WO2015085819A1 - 一种公私隔离的方法及装置 - Google Patents

一种公私隔离的方法及装置 Download PDF

Info

Publication number
WO2015085819A1
WO2015085819A1 PCT/CN2014/087815 CN2014087815W WO2015085819A1 WO 2015085819 A1 WO2015085819 A1 WO 2015085819A1 CN 2014087815 W CN2014087815 W CN 2014087815W WO 2015085819 A1 WO2015085819 A1 WO 2015085819A1
Authority
WO
WIPO (PCT)
Prior art keywords
event
short message
call
record
database
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2014/087815
Other languages
English (en)
French (fr)
Inventor
王力
王鹏程
李旋
苏云琳
刘伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from CN201310666504.2A external-priority patent/CN103685266B/zh
Priority claimed from CN201310713538.2A external-priority patent/CN103647784B/zh
Application filed by Beijing Qihoo Technology Co Ltd, Qizhi Software Beijing Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Priority to US15/103,531 priority Critical patent/US20160316330A1/en
Publication of WO2015085819A1 publication Critical patent/WO2015085819A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/02Services making use of location information
    • H04W4/021Services related to particular areas, e.g. point of interest [POI] services, venue services or geofences
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/104Grouping of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2143Clearing memory, e.g. to prevent the data from being stolen
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/12Messaging; Mailboxes; Announcements
    • H04W4/14Short messaging services, e.g. short message services [SMS] or unstructured supplementary service data [USSD]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/16Communication-related supplementary services, e.g. call-transfer or call-hold

Definitions

  • the present application relates to the field of network security technologies, and in particular, to a method and apparatus for public and private isolation.
  • BYOD Bit Your Own Device
  • WI-free Wi-Fi
  • the same mobile terminal device has both personal application and enterprise application data, and the personal application can access and access the enterprise data at will, so that there is a risk that the enterprise data is illegally uploaded, shared and leaked by the personal application.
  • Mobile devices are easily lost, and corporate sensitive data stored in mobile devices is also exposed to the risk of compromise. Lost devices may also become a springboard for attacking corporate networks.
  • the National Internet Emergency Center more than 160,000 malicious programs were discovered in 2012, a 25-fold increase from 2011. In the first half of 2013, the Android mobile phone virus skyrocketed about 8 times.
  • Root super user rights
  • one technical problem to be solved by the present application is to provide a method and apparatus for public-private isolation, setting a work area on a mobile terminal and completing corresponding operations.
  • a public-private isolation method includes: monitoring a system event of a mobile terminal, determining whether the system event meets a preset work area rule; and when the system event meets the work area rule, in a work space An operation corresponding to the system event is performed, and data corresponding to the operation is encrypted and stored in a database of the workspace space.
  • a public-private device includes: an event monitoring module configured to monitor a system event of the mobile terminal to determine whether the system event meets a preset work area rule; and an execution module configured to: when the system event meets When the workspace rule is described, an operation corresponding to the system event is performed in the workspace space, and data corresponding to the operation is encrypted and stored in a database of the workspace space.
  • the public-private isolation method and device of the present application establishes a safe and independent working area on the mobile terminal
  • Some work data, that is, enterprise applications and data are stored in a protected security zone, so that personal applications cannot access enterprise data, and corporate data is prevented from being illegally accessed by personal applications, not only completely separating enterprise data and personal data, but also making IT
  • the department is able to better protect the company's applications and data, and provides employees with an undifferentiated personal application experience that achieves a dual-use effect.
  • FIG. 1 is a flow chart of one embodiment of a method of public-private isolation in accordance with the present application
  • FIG. 2 is a flow chart of a call and short message processing in an embodiment of a public-private isolation method according to the present application
  • FIG. 3 is a schematic illustration of one embodiment of a public-private isolated device in accordance with the present application.
  • FIG. 4 is a schematic diagram of an embodiment of a public-private isolated device in accordance with the present application interacting with enterprise network information.
  • the method for company isolation of the present application ensures the security of data and applications on the mobile terminal by establishing a strict office area or work area on the mobile terminal through encryption, monitoring, and the like, and corresponding to the work area. There is also a human area in the mobile terminal for storing data irrelevant to the work.
  • the work area and the personal area may be defined as follows: in the process of using the device, in order to conveniently manage the personal data and the work data in the device, a part of the disk storage space may be drawn in the device, and a new configuration may be configured. Permission information, which can be used to store and manage work data. This part of the disk storage space can be called a work area.
  • the remaining part of the disk storage space in the device can be used for storing and managing personal data or other materials, and the remaining part of the disk storage space can have initial permission information, and this part of the disk storage space can be referred to as an individual. Area.
  • the personal area and the work area may have different UIs (User Interfaces) for convenience of operation, but some system files may be used in common.
  • UIs User Interfaces
  • FIG. 1 is a flow chart of an embodiment of a public-private isolation method of the present application, as shown in FIG. 1:
  • Step 101 Monitor system events of the mobile terminal to determine whether the system event meets the preset work area specification then.
  • Step 102 When the system event meets the work area rule, perform an operation corresponding to the system event in the work area space,
  • step 103 the data corresponding to the operation is encrypted and stored in a database of the workspace space.
  • the so-called public-private isolation refers to isolating the user-related data of the user from the private data
  • the mobile terminal can adopt, for example, a game console, a laptop computer, a portable media player, a tablet computer, a tablet computer. , PDAs, mobile computers, and mobile phones, etc.
  • the mobile terminal can input by using an input form such as a sliding input, a gesture input, a touch input, and a voice input.
  • an input form such as a sliding input, a gesture input, a touch input, and a voice input.
  • the database of the workspace space is a database that is independently set with respect to the original database in the mobile terminal or a database of various applications in the mobile terminal, and is used for storing data in the work area.
  • the area space is the logical running space of the resources (memory, memory card, etc.) of the mobile terminal and the user division. Workspace rules can be configured based on contacts, keywords in text messages, and the like.
  • the workspace space encrypted data may be placed in a database of the workspace space or in a storage device of the mobile terminal, and the encrypted data may be data related to the system file, or a financial file, production file, and sales selected by the user.
  • Data in files, market files, human resources files, etc.; encrypted data can also be data of a user's personal files, such as photos, videos, logs, and the like.
  • a user enters a work area to perform work (enterprise) operations, such as editing a schedule, texting, writing an email, downloading a report, or taking a photo, etc., and the same data person as the work operation, such as a schedule.
  • work (enterprise) operations such as editing a schedule, texting, writing an email, downloading a report, or taking a photo, etc.
  • the same data person as the work operation such as a schedule.
  • the data such as arrangement, picture, mail, report, and short message are encrypted and stored in the database of the workspace space, and the operation data not related to the work is stored in the workspace space, such as the public space of the mobile terminal, so that the public, Private data can be isolated, and other applications in the mobile terminal cannot be used even if data is obtained by encrypting the data.
  • a password is required.
  • the mobile terminal When the user views the data stored in the database in the workspace space, a password is required.
  • the mobile terminal When the mobile terminal is lost, the user sets a password for viewing the workspace data (this function can be set by the user according to his or her habits and wishes). If you do not know the user password, you cannot view the workspace data. Alternatively, you can remotely operate the enterprise management server, invoke the workspace application in the mobile terminal, delete the workspace data stored in the mobile terminal, and protect the security of the enterprise data. .
  • the system event may include a call event and a short message event, where the call event includes: an incoming call event and an outgoing call event, wherein the incoming call event includes a received call event and a missed call event; the short message event includes receiving a short message event and Send SMS events.
  • the work area rule for the call event can be configured as the contact of the call event stored in the database of the work space
  • the work area rule for the short message event can be configured as the contact of the short message stored in the database of the work space
  • the contact information includes the caller's or called party's phone number MSISDN (Mobile Subscriber International ISDN/PSTN Number), which is the mobile station identification number. Code), as well as the MSISDN of the recipient or sender of the SMS message in the SMS event.
  • MSISDN Mobile Subscriber International ISDN/PSTN Number
  • FIG. 2 is a flow chart of a call and short message processing in an embodiment of a public-private isolation method according to the present application, as shown in FIG. 2:
  • Step 201 Determine whether the system event is a call event and a short message event.
  • Step 202 Determine whether the contact is stored in a database in the workspace space.
  • Step 203 When the calling party or the called party's telephone number of the call, or the sender's or recipient's telephone number of the short message is stored in the database of the workspace space, the call record or the short message is encrypted, and the call record or The SMS is stored in a database in the workspace space.
  • Step 204 Delete the call record or short message in the call record or short message record of the mobile terminal.
  • the system event is a call event
  • whether the phone number of the calling party or the called party that detects the call event is stored in the database of the workspace space determines whether the work area rule is met, and if so, is stored in the workspace space.
  • the database is in compliance with the workspace rules, otherwise it does not meet the workspace rules. Therefore, the call can be made in the workspace space, for example, in the database of the workspace space, the contact is called, and the call record of the missed call is viewed in the workspace space, and then the data corresponding to the call event is used. Encryption such as incoming or outgoing calls or missed calls, and storing them in a database in the workspace space. And, the record of the call event in the call record of the mobile terminal can be deleted.
  • the call record and the short message record of the mobile terminal refer to a call record and a short message record of the non-work area (ie, the personal area).
  • a short message event similar to a call event, when the sender or recipient's phone number of the SMS event is stored in the database of the workspace space, the work area rule is met, otherwise the work area rule is not met. Then, operations related to the short message event are performed in the workspace space, such as editing and viewing short messages in the workspace space. Then, the short message is encrypted and stored in a database in the workspace space, and the related record information of the short message, such as a transmission record, a reception record, etc., can be encrypted and stored in a database in the workspace space, and the mobile terminal can also be The short message record is deleted in the short message record.
  • a call option interface may also be provided, where the user selects whether the caller record of the mobile terminal is deleted when the calling party MSISDN or the called party MSISDN of the call event is stored in the database of the workspace space, so that the user Ability to set according to your own habits and improve user satisfaction.
  • the system event includes a call event and a short message event, wherein the call event includes a received call event, an outgoing call event, and a missed call event; the short message time includes receiving a short message event and sending a short message event, and is discussed in detail based on the above system event.
  • FIG. 3 is a flowchart of a call and short message processing in another embodiment of the public-private isolation method according to the present application, the method including steps S301 to S312.
  • Step S301 establishing a work area for storing enterprise data in the mobile terminal.
  • the purpose of establishing the working area is to store the data generated in the work, and to realize the isolation and storage of the data in the work area and the data of the personal area (ie, public-private isolation), so as to manage the data in the work area.
  • the data of the work area can be saved in an encrypted manner.
  • the user can set an unlock password for the data of the work area, and the user is allowed to access the data in the work area when the unlock code input by the user is correct.
  • the following methods can be adopted: respectively, creating and recording the user's personal area and the work area Launcher, and prompting the user to input the password before displaying the desktop.
  • Log in If the user password is entered correctly and can be legally registered in the work area, the workspace Launcher is started, and the user is provided with a desktop of the work area, and the user can enter the application in the work area through the desktop; if the user does not log in, the default personal area is selected.
  • the Launcher is launched, and the user enters the application of the personal area through the default Launcher to achieve isolation between the work area and the personal area.
  • the Launcher is the launcher or desktop in the system, and can enter other applications from icons on the desktop.
  • step S302 the system event is monitored, and it is determined whether the system event meets the work area rule.
  • the operation corresponding to the event is performed in the work area. If not, the operation corresponding to the system event is performed in the personal area.
  • the mobile terminal in order to better manage the data of the work area, is provided with an address book to store the information of the contact, wherein the address book can be configured with one or more, to configure two as an example, wherein One is a corporate address book configured for work, and the other is a user's private address book.
  • the address book can store the contact number, email account, instant messaging account and other contact information.
  • the enterprise address book is set in the working area, and the enterprise address book stores contacts related to the work of the user.
  • the contact included in the enterprise address book may be all colleagues of the department where the user is located, and the The user communication theory can also include the user's customer.
  • the enterprise address book can also be synchronized with the server side, that is, the user's corporate address book is periodically updated according to the server, for example, the new corporate address book management personnel are added.
  • the contact is updated to the user's corporate directory. It should be noted that users in the same department often face different work contacts. For example, the administrative department of user A belongs to the administrative department, and the work of the personnel department is relatively close. User B also belongs to the administrative department.
  • the contacts that are often synchronized from the server are usually only the work contacts of the department, and cannot completely cover the work contacts that each colleague faces.
  • the personal contacts imported by the user may also be stored in the enterprise address book, and the contacts may be contacts that are closely related to the user and are not in the department. , customers mentioned in the above example, etc.
  • the setting of personal import contacts enables different users to set contacts in the work area according to their own needs, which is convenient for users to operate, and also ensures the security of enterprise data.
  • the private address book is set in a non-work area and may include contacts related to the user's personal, such as relatives, friends, and the like.
  • the contacts in the workspace can be coincident with the contacts in the user's private address book.
  • contact A is the colleague of the user and is also a friend of the user, then contact People A can be kept in both the corporate directory and the private address book to ensure the security of corporate data.
  • the system events are monitored in the foregoing step S302, and the operations of the steps may be performed according to different system events, including the following steps:
  • System events are monitored to determine if the contact corresponding to the system event is a work contact. When it is a work contact, confirm that it meets the work area rules. At this time, perform corresponding operations in the work area according to the category of the system event, such as editing a short message, viewing a short message, and viewing a missed call. When it is not a work contact, it is confirmed that the preset rule is not met. At this time, the corresponding operation is performed in the non-work area according to the category of the system event.
  • the working contact is a contact in the enterprise address book set by the enterprise or in the address book of the user personally imported into the work area, that is, the information of the contact is stored in the database of the workspace space.
  • the system event is to receive a text message event.
  • step S302 determines that the contact corresponding to the received short message event is a work contact, step S303 is performed, otherwise step S304 is performed.
  • Step S303 intercepting the short message record of the short message entering the mobile terminal, viewing the short message in the workspace area, and encrypting the short message and storing the short message in the database of the work area.
  • Step S304 the short message is stored in the short message record of the mobile terminal.
  • Step S303 intercepts the short message into the inbox of the short message record of the mobile terminal (ie, the location where the short message is stored in the non-work area), and encrypts the short message and stores it in the work area, thereby realizing the separation of public and private data. It avoids the work-related incoming mail being in the user's system inbox and being viewed maliciously, thus ensuring the security of enterprise data.
  • the system event is in the send SMS event.
  • step S302 determines whether the contact corresponding to the short message sending event is a working contact. When it is a work contact, step S305 is performed, and when it is not a work contact, step S306 is performed.
  • Step S305 intercepting the short message record of the short message and the mobile terminal entering the record, editing the short message in the workspace area, encrypting the short message and the sending record thereof, and storing the short message in the database of the workspace space.
  • Step S306 the short message and its transmission record are stored in the short message record of the mobile terminal.
  • Step S305 intercepts the short message box and the short message record box of the mobile terminal that has entered the record, and encrypts the short message and the transmission record thereof into the work area, thereby realizing the separation of public and private data and avoiding work-related
  • the sender is in the user's system outbox and is viewed maliciously, thus ensuring the security of corporate data.
  • the system event is an outgoing event.
  • step S302 determines whether the contact corresponding to the outgoing event is a work contact. When it is a work contact, step S307 is performed, and when it is not a work contact, step S308 is performed.
  • step S307 the outgoing record is encrypted and stored in a database in the workspace space.
  • Step S308 storing the outgoing call record in the call record of the mobile terminal.
  • the method may further include: determining whether the user has set a call record of the work contact displayed in the call record of the operating system.
  • step S207 may delete the call record in the call record of the mobile terminal or intercept the call of the call record into the mobile terminal before storing the call record. Recorded.
  • the call record of the work contact is displayed in the call record of the operating system, the call record is displayed in the call record of the mobile terminal and simultaneously stored in the database of the workspace space.
  • the user can separately set whether the call record of each contact in the work area is displayed in the system call record, or can be uniformly set, that is, set all call records to be displayed in the system call.
  • the record or all call records are not displayed in the system call log.
  • the system event is a received call event.
  • step S302 determines whether the contact corresponding to the answering the phone event is a work contact. When it is a work contact, step S309 is performed, and when it is not a work contact, step S310 is performed.
  • Step S309 the record of the received call event is stored in a database of the workspace space.
  • the operating system is Android.
  • the methods for monitoring system calls or outgoing calls mainly include: TelephonyManager.listen() (listening to the incoming call status).
  • the maintenance (copy and transfer) of the operating system's call record may be as follows: receiving a call event and an incoming call through the PhoneStateReceiver broadcast receiver.
  • Event when an outgoing event or an incoming call event is initiated, the CallLogObserverService service is started to maintain the call record, including the copy and transfer operation of the call record.
  • the PhoneStateReceiver broadcast receiver ensures that when the CallLogObserverService service is started when a call event occurs, it can be implemented by the startService service provided by the operating system.
  • the PhoneStateReceiver broadcast receiver receives events for making and receiving calls by the following code:
  • the CallLogObserverService service can be implemented during the copy of the call record: a listener service ContentObserver is registered during the startup of the CallLogObserverService service, and a change handler is processed; the change of the call record database of the listener service ContentObserver terminology system is monitored.
  • the URI is android.provider.CallLog.Calls.CONTENT-URI).
  • Step S310 storing the call record generated by the received call event in the call record of the mobile terminal.
  • the method may further include: prompting the user whether to store the recorded call record in the mobile terminal A record of incoming call events.
  • the call record generated by the secondary call event is deleted in the call record of the mobile terminal or pre-blocked into the call record of the mobile terminal by step S209.
  • the record of the received call event is stored in the call record of the mobile terminal, and then the record of the received call event is encrypted and stored in the database of the workspace space.
  • the system event is a missed call event.
  • step S302 determines whether the contact corresponding to the missed call event is a work contact. When it is a work contact, step S311 is performed, and when it is not a work contact, step S312 is performed.
  • Step S311 storing the record of the missed call event in the database of the workspace space.
  • Step S312 storing the record of the missed call event in the call record of the mobile terminal.
  • the following may further include the following : Prompt the user whether to store a record of the missed call event in the call record of the mobile terminal.
  • the record of the missed call event is deleted in the call record of the mobile terminal through step S311, or the record of intercepting the incoming call event is entered into the call record of the mobile terminal.
  • the record of the missed call event is stored in the call record of the mobile terminal.
  • the embodiment of the present application establishes a work area for storing enterprise data in a mobile terminal, and saves it in an encrypted manner, and simultaneously monitors system events. When the work area rules are met, an operation corresponding to the event is performed in the work area. It can be seen that the method provided by the embodiment of the present application can avoid leakage of enterprise data caused by attacks by malicious programs. Even if the mobile terminal is lost, because the work area is encrypted, other people cannot read the enterprise data, and the enterprise data is guaranteed. Security and can be obtained without malicious programs.
  • the system event may further include: a mail event, and the work area rule of the mail event may be configured to be stored in the database of the workspace space by the sender of the mail or the email account of the recipient. Therefore, according to an embodiment of the present application, a mail rule option interface may be provided, where the user sets an email account that can only be received in the work area or using the work area application, and stores the email account in the database of the workspace space, so that the work is performed. Mail and private The data of the mail is quarantined.
  • the system event When it is determined that the system event is to receive the mail, and the sender's email account is stored in the database of the workspace space, the system event conforms to the workspace rule, so the edit mail, the mail, the attachment, and the attachment can be executed in the workspace space. Uploading attachments and other operations related to mail events, and encrypting the contents of the mail and the downloaded mail attachments, and storing the encrypted mail contents and attachments of the downloaded mail in a database of the workspace space.
  • the user can store various information of the working contact in the enterprise address book set in the database of the workspace space, including: the mobile phone number MSISDN, the landline number, the email account, and the like. Whether the calling party MSISDN or the called party MSISDN of the call event, or the sender MSISDN or the recipient MSISDN of the short message event, or the sender email account or the recipient email account of the mail event is stored in the corporate address book If yes, the call record, short message, email and other data corresponding to the system event are encrypted and stored in the database of the workspace space.
  • the password can be locked to the work area. After the password input by the user is successfully verified, the user unlocked in the work area can enter the work area to view the call record, SMS, email or email attachment, etc.
  • the call log, SMS, email or email attachment in the database of the workspace space is decrypted for the user to view.
  • the temporary files of the call records, short messages, emails or email attachments generated by the third-party software are deleted.
  • the browser's cache is cleared.
  • the encryption algorithm for encrypting the call record, the short message, the mail, or the mail attachment is the AES256 encryption algorithm.
  • the workspace application is run on the mobile terminal and enters the work area, and the user is provided with a contact option interface, and the user selects a work contact from the contacts of the mobile terminal address book, and selects the work selected by the user.
  • Contacts are stored in a database in the workspace space, making it easy for users to set up work contacts.
  • the work in the mobile terminal can be conveniently performed. Updates to district applications or updates to policies and procedures.
  • the mobile terminal may send the financial file, the production file, the sales file, the market file, the human resource file, and the like to the enterprise management platform, and receive the processing result of the enterprise management platform, and encrypt and store the file.
  • monitoring system events of the mobile terminal and deleting records in the mobile terminal may be set according to different operating systems.
  • the operating system in the mobile terminal is an Android system.
  • the default Launcher of the original personal area of the system will be recorded (the desktop launcher in Android, the desktop UI of the Android system is collectively called Launcher). If it has not been set or is already the application of this workspace, then it has been Some launchers randomly choose a Launcher as a personal area.
  • the work area application installed in the mobile terminal is hardened.
  • the operating system in the mobile terminal is Android, because the applications on the Android are mostly developed by JAVA, and developed by JAVA.
  • the end result of the application compilation is not a binary file, it is easier to get some information through the decompiled file, for example, password, part of the code, and so on.
  • the program can be prevented from being easily reversed, and key information such as a key system is obtained, and the data encryption function is added to the program at the same time, and the safety factor is increased.
  • the third-party software sometimes needs to call a workspace application at runtime, such as a tablet, a mail client, or some other application, etc., because the data file stored in the database of the workspace space has been After the encryption process is saved, the workspace application provides a compiled so file, thereby encrypting and decrypting the contents of the class.dex file through the o file.
  • a workspace application at runtime, such as a tablet, a mail client, or some other application, etc.
  • the third-party application apk initializes the call to the so file, ensuring that the so-li library runs at a later time than the third-party application reads and writes the file, avoiding the occurrence of the class.dex file.
  • the file library provided by the workspace application intercepts all file operations of the third-party application, implements encryption, and implements public-private isolation.
  • the public-private isolated device 42 includes an event monitoring module 422 and an execution module 424.
  • the event monitoring module 422 is configured to monitor system events of the mobile terminal to determine whether the system event meets the preset work area rules.
  • the execution module 424 is configured to: when the system event meets the work area rule, for example, whether the work area rule is a call, a short message, a mailbox, a keyword in a short message, or the like is stored in the work area database.
  • the operation corresponding to the system event is performed in the workspace space, and the data corresponding to the operation is encrypted and stored in the database of the workspace space.
  • the system event includes: a call event and a short message event.
  • the execution module 424 includes a call and SMS execution module 4242, a user option module 4244, and a mail execution module 4246.
  • the call and short message execution module 4242 is configured to store the phone number of the calling party or the called party's phone number, or the sender's phone number of the short message event or the recipient's phone number in the workspace space when determining the call event In the database, the system event complies with the work area rule; and the recording of the call event or the short message encryption of the short message time, storing the record of the call event or the short message of the short message event in the database In the database of the workspace space.
  • the call and short message execution module 4242 is further configured to: in the call record of the mobile terminal, the call event The record of the piece is deleted, or the short message of the short message is deleted in the short message record of the mobile terminal.
  • the call and short message execution module 4242 is further configured to intercept the record of the call event and enter the call record of the mobile terminal, or intercept the short message of the short message event into the short message record of the mobile terminal.
  • the user option module 4244 is configured to provide a call option interface, and the user selects whether to delete the call record of the mobile terminal when the calling party or the called party phone number of the incoming call is stored in the database of the workspace space.
  • the user option module 4244 is further configured to provide a mail rule option interface, and the user sets the email account that can only be received in the work area or the work area application, and stores the email account in the database of the workspace space.
  • the mail execution module 4246 is configured to: when the system event is determined to be a received mail, and the sender's email account is stored in the database of the workspace space, the system event conforms to the work area rule; and, the mail content and the download The email attachment is encrypted, and the content of the email and the attachment of the downloaded email are stored in the database of the workspace space.
  • the executing module 424 is further configured to: after the password input by the user is successfully verified, and the user enters the work area to view the call record, the short message, the mail, or the email attachment, the call event stored in the database in the workspace space is Recording, text message short message, mail event mail or mail event email attachment decryption; when it is judged that the user finishes viewing, the temporary record of the call record, short message, mail or email attachment generated by decryption.
  • the execution module 424 is further configured to: when the user views the data stored in the workspace database by using a browser, and the user exits the browser, the browser cache is cleared.
  • the user option module 4244 is further configured to run the workspace application on the mobile terminal and enter the work area, provide a contact option interface to the user, and receive the work contact selected by the user from the contacts of the mobile terminal address book, and The work contacts selected by the user are stored in a database in the workspace space.
  • the policy and rule receiving module 426 is configured to receive the work area policies and rules sent by the enterprise management platform, and store the work area policies and rules in the database of the work area.
  • workspace rules include: calls, text messages, mailboxes, keywords in text messages are stored in the workspace database, and so on.
  • the work area strategy includes: when the contact of the call or the short message is the set work area contact, the call record, the short message are encrypted and stored, and the record is deleted in the mobile terminal; when the user views the information in the work area, the password check is needed. Right; regularly download and update workspace applications; regular antivirus; set the priority of the workspace application, and so on.
  • FIG. 5 is a schematic diagram of an embodiment of a public-private isolated device in accordance with the present application interacting with enterprise network information.
  • a public-private isolated device 42 is provided in the mobile terminal 4.
  • the public-private isolated device 42 can have various implementations, such as integrated circuits, plug-ins, applications, and the like.
  • the public-private isolated device 42 receives the work area policies and rules sent by the enterprise management platform (server) 52 and stores the work area policies and rules in a database of the work area.
  • the enterprise management platform (server) 52 deployed in the enterprise network administrators can easily implement mobile terminal management, policy management delivery, and enterprise application management, which can reduce management complexity and save IT manpower investment.
  • the report, the official document is delivered, and the like of the mobile terminal 4 can be implemented by the mail, service, and OA server 52 deployed in the internal network.
  • the public-private isolated device 42 communicates with the mail, service, and OA server 54 to perform business operations. For example, sending and receiving text messages, writing emails, or downloading official documents, etc., encrypting files, pictures, emails, text messages, etc., and storing them in a database in the workspace space.
  • the method and device for public and private isolation of the present application can be configured not only in a mobile terminal but also in a personal terminal such as a personal PC or a tablet computer.
  • the public-private isolation method and device of the present application establishes a safe and independent working area on the mobile terminal without affecting the employee's feelings about the use of the personal application, and stores all the work data, that is, the enterprise application and the data.
  • Protected security zone Personal applications can't access corporate data, avoid corporate data being illegally accessed by personal applications, not only completely isolate corporate data and personal data, but also enable IT departments to better protect enterprise applications and data, and provide employees with no difference. Personal application experience, to achieve a dual-use effect.
  • the method and system of the present application of the present invention may be implemented in a number of ways.
  • the methods and systems of the present application can be implemented in software, hardware, firmware, or any combination of software, hardware, and firmware.
  • the above-described sequence for the steps of the method is for illustrative purposes only, and the steps of the method of the present application are not limited to the order specifically described above unless otherwise specifically stated.
  • the present application may also be embodied as a program recorded in a recording medium, the program comprising machine readable instructions for configuring the method of the present application in accordance with the present invention.
  • the present application also covers a recording medium storing a program for executing the method according to the present application of the present invention.
  • the various component embodiments of the present invention may be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof.
  • a microprocessor or digital signal processor may be used in practice to implement some or all of the functionality of some or all of the components of the public-private isolation device in accordance with embodiments of the present invention.
  • the invention can also be implemented as a device or device program (e.g., a computer program and a computer program product) for performing some or all of the methods described herein.
  • a program implementing the invention may be stored on a computer readable medium or may be in the form of one or more signals. Such signals may be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
  • Figure 6 illustrates a device device that can implement public-private isolation in accordance with the present invention.
  • the device conventionally includes a processor 610 and a computer program product or computer readable medium in the form of a memory 620.
  • the memory 620 may be an electronic memory such as a flash memory, an EEPROM (Electrically Erasable Programmable Read Only Memory), an EPROM, a hard disk, or a ROM.
  • Memory 620 has a memory space 630 for program code 631 for performing any of the method steps described above.
  • storage space 630 for program code may include various program code 631 for implementing various steps in the above methods, respectively.
  • the program code can be read from or written to one or more computer program products.
  • the program includes a program code carrier such as a hard disk, a compact disk (CD), a memory card, or a floppy disk.
  • a computer program product is typically a portable or fixed storage unit as described with reference to FIG.
  • the storage unit may have a storage section, a storage space, and the like arranged similarly to the storage 620 in the server of FIG.
  • the program code can be compressed, for example, in an appropriate form.
  • the storage unit includes computer readable code 631', code that can be read by a processor, such as 610, which, when executed by a server, causes the server to perform various steps in the methods described above.
  • "One embodiment," or "an embodiment," or "one or more embodiments" as used herein means that the particular features, structures, or characteristics described in connection with the embodiments are included in at least one embodiment of the invention.
  • phrase "in one embodiment" is not necessarily referring to the same embodiment.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Computing Systems (AREA)
  • Bioethics (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Telephone Function (AREA)
  • Telephonic Communication Services (AREA)

Abstract

一种公私隔离的方法和装置,对移动终端的系统事件进行监测,判断系统事件是否符合预设的工作区规则,当系统事件符合工作区规则时,在工作区空间内执行与系统事件对应的操作,将与操作相对应的数据加密并存储在工作区空间的数据库中。所述公私隔离的方法和装置,在移动终端上建立一个安全、独立的工作区,将所有的工作数据存储在受保护的安全区内,使个人应用无法访问企业数据,避免企业数据被个人应用非法存取,能够使IT部门更好地保护企业的应用和数据,也为员工提供了无差别的个人应用体验,达到一机两用的效果。

Description

一种公私隔离的方法及装置 技术领域
本申请涉及网络安全技术领域,尤其涉及一种公私隔离的方法及装置。
背景技术
随着智能终端的成熟与普及,以手机、平板为代表的个人智能终端设备逐渐进入企业领域。据国际权威咨询公司预测,到2014年90%的企业将会支持员工在个人移动终端上运行企业办公应用程序,员工使用个人智能终端设备办公已经成为一种无法逆转的潮流。这类被称为BYOD(Bring Your Own Device,自带设备办公)的现象为企业安全和管理带来了新的挑战。企业员工的移动设备可以在任何时间、地点接入移动互联网或公共/家庭Wi-Fi(WIreless-Fidelity,无线保真)网络,移动终端中的企业数据也会暴露在来自互联网的攻击之下,BYOD打破了原有企业网络边界,正是这种边界的模糊性使BYOD成为企业信息安全体系的薄弱环节,需要新的方法保护企业数据的安全。
同一移动终端设备上既有个人应用,又有企业应用个数据,个人应用可以随意访问、存取企业数据,从而存在企业数据被个人应用非法上传、共享和外泄的风险。如存储在手机中的办公邮件、文件、图片、通信记录以及与业务内容有关的短信等,这些敏感信息的泄露会给企业带来极大的信息安全风险。移动设备容易丢失,移动设备中所保存的企业敏感数据也因此面临泄密风险,丢失的设备也可能会成为攻击企业网络的跳板。根据国家互联网应急中心统计,2012年新发现的恶意程序超过16万,较2011年增长25倍。2013年上半年安卓手机病毒暴涨了8倍左右。同时,由于Root(超级用户权限)权限滥用和新的黑客攻击技术,移动终端很容易成为黑客入侵渗透企业内网的跳板。
发明内容
有鉴于此,本申请要解决的一个技术问题是提供一种公私隔离的方法及装置,在移动终端上设置工作区并完成相应的操作。
一种公私隔离的方法,包括:对移动终端的系统事件进行监测,判断所述系统事件是否符合预设的工作区规则;当所述系统事件符合所述工作区规则时,在工作区空间内执行与所述系统事件对应的操作,将与所述操作相对应的数据加密并存储在所述工作区空间的数据库中。
一种公私隔离的装置,包括:事件监控模块,配置为对移动终端的系统事件进行监测,判断所述系统事件是否符合预设的工作区规则;执行模块,配置为当所述系统事件符合所述工作区规则时,在工作区空间内执行与所述系统事件对应的操作,将与所述操作相对应的数据加密并存储在所述工作区空间的数据库中。
本申请的公私隔离的方法和装置,在移动终端上建立一个安全、独立的工作区,将所 有的工作数据,即企业应用和数据存储在受保护的安全区内,使个人应用无法访问企业数据,避免企业数据被个人应用非法存取,不仅仅将企业数据和个人数据完全隔离,使IT部门能够更好地保护企业的应用和数据,也为员工提供了无差别的个人应用体验,达到一机两用的效果。
附图说明
为了更清楚地说明本申请实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作一简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
图1为根据本申请的公私隔离的方法的一个实施例的流程图;
图2为根据本申请的公私隔离的方法的一个实施例中对通话、短信处理的流程图;
图3为根据本申请的公私隔离的装置的一个实施例的示意图;
图4为根据本申请的公私隔离的装置的一个实施例与企业网信息交互的示意图。
具体实施方式
下面参照附图对本申请进行更全面的描述,其中说明本申请的示例性实施例。下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请的公司隔离的方法,通过在移动终端上建立一个严格的办公区域或工作区,通过加密、监测等多种手段,保证工作中的数据和应用在移动终端上的安全,与工作区对应,移动终端中还存在一个人区,用以存储于工作无关的数据。
其中,在本申请实施例中,工作区和个人区可以定义如下:在设备使用过程中,为了方便管理设备中的个人资料和工作资料,可以在设备中划出一部分磁盘存储空间,配置新的权限信息,可以用于存储和管理工作资料,可以将这部分磁盘存储空间称为工作区。而该设备中剩余的另一部分磁盘存储空间,可以用于存储、管理个人资料或者其他资料,所述剩余的另一部分磁盘存储空间可以拥有初始的权限信息,可以将这部分磁盘存储空间称为个人区。
此外,为方便操作,个人区和工作区可以具有不同的UI(User Interface,用户界面),但是可以共同使用某些系统文件。
实施例一
图1为本申请的公私隔离的方法的一个实施例的流程图,如图1所示:
步骤101,对移动终端的系统事件进行监测,判断系统事件是否符合预设的工作区规 则。
步骤102,当系统事件符合工作区规则时,在工作区空间内执行与系统事件对应的操作,
步骤103,将与操作相对应的数据加密并存储在工作区空间的数据库中。
本实施例中,所谓公私隔离指的是将用户的办公相关的数据和私人数据相隔离,其中,移动终端可采用如游戏控制台,膝上型计算机,便携式媒体播放器,板式计算机,平板计算机,PDA,移动计算机,以及移动电话等等。
其中,移动终端可以采用滑动输入,手势输入,触摸输入,以及语音输入等输入形式进行输入。
本实施例中,工作区空间的数据库是相对于移动终端中原有的数据库、或相对于移动终端中各种应用的数据库独立设置的数据库,为工作区存储数据使用。区空间是移动终端的资源(内存和存储卡等)和用户划分的逻辑运行空间。工作区规则可以是依据联系人、短信中的关键字等进行配置。
可以在工作区空间的数据库中,或者在移动终端的存储装置中放置工作区空间加密的数据,加密的数据可以是涉及系统文件内的数据,或者是用户选定的财务文件、生产文件、销售文件、市场文件、人力资源文件等内的数据;加密的数据还可以是用户个人文件的数据,例如:照片、视频、日志等等。
根据本申请的一个实施例,用户进入工作区进行有关工作(企业)操作,例如编辑日程安排、发短信、写邮件、下载报表或拍照等等,可以将与工作操作相同的数据人,如日程安排、图片、邮件、报表、短信等数据进行加密,并存储在工作区空间的数据库中,而与工作无关的操作数据存储在给工作区空间内,如移动终端的公共空间等,使得公、私的数据得以隔离,通过对数据加密使得移动终端内的其它应用即使获取数据也无法使用。
当用户查看存储在工作区空间的数据库中的数据时,需要输入密码,当移动终端丢失时,由于用户设置了查看工作区数据的用户密码(此功能可以由用户根据自身的习惯、意愿进行设置),如不知道用户密码则无法查看工作区数据,或者,可以通过企业管理管理服务器远程操作,调用移动终端中的工作区应用,删除移动终端中存储的工作区数据,能够保护企业数据的安全。
实施例二
本申请实施例中,系统事件可以包括通话事件和短信事件,其中,通话事件包括:来电事件、去电事件,其中来电事件包括已接来电事件和未接来电事件;短信事件包括接收短信事件和发送短信事件。因此,对于通话事件的工作区规则可以配置为通话事件的联系人存储于工作区空间的数据库中,对于短信事件的工作区规则可以配置为短信的联系人存储于工作区空间的数据库中,其中,联系人的信息包括通话事件中主叫方或被叫方的电话号码MSISDN(Mobile Subscriber International ISDN/PSTN Number,即移动台识别号 码),以及短信事件中短信的收件人或发件人的MSISDN。
在检测到上述几种事件后可以依据具体的系统事件执行相应的操作,下面举例论述具体的公私隔离方法。
图2为根据本申请的公私隔离的方法的一个实施例中对通话、短信处理的流程图,如图2所示:
步骤201,判断系统事件是否为通话事件和短信事件。
步骤202,判断联系人是否存储在工作区空间的数据库中。
步骤203,当通话的主叫方或被叫方电话号码、或短信的发件人或收件人的电话号码存储在工作区空间的数据库中,对通话记录或短信加密,将此通话记录或短信存储在工作区空间的数据库中。
步骤204,在移动终端的通话记录或短消息记录中将此通话记录或短消息删除。
因此当系统事件为通话事件时,可以依据检测该通话事件的主叫方或被叫方的电话号码是否存储于工作区空间的数据库中确定是否符合工作区规则,如是,即存储于工作区空间的数据库中则符合工作区规则,否则不符合工作区规则。从而在可以在工作区空间进行该通话,例如在工作区空间的数据库中查找联系人拔打电话,又如在工作区空间内查看未接来电的通话记录等,然后将该通话事件对应的数据如来电或去电或未接来电的记录等进行加密,并将其存储到工作区空间的数据库中。并且,可以将移动终端的通话记录中该通话事件的记录删除。本申请实施例中,移动终端的通话记录和短消息记录指的是非工作区(即个人区)的通话记录和短消息记录。
对于短信事件,与通话事件类似,当短信事件的发件人或收件人的电话号码存储于工作区空间的数据库中则符合工作区规则,否则不符合工作区规则。则在工作区空间内执行与该短信事件相关的操作,如在工作区空间内编辑、查看短信等。然后将该短信进行加密并存储在工作区空间的数据库中,并且该短信的相关记录信息如发送记录、接收记录等均可加密后存储在工作区空间的数据库中,并且,还可以将移动终端的短消息记录中将该短信删除。
本申请实施例中,还可以提供通话选项界面,由用户选择当通话事件的主叫方MSISDN或被叫方MSISDN存储在工作区空间的数据库中时,是否删除移动终端的通话记录,这样,用户能够根据自己的习惯进行设置,提高用户使用的满意度。
通过上述的步骤,能够使工作的通话、邮件与私人的通话和邮件进行隔离,从而保证工作信息的安全。
本申请实施例中,系统事件包括通话事件和短信事件,其中通话事件包括已接来电事件、去电事件和未接来电事件;短信时间包括接收短信事件和发送短信事件,基于上述系统事件详细论述公私隔离的一种可选方法。
图3为根据本申请的公私隔离的方法的另一个实施例中对通话、短信处理的流程图,该方法包括步骤S301至S312。
步骤S301,在移动终端中建立一个用于存储企业数据的工作区。
其中,建立该工作区的目的在于存储工作中所产生的数据,实现将工作区中的数据与个人区的数据进行隔离存储(即公私隔离),以便对工作区中的数据进行管理。为了保证工作区数据的安全,工作区的数据可以采用加密的方式进行保存,用户可以为工作区的数据设置解锁密码,当用户输入的解锁码正确时,才允许用户访问工作区中的数据。
以在安卓系统中为例,在对工作区的数据设置解锁密码并隔离保存时,可以采取如下方式:分别创建并记录用户的个人区和工作区的Launcher,在显示桌面前,提示用户输入密码进行登录。若用户密码输入正确可以合法登入工作区,则启动工作区Launcher,给用户提供工作区的桌面,用户可以通过该桌面进入工作区中的应用;若用户未进行登录,则从选择默认的个人区Launcher启动,用户通过该默认的Launcher进入个人区的应用,以达到工作区和个人区的隔离。其中,Launcher为卓系统中的启动器或者桌面,可以从桌面上的图标进入其他应用。
步骤S302,对系统事件进行监听,并判断该系统事件是否符合工作区规则。
其中,若符合,在工作区内执行与该事件对应的操作。若不符合,则在个人区执行与系统事件对应的操作。
本实施例中,为了能够更好地对工作区的数据进行管理,移动终端中设置有通讯录来存储联系人的信息,其中通讯录可以配置一个或多个,以配置两个为例,其中,一个为配置为工作的企业通讯录,另一个为用户的私人通讯录,通讯录中可以保存有联系人的电话号码,邮箱账号,即时通讯账号等联系方式。
其中,企业通讯录设置在上述工作区内,企业通讯录中存储有与该用户工作相关的联系人,例如,企业通讯录中包括的联系人可以是该用户所处部门的全部同事,并且该企业通讯论中也可以包括该用户的客户等。另外,为了方便对企业通讯录进行管理和更新,该企业通讯录还可以与服务器端同步,即用户的企业通讯录则会定时根据服务器来进行同步更新,例如,将企业通讯录管理人员新加入的联系人更新至用户的企业通讯录中。需要说明的是,处于相同部门的用户,其所面对的工作联系人往往是不同的,例如,用户A所属行政部,其与人事部的工作来往较为密切,用户B也所属行政部,而其与国际部的工作来往较为密切,而往往从服务器同步的联系人通常仅是该部门所共同的工作联系人,而不能完全涵盖每个同事所面对的工作联系人。本实施例为了满足不同用户的需求,在工作区中,还可以在上述企业通讯录中存储用户个人导入的联系人,这些联系人可以为与该用户工作关系密切而又非本部门的联系人,如上例所提到的客户等。个人导入联系人的设置能够使得不同的用户根据其自身的需求来设定工作区的联系人,方便用户操作,同时也保证了企业数据的安全。
与上述描述的工作区通讯录不同的是,私人通讯录设置在非工作区,可以包括与用户个人相关的联系人,例如,亲人、朋友等。但是,工作区的联系人可以与用户私人通讯录中的联系人可以重合,例如,联系人A即为该用户的同事,也是该用户的朋友,则联系 人A可以同时被保存在企业通讯录和私人通讯录中,以保证企业数据的安全。
由于本实施例中存在多种不同的系统事件,因此上述步骤S302中对系统事件进行监听,依据不同的系统事件可以执行步骤的操作,具体包括如下步骤:
对系统事件进行监测,判断与系统事件对应的联系人是否为工作联系人。当为工作联系人时,确认符合工作区规则,此时,根据系统事件的类别在工作区执行相应的操作,例如编辑短信、查看短信、查看未接来电等。当不为工作联系人时,确认不符合预设规则符合,此时,根据系统事件的类别在非工作区内执行相应的操作。
其中,工作联系人为处于上述企业设定的企业通讯录中或处于上述用户个人导入到工作区的通讯录中的联系人,即该联系人的信息存储于工作区空间的数据库中。
下面分别介绍上述五种系统事件发生时,本方法的具体执行过程。
第一种情况,系统事件为接收短信事件。
当系统事件为接收短信事件时,步骤S302判断与接收短信事件对应的联系人是工作联系人时,执行步骤S303,否则执行步骤S304。
步骤S303,拦截该短信进入移动终端的短消息记录,在工作区空间查看该短信,并将该短信加密后存储到工作区的数据库中。
步骤S304,将该短信存入移动终端的短消息记录。
步骤S303拦截该短信进入移动终端的短消息记录的收件箱中(即非工作区中存储短信的位置),并将该短信加密后存储到工作区中的操作,实现了公私数据的分离,避免了与工作相关的来信处于用户的系统收件箱中而被恶意查看,从而保证了企业数据的安全。
第二种情况,系统事件为发送短信事件中。
当系统事件为发送短信事件时,步骤S302判断与发送短信事件对应的联系人是否为工作联系人。当是工作联系人时,执行步骤S305,当不是工作联系人时,则执行步骤S306。
步骤S305,拦截该短信及其发送记录进入的移动终端的短消息记录,在工作区空间编辑该短信,并将该短信以及其发送记录加密后存储到工作区空间的数据库中。
步骤S306,将该短信及其发送记录存储到移动终端的短消息记录中。
步骤S305拦截该短信及其发送记录进入的移动终端的短消息记录箱,并将该短信及其发送记录加密后存储到工作区中的操作,实现了公私数据的分离,避免了与工作相关的发信处于用户的系统发件箱中而被恶意查看,从而保证了企业数据的安全。
第三种情况,系统事件为去电事件。
当系统事件为去电事件时,步骤S302判断与去电事件对应的联系人是否为工作联系人。当是工作联系人时,执行步骤S307,当不是工作联系人,则执行步骤S308。
步骤S307,将去电记录加密后存储在在工作区空间的数据库中。
步骤S308,在移动终端的通话记录中存储该去电记录。
需要说明的是,为了使得用户方便查看拔打记录,在步骤S307存储去电记录之前, 还可以包括如下操作:判断用户是否已设置在操作系统的通话记录中显示工作联系人的通话记录。当未设置在操作系统的通话记录中显示工作联系人的通话记录时,步骤S207存储去电记录之前可以将移动终端的通话记录中该去电记录删除或者拦截该去电记录进入移动终端的通话记录中。当设置在操作系统的通话记录中显示工作联系人的通话记录时,则将该拔打记录显示在移动终端的通话记录中,并同时在工作区空间的数据库中存储。并且,本实施例中,根据不同的需求,用户可以分别设置工作区中每个联系人的通话记录是否显示在系统通话记录中,也可以进行统一设置,即设置成全部通话记录显示在系统通话记录中或者全部通话记录不显示在系统通话记录中。
第四种情况,系统事件为已接来电事件。
当系统事件为已接来电事件时,步骤S302判断与接听电话事件对应的联系人是否为工作联系人。当是工作联系人时,执行步骤S309,当不是工作联系人,则执行步骤S310。
步骤S309,将该已接来电事件的记录存储在所述工作区空间的数据库中。
其中,对于系统事件的监听以及通讯记录或短消息记录中记录的删除,移动终端中不同的操作系统具有不同的方式,可以依据不同的操作系统类型确定操作方式。
例如,操作系统为安卓,首先,注册去电广播监听、由OutCallReceiver获取拔出号码,判断是否为存储在工作区空间的数据库中的联系人,如果是,则在移动终端的来电记录中删除此通话记录。监听系统来电或去电的方法主要包括:TelephonyManager.listen()(监听来电状态)。
又如,在安卓系统中对于当系统事件为去电事件或来电事件时,对操作系统的通话记录的维护(拷贝和转移),可采用如下方式:通过PhoneStateReceiver广播接收器接收去电事件和来电事件,当去电事件或来电事件时,启动CallLogObserverService服务对通话记录进行维护,包括通话记录的拷贝和转移操作。其中,PhoneStateReceiver广播接收器,保证在出现通话事件时启动CallLogObserverService服务时,并可通过操作系统提供的startService服务实现。PhoneStateReceiver广播接收器接收对于拔打电话和接听电话的事件可通过如下代码实现:
Figure PCTCN2014087815-appb-000001
具体地,在启动CallLogObserverService服务之前,还需要获取对于操作系统通讯录的读写权限,可采用如下方式:在androidmanifest.xml中声明用到的权限:
<uses-permission android:name=″android.permission.READ-PHONE-STATE″/>
其中,在进行通话记录的拷贝时可通过CallLogObserverService服务实现:在CallLogObserverService服务启动的过程中注册了一个监听服务ContentObserver,以及处理变化的Handler;监听服务ContentObserver用语监听系统的通话记录数据库的变化 (其URI为android.provider.CallLog.Calls.CONTENT-URI),当有通话记录的变动时,调用该Handler的onChange方法,更新工作区的通话记录数据库。
步骤S310,将该已接来电事件产生的通话记录存储在移动终端的通话记录中。
其中,当来电事件的工作联系人同时也是私人通讯路中的联系人时,在步骤S309存储该来电事件的记录之前,还可以包括如下操作:提示用户是否在移动终端的通话记录中存储该已接来电事件的记录。当用户选择否时,通过步骤S209将该次已接来电事件产生的通话记录在移动终端的通话记录中删除或预先拦截其进入移动终端的通话记录中。当用户选择是时,则将该次已接来电事件的记录存储在移动终端的通话记录中,然后对该已接来电事件的记录加密后存储在工作区空间的数据库中。上述提示用户操作能够根据用户的不同需求来实现保存或者删除通话记录,保证了工作区数据安全性的同时也便于用户操作。
第五种情况,系统事件为未接来电事件。
当系统事件为未接来电事件时,步骤S302判断与未接来电事件对应的联系人是否为工作联系人。当是工作联系人时,执行步骤S311,当不是工作联系人,则执行步骤S312。
步骤S311,将该未接来电事件的记录存储到所述工作区空间的数据库中。
步骤S312,将该未接来电事件的记录存储在移动终端的通话记录中。
需要说明的是,当未接来电事件的MSISDN(即工作联系人的MSISDN)与私人通讯录中的联系人的MSISDN重合时,在步骤S311存储该未接来电事件的记录之前,还可以包括如下:提示用户是否在移动终端的通话记录中存储该未接来电事件的记录。当用户选择否时,通过步骤S311将该条未接来电事件的记录在移动终端的通话记录中删除,或拦截该来电事件的记录进入移动终端的通话记录中。当用户选择是时,则将该次未接来电事件的记录存储在移动终端的通话记录中。
需要说明的是,本实施上述所描述的五种系统事件只是示例性的,并不限制本申请实施例所保护的范围,其他移动终端能够支持的系统事件也在本申请实施例所保护的范围之内。
本申请实施例通过在移动终端中建立存储企业数据的工作区,并以加密方式保存,同时对系统事件进行监测,当符合工作区规则时,在工作区内执行与该事件对应的操作。可见,本申请实施例所提供的方法可以避免由于恶意程序的攻击造成的企业数据的泄漏,即使移动终端丢失,由于工作区已加密,其他人也不能读取得到企业数据,保证了企业数据的安全性,并且能不被恶意程序所获取。
实施例三
本申请实施例中,系统事件还可以包括:邮件事件,则该邮件事件的工作区规则可以配置为邮件的发件人或收件人的邮箱账号存储于工作区空间的数据库中。因此,根据本申请的一个实施例,可以提供邮件规则选项界面,由用户设置只能在工作区或使用工作区应用接收的邮箱账号,并将邮箱账号存储在工作区空间的数据库中,使得工作邮件和私人 邮件的数据进行隔离。
当判断系统事件为接收邮件、并且发件人的邮箱账号存储在工作区空间的数据库中时,该系统事件符合工作区规则,因此可以在工作区空间内执行编辑邮件、查看邮件、下载附件、上传附件等与邮件事件相关的操作,并且可以将邮件内容以及下载的邮件附件加密,并将加密后的邮件内容以及下载的邮件的附件存储在工作区空间的数据库中。
本申请实施例中,用户在工作区空间的数据库中设置的企业通信录中可以存储工作联系人的各种信息包括:手机号码MSISDN、座机号码、邮箱账号等。当通话事件的主叫方MSISDN或被叫方MSISDN、或短信事件的发件人MSISDN或收件人MSISDN、或邮件事件的发件人邮箱账号或收件人邮箱账号是否存储于企业通讯录中,如果是则对该系统事件对应的通话记录、短信、邮件等数据加密并存储在工作区空间的数据库中。
由于工作区数据保密性要求较高,因此可以设置密码锁定工作区,当对用户输入的密码验证成功后,工作区解锁用户可进入工作区查看通话记录、短信、邮件或邮件附件等,对存储在工作区空间的数据库中的通话记录、短信、邮件或邮件附件进行解密从而供用户查看。
由于有些邮件的附件需要过第三方软件打开,因此当判断用户结束查看时,删除第三方软件打开的通过解密产生的通话记录、短信、邮件或邮件附件的临时文件。当用户退出浏览器时,将浏览器的缓存清除。
本申请实施例中对工作区数据进行加密时,可以采用多种加密算法,例如,通话记录、短信、邮件或邮件附件进行加密的加密算法为AES256加密算法。
根据本申请的一个实施例,在移动终端上运行工作区应用并进入工作区,对用户提供联系人选项界面,用户从移动终端通讯录的联系人中选取工作联系人,并将用户选取的工作联系人存储在工作区空间的数据库中,可以方便用户设置工作联系人。
接收服务器侧(如企业的企业管理平台)发送的工作区策略和规则,并将工作区策略和规则存储在工作区的数据库中,依据该工作区策略和规则可以方便地进行移动终端中的工作区应用的更新或策略、规程的更新。
根据本申请的一个实施例,移动终端可以将财务文件、生产文件、销售文件、市场文件、人力资源文件等发送到企业管理平台,并接收企业管理平台的处理结果,并加密存储。
根据本申请的一个实施例,对移动终端的系统事件进行监测、将移动终端中的记录删除可以根据不同的操作系统进行设置,例如,移动终端中的操作系统为安卓系统。
先登录工作区应用后会记录系统原来的个人区的默认Launcher(安卓系统中的桌面启动器,安卓系统的桌面UI统称为Launcher),如果没有设置过或者已经是本工作区应用,则从已有的launcher随机选择一个作为个人区的Launcher。
根据本申请的一个实施例,对在移动终端中安装的工作区应用进行加固处理,例如,移动终端中的操作系统为安卓,因为安卓上的应用多为JAVA语言开发,由于用JAVA开发 的应用编译的最终结果不是二进制文件,比较容易通过反编译文件获取一些信息,例如,密码,部分代码等等。
改变工作区应用的class.dex文件的内容,例如改变一些属性名称,并对其内容通过一些算法进行加密。在工作区应用的apk运行时再动态的去解密,还原内容,在修改class.dex的时候要保证其符合dex文件的固有格式。在对工作区应用重新打包的过程中,修改Android程序的全局配置文件AndroidManifest.xml里面的一些配置信息,例如package;application、service、provider的name属性;provider的authorities属性,并且修改.smali文件里面和上面这些属性对应的一些引用。
通过上述的对移动终端中安装的工作区应用进行加固处理,可以防止程序被人轻易逆向,获取密钥体系等关键信息,加固同时给程序增加了数据加密的功能,增加安全系数。
根据本申请的一个实施例,第三方软件在运行时有时需要调用工作区应用,例如写字板、邮件客户端或其他的一些应用等等,由于工作区空间的数据库中存储的数据文件是进过加密处理后保存的,因此工作区应用提供了一个编译好的so文件,从而通过o文件实现对class.dex文件的内容加密、解密等处理。
并且,可以通过在第三方应用中注入代码,使得第三方应用apk初始化时去调用这个so文件,保证so库运行的时机比第三方应用的读写文件的时间早,避免出现class.dex文件变成“一半加密的状态”,导致文件损坏,无法实现公私隔离的功能。在第三方应用运行的过程中,工作区应用提供的so库里面会拦截这个第三方应用的所有文件操作,实现加密,可以实现公私隔离的功能。
图4为根据本申请的公私隔离的装置的一个实施例的示意图,如图4所示,公私隔离的装置42包括:事件监控模块422和执行模块424。
事件监控模块422,配置为对移动终端的系统事件进行监测,判断系统事件是否符合预设的工作区规则。执行模块424,配置为当系统事件符合工作区规则时,例如,工作区规则为通话、短信的联系人、邮箱、短信中的关键字等是否存储在工作区数据库中等等。在工作区空间内执行与系统事件对应的操作,将与操作相对应的数据加密并存储在工作区空间的数据库中。
根据本申请的一个实施例,所述系统事件包括:通话事件和短信事件。
执行模块424包括通话和短信执行模块4242、用户选项模块4244和邮件执行模块4246。
通话和短信执行模块4242,配置为当判断通话事件的主叫方的电话号码或被叫方的电话号码、或短信事件的发件人的电话号码或收件人的电话号码存储在工作区空间的数据库中时,所述系统事件符合所述工作区规则;以及对所述通话事件的记录或所述短信时间的短信加密,将所述通话事件的记录或所述短信事件的短信存储在所述工作区空间的数据库中。
所述通话和短信执行模块4242,还配置为在所述移动终端的通话记录中将所述通话事 件的记录删除,或在所述移动终端的短消息记录中将所述短信事件的短信删除。
所述通话和短信执行模块4242,还配置为拦截所述通话事件的记录进入移动终端的通话记录中,或拦截所述短信事件的短信进入所述移动终端的短消息记录中。
用户选项模块4244,配置为提供通话选项界面,用户选择当来电的主叫方或被叫方电话号码存储在工作区空间的数据库中时,是否删除所述移动终端的通话记录。
用户选项模块4244,还配置为提供邮件规则选项界面,由用户设置只能在工作区或使用工作区应用接收的邮箱账号,并将邮箱账号存储在工作区空间的数据库中。
邮件执行模块4246,配置为当判断系统事件为接收邮件,并且发件人的邮箱账号存储在工作区空间的数据库中时,所述系统事件符合所述工作区规则;以及,将邮件内容以及下载的邮件附件加密,并将邮件内容以及下载的邮件的附件存在工作区空间的数据库中。
所述执行模块424,还配置为对用户输入的密码验证成功后,且用户进入工作区查看通话记录、短信、邮件或邮件附件时,对存储在所述工作区空间的数据库中的通话事件的记录、短信事件的短信、邮件事件的邮件或邮件事件的邮件附件进行解密;当判断用户结束查看时,通过解密产生的通话记录、短信、邮件或邮件附件的临时文件。
所述执行模块424,还配置为当用户采用浏览器查看工作区数据库中存储的数据,且用户退出浏览器时,将浏览器的缓存清除。
所述用户选项模块4244,还配置为在移动终端上运行工作区应用并进入工作区,对用户提供联系人选项界面,接收用户从移动终端通讯录的联系人中选取的工作联系人,并将用户选取的工作联系人存储在工作区空间的数据库中。
策略和规则接收模块426,配置为接收企业管理平台发送的工作区策略和规则,并将工作区策略和规则存储在工作区的数据库中。例如,工作区规则包括:通话、短信的联系人、邮箱、短信中的关键字是否存储在工作区数据库中等等。工作区策略包括:当通话或短信的联系人为设定的工作区联系人时,将通话记录、短信加密存储、并在移动终端中删除记录;当用户查看工作区中的信息时需要进行密码鉴权;定期下载、更新工作区应用;定期杀毒;设置工作区应用的优先级等等。
图5为根据本申请的公私隔离的装置的一个实施例与企业网信息交互的示意图。如图5所示,在移动终端4中设置公私隔离的装置42,公私隔离的装置42可以有多种实现方式,例如,集成电路、插件、应用等等。
公私隔离的装置42接收企业管理平台(服务器)52发送的工作区策略和规则,并将工作区策略和规则存储在工作区的数据库中。通过部署于企业网内部的企业管理平台(服务器)52,管理员可以轻松实现移动终端管理、策略管理下发、企业应用管理等,可以降低管理的复杂度,节约IT人力投入。
通过部署在企业网内部中的邮件、业务、OA服务器52可以实现移动终端4的报表、公文下发等。公私隔离的装置42与邮件、业务、OA服务器54进行通信,进行业务操 作,例如收发短信、写邮件或下载公文等等,将文件、图片、邮件、短信等数据进行加密,并存储在工作区空间的数据库中。
本申请的公私隔离的方法和装置,不仅仅可以配置为移动终端中,也可以应用在个人PC、平板电脑等个人终端中。
本申请的公私隔离的方法和装置,在不影响员工对个人应用使用的感受的基础上,在移动终端上建立一个安全、独立的工作区,将所有的工作数据,即企业应用和数据存储在受保护的安全区内。个人应用无法访问企业数据,避免企业数据被个人应用非法存取,不仅仅将企业数据和个人数据完全隔离,使IT部门能够更好地保护企业的应用和数据,也为员工提供了无差别的个人应用体验,达到一机两用的效果。
可能以许多方式来实现本发明本申请的方法和系统。例如,可通过软件、硬件、固件或者软件、硬件、固件的任何组合来实现本发明本申请的方法和系统。用于配置为方法的步骤的上述顺序仅是为了进行说明,本发明本申请的方法的步骤不限于以上具体描述的顺序,除非以其它方式特别说明。此外,在一些实施例中,还可将本发明本申请实施为记录在记录介质中的程序,这些程序包括用于配置为实现根据本发明本申请的方法的机器可读指令。因而,本发明本申请还覆盖存储用于配置为执行根据本发明本申请的方法的程序的记录介质。
本申请的描述是为了示例和描述起见而给出的,而并不是无遗漏的或者将本申请限于所公开的形式。很多修改和变化对于本领域的普通技术人员而言是显然的。选择和描述实施例是为了更好说明本申请的原理和实际应用,并且使本领域的普通技术人员能够理解本申请从而设计适于特定用途的带有各种修改的各种实施例。
本发明的各个部件实施例可以以硬件实现,或者以在一个或者多个处理器上运行的软件模块实现,或者以它们的组合实现。本领域的技术人员应当理解,可以在实践中使用微处理器或者数字信号处理器(DSP)来实现根据本发明实施例的公私隔离设备中的一些或者全部部件的一些或者全部功能。本发明还可以实现为用于执行这里所描述的方法的一部分或者全部的设备或者装置程序(例如,计算机程序和计算机程序产品)。这样的实现本发明的程序可以存储在计算机可读介质上,或者可以具有一个或者多个信号的形式。这样的信号可以从因特网网站上下载得到,或者在载体信号上提供,或者以任何其他形式提供。
例如,图6示出了可以实现根据本发明的公私隔离的装置设备。该设备传统上包括处理器610和以存储器620形式的计算机程序产品或者计算机可读介质。存储器620可以是诸如闪存、EEPROM(电可擦除可编程只读存储器)、EPROM、硬盘或者ROM之类的电子存储器。存储器620具有用于执行上述方法中的任何方法步骤的程序代码631的存储空间630。例如,用于程序代码的存储空间630可以包括分别用于实现上面的方法中的各种步骤的各个程序代码631。这些程序代码可以从一个或者多个计算机程序产品中读出或者写入到这一个或者多个计算机程序产品中。这些计算机程序产 品包括诸如硬盘,紧致盘(CD)、存储卡或者软盘之类的程序代码载体。这样的计算机程序产品通常为如参考图7所述的便携式或者固定存储单元。该存储单元可以具有与图4的服务器中的存储器620类似布置的存储段、存储空间等。程序代码可以例如以适当形式进行压缩。通常,存储单元包括计算机可读代码631’,即可以由例如诸如610之类的处理器读取的代码,这些代码当由服务器运行时,导致该服务器执行上面所描述的方法中的各个步骤。
□本文中所称的“一个实施例”、“实施例”或者“一个或者多个实施例”意味着,结合实施例描述的特定特征、结构或者特性包括在本发明的至少一个实施例中。此外,请注意,这里“在一个实施例中”的词语例子不一定全指同一个实施例。
□在此处所提供的说明书中,说明了大量具体细节。然而,能够理解,本发明的实施例可以在没有这些具体细节的情况下被实践。在一些实例中,并未详细示出公知的方法、结构和技术,以便不模糊对本说明书的理解。
应该注意的是上述实施例对本发明进行说明而不是对本发明进行限制,并且本领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施例。在权利要求中,不应将位于括号之间的任何参考符号构造成对权利要求的限制。单词“包含”不排除存在未列在权利要求中的元件或步骤。位于元件之前的单词“一”或“一个”不排除存在多个这样的元件。本发明可以借助于包括有若干不同元件的硬件以及借助于适当编程的计算机来实现。在列举了若干装置的单元权利要求中,这些装置中的若干个可以是通过同一个硬件项来具体体现。单词第一、第二、以及第三等的使用不表示任何顺序。可将这些单词解释为名称。
此外,还应当注意,本说明书中使用的语言主要是为了可读性和教导的目的而选择的,而不是为了解释或者限定本发明的主题而选择的。因此,在不偏离所附权利要求书的范围和精神的情况下,对于本技术领域的普通技术人员来说许多修改和变更都是显而易见的。对于本发明的范围,对本发明所做的公开是说明性的,而非限制性的,本发明的范围由所附权利要求书限定。

Claims (18)

  1. 一种公私隔离的方法,其特征在于,包括:
    对移动终端的系统事件进行监测,判断所述系统事件是否符合预设的工作区规则;
    当所述系统事件符合所述工作区规则时,在工作区空间内执行与所述系统事件对应的操作,将与所述操作相对应的数据加密并存储在所述工作区空间的数据库中。
  2. 如权利要求1所述的方法,其特征在于:
    所述系统事件包括:通话事件和短信事件;
    当判断所述通话事件的主叫方的电话号码或被叫方的电话号码、或短信事件的发件人的电话号码或收件人的电话号码存储在工作区空间的数据库中时,所述系统事件符合所述工作区规则;
    将与所述操作相对应的数据加密并存储在所述工作区空间的数据库中,包括:对所述通话事件的记录或所述短信事件的短信加密,将所述通话事件的记录或所述短信事件的短信存储在所述工作区空间的数据库中。
  3. 根据权利要求2所述的方法,其特征在于,将所述通话事件的记录或所述短信事件的短信存储在所述工作区空间的数据库中之后,还包括:
    在所述移动终端的通话记录中将所述通话事件的记录删除,或在所述移动终端的短消息记录中将所述短信事件的短信删除。
  4. 根据权利要求2所述的方法,其特征在于,所述将所述通话事件的记录或所述短信事件的短信存储在所述工作区空间的数据库中之前,还包括:
    拦截所述通话事件的记录进入移动终端的通话记录中,或拦截所述短信事件的短信进入所述移动终端的短消息记录中。
  5. 如权利要求2所述的方法,其特征在于,所述在所述移动终端的通话记录中将所述通话事件的记录删除之前,还包括:
    提供通话选项界面,由用户选择当来电的主叫方或被叫方电话号码存储在工作区空间的数据库中时,是否删除所述移动终端的通话记录,并在用户选择删除后执行所述将通话时间的记录删除的步骤。
  6. 如权利要求1所述的方法,其特征在于,还包括:
    提供邮件规则选项界面,由用户设置只能在工作区或使用工作区应用接收的邮箱账号,并将所述邮箱账号存储在所述工作区空间的数据库中;
    则当判断所述系统事件为接收邮件,并且发件人的邮箱账号存储在工作区空间的数据库中时,所述系统事件符合所述工作区规则;
    所述将与所述操作相对应的数据加密并存储在所述工作区空间的数据库中,包括:将邮件内容以及下载的邮件附件加密,并将邮件内容以及下载的邮件的附件存储在所述工作区空间的数据库中。
  7. 如权利要求2或6所述的方法,其特征在于,当对用户输入的密码验证成功后,且用户进入工作区查看通话记录、短信、邮件或邮件附件时,所述的方法还包括:
    对存储在所述工作区空间的数据库中的通话事件的记录、短信事件的短信、邮件事件的邮件或邮件事件的邮件附件进行解密;
    当判断用户结束查看时,删除通过解密产生的通话记录、短信、邮件或邮件附件的临时文件。
  8. 如权利要求7所述的方法,其特征在于,还包括:
    若用户采用浏览器查看工作区数据库中存储的数据,当用户退出浏览器时,将浏览器的缓存清除。
  9. 如权利要求7所述的方法,其特征在于,还包括:
    在移动终端上运行工作区应用并进入工作区,对用户提供联系人选项界面,接收用户从移动终端通讯录的联系人中选取的工作联系人,并将用户选取的工作联系人存储在所述工作区空间的数据库中;
    接收企业管理平台发送的工作区策略和规则,并将所述工作区策略和规则存储在所述工作区空间的数据库中。
  10. 一种公私隔离的装置,包括:
    事件监控模块,配置为对移动终端的系统事件进行监测,判断所述系统事件是否符合预设的工作区规则;
    执行模块,配置为当所述系统事件符合所述工作区规则时,在工作区空间内执行与所述系统事件对应的操作,将与所述操作相对应的数据加密并存储在所述工作区空间的数据库中。
  11. 如权利要求10所述的装置,其特征在于,所述执行模块包括:通话和短信执行模块;
    所述系统事件包括:通话事件和短信事件;所述通话和短信执行模块,配置为当判断所述通话事件的主叫方的电话号码或被叫方的电话号码、或短信事件的发件人的电话号码或收件人的电话号码存储在工作区空间的数据库中时,所述系统事件符合所述工作区规则;以及对所述通话事件的记录或所述短信时间的短信加密,将所述通话事件的记录或所述短信事件的短信存储在所述工作区空间的数据库中。
  12. 如权利要求11所述的装置,其特征在于:
    所述通话和短信执行模块,还配置为在所述移动终端的通话记录中将所述通话事件的记录删除,或在所述移动终端的短消息记录中将所述短信事件的短信删除。
  13. 如权利要求11所述的装置,其特征在于:
    所述通话和短信执行模块,还配置为拦截所述通话事件的记录进入移动终端的通话记录中,或拦截所述短信事件的短信进入所述移动终端的短消息记录中。
  14. 如权利要求11所述的装置,其特征在于,所述执行模块还包括:
    用户选项模块,配置为提供通话选项界面,用户选择当来电的主叫方或被叫方电话号码存储在工作区空间的数据库中时,是否删除所述移动终端的通话记录。
  15. 如权利要求6所述的装置,其特征在于,所述执行模块还包括:邮件执行模块;
    所述用户选项模块,还配置为提供邮件规则选项界面,由用户设置只能在工作区或使用工作区应用接收的邮箱账号,并将所述邮箱账号存储在所述工作区空间的数据库中;
    所述邮件执行模块,配置为当判断所述系统事件为接收邮件,并且发件人的邮箱账号存储在工作区空间的数据库中时,所述系统事件符合所述工作区规则;以及将邮件内容以及下载的邮件附件加密,并将邮件内容以及下载的邮件的附件存储在所述工作区空间的数据库中。
  16. 如权利要求11或13所述的装置,其特征在于:
    所述执行模块,还配置为对用户输入的密码验证成功后,且用户进入工作区查看通话记录、短信、邮件或邮件附件时,对存储在所述工作区空间的数据库中的通话事件的记录、短信事件的短信、邮件事件的邮件或邮件事件的邮件附件进行解密;当判断用户结束查看时,通过解密产生的通话记录、短信、邮件或邮件附件的临时文件。
  17. 如权利要求11所述的方法,其特征在于:
    所述执行模块,还配置为当用户采用浏览器查看工作区数据库中存储的数据,且用户退出浏览器时,将浏览器的缓存清除。
  18. 如权利要求16所述的装置,其特征在于,还包括:策略和规则接收模块;
    所述用户选项模块,还配置为在移动终端上运行工作区应用并进入工作区,对用户提供联系人选项界面,接收用户从移动终端通讯录的联系人中选取的工作联系人,并将用户选取的工作联系人存储在所述工作区空间的数据库中;
    所述策略和规则接收模块,配置为接收企业管理平台发送的工作区策略和规则,并将所述工作区策略和规则存储在所述工作区空间的数据库中。
PCT/CN2014/087815 2013-12-10 2014-09-30 一种公私隔离的方法及装置 Ceased WO2015085819A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US15/103,531 US20160316330A1 (en) 2013-12-10 2014-09-30 Method and device for business and private region separation

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
CN201310666504.2A CN103685266B (zh) 2013-12-10 2013-12-10 企业数据的保护方法和装置
CN201310666504.2 2013-12-10
CN201310713538.2A CN103647784B (zh) 2013-12-20 2013-12-20 一种公私隔离的方法和装置
CN201310713538.2 2013-12-20

Publications (1)

Publication Number Publication Date
WO2015085819A1 true WO2015085819A1 (zh) 2015-06-18

Family

ID=53370596

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/087815 Ceased WO2015085819A1 (zh) 2013-12-10 2014-09-30 一种公私隔离的方法及装置

Country Status (2)

Country Link
US (1) US20160316330A1 (zh)
WO (1) WO2015085819A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111339543A (zh) * 2020-02-27 2020-06-26 深信服科技股份有限公司 一种文件处理方法及装置、设备、存储介质

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3687106A1 (en) * 2019-01-25 2020-07-29 Usecrypt S.A. User device and method of providing notification in messaging application on user device
US11595789B2 (en) * 2019-05-31 2023-02-28 Apple Inc. Missed communication notification

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030051152A1 (en) * 2001-09-11 2003-03-13 Luc Wuidart Method and device for storing and reading digital data on/from a physical medium
CN1845032A (zh) * 2005-04-06 2006-10-11 杭州波导软件有限公司 一种移动终端用户使用权限分级管理实现方法
CN103647784A (zh) * 2013-12-20 2014-03-19 北京奇虎科技有限公司 一种公私隔离的方法和装置
CN103685266A (zh) * 2013-12-10 2014-03-26 北京奇虎科技有限公司 企业数据的保护方法和装置

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060230234A1 (en) * 2005-03-30 2006-10-12 Sap Ag. Browser cache management
US20100149981A1 (en) * 2008-12-12 2010-06-17 At&T Intellectual Property I, L.P. Determining Normal Call Blocking Volume From Call Blast Affecting Trunk Groups
US9665576B2 (en) * 2012-05-14 2017-05-30 International Business Machines Corporation Controlling enterprise data on mobile device via the use of a tag index
US9967241B2 (en) * 2013-03-15 2018-05-08 Verizon Patent And Licensing Inc. Persona based billing
CN107241110B (zh) * 2016-03-24 2019-11-01 深圳富泰宏精密工业有限公司 交互式通信系统、方法及其穿戴式装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030051152A1 (en) * 2001-09-11 2003-03-13 Luc Wuidart Method and device for storing and reading digital data on/from a physical medium
CN1845032A (zh) * 2005-04-06 2006-10-11 杭州波导软件有限公司 一种移动终端用户使用权限分级管理实现方法
CN103685266A (zh) * 2013-12-10 2014-03-26 北京奇虎科技有限公司 企业数据的保护方法和装置
CN103647784A (zh) * 2013-12-20 2014-03-19 北京奇虎科技有限公司 一种公私隔离的方法和装置

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111339543A (zh) * 2020-02-27 2020-06-26 深信服科技股份有限公司 一种文件处理方法及装置、设备、存储介质

Also Published As

Publication number Publication date
US20160316330A1 (en) 2016-10-27

Similar Documents

Publication Publication Date Title
CN103647784B (zh) 一种公私隔离的方法和装置
US9659165B2 (en) Method and apparatus for accessing corporate data from a mobile device
Wei et al. Malicious android applications in the enterprise: What do they do and how do we fix it?
US8387141B1 (en) Smartphone security system
US9396325B2 (en) Provisioning an app on a device and implementing a keystore
CN104462997B (zh) 一种保护移动终端上工作数据的方法、装置和系统
CN104268479B (zh) 一种文本操作隔离的方法、装置及移动终端
CN105610671A (zh) 一种终端数据保护的方法及装置
CN103685266B (zh) 企业数据的保护方法和装置
US20200311277A1 (en) Method, system and device for security configurations
US20130232543A1 (en) System and method to provide server control for access to mobile client data
CN103686716B (zh) 安卓系统机密性完整性增强访问控制系统
CN105830477A (zh) 集成操作系统的域管理
CN103646215A (zh) 一种应用程序的安装控制方法、相关系统及装置
CN103677935A (zh) 一种应用程序的安装控制方法、系统及装置
CN103491532B (zh) 一种基于Android平台的协作式隐私保护方法及系统
CN104468611A (zh) 基于双系统切换的数据安全处理方法及装置
CN102316197A (zh) 获取联系人信息的方法及装置
WO2017045417A1 (zh) 远程控制方法、装置及移动终端
CN106453398B (zh) 一种数据加密系统及方法
US11445057B2 (en) Private contact sharing
WO2012151975A1 (zh) 终端信息保密方法及装置
US11122014B2 (en) User device and method of providing notification in messaging application on user device
US20160316330A1 (en) Method and device for business and private region separation
US9754086B1 (en) Systems and methods for customizing privacy control systems

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14869163

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 15103531

Country of ref document: US

122 Ep: pct application non-entry in european phase

Ref document number: 14869163

Country of ref document: EP

Kind code of ref document: A1