Key management method, storage medium, and electronic device
By generating and storing the first ciphertext of the recovery key, the problem of data encryption keys being unavailable due to forgotten hardware keys or passwords is solved, enabling reliable decryption and secure storage in the event of hardware failure.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2026-04-02
AI Technical Summary
If the user password or hardware key cannot be obtained, the electronic device cannot decrypt the ciphertext of the data encryption key, resulting in the inability to access the content data.
A key management method is provided, which generates a recovery key to encrypt the data encryption key, generates a first ciphertext and stores it in the unencrypted area of a non-volatile memory. The decryption process does not require a hardware key or user password, thus increasing the ways to obtain the data encryption key.
Even in the event of hardware damage or forgotten passwords, the data encryption key can still be decrypted, improving the reliability of data encryption key acquisition and storage security, and reducing the risk of key leakage.
Smart Images

Figure CN2025098049_02042026_PF_FP_ABST
Abstract
Description
Key management method, storage medium and electronic device
[0001] The present application claims priority from the Chinese patent application No. 202411398353.1 filed with the State Intellectual Property Office on September 30, 2024 and entitled "Key management method, storage medium and electronic device", the whole content of which is incorporated herein by reference. TECHNICAL FIELD
[0002] The present application relates to the technical field of computers, in particular to a key management method, a storage medium and an electronic device. BACKGROUND
[0003] Full-disk encryption technology is used to encrypt content data using a data encryption key before the electronic device is locked or powered off, so as to improve the storage security of business data.
[0004] In the related art, a user password and / or a hardware key are used to encrypt and protect a data encryption key, and a ciphertext of the data encryption key is generated. After the screen of the electronic device is unlocked or the electronic device is powered on, a security chip of the electronic device decrypts the ciphertext of the data encryption key through the user password and / or the hardware key to obtain the data encryption key, and decrypts a ciphertext of target content data stored in a hard disk using the data encryption key to obtain the target content data.
[0005] However, in the case where the user password or the hardware key cannot be obtained, the electronic device cannot decrypt the ciphertext of the data encryption key, resulting in that the content data cannot be obtained. SUMMARY
[0006] To solve the above technical problems, the present application provides a key management method, a storage medium and an electronic device. In the technical solution provided by the present application, in response to a request to generate a recovery key, the recovery key is displayed; the data encryption key is encrypted using the recovery key to obtain a first ciphertext of the data encryption key; and the first ciphertext is stored in a non-encrypted storage area of a non-volatile memory. Since the decryption process of the first ciphertext does not require the hardware key and / or the user password, in the case where the user password or the hardware key cannot be obtained, the electronic device can also decrypt the ciphertext of the data encryption key to obtain the data encryption key, so that the first ciphertext of the data encryption key does not depend on the hardware key and / or the user password for decryption, and in the case where the hardware of the electronic device is damaged, the first ciphertext stored in the non-volatile memory can also be decrypted using the recovery key to obtain the data encryption key.
[0007] To achieve the above technical purposes, the present application provides the following technical solutions:
[0008] In a first aspect, a key management method is provided, and is applied to a first electronic device. The method comprises: in response to a request for generating a recovery key, displaying the recovery key; encrypting a data encryption key using the recovery key to obtain first ciphertext of the data encryption key, the data encryption key being used for encrypting and / or decrypting target content data in a non-volatile memory; and storing the first ciphertext in a non-encrypted storage area of the non-volatile memory.
[0009] By the above method, the data encryption key is encrypted by the recovery key to generate the first ciphertext of the data encryption key. Compared with the related art in which the hardware key of the electronic device is used to participate in decryption of the data encryption key, since the hardware key of the electronic device can be engraved in a mainboard, damage or loss of the mainboard can cause loss of the hardware key, making it difficult to decrypt the second ciphertext of the data encryption key, and thus the data encryption key cannot be obtained.
[0010] In the scheme provided in the embodiment, the first ciphertext of the data encryption key is decrypted using the recovery key, so that the process of obtaining the data encryption key does not need to use the hardware key, and the dependence of the data encryption key on the hardware key of the electronic device is reduced. In the case where the electronic device is damaged and the non-volatile memory is intact, the non-volatile memory can be connected to another electronic device, and the key management method is executed in the other electronic device. In this way, the reliability of the data encryption key obtaining manner is improved, and loss of the hardware key or user password is avoided, so that the loss of the content data caused to the user is avoided.
[0011] In addition, the first ciphertext of the data encryption key is stored in the non-encrypted area of the non-volatile memory, which reduces the difficulty of reading the first ciphertext of the data encryption key by the electronic device. At the same time, the first ciphertext of the data encryption key needs to be decrypted by the recovery key, so that storing the first ciphertext of the data encryption key in the non-encrypted area will not cause leakage of the data encryption key. In this way, the storage security of the data encryption key is improved while the data encryption key is obtained, so that the reliability of the key management method is improved.
[0012] In a possible implementation, in response to the key generation operation, after the recovery key is generated, the method further comprises: in response to an account login operation, sending account information to a server; and in response to a key binding operation, sending a key binding request to the server, the key binding request carrying key data, the key data being the encrypted recovery key, and the key binding request being used to request binding of the account information and the recovery key.
[0013] By storing the recovery key in the server, it is helpful to avoid that the first ciphertext of the data encryption key cannot be decrypted due to user forgetting the recovery key.
[0014] In a possible implementation, before the key binding request is sent to the server in response to the key binding operation, the method further includes: obtaining an end-to-cloud key, the end-to-cloud key being used to encrypt communication data between the first electronic device and the server; and obtaining the key data by encrypting the recovery key according to a public key in the end-to-cloud key.
[0015] In this way, it is helpful to avoid leakage of the recovery key in the communication process between the electronic device and the server.
[0016] In a possible implementation, the recovery key includes a first sub-key and a second sub-key; and in response to the operation of generating the recovery key, the displaying of the recovery key includes: displaying the first sub-key; the key data is the encrypted second sub-key; and the key binding request is used to request binding of the account information and the second sub-key.
[0017] By dividing the recovery key into the first sub-key and the second sub-key and using different ways to store the sub-keys, it is helpful to reduce the risk of leakage of the recovery key, improve the storage security of the recovery key, and further reduce the risk of leakage of the data encryption key.
[0018] In a possible implementation, the method further includes: obtaining a first credential according to the recovery key, the first credential being used to identify the recovery key; and storing the first credential in the non-volatile memory.
[0019] In this way, it is helpful to verify whether the recovery key provided by the user is correct, so as to improve the security of the function of decrypting the data encryption key based on the recovery key or resetting the user password based on the recovery key.
[0020] In a possible implementation, after the first ciphertext is stored in the non-encrypted storage area of the non-volatile memory, the method further includes: receiving the recovery key in response to a user operation; reading the first ciphertext from the non-encrypted storage area in the non-volatile memory; and obtaining the data encryption key by decrypting the first ciphertext using the recovery key.
[0021] In this way, the user provides the recovery key to decrypt the first ciphertext and obtain the data encryption key. The method of obtaining the data encryption key is expanded.
[0022] In a possible implementation, the second ciphertext of the data encryption key is stored in a startup area of the non-volatile memory, the second ciphertext being obtained by encrypting the data encryption key using a preset first user password; and after the first ciphertext is stored in the non-encrypted storage area of the non-volatile memory, the method further includes: receiving a second user password provided by the user in response to an operation of inputting the user password; reading the second ciphertext from the startup area in the non-volatile memory; and displaying a second interface in a case where the second user password cannot decrypt the second ciphertext, the second interface being used to receive the recovery key.
[0023] Thus, the key management method provided by the present application can be used as an extension of the full-disk encryption algorithm, so that the data encryption key can be obtained by decrypting the first ciphertext and can also be obtained by decrypting the second ciphertext. In this way, the access to the data encryption key is increased, which helps to reduce the risk that the data encryption key cannot be obtained. In the case where at least one of the recovery key or the user password (and / or the hardware key) is not lost, the electronic device can successfully obtain the data encryption key after being powered on or unlocked.
[0024] In a possible implementation, the method further includes: in the case where the recovery key satisfies the verification condition, displaying a third interface, the third interface being used to receive an operation of resetting the user password; and in response to a third user password input by the user on the third interface, replacing the first user password with the third user password, the first user password being used to encrypt the data encryption key to output the second ciphertext, and / or decrypt the second ciphertext to output the data encryption key, the second ciphertext being stored in the encrypted area of the non-volatile memory.
[0025] Thus, in the case where the recovery key is correct, the resetting of the user password is triggered, which helps to improve the security in the process of resetting the user password.
[0026] In a possible implementation, in the case where the recovery key satisfies the verification condition, displaying the third interface includes: obtaining a first credential according to the recovery key, the first credential being used to determine the correctness of the recovery key provided by the user; and in the case where the first credential is the same as a second credential stored in the non-volatile memory, displaying the third interface.
[0027] By verifying whether the first credential and the second credential are consistent, it can be quickly verified whether the recovery key input by the user is correct.
[0028] In a possible implementation, the user operation is obtained from a lock screen interface, the lock screen interface being a display interface of the first electronic device in the case where the first electronic device is powered on, woken up, or requested to open the first application; or the user operation is obtained from a password resetting interface.
[0029] In a possible implementation, the number of data bits of the recovery key is greater than or equal to the number of data bits of the data encryption key.
[0030] In a second aspect, a key management method is provided, which is applied to a second electronic device and includes: in response to a user operation, receiving a recovery key; obtaining a first ciphertext of a data encryption key from a non-encrypted storage area in a non-volatile memory; and using the recovery key to decrypt the first ciphertext to obtain the data encryption key, the data encryption key being used to encrypt and / or decrypt target content data in the non-volatile memory.
[0031] By the above method, the data encryption key is encrypted by the recovery key to generate the first ciphertext of the data encryption key. Compared with the related art in which the hardware key of the electronic device is used to participate in the decryption of the data encryption key, since the hardware key of the electronic device can be engraved in the mainboard, damage or loss of the mainboard will cause loss of the hardware key, making the second ciphertext of the data encryption key difficult to decrypt, resulting in that the data encryption key cannot be obtained.
[0032] In the scheme provided in the embodiment, the first ciphertext of the data encryption key is decrypted using the recovery key, so that the process of obtaining the data encryption key does not need to use the hardware key, reducing the dependence of the data encryption key on the hardware key in the electronic device. In the case where the electronic device is damaged and the non-volatile memory is intact, the non-volatile memory can be connected to other electronic devices, and the present key management method can be executed in other electronic devices. In this way, it is helpful to improve the reliability of the data encryption key obtaining method and to avoid the loss caused by forgetting the hardware key or user password, so that the user cannot obtain the content data.
[0033] In addition, the first ciphertext of the data encryption key is stored in the non-encrypted area of the non-volatile memory, reducing the difficulty of the electronic device reading the first ciphertext of the data encryption key. At the same time, the first ciphertext of the data encryption key needs to be decrypted by the recovery key, so storing the first ciphertext of the data encryption key in the non-encrypted area will not cause the data encryption key to be leaked. In this way, the storage security of the data encryption key can be improved while ensuring that the data encryption key is obtained, thereby improving the reliability of the key management method.
[0034] In a possible implementation, the recovery key is received in response to a user operation, including: the recovery key input by the user is received in response to an operation of inputting the recovery key.
[0035] In a possible implementation, the recovery key is received in response to a user operation, including: a key acquisition request is sent to a server in response to an operation of searching for the recovery key; key data sent by the server is received; and the recovery key is acquired according to the key data.
[0036] In a possible implementation, the recovery key includes a first sub-key and a second sub-key, and the recovery key is received in response to a user operation, including: the first sub-key is received in response to a user operation; and the key data is the encrypted second sub-key.
[0037] In a possible implementation, the recovery key is acquired according to the key data, including: the recovery key is acquired by decrypting the key data according to a private key in an end-cloud key, and the end-cloud key is used to encrypt communication data between the second electronic device and the server.
[0038] In a possible implementation, before the receiving, from the server, the key data bound to the account information in response to the operation of searching for the recovery key, the method further includes: displaying a first interface, the first interface being configured to receive the account information input by the user.
[0039] In a possible implementation, the obtaining the first ciphertext of the data encryption key from the non-encrypted storage area in the non-volatile memory includes: obtaining a first file directory corresponding to the non-encrypted storage area according to a file management system used to manage the non-volatile memory, the file management system being configured to divide storage areas in the non-volatile memory, and the first file directory being configured to index data stored in the non-encrypted storage area; and reading the first ciphertext from at least one file stored in the first file directory.
[0040] In a possible implementation, the non-volatile memory stores a second ciphertext of the data encryption key, the second ciphertext being obtained by encrypting the data encryption key by using a preset first user password; and before the receiving the recovery key in response to the user operation, the method further includes: in response to an operation of inputting the user password, receiving a second user password provided by the user; obtaining the second ciphertext of the data encryption key from a startup area in the non-volatile memory; and in a case where the second user password fails to decrypt the second ciphertext, displaying a second interface, the second interface being configured to receive the recovery key.
[0041] In a possible implementation, the non-volatile memory is a non-volatile memory installed in the second electronic device, or the non-volatile memory is a non-volatile memory detached from another electronic device and having a data transmission channel with the second electronic device.
[0042] In a possible implementation, after the receiving the recovery key in response to the user operation, the method further includes: in a case where the recovery key satisfies a verification condition, displaying a third interface, the third interface being configured to receive an operation of resetting the user password; and in response to a third user password input by the user on the third interface, replacing the first user password by the third user password, the first user password being used to encrypt the data encryption key to output the second ciphertext and / or to decrypt the second ciphertext to output the data encryption key, the second ciphertext being stored in the encrypted area of the non-volatile memory.
[0043] In a possible implementation, the displaying the third interface in a case where the recovery key satisfies the verification condition includes: obtaining a first credential according to the recovery key, the first credential being used to determine correctness of the recovery key provided by the user; and in a case where the first credential is identical to a second credential stored in the non-volatile memory, displaying the third interface.
[0044] In a possible implementation, the user operation is obtained from a lock screen interface, and the lock screen interface is a display interface of the second electronic device in a case where the second electronic device is powered on, wakes up, or requests to open the first application; or the user operation is obtained from a password resetting interface.
[0045] In a third aspect, a first electronic device is provided. The first electronic device includes at least one processor and a memory. The at least one processor is configured to execute instructions stored in the memory, so that the electronic device performs the method in the first aspect and any possible implementation of the first aspect. The first electronic device displays the recovery key in response to the operation of requesting to generate the recovery key; encrypts the data encryption key using the recovery key to obtain first ciphertext of the data encryption key, the data encryption key being used to encrypt and / or decrypt target content data in the non-volatile memory; and stores the first ciphertext to a non-encrypted storage area of the non-volatile memory.
[0046] In a possible implementation, when the processor reads the computer instructions from the memory, the first electronic device further performs: in response to an account login operation, sending account information to the server; and in response to a key binding operation, sending a key binding request to the server, the key binding request carrying key data, the key data being the encrypted recovery key, and the key binding request being used to request to bind the account information and the recovery key.
[0047] In a possible implementation, when the processor reads the computer instructions from the memory, the first electronic device further performs: obtaining an end-to-cloud key, the end-to-cloud key being used to encrypt communication data between the first electronic device and the server; and encrypting the recovery key according to a public key in the end-to-cloud key to obtain the key data.
[0048] In a possible implementation, the recovery key includes a first sub-key and a second sub-key; and displaying the recovery key in response to the operation of requesting to generate the recovery key includes: displaying the first sub-key; the key data is the encrypted second sub-key; and the key binding request is used to request to bind the account information and the second sub-key.
[0049] In a possible implementation, when the processor reads the computer instructions from the memory, the first electronic device further performs: obtaining a first credential according to the recovery key, the first credential being used to identify the recovery key; and storing the first credential in the non-volatile memory.
[0050] In a possible implementation, when the processor reads the computer instructions from the memory, the first electronic device further performs: receiving the recovery key in response to a user operation; reading the first ciphertext from the non-encrypted storage area in the non-volatile memory; and decrypting the first ciphertext using the recovery key to obtain the data encryption key.
[0051] In a possible implementation, the second ciphertext of the data encryption key is stored in a startup area of the non-volatile memory, and the second ciphertext is obtained by encrypting the data encryption key by using a preset first user password; when the processor reads the computer instructions from the memory, the first electronic device further performs: in response to the operation of inputting the user password, receiving a second user password provided by the user; reading the second ciphertext from the startup area of the non-volatile memory; and in a case where the second user password cannot decrypt the second ciphertext, displaying a second interface, the second interface being configured to receive a recovery key.
[0052] In a possible implementation, when the processor reads the computer instructions from the memory, the first electronic device further performs: in a case where the recovery key satisfies a verification condition, displaying a third interface, the third interface being configured to receive an operation of resetting the user password; and in response to a third user password input by the user on the third interface, replacing the first user password by the third user password, the first user password being configured to encrypt the data encryption key to output the second ciphertext and / or decrypt the second ciphertext to output the data encryption key, the second ciphertext being stored in the encryption area of the non-volatile memory.
[0053] In a possible implementation, in a case where the recovery key satisfies the verification condition, displaying the third interface includes: obtaining a first credential according to the recovery key, the first credential being configured to determine the correctness of the recovery key provided by the user; and in a case where the first credential is same as a second credential stored in the non-volatile memory, displaying the third interface.
[0054] In a possible implementation, the user operation is obtained from a lock screen interface, the lock screen interface being a display interface of the first electronic device in a case where the first electronic device is powered on, wakes up, or requests to open a first application.
[0055] In a possible implementation, a data bit number of the recovery key is greater than or equal to a data bit number of the data encryption key.
[0056] In a fourth aspect, a second electronic device is provided. The second electronic device includes at least one processor and a memory, and the at least one processor is configured to execute instructions stored in the memory, so that the second electronic device performs the method in the second aspect and any possible implementation of the second aspect. The second electronic device receives a recovery key in response to a user operation; obtains a first ciphertext of a data encryption key from a non-encrypted storage area of a non-volatile memory; and decrypts the first ciphertext by using the recovery key to obtain the data encryption key, the data encryption key being configured to encrypt and / or decrypt target content data in the non-volatile memory.
[0057] In a possible implementation, the receiving the recovery key in response to the user operation comprises: in response to an operation of inputting the recovery key, receiving the recovery key input by the user.
[0058] In a possible implementation, the receiving the recovery key in response to the user operation comprises: in response to an operation of searching for the recovery key, sending a key acquisition request to the server; receiving key data sent by the server; and acquiring the recovery key according to the key data.
[0059] In a possible implementation, the recovery key comprises a first sub-key and a second sub-key, and the receiving the recovery key in response to the user operation comprises: receiving the first sub-key in response to the user operation; and the key data is the encrypted second sub-key.
[0060] In a possible implementation, the acquiring the recovery key according to the key data comprises: decrypting the key data according to a private key in an end-cloud key, and acquiring the recovery key, the end-cloud key being used to encrypt communication data between the second electronic device and the server.
[0061] In a possible implementation, when the processor reads the computer instruction from the memory, the second device further performs: displaying a first interface, the first interface being used to receive account information input by the user.
[0062] In a possible implementation, the acquiring the first ciphertext of the data encryption key from the non-encrypted storage area in the non-volatile memory comprises: acquiring a first file directory corresponding to the non-encrypted storage area according to a file management system used to manage the non-volatile memory, the file management system being used to divide storage areas in the non-volatile memory, and the first file directory being used to index data stored in the non-encrypted storage area; and reading the first ciphertext from at least one file stored in the first file directory.
[0063] In a possible implementation, the non-volatile memory stores a second ciphertext of the data encryption key, the second ciphertext being obtained by encrypting the data encryption key by using a preset first user password; when the processor reads the computer instruction from the memory, the electronic device further performs: in response to an operation of inputting the user password, receiving a second user password provided by the user; acquiring the second ciphertext of the data encryption key from a startup area in the non-volatile memory; and in a case where the second user password cannot decrypt the second ciphertext, displaying a second interface, the second interface being used to receive a recovery key.
[0064] In a possible implementation, the non-volatile memory is a non-volatile memory installed in the second electronic device, or the non-volatile memory is a non-volatile memory detached from another electronic device and having a data transmission channel with the second electronic device.
[0065] In a possible implementation, when the processor reads the computer instructions from the memory, the second electronic device further performs: in a case where the recovery key satisfies the verification condition, displaying a third interface, the third interface being configured to receive an operation of resetting the user password; and in response to a third user password input by a user on the third interface, replacing the first user password with the third user password, the first user password being used to encrypt the data encryption key to output second ciphertext, and / or decrypt the second ciphertext to output the data encryption key, the second ciphertext being stored in the encrypted area of the non-volatile memory.
[0066] In a possible implementation, in a case where the recovery key satisfies the verification condition, displaying the third interface comprises: obtaining a first credential according to the recovery key, the first credential being used to determine the correctness of the recovery key provided by the user; and in a case where the first credential is the same as a second credential stored in the non-volatile memory, displaying the third interface.
[0067] In a possible implementation, the user operation is obtained from a lock screen interface, the lock screen interface being a display interface of the second electronic device in a case where the second electronic device is powered on, wakes up, or requests to open the first application; or the user operation is obtained from a password resetting interface.
[0068] In a fifth aspect, a computer readable storage medium is provided, and the computer readable storage medium stores computer program instructions. The computer program instructions are executed by a processing circuit to implement the method in any possible implementation of the first aspect or the method in any possible implementation of the second aspect.
[0069] In a sixth aspect, a chip system is provided, and the chip system comprises a processing circuit and a storage medium. The storage medium stores computer program instructions. The computer program instructions are executed by the processing circuit to implement the method in any possible implementation of the first aspect or the method in any possible implementation of the second aspect.
[0070] In a seventh aspect, a computer program product containing instructions is provided, and when the computer program product is run on a computer, the computer is caused to execute the method in any possible implementation of the first aspect or the method in any possible implementation of the second aspect.
[0071] The technical effects of any possible implementation of the third aspect to the seventh aspect can refer to the technical effects of the first aspect and any possible implementation of the first aspect, or refer to the technical effects of the second aspect and any possible implementation of the second aspect, which will not be described herein again. BRIEF DESCRIPTION OF DRAWINGS
[0072] FIG. 1 is a system schematic diagram of a communication system provided by an embodiment of the present application;
[0073] FIG. 2 is a schematic diagram of a first electronic device and a second electronic device provided by an embodiment of the present application, wherein the first electronic device and the second electronic device are different electronic devices, and the first electronic device and the second electronic device share a non-volatile memory;
[0074] FIG. 3 is a schematic diagram of a structure of the first electronic device 100 or the second electronic device 300 provided by an embodiment of the present application;
[0075] FIG. 4 is a schematic diagram of a structure of the server 200 provided by an embodiment of the present application;
[0076] FIG. 5A is a schematic diagram of a functional module provided by an embodiment of the present application;
[0077] FIG. 5B is a schematic diagram of a layered software architecture provided by an embodiment of the present application;
[0078] FIG. 6 is a schematic diagram of a flow of a key management method provided by an embodiment of the present application;
[0079] FIG. 7 is a schematic diagram of a scenario of a reply key creation process provided by an embodiment of the present application;
[0080] FIG. 8 is a schematic diagram of a flow of a recovery key saving process provided by an embodiment of the present application;
[0081] FIG. 9 is a schematic diagram of division of a recovery key provided by an embodiment of the present application;
[0082] FIG. 10 is a schematic diagram of a flow of a credential generation process provided by an embodiment of the present application;
[0083] FIG. 11 is a schematic diagram of interaction of functional modules in a data encryption key encryption process provided by an embodiment of the present application;
[0084] FIG. 12 is a schematic diagram of a flow of a key management method provided by an embodiment of the present application;
[0085] FIG. 13 is a schematic diagram of display of an interface switching process provided by an embodiment of the present application;
[0086] FIG. 14 is a schematic diagram of interaction of functional modules in an execution process of a key management method provided by an embodiment of the present application;
[0087] FIG. 15 is a schematic diagram of a flow of a key management method combined with a full-disk encryption method provided by an embodiment of the present application;
[0088] FIG. 16 is a schematic diagram of a scenario of a key management method provided by an embodiment of the present application;
[0089] FIG. 17 is a schematic diagram of a scenario of a key management method provided by an embodiment of the present application;
[0090] FIG. 18 is a schematic diagram of a flow of a key management method provided by an embodiment of the present application;
[0091] FIG. 19 is a fourth flow diagram of a key management method according to an embodiment of the present application;
[0092] FIG. 20 is a diagram of a scenario of resetting a user password according to a recovery key according to an embodiment of the present application;
[0093] FIG. 21 is a diagram of interaction of functional modules in a password resetting process according to an embodiment of the present application;
[0094] FIG. 22 is a diagram of a structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0095] The technical solutions in the embodiments of the present application will be described below with reference to the drawings.
[0096] In the description of the embodiments of the present application, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but optionally further includes other steps or units not listed or optionally further includes other steps or units inherent to the process, method, product or device.
[0097] Hereinafter, the terms "first", "second", and the like are used only for the purpose of description, and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second", and the like can explicitly or implicitly include one or more of the features.
[0098] In the embodiments of the present application, the words "exemplarily" or "for example" are used to represent an example, illustration or description. Any embodiment or design scheme described as "exemplarily" or "for example" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the words "exemplarily" or "for example" are used to present the relevant concept in a specific manner.
[0099] In the description of the embodiments of the present application, the meaning of "a plurality of" is two or more, unless otherwise specified. In this document, "and / or" is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the three cases of A alone, A and B together, and B alone.
[0100] With the development and popularity of electronic devices, electronic devices are widely used in all aspects of user life. Content data will be generated in the process of user using electronic devices, and protecting the use safety and storage safety of content data is a key link that cannot be ignored in the process of using electronic devices. Generally, content data needs to be protected by using a data encryption algorithm to avoid content data leakage. For example, electronic devices protect content data by full-disk encryption, setting user passwords and the like.
[0101] In a possible implementation, a file safe is arranged in the operating system of the electronic device, and the file safe is a built-in encryption function in the electronic device, which is used to securely protect static data. For example, the file safe uses an AES-XTS data encryption algorithm to protect content data stored in the electronic device. Optionally, the keys required by the data encryption algorithm include at least one of the following: a user password and a hardware key. The user password includes but is not limited to a lock screen password set by the user, an application password and the like. The hardware key is information engraved in the hardware of the electronic device. For example, the hardware key is information engraved on the motherboard.
[0102] In a case where content data stored in the file safe needs to be obtained, the user inputs a user password; a security chip decrypts the ciphertext of the data encryption key according to the hardware key and / or the user password, obtains the data encryption key, and decrypts the ciphertext of the content data stored in the file safe using the data encryption key to obtain decrypted content data.
[0103] Since the ciphertext of the data encryption key needs to be decrypted using the hardware key and / or the user password, in a case where the hardware key cannot be obtained due to damage of the device motherboard or the user password is forgotten, the ciphertext of the data encryption key cannot be decrypted. This makes the data encryption key unable to be normally obtained, and further causes the ciphertext of the content data in the non-volatile memory to be unable to be decrypted by the data encryption key, affecting normal reading and use of the content data.
[0104] Based on the above problems, the present application provides a key management method, which displays a recovery key in response to a request for generating the recovery key; encrypts a data encryption key using the recovery key to obtain a first ciphertext of the data encryption key, the data encryption key being used to encrypt and / or decrypt target content data in a non-volatile memory; and stores the first ciphertext to a non-encrypted storage area of the non-volatile memory.
[0105] By the method, the data encryption key is encrypted by the recovery key to generate the first ciphertext of the data encryption key. Compared with the related art in which the hardware key of the electronic device is used to participate in decryption of the data encryption key, since the hardware key of the electronic device can be engraved in the mainboard, damage or loss of the mainboard can cause loss of the hardware key, so that the second ciphertext of the data encryption key is difficult to decrypt, and the data encryption key cannot be obtained.
[0106] In the scheme provided in the embodiment, the first ciphertext of the data encryption key is decrypted by the recovery key, so that the process of obtaining the data encryption key does not need to use the hardware key, and the dependence of the data encryption key on the hardware key of the electronic device is reduced. In the case where the electronic device is damaged and the non-volatile memory is intact, the non-volatile memory can be connected to other electronic devices, and the key management method is executed in the other electronic devices. In this way, the reliability of the data encryption key obtaining mode is improved, and loss of the hardware key or user password is avoided, so that the loss of the user caused by the unobtainable content data is avoided.
[0107] In addition, the first ciphertext of the data encryption key is stored in the non-encrypted area of the non-volatile memory, which reduces the difficulty of reading the first ciphertext of the data encryption key by the electronic device. At the same time, the first ciphertext of the data encryption key needs to be decrypted by the recovery key, so storing the first ciphertext of the data encryption key in the non-encrypted area will not cause leakage of the data encryption key. In this way, the storage security of the data encryption key is improved while the data encryption key is obtained, so that the reliability of the key management method is improved.
[0108] In some embodiments, the key management scheme provided in the embodiments of the present application can be implemented as a supplement to the full-disk encryption method. In some full-disk encryption methods, before the electronic device is powered off or locked, the content data needs to be encrypted by the data encryption key to obtain the ciphertext of the content data, and the ciphertext of the content data is stored in the non-volatile memory. Optionally, the data encryption key is encrypted by the hardware key and / or the user password of the electronic device to obtain the second ciphertext of the data encryption key. The second ciphertext is stored in the startup area of the non-volatile memory. In the case where the data encryption key needs to be obtained, the second ciphertext is decrypted by the security chip in the electronic device according to the hardware key and / or the user password to obtain the data encryption key.
[0109] It can be seen that the second key in the full-disk encryption method and the first key generated by the key management method provided in the embodiments of the present application have different decryption methods and storage areas. Therefore, the full-disk encryption method is supplemented by the present scheme, which helps to expand the data encryption key obtaining approach.
[0110] In a possible implementation, in a case where the data encryption key cannot be obtained by decrypting the second ciphertext, the electronic device decrypts the first ciphertext of the data encryption key by using the key management method to obtain the data encryption key. That is, the key management method provided in the present application can be used as an extension of the full-disk encryption algorithm, so that the data encryption key can be obtained by decrypting the first ciphertext and by decrypting the second ciphertext. In this way, the obtaining approach of the data encryption key is increased, which helps to reduce the risk that the data encryption key cannot be obtained. In a case where at least one of the recovery key or the user password (and / or the hardware key) is not lost, the electronic device can successfully obtain the data encryption key after the electronic device is started or unlocked.
[0111] It can be seen that the scheme provided in the embodiment helps to ensure the stability of successfully obtaining the data encryption key in various use environments, and helps to avoid the problem that the content data cannot be read due to the data encryption key being unable to be obtained, and the use experience of the user is affected.
[0112] The following describes a communication system to which the key management method provided in the embodiments of the present application is applied. FIG. 1 is a schematic diagram of a communication system to which the key management method provided in the embodiments of the present application is applied. As shown in FIG. 1, the communication system includes a first electronic device 100.
[0113] In some embodiments, the first electronic device 100 is also referred to as at least one of an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile terminal, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device.
[0114] The first electronic device 100 in the embodiments of the present application includes, but is not limited to, a mobile phone, a personal computer, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a vehicle-mounted terminal, a road side unit (RSU) with terminal function, and the like.
[0115] Optionally, the operating system installed in the first electronic device 100 includes, but is not limited to or other operating systems.
[0116] As shown in FIG. 1, the communication system can further include at least one of a server 200 and a second electronic device 300. Among them, the first electronic device 100 included in the communication system participates in the encryption process of the data encryption key; the second electronic device 300 participates in the decryption process of the data encryption key. The server 200 can provide a user with a service for storing a recovery key used for encrypting and / or decrypting the data encryption key.
[0117] In some embodiments, the server 200 is a cloud server or a network server or other device or server with computing functions. The above-mentioned server can be a server, a server cluster composed of multiple servers, or a cloud computing data center. The server 200 can be a server of the operating system corresponding to the first electronic device 100 or the second electronic device 300, or a background server of a third-party application installed in the first electronic device 100 or the second electronic device 300. Optionally, the third-party application includes, but is not limited to, a cloud storage application, a social application, etc.
[0118] In some embodiments, the second electronic device 300 includes the first electronic device 100. For example, the second electronic device 300 and the first electronic device 100 are the same electronic device. For another example, the second electronic device 300 is another electronic device different from the first electronic device 100. In this case, the first electronic device 100 and the second electronic device 300 perform corresponding operations based on the same non-volatile memory.
[0119] FIG. 2 is a schematic diagram of the first electronic device and the second electronic device being different electronic devices but sharing the non-volatile memory according to an embodiment of the present application. As shown in FIG. 2, the first electronic device 100 is installed with the non-volatile memory 101. In the case that the mainboard or other hardware of the first electronic device 100 is damaged, the non-volatile memory 101 can be unloaded from the first electronic device 100; then, the user connects the non-volatile memory 101 with the second electronic device 300, so that the second electronic device 300 can read the data stored in the non-volatile memory 101, thereby realizing the key management method provided in the embodiment.
[0120] The structures of the first electronic device 100 and the second electronic device 300 are described below. For ease of understanding, refer to FIG. 3, which shows a structural schematic diagram of the first electronic device 100 or the second electronic device 300. Optionally, the first electronic device 100 and the second electronic device 300 have similar structures. The structure of the electronic device is described by taking the first electronic device 100 as an example. As shown in FIG. 3, the first electronic device 100 includes a processor 110, a memory 120, a communication module 130, and a display screen 140.
[0121] The processor 110 can include one or more processing units. For example, the processor 110 includes at least one of an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices or integrated in one or more processors.
[0122] The memory 120 includes an external memory and an internal memory, and the internal memory can be used to store computer executable program codes. The executable program codes include instructions. The processor 110 executes various function applications and data processing of the first electronic device 100 by running the instructions stored in the internal memory. Exemplarily, the internal memory includes a program storage area and a data storage area. The memory 120 can be arranged in the processor 110 to store instructions and data. The external memory refers to a memory card connected to the first electronic device 100 through an external memory interface.
[0123] Optionally, the memory 120 includes a non-volatile memory for saving user data generated in the process of using the first electronic device 100 by a user and ciphertext of a data encryption key. The non-volatile memory refers to a memory capable of storing data for a long time. The non-volatile memory can ensure that the data stored therein is not lost after power failure. Exemplarily, the type of the non-volatile memory includes at least one of a flash memory, a solid state drive (SSD), a hybrid hard drive (HHD), and a hard disk drive (HDD). For example, the non-volatile memory is a detachable solid state drive in the first electronic device.
[0124] Exemplarily, the non-volatile memory is installed inside the first electronic device 100, and the non-volatile memory in the first electronic device 100 is detachable. Exemplarily, the non-volatile memory is connected with the data reading interface on the bus of the first electronic device 100 through a connecting line.
[0125] The communication module 130 is configured to implement the communication function of the first electronic device 100. Optionally, the communication module 130 includes an antenna, a mobile communication module, a wireless communication module, a modem processor, a baseband processor and the like. Optionally, at least part of the functions of the mobile communication module can be arranged in the processor. The wireless communication module is configured to support the first electronic device 100 to perform wireless communication.
[0126] The first electronic device 100 implements the display function through the GPU, the display screen 140 and the like. The display screen 140 is configured to display images, videos and the like. In some embodiments, the first electronic device 100 can include one or N display screens 140, and N is a positive integer greater than 1. The GPU and the display screen 140 can be configured to support the first electronic device 100 to display system tools or application programs.
[0127] The structure of the second electronic device 300 will be described in detail with reference to the structure of the first electronic device 100. It can be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the first electronic device 100 or the second electronic device 300. In some other embodiments of the present application, the first electronic device 100 or the second electronic device 300 can include more or fewer components than those illustrated, or combine some components, or split some components, or different arrangement of components. The components illustrated can be implemented in hardware, software or a combination of software and hardware.
[0128] Exemplarily, FIG. 4 is a structure diagram of the server 200 provided by the present application. As shown in FIG. 4, the server 200 includes at least one processor 401, a communication line 402, a memory 403 and at least one communication interface 404. The memory 403 can also be included in the processor 401.
[0129] The processor 401 includes but is not limited to a general central processing unit (CPU), a microprocessor, an application specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of programs of the present application.
[0130] The communication line 402 can include at least one channel for transmitting information between the above components.
[0131] The memory 403 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to this. The memory 403 can exist independently and be connected to the processor 401 through the communication line 402. The memory 403 can also be integrated with the processor 401.
[0132] The memory 403 is configured to store computer-executed instructions for implementing the solutions of the present application, and the processor 401 is configured to control the execution of the computer-executed instructions stored in the memory 403. The processor 401 is configured to execute the computer-executed instructions stored in the memory 403, so as to implement the key management method provided in the following embodiments of the present application.
[0133] The communication interface 404 is configured to communicate with other devices. In the embodiments of the present application, the communication interface 404 can be a module, a circuit, a bus, an interface, a transceiver or other device capable of realizing the communication function. Optionally, when the communication interface 404 is a transceiver, the transceiver can be a separately arranged transmitter, which can be used to send information to other devices. The transceiver can also be a separately arranged receiver, which can be used to receive information from other devices. The transceiver can also be a component integrating the functions of sending and receiving information. The specific implementation of the transceiver is not limited in the embodiments of the present application.
[0134] Optionally, the computer-executed instructions in the embodiments of the present application can also be referred to as application program codes, instructions, computer programs or other names, which are not limited in the embodiments of the present application.
[0135] In a particular implementation, as an example, the processor 401 can include one or more CPUs, such as CPU0 and CPU1 in FIG. 4. In a particular implementation, as an example, the server 200 can include multiple processors, such as the processor 401 and the processor 407 in FIG. 4. Each of these processors can be a single-CPU processor or a multi-CPU processor. A processor here can refer to one or more devices, circuits, and / or processing cores for processing data, such as computer program instructions.
[0136] It can be understood that the structure as shown in FIG. 4 does not constitute a specific limitation on the implementation of the structure of the server 200. In other embodiments of the present application, the server 200 can include more or fewer components than shown, or combine certain components, or split certain components, or different arrangement of components. The components shown can be implemented in hardware, software, or a combination of software and hardware.
[0137] In a possible implementation, the key management method provided in the present application is implemented by at least one functional module in the first electronic device 100 and / or the second electronic device 300. The types and functions of the functional modules are introduced below by taking the first electronic device 100 as an example. As shown in FIG. 5A, the software functional modules in the first electronic device 100 provided in the embodiments of the present application at least include a recovery key management module and a file encryption module.
[0138] The file encryption module is configured to provide protection services for content data generated in the running process of the first electronic device 100. Optionally, the file encryption module is configured to encrypt the content data according to the data encryption key to obtain the ciphertext of the content data in the case of needing to protect the content data. The file encryption module is further configured to decrypt the ciphertext of the content data according to the data encryption key to obtain the content data.
[0139] Optionally, the file encryption module is further configured to generate a recovery key and encrypt the data encryption key using the recovery key to obtain the first ciphertext of the data encryption key.
[0140] The recovery key management module is configured to provide management services for the recovery key. Optionally, the recovery key management module is configured to display the recovery key in response to a user operation. The recovery key management module is further configured to store the first ciphertext of the data encryption key. The recovery key is configured to protect the data encryption key.
[0141] In one example, in the process of generating the recovery key, the file encryption module generates the recovery key and the first ciphertext; the file encryption module sends the recovery key to the recovery key management module, so that the recovery key management module displays the recovery key to the user and stores the first ciphertext in the non-encryption area of the non-volatile memory. Subsequently, the recovery key can be kept by the user or bound with the user's account information for storage in the server. In the case of needing to use the recovery key, the user provides the recovery key through user operation.
[0142] In one example, in the process of decrypting the data encryption key using the recovery key, the recovery key management module receives the recovery key through user operation and reads the first ciphertext from the non-encryption area of the non-volatile memory; the file encryption module acquires the first ciphertext and the recovery key through the recovery key management module; the file encryption module decrypts the first ciphertext using the recovery key to obtain the data encryption key.
[0143] Optionally, the functional modules in the first electronic device 100 further include at least one of the following: a hardware key reading module, a password management module, and a key management module.
[0144] The hardware key reading module is configured to read the hardware key from the hardware of the first electronic device 100. In some embodiments, the hardware key is engraved on the hardware of the electronic device. For example, the hardware key is engraved on the mainboard of the first electronic device 100. Optionally, the hardware key reading module reads the hardware key in the mainboard and provides the hardware key to the key management module, so that the key management module encrypts the data encryption key based on the hardware key.
[0145] The password management module is configured to provide management services for the user password set by the user. Optionally, the user password includes but is not limited to: a lock screen password, an application password, and the like. The lock screen password is used to restore the first electronic device 100 from the lock screen state to the working state; the application password is used to unlock the application of the first electronic device, so that the first electronic device 100 displays the user interface of the application. Illustratively, the password management module is configured to generate identity authentication information according to the user password, and determine whether the user can unlock the first electronic device 100 or the application in the first electronic device through the identity authentication information.
[0146] Optionally, the password management module is configured to provide the user password input by the user to the key management module, so that the key management module encrypts the data encryption key based on the hardware key.
[0147] Optionally, the password management module is configured to provide the user password to the key management module to trigger the key management module to use the user password to unlock the second ciphertext or trigger the key management module to encrypt the data encryption key using the user password to obtain the second ciphertext, in the case of determining that the user password is correct.
[0148] The key management module is configured to generate a data encryption key. In some examples, the key management module sends the data encryption key to the file encryption module after the data encryption key is generated, to trigger the file encryption module to encrypt the content data by using the data encryption key. In other examples, the key management module sends the data encryption key to the file encryption module after the data encryption key is generated, to trigger the file encryption module to encrypt the data encryption key by using the recovery key to output the first ciphertext. In yet other examples, the key management module encrypts the data encryption key by using the user password and / or the hardware key after the data encryption key is obtained, to output the second ciphertext.
[0149] In the embodiments of the present application, the key management method is cooperatively completed by a plurality of functional modules. The interaction logic between the functional modules will be described below.
[0150] In some embodiments, the file encryption module, the recovery key management module, the password management module, the hardware key reading module, and the key management module are arranged in the application program framework layer in the software layered architecture of the first electronic device 100 and the second electronic device 300.
[0151] As shown in FIG. 5B, the layered architecture divides the software into several layers, and each layer has a clear role and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the operating system is divided into four layers, from top to bottom, the application program layer, the application program framework layer, the TS (arkts runtime) runtime and the system library, and the kernel layer.
[0152] The application program layer includes a series of applications. For example, the applications include telephone, short message, photo album, video player, and the like. The application program framework layer provides the application program of the application program layer with an application programming interface (application programming interface, API) and a programming framework. The application program framework layer includes some pre-defined functions.
[0153] The window manager is configured to manage the window program. The window manager can obtain the size of the display screen, determine whether there is a status bar, lock the screen, and intercept the screen, and the like.
[0154] The system library can include a plurality of functional modules. For example, the surface manager, the media library, the three-dimensional graphics processing library (for example, OpenGL ES), the two-dimensional graphics engine, and the like.
[0155] The surface manager is used to manage the display subsystem and provides a fusion of two-dimensional (2D) and three-dimensional (3D) layers for multiple applications.
[0156] The media library supports playback and recording of a plurality of commonly used audio, video formats, and static image files, etc. The media library can support a plurality of audio and video encoding formats, such as: moving picture experts group 4 (MPEG4), high efficiency video coding (H.264), moving picture experts group audio layer III (MP3), advanced audio coding (AAC), adaptive multi rate (AMR), joint photographic experts group (JPG), portable network graphics (PNG), etc.
[0157] The three-dimensional graphics processing library is used to implement three-dimensional graphics drawing, image rendering, synthesis, and layer processing, etc. The two-dimensional graphics engine is a drawing engine for 2D drawing.
[0158] The key management method is described below through several embodiments. Optionally, the data encryption key encryption process and the data encryption key decryption process are supported to be performed by the same electronic device. Alternatively, the data encryption key encryption process and the data encryption key decryption process are supported to be performed by different electronic devices. In order to clearly describe, in the following embodiments, the first electronic device is used as the execution subject of the data encryption key encryption process, and the second electronic device is used as the execution subject of the data encryption key decryption process.
[0159] The key management method is described below through several embodiments. Optionally, the data encryption key encryption process and the data encryption key decryption process are supported to be performed by the same electronic device. Alternatively, the data encryption key encryption process and the data encryption key decryption process are supported to be performed by different electronic devices. In order to clearly describe, in the following embodiments, the first electronic device is used as the execution subject of the data encryption key encryption process, and the second electronic device is used as the execution subject of the data encryption key decryption process.
[0160] In step S610, the first electronic device displays the recovery key in response to a request for generating the recovery key.
[0161] Optionally, the recovery key is used to protect a data encryption key. The data encryption key is a key used to protect content data in the first electronic device. The data encryption key is also referred to as an encryption key.
[0162] In the key management method provided in this embodiment, the recovery key is generated by the first electronic device, and the manner of storing the recovery key is determined by a user of the first electronic device. For example, the manner of storing the recovery key is determined by the user personally.
[0163] Optionally, the data encryption key is generated by the first electronic device. Optionally, for different users using the same first electronic device, the data encryption keys corresponding to the different users respectively can be the same or different.
[0164] For example, in a case where a device usage account is used by a user to log in to the first electronic device for the first time, the first electronic device generates a data encryption key corresponding to the device usage account, and uses the data encryption key to perform encrypted storage on content data generated by the user in the first electronic device. The embodiments herein are described by taking one encryption key in the first electronic device as an example.
[0165] Optionally, the recovery key is a key used in a symmetric encryption algorithm. That is, the encryption and decryption of the data encryption key can be completed by using the recovery key. For example, the first electronic device encrypts the data encryption key by using the recovery key to obtain first ciphertext of the data encryption key. The first ciphertext is encrypted data of the data encryption key. For another example, the first electronic device decrypts the first ciphertext by using the recovery key to obtain the data encryption key.
[0166] Optionally, the operation of requesting to generate the recovery key is triggered by a user using the first electronic device. For example, the operation of requesting to generate the recovery key includes at least one of the following: a click operation, a double-click operation, a long-press operation, a sliding operation, a key operation, a gesture operation, a voice operation, and the like. For example, the operation of requesting to generate the recovery key is implemented as an operation of clicking a key generation button. For example, the first electronic device generates and displays the recovery key in response to the operation of clicking the key generation button.
[0167] Optionally, the operation of requesting to generate the recovery key is triggered by a user using the first electronic device. For example, the operation of requesting to generate the recovery key includes at least one of the following: a click operation, a double-click operation, a long-press operation, a sliding operation, a key operation, a gesture operation, a voice operation, and the like. For example, the operation of requesting to generate the recovery key is implemented as an operation of clicking a key generation button. For example, the first electronic device generates and displays the recovery key in response to the operation of clicking the key generation button.
[0168] FIG. 7 is a schematic diagram of a scenario of a recovery key creation process provided in an embodiment of the present application. As shown in FIG. 7, a user performs an operation of requesting to generate a recovery key; and the first electronic device generates the recovery key in response to the operation of requesting to generate the recovery key. Optionally, the first electronic device can also display the recovery key in a key display interface 710.
[0169] In some embodiments, the first electronic device randomly generates the recovery key in response to the operation of requesting to generate the recovery key. Optionally, the recovery key is a string of random numbers. For example, the first electronic device randomly generates a 256-bit random number as the recovery key in response to the operation of requesting to generate the recovery key.
[0170] In some embodiments, the data bit number of the recovery key is greater than or equal to the data bit number of the data encryption key. For example, the data encryption key is 128 bits, and the recovery key is 256 bits. For another example, the data encryption key is 128 bits, and the recovery key is 128 bits.
[0171] Optionally, in the process of generating the recovery key, the first electronic device determines the data bit number of the recovery key according to the data bit number of the data encryption key.
[0172] For example, the first electronic device obtains a first value in response to the operation of requesting to generate the recovery key. The first value is the data bit number of the data encryption key. The first electronic device determines a second value according to the first value. The second value is the data bit number of the recovery key. Then, the first electronic device randomly generates the recovery key with the length of the second value.
[0173] By setting the data bit number of the recovery key to be greater than or equal to the data bit number of the data encryption key, the difficulty of cracking the first ciphertext obtained by encrypting the data encryption key with the recovery key is increased, thereby ensuring the security of the first ciphertext.
[0174] In some embodiments, the first electronic device randomly generates the recovery key in the data sequence format, and the first electronic device displays the recovery key in the data sequence format. Optionally, the recovery key in the data sequence format is a string of random numbers.
[0175] In some other embodiments, the first electronic device converts the format of the recovery key to generate the recovery key in the first data format, so as to facilitate the user to observe and / or input the recovery key. The following describes the process of converting the data format of the recovery key through several embodiments.
[0176] In some embodiments, the first electronic device displays the recovery key in the first data format. Optionally, the first electronic device generates the recovery key in the data sequence format in response to the operation of requesting to generate the recovery key; the first electronic device converts the recovery key in the data sequence format to the recovery key in the first data format; and the first electronic device displays the recovery key in the first data format.
[0177] The first data format is a data format obtained after data format conversion. Optionally, the recovery key of the first data format is composed of at least one of the following elements: a number, a lowercase letter, an uppercase letter, and a punctuation mark. The punctuation mark includes at least one of the following: +, =, / , and the like.
[0178] For example, the recovery key of the first data format includes a plurality of sequence groups, each sequence group includes an equal number of elements, and adjacent sequence groups are connected by "-". For example, the recovery key of a certain first data format is represented as: wf9+-x6ls-Fwn9-D6FW-Bsfs-ykHp-m8Kr-afz7-Dxxx-LhxC-4Tg=. In this example, "wf9+" represents a sequence group, "x6ls" represents a sequence group, and so on.
[0179] In one example, after the first electronic device randomly generates the recovery key, the first electronic device divides the numbers in the recovery key of the data sequence format into a plurality of number groups. For each number group in the plurality of number groups, the first electronic device converts the numbers into binary numbers through a base conversion. The first electronic device divides the binary number groups into a plurality of binary subgroups. For each binary subgroup in the plurality of binary subgroups, the first electronic device expands the binary bits included in the binary subgroup to obtain an expanded binary subgroup. The first electronic device determines the elements corresponding to the expanded binary subgroup according to the format coding table. The electronic device composes the recovery key of the first data format according to the elements corresponding to each binary subgroup.
[0180] In this example, the plurality refers to two or more than two, and the recovery key of the data sequence format is a string of random numbers. For example, the format coding table is used to indicate the elements corresponding to the binary subgroup. For example, the format coding table includes a Base coding table.
[0181] For example, the recovery key of the data sequence format is [1, 2, 3, 4,...], and the first electronic device divides the recovery key of the data sequence format into a plurality of element groups. In the following, the first element group in the plurality of element groups is taken as an example to introduce the data format conversion process.
[0182] Suppose that the first element group includes: 1, 2, 3. Wherein, "1" is represented by 8 bits of binary under the American Standard Code for Information Interchange (ASCII), and the first element group has a binary bit number of 24 bits. Subsequently, the first electronic device divides the element group by binary bits to obtain 3 binary subgroups. Wherein, each binary subgroup is 6 bits. For each binary subgroup, the first electronic device adds two 0s to the high bits of the binary subgroup to obtain an expanded binary subgroup. Wherein, the expanded binary subgroup is 8 bits. The recovery key in the first data format includes an element corresponding to each expanded binary subgroup respectively.
[0183] For example, the expanded binary subgroup represents 0 under the ASCII encoding, and the element corresponding to 0 in the format coding table is A. The first electronic device determines that the element corresponding to the expanded binary subgroup is A.
[0184] In this embodiment, the data format of the recovery key is converted first, and then the recovery key after the data format conversion is displayed. Compared with a string of random numbers, the recovery key after the data format conversion is more convenient for users to observe, remember and input. By displaying the key in the first data format, the operation difficulty of the subsequent user input of the data encryption key is reduced in this way, thereby improving the operation convenience of the user to obtain the data encryption key by decrypting the recovery key, and then to obtain the content data.
[0185] In some embodiments, in the process of displaying the recovery key, the first electronic device generates key data in response to an operation of indicating to save the recovery key. Wherein, the key data is used to record the recovery key.
[0186] Optionally, the form of the key data includes but is not limited to at least one of the following: text, screenshot, file, etc. Subsequently, the first electronic device stores the key data in the first electronic device in response to an operation of storing the key data. The first electronic device sends the key data to other electronic devices or servers in response to an operation of sending the key data, so as to store the key data by the other electronic devices.
[0187] In other embodiments, in the process of displaying the recovery key, the data saving function of the first electronic device is in a disabled state. That is, the first electronic device does not support copying the recovery key, taking a screenshot of the display interface of the recovery key, or generating a file including the recovery key under the indication of the user.
[0188] Optionally, the first electronic device displays a saving failure prompt in response to the operation of indicating to save the recovery key. The saving failure prompt is used to remind the first electronic device that the long-term saving of the recovery key is not supported. In this way, the storage of the recovery key in the first electronic device is avoided, which helps to improve the security of the storage of the recovery key.
[0189] Optionally, the first electronic device does not store the recovery key for a long time. For example, after displaying the recovery key, the first electronic device deletes the data related to the recovery key in response to the operation of canceling the display of the recovery key. In this way, the first ciphertext and the recovery key are avoided to be stored in the first electronic device at the same time. After the recovery key is displayed to the user, other users cannot obtain the recovery key from the first electronic device, which helps to avoid the leakage of the recovery key from the first electronic device and thus the leakage of the data encryption key, threatening the storage security of the content data in the non-volatile memory.
[0190] In some embodiments, step S610 involves that the functional modules of the first electronic device include a file encryption module and a recovery key management module. Optionally, in response to the operation of requesting the recovery key, the file encryption module generates the recovery key; then, the file encryption module transmits the recovery key to the recovery key management module; and the recovery key management module displays the recovery key to the user.
[0191] Optionally, step S610 also involves a key management module. After the key management module generates the data encryption key, the data encryption key is transmitted to the file encryption module; and the file encryption module determines the data bit number of the recovery key according to the data bit number of the data encryption key, and then generates the recovery key.
[0192] In one example, the generation of the recovery key is triggered by the user. For example, the first electronic device displays a setting interface of an operating system; and the first electronic device displays a key generation interface in response to the operation of detecting a request to switch the interface in the setting interface. The key generation interface is an interface provided by the operating system of the first electronic device. For example, the key generation interface displays a first control for requesting the generation of the recovery key; and the first electronic device displays the recovery key in the key generation interface in response to the operation of clicking the first control.
[0193] Optionally, the first electronic device can also trigger the generation of the recovery key according to the voice operation, remote control operation, and other ways of the user. Optionally, the first electronic device also supports providing other entrances for the user in addition to the setting interface to obtain the recovery key.
[0194] The scheme provided by the present example supports the user to actively apply for the recovery key. The user controls the timing of the first electronic device to generate and display the recovery key, which helps to ensure that the user is provided with the recovery key after understanding the purpose of the recovery key. In this way, it helps to remind the user to carefully keep the recovery key, thereby helping to reduce the possibility of forgetting the recovery key.
[0195] In another example, the generation process of the recovery key is automatically triggered by the first electronic device. Illustratively, the first electronic device acquires the login times of the device usage account in response to the account login operation of the device; in the case of determining that the device usage account is the first login, the first electronic device displays the recovery key. In this case, the first electronic device automatically generates and displays the recovery key after the user logs in the first electronic device.
[0196] As known from the foregoing, the first electronic device can generate and display the recovery key after receiving the operation of requesting the recovery key. The storage mode of the recovery key includes being personally kept by the user, and being stored by other devices (such as being stored by the server) by binding the recovery key and the user account.
[0197] In a possible implementation, the personal keeping by the user includes that the user records the recovery key by hand copying, photographing, etc. The specific scheme of personal keeping is determined by the user and is not limited herein. The binding of the recovery key and the user account means that the recovery key is associated with a user credential capable of indicating the identity of the user, so as to subsequently acquire the recovery key through the user credential.
[0198] In another possible implementation, the recovery key is stored by the server. Optionally, the user logs in the user account through the first electronic device, and requests the server to establish a binding relationship between the user account and the recovery key through the first electronic device. In this way, the recovery key is saved by the server. The following describes the storage method of the recovery key through several embodiments.
[0199] In some embodiments, after step S610, there is further (not shown in FIG. 6) step S613, the first electronic device sends the recovery key to the server, so as to store the recovery key by the server.
[0200] FIG. 8 is a flow diagram of a recovery key storage process provided by an embodiment of the present application. As shown in FIG. 8, the recovery key storage process includes the following steps, which are completed by the first electronic device 100 and the server 200 in FIG. 1.
[0201] Step S810, the first electronic device displays a first interface in response to an account login operation.
[0202] The account login operation is used to log in a user account possessed by a user using the first electronic device. The first interface is used to log in the user account.
[0203] Optionally, the first electronic device displays, in response to the operation of logging in the user account, a key display interface for displaying the recovery key as the first interface. In this way, the user logs in the user account through the first interface, and a binding relationship between the recovery key and the user account is established.
[0204] For example, step S810 is performed after the recovery key is generated in response to the operation of requesting to generate the recovery key in step S610. After the recovery key is generated, the binding relationship between the recovery key and the user account can be established through steps S810-S870, so that in the case where the user needs to obtain the recovery key, the recovery key generated in step S610 can be found by the server based on the binding relationship between the recovery key and the user account.
[0205] In step S820, the first electronic device acquires the account information and the login password in response to the operation of inputting the account information.
[0206] The account information corresponds to a credential capable of identifying the identity of the user, and different users have different account information. Optionally, the type of the account information includes but is not limited to at least one of the following: third-party account information, native account information. The third-party account information is an account registered by the user in a third-party application. In this case, the server is a server that provides background support for the third-party application. For example, the third-party application includes but is not limited to a social application, a cloud storage application, etc.
[0207] For example, the native account information is account information of the user under the operating system of the first electronic device. In this case, the server is a cloud platform for supporting the operating system.
[0208] In step S830, the first electronic device generates a login verification request in response to the operation of verifying the account information.
[0209] The login verification request is used to request verification of whether the account information exists. For example, the login verification request carries the user account and the account login password.
[0210] Optionally, the operation of verifying the account information can be implemented as at least one of the following: a click operation, a long press operation, a sliding wipe operation, a gesture operation, a voice operation, etc. For example, the first interface displays a control for logging in the user account, and the first electronic device generates the login verification request in response to the operation of clicking the control.
[0211] In step S840, the first electronic device sends the login verification request to the server.
[0212] Optionally, the server verifies the account information according to the login verification request. For example, in the case that the account information does not exist or the login password is incorrect, the server performs steps S850 and S860, and then stops performing other steps; in the case that the account information exists and the login password is correct, the first electronic device performs step S870.
[0213] In step S850, in the case that the account information does not exist, the server sends a verification failure notification to the first electronic device.
[0214] For example, the verification failure notification is used to indicate that the login key is incorrect or the account information does not exist.
[0215] In step S860, the first electronic device displays a verification failure prompt.
[0216] In step S870, in the case that the account information exists, the first electronic device sends a key binding request to the server in response to the key binding operation.
[0217] Optionally, the key binding request carries key data related to the recovery key. For example, the key data includes at least one of the following: the recovery key, and ciphertext of the recovery key. The key data of the recovery key is obtained by encrypting the recovery key, that is, the key data is the encrypted recovery key. For example, the key binding request includes the ciphertext of the recovery key.
[0218] In one example, the first electronic device acquires an end-cloud key in response to the operation of binding the recovery key; the first electronic device acquires the key data of the recovery key by encrypting the recovery key with the public key in the end-cloud key; the first electronic device carries the key data of the recovery key in the key binding request; and the first electronic device stores the private key in the end-cloud key.
[0219] For example, the private key in the end-cloud key is used to decrypt the ciphertext of the recovery key. Optionally, the end-cloud key is generated by the first electronic device, and the end-cloud key is used to protect the communication data transmitted between the server and the first electronic device. For example, the end-cloud key includes a public key and a private key, the public key is known to the first electronic device and the server, and the private key is known to the first electronic device.
[0220] In this way, the recovery key is not directly carried in the communication process between the electronic device and the server, which helps to avoid the key binding request sent by the electronic device to the server being hijacked, thereby causing the recovery key to be leaked. At the same time, the present embodiment does not need to store the recovery key in the server, which helps to ensure the storage security of the recovery key in the server and helps to avoid the server being attacked to steal the recovery key.
[0221] At step S880, the server establishes a binding relationship between the recovery key and the account information according to the key binding request.
[0222] Optionally, the server stores the ciphertext of the recovery key into a storage space corresponding to the user account according to the key binding request, so that the server can provide the first electronic device with the recovery key bound to the account information through the account information in the future.
[0223] In this way, the user can find the recovery key through the registered account, and the server stores the recovery key, which helps to avoid the user forgetting the recovery key, thereby improving the storage reliability of the recovery key.
[0224] In order to further improve the storage security of the recovery key and reduce the possibility of recovery key leakage, the storage method of the recovery key is introduced and described through several embodiments.
[0225] In some embodiments, the recovery key includes a first sub-key, and the first electronic device generates the first sub-key and displays the first sub-key in response to the operation of requesting the recovery key. Optionally, the recovery key further includes a second sub-key. The first electronic device generates the first sub-key and the second sub-key in response to the operation of requesting the recovery key. Subsequently, the first electronic device displays the first sub-key.
[0226] For example, the first electronic device generates the first sub-key and the second sub-key in response to the operation of requesting the recovery key, including: the first electronic device generates the recovery key in response to the operation of requesting the recovery key; and the first electronic device divides the recovery key to obtain the first sub-key and the second sub-key. Subsequently, the first electronic device displays the first sub-key.
[0227] In one example, the recovery key includes 2n elements, n is a positive integer, the first sub-key includes the first n elements, and the second sub-key includes the last n elements, or the second sub-key includes the first n elements, and the first sub-key includes the last n elements.
[0228] In another example, the recovery key includes p*q elements, p and q are positive integers, the first electronic device divides the recovery key into p element groups, and each element group includes q consecutive elements in the recovery key. For example, the first sub-key includes the element groups at odd positions in the p element groups, and the second sub-key includes the element groups at even positions in the p element groups. For example, the first sub-key includes the element groups at even positions in the p element groups, and the second sub-key includes the element groups at odd positions in the p element groups.
[0229] FIG. 9 is a diagram illustrating a division of the recovery key according to an embodiment of the present application. As shown in FIG. 9, the recovery key 900 includes 32 elements. The first electronic device divides the recovery key 900 into 8 element groups, each of which includes 4 elements. The 8 element groups are element group 1, element group 2, element group 3, element group 4, element group 5, element group 6, element group 7, and element group 8. The first electronic device groups the element group 1, the element group 3, the element group 5, and the element group 7 into a first sub-key 910, and groups the element group 2, the element group 4, the element group 6, and the element group 8 into a second sub-key 920.
[0230] Optionally, in addition to displaying the first sub-key, the first electronic device also displays the second sub-key. For example, the first electronic device displays the first sub-key and the second sub-key in the same interface. Optionally, the first electronic device does not display the second sub-key.
[0231] For example, the first electronic device encrypts the second sub-key according to the public key in the end-to-cloud key to obtain the ciphertext of the second sub-key; the first electronic device sends the ciphertext of the second sub-key to the server; and the server stores the ciphertext of the second sub-key to the account space corresponding to the account information.
[0232] In some embodiments, in the case where the data encryption key needs to be decrypted, the first electronic device or the second electronic device obtains the first sub-key from the user side and obtains the second sub-key from the server through the account information; the first electronic device or the second electronic device splices the first sub-key and the second sub-key to obtain the recovery key. Then, the recovery key is used to decrypt the first ciphertext of the data encryption key to obtain the data encryption key.
[0233] The present embodiment helps to reduce the risk of leakage of the recovery key and improve the security of the storage of the recovery key by dividing the recovery key into at least two sub-keys and using different ways to store the at least two sub-keys.
[0234] In order to verify the correctness of the recovery key provided by the user in the subsequent use process. The method for verifying the correctness of the recovery key is introduced and explained as follows. Optionally, after generating the recovery key, the first electronic device generates and stores a first credential of the recovery key, and verifies the accuracy of the recovery key input by the user subsequently through the first credential.
[0235] As shown in FIG. 10, after step S610, the key management method further includes steps S616 and S617, which are performed by the first electronic device 100 in FIG. 1.
[0236] Step S616. The first electronic device obtains the second credential according to the recovery key.
[0237] The second credential is used to indicate the recovery key generated by the first electronic device. Optionally, a mapping relationship between the second credential and the recovery key is determined. That is, the same recovery key processed using the same encoding manner can obtain a determined second credential; different recovery keys processed using the same encoding manner can obtain different second credentials, respectively. For details of the use of the second credential, refer to the embodiments on the second electronic device side.
[0238] For example, S613, S616 and S620 are executed synchronously. For another example, S613, S616 and S620 are executed sequentially.
[0239] In one example, the first electronic device performs mapping processing on the recovery key to obtain the second credential, and stores the second credential in the encrypted area of the non-volatile memory.
[0240] Optionally, the first electronic device performs mapping processing on the recovery key to obtain the second credential, including: the first electronic device processes the recovery key by an encryption algorithm to obtain the second credential.
[0241] Step S617. The first electronic device stores the second credential.
[0242] Optionally, the first electronic device stores the second credential in the non-volatile memory.
[0243] In some embodiments, the functions of the first electronic device involved in steps S616 and S617 include a recovery key management module. Optionally, after the recovery key management module receives the recovery key from the file encryption module, the recovery key management module encrypts the recovery key to obtain the first credential, and the recovery key management module stores the first credential.
[0244] For example, in a case where the reset of the user password is triggered by the recovery key, the recovery key management module sends the first credential to the password management module, and the password management module stores the first credential in the non-volatile memory.
[0245] The scheme of the present embodiment generates a credential corresponding to the recovery key, so that the authenticity of the obtained recovery key is verified using the first credential when the user-provided recovery key is received subsequently. In this way, it is helpful to avoid invalid calculations of the electronic device caused by incorrect recovery keys.
[0246] After the first electronic device generates the recovery key, the first electronic device processes the data encryption key using the recovery key to achieve protection of the data encryption key. The process is described below by step S620.
[0247] In step S620, the first electronic device encrypts the data encryption key using the recovery key to obtain the first ciphertext of the data encryption key.
[0248] For example, step S620 is executed after step S610 is completed. There is no strict execution sequence between step S620 and steps S613 and S616. For example, step S620 can be executed before step S613, or step S620 is executed after step S613, or step S620 is executed synchronously with step S613.
[0249] In some embodiments, the first ciphertext of the data encryption key is ciphertext data obtained by encrypting the data encryption key using the recovery key. The data encryption key can be obtained by decrypting the first ciphertext using the recovery key.
[0250] Optionally, the first electronic device encrypts the data encryption key using the data encryption key based on a symmetric encryption algorithm to obtain the first ciphertext.
[0251] For example, the type of symmetric encryption algorithm includes at least one of the following: advanced encryption standard (AES), data encryption standard (DES), triple data encryption standard (3DES), rivest cipher (RC), etc. In the encryption process of the data key, the encryption process can also be assisted by galois counter mode (GCM). For example, the first electronic device encrypts the data encryption key using the recovery key by AES-GCM encryption algorithm to obtain the first ciphertext.
[0252] In some embodiments, step S620 involves a function module of the first electronic device, including a file encryption module. Optionally, after generating the recovery key, the file encryption module encrypts the data encryption key using the recovery key to generate the first ciphertext of the data encryption key.
[0253] In step S630, the first electronic device stores the first ciphertext in the non-encrypted area of the non-volatile memory.
[0254] Optionally, the non-volatile memory refers to a memory capable of storing data for a long time. The non-volatile memory can ensure that the data stored therein is not lost after power-off. Illustratively, the type of non-volatile memory includes at least one of the following: flash memory, solid state drive (SSD), hybrid hard drive (HHD), and hard disk drive (HDD). For example, the non-volatile memory is a detachable solid state drive in the first electronic device.
[0255] In some embodiments, the non-volatile memory is used to store content data generated during the running of the first electronic device. Optionally, in the case where the first electronic device is in a running state, the non-volatile memory stores unencrypted content data (except for data on which the user performs an encryption operation); in the case where the first electronic device is in a sleep or shutdown state, the encrypted region of the non-volatile memory stores ciphertext of the content data. The ciphertext of the content data is obtained by encrypting the content data with a data encryption key.
[0256] Optionally, the content data includes at least one of the following: running data, service data. The running data is data recording the use of the first electronic device. Optionally, the running data includes at least one of the following: log files, temporary files, performance parameters, etc. Illustratively, the log files and temporary files are used to record events occurring during the running of the first electronic device. The performance parameters are used to reflect the performance changes during the running of the first electronic device.
[0257] The service data is data related to the user using the first electronic device. For example, the service data includes documents, pictures, videos, audios, binary files, etc. downloaded, edited or viewed by the user in the first electronic device.
[0258] In some embodiments, the data storage region in the non-volatile memory is divided into an encrypted region and a non-encrypted region. The non-encrypted region is also referred to as a non-encrypted storage area, and the encrypted region is also referred to as an encrypted storage area.
[0259] The non-encrypted region is used to store data that does not need to be encrypted. The electronic device can read data from the non-encrypted region and use the data. The electronic device mentioned here includes the first electronic device and other electronic devices. For example, in the case where the connection relationship between the first electronic device and the non-volatile memory is disconnected, after the second electronic device is connected to the non-volatile memory, the second electronic device can read the data stored in the non-encrypted region of the non-volatile memory.
[0260] Optionally, the first electronic device stores the first ciphertext of the data encryption key in the non-encrypted area. Illustratively, the first electronic device stores the first ciphertext in a first file directory in the non-encrypted area. In the case where the first ciphertext is needed, the first ciphertext can be read from the first file directory in the non-encrypted area. The electronic device mentioned herein includes the first electronic device.
[0261] In the embodiment, the electronic device generates the recovery key and stores the first ciphertext of the data encryption key encrypted by the recovery key in the non-encrypted area of the non-volatile memory, which facilitates subsequent decryption of the data encryption key by using the recovery key kept by the user and the first ciphertext stored in the non-encrypted area. In this way, a relatively simple and fast method for obtaining the data encryption key is provided, which reduces the difficulty of obtaining the data encryption key while ensuring the security of the data encryption key.
[0262] Optionally, for the content data, the first electronic device encrypts the content data by using the data encryption key to obtain a ciphertext of the content data; and the first electronic device stores the ciphertext of the content data in the encrypted area.
[0263] The timing of encrypting the content data by using the data encryption key is described below.
[0264] In some embodiments, upon receiving the data protection instruction, the first electronic device encrypts the content data by using the data encryption key to generate a ciphertext of the content data.
[0265] Optionally, the data protection instruction is generated by the first electronic device. Illustratively, before the first electronic device is powered off or locked, the first electronic device generates the data protection instruction to trigger the step of encrypting the content data by using the data encryption key.
[0266] Since the electronic device is in a use state, the user can use the service data at any time. Therefore, in the case where it is determined that the first electronic device is about to be locked or powered off, encrypting the content data by using the data encryption key can reduce the interference of content data encryption on the user experience while ensuring the storage security of the content data.
[0267] Illustratively, before the first application is closed, the first electronic device generates the data protection instruction to trigger the step of encrypting the content data related to the first application by using the data encryption key. Encrypting the content data by using the data encryption key before the first application is closed can improve the storage security of the content data related to the first application and reduce the risk of theft, misuse or modification of the content data by other applications.
[0268] Optionally, the first application is an application installed in the first electronic device.
[0269] Optionally, the first electronic device encrypts the file containing the content data using the data encryption key to obtain an encrypted file; and the first electronic device stores the encrypted file in the encrypted area. The encrypted file includes the ciphertext of the content data.
[0270] In one example, the first electronic device generates a data protection instruction in response to an operation indicating a lock screen; the first electronic device triggers encryption of the content data using the data encryption key based on the data protection instruction to obtain the ciphertext of the content data; and the first electronic device stores the ciphertext of the content data in the encrypted area.
[0271] The operation indicating the lock screen includes, but is not limited to, a click operation, a double-click operation, a long-press operation, a sliding operation, a gesture operation, etc.
[0272] In another example, the first electronic device automatically generates a data protection instruction when the standby duration reaches the duration threshold; the first electronic device encrypts the content data using the data encryption key to obtain the ciphertext of the content data; and then the first electronic device enters a lock screen state.
[0273] In another example, the first electronic device generates a data protection instruction in response to an operation indicating a shutdown; the first electronic device triggers encryption of the content data using the data encryption key based on the data protection instruction to obtain the ciphertext of the content data; and the first electronic device stores the ciphertext of the content data in the encrypted area. Then the first electronic device powers off each device and shuts down.
[0274] In some embodiments, step S630 involves that the functional module of the first electronic device includes a recovery key management module. Optionally, the file encryption module stores the first ciphertext in a non-encrypted area in the non-volatile memory after generating the first ciphertext.
[0275] The following describes the interaction process of the functional modules in the first electronic device in the data encryption key encryption process. This embodiment involves the file encryption module and the recovery key management module in FIG. 5A. Optionally, this embodiment also involves an interface display module in the first electronic device. The interface display module is configured to control the first electronic device to display a key display interface to a user. As shown in FIG. 11, this embodiment includes at least the following steps:
[0276] In step S1110, the file encryption module encrypts the data encryption key according to the first user password to obtain the second ciphertext of the data encryption key.
[0277] The second ciphertext is encrypted by the file encryption module using the first user password and / or the hardware key, and is obtained by encrypting the data encryption key. Optionally, the second ciphertext is stored in a startup area of the non-volatile memory. The startup area is used to store resources required in the startup process of the electronic device. For example, in the startup or wake-up process of the first electronic device, the second ciphertext is read from the startup area by a security chip in the first electronic device, and the second ciphertext is decrypted by the first user password and / or the hardware key to obtain the data encryption key.
[0278] The startup area refers to a storage area in the non-volatile memory for storing system resources. Optionally, the startup area belongs to an encrypted area. For example, in the startup process of the first electronic device, the first electronic device reads resource files required for loading the startup operating system from the startup area.
[0279] For example, the file encryption module acquires the data encryption key through the key management module in response to an operation of unlocking the first electronic device, and encrypts the data encryption key according to the first user password to obtain the data encryption key.
[0280] The operation of unlocking the first electronic device is used to control the first electronic device to enter a running state. Optionally, the operation of unlocking the first electronic device can be implemented by inputting the first user password to the first electronic device in the case of starting up the first electronic device or needing to unlock. Optionally, the first user password is a lock screen password or a startup password set by the user.
[0281] Optionally, the file encryption module encrypts the data encryption key by the first user password and the hardware key to obtain the second ciphertext of the data encryption key. For example, the first user password is provided by the password management module to the file encryption module, and the hardware key is provided by the hardware key reading module to the file encryption module.
[0282] In one example, the file encryption key encrypts the data encryption key using the user password. In another example, the file encryption key encrypts the data encryption key using the hardware key. In yet another example, the file encryption key encrypts the data encryption key using the user password and the hardware key.
[0283] Optionally, the specific method of encrypting the data encryption key by the file encryption module using the user password and / or the hardware key is determined according to the encryption algorithm used in the full-disk encryption, and the encryption algorithm used in the generation of the second ciphertext is not limited again in the present application.
[0284] In step S1112, the file encryption module encrypts the content data according to the data encryption key to obtain the ciphertext of the content data.
[0285] Optionally, the file encryption module encrypts the content data according to the data encryption key in response to the operation of locking the first electronic device, and obtains the ciphertext of the content data. The operation of locking the first electronic device is used to control the first electronic device to enter a non-running state such as shutdown or hibernation. Optionally, the operation of unlocking the first electronic device is implemented as an operation of controlling the first electronic device to shut down, or an operation of controlling the first electronic device to lock the screen.
[0286] To ensure the storage safety of the content data stored in the non-volatile memory after the first electronic device is shut down or hibernated, the file encryption module encrypts the content data using the data encryption key before entering the non-running state, and obtains the ciphertext of the content data. Optionally, the ciphertext of the content data is stored in the encryption area of the non-volatile memory.
[0287] For example, after the encryption of the content data is completed, the file encryption module deletes the data encryption key. That is, after the first electronic device is shut down or hibernated, the ciphertext of the content data is stored in the encryption area of the non-volatile memory, but the content data itself is not stored. Optionally, the embodiment can also start from step S1112.
[0288] Step S1113: The file encryption module decrypts the second ciphertext of the data encryption key according to the first user password, and obtains the data encryption key.
[0289] Optionally, the user wakes up the first electronic device, and after the first electronic device is restarted or the screen is unlocked, the file encryption module decrypts the second ciphertext by the first user password and / or the hardware key, and obtains the data encryption key.
[0290] Step S1114: The file encryption module decrypts the ciphertext of the first content data according to the data encryption key in response to the operation of obtaining the first content data, and obtains the first content data.
[0291] The first content data is any one of the content data. For example, the first content data is a file edited by the user. Optionally, the ciphertext of the first content data is stored in the encryption area of the non-volatile memory.
[0292] Optionally, after step S1113 is executed, the file encryption module decrypts the ciphertext of all content data in the encryption area using the data encryption key. Optionally, after step S1113 is executed, the file encryption module reads the ciphertext of the first content data from the encryption area of the non-volatile memory in the case that the first electronic device needs to use the first content data; and the file encryption module decrypts the ciphertext of the first content data using the data encryption key to obtain the first content data.
[0293] In step S1120, the interface display module sends a recovery key generation request to the recovery key management module. The recovery key generation request is used to request generation of the recovery key.
[0294] Optionally, the interface display module sends the recovery key generation request to the recovery key management module in response to the operation of requesting generation of the recovery key. Optionally, the recovery key generation request carries the first user password. The first user password is the password of the device usage account. Illustratively, in the case where the first user password is correct, the first electronic device switches from the lock screen state to the running state.
[0295] By carrying the first user password in the recovery key generation request, the identity of the user currently using the first electronic device can be indicated.
[0296] In step S1121, the recovery key management module sends the recovery key generation request to the file encryption module.
[0297] In step S1130, the file encryption module generates the recovery key.
[0298] Optionally, the file encryption module randomly generates the recovery key after receiving the recovery key generation request. Illustratively, the file encryption module performs format conversion on the recovery key to obtain the recovery key in the first data format.
[0299] In step S1140, the file encryption module encrypts the data encryption key according to the recovery key to obtain the first ciphertext of the data encryption key.
[0300] In step S1141, the file encryption module sends the recovery key and the first ciphertext to the recovery key management module.
[0301] Optionally, the file encryption module sends the recovery key in the first data format to the recovery key.
[0302] In step S1150, the recovery key management module stores the first ciphertext in the non-encrypted area of the non-volatile memory.
[0303] Optionally, the recovery key management module stores the first ciphertext under the first file directory. The first file directory is the file directory corresponding to the non-encrypted area in the non-volatile memory.
[0304] In step S1160, the recovery key management module sends the recovery key to the interface display module.
[0305] Optionally, the interface display module displays the recovery key in the recovery key interface after receiving the recovery key.
[0306] Optionally, after the interface display module displays the recovery key to the user, the first electronic device can further generate a first credential for the first credential, so that after the user subsequently obtains the recovery key through the user operation, the first credential is used to verify whether the recovery key is correct. The key management method can further select to perform the following two steps.
[0307] In step S1170, the recovery key management module obtains the first credential according to the recovery key.
[0308] Optionally, the recovery key management module encodes the recovery key to obtain the first credential of the recovery key. For example, the recovery key management module encrypts the recovery key using a first encryption algorithm to generate the first credential of the recovery key. The first encryption algorithm belongs to a symmetric encryption algorithm.
[0309] In step S1171, the recovery key management module stores the first credential.
[0310] Optionally, the recovery key management module sends the first credential to the password management module, so that the password management module verifies the correctness of the recovery key provided by the user according to the first credential, and provides a function of resetting the user password under the condition that the recovery key is correct.
[0311] For the content not described in detail in the present embodiment, please refer to the above embodiments, which will not be repeated here.
[0312] In the present embodiment, the recovery key for generating the user protection data encryption key is supported, and the encryption and decryption of the data encryption key can be realized using the recovery key. Since the recovery key is generated by the file encryption module hardware key and is kept by the user, the encryption and decryption process of the data encryption key does not depend on the hardware key. This method helps to reduce the dependence of the hardware key in the process of decrypting the ciphertext of the data encryption key, thereby avoiding the problem that the data encryption key cannot be obtained due to the damage of the hardware.
[0313] In addition, the first ciphertext is stored in a non-encrypted area, which facilitates reading the first ciphertext. Even in the case of damage of other hardware in the electronic device, the data encryption key can be decrypted by the first ciphertext and the recovery key through the installation of the non-volatile memory to other electronic devices.
[0314] The key management method is described below with the second electronic device 300 shown in FIG. 1 as the execution subject. Optionally, the function modules of the second electronic device 300 include a recovery key management module. The function modules in the second electronic device 300 can also include a file encryption module, a key management module, a hardware key reading module, and a password management module. Please refer to FIG. 12, which is a flowchart of the key management method according to an embodiment of the present application. As shown in FIG. 12, the key management method according to an embodiment of the present application includes at least steps S1210 to S1250.
[0315] In step S1210, the second electronic device receives the recovery key in response to a user operation.
[0316] In some embodiments, the first electronic device and the second electronic device are the same device, or the second electronic device is another device different from the first electronic device. Optionally, the first electronic device and the second electronic device are the same device in the scenario of using the recovery key to decrypt the ciphertext of the content data, or the first electronic device and the second electronic device are different electronic devices. Illustratively, in the case that the user forgets the user password, resulting in the inability to decrypt the second ciphertext of the data decryption key according to the user password, the data encryption key can be obtained by using the recovery key to decrypt the first ciphertext of the data decryption key. In this case, the first electronic device and the second electronic device are the same electronic device.
[0317] Illustratively, in the case of hardware damage / upgrade of the first electronic device, the non-volatile memory in the first electronic device is connected to the second electronic device. By providing the recovery key to the second electronic device, the first ciphertext of the data encryption key is decrypted to obtain the data encryption key. Then the second electronic device uses the data encryption key to decrypt the ciphertext of the content data stored in the encrypted area of the non-volatile memory to obtain the content data generated by the user during the use of the first electronic device. In this case, the first electronic device and the second electronic device are different electronic devices.
[0318] Optionally, in the scenario of changing the user password using the recovery key, the first electronic device and the second electronic device are the same device.
[0319] The user operation is used to provide the recovery key to the second electronic device. Optionally, the data format of the recovery key provided by the user operation to the second electronic device includes but is not limited to the recovery key in the first data format and the recovery key in the data sequence format.
[0320] In some embodiments, the user operation includes at least one of the following: an operation of inputting the recovery key and an operation of finding the recovery key.
[0321] Optionally, the user provides the second electronic device with the recovery key in the first data format by inputting the recovery key; the second electronic device acquires the recovery key in the first data format input by the user in response to the operation of inputting the recovery key; and the second electronic device obtains the recovery key in the data sequence format (e.g., a string of random numbers) by performing data format conversion on the recovery key in the first data format, so as to decrypt the first ciphertext by using the recovery key in the data sequence format in the subsequent steps.
[0322] Optionally, the operation of the user is implemented by an operation of logging in the account space of the user account, and the recovery key bound to the account information is found from the account space by an operation of searching for the recovery key.
[0323] Exemplarily, in the case where the user account belongs to a native account, the second electronic device supports logging in the account space of the user account in the locked screen state. As shown in FIG. 13, in the case where the second electronic device is in the locked screen state, a display login control 1310 is displayed in a locked screen interface 1300; the second electronic device displays a first interface 1320 in response to an operation of logging in the user account; the second electronic device acquires the account information and the login password in response to an operation of inputting the account information; the second electronic device generates a login verification request in response to an operation of verifying the account information; and the second electronic device sends the login verification request to the server. In the case where the account information is verified to exist, the second electronic device sends a key acquisition request to the server in response to an operation of searching for the recovery key. After receiving the key binding request, the server finds the key data bound to the account information and sends the key data to the second electronic device.
[0324] The first interface is a user interface provided by an application or a cloud platform to which the user account belongs. Optionally, the first interface displays a second control for searching for the recovery key; and the second electronic device requests the server to search for the recovery key bound to the account information in response to an operation of clicking the second control. The display effect of the login control is as shown in the “login” control in the first interface 1320 in FIG. 13.
[0325] In some embodiments, the key data includes the recovery key, or includes ciphertext of the recovery key.
[0326] Optionally, in the case where the key data includes the recovery key, the second electronic device reads the recovery key from the key data. Optionally, in the case where the key data includes ciphertext of the recovery key, the second electronic device decrypts the ciphertext of the recovery key by using the private key in the end-cloud key to obtain the recovery key. For details of the end-cloud key, refer to the embodiments on the first electronic device side.
[0327] Exemplarily, in a case where the user account belongs to a third-party application account, the second electronic device can not support logging in the account space of the user account in the lock screen state. In this case, the user can log in the user account through another electronic device, obtain the recovery key, and manually input the recovery key to the second electronic device.
[0328] In some embodiments, the user operation is obtained from a lock screen interface, which is a display interface of the first electronic device in a case where the first electronic device is powered on, woken up, or requested to open the first application; or the user operation is obtained from a password resetting interface. That is, the user operation is used to unlock the first electronic device, wake up the first electronic device, or trigger to start the application installed in the first electronic device by using the recovery key. Exemplarily, the user operation is also used to update the user password by using the recovery key. The password resetting interface is used to reset the user password, and the password resetting interface includes the third interface in the following embodiments. For the above various implementation scenarios, please refer to the introduction of the following embodiments.
[0329] In step S1220, the second electronic device obtains the first ciphertext of the data encryption key from the non-encrypted storage area in the non-volatile memory.
[0330] For the related introduction of the first ciphertext and the non-volatile memory, please refer to the above embodiments.
[0331] Optionally, the second electronic device obtaining the first ciphertext of the data encryption key from the non-encrypted storage area in the non-volatile memory includes: the second electronic device determining a file management system corresponding to the non-volatile memory; determining the non-encrypted storage area according to the file management system; and traversing at least one file stored in the non-encrypted storage area to obtain the first ciphertext.
[0332] The file management system is used to divide the storage space of the non-volatile memory. Different operating systems correspond to different file management systems, and different file management manners correspond to different division manners of the storage space of the non-volatile memory. For example, the file names corresponding to the non-encrypted area are different for different file management systems.
[0333] Optionally, in a case where the first electronic device and the second electronic device are different, the second electronic device determines the file management system corresponding to the non-volatile memory through the driver software; the second electronic device determines the first file directory corresponding to the non-encrypted area in the non-volatile memory according to the file management system corresponding to the non-volatile memory; and the second electronic device traverses at least one file stored in the non-encrypted storage area according to the first file directory to obtain the first ciphertext.
[0334] The first file directory is a file directory corresponding to the non-encrypted area, and data stored in the non-encrypted area is arranged under the first file directory. For example, the first file directory is a "data / " directory.
[0335] For example, the second electronic device traverses at least one file stored in the non-encrypted storage area according to the first file directory to obtain the first ciphertext, including: the second electronic device determines a running file set included in the first file according to the first file directory; and the second electronic device traverses each file included in the running file set to obtain the first ciphertext.
[0336] The running file set is used to store data generated by the first electronic device in a running process. The first ciphertext is generated in the running process of the first electronic device, and therefore the first ciphertext can be stored in the running file set.
[0337] In this way, the total number of files that need to be traversed in the non-encrypted area of the electronic device is reduced, and therefore the speed of obtaining the recovery key from the non-volatile memory of the electronic device is improved.
[0338] In step S1230, the second electronic device uses the recovery key to decrypt the first ciphertext to obtain a data encryption key.
[0339] The data encryption key is used to encrypt and / or decrypt target content data in the non-volatile memory. For details of the data encryption key, refer to the embodiments on the first electronic device side.
[0340] In step S1240, the second electronic device obtains ciphertext of target content data from the non-volatile memory.
[0341] In some embodiments, the ciphertext of the target content data is stored in the encrypted area of the non-volatile memory. Optionally, the target content data is any content data that needs to be decrypted from the encrypted area.
[0342] Optionally, the target content data is all content data, or the target content data is part of the content data. The all content data refers to content data corresponding to the ciphertext of each content data in the encrypted area.
[0343] For example, the target content data is content data used in the running process of the second electronic device; and the second electronic device uses the data encryption key to decrypt the ciphertext of the target content data to obtain the target content data in response to an instruction to display the content data.
[0344] The instruction to display the content data is used to indicate a file identifier or a file storage address of the target content data. The second electronic device reads the ciphertext of the target content data from the encrypted area according to the file identifier or the file storage address.
[0345] Optionally, the instruction of displaying the content data is generated by the second electronic device in response to an operation of viewing the target content data. The operation of viewing the target content data includes at least one of the following: triggering a display icon of the target content data, and instructing to open the target content data by a program code.
[0346] At step S1250, the second electronic device decrypts the ciphertext of the target content data by using the data encryption key to obtain the target content data.
[0347] Optionally, the encryption method of the content data protected by the data encryption key belongs to a symmetric encryption algorithm. For example, the first electronic device encrypts the target content data by using the data encryption key based on a second encryption algorithm to obtain the ciphertext of the target content data; and the second electronic device decrypts the ciphertext of the target content data by using the data encryption key based on the second encryption algorithm to obtain the target content data.
[0348] The second encryption algorithm is any one of the symmetric encryption algorithms. For example, in the case that the first electronic device and the second electronic device are provided with the same application framework layer, the second encryption method is known to the second electronic device. For example, the second encryption algorithm is set in a file encryption module of the second electronic device.
[0349] Subsequently, the second electronic device displays the target content data.
[0350] In one example, the target content data is a first document edited by a user in history, the second electronic device reads the ciphertext of the first document from the encryption area in response to an operation of displaying the first document; the second electronic device decrypts the ciphertext of the first document by using the data encryption key to obtain the first document; and the second electronic device displays the second document.
[0351] The following describes the interaction process between the functional modules in the second electronic device in the process of executing the key management method by the second electronic device. The present embodiment is cooperatively completed by the file encryption module and the recovery key management module shown in FIG. 5A. In the present embodiment, the non-volatile memory is an SSD. The SSD is detached from the first electronic device. The SSD is connected to the second electronic device, and the second electronic device can read data from the SSD. As shown in FIG. 14, the present embodiment includes at least the following steps:
[0352] At S1410, the recovery key management module receives the recovery key in response to a user operation.
[0353] In one example, the recovery key management module receives the recovery key input by a user. In another example, the recovery key management module reads the recovery key from a USB storage device.
[0354] In one example, the recovery key management module acquires the recovery key from a server that stores a binding relationship between the account information and the recovery key, and in a case where the user inputs the account information and the login password in the second electronic device, the recovery key management module requests the server to acquire the recovery key.
[0355] S1420, the recovery key management module obtains the first ciphertext of the data encryption key from the non-encrypted storage area in the non-volatile memory.
[0356] Optionally, the recovery key management module queries the first ciphertext in the non-encrypted storage area of the non-volatile memory. Illustratively, the recovery key management module reads the first ciphertext from a first file directory in the non-encrypted area.
[0357] S1430, the recovery key management module sends the recovery key and the first ciphertext to the file encryption module.
[0358] Optionally, in a case where the recovery key management module acquires the recovery key in the first data format, the recovery key management module performs format conversion on the recovery key in the first data format to obtain the recovery key in the data sequence format. The recovery key management module sends the first ciphertext and the recovery key in the data sequence format to the file encryption module.
[0359] S1440, the file encryption module decrypts the first ciphertext using the recovery key to obtain the data encryption key.
[0360] S1450, the file encryption module decrypts the ciphertext of the target content data using the data encryption key to obtain the target content data.
[0361] Optionally, the target content data is all the content data. For example, in a case where the second electronic device is powered on or unlocked from the lock screen state, the file encryption module reads the ciphertext of the content data stored in the encrypted area one by one.
[0362] Optionally, the file encryption module decrypts the ciphertext of the target content data based on the second encryption algorithm according to the data encryption key to obtain the target content data. Illustratively, the decrypted target content data is stored in the encrypted area, and the second electronic device can read and directly use the target content data from the encrypted area. In a case where the second electronic device is powered off, locked, or an application is closed, the second electronic device deletes the target content data stored in the encrypted area.
[0363] After the electronic device is powered on, unlocked, or the application is reopened, if the user needs to use the target content data, the second electronic device responds to the operation of finding the target content data to acquire the target content data from the SSD; and the second electronic device displays the target content data to the user.
[0364] In the scheme provided in the embodiment, the first ciphertext of the data encryption key is generated by the recovery key, so that the process of obtaining the data encryption key does not need to use the hardware key, and the dependence of the data encryption key on the hardware key in the electronic device is reduced. In the case that the hardware of the electronic device is damaged and the non-volatile memory is intact, the non-volatile memory can be connected to other electronic devices, and the key management method is executed in the other electronic devices. In this way, the reliability of the obtaining manner of the data encryption key is improved, and the loss caused by the forgetting of the hardware key or the user password and the failure to obtain the content data by the user are avoided.
[0365] The following describes a scenario example in which the second electronic device 300 in FIG. 1 executes the key management method through several examples.
[0366] Example 1: A scenario in which the recovery key management method is used in combination with a full-disk encryption method. In this embodiment, the second electronic device and the first electronic device are the same electronic device. As shown in FIG. 15, the embodiment at least includes the following steps:
[0367] S1510: The second electronic device receives a second user password in response to an operation of inputting the user password.
[0368] The second user password is a user password input by a user, and the second user password is used to attempt to unlock the second ciphertext to obtain the data encryption key.
[0369] For example, in the process of starting up or unlocking the second electronic device, the second electronic device displays a lock screen interface, the lock screen interface includes a password input field, and the second electronic device receives the second user password in response to an input operation on the password input field.
[0370] S1520: The second electronic device obtains the second ciphertext of the data encryption key from the startup area in the non-volatile memory.
[0371] After receiving the second user password, the second electronic device reads the second ciphertext and decrypts the second ciphertext using the second user password.
[0372] In some embodiments, the second electronic device reads the second ciphertext from the startup area by using the security chip. Optionally, the second electronic device decrypts the second ciphertext by using the first user password and / or the hardware key.
[0373] For example, in the case that the second electronic device can obtain the data encryption key by decrypting the second ciphertext, since the data encryption key has been obtained, the second electronic device can directly execute step S1570. In the case that the second electronic device cannot obtain the data encryption key by decrypting the second ciphertext, the second electronic device starts from step S1530.
[0374] S1530, in the case that the second user password is different from the first user password, the second electronic device displays a second interface.
[0375] The second interface is configured to receive a recovery key. For example, the second interface is an interface for inputting the recovery key, and the second interface displays a key input field. For another example, the second interface displays an account login control, and the second electronic device displays the first interface in response to the account login control, and obtains the recovery key from the server through the account information.
[0376] In some embodiments, in the case that the second user password is different from the first user password, the second electronic device cannot decrypt the second ciphertext through the second user password, which indicates that the second user password input by the user is incorrect. That is, the second user password input by the user is inconsistent with the first user password set in the second electronic device. That is, in the case that the second user password cannot decrypt the second ciphertext, the second electronic device displays the second interface.
[0377] Optionally, the second electronic device stores first verification information used to represent the first user password, and generates second verification information of the second user password after receiving the second user password.
[0378] For example, the second electronic device encrypts the second user password through a third encryption algorithm to obtain the second verification information. The third encryption algorithm is the same as the second encryption algorithm, or the third encryption algorithm is irrelevant to the second encryption algorithm.
[0379] Subsequently, the second electronic device compares whether the first verification information and the second verification information are the same. In the case that the first verification information and the second verification information are the same, it indicates that the second user password is the same as the first user password; in the case that the first verification information and the second verification information are different, it indicates that the second user password is different from the first user password, and the second user password is incorrect.
[0380] For example, in the case that the second user password is different from the first user password, the second electronic device records the number of errors of incorrect passwords. In one example, in the case that the number of errors is less than a first threshold, the second electronic device clears the password input field so that the first user can correct the user password; in the case that the number of errors is greater than or equal to the first threshold, the second electronic device displays the second interface, or the second electronic device displays a third control in the lock screen interface, and the second electronic device displays the second interface in response to the operation of triggering the third control.
[0381] The first threshold is pre-set. For example, the first threshold is equal to 1, 2, 3, …, and the application does not limit the value of the first threshold.
[0382] S1540, the second electronic device receives the recovery key in response to a user operation.
[0383] S1550, the second electronic device obtains the first ciphertext of the data encryption key from the non-encrypted storage area in the non-volatile memory.
[0384] S1560, the second electronic device decrypts the first ciphertext using the recovery key to obtain the data encryption key.
[0385] S1570, the second electronic device decrypts the ciphertext of the target data using the data encryption key to obtain the target content data.
[0386] The steps S1540-S1570 are described above and will not be repeated here.
[0387] The key management method provided in the present application can be used as an extension of the full-disk encryption algorithm, so that the data encryption key can be obtained by decrypting the first ciphertext and by decrypting the second ciphertext. This increases the way to obtain the data encryption key, which helps to reduce the risk of not being able to obtain the data encryption key. In the case that at least one of the recovery key or the user password (and / or the hardware key) is not lost, the electronic device can successfully obtain the data encryption key after being powered on or unlocked, which helps to improve the reliability of the key management method.
[0388] Example 2: Scenario of obtaining the data stored in the non-volatile memory through the recovery key after the hardware device of the first electronic device is replaced. In this embodiment, the second electronic device 300 in FIG. 1 is obtained after the first electronic device 100 is replaced with part of the electronic device.
[0389] As shown in FIG. 16, the second electronic device is installed with a non-volatile memory, and the user provides the recovery key to the second electronic device; the second electronic device can successfully decrypt the data encryption key according to the recovery key, so as to decrypt the ciphertext of the content data stored in the non-volatile memory through the data encryption key. Subsequently, the second electronic device provides the content data for the user to use.
[0390] Example 3: Scenario of obtaining the content data stored in the external non-volatile memory through the recovery key. In this embodiment, it is executed by the second electronic device 300 in FIG. 1. In this embodiment, the second electronic device and the first electronic device are different electronic devices.
[0391] As shown in FIG. 17, the second electronic device is connected with the non-volatile memory detached from the first electronic device. The user provides the recovery key to the second electronic device; the second electronic device can successfully decrypt the data encryption key according to the recovery key, so as to decrypt the ciphertext of the content data stored in the non-volatile memory by the data encryption key. Subsequently, the second electronic device provides the content data for the user to use.
[0392] Through Examples 2 and 3, it can be found that, since in the key management method provided in the present solution, the first ciphertext of the data encryption key is decrypted depending on the recovery key, instead of the hardware key of the electronic device. Therefore, in the case where the hardware of the electronic device is replaced, or only the non-volatile memory is kept intact, the first ciphertext can still be read from the non-volatile memory, and the data encryption key can be obtained by the recovery key provided by the user and the first ciphertext. In this way, it helps to improve the adaptability of the key management method to different scenarios, so that the key management method is more universal.
[0393] In some embodiments, the recovery key is also used to trigger the modification of the user password. In some embodiments, in the case where the recovery key satisfies a verification condition, a third interface is displayed, the third interface being used to receive an operation of resetting the user password; in response to a third user password input by the user on the third interface, the first user password is replaced by the third user password, the first user password being used to encrypt the data encryption key to output the second ciphertext, and / or decrypt the second ciphertext to output the data encryption key, the second ciphertext being stored in the encrypted area of the non-volatile memory.
[0394] The verification condition is used to verify whether the recovery key provided by the user is correct. The verification condition is at least one of the following: the recovery key correctly decrypts the first ciphertext, and the first credential and the second credential are the same. For details of the verification condition, please refer to the following embodiments.
[0395] Optionally, the third interface is used to reset the user password, and the third user password is set by the user, the third user password being used to replace the first user password.
[0396] In some embodiments, the key management method further includes the following steps: the execution subject of the following steps is the second electronic device 300 shown in FIG. 1. In the present example, the second electronic device and the first electronic device are the same electronic device. Optionally, the functional modules of the second electronic device 300 include a recovery key management module and a password management module. Please refer to FIG. 18, which is a third flowchart of the key management method provided in the embodiments of the present application.
[0397] In step S1810, the second electronic device receives the recovery key in response to the user operation.
[0398] For details of step S1810, please refer to the description of step S1210 above, which will not be repeated here.
[0399] Step S1820, in case that the first ciphertext is correctly decrypted by the recovery key, the second electronic device acquires the updated user password in response to the operation of resetting the user password.
[0400] Optionally, in case that the first ciphertext is decrypted by the recovery key to obtain the data encryption key, it indicates that the recovery key input by the user is correct, and further indicates that the user is the user of the second electronic device. In this case, the second electronic device supports resetting the user password. In case that the first ciphertext cannot be decrypted by the recovery key to obtain the data encryption key, the second electronic device does not reset the user password.
[0401] Step S1830, the second electronic device replaces the first user password with the third user password.
[0402] After the replacement is completed, the user can use the third user password to unlock the second electronic device.
[0403] In the present example, the second electronic device and the first electronic device are the same electronic device. Optionally, the function modules of the second electronic device 300 include a password management module. Please refer to FIG. 19, which is a fourth flowchart of a key management method provided by the present application.
[0404] Step S1910, the second electronic device receives the recovery key in response to the user operation.
[0405] For details of step S1910, please refer to the description of step S1210 above, which will not be repeated here.
[0406] Step S1920, the second electronic device generates the first credential according to the recovery key.
[0407] The second credential is used to determine the correctness of the recovery key provided by the user.
[0408] Step S1930, in case that the first credential and the second credential stored in the non-volatile memory satisfy the verification condition, a third interface is displayed.
[0409] Optionally, the verification condition is that the second credential is consistent with the first credential. Illustratively, in case that the second credential is the same as the first credential, the second electronic device acquires the second user password in response to the operation of resetting the user password; in case that the second credential is different from the first credential, the second electronic device displays a key error prompt. The key error prompt is used to remind the user that the recovery key provided by the user is incorrect.
[0410] The first user password and the second user password are a lock screen password for converting the first electronic device from a locked state to an unlocked state. Optionally, the first user password and the second user password are used for encrypting and / or decrypting the second ciphertext of the data encryption key. The second ciphertext is stored in the startup area of the non-volatile memory.
[0411] In step S1940, the second electronic device replaces the first user password with the third user password in response to the third user password input by the user on the third interface.
[0412] After the replacement is completed, the user can use the third user password to unlock the second electronic device.
[0413] The embodiment provides a new way of updating a user password, and resetting the user password by restoring a key, which helps to improve the security of resetting the user password.
[0414] FIG. 20 is a schematic diagram of a scenario of resetting a user password according to a restoration key. As shown in FIG. 20, in the case where the user forgets the first user password, the second electronic device is supported to provide a restoration key, and a process of resetting the user password is triggered by the restoration key.
[0415] The embodiment triggers the process of resetting the user password by the restoration key. Since the restoration key is known to the user using the second electronic device, the restoration key is reset by the restoration key, which helps to improve the security of resetting the user password.
[0416] The following describes an interaction process between functional modules in the second electronic device in the process of the second electronic device performing the key management method. The embodiment is cooperatively completed by the file encryption module, the restoration key management module, and the password management module shown in FIG. 5A. As shown in FIG. 21, the embodiment at least includes the following steps:
[0417] In step S2110, the restoration key management module acquires the restoration key in response to a user operation.
[0418] In step S2120, the restoration key management module sends the restoration key to the password management module.
[0419] In step S2130, the password management module acquires the first credential according to the restoration key.
[0420] Optionally, the password management module encrypts the restoration key by using a second encryption algorithm to acquire the first credential.
[0421] In step S2140, the password management module verifies whether the first credential is consistent with the second credential stored in the non-volatile memory.
[0422] Optionally, the first credential is stored in the non-volatile memory, and the password management module reads the first credential from the non-volatile memory. The password management module compares whether the second credential is the same as the first credential.
[0423] Illustratively, in the case that the second credential is the same as the first credential, the password management module determines that the verification is successful. That is, the recovery key input by the user is correct, the password management module informs the recovery key management module that the recovery key verification is successful, and the recovery key management module performs step S2150.
[0424] Illustratively, in the case that the second credential is different from the first credential, the password management module determines that the verification fails, that is, the recovery key input by the user is incorrect, the password management module informs the recovery key management module that the recovery key verification fails, and the present process ends.
[0425] Step S2150, the recovery key management module acquires a third user password in response to an operation of resetting the user password. The third user password is a user password newly set by the user.
[0426] Optionally, the operation of resetting the user password is implemented by inputting the third user password in a third interface.
[0427] Step S2160, the recovery key management module sends the third user password to the password management module.
[0428] Step S2170, the password management module replaces the first user password with the third user password. Optionally, after the replacement is successful, the password management module informs the recovery key management module that the third user password is registered successfully, so that the recovery key management module determines that the replacement of the first user password with the third user password is completed.
[0429] Step S2180, the recovery key management module sends the third user password to the file encryption module.
[0430] Step S2190, the file encryption module encrypts the data encryption key according to the third user password to acquire updated second ciphertext.
[0431] Optionally, after the second ciphertext is acquired, the file encryption module informs the recovery key management module that the second ciphertext is generated successfully. Subsequently, the file encryption module stores the second ciphertext in the encrypted area of the non-volatile memory.
[0432] After the user password reset is completed, the user can unlock the second electronic device by the third user password.
[0433] The embodiment supports the user to open the reset process of the user password through the recovery key after forgetting the user password. In this way, it helps to make up for the inconvenience caused by the electronic device being unable to be unlocked due to the user forgetting the user password.
[0434] The key management method provided by the embodiment is described in detail above in combination with FIGS. 6 to 21. The electronic device related to the embodiment is described in detail below in combination with FIG. 22. All or part of any feature of any embodiment in the present application can be freely combined. The combined technical solution also belongs to the scope described in the present application.
[0435] In a possible design, FIG. 22 is a structural schematic diagram of an electronic device provided by an embodiment of the present application. Optionally, the electronic device 2200 represents at least one of the first electronic device 100 and the second electronic device 300 in FIG. 1. As shown in FIG. 22, the electronic device 2200 can include a transceiver unit 2201 and a processing unit 2202. The electronic device 2200 can be used to implement the functions of the electronic device involved in the above method embodiments.
[0436] Optionally, the transceiver unit 2201 is configured to support the second electronic device to perform S922, S930, S940 and S970 in FIG. 9; and / or, is configured to support the first electronic device to perform S1410 in FIG. 14, and / or, is configured to support the first electronic device to perform S1510, S1530 and S1550 in FIG. 15, and / or, is configured to support the first electronic device to perform S1470 in FIG. 19.
[0437] Optionally, the processing unit 2202 is configured to support the second electronic device to perform S910, S950, S960 in FIG. 9; and / or, is configured to support the first electronic device to perform S1420 and S1430 in FIG. 14, and / or, is configured to support the first electronic device to perform S1532-S1540 and S1550-S1554 in FIG. 15; and / or, is configured to support the first electronic device to perform S1440-S1460 in FIG. 16, and / or, is configured to support the first electronic device to perform S1710-S1740 in FIG. 17, and / or, is configured to support the first electronic device to perform S1810-S1870 in FIG. 18, and / or, is configured to support the first electronic device to perform S1480-S1490 in FIG. 19, and / or, is configured to support the first electronic device to perform S1495-S1496 in FIG. 22.
[0438] The transceiving unit can include a receiving unit and a sending unit, can be implemented by a transceiver or a transceiver related circuit component, and can be a transceiver or a transceiving module. The operations and / or functions of each unit in the electronic device 2200 are respectively used to implement the corresponding procedures of the key management method described in the above method embodiments. All related contents of each step described in the above method embodiments can be referred to the function description of the corresponding functional unit, and will not be repeated here for brevity.
[0439] Optionally, the electronic device 2200 shown in FIG. 22 can further include a storage unit (not shown in FIG. 22) having a program or instruction stored therein. When the transceiving unit 2201 and the processing unit 2202 execute the program or instruction, the electronic device 2200 shown in FIG. 22 can perform the key management method described in the above method embodiments.
[0440] The technical effects of the electronic device 2200 shown in FIG. 22 can refer to the technical effects of the key management method described in the above method embodiments, which will not be repeated here.
[0441] In addition to the form of the electronic device 2200, the technical solutions provided in the present application can also be a functional unit or a chip in the electronic device, or a device matched with the electronic device.
[0442] The technical effects of the first electronic device 2200 shown in FIG. 22 can refer to the technical effects of the key management method described in the above method embodiments, which will not be repeated here.
[0443] In addition to the form of the first electronic device 2200, the technical solutions provided in the present application can also be a functional unit or a chip in the first electronic device, or a device matched with the first electronic device.
[0444] The chip system provided in the present application embodiment includes a processor and a memory coupled with the processor. The memory is used to store a program or instruction. When the program or instruction is executed by the processor, the chip system implements the method in any of the above method embodiments.
[0445] The chip system provided in the present application embodiment includes a processor and a memory coupled with the processor. The memory is used to store a program or instruction. When the program or instruction is executed by the processor, the chip system implements the method in any of the above method embodiments.
[0446] Optionally, the processor in the chip system can be one or more. The processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which is implemented by reading software codes stored in a memory.
[0447] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or arranged separately from the processor, and the embodiments of the present application do not limit the same. Exemplarily, the memory can be a non-transient processor, for example, a read-only memory (ROM), which can be integrated on the same chip as the processor or arranged on different chips respectively, and the embodiments of the present application do not limit the type of the memory and the arrangement manner of the memory and the processor.
[0448] Exemplarily, the chip system can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD) or other integrated chip.
[0449] It should be understood that each step in the above method embodiments can be completed by the integrated logic circuit of hardware in the processor or the instruction in the form of software. The method steps disclosed in the embodiments of the present application can be directly embodied as hardware processor execution or executed by the combination of hardware and software modules in the processor.
[0450] The embodiments of the present application further provide a computer readable storage medium, which stores a computer program. When the computer program runs on a computer, the computer is caused to execute the above related steps to implement the key management method in the above embodiments.
[0451] The embodiment of the present application further provides a computer program product, which, when running on a computer, causes the computer to execute the related steps to realize the key management method in the above embodiment.
[0452] In addition, the embodiment of the present application further provides an apparatus. The apparatus can be specifically a component or a module, and can include one or more processors and memories connected thereto. The memories are used to store computer programs. When the computer programs are executed by the one or more processors, the apparatus executes the key management method in the above method embodiments.
[0453] The computer readable storage medium, the computer program product or the chip provided by the embodiment of the present application are all used to execute the corresponding method provided above. Therefore, the beneficial effects achieved thereby can refer to the beneficial effects in the corresponding method provided above, which will not be described here again.
[0454] The steps of the method or algorithm described in connection with the embodiments disclosed herein can be implemented in hardware, or as software executed by a processor. The software instructions can be included in a software module or used by a processor. The software module can be stored in a random access memory, a flash memory, a read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a read-only optical disk, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an application-specific integrated circuit.
[0455] From the above description of the embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional modules is taken as an example for illustration. In actual application, the above functions can be completed by different functional modules according to needs; that is, the internal structure of the apparatus is divided into different functional modules to complete all or part of the functions described above. The specific working process of the above-described system, apparatus and unit can refer to the corresponding process in the foregoing method embodiments, which will not be described here again.
[0456] In several embodiments provided in the present application, it should be understood that the disclosed method can be implemented in other ways. The above-described device embodiments are only illustrative. For example, the division of the modules or units is only a logical function division, and actual implementation can have another division manner. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, modules or units, which can be electrical, mechanical or other forms.
[0457] In addition, each function unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit. The computer readable storage medium includes, but is not limited to, any one of the following: a U disk, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk or an optical disk, and various media that can store program codes.
[0458] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited to this. Any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A key management method characterized by comprising: The method is performed by a first electronic device, and the method comprises: In response to a key generation operation, a recovery key is generated, and the recovery key is displayed; A data encryption key is encrypted using the recovery key to obtain first ciphertext of the data encryption key, the data encryption key being used to encrypt target content data in a non-volatile memory and / or to decrypt; The first ciphertext is stored in a non-encrypted storage area of the non-volatile memory.
2. The method of claim 1, wherein, After the recovery key is generated in response to the key generation operation, the method further comprises: In response to an account login operation, account information is sent to a server; In response to a key binding operation, a key binding request is sent to the server, the key binding request carrying key data, the key data being the encrypted recovery key, and the key binding request being used to request binding of the account information and the recovery key.
3. The method of claim 2, wherein, Before the key binding request is sent to the server in response to the key binding operation, the method further comprises: An end-to-cloud key is obtained, the end-to-cloud key being used to encrypt communication data between the first electronic device and the server; The recovery key is encrypted according to a public key in the end-to-cloud key to obtain the key data.
4. The method of claim 2, wherein, The recovery key comprises a first sub-key and a second sub-key; The recovery key is displayed in response to the key generation operation, and the first sub-key is displayed. The key data is the encrypted second sub-key, and the key binding request is used to request binding of the account information and the second sub-key.
5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: A first credential is obtained according to the recovery key, the first credential being used to identify the recovery key; The first credential is stored in the non-volatile memory.
6. The method according to claim 1 or 5, characterized in that, After the first ciphertext is stored in the non-encrypted storage area of the non-volatile memory, the method further comprises: In response to a user operation, the recovery key is received; The first ciphertext is read from the non-encrypted storage area in the non-volatile memory; The data encryption key is obtained by decrypting the first ciphertext using the recovery key.
7. The method according to any one of claims 1 to 6, characterized in that, Second ciphertext of the data encryption key is stored in a startup area of the non-volatile memory, the second ciphertext being obtained by encrypting the data encryption key using a preset first user password; After the first ciphertext is stored in the non-encrypted storage area of the non-volatile memory, the method further comprises: In response to an operation of inputting a user password, a second user password provided by a user is received; The second ciphertext is read from the startup area in the non-volatile memory; In a case where the second user password cannot decrypt the second ciphertext, a second interface is displayed, the second interface being used to receive the recovery key.
8. The method according to any one of claims 1 to 7, characterized in that, The method further comprises: In a case where the recovery key satisfies a verification condition, a third interface is displayed, the third interface being used to receive an operation of resetting a user password; In response to a third user password input by the user at the third interface, the first user password is replaced by the third user password, the first user password is used to encrypt the data encryption key to output second ciphertext, and / or the second ciphertext stored in the encrypted area of the non-volatile memory is decrypted to output the data encryption key.
9. The method of claim 8, wherein, The third interface is displayed in a case where the recovery key meets a verification condition. A first credential is obtained according to the recovery key, and the first credential is used to determine the correctness of the recovery key provided by the user. The third interface is displayed in a case where the first credential is the same as a second credential stored in the non-volatile memory.
10. The method according to any one of claims 6 to 9, characterized in that, The user operation is obtained from a lock screen interface, and the lock screen interface is a display interface of the first electronic device in a case where the first electronic device is powered on, wakes up, or requests to open a first application; or the user operation is obtained from a password reset interface.
11. The method according to any one of claims 1 to 10, characterized in that, A data bit number of the recovery key is greater than or equal to a data bit number of the data encryption key.
12. A key management method characterized by comprising: The method is performed by a second electronic device, and the method comprises: In response to a user operation, a recovery key is received; First ciphertext of a data encryption key is obtained from a non-encrypted storage area in a non-volatile memory; The first ciphertext is decrypted using the recovery key to obtain the data encryption key, and the data encryption key is used to encrypt and / or decrypt target content data in the non-volatile memory.
13. The method of claim 12, wherein, The recovery key is received in response to a user operation, comprising: In response to an operation of inputting the recovery key, the recovery key input by the user is received.
14. The method of claim 12, wherein, The recovery key is received in response to a user operation, comprising: In response to an operation of searching for the recovery key, a key acquisition request is sent to a server, and the key acquisition request is used to acquire key data bound to account information; Key data sent by the server is received; The recovery key is obtained according to the key data.
15. The method of claim 14, wherein, The recovery key comprises a first sub-key and a second sub-key, the recovery key is received in response to a user operation, comprising receiving the first sub-key in response to the user operation; and the key data is the encrypted second sub-key.
16. The method according to claim 14 or 15, characterized in that The recovery key is obtained according to the key data, comprising: The key data is decrypted according to a private key in an end-cloud key to obtain the recovery key, and the end-cloud key is used to encrypt communication data between the second electronic device and the server.
17. The method according to any one of claims 14 to 16, characterized in that, Before the key acquisition request is sent to the server in response to the operation of searching for the recovery key, the method further comprises: A first interface is displayed, and the first interface is used to receive the account information input by the user.
18. The method according to any one of claims 12 to 17, characterized in that, The first ciphertext of the data encryption key is obtained from the non-encrypted storage area in the non-volatile memory, comprising: A first file directory corresponding to the non-encrypted storage area is obtained according to a file management system used to manage the non-volatile memory, the file management system is used to divide a storage area in the non-volatile memory, and the first file directory is used to index data stored in the non-encrypted storage area; read the first ciphertext from at least one file stored in the first file directory.
19. The method according to any one of claims 12 to 18, characterized in that, The non-volatile memory stores a second ciphertext of the data encryption key, the second ciphertext being obtained by encrypting the data encryption key with a preset first user password; Before receiving the recovery key in response to the user operation, the method further includes: In response to an operation of inputting a user password, receiving a second user password provided by the user; Obtaining the second ciphertext of the data encryption key from a boot area in the non-volatile memory; In a case where the second user password fails to decrypt the second ciphertext, displaying a second interface, the second interface being configured to receive the recovery key.
20. The method of any one of claims 12-19, wherein: The non-volatile memory is a non-volatile memory installed in the second electronic device, or the non-volatile memory is a non-volatile memory detached from another electronic device and having a data transmission channel with the second electronic device.
21. The method according to any one of claims 12 to 20, characterized in that, After receiving the recovery key in response to the user operation, the method further includes: In a case where the recovery key satisfies a verification condition, displaying a third interface, the third interface being configured to receive an operation of resetting a user password; In response to a third user password input by the user on the third interface, replacing the first user password with the third user password, the first user password being used to encrypt the data encryption key to output the second ciphertext, and / or decrypt the second ciphertext to output the data encryption key, the second ciphertext being stored in an encryption area of the non-volatile memory.
22. The method of claim 21, wherein, The displaying of the third interface in the case where the recovery key satisfies the verification condition includes: According to the recovery key, obtaining a first credential, the first credential being used to determine the correctness of the recovery key provided by the user; In a case where the first credential is identical to a second credential stored in the non-volatile memory, displaying the third interface.
23. The method according to any one of claims 12 to 22, characterized in that, The user operation is obtained from a lock screen interface, the lock screen interface being a display interface of the second electronic device in a case where the second electronic device is powered on, woken up, or requested to open a first application; or the user operation is obtained from a password resetting interface.
24. An electronic device, comprising: The electronic device includes: a display screen configured to display an interface; a transceiver configured to transmit and receive radio signals; a memory configured to store computer program instructions; a processor configured to execute the computer program instructions to support the electronic device to implement the method of any one of claims 1-11, or to support the electronic device to implement the method of any one of claims 12-23.
25. A computer readable storage medium, characterized in that, The computer readable storage medium stores computer programs, when the computer programs are run on a computer, causing the method of any one of claims 1-11, or to support the electronic device to implement the method of any one of claims 12-23.
26. A computer program product comprising instructions, wherein: When the computer program product is run on a computer, it causes the computer to perform the method of any one of claims 1 to 11, or to support the electronic device to implement the method of any one of claims 12 to 23.
Citation Information
Patent Citations
Data protection method and electronic equipment
CN113609498A
Storage device with encryption function
CN115017556A
A method for backup and recovery of encryption key
CN1702999A
Key Recovery in Encrypting Storage Devices
US20090080662A1
Cryptographic key management
US20210019450A1