Data protection method and apparatus, and electronic device

By setting dynamically adjustable encryption methods and data types in electronic devices, the problem of differentiated encryption in existing technologies is solved, enabling the protection of data security while ensuring normal business operation and improving user experience.

WO2025251999A1PCT designated stage Publication Date: 2025-12-11HUAWEI TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/098050
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-07
Filing Date
2025-05-29
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

In existing technologies, electronic devices cannot perform differentiated encryption based on specific files or business scenarios, which affects the normal operation of business while protecting data security.

Method used

By setting different encryption methods and data types on electronic devices, the encryption method of data can be dynamically adjusted to adapt to different business processing scenarios. For example, the existence and release of encryption keys can be adjusted in the locked and unlocked states to ensure data security and normal business operation.

Benefits of technology

It enables normal processing in different business scenarios while ensuring data security, thereby improving user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025098050_11122025_PF_FP_ABST
    Figure CN2025098050_11122025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a data protection method and apparatus, and an electronic device. The method comprises: in response to a first trigger event, modifying an encryption mode of first data, the encryption mode including a first encryption mode and a second encryption mode, an encryption key in the first encryption mode being still present even after an electronic device is screen-locked, and an encryption key in the second encryption mode being released after the electronic device is screen-locked. The data protection method and apparatus and the electronic device provided by the present application ensure normal operation of rational services while protecting data security.
Need to check novelty before this filing date? Find Prior Art

Description

Method, device and electronic device for data protection

[0001] The present application claims priority to the Chinese patent application No. 202410740883.3, filed on June 7, 2024, and entitled "Method, device and electronic device for data protection", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the technical field of electronic devices, and more particularly, to a method, device and electronic device for data protection. BACKGROUND

[0003] With the development of science and technology, people's production and life are increasingly dependent on electronic devices. The data carried on the electronic devices, such as files, resources, account information or passwords, etc., mostly involve the privacy of users. Therefore, while providing various services for users, the electronic devices also need to consider the protection of files involving user privacy.

[0004] Currently, the electronic devices usually set the same encryption mode for the files under the same directory in units of the directory of the application program. This makes it impossible to protect the files according to specific files or actual business scenarios, which may affect the normal operation of the business.

[0005] Therefore, how to protect the data security while ensuring the normal operation of the reasonable business is a problem to be solved at present. SUMMARY

[0006] The present application provides a method, device and electronic device for data protection. The method ensures the normal operation of the business while protecting the data security.

[0007] In a first aspect, a method for data protection is provided. The method is applied to an electronic device, and the method comprises: in response to a first trigger event, modifying an encryption mode of first data, the encryption mode comprising a first encryption mode and a second encryption mode, an encryption key in the first encryption mode persisting after the electronic device is locked, and an encryption key in the second encryption mode being released after the electronic device is locked.

[0008] It should be noted that the first data is the data carried on the electronic device, such as files, resources, account information or passwords, etc. The first data can be related to the business performed by the electronic device. In the method, device and electronic device for data protection provided by the present application, the specific form of the data includes but is not limited to files, resources, account information or passwords, etc., which are not limited by the embodiments of the present application.

[0009] Optionally, the modifying the encryption manner of the first data comprises modifying the first encryption manner to the second encryption manner, or modifying the second encryption manner to the first encryption manner.

[0010] It can be understood that the encryption key in the first encryption manner persists after the electronic device is locked, and the data encrypted by the first encryption manner can be continuously accessed after the electronic device is locked; the encryption key in the second encryption manner is released after the electronic device is locked, and the data encrypted by the second encryption manner cannot be continuously accessed after the electronic device is locked. It can be seen that the data encrypted by the second encryption manner has higher security.

[0011] Based on the above scheme, the encryption manner of the data can be dynamically adjusted under different trigger events to adapt to different business processing scenarios of the electronic device, so that the electronic device can ensure data security while ensuring normal processing of the data by the business, and improve user experience.

[0012] In combination with the first aspect, in some implementations of the first aspect, the electronic device comprises second data different from the encryption manner of the first data, and the second data and the first data belong to the same directory.

[0013] For example, the first data and the second data can be file data, and when the first data is a first file and the second data is a second file, the first data and the second data can belong to the same folder. The folder belongs to an application of the electronic device.

[0014] Based on the above scheme, the electronic device can set different encryption manners based on different data, and data belonging to the same directory can also have different encryption manners. That is, the electronic device can set an independent encryption manner for each data, and set different protection measures for data not to be provided.

[0015] In combination with the first aspect, in some implementations of the first aspect, in response to the first trigger event, the modifying the encryption manner of the first data comprises: in response to the first trigger event, modifying a data type of the first data, the data type comprising a first type encrypted by the first encryption manner and a second type encrypted by the second encryption manner.

[0016] Optionally, the modifying the data type of the first data comprises modifying the first type to the second type, or modifying the second type to the first type.

[0017] For example, taking the first data as a first file, in response to the first trigger event, the file type of the first file is modified. For example, the file type of the first file is modified to the first type, or the file type of the first file is modified to the second type.

[0018] Based on the above scheme, the electronic device can dynamically adjust the encryption mode of the data by modifying the data type of the data to adapt to the current business processing scenario of the electronic device.

[0019] In some implementations of the first aspect, in response to the first trigger event, the data type of the first data is modified, including: in response to no access to the first data within a first preset time length, modifying the data type of the first data to the second type.

[0020] It should be noted that, if the original data type of the first data is the first type, in response to the electronic device not accessing the first data within the first preset time length, the data type of the first data is modified from the first type to the second type; if the original data type of the first data is the second type, in response to the electronic device not accessing the first data within the first preset time length, the data type of the first data is maintained as the first data.

[0021] For example, the first preset time length can be determined by system preset, user setting or artificial intelligence learning, which is not limited in the present application.

[0022] For example, the electronic device does not process the business corresponding to the first data within the first preset time length (for example, 2 hours), indicating that the electronic device temporarily has no demand to access the first data, or the electronic device has completed the business corresponding to the first data, and then the data type of the first data can be modified to the second type to improve the protection degree of the first data.

[0023] Optionally, in response to the unlocking operation and no access to the first data within the first preset time length, the data type of the first data is modified to the second type.

[0024] It can be understood that the modification of the data type can be triggered when the electronic device is unlocked.

[0025] In some implementations of the first aspect, in response to the first trigger event, the data type of the first data is modified, including: in response to the lock screen operation and the electronic device executing the business corresponding to the first data, the data type of the first data is modified to the first type.

[0026] It should be noted that, if the original data type of the first data is the second type, in response to the lock screen operation and the electronic device executing the business corresponding to the first data, the data type of the first data is modified to the first type; if the original data type of the first data is the first type, in response to the lock screen operation and the electronic device executing the business corresponding to the first data, the data type of the first data is maintained as the first type.

[0027] For example, when the electronic device is in a locked state, the electronic device still needs to process a service corresponding to the first data, which means that the electronic device needs to access the first data even when the electronic device is in a locked state. In this case, the data type of the first data can be modified to the first type to ensure smooth execution of the service corresponding to the first data.

[0028] For example, the service corresponding to the first data includes data uploading, data synchronization, data updating, and the like related to interaction between the electronic device and the cloud; the service also includes data editing, data saving, and data local caching, and the like processed by the electronic device; and the service also includes screen projection, audio / video playing, and calling, and the like performed in the background of the electronic device.

[0029] With reference to the first aspect, in some implementations of the first aspect, the modifying, in response to the first trigger event, the data type of the first data comprises: in response to the first trigger event and the encryption key of the first data existing, modifying the data type of the first data.

[0030] That is, the electronic device can modify the data type of the first data on the premise that the first trigger event occurs and the encryption key of the first data exists.

[0031] For example, in response to the electronic device not accessing the first data within a first preset time length and the encryption key of the first data existing, the data type of the first data is modified to the second type. In response to a lock screen operation, the electronic device executing the service corresponding to the first data, and the encryption key of the first data existing, the data type of the first data is modified to the first type.

[0032] For example, if the original data type of the first data is the first type, the original encryption mode of the first data is the first encryption mode, and the encryption key of the first data is the encryption key in the first encryption mode. In response to the electronic device not accessing the first data within a first preset time length and the encryption key in the first encryption mode existing, the data type of the first data is modified to the second type.

[0033] With reference to the first aspect, in some implementations of the first aspect, the modifying, in response to the first trigger event, the encryption mode of the first data comprises: in response to a lock screen operation and the electronic device executing the service corresponding to the first data, releasing the encryption key of the first data after the service corresponding to the first data is completed.

[0034] It should be noted that the electronic device can modify the timing of releasing the encryption key of the first data. When the electronic device needs to execute the service corresponding to the first data after the electronic device is locked, the timing of releasing the encryption key of the first data can be extended to after the electronic device completes the service corresponding to the first data.

[0035] It can be understood that when the electronic device is locked and a second preset time period after the first data corresponding service is completed, the encryption key of the first data can be released.

[0036] Based on the above scheme, in some data corresponding service scenarios, the encryption mode can be adjusted without changing the data type, which avoids a large amount of overhead while taking into account the security of the data and the normal operation of the data corresponding service.

[0037] In combination with the first aspect, in some implementations of the first aspect, the first data includes a batch file.

[0038] In combination with the first aspect, in some implementations of the first aspect, the first data corresponding service includes data transmission.

[0039] For example, the data transmission includes data updating, data synchronization, etc.

[0040] In combination with the first aspect, in some implementations of the first aspect, the encryption mode of the first data is the second encryption mode.

[0041] For example, the first data corresponding service is a mobile phone cloning service. In response to the lock screen operation and the electronic device performing the mobile phone cloning service, the encryption key of the first data can be released 2 hours after the electronic device completes the mobile phone cloning service.

[0042] In combination with the first aspect, in some implementations of the first aspect, the first data includes first information, the first information is used to indicate the data type of the first data, the data type includes a first type encrypted by the first encryption mode and a second type encrypted by the second encryption mode.

[0043] For example, the first information can indicate the data type in the form of a field, a bit, etc. For example, '00' represents the first type and '01' represents the second type.

[0044] It can be understood that the data type is related to the encryption mode, and the electronic device can determine the encryption mode according to the data type. When the data type of the first data is the first type, the first encryption mode can be used to encrypt the first data; when the data type of the first data is the second type, the second encryption mode can be used to encrypt the second data.

[0045] In combination with the first aspect, in some implementations of the first aspect, the encryption key in the second encryption mode is related to the identity of an application, and the application includes the first data.

[0046] In a second aspect, a device for data protection is provided, the device comprising: a processing unit configured to modify an encryption manner of first data in response to a first trigger event, the encryption manner comprising a first encryption manner and a second encryption manner, an encryption key in the first encryption manner persisting after the device is locked, and an encryption key in the second encryption manner being released after the device is locked.

[0047] With reference to the second aspect, in some implementations of the second aspect, the device comprises second data different from the encryption manner of the first data, the second data belonging to a same directory as the first data.

[0048] With reference to the second aspect, in some implementations of the second aspect, the processing unit is specifically configured to modify a data type of the first data in response to the first trigger event, the data type comprising a first type encrypted by the first encryption manner and a second type encrypted by the second encryption manner.

[0049] With reference to the second aspect, in some implementations of the second aspect, the processing unit is specifically configured to modify the data type of the first data to the second type in response to no access to the first data within a first preset time length.

[0050] With reference to the second aspect, in some implementations of the second aspect, the processing unit is specifically configured to modify the data type of the first data to the first type in response to a lock screen operation and the device executing a service corresponding to the first data.

[0051] With reference to the second aspect, in some implementations of the second aspect, the processing unit is specifically configured to modify the data type of the first data in response to the first trigger event and the encryption key of the first data existing.

[0052] With reference to the second aspect, in some implementations of the second aspect, the processing unit is specifically configured to release the encryption key of the first data after completion of the service corresponding to the first data in response to a lock screen operation and the device executing the service corresponding to the first data.

[0053] With reference to the second aspect, in some implementations of the second aspect, the first data comprises a batch file.

[0054] With reference to the second aspect, in some implementations of the second aspect, the service corresponding to the first data comprises data transmission.

[0055] With reference to the second aspect, in some implementations of the second aspect, the encryption manner of the first data is the second encryption manner.

[0056] In some embodiments of the second aspect, the first data comprises first information, the first information being used to indicate a data type of the first data, the data type comprising a first type encrypted by the first encryption manner and a second type encrypted by the second encryption manner.

[0057] In some embodiments of the second aspect, the encryption key in the second encryption manner is related to an identification of an application, the application comprising the first data.

[0058] In a third aspect, an electronic device is provided, comprising: one or more processors; one or more memories; the one or more memories storing one or more computer programs comprising instructions which, when executed by the one or more processors, cause the electronic device to perform the method in the first aspect and any possible implementation thereof.

[0059] In a fourth aspect, an apparatus for data protection is provided, comprising: a processor coupled with a memory, the memory being configured to store a computer program, the processor being configured to execute the computer program, so that the apparatus for data protection performs the method in the first aspect and any possible implementation thereof.

[0060] In some embodiments of the fourth aspect, further comprising one or more of the memory and a transceiver, the transceiver being configured to receive a signal and / or transmit a signal.

[0061] In a fifth aspect, a computer readable storage medium is provided, having stored thereon a computer program which, when executed by a computer, causes the computer to implement the method in the first aspect and any possible implementation thereof.

[0062] In a sixth aspect, a computer program product is provided, comprising instructions which, when executed on a computer, cause the computer to perform the method in the first aspect and any possible implementation thereof.

[0063] In a seventh aspect, a chip is provided, comprising a processor and a data interface, the processor reading instructions stored on a memory through the data interface to perform the method in the first aspect and any possible implementation thereof.

[0064] In some embodiments of the seventh aspect, the processor is coupled with the memory through the interface.

[0065] In some embodiments of the seventh aspect, the chip system further comprises the memory, the memory storing the computer program or the computer instructions. BRIEF DESCRIPTION OF DRAWINGS

[0066] FIG. 1 is a structural schematic diagram of an electronic device.

[0067] FIG. 2 is a software structure block diagram of an electronic device according to an embodiment of the present application.

[0068] FIG. 3 is a file structure schematic diagram according to an embodiment of the present application.

[0069] FIG. 4 is a file type switching schematic diagram according to an embodiment of the present application.

[0070] FIG. 5 is a method schematic flow diagram of dynamically adjusting encryption mode according to an embodiment of the present application.

[0071] FIG. 6 is a method schematic flow diagram of data protection according to an embodiment of the present application. DETAILED DESCRIPTION

[0072] The technical solutions in the present application will be described below in conjunction with the accompanying drawings.

[0073] The terms used in the following embodiments are only for the purpose of describing specific embodiments and are not intended to be limiting of the present application. As used in the specification and the appended claims, the singular forms "a," "an" and "the" are intended to include both singular and plural forms, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. The term "and / or" used in the context of the present application refers to three relationships: A and / or B, A or B, and A and B. For example, A and / or B can mean A alone, A and B together, B alone, and the like, where A and B can be singular or plural.

[0074] Reference in the specification to "one embodiment" or "some embodiments" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrase "in one embodiment" or "in some embodiments" in various places in the specification are not necessarily all referring to the same embodiment, although it can. The terms "including," "comprising," "having," and variations thereof are meant to encompass the items listed thereafter and equivalents thereof as well as additional items. The terms "coupled" and "connected," and variations thereof, are intended to encompass a connection between two or more elements, which is sufficient to permit a flow of current between the elements. Such a connection can be direct or indirect, and it can include wired or wireless connections.

[0075] The following introduces electronic devices, user interfaces for such electronic devices, and embodiments for using such electronic devices. In some embodiments, an electronic device can be a portable electronic device that also contains other functions such as personal digital assistant and / or music player functions, such as a mobile phone, a tablet computer, a wearable electronic device with wireless communication capabilities (e.g., a smart watch), etc. Exemplary embodiments of portable electronic devices include, but are not limited to, portable electronic devices that run the Android® operating system, the iOS® operating system, the Windows® operating system, or other operating systems. The portable electronic devices described above can also be other portable electronic devices, such as a laptop computer, etc. It should also be understood that in other embodiments, the electronic devices described above can not be portable electronic devices, but can be desktop computers. In other embodiments, the electronic devices can be instruments for measurement, such as an oscilloscope.

[0076] For example, FIG. 1 shows a structural diagram of an electronic device 100. The electronic device 100 can include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headset jack 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 can include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0077] It can be understood that the structure illustrated by the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 can include more or fewer components than illustrated, or combine certain components, or split certain components, or different arrangement of components. The illustrated components can be implemented in hardware, software, or a combination of software and hardware.

[0078] ​The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices or integrated in one or more processors.

[0079] The controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of fetching and executing instructions.

[0080] The processor 110 can also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can save instructions or data that the processor 110 has just used or repeatedly uses. If the processor 110 needs to use the instructions or data again, it can directly call from the memory. This avoids repeated access and reduces the waiting time of the processor 110, thereby improving the efficiency of the system.

[0081] In some embodiments, the processor 110 can include one or more interfaces. The interfaces can include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.

[0082] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor, and the baseband processor, etc.

[0083] The antenna 1 and the antenna 2 are used for transmitting and receiving electromagnetic wave signals.

[0084] The mobile communication module 150 can provide a solution for wireless communication including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc.

[0085] The modem processor can include a modulator and a demodulator. The modulator is used to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate a received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. The low-frequency baseband signal processed by the baseband processor is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the microphone 170B, etc.), or displays an image or a video through the display screen 194.

[0086] The wireless communication module 160 can provide a solution for wireless communication including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) network), bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, etc. applied to the electronic device 100. The wireless communication module 160 can be one or more devices integrated with at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signals, and transmits the processed signals to the processor 110. The wireless communication module 160 can also receive signals to be transmitted from the processor 110, perform frequency modulation and amplification on the signals, and convert the signals into electromagnetic wave radiation via the antenna 2.

[0087] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include a global positioning system (GPS), a global navigation satellite system (GLONASS), a beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS), and / or a satellite based augmentation systems (SBAS).

[0088] The electronic device 100 implements a display function through a GPU, a display screen 194, and an application processor, etc. The GPU is a microprocessor for image processing, which is connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs, which execute program instructions to generate or change display information.

[0089] The display screen 194 is configured to display images, videos, and the like. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diodes (QLED), or the like. In some embodiments, the electronic device 100 can include one or N display screens 194, where N is a positive integer greater than 1.

[0090] The electronic device 100 can implement the photographing function through the ISP, the camera 193, the video codec, the GPU, the display screen 194, and the application processor.

[0091] The ISP is configured to process the data fed back by the camera 193. For example, when taking a photo, the shutter is opened, the light is transmitted to the camera photosensitive element through the lens, the light signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to the ISP for processing to convert it into an image visible to the naked eye. The ISP can also algorithmically optimize the noise and brightness of the image. The ISP can also optimize the exposure, color temperature, and other parameters of the shooting scene. In some embodiments, the ISP can be disposed in the camera 193.

[0092] The camera 193 is configured to capture still images or videos. An object generates an optical image through a lens and projects it onto a photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then transmitted to the ISP to convert it into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into a standard RGB, YUV, or the like format image signal.

[0093] The digital signal processor is configured to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is configured to perform Fourier transform on the frequency point energy, and the like.

[0094] A video codec is used to compress or decompress digital video. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record videos in a variety of encoding formats, such as moving picture experts group (MPEG) 1, MPEG 2, MPEG 3, MPEG 4, and the like.

[0095] An NPU is a neural-network (NN) computing processor that quickly processes input information by drawing on the structure of a biological neural network, such as the transmission mode between human brain neurons, and can also continuously self-learn. Through the NPU, the electronic device 100 can implement intelligent cognitive applications, such as image recognition, face recognition, voice recognition, text understanding, and the like.

[0096] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to implement a data storage function. For example, music, video, and the like are saved in the external memory card.

[0097] The internal memory 121 can be used to store computer executable program code, which includes instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program required for a function (such as a sound playing function, an image playing function, and the like), and the like. The data storage area can store data created during use of the electronic device 100 (such as audio data, a phonebook, and the like), and the like. In addition, the internal memory 121 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, a universal flash storage (UFS), and the like.

[0098] The electronic device 100 can implement audio functions through an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, an application processor, and the like. For example, music playing, recording, and the like.

[0099] The audio module 170 is configured to convert digital audio information into an analog audio signal output, and to convert an analog audio input into a digital audio signal. The audio module 170 can also be configured to encode and decode audio signals. In some embodiments, the audio module 170 can be disposed in the processor 110, or some of the functions of the audio module 170 can be disposed in the processor 110.

[0100] The speaker 170A, also referred to as a "loudspeaker", is configured to convert an audio electrical signal into a sound signal. The electronic device 100 can listen to music or a hands-free call through the speaker 170A.

[0101] The microphone 170B, also referred to as a "receiver", is configured to convert an audio electrical signal into a sound signal. When the electronic device 100 is engaged in a call or a voice message, the microphone 170B can be used to receive a voice by being close to a human ear.

[0102] The microphone 170C is configured to convert a sound signal into an electrical signal.

[0103] The pressure sensor 180A is configured to sense a pressure signal, and can convert the pressure signal into an electrical signal.

[0104] The fingerprint sensor 180H is configured to acquire a fingerprint. The electronic device 100 can use the acquired fingerprint characteristics to implement fingerprint unlocking, access to an application lock, fingerprint photographing, fingerprint call receiving, and the like.

[0105] The touch sensor 180K, also referred to as a "touch panel". The touch sensor 180K is configured to detect a touch operation acting on or near the touch sensor 180K.

[0106] FIG. 2 is a software structure block diagram of the electronic device 100 according to an embodiment of the disclosure. A layered architecture divides software into several layers, each of which has a clear role and division of labor. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom, an application layer, an application framework layer, an Android runtime and a system library, and a kernel layer. The application layer can include a series of application packages.

[0107] As shown in FIG. 2, the application layer can include a camera, a setting, a skin module, a user interface (UI), a third-party application, and the like. Among them, the third-party application can include a gallery, a calendar, a call, a map, a navigation, a WLAN, a Bluetooth, music, a video, a short message, and the like.

[0108] The application framework layer provides an application programming interface (API) and programming framework for applications of the application layer. The application framework layer can include some pre-defined functions.

[0109] As shown in FIG. 2, the application framework layer can include a window manager, a content provider, a view system, a telephony manager, a resource manager, a notification manager, etc.

[0110] The window manager is used to manage window programs. The window manager can acquire a display screen size, determine whether there is a status bar, lock a screen, and intercept a screen, etc. The content provider is used to store and acquire data, and make the data accessible by an application. The data can include videos, images, audios, dialed and received calls, browsing history and bookmarks, a phonebook, etc.

[0111] The view system includes visual controls, such as a control for displaying text, a control for displaying pictures, etc. The view system can be used to build an application. A display interface can be composed of one or more views.

[0112] The telephony manager is used to provide a communication function of the electronic device 100. For example, management of a call state (including call connection, call hang-up, etc.).

[0113] The resource manager provides various resources for an application, such as localized strings, icons, pictures, layout files, video files, etc.

[0114] The notification manager makes an application display notification information in a status bar, which can be used to convey a notification type of message, which can automatically disappear after a short stay without user interaction. For example, the notification manager is used to notify a download completion, a message reminder, etc. The notification manager can also be a notification that appears in a system top status bar in a chart or a scroll bar text form, such as a notification of an application running in the background, and can also be a notification that appears on a screen in a dialog window form. For example, a text information is prompted in a status bar, a prompt sound is emitted, the electronic device is vibrated, an indicator light is blinked, etc.

[0115] The runtime includes a core library and a virtual machine. The Android runtime is responsible for the invocation and management of the Android system.

[0116] The core library includes two parts: one part is a function function that a java language needs to call, and the other part is an Android core library.

[0117] The application program layer and the application framework layer run in a virtual machine. The virtual machine executes the java files of the application program layer and the application framework layer into binary files. The virtual machine is used to perform functions such as management of object life cycle, stack management, thread management, management of security and exceptions, and garbage collection.

[0118] The system library can include a plurality of functional modules. For example, a surface manager, media libraries, a three-dimensional graphics processing library (for example, OpenGL ES), a two-dimensional graphics engine (for example, SGL), and the like.

[0119] The surface manager is used to manage the display subsystem and provides fusion of 2D and 3D layers for a plurality of application programs.

[0120] The media libraries support playback and recording of a plurality of commonly used audio, video formats, and static image files. The media libraries can support a plurality of audio and video encoding formats, for example, MPEG4, H.264, MP3, AAC, AMR, JPG, PNG, and the like.

[0121] The three-dimensional graphics processing library is used to implement three-dimensional graphics drawing, image rendering, synthesis, and layer processing, and the like.

[0122] The two-dimensional graphics engine is a drawing engine for 2D drawing.

[0123] In addition, the system library can also include a state monitoring service module, for example, a physical state identification module used to analyze and identify user gestures, and a sensor service module used to monitor sensor data uploaded by various sensors of the hardware layer to determine the physical state of the electronic device 100.

[0124] The kernel layer is a layer between hardware and software. The kernel layer at least includes a display driver, a camera driver, an audio driver, and a sensor driver.

[0125] The hardware layer can include various sensors, for example, the various sensors introduced in FIG. 1.

[0126] In combination with the electronic device introduced in FIG. 1 and FIG. 2, in the embodiments of the present application, the electronic device, such as a mobile phone terminal, a tablet computer, etc., can be a device running various application programs. The physical devices involved in the electronic device 100 mainly include sensors, decision support systems (DSS) display chips, touch display screens, fingerprint recognition modules, etc. hardware components; and kernel software layers such as screen management modules, display drivers, fingerprint drivers, and anti-mis-touch; application program framework layer functions such as anti-mis-touch input, screen control, always-on display (AOD) service, and power management; and application layer services such as special adaptation applications (camera), three-party applications, system hibernation, AOD, etc.

[0127] With the development of science and technology, people's production and life are more and more inseparable from electronic devices. Various data carried on the electronic device, such as files, resources, account information or passwords, etc., mostly involve the privacy of users, therefore, while the electronic device provides various services for users, it also needs to consider the protection of data involving user privacy.

[0128] In order to protect user privacy, in one implementation, before the first unlocking after the electronic device is powered on, the file and other data exist in the form of encrypted ciphertext, which is difficult to crack; after the first unlocking of the electronic device, the file and other data exist in the form of decrypted plaintext, which is easy to crack. After the first unlocking of the electronic device, even if the electronic device is locked again, the file and other data will be easily cracked, causing user loss.

[0129] In another implementation, the application program carried on the electronic device generally has multiple directories under it, and each directory can store multiple data. In units of directories, an encryption mode is set, and one or more data under each directory will adopt the same encryption mode to realize data protection. Before the electronic device is unlocked for the first time after being powered on, the data exists in the form of encrypted ciphertext, and the difficulty of cracking is great; after the electronic device is unlocked for the first time, the data exists in the form of decrypted plaintext, and the system or the application program can access the plaintext data; after the electronic device is locked again for a period of time, the decryption key of the data will be released, so that the system or the application program will not be able to continue to access the data, and only when the electronic device is unlocked again, the decryption key is regenerated, and the data will be decrypted again. Such an encryption mode is suitable for all data under the same directory, and cannot be differentiated. Although in this encryption mode, when the electronic device is locked again, the decryption key is released, the protection of the data can be realized, but in the locked state of the electronic device, the data cannot be accessed, which will hinder the operation of some businesses. For example, the gallery application needs to process the recently taken images, so that the gallery application can classify the images. When the electronic device is locked, the gallery application cannot read the images, resulting in an abnormal image processing business. For another example, when the electronic device is unlocked, the social application program is uploading multiple images in the gallery application program to the cloud disk, and when the electronic device is locked, the images in the gallery application program cannot be accessed, resulting in an abnormal image transmission business. For another example, when the electronic device is unlocked, the mobile phone cloning business is being processed, and when the electronic device is locked, the file transmission in the mobile phone cloning business scenario will be hindered, resulting in a failed mobile phone cloning.

[0130] Therefore, in order to solve the above problems, the present application provides a data protection method, device and electronic device. On the one hand, the electronic device can set different encryption modes based on different data under the application program directory, and provide different protection measures for different data. For example, the file data is divided into A class files and B class files. Among them, after the electronic device is unlocked for the first time, even if the electronic device is locked again, the encryption key of the A class file will continue to exist, and the A class file is in the form of plaintext, allowing the system or the application program to access; after the electronic device is unlocked for the first time and locked again, the encryption key of the B class file will be released, and the B class file exists in the form of ciphertext, and the system or the application program cannot access the B class file. On the other hand, the encryption mode of the same data can also be dynamically adjusted to adapt to different business processing scenarios. The electronic device can ensure data security while ensuring normal processing of data by businesses, and improve user experience.

[0131] It should be noted that in the data protection method, device and electronic equipment provided in the embodiments of the present application, the file protection will be taken as an example for specific introduction, and the data to which the data protection method provided by the present application is applicable includes but is not limited to files, resources, account information or passwords, etc., which are not limited by the present application.

[0132] Firstly, the data protection method provided by the present application can be applied to an electronic equipment, the electronic equipment carries various application programs, each application program has one or more directories, and each directory includes one or more data. The data protection method of the present application can set an independent encryption mode for each data, and set different protection measures for different data.

[0133] For example, there are one or more folders under an application program, each folder includes one or more files, and the files can be divided into file types, and different encryption modes can be set for files of different file types.

[0134] For example, file 1 and file 2 belong to directory 1 (or folder 1), wherein file 1 is a class A file and file 2 is a class B file, file 1 can be encrypted in the encryption mode of class A file to protect file 1, and file 2 can be encrypted in the encryption mode of class B file to protect file 2.

[0135] As can be seen, even if the above-mentioned file 1 and file 2 belong to the same directory or the same folder, the encryption mode will be different because the types of file 1 and file 2 are different, and the protection degree will also be different.

[0136] In the data protection method provided in the embodiments of the present application, the encryption mode of the data can be determined according to the data type. When the data type is a first type, the data is encrypted by a first encryption mode; when the data type is a second type, the data is encrypted by a second encryption mode. In the data protection method provided in the embodiments of the present application, the first type can be referred to as class A, and the second type can be referred to as class B. Among them, the encryption key in the first encryption mode exists continuously after the electronic equipment is locked, and the encryption key in the second encryption mode is released after the electronic equipment is locked.

[0137] Taking the file protection as an example, the file types are divided into class A files and class B files, and the encryption modes of different file types will also be different. The class A file can be understood as the first type of data, and the class A file is encrypted by the first encryption mode; the class B file can be understood as the second type of data, and the class B file is encrypted by the second encryption mode.

[0138] The encryption mode of the class A file and the encryption mode of the class B file will be specifically introduced below taking the file protection as an example.

[0139] The A-class file is a file that can be accessed after the electronic device is locked. After the electronic device is unlocked for the first time after being powered on, the ciphertext of the A-class file is decrypted into a plaintext file. When the electronic device is locked again, the encryption key of the A-class file will not be released and will exist continuously. When the electronic device is locked, the system or application program can still access the A-class file and perform a service related to the A-class file. The encryption key of the A-class file can be understood as the encryption key in the first encryption mode, and the encryption key of the A-class file is used to encrypt the random number of the file, and the random number of the file is used to generate the key for encrypting the A-class file. By encrypting the random number of the file through the encryption key of the A-class file, the security of storing the random number of the file can be improved, thereby improving the security of the A-class file.

[0140] It should be noted that each file has a randomly generated random number, and the random number of each file can be used to generate a file encryption key (FEK) of the file. In order to store the random number of each file, the electronic device needs to encrypt the random number of each file. The keys used to encrypt the random number of the file are different for different types of files. For the A-class file, the random number of the file needs to be encrypted using the encryption key of the A-class file.

[0141] In the process of encrypting the A-class file, the electronic device generates a root key when it is unlocked, and derives the encryption key of the A-class file using the root key. First, the random number (random) of the file is encrypted using the encryption key of the A-class file to obtain the encrypted random number of the file, and the electronic device can save the encrypted random number of the file. Second, the FEK of the file is obtained by encrypting the random number of the file using the original key. Finally, the plaintext of the file is encrypted using the FEK of the file to obtain the key of the file, and the encryption of the file is completed.

[0142] For example, file 1 is an A-class file, and the encryption mode of file 1 mainly includes the following steps:

[0143] Step 1: When the electronic device is unlocked for the first time, a UserRootSecret is created for the user.

[0144] The UserRootSecret can be understood as a root key for encrypting and protecting user data, and is used to generate other encryption keys to ensure the security of files or data. The UserRootSecret exists after the electronic device is unlocked and disappears after being locked. It can be understood that the UserRootSecret is regenerated each time the user unlocks, but the UserRootSecret corresponds to the user, and the UserRootSecret generated each time can be the same.

[0145] Step 2: Derive the encryption key of the A-class file through the UserRootSecret.

[0146] It should be noted that the encryption key of the A-type file is Key2, and the encryption key of the A-type file will not be released after the electronic device is locked, and the key will exist all the time.

[0147] Exemplarily, the encryption key of the A-type file can be derived from the UserRootSecret through a key derivation function (KDF) encryption algorithm. The key derived through the KDF encryption algorithm can be used in the encryption process to protect the security of the file or data.

[0148] Step 3: encrypt the random number of file 1 using the encryption key of the A-type file to obtain the encrypted random number of file 1.

[0149] Exemplarily, the encryption (Encrypt, Enc) operation is performed using Key2 and the random number (random) of file 1 to obtain the encrypted random number (EN1_random) of file 1.

[0150] It should be noted that the random number can also be a random string, which is used to increase the security of the encryption process. Generally, the random number is unpredictable, which can make the ciphertext generated by multiple encryption different, thereby improving the difficulty of cracking the ciphertext.

[0151] It should be noted that different files have corresponding random numbers, in order to ensure the security of the random number of the file, the random number of the file can be encrypted to obtain the encrypted random number of the file for storage.

[0152] Step 4: encrypt the random number of file 1 using the original key to obtain the file encryption key of file 1.

[0153] Exemplarily, the encryption operation is performed on the random number (random) of file 1 using the original key (ClassKey) through the KDF encryption algorithm to obtain the FEK of file 1. The FEK of file 1 can be used to encrypt file 1, which is derived from the original key and the random number of file 1, thereby increasing a layer of security protection.

[0154] It should be noted that the original key is related to the universal flash storage (UFS) hardware of the electronic device. Generally, a UFS has 8-16 original keys, and different applications can reuse the same original key.

[0155] Step 5: encrypt the plaintext of file 1 using the file encryption key of file 1 to obtain the ciphertext of file 1.

[0156] For example, the plaintext body of the file 1 is encrypted by the FEK of the file 1 using the advanced encryption standard-extended tweaked codebook mode (AES-XTS) encryption algorithm to obtain the encrypted body of the file 1.

[0157] It should be noted that the AES-XTS encryption algorithm can ensure the security of the file, so that an unauthorized user is difficult to access or decrypt the file even in the case of loss or theft of the electronic device.

[0158] It can be understood that the electronic device includes a kernel file system, and the kernel file system implements encryption of the file 1 by performing the above steps 1 to 5. The encryption key Key2 of the A-type file obtained by the above step 2 is generated when the electronic device is powered on and unlocked for the first time, and the Key2 will exist continuously when the electronic device is locked again.

[0159] For example, when the electronic device is powered on and unlocked for the first time, the Key2 is generated, and the Key2 is finally obtained by a series of encryption algorithms to obtain the FEK. The encrypted body of the file 1 is decrypted by the FEK to obtain the plaintext of the file 1, so that the system or the application program can access the file 1.

[0160] It should be noted that the main steps of the above-mentioned A-type file encryption method are only illustrative, and the embodiments of the present application do not limit the specific encryption method of the A-type file.

[0161] The B-type file is a file that cannot be accessed after the electronic device is locked for a certain period of time. After the electronic device is powered on and unlocked for the first time, the encrypted body of the B-type file is decrypted into a plaintext file. When the electronic device is locked again, the key will be released, and the system or the application program will not be able to access the B-type file or execute the business related to the B-type file. Only when the electronic device is unlocked again, the key will be obtained again, the encrypted body of the B-type file will be decrypted into a plaintext file, and the system or the application program can access the B-type file. The above-mentioned key will be released after the electronic device is locked for a certain period of time, or the key can be released immediately after the electronic device is locked. The encryption key of the B-type file can be understood as the encryption key in the second encryption method, and the encryption key of the B-type file is used to encrypt the random number of the file, and the random number of the file is used to generate the key for encrypting the B-type file. By encrypting the random number of the file by the encryption key of the B-type file, the security of the random number of the file can be improved, thereby improving the security of the B-type file.

[0162] For the B-class file, the random number of the file needs to be encrypted using the encryption key of the B-class file.

[0163] In the process of encrypting the B-class file, the root key is generated when the electronic device is unlocked, and the encryption key of the B-class file is derived using the root key and the application identifier. First, the random number of the file is encrypted using the encryption key of the B-class file to obtain the secret random number of the file, and the electronic device can save the encrypted random number of the file. Second, the random number of the file is encrypted using the original key to obtain the FEK of the file. Finally, the plaintext of the file is encrypted using the FEK of the file to obtain the key of the file, and the encryption of the file is completed.

[0164] For example, the file 2 is a B-class file, and the encryption method of the file 2 will mainly include the following steps:

[0165] Step 1: When the electronic device is unlocked for the first time, a UserRootSecret is created for the user.

[0166] The UserRootSecret can be understood as a root key for encrypting and protecting user data, and is used to generate other encryption keys to ensure the security of files or data. The UserRootSecret exists after the electronic device is unlocked, and disappears after the screen is locked. It can be understood that the UserRootSecret is regenerated every time the user unlocks, but the UserRootSecret corresponds to the user, and the UserRootSecret generated each time can be the same.

[0167] Step 2: Derive the encryption key of the B-class file by deriving the UserRootSecret and the application identifier.

[0168] It should be noted that the encryption key of the B-class file is APP_ID Key2, and the encryption key of the B-class file will be released after the electronic device is locked for a period of time. When the electronic device is unlocked again, the encryption key of the B-class file will be regenerated.

[0169] For example, the UserRootSecret and the application identifier (application_identifier, APP_ID) can be derived into the encryption key of the B-class file through the KDF encryption algorithm. The key derived through the KDF encryption algorithm can be used in the encryption process to protect data or the security of data. The application identifier can be the application package name.

[0170] Step 3: Encrypt the random number of the file 2 using the encryption key of the B-class file to obtain the encrypted random number of the file 2.

[0171] For example, an Encrypt (Enc) operation is performed using the APP ID Key2 and the random number (random) of file 2 to obtain an encrypted random number (EN2_random) of file 2.

[0172] It should be noted that the random number can also be a random string, which is used to increase the security of the encryption process. Generally, the random number is unpredictable, which can make the ciphertext generated by multiple encryption different, thereby improving the difficulty of cracking the ciphertext.

[0173] Step 4: The random number of file 2 is encrypted using the original key to obtain a file encryption key of file 2.

[0174] For example, an encryption operation is performed on the random number (random) of file 2 using the original key (ClassKey) through a KDF encryption algorithm to obtain the FEK of file 2. The FEK of file 2 can be used to encrypt file 2 and is derived from the original key and the random number of file 2, thereby increasing a layer of security protection.

[0175] It should be noted that the original key is related to the universal flash storage (UFS) hardware of the electronic device. Generally, a UFS has 8-16 original keys, and different applications can reuse the same original key.

[0176] Step 5: The plaintext of file 2 is encrypted using the file encryption key of file 2 to obtain the ciphertext of file 2.

[0177] For example, the plaintext (plaintextbody) of file 2 is encrypted using the FEK of file 2 through an AES-XTS encryption algorithm to obtain the ciphertext (encryptedbody) of file 2.

[0178] It should be noted that the AES-XTS encryption algorithm can ensure the security of the file, so that even if the electronic device is lost or stolen, an unauthorized user is difficult to access or decrypt the file.

[0179] It can be understood that the electronic device includes a kernel file system, and the kernel file system implements the encryption of file 2 by performing the above steps 1-5. The encryption key APP ID Key2 of the B-type file obtained through the above step 2 is generated when the electronic device is unlocked for the first time after booting. When the electronic device is locked again for a period of time, the APP ID Key2 will be released, and when the electronic device is unlocked again, the APP ID Key2 will be regenerated.

[0180] For example, when the electronic device is unlocked, APP ID Key2 is generated, APP ID Key2 is encrypted through a series of encryption algorithms, and finally FEK is obtained. FEK is used to decrypt the ciphertext of file 2 to obtain the plaintext of file 2, so that the system or application program can access file 2.

[0181] It should be noted that the above-mentioned main steps of the B-type file encryption method are only illustrative, and the embodiments of the present application do not limit the specific encryption method of the B-type file.

[0182] As can be seen, the encryption key of the A-type file and the encryption key of the B-type file are both used to encrypt the random number of the file, but the encryption key of the A-type file is generated when the electronic device is unlocked for the first time after booting, and will exist continuously regardless of whether the electronic device is locked again, so that the system or application program can continuously access the A-type file. The encryption key of the B-type file is generated when the electronic device is unlocked for the first time after booting, and will be released when the electronic device is locked again for a certain period of time, so that the system or application program cannot access the B-type file. In short, the protection of the B-type file is higher.

[0183] It should be noted that before the electronic device is shipped, a file type of a certain file can be preset as an A-type file or a B-type file. Information indicating the file type can be carried in the metadata of the file. The metadata of the file can be understood as information describing the properties and characteristics of the file.

[0184] For example, as shown in FIG. 3, a file structure diagram is shown, and file 1 and file 2 shown in FIG. 3 belong to the same directory. As can be seen, a directory can include multiple files.

[0185] File 1 includes the metadata of file 1 and the ciphertext of file 1, and the metadata of file 1 includes the encryption random number of file 1 and the type of file 1. The ciphertext of file 1 is encrypted using the FEK of file 1, and the type of file 1 can be preset by the system, and can be represented in the form of a field, a bit, etc. For example, '00' represents an A-type file, and '01' represents a B-type file. The random number of file 1 is randomly generated, and the encryption key of file 1 can be used to encrypt the random number of file 1 to obtain the encryption random number of file 1, and saved to the metadata of file 1. The encryption key of file 1 is related to the file type of file 1. If file 1 is an A-type file, the encryption key of file 1 is the encryption key of the A-type file; if file 1 is a B-type file, the encryption key of file 1 is the encryption key of the B-type file.

[0186] Similarly, the file 2 includes metadata of the file 2 and ciphertext of the file 2, and the metadata of the file 2 includes an encryption random number of the file 2 and a type of the file 2. The ciphertext of the file 2 is encrypted by using the FEK of the file 2, and the type of the file 2 can be preset by the system. The random number of the file 2 is randomly generated, and the encryption random number of the file 2 is obtained by encrypting the random number of the file 2 by using the encryption key of the file 2 and is saved in the metadata of the file 2. The encryption key of the file 2 is related to the type of the file 2, if the file 2 is a type-A file, the encryption key of the file 2 is the encryption key of the type-A file; if the file 2 is a type-B file, the encryption key of the file 2 is the encryption key of the type-B file.

[0187] For example, the type-A file can be a file currently accessed by the electronic device, or a file with a low protection degree preset by the system. For example, a file currently downloaded in the background, or a file updated in real time when the electronic device is locked. The type-B file can be a file not currently accessed by the electronic device, or a file with a high protection degree preset by the system. For example, a file stored in a memo, or a mobile phone message.

[0188] It should be noted that although the system can preset the type of the file, the type of the file can also be dynamically adjusted as the current business processing scene of the electronic device changes.

[0189] For ease of understanding, as shown in FIG. 4, a schematic diagram of file type switching is shown.

[0190] As shown in (a) of FIG. 4, a directory of a gallery application includes type-A files and type-B files, where the type-A files include picture 3 and picture 4, and the type-B files include picture 1 and picture 2. The electronic device is currently processing the picture 3 in the type-A files, and the picture 3 can continue to be processed even when the electronic device is locked.

[0191] As shown in (b) of FIG. 4, when the system service module in the electronic device determines that the picture 3 has been processed and the encryption key of the picture 3 has not been released, the type of the picture 3 can be switched to type-B. After the kernel file system switches the file type, in the directory, the type-A files include the picture 4, and the type-B files include the picture 1, the picture 2, and the picture 3.

[0192] It should be noted that the switching of the file type from type-B to type-A is similar to the schematic diagram shown in FIG. 4, and details are not described herein to avoid redundancy.

[0193] In an implementation manner, the file type of a certain file is switched from type-A to type-B, the encryption key of the type-A file is not released, the encryption random number of the file is decrypted by using the encryption key of the type-A file to obtain the random number of the file, and the random number of the file is re-encrypted by using the encryption key of the type-B file.

[0194] For example, the type of file 1 is switched from class A to class B, and when the Key2 is not released, the encrypted random number EN1_random of file 1 is decrypted using the Key2 to obtain the random number random1 of file 1, and the random number random1 of file 1 is re-encrypted using the APP ID Key2 to obtain EN2_random. The random number random1 of file 1 does not change, and after the random number random1 of file 1 is re-encrypted using the APP ID Key2, the FEK of file 1 does not change, and thus the ciphertext of file 1 is not affected.

[0195] In another implementation, the type of a file is switched from class B to class A, the encryption key of the class B file is not released, the encrypted random number of the file is decrypted using the encryption key of the class B file to obtain the random number of the file, and the random number of the file is re-encrypted using the encryption key of the class B file.

[0196] For example, the type of file 2 is switched from class B to class A, and when the APP ID Key2 is not released, the encrypted random number EN2_random of file 1 is decrypted using the APP ID Key2 to obtain the random number random2 of file 2, and the random number random2 of file 2 is re-encrypted using the Key2 to obtain EN1_random. The random number random2 of file 2 does not change, and after the random number random2 of file 2 is re-encrypted using the encryption key Key2 of the class A file, the FEK of file 2 does not change, and thus the ciphertext of file 2 is not affected.

[0197] It can be seen that when the type of the file changes, only the random number of the file needs to be re-encrypted, and the file does not need to be re-encrypted, thereby saving certain overhead while ensuring data protection security.

[0198] Secondly, the data protection method provided by the application can be dynamically adjusted. In response to a first trigger event, the encryption mode of the data can be modified. Different first trigger events can result in different modifications of the encryption mode of the data. The specific modifications of the encryption mode mainly include the following two scenarios:

[0199] On the one hand, the data type of the data can be modified to a second type when the electronic device does not access the data within a preset time length, and the data type of the data can be modified to a first type when the electronic device is locked and a business corresponding to the data is executed. That is, by modifying the data type, the encryption mode of the data is dynamically adjusted. On the other hand, the timing of releasing the encryption key can be adjusted when the electronic device is locked and the business corresponding to the data is executed. That is, the timing of releasing the encryption key can be temporarily adjusted on the premise that the data type remains unchanged, so as to dynamically adjust the encryption mode.

[0200] It should be noted that the encryption mode includes a first encryption mode and a second encryption mode. The encryption mode can be modified from the first encryption mode to the second encryption mode, or from the second encryption mode to the first encryption mode; the data type can be modified from the first type to the second type, or from the second type to the first type.

[0201] The following will be a specific introduction to the above two scenarios of dynamically adjusting the encryption mode:

[0202] In an implementation mode, the encryption mode is dynamically adjusted by modifying the data type.

[0203] It should be noted that the prerequisite for the change of the data type is that the encryption key of the original data type has not been released.

[0204] Taking a protected file as an example, a scenario of dynamically adjusting the encryption mode is introduced.

[0205] Illustratively, the file type can be switched from a class A file to a class B file, or from a class B file to a class A file.

[0206] In the scenario of switching the class A file to the class B file, it is assumed that the system preset file type is class A, and the encryption key of the class A file is persistent. That is, when the class A file is decrypted into plaintext, the system or application program can still access the class A file even if the electronic device is locked.

[0207] When the current business related to the class A file is completed, and the encryption key of the class A file has not been released, the file type can be switched to class B to improve the protection level of the file. Alternatively, when the business related to the class A file is not processed within a preset time period, indicating that the system or application program currently has no need to access the class A file, and the encryption key of the class A file has not been released, the file type can be switched to class B.

[0208] That is, when the electronic device does not need to access a certain file in the current business processing scenario, the file type of the file can be switched to a class B file with a higher protection level. If the system preset file type of the file is a class B file, the file type of the file can remain unchanged.

[0209] For example, the current service of the electronic device is to process images in a gallery application. The images in the gallery application can be a type A file, which is a file type preset by the system for processing. That is, when the electronic device is locked, the images in the gallery application can also be accessed by the system or the application, facilitating the processing of the images. Assuming that it is predicted that the images in the gallery application need to be processed for 24 hours, when the service processing time reaches 24 hours, the electronic device determines whether the current service (i.e., processing the images in the gallery application) has been completed. When the electronic device determines that the current service has been completed, it further needs to determine whether the encryption key of the images in the gallery application as a type A file has not been released. When the above two conditions are met, the electronic device can switch the file type to type B.

[0210] In the scenario of switching the type B file to the type A file, assuming that the system presets the file type as type B, the encryption key of the type B file will be released after the electronic device is locked for a period of time. That is, when the electronic device is locked, the system or the application cannot access the type B file. When the electronic device is unlocked again, the encryption key of the type B file will be generated again.

[0211] When the electronic device needs to process a service related to the type B file while being locked, and the encryption key of the type B file has not been released, the file type can be switched to type A to ensure the normal processing of the current service. If the system preset file type of the file is type A, the file type of the file can remain unchanged.

[0212] For example, the electronic device needs to share images or videos with other users through a social application. When the electronic device is locked, the normal transmission of the shared images or videos also needs to be ensured. If the shared images or videos are type B files, and the encryption key of the type B file has not been released, the electronic device can switch the file type to type A.

[0213] Based on the above scheme, the data protection method provided in the present application meets the current data security while taking into account the normal processing of the corresponding service of the data, and protects the privacy of the user without affecting the normal function of the electronic device.

[0214] In another implementation manner, the data type is maintained unchanged, and the encryption method is temporarily modified.

[0215] Another scenario of dynamically adjusting the encryption method is introduced by taking the protection of a file as an example.

[0216] According to the above description, the encryption method of the same file type is the same, for example, in the encryption method of the B type file, the electronic device generates the encryption key APP ID Key2 of the B type file, and when the electronic device is locked for a period of time, APP ID Key2 will be released, and the system or application program will not be able to access the B type file.

[0217] In order to enable the system or application program to access the file when the electronic device is locked, the method described above can be used to switch the type of the file from B to A. However, in some critical business processing scenarios, switching the file type and re-encrypting the random number of the file will cause a large amount of overhead and affect the power consumption of the electronic device. Therefore, in the data protection method provided in the embodiments of the present application, for more rich business processing scenarios using the electronic device, the data type can also not be changed, and the encryption method can be adjusted.

[0218] It should be noted that the above-mentioned critical business processing scenarios can include mobile phone cloning scenarios, uploading multiple images in the gallery application to the cloud disk, and the like. In short, the business scenario of maintaining the data type unchanged and dynamically adjusting the encryption method usually involves batch files. In contrast, the business scenario of dynamically adjusting the encryption method by adjusting the data type usually involves non-batch files.

[0219] Specifically, the electronic device provides a key dynamic release management mechanism. Taking the protected file as an example, for the B type file in the critical business processing scenario, the encryption key of the B type file can be temporarily extended to be released to ensure the normal processing of the critical business. When the critical business processing is completed, the encryption key of the B type file can be released to ensure the security of the B type file.

[0220] Exemplarily, taking the adjustment of the encryption method of the B type file as an example, as shown in FIG. 5, a method for dynamically adjusting the encryption method is introduced. The method dynamically adjusts the encryption method without changing the file type. The security of the file data is ensured, and the normal operation of the reasonable business is ensured.

[0221] S501, determine that the critical business accesses the B type file.

[0222] Exemplarily, when the system service module in the electronic device determines that the current critical business of the electronic device needs to access the B type file, the adjustment of the encryption method of the B type file can be triggered.

[0223] It can be understood that the key service includes a mobile phone cloning scenario, uploading multiple images in a gallery application to a cloud disk, and the like, which involves processing of batch files. In the mobile phone cloning service scenario, the images, videos, messages, and the like that need to be cloned can be B-type files. In the service scenario of uploading multiple images in a gallery application to a cloud disk, the images in the gallery can be B-type files.

[0224] S502, releasing the encryption key of the B-type file after the key service completes a preset time length.

[0225] For example, when the system service module determines that the current key service of the electronic device needs to access the B-type file, the system service module can request the file management module of the electronic device to retain the key, that is, to request that the key of the B-type file is not released within a period of time after the electronic device is locked. The file management module can send indication information to the kernel file system to instruct the kernel file system not to release the key of the B-type file within a period of time after the electronic device is locked. When the kernel file system determines that the key service completes a preset time length, the encryption key of the B-type file can be released.

[0226] It should be noted that the above limitation of the functional modules in the electronic device is only an example, and the specific steps performed by each functional module in the electronic device are not limited.

[0227] It should be noted that after dynamically adjusting the encryption mode of the B-type file, the retention time of the encryption key of the B-type file can be longer to ensure the normal operation of the key service.

[0228] For example, in the service scenario of uploading multiple images in a gallery application to a cloud disk, the system service module determines that the images in the gallery are currently being transmitted, the system service module requests the file management module to retain the encryption key of the images in the gallery, and the file management module instructs the kernel file system not to release the encryption key of the images in the gallery within a period of time after the electronic device is locked according to the request of the system service module, and instructs to release the encryption key of the images in the gallery after a preset time length of the service is completed.

[0229] For another example, in the mobile phone cloning service scenario, the system service module determines that the mobile phone cloning task is currently being executed, the system service module requests the file management module to retain the encryption key of the file under the mobile phone cloning service, and the file management module instructs the kernel file system not to release the encryption key of the file under the mobile phone cloning service within a period of time after the electronic device is locked according to the request of the system service module, and instructs to release the encryption key of the file under the mobile phone cloning service after a preset time length of the service is completed.

[0230] Based on the above scheme, in some business scenarios, the encryption mode can be adjusted without changing the data type, which avoids causing a large amount of overhead while taking into account the security of the data and the normal operation of the data corresponding business.

[0231] As shown in FIG. 6, a schematic flowchart of a data protection method provided by the present application is shown, which can be applied to an electronic device, and the method will be specifically introduced below.

[0232] S601, in response to a first trigger event, modifying an encryption mode of first data.

[0233] It can be understood that the first data is data carried on the electronic device, for example, a file, a resource, account information, or a password, etc. The first data can be related to a business performed by the electronic device.

[0234] It should be noted that in the method, the apparatus and the electronic device for protecting data provided by the embodiments of the present application, the specific form of the data includes but is not limited to a file, a resource, account information, or a password, etc., which is not limited by the embodiments of the present application.

[0235] The encryption mode includes a first encryption mode and a second encryption mode, wherein the encryption key in the first encryption mode persists after the electronic device is locked, and the encryption key in the second encryption mode is released after the electronic device is locked.

[0236] Optionally, the encryption key in the second encryption mode is related to an identifier of an application program, and the application program includes the first data.

[0237] For example, the first encryption mode can be understood as the encryption mode of the A-type file, and the second encryption mode can be understood as the encryption mode of the B-type file. The encryption key in the first encryption mode can be understood as the encryption key of the A-type file. After the electronic device is powered on and unlocked for the first time, the ciphertext of the A-type file can be decrypted into a plaintext file; when the electronic device is locked again, the encryption key of the A-type file will not be released and will persist. That is, after the electronic device is locked, the system or the application program can still access the data encrypted in the first encryption mode. The encryption key in the second encryption mode can be understood as the encryption key of the B-type file. After the electronic device is powered on and unlocked for the first time, the ciphertext of the B-type file will be decrypted into a plaintext file; when the electronic device is locked again, the encryption key of the B-type file will be released. That is, after the electronic device is locked, the system or the application program will not be able to access the data encrypted in the second encryption mode.

[0238] Specifically, in response to the first trigger event, the encryption mode of the first data can be modified from the first encryption mode to the second encryption mode, or the encryption mode of the first data can be modified from the second encryption mode to the first encryption mode.

[0239] In an implementation, the electronic device includes second data different from the first data encryption manner, and the second data belongs to the same directory as the first data.

[0240] For example, when the first data is a first file and the second data is a second file, the first file and the second file belong to the same folder, and the folder belongs to an application of the electronic device.

[0241] That is, the data protection method provided by the present application is based on different data and sets different encryption manners with data granularity. For example, even if the first file and the second file belong to the same folder, the first file and the second file can have different encryption manners.

[0242] The following specifically introduces how to modify the encryption manner of the first data when different first trigger events occur:

[0243] In an implementation, in response to the first trigger event, the data type of the first data is modified, and the data type includes a first type encrypted by the first encryption manner and a second type encrypted by the second encryption manner.

[0244] For example, the first type is referred to as type A, and the second type is referred to as type B. For example, the data type can be understood as a file type, and the file type includes type A files and type B files.

[0245] Optionally, the first data includes first information, and the first information is used to indicate the data type of the first data.

[0246] For example, the first information can indicate the data type in the form of a field, a bit, etc. For example, '00' represents the first type, and '01' represents the second type.

[0247] It can be understood that the data type is related to the encryption manner, and the electronic device can determine the encryption manner according to the data type. When the data type of the first data is the first type, the first data can be encrypted by the first encryption manner; and when the data type of the first data is the second type, the second data can be encrypted by the second encryption manner.

[0248] It can be seen that in response to the first trigger event, the data type of the first data is modified, so that the encryption manner of the first data can be modified.

[0249] Specifically, modifying the data type of the first data includes modifying the data type of the first data from the first type to the second type, and also includes modifying the data type of the first data from the second type to the first type.

[0250] For example, when the data type of the first data is modified to the first type, the encryption mode of the first data is modified to the first encryption mode; and when the data type of the first data is modified to the second type, the encryption mode of the first data is modified to the second encryption mode.

[0251] Optionally, in response to no access to the first data within a first preset time period, the data type of the first data is modified to the second type.

[0252] For example, the first preset time period can be determined by system preset, user setting or artificial intelligence learning, which is not limited in the present application.

[0253] It should be noted that when the original data type of the first data is the first type, in response to no access to the first data within the first preset time period, the data type of the first data is modified to the second type; and when the original data type of the first data is the second type, in response to no access to the first data within the first preset time period, the data type of the first data is kept as the second type.

[0254] For example, when the electronic device does not process the service corresponding to the first data within the first preset time period (for example, 2 hours), it indicates that the electronic device temporarily has no demand to access the first data, or the electronic device has completed the service corresponding to the first data, and then the data type of the first data can be modified to the second type to improve the protection degree of the first data.

[0255] Optionally, in response to the unlocking operation and no access to the first data within the first preset time period, the data type of the first data is modified to the second type.

[0256] It can be understood that the modification of the data type can be triggered when the electronic device is unlocked.

[0257] Optionally, in response to the locking operation and the electronic device executing the service corresponding to the first data, the data type of the first data is modified to the first type.

[0258] It should be noted that when the original data type of the first data is the second type, in response to the locking operation and the electronic device executing the service corresponding to the first data, the data type of the first data is modified to the first type; and when the original data type of the first data is the first type, in response to the locking operation and the electronic device executing the service corresponding to the first data, the data type of the first data is kept as the first type.

[0259] For example, when the electronic device is locked, it still needs to process the service corresponding to the first data, which indicates that the electronic device needs to access the first data even when it is locked, and then the data type of the first data can be modified to the first type to facilitate the smooth execution of the service corresponding to the first data.

[0260] Exemplarily, the service corresponding to the first data includes data uploading, data synchronization, data updating and the like related to the interaction between the electronic device and the cloud; further includes data editing, data saving, data local caching and the like processed by the electronic device; further includes screen projection, audio / video playing, calling and the like running in the background of the electronic device.

[0261] It should be noted that the data type of the first data is modified in response to the first trigger event and the existence of the encryption key of the first data.

[0262] That is to say, the precondition that the electronic device can modify the data type of the first data is that not only the first trigger event occurs, but also the encryption key of the first data exists.

[0263] Exemplarily, the data type of the first data is modified to the second type in response to that the electronic device does not access the first data within the first preset time length and the existence of the encryption key of the first data. The data type of the first data is modified to the first type in response to the lock screen operation, the electronic device executing the service corresponding to the first data and the existence of the encryption key of the first data.

[0264] For example, if the original data type of the first data is the first type, the original encryption mode of the first data is the first encryption mode, and the encryption key of the first data is the encryption key in the first encryption mode. The data type of the first data is modified to the second type in response to that the electronic device does not access the first data within the first preset time length and the existence of the encryption key in the first encryption mode.

[0265] In an implementation manner, the encryption key of the first data is released after the service corresponding to the first data is completed in response to the lock screen operation and the electronic device executing the service corresponding to the first data.

[0266] It should be noted that the electronic device can modify the timing of releasing the encryption key of the first data. When the electronic device needs to execute the service corresponding to the first data after being locked, the release timing of the encryption key of the first data can be extended to after the electronic device completes the service corresponding to the first data.

[0267] It can be understood that the encryption key of the first data can be released after the electronic device is locked and a second preset time length after the service corresponding to the first data is completed.

[0268] Optionally, the first data includes batch files.

[0269] Optionally, the service corresponding to the first data includes data transmission, wherein the data transmission includes data updating, data synchronization and the like.

[0270] Optionally, the encryption mode corresponding to the first data is the second encryption mode.

[0271] For example, the first data corresponds to a mobile phone cloning service. In response to the lock screen operation and the electronic device executing the mobile phone cloning service, the encryption key of the first data can be released 2 hours after the electronic device completes the mobile phone cloning service.

[0272] It can be seen that when the electronic device still needs to process batch data when the screen is locked, the encryption key release time can be temporarily adjusted without changing the data type, thereby saving the power consumption of the electronic device while ensuring the normal execution of the service.

[0273] The data protection method provided in the present application can set different encryption methods for different data types of data and provide different degrees of protection measures for different data. In addition, the encryption method of the same data can also be dynamically adjusted to adapt to different service processing scenarios, so that the electronic device can ensure data security while ensuring normal processing of data by the service, thereby improving the user experience.

[0274] The embodiment of the present application provides a computer program product, when the computer program product runs on the device, makes the device execute the technical solutions in the above embodiments. Its implementation principle and technical effects are similar to the above method related embodiments, and will not be repeated here.

[0275] The embodiment of the present application provides a readable storage medium, the readable storage medium contains instructions, when the instructions run on the device, make the device execute the technical solutions of the above embodiments. Its implementation principle and technical effects are similar, and will not be repeated here.

[0276] The embodiment of the present application provides a chip, the chip is used for executing instructions, when the chip runs, executes the technical solutions in the above embodiments. Its implementation principle and technical effects are similar, and will not be repeated here.

[0277] Those skilled in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solutions. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of the present application.

[0278] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described device and unit (module) can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.

[0279] In several embodiments provided in the present application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other manners. For example, the embodiments of the apparatus described above are merely schematic. For example, the division of the units is only a logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between the units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.

[0280] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place or distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.

[0281] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.

[0282] If the above functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and various program codes that can be stored in the medium.

[0283] The above description is merely a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method of data protection, characterized in that, The method is applied to an electronic device, and the method comprises: In response to a first trigger event, modifying an encryption mode of first data, the encryption mode comprising a first encryption mode and a second encryption mode, an encryption key in the first encryption mode persisting after the electronic device is locked, and an encryption key in the second encryption mode being released after the electronic device is locked.

2. The method of claim 1, wherein, The electronic device comprises second data different from the encryption mode of the first data, the second data belonging to a same directory as the first data.

3. The method according to claim 1 or 2, characterized in that, The response to the first trigger event, modifying the encryption mode of the first data, comprises: In response to the first trigger event, modifying a data type of the first data, the data type comprising a first type encrypted by the first encryption mode and a second type encrypted by the second encryption mode.

4. The method of claim 3, wherein, The response to the first trigger event, modifying the data type of the first data, comprises: In response to no access to the first data within a first preset time length, modifying the data type of the first data to the second type.

5. The method of claim 3, wherein, The response to the first trigger event, modifying the data type of the first data, comprises: In response to a lock screen operation and the electronic device executing a service corresponding to the first data, modifying the data type of the first data to the first type.

6. The method according to claim 4 or 5, characterized in that, The response to the first trigger event, modifying the data type of the first data, comprises: In response to the first trigger event and the encryption key of the first data existing, modifying the data type of the first data.

7. The method according to any one of claims 1 to 6, characterized in that, The response to the first trigger event, modifying the encryption mode of the first data, comprises: In response to a lock screen operation and the electronic device executing a service corresponding to the first data, releasing the encryption key of the first data after the service corresponding to the first data is completed.

8. The method of claim 7, wherein, The first data comprises a batch file.

9. The method according to claim 7 or 8, characterized in that, The service corresponding to the first data comprises data transmission.

10. The method according to any one of claims 7 to 9, characterized in that, The encryption mode of the first data is the second encryption mode.

11. The method according to any one of claims 1 to 10, characterized in that, The first data comprises first information, the first information being used to indicate a data type of the first data, the data type comprising a first type encrypted by the first encryption mode and a second type encrypted by the second encryption mode.

12. The method according to any one of claims 1 to 11, characterized in that, The encryption key in the second encryption mode is related to an identity of an application, the application comprising the first data.

13. An electronic device, comprising: Comprise: One or more processors; One or more memories; The one or more memories store one or more computer programs comprising instructions which, when executed by the one or more processors, cause the electronic device to perform the method of any one of claims 1 to 12.

14. An apparatus for data protection, the apparatus comprising: Comprise: A processor coupled with a memory, the memory being used to store a computer program, and the processor being used to run the computer program, so that the data protection device performs the method of any one of claims 1 to 12.

15. The apparatus for data protection of claim 14, wherein, Further comprise one or more of the memory and a transceiver, the transceiver being used to receive a signal and / or send a signal.

16. A computer readable storage medium characterized by: a computer program product stored on a computer readable medium, which, when executed by a computer, causes the computer to carry out the method of any one of claims 1 to 12.

17. A computer program product comprising instructions, characterized in that, a computer program product stored on a computer readable medium, which, when executed by a computer, causes the computer to carry out the method of any one of claims 1 to 12.

18. A chip, characterized by a chip comprising a processor and a data interface, the processor reading instructions stored on a memory via the data interface to carry out the method of any one of claims 1 to 12.

Citation Information

Patent Citations

  • Data protection method and device and electronic equipment

    CN121093351A

  • Portable equipment and data protection method thereof

    CN101295341A

  • Device state driven encryption key management

    CN113544666A

  • Data processing method and device, equipment and storage medium

    CN114254334A

  • Method and apparatus for encryption of data

    US20030118185A1