WO2015131585A1 - 一种保证sd卡安全的方法和装置 - Google Patents

一种保证sd卡安全的方法和装置 Download PDF

Info

Publication number
WO2015131585A1
WO2015131585A1 PCT/CN2014/092708 CN2014092708W WO2015131585A1 WO 2015131585 A1 WO2015131585 A1 WO 2015131585A1 CN 2014092708 W CN2014092708 W CN 2014092708W WO 2015131585 A1 WO2015131585 A1 WO 2015131585A1
Authority
WO
WIPO (PCT)
Prior art keywords
card
password
encrypted
security
access
Prior art date
Application number
PCT/CN2014/092708
Other languages
English (en)
French (fr)
Inventor
杨飞
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2015131585A1 publication Critical patent/WO2015131585A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/068Authentication using credential vaults, e.g. password manager applications or one time password [OTP] applications

Definitions

  • the present invention relates to a mobile terminal application technology, and more particularly to a method and apparatus for implementing secure digital memory card (SD card) security management.
  • SD card secure digital memory card
  • mobile terminals such as smart phones and tablets have been rapidly developed and widely used. People are getting used to doing a lot of important operations using mobile terminals, such as mobile terminal payments. In this way, more and more important user information, such as personal payment account, mailbox, password, file and photo, needs to be saved in the mobile terminal. Therefore, people have higher and higher requirements for the security of mobile terminals.
  • Security configuration items such as pattern password configuration items, numeric password configuration items, and personal identification password PIN configurations. By selecting at least one of these configuration items, the security of the mobile terminal can be better increased.
  • the above security configuration item can only provide better security protection for the built-in memory in the mobile terminal, and does not provide security protection for an external secure digital memory card (SD, Secure Digital Memory Card) in the mobile terminal. The role. Once the phone is lost or the SD card is stolen and the data is read by other devices, important user data saved in the SD card will be leaked.
  • SD Secure Digital Memory Card
  • some mobile terminal users encrypt the important user data to be saved to the SD card by using the encryption software, and then save it to the SD card.
  • this method can improve the security of the data in the SD card, there are still several defects.
  • the above drawbacks reduce the security of this method to protect data in the SD card, thereby hindering It has been widely used.
  • the present invention provides a method and device for ensuring the security of an SD card, and fully utilizes the security function of the SD card, thereby effectively improving the security of data in the SD card.
  • a method for securing a secure digital memory card SD card comprising:
  • the secure access to the SD card is to access the SD card when the security function of the SD card is activated.
  • the first password is obtained and saved in the local storage according to the mobile device international identity code IMEI code.
  • the method further includes:
  • the encryption strategy includes:
  • the SD card configuration item for configuring whether to encrypt the SD card is selected, the SD card needs to be encrypted; or,
  • the SD card needs to be encrypted.
  • the security configuration item is selected to include: a pattern password configuration item for configuring whether to enable the graphic password, a digital password configuration item for configuring whether to enable the digital password, and Set at least one of the PIN configuration items for which the personal identification password PIN is enabled to be selected.
  • the method further includes:
  • the first password is sent to the SD card, and the SD card saves the first password as a second password in the SD to activate the security function of the SD card. And allowing the terminal to securely access the SD card.
  • the method further includes:
  • the SD card is normally accessed; wherein the SD card is accessed when the SD card is normally accessed to turn off the security function of the SD card.
  • the method further includes:
  • the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to selected, it is determined that the SD card needs to be encrypted, and the first password is sent to the SD card, and the SD card will be the first The password is saved as a second password in the SD to activate the security function of the SD card and allow the terminal to securely access the SD card.
  • the method further includes:
  • the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to unchecked, deleting the second password saved in the SD card to turn off the security function, and allowing the terminal to access the general The SD card; wherein the ordinary access SD card accesses the SD card when the security function of the SD card is turned off.
  • the method further includes:
  • the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to unchecked, deleting the second password saved in the SD card to turn off the security function, and allowing the terminal to access the general SD card.
  • a device for securing a secure digital memory card SD card including a security detection unit and security Access unit, where
  • the security detecting unit is configured to: determine whether the SD card is encrypted when the SD card has been inserted into the terminal, and send a first message to the security access unit when it is determined that the SD card is encrypted. ;
  • the security access unit is configured to trigger the SD when receiving the first message from the security detection unit and receiving a first password saved by a local memory of the terminal sent by the terminal.
  • the authentication function in the security function of the card authenticating the terminal according to the first password, and if the identity verification is successful, allowing the terminal to securely access the SD card, if the identity verification fails, the terminal is not allowed Said terminal accessing said SD card;
  • the secure access to the SD card is to access the SD card when the security function of the SD card is activated.
  • the first password is obtained and saved in the local storage according to the mobile device international identity code IMEI code.
  • the security detection unit is further configured to:
  • the encryption strategy includes:
  • the SD card configuration item for configuring whether to encrypt the SD card is selected, the SD card needs to be encrypted; or,
  • the SD card needs to be encrypted.
  • the security configuration item is selected to include: a pattern password configuration item for configuring whether to enable the graphic password, a digital password configuration item for configuring whether to enable the numeric password, and a configuration for enabling the personal identification password PIN. At least one configuration item in the PIN configuration item is selected.
  • the security access unit is further configured to:
  • the security access unit is further configured to: when receiving the third message from the security detecting unit, allow the terminal to access the SD card normally;
  • the ordinary access to the SD card is to access the SD card when the security function of the SD card is turned off.
  • the security detecting unit is further configured to: when the terminal is allowed to access the SD card normally, and the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to be selected, Sending the second message by the security access unit;
  • the secure access unit is further configured to: when receiving the second message from the security detecting unit, send the first password to the SD card, so that the SD card will be the first
  • the password is saved as a second password in the SD, and the security function of the SD card is activated, and the terminal is allowed to securely access the SD card.
  • the detecting unit is further configured to: when the terminal is allowed to securely access the SD card, and the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to unchecked, to the security access unit Send a fourth message;
  • the secure access unit is further configured to, when receiving the fourth message from the security detecting unit, delete a second password saved in the SD card to close the security function and allow the terminal Ordinary access to the SD card;
  • the ordinary access SD card accesses the SD card when the security function of the SD card is turned off.
  • the detecting unit is further configured to: when the terminal is allowed to securely access the SD card, and the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to unchecked, to the security access unit Send a fourth message;
  • the secure access unit is further configured to, when receiving the fourth message from the security detecting unit, delete a second password saved in the SD card to close the security function and allow the terminal Ordinary access to the SD card.
  • a computer program comprising program instructions that, when executed by a computer, cause the computer to perform any of the methods described above for securing the SD card.
  • a carrier carrying the computer program A carrier carrying the computer program.
  • the technical solution of the present invention includes: determining whether the SD card is encrypted when the SD card is inserted; and if determining that the SD card is encrypted, sending the first password saved in the local memory of the mobile terminal to the SD card.
  • the SD card is allowed to be securely accessed, otherwise the SD card is not allowed to be accessed; wherein the secure access SD card accesses the SD card when the security function of the SD card is activated.
  • the stealer when the encrypted SD card is stolen, the stealer cannot obtain the first password and pass the identity verification in the security function of the SD card, thereby effectively avoiding other
  • the device reads the data in the SD card, which effectively reduces the possibility of data cracking in the SD card.
  • the security function of the encrypted SD card ensures that unless the SD card is physically destroyed, the Formatting or deleting all data maliciously destroys the data in the SD card, further reducing the possibility of maliciously destroying the data in the SD card. From the above two aspects, it is not difficult to see that the technical solution of the present invention effectively improves the security of data in the SD card, and better improves the user experience of the security function of the mobile terminal.
  • the technical solution of the present invention is to calculate the first password for activating the security function of the SD card through the IMEI code through a preset encryption algorithm and save the first password as the second password for encrypting the SD card, thus avoiding When the user encrypts the data by the encryption software, forgetting to encrypt the password causes the possibility that the encrypted data cannot be decrypted and used, which increases the ease of use of the technical solution of the present invention.
  • FIG. 1 is a flow chart of a method for securing an SD card according to the present invention
  • FIG. 2 is a schematic structural diagram of a device for securing an SD card according to the present invention.
  • FIG. 1 is a flowchart of a method for securing an SD card according to the present invention. As shown in FIG. 1, the method includes:
  • Step 101 When it is detected that the SD card is inserted, it is determined whether the SD card is encrypted.
  • the detecting that the SD card is inserted may include detecting that the SD card is inserted when the mobile terminal is started, or detecting that the SD card is inserted.
  • the specific implementation of detecting whether the SD card is inserted in the mobile terminal and whether the SD card is inserted in the mobile terminal is a well-known technical means of those skilled in the art, and details are not described herein again.
  • Step 102 If it is determined that the SD card is encrypted, the first password saved in the local memory of the mobile terminal is sent to the SD card to trigger identity verification in the security function of the SD card, and if the identity verification is successful, the SD card is allowed to be securely accessed. Otherwise, access to the SD card is not allowed.
  • the secure access SD card accesses the SD card when the security function of the SD card is activated.
  • sending the first password saved in the local memory of the mobile terminal to the SD card to trigger the identity verification in the security function of the SD card may include: sending, by requesting the first security command corresponding to the identity verification, to the SD card a first password, wherein the first security command includes a first password; the first security command triggers the SD card to compare whether the first password and the second password are consistent, and the SD card returns a consistency by responding to the second security command corresponding to the identity verification. The authentication result; the second security command triggers this step to determine whether the authentication is successful.
  • the first password in this step is obtained according to the mobile device international identity code (IMEI code) and stored in the local storage.
  • IMEI code mobile device international identity code
  • the first password may be calculated according to a preset cryptographic algorithm according to the IMEI code before step 101, and the first password is saved in the local storage.
  • the input of the cryptographic algorithm is an IMEI code, and the output is the first password.
  • the cryptographic algorithm ensures that the IMEI code has a one-to-one correspondence with the first password.
  • a person skilled in the art can design a cryptographic algorithm by various methods, for example, a cryptographic algorithm combined with various mathematical operations.
  • the method of the present invention may further include: determining that the SD card is not encrypted, and determining whether the SD card needs to be encrypted according to a preset encryption policy.
  • the encryption policy in this step may include:
  • the SD card configuration item for configuring whether to encrypt the SD card is selected, the SD card needs to be encrypted.
  • the encryption policy in this step may include:
  • the SD card needs to be encrypted.
  • the security configuration item of the mobile terminal is selected to include: a pattern password configuration item for configuring whether to enable the graphic password, a digital password configuration item for configuring whether to enable the digital password, and a configuration for enabling the personal identification number (PIN). At least one of the PIN configuration items is selected. It should be clear to those skilled in the art that in some operating systems of the mobile terminal, two or three of the above three configuration items may be simultaneously selected.
  • the encrypted SD card configuration item when the security configuration item of the mobile terminal is unchecked, the encrypted SD card configuration item may be set to gray, that is, the SD card configuration item may not be selected at this time.
  • the method of the present invention further determines whether the SD card needs to be encrypted according to a preset encryption policy
  • the method may include: if it is determined that the SD card needs to be encrypted, the first password is sent to the SD card and saved as the second password in the SD to activate the security function of the SD card and allow secure access to the SD card.
  • the SD card when the security function of the SD card is activated, or the authentication is successful, the SD card encrypts and saves the received data based on the second password for the read access request, for the read access request.
  • the SD card decrypts and sends out the data to be read based on the second password.
  • the security function of the SD card refer to the SD card protocol, which is not described here.
  • the second password stored in the SD corresponds to the IMEI code of the mobile terminal inserted by the SD card, and since the IMEI code is in one-to-one correspondence with the mobile terminal, Therefore, the mobile terminal is bound to the SD card inserted therein by this step.
  • the method of the present invention may further include: if it is determined that the SD card does not need to be encrypted, the ordinary access SD card is allowed. Among them, the ordinary access SD card accesses the SD card when the security function of the SD card is turned off.
  • the method may further include:
  • the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to selected, it is determined that the SD card needs to be encrypted, and the first password is sent to the SD card and saved as the second password in the SD to activate the security of the SD card.
  • the method of the present invention may further include:
  • the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to unchecked, the second password saved in the SD card is deleted to turn off the security function and allow normal access to the SD card.
  • deleting the second password saved in the SD card to turn off the security function may include: sending a fourth security corresponding to the security function to the SD card, triggering the SD card to delete the SD card for saving.
  • the second password wherein the fourth security command includes a password for authentication.
  • the SD card first performs identity verification according to the password carried by the fourth command before deleting the second password according to the fourth command. If the password is the first password, the authentication is performed, and the security function is turned off.
  • the method of the present invention implements communication with the SD card through a security command based on the serial peripheral interface (SPI interface) specified by the SD card protocol.
  • SPI interface serial peripheral interface
  • the security command includes at least the first security command, the second security command, the third security command, and the fourth security command.
  • the specific format of the security command refer to the related protocol of the SD card, and details are not described herein.
  • FIG. 2 is a schematic structural diagram of a device for securing an SD card according to the present invention. As shown in FIG. 2, the security detection unit 201 and the security access management unit 202 are included.
  • the security detecting unit 201 is configured to: determine whether the SD card is encrypted when the SD card is inserted, and send the first message when it is determined that the SD card is encrypted.
  • the security access unit 202 is configured to: when receiving the first message from the security detection unit, send the first password saved by the local memory of the mobile terminal to the SD card to trigger identity verification in the security function of the SD card, if the identity verification If successful, it allows secure access to the SD card, otherwise access to the SD card is not allowed.
  • the secure access SD card accesses the SD card when the security function of the SD card is activated.
  • the first password is obtained according to the mobile device international identity code IMEI code and stored in the local storage.
  • the security detecting unit 201 is further configured to: when it is determined that the SD card is not encrypted, determine whether the SD card needs to be encrypted according to a preset encryption policy, and when it is determined that the SD card needs to be encrypted, send a second message, when it is determined that encryption is not required The third message is sent when the SD card is used.
  • the encryption strategy includes:
  • the SD card configuration item used to configure whether to encrypt the SD card is selected, the SD card needs to be encrypted; or,
  • the SD card needs to be encrypted.
  • the security configuration item is selected to include: a pattern password configuration item for configuring whether to enable a graphic password, a digital password configuration item for configuring whether to enable a numeric password, and a PIN configuration for configuring whether to enable a personal identification number (PIN). At least one of the items in the item is selected.
  • the security access unit 202 is further configured to: when receiving the second message from the security detection unit, send the first password to the SD card and save as the second password in the SD to activate the security function of the SD card and allow security Access the SD card.
  • the secure access unit 202 is further configured to allow normal access to the SD card when receiving the third message from the security detecting unit; wherein the normal access SD card accesses the SD card when the security function of the SD card is turned off.
  • the security detecting unit 201 is further configured to transmit the second message when the normal access to the SD card is permitted and it is detected that the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to selected.
  • the security detecting unit 201 is further configured to transmit a fourth message when the secure access to the SD card is permitted and the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to unchecked.
  • the security access unit 202 is further configured to, when receiving the fourth message from the security detecting unit, delete the second password saved in the SD card to turn off the security function and allow normal access to the SD card; wherein, the ordinary access SD card is Access the SD card when turning off the security function of the SD card.
  • the embodiment of the invention also discloses a device for guaranteeing the security of a secure digital memory card SD card, Including a security detection unit and a security access unit, wherein
  • the security detecting unit is configured to: determine whether the SD card is encrypted when the SD card has been inserted into the terminal, and send a first message to the security access unit when it is determined that the SD card is encrypted. ;
  • the security access unit is configured to trigger the SD when receiving the first message from the security detection unit and receiving a first password saved by a local memory of the terminal sent by the terminal.
  • the authentication function in the security function of the card authenticating the terminal according to the first password, and if the identity verification is successful, allowing the terminal to securely access the SD card, if the identity verification fails, the terminal is not allowed Said terminal accessing said SD card;
  • the secure access to the SD card is to access the SD card when the security function of the SD card is activated.
  • the first password is obtained and saved in the local storage according to the mobile device international identity code IMEI code.
  • the security detection unit is further configured to:
  • the encryption strategy includes:
  • the SD card configuration item for configuring whether to encrypt the SD card is selected, the SD card needs to be encrypted; or,
  • the SD card needs to be encrypted.
  • the security configuration item is selected to include: a pattern password configuration item for configuring whether to enable the graphic password, a digital password configuration item for configuring whether to enable the numeric password, and a configuration for enabling the personal identification password PIN. At least one configuration item in the PIN configuration item is selected.
  • the security access unit is further configured to:
  • the security access unit is further configured to: when receiving the third message from the security detecting unit, allow the terminal to access the SD card normally;
  • the ordinary access to the SD card is to access the SD card when the security function of the SD card is turned off.
  • the security detecting unit is further configured to: when the terminal is allowed to access the SD card normally, and the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to be selected, Sending the second message by the security access unit;
  • the secure access unit is further configured to: when receiving the second message from the security detecting unit, send the first password to the SD card, so that the SD card will be the first
  • the password is saved as a second password in the SD, and the security function of the SD card is activated, and the terminal is allowed to securely access the SD card.
  • the detecting unit is further configured to: when the terminal is allowed to securely access the SD card, and the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to unchecked, to the security access unit Send a fourth message;
  • the secure access unit is further configured to, when receiving the fourth message from the security detecting unit, delete a second password saved in the SD card to close the security function and allow the terminal Ordinary access to the SD card;
  • the ordinary access SD card accesses the SD card when the security function of the SD card is turned off.
  • the detecting unit is further configured to: when the terminal is allowed to securely access the SD card, and the encrypted SD card configuration item for configuring whether to encrypt the SD card is changed to unchecked, to the security access unit Send a fourth message;
  • the secure access unit is further configured to, when receiving the fourth message from the security detecting unit, delete a second password saved in the SD card to close the security function and allow the terminal Ordinary access to the SD card.
  • the device can exist independently of the terminal and the SD card, or can be located in an existing terminal or an SD card, and integrated with an existing terminal or an SD card.
  • the embodiment of the invention also discloses a computer program, comprising program instructions, which when executed by a computer, enable the computer to perform any of the above methods for securing the SD card.
  • the invention also discloses a carrier carrying the computer program.
  • the stealer when the encrypted SD card is stolen, the stealer cannot obtain the first password and pass the identity verification in the security function of the SD card, thereby effectively avoiding other
  • the device reads the data in the SD card, which effectively reduces the possibility of data cracking in the SD card.
  • the security function of the encrypted SD card ensures that unless the SD card is physically destroyed, the Formatting or deleting all data maliciously destroys the data in the SD card, further reducing the possibility of maliciously destroying the data in the SD card. From the above two aspects, it is not difficult to see that the technical solution of the present invention effectively improves the security of data in the SD card, and better improves the user experience of the security function of the mobile terminal. Therefore, the present invention has strong industrial applicability.

Abstract

本发明公开了一种实现安全数字存储卡(SD卡)安全管理的方法和装置,包括检测出插有SD卡时,确定SD卡是否已加密;如果确定出SD卡已加密,将终端的本地存储器保存的第一密码发送给SD卡,以触发SD卡的安全功能中的身份验证,如果身份验证成功,则允许安全访问SD卡,否则不允许访问SD卡;其中,安全访问SD卡为激活SD卡的安全功能时访问SD卡。通过本发明提供的技术方案,充分利用了SD卡的安全功能,有效提高了SD卡中数据的安全性。

Description

一种保证SD卡安全的方法和装置 技术领域
本发明涉及移动终端应用技术,尤指一种实现安全数字存储卡(SD卡)安全管理的方法和装置。
背景技术
随着移动互联网技术的迅猛发展,移动终端如智能手机和平板电脑得到了高速发展和广泛应用。人们逐渐习惯了使用移动终端完成很多重要的操作,例如移动终端支付等。这样,需要在移动终端中保存越来越多的重要用户信息,例如个人支付账号、邮箱、密码、文件和相片等。因此人们对移动终端的安全性的要求也越来越高。
目前,在例如安卓操作系统(ANDROID)、苹果手机操作系统(IOS)和微软视窗手机操作系统(WINDOWS PHONE)等主流操作系统中,均提供了多种可选择的用于增强移动终端安全性的安全配置项,例如图案密码配置项、数字密码配置项和个人识别密码PIN配置等。通过选中这些配置项中的至少一个配置项,可以较好地增加移动终端的安全性。然而,上述安全配置项只能对移动终端中的内置存储器起到较好的安全性保护的作用,对于移动终端中外置的安全数字存储卡(SD,Secure Digital Memory Card)没有起到安全性保护的作用。一旦手机丢失或者SD卡被盗取并通过其他设备读取数据,SD卡中保存的重要用户数据就会泄露。
为此,有些移动终端的用户通过使用加密软件,将要保存到SD卡中的重要用户数据加密,然后再保存到SD卡中。这种方法,虽然可以提高SD卡中的数据的安全性,但是仍然存在几个方面缺陷。第一,一旦SD卡被盗取并通过其他设备读取到加密后的密文数据,有可能破解密文数据得到解密后的数据即明文数据;第二,即使在上述情况下无法破解密文数据,也可以以格式化或全部删除数据的方式恶意破坏密文数据;第三,如果用户因长期不使用SD卡中密文数据而忘记密码,则其自身也无法从密文数据中提读取明文数据。上述缺陷,降低了这种方法保护SD卡中数据的安全性,从而阻碍 了其得到广泛的应用。
发明内容
为了解决上述技术问题,本发明提供了一种保证SD卡安全的方法和装置,充分利用SD卡的安全功能,能够有效提高SD卡中数据的安全性。
为了达到本发明目的,采用如下技术方案:
一种保证安全数字存储卡SD卡安全的方法,包括:
检测出终端插有SD卡时,确定所述SD卡是否已加密;
如果确定出SD卡已加密,将所述终端的本地存储器保存的第一密码发送给所述SD卡,以触发所述SD卡的安全功能中的身份验证功能;
根据所述第一密码对所述终端进行身份验证,如果身份验证成功,则允许所述终端安全访问所述SD卡;如果身份验证失败,不允许所述终端访问所述SD卡;
其中,安全访问所述SD卡为激活所述SD卡的安全功能时访问所述SD卡。
可选地,所述第一密码是根据移动设备国际身份码IMEI码获取、保存在所述本地存储器中的。
可选地,所述确定SD卡是否已加密的步骤之后,该方法还包括:
如果确定出所述SD卡未加密,根据预先设置的加密策略确定是否需要加密SD卡;
其中,加密策略包括:
如果用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密SD卡;或者,
如果用于配置所述终端是否启用安全功能的安全配置项为选中,且用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密SD卡。
可选地,所述安全配置项为选中包括:用于配置是否启用图形密码的图案密码配置项、用于配置是否启用数字密码的数字密码配置项、以及用于配 置是否启用个人识别密码PIN的PIN配置项中的至少一个配置项为选中。
可选地,所述根据预先设置的加密策略确定是否需要加密SD卡的步骤之后,该方法还包括:
如果确定出需要加密SD卡,将所述第一密码发送给所述SD卡,所述SD卡将所述第一密码保存为SD中的第二密码,以激活所述SD卡的安全功能,并允许所述终端安全访问所述SD卡。
可选地,所述根据预先设置的加密策略确定是否需要加密SD卡的步骤之后,该方法还包括:
如果确定出不需要加密所述SD卡,则允许普通访问所述SD卡;其中,普通访问所述SD卡为关闭所述SD卡的安全功能时访问所述SD卡。
可选地,所述允许普通访问所述SD卡之后,该方法还包括:
如果用于配置是否加密所述SD卡的加密SD卡配置项改变为选中,则确定出需要加密SD卡,将所述第一密码发送给所述SD卡,所述SD卡将所述第一密码保存为所述SD中的第二密码,以激活所述SD卡的安全功能,并允许所述终端安全访问所述SD卡。
可选地,所述允许所述终端安全访问所述SD卡的步骤之后,该方法还包括:
如果用于配置是否加密所述SD卡的加密SD卡配置项改变为未选中,则删除所述SD卡中保存的第二密码,以关闭所述安全功能,并允许所述终端普通访问所述SD卡;其中,普通访问SD卡为关闭SD卡的安全功能时访问所述SD卡。
可选地,所述允许所述终端安全访问所述SD卡的步骤之后,该方法还包括:
如果用于配置是否加密所述SD卡的加密SD卡配置项改变为未选中,则删除所述SD卡中保存的第二密码,以关闭所述安全功能,并允许所述终端普通访问所述SD卡。
一种保证安全数字存储卡SD卡安全的装置,包括安全检测单元和安全 访问单元,其中,
所述安全检测单元设置成:检测出所述SD卡已经被插入终端时,确定所述SD卡是否已加密,当确定出所述SD卡已加密时,发送第一消息给所述安全访问单元;
所述安全访问单元设置成:接收到来自所述安全检测单元的所述第一消息时,且接收到所述终端发来的所述终端的本地存储器保存的第一密码时,触发所述SD卡的安全功能中的身份验证功能;根据所述第一密码对所述终端进行身份验证,如果身份验证成功,则允许所述终端安全访问所述SD卡,如果身份验证失败,则不允许所述终端访问所述SD卡;
其中,安全访问所述SD卡为激活所述SD卡的安全功能时访问所述SD卡。
可选地,所述第一密码是根据移动设备国际身份码IMEI码获取、保存在所述本地存储器中的。
可选地,所述安全检测单元还设置成:
当确定出SD卡未加密时,根据预先设置的加密策略确定是否需要加密SD卡,当确定出需要加密SD卡时,向所述安全访问单元发送第二消息,当确定出不需要加密SD卡时,向所述安全访问单元发送第三消息;
其中,加密策略包括:
如果用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密所述SD卡;或者,
如果用于配置所述终端是否启用安全功能的安全配置项为选中,且用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密所述SD卡。
可选地,所述安全配置项为选中包括:用于配置是否启用图形密码的图案密码配置项、用于配置是否启用数字密码的数字密码配置项、以及用于配置是否启用个人识别密码PIN的PIN配置项中的至少一个配置项为选中。
可选地,所述安全访问单元还设置成:
当接收到来自所述安全检测单元的所述第二消息时,将所述第一密码发送给所述SD卡,以使得所述SD卡将所述第一密码保存为所述SD中的第二 密码,并激活所述SD卡的安全功能,并允许所述安全访问所述SD卡。
可选地,所述安全访问单元还设置成:当接收到来自所述安全检测单元的所述第三消息时,允许所述终端普通访问所述SD卡;
其中,普通访问所述SD卡为关闭所述SD卡的安全功能时访问所述SD卡。
可选地,所述安全检测单元还设置成:当允许所述终端普通访问所述SD卡,且检测出用于配置是否加密所述SD卡的加密SD卡配置项改变为选中时,向所述安全访问单元发送所述第二消息;
所述安全访问单元还设置成:当接收到来自所述安全检测单元的所述第二消息时,将所述第一密码发送给所述SD卡,以使得所述SD卡将所述第一密码保存为SD中的第二密码,并激活所述SD卡的安全功能,并允许所述终端安全访问SD卡。
可选地,所述检测单元还设置成:当允许所述终端安全访问SD卡,且用于配置是否加密所述SD卡的加密SD卡配置项改变为未选中时,向所述安全访问单元发送第四消息;
所述安全访问单元还设置成,当接收到来自所述安全检测单元的所述第四消息时,删除所述SD卡中保存的第二密码,以关闭所述安全功能,并允许所述终端普通访问SD卡;
其中,普通访问SD卡为关闭SD卡的安全功能时访问SD卡。
可选地,所述检测单元还设置成:当允许所述终端安全访问SD卡,且用于配置是否加密所述SD卡的加密SD卡配置项改变为未选中时,向所述安全访问单元发送第四消息;
所述安全访问单元还设置成,当接收到来自所述安全检测单元的所述第四消息时,删除所述SD卡中保存的第二密码,以关闭所述安全功能,并允许所述终端普通访问SD卡。
一种计算机程序,包括程序指令,当该程序指令被计算机执行时,使得该计算机可执行上述任意的保证SD卡安全的方法。
一种载有所述计算机程序的载体。
与相关技术相比,本发明技术方案包括:检测出插有SD卡时,确定SD卡是否已加密;如果确定出SD卡已加密,将移动终端的本地存储器保存的第一密码发送给SD卡,以触发SD卡的安全功能中的身份验证,如果身份验证成功,则允许安全访问SD卡,否则不允许访问SD卡;其中,安全访问SD卡为激活SD卡的安全功能时访问SD卡。通过本发明技术方案,一方面,当出现已加密的SD卡被盗取的情况时,由于盗取者无法获取第一密码并通过SD卡的安全功能中的身份验证,这样有效避免了通过其他设备读取SD卡中数据,有效降低了SD卡中数据破解的可能性;另一方面,当出现上述情况时,已加密的SD卡的安全功能保证了除非以物理方式破坏SD卡,不能以格式化或全部删除数据的方式恶意破坏SD卡中数据,进一步降低了恶意破坏SD卡中数据的可能性。从上述两方面的有益效果,不难看出本发明技术方案有效提高了SD卡中数据的安全性,较好提高了移动终端的安全功能的用户体验。
另外,由于本发明技术方案是通过IMEI码经过预先设置的加密算法计算用于激活SD卡的安全功能的第一密码和将第一密码保存为用于加密SD卡的第二密码,因此避免了用户通过加密软件加密数据时忘记加密密码造成加密后的数据的不可解密和使用的可能性,增加了本发明技术方案的易用性。
本发明的其它特征和优点将在随后的说明书中阐述,并且,部分地从说明书中变得显而易见,或者通过实施本发明而了解。本发明的目的和其他优点可通过在说明书、权利要求书以及附图中所特别指出的结构来实现和获得。
附图概述
附图用来提供对本发明技术方案的进一步理解,并且构成说明书的一部分,与本申请的实施例一起用于解释本发明的技术方案,并不构成对本发明技术方案的限制。
图1为本发明保证SD卡安全的方法的流程图;
图2为本发明保证SD卡安全的装置的组成结构示意图。
本发明的较佳实施方式
下文中将结合附图对本发明的实施例进行详细说明。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互任意组合。
在附图的流程图示出的步骤可以在诸如一组计算机可执行指令的计算机系统中执行。并且,虽然在流程图中示出了逻辑顺序,但是在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤。
图1为本发明保证SD卡安全的方法的流程图,如图1所示,包括:
步骤101:检测出插有SD卡时,确定SD卡是否已加密。
其中,检测出插有SD卡可以包括移动终端启动时检测出插有SD卡,或者检测出插入SD卡。检测测移动终端中是否插有SD卡、以及移动终端中是否插入SD卡的具体实现,为本领域技术人员的公知技术手段,此处不再赘述。
本步骤中确定SD卡是否为已加密或未加密的具体实现,属于本领域技术人员的惯用技术手段,此处不再赘述。
步骤102:如果确定出SD卡已加密,将移动终端的本地存储器保存的第一密码发送给SD卡,以触发SD卡的安全功能中的身份验证,如果身份验证成功,则允许安全访问SD卡,否则不允许访问SD卡。
其中,安全访问SD卡为激活SD卡的安全功能时访问SD卡。
本步骤中,将移动终端的本地存储器保存的第一密码发送给SD卡,以触发SD卡的安全功能中的身份验证可以包括:本步骤通过请求身份验证相应的第一安全命令向SD卡发送第一密码,其中,第一安全命令中包括第一密码;第一安全命令触发SD卡比较第一密码和第二密码是否一致,SD卡通过响应身份验证相应的第二安全命令返回是否一致的身份验证结果;第二安全命令触发本步骤确定是否身份验证成功。
本步骤中,如果确定出身份验证失败,则不允许访问SD卡,同时还可 以以人机交互的方式如在移动终端的显示屏上以提示框的方式提示:SD卡加密不能访问。
本步骤中第一密码是根据移动设备国际身份码(IMEI码)获取、保存在本地存储器中。
可以在步骤101之前根据IMEI码经过预先设置的密码算法,计算第一密码,并将第一密码保存在本地存储器中。其中,密码算法的输入为IMEI码,输出为第一密码。通过密码算法保证IMEI码与第一密码一一对应。本领域技术人员可以通过多种方法设计密码算法,例如,多种数学运算结合的密码算法。
可选地,
步骤101中确定SD是否已加密之后,本发明方法还可以包括:确定出SD卡未加密,根据预先设置的加密策略确定是否需要加密SD卡。
在一个实施例中,本步骤中的加密策略可以包括:
如果用于配置是否加密SD卡的加密SD卡配置项为选中,则需要加密SD卡。
在另一个实施例中,本步骤中的加密策略可以包括:
如果用于配置移动终端是否启用安全功能的安全配置项为选中,且加密SD卡配置项为选中,则需要加密SD卡。
其中,移动终端的安全配置项为选中包括:用于配置是否启用图形密码的图案密码配置项、用于配置是否启用数字密码的数字密码配置项、以及用于配置是否启用个人识别密码(PIN)的PIN配置项中的至少一个配置项为选中。本领域技术人员应该清楚的是,在移动终端的某些操作系统中,可以支持同时选中上述三个配置项中的两项或者三项。
需要说明的是,在上面的实施例中,当移动终端的安全配置项为未选中时,加密SD卡配置项可以设置为灰色,也就是说,此时SD卡配置项不可选中。
可选地,
根据预先设置的加密策略确定是否需要加密SD卡之后,本发明方法还 可以包括:如果确定出需要加密SD卡,将第一密码发送给SD卡并保存为SD中的第二密码,以激活SD卡的安全功能,并允许安全访问SD卡。
具体来讲,向SD卡发送与激活安全功能相应的第三安全命令,触发SD卡将第一密码保存为SD卡中的第二密码,从而触发SD卡激活安全功能,并允许安全访问SD卡;其中,第三安全命令中包括第一密码。
需要说明的是,当SD卡的安全功能激活,或者身份验证成功之后,对于写入的访问请求,SD卡会基于第二密码对接收到的数据进行加密并保存下来,对于读取的访问请求,SD卡会基于第二密码对要读出的数据进行解密并发送出去。其中,SD卡的安全功能的更详细内容可以参考SD卡协议,此处不再赘述。
通过上述说明不难看出,当通过本步骤激活SD卡的安全功能时,SD中保存的第二密码与SD卡插入的移动终端的IMEI码一一对应,由于IMEI码与移动终端一一对应,因此通过本步骤将移动终端和插入其中的SD卡绑定。
可选地,
根据预先设置的加密策略确定是否需要加密SD卡之后,本发明方法还可以包括:如果确定出不需要加密SD卡,允许普通访问SD卡。其中,普通访问SD卡为关闭SD卡的安全功能时访问SD卡。
相应地,
允许普通访问SD卡之后,该方法还可以包括:
如果用于配置是否加密SD卡的加密SD卡配置项改变为选中,则确定出需要加密SD卡,将第一密码发送给SD卡并保存为SD中的第二密码,以激活SD卡的安全功能,并允许安全访问SD卡。
相应地,
允许安全访问SD卡之后,本发明方法还可以包括:
如果用于配置是否加密SD卡的加密SD卡配置项改变为未选中,则删除SD卡中保存的第二密码,以关闭安全功能,并允许普通访问SD卡。
本步骤中,删除SD卡中保存的第二密码,以关闭安全功能可以包括:向SD卡发送与关闭安全功能相应的第四安全,触发SD卡删除SD卡中保存 的第二密码;其中,第四安全命令中包括用于身份验证的密码。本领域技术人员清楚的是,SD卡在根据第四命令删除第二密码之前首先根据第四命令携带的密码进行身份验证,如果该密码为第一密码,则通过身份验证,并关闭安全功能。
综上所述,在SD卡的安全功能激活时,只有激活该SD卡的移动终端能够关闭该SD卡的安全功能。
需要说明的是,本发明方法基于SD卡协议规定的串行外围设备接口(SPI接口)实现与SD卡通过安全命令进行通信。具体实现属于本领域技术人员的惯用技术手段,并不用于限定本发明的保护范围,这里不再赘述。
综上所述,安全命令至少包括第一安全命令、第二安全命令、第三安全命令和第四安全命令,安全命令的具体格式可以参考SD卡的相关协议,此处不再赘述。
图2为本发明保证SD卡安全的装置的组成结构示意图,如图2所示,包括安全检测单元201和安全访问管理单元202,其中,
安全检测单元201设置成:检测出插有SD卡时,确定SD卡是否已加密,当确定出SD卡已加密时,发送第一消息。
安全访问单元202设置成:接收到来自安全检测单元的第一消息时,将移动终端的本地存储器保存的第一密码发送给SD卡,以触发SD卡的安全功能中的身份验证,如果身份验证成功,则允许安全访问SD卡,否则不允许访问SD卡。
其中,安全访问SD卡为激活SD卡的安全功能时访问SD卡。
其中,第一密码是根据移动设备国际身份码IMEI码获取、保存在本地存储器中。
可选地,
安全检测单元201还设置成:当确定出SD卡未加密时,根据预先设置的加密策略确定是否需要加密SD卡,当确定出需要加密SD卡时,发送第二消息,当确定出不需要加密SD卡时,发送第三消息。
其中,加密策略包括:
如果用于配置是否加密SD卡的加密SD卡配置项为选中,则需要加密SD卡;或者,
如果用于配置移动终端是否启用安全功能的安全配置项为选中,且用于配置是否加密SD卡的加密SD卡配置项为选中,则需要加密SD卡。
其中,安全配置项为选中包括:用于配置是否启用图形密码的图案密码配置项、用于配置是否启用数字密码的数字密码配置项、以及用于配置是否启用个人识别密码(PIN)的PIN配置项中的至少一个配置项为选中。
可选地,
安全访问单元202还设置成:当接收到来自安全检测单元的第二消息时,将第一密码发送给SD卡并保存为SD中的第二密码,以激活SD卡的安全功能,并允许安全访问SD卡。
可选地,
安全访问单元202还设置成:当接收到来自安全检测单元的第三消息时,允许普通访问SD卡;其中,普通访问SD卡为关闭SD卡的安全功能时访问SD卡。
可选地,
安全检测单元201还设置成:当允许普通访问SD卡,且检测出用于配置是否加密SD卡的加密SD卡配置项改变为选中时,发送第二消息。
可选地,
安全检测单元201还设置成:当允许安全访问SD卡,且用于配置是否加密SD卡的加密SD卡配置项改变为未选中时,发送第四消息。
相应地,
安全访问单元202还设置成,当接收到来自安全检测单元的第四消息时,删除SD卡中保存的第二密码,以关闭安全功能,并允许普通访问SD卡;其中,普通访问SD卡为关闭SD卡的安全功能时访问SD卡。
本发明实施例还公开了一种保证安全数字存储卡SD卡安全的装置,包 括安全检测单元和安全访问单元,其中,
所述安全检测单元设置成:检测出所述SD卡已经被插入终端时,确定所述SD卡是否已加密,当确定出所述SD卡已加密时,发送第一消息给所述安全访问单元;
所述安全访问单元设置成:接收到来自所述安全检测单元的所述第一消息时,且接收到所述终端发来的所述终端的本地存储器保存的第一密码时,触发所述SD卡的安全功能中的身份验证功能;根据所述第一密码对所述终端进行身份验证,如果身份验证成功,则允许所述终端安全访问所述SD卡,如果身份验证失败,则不允许所述终端访问所述SD卡;
其中,安全访问所述SD卡为激活所述SD卡的安全功能时访问所述SD卡。
可选地,所述第一密码是根据移动设备国际身份码IMEI码获取、保存在所述本地存储器中的。
可选地,所述安全检测单元还设置成:
当确定出SD卡未加密时,根据预先设置的加密策略确定是否需要加密SD卡,当确定出需要加密SD卡时,向所述安全访问单元发送第二消息,当确定出不需要加密SD卡时,向所述安全访问单元发送第三消息;
其中,加密策略包括:
如果用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密所述SD卡;或者,
如果用于配置所述终端是否启用安全功能的安全配置项为选中,且用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密所述SD卡。
可选地,所述安全配置项为选中包括:用于配置是否启用图形密码的图案密码配置项、用于配置是否启用数字密码的数字密码配置项、以及用于配置是否启用个人识别密码PIN的PIN配置项中的至少一个配置项为选中。
可选地,所述安全访问单元还设置成:
当接收到来自所述安全检测单元的所述第二消息时,将所述第一密码发送给所述SD卡,以使得所述SD卡将所述第一密码保存为所述SD中的第二 密码,并激活所述SD卡的安全功能,并允许所述安全访问所述SD卡。
可选地,所述安全访问单元还设置成:当接收到来自所述安全检测单元的所述第三消息时,允许所述终端普通访问所述SD卡;
其中,普通访问所述SD卡为关闭所述SD卡的安全功能时访问所述SD卡。
可选地,所述安全检测单元还设置成:当允许所述终端普通访问所述SD卡,且检测出用于配置是否加密所述SD卡的加密SD卡配置项改变为选中时,向所述安全访问单元发送所述第二消息;
所述安全访问单元还设置成:当接收到来自所述安全检测单元的所述第二消息时,将所述第一密码发送给所述SD卡,以使得所述SD卡将所述第一密码保存为SD中的第二密码,并激活所述SD卡的安全功能,并允许所述终端安全访问SD卡。
可选地,所述检测单元还设置成:当允许所述终端安全访问SD卡,且用于配置是否加密所述SD卡的加密SD卡配置项改变为未选中时,向所述安全访问单元发送第四消息;
所述安全访问单元还设置成,当接收到来自所述安全检测单元的所述第四消息时,删除所述SD卡中保存的第二密码,以关闭所述安全功能,并允许所述终端普通访问SD卡;
其中,普通访问SD卡为关闭SD卡的安全功能时访问SD卡。
可选地,所述检测单元还设置成:当允许所述终端安全访问SD卡,且用于配置是否加密所述SD卡的加密SD卡配置项改变为未选中时,向所述安全访问单元发送第四消息;
所述安全访问单元还设置成,当接收到来自所述安全检测单元的所述第四消息时,删除所述SD卡中保存的第二密码,以关闭所述安全功能,并允许所述终端普通访问SD卡。
该装置可以独立于终端和SD卡而存在,也可以位于现有的终端或SD卡中,与现有的终端或SD卡融为一体。
本发明实施例还公开了一种计算机程序,包括程序指令,当该程序指令被计算机执行时,使得该计算机可执行上述任意的保证SD卡安全的方法。
本发明还公开了一种载有所述计算机程序的载体。
虽然本发明所揭露的实施方式如上所述,但所述的内容仅为便于理解本发明而采用的实施方式,并非用以限定本发明。任何本发明所属领域内的技术人员,在不脱离本发明所揭露的精神和范围的前提下,可以在实施的形式及细节上进行任何的修改与变化,但本发明的专利保护范围,仍须以所附的权利要求书所界定的范围为准。
工业实用性
通过本发明技术方案,一方面,当出现已加密的SD卡被盗取的情况时,由于盗取者无法获取第一密码并通过SD卡的安全功能中的身份验证,这样有效避免了通过其他设备读取SD卡中数据,有效降低了SD卡中数据破解的可能性;另一方面,当出现上述情况时,已加密的SD卡的安全功能保证了除非以物理方式破坏SD卡,不能以格式化或全部删除数据的方式恶意破坏SD卡中数据,进一步降低了恶意破坏SD卡中数据的可能性。从上述两方面的有益效果,不难看出本发明技术方案有效提高了SD卡中数据的安全性,较好提高了移动终端的安全功能的用户体验。因此本发明具有很强的工业实用性。

Claims (15)

  1. 一种保证安全数字存储卡SD卡安全的方法,包括:
    检测出终端插有SD卡时,确定所述SD卡是否已加密;
    如果确定出SD卡已加密,将所述终端的本地存储器保存的第一密码发送给所述SD卡,以触发所述SD卡的安全功能中的身份验证功能;
    根据所述第一密码对所述终端进行身份验证,如果身份验证成功,则允许所述终端安全访问所述SD卡;如果身份验证失败,则不允许所述终端访问所述SD卡;
    其中,安全访问所述SD卡为激活所述SD卡的安全功能时访问所述SD卡。
  2. 根据权利要求1所述的保证SD卡安全的方法,其中,所述第一密码是根据移动设备国际身份码IMEI码获取、保存在所述本地存储器中的。
  3. 根据权利要求1所述的保证SD卡安全的方法,其中,所述确定SD卡是否已加密的步骤之后,该方法还包括:
    如果确定出所述SD卡未加密,根据预先设置的加密策略确定是否需要加密SD卡;
    其中,加密策略包括:
    如果用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密SD卡;或者,
    如果用于配置所述终端是否启用安全功能的安全配置项为选中,且用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密SD卡。
  4. 根据权利要求3所述的保证SD卡安全的方法,其中,所述安全配置项为选中包括:用于配置是否启用图形密码的图案密码配置项、用于配置是否启用数字密码的数字密码配置项、以及用于配置是否启用个人识别密码PIN的PIN配置项中的至少一个配置项为选中。
  5. 根据权利要求3所述的保证SD卡安全的方法,其中,所述根据预先设置的加密策略确定是否需要加密SD卡的步骤之后,该方法还包括:
    如果确定出需要加密SD卡,将所述第一密码发送给所述SD卡,所述SD卡将所述第一密码保存为SD中的第二密码,以激活所述SD卡的安全功能,并允许所述终端安全访问所述SD卡。
  6. 根据权利要求3所述的保证SD卡安全的方法,其中,所述根据预先设置的加密策略确定是否需要加密SD卡的步骤之后,该方法还包括:
    如果确定出不需要加密所述SD卡,则允许普通访问所述SD卡;其中,普通访问所述SD卡为关闭所述SD卡的安全功能时访问所述SD卡。
  7. 根据权利要求6所述的保证SD卡安全的方法,其中,所述允许普通访问所述SD卡之后,该方法还包括:
    如果用于配置是否加密所述SD卡的加密SD卡配置项改变为选中,则确定出需要加密SD卡,将所述第一密码发送给所述SD卡,所述SD卡将所述第一密码保存为所述SD中的第二密码,以激活所述SD卡的安全功能,并允许所述终端安全访问所述SD卡。
  8. 根据权利要求1-5中任一项所述的保证SD卡安全的方法,其中,所述允许所述终端安全访问所述SD卡的步骤之后,该方法还包括:
    如果用于配置是否加密所述SD卡的加密SD卡配置项改变为未选中,则删除所述SD卡中保存的第二密码,以关闭所述安全功能,并允许所述终端普通访问所述SD卡;其中,普通访问SD卡为关闭SD卡的安全功能时访问所述SD卡。
  9. 根据权利要求6或7所述的保证SD卡安全的方法,其中,所述允许所述终端安全访问所述SD卡的步骤之后,该方法还包括:
    如果用于配置是否加密所述SD卡的加密SD卡配置项改变为未选中,则删除所述SD卡中保存的第二密码,以关闭所述安全功能,并允许所述终端普通访问所述SD卡。
  10. 一种保证安全数字存储卡SD卡安全的装置,包括安全检测单元和安全访问单元,其中,
    所述安全检测单元设置成:检测出所述SD卡已经被插入终端时,确定所述SD卡是否已加密,当确定出所述SD卡已加密时,发送第一消息给所述 安全访问单元;
    所述安全访问单元设置成:接收到来自所述安全检测单元的所述第一消息时,且接收到所述终端发来的所述终端的本地存储器保存的第一密码时,触发所述SD卡的安全功能中的身份验证功能;根据所述第一密码对所述终端进行身份验证,如果身份验证成功,则允许所述终端安全访问所述SD卡,如果身份验证失败,则不允许所述终端访问所述SD卡;
    其中,安全访问所述SD卡为激活所述SD卡的安全功能时访问所述SD卡。
  11. 根据权利要求10所述的保证SD卡安全的装置,其中,所述第一密码是根据移动设备国际身份码IMEI码获取、保存在所述本地存储器中的。
  12. 根据权利要求10所述的保证SD卡安全的装置,其中:
    所述安全检测单元还设置成:
    当确定出SD卡未加密时,根据预先设置的加密策略确定是否需要加密SD卡,当确定出需要加密SD卡时,向所述安全访问单元发送第二消息,当确定出不需要加密SD卡时,向所述安全访问单元发送第三消息;
    其中,加密策略包括:
    如果用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密所述SD卡;或者,
    如果用于配置所述终端是否启用安全功能的安全配置项为选中,且用于配置是否加密所述SD卡的加密SD卡配置项为选中,则需要加密所述SD卡。
  13. 根据权利要求12所述的保证SD卡安全的装置,其中,所述安全配置项为选中包括:用于配置是否启用图形密码的图案密码配置项、用于配置是否启用数字密码的数字密码配置项、以及用于配置是否启用个人识别密码PIN的PIN配置项中的至少一个配置项为选中。
  14. 根据权利要求12所述的保证SD卡安全的装置,其中:
    所述安全访问单元还设置成:
    当接收到来自所述安全检测单元的所述第二消息时,将所述第一密码发 送给所述SD卡,以使得所述SD卡将所述第一密码保存为所述SD中的第二密码,并激活所述SD卡的安全功能,并允许所述安全访问所述SD卡。
  15. 根据权利要求12所述的保证SD卡安全的装置,其中:
    所述安全访问单元还设置成:当接收到来自所述安全检测单元的所述第三消息时,允许所述终端普通访问所述SD卡;
    其中,普通访问所述SD卡为关闭所述SD卡的安全功能时访问所述SD卡。
PCT/CN2014/092708 2014-09-30 2014-12-01 一种保证sd卡安全的方法和装置 WO2015131585A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410525026.8A CN105530641A (zh) 2014-09-30 2014-09-30 一种移动终端中实现sd卡安全管理的方法和装置
CN201410525026.8 2014-09-30

Publications (1)

Publication Number Publication Date
WO2015131585A1 true WO2015131585A1 (zh) 2015-09-11

Family

ID=54054464

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/092708 WO2015131585A1 (zh) 2014-09-30 2014-12-01 一种保证sd卡安全的方法和装置

Country Status (2)

Country Link
CN (1) CN105530641A (zh)
WO (1) WO2015131585A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106971122A (zh) * 2017-02-06 2017-07-21 深圳市金立通信设备有限公司 安全控制方法、及终端
CN107145308B (zh) * 2017-05-04 2021-06-22 惠州Tcl移动通信有限公司 移动终端、及其sd卡操作控制方法、系统、存储装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101902740A (zh) * 2010-07-09 2010-12-01 武汉天喻信息产业股份有限公司 基于可认证sd/mmc卡的ota认证方法
CN102291715A (zh) * 2010-06-18 2011-12-21 黄金富 保护手机内个人资料的方法和相应系统
US20120252531A1 (en) * 2011-03-31 2012-10-04 Verizon Patent And Licensing Inc. Provisioning mobile terminals with a trusted key for generic bootstrap architecutre
CN103916841A (zh) * 2012-12-30 2014-07-09 北京握奇数据系统有限公司 一种sd卡和外接设备进行绑定和校验的方法

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8566611B2 (en) * 2007-08-28 2013-10-22 Panasonic Corporation Electronic device, unlocking method, and program
GB2466284B (en) * 2008-12-18 2011-01-12 Gigflash Ltd Method of unlocking portable memory device
CN103530580A (zh) * 2013-09-13 2014-01-22 华为终端有限公司 终端安全数据存储卡sd卡安全管理方法、装置及终端
CN103699853B (zh) * 2013-12-27 2017-01-04 北京大唐智能卡技术有限公司 一种智能sd卡及其控制系统及方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102291715A (zh) * 2010-06-18 2011-12-21 黄金富 保护手机内个人资料的方法和相应系统
CN101902740A (zh) * 2010-07-09 2010-12-01 武汉天喻信息产业股份有限公司 基于可认证sd/mmc卡的ota认证方法
US20120252531A1 (en) * 2011-03-31 2012-10-04 Verizon Patent And Licensing Inc. Provisioning mobile terminals with a trusted key for generic bootstrap architecutre
CN103916841A (zh) * 2012-12-30 2014-07-09 北京握奇数据系统有限公司 一种sd卡和外接设备进行绑定和校验的方法

Also Published As

Publication number Publication date
CN105530641A (zh) 2016-04-27

Similar Documents

Publication Publication Date Title
KR102399582B1 (ko) 모바일 디바이스를 사용한 시스템 액세스
US11706033B2 (en) Secure distributed information system
US8595810B1 (en) Method for automatically updating application access security
US20170063827A1 (en) Data obfuscation method and service using unique seeds
KR101356282B1 (ko) 이동 장치로부터 컴퓨터로의 안전한 원격 웨이크, 부트, 및 로그인을 하기 위한 방법 및 시스템
CN112513857A (zh) 可信执行环境中的个性化密码安全访问控制
US9225696B2 (en) Method for different users to securely access their respective partitioned data in an electronic apparatus
CN108763917B (zh) 一种数据加解密方法及装置
EP2628133B1 (en) Authenticate a fingerprint image
WO2013182154A1 (zh) 一种对通讯终端上应用程序加、解密的方法、系统和终端
WO2017063517A1 (zh) 一种近距离通信的建立方法和装置
WO2018205456A1 (zh) 密码输入方法、计算机设备和存储介质
WO2015180689A1 (zh) 验证信息的获取方法及装置
WO2015117523A1 (zh) 访问控制方法及装置
CN107958155A (zh) 一种系统初始化方法和装置
Hufstetler et al. Nfc unlock: Secure two-factor computer authentication using nfc
EP2840818B1 (en) Method and device for information security management of mobile terminal, and mobile terminal
US11405782B2 (en) Methods and systems for securing and utilizing a personal data store on a mobile device
CN109977039A (zh) 硬盘加密密钥存储方法、装置、设备及可读存储介质
US20170026385A1 (en) Method and system for proximity-based access control
US20110154436A1 (en) Provider Management Methods and Systems for a Portable Device Running Android Platform
EP3507998A1 (en) Secure messaging session
EP2985712B1 (en) Application encryption processing method, apparatus, and terminal
CN108701200B (zh) 改善的存储系统
WO2015131585A1 (zh) 一种保证sd卡安全的方法和装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14884643

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14884643

Country of ref document: EP

Kind code of ref document: A1