Equipment authentication method and electronic equipment
By using device credential slicing and one-time credentials in device authentication, the requirements of existing device authentication methods for security environment and storage space are solved, and safe and convenient authentication of various electronic devices is achieved, adapting to the interconnection and interoperability of devices of different types and network states.
Patent Information
- Application Number
- CN202410405314.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-03
- Publication Date
- 2025-10-14
AI Technical Summary
Existing device authentication methods have high requirements on the security environment and storage space of electronic devices, cannot adapt to electronic devices of different types and network connection status, and have problems such as account credential leakage and difficulty in implementing the authorization process.
The device credential slices of the second electronic device are obtained through the first electronic device and spliced together to complete the authentication, reducing the execution environment and storage space requirements for the second electronic device, supporting the authentication of different types of devices, and simplifying the authentication process through one-time credentials and PIN codes.
It achieves secure authentication between devices that do not have a TEE environment and have limited storage space, improves the authentication success rate and flexibility, and adapts to the interconnection and interoperability of various device types.
Smart Images

Figure CN120786368A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of Internet, and particularly relates to a device authentication method and an electronic device. BACKGROUND
[0002] With the operating system compatible with multiple types of electronic devices, mutual trust authentication between electronic devices becomes a prerequisite for secure and reliable transmission. The main method for authentication between electronic devices is to exchange authentication credentials between electronic devices, and after determining that the authentication of the two ends of the electronic devices in communication is completed, the secure encryption transmission is realized based on the authentication result, thereby ensuring the security of the communication between the electronic devices.
[0003] Two electronic devices can perform device authentication when logging into the same user account. The electronic device can obtain an account credential bound to the user account from the server, which can be, for example, a preshared key (PSK). The electronic devices can pass the account credential and authenticate the received account credential based on the server public key. After the device authentication is passed, the electronic devices can access resources to each other.
[0004] In the above device authentication process, the electronic device needs to have a trusted execution environment (TEE) to receive the account credential issued by the server, and the electronic device needs to have sufficient storage space to store the account credential, and the security of the electronic device is required to prevent the account credential from being leaked. It can be seen that the current device authentication method is limited and not flexible enough. SUMMARY
[0005] The present application provides a device authentication method and an electronic device to provide a safe and convenient device authentication scheme.
[0006] In a first aspect, the present application provides a device authentication method, which can be executed by a first electronic device. The method comprises: receiving an access request sent by a second electronic device; sending a first authentication request message to the second electronic device; receiving first information sent by the second electronic device, the first information being related to the device type of the second electronic device; sending a second authentication request message to a server, the second authentication request message being used to request to obtain a device credential of the second electronic device, the second request message comprising the first information; receiving device credential information of the second electronic device sent by the server, the device credential information of the second electronic device being determined by the server according to the first information; and performing device authentication on the second electronic device according to the device credential information of the second electronic device.
[0007] In the above method, when the first electronic device needs to authenticate the second electronic device, the first information sent by the second electronic device to the first electronic device is information used to obtain the device credential of the second electronic device, and the second electronic device stores the first information used to obtain the device credential, so that the requirements on the execution environment and storage space of the second electronic device are lower, thereby reducing the performance requirements on the second electronic device in the device authentication process, providing a more universal device authentication scheme, and realizing the interconnection and intercommunication between various electronic devices.
[0008] In a possible design, the device credential information of the second electronic device is a first slice of the device credential of the second electronic device; and the method further includes: receiving the second slice of the device credential of the second electronic device sent by the second electronic device.
[0009] The device authentication of the second electronic device according to the device credential information of the second electronic device includes: splicing the first slice of the device credential of the second electronic device and the second slice of the device credential of the second electronic device to obtain the complete device credential of the second electronic device; and performing device authentication of the second electronic device according to the complete device credential of the second electronic device.
[0010] With this design, the first electronic device can obtain the first slice and the second slice of the device credential of the second electronic device from the server and the second electronic device respectively, and splice the first slice and the second slice to obtain the complete device credential of the second electronic device, so that the second electronic device does not need to store the complete device credential and still can implement device authentication of the second electronic device by other electronic devices.
[0011] In a possible design, the device credential information of the second electronic device is a first slice of the device credential of the second electronic device.
[0012] The device authentication of the second electronic device according to the device credential information of the second electronic device includes: sending the first slice of the device credential of the second electronic device to the second electronic device, receiving the complete device credential of the second electronic device sent by the second electronic device, the complete device credential of the second electronic device being obtained by the second electronic device by splicing the first slice of the device credential of the second electronic device and a second slice of the device credential of the second electronic device, and performing device authentication of the second electronic device according to the complete device credential of the second electronic device.
[0013] Through the design, the second electronic device can store a second slice of the device credential of the second electronic device without storing the complete device credential, the first electronic device can assist the second electronic device in obtaining a first slice of the device credential of the second electronic device from the server, the second electronic device splices the complete device credential of the second electronic device according to the stored second slice and the received first slice, the second electronic device sends the complete device credential of the second electronic device to the first electronic device, so that the first electronic device performs device authentication on the second electronic device, and the scheme has lower requirements on the execution environment of the second electronic device and improves the success rate of device authentication.
[0014] In a possible design, the first information includes at least one of a device identifier of the second electronic device, a device credential index value of the second electronic device, and a second slice of the device credential of the second electronic device.
[0015] Through the design, the first information in the present application can be flexibly set as various types of information that have a corresponding relationship with the device credential of the second electronic device, thereby providing various ways of obtaining the device credential of the second electronic device.
[0016] In a possible design, the device credential information of the second electronic device is the complete device credential of the second electronic device.
[0017] Through the design, the first electronic device can further obtain the complete device credential of the second electronic device from the server according to the first information, so as to reduce the number of communications between the first electronic device and the second electronic device and improve the efficiency of device authentication.
[0018] In a possible design, the second electronic device is an electronic device without a trusted execution environment (TEE).
[0019] Through the design, the device authentication method provided in the present application can be used for device authentication of an electronic device without a TEE, and interconnection and intercommunication between the electronic device without a TEE and other electronic devices are implemented.
[0020] In a possible design, the method further includes: sending an access request to the second electronic device; receiving a third authentication request message sent by the second electronic device; and sending a device credential of the first electronic device to the second electronic device based on the device type of the second electronic device, where the device credential of the first electronic device is used for device authentication of the second electronic device on the first electronic device.
[0021] Through the design, the first electronic device can determine the device credential of the first electronic device for device authentication according to the device type of the second electronic device, so that device authentication is performed using different device credentials for different types of electronic devices, device authentication between multiple types of electronic devices is achieved, and interworking of multiple types of electronic devices is further achieved.
[0022] In a possible design, the device credential of the first electronic device sent to the second electronic device based on the device type of the second electronic device includes: determining a first device credential type corresponding to the device type of the second electronic device according to a preset correspondence between device types of receiving-end electronic devices and types of device credentials; and sending the device credential of the first electronic device to the second electronic device according to the first device credential type.
[0023] Through the design, the first electronic device can prestore the correspondence between the device types of receiving-end electronic devices and the types of device credentials, so that when the first electronic device sends the device credential of the first electronic device to the second electronic device, the first electronic device can determine the device credential of the first electronic device sent to the second electronic device according to the device type of the second electronic device, to ensure that the second electronic device can perform device authentication on the first electronic device based on the received device credential of the first electronic device, and improve the success rate of device authentication.
[0024] In a possible design, the device credential of the first electronic device is a one-time credential or a personal identification number (PIN) code.
[0025] Through the design, the device credential of the first electronic device can be designed as a one-time credential. For example, when the second electronic device is a public device, the first electronic device can send a one-time credential of the first electronic device to the second electronic device, to prevent the risk of leakage of the device credential of the public device. In the present application, the device credential of the first electronic device can also be designed as a PIN code. For example, when the second electronic device is a low-sensitivity device without a screen, the first electronic device can send the PIN code as the device credential of the first electronic device to the second electronic device, to simplify the device authentication process and improve the success rate of device authentication.
[0026] In a possible design, the method further includes: receiving a first request message sent by a third electronic device, where the first request message is used to request the first electronic device to assist the third electronic device in obtaining a device credential of the third electronic device; sending a second request message to the server, where the second request message is used to request the server to obtain the device credential of the third electronic device; receiving the device credential of the third electronic device sent by the server; and sending the device credential of the third electronic device to the third electronic device.
[0027] Through the design, for a third electronic device that cannot directly obtain device credentials from a server, the first electronic device can assist the third electronic device in obtaining device credentials of the third electronic device from the server, so that the third electronic device can obtain and store its own device credentials, and other electronic devices can perform device authentication on the third electronic device, and then the third electronic device can access other electronic devices.
[0028] In a second aspect, the present application provides an electronic device, which includes a plurality of functional modules; the plurality of functional modules interact to implement the method performed by the first electronic device in the first aspect and each of the implementations thereof. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be combined or divided based on specific implementation.
[0029] In a third aspect, the present application provides an electronic device, which includes at least one processor and at least one memory, and the at least one memory stores computer program instructions. When the electronic device is running, the at least one processor executes the method performed by the first electronic device in the first aspect and each of the implementations thereof.
[0030] In a fourth aspect, the present application further provides a computer program product containing instructions, which, when executed on a computer, causes the computer to perform the method performed by the first electronic device in any of the aspects and each of the implementations thereof.
[0031] In a fifth aspect, the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed on a computer, the computer program causes the computer to perform the method performed by the first electronic device in any of the aspects and each of the implementations thereof.
[0032] In a sixth aspect, the present application further provides a chip, which is used to read a computer program stored in a memory and execute the method performed by the first electronic device in any of the aspects and each of the implementations thereof.
[0033] In a seventh aspect, the present application further provides a chip system, which includes a processor for supporting a computer device to implement the method performed by the first electronic device in any of the aspects and each of the implementations thereof. In a possible design, the chip system further includes a memory for saving necessary programs and data of the computer device. The chip system can be composed of a chip, or can include a chip and other discrete devices. BRIEF DESCRIPTION OF DRAWINGS
[0034] Figure 1 A schematic diagram of a method for device authentication based on a user account;
[0035] Figure 2 A schematic diagram of a device authentication scenario provided for an embodiment of the present application;
[0036] Figure 3 A structural schematic diagram of an electronic device provided for an embodiment of the present application;
[0037] Figure 4 A software structural block diagram of an electronic device provided for an embodiment of the present application;
[0038] Figure 5 A schematic diagram of a device credential issuing manner provided for an embodiment of the present application;
[0039] Figure 6 A schematic diagram of a device authentication provided for an embodiment of the present application;
[0040] Figure 7 A schematic diagram of a device authentication method provided for an embodiment of the present application;
[0041] Figure 8 A schematic diagram of a device authentication method provided for an embodiment of the present application;
[0042] Figure 9 A schematic diagram of still another device authentication method provided for an embodiment of the present application;
[0043] Figure 10 A flowchart of a device authentication method provided for an embodiment of the present application. DETAILED DESCRIPTION
[0044] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the drawings. In the description of the embodiments of the present application, the terms “first” and “second” are used only for the purpose of description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features with “first” and “second” can explicitly or implicitly include one or more of the features.
[0045] It should be understood that "at least one" in the embodiments of the present application means one or more, and "multiple" means two or more. The "and / or" describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it. "At least one of the following" or the like means any combination of these items, including any combination of single item or multiple items. For example, at least one of a, b or c can represent a, b, c, a and b, a and c, b and c, or a, b and c, where a, b and c can be single or multiple.
[0046] With the development of the operating system, the operating system can be compatible with multiple types of electronic devices, such as the development of the HarmonyOS With the development of the ecological system, more and more electronic devices can be compatible, and mutual trust authentication between electronic devices becomes a prerequisite for secure and reliable transmission.
[0047] Figure 1 A schematic diagram of a method for device authentication based on a user account. Figure 1 In the first electronic device and the second electronic device are taken as examples for device authentication, Figure 1 The server in the method can be a server providing authentication cloud service, such as an electronic device manufacturer server, an application server, etc. For reference Figure 1 The user account A has been logged in the second electronic device. The second electronic device can authenticate the first electronic device, which can include the following steps:
[0048] Step 1: The first electronic device logs in the user account A or a user account B associated with the user account A.
[0049] Step 2: The first electronic device can request the server to download the account credential of the user account A.
[0050] The account credential of the user account A can include an account signature and a server public key.
[0051] Step 3: The second electronic device can authenticate the first electronic device according to the account credential of the user A.
[0052] Specifically, the first electronic device can encrypt the account signature using the server public key, and then send the encrypted account signature to the second electronic device. The second electronic device stores an account credential of the user account A, which is pre-issued by the server to the second electronic device. After receiving the encrypted account signature sent by the first electronic device, the second electronic device can decrypt the encrypted account signature using the server public key, and then verify the account signature. If the verification is passed, it means that the second electronic device is authenticated by the first electronic device.
[0053] Step 4: The second electronic device authorizes the first electronic device to access the resource.
[0054] After the second electronic device authenticates the first electronic device, the second electronic device can display the authorization request information, such as Figure 1 The authorization request information displayed by the second electronic device in step 4 can include the resource requested by the first electronic device to access and "reject" and "agree" controls. After the user confirms the authorization in the authorization request information displayed by the second electronic device, the first electronic device can access the related resource. The first electronic device and the second electronic device can be networked and data encrypted by a distributed soft bus, thereby ensuring the security of data transmission.
[0055] The device authentication method described above has requirements for the security environment of the electronic device and the performance of the electronic device, which causes the device authentication method to have limitations. For example Figure 1 The device authentication method described above has requirements for the security environment of the electronic device and the performance of the electronic device, which causes the device authentication method to have limitations. For example
[0056] 1. If the electronic device does not have a TEE, it cannot receive the account credential.
[0057] In the device authentication method described above, the first electronic device and the second electronic device both need to have a TEE environment, otherwise the server will not issue the user credential to the electronic device. Therefore, the electronic device cannot perform device authentication without obtaining the account credential.
[0058] 2. If the storage space of the electronic device is small, the account credential of the user account cannot be stored.
[0059] In some examples, the electronic device may, for example, be an Internet of Things (IoT) thin device. The storage space of such a device, such as read-only memory (ROM), is small and may not be able to store the account credential of the user account.
[0060] 3. If the device authentication scenario is not related to the user account, the above device authentication method is no longer applicable.
[0061] It can be learned from the introduction of the above device authentication method that the device authentication method is based on user account, and cannot be applied to device authentication scenarios irrelevant to user account.
[0062] 4. If the electronic device cannot access the network, the account credential of the user account cannot be received.
[0063] If the electronic device cannot access the network, the electronic device cannot interact with the server, and thus the account credential of the user account cannot be received.
[0064] 5. If the first electronic device or the second electronic device is a public device, there is a security risk of leakage of the account credential of the user account.
[0065] In a daily use scenario, a user may need to log in to a user account on a public device, and thus the server sends the account credential of the user account to the public device for device authentication. After the user ends the use of the public device, the account credential of the user account is still stored in the public device, and the public device is also used by other people, and thus there is a security risk of leakage of the account credential of the user account.
[0066] 6. If the first electronic device or the second electronic device is a screenless device, the authorization process is difficult to perform.
[0067] It can be learned from the introduction of the above device authentication method that after the second electronic device authenticates the first electronic device, the second electronic device can display authorization request information to authorize the first electronic device to access the resource. However, when the second electronic device is a screenless device, it is difficult to perform the authorization process.
[0068] In addition, in some other device authentication manners, electronic devices can exchange personal identification numbers (PINs) to complete device authentication. For example, when the first electronic device requests the second electronic device to perform device authentication, the second electronic device can display a PIN code, the user can input the PIN code in the first electronic device, and if the PIN code input by the user is consistent with the PIN code displayed by the second electronic device, the device authentication is passed. In this manner, if the electronic device is a screenless device, the device authentication based on the PIN code is also difficult to implement.
[0069] In summary, the current device authentication manners are limited and not flexible enough.
[0070] To solve the above problems, an embodiment of the present application provides a device authentication method to provide a safe and convenient device authentication solution. Figure 2 A schematic diagram of a device authentication scenario provided by an embodiment of the present application is shown in FIG. 1. Figure 2The device authentication scenario can include a first electronic device and a second electronic device. Figure 2 The device authentication method provided in the embodiments of the present application involves the modules of an electronic device. Taking the first electronic device as an example, the first electronic device can include an application (APP), an identity service (IS) module, a device management (DM) module, a device authentication (DA) module, and data buffer units (DBUS). The APP can be used to request a device credential of the first electronic device from a server. The IS module can be an independent management service module established for saving a device credential. The IS module can be specifically used for importing, exporting, querying, and listening to changes in the device credential attribute, and verifying the device credential. The DM module is used to discover a device and report the device that needs to be authenticated to the APP. The DA module is used to perform device authentication according to the device credential.
[0071] Optionally, Figure 2 The device authentication scenario can also include a server. The server can be used to provide a device authentication cloud service. The server can be a single server or a server cluster composed of multiple servers. The embodiments of the present application do not limit this.
[0072] In the device authentication method provided in the embodiments of the present application, the first electronic device receives an access request sent by the second electronic device, sends a first authentication request message to the second electronic device, and the first authentication request message is used to request device authentication of the second electronic device. The first electronic device receives first information sent by the second electronic device, and the first information is related to the device type of the second electronic device. The first electronic device sends a second authentication request message to the server, and the second authentication request message is used to request to obtain the device credential of the second electronic device. The second authentication request message includes the first information. The first electronic device receives the device credential information of the second electronic device sent by the server, and the device credential of the second electronic device is determined by the server according to the first information. The first electronic device performs device authentication on the second electronic device according to the device credential information of the second electronic device. In this way, when the first electronic device needs to authenticate the second electronic device, the information sent by the second electronic device to the first electronic device is used to obtain the device credential of the second electronic device, such as a device credential index value, a device identifier, a device credential slice, etc. Therefore, based on the scheme provided in the embodiments of the present application, the second electronic device stores the information used to obtain the device credential, so that the requirements for the execution environment and the storage space of the second electronic device are lower, the performance requirements for the second electronic device in the device authentication process are reduced, a more universal device authentication scheme is provided, and the interconnection and intercommunication between various electronic devices are realized.
[0073] The following describes electronic devices and embodiments for using such electronic devices. The electronic devices of the embodiments of the present application may be tablet computers, mobile phones, in-vehicle devices, augmented reality (AR) / virtual reality (VR) devices, laptop computers, ultra-mobile personal computers (UMPCs), netbooks, personal digital assistants (PDAs), wearable devices, etc. They may also be IoT devices such as smart speakers and smart air conditioners. The embodiments of the present application do not impose any restrictions on the specific type of electronic devices.
[0074] In some embodiments of the present application, the electronic device may also be a portable terminal device that also includes other functions such as a personal digital assistant and / or a music player. Or portable terminal devices with other operating systems.
[0075] Figure 3 Schematic diagram of the structure of an electronic device 100 provided in an embodiment of the present application. Figure 3 As shown, the electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc.
[0076] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices or integrated in one or more processors. The controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of fetching and executing instructions. A memory can also be provided in the processor 110 for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can save instructions or data that the processor 110 has just used or repeatedly uses. If the processor 110 needs to use the instructions or data again, it can directly call from the memory. This avoids repeated access and reduces the waiting time of the processor 110, thereby improving the efficiency of the system.
[0077] The USB interface 130 is an interface conforming to the USB standard specification, and can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 can be used to connect a charger to charge the electronic device 100, or to transmit data between the electronic device 100 and a peripheral device. The charging management module 140 is configured to receive charging input from the charger. The power management module 141 is configured to connect the battery 142 and the charging management module 140. The power management module 141 receives input from the battery 142 and / or the charging management module 140 to power the processor 110, the internal memory 121, the external memory, the display screen 194, the camera 193, and the wireless communication module 160, etc.
[0078] The wireless communication function of the electronic device 100 can be realized through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor, and the baseband processor, etc. The antenna 1 and the antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example, the antenna 1 can be multiplexed as a diversity antenna of a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0079] The mobile communication module 150 can provide a solution for wireless communication including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive an electromagnetic wave by the antenna 1, and perform filtering, amplification, etc. on the received electromagnetic wave, and transfer the processed signal to the modem processor to be demodulated. The mobile communication module 150 can also amplify a signal modulated by the modem processor, and radiate the signal as an electromagnetic wave through the antenna 1. In some embodiments, at least part of the function modules of the mobile communication module 150 can be disposed in the processor 110. In some embodiments, at least part of the function modules of the mobile communication module 150 can be disposed in the same device as at least part of the modules of the processor 110.
[0080] The wireless communication module 160 can provide a solution for wireless communication including wireless local area networks (WLAN) (e.g., wireless fidelity (Wi-Fi) network), bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, etc. applied to the electronic device 100. The wireless communication module 160 can be one or more devices integrated with at least one communication processing module. The wireless communication module 160 receives an electromagnetic wave via the antenna 2, performs frequency modulation and filtering on the electromagnetic wave signal, and transmits the processed signal to the processor 110. The wireless communication module 160 can also receive a signal to be transmitted from the processor 110, perform frequency modulation and amplification on the signal, and radiate the signal as an electromagnetic wave through the antenna 2.
[0081] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include global positioning system (GPS), global navigation satellite system (GLONASS), beidu navigation satellite system (BDS), quasi-zenith satellite system (QZSS), and / or satellite based augmentation systems (SBAS).
[0082] The display screen 194 is configured to display a display interface of an application, for example, a display page of an application installed on the electronic device 100, and the like. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diodes (QLED), or the like. In some embodiments, the electronic device 100 can include one or N display screens 194, where N is a positive integer greater than 1.
[0083] The camera 193 is configured to capture a still image or a video. An object generates an optical image through a lens and projects the optical image to a photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts an optical signal into an electrical signal, and then transmits the electrical signal to an ISP to convert the electrical signal into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into an image signal in a standard format, such as RGB, YUV, or the like. In some embodiments, the electronic device 100 can include one or N cameras 193, where N is a positive integer greater than 1.
[0084] The internal memory 121 can be configured to store computer-executable program codes including instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 can include a program storage area and a data storage area. The program storage area can store an operating system, software codes of at least one application program, and the like. The data storage area can store data generated during use of the electronic device 100, such as captured images, recorded videos, and the like. In addition, the internal memory 121 can include a high-speed random access memory, and can further include a non-volatile memory, such as at least one of a magnetic disk storage device, a flash memory device, a universal flash storage (UFS), and the like.
[0085] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to extend the storage capacity of the electronic device. The external memory card communicates with the processor 110 through the external memory interface 120 to implement a data storage function. For example, files such as pictures and videos are saved in the external memory card.
[0086] The electronic device 100 can implement an audio function through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the earphone interface 170D, the application processor, and the like. For example, music playback, recording, and the like.
[0087] The sensor module 180 can include a pressure sensor 180A, an acceleration sensor 180B, a touch sensor 180C, and the like.
[0088] The pressure sensor 180A is used to sense a pressure signal and can convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A can be disposed on the display screen 194.
[0089] The touch sensor 180C is also referred to as a "touch panel". The touch sensor 180C can be disposed on the display screen 194, and the touch sensor 180C and the display screen 194 together form a touch screen, also referred to as a "touch screen". The touch sensor 180C is used to detect a touch operation acting on or near the touch sensor 180C. The touch sensor can transmit the detected touch operation to the application processor to determine the touch event type. Visual output related to the touch operation can be provided through the display screen 194. In other embodiments, the touch sensor 180C can also be disposed on the surface of the electronic device 100, which is different from the position of the display screen 194.
[0090] The keys 190 include a power key, a volume key, and the like. The keys 190 can be mechanical keys. They can also be touch keys. The electronic device 100 can receive key inputs and generate key signal inputs related to user settings and function control of the electronic device 100. The motor 191 can generate a vibration prompt. The motor 191 can be used for incoming call vibration prompts and also for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, playing audio, and the like) can correspond to different vibration feedback effects. The touch vibration feedback effect can also be customizable. The indicator 192 can be an indicator light and can be used to indicate a charging state, a power change, and can also be used to indicate a message, a missed call, a notification, and the like. The SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to achieve contact and separation with the electronic device 100.
[0091] It can be understood that, Figure 3The illustrated components do not constitute a specific limitation on the electronic device 100, and the electronic device can also include more or fewer components than those illustrated, or combine certain components, or split certain components, or different arrangement of components. In addition, Figure 3 The combination / connection relationship between the components in the electronic device 100 can also be adjusted and modified.
[0092] Figure 4 A software structure block diagram of an electronic device is provided in an embodiment of the present application. As shown in Figure 4 The software structure of the electronic device can be a layered architecture, for example, the software can be divided into several layers, each layer has a clear role and division of labor. The layers communicate with each other through a software interface. In some embodiments, the operating system is divided into four layers, from top to bottom, the application layer, the application framework layer (framework, FWK), the runtime and system library, and the kernel layer.
[0093] The application layer can include a series of application packages. As shown in Figure 4 The application layer can include a camera, a setting, a skin module, a user interface (UI), a third-party application, and the like. Among them, the third-party application can include a gallery, a calendar, a call, a map, a navigation, a WLAN, a Bluetooth, music, a video, a short message, and the like. In an embodiment of the present application, the application layer can include a target installation package of a target application requested by the electronic device to download from a server, and the function files and layout files in the target installation package are adapted to the electronic device.
[0094] The application framework layer provides an application programming interface (API) and a programming framework for the application of the application layer. The application framework layer can include some pre-defined functions. As shown in Figure 4 The application framework layer can include a window manager, a content provider, a view system, a phone manager, a resource manager, and a notification manager.
[0095] The window manager is used to manage the window program. The window manager can obtain the size of the display screen, determine whether there is a status bar, lock the screen, and intercept the screen, etc. The content provider is used to store and obtain data, and make the data accessible to the application. The data can include video, image, audio, dialed and received calls, browsing history and bookmarks, phonebook, and the like.
[0096] The view system includes visual controls, such as controls that display text, controls that display pictures, and the like. The view system can be used to build an application. A display interface can be composed of one or more views. For example, a display interface that includes a short message notification icon can include a view that displays text and a view that displays a picture.
[0097] The phone manager is used to provide communication functions of the electronic device. For example, management of call status (including call connection, call hang-up, and the like).
[0098] The resource manager provides various resources for an application, such as localized strings, icons, pictures, layout files, video files, and the like.
[0099] The notification manager enables an application to display notification information in a status bar, which can be used to convey a message of the notification type, which can automatically disappear after a short stay without user interaction. For example, the notification manager is used to notify a download completion, a message reminder, and the like. The notification manager can also be a notification that appears in a system top status bar in a chart or a scroll bar text form, a notification of an application running in the background, and the like, and can also be a notification that appears on a screen in a dialog window form. For example, a text information is prompted in a status bar, a prompt sound is emitted, the electronic device is vibrated, a light flashes, and the like.
[0100] The runtime includes a core library and a virtual machine. The runtime is responsible for scheduling and management of the operating system.
[0101] The core library includes two parts: one part is a function function that the java language needs to call, and the other part is the core library of the operating system. The application layer and the application framework layer run in the virtual machine. The virtual machine executes the java file of the application layer and the application framework layer into a binary file. The virtual machine is used to perform the management of the object life cycle, the stack management, the thread management, the security and the exception management, and the garbage collection and the like.
[0102] The system library can include a plurality of function modules. For example: a surface manager, media libraries, a three-dimensional graphics processing library (for example: OpenGL ES), a two-dimensional graphics engine (for example: SGL), an image processing library, and the like.
[0103] The surface manager is used to manage a display subsystem, and provides a fusion of 2D and 3D layers for a plurality of applications.
[0104] The media library supports a plurality of commonly used audio, video format playback and recording, and static image files and the like. The media library can support a plurality of audio and video encoding formats, such as: MPEG4, H.264, MP3, AAC, AMR, JPG, PNG, and the like.
[0105] The three-dimensional graphics processing library is used to implement three-dimensional graphics drawing, image rendering, composition, and layer processing.
[0106] The 2D graphics engine is a drawing engine for 2D drawing.
[0107] The kernel layer is a layer between hardware and software. The kernel layer at least includes display drivers, camera drivers, audio drivers, and sensor drivers.
[0108] The hardware layer can include various sensors, such as acceleration sensors, gyroscope sensors, and touch sensors.
[0109] It should be noted that, Figure 3 and Figure 4 The structure shown in FIG. 1 is only an example of the electronic device provided in the embodiments of the present application, and cannot limit the electronic device provided in the embodiments of the present application in any way. In specific implementations, the electronic device can have more or fewer devices or modules than the structure shown in FIG. 1. Figure 3 or Figure 4 The structure shown in FIG. 1 is only an example of the electronic device provided in the embodiments of the present application, and cannot limit the electronic device provided in the embodiments of the present application in any way. In specific implementations, the electronic device can have more or fewer devices or modules than the structure shown in FIG. 1.
[0110] The device authentication method provided in the embodiments of the present application is introduced as follows.
[0111] The device authentication method provided in the embodiments of the present application can be applied to Figure 2 the device authentication scenario shown in FIG. 1. Before accessing resources of each other, the electronic devices need to perform device authentication on the peer electronic device, for example, Figure 2 Before the first electronic device accesses the second electronic device, the second electronic device needs to perform device authentication on the first electronic device. Similarly, before the second electronic device accesses the first electronic device, the first electronic device also needs to perform device authentication on the second electronic device. As known from the foregoing introduction, the performance and type of different electronic devices are different, and a single authentication method is not suitable for various types of electronic devices. In the embodiments of the present application, the authentication method supported by the electronic device can be determined according to the performance and type of the electronic device, so that the device authentication method provided in the embodiments of the present application can be applied to the device authentication process of various types of electronic devices, thereby realizing the interconnection and intercommunication of various types of electronic devices.
[0112] First, the device credential used for device authentication provided in the embodiments of the present application is introduced. The device credential in the embodiments of the present application can be any one of a certificate, a one-time (OT) credential, and a PIN code. In the device authentication method provided in the embodiments of the present application, each electronic device corresponds to a device credential, which can be used by other electronic devices to perform device authentication on the electronic device. The server can generate the device credential of the electronic device, and distribute the generated device credential to the electronic device. The electronic device can store the device credential of the electronic device.
[0113] As can be known from the foregoing, some electronic devices can not be able to connect to a mobile network, and the server can send the device credential of the electronic device to the master device associated with the electronic device, and the master device sends the device credential of the electronic device to the electronic device. For example, Figure 5 A schematic diagram of a device credential issuing method provided by an embodiment of the present application is shown in FIG. 1. Referring to Figure 5 , a communication connection can be established between the first electronic device and the second electronic device, which can be a Bluetooth connection, a wireless fidelity (Wi-Fi) connection, a star flash connection, etc. When the second electronic device cannot interact with the server through a mobile network, the second electronic device can send a request message to the first electronic device to request the first electronic device to assist the second electronic device in obtaining the device credential of the second electronic device, and the first electronic device can send a request message to the server to request the device credential of the second electronic device. After the server generates the device credential of the second electronic device, the server can send the device credential of the second electronic device to the first electronic device, and the first electronic device sends the device credential of the second electronic device to the second electronic device through the communication connection between the first electronic device and the second electronic device. For example, referring to Figure 5 , the DM module of the first electronic device can discover the second electronic device, and when it is determined that the second electronic device cannot obtain the device credential of the second electronic device, the first electronic device can request the device credential of the second electronic device from the server through the APP, the APP can send the obtained device credential of the second electronic device to the IS module of the first electronic device, the IS module of the first electronic device can send the device credential of the second electronic device to the IS module of the second electronic device, and the IS module of the second electronic device can store the device credential of the second electronic device.
[0114] The device authentication method provided by the embodiment of the present application can be applied to device authentication between electronic devices of various types, such as a device without a TEE, a public device, or a screenless device.
[0115] In the device authentication method provided by the embodiments of the present application, when the second electronic device is an electronic device without a TEE, and the first electronic device needs to perform device authentication on the second electronic device, since the second electronic device cannot provide a secure storage environment, the server cannot send the complete device credential of the second electronic device to the second electronic device, the server can store the correspondence between the device identifier of the second electronic device, the device credential index value of the second electronic device, and the device credential of the second electronic device, the server can send the device credential index value of the second electronic device to the second electronic device, and the second electronic device can store the device credential index value of the second electronic device; or the server can split the device credential of the second electronic device, and send part of the device credential of the second electronic device to the second electronic device, and the second electronic device can store the part of the device credential. For example, the server can split the device credential of the second electronic device into two slices: a first slice and a second slice, the server can send the second slice of the device credential of the second electronic device to the second electronic device, and the second electronic device can store the second slice of the device credential of the second electronic device.
[0116] When the first electronic device performs device authentication on the second electronic device without a TEE, the first electronic device needs to obtain the device credential of the second electronic device. In the embodiments of the present application, the first electronic device can obtain the first slice and the second slice of the device credential of the second electronic device respectively, and perform string concatenation on the first slice and the second slice to synthesize the complete device credential of the second electronic device; or the first electronic device can also obtain the complete device credential of the second electronic device.
[0117] In an optional implementation, the second electronic device can send first information used to obtain the device credential of the second electronic device to the first electronic device, wherein the first information can include at least one of the device identifier of the second electronic device, the device credential index value of the second electronic device, and the second slice of the device credential of the second electronic device. The first electronic device can obtain the first slice from the server according to the first information, and the first electronic device can obtain the second slice of the device credential of the second electronic device from the second electronic device, and the first electronic device performs string concatenation on the first slice and the second slice to synthesize the complete device credential of the second electronic device.
[0118] In another optional implementation, the second electronic device can send the first information to the first electronic device, and then the first electronic device can obtain the complete device credential of the second electronic device from the server according to the first information.
[0119] In another alternative implementation, the second electronic device can send the device identifier of the second electronic device or the device credential index value of the second electronic device to the first electronic device, and then the first electronic device can obtain the first slice of the second electronic device from the server according to the device identifier of the second electronic device or the device credential index value of the second electronic device, send the first slice to the second electronic device, and then the second electronic device can perform string concatenation on the first slice and the second slice to synthesize the complete device credential of the second electronic device, and send the complete device credential of the second electronic device to the first electronic device.
[0120] Based on the above introduction, the first electronic device in the embodiments of the present application can obtain the device credential of the second electronic device in the following ways:
[0121] Method 1: The first electronic device sends a first authentication request message to the second electronic device, and the first authentication request message is used to request device authentication of the second electronic device. The second electronic device can send the device credential index value stored in the second electronic device to the first electronic device, and after the first electronic device obtains the device credential index value of the second electronic device, the first electronic device can send a second authentication request message to the server, and the second authentication request message is used to request device authentication of the second electronic device, and the second authentication request message can include the device credential index value of the second electronic device. After the server receives the request message sent by the first electronic device, the server can find the first slice of the device credential of the second electronic device according to the device credential index value of the second electronic device, and send the first slice of the device credential of the second electronic device to the first electronic device. The second electronic device sends the first slice of the device credential of the second electronic device to the first electronic device, and the first electronic device performs string concatenation on the first slice and the second slice to obtain the complete device credential of the second electronic device.
[0122] Method 2: The first electronic device sends a first authentication request message to the second electronic device, and the first authentication request message is used to request device authentication of the second electronic device. The second electronic device can send the second slice of the device credential stored in the second electronic device to the first electronic device, and the first electronic device can send a second authentication request message to the server, and the second authentication request message is used to request device authentication of the second electronic device, and the second authentication request message can include the second slice of the device credential of the second electronic device. After the server receives the request message sent by the first electronic device, the server can find the first slice of the device credential of the second electronic device according to the second slice of the device credential of the second electronic device, and send the first slice of the device credential of the second electronic device to the first electronic device. The first electronic device performs string concatenation on the first slice and the second slice to obtain the complete device credential of the second electronic device.
[0123] Manner 3: The first electronic device sends a first authentication request message to the second electronic device, and the first authentication request message is used to request device authentication of the second electronic device. The second electronic device can send a second slice of a device credential stored in the second electronic device to the first electronic device, and the first electronic device can send a second authentication request message to the server, the second authentication request message being used to request device authentication of the second electronic device, and the second authentication request message can include a device identifier of the second electronic device. The server can find the device credential of the second electronic device according to the device identifier of the second electronic device, and the server can send a first slice of the device credential of the second electronic device to the first electronic device. The first electronic device concatenates the first slice and the second slice to obtain a complete device credential of the second electronic device.
[0124] In this embodiment, the step of the first electronic device sending the second authentication request message to the server and the step of the first electronic device sending the first authentication request message to the second electronic device do not have a sequence of execution, the first electronic device can first send the first authentication request message to the second electronic device and then send the second authentication request message to the server, or the first electronic device can first send the second authentication request message to the server and then send the first authentication request message to the second electronic device, or the first electronic device can send the third message to the server and send the first authentication request message to the second electronic device at the same time, and the embodiments of the present application do not limit this.
[0125] Manner 4: The first electronic device sends a first authentication request message to the second electronic device, and the first authentication request message is used to request device authentication of the second electronic device. The second electronic device can send a device credential index value stored in the second electronic device to the first electronic device, and after the first electronic device obtains the device credential index value of the second electronic device, the first electronic device can send a second authentication request message to the server, the second authentication request message being used to request device authentication of the second electronic device, and the second authentication request message can include the device credential index value of the second electronic device. After the server receives the request message sent by the first electronic device, the server can find the device credential of the second electronic device according to the device credential index value of the second electronic device, and send the device credential of the second electronic device to the first electronic device.
[0126] Manner 5: The first electronic device sends a first authentication request message to the second electronic device, and the first authentication request message is used to request device authentication of the second electronic device. The second electronic device can send a second slice of a device credential stored in the second electronic device to the first electronic device. After the first electronic device obtains the second slice of the device credential of the second electronic device, the first electronic device can send a second authentication request message to the server, and the second authentication request message is used to request device authentication of the second electronic device. The second slice of the device credential of the second electronic device can be included in the second authentication request message. After the server receives the second authentication request message sent by the first electronic device, the server can find the device credential of the second electronic device according to the second slice of the device credential of the second electronic device, and send the device credential of the second electronic device to the first electronic device.
[0127] Manner 6: The first electronic device sends a second authentication request message to the server, and the second authentication request message is used to request device authentication of the second electronic device. The device identifier of the second electronic device can be included in the second authentication request message. After the server receives the second authentication request message sent by the first electronic device, the server can find the device credential of the second electronic device according to the device identifier of the second electronic device, and send the device credential of the second electronic device to the first electronic device. The first electronic device can obtain the device identifier of the second electronic device when discovering the second electronic device, or the first electronic device receives the device identifier of the second electronic device sent by the second electronic device after sending an authentication request message to the second electronic device.
[0128] Manner 7: The first electronic device sends a first authentication request message to the second electronic device, and the first authentication request message is used to request device authentication of the second electronic device. The second electronic device can send a device credential index value stored in the second electronic device to the first electronic device. After the first electronic device obtains the device credential index value of the second electronic device, the first electronic device can send a second authentication request message to the server, and the second authentication request message is used to request device authentication of the second electronic device. The device credential index value of the second electronic device can be included in the second authentication request message. After the server receives the second authentication request message sent by the first electronic device, the server can find a first slice of the device credential of the second electronic device according to the device credential index value of the second electronic device, and send the first slice of the device credential of the second electronic device to the first electronic device. The first electronic device sends the first slice of the device credential of the second electronic device to the second electronic device. The second electronic device performs string splicing on the first slice and a second slice to obtain a complete device credential of the second electronic device. The second electronic device sends the device credential of the second electronic device to the first electronic device.
[0129] Manner 8: The first electronic device sends a second authentication request message to the server, the second authentication request message being used to request device authentication of the second electronic device, and the second authentication request message can include the device identifier of the second electronic device. After receiving the request message sent by the first electronic device, the server can find the first slice of the device credential of the second electronic device according to the device identifier of the second electronic device, and send the first slice of the device credential of the second electronic device to the first electronic device. The first electronic device sends the first slice of the device credential of the second electronic device to the second electronic device, and the second electronic device performs string splicing on the first slice and the second slice to obtain the complete device credential of the second electronic device. The second electronic device sends the device credential of the second electronic device to the first electronic device.
[0130] It should be noted that, since the second electronic device does not have a TEE, in the above-mentioned manners 7 and 8, after the second electronic device generates the device credential of the second electronic device according to the first slice and the second slice, and sends the device credential of the second electronic device to the first electronic device, the second electronic device will not continue to save the first slice and the device credential of the second electronic device, but still only save the device credential index value or the second slice of the second electronic device.
[0131] In the embodiments of the present application, after the first electronic device obtains the device credential of the second electronic device, the first electronic device performs device authentication on the second electronic device according to the device credential of the second electronic device. Optionally, the server public key is stored in the first electronic device, and when the first electronic device performs device authentication on the second electronic device according to the device credential of the second electronic device, the first electronic device can authenticate the device credential of the second electronic device according to the server public key to obtain a device authentication result.
[0132] For example, when the first electronic device and the second electronic device have the structure as shown in Figure 2 , the device authentication method provided by the embodiments of the present application can refer to Figure 6 . For reference Figure 6 , Figure 6 , taking the device authentication of the second electronic device by the first electronic device as an example, the second electronic device is an electronic device without a TEE, the server can store the correspondence between the device identifier of the second electronic device, the device credential index value and the device credential, the server can send the device credential index value of the second electronic device to the second electronic device; or the server can divide the device credential of the second electronic device into a first slice and a second slice, the server sends the second slice of the device credential of the second electronic device to the second electronic device, and the second electronic device can store the second slice of the device credential of the second electronic device. As Figure 6In the embodiment, the IS module of the second electronic device can store the device credential index value of the second electronic device or the second slice of the device credential of the second electronic device. When other electronic devices perform device authentication on the second electronic device, the IS module can send the device credential index value of the second electronic device or the second slice of the device credential of the second electronic device to the DA module of the second electronic device.
[0133] refer to Figure 6 When the first electronic device performs device authentication on the second electronic device, the following steps may be included:
[0134] Step a: The first electronic device discovers the second electronic device.
[0135] For example, the DBUS of the first electronic device and the DBUS of the second electronic device can establish a communication connection, such as a Bluetooth connection, a Wi-Fi connection, a StarFlash connection, etc. The DM module of the first electronic device discovers the second electronic device through the DBUS of the first electronic device, and the DM module of the first electronic device can report the information of discovering the second electronic device to the APP.
[0136] In an embodiment of the present application, the first electronic device determines that it is necessary to perform device authentication on the second electronic device. If the first electronic device discovers the second electronic device, the second electronic device sends an access request to the first electronic device, then the first electronic device determines that it is necessary to perform device authentication on the second electronic device. At this time, the first electronic device needs to obtain the device credentials of the second electronic device, then the first electronic device can send a first authentication request message to the second electronic device, and the first authentication request message is used to request device authentication for the second electronic device.
[0137] In an optional embodiment, a first electronic device receives an access request sent by a second electronic device, and the access request may include information indicating that the second electronic device does not have a TEE. For example, the access request may include device type information of the second electronic device. The first electronic device may determine that the second electronic device is an electronic device without a TEE based on the device type information of the second electronic device, or the access request may also include other information indicating that the second electronic device does not have a TEE. This embodiment of the present application is not limited to this.
[0138] In an alternative embodiment ,like Figure 6 As shown in (a), the first electronic device can obtain the first slice and the second slice of the device credential of the second electronic device and determine the device credential of the second electronic device to complete device authentication. This embodiment includes the following steps:
[0139] Step b: The second electronic device sends the second slice of the device credentials of the second electronic device to the first electronic device.
[0140] Step c: The first electronic device acquires a first slice of the device credential of the second electronic device from the server.
[0141] Optionally, the first electronic device can acquire the first slice of the device credential of the second electronic device from the server according to at least one of the device identity of the second electronic device, the device credential index value of the second electronic device, and a second slice of the device credential of the second electronic device.
[0142] Step d: The first electronic device synthesizes the device credential of the second electronic device according to the first slice and the second slice, and performs device authentication on the second electronic device according to the device credential of the second electronic device.
[0143] For example, referring to (a) in Figure 6 , the IS module of the first electronic device can send the first slice of the device credential of the second electronic device acquired from the server to the DA module of the first electronic device, the DA module of the second electronic device can send the second slice of the device credential of the second electronic device to the DA module of the first electronic device, and the DA module of the first electronic device can synthesize the device credential of the second electronic device according to the first slice and the second slice, and perform device authentication on the second electronic device according to the device credential of the second electronic device.
[0144] In another alternative embodiment As shown in (b) in Figure 6 , the first electronic device can acquire the complete device credential of the second electronic device from the server to complete the device authentication, and the embodiment includes the following steps:
[0145] Step e: The second electronic device sends the device credential index value of the second electronic device to the first electronic device.
[0146] Step f: The first electronic device acquires the device credential of the second electronic device from the server according to the device credential index value of the second electronic device.
[0147] Step g: The first electronic device performs device authentication on the second electronic device according to the device credential of the second electronic device.
[0148] For example, referring to Figure 6In (b) of the above, the DA module of the second electronic device can send the device credential index value of the second electronic device to the DA module of the first electronic device, the DA module of the first electronic device sends the device credential index value of the second electronic device to the IS module of the first electronic device, the IS module of the first electronic device sends the device credential index value of the second electronic device to the APP of the first electronic device, the APP of the first electronic device acquires the device credential of the second electronic device from the server according to the device credential index value of the second electronic device, and the IS module of the first electronic device can send the device credential of the second electronic device acquired from the server to the DA module of the first electronic device, and the DA module of the first electronic device performs device authentication on the second electronic device according to the device credential of the second electronic device.
[0149] In yet another alternative embodiment As shown in (c) of the above, the first electronic device can acquire the first slice of the device credential of the second electronic device from the server and send the first slice to the second electronic device, and the first electronic device acquires the device credential of the second electronic device from the second electronic device to complete the device authentication, and the embodiment includes the following steps: Figure 6
[0150] Step h: The first electronic device acquires the first slice of the device credential of the second electronic device from the server.
[0151] Optionally, the first electronic device can acquire the first slice of the device credential of the second electronic device from the server according to the device credential index value of the second electronic device or the device identifier of the second electronic device.
[0152] Step i: The first electronic device sends the first slice of the device credential of the second electronic device to the second electronic device.
[0153] Step j: The second electronic device synthesizes the device credential of the second electronic device according to the first slice and the second slice.
[0154] Step k: The second electronic device sends the device credential of the second electronic device to the first electronic device.
[0155] Step l: The first electronic device performs device authentication on the second electronic device according to the device credential of the second electronic device.
[0156] For example, referring to Figure 6 In (c), the IS module of the first electronic device can send the first slice of the device credentials of the second electronic device obtained from the server to the DA module of the first electronic device, and the DA module of the first electronic device can send the first slice of the device credentials of the second electronic device to the DA module of the second electronic device. The IS module of the second electronic device can send the second slice of the device credentials of the second electronic device to the DA module of the first electronic device, and the DA module of the second electronic device can synthesize the device credentials of the second electronic device based on the first slice and the second slice, and the DA module of the second electronic device can send the device credentials of the second electronic device to the DA module of the first electronic device, and the DA module of the first electronic device performs device authentication on the second electronic device based on the device credentials of the second electronic device.
[0157] Optionally, in Figure 6 In the embodiment shown, the server public key is stored in the first electronic device. When the first electronic device authenticates the second electronic device based on the device credentials of the second electronic device, it can authenticate the device credentials of the second electronic device based on the server public key to obtain a device authentication result.
[0158] It should be noted that Figure 6 In the embodiment shown, Figure 6 (a) corresponds to the above-mentioned method 1 to method 3 in which the first electronic device obtains the device credential of the second electronic device. Figure 6 (b) corresponds to the method 4 in the above embodiment. Figure 6 (c) corresponds to the above-mentioned methods 7-8, and the device interaction process corresponding to other methods is the same as Figure 6 The processes in the illustrated embodiments are similar, such as Mode 5 and Mode 6, which can be referred to Figure 6 The process shown in (b) will not be described in detail in this embodiment of the present application.
[0159] Through the above implementation, the second electronic device that does not have a TEE can store part of the device credentials. When the first electronic device performs device authentication on the second electronic device, it can obtain part of the device credentials of the second electronic device from the server and the second electronic device respectively, and then obtain the complete device credentials of the second electronic device to complete the device authentication of the second electronic device; or the second electronic device that does not have a TEE can use the device credential index value. When the first electronic device performs device authentication on the second electronic device, the second electronic device can send the device credential index value of the second electronic device to the first electronic device, so that the first electronic device can obtain the device credentials of the second electronic device from the server according to the device credential index value of the second electronic device to complete the device authentication of the second electronic device; the above method provides a device authentication method for a TEE-free device, which enables intercommunication between a TEE-free electronic device and other electronic devices.
[0160] In the embodiment of the present application, the second electronic device can also perform device authentication on the first electronic device. Specifically, the first electronic device can send the device credential of the first electronic device to the second electronic device. For example, in step e described above, the first electronic device can send the device credential of the first electronic device to the second electronic device at the same time when sending the first slice to the second electronic device, or the first electronic device can send the device credential of the first electronic device to the second electronic device at other time, which is not limited in the embodiment of the present application. The server public key is stored in the second electronic device. When performing device authentication on the first electronic device according to the device credential of the first electronic device, the second electronic device can authenticate the device credential of the first electronic device according to the server public key to obtain a device authentication result.
[0161] In the device authentication method provided in the embodiment of the present application, when the first electronic device requests to access the second electronic device, the first electronic device sends an access request to the second electronic device. At this time, the second electronic device needs to obtain the device credential of the first electronic device to perform device authentication on the first electronic device. For example, the second electronic device can send a third authentication request message to the first electronic device after receiving the access request, and the third authentication request message is used to request to perform device authentication on the first electronic device. In the embodiment of the present application, the first electronic device can determine the device credential of the first electronic device sent to the second electronic device according to the device type of the second electronic device, and the second electronic device can perform device authentication on the first electronic device according to the device credential of the first electronic device.
[0162] In an optional implementation, after discovering the second electronic device, the first electronic device can obtain the device type information of the second electronic device, and determine the device type of the second electronic device according to the device type information of the second electronic device. For example, after discovering the second electronic device, the first electronic device can establish a communication connection with the second electronic device, the first electronic device sends an access request to the second electronic device through the communication connection, and the second electronic device can send the device type information of the second electronic device to the first electronic device. The first electronic device can store a preset correspondence between the device type of the receiving end electronic device and the device credential type, for example, the preset correspondence between the device type of the receiving end electronic device and the device credential type can include: public device corresponds to one-time credential, screenless low-sensitive device corresponds to PIN code, and screenless high-sensitive device corresponds to one-time credential. The first electronic device can determine the first device credential type corresponding to the device type of the second electronic device, and send the device credential of the first electronic device to the second electronic device according to the first device credential type.
[0163] In the embodiments of the present application, when the second electronic device is a public device, the device credential of the first electronic device determined by the first electronic device is a one-time (OT) credential corresponding to the first electronic device. As introduced before, the OT credential is a temporary credential generated by the server and is only used for the device authentication process between the first electronic device and the second electronic device this time, so that there is no need to worry about the impact of the leakage of the device credential on the user data. When the second electronic device is a screenless device, the device credential of the first electronic device determined by the first electronic device is a PIN code or an OT credential corresponding to the first electronic device, so as to simplify the device authentication process and realize the interconnection and intercommunication between the electronic device and the screenless device. The device authentication method provided by the embodiments of the present application when the second electronic device is different types of electronic devices will be further introduced as follows:
[0164] 1. The second electronic device is a public device
[0165] In some embodiments, the second electronic device is a public device, and the first electronic device performs device authentication on the first electronic device before accessing the second electronic device. In this scenario, the second electronic device can perform device authentication on the first electronic device according to the OT credential of the first electronic device.
[0166] As Figure 7 A schematic diagram of a device authentication method provided by the embodiments of the present application is shown in FIG. 1. As shown in FIG. 1, the method can include the following steps: Figure 7
[0167] Step a: The first electronic device discovers the second electronic device.
[0168] For example, the DBUS of the first electronic device can establish a communication connection, such as a Bluetooth connection, a Wi-Fi connection, a star flash connection, etc., with the DBUS of the second electronic device. The DM module of the first electronic device discovers the second electronic device through the DBUS of the first electronic device, and the DM module of the first electronic device can report the information of discovering the second electronic device to the APP.
[0169] In the embodiments of the present application, the second electronic device determines that the first electronic device needs to be authenticated, such as when the first electronic device discovers the second electronic device and the first electronic device sends an access request to the second electronic device. The second electronic device determines that the first electronic device needs to be authenticated. At this time, the second electronic device needs to obtain the device credential of the first electronic device, and the second electronic device can send a third authentication request message to the first electronic device, where the third authentication request message is used to request the device authentication of the first electronic device.
[0170] Step b. The first electronic device obtains the OT credential corresponding to the first electronic device from the server.
[0171] In an optional implementation, when the first electronic device determines that the device credential of the first electronic device needs to be sent to the second electronic device, the first electronic device sends a request message to the server, where the request message is used to request the device credential of the first electronic device.
[0172] Optionally, when the first electronic device determines that the second electronic device is a public device, the request message sent by the first electronic device to the server can be used to request the OT credential corresponding to the first electronic device. After receiving the request message sent by the first electronic device, the server can generate the OT credential corresponding to the first electronic device, and send the OT credential corresponding to the first electronic device to the electronic device. Alternatively, the request message sent by the first electronic device can include the device type or the device identifier of the second electronic device. After receiving the request message sent by the first electronic device, the server can determine that the second electronic device is a public device according to the device type or the device identifier of the second electronic device, and generate the OT credential corresponding to the first electronic device, and send the OT credential corresponding to the first electronic device to the first electronic device.
[0173] Step c: The first electronic device sends the OT credential corresponding to the first electronic device to the second electronic device.
[0174] Step d: The second electronic device performs device authentication on the first electronic device according to the OT credential corresponding to the first electronic device.
[0175] Optionally, step c can be performed by the DA module of the second electronic device. After receiving the OT credential corresponding to the first electronic device, the IS module of the second electronic device can send the OT credential corresponding to the first electronic device to the DA module.
[0176] In a specific implementation, the server public key is stored in the second electronic device. When the second electronic device performs device authentication on the first electronic device according to the OT credential corresponding to the first electronic device, the second electronic device can authenticate the OT credential corresponding to the first electronic device according to the server public key to obtain a device authentication result.
[0177] It should be noted that the second electronic device will not continue to store the OT credential of the first electronic device after the use of the OT credential of the first electronic device ends, that is, the second electronic device will delete the OT credential of the first electronic device after completing the device authentication and data transmission with the first electronic device. For example, after the first electronic device is offline, the DM module of the second electronic device can determine that the first electronic device has been offline, and then the DM module can send a notification message to the IS module to notify the IS module to delete the OT credential corresponding to the first electronic device. Through the above design, the information security of the first electronic device can be ensured, and the storage space of the second electronic device can be saved.
[0178] Additionally, the example can also include the following steps:
[0179] Step e: The second electronic device and the first electronic device negotiate a transmission key based on the OT credential, and the first electronic device and the second electronic device perform data encryption transmission based on the transmission key.
[0180] When the first electronic device and the second electronic device end this data transmission, the second electronic device deletes the transmission key, and the next time the first electronic device accesses the second electronic device, device authentication needs to be performed again, further ensuring the security of user device interaction with the public device.
[0181] 2. The second electronic device is a screenless device.
[0182] In some examples, the second electronic device is a screenless device, and the second electronic device cannot provide a convenient user interaction mode, such as a smart lamp, a smart curtain, etc. For such devices, the device authentication method provided by the embodiments of the present application can be more simplified.
[0183] For example, Figure 8 A schematic diagram of a device authentication method provided by an embodiment of the present application. Referring to Figure 8 , the second electronic device is a screenless device, and the second electronic device can access a network to interact with a server. The server can store the correspondence between the screenless device and the master device of the screenless device. When the first electronic device requests to access the second electronic device, the first electronic device determines that the second electronic device is a screenless device, and the first electronic device sends an authorization request message to the second electronic device. The second electronic device can send the authorization request message to the server. After receiving the authorization request message sent by the second electronic device, the server can determine the master device corresponding to the second electronic device, such as determining that the master device corresponding to the second electronic device is the third electronic device, and the server can send the authorization request message to the third electronic device. After receiving the authorization request message, the third electronic device can display authorization information, such as "the first electronic device requests to access the second electronic device, do you accept?". The user can operate to determine the authorization in the third electronic device, the third electronic device sends a confirmation authorization message to the server, the server sends a confirmation authorization message to the second electronic device, and the second electronic device sends a confirmation authorization message to the first electronic device, thereby completing the device authentication of the first electronic device and the second electronic device, and the first electronic device can access the second electronic device.
[0184] Optionally, if the second electronic device has established a communication connection with the third electronic device, such as a Bluetooth connection, a Wi-Fi connection or a Starlink connection, the second electronic device can also send the authorization request message to the third electronic device through the communication connection between the second electronic device and the third electronic device, without the need to obtain authorization from the third electronic device through the server again.
[0185] Figure 9 Another device authentication method provided by the embodiments of the present application is shown in the schematic diagram. Referring to Figure 9 , the first electronic device and the second electronic device can interact through short-range communication, such as the first electronic device and the second electronic device interacting with data through a Bluetooth connection. When the first electronic device accesses the second electronic device, the first electronic device sends an access request to the second electronic device, at which time the second electronic device needs to obtain the device credentials of the first electronic device. The second electronic device sends a third authentication request message to the first electronic device, the third authentication request message being used to request device authentication of the first electronic device. The first electronic device sends the device credentials of the first electronic device to the second electronic device based on the device type of the second electronic device, so that the second electronic device performs device authentication on the first electronic device.
[0186] In an implementation, when the first electronic device determines that the second electronic device is a screenless low-sensitive device, the first electronic device can randomly generate a PIN code and send the generated PIN code as the device credentials of the first electronic device to the second electronic device. For example, the first electronic device can generate a 128-bit PIN code. After the second electronic device receives the PIN code sent by the first electronic device, the second electronic device completes the authentication of the first electronic device.
[0187] In another implementation, when the first electronic device determines that the second electronic device is a screenless high-sensitive device, the first electronic device requests the server to obtain the OT credentials corresponding to the first electronic device. After the server generates the OT credentials corresponding to the first electronic device, the server sends the OT credentials corresponding to the first electronic device to the first electronic device. The first electronic device sends the OT credentials corresponding to the first electronic device to the second electronic device. After the second electronic device receives the OT credentials sent by the first electronic device, the second electronic device completes the authentication of the first electronic device.
[0188] It should be noted that the low-sensitive device in the above embodiments can be a screenless device with low sensitivity to access rights or security, and the high-sensitive device can be a screenless device with high sensitivity to access rights or security. In the implementation, the first electronic device can determine whether the second electronic device is a low-sensitive device or a high-sensitive device according to the device type of the second electronic device.
[0189] In this way, the first electronic device can determine the device credential of the first electronic device for device authentication according to the device type of the second electronic device, so that device authentication is performed using different device credentials for different types of electronic devices, device authentication between electronic devices of multiple types is achieved, and further, interworking of electronic devices of multiple types is achieved.
[0190] Based on the same concept, the embodiments of the present application also provide a device authentication method, which can be executed by a first electronic device. Figure 10 A flowchart of a device authentication method provided by the embodiments of the present application is shown in Figure 10 The method comprises the following steps:
[0191] S1001: The first electronic device receives an access request sent by a second electronic device.
[0192] S1002: The first electronic device sends a first authentication request message to the second electronic device.
[0193] S1003: The first electronic device receives first information sent by the second electronic device.
[0194] The first information is related to the device type of the second electronic device, and the first information is used to obtain the device credential of the second electronic device.
[0195] S1004: The first electronic device sends a second authentication request message to a server.
[0196] The second authentication request message is used to request to obtain the device credential of the second electronic device, and the second request message comprises the first information.
[0197] S1005: The first electronic device receives device credential information of the second electronic device sent by the server.
[0198] The device credential information of the second electronic device is determined by the server according to the first information. For example, the server can store the correspondence between the device credential information of the second electronic device and the first information. After receiving the first information, the server can find the device credential information of the second electronic device corresponding to the first information according to the first information.
[0199] S1006: The first electronic device performs device authentication on the second electronic device according to the device credential information of the second electronic device.
[0200] It should be noted that the device authentication method shown in the embodiments of the present application can refer to the above-mentioned embodiments of the present application in the specific implementation, and the repeated parts will not be described again. Figure 10
[0201] Based on the above embodiments, the present application further provides an electronic device, which comprises a plurality of functional modules; the plurality of functional modules interact to realize the functions performed by the first electronic device in the methods described in the embodiments of the present application. The plurality of functional modules can be implemented based on software, hardware or a combination of software and hardware, and the plurality of functional modules can be combined or divided in any manner based on specific implementation. The plurality of functional modules in the first electronic device can be IS modules, DM modules, DA modules and DBUS as shown in the following figure, and the functions of the modules can be referred to the above embodiments, and details are not described herein. Figure 2
[0202] Based on the above embodiments, the present application further provides an electronic device, which comprises at least one processor and at least one memory, and the at least one memory stores computer program instructions, and the electronic device runs, and the at least one processor performs the functions performed by the first electronic device in the methods described in the embodiments of the present application.
[0203] Based on the above embodiments, the present application further provides a computer program product comprising instructions, which, when executed on a computer, cause the computer to perform the methods described in the embodiments of the present application.
[0204] Based on the above embodiments, the present application further provides a computer readable storage medium, which stores a computer program, and when the computer program is executed by a computer, the computer performs the methods described in the embodiments of the present application.
[0205] Based on the above embodiments, the present application further provides a chip for reading a computer program stored in a memory, and realizing the methods described in the embodiments of the present application.
[0206] Based on the above embodiments, the present application provides a chip system, which comprises a processor for supporting a computer device to realize the methods described in the embodiments of the present application. In a possible design, the chip system further comprises a memory for saving necessary programs and data of the computer device. The chip system can be composed of a chip, or can comprise a chip and other discrete devices.
[0207] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems or computer program products. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage etc.) containing computer-usable program code.
[0208] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.
[0209] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.
[0210] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.
[0211] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A device authentication method, characterized in that: Applied to a first electronic device, the method includes: receiving an access request sent by a second electronic device; Sending a first authentication request message to the second electronic device; receiving first information sent by the second electronic device, where the first information is related to a device type of the second electronic device; Sending a second authentication request message to the server, where the second authentication request message is used to request obtaining the device credential of the second electronic device, and the second request message includes the first information; receiving device credential information of the second electronic device sent by the server, where the device credential information of the second electronic device is determined by the server according to the first information; Device authentication is performed on the second electronic device according to the device credential information of the second electronic device.
2. The method according to claim 1, wherein The device credential information of the second electronic device is a first slice of the device credential of the second electronic device; The method further comprises: receiving a second slice of the device credentials of the second electronic device sent by the second electronic device; The performing device authentication on the second electronic device according to the device credential information of the second electronic device includes: concatenating the first slice of the device credential of the second electronic device and the second slice of the device credential of the second electronic device to obtain a complete device credential of the second electronic device; Device authentication is performed on the second electronic device based on the complete device credentials of the second electronic device.
3. The method according to claim 1, wherein The device credential information of the second electronic device is a first slice of the device credential of the second electronic device; The performing device authentication on the second electronic device according to the device credential information of the second electronic device includes: Send a first slice of the device credentials of the second electronic device to the second electronic device, and receive the complete device credentials of the second electronic device sent by the second electronic device, where the complete device credentials of the second electronic device are obtained by concatenating the first slice of the device credentials of the second electronic device and the second slice of the device credentials of the second electronic device by the second electronic device; perform device authentication on the second electronic device based on the complete device credentials of the second electronic device.
4. The method according to any one of claims 1 to 3, wherein The first information includes at least one of a device identification of the second electronic device, a device credential index value of the second electronic device, and a second slice of the device credential of the second electronic device.
5. The method according to any one of claims 1 to 4, characterized in that The method further comprises: sending an access request to the second electronic device; receiving a third authentication request message sent by the second electronic device; The device credential of the first electronic device is sent to the second electronic device based on the device type of the second electronic device. The device credential of the first electronic device is used by the second electronic device to perform device authentication on the first electronic device.
6. The method according to claim 5, wherein The device credential of the first electronic device sent to the second electronic device based on the device type of the second electronic device includes: According to the preset correspondence between the device type and the device credential type of the receiving electronic device, the first device credential type corresponding to the device type of the second electronic device is determined; and the device credential of the first electronic device is sent to the second electronic device according to the first device credential type.
7. The method according to claim 5 or 6, wherein: The device credential of the first electronic device is a one-time credential or a personal identification PIN code.
8. The method according to any one of claims 1 to 7, wherein: The method further comprises: receiving a first request message sent by a third electronic device, where the first request message is used to request the first electronic device to assist the third electronic device in obtaining a device credential of the third electronic device; Sending a second request message to the server, where the second request message is used to request the server to obtain the device credential of the third electronic device; receiving the device credential of the third electronic device sent by the server; The device credential of the third electronic device is sent to the third electronic device.
9. An electronic device, characterized in that: The system comprises at least one processor coupled to at least one memory, and the at least one processor is configured to read a computer program stored in the at least one memory to execute the method according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, which, when executed on a computer, enable the computer to execute the method according to any one of claims 1 to 8.