Unlocking risk prevention and control method and electronic device
Patent Information
- Application Number
- PCT/CN2025/146849
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-27
- Filing Date
- 2025-12-29
- Publication Date
- 2026-10-01
Smart Images

Figure CN2025146849_01102026_PF_FP_ABST
Abstract
Description
A method for unlocking risk control and electronic devices
[0001] Cross-reference to related applications
[0002] This application claims priority to Chinese patent application filed on March 27, 2025, with application number 202510380808.5 and entitled "A method for unlocking risk prevention and control and an electronic device", the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of terminal technology, and in particular to a method for unlocking risk prevention and control and an electronic device. Background Technology
[0004] With the widespread use of mobile devices, users have raised higher requirements for the security of the data stored on these devices. Users' electronic devices not only contain their personal privacy information (such as photos, chat logs, and payment information), but may also contain sensitive corporate data (such as business documents and customer information). Therefore, how to ensure device security while preventing unauthorized access that could lead to the leakage or loss of important data has become an important research direction in the field of mobile device system security.
[0005] Current system security solutions allow electronic devices to set lock screen passwords and biometric authentication methods, such as face unlock and fingerprint unlock. When using an electronic device, users need to unlock it through the pre-set lock screen method on the lock screen interface before the electronic device can display the main interface, and users can continue to use other functions of the electronic device.
[0006] While biometric authentication unlocking methods improve convenience, they have inherent security flaws compared to screen lock passwords. Preventing data from being unlocked while the electronic device is locked remains a core issue for mobile device system security. Summary of the Invention
[0007] This application provides a method and electronic device for preventing and controlling unlocking risks, in order to improve the ability to prevent and control the risks of abnormal unlocking.
[0008] Firstly, this application provides a method for unlocking risk control, which can be executed by an electronic device. The method includes: the electronic device acquiring status information corresponding to multiple risk factors of the electronic device, wherein the status information corresponding to the multiple risk factors includes at least two of location information, network status information, paired device information, and lock screen information; when the risk status indicated by the status information corresponding to the multiple risk factors meets preset control conditions, the electronic device disables the biometric unlocking function of the electronic device.
[0009] In the above methods, the electronic device is judged based on the status of multiple risk factors to determine whether there is an abnormal unlock risk, thereby more accurately distinguishing whether there is attacker behavior. When it is determined that the electronic device needs to be subject to risk control, the biometric unlock function of the electronic device is disabled, and users can only unlock the electronic device through a preset lock screen password, thereby achieving a higher level of security control and ensuring user information security.
[0010] In one possible design, the risk status indicated by the status information corresponding to the multiple risk factors meets preset control conditions, including at least one of the following: the location information of the electronic device indicates that the location is not within the commonly used location range of the electronic device; the network status information of the electronic device indicates that the duration of the electronic device's network outage is greater than or equal to a first preset threshold; the pairing device information of the electronic device indicates that the historical pairing device of the electronic device is offline; the lock screen information of the electronic device indicates that the duration of the electronic device's lock screen state is greater than or equal to a second preset threshold; the lock screen information of the electronic device indicates that the number of failed unlock attempts is greater than or equal to a third preset threshold. Through this design, the electronic device can be pre-configured with control conditions corresponding to multiple risk factors. These risk factors and their corresponding preset control conditions differ from risk judgment factors triggered by user-defined SOS modes or lost modes. The electronic device can automatically perform risk detection based on information such as location, network connection status, pairing device connection status, and lock screen status, thereby enabling timely detection of abnormal unlocking risks and improving the accuracy of risk detection.
[0011] In one possible design, disabling the biometric unlocking function of the electronic device includes erasing or disabling key information in the biometric unlocking path, wherein the key information is used to obtain file keys for encrypting or decrypting system files. Through this design, this application can provide a cryptographic-level risk control method that ensures that even if an attacker bypasses the lock screen and enters the desktop, they cannot normally access the data. Compared to disabling facial recognition or fingerprint recognition controls, this significantly improves the security strength of risk control.
[0012] In one possible design, after disabling the biometric unlocking function of the electronic device, the method further includes: receiving a lock screen password input by the user; unlocking the electronic device if the user-input lock screen password matches a preset lock screen password; and re-enabling the biometric unlocking function of the electronic device. With this design, when the biometric unlocking function is disabled, the electronic device can only be unlocked by the user inputting a lock screen password. When the user inputs the correct lock screen password, the electronic device can re-enabling the biometric unlocking function, allowing the user to unlock the device via biometrics the next time. This ensures that the user can use the biometric unlocking function normally in secure scenarios, guaranteeing a positive user experience.
[0013] In one possible design, the lock screen password includes at least one of the following: a lock screen password or a lock screen pattern.
[0014] In one possible design, re-enabling the biometric unlocking function of the electronic device includes: recovering or enabling key information in the biometric unlocking path based on the lock screen password, wherein the key information is used to obtain file keys for encrypting or decrypting system files. Through this design, the electronic device can recover or enable key information in the unlocking path, thereby restoring the biometric unlocking function of the electronic device at the cryptographic level and ensuring that the biometric unlocking function works normally.
[0015] In one possible design, the key information includes ciphertext for deriving a file key, and / or a first key for decrypting the ciphertext. Through this design, the electronic device in this application can achieve cryptographic-level risk management in multiple ways, flexibly preventing and controlling the risk of abnormal unlocking.
[0016] In one possible design, the biometric unlocking function of the electronic device includes at least one of face unlocking, fingerprint unlocking, and iris unlocking.
[0017] Secondly, this application provides an electronic device comprising multiple functional modules; the multiple functional modules interact to implement the methods performed by the electronic device in the first aspect and its various embodiments described above. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the multiple functional modules can be arbitrarily combined or divided based on specific implementations.
[0018] Thirdly, this application provides an electronic device including at least one processor and at least one memory, wherein the at least one memory stores computer program instructions, and when the electronic device is running, the at least one processor executes the methods described in the first aspect and its various embodiments.
[0019] Fourthly, this application also provides a computer program product containing instructions that, when the computer program product is run on a computer, cause the computer to perform the method executed by the electronic device in any of the above aspects and embodiments.
[0020] Fifthly, this application also provides a computer-readable storage medium storing a computer program that, when executed by a computer, causes the computer to perform the method executed by the electronic device in any of the above aspects and embodiments.
[0021] Sixthly, this application also provides a chip for reading a computer program stored in a memory and executing the method executed by the electronic device in any of the above aspects and embodiments.
[0022] Seventhly, this application also provides a chip system including a processor for supporting a computer device in implementing the methods executed by electronic devices in any of the above aspects and their embodiments. In one possible design, the chip system further includes a memory for storing programs and data necessary for the computer device. The chip system may be composed of chips or may include chips and other discrete devices. Attached Figure Description
[0023] Figure 1 is a schematic diagram of a lock screen interface provided in an embodiment of this application;
[0024] Figure 2 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;
[0025] Figure 3 is a software structure block diagram of an electronic device provided in an embodiment of this application;
[0026] Figure 4 is a schematic diagram of the unlocking path of an electronic device in the locked state according to an embodiment of this application;
[0027] Figure 5 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;
[0028] Figure 6 is a flowchart of an unlocking risk prevention and control method provided in an embodiment of this application. Detailed Implementation
[0029] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings. In the description of the embodiments of this application, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first" and "second" may explicitly or implicitly include one or more of that feature.
[0030] It should be understood that in the embodiments of this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, a and b, a and c, b and c, or a, b, and c, where a, b, and c can be single or multiple.
[0031] Data security and unlocking are core issues in the field of mobile device security. Current system security solutions allow electronic devices to set lock screen passwords, such as lock screen passwords or gestures, as well as biometric authentication methods like face unlock or fingerprint unlock. For example, Figure 1 is a schematic diagram of a lock screen interface provided in an embodiment of this application. Referring to Figure 1, the electronic device displays a lock screen interface, which includes face recognition controls, fingerprint recognition controls, and lock screen password input controls. The user needs to unlock the device using a preset unlocking method, such as entering a lock screen password or unlocking the device through face recognition or fingerprint recognition. After unlocking, the main interface is displayed, allowing the user to continue using other functions of the electronic device.
[0032] However, compared to screen lock passwords, biometric unlocking has inherent security flaws. For example, if an electronic device is stolen, the user's biometric unlocking method can be forcibly unlocked, leading to the risk of user information leakage.
[0033] In some implementations, electronic devices can disable facial recognition or fingerprint unlocking when a risk event is detected. Risk events include any of the following: activating SOS mode, removing the SIM card, setting the device to lost mode, or not using a lock screen password for an extended period. However, these risk events are caused by active actions by the user or attacker. Prevention based on these events is a passive defense technique, easily bypassed by attackers. For example, an attacker can perform a resource-saving unlock attack without removing the SIM card, or the user may not activate SOS mode or set the device to lost mode in time, thus failing to trigger the risk event and prevent the electronic device from performing risk control. Furthermore, electronic devices typically disable facial recognition or fingerprint unlocking by not displaying the facial recognition or fingerprint control on the lock screen, a low-level interface-level disabling solution with a low level of security.
[0034] To address the aforementioned issues, this application provides a method for preventing and controlling unlocking risks, which can be executed by an electronic device. In this method, status information corresponding to multiple risk factors of the electronic device is acquired. This status information includes at least two of the following: location information, network status information, paired device information, and lock screen information. When the risk status indicated by the status information corresponding to the multiple risk factors meets preset control conditions, the biometric unlocking function of the electronic device is disabled. Through this method, the electronic device determines whether there is an abnormal unlocking risk based on the status of multiple risk factors, thereby more accurately distinguishing whether attacker behavior exists. When it is determined that the electronic device needs risk control, the biometric unlocking function is disabled, allowing users to unlock the electronic device only through a preset lock screen password, achieving stronger security control and ensuring user information security.
[0035] The following describes an electronic device and embodiments for using such an electronic device. The electronic device in this application embodiment can be a tablet computer, mobile phone, in-vehicle device, augmented reality (AR) / virtual reality (VR) device, laptop computer, ultra-mobile personal computer (UMPC), netbook, personal digital assistant (PDA), wearable device, etc. This application embodiment does not impose any limitations on the specific type of electronic device.
[0036] In some embodiments of this application, the electronic device may also be a portable terminal device that includes other functions such as a personal digital assistant and / or a music player. Exemplary embodiments of the portable terminal device include, but are not limited to, devices equipped with... Or portable terminal devices with other operating systems.
[0037] Figure 2 is a schematic diagram of the structure of an electronic device 100 provided in an embodiment of this application. As shown in Figure 2, the electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, buttons 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc.
[0038] Processor 110 may include one or more processing units, such as an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural network processing unit (NPU). Different processing units may be independent devices or integrated into one or more processors. The controller may serve as the central nervous system and command center of the electronic device 100. The controller can generate operation control signals based on instruction opcodes and timing signals to control instruction fetching and execution. Processor 110 may also include memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that processor 110 has recently used or is repeatedly used. If processor 110 needs to reuse an instruction or data, it can directly retrieve it from the memory. This avoids repeated access, reduces the waiting time of processor 110, and thus improves system efficiency.
[0039] USB interface 130 is a USB standard compliant interface, specifically a Mini USB interface, Micro USB interface, USB Type-C interface, etc. USB interface 130 can be used to connect a charger to charge electronic device 100, and can also be used for data transfer between electronic device 100 and peripheral devices. Charging management module 140 receives charging input from the charger. Power management module 141 connects battery 142, charging management module 140, and processor 110. Power management module 141 receives input from battery 142 and / or charging management module 140, providing power to processor 110, internal memory 121, external memory, display 194, camera 193, and wireless communication module 160, etc.
[0040] The wireless communication function of electronic device 100 can be implemented through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor, and baseband processor. Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with tuning switches.
[0041] The mobile communication module 150 can provide solutions for wireless communication, including 2G / 3G / 4G / 5G, applied to the electronic device 100. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves via antenna 1, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 150 may be housed in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 may be housed in the same device.
[0042] The wireless communication module 160 can provide solutions for wireless communication applications on the electronic device 100, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared (IR) technologies. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via antenna 2, performs frequency modulation and filtering of the electromagnetic wave signals, and sends the processed signal to processor 110. The wireless communication module 160 can also receive signals to be transmitted from processor 110, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via antenna 2.
[0043] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, enabling electronic device 100 to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time-Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include the Global Positioning System (GPS), the Global Navigation Satellite System (GLONASS), the BeiDou Navigation Satellite System (BDS), the Quasi-Zenith Satellite System (QZSS), and / or satellite-based augmentation systems (SBAS).
[0044] The display screen 194 is used to display the display interface of an application, such as the display page of an application installed on the electronic device 100. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Miniled LED, a MicroLED, a Micro-OLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the electronic device 100 may include one or N display screens 194, where N is a positive integer greater than 1.
[0045] Camera 193 is used to capture still images or videos. An object is projected onto a photosensitive element by generating an optical image through the lens. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then passed to an ISP for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into image signals in standard RGB, YUV, or other formats. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.
[0046] Internal memory 121 can be used to store computer executable program code, which includes instructions. Processor 110 executes various functional applications and data processing of electronic device 100 by running the instructions stored in internal memory 121. Internal memory 121 may include a program storage area and a data storage area. The program storage area may store the operating system and software code for at least one application program. The data storage area may store data generated during the use of electronic device 100 (e.g., captured images, recorded videos, etc.). Furthermore, internal memory 121 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc.
[0047] The external storage interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device. The external memory card communicates with the processor 110 through the external storage interface 120 to perform data storage functions. For example, images, videos, and other files can be saved on the external memory card.
[0048] Electronic device 100 can implement audio functions, such as music playback and recording, through audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor.
[0049] The sensor module 180 may include a pressure sensor 180A, an acceleration sensor 180B, a touch sensor 180C, etc.
[0050] The pressure sensor 180A is used to sense pressure signals and can convert the pressure signals into electrical signals. In some embodiments, the pressure sensor 180A may be disposed on the display screen 194.
[0051] Touch sensor 180C, also known as a "touch panel," can be located on display screen 194. The touch sensor 180C and display screen 194 together form a touchscreen, also known as a "touch screen." Touch sensor 180C detects touch operations applied to or near it. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through display screen 194. In other embodiments, touch sensor 180C may also be located on the surface of electronic device 100, in a different position than display screen 194.
[0052] Buttons 190 include a power button, volume buttons, etc. Buttons 190 can be mechanical buttons or touch buttons. Electronic device 100 can receive button inputs and generate key signal inputs related to user settings and function control. Motor 191 can generate vibration alerts. Motor 191 can be used for incoming call vibration alerts or for touch vibration feedback. For example, touch operations applied to different applications (such as taking photos, audio playback, etc.) can correspond to different vibration feedback effects. Touch vibration feedback effects can also be customized. Indicator 192 can be an indicator light, used to indicate charging status, battery level changes, or to indicate messages, missed calls, notifications, etc. SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to achieve contact and separation with electronic device 100.
[0053] It is understood that the components shown in Figure 2 do not constitute a specific limitation on the electronic device 100. The electronic device may include more or fewer components than shown, or combine some components, or separate some components, or have different component arrangements. Furthermore, the combination / connection relationships between the components in Figure 2 can also be adjusted and modified.
[0054] Figure 3 is a software structure block diagram of an electronic device provided in an embodiment of this application. As shown in Figure 3, the software structure of the electronic device can be a layered architecture. For example, the software can be divided into several layers, each with a clear role and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the operating system is divided into four layers, from top to bottom: the application layer, the application framework layer (framework, FWK), the runtime and system libraries, and the kernel layer.
[0055] The application layer can include a series of application packages. As shown in Figure 3, the application layer can include camera, settings, skin modules, user interface (UI), third-party applications, etc. Third-party applications can include gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, SMS, etc.
[0056] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer can include some predefined functions. As shown in Figure 3, the application framework layer can include a window manager, content provider, view system, phone manager, resource manager, and notification manager.
[0057] The window manager is used to manage windowed applications. It can obtain the screen size, determine if a status bar is present, lock the screen, and capture screenshots. The content provider stores and retrieves data, making this data accessible to applications. This data may include videos, images, audio, made and received phone calls, browsing history and bookmarks, phone books, etc.
[0058] A view system includes visual controls, such as controls for displaying text and controls for displaying images. View systems can be used to build applications. A display interface can consist of one or more views. For example, a display interface including a text notification icon could include views for displaying text and views for displaying images.
[0059] A phone manager is used to provide communication functions for electronic devices. For example, it manages call status (including connection and disconnection).
[0060] The file explorer provides applications with various resources, such as localized strings, icons, images, layout files, video files, and more.
[0061] The notification manager allows applications to display notifications in the status bar. These notifications can be used to deliver informational messages and can disappear automatically after a short pause, requiring no user interaction. For example, the notification manager can be used to notify users of completed downloads or message alerts. The notification manager can also display notifications as icons or scrolling text in the top status bar, such as notifications from background applications, or as dialog boxes on the screen. Examples include displaying text messages in the status bar, emitting sounds, vibrating electronic devices, and flashing indicator lights.
[0062] The runtime includes the core libraries and the virtual machine. The runtime is responsible for the scheduling and management of the operating system.
[0063] The core library consists of two parts: one part contains the functionalities that the Java language needs to call, and the other part contains the core libraries of the operating system. The application layer and application framework layer run in the virtual machine. The virtual machine executes the Java files of the application layer and application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.
[0064] System libraries can include multiple functional modules. For example: surface manager, media libraries, 3D graphics processing libraries (e.g., OpenGL ES), 2D graphics engines (e.g., SGL), image processing libraries, etc.
[0065] The Surface Manager is used to manage the display subsystem and provides the blending of 2D and 3D layers for multiple applications.
[0066] The media library supports playback and recording of various common audio and video formats, as well as still image files. It supports multiple audio and video encoding formats, such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG.
[0067] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.
[0068] A 2D graphics engine is a graphics engine for 2D drawing.
[0069] The kernel layer is the layer between hardware and software. The kernel layer contains at least the display driver, camera driver, audio driver, and sensor driver.
[0070] The hardware layer can include various types of sensors, such as accelerometers, gyroscopes, and touch sensors.
[0071] It should be noted that the structures shown in Figures 2 and 3 are merely examples of electronic devices provided in the embodiments of this application, and cannot be used to limit the electronic devices provided in the embodiments of this application. In specific implementations, electronic devices may have more or fewer devices or modules than those shown in Figures 2 or 3.
[0072] The following describes the unlocking risk prevention method provided in the embodiments of this application.
[0073] In this embodiment, when the electronic device is in a locked state, the user can unlock it using a preset unlocking method. This preset unlocking method may include a lock screen password, and / or biometric unlocking. The lock screen password may include a lock screen password, and / or a lock screen pattern. Biometric unlocking may include at least one of facial recognition, fingerprint recognition, and iris recognition. When the electronic device is locked, the user cannot use most of its functions, nor can they access the data stored on it. Therefore, the electronic device lock screen password can be considered as encrypting the data on the electronic device.
[0074] Since biometric unlocking is less secure than password unlocking, when an electronic device determines that there is a risk and unlocking risk control is required, the electronic device can disable biometric unlocking to ensure the security of unlocking the electronic device.
[0075] In this embodiment of the application, the electronic device can analyze whether there is a risk based on multiple risk factors. Optionally, the electronic device can obtain the status information corresponding to multiple risk factors. When the risk status indicated by the status information corresponding to multiple risk factors meets the preset control conditions, the electronic device can determine that there is a risk and control the unlocking method of the electronic device.
[0076] Optionally, the electronic device can detect the status of multiple risk factors in real time and store the status information corresponding to each detected risk factor in local storage space. The electronic device can determine whether there is a risk based on the detected status changes of multiple risk factors and the stored historical status changes of multiple risk factors.
[0077] In one optional implementation, the multiple risk factors include at least two of the following: electronic device location, network connection status, device configuration status, and screen lock status. When the electronic device obtains status information corresponding to these multiple risk factors, it can obtain at least two of the following: location information, network status information, paired device information, and screen lock information. The location information can indicate the current geographical location of the electronic device. The network status information can include the duration of the electronic device's network outage, which is the duration during which the electronic device is not connected to the network. The network status information can also include at least one of the following: the network type the electronic device is connected to, the network identifier, and the duration of network connection. The network type includes, for example, wireless networks and cellular networks. The paired device information includes the identifiers and online status of historical paired devices of the electronic device. The screen lock information can include the duration of the screen lock status and the number of failed unlock attempts. The duration of the screen lock status can be the time between the most recent screen lock time and the current time. The number of failed unlock attempts is the number of times the user failed to unlock due to biometric mismatch or an incorrect entered screen lock password. In this embodiment, the electronic device can be pre-configured with control conditions corresponding to multiple risk factors. For example, taking risk factors including electronic device location, network connection status, device configuration status, and screen lock status as an example, the preset control conditions can include at least one of the following: the location information of the electronic device indicates that the location is not within the range of the electronic device's usual location; the network status information of the electronic device indicates that the duration of the electronic device's network outage is greater than or equal to a first preset threshold; the paired device information of the electronic device indicates that the historical paired device of the electronic device is offline; the screen lock information of the electronic device indicates that the duration of the screen lock status of the electronic device is greater than or equal to a second preset threshold; the screen lock information of the electronic device indicates that the number of failed unlock attempts is greater than or equal to a third preset threshold. When the electronic device determines that the risk status indicated by the status information of multiple risk factors meets the above preset control conditions, the electronic device can determine that there is an abnormal unlock risk, and the electronic device needs to perform risk control.
[0078] Optionally, when determining whether the status information corresponding to a risk factor meets the preset control conditions, the electronic device can compare the status information of each risk factor with its corresponding preset control conditions. When it is determined that the risk status corresponding to multiple risk factors meets the preset control conditions, the electronic device can determine that there is a risk of abnormal unlocking of the electronic device.
[0079] For example, when the risk factor is the location of an electronic device, the preset control condition corresponding to this risk factor is that the electronic device's location is not within its usual location range. The electronic device can store its usual locations and compare its current location with these usual locations to determine whether the current location falls within the usual range.
[0080] For example, when the risk factor is network connection status, the preset control condition corresponding to this risk factor is that the network disconnection time of the electronic device is greater than or equal to the first preset threshold. The electronic device can detect the network connection status of the electronic device. When the electronic device disconnects from the network, the electronic device can record the time when the electronic device disconnects from the network and calculate the duration between the disconnection time and the current time. This duration is the network disconnection duration. The electronic device can compare whether the network disconnection duration is greater than or equal to the first preset threshold.
[0081] For example, when the risk factor is the paired device status, the preset control condition corresponding to this risk factor is that the historical paired devices of the electronic device are in an offline state. The electronic device can store the identifiers of other electronic devices paired or connected to it, and detect whether the paired device is online. The online status of the paired device is used to indicate whether the paired device is connected to the electronic device. The paired device being online means that the paired device is currently connected to the electronic device, and the paired device being offline means that the paired device is not currently connected to the electronic device.
[0082] For example, when the risk factor is the screen lock state, the preset control condition corresponding to this risk factor is that the duration of the electronic device's screen lock state is greater than or equal to a second preset threshold. When the electronic device determines to switch from the unlock state to the screen lock state, it can record the time when the electronic device last entered the screen lock state and calculate the duration between the time when it entered the screen lock state and the current time. This duration is the screen lock state duration, and the electronic device can compare whether the screen lock state duration is greater than or equal to the second preset threshold.
[0083] For example, when the risk factor is a locked screen state, the preset control condition corresponding to this risk factor can also be that the number of failed unlock attempts of the electronic device is greater than or equal to a third preset threshold. The electronic device can record the number of times the user fails to unlock and determine whether the number of failed unlock attempts is greater than or equal to the third preset threshold.
[0084] It should be noted that the multiple risk factors and their corresponding preset control conditions in the above embodiments are only examples and not limitations. In practice, risk factors may also be other factors that may affect the security of unlocking electronic devices, and the preset control conditions corresponding to each risk factor may also have other implementation forms. This application embodiment does not limit these aspects.
[0085] In this embodiment of the application, when an electronic device determines whether there is a risk of abnormal unlocking based on the status information of multiple risk factors, it can determine that there is a risk of abnormal unlocking when the status of all risk factors among the multiple risk factors meets the preset control conditions, or the electronic device can determine that there is a risk of abnormal unlocking when the status of at least one risk factor among the multiple risk factors meets the preset control conditions.
[0086] In some examples, electronic devices can also assign different weight values to multiple risk factors. For example, electronic devices can determine the weight values of different risk factors based on the degree of impact of different risk factors on the security of electronic devices. When electronic devices determine that the sum of the weight values corresponding to at least one risk factor that meets the preset control conditions is greater than a third preset threshold, electronic devices can determine that there is an abnormal unlocking risk.
[0087] Through the above design, electronic devices can fuse and judge the status of multiple risk factors to accurately distinguish between attacker behavior and normal user behavior. Moreover, the risk factors provided in this application embodiment are different from risk judgment factors triggered by active operations such as user-set SOS mode and lost mode. Electronic devices can automatically perform risk detection based on information such as location, network connection status, paired device connection status, and screen lock status, thereby enabling timely detection of abnormal unlocking risks of electronic devices and improving the accuracy of risk detection.
[0088] In this embodiment of the application, when it is determined that there is a risk of abnormal unlocking, the electronic device is subject to risk control, and the biometric unlocking function of the electronic device is disabled. When the electronic device is in the locked screen state, it only supports the user to unlock it through a preset lock screen password.
[0089] In one optional implementation, the electronic device can erase or disable key information in the biometric unlocking path. This key information is a file key used to obtain encryption or decryption keys for system files, thereby disabling the biometric unlocking function of the electronic device. Optionally, the key information may include ciphertext used to derive the file key, and / or a first key used to decrypt the ciphertext. When the electronic device first generates a system file, it can generate a file key associated with the system file. The process of unlocking the electronic device based on the user's biometrics can be a process of restoring the file key based on the user's biometrics and decrypting the system file based on the file key. In this embodiment, the electronic device can erase the ciphertext used to derive the file key, thereby disconnecting the path for restoring the file key, or the electronic device can disable the function of decrypting the ciphertext with the first key, thereby prohibiting the derivation of the file key.
[0090] For example, Figure 4 is a schematic diagram of the unlocking path of an electronic device in the lock screen state provided by an embodiment of this application. Referring to Figure 4, when a user unlocks the electronic device using biometrics such as face or fingerprint, the electronic device generates a first key based on the detected face or fingerprint information. The electronic device decrypts the ciphertext stored in the electronic device based on the first key to obtain plaintext. The electronic device can derive a file key based on the plaintext and a random number. For example, the random number can be a file identifier generated when creating a system file, and the file key can be used to decrypt the system files of the electronic device. In this embodiment of the application, the electronic device can erase the ciphertext in the biometric unlocking path shown in Figure 4 or disable the first key. Disabling the first key can disable the function of using the first key to decrypt ciphertext, thereby disabling the biometric unlocking function of the electronic device.
[0091] This approach provides a cryptographic-level risk management method that ensures that even if an attacker bypasses the lock screen and enters the desktop, they cannot access the data normally. Compared to disabling facial recognition or fingerprint recognition controls, this method significantly enhances the security strength of risk management.
[0092] In this embodiment, after disabling biometric authentication, the electronic device only supports unlocking via a preset lock screen password. When the user enters the lock screen password, the electronic device unlocks if the entered password matches the preset password. After the user completes one unlocking process using the lock screen password, the electronic device can re-enable the biometric unlocking function.
[0093] In one optional implementation, the electronic device can recover or enable key information in the biometric unlock path based on the lock screen password to re-enable the biometric unlock function of the electronic device. The key information includes ciphertext for deriving a file key and / or a first key for decrypting the ciphertext. For example, the electronic device can generate the ciphertext in the biometric unlock path shown in Figure 4 based on the lock screen password, or the electronic device can enable the first key to restore the function of decrypting the ciphertext to obtain plaintext, thereby re-enabling the biometric unlock function of the electronic device.
[0094] Based on the unlocking risk prevention and control method provided in this application embodiment, Figure 5 is a structural schematic diagram of an electronic device provided in this application embodiment. Referring to Figure 5, the electronic device may include a sensing module 501, a decision module 502, and an execution module 503. The sensing module 501 is used to detect the status of multiple risk factors to obtain status information corresponding to the multiple risk factors. The status information corresponding to the multiple risk factors includes at least two of location information, network status information, paired device information, and lock screen information. The decision module 502 is used to determine whether the electronic device has an abnormal unlocking risk based on the status information corresponding to the multiple risk factors. The decision module 502 can receive the status information corresponding to the risk factors sent by the sensing module 501, and can also obtain the status information corresponding to the risk factors detected historically from the local storage space of the electronic device. The decision module 502 can determine that the electronic device has an abnormal unlocking risk when the risk status indicated by the status information corresponding to the multiple risk factors meets preset control conditions. The execution module 503 is used to disable the biometric unlocking function of the electronic device when the decision module 502 determines that the electronic device has an abnormal unlocking risk.
[0095] Based on the architecture of the electronic device shown in Figure 5, Figure 6 is a flowchart of an unlocking risk prevention method provided by an embodiment of this application. Referring to Figure 6, the method may include the following steps:
[0096] S601: The electronic device obtains status information corresponding to multiple risk factors of the electronic device, including at least two of the following: location information, network status information, paired device information, and lock screen information.
[0097] Optionally, S601 can be executed by the sensing module 501 shown in FIG5.
[0098] S602: When the risk status indicated by the status information corresponding to multiple risk factors meets the preset control conditions, the biometric unlocking function of the electronic device shall be disabled.
[0099] Optionally, the step in S602 to determine whether the risk status indicated by the status information corresponding to multiple risk factors meets the preset control conditions can be executed by the decision module 502 shown in Figure 5, and the biometric unlocking function of the electronic device can be disabled by the execution module 503 shown in Figure 5.
[0100] It should be noted that the unlocking risk prevention and control method shown in Figure 6 of this application can be referred to the above embodiments of this application in specific implementation, and repeated parts will not be described again.
[0101] Based on the above embodiments, this application also provides an electronic device, which includes at least one processor and at least one memory, wherein the at least one memory stores computer program instructions. When the electronic device is running, the at least one processor executes the functions performed by the electronic device in the various methods described in the embodiments of this application. The steps performed by the electronic device in the embodiment shown in FIG6 are executed as follows.
[0102] Based on the above embodiments, this application also provides a computer program product containing instructions, which, when run on a computer, causes the computer to perform the methods described in the embodiments of this application.
[0103] Based on the above embodiments, this application also provides a computer-readable storage medium storing a computer program, which, when executed by a computer, causes the computer to perform the methods described in the embodiments of this application.
[0104] Based on the above embodiments, this application also provides a chip for reading computer programs stored in a memory to implement the methods described in the embodiments of this application.
[0105] Based on the above embodiments, this application provides a chip system including a processor for supporting a computer device in implementing the methods described in the embodiments of this application. In one possible design, the chip system further includes a memory for storing necessary programs and data of the computer device. This chip system may be composed of chips or may include chips and other discrete devices.
[0106] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0107] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.
[0108] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0109] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0110] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of protection of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for unlocking risk prevention and control, characterized in that, Applied to electronic devices, the method includes: Obtain status information corresponding to multiple risk factors of the electronic device, wherein the status information corresponding to the multiple risk factors includes at least two of location information, network status information, paired device information, and screen lock information; When the risk status indicated by the status information corresponding to the multiple risk factors meets the preset control conditions, the biometric unlocking function of the electronic device is disabled.
2. The method as described in claim 1, characterized in that, The risk status indicated by the status information corresponding to the multiple risk factors meets the preset control conditions, including at least one of the following: The location indicated by the location information of the electronic device is not within the range of the electronic device's usual locations; The network status information of the electronic device indicates that the duration of the electronic device's network outage is greater than or equal to a first preset threshold. The pairing device information of the electronic device indicates that the historical pairing device of the electronic device is offline; The screen lock information of the electronic device indicates that the duration of the screen lock state of the electronic device is greater than or equal to a second preset threshold. The lock screen information of the electronic device indicates that the number of failed unlock attempts of the electronic device is greater than or equal to a third preset threshold.
3. The method as described in claim 1 or 2, characterized in that, Disabling the biometric unlocking function of the electronic device includes: Erase or disable the key information in the biometric unlocking path, which is used to obtain the file key for encrypting or decrypting system files.
4. The method according to any one of claims 1-3, characterized in that, After disabling the biometric unlocking function of the electronic device, the method further includes: The device receives a lock screen password input by the user and unlocks the electronic device when the user-input lock screen password matches a preset lock screen password. Re-enable the biometric unlocking function of the electronic device.
5. The method as described in claim 4, characterized in that, The lock screen password includes at least one of the following: lock screen password, lock screen pattern.
6. The method as described in claim 4 or 5, characterized in that, The reactivation of the biometric unlocking function of the electronic device includes: The key information in the biometric unlocking path is restored or enabled based on the lock screen password. The key information is used to obtain the file key for encrypting or decrypting system files.
7. The method as described in claim 3 or 6, characterized in that, The key information includes ciphertext for deriving a file key, and / or a first key for decrypting the ciphertext.
8. The method according to any one of claims 1-7, characterized in that, The biometric unlocking function of the electronic device includes at least one of face unlocking, fingerprint unlocking, and iris unlocking.
9. An electronic device, characterized in that, It includes at least one processor coupled to at least one memory, the at least one processor being configured to read a computer program stored in the at least one memory to perform the method as described in any one of claims 1-8.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-8.