CN101854581A - Method for setting security level of mobile terminal on basis of position information and mobile terminal - Google Patents

Method for setting security level of mobile terminal on basis of position information and mobile terminal Download PDF

Info

Publication number
CN101854581A
CN101854581A CN200910081050A CN200910081050A CN101854581A CN 101854581 A CN101854581 A CN 101854581A CN 200910081050 A CN200910081050 A CN 200910081050A CN 200910081050 A CN200910081050 A CN 200910081050A CN 101854581 A CN101854581 A CN 101854581A
Authority
CN
China
Prior art keywords
portable terminal
information
residing
corresponding relation
primary importance
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN200910081050A
Other languages
Chinese (zh)
Other versions
CN101854581B (en
Inventor
陈兴文
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Lenovo Beijing Ltd
Original Assignee
Lenovo Beijing Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Lenovo Beijing Ltd filed Critical Lenovo Beijing Ltd
Priority to CN200910081050.6A priority Critical patent/CN101854581B/en
Publication of CN101854581A publication Critical patent/CN101854581A/en
Application granted granted Critical
Publication of CN101854581B publication Critical patent/CN101854581B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The invention discloses a method for setting the security level of a mobile terminal on the basis of position information and the mobile terminal. The method comprises the steps of: acquiring the position information in which the mobile terminal is located; searching correspondence relationship between the position information and a strategy file, and acquiring the strategy file corresponding to the position information in which the mobile terminal is located; and setting the security level of the mobile terminal according to the searched strategy file. In the invention, the feature of the position information can be acquired by using the mobile terminal and the use permission of the mobile terminal is managed so as to ensure that the mobile terminal has different use permissions in different area coverage, thus the security of the mobile terminal is improved; and particularly for the mobile terminal belonging to an enterprise, a security strategy can be customized according to requirements on confidentiality, thereby the requirements on enterprise information security management are met.

Description

Position-based information setting portable terminal safe level method for distinguishing and portable terminal
Technical field
The present invention relates to communication technical field, particularly a kind of position-based information setting portable terminal safe level method for distinguishing and portable terminal.
Background technology
Along with GPS (Global Positioning System, the whole world is decided to be system) extensive use, GPS has been integrated into wireless communication module gradually, for example, WWAN (Wireless Wide Area Network, wireless broadband network) in the card, the WWAN technology is to make notebook computer or other portable terminal can be connected to the Internet anywhere in the cellular network coverage.The application of GPS at present mainly is confined to the service of positional information, comprises Map Services or navigation Service etc.With applying GPS in the notebook is example, independently GPS module is set in notebook, such as increasing external GPS module by blue tooth interface, during work, the GPS module is obtained location coordinate information, location coordinate information sends the corresponding map software in the notebook to, and map software is converted to the positional information of base map with location coordinate information, is the user-provided location information service then.
Find in the research process of inventor to prior art, for the portable terminal with GPS itself, especially concerning the portable terminal that belongs to enterprise, because the needs of maintaining secrecy, wish that portable terminal limits its rights of using when shifting out Administrative Area, guaranteeing the safety in utilization of portable terminal,, and can't be applied in the security management to portable terminal though GPS can be used in combination with portable terminal.
Summary of the invention
The purpose of the embodiment of the invention is to provide a kind of position-based information setting portable terminal safe level method for distinguishing and portable terminal, to solve the not high problem of fail safe that has the portable terminal of GPS in the prior art.
For solving the problems of the technologies described above, the embodiment of the invention provides following technical scheme:
A kind of position-based information setting portable terminal safe level method for distinguishing comprises:
Obtain the residing positional information of portable terminal;
Search the corresponding relation of positional information and strategy file, obtain and the residing positional information corresponding strategy of described portable terminal file;
The level of security of described portable terminal is set according to the described strategy file that finds.
The described residing positional information of portable terminal of obtaining comprises:
Obtain the residing positional information of described portable terminal by the GPS module; Or
Obtain the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze described master site information and described aided location information obtains the residing precise position information of described portable terminal; Or
Link to each other with wireless router by wireless module, and obtain the residing positional information of described portable terminal from described wireless router.
Also comprise:
Dispose the corresponding relation of described positional information and strategy file;
Described strategy file is encrypted, and stored the corresponding relation of described positional information and strategy file.
The corresponding relation of described allocation position information and strategy file comprises:
Dispose the corresponding relation of described positional information and policy information according to the configuration order of described mobile terminal user input; Or
Dispose the corresponding relation of described positional information and policy information according to the configuration order of server transmission.
Describedly comprise according to the configuration order allocation position information of mobile terminal user input and the corresponding relation of policy information:
Enter configuration interface behind the described mobile terminal-opening;
Receive the configuration order that the user imports by described configuration interface, comprise the corresponding relation of described positional information and policy information in the described configuration order;
Upgrade configured corresponding relation according to described configuration order.
The corresponding relation that the described configuration order that sends according to server disposes described positional information and policy information comprises:
The configuration request message that reception server sends;
Described configuration request message checking is received the configuration order that described server sends by the back, comprise the corresponding relation of described positional information and policy information in the described configuration order;
Upgrade configured corresponding relation according to described configuration order, and return the renewal success message to described server.
The corresponding relation of described positional information and strategy file is specially: the positional information that sets in advance according to user's request and the corresponding relation of strategy file.
A kind of portable terminal comprises:
Acquiring unit is used to obtain the residing positional information of described portable terminal;
Search the unit, be used to search the corresponding relation of positional information and strategy file, obtain and the residing positional information corresponding strategy of described portable terminal file;
The unit is set, is used for being provided with the level of security of described portable terminal according to the described strategy file that finds.
Described acquiring unit comprises at least one following unit:
First acquiring unit is used for obtaining the residing positional information of described portable terminal by the GPS module;
Second acquisition unit, be used for obtaining the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze described master site information and described aided location information obtains the residing precise position information of described portable terminal;
The 3rd acquiring unit is used for linking to each other with wireless router by wireless module, and obtains the residing positional information of described portable terminal from described wireless router.
Also comprise:
Dispensing unit is used for the corresponding relation of pre-configured described positional information and strategy file;
Ciphering unit is used for described strategy file is encrypted;
Memory cell is used to store the corresponding relation of described positional information and strategy file.
Described dispensing unit comprises a following unit at least:
First dispensing unit is used for disposing according to the configuration order of described mobile terminal user input the corresponding relation of described positional information and policy information;
Second dispensing unit is used for disposing according to the configuration order that server sends the corresponding relation of described positional information and policy information.
Described first dispensing unit comprises:
Configuration interface enters the unit, is used for entering configuration interface behind the described mobile terminal-opening;
The configuration order receiving element is used for receiving the configuration order that the user imports by described configuration interface, comprises the corresponding relation of described positional information and policy information in the described configuration order;
The corresponding relation updating block is used for upgrading configured corresponding relation according to described configuration order.
Described second dispensing unit comprises:
The request message receiving element is used for the configuration request message that reception server sends;
The configuration order receiving element is used for described configuration request message checking is received the configuration order that described server sends by the back, comprises the corresponding relation of described positional information and policy information in the described configuration order;
The corresponding relation updating block is used to upgrade configured corresponding relation;
Updating message is returned the unit, is used for returning the renewal success message to described server.
A kind of position-based information setting portable terminal safe level method for distinguishing comprises:
Obtain the primary importance information of the residing primary importance of portable terminal;
Judge that based on described primary importance information whether described primary importance belongs to the first area, produces a judged result;
When described judged result represented that described primary importance belongs to described first area, the level of security that described portable terminal is set according to first strategy was first level of security;
When described judged result represents that described primary importance belongs to the nonoverlapping second area in described first area, the level of security that described portable terminal is set according to second strategy is second level of security, and described second level of security is different with described first level of security.
The described primary importance information of obtaining the residing primary importance of portable terminal comprises:
Obtain the primary importance information of the residing primary importance of described portable terminal by the GPS module; Or
Obtain the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze the primary importance information that described master site information and described aided location information obtain the residing primary importance of described portable terminal; Or
Link to each other with wireless router by wireless module, and obtain the primary importance information of the residing primary importance of described portable terminal from described wireless router.
Described first strategy and described second strategy that preservation sets in advance.
A kind of portable terminal comprises:
Acquiring unit is used to obtain the primary importance information of the residing primary importance of portable terminal;
Judging unit is used for judging that based on described primary importance information whether described primary importance belongs to the first area, produces a judged result;
The unit is set, be used for when described judged result represents that described primary importance belongs to described first area, the level of security that described portable terminal is set according to first strategy is first level of security, when described judged result represents that described primary importance belongs to the nonoverlapping second area in described first area, the level of security that described portable terminal is set according to second strategy is second level of security, and described second level of security is different with described first level of security.
Described acquiring unit comprises at least one following unit:
First acquiring unit is used for obtaining by the GPS module primary importance information of the residing primary importance of described portable terminal; Or
Second acquisition unit, be used for obtaining the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze the primary importance information that described master site information and described aided location information obtain the residing primary importance of described portable terminal; Or
The 3rd acquiring unit is used for linking to each other with wireless router by wireless module, and obtains the primary importance information of the residing primary importance of described portable terminal from described wireless router.
Also comprise: preserve the unit, be used to preserve described first strategy and described second strategy that sets in advance.
The technical scheme that is provided by the above embodiment of the invention as seen, the present invention obtains the residing positional information of portable terminal, search the corresponding relation of positional information and strategy file, obtain and the residing positional information corresponding strategy of portable terminal file, the level of security of portable terminal is set according to the strategy file that finds.The present invention has utilized portable terminal can obtain the characteristic of positional information, the rights of using of portable terminal is managed, so that portable terminal has different rights of using, the fail safe that improves portable terminal thus in different regional extents; Special in the portable terminal that belongs to enterprise, can carry out the customization of security strategy according to the demand of maintaining secrecy, thereby satisfy the demand of enterprise information security management.
Description of drawings
Fig. 1 the present invention is based on the first embodiment flow chart that positional information is provided with portable terminal safe level method for distinguishing;
Fig. 2 the present invention is based on the second embodiment flow chart that positional information is provided with portable terminal safe level method for distinguishing;
Fig. 3 the present invention is based on the 3rd embodiment flow chart that positional information is provided with portable terminal safe level method for distinguishing;
Fig. 4 the present invention is based on the 4th embodiment flow chart that positional information is provided with portable terminal safe level method for distinguishing;
The system configuration schematic diagram that Fig. 5 controls for portable terminal of the present invention;
Fig. 6 is first embodiment of portable terminal of the present invention;
Fig. 7 is second embodiment of portable terminal of the present invention;
Fig. 8 is the 3rd embodiment of portable terminal of the present invention.
Embodiment
In following a plurality of embodiment of the present invention, some embodiment provides a kind of position-based information setting portable terminal safe level method for distinguishing, some embodiment provides a kind of portable terminal, described terminal control method is by obtaining the residing positional information of portable terminal, search the corresponding relation of positional information and strategy file, obtain and the residing positional information corresponding strategy of portable terminal file, the level of security of portable terminal is set according to the strategy file that finds.
In order to make those skilled in the art person understand technical scheme in the embodiment of the invention better, and the above-mentioned purpose of the embodiment of the invention, feature and advantage can be become apparent more, below in conjunction with accompanying drawing technical scheme in the embodiment of the invention is described in further detail.
The present invention is based on positional information terminal control method the first embodiment flow process as shown in Figure 1, comprise the GPS module in this portable terminal:
Step 101: obtain the residing positional information of portable terminal.
Concrete, can obtain the positional information of portable terminal by the GPS module; Perhaps obtain the master site information of portable terminal by the GPS module, and obtain the aided location information of described portable terminal from the base station by wireless communication module, analyze the precise position information that described master site information and described aided location information obtain described portable terminal; Perhaps link to each other with wireless router, and obtain the positional information of described portable terminal from described wireless router by wireless module.
Step 102: search the corresponding relation of positional information and strategy file, obtain and the residing positional information corresponding strategy of portable terminal file.
Wherein, the corresponding relation of positional information and strategy file can dispose in the following manner: dispose the corresponding relation of described positional information and policy information according to the configuration order of described mobile terminal user input, or dispose the corresponding relation of described positional information and policy information according to the configuration order that server sends.
Step 103: the level of security that portable terminal is set according to the strategy file that finds.
The present invention is based on positional information terminal control method the second embodiment flow process as shown in Figure 2, comprise the GPS module in this portable terminal:
Step 201: the primary importance information of obtaining the residing primary importance of portable terminal.
Wherein, can obtain the primary importance information of the residing primary importance of described portable terminal by the GPS module; Or obtain the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze the primary importance information that described master site information and described aided location information obtain the residing primary importance of described portable terminal; Or link to each other with wireless router, and obtain the primary importance information of the residing primary importance of described portable terminal from described wireless router by wireless module.
Step 202: judge based on primary importance information whether primary importance belongs to the first area, if then execution in step 203; If belong to and the nonoverlapping second area in first area, then execution in step 204.
Step 203: the level of security that portable terminal is set according to first strategy is first level of security, finishes current flow process.
Step 204: the level of security that portable terminal is set according to second strategy is second level of security, and second level of security is different with described first level of security, finishes current flow process.
The present invention is based on positional information terminal control method the 3rd embodiment flow process as shown in Figure 3, comprise GPS module and wireless communication module in this portable terminal, this embodiment shows according to the configuration order allocation position information of user's input and the corresponding relation of policy information, and portable terminal is carried out the process that level of security is provided with:
Step 301: enter configuration interface behind the mobile terminal-opening.
The embodiment of the invention can be on the basis of applying GPS and radio communication, in conjunction with Always on technology, make no matter portable terminal is in which kind of state (off-mode, sleep state etc.), obtain the function of positional information and open always according to the function that positional information is carried out safety management.
Always on technology refers in portable terminal to embed an independently system or revise the existing system framework and make and constitute hybrid system configuration in the portable terminal, when portable terminal is in dormancy/standby/off-mode following time, some parts in this mixed architecture can work on, to realize Secure Application.Need to prove, all level of security settings of portable terminal also can be managed separately by the system that realizes Always on technology, perhaps all level of security settings of portable terminal are except being finished by main system, can also finish separately by one or more system in the hybrid system configuration or cooperation is finished, this embodiment of the invention is not limited.
When GPS and radio communication during in conjunction with this Always on technology, by the system that carries out Always on technology GPS module and wireless communication module are controlled, to obtain the positional information of portable terminal, its control procedure is similar with the process of GPS module and wireless communication module being controlled by the portable terminal main system, does not repeat them here.
When portable terminal was notebook computer, configuration interface can be specially the BIOS interface.
Step 302: the configuration order that receives user's input by configuration interface.
Can comprise the corresponding relation of positional information and strategy file in the configuration order, for example can be specially:
When portable terminal was positioned at company's office areas, strategy file used the authority of portable terminal all functions resource for the user has, and therefore all software and hardwares that can dispose portable terminal according to this strategy file all can use; When portable terminal shifts out Administrative Area and in certain safe range the time, strategy file is basic document browsing authority for the user has, the therefore interfaces such as USB that can the dispose portable terminal use that is under an embargo according to this strategy file; When portable terminal shifted out above-mentioned safe range, strategy file can't be opened portable terminal for the user or use its any resource, therefore can dispose portable terminal according to this strategy file and be automatically locked or encrypt.
Further,, then can recover authority that resource uses etc., perhaps be provided with regularly, prevent losing of portable terminal with this to the user of appointment or server reporting position information etc. if can be arranged on when shifting out safe range the input web-privilege password Web.
Need to prove, only enumerated an example above, in actual application, can be as required, the corresponding relation of corresponding positional information of flexible configuration such as safety management requirement of enterprise and strategy file for example.
Step 303: upgrade configured corresponding relation according to configuration order.
If the corresponding relation of stored position information and strategy file not in the portable terminal is then preserved the described corresponding relation of initial setting up; If stored the corresponding relation of positional information and strategy file in the portable terminal, then the corresponding relation with latest configuration upgrades configured corresponding relation.
Step 304: the corresponding relation of described strategy file being encrypted back stored position information and strategy file.
In order to guarantee the fail safe of strategy file, storage again after can encrypting strategy file to guarantee that strategy file is not arbitrarily changed, improves the fail safe of portable terminal.
Step 305: obtain the master site information of portable terminal from the GPS module, obtain the aided location information of portable terminal from wireless communication module.
Wherein, wireless communication module can have AGPS (Assisted Global Positioning System, assisted global is decided navigation system) function, and this function is a kind of technology that base station information and GPS information position portable terminal that combines; Wireless communication module also can integrated GPS module, promptly has been equivalent to the GPS function integrated, equally also can be in conjunction with the aided location information that the base station provided, thus realize location positioning accurately, and its speed of searching for mobile terminal locations first is very fast.
Step 306: by analyzing the precise position information that master site information and aided location information obtain portable terminal.
Step 307: search the corresponding relation of positional information and strategy file, obtain positional information corresponding strategy file with portable terminal.
Step 308: according to the rights of using of the strategy file control portable terminal that finds.
The present invention is based on positional information terminal control method the 4th embodiment flow process as shown in Figure 4, comprise the GPS module in this portable terminal, this embodiment shows the configuration order allocation position information that sends according to server and the corresponding relation of policy information, and the process that portable terminal is controlled:
Step 401: the configuration request message that reception server sends.
The control method of portable terminal of the present invention can be applied in the management of enterprise to portable terminal especially, therefore can unify configuration to the corresponding relation of all location information of terminals and strategy file by enterprise servers.
Step 402: to the configuration order of configuration request message checking by back reception server transmission.
The corresponding relation that comprises described positional information and policy information in the configuration order can be specially:
1) unrestricted state
For example, in setting occasions such as companies, the user can use all resources of portable terminal fully, comprises hardware resource and software resource.
2) hardware interface restriction state
For example, at user's durante absentia, ports such as USB interface, card reader interface, network interface can not use, but can normally use other resource.
3) confidential documents restriction mode of operation
For example, at special occasions, the operation that is under an embargo of treated confidential documents.
Above configured corresponding relation is only done example, the corresponding relation of flexible configuration positional information and strategy file as required during actual the use.
Step 403: upgrade configured corresponding relation according to configuration order.
Step 404: return the renewal success message to server.
Step 405: strategy file is encrypted, and the corresponding relation of stored position information and strategy file.
Step 406: the positional information of obtaining portable terminal by the GPS module.
Step 407: search the corresponding relation of positional information and strategy file, obtain positional information corresponding strategy file with portable terminal.
Step 408: the rights of using of controlling described portable terminal according to the strategy file that finds.
In the various embodiments described above, can dispose different wireless communication modules according to the difference of mobile terminal style.For example, when portable terminal was notebook computer, wireless communication module can be the WWAN module, and when mobile each terminal was mobile phone or PDA, wireless communication module can be gsm module or CDMA module etc.
Need to prove, the embodiment of the invention is carried out safety management except being used for to the portable terminal in the enterprise, for example the notebook computer to the employee carries out security control, also can be used for personal communications terminal is carried out safety management, for example mobile phone is carried out the demand configuration, when judging that according to the positional information of mobile phone mobile phone moves in the meeting room, it is quiet etc. that mobile phone is set to.That is to say that the present invention is used in any occasion that positional information is combined with mobile terminal administration, and this embodiment of the invention is not limited.
The present invention is based on positional information terminal control method embodiment application scenarios as shown in Figure 5, the figure shows the system configuration schematic diagram that portable terminal of the present invention is controlled:
Among Fig. 5, suppose that portable terminal is a notebook computer, what then need to communicate by letter with notebook computer comprises satellite, base station and server.Wherein, rights management control module internal memory contains the positional information of configuration and the corresponding relation of strategy file, this corresponding relation can be transferred to the rights management control module by the communication mould by server, in control procedure, GPS module in the position information acquisition module receives the master site information of this notebook computer of satellite transmits, the WWAN module receives the aided location information of base station transmits, after analyzing master site information and aided location information, analysis module obtains the precise position information of notebook computer, and this precise position information is transferred to the position information process module, the position information process module is searched configured corresponding relation from the authority management control module, obtain and this positional information corresponding strategy file, with the strategy file notice rights management control module that obtains, according to this strategy file control enable module, use limits to the resource in the notebook computer by this rights management control module.
Below in conjunction with concrete application scenarios the embodiment of the invention is described, suppose that certain company personnel has distributed one and had the notebook computer that above-mentioned level of security is provided with function, the scope of application of this notebook computer comprises three zones, (for example be respectively beyond Office Area, company, the company, family), wherein the level of security of Office Area is minimum, and the level of security of company's scope takes second place, (for example, family) level of security is the highest beyond the company.The employee is in the process of using this notebook computer, when judging this notebook computer and be in the Office Area, first strategy that sets in advance is stored in a safety zone on the hard disk for all Edit Document unifications of active user, or and, need not input password and (for example just can open the office mailbox, Lotus Notes), or and, USB interface all can be used; When judging this notebook computer and be in company's scope, second strategy that sets in advance only can be visited the file that is stored on the safety zone for the user, but can not edit, or and, need the input password (for example just can open the office mailbox, Lotus Notes), or and, USB interface is all forbidden; When judging this notebook computer and be in non-company scope, the 3rd strategy that sets in advance becomes hidden state for described safety zone, the user can't see this safety zone, or and, the user (for example can't use the office mailbox, Lotus Notes), or and, USB interface is all forbidden; The employee carries notebook computer when move in these three zones, the positional information of this notebook computer present position that this notebook computer just can be automatically gathered according to the GPS module, automatically judge this current which zone that belongs in above-mentioned three zones, the level of security of this portable terminal automatically is set then, to realize security management to portable terminal in the enterprise according to the corresponding strategy file that sets in advance.
Need to prove, except the mode that GPS module and WWAN module combine of passing through shown in the foregoing description is obtained the positional information of portable terminal, can also only obtain the positional information of portable terminal by the GPS module, perhaps insert wireless router by the wireless module in the portable terminal, and obtain the positional information of portable terminal from this wireless router, do not limit for the mode embodiment of the invention of obtaining location information of mobile terminal.
Corresponding with the terminal control method that the present invention is based on positional information, the present invention also provides the embodiment of portable terminal.
The first embodiment block diagram of portable terminal of the present invention as shown in Figure 6, this portable terminal comprises: acquiring unit 610, search unit 620 and unit 630 is set.
Wherein, acquiring unit 610 is used to obtain the residing positional information of described portable terminal; Search the corresponding relation that unit 620 is used to search positional information and strategy file, obtain and the residing positional information corresponding strategy of described portable terminal file; The level of security that unit 630 is used for being provided with according to the described strategy file that finds described portable terminal is set.
The second embodiment block diagram of portable terminal of the present invention as shown in Figure 7, this portable terminal comprises: dispensing unit 710, ciphering unit 720, memory cell 730, acquiring unit 740, search unit 750 and unit 760 is set.
Wherein, dispensing unit 710 is used for the corresponding relation of pre-configured described positional information and strategy file; Ciphering unit 720 is used for described strategy file is encrypted; Memory cell 730 is used to store the corresponding relation of described positional information and strategy file; Acquiring unit 740 is used to obtain the residing precise position information of described portable terminal; Search the corresponding relation that unit 750 is used to search positional information and strategy file, obtain and the residing positional information corresponding strategy of described portable terminal file; The level of security that unit 760 is used for being provided with according to the described strategy file that finds described portable terminal is set.
Concrete, acquiring unit 740 can comprise at least one following unit (not shown among Fig. 7): first acquiring unit is used for obtaining the residing positional information of described portable terminal by the GPS module; Second acquisition unit, be used for obtaining the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze described master site information and described aided location information obtains the residing precise position information of described portable terminal; The 3rd acquiring unit is used for linking to each other with wireless router by wireless module, and obtains the residing positional information of described portable terminal from described wireless router.
Concrete, dispensing unit 710 comprises at least one following unit (not shown among Fig. 7): first dispensing unit is used for disposing according to the configuration order of described mobile terminal user input the corresponding relation of described positional information and policy information; Second dispensing unit is used for disposing according to the configuration order that server sends the corresponding relation of described positional information and policy information.
Wherein, first dispensing unit can comprise: configuration interface enters the unit, is used for entering configuration interface behind the described mobile terminal-opening; The configuration order receiving element is used for receiving the configuration order that the user imports by described configuration interface, comprises the corresponding relation of described positional information and policy information in the described configuration order; The corresponding relation updating block is used for upgrading configured corresponding relation according to described configuration order.
Wherein, second dispensing unit can comprise: the request message receiving element is used for the configuration request message that reception server sends; The configuration order receiving element is used for described configuration request message checking is received the configuration order that described server sends by the back, comprises the corresponding relation of described positional information and policy information in the described configuration order; The corresponding relation updating block is used to upgrade configured corresponding relation; Updating message is returned the unit, is used for returning the renewal success message to described server.
The 3rd embodiment block diagram of portable terminal of the present invention as shown in Figure 8, this portable terminal comprises: acquiring unit 810, judging unit 820 and unit 830 is set.
Wherein, acquiring unit 810 is used to obtain the primary importance information of the residing primary importance of portable terminal; Judging unit 820 is used for judging that based on described primary importance information whether described primary importance belongs to the first area, produces a judged result; Unit 830 is set to be used for when described judged result represents that described primary importance belongs to described first area, the level of security that described portable terminal is set according to first strategy is first level of security, when described judged result represents that described primary importance belongs to the nonoverlapping second area in described first area, the level of security that described portable terminal is set according to second strategy is second level of security, and described second level of security is different with described first level of security.
Concrete, acquiring unit 810 can comprise at least one following unit (not shown among Fig. 8): first acquiring unit is used for obtaining by the GPS module primary importance information of the residing primary importance of described portable terminal; Or second acquisition unit, be used for obtaining the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze the primary importance information that described master site information and described aided location information obtain the residing primary importance of described portable terminal; Or the 3rd acquiring unit, be used for linking to each other with wireless router, and obtain the primary importance information of the residing primary importance of described portable terminal from described wireless router by wireless module.
Further, this portable terminal can also comprise (not shown among Fig. 8): preserve the unit, be used to preserve described first strategy and described second strategy that sets in advance.
As seen through the above description of the embodiments, the present invention has utilized GPS can obtain the characteristic of positional information, rights of using to portable terminal manage, so that portable terminal has different rights of using, the fail safe that improves portable terminal thus in different regional extents; Special in the portable terminal that belongs to enterprise, can carry out the customization of security strategy according to the demand of maintaining secrecy, thereby satisfy the demand of enterprise information security management.
The technology that those skilled in the art can be well understood in the embodiment of the invention can realize by the mode that software adds essential general hardware platform.Based on such understanding, the part that technical scheme in the embodiment of the invention contributes to prior art in essence in other words can embody with the form of software product, this computer software product can be stored in the storage medium, as ROM/RAM, magnetic disc, CD etc., comprise that some instructions are with so that a computer equipment (can be a personal computer, server, the perhaps network equipment etc.) carry out the described method of some part of each embodiment of the present invention or embodiment.
Above-described embodiment of the present invention does not constitute the qualification to protection range of the present invention.Any modification of being done within the spirit and principles in the present invention, be equal to and replace and improvement etc., all should be included within protection scope of the present invention.

Claims (19)

1. a position-based information setting portable terminal safe level method for distinguishing is characterized in that, comprising:
Obtain the residing positional information of portable terminal;
Search the corresponding relation of positional information and strategy file, obtain and the residing positional information corresponding strategy of described portable terminal file;
The level of security of described portable terminal is set according to the described strategy file that finds.
2. method according to claim 1 is characterized in that, the described residing positional information of portable terminal of obtaining comprises:
Obtain the residing positional information of described portable terminal by the GPS module; Or
Obtain the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze described master site information and described aided location information obtains the residing precise position information of described portable terminal; Or
Link to each other with wireless router by wireless module, and obtain the residing positional information of described portable terminal from described wireless router.
3. method according to claim 1 is characterized in that, also comprises:
Dispose the corresponding relation of described positional information and strategy file;
Described strategy file is encrypted, and stored the corresponding relation of described positional information and strategy file.
4. method according to claim 3 is characterized in that, the corresponding relation of described allocation position information and strategy file comprises:
Dispose the corresponding relation of described positional information and policy information according to the configuration order of described mobile terminal user input; Or
Dispose the corresponding relation of described positional information and policy information according to the configuration order of server transmission.
5. method according to claim 4 is characterized in that, describedly comprises according to the configuration order allocation position information of mobile terminal user input and the corresponding relation of policy information:
Enter configuration interface behind the described mobile terminal-opening;
Receive the configuration order that the user imports by described configuration interface, comprise the corresponding relation of described positional information and policy information in the described configuration order;
Upgrade configured corresponding relation according to described configuration order.
6. method according to claim 4 is characterized in that, the corresponding relation that the described configuration order that sends according to server disposes described positional information and policy information comprises:
The configuration request message that reception server sends;
Described configuration request message checking is received the configuration order that described server sends by the back, comprise the corresponding relation of described positional information and policy information in the described configuration order;
Upgrade configured corresponding relation according to described configuration order, and return the renewal success message to described server.
7. according to any described method of claim 1 to 6, it is characterized in that the corresponding relation of described positional information and strategy file is specially: the positional information that sets in advance according to user's request and the corresponding relation of strategy file.
8. a portable terminal is characterized in that, comprising:
Acquiring unit is used to obtain the residing positional information of described portable terminal;
Search the unit, be used to search the corresponding relation of positional information and strategy file, obtain and the residing positional information corresponding strategy of described portable terminal file;
The unit is set, is used for being provided with the level of security of described portable terminal according to the described strategy file that finds.
9. portable terminal according to claim 8 is characterized in that, described acquiring unit comprises at least one following unit:
First acquiring unit is used for obtaining the residing positional information of described portable terminal by the GPS module;
Second acquisition unit, be used for obtaining the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze described master site information and described aided location information obtains the residing precise position information of described portable terminal;
The 3rd acquiring unit is used for linking to each other with wireless router by wireless module, and obtains the residing positional information of described portable terminal from described wireless router.
10. portable terminal according to claim 8 is characterized in that, also comprises:
Dispensing unit is used for the corresponding relation of pre-configured described positional information and strategy file;
Ciphering unit is used for described strategy file is encrypted;
Memory cell is used to store the corresponding relation of described positional information and strategy file.
11. portable terminal according to claim 10 is characterized in that, described dispensing unit comprises a following unit at least:
First dispensing unit is used for disposing according to the configuration order of described mobile terminal user input the corresponding relation of described positional information and policy information;
Second dispensing unit is used for disposing according to the configuration order that server sends the corresponding relation of described positional information and policy information.
12. portable terminal according to claim 11 is characterized in that, described first dispensing unit comprises:
Configuration interface enters the unit, is used for entering configuration interface behind the described mobile terminal-opening;
The configuration order receiving element is used for receiving the configuration order that the user imports by described configuration interface, comprises the corresponding relation of described positional information and policy information in the described configuration order;
The corresponding relation updating block is used for upgrading configured corresponding relation according to described configuration order.
13. portable terminal according to claim 11 is characterized in that, described second dispensing unit comprises:
The request message receiving element is used for the configuration request message that reception server sends;
The configuration order receiving element is used for described configuration request message checking is received the configuration order that described server sends by the back, comprises the corresponding relation of described positional information and policy information in the described configuration order;
The corresponding relation updating block is used to upgrade configured corresponding relation;
Updating message is returned the unit, is used for returning the renewal success message to described server.
14. a position-based information setting portable terminal safe level method for distinguishing is characterized in that, comprising:
Obtain the primary importance information of the residing primary importance of portable terminal;
Judge that based on described primary importance information whether described primary importance belongs to the first area, produces a judged result;
When described judged result represented that described primary importance belongs to described first area, the level of security that described portable terminal is set according to first strategy was first level of security;
When described judged result represents that described primary importance belongs to the nonoverlapping second area in described first area, the level of security that described portable terminal is set according to second strategy is second level of security, and described second level of security is different with described first level of security.
15. method according to claim 14 is characterized in that, the described primary importance information of obtaining the residing primary importance of portable terminal comprises:
Obtain the primary importance information of the residing primary importance of described portable terminal by the GPS module; Or
Obtain the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze the primary importance information that described master site information and described aided location information obtain the residing primary importance of described portable terminal; Or
Link to each other with wireless router by wireless module, and obtain the primary importance information of the residing primary importance of described portable terminal from described wireless router.
16. method according to claim 14 is characterized in that, also comprises: preserve described first strategy and described second strategy that sets in advance.
17. a portable terminal is characterized in that, comprising:
Acquiring unit is used to obtain the primary importance information of the residing primary importance of portable terminal;
Judging unit is used for judging that based on described primary importance information whether described primary importance belongs to the first area, produces a judged result;
The unit is set, be used for when described judged result represents that described primary importance belongs to described first area, the level of security that described portable terminal is set according to first strategy is first level of security, when described judged result represents that described primary importance belongs to the nonoverlapping second area in described first area, the level of security that described portable terminal is set according to second strategy is second level of security, and described second level of security is different with described first level of security.
18. portable terminal according to claim 17 is characterized in that, described acquiring unit comprises at least one following unit:
First acquiring unit is used for obtaining by the GPS module primary importance information of the residing primary importance of described portable terminal; Or
Second acquisition unit, be used for obtaining the residing master site information of described portable terminal by the GPS module, and obtain the residing aided location information of described portable terminal from the base station by wireless communication module, analyze the primary importance information that described master site information and described aided location information obtain the residing primary importance of described portable terminal; Or
The 3rd acquiring unit is used for linking to each other with wireless router by wireless module, and obtains the primary importance information of the residing primary importance of described portable terminal from described wireless router.
19. portable terminal according to claim 17 is characterized in that, also comprises: preserve the unit, be used to preserve described first strategy and described second strategy that sets in advance.
CN200910081050.6A 2009-03-31 2009-03-31 Method for setting security level of mobile terminal on basis of position information and mobile terminal Active CN101854581B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN200910081050.6A CN101854581B (en) 2009-03-31 2009-03-31 Method for setting security level of mobile terminal on basis of position information and mobile terminal

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN200910081050.6A CN101854581B (en) 2009-03-31 2009-03-31 Method for setting security level of mobile terminal on basis of position information and mobile terminal

Publications (2)

Publication Number Publication Date
CN101854581A true CN101854581A (en) 2010-10-06
CN101854581B CN101854581B (en) 2013-10-02

Family

ID=42805793

Family Applications (1)

Application Number Title Priority Date Filing Date
CN200910081050.6A Active CN101854581B (en) 2009-03-31 2009-03-31 Method for setting security level of mobile terminal on basis of position information and mobile terminal

Country Status (1)

Country Link
CN (1) CN101854581B (en)

Cited By (30)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102497637A (en) * 2011-12-14 2012-06-13 北京博大光通国际半导体技术有限公司 Security information protection secret-related equipment processing system and method based on WSN base station control
CN102664895A (en) * 2012-04-28 2012-09-12 珠海报业文化传播有限公司 Partition echoing posting-before-verifying commenting system
CN102823283A (en) * 2011-03-25 2012-12-12 松下电器产业株式会社 Information communication terminal with security control function, communication system, and method of communication performed by said terminal
JP2013003604A (en) * 2011-06-10 2013-01-07 Sharp Corp Information terminal, method for controlling information terminal, control program, and recording medium
JP2013003602A (en) * 2011-06-10 2013-01-07 Sharp Corp Information terminal, method for controlling information terminal, control program, and recording medium
CN103067583A (en) * 2012-12-26 2013-04-24 鸿富锦精密工业(深圳)有限公司 Portable wireless communication device
CN103327447A (en) * 2013-05-23 2013-09-25 福建鑫诺通讯技术有限公司 Position binding method for wireless terminal
CN103491539A (en) * 2013-08-27 2014-01-01 展讯通信(上海)有限公司 Method and device for controlling access right of mobile equipment
CN103874064A (en) * 2012-12-17 2014-06-18 联想(北京)有限公司 Position information protecting method and electronic equipment
CN103891317A (en) * 2011-10-17 2014-06-25 诺基亚公司 An automatic approach for the personalized privacy recommendation related to the location
CN104239780A (en) * 2013-06-24 2014-12-24 株式会社OPTiM User terminal, security set selection method, and user terminal program
CN104850803A (en) * 2015-05-25 2015-08-19 小米科技有限责任公司 Terminal control method and apparatus
CN104932874A (en) * 2014-03-19 2015-09-23 华为技术有限公司 Terminal and control method thereof
CN104954314A (en) * 2014-03-24 2015-09-30 阿里巴巴集团控股有限公司 Safety prompting method and safety prompting device
CN105046131A (en) * 2015-07-20 2015-11-11 努比亚技术有限公司 Fingerprint identification apparatus and method
CN105164970A (en) * 2013-05-30 2015-12-16 英特尔公司 Adaptive authentication systems and methods
CN105431857A (en) * 2013-05-29 2016-03-23 慧与发展有限责任合伙企业 Passive security of applications
WO2016173357A1 (en) * 2015-04-27 2016-11-03 华为技术有限公司 Method and device for implementing multimedia conference
WO2016184136A1 (en) * 2015-05-15 2016-11-24 中兴通讯股份有限公司 Method and device for guaranteeing terminal security
CN103856447B (en) * 2012-11-30 2017-04-05 富士通株式会社 Integral unit performs device, generating means and correlation method and corresponding mobile terminal
CN106911997A (en) * 2015-12-22 2017-06-30 中电科技(北京)有限公司 A kind of geo-fencing system and its implementation based on UEFI firmwares
CN106961677A (en) * 2016-01-11 2017-07-18 中国移动通信集团公司 A kind of management method and server, terminal
CN107391977A (en) * 2017-07-04 2017-11-24 阿里巴巴集团控股有限公司 Control, automatic switching method, device and the equipment of authority
WO2018032343A1 (en) * 2016-08-16 2018-02-22 陈银芳 Method and system for implementing app hiding at different places
CN109327835A (en) * 2018-09-18 2019-02-12 上海华章信息科技有限公司 A method of identity is automatically switched based on wireless device around
CN110503800A (en) * 2019-08-27 2019-11-26 安徽华米信息科技有限公司 A kind of anti-loss method, the device of intelligence wearable device
CN110650467A (en) * 2018-06-26 2020-01-03 华为技术有限公司 Method and device for managing user data
CN111194030A (en) * 2019-04-18 2020-05-22 深圳金澜汉源科技有限公司 Terminal position information confidentiality method, operating system and mobile terminal
CN112083851A (en) * 2020-08-06 2020-12-15 曙光信息产业(北京)有限公司 Interface positioning method and device for BIOS (basic input output System) configuration options, server and computer readable storage medium
CN116362942A (en) * 2023-03-27 2023-06-30 深圳中新智城科技有限公司 Intelligent park information safety management system based on big data

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1756304A (en) * 2004-09-27 2006-04-05 乐金电子(昆山)电脑有限公司 Automatic secrecy setting device and method for portable information apparatus
CN101094225B (en) * 2006-11-24 2011-05-11 中兴通讯股份有限公司 Network, system and method of differentiated security service
CN101247581B (en) * 2007-02-15 2011-12-07 联想(北京)有限公司 Method and system for controlling mobile terminal state

Cited By (42)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102823283B (en) * 2011-03-25 2016-08-31 松下电器(美国)知识产权公司 Possess the information communication terminal of safety control function, communication system and the communication means performed by this terminal
CN102823283A (en) * 2011-03-25 2012-12-12 松下电器产业株式会社 Information communication terminal with security control function, communication system, and method of communication performed by said terminal
JP2013003602A (en) * 2011-06-10 2013-01-07 Sharp Corp Information terminal, method for controlling information terminal, control program, and recording medium
JP2013003604A (en) * 2011-06-10 2013-01-07 Sharp Corp Information terminal, method for controlling information terminal, control program, and recording medium
CN103891317A (en) * 2011-10-17 2014-06-25 诺基亚公司 An automatic approach for the personalized privacy recommendation related to the location
CN103891317B (en) * 2011-10-17 2017-11-28 诺基亚技术有限公司 The automated process recommended for the personalized privacy related to position
CN102497637A (en) * 2011-12-14 2012-06-13 北京博大光通国际半导体技术有限公司 Security information protection secret-related equipment processing system and method based on WSN base station control
CN102497637B (en) * 2011-12-14 2015-09-02 北京博大光通国际半导体技术有限公司 Security information protection secret-related equipment processing system and method based on WSN base station control
CN102664895B (en) * 2012-04-28 2015-03-11 珠海报业文化传播有限公司 Partition echoing posting-before-verifying commenting system
CN102664895A (en) * 2012-04-28 2012-09-12 珠海报业文化传播有限公司 Partition echoing posting-before-verifying commenting system
CN103856447B (en) * 2012-11-30 2017-04-05 富士通株式会社 Integral unit performs device, generating means and correlation method and corresponding mobile terminal
CN103874064A (en) * 2012-12-17 2014-06-18 联想(北京)有限公司 Position information protecting method and electronic equipment
CN103067583A (en) * 2012-12-26 2013-04-24 鸿富锦精密工业(深圳)有限公司 Portable wireless communication device
CN103327447A (en) * 2013-05-23 2013-09-25 福建鑫诺通讯技术有限公司 Position binding method for wireless terminal
CN105431857A (en) * 2013-05-29 2016-03-23 慧与发展有限责任合伙企业 Passive security of applications
US10666635B2 (en) 2013-05-30 2020-05-26 Intel Corporation Adaptive authentication systems and methods
CN105164970B (en) * 2013-05-30 2019-12-17 英特尔公司 adaptive authentication system and method
CN105164970A (en) * 2013-05-30 2015-12-16 英特尔公司 Adaptive authentication systems and methods
CN110096855B (en) * 2013-05-30 2023-08-15 英特尔公司 Adaptive authentication system and method
CN110096855A (en) * 2013-05-30 2019-08-06 英特尔公司 Adaptive Verification System and method
CN104239780A (en) * 2013-06-24 2014-12-24 株式会社OPTiM User terminal, security set selection method, and user terminal program
CN103491539A (en) * 2013-08-27 2014-01-01 展讯通信(上海)有限公司 Method and device for controlling access right of mobile equipment
CN104932874A (en) * 2014-03-19 2015-09-23 华为技术有限公司 Terminal and control method thereof
CN104954314B (en) * 2014-03-24 2019-06-28 阿里巴巴集团控股有限公司 Security prompt method and device
CN104954314A (en) * 2014-03-24 2015-09-30 阿里巴巴集团控股有限公司 Safety prompting method and safety prompting device
WO2016173357A1 (en) * 2015-04-27 2016-11-03 华为技术有限公司 Method and device for implementing multimedia conference
CN106295344A (en) * 2015-05-15 2017-01-04 中兴通讯股份有限公司 A kind of method and apparatus ensureing terminal security
WO2016184136A1 (en) * 2015-05-15 2016-11-24 中兴通讯股份有限公司 Method and device for guaranteeing terminal security
CN104850803A (en) * 2015-05-25 2015-08-19 小米科技有限责任公司 Terminal control method and apparatus
CN105046131A (en) * 2015-07-20 2015-11-11 努比亚技术有限公司 Fingerprint identification apparatus and method
CN106911997A (en) * 2015-12-22 2017-06-30 中电科技(北京)有限公司 A kind of geo-fencing system and its implementation based on UEFI firmwares
CN106911997B (en) * 2015-12-22 2021-05-28 中电科技(北京)有限公司 Geographic fence system based on UEFI firmware and implementation method thereof
CN106961677A (en) * 2016-01-11 2017-07-18 中国移动通信集团公司 A kind of management method and server, terminal
WO2018032343A1 (en) * 2016-08-16 2018-02-22 陈银芳 Method and system for implementing app hiding at different places
CN107391977A (en) * 2017-07-04 2017-11-24 阿里巴巴集团控股有限公司 Control, automatic switching method, device and the equipment of authority
CN110650467A (en) * 2018-06-26 2020-01-03 华为技术有限公司 Method and device for managing user data
CN110650467B (en) * 2018-06-26 2022-03-29 华为技术有限公司 Method and device for managing user data
CN109327835A (en) * 2018-09-18 2019-02-12 上海华章信息科技有限公司 A method of identity is automatically switched based on wireless device around
CN111194030A (en) * 2019-04-18 2020-05-22 深圳金澜汉源科技有限公司 Terminal position information confidentiality method, operating system and mobile terminal
CN110503800A (en) * 2019-08-27 2019-11-26 安徽华米信息科技有限公司 A kind of anti-loss method, the device of intelligence wearable device
CN112083851A (en) * 2020-08-06 2020-12-15 曙光信息产业(北京)有限公司 Interface positioning method and device for BIOS (basic input output System) configuration options, server and computer readable storage medium
CN116362942A (en) * 2023-03-27 2023-06-30 深圳中新智城科技有限公司 Intelligent park information safety management system based on big data

Also Published As

Publication number Publication date
CN101854581B (en) 2013-10-02

Similar Documents

Publication Publication Date Title
CN101854581B (en) Method for setting security level of mobile terminal on basis of position information and mobile terminal
US8429410B2 (en) System and method of installing software applications on electronic devices
US9542571B2 (en) System and method of owner application control of electronic devices
US8695058B2 (en) Selective management of mobile device data in an enterprise environment
CN101400060B (en) A method and devices for providing secure data backup from a mobile communication device to an external computing device
EP2619702B1 (en) Method for establishing a plurality of modes of operation on a mobile device
US8296580B2 (en) System and method for protecting data on a mobile device
CA2509358C (en) System and method of owner control of electronic devices
EP1821555A1 (en) Method and system for sharing memory area of mobile terminal
EP2343852B1 (en) Key distribution method and system
EP1653386A2 (en) Information processing apparatus and operation control method
CA2800504C (en) Designation of classes for certificates and keys
CN103813314A (en) Soft SIM card enabling method and network access method, terminal, and network access device
CN102171674B (en) Method and apparatus for access to a computer unit
CA2799903C (en) Certificate management method based on connectivity and policy
CN104737566A (en) Method for incorporating subscriber identity data into a subscriber identity module
CN101459902A (en) Credible service manager system and method for mobile payment
CN103988530A (en) Enhanced lifecycle management of security module
CN104969176A (en) Managing application access to certificates and keys
CN102480724A (en) Software authentication data card, software authentication system and software authentication method
CN104732166A (en) Data storing and reading method and device and equipment
CN112528248A (en) User authority management scheme facing multiple applications
CN106557372B (en) Application sharing method and device and terminal
EP2355438B1 (en) System and method for protecting data on a mobile device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant