrypt communication data between the first electronic device and the server; The recovery key is encrypted according to a public key in the end-to-cloud key to obtain the key data.

4. The method of claim 2, wherein, The recovery key comprises a first sub-key and a second sub-key; The recovery key is displayed in response to the key generation operation, and the first sub-key is displayed. The key data is the encrypted second sub-key, and the key binding request is used to request binding of the account information and the second sub-key.

5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: A first credential is obtained according to the recovery key, the first credential being used to identify the recovery key; The first credential is stored in the non-volatile memory.

6. The method according to claim 1 or 5, characterized in that, After the first ciphertext is stored in the non-encrypted storage area of the non-volatile memory, the method further comprises: In response to a user operation, the recovery key is received; The first ciphertext is read from the non-encrypted storage area in the non-volatile memory; The data encryption key is obtained by decrypting the first ciphertext using the recovery key.

7. The method according to any one of claims 1 to 6, characterized in that, Second ciphertext of the data encryption key is stored in a startup area of the non-volatile memory, the second ciphertext being obtained by encrypting the data encryption key using a preset first user password; After the first ciphertext is stored in the non-encrypted storage area of the non-volatile memory, the method further comprises: In response to an operation of inputting a user password, a second user password provided by a user is received; The second ciphertext is read from the startup area in the non-volatile memory; In a case where the second user password cannot decrypt the second ciphertext, a second interface is displayed, the second interface being used to receive the recovery key.

8. The method according to any one of claims 1 to 7, characterized in that, The method further comprises: In a case where the recovery key satisfies a verification condition, a third interface is displayed, the third interface being used to receive an operation of resetting a user password; In response to a third user password input by the user at the third interface, the first user password is replaced by the third user password, the first user password is used to encrypt the data encryption key to output second ciphertext, and / or the second ciphertext stored in the encrypted area of the non-volatile memory is decrypted to output the data encryption key.

9. The method of claim 8, wherein, The third interface is displayed in a case where the recovery key meets a verification condition. A first credential is obtained according to the recovery key, and the first credential is used to determine the correctness of the recovery key provided by the user. The third interface is displayed in a case where the first credential is the same as a second credential stored in the non-volatile memory.

10. The method according to any one of claims 6 to 9, characterized in that, The user operation is obtained from a lock screen interface, and the lock screen interface is a display interface of the first electronic device in a case where the first electronic device is powered on, wakes up, or requests to open a first application; or the user operation is obtained from a password reset interface.

11. The method according to any one of claims 1 to 10, characterized in that, A data bit number of the recovery key is greater than or equal to a data bit number of the data encryption key.

12. A key management method characterized by comprising: The method is performed by a second electronic device, and the method comprises: In response to a user operation, a recovery key is received; First ciphertext of a data encryption key is obtained from a non-encrypted storage area in a non-volatile memory; The first ciphertext is decrypted using the recovery key to obtain the data encryption key, and the data encryption key is used to encrypt and / or decrypt target content data in the non-volatile memory.

13. The method of claim 12, wherein, The recovery key is received in response to a user operation, comprising: In response to an operation of inputting the recovery key, the recovery key input by the user is received.

14. The method of claim 12, wherein, The recovery key is received in response to a user operation, comprising: In response to an operation of searching for the recovery key, a key acquisition request is sent to a server, and the key acquisition request is used to acquire key data bound to account information; Key data sent by the server is received; The recovery key is obtained according to the key data.

15. The method of claim 14, wherein, The recovery key comprises a first sub-key and a second sub-key, the recovery key is received in response to a user operation, comprising receiving the first sub-key in response to the user operation; and the key data is the encrypted second sub-key.

16. The method according to claim 14 or 15, characterized in that The recovery key is obtained according to the key data, comprising: The key data is decrypted according to a private key in an end-cloud key to obtain the recovery key, and the end-cloud key is used to encrypt communication data between the second electronic device and the server.

17. The method according to any one of claims 14 to 16, characterized in that, Before the key acquisition request is sent to the server in response to the operation of searching for the recovery key, the method further comprises: A first interface is displayed, and the first interface is used to receive the account information input by the user.

18. The method according to any one of claims 12 to 17, characterized in that, The first ciphertext of the data encryption key is obtained from the non-encrypted storage area in the non-volatile memory, comprising: A first file directory corresponding to the non-encrypted storage area is obtained according to a file management system used to manage the non-volatile memory, the file management system is used to divide a storage area in the non-volatile memory, and the first file directory is used to index data stored in the non-encrypted storage area; read the first ciphertext from at least one file stored in the first file directory.

19. The method according to any one of claims 12 to 18, characterized in that, The non-volatile memory stores a second ciphertext of the data encryption key, the second ciphertext being obtained by encrypting the data encryption key with a preset first user password; Before receiving the recovery key in response to the user operation, the method further includes: In response to an operation of inputting a user password, receiving a second user password provided by the user; Obtaining the second ciphertext of the data encryption key from a boot area in the non-volatile memory; In a case where the second user password fails to decrypt the second ciphertext, displaying a second interface, the second interface being configured to receive the recovery key.

20. The method of any one of claims 12-19, wherein: The non-volatile memory is a non-volatile memory installed in the second electronic device, or the non-volatile memory is a non-volatile memory detached from another electronic device and having a data transmission channel with the second electronic device.

21. The method according to any one of claims 12 to 20, characterized in that, After receiving the recovery key in response to the user operation, the method further includes: In a case where the recovery key satisfies a verification condition, displaying a third interface, the third interface being configured to receive an operation of resetting a user password; In response to a third user password input by the user on the third interface, replacing the first user password with the third user password, the first user password being used to encrypt the data encryption key to output the second ciphertext, and / or decrypt the second ciphertext to output the data encryption key, the second ciphertext being stored in an encryption area of the non-volatile memory.

22. The method of claim 21, wherein, The displaying of the third interface in the case where the recovery key satisfies the verification condition includes: According to the recovery key, obtaining a first credential, the first credential being used to determine the correctness of the recovery key provided by the user; In a case where the first credential is identical to a second credential stored in the non-volatile memory, displaying the third interface.

23. The method according to any one of claims 12 to 22, characterized in that, The user operation is obtained from a lock screen interface, the lock screen interface being a display interface of the second electronic device in a case where the second electronic device is powered on, woken up, or requested to open a first application; or the user operation is obtained from a password resetting interface.

24. An electronic device, comprising: The electronic device includes: a display screen configured to display an interface; a transceiver configured to transmit and receive radio signals; a memory configured to store computer program instructions; a processor configured to execute the computer program instructions to support the electronic device to implement the method of any one of claims 1-11, or to support the electronic device to implement the method of any one of claims 12-23.

25. A computer readable storage medium, characterized in that, The computer readable storage medium stores computer programs, when the computer programs are run on a computer, causing the method of any one of claims 1-11, or to support the electronic device to implement the method of any one of claims 12-23.

26. A computer program product comprising instructions, wherein: When the computer program product is run on a computer, it causes the computer to perform the method of any one of claims 1 to 11, or to support the electronic device to implement the method of any one of claims 12 to 23.