Equipment disconnection overtime locking control method and system and electronic equipment

By storing device offline data in a trusted execution environment and utilizing unique hardware identifiers and message authentication codes, the problem of devices escaping supervision after being maliciously flashed is solved, enabling hardware-level locking and automatic recovery, thus ensuring device security and compliance.

CN121864474APending Publication Date: 2026-04-14SHANGHAI SUMI TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANGHAI SUMI TECH CO LTD
Filing Date
2026-02-13
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In existing technologies, devices are easily maliciously flashed after the network connection is lost, causing them to fall outside the original manufacturer's regulatory system and become unable to receive vulnerability patches and security updates, thus harming the interests of channel customers and end users.

Method used

The secure program runs in a trusted execution environment, storing critical status data such as the cumulative time the device has been offline in a secure storage partition with anti-replay attack features. It also uses a unique hardware identifier and message authentication code to achieve a strong binding between the data and the physical chip, triggering a hardware-level locking mechanism.

Benefits of technology

When a device remains offline for more than a set threshold, it can be locked at the hardware level to prevent malicious flashing and tampering, provide an automatic recovery mechanism, reduce the complexity of operation and maintenance, and ensure the security and compliance of the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864474A_ABST
    Figure CN121864474A_ABST
Patent Text Reader

Abstract

The invention discloses a device disconnection overtime locking control method and system and electronic device.The method comprises the steps that after a device is started, an encrypted channel between a client application and a trusted application is established through the client application, and locking basic configuration and state data are read from a secure storage partition; wherein the client application runs in a common execution environment of the system, and the trusted application runs in a trusted execution environment of the system; the client application detects the network connection condition of the equipment in real time to obtain accumulated network disconnection time, and triggers the trusted application every a first time threshold value, so that the accumulated network disconnection time is encrypted and written into the secure storage partition through the trusted application; and when the accumulated network disconnection time exceeds a preset second time threshold value, the trusted application sets a machine locking position state of the equipment in the secure storage partition, and triggers the equipment to lock the machine.
Need to check novelty before this filing date? Find Prior Art