IP Library › Granted Patent US 12,526,137
Granted Patent B2
US 12,526,137 · App. 18/003,265 · Granted Jan 13, 2026

Method for saving ciphertext and apparatus

Inventors: Hongjian Yu (Shenzhen, CN); Shuang Li (Shenzhen, CN); Fei Wang (Shenzhen, CN)
Assignee: HONOR DEVICE CO., LTD.
H04L9/14G06F21/79
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,526,137
App. No.
18/003,265
Granted
Jan 13, 2026
Kind
B2
Abstract

This application provides a method for saving a ciphertext and an apparatus. The method includes: obtaining an encryption instruction, where the encryption instruction instructs to encrypt a file in an external memory; obtaining an eigenvalue of a first account identifier based on the encryption instruction; encrypting a first key by using the eigenvalue of the first account identifier to generate a first ciphertext, where the first key is used to encrypt a second key, and the second key is used to encrypt a first file in the external memory; encrypting the eigenvalue of the first account identifier to generate a second ciphertext; and storing the first ciphertext and the second ciphertext in a non-erasable partition.

Claims (119)

1 . A chip, comprising:

at least one processor; and

at least one non-transitory storage medium coupled to the at least one processor, the at least one non-transitory storage medium storing instructions that, when executed by the at least one processor, cause the chip to perform the following:

displaying an encryption setting interface of an external memory;

receiving a first operation that is performed by a user on the encryption setting interface;

encrypting a file in the external memory in response to the first operation;

receiving a second operation of the user;

displaying a factory reset setting interface in response to the second operation;

receiving a third operation that is performed by the user on the factory reset setting interface;

performing a factory reset in response to the third operation;

displaying an account verification interface;

receiving verification information that is input by the user on the account verification interface; and

when the verification information is verified, and when an operation in which the user accesses the file in the external memory is received, decrypting the file that is encrypted in the external memory;

wherein receiving the first operation that is performed by the user on the encryption setting interface comprises:

obtaining an encryption instruction, wherein the encryption instruction instructs to encrypt the file in the external memory; and

wherein the instructions, when executed by the at least one processor, cause the chip to further perform:

obtaining an eigenvalue of a first account identifier based on the encryption instruction;

encrypting a first key by using the eigenvalue of the first account identifier to generate a first ciphertext, wherein the first key is used to encrypt a second key, and the second key is used to encrypt the file in the external memory;

encrypting the eigenvalue of the first account identifier to generate a second ciphertext; and

storing the first ciphertext and the second ciphertext in a non-erasable partition.

2 . The chip according to claim 1 , wherein when the at least one processor executes the instructions, the chip is caused to further perform the following steps:

receiving a fourth operation that is performed by the user on the encryption setting interface;

encrypting the file in the external memory in response to the fourth operation;

receiving a fifth operation of the user;

displaying a user reset setting interface in response to the fifth operation;

receiving a sixth operation that is performed by the user on the user reset setting interface;

performing a user reset in response to the sixth operation;

displaying a lock screen password verification interface;

receiving a lock screen password that is input by the user on the lock screen password verification interface; and

when the lock screen password is verified, and when an operation in which the user accesses the file in the external memory is received, decrypting the file that is encrypted in the external memory.

3 . The chip according to claim 1 wherein when the at least one processor executes the instructions, the chip is caused to further perform the following steps:

obtaining indication information for switching an account;

verifying the first account identifier based on the indication information;

obtaining an eigenvalue of a second account identifier after the first account identifier is verified; and

updating the first ciphertext and the second ciphertext based on the eigenvalue of the second account identifier.

4 . The chip according to claim 1 wherein before the decrypting the encrypted file in the external memory, when the at least one processor executes the instructions, the chip is caused to further perform the following steps:

verifying the first account identifier based on the verification information after the factory reset is completed; and

when the first account identifier is verified successfully, decrypting the first ciphertext and the second ciphertext to generate the first key.

5 . The chip according to claim 4 , wherein the verifying the first account identifier based on the verification information comprises:

verifying the first account identifier based on the verification information, when a factory reset protection (FRP) state has been triggered.

6 . The chip according to claim 4 , wherein when the at least one processor executes the instructions, the chip is caused to further perform the following steps:

encrypting the first key by using an empty auth to generate a third ciphertext;

encrypting the empty auth to generate a fourth ciphertext; and

storing the third ciphertext and the fourth ciphertext in the non-erasable partition.

7 . The chip according to claim 6 , wherein when the at least one processor executes the instructions, the chip is caused to further perform the following steps:

copying the third ciphertext and the fourth ciphertext from the non-erasable partition to an erasable partition;

generating the first key based on the third ciphertext and the fourth ciphertext in the erasable partition; and

decrypting, based on the first key, the first file that is encrypted in the external memory.

8 . The chip according to claim 1 wherein the performing a factory reset in response to the third operation comprises:

obtaining a factory reset instruction that is triggered by the third operation on the factory reset setting interface; and

formatting data in the erasable partition based on the factory reset instruction.

9 . The chip according to claim 1 wherein the encrypting a first key by using the eigenvalue of the first account identifier comprises:

invoking a key management module to encrypt the first key by using the eigenvalue of the first account identifier; and

wherein the encrypting the eigenvalue of the first account identifier comprises:

invoking the key management module to encrypt the eigenvalue of the first account identifier.

10 . The chip according to claim 1 wherein the storing the first ciphertext and the second ciphertext in a non-erasable partition comprises:

invoking a trusted execution environment application programming interface to store the first ciphertext and the second ciphertext in the non-erasable partition.

11 . The chip according to claim 1 wherein the first key is further used to encrypt a third key, and the third key is used to encrypt a second file that is encrypted in the external memory.

12 . The chip according to claim 1 wherein when the at least one processor executes the instructions, the chip is caused to further perform the following steps:

obtaining an eigenvalue of a lock screen password based on the encryption instruction;

encrypting the first key by using the eigenvalue of the lock screen password to generate a fifth ciphertext;

encrypting the eigenvalue of the lock screen password to generate a sixth ciphertext; and

storing the fifth ciphertext and the sixth ciphertext in the erasable partition;

wherein the encrypting the first key by using the eigenvalue of the lock screen password comprises:

invoking a key management module to encrypt the first key by using the eigenvalue of the lock screen password; and

wherein the encrypting the eigenvalue of the lock screen password comprises:

invoking the key management module to encrypt the eigenvalue of the lock screen password.

13 . The chip according to claim 12 , wherein when the at least one processor executes the instructions, the chip is caused to further perform the following steps:

obtaining a user reset instruction that is triggered by a setting interface; and

backing up the fifth ciphertext and the sixth ciphertext to the non-erasable partition based on the user reset instruction.

14 . The chip according to claim 13 , wherein the backing up the fifth ciphertext and the sixth ciphertext to the non-erasable partition based on the user reset instruction comprises:

decrypting the first key from the fifth ciphertext and the sixth ciphertext based on the user reset instruction;

encrypting the first key by using an empty auth to generate a seventh ciphertext;

encrypting the empty auth to generate an eighth ciphertext; and

storing the seventh ciphertext and the eighth ciphertext in the non-erasable partition.

15 . The chip according to claim 14 , wherein when the at least one processor executes the instructions, the chip is caused to further perform the following steps:

copying the seventh ciphertext and the eighth ciphertext from the non-erasable partition to the erasable partition after a user reset is completed;

decrypting the first key from the seventh ciphertext and the eighth ciphertext in the erasable partition; and

decrypting, based on the first key, the first file that is encrypted in the external memory.

16 . The chip according to claim 12 , wherein the erasable partition is a data partition, and the eigenvalue of the lock screen password is a hash value of the lock screen password.

17 . The chip according to claim 1 wherein the non-erasable partition is a secure storage partition, and the eigenvalue of the first account identifier is a hash value of the first account identifier.

18 . A method for saving a ciphertext, comprising:

displaying an encryption setting interface of an external memory;

receiving a first operation that is performed by a user on the encryption setting interface;

encrypting a file in the external memory in response to the first operation, wherein encrypting the file in the external memory comprises:

obtaining an encryption instruction, wherein the encryption instruction instructs to encrypt the file in the external memory;

obtaining an eigenvalue of a first account identifier based on the encryption instruction;

encrypting a first key by using the eigenvalue of the first account identifier to generate a first ciphertext, wherein the first key is used to encrypt a second key, and the second key is used to encrypt the file in the external memory;

encrypting the eigenvalue of the first account identifier to generate a second ciphertext; and

storing the first ciphertext and the second ciphertext in a non-erasable partition;

receiving a second operation of the user;

displaying a factory reset setting interface in response to the second operation;

receiving a third operation that is performed by the user on the factory reset setting interface;

performing a factory reset in response to the third operation;

displaying an account verification interface;

receiving verification information that is input by the user on the account verification interface; and

when the verification information is verified, and when an operation in which the user accesses the file in the external memory is received, decrypting the file that is encrypted in the external memory.

19 . The method according to claim 18 , wherein:

the displaying an account verification interface comprises displaying the account verification interface when a factory reset protection (FRP) state has been triggered; and

the method further comprises, after the verification information is verified:

encrypting the first key by using an empty auth to generate a third ciphertext;

encrypting the empty auth to generate a fourth ciphertext; and

storing the third ciphertext and the fourth ciphertext in the non-erasable partition.

20 . A non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the processor is enabled to perform operations comprising:

displaying an encryption setting interface of an external memory;

receiving a first operation that is performed by a user on the encryption setting interface;

encrypting a file in the external memory in response to the first operation, wherein encrypting the file in the external memory comprises:

obtaining an encryption instruction, wherein the encryption instruction instructs to encrypt the file in the external memory;

obtaining an eigenvalue of a first account identifier based on the encryption instruction;

encrypting a first key by using the eigenvalue of the first account identifier to generate a first ciphertext, wherein the first key is used to encrypt a second key, and the second key is used to encrypt the file in the external memory;

encrypting the eigenvalue of the first account identifier to generate a second ciphertext; and

storing the first ciphertext and the second ciphertext in a non-erasable partition;

receiving a second operation of the user;

displaying a factory reset setting interface in response to the second operation;

receiving a third operation that is performed by the user on the factory reset setting interface;

performing a factory reset in response to the third operation;

displaying an account verification interface;

receiving verification information that is input by the user on the account verification interface; and

when the verification information is verified, and when an operation in which the user accesses the file in the external memory is received, decrypting the file that is encrypted in the external memory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2024
From: YU, HONGJIAN; LI, SHUANG; WANG, FEI
To: HONOR DEVICE CO., LTD.
Reel/Frame 066654/0841 →
Priority Claims (1)
CN 202110566480.8 · May 24, 2021 · national
Continuity (1)
Related Publication 20230254143A1 · Aug 10, 2023
References Cited (26)
US 7729690B1 · Huang et al. · 2010 [cited by applicant]
US 8239679B2 · Shan · 2012 [cited by applicant]
US 10164955B1 · Michael et al. · 2018 [cited by applicant]
US 20120185759A1 · Helen et al. · 2012 [cited by applicant]
US 20140373184A1 · Mahaffey · 2014 [cited by examiner]
US 20170337390A1 · Hamilton · 2017 [cited by examiner]
US 20180046805A1 · Le Roy et al. · 2018 [cited by applicant]
US 20180091301A1 · David et al. · 2018 [cited by applicant]
US 20180324162A1 · Teshome · 2018 [cited by examiner]
US 20190244186A1 · Guo · 2019 [cited by examiner]
US 20200151356A1 · Kurt · 2020 [cited by applicant]
US 20200285775A1 · Zankharia · 2020 [cited by examiner]
US 20210224393A1 · Ko · 2021 [cited by examiner]
US 20210325948A1 · Lee · 2021 [cited by examiner]
US 20220147641A1 · Fang · 2022 [cited by examiner]
US 20220156391A1 · Fang · 2022 [cited by examiner]
CN 101075874A · 2007 [cited by applicant]
CN 201518127U · 2010 [cited by applicant]
CN 105809045A · 2016 [cited by applicant]
CN 111614698A · 2020 [cited by applicant]
CN 111966373A · 2020 [cited by applicant]
CN 112262548A · 2021 [cited by applicant]
CN 112560058A · 2021 [cited by applicant]
CN 112632593A · 2021 [cited by applicant]
CN 113408016A · 2021 [cited by applicant]
Istorage Limited, “Non-Proprietary Security Policy,” Datashur; Secure USB Flash Drive; datAshur Pro 3.0; FIPS 140-2 Security Policy Version 1.2; Jul. 14, 2017; 14 pages, XP093012314; Retrieved from the internet, URL:htt… [cited by applicant]