Electronic device and control method therefor

WO2026160879A1PCT designated stage Publication Date: 2026-07-30SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2026-01-22
Publication Date
2026-07-30

Smart Images

  • Figure KR2026001329_30072026_PF_FP_ABST
    Figure KR2026001329_30072026_PF_FP_ABST
Patent Text Reader

Abstract

Provided are an electronic device and a control method therefor. The electronic device comprises: a memory storing instructions; and a processor; wherein the instructions, when executed individually or collectively by the processor, may cause the electronic device to: acquire information about a user and usage information of the electronic device; acquire information about reliability of the user on the basis of the information about the user and the usage information of the electronic device; acquire information about a risk level of a user operation on the basis of the usage information of the electronic device; identify an abnormal access to the electronic device on the basis of the information about the reliability of the user and the information about the risk level of the user operation; and perform a security operation of the electronic device with respect to the abnormal access when the abnormal access to the electronic device is identified.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic device and control method thereof

[0001] The present disclosure relates to an electronic device and a method for controlling the same, and more specifically, to an electronic device and a method for controlling the same that detect abnormal access to the electronic device and perform a security operation.

[0002] As communication technology develops and the proliferation of electronic devices increases, continuous efforts are being made to maintain communication security between electronic devices. Accordingly, most electronic devices adopt various authentication methods to protect personal information. For example, electronic devices protect personal information through the 3Ps, such as PIN information, pattern information, and password information.

[0003] However, 3Ps can be leaked through shoulder surfing or brute force attacks. Such 3P leaks can lead to the addition of illegal biometric authentication information or the deletion of existing biometric authentication information. This can result in additional damage, such as financial transactions, and thus requires the exploration of measures to ensure the security of users' personal information.

[0004] Meanwhile, the information described above may be provided as related art for the purpose of aiding understanding of the present disclosure. No claim or determination is made as to whether any of the foregoing may be applied as prior art related to the present disclosure.

[0005] According to one embodiment of the present disclosure, an electronic device comprises: a memory for storing instructions; and a processor; wherein, when the instructions are executed individually or collectively by the processor, the electronic device obtains information about a user and information on the use of the electronic device, obtains information about the reliability of the user based on the information about the user and information on the use of the electronic device, obtains information about the risk of the user's operation based on the information on the use of the electronic device, identifies whether there is abnormal access to the electronic device based on the information about the reliability of the user and information about the risk of the user's operation, and if abnormal access to the electronic device is identified, performs a security operation of the electronic device regarding the abnormal access.

[0006] When the above instructions are executed individually or collectively by the processor, the electronic device may obtain a first score for the reliability of the user based on connection information with an external device connected to the electronic device, location information of the user, wearing information of a wearable device connected to the electronic device, movement information of the electronic device, and touch information input on the electronic device, and obtain a second score for the risk of the user's behavior based on sensitivity information of the application used by the user and behavioral sensitivity information of the user using the electronic device.

[0007] A first factor corresponding to connection information with the external device, a second factor corresponding to the user's location information, and a third factor corresponding to the wearing information of the wearable device are factors having fixed values, and a fourth factor corresponding to movement information of the electronic device and touch information input on the electronic device is a factor having a value that varies according to conditions, a first weight corresponding to the first factor has a value that varies according to the amount of usage of the external device by the user, a fourth weight corresponding to the fourth factor has a value that varies according to existing learning results, a second weight corresponding to the second factor and a third weight corresponding to the third factor have fixed values, and the first score may be a score obtained as the sum of the products of the weights corresponding to the first to fourth factors.

[0008] The fifth factor corresponding to the sensitivity information of the above application and the sixth factor corresponding to the behavioral sensitivity information are factors having values ​​that vary according to conditions, the fifth weight corresponding to the fifth factor and the sixth weight corresponding to the sixth factor have values ​​that vary according to existing learning results, and the second score may be a score obtained as the sum of the products of the weights corresponding to the fifth and sixth factors.

[0009] When the above instructions are executed individually or collectively by the processor, the electronic device may acquire a behavior graph for operations up to the point where the electronic device is unlocked and performs a sensitive action, and acquire behavior sensitivity information based on the behavior graph.

[0010] The above behavior graph may consist of nodes corresponding to actions and edges representing the preceding and succeeding behavior relationships.

[0011] When the above instructions are executed individually or collectively by the processor, the electronic device may identify whether there is abnormal access to the electronic device based on whether the difference between the second score and the first score is greater than or equal to a threshold value.

[0012] When the above instructions are executed individually or collectively by the processor, the electronic device may be configured to perform different security operations according to the difference value when the difference value between the second score and the first score is greater than or equal to the threshold value.

[0013] When the above instructions are executed individually or collectively by the processor, the electronic device may perform a first security operation of storing usage information of the electronic device related to the abnormal access when the difference value is in a first range, perform a second security operation of transmitting information related to the abnormal access to the wearable device when the difference value is in a second range greater than the first range, perform a third security operation of switching the electronic device to a locked state and requesting re-authentication when the difference value is in a third range greater than the second range, and perform a fourth security operation of requesting additional authentication when the difference value is in a fourth range greater than the third range.

[0014] Meanwhile, a control method for an electronic device according to one embodiment of the present disclosure comprises: a step of obtaining information about a user and information on the use of the electronic device; a step of obtaining information on the reliability of the user based on the information about the user and information on the use of the electronic device, and obtaining information on the risk of the user's operation based on the information on the use of the electronic device; a step of identifying whether there is abnormal access to the electronic device based on the information on the reliability of the user and information on the risk of the user's operation; and a step of performing a security operation of the electronic device regarding the abnormal access when abnormal access to the electronic device is identified.

[0015] The step of obtaining information on the risk level of the user action may include: a step of obtaining a first score on the user's reliability based on connection information with an external device connected to the electronic device, location information of the user, wearing information of a wearable device connected to the electronic device, movement information of the electronic device, and touch information input on the electronic device; and a step of obtaining a second score on the risk level of the user action based on sensitivity information of an application used by the user and behavioral sensitivity information of the user using the electronic device.

[0016] A first factor corresponding to connection information with the external device, a second factor corresponding to the user's location information, and a third factor corresponding to the wearing information of the wearable device are factors having fixed values, and a fourth factor corresponding to movement information of the electronic device and touch information input on the electronic device is a factor having a value that varies according to conditions, a first weight corresponding to the first factor has a value that varies according to the amount of usage of the external device by the user, a fourth weight corresponding to the fourth factor has a value that varies according to existing learning results, a second weight corresponding to the second factor and a third weight corresponding to the third factor have fixed values, and the first score may be a score obtained as the sum of the products of the weights corresponding to the first to fourth factors.

[0017] The fifth factor corresponding to the sensitivity information of the above application and the sixth factor corresponding to the behavioral sensitivity information are factors having values ​​that vary according to conditions, the fifth weight corresponding to the fifth factor and the sixth weight corresponding to the sixth factor have values ​​that vary according to existing learning results, and the second score may be a score obtained as the sum of the products of the weights corresponding to the fifth and sixth factors.

[0018] The step of obtaining information regarding the risk level of the above user action may involve obtaining a behavior graph for actions up to the performance of sensitive actions after the electronic device is unlocked, and obtaining the behavior sensitivity information based on the behavior graph.

[0019] The above behavior graph may consist of nodes corresponding to actions and edges representing the preceding and succeeding behavior relationships.

[0020] The above identifying step can identify whether there is abnormal access to the electronic device based on whether the difference between the second score and the first score is greater than or equal to a threshold value.

[0021] The step of performing the above may perform different security operations depending on the difference value when the difference value between the second score and the first score is greater than or equal to the threshold value.

[0022] The steps performed above may include: a first security operation to store usage information of the electronic device related to the abnormal access when the difference value is in a first range; a second security operation to transmit information related to the abnormal access to the wearable device when the difference value is in a second range greater than the first range; a third security operation to switch the electronic device to a locked state and request re-authentication when the difference value is in a third range greater than the second range; and a fourth security operation to request additional authentication when the difference value is in a fourth range greater than the third range.

[0023] In relation to the description of the drawings, the same or similar reference numerals may be used for identical or similar components.

[0024] FIG. 1 is a drawing for explaining the theft of personal information from an electronic device according to one embodiment of the present disclosure.

[0025] FIG. 2 is a block diagram showing the configuration of an electronic device according to one embodiment of the present disclosure.

[0026] FIG. 3 is a block diagram of a configuration for protecting personal information by detecting abnormal access according to one embodiment of the present disclosure.

[0027] FIG. 4 is a block diagram illustrating a set of libraries for protecting 3P according to one embodiment of the present disclosure.

[0028] FIG. 5 is a flowchart illustrating a method for detecting abnormal access and performing a security operation according to one embodiment of the present disclosure.

[0029] FIGS. 6a to 7b are drawings for explaining a method for calculating a first score and a second score according to one embodiment of the present disclosure.

[0030] FIGS. 8a and FIGS. 8b are drawings illustrating behavior graphs according to one embodiment of the present disclosure.

[0031] FIG. 9 is a flowchart illustrating a method for performing different security operations according to the difference value of the first and second scores, according to one embodiment of the present disclosure.

[0032] The present disclosure will be described in detail below with reference to the attached drawings.

[0033] The terms used in the embodiments of this disclosure have been selected to be as widely used as possible, taking into account their functions within this disclosure; however, these terms may vary depending on the intent of those skilled in the art, case law, the emergence of new technologies, etc. Additionally, in specific cases, terms may be arbitrarily selected by the applicant, and in such cases, their meanings will be described in detail in the description section of the disclosure. Therefore, terms used in this disclosure should be defined not merely by their names, but based on their meanings and the overall content of this disclosure.

[0034] In this specification, expressions such as “have,” “may have,” “include,” or “may include” indicate the presence of the above features (e.g., numerical values, functions, actions, or components such as parts) and do not exclude the presence of additional features.

[0035] The expression "at least one of A or / and B" should be understood as representing either "A" or "B" or "A and B".

[0036] Expressions such as "first," "second," "first," or "second" used in this specification may modify various components regardless of order and / or importance, and are used only to distinguish one component from another and do not limit said components.

[0037] Where it is stated that a component (e.g., a first component) is "(operatively or communicatively) coupled with / to" or "connected to" another component (e.g., a second component), it should be understood that the component may be directly connected to the other component or connected through the other component (e.g., a third component).

[0038] The singular expression includes the plural expression unless the context clearly indicates otherwise. In this application, terms such as “comprising” or “consisting of” are intended to specify the existence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.

[0039] In the embodiments, a "module" or "part" performs at least one function or operation and may be implemented in hardware or software, or a combination of hardware and software. Additionally, a plurality of "modules" or a plurality of "parts" may be integrated into at least one module and implemented by at least one processor, except for a "module" or "part" that needs to be implemented in specific hardware.

[0040] In the present disclosure, the term "user" may refer to a person using an electronic device or a device using an electronic device (e.g., an artificial intelligence electronic device).

[0041] In the present disclosure, the term "user input" refers to user input for controlling an electronic device and may be referred to by various terms such as user command, user interaction, user touch, etc.

[0042] In the present disclosure, the UI is a visual and functional layer that enables interaction between an electronic device (100) and a user, and can provide information or control the functions of the electronic device (100). UI elements are components that make up the UI and can be used to interact with the user. In this case, UI elements may be referred to by various terms such as icons, indicators, objects, etc.

[0043] The various elements and areas in the drawings are depicted schematically. Accordingly, the technical concept of the present invention is not limited by the relative sizes or spacing depicted in the attached drawings.

[0044] FIG. 1 is a drawing for explaining the theft of personal information by an electronic device according to one embodiment of the present disclosure.

[0045] The electronic device (100) may maintain a locked state (10). The locked state is a state in which the functions of the electronic device (200) are partially restricted to limit use by unauthorized users, and may be referred to by various terms such as a blocked state, a standby state, a protected state, or a disabled state. While the electronic device (100) maintains a locked state (10), the electronic device (100) may be stolen or misappropriated by an attacker.

[0046] An electronic device (100) can be converted from a locked state (10) to an unlocked state (20) through the device's 3P. The unlocked state is a state in which the functions of the electronic device (100) can be used through user authentication using 3P from the locked state, and can be referred to by various terms such as unlocked state, activated state, and access allowed state. While the electronic device (100) is being converted from a locked state (10) to an unlocked state (20), a situation may occur in which the 3P is leaked through an attack such as shoulder surfing by an attacker.

[0047] Additionally, the electronic device (100) may leak information (30) in the device unlocked state (20). Here, the information leak may be a leak of the user's personal information or 3P related to financial transactions. In one embodiment, the electronic device (100) may leak 3P related to financial transactions while performing user authentication using 3P related to financial transactions to perform financial transactions (40).

[0048] Additionally, while the electronic device (100) maintains a device locked state (20), financial transactions (40) can be performed through biometric authentication. At this time, a problem arises in which the electronic device (100) can be used for illegal financial transactions through illegal biometric authentication information generated by an attacker.

[0049] As described above, the present disclosure is to provide a security operation by detecting abnormal access, such as 3P theft, that may occur while the electronic device (100) maintains a locked state (10) or an unlocked state (20).

[0050]

[0051] FIG. 2 is a block diagram showing the configuration of an electronic device according to one embodiment of the present disclosure. As shown in FIG. 2, the electronic device (100) may include a communication interface (110), a sensor (120), a display (130), a memory (140), and a processor (150). Meanwhile, the configuration of the electronic device (100) as shown in FIG. 2 is merely one embodiment, and it is obvious that some components may be deleted or some components may be added depending on the implementation example of the device (100).

[0052] In addition, the electronic device (100) according to one embodiment of the present disclosure may be implemented as an electronic device such as a smartphone, but this is merely one embodiment and it is obvious that it may be implemented as various user terminals such as a smart watch, a tablet PC, etc.

[0053] The communication interface (110) is a configuration that performs communication with various types of external devices according to various types of communication methods. The communication interface (110) may include at least one wireless communication module. Here, each communication module may be implemented in the form of at least one hardware chip. The wireless communication module may be a module that communicates with an external device wirelessly. For example, the wireless communication module may include at least one module among a Wi-Fi interface, a Bluetooth interface, an infrared communication interface, or other wireless communication interfaces. The other wireless communication interface may include at least one communication chip that performs communication according to various wireless communication standards such as Zigbee, 3G (3rd Generation), 3GPP (3rd Generation Partnership Project), LTE (Long Term Evolution), LTE-A (LTE Advanced), 4G (4th Generation), 5G (5th Generation), etc., in addition to the communication methods described above.

[0054] In one embodiment, the electronic device (100) may further include a Global Positioning System (GPS) module. The GPS module is configured to receive GPS signals and determine the user's location.

[0055] The sensor (120) can acquire data about the surrounding environment of the electronic device (100) or a user using the electronic device (100). The sensor (120) may include an inertial sensor, a magnetic sensor, a barometric pressure sensor, a biosensor, a temperature sensor, and an electrode sensor.

[0056] An inertial sensor is a sensor that detects inertia, such as an accelerometer or a gyroscope. An inertial sensor may be equipped with only an accelerometer (3-axis) or a 6-axis sensor including an accelerometer and a gyroscope. An inertial sensor can acquire sensing values ​​regarding motion, gesture, impact, posture, and activity (sedentary, moving, sports) of an electronic device (100). A magnetic sensor is a sensor that can acquire sensing values ​​for measuring orientation by detecting external magnetic force and detecting the Earth's magnetic field. A barometric pressure sensor is a sensor for detecting air pressure, and altitude can be estimated using the barometric pressure sensor. A biosensor is a sensor that receives light absorbed, scattered, or reflected by irradiating light onto a living organism. The emitter of a biosensor emits light of various bands and may be composed of elements such as LEDs, lasers, and VCSELs (vertical cavity surface emitting lasers). The band of the light-emitting part can be composed of various wavelengths such as green, red, infrared (IR), blue, yellow, and ultraviolet (UV). The receiver of the biosensor can receive light reflected or transmitted by the light irradiated from the light-emitting part and store the converted value in memory (140) or sensor buffer through an ADC (analog to digital converter). The receiver of the biosensor can be composed of a photodiode (PD) or a CMOS (complementary metal-oxide-semiconductor) (camera). The receiver of the biosensor may have a filter to accept light of a specific band or filter out light outside of a specific band. The control unit of the biosensor can be an IC or an AFE (analog front-end), and can control the light-emitting part and the receiver, process received data, and transmit it to a processor (150) or store it in memory (140). Additionally, the biosensor can detect a target by emitting sound waves instead of light to the body.Alternatively, biosensors can utilize various combinations of methods, such as emitting light and receiving absorbed, scattered, or reflected light, emitting sound waves and receiving reflected sound waves, or sensing images. Biosensors may include photoplethysmogram (PPG) sensors that detect pulse waves using light, and can measure heart rate (HR), heart rate variability (HRV), blood oxygen saturation (SpO2), and blood pressure. Furthermore, biosensors may include biomarker sensors that detect specific substances or components within the body. Biomarkers serve as indicators of internal bodily changes, such as cells, blood vessels, proteins, DNA (deoxyribonucleic acid), RNA (ribonucleic acid), and metabolites; they can detect blood glucose, alcohol, advanced glycation end-products (AGEs), and antioxidants. Temperature sensors are sensors that measure the temperature of living organisms or components. Depending on the method, temperature sensors are classified into contact and non-contact types. The temperature value measured by the temperature sensor can be stored in memory (140) or transmitted to a processor (150) to be used to estimate the skin temperature sensor, or to be used for situational awareness and estimating body temperature.

[0057] In one embodiment, the processor (150) can obtain information about the user's movement based on a sensing value obtained through an inertial sensor, and can obtain the user's biometric information based on a sensing value obtained through a biometric sensor or a temperature sensor.

[0058] The display (130) is a display device and can display a graphic user interface (GUI) for applications, functions, and services. The display (130) may have a touch panel superimposed or integrated on at least part or the whole, and may include a touch, pressure sensing, and electrode sensing element through a transparent electrode for bio-sensing. Additionally, the display (140) may include elements such as a liquid crystal display (LCD), an organic light emitting display (OLED), or a micro LED.

[0059] Meanwhile, the display (130) may provide a UI related to security operations. For example, the display (130) may provide a UI containing information related to abnormal access. In one embodiment, the display (130) may provide a UI for user authentication.

[0060] Memory (140) may store at least one instruction regarding the electronic device (100). Additionally, an operating system (O / S) for operating the electronic device (100) may be stored in memory (140). Furthermore, various software programs or applications for operating the electronic device (100) may be stored in memory (140) according to various embodiments of the present disclosure. In one embodiment, various software modules for operating the electronic device (100) may be stored in memory (140) according to various embodiments of the present disclosure, and at least one processor (150) may control the operation of the electronic device (100) by executing the various software modules stored in memory (140). That is, memory (140) is accessed by at least one processor (150), and data reading / writing / modification / deletion / updating by at least one processor (150) may be performed.

[0061] In one or more embodiments, the memory (140) may store various data or programs for estimating a circadian rhythm.

[0062] The processor (150) can control the electronic device (100) according to at least one instruction stored in memory (120).

[0063] In particular, the processor (150) may include one or more processors. Specifically, one or more processors may include one or more of a CPU (central processing unit), GPU (graphics processing unit), APU (accelerated processing unit), MIC (many integrated core), DSP (digital signal processor), NPU (neural processing unit), hardware accelerator, or machine learning accelerator. One or more processors may control one or any combination of other components of an electronic device and may perform operations or data processing related to communication. One or more processors may execute one or more programs or instructions stored in memory. For example, one or more processors may perform a method according to one embodiment of the present disclosure by executing one or more instructions stored in memory. For example, the processor (110) may correspond to a plurality of processors that collectively perform a plurality of operations by dividing them among the processors.

[0064] When a method according to one embodiment of the present disclosure includes a plurality of operations, the plurality of operations may be performed by a single processor or by a plurality of processors. That is, when a first operation, a second operation, and a third operation are performed by a method according to one embodiment, the first operation, the second operation, and the third operation may all be performed by a first processor, or the first operation and the second operation may be performed by a first processor (e.g., a general-purpose processor) and the third operation may be performed by a second processor (e.g., an artificial intelligence dedicated processor). For example, according to one embodiment of the present disclosure, an operation of identifying a control target device using a neural network model may be performed by a processor that performs parallel operations, such as a GPU or an NPU, and an operation of calculating an angle may be performed by a general-purpose processor, such as a CPU.

[0065] One or more processors may be implemented as a single-core processor comprising one core, or as one or more multicore processors comprising multiple cores (e.g., homogeneous multicore or heterogeneous multicore). When one or more processors are implemented as multicore processors, each of the multiple cores included in the multicore processor may include internal processor memory such as cache memory or on-chip memory, and a common cache shared by multiple cores may be included in the multicore processor. Additionally, each of the multiple cores included in the multicore processor (or some of the multiple cores) may independently read and execute program instructions for implementing a method according to one embodiment of the present disclosure, or all (or some) of the multiple cores may be linked together to read and execute program instructions for implementing a method according to one embodiment of the present disclosure.

[0066] When a method according to one embodiment of the present disclosure includes a plurality of operations, the plurality of operations may be performed by one of the plurality of cores included in a multi-core processor, or may be performed by a plurality of cores. For example, when a first operation, a second operation, and a third operation are performed by a method according to one embodiment, the first operation, the second operation, and the third operation may all be performed by a first core included in a multi-core processor, or the first operation and the second operation may be performed by a first core included in a multi-core processor and the third operation may be performed by a second core included in a multi-core processor.

[0067] In embodiments of the present disclosure, the processor (150) may mean a system on chip (SoC) in which one or more processors and other electronic components are integrated, a single-core processor, a multi-core processor, or a core included in a single-core processor or a multi-core processor, wherein the core may be implemented as a CPU, GPU, APU, MIC, DSP, NPU, hardware accelerator, or machine learning accelerator, but the embodiments of the present disclosure are not limited thereto.

[0068] In particular, the processor (150) obtains information about a user and usage information of the electronic device by executing at least one instruction stored in memory (140), obtains information about the reliability of the user based on the information about the user and usage information of the electronic device (100), obtains information about the risk of user operation based on the usage information of the electronic device (100), identifies whether there is abnormal access to the electronic device based on the information about the reliability of the user and the information about the risk of user operation, and if abnormal access to the electronic device (100) is identified, performs a security operation of the electronic device (100) regarding the abnormal access.

[0069] In one or more embodiments, the processor (150) may obtain a first score for the reliability of the user based on connection information with an external device connected to the electronic device (100), location information of the user, wearing information of a wearable device connected to the electronic device (100), movement information of the electronic device (100), and touch information input on the electronic device (100), and may obtain a second score for the risk of the user's behavior based on sensitivity information of the application used by the user and behavioral sensitivity information of the user using the electronic device (100).

[0070] Here, the first factor corresponding to connection information with an external device, the second factor corresponding to user location information, and the third factor corresponding to wearing information of the wearable device are factors having fixed values, and the fourth factor corresponding to movement information of the electronic device (100) and touch information input on the electronic device (100) is a factor having a value that varies according to conditions, the first weight corresponding to the first factor has a value that varies according to the amount of usage of the external device by the user, the fourth weight corresponding to the fourth factor has a value that varies according to existing learning results, and the second weight corresponding to the second factor and the third weight corresponding to the third factor may have fixed values. The first score may be a score obtained by the sum of the products of the weights corresponding to the first to fourth factors.

[0071] Additionally, the fifth factor corresponding to the application's sensitivity information and the sixth factor corresponding to the behavioral sensitivity information are factors that have values ​​that vary according to conditions, and the fifth weight corresponding to the fifth factor and the sixth weight corresponding to the sixth factor may have values ​​that vary according to existing learning results. The second score may be a score obtained as the sum of the products of the weights corresponding to the fifth and sixth factors.

[0072] In one or more embodiments, the processor (150) may obtain a behavior graph for actions up to the performance of sensitive actions after the electronic device (100) is unlocked, and obtain behavior sensitivity information based on the behavior graph. Here, the behavior graph may be composed of nodes corresponding to actions and edges representing preceding and succeeding action relationships.

[0073] In one or more embodiments, the processor (150) can identify whether there is abnormal access to the electronic device (100) based on whether the difference between the second score and the first score is greater than or equal to a threshold value. In particular, the processor (150) can perform different security actions depending on the difference value when the difference between the second score and the first score is greater than or equal to a threshold value. In one or more embodiments, the processor (150) can perform a first security action of storing usage information of the electronic device (100) related to abnormal access when the difference value is in a first range, perform a second security action of transmitting information related to abnormal access to a wearable device when the difference value is in a second range greater than the first range, perform a third security action of switching the electronic device (100) to a locked state and requesting re-authentication when the difference value is in a third range greater than the second range, and perform a fourth security action of requesting additional authentication when the difference value is in a fourth range greater than the third range.

[0074] FIG. 3 is a block diagram of a configuration for protecting personal information by detecting abnormal access according to one embodiment of the present disclosure. As shown in FIG. 3, an electronic device (100) may include an abnormal access detection module (310), a 3P protection module (320), an abnormal biometric information additional detection module (330), and a personal information protection module (340).

[0075] The abnormal access detection module (310) can detect abnormal access caused by the theft and misappropriation of the electronic device. In one or more embodiments, the abnormal access detection module (310) obtains information about a user and usage information of the electronic device (100), obtains information about the user's trustworthiness based on the information about the user and usage information of the electronic device (100), obtains information about the risk of user behavior based on the usage information of the electronic device (100), and can identify whether there is abnormal access to the electronic device based on the information about the user's trustworthiness and the information about the risk of user behavior. This will be explained in detail later with reference to FIGS. 5 to 8b.

[0076] The 3P protection module (320) is configured to prevent 3P leakage and can provide Screen protection, Randomized / Fake PIN Input, and Gaze Detection. Screen protection is a technology used to prevent physical security threats such as shoulder surfing and can provide a Privacy Screen Filter, screen blur, automatic screen lock function, etc. Randomized / Fake PIN Input is a technology that provides a random PIN keypad or a fake PIN keypad to prevent shoulder surfing or brute force attacks. Gaze Detection is a technology that detects whether someone nearby is peeking at the screen when the user is looking at the screen.

[0077] The abnormal biometric information addition detection module (330) is configured to detect whether illegally registered biometric information has been added (or registered) and may provide Trusted Location and Touch Dynamics. Trusted Location is a technology that restricts biometric information registration or authentication to only specific physical locations. Touch Dynamics is a technology that analyzes the user's touch pattern (touch motion on a smartphone or tablet screen) to identify whether the user is legitimate or to prevent the addition of illegal biometric information.

[0078] The personal information protection module (340) may be a configuration for protecting personal information (specifically, credential information) within the device. Here, the personal information may include information necessary to authenticate a user to a system, network, or application. In particular, the personal information protection module (340) may provide credential scanning, 2-factor authentication, etc. Credential scanning is a technology that detects and prevents the exposure of sensitive credential information during software development, distribution, or IT system operation. 2-factor authentication is a technology that requires two different authentication factors to strengthen the user authentication process.

[0079] FIG. 4 is a block diagram illustrating a library set for protecting 3P according to one embodiment of the present disclosure. The library set included in the electronic device (100) may include Proximity (401), Touch Dynamics (402), On-body Detection (403), Randomized / Fake PIN Input (404), Gaze Detection (405), Credential Scanning (406), Screen protection (407), App Usage patterns (408), Trusted Location (409), and 2FA (2 factor authentication) (410), as shown in FIG. 4.

[0080] Proximity (401) can determine whether access rights exist by checking whether the physical location or distance of a user or electronic device (100) meets specific conditions. In particular, Proximity (401) can determine whether access rights exist based on connection information with an external device connected to the electronic device (100). Here, the external device is a reliable external device and may include a previously registered external device or an external device with a history of connection.

[0081] Touch Dynamics (402) can identify whether a user is legitimate by analyzing patterns of touch actions of a user input on an electronic device (100). That is, Touch Dynamics (402) can identify whether a user is legitimate by comparing patterns of touch actions of a user input on an electronic device (100) with previously learned touch actions of the user. For example, Touch Dynamics (402) can identify whether a user is legitimate by comparing patterns of the user's touch location, touch speed, and touch pressure input on an electronic device (100). Alternatively, Touch Dynamics (402) can identify whether a user is legitimate by analyzing whether the movement of the electronic device (100) detected through the sensor (120) is similar to existing movements.

[0082] On-body Detection (403) can identify whether the user is a legitimate user by analyzing whether the electronic device (100) or the wearable device connected to the electronic device (100) is worn (or carried) by the user.

[0083] Randomized / Fake PIN Input (404) can provide a random PIN keypad or a fake PIN keypad to prevent Shoulder Surfing or Brute Force attacks.

[0084] Gaze Detection (405) is a technology that detects whether someone is peeking at the screen from the surroundings when the user is looking at the screen. Specifically, Gaze Detection (405) uses a camera to detect the gaze of other people looking at the screen from the surroundings in addition to the user's gaze, and if the gaze of another person is detected, it can display a warning or blur the screen.

[0085] Credential Scanning (406) can detect and prevent sensitive credentials from being exposed during software development, distribution, or IT system operation. Specifically, Credential Scanning (406) can prevent credentials from being exposed by scanning in real time pattern matching, neural network models for detecting credential exposure, code analysis, uploaded files, etc.

[0086] Screen protection (407) is a technology used to prevent physical security threats such as shoulder surfing, and can provide privacy screen filters, screen blur, automatic screen locking functions, etc.

[0087] App Usage patterns (408) can identify whether a user is a legitimate user by comparing the user's application usage patterns with previously learned usage patterns.

[0088] Trusted Location (409) may restrict biometric information registration or authentication to specific physical locations only. Specifically, Trusted Location (409) allows biometric information to be registered only at a location where the user's location information obtained through the communication interface (110) or sensor (130) is already registered (e.g., an office).

[0089] 2FA (2 factor authentication) (410) may require two different authentication factors to strengthen the user authentication process. For example, 2FA (410) may require at least two authentications among SMS or email authentication, use of an authentication app, a hardware security key, and biometric authentication.

[0090] FIG. 5 is a flowchart illustrating a method for detecting abnormal access and performing a security operation according to one embodiment of the present disclosure.

[0091] In the following embodiments, each operation may be performed sequentially, but is not necessarily performed sequentially. For example, the order of each operation may be changed, and at least two operations may be performed in parallel.

[0092] According to one or more embodiments, 510 to 560 may be understood to be performed in a processor (e.g., processor (150) of FIG. 2) of an electronic device (e.g., electronic device (100) of FIG. 2).

[0093] In one or more embodiments, the electronic device (100) may obtain information about a user and usage information of the electronic device (100) (510). In one or more embodiments, the information about the user may include location information of the user and wearing information of a wearable device connected to the electronic device. Here, the location information of the user may be obtained through a communication interface and a GPS module of the electronic device (100) or a wearable device connected to the electronic device (100). The wearing information of the wearable device connected to the electronic device (100) may be obtained by a sensing value sensed from the wearable device connected to the electronic device. In one or more embodiments, the usage information of the electronic device (100) may include connection information with an external device connected to the electronic device (100), movement information of the electronic device (100), touch information input on the electronic device (100), sensitivity information of an application used by the user, and behavioral sensitivity information of the user using the electronic device (100). Here, connection information with an external device connected to the electronic device (100) may include communication connection information with the external device and reliability information of the connected external device. Movement information of the electronic device (100) may be obtained through a sensing value obtained via a sensor (120) of the electronic device (100). Touch information input on the electronic device (100) may include information regarding the location, speed, pressure, etc. of the touch input on the electronic device (100). Application sensitivity information may be determined according to the level of security requirements of the application used by the user. For example, in the case of a financial application or a chat application, it may be a high-sensitivity application, while a camera application or a search application that does not require user login may be a low-sensitivity application. Behavioral sensitivity information may indicate information regarding actions by a user of the electronic device (100) attempting to access or edit personal information or authentication information.

[0094] The electronic device (100) can obtain information about the user's reliability based on information about the user and information about the use of the electronic device (520). Specifically, the electronic device (100) can obtain a first score about the user's reliability based on connection information with an external device connected to the electronic device (100), location information of the user, wearing information of a wearable device connected to the electronic device (100), movement information of the electronic device (100), and touch information input on the electronic device (100).

[0095] In one or more embodiments, the electronic device (100) may obtain a first score as the sum of products of a first factor corresponding to connection information with an external device, a second factor corresponding to user location information, a third factor corresponding to wearing information of a wearable device, and a fourth factor corresponding to movement information of the electronic device (100) and touch information input on the electronic device (100), and corresponding weights. Here, the first to fourth factors have values ​​within a preset range (e.g., 0 to 1), and each factor may have a corresponding weight. The factors may have a fixed value or a value that changes depending on the state, depending on the type of the acquired corresponding information. Additionally, the weight may also have a fixed value or a variable value depending on the type of the factor. This will be explained with reference to FIGS. 6a and FIGS. 7a.

[0096] The first factor (f1) is a factor obtained by Proximity (401) and can be obtained based on connection information with an external device (in particular, a wearable device). If it is determined that the device is connected to and worn by the external device, the first factor (f1) is determined to be 1; if it is determined that the device is connected to and not worn by the external device, the first factor (f1) is determined to be 0.5; and if it is determined that the device is not connected to the external device, the first factor (f1) is determined to be 0. Here, the first factor (f1) may have a fixed value (static value). Additionally, the first weight (w1) corresponding to the first factor (f1) may have a value (dynamic value) that varies depending on the usage of the external device (in particular, a wearable device) by the user. In particular, the first weight (w1) can be calculated by the following mathematical formula 1, as shown in FIG. 7a.

[0097]

[0098] Here, w 1b can be a default weight.

[0099] The second factor (f2) is a factor obtained by the Trusted Location (409) and can be obtained based on the location information of the user (or electronic device (100)). That is, the second factor (f2) can have a value between 0 and 1 depending on whether the space where the user is located is a safe space (e.g., inside a home, office, etc.) or a dangerous space (e.g., a public place). Here, the second factor (f2) can have a fixed value (static value). Also, the second weight (w2) corresponding to the second factor (f2) can have a fixed value (static value).

[0100] The third factor (f3) is a factor obtained by On-body detection (403) and can be obtained based on the wearing information of the electronic device (100) (or wearable device). That is, if the user is not separated from the electronic device (100) after performing user authentication (i.e., when the electronic device (100) is worn), the third factor (f3) is determined to be 1, and if the user is separated from the electronic device (100) after performing user authentication (i.e., when the electronic device (100) is not worn), the third factor (f3) can be determined to be 0. Here, the third factor (f3) may have a fixed value (static value). Also, the third weight (w3) corresponding to the third factor (f3) may have a fixed value (static value).

[0101] The fourth factor (f4) is a factor obtained by Touch dynamics (402) and can be obtained based on movement information (or touch information) of the electronic device (100). That is, the fourth factor (f4) can have a value between 0 and 1 according to the touch dynamic score. Here, the touch dynamic score can be determined by the similarity between a previously learned movement pattern (or touch pattern) and a movement pattern (or touch pattern) input by a user. Here, the fourth factor (f4) can have a dynamic value that varies depending on whether it is determined to be a user. In addition, the fourth weight (w4) corresponding to the fourth factor (f4) can have a dynamic value that varies according to the existing learning result (i.e., the amount of learning of user data (e.g., movement pattern or touch pattern, etc.). In particular, the fourth weight (w4) can be calculated by the following mathematical formula 2, as shown in FIG. 7a.

[0102]

[0103]

[0104] Here, w4b may be a default weight. That is, as shown in Equation 2 above, if the data training time is less than one week, the weight may be reduced.

[0105] The electronic device (100) can obtain a first score(s) as the sum of the products of the first to fourth factors (f1 to f4) and the corresponding weights (w1 to w4), as shown in mathematical formula 3 below.

[0106]

[0107] The electronic device (100) can obtain information regarding the risk level of user behavior based on usage information of the electronic device (100) (530). Specifically, the electronic device (100) can obtain a second score regarding the risk level of user behavior based on sensitivity information of the application used by the user and sensitivity information of the user's behavior using the electronic device (100).

[0108] In one or more embodiments, the electronic device (100) may obtain a second score as the sum of the products of a fifth factor corresponding to the sensitivity information of the application and a sixth factor corresponding to the behavioral sensitivity information, and the corresponding weights. Here, the fifth factor and the sixth factor have values ​​within a preset range (e.g., 0 to 1), and each factor may have a corresponding weight. The fifth and sixth factors may have values ​​that change according to conditions. Additionally, the weights corresponding to the fifth and sixth factors may also have varying values. This will be explained with reference to FIGS. 6b and FIGS. 7b.

[0109] The fifth factor (f'1) is a factor obtained through App access and can be obtained based on the sensitivity of the application used by the user. That is, the fifth factor (f'1) can have a value between 0 and 1 depending on the sensitivity of the application. In particular, for applications with high security requirements, the sensitivity may be close to 1, and for applications with low security requirements, the sensitivity may be close to 0. Here, the fifth factor (f'1) can have a dynamic value that varies depending on the conditions. In addition, the fifth weight (w'1) corresponding to the fifth factor (f'1) can have a dynamic value that varies depending on the time of application access. In particular, the fifth weight (w'1) can be calculated by the following Equation 4, as illustrated in FIG. 7b.

[0110]

[0111] The sixth factor (f'2) is a factor obtained by Behavior and can be obtained based on behavioral sensitivity information used by the user. Here, behavioral sensitivity information can be determined based on whether the user using the electronic device (100) attempts to access or edit personal information or authentication information. The sixth factor (f'2) can have a value between 0 and 1 depending on the behavioral sensitivity. In particular, behaviors such as adding biometric authentication information or accessing authentication records have a behavioral sensitivity close to 1, while behaviors not related to authentication may have a sensitivity close to 0. Here, the sixth factor (f'2) can have a dynamic value that varies depending on the condition.

[0112] In particular, the electronic device (100) can acquire a behavior graph for actions up to the point where the electronic device (100) performs a sensitive action after being unlocked, and can acquire behavior sensitivity information based on the behavior graph. Here, the behavior graph may be composed of nodes corresponding to actions and edges representing the preceding and succeeding action relationships.

[0113] For example, if a sensitive action is performed immediately after an unlock action, the electronic device (100) can obtain a first action graph including a first node (810) corresponding to the unlock action and a second node (820) corresponding to the sensitive action, as shown in FIG. 8a. Here, the action graph can obtain an edge connecting the first node (810) to the second node (820).

[0114] As another example, if the unlock action is performed followed by the first action -> second action -> first action -> third action -> fourth action -> sensitive action, the electronic device (100) can obtain a second action graph including a first node (810) corresponding to the unlock action, third to sixth nodes (830 to 860) corresponding to the first to fourth actions, and a seventh node (870) corresponding to the sensitive action, as illustrated in FIG. 8b. Here, the action graph can obtain edges connecting nodes according to the sequence of the user's actions.

[0115] In addition, the sixth weight (w'2) corresponding to the sixth factor (f'2) may have a dynamic value that varies according to the behavior graph. In particular, the sixth weight (w'2) can be calculated by the following mathematical formula 5, as shown in FIG. 7b.

[0116]

[0117] Here, diameter may be the diameter of the action graph (i.e., the length of the shortest path between the two farthest nodes in the action graph), time may be the time taken to construct the action graph, number of nodes may be the number of nodes included in the action graph, number of edges may be the number of edges included in the action graph, number of loops may be the number of loops included in the action graph, and circuit rank may be a value representing the number of cycles in the graph.

[0118] For example, if the sensitive action is reached quickly and simply from the Unlock action, the 6th weight (w'2) may increase, and if time and multiple actions are taken to reach the sensitive action, the 6th weight (w'2) may decrease.

[0119] The electronic device (100) can obtain a second score (s') as the sum of the products of the fifth and sixth factors (f'1 and f'2) and the corresponding weights (w'1 to w'2), as shown in mathematical formula 6 below.

[0120]

[0121] Meanwhile, as described above, calculating the first score(s) and the second score(s') is merely one embodiment, and it goes without saying that they can be calculated by other methods.

[0122] Referring again to FIG. 5, the electronic device (100) can identify whether there is abnormal access to the electronic device (100) based on information regarding the reliability of the user and information regarding the risk of the user's actions (540). In one or more embodiments, the electronic device (100) can identify whether there is abnormal access to the electronic device (100) based on whether the difference between the second score (s') and the first score (s) is greater than or equal to a threshold value. That is, if the difference between the second score (s') and the first score (s) is greater than or equal to a threshold value, the electronic device (100) can identify abnormal access to the electronic device (100), and if the difference between the second score (s') and the first score (s) is less than a threshold value, the electronic device (100) can identify normal access to the electronic device (100).

[0123] In one or more embodiments, the threshold value may be a changed value rather than a fixed value. For example, if a "False alarm" occurs, the electronic device (100) may adjust (or increase) the threshold value. As another example, if the electronic device (100) is used by a trusted person (e.g., family, friend, etc.) of the registered user, the electronic device (100) may adjust (or increase) the threshold value. As yet another example, if the electronic device (100) is used by a user permitted by the registered user, the electronic device (100) may adjust (or increase) the threshold value.

[0124] When abnormal access to the electronic device (100) is identified (550-Y), the electronic device (100) may perform a security action for the abnormal access (560). In one or more embodiments, when abnormal access to the electronic device (100) is identified, the electronic device (100) may perform different security actions depending on the difference between the second score (s') and the first score (s). This will be explained with reference to FIG. 9.

[0125] FIG. 9 is a flowchart illustrating a method for performing different security operations according to the difference value of the first and second scores, according to one embodiment of the present disclosure.

[0126] In the following embodiments, each operation may be performed sequentially, but is not necessarily performed sequentially. For example, the order of each operation may be changed, and at least two operations may be performed in parallel.

[0127] According to one or more embodiments, 910 to 980 may be understood to be performed in a processor (e.g., processor (150) of FIG. 2) of an electronic device (e.g., electronic device (100) of FIG. 2).

[0128] The electronic device (100) can identify whether the difference between the second score and the first score is greater than or equal to a threshold value (910).

[0129] If the difference between the second score and the first score is identified as being greater than or equal to a threshold value (910-Y), the electronic device (100) can identify whether the difference between the second score and the first score is within the first range (920).

[0130] If the difference between the second score and the first score is within the first range (920-Y), the electronic device (100) can perform a first security operation (930). Here, the first security operation may be an operation to store usage information of the electronic device related to abnormal access. That is, the electronic device (100) can store usage information of the electronic device related to abnormal access (e.g., information about user actions, application usage information, etc.) in memory (140).

[0131] If the difference between the second score and the first score is outside the first range (920-N), the electronic device (100) can identify whether the difference between the second score and the first score is within the second range (940). Here, the second range may be a range having a value greater than the first range.

[0132] If the difference between the second score and the first score is within the second range (940-Y), the electronic device (100) may perform a second security operation (950). Here, the second security operation may be an operation of transmitting information related to abnormal access to an external device (e.g., a wearable device) connected to the electronic device (100). Alternatively, the electronic device (100) may provide information related to abnormal access to an external device with the same account as the user of the electronic device (100). Here, this information related to abnormal access may include usage information of the electronic device (100) (e.g., information about the user's actions, application usage information, etc.).

[0133] If the difference between the second score and the first score is outside the second range (940-N), the electronic device (100) can identify whether the difference between the second score and the first score is in the third range (960). Here, the third range may be a range having a value greater than the second range.

[0134] If the difference between the second score and the first score is within the third range (960-Y), the electronic device (100) can perform a third security action (970). Here, the third security action may be an action that switches the electronic device (100) to a locked state and requests re-authentication. For example, the electronic device (100) may switch the state of the electronic device (100) to a locked state and provide a UI that says, "Abnormal access detected. Requesting re-authentication."

[0135] If the difference between the second score and the first score is outside the third range (960-N), the electronic device (100) may perform a fourth security operation (980). Here, the fourth security operation may be an operation that requires additional authentication from the user of the electronic device (100). For example, the electronic device (100) may perform an operation that additionally requires SMS authentication and biometric authentication from the user of the electronic device (100) in addition to existing authentication operations.

[0136] As described above, by detecting abnormal access to the electronic device (100) and providing a security operation, it is possible to prevent the theft and misappropriation of the electronic device (100) by an attacker.

[0137]

[0138] Meanwhile, the method according to various embodiments of the present disclosure may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or distributed online (e.g., download or upload) through an application store (e.g., Play Store™) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product (e.g., downloadable app) may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0139] A method according to various embodiments of the present disclosure may be implemented as software comprising instructions stored on a machine-readable storage medium (e.g., a computer). The machine may include an electronic device (e.g., a TV) according to the disclosed embodiments, which is a device capable of calling instructions stored from the storage medium and operating according to the called instructions.

[0140] Meanwhile, a device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory storage medium' simply means that it is a tangible device and does not contain a signal (e.g., electromagnetic waves), and this term does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily. For example, a 'non-transitory storage medium' may include a buffer in which data is stored temporarily.

[0141] When the above instruction is executed by a processor, the processor may perform the function corresponding to the instruction directly or by using other components under the control of the processor. The instruction may include code generated or executed by a compiler or an interpreter.

[0142] Although preferred embodiments of the present disclosure have been illustrated and described above, the present disclosure is not limited to the specific embodiments described above. It is understood that various modifications can be made by those skilled in the art without departing from the essence of the present disclosure as claimed in the claims, and such modifications should not be understood individually from the technical spirit or perspective of the present disclosure.

Claims

1. In an electronic device, Memory for storing instructions; and Includes a processor; When the above instructions are executed individually or collectively by the processor, the electronic device, Acquire information about the user and usage information of the electronic device, Information regarding the reliability of the user is obtained based on information about the user and usage information of the electronic device, and information regarding the risk of the user's operation is obtained based on usage information of the electronic device. Based on information regarding the reliability of the user and information regarding the risk of the user's operation, it identifies whether there is abnormal access to the electronic device, and An electronic device that performs a security operation of the electronic device for said abnormal access when an abnormal access to said electronic device is identified.

2. In Paragraph 1, When the above instructions are executed individually or collectively by the processor, the electronic device, A first score for the reliability of the user is obtained based on connection information with an external device connected to the electronic device, location information of the user, wearing information of a wearable device connected to the electronic device, movement information of the electronic device, and touch information input on the electronic device, and An electronic device that obtains a second score for the risk of the user's behavior based on sensitivity information of the application used by the user and sensitivity information of the user's behavior using the electronic device.

3. In Paragraph 2, The first factor corresponding to the connection information with the external device, the second factor corresponding to the user's location information, and the third factor for the wearing information of the wearable device are factors having the fixed value, and The fourth factor corresponding to the movement information of the electronic device and the touch information input on the electronic device is a factor having a value that varies according to conditions, and The first weight corresponding to the above first factor has a value that varies according to the amount of usage by the user of the external device, and The fourth weight corresponding to the above fourth factor has a value that varies according to the existing learning result, and The second weight corresponding to the second factor and the third weight corresponding to the third factor have fixed values, and An electronic device in which the first score is a score obtained as the sum of the products of weights corresponding to the first to fourth factors.

4. In Paragraph 2, The fifth factor corresponding to the sensitivity information of the above application and the sixth factor corresponding to the behavioral sensitivity information are factors having values ​​that vary according to conditions, and The fifth weight corresponding to the above fifth factor and the sixth weight corresponding to the above sixth factor have values ​​that vary according to existing learning results, and The electronic device, wherein the second score is a score obtained as the sum of the products of weights corresponding to the fifth and sixth factors.

5. In Paragraph 2, When the above instructions are executed individually or collectively by the processor, the electronic device, Acquire a behavior graph for the operation from the time the electronic device is unlocked until it performs a sensitive action, and An electronic device for acquiring behavioral sensitivity information based on the above behavior graph.

6. In Paragraph 5, The above behavior graph is, An electronic device characterized by being composed of nodes corresponding to actions and edges representing prior and subsequent action relationships.

7. In Paragraph 2, When the above instructions are executed individually or collectively by the processor, the electronic device, An electronic device that identifies whether there is abnormal access to the electronic device based on whether the difference between the second score and the first score is greater than or equal to a threshold value.

8. In Paragraph 7, When the above instructions are executed individually or collectively by the processor, the electronic device, An electronic device that performs different security operations according to the difference value when the difference value between the second score and the first score is greater than or equal to the threshold value.

9. In Paragraph 8, When the above instructions are executed individually or collectively by the processor, the electronic device, If the above difference value is within the first range, a first security operation is performed to store usage information of the electronic device related to the above abnormal access, and If the above difference value is a second range greater than the first range, a second security operation is performed to transmit information related to the above abnormal access to the wearable device, and If the above difference value is a third range greater than the above second range, the electronic device is switched to a locked state and a third security operation requiring re-authentication is performed, and An electronic device that performs a fourth security operation requiring additional authentication when the above difference value is a fourth range greater than the above third range.

10. In a method for controlling an electronic device, A step of obtaining information about the user and usage information of the electronic device; A step of obtaining information regarding the reliability of the user based on information regarding the user and usage information of the electronic device, and obtaining information regarding the risk of the user's operation based on usage information of the electronic device; A step of identifying whether there is abnormal access to the electronic device based on information regarding the reliability of the user and information regarding the risk of the user's operation; and A control method comprising the step of performing a security operation of the electronic device for the abnormal access when abnormal access to the electronic device is identified.

11. In Paragraph 10, The step of obtaining information regarding the risk level of the above user action is, A step of obtaining a first score for the reliability of the user based on connection information with an external device connected to the electronic device, location information of the user, wearing information of a wearable device connected to the electronic device, movement information of the electronic device, and touch information input on the electronic device; and A control method comprising the step of obtaining a second score for the risk of the user action based on sensitivity information of the application used by the user and sensitivity information of the user's behavior using the electronic device.

12. In Paragraph 11, The first factor corresponding to the connection information with the external device, the second factor corresponding to the user's location information, and the third factor for the wearing information of the wearable device are factors having the fixed value, and The fourth factor corresponding to the movement information of the electronic device and the touch information input on the electronic device is a factor having a value that varies according to conditions, and The first weight corresponding to the above first factor has a value that varies according to the amount of usage by the user of the external device, and The fourth weight corresponding to the above fourth factor has a value that varies according to the existing learning result, and The second weight corresponding to the second factor and the third weight corresponding to the third factor have fixed values, and A control method in which the first score is a score obtained as the sum of the products of weights corresponding to the first to fourth factors.

13. In Paragraph 11, The fifth factor corresponding to the sensitivity information of the above application and the sixth factor corresponding to the behavioral sensitivity information are factors having values ​​that vary according to conditions, and The fifth weight corresponding to the above fifth factor and the sixth weight corresponding to the above sixth factor have values ​​that vary according to existing learning results, and A control method in which the second score is a score obtained as the sum of the products of weights corresponding to the fifth and sixth factors.

14. In Paragraph 11, The step of obtaining information regarding the risk level of the above user action is, A control method for obtaining a behavior graph for operations up to the performance of sensitive actions after the electronic device is unlocked, and obtaining behavior sensitivity information based on the behavior graph.

15. In Paragraph 14, The above behavior graph is, A control method characterized by being composed of nodes corresponding to actions and edges representing prior and subsequent action relationships.