Authentication method and electronic device

By using a cross-device authentication method and a second electronic device for identity authentication, the problem of smart devices failing to successfully collect user identity information is solved, improving the convenience and reliability of authentication and enhancing the user experience.

CN113641981BActive Publication Date: 2025-12-09HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110313313.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-02-10
Filing Date
2021-03-24
Publication Date
2025-12-09
Estimated Expiration
2041-03-24

AI Technical Summary

Technical Problem

When using smart devices, authentication failures due to the device's inability to successfully collect user identity information negatively impact the user experience.

Method used

The cross-device authentication method utilizes a second electronic device for identity authentication, obtains and matches identity information to resolve authentication failure issues, including the generation of cross-device authentication results and the matching of local authentication results.

Benefits of technology

It improves the convenience of cross-device authentication, enhances the user experience, and ensures the reliability and security of authentication results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113641981B_ABST
    Figure CN113641981B_ABST
Patent Text Reader

Abstract

The application provides an authentication method and an electronic device. The authentication method is executed by a first electronic device, and the method comprises the following steps: the first electronic device receives an authentication request, wherein the authentication request is used for requesting authentication of a first service; the first electronic device determines a risk security level corresponding to the first service; then the first electronic device determines an authentication mode meeting the risk security level according to the risk security level; finally, the first electronic device dispatches M electronic devices to authenticate the first service according to the authentication mode, wherein M is a positive integer. The authentication mode of the first service meets the corresponding risk security level, so that the security of the authentication result can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross Reference to Related Applications

[0002] The present application claims priority to a Chinese patent application No. 202110162842.7, filed on February 5, 2021, entitled “An authentication method and electronic device”; the present application also claims priority to a Chinese patent application No. 202010393895.5, filed on May 11, 2020, entitled “An authentication method, device and readable storage medium”; the present application also claims priority to a Chinese patent application No. 202110155795.3, filed on February 4, 2021, entitled “A cross-device authentication method and electronic device”; the present application also claims priority to a Chinese patent application No. 202110185361.8, filed on February 10, 2021, entitled “A data association method and electronic device”; the present application also claims priority to a Chinese patent application No. 202011063402.8, filed on September 30, 2020, entitled “A cross-device authentication method and related device”; the present application also claims priority to a Chinese patent application No. 202011070212.9, filed on September 30, 2020, entitled “A multi-device cooperative authentication method, device and system”. The above contents are incorporated herein by reference. TECHNICAL FIELD

[0003] The present application relates to the technical field of terminals, and in particular to an authentication method and electronic device. BACKGROUND

[0004] With the development of biometric technology and image recognition technology, in addition to the traditional user authentication method based on username and password, a user can also be authenticated by biometric information (e.g., face, fingerprint, voiceprint, etc.).

[0005] In actual application, a user uses a smart device currently being operated to locally authenticate a service being accessed. The authentication may fail due to the smart device failing to successfully collect the user's identity information locally. When the identity authentication fails, the smart device refuses to execute the service, which causes the user to fail to normally access the service and affects the user's experience. SUMMARY

[0006] The present application provides an authentication method and electronic device to implement cross-device authentication, which can improve the convenience of cross-device authentication and effectively improve the user experience.

[0007] In a first aspect, the method is applicable to a communication system composed of at least two electronic devices, the method can be executed by a first electronic device of the communication system, the first electronic device is connected with a second electronic device, and the method comprises the following steps: the first electronic device receives a first operation, in response to the first operation, the first electronic device performs local authentication on the first operation, in response to detecting that a local authentication result of the first electronic device is authentication failure, the first electronic device initiates cross-device authentication, wherein the cross-device authentication is used for the first electronic device to be authenticated by the second electronic device; the first electronic device acquires a cross-device authentication result; then the first electronic device determines that the cross-device authentication result is authentication success, and executes an instruction corresponding to the first operation, otherwise, the first electronic device does not execute the instruction corresponding to the first operation.

[0008] In the embodiments of the present application, the above method can realize cross-device authentication, improve the convenience of cross-device authentication, and effectively improve the user experience.

[0009] In a possible design, the first electronic device initiates the cross-device authentication, which comprises the following steps: the first electronic device sends a first request message to the second electronic device, the first request message is used for requesting to acquire a local authentication result of the second electronic device. The first electronic device acquires the cross-device authentication result, which comprises the following steps: the first electronic device receives a first response message from the second electronic device, the first response message comprises the cross-device authentication result, and the cross-device authentication result is the local authentication result of the second electronic device.

[0010] In the embodiments of the present application, the first electronic device can acquire the authentication result of the first operation of the second electronic device from the second electronic device by using the above method, thereby solving the problem that the first electronic device cannot successfully collect the identity information of the user, resulting in authentication failure.

[0011] In a possible design, the first electronic device initiates the cross-device authentication, which comprises the following steps: the first electronic device sends a second request message to the second electronic device, the second request message is used for requesting to acquire identity authentication information of the second electronic device; then the first electronic device receives a second response message from the second electronic device, the second response message comprises the identity authentication information of the second electronic device. The first electronic device acquires the cross-device authentication result, which comprises the following steps: the first electronic device authenticates the first operation according to the identity authentication information of the second electronic device, and generates the cross-device authentication result.

[0012] In the embodiments of the present application, the first electronic device can acquire the identity authentication information, such as face information, used for authenticating the first operation from the second electronic device by using the above method, so that the first electronic device authenticates the first operation by using the identity authentication information, thereby solving the problem that the first electronic device cannot successfully collect the identity information of the user, resulting in authentication failure.

[0013] In a possible design, the first electronic device stores preset information; the first electronic device can match the identity authentication information sent by the second electronic device with the preset information to generate a matching result; when the matching result is greater than a first preset threshold, the first electronic device determines that the local authentication result of the second electronic device is authentication passed, otherwise, the first electronic device determines that the local authentication result of the second electronic device is authentication failed.

[0014] In the embodiment of the present application, the first electronic device can obtain the identity authentication information from the second electronic device, so as to solve the problem that the first electronic device cannot successfully collect the identity information of the user. In addition, the first electronic device matches the preset information locally with the obtained identity information, so as to perform authentication by using the matching result. The authentication result can represent whether the identity authentication of the first electronic device to the user is passed.

[0015] In a possible design, the manner in which the first electronic device performs local authentication on the first operation can be that: the first electronic device stores preset information; in response to the first operation, the first electronic device obtains the identity authentication information of a user inputting the first operation; then the first electronic device matches the identity authentication information of the user with the preset information; and the first electronic device determines whether the local authentication result of the first electronic device is passed according to the matching result. Exemplarily, if the identity authentication information of the user inputting the first operation obtained by the first electronic device is incomplete, the local authentication result of the first electronic device can be failed.

[0016] In a possible design, the first electronic device determines whether the local authentication result of the first electronic device is passed according to the matching result, including: the first electronic device compares a matching degree in the matching result with a second preset threshold; when the matching degree is greater than the second preset threshold, the first electronic device determines that the local authentication result of the first electronic device is authentication passed, otherwise, the first electronic device determines that the local authentication result of the first electronic device is authentication failed. Exemplarily, if the identity authentication information of the user inputting the first operation obtained by the first electronic device is incomplete, the matching result can be less than the second preset threshold, and the local authentication result of the first electronic device can be failed.

[0017] In a possible design, the identity authentication information includes any one or more of face information, fingerprint information, voiceprint information, iris information, and touch screen behavior information; and the preset information includes any one or more of face information, fingerprint information, voiceprint information, iris information, and touch screen behavior information.

[0018] In a possible design, the first operation is any one of a screen unlocking operation, an application unlocking operation, or an operation on a function control in an application.

[0019] In a possible design, the first electronic device and the second electronic device log in to a same user account, and the user account is one of an instant messaging account, an email account, and a mobile phone number.

[0020] In a possible design, the method further includes: detecting, by the first electronic device, a distance between the first electronic device and the second electronic device; and determining, by the first electronic device, that the cross-device authentication result is passed, and in response to detecting that the distance between the first electronic device and the second electronic device is less than a first preset distance, executing, by the first electronic device, the instruction corresponding to the first operation.

[0021] In a possible design, the first electronic device detects the distance between the first electronic device and the second electronic device by using a Bluetooth positioning technology, an ultra-wideband (UWB) positioning technology, or a wireless fidelity (WiFi) positioning technology.

[0022] In a possible design, the connecting of the first electronic device and the second electronic device includes: establishing, by the first electronic device, a connection with the second electronic device by using a near field communication protocol, and the near field communication protocol includes one or more of a WiFi communication protocol, a UWB communication protocol, a Bluetooth communication protocol, a Zigbee communication protocol, or an NFC protocol.

[0023] In a possible design, before starting the cross-device authentication, the first electronic device further receives a second operation, the second operation is used to trigger starting of the cross-device authentication function, and in response to the second operation and in response to detecting that the local authentication result of the first electronic device is failed, the first electronic device starts the cross-device authentication.

[0024] In a possible design, the method further includes: obtaining, by the first electronic device, security state information of the second electronic device; determining, by the first electronic device, that the cross-device authentication result is passed, and determining, by the first electronic device, that the security state information of the second electronic device indicates that the second electronic device is in a secure state, and executing, by the first electronic device, the instruction corresponding to the first operation. For example, the first electronic device obtains a detection result of a security application of the second electronic device, and determines, according to the detection result, that the second electronic device does not have a virus such as a Trojan horse and further has a secure execution chip, and thus it can be determined that the second electronic device is a secure device, and the information obtained from the second electronic device is also secure.

[0025] In a second aspect, an embodiment of the present application provides an authentication method, which is applicable to a communication system composed of at least two electronic devices, and can be executed by a first electronic device of the communication system. The method includes: receiving, by the first electronic device, an authentication request, the authentication request being used to request authentication of a first service; determining, by the first electronic device, an authentication mode corresponding to the first service; and according to the authentication mode, scheduling M electronic devices to perform authentication on the first service, where M is a positive integer.

[0026] In the method, the same service is authenticated by at least two electronic devices using a single or multiple authentication factors, so that the security of the authentication result can be improved.

[0027] In a possible design, the first electronic device determines the authentication manner corresponding to the first service, including: the first electronic device determines a risk security level corresponding to the first service, and then the first electronic device determines an authentication manner meeting the security risk level according to the risk security level.

[0028] In the method, the authentication manner for the first service meets the corresponding risk security level, so that the security of the authentication result can be improved, and the authentication of the same service by at least two electronic devices can be implemented, so that the reliability of the authentication result can be ensured, and the authentication security level of the device can be improved. For example, for a high-security-level door opening service, a camera and a door lock are called to perform face authentication and fingerprint authentication, so that the reliability of the authentication result can be ensured, and the authentication security level of the device can be improved.

[0029] In a possible design, the first electronic device determines the authentication manner meeting the security risk level according to the risk security level, including: the first electronic device determines available authentication factors and available collection capabilities associated with the available authentication factors, and then determines the authentication manner meeting the security risk level according to the risk security level, the available authentication factors, and the available collection capabilities associated with the available authentication factors.

[0030] In the method, in the process of determining the authentication manner, the available authentication factors and the available collection capabilities associated with the available authentication factors are screened, so that the problem that the collection manner of the selected authentication factor is unavailable and causes collection failure can be avoided.

[0031] In a possible design, when the authentication request includes a biological feature, the biological feature is identified to determine a user corresponding to the biological feature, and then it is determined whether the user has the permission to perform the first service. If the user has the permission to perform the first service, the first electronic device schedules M electronic devices to authenticate the first service according to the authentication manner, otherwise, the first electronic device does not schedule the M electronic devices to authenticate the first service.

[0032] In the method, the permission of the user performing the operation can be further determined, so that the user without the operation permission can be prevented from accessing the first service, and the security of the first service being accessed can be ensured.

[0033] In a possible design, the first electronic device determines the authentication manner satisfying the risk security level according to the risk security level, including: the first electronic device determines available authentication factors associated with the user, and authentication capabilities and available collection capabilities associated with the available authentication factors; and the first electronic device determines the authentication manner satisfying the risk security level according to the risk security level, and the available authentication factors, the available authentication capabilities, and the available collection capabilities.

[0034] In the method, in the process of determining the authentication manner, the available authentication factors are screened from the available authentication factors, and the available collection capabilities and the authentication capabilities associated with the available authentication factors, to avoid the problem that the collection manner of the selected authentication factor is unavailable, resulting in collection failure, or the problem that the authentication manner of the selected authentication factor is unavailable, resulting in authentication failure.

[0035] In a possible design, the first electronic device determines the authentication manner according to the risk security level, including: the first electronic device determines the authentication manner satisfying the risk security level by using a decision strategy, where the decision strategy includes but is not limited to at least one of the following: preferentially using an already collected authentication factor for authentication; preferentially using a collection capability with a user-unaware feature to collect an authentication factor; and preferentially using a collection capability on a near-end device of the user to collect an authentication factor, where the near-end device is at least one of the M electronic devices.

[0036] In the method, the authentication manner determined by the first electronic device according to the decision strategy is more suitable for the current authentication scenario, and can effectively improve authentication efficiency and enhance user experience.

[0037] In a possible design, after the first electronic device schedules the M electronic devices to perform authentication on the first service, the method further includes: the first electronic device acquires authentication results of the M electronic devices from the M electronic devices; and the first electronic device aggregates the authentication results of the M electronic devices to generate a final authentication result.

[0038] In the method, when the first electronic device performs superimposed authentication on the same service by using at least two authentication factors, the final authentication result can be obtained by aggregating at least two authentication results. The method can improve reliability of the authentication result.

[0039] In a possible design, after the first electronic device schedules the M electronic devices to perform authentication on the first service, the method further includes: if the authentication is passed, the first electronic device instructs an operating device to perform the first service, where the operating device is at least one of the first electronic device and the M electronic devices.

[0040] In the method, the first electronic device can instruct the operation device to perform the first service only after passing the authentication according to the method, so as to guarantee the security of the first service.

[0041] In a possible design, the first electronic device further synchronizes resources in the M electronic devices to obtain a synchronized resource pool, where the resource pool includes the authentication factors, the collection capabilities, and the authentication capabilities of the M electronic devices.

[0042] The first electronic device determines an authentication mode that meets the security risk level according to the risk security level, and the authentication mode specifically includes:

[0043] The first electronic device determines an authentication mode that meets the security risk level according to the risk security level and the resource pool.

[0044] In the method, the first electronic device can obtain the authentication factors, the collection capabilities, and the authentication capabilities of each electronic device in the device networking by maintaining the resource pool, and thus can determine the authentication mode that meets the security risk level, which can enrich the authentication mode to some extent and facilitate the first electronic device to use a more suitable authentication mode to authenticate the first service.

[0045] In a possible design, the first electronic device is any one of the M electronic devices, or the first electronic device does not belong to the M electronic devices.

[0046] In a possible design, the M electronic devices are connected to the same local area network, and / or the M electronic devices are pre-bound to the same user account.

[0047] In a possible design, the first service is a door opening service, and the risk security level corresponding to the door opening service is a high risk security level.

[0048] Alternatively, the operation of triggering the access to the first service is a first operation on the smart home device, the first operation does not involve personal privacy data, and the risk security level corresponding to the first service is a low risk security level.

[0049] Alternatively, the operation of triggering the access to the first service is a second operation on the smart home device, the second operation involves personal privacy data but the risk is moderate, and the risk security level corresponding to the first service is a moderate risk security level.

[0050] Alternatively, the operation of triggering the access to the first service is a third operation on the smart home device, the third operation involves personal privacy data but the risk is high, and the risk security level corresponding to the first service is a high risk security level.

[0051] In a possible design, the first electronic device receives an authentication request, including: the first electronic device receiving a target operation, the target operation being used to trigger generation of the authentication request; the first electronic device determining an authentication manner corresponding to a first service, including: the first electronic device determining a target security value required for performing a target operation, the target operation being used to trigger performance of the first service; the first electronic device determining M1 authentication devices, M1 being a positive integer, the M1 authentication devices being devices having the capability of authenticating user information, and the M1 authentication devices being included in the M electronic devices. The first electronic device performs authentication on the first service according to the authentication manner, including: the first electronic device obtaining an authentication result of at least one authentication device of the M1 authentication devices; the first electronic device determining a total authentication security value according to a correspondence between an authentication manner and an authentication security value of the at least one authentication device and the authentication result; and if the total authentication security value is not less than the target security value, the authentication is passed. When the authentication is passed, the method further includes triggering the operation device to perform the target operation.

[0052] In a possible implementation, the operation device is configured to receive a target operation request, the target operation request being used to request performance of the target operation. It can be seen that, since the total authentication security value is determined according to the authentication result of at least one authentication device of the M1 authentication devices and the correspondence between the authentication manner and the authentication security value of the at least one authentication device, and the operation device is triggered to perform the target operation in a case where the total authentication security value is not less than the target security value required for performing the target operation, the required identity authentication level is provided for the target operation.

[0053] In a possible implementation, when M1 is equal to 1, the apparatus receives a first authentication request, the apparatus determines a target security value required for performing the target operation, the apparatus determines an authentication result of at least one authentication device of the authentication device, and the apparatus determines an authentication security value corresponding to the authentication device according to the correspondence between the authentication manner and the authentication security value of the at least one authentication device and the authentication result. If the authentication security value corresponding to the authentication device is not less than the target security value, the apparatus triggers the operation device to perform the target operation. In a case where M1 is equal to 1, the authentication security value corresponding to the authentication device determined by the apparatus is the total authentication security value mentioned in the method embodiment of the first aspect.

[0054] In a possible implementation, the manner in which the apparatus determines the M1 authentication devices includes: determining a set of authentication policy groups, the set of authentication policy groups including one or more authentication policies, and all authentication policies included in the set of authentication policy groups corresponding to a total authentication security value that is not less than the target security value; and determining, as one of the M1 authentication devices, an authentication device corresponding to each authentication policy in the set of authentication policy groups. The M1 authentication devices include a first authentication device. The set of authentication policy groups includes a first authentication policy, the first authentication policy including the first authentication device and a first authentication manner corresponding to the first authentication device, and the first authentication policy corresponding to a first authentication security value. In this way, the apparatus can determine that one authentication policy is used to authenticate the user information, or that a combination of multiple authentication policies is used to cooperatively authenticate the user information, thereby providing a required identity authentication level for the target operation.

[0055] In a possible implementation, in the process of determining the M1 authentication devices, the apparatus determines that there is one authentication device in authentication devices that are currently in a communicable state, and that in the case where the authentication device uses an authentication manner for authentication, the authentication manner corresponding to the authentication device corresponds to an authentication security value that is greater than the target security value. In this case, the authentication device can also be determined as the M1 authentication devices. In this implementation, M1 is 1. In other words, in this implementation, the set of authentication policy groups determined by the apparatus includes only one authentication policy.

[0056] In a possible implementation, the set of authentication policy groups further satisfies that the authentication manner corresponding to each authentication policy in all authentication policies included in the set of authentication policy groups is a biometric authentication manner. In this way, the user can complete authentication only by using the biometric authentication manner, thereby avoiding the cumbersome process of inputting a password.

[0057] In a possible implementation, at least one authentication policy in all authentication policies included in the set of authentication policy groups corresponds to an authentication security value that is lower than the target security value, and / or the set of authentication policy groups further satisfies that the authentication manner corresponding to each authentication policy in all authentication policies included in the set of authentication policy groups is a biometric authentication manner. When the user completes authentication only by using the biometric authentication manner, the cumbersome process of inputting a password can be avoided. When at least one authentication policy corresponds to an authentication security value that is lower than the target security value, it can be seen that, in this implementation, an authentication device with relatively low authentication capability can be combined to complete an authentication that requires a relatively high authentication level. In this way, when the user needs to perform an operation that requires a relatively high identity authentication, several authentication devices with relatively low authentication capability can be used to cooperatively authenticate, thereby improving the security of identity authentication.

[0058] In a possible implementation, each authentication policy in the authentication policy group corresponds to an authentication security value lower than the target security value, and / or the authentication policy group further satisfies that each authentication policy in the authentication policy group corresponds to a biometric authentication manner. When the user completes authentication only through the biometric authentication manner, the user can be exempted from the cumbersome password input process. When each authentication policy corresponds to an authentication security value lower than the target security value, it can be seen that, in this implementation, the user can complete an authentication with a higher authentication level only through authentication devices with lower authentication capabilities. Therefore, when the user needs to perform an operation with a higher authentication requirement, the user can also perform collaborative authentication through several authentication devices with lower authentication capabilities, thereby improving the security of identity authentication.

[0059] In a possible implementation, the target operation and the authentication policy group have a preset correspondence, and / or the authentication policy group further satisfies that each authentication policy in the authentication policy group corresponds to a biometric authentication manner. When the user completes authentication only through the biometric authentication manner, the user can be exempted from the cumbersome password input process. When the target operation and the authentication policy group have a preset correspondence, it can be seen that, in this implementation, the user can customize authentication policies for some operations, thereby improving the flexibility of the scheme.

[0060] In a possible implementation, at least one authentication policy in the authentication policy group corresponds to an authentication security value not lower than the target security value, and / or the authentication policy group further satisfies that each authentication policy in the authentication policy group corresponds to a biometric authentication manner. When the user completes authentication only through the biometric authentication manner, the user can be exempted from the cumbersome password input process. When at least one authentication policy in the authentication policy group corresponds to an authentication security value not lower than the target security value, the probability that the total authentication security value is not less than the target security value can be improved.

[0061] To improve the flexibility of the scheme, in another possible implementation, the manner in which the apparatus determines the M1 authentication devices includes that the apparatus determines, as the M1 authentication devices, authentication devices that satisfy a preset condition, the preset condition being that the apparatus and the first authentication device are in a communication-reachable state. Moreover, the scheme can simplify the scheme of the apparatus in determining the M1 authentication devices. In a possible implementation, in the process of determining the M1 authentication devices, the apparatus determines that there is only one authentication device in a communication-reachable state, and the apparatus determines, as the M1 authentication devices, the authentication device in the communication-reachable state. In this implementation, M1 is 1.

[0062] In a possible implementation, the device is the operation device, or the device is a router, or the device is one of the M1 authentication devices, or the operation device is one of the M1 authentication devices, the device is one of the M1 authentication devices other than the operation device, or the device is located in a server.

[0063] In a possible implementation, when the device is one of the M1 authentication devices, the determining the authentication result of at least one of the M1 authentication devices comprises: the device authenticates the user information to determine the authentication result corresponding to the device; and the device receives a second authentication response returned by each of the M1 authentication devices other than the device, and determines the authentication result of at least one of the M1 authentication devices according to the second authentication response. The second authentication response is sent by the at least one authentication device to the device after the at least one authentication device completes the authentication of the user information, in which case the authentication result can be authentication success or authentication failure. Alternatively, the second authentication response is sent by the at least one authentication device to the device after the at least one authentication device fails to complete the authentication of the user information within a predetermined time, in which case the authentication device sends the second authentication response to the device after failing to complete the authentication of the user information within the predetermined time, i.e., the authentication result is authentication failure. For example, the predetermined time can be a time period starting from receiving the second authentication request, for example, within 10 seconds or 2 minutes after receiving the second authentication request. The second authentication response returned by the first authentication device is used to indicate the authentication result of the first authentication device. That is, the device used to perform the authentication method can be one of the M1 authentication devices, and in this case, the device can also perform the authentication of the user information.

[0064] In a possible implementation, when the device is not one of the M1 authentication devices, such as a server, a router, or an operation device without authentication capability, in this case, the device receives a second authentication response returned by each of the M1 authentication devices, and determines the authentication result of at least one of the M1 authentication devices according to the second authentication response; the second authentication response is sent by the at least one authentication device to the device after the at least one authentication device completes the authentication of the user information, in which case the authentication result can be authentication success or authentication failure. Alternatively, the second authentication response is sent by the at least one authentication device to the device after the at least one authentication device fails to complete the authentication of the user information within a predetermined time, in which case the authentication result is authentication failure. The second authentication response returned by the first authentication device is used to indicate the authentication result of the first authentication device.

[0065] In a possible implementation, when the first condition is met, i.e., the device is the operation apparatus, the device triggers the operation apparatus to perform the target operation, including: the device performing the target operation.

[0066] In another possible implementation, when the first condition is not met, i.e., the device is not the operation apparatus, such as the device being a router, or the device being one of the M1 authentication apparatuses, or the operation apparatus being one of the M1 authentication apparatuses, the device being one of the M1 authentication apparatuses other than the operation apparatus, or the device being a server, in this case, the device triggers the operation apparatus to perform the target operation, including: the device sending a first authentication success response to the operation apparatus; wherein the first authentication success response is used to indicate that the device succeeds in authenticating the target operation. Subsequently, after the operation apparatus receives the first authentication success response, the above-mentioned target operation can be performed.

[0067] In a possible implementation, after the device determines the target security value required for performing the target operation, before determining the M1 authentication apparatuses, the method further includes: when the operation apparatus has authentication capability, the device determines that the authentication security value of the operation apparatus is less than the target security value. In this way, when the authentication capability of the operation apparatus is insufficient, the help of other authentication apparatuses is sought, thereby improving the rationality of the scheme.

[0068] In another possible implementation, after the device determines the target security value required for performing the target operation, the method further includes: when the operation apparatus has authentication capability, the device determines that the authentication security value of the operation apparatus is not less than the target security value; when the first condition is met, the method further includes: the device authenticating the user information; when the device succeeds in authenticating the user information, performing the target operation. When the first condition is not met, the method further includes: the device sending a third authentication request to the operation apparatus, wherein the third authentication request is used to request: the operation apparatus authenticating the user information, and performing the target operation when the authentication of the user information succeeds. In this way, when the authentication capability of the operation apparatus is sufficient, the operation apparatus performs the authentication, thereby improving the rationality of the scheme.

[0069] In a possible implementation, the device determines the target security value required for performing the target operation, including: the device determining, according to a preset correspondence between operations and security values, a security value corresponding to the target operation as the target security value. In this way, the correspondence between operations and security values can be preset, thereby providing the operations with authentication capability of a corresponding security level.

[0070] In a possible implementation, the authentication security value of an authentication device is associated with a root key storage environment of the authentication device and an authentication mode adopted by the authentication device. In this way, the authentication security value of the authentication mode of an authentication device can be determined according to the root key storage environment and the authentication mode, and the authentication security value can more comprehensively reflect the authentication capability of the authentication device.

[0071] In a possible implementation, before determining the total authentication security value according to the correspondence between the authentication mode and the authentication security value of the at least one authentication device and the authentication result, the apparatus further includes: determining a root key storage environment score corresponding to the root key storage environment of the first authentication device according to a preset correspondence between a root key storage environment and a root key storage environment score and the root key storage environment of the first authentication device; determining an authentication mode score corresponding to the authentication mode of the first authentication device according to a preset correspondence between an authentication mode and an authentication mode score and the authentication mode of the first authentication device; and calculating the authentication security value of the authentication mode of the first authentication device according to a first calculation rule, the root key storage environment score and the authentication mode score corresponding to the authentication mode of the first authentication device. In this way, the authentication security value of the authentication mode of an authentication device can be determined according to the root key storage environment and the authentication mode, and the authentication security value can more comprehensively reflect the authentication capability of the authentication device.

[0072] In a possible implementation, the apparatus determines the total authentication security value according to the correspondence between the authentication mode and the authentication security value of the at least one authentication device and the authentication result, and includes: when the authentication result corresponding to the first authentication device is authentication success, determining the authentication security value of the authentication mode of the first authentication device according to the correspondence between the authentication mode and the authentication security value of the first authentication device; when the authentication result corresponding to the first authentication device is authentication failure, determining the authentication security value of the authentication mode of the first authentication device as 0; and calculating the total authentication security value according to the authentication security value of the authentication mode of each of the M1 authentication devices and a second calculation rule. In this way, the total authentication security value can reflect the total authentication capability of the M1 authentication devices currently performing authentication, so that whether to allow the target operation to be performed is determined according to the total authentication capability.

[0073] In a possible implementation, after the device determines the M1 authentication devices, before the device determines the authentication result of at least one of the M1 authentication devices, when the device is not an authentication device, for example, the device is an operating device, a server, or a router without authentication capability, the device sends a second authentication request to each of the M1 authentication devices, where the second authentication request is used to request the authentication device to authenticate the user information. Or, when the device is one of the M1 authentication devices, the device sends a second authentication request to each of the M1 authentication devices except the device.

[0074] In a possible implementation, the M1 authentication devices include a first authentication device, and the device sends a second authentication request to each of the M1 authentication devices, including: the device sends the second authentication request to the first authentication device, and the second authentication request carries indication information used to indicate a first authentication manner of the first authentication device. In this way, the first authentication device can authenticate the user information by using the first authentication manner indicated in the second authentication request.

[0075] In a possible implementation, before the device sends the second authentication request to the first authentication device, the device determines the first authentication manner of the first authentication device in the following ways:

[0076] determining all or part of the authentication manners supported by the first authentication device as the first authentication manner of the first authentication device;

[0077] determining all or part of the biometric authentication manners supported by the first authentication device as the first authentication manner of the first authentication device, so that the cumbersome password input process can be avoided;

[0078] determining one of the authentication manners supported by the first authentication device as the first authentication manner of the first authentication device, where the one of the authentication manners has the highest authentication security value, so that the authentication security level of authenticating the user information can be improved;

[0079] determining one of the biometric authentication manners supported by the first authentication device as the first authentication manner of the first authentication device, where the one of the biometric authentication manners has the highest authentication security value, so that the cumbersome password input process can be avoided and the authentication security level of authenticating the user information can be improved.

[0080] In a possible implementation, to improve flexibility of the scheme, before determining the authentication result of at least one of the M1 authentication devices, the apparatus further includes: receiving, by the apparatus, a first message sent by the first authentication device, the first message carrying indication information indicating an authentication mode supported by the first authentication device. Alternatively, the apparatus sends a query request to the first authentication device, the query request being used to query an authentication mode supported by the first authentication device, and the apparatus receives a query response returned by the first authentication device, the query response carrying the indication information indicating the authentication mode supported by the first authentication device.

[0081] In a possible implementation, the apparatus is a router, an operation device, one of the M1 authentication devices, or located in a server. When the apparatus is the router, the router, the operation device, and the M1 authentication devices are in the same local area network, so that data between the apparatus, the operation device, and the authentication devices can be transmitted through the same local area network, and the data transmission speed can be improved.

[0082] In a possible design, the first electronic device receives an authentication request, including: the first electronic device receives a first operation, the first operation being used to trigger generation of the authentication request; and the determining of the authentication mode corresponding to the first service includes: determining a first authentication mode corresponding to the first service.

[0083] The method further includes: the first electronic device detecting, according to the first authentication mode, whether a local authentication result of the first electronic device is passed in response to receiving the first operation; and in response to detecting that the local authentication result of the first electronic device is not passed, the first electronic device determining the authentication mode corresponding to the first service, further including: determining a second authentication mode corresponding to the first service.

[0084] The method further includes: the first electronic device sending, according to the second authentication mode, a request for obtaining a local authentication result of the second electronic device to the second electronic device; the first electronic device receiving the local authentication result of the second electronic device sent by the second electronic device; in response to receiving the local authentication result of the second electronic device, detecting whether the local authentication result of the second electronic device is passed; and in response to detecting that the local authentication result of the second electronic device is passed, the first electronic device executing an instruction corresponding to the first operation.

[0085] In this way, the identity of the first electronic device can be authenticated through the local authentication result of the second electronic device, effectively improving the convenience of cross-device authentication and creating a better user experience.

[0086] In a possible implementation, after the first electronic device receives the first operation, the method further includes: detecting, by the first electronic device, whether the first operation triggers a locked low-risk application; and in response to detecting that the first operation triggers the locked low-risk application, detecting, by the first electronic device, whether the local authentication result of the first electronic device is passed. In this way, for the locked low-risk application, the identity authentication of the first electronic device can be implemented by using the local authentication result of the second electronic device, and the convenience of controlling the locked low-risk application is effectively improved.

[0087] In a possible implementation, when the first operation is a first voice instruction, before the first electronic device detects whether the local authentication result of the first electronic device is passed, the method further includes: detecting, by the first electronic device, whether a voiceprint feature in the first voice instruction conforms to a voiceprint feature of a preset user; and in response to detecting that the voiceprint feature in the first voice instruction conforms to the voiceprint feature of the preset user, detecting, by the first electronic device, whether the local authentication result of the first electronic device is passed. In this way, the first electronic device can implement voice control of the first electronic device based on the local authentication result of the second electronic device, and the convenience of voice control is improved.

[0088] In a possible implementation, the first electronic device performs local continuous authentication and generates the local authentication result of the first electronic device at the same time as or after the first electronic device receives the first operation, and the manner in which the first electronic device performs the local continuous authentication includes at least one of the following: face recognition authentication, iris recognition authentication, and touch screen behavior recognition authentication; and the local authentication result of the first electronic device can represent whether the identity authentication of the first electronic device is passed.

[0089] In a possible implementation, the second electronic device performs local continuous authentication and generates the local authentication result of the second electronic device at the same time as or before the first electronic device receives the first operation; and the manner in which the second electronic device performs the local continuous authentication includes at least one of the following: face recognition authentication, iris recognition authentication, and touch screen behavior recognition authentication; and the local authentication result of the second electronic device can represent whether the identity authentication of the second electronic device is passed.

[0090] In a possible implementation, before the first electronic device executes the instruction corresponding to the first operation, the method further includes: detecting, by the first electronic device, a distance between the first electronic device and the second electronic device; and in response to detecting that the distance between the first electronic device and the second electronic device is less than a first preset distance, executing, by the first electronic device, the instruction corresponding to the first operation. In this way, while the convenience of identity authentication is improved by using cross-device authentication, the security of cross-device authentication is ensured by limiting the distance between the first electronic device and the second electronic device.

[0091] In a possible implementation, before the first electronic device executes the instruction corresponding to the first operation, the method further includes: detecting, by the first electronic device, whether the first electronic device is in a secure state; and in response to detecting that the first electronic device is in the secure state, executing, by the first electronic device, the instruction corresponding to the first operation. In this way, the convenience of identity authentication is improved by using cross-device authentication, and the security of cross-device authentication is ensured by confirming the secure state of the second electronic device.

[0092] In a possible implementation, before the first electronic device executes the instruction corresponding to the first operation, the method further includes: detecting, by the first electronic device, whether the priority of the local continuous authentication of the second electronic device is lower than the priority of the local continuous authentication of the first electronic device; and in response to detecting that the priority of the local continuous authentication of the second electronic device is not lower than the priority of the local continuous authentication of the first electronic device, executing, by the first electronic device, the instruction corresponding to the first operation. In this way, the convenience of identity authentication is improved by using cross-device authentication, and the security of cross-device authentication is ensured by confirming that the priority of the local continuous authentication of the second electronic device is not lower than the priority of the local continuous authentication of the first electronic device.

[0093] In a possible design, the first electronic device receives an authentication request, including:

[0094] The first electronic device receives a target operation on a first interface of the first electronic device, where the target operation is used to trigger access to the first service, and the first service is associated with the second electronic device; the first electronic device determines an authentication manner corresponding to the first service, including: the first electronic device acquires a target authentication manner corresponding to the first service; and the first electronic device schedules M electronic devices to perform authentication on the first service according to the authentication manner, including: the first electronic device collects authentication information according to the target authentication manner.

[0095] The first electronic device sends an authentication request to the second electronic device, where the authentication request includes authentication information, and the authentication request is used to request the second electronic device to perform authentication on the first service, and the second electronic device is included in the M electronic devices.

[0096] The first service is associated with the second electronic device, which can mean that the first service is a service in the second electronic device, or the first service is related to sensitive data of the second electronic device, or the first service is a service of the second electronic device.

[0097] In the method, the first electronic device can collect the authentication information, and the second electronic device can authenticate the authentication information, so as to collect the authentication information across devices, improve the convenience of the authentication operation, avoid the user operation on multiple electronic devices, and improve the user experience. In addition, the first electronic device and the second electronic device cooperatively authenticate the first service, so as to improve the security of the authentication result, and avoid the problem that the security of the authentication result is low due to the limitation of hardware or insufficient authentication and collection capabilities of a single electronic device.

[0098] In a possible design, the method further includes: the first electronic device receives the authentication result sent by the second electronic device; and the first electronic device responds to the target operation according to the authentication result. For example, in a non-multi-screen cooperation scenario, the first electronic device can respond to the payment operation with a payment success or a payment failure according to the authentication result of the second electronic device.

[0099] In a possible design, the method further includes: the first electronic device receives the authentication result sent by the second electronic device; and the first electronic device switches from displaying the first interface to displaying a second interface in response to the authentication result, where the second interface includes a result of triggering the first service. For example, in a multi-screen cooperation scenario, after the second electronic device authenticates the payment operation, the interface is switched, and the interface is synchronized to the first electronic device, so that the first electronic device also switches the interface.

[0100] In a possible design, the multi-screen cooperation scenario refers to that the first electronic device and the second electronic device perform multi-screen cooperation, the target operation is a first object acting on a first window in the first interface, the first window is a display window of the second electronic device, and the first service is a service of the second electronic device.

[0101] In a possible design, the first electronic device obtains the target authentication manner corresponding to the first service, including:

[0102] The first electronic device obtains the target authentication manner corresponding to the first service from the first electronic device. It should be understood that, before this, the first electronic device needs to synchronize resources with the second electronic device, that is, the first electronic device and the second electronic device need to synchronize the authentication manners corresponding to different services or the authentication manners corresponding to different operations, so as to facilitate the first electronic device to decide the target authentication manner corresponding to the first service. If the first electronic device has a secure execution environment, the method can improve the security of the authentication result to a certain extent.

[0103] In a possible design, the first electronic device can obtain, from the second electronic device, a target authentication manner corresponding to the first service. Alternatively, the first electronic device can send a request message to the second electronic device, and then the second electronic device sends an authentication manner to the first electronic device. In this method, the first electronic device decides the target authentication manner corresponding to the first service. Optionally, the first electronic device can also synchronize resources with the second electronic device, that is, the first electronic device and the second electronic device synchronize authentication manners corresponding to different services or authentication manners corresponding to different operations, so as to facilitate the first electronic device to decide the target authentication manner corresponding to the first service. For example, in the case that the first electronic device has a collection capability, the first electronic device is preferred to be used for collection.

[0104] In addition, an authentication method is provided in the embodiments of this application, which can be applied to a second electronic device, and the first electronic device and the second electronic device can be connected through a wired or wireless manner. The method comprises the following steps.

[0105] The second electronic device receives a request message from the first electronic device, where the request message is used to request a target authentication manner corresponding to a first service, and the first service is associated with the second electronic device. The second electronic device sends the target authentication manner corresponding to the first service to the first electronic device. The second electronic device can also receive an authentication request from the first electronic device, where the authentication request comprises authentication information. Then, the second electronic device performs authentication on the first service according to the authentication information, and generates an authentication result.

[0106] In this method, the second electronic device decides the target authentication manner corresponding to the first service, and the second electronic device performs authentication by using the authentication information obtained from the first electronic device, which can complete cooperative authentication of the first electronic device and the second electronic device, so as to improve the security and reliability of the authentication result, and avoid the problem that the security of the authentication result is low due to the limitation of hardware or insufficient authentication capability and collection capability of a single device.

[0107] In a possible design, the method further comprises the following step: the second electronic device sends the authentication result to the first electronic device, where the authentication result is used to trigger the first electronic device to respond to a target operation triggering the first service.

[0108] In a possible design, the second electronic device can respond to the target operation triggering the first service according to the authentication result, switch from a first interface to a second interface, where the second interface comprises a result of triggering the first service, and then synchronize the second interface to the first electronic device.

[0109] In a possible design, the first service is associated with the second electronic device, and the first service comprises the following steps.

[0110] The first service is a service in the second electronic device, or the first service is associated with sensitive data of the second electronic device, or the first service is a service of the second electronic device.

[0111] In a possible design, the first electronic device and the second electronic device perform multi-screen cooperation, the target operation for triggering access to the first service is a first object acting on a first window, the first window is a display window of the second electronic device, and the first service is a service of the second electronic device.

[0112] In a possible design, an embodiment of the present application provides a cross-device authentication method, which can be applied to a first electronic device connected with a second electronic device, and the method comprises the following steps.

[0113] The first electronic device receives a target operation of a user acting on the first electronic device, the target operation is used to trigger access to a first service, the first service is associated with the second electronic device; the first electronic device determines an authentication mode corresponding to the first service according to a resource pool, the resource pool comprises an authentication mode corresponding to an operation of the second electronic device and a template of authentication information; the first electronic device collects authentication information according to the authentication mode; and then the first electronic device performs authentication on the first service by using the authentication information, to generate an authentication result.

[0114] Optionally, the first electronic device can further send the authentication result to the second electronic device, so that the second electronic device responds.

[0115] In the method, the first electronic device collects authentication information and performs authentication by using the authentication mode obtained from the second electronic device, to improve the convenience of the authentication operation, avoid the user performing operations on multiple electronic devices, and improve the user experience. In addition, the first electronic device and the second electronic device perform authentication on the first service in cooperation, to improve the security of the authentication result, and avoid the problem that the security of the authentication result is low due to the limitation of hardware or insufficient authentication and collection capabilities of a single electronic device.

[0116] In a possible design, before the first electronic device receives the target operation of the user acting on the first electronic device, the method further comprises the following steps.

[0117] The first electronic device can further synchronize resources from the second electronic device to generate a resource pool, and the resource pool further comprises an authentication mode corresponding to an operation of the first electronic device and a template of authentication information. In this way, the first electronic device can determine the authentication mode by using the resource pool, and perform authentication on the collected authentication information by using the template of authentication information.

[0118] In a possible design, before the first electronic device receives the authentication request, the method further comprises the following steps.

[0119] The first electronic device receives an operation of a user, the operation including feature information input by the user, the feature information being associated with a user identifier of the user; the feature information is matched by using a first feature template in the first electronic device, to generate a first matching result; then the first electronic device sends the feature information to a second electronic device; the second electronic device matches the feature information by using a second feature template in the second electronic device to obtain a second matching result, and the first electronic device acquires the second matching result from the second electronic device. When the first matching result and the second matching result are both matching successes, the first electronic device establishes an association relationship between the first feature template, the second feature template, and the user identifier.

[0120] The method can associate feature templates of the same user in multiple electronic devices, so that, in a new-old device replacement scenario, the user can acquire the feature templates on each device belonging to the same user according to the association relationship, and then distribute the feature templates on each old device to the new electronic device correspondingly, to realize one-key migration of the feature templates on the new and old devices.

[0121] In a possible design, the method further includes: the first electronic device acquires usage constraint conditions of the first feature template and the second feature template; and the first electronic device establishes an association relationship between the first feature template, the second feature template, and the usage constraint conditions. The usage constraint conditions can include at least one of the following constraint conditions: 1, a constraint condition on usage permission of the feature template; 2, a constraint condition on a device environment to which the feature template is applicable; 3, a constraint condition on a service to which the feature template is applicable; and 4, a constraint condition on a security level of the feature template. For example, the user configures usage constraint conditions of the first feature template and the second feature template on the first electronic device, such as configuring applicable services, so that the first electronic device can acquire the usage constraint conditions of the first feature template and the second feature template according to the configuration information of the user. For another example, the first electronic device can acquire the usage constraint conditions of the first feature template and the second feature template from a cloud server or another device. In the method, the feature template is associated with the usage constraint conditions, so that the usage scenario of the feature template can be constrained, and the feature template can be prevented from being misused.

[0122] In a possible design, the method further includes: the first electronic device can share first record information and / or second record information to the second electronic device; wherein the first record information includes an association relationship between the first feature template, the second feature template, and the user identifier; and the second record information includes an association relationship between the first feature template, the second feature template, and the usage constraint conditions. In this way, other electronic devices can provide personalized services for the user according to the record information, such as providing cross-device authentication or device collaborative authentication services.

[0123] In a possible design, the feature information includes user secret data and / or biometric feature data, the first feature template includes a template of the user secret data and / or a template of the biometric feature data, and the second feature template includes the template of the user secret data and / or the template of the biometric feature data.

[0124] In a possible design, the second electronic device and the first electronic device are connected to a same local area network, and / or the second electronic device and the first electronic device are pre-bound to a same user account.

[0125] In addition, an embodiment of the present application provides a data association method, which can be applied to a first electronic device, and the method includes: receiving, by the first electronic device, a first operation of a user, the first operation being used to request input of a first feature template; in response to the first operation, performing, by the electronic device, authentication on the identity of the user by using an existing second feature template, wherein the second feature template is associated with a user identifier of the user; when the authentication is passed, receiving a first feature template input by the user; and establishing an association relationship between the first feature template and the user identifier.

[0126] In the method, because the second feature template is bound to the user identifier, the identity of the user can be authenticated by using the second feature template, and in the case that the authentication is passed, the association relationship between the first feature template and the user identifier can be established, so that the features belonging to the same user in the electronic device can be associated together. The association relationship can be shared to other electronic devices, so that the other electronic devices can provide personalized services for the user according to the record information, such as providing cross-device authentication or device collaborative authentication services.

[0127] In a possible design, the electronic device receives a second operation of the user; the second operation is used to trigger association of an already-input third feature template with the user identifier; and in response to the second operation, the electronic device establishes an association relationship between the third feature template and the user identifier. According to the method, the user can manually associate the already-input feature templates in the electronic device.

[0128] In a possible design, before the electronic device receives the second operation of the user, if the user cannot distinguish which feature templates belong to the same user by relying on the naming information of the feature templates alone, the method can further include a feature template identification process. Specifically, the electronic device can further receive feature information input by the user; and match the feature information input by the user with at least one feature template in the first electronic device, to determine the third feature template that matches the feature input by the user.

[0129] In a possible design, the method further includes: the electronic device obtaining a use constraint condition corresponding to the third feature template; and the electronic device establishing an association between the third feature template and the use constraint condition. The use constraint condition can include at least one of the following constraint conditions: 1, a constraint condition on a use permission of the feature template; 2, a constraint condition on a device environment to which the feature template is applicable; 3, a constraint condition on a service to which the feature template is applicable; and 4, a constraint condition on a security level of the feature template.

[0130] In the method, after the feature template and the use constraint condition are associated, the user can share record information including the use constraint condition to other trusted devices, such as other electronic devices or a hub device in a device group network, so that the other electronic devices can provide personalized services for the user according to the record information, such as providing cross-device authentication or device collaborative authentication services.

[0131] In a possible design, after the first electronic device receives the first feature template input by the user, the method further includes: the first electronic device sending the first feature template to a second electronic device, where the second electronic device is connected to the first electronic device. The second electronic device matches the feature information with a fourth feature template in the second electronic device to obtain a matching result, and the first electronic device obtains the matching result from the second electronic device; and when the matching results are both successful, an association between the fourth feature template, the first feature template and the user identifier is established.

[0132] The method can associate feature templates of the same user in multiple electronic devices, so that when the user is in a new-old device replacement scenario, the user can obtain feature templates on devices belonging to the same user according to the association, and then distribute the feature templates on the old devices to the new electronic devices correspondingly, to realize one-key migration of the feature templates on the new and old devices.

[0133] In a possible design, the method further includes: the electronic device sharing record information to the second electronic device, where the record information includes an association between the fourth feature template, the first feature template and the user identifier. In this way, the other electronic devices can provide personalized services for the user according to the record information, such as providing cross-device authentication or device collaborative authentication services.

[0134] In a possible design, the feature information includes user secret data and / or biometric data, the first feature template includes a template of the user secret data and / or a template of the biometric data, and the second feature template includes the template of the user secret data and / or the template of the biometric data.

[0135] In a possible design, the second electronic device and the first electronic device are connected to a same local area network, and / or the second electronic device and the first electronic device are pre-bound to a same user account.

[0136] In a third aspect, an embodiment of the present application provides a first electronic device, including a processor and a memory, where the memory is configured to store one or more computer programs; and when the one or more computer programs stored in the memory are executed by the processor, the first electronic device is enabled to implement any of the methods performed by the first electronic device in any of the possible designs of the first aspect.

[0137] In a fourth aspect, an embodiment of the present application provides a second electronic device, including a processor and a memory, where the memory is configured to store one or more computer programs; and when the one or more computer programs stored in the memory are executed by the processor, the second electronic device is enabled to implement any of the methods performed by the second electronic device in any of the possible designs of the first aspect.

[0138] In a fifth aspect, a communication apparatus is provided, including a receiving apparatus and a processor, to perform any of the embodiments of the methods in the first aspect.

[0139] The processor can be configured to invoke and run the computer program or the instruction from the memory, and when the processor executes the computer program or the instruction in the memory, the communication apparatus can perform any of the embodiments of the methods in the first aspect.

[0140] Optionally, the processor can be one or more.

[0141] The receiving apparatus is configured to perform functions related to receiving. The receiving apparatus can be a receiving unit. In one design, the communication apparatus can be a communication chip, and the receiving apparatus can be an input circuit or a port of the communication chip. In another design, the receiving apparatus can also be a receiver, or a receiver.

[0142] In one possible implementation, the communication apparatus can further include a sending apparatus, configured to perform functions related to sending. The sending apparatus can be a sending unit. In one design, the communication apparatus can be a communication chip, and the sending apparatus can be an output circuit or a port of the communication chip. In another design, the sending apparatus can also be a transmitter, or a transmitter.

[0143] In a sixth aspect, a communication apparatus is provided, which can be the apparatus for performing the authentication method. The communication apparatus comprises a processor and a memory. Optionally, the communication apparatus further comprises a communication interface. The memory is configured to store a computer program or instructions. The processor is configured to invoke and execute the computer program or instructions stored in the memory. When the processor executes the computer program or instructions stored in the memory, the communication apparatus can perform any of the embodiments of the method in the first aspect via the communication interface.

[0144] Optionally, the processor can be one or more, and the memory can be one or more.

[0145] Optionally, the memory can be integrated with the processor, or the memory can be separately arranged from the processor.

[0146] Optionally, the communication interface can be an input / output circuit or port, and can also be a transmitter and a receiver, or a transmitter and a receiver.

[0147] In a seventh aspect, a communication apparatus is provided, which comprises a processor. The processor is coupled with a memory and can be configured to execute the method in the first aspect and any possible implementation manner of the first aspect. Optionally, the communication apparatus further comprises the memory. Optionally, the communication apparatus further comprises a communication interface, and the processor is coupled with the communication interface.

[0148] In another implementation manner, the communication apparatus can be the apparatus for performing the method in the first aspect. The communication interface can be a transceiver, or an input / output interface. Optionally, the transceiver can be a transceiving circuit. Optionally, the input / output interface can be an input / output circuit.

[0149] In yet another implementation manner, the communication apparatus can also be a chip or a chip system. When the communication apparatus is a chip or a chip system, the communication interface can be an input / output interface, an interface circuit, an output circuit, an input circuit, a pin or related circuit on the chip or the chip system. The processor can also be embodied as a processing circuit or a logic circuit.

[0150] In an eighth aspect, an authentication system is provided, which comprises a plurality of electronic devices connected with each other, and the plurality of electronic devices comprises a collection device, an authentication device and a decision device.

[0151] The decision device is configured to receive an authentication request, and the authentication request is used to request authentication of a first service; and determine an authentication mode corresponding to the first service.

[0152] The decision device is further configured to, according to the authentication mode, schedule the collection device to collect an authentication factor, and schedule the authentication device to perform authentication.

[0153] The collection device is configured to collect at least one authentication factor and send the at least one authentication factor to the authentication device.

[0154] The authentication device is configured to authenticate the at least one authentication factor to obtain at least one authentication result and send the at least one authentication result to the decision device.

[0155] The decision device is configured to process the at least one authentication result to obtain an authentication result of the first service.

[0156] In a possible design of the present disclosure, when determining the authentication manner corresponding to the first service, the decision device is specifically configured to:

[0157] determine a risk security level corresponding to the first service;

[0158] determine the authentication manner satisfying the security risk level according to the risk security level.

[0159] In a possible design of the present disclosure, the system further includes a service device.

[0160] The service device is configured to receive a target operation, where the target operation is used to trigger generation of the authentication request and send the authentication request to the decision device.

[0161] When the decision device receives the authentication request, the decision device is specifically configured to receive the authentication request from the service device.

[0162] When the decision device determines the authentication manner corresponding to the first service, the decision device is specifically configured to: determine a target security value required for performing the target operation, where the target operation is used to trigger performance of the first service; and determine M1 authentication devices, where M1 is a positive integer, the M1 authentication devices are devices having the capability of authenticating user information, and the M1 authentication devices are included in the M electronic devices.

[0163] When the decision device processes the at least one authentication result to obtain the authentication result of the first service, the decision device is specifically configured to:

[0164] obtain an authentication result of at least one authentication device in the M1 authentication devices;

[0165] determine a total authentication security value according to a correspondence between the authentication manner and the authentication security value of the at least one authentication device and the authentication result;

[0166] if the total authentication security value is not less than the target security value, the authentication is passed.

[0167] The decision device is further configured to trigger the operation device to perform the target operation.

[0168] In a possible design of the method, when the decision device receives the authentication request, the decision device is specifically configured to receive a first operation, where the first operation is used to trigger generation of the authentication request.

[0169] The decision device determines the authentication manner corresponding to the first service, and is specifically configured to:

[0170] The decision device determines the first authentication manner corresponding to the first service.

[0171] The decision device is further configured to, according to the first authentication manner, in response to receiving the first operation, detect whether a local authentication result of the decision device is passed.

[0172] In response to detecting that the local authentication result of the decision device is not passed, the decision device determines a second authentication manner corresponding to the first service, and sends a request for obtaining a local authentication result of an authentication device to the authentication device.

[0173] The authentication result is sent by the authentication device to the decision device.

[0174] The decision device is further configured to, in response to receiving the local authentication result of the authentication device, detect whether the local authentication result of the authentication device is passed, and in response to detecting that the local authentication result of the authentication device is passed, the authentication device executes an instruction corresponding to the first operation.

[0175] In a possible design of the system, the system further includes a service device.

[0176] The service device is configured to receive a target operation acting on a first interface of a first electronic device, where the target operation is used to trigger access to a first service, and the first service is associated with a second electronic device.

[0177] When the decision device receives the authentication request, the decision device is specifically configured to receive the authentication request from the service device.

[0178] When the decision device determines the authentication manner corresponding to the first service, the decision device is specifically configured to obtain a target authentication manner corresponding to the first service.

[0179] The decision device is further configured to: according to the target authentication manner, collect authentication information; and send an authentication request including the authentication information to an authentication device.

[0180] The authentication device is configured to perform authentication on the first service according to the authentication request.

[0181] In a possible design, the plurality of electronic devices includes a first device and a second device, and the first device and the second device are any two electronic devices in the plurality of electronic devices.

[0182] In a possible implementation, the plurality of electronic devices includes a first device and a second device, and the first device and the second device are any two electronic devices in the plurality of electronic devices; the first device is configured to send first information to the second device before the collection device acquires at least one authentication factor, where the first information includes at least one of the following: collection capability of the first device, authentication capability of the first device, and decision capability of the first device; the collection capability of the first device includes a type of authentication factor that can be acquired by the first device, the authentication capability of the first device includes a type of authentication factor that can be authenticated by the first device, and the decision capability of the first device indicates whether the first device can obtain the at least one aggregated result according to the at least one authentication result.

[0183] In a possible implementation, at least two electronic devices in the plurality of electronic devices are configured to determine a type of the at least one authentication factor before the collection device acquires the at least one authentication factor; or at least one electronic device in the plurality of electronic devices is configured to determine a type of the at least one authentication factor in response to a user input operation before the collection device acquires the at least one authentication factor.

[0184] In embodiments of this application, resource information can be synchronized between the plurality of electronic devices, where the resource information includes at least one of the following: collection capability, authentication capability, and decision capability. After the resource information is synchronized, any electronic device can acquire resource information of other electronic devices in the plurality of electronic devices. Therefore, the plurality of electronic devices can coordinate to determine a type of at least one authentication factor used in a user identity authentication process based on the acquired resource information, so as to implement a secure, reliable, and less power-consuming authentication process through the collection device, the authentication device, and the decision device.

[0185] In a possible implementation, the plurality of electronic devices are further configured to receive a first aggregated result and a second aggregated result sent by the decision device, where the first aggregated result and the second aggregated result are aggregated results obtained by the decision device at different times.

[0186] In embodiments of this application, the aggregated results obtained by the plurality of electronic devices can include aggregated results obtained at different times. Any electronic device can perform continuous authentication of a user identity according to the aggregated results obtained at different times, and the security and reliability are higher.

[0187] In a possible implementation, the manner in which the plurality of electronic devices are connected to each other specifically includes that the plurality of electronic devices are connected to the same local area network and / or the plurality of electronic devices are logged in to the same user account.

[0188] In the embodiments of the present application, the manner in which the plurality of electronic devices are connected to each other can be a relatively secure and reliable manner. The authentication process of the user identity through the plurality of electronic devices can further improve the security and reliability of the authentication process.

[0189] In a possible implementation, when the authentication device authenticates the at least one authentication factor to obtain at least one authentication result, the authentication device is specifically configured to: compare the at least one authentication factor with at least one pre-stored template authentication factor to obtain a similarity between the at least one authentication factor and the at least one template authentication factor, and the at least one authentication result is the similarity between the at least one authentication factor and the at least one template authentication factor; and when the similarity between the at least one authentication factor and the at least one template authentication factor is greater than a first threshold value, the at least one authentication result indicates that the user is legitimate.

[0190] In a possible implementation, the plurality of electronic devices further include a use device, and the use device is configured to: when the use device receives the at least one aggregation result and the at least one aggregation result indicates that the user is legitimate, perform a first operation.

[0191] In the embodiments of the present application, the use device can perform a corresponding user operation according to the at least one aggregation result obtained by the plurality of electronic devices, so as to implement a secure and reliable authentication process with less impact on power consumption without affecting the normal use of the use device by the user.

[0192] In a possible implementation, when the at least one authentication result indicates that the user is legitimate, the at least one aggregation result indicates that the user is legitimate, including at least one of the following: when any one of the at least one authentication result indicates that the user is legitimate, the at least one aggregation result indicates that the user is legitimate; and when the number of authentication results in the at least one authentication result that indicate that the user is legitimate is greater than a second threshold value, the at least one aggregation result indicates that the user is legitimate.

[0193] In the embodiments of the present application, there are various manners to determine whether the at least one aggregation result indicates that the user is legitimate, and different manners can be used for different application scenarios, so that the flexibility is stronger and the application scenarios are more extensive.

[0194] In a possible implementation, the usage device is further configured to: after the usage device receives the at least one aggregated result, and before the usage device performs the first operation, detect a second operation acting on the usage device; and in response to detecting the second operation, run a first application.

[0195] In a possible implementation, the plurality of electronic devices includes a third device, a fourth device, a fifth device, and a sixth device, wherein the collection device is the third device, the authentication device is the fourth device, the decision device is the fifth device, and the usage device is the sixth device; or the plurality of electronic devices includes a seventh device and an eighth device, wherein the collection device, the authentication device, and the usage device are the seventh device, and the decision device is the eighth device.

[0196] In an embodiment of the present application, the collection device, the authentication device, the decision device, and the usage device can be four different devices, or can be less than four devices. Any one of the plurality of electronic devices can be at least one of the collection device, the authentication device, the decision device, and the usage device, that is, any one of the electronic devices can include multiple roles, which is more flexible in implementation and has a wider application scenario. Even a system with a small number of included devices can implement a secure and reliable authentication process with less impact on power consumption.

[0197] In a possible implementation, the plurality of electronic devices includes a ninth device, a tenth device, an eleventh device, a twelfth device, a thirteenth device, a fourteenth device, a fifteenth device, and a sixteenth device, the collection device includes the ninth device and the tenth device, the authentication device includes the eleventh device and the twelfth device, the decision device includes the thirteenth device and the fourteenth device, and the usage device includes the fifteenth device and the sixteenth device.

[0198] In an embodiment of the present application, any one of the collection device, the authentication device, the decision device, and the usage device is not limited to a single device, which realizes the integration and comprehensive scheduling of the collection capability, the authentication capability, and the decision capability of the plurality of electronic devices, reduces the processing pressure of a single device and the impact on power consumption, and is more usable.

[0199] In a ninth aspect, a computer program product is provided, which includes a computer program (which can also be referred to as code or instructions), when the computer program is executed, causes a computer to perform the method in any possible implementation of the first aspect or the second aspect, or causes the computer to perform the method in any implementation.

[0200] In a tenth aspect, a computer-readable storage medium is provided, and the computer-readable medium stores a computer program (which can also be referred to as code or instructions) that, when executed on a computer, causes the computer to perform the method in any possible implementation of the first aspect or the second aspect, or causes the computer to perform the method in any implementation.

[0201] In an eleventh aspect, a processing apparatus is provided, and the processing apparatus includes an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, so that the method in any aspect of the first aspect or any possible implementation of the first aspect is implemented, or so that the method in any aspect of the second aspect or any possible implementation of the second aspect is implemented.

[0202] In a specific implementation process, the processing apparatus can be a chip, the input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be a transistor, a gate circuit, a flip-flop, and various logic circuits, etc. The input signal received by the input circuit can be received and input by a receiver, the signal output by the output circuit can be output to a transmitter and transmitted by the transmitter, and the input circuit and the output circuit can be the same circuit which is used as the input circuit and the output circuit at different times. The specific implementation of the processor and various circuits is not limited by the embodiments of the present application.

[0203] The technical effects achieved by the various designs in any of the second aspect to the eleventh aspect above can refer to the technical effects achieved by the respective designs in the first aspect described above, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0204] FIG. 1A A communication system schematic diagram is provided for the embodiments of the present application;

[0205] FIG. 1B A smart home communication system schematic diagram is provided for the embodiments of the present application;

[0206] FIG. 2 A mobile phone structure schematic diagram is provided for the embodiments of the present application;

[0207] FIG. 3 An authentication method flowchart is provided for the embodiments of the present application;

[0208] FIG. 4 Another authentication method flowchart is provided for the embodiments of the present application;

[0209] FIG. 5 A device structure schematic diagram is provided for the embodiments of the present application;

[0210] FIG. 6A A resource synchronization method provided by an embodiment of the present application;

[0211] FIG. 6B Another resource synchronization method provided by an embodiment of the present application;

[0212] FIG. 7A An open door scenario provided by an embodiment of the present application;

[0213] FIG. 7B An authentication method flowchart in an open door scenario provided by an embodiment of the present application;

[0214] FIG. 7C Another open door scenario provided by an embodiment of the present application;

[0215] FIG. 7D Another open door scenario provided by an embodiment of the present application;

[0216] FIG. 8 A set of interface diagrams provided by an embodiment of the present application;

[0217] FIG. 9A A voice operation intelligent television scenario provided by an embodiment of the present application;

[0218] FIG. 9B An authentication method flowchart in a voice operation intelligent television scenario provided by an embodiment of the present application;

[0219] FIG. 10A Another voice operation intelligent television scenario provided by an embodiment of the present application;

[0220] FIG. 10B An authentication method flowchart in another voice operation intelligent television scenario provided by an embodiment of the present application;

[0221] FIG. 11A Another voice operation intelligent television scenario provided by an embodiment of the present application;

[0222] FIG. 11B An authentication method flowchart in another voice operation intelligent television scenario provided by an embodiment of the present application;

[0223] FIG. 12A A voice operation microwave oven scenario provided by an embodiment of the present application;

[0224] FIG. 12B An authentication method flowchart in a voice operation microwave oven scenario provided by an embodiment of the present application;

[0225] FIG. 13A flowchart of an authentication method provided by an embodiment of the present application is shown in FIG. 1;

[0226] FIG. 14 A flowchart of another authentication method provided by an embodiment of the present application is shown in FIG. 2;

[0227] FIG. 15A A schematic diagram of a possible application scenario provided by an embodiment of the present application is shown in FIG. 3;

[0228] FIG. 15B A schematic diagram of an application scenario provided by an embodiment of the present application is shown in FIG. 4;

[0229] FIG. 15C A schematic diagram of an application scenario provided by an embodiment of the present application is shown in FIG. 5;

[0230] FIG. 16 A flowchart of an authentication method provided by an embodiment of the present application is shown in FIG. 6;

[0231] FIG. 17 A flowchart of an authentication method provided by an embodiment of the present application is shown in FIG. 7;

[0232] FIG. 18 A structural schematic diagram of a device provided by an embodiment of the present application is shown in FIG. 8;

[0233] FIG. 19 A structural schematic diagram of another device provided by an embodiment of the present application is shown in FIG. 9;

[0234] FIG. 20 A flowchart of a cross-device authentication method provided by an embodiment of the present application is shown in FIG. 10;

[0235] FIG. 21 A system architecture schematic diagram of a communication system provided by an embodiment of the present application is shown in FIG. 11;

[0236] FIG. 22 An interface schematic diagram of starting cross-device authentication provided by an embodiment of the present application is shown in FIG. 12;

[0237] FIG. 23A to FIG. 23D A schematic diagram of a voice control scenario provided by an embodiment of the present application is shown in FIG. 13;

[0238] FIG. 24A to FIG. 24G An interface schematic diagram of application locking provided by an embodiment of the present application is shown in FIG. 14;

[0239] FIG. 24H to FIG. 24M An interface schematic diagram of application function locking provided by an embodiment of the present application is shown in FIG. 15;

[0240] FIG. 25A to FIG. 25J A schematic diagram of a voice control scenario provided by an embodiment of the present application is shown in FIG. 16;

[0241] FIG. 26A to FIG. 26CA low-risk application setting interface provided by an embodiment of the present application;

[0242] FIG. 27A to FIG. 27D A voice control scenario provided by an embodiment of the present application;

[0243] FIG. 28A to FIG. 28H A screen projection triggering interface provided by an embodiment of the present application;

[0244] FIG. 28I to FIG. 28J A screen projection control interface provided by an embodiment of the present application;

[0245] FIG. 29A to FIG. 29I A screen projection control interface provided by an embodiment of the present application;

[0246] FIG. 30A to FIG. 30C A screen projection control interface provided by an embodiment of the present application;

[0247] FIG. 31A to FIG. 31B A screen projection control interface provided by an embodiment of the present application;

[0248] FIG. 32A to FIG. 32E An authorized user adding interface provided by an embodiment of the present application;

[0249] FIG. 33A to FIG. 33C A screen projection control interface provided by an embodiment of the present application;

[0250] FIG. 34A to FIG. 34C A cross-device authentication system provided by an embodiment of the present application;

[0251] FIG. 35 A cross-device authentication method in a voice control scenario provided by an embodiment of the present application;

[0252] FIG. 36 A cross-device authentication method in a screen projection control scenario provided by an embodiment of the present application;

[0253] FIG. 37 A cross-device authentication method provided by an embodiment of the present application;

[0254] FIG. 38A And FIG. 38B A device authentication method provided by an embodiment of the present application;

[0255] FIG. 39A A PC interface provided by an embodiment of the present application;

[0256] FIG. 39B A PC and mobile phone collaborative face authentication provided by an embodiment of the present application;

[0257] FIG. 39C Another interface diagram of a PC provided by an embodiment of the present application;

[0258] FIG. 39D Another interface diagram of a PC provided by an embodiment of the present application;

[0259] FIG. 40 Another cross-device authentication method diagram provided by an embodiment of the present application;

[0260] FIG. 41 Another cross-device authentication method diagram provided by an embodiment of the present application;

[0261] FIG. 42 A payment scene diagram of a smart TV provided by an embodiment of the present application;

[0262] FIG. 43 A driving scene diagram provided by an embodiment of the present application;

[0263] FIG. 44 A device structure diagram provided by an embodiment of the present application;

[0264] FIG. 45 A software structure diagram of an electronic device provided by an embodiment of the present application;

[0265] FIG. 46A and FIG. 46B A group of interface diagrams provided by an embodiment of the present application;

[0266] FIG. 47 Another group of interface diagrams provided by an embodiment of the present application;

[0267] FIG. 48A and FIG. 48B Another group of interface diagrams provided by an embodiment of the present application;

[0268] FIG. 49A and FIG. 49B Another group of interface diagrams provided by an embodiment of the present application;

[0269] FIG. 50 Another group of interface diagrams provided by an embodiment of the present application;

[0270] FIG. 51A A fingerprint distribution method diagram provided by an embodiment of the present application;

[0271] FIG. 51B A face distribution method diagram provided by an embodiment of the present application;

[0272] FIG. 51C A data association method diagram provided by an embodiment of the present application;

[0273] FIG. 52 A correlation scene schematic diagram provided for an embodiment of the present application;

[0274] FIG. 53 Another set of interface schematic diagrams provided for an embodiment of the present application;

[0275] FIG. 54 A data correlation method schematic diagram provided for an embodiment of the present application;

[0276] FIG. 55 Another data correlation method schematic diagram provided for an embodiment of the present application;

[0277] FIG. 56A to FIG. 56D Still some electronic device structure schematic diagrams provided for an embodiment of the present application;

[0278] FIG. 57 A resource synchronization process flow schematic diagram provided for an embodiment of the present application;

[0279] FIG. 58 A multi-device collaboration authentication method flow schematic diagram provided for an embodiment of the present application;

[0280] FIG. 59-FIG. 60 Some decision process flow schematic diagrams provided for an embodiment of the present application;

[0281] FIG. 61-FIG. 77 Still some multi-device collaboration authentication method flow schematic diagrams provided for an embodiment of the present application;

[0282] FIG. 78 A software structure schematic diagram of an electronic device provided for an embodiment of the present application.

[0283] FIG. 79 An electronic device structure schematic diagram provided for an embodiment of the present application. DETAILED DESCRIPTION

[0284] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application. In the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing the specific embodiments and are not intended to be limiting on the present application. As used in the specification and the appended claims of the present application, "one", "a", "said", "the above", "the", and "this" include, for example, "one or more" unless there is clear indication to the contrary in the context. It should also be understood that in the following embodiments of the present application, "at least one" and "one or more" mean one or more than two (including two). The term "and / or" is used to describe the association relationship of the associated objects, which means that there can be three relationships; for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. The character " / " generally represents a "and" or "or" relationship between the associated objects.

[0285] In the present specification, the reference to "one embodiment" or "some embodiments" or the like means that a particular feature, structure, or characteristic described in connection with the embodiment is included in one or more embodiments of the present application. Therefore, the statements "in one embodiment", "in some embodiments", "in other some embodiments", "in yet some embodiments", and the like appearing in various places in the specification are not necessarily all referring to the same embodiment, but can refer to other embodiments. The terms "include", "contain", "have" and their variants mean "including but not limited to", unless otherwise specifically emphasized. The term "connected" includes direct connection and indirect connection, unless otherwise specified. "First", "second", etc. are used only for the purpose of description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features.

[0286] In the embodiments of the present application, the words "exemplarily" or "for example" are used to mean as an example, illustration or description. Any embodiment or design scheme described as "exemplarily" or "for example" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the use of the words "exemplarily" or "for example" is intended to present the relevant concept in a specific manner.

[0287] Before introducing the technical solutions of the embodiments of the present application, some terms in the present application are explained and described, so as to facilitate understanding by those skilled in the art.

[0288] Some concepts related to the embodiments of the present application are introduced as follows:

[0289] (1) Authentication device, operation device

[0290] In the embodiments of the present application, a terminal device with the capability of authentication is referred to as an authentication device. For example, a smart speaker has the capability of authenticating the voiceprint of a user, so the smart speaker belongs to an authentication device.

[0291] In the embodiments of the present application, a device performing a service is referred to as an operation device. For example, a device performing a door opening service is a door lock, so the operation device is the door lock. For another example, a device performing a microwave heating service for five minutes is a microwave oven, so the operation device is the microwave oven.

[0292] (2) Correspondence between authentication methods and scores of authentication methods

[0293] An authentication method includes authenticating a user by using a biological feature (for example, a fingerprint, a voiceprint, an iris, etc.) and authenticating a user by using a username and a password. In one possible case, if the security authentication level of a service requested by a user to access is a low security level, the authentication method used by an electronic device can be to authenticate a single authentication factor, such as a fingerprint. In another possible case, if the security authentication level of a service requested by a user to access is a high security level, the authentication method used by an electronic device can be to authenticate multiple authentication factors, such as fingerprint authentication of a fingerprint and face authentication of a face.

[0294] In this way, the use of a biological feature to authenticate a user can simplify user operations. For example, in the application scenario of payment, if a user wants to use a mobile phone to pay, the user needs to input a password, and a mobile phone using a biological feature authentication can authenticate a fingerprint or face information of the user, thereby avoiding the trouble of inputting a password.

[0295] False acceptance rate (FAR) and false rejection rate (FRR) are some evaluation indexes used to evaluate the performance of an algorithm in the authentication method using a biological feature to authenticate a user.

[0296] In this way, the false acceptance rate is simply the proportion of “treating non-matching as matching”. The false rejection rate is simply the proportion of “treating matching as non-matching”.

[0297] The false acceptance rate and the false rejection rate are described below by taking fingerprint recognition as an example.

[0298] In fingerprint recognition, the false acceptance rate can refer to the proportion of different fingerprints being considered as the same fingerprint when the matching rate between different fingerprints is greater than a given threshold value when a fingerprint recognition algorithm is tested on a standard fingerprint database. In other words, the false acceptance rate is simply the proportion of “treating non-matching fingerprints as matching fingerprints”.

[0299] The false rejection rate can refer to a proportion of the same fingerprints that are considered to be different fingerprints when a fingerprint recognition algorithm is tested on a standard fingerprint database, i.e., a proportion of "fingerprint that should be matched successfully but is considered to be not matched".

[0300] For example:

[0301] Suppose there are 110 people, and there are 8 fingerprint images of the thumbs of each person, i.e., 110 classes, and 8 images in each class. The ideal case is that any two images in each class are matched successfully, and any image in different classes is matched unsuccessfully. Each image in the database is matched with all other images except itself, and the false acceptance rate and the false rejection rate are calculated respectively.

[0302] False acceptance rate: suppose that due to the performance of the fingerprint recognition algorithm, the matching failure is considered to be a matching success, and the number of such errors is assumed to be 1000. In the theoretical case, the images from the same fingerprint are all matched successfully, and the number of times is 7*8*110=6160. The total number of matching times is 880*(880-1)=773520. The number of matching failures is 773520-6160=767360. Then the false acceptance rate FAR is 1000 / 767360*100%=0.13%.

[0303] False rejection rate: suppose that due to the performance of the fingerprint recognition algorithm, the matching success is considered to be a matching failure, and the number of such errors is assumed to be 160. Then the false rejection rate is 160 / 6160=2.6%.

[0304] In the embodiments of the present application, the score of an authentication mode can be determined according to the false rejection rate and the false acceptance rate of the authentication mode. Generally, the smaller the false rejection rate and the false acceptance rate of an authentication mode are, the higher the score of the authentication mode corresponding to the authentication mode is. The larger the false rejection rate and the false acceptance rate of an authentication mode are, the lower the score of the authentication mode corresponding to the authentication mode is.

[0305] Table 1 exemplarily shows the correspondence between several authentication modes and the scores of the authentication modes.

[0306] Table 1

[0307] Authentication method Score (points) of authentication method Recognizing a password 90 Recognizing a username and a password 90 Iris recognition 90 Fingerprint recognition 90 3D face recognition (structured light) 90 3D face recognition (binocular) 80 2D face recognition 70 Bone voiceprint recognition 70 Voiceprint recognition 20

[0308] (3) The security environment of an authentication device can include: an inside secure element (inSE) level, a trusted execution environment (TEE) level, a white box, and a key segmentation.

[0309] In the embodiments of the present application, the hardware security unit can refer to an independent security unit built in the main chip, which provides functions such as secure storage of private information and secure execution of important programs. The security level of using the inSE level to protect the root key is high, and hardware tamper resistance can be achieved.

[0310] In the embodiments of the present application, the TEE can refer to a trusted execution environment, which is a hardware security isolation area of the main processor, and provides functions such as confidentiality and integrity protection of code and data, and secure access of external devices. The security level of using the TEE level to protect the root key is high, and hardware security level can be reached.

[0311] (4) The distributed storage system is to store data in multiple independent devices. The traditional network storage system uses a centralized storage server to store all data, and the storage server becomes the bottleneck of system performance and the focus of reliability and security, which cannot meet the needs of large-scale storage applications. The distributed network storage system uses a scalable system structure, uses multiple storage servers to share the storage load, and uses a location server to locate the storage information. It not only improves the reliability, availability and access efficiency of the system, but also is easy to expand.

[0312] (5) The authentication factor can include user secret data, biometric data, and the like. The user secret data can include a user's lock screen password, a user's protection password, and the like. The biometric data can include one or more of the following: physical biometric features, behavioral biometric features, and soft biometric features. The physical biometric features can include face, fingerprint, iris, retina, deoxyribonucleic acid (DNA), skin, hand shape, and vein. The behavioral biometric features can include voiceprint, signature, and gait. The soft biometric features can include gender, age, height, and weight.

[0313] (6) The business is a transaction performed by a device to realize its function or service. For example, the business can be an unlocking business, a payment business, a door opening business, an artificial intelligence (AI) computing business, various application businesses, and a distribution business.

[0314] At present, the identity authentication of the device is basically based on a single-device authentication process. For example, when a user opens a secure cabinet application of a mobile phone, the interface prompts the user to perform fingerprint authentication. Then the user inputs the user's fingerprint on the mobile phone, and the mobile phone performs fingerprint authentication to generate an authentication result. There is currently no related authentication scheme for collaborative authentication between multiple devices.

[0315] In order to realize the cooperative authentication between devices, an authentication method provided in the embodiments of the present application can be used to realize the authentication of the same service by at least two electronic devices, for example, a PC collects a face, the PC sends the face to a mobile phone, and the mobile phone uses the face collected by the PC to authenticate a payment service triggered by a user, so that the authentication factor can be collected across devices, the same service can be authenticated cooperatively, and the convenience of the authentication method can be improved. In another possible way, the method can be used to realize the authentication of the same service by at least two electronic devices using at least two authentication factors, for example, a door lock collects a fingerprint, a camera on the door collects a face, and a smart speaker uses the fingerprint obtained from the door lock and the face obtained from the camera to authenticate the opening door service by using the two authentication factors, so that the reliability of the authentication result can be ensured, and the authentication security level of the device can be improved.

[0316] The authentication method provided in the embodiments of the present application can be applied to FIG. 1A As shown in FIG. 1, the communication system architecture can at least include an electronic device 100 and an electronic device 200. FIG. 1A As shown in FIG. 1, the communication system architecture can at least include an electronic device 100 and an electronic device 200.

[0317] The electronic device 100 and the electronic device 200 can be connected by wire or wirelessly. In this embodiment, when the electronic device 100 and the electronic device 200 are connected wirelessly, the wireless communication protocol used can be a wireless fidelity (Wi-Fi) protocol, a Bluetooth protocol, a ZigBee protocol, a near field communication (NFC) protocol, various cellular network protocols, and the like, which are not limited here.

[0318] In specific implementations, the aforementioned electronic devices 100 and 200 can be mobile phones, tablets, handheld computers, personal computers (PCs), cellular phones, personal digital assistants (PDAs), wearable devices (such as smartwatches), smart home devices (such as televisions), in-vehicle computers, game consoles, and augmented reality (AR) / virtual reality (VR) devices, etc. This embodiment does not impose special restrictions on the specific device forms of electronic devices 100 and 200. In this embodiment, electronic devices 100 and 200 can have the same device form. For example, both electronic devices 100 and 200 can be mobile phones. Electronic devices 100 and 200 can also have different device forms. For example, electronic device 100 can be a PC, and electronic device 200 can be a mobile phone.

[0319] The aforementioned electronic devices 100 and 200 can be touchscreen devices or non-touchscreen devices. In this embodiment, both electronic devices 100 and 200 are terminals that can run an operating system, install applications, and have a display (or screen).

[0320] In one possible embodiment of this application, the system architecture may further include a server 300, through which the electronic device 100 can establish a wired or wireless connection with the electronic device 200.

[0321] like FIG. 1B As shown, the communication system can be a smart home system. Smart home devices within this system can include: mobile phone 11, smart camera 12, smart TV 13, smart speaker 14, smart bracelet 15, and smart door lock 16, etc. In specific implementations, the number of devices can be more or less. Multiple devices can connect and communicate via a network. These devices can connect and communicate with each other via wired (e.g., USB, twisted pair, coaxial cable, and / or fiber optic) or wireless (e.g., wireless fidelity, Wi-Fi, Bluetooth, and / or mobile network) methods. That is, the network can include, but is not limited to, at least one of the following: wired lines, wireless lines, and other communication lines; routers, access points (APs), and other gateway devices; and cloud servers, etc. For example, multiple devices can access the same local area network (LAN) through communication lines and gateway devices, and communicate through that LAN.

[0322] In some embodiments, the plurality of devices connected through the network are mutually trusted devices. For example, a user terminal device such as a smartphone or tablet in the plurality of devices can be installed with an application (such as, but not limited to, Huawei Smart Home) for implementing communication. The application can log in an account, which can be referred to as an account application hereinafter. The user terminal device in the plurality of devices can log in the same account or an associated account through the account application, thereby communicating through the account application server. Other devices in the plurality of devices except the user terminal device can be connected to the account application server through wireless means such as Bluetooth or Wi-Fi or wired means such as USB (for example, a user can manually add a smart home device to Huawei Smart Home through Bluetooth). Thus, the plurality of devices can identify the identity of a communication object through the account application server (for example, a device logged in or registered on Huawei Smart Home is a trusted device, otherwise it is an untrusted device), thereby communicating through the account application server with high security. The other devices can include, but are not limited to, smart television sets, smart cameras, smart home devices, smart wristbands, smart watches, smart glasses, and wearable devices.

[0323] Without being limited to the above-mentioned cases, in a specific implementation, any one of the plurality of devices can need to be verified before accessing the same Wi-Fi network. Thus, the plurality of devices can identify the identity of a communication object through the Wi-Fi network (for example, a device passing the password verification is a trusted device, otherwise it is an untrusted device), thereby communicating through the Wi-Fi network with high security. The embodiments of the present application are not limited in this regard.

[0324] The authentication method provided by the embodiments of the present application can be applied to an electronic device. In some embodiments, the electronic device can be a portable terminal containing functions such as a personal digital assistant and / or a music player, such as a mobile phone, a tablet computer, a wearable device (such as a smart watch) with wireless communication function, a vehicle-mounted device, and the like. Exemplary embodiments of the portable terminal include, but are not limited to, a portable terminal equipped with an operating system such as Harmony (HarmonyOS) or other operating systems. The portable terminal can also be a laptop computer (Laptop) with a touch-sensitive surface (such as a touch panel), and the like. It should also be understood that, in other embodiments, the terminal can also be a desktop computer with a touch-sensitive surface (such as a touch panel).

[0325] FIG. 2 A structural schematic diagram of the electronic device 200 is shown.

[0326] The electronic device 200 can include a processor 210, an external memory interface 220, an internal memory 221, a universal serial bus (USB) interface 230, a charging management module 240, a power management module 241, a battery 242, an antenna 1, an antenna 2, a mobile communication module 250, a wireless communication module 260, an audio module 270, a speaker 270A, a receiver 270B, a microphone 270C, a headset interface 270D, a sensor module 280, a key 290, a motor 291, an indicator 292, a camera 293, a display screen 294, and a subscriber identification module (SIM) card interface 295, etc. The sensor module 280 can include a pressure sensor 280A, a gyro sensor 280B, a barometric pressure sensor 280C, a magnetic sensor 280D, an acceleration sensor 280E, a distance sensor 280F, a proximity light sensor 280G, a fingerprint sensor 280H, a temperature sensor 280J, a touch sensor 280K, an ambient light sensor 280L, a bone conduction sensor 280M, a pulse sensor 280N, and a heart rate sensor 280P, etc.

[0327] Next, the working principle of the sensor is exemplarily described taking the pulse sensor 280N and the heart rate sensor 280P as examples.

[0328] The pulse sensor 280N can detect a pulse signal. In some embodiments, the pulse sensor 280N can detect the pressure change generated by the arterial pulse and convert it into an electrical signal. There are many kinds of pulse sensors, such as piezoelectric pulse sensors, piezoresistive pulse sensors, photoelectric pulse sensors, etc. Among them, the piezoelectric pulse sensor and the piezoresistive pulse sensor can convert the pressure process of pulse beats into signal output through micro-pressure type materials (such as piezoelectric sheets, bridges, etc.). The photoelectric pulse sensor can convert the change of the light transmittance of blood vessels in the pulse beat process into signal output through reflection or transmission, etc. For example, the pulse signal is obtained through photoplethysmographic (PPG) method.

[0329] The heart rate sensor 280P can detect a heart rate signal. In some embodiments, the heart rate sensor 280P can acquire the heart rate signal by PPG. The heart rate sensor 280P can convert changes in blood vessel dynamics, such as blood pulse rate (heart rate) or blood volume (cardiac output), into signal output by reflection or transmission, etc. In some embodiments, the heart rate sensor 280P can measure the signal of the electrical activity induced in the cardiac tissue by the electrodes connected to the human skin, i.e., acquire the heart rate signal by electrocardiography (ECG).

[0330] In some embodiments, the pulse sensor 280N and the heart rate sensor 280P can be packaged in a pulse heart rate sensor. The pulse heart rate sensor can acquire the pulse signal and the heart rate signal by PPG.

[0331] The processor 210 can include one or more processing units, for example: the processor 210 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units can be independent devices, or can be integrated in one or more processors.

[0332] The electronic device 200 implements a display function through a GPU, a display screen 294, and an application processor, etc. The GPU is a microprocessor for image processing, connected to the display screen 294 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 210 can include one or more GPUs that execute program instructions to generate or change display information.

[0333] The electronic device 200 can implement a shooting function through an ISP, a camera 293, a video codec, a GPU, a display screen 294, and an application processor, etc.

[0334] The SIM card interface 295 is configured to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 295 to achieve contact and disconnection with the electronic device 200. The electronic device 200 can support one or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 295 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 295 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 295 can be compatible with different types of SIM cards. The SIM card interface 295 can also be compatible with external storage cards. The electronic device 200 interacts with a network through the SIM card to implement functions such as call and data communication. In some embodiments, the electronic device 200 uses an eSIM, for example, an embedded SIM card.

[0335] The wireless communication function of the electronic device 200 can be implemented through the antenna 1, the antenna 2, the mobile communication module 250, the wireless communication module 260, a modem processor, and a baseband processor, and the like. The antenna 1 and the antenna 2 are configured to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 200 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example, the antenna 1 can be multiplexed as a diversity antenna of a wireless local area network. In some other embodiments, the antennas can be used in combination with a tuning switch.

[0336] The mobile communication module 250 can provide a solution including 2G / 3G / 4G / 5G wireless communication applied to the electronic device 200. The mobile communication module 250 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), and the like. The mobile communication module 250 can receive electromagnetic waves from the antenna 1, and perform filtering, amplification, and the like on the received electromagnetic waves, and transmit the processed electromagnetic waves to the modem processor for demodulation. The mobile communication module 250 can also amplify signals modulated by the modem processor, and convert the signals into electromagnetic waves to be radiated through the antenna 1. In some embodiments, at least part of the function modules of the mobile communication module 250 can be arranged in the processor 210. In some embodiments, at least part of the function modules of the mobile communication module 250 and at least part of the modules of the processor 210 can be arranged in the same device.

[0337] The wireless communication module 260 can provide a solution for wireless communication including wireless local area networks (WLAN) (e.g., wireless fidelity (Wi-Fi) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared radiation (IR) technology, etc. applied to the electronic device 200. The wireless communication module 260 can be one or more devices that integrate at least one communication processing module. The wireless communication module 260 receives an electromagnetic wave via the antenna 2, frequency-modulates and filters the electromagnetic wave signal, and transmits the processed signal to the processor 210. The wireless communication module 260 can also receive a signal to be transmitted from the processor 210, frequency-modulate it, amplify it, and radiate it as an electromagnetic wave via the antenna 2.

[0338] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 200 are coupled, and the antenna 2 and the wireless communication module 260 are coupled, so that the electronic device 200 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. In the embodiments of the present application, the electronic device 200 can synchronize the authentication factors, the collection capabilities, and the authentication capabilities of the resources with other electronic devices in the device group network through the mobile communication module 250 and / or the wireless communication module 260, so that the multiple devices in the subsequent device group network can perform the authentication of the user identity in cooperation. The collection capability refers to the ability of the electronic device to collect authentication factors for identifying the user identity. The authentication capability refers to the ability of the electronic device to authenticate the collected authentication factors to obtain an authentication result. Different authentication factors can correspond to different collection capabilities, and different authentication factors can correspond to different authentication capabilities. After the above-mentioned resource synchronization between the multiple devices, the resource information after the synchronization can be stored in the memory 221, can be uploaded to the connected cloud server, can be stored in the device (hereinafter referred to as the hub device) for realizing resource integration in the multi-device group, or can be stored in the external storage device connected to the device, and the embodiments of the present application are not limited thereto.

[0339] It can be understood that, FIG. 2 The components shown do not constitute a specific limitation on the electronic device 200, and the electronic device 200 can further include more or fewer components than shown, or combine certain components, or split certain components, or different arrangement of components. In addition, FIG. 2 The combination / connection relationship between the components in the above-mentioned embodiments can also be adjusted and modified.

[0340] The software system of the electronic device can employ a layered architecture, an event-driven architecture, a microkernel architecture, a microservice architecture, or a cloud architecture. In this embodiment of the present application, a layered architecture is taken as an example, wherein the layered architecture can include a Harmony operating system or other operating systems. The authentication method provided in this embodiment of the present application can be applicable to a terminal integrating the above operating systems.

[0341] It can be understood that the electronic device 200 can be a device of different types, for example, the electronic device 200 is a smart phone, a tablet computer, or other user terminal device. For another example, the electronic device 200 is a smart camera or other smart home device. For another example, the electronic device 200 is a smart bracelet or other wearable device.

[0342] The present application provides an authentication method, which can be executed by a first electronic device. The first electronic device can be any electronic device in the above communication system, such as an electronic device with authentication capability, or an electronic device with collection capability, or an electronic device with both collection capability and authentication capability, or a hub device with scheduling capability, such as FIG. 3 as shown, the method includes the following steps:

[0343] S301, the first electronic device receives an authentication request, the authentication request being used to request authentication of a first service.

[0344] In this step, the first electronic device can receive an operation from a user, and generate an authentication request in response to the operation; or the user performs an operation on a second electronic device, the second electronic device generates an authentication request and sends it to the first electronic device in response to the operation, and then the first electronic device receives the authentication request from the second electronic device.

[0345] S302, the first electronic device determines an authentication mode corresponding to the first service.

[0346] In one possible mode, in this step, if the first service is a service of low security level, the authentication mode corresponding to the first service can be to use a single authentication factor for authentication; if the first service is a service of high security level, the authentication mode corresponding to the first service can be to use at least two authentication factors for authentication.

[0347] In this step, the first electronic device can independently determine the authentication mode corresponding to the first service; or the first electronic device can determine the authentication mode corresponding to the first service according to its own decision, and then combine the authentication mode corresponding to the first service determined by other electronic devices to finally determine the authentication mode corresponding to the first service.

[0348] S303, the first electronic device schedules M electronic devices to authenticate the first service according to the authentication mode, where M is a positive integer.

[0349] In this step, exemplarily, the first electronic device can schedule electronic device A (electronic device A can be the first electronic device or one of the M electronic devices) to collect an authentication factor according to the authentication mode, schedule electronic device B to authenticate the authentication factor collected by electronic device A to generate an authentication result, thereby realizing cross-device collection of authentication factors and multi-device cooperation to authenticate the same service; another example is that the first electronic device can schedule electronic device A to collect a first authentication factor and schedule electronic device B to collect a second authentication factor according to the authentication mode, schedule electronic device C to authenticate the first authentication factor to generate a first authentication result, and schedule electronic device D to authenticate the second authentication factor to generate a second authentication result, thereby combining the two authentication results to complete the authentication of the first service.

[0350] Specifically, FIG. 3 The authentication method can have the following different implementation manners, which will be described in detail below.

[0351] Implementation manner one

[0352] Based on the above FIG. 3 In the above S302, the specific manner of the first electronic device determining the authentication mode corresponding to the first service can be: the first electronic device first determines the risk security level corresponding to the first service; then the first electronic device determines the authentication mode meeting the security risk level according to the risk security level.

[0353] In the traditional technology, a user generally holds multiple terminals such as a mobile phone, a smart watch, etc., and different terminals have different authentication capabilities. If the user only uses the authentication mode (such as voiceprint, 2D face, etc.) that the terminal can provide to authenticate a service, there can be a security risk. For example, a smart door lock can generally authenticate the user's identity by using the user's fingerprint, and the door is opened when the authentication is passed. However, this can cause the door lock to be opened illegally by a user who has stolen the homeowner's fingerprint, which shows that the traditional authentication mode still has the problem of insufficient security. However, in the authentication method provided by the implementation manner one of the present application, because the authentication mode of the first service meets the corresponding risk security level, the security of the authentication result can be improved, the method can use multiple authentication factors on multiple electronic devices to authenticate the same service, to ensure the reliability of the authentication result, and to improve the authentication security level of the device. For example, for a high-security-level door opening service, the camera and the door lock are called to cooperate to perform face authentication and fingerprint authentication.

[0354] For example,FIG. 4 The specific flow of the authentication method corresponding to the implementation mode one includes the following steps.

[0355] S401, the first electronic device receives an authentication request, the authentication request being used to request authentication of a first service.

[0356] The first electronic device can receive an operation of a user acting on the first electronic device to generate the authentication request, or the first electronic device can receive the authentication request from another electronic device.

[0357] For example, the user issues a voice wake-up to open the gallery application, the first electronic device is a smart speaker, the smart speaker receives the wake-up voice from the user, and the wake-up voice is the authentication request. The first service can refer to opening the gallery application. For another example, the first electronic device receives the authentication request of the user forwarded from another electronic device. For example, the user performs a door opening operation, and the door lock forwards the authentication request related to the door opening operation to the smart speaker. In this example, the first service can refer to the door opening service.

[0358] S402, the first electronic device determines a risk security level corresponding to the execution of the first service.

[0359] For example, as shown in Table 8 below, different wake-up voices / operations correspond to different risk security levels. For example, the first service is "opening the weather application", and because this service or operation does not involve personal data, there is no risk, so the corresponding risk security level is determined to be the first level; for example, the first service is "opening the gallery application", and because this service or operation involves personal data, the risk is moderate, so the corresponding risk security level is determined to be the third level; for example, the service or operation of "opening the safe application" involves sensitive personal data, and the risk is high, so the corresponding risk security level is determined to be the fourth level.

[0360] S403, the first electronic device determines an authentication mode meeting the security risk level according to the risk security level.

[0361] In this step, the authentication mode meeting the security risk level can be authentication of one authentication factor, or authentication of two or more authentication factors. When the authentication mode is authentication of two or more authentication factors, it is also called authentication combination mode.

[0362] In one possible implementation, the first electronic device determines at least one authentication mode meeting the security risk level by using a decision strategy; wherein the decision strategy includes but is not limited to at least one of the following:

[0363] Preferentially using the collected authentication factors; preferentially using the collection capability with user-unaware features to collect the authentication factors; preferentially using the collection capability on the user's nearby device to collect the authentication factors. For specific examples, refer to the embodiments shown in the foregoing.

[0364] In one possible implementation, the first electronic device and the M electronic devices pre-determine available authentication factors and available collection capabilities associated with the available authentication factors from each device, and determine an authentication mode that meets the security risk level according to the risk security level and the available authentication factors and the available collection capabilities associated with the available authentication factors. For example, if neither the first electronic device nor the M electronic devices support voiceprint authentication, and the first electronic device has a collection capability of fingerprints and an authentication capability of fingerprints, i.e., the collection capability of voiceprints is unavailable, then the authentication mode of voiceprints is not used, and the authentication mode of fingerprints is used.

[0365] In another possible implementation, if the authentication request includes a biological feature, the biological feature is identified to determine a user corresponding to the biological feature, and then available authentication factors associated with the user, available authentication capabilities, and available collection capabilities associated with the available authentication factors are determined; and an authentication mode that meets the security risk level is determined according to the risk security level and the available authentication factors, the available authentication capabilities, and the available collection capabilities. For example, in combination with the first embodiment, the smart speaker obtains an authentication request from the door lock, if the authentication request includes a fingerprint of a user, the smart speaker first determines that the fingerprint corresponds to a user Alisa, and then obtains available authentication factors associated with the user Alisa, such as a face and a touch screen behavior, and the processor of the smart speaker determines a collection capability of 3D face and an authentication capability of 3D face from available authentication units and available collection units associated with the available authentication factors according to the determined 3D face authentication mode. For example, the collection capability of 3D face belongs to a camera, and the authentication capability of 3D face belongs to the smart speaker. That is, the smart speaker schedules the camera to collect a face image, and the authentication unit of 3D face of the smart speaker authenticates the collected face image.

[0366] In another possible implementation, the first electronic device and the M electronic devices pre-synchronize resources in the M electronic devices to obtain a synchronized resource pool, wherein the resource pool includes authentication factors, collection capabilities, and authentication capabilities in the M electronic devices, and at least one authentication mode that meets the security risk level is determined according to the risk security level and the resource pool. That is, the first electronic device can obtain currently available authentication factors, collection capabilities, and authentication capabilities, and select collection capabilities and authentication capabilities that meet the security level from the currently available authentication factors, collection capabilities, and authentication capabilities, and determine at least one authentication mode according to the selected collection capabilities and authentication capabilities.

[0367] Exemplarily, when the first service is of a low security risk level, a weak-trust authentication manner can be adopted for authentication, for example, a voiceprint authentication, a password authentication, etc.; when the first service is of a medium security risk level, a middle-trust authentication manner can be adopted for authentication, for example, a face authentication, or a voiceprint authentication and a touch screen behavior authentication; when the first service is of a high security risk level, a high-trust authentication manner can be adopted for authentication, for example, a fingerprint authentication and a voiceprint authentication, or a 3D face authentication and a fingerprint authentication.

[0368] It should be noted that in a possible case, the first electronic device can also determine the at least one authentication manner corresponding to the first service according to a preset configuration table.

[0369] S404, the first electronic device schedules M electronic devices to perform authentication on the first service according to the authentication manner.

[0370] In the embodiments of the present application, the first electronic device can belong to the M electronic devices, or can not belong to the M electronic devices. Exemplarily, the first electronic device schedules a second electronic device to perform authentication on the first service according to the at least one authentication manner; or the first electronic device schedules the first electronic device and the second electronic device to perform authentication on the first service according to the at least one authentication manner. If the final authentication result is authentication passed, the operation device is triggered to perform the first service, otherwise, the first service is not performed.

[0371] In a possible implementation, when the authentication request includes a biological feature, the first electronic device first identifies the biological feature to determine a user corresponding to the biological feature; it is judged whether the user has the permission to perform the first service, if the user has the permission to perform the first service, the M electronic devices are further scheduled to perform authentication on the first service. Exemplarily, in combination with Embodiment One, the smart speaker obtains an authentication request from the door lock, if the authentication request includes a fingerprint of a user, the smart speaker first determines that the user corresponding to the fingerprint is the householder Alisa, and then judges whether the householder Alisa has the permission to open the door, if the householder Alisa has the permission to open the door, the camera is further scheduled to collect a face, and the 3D face authentication is performed by using the face image. It should be noted that in another possible manner, the first electronic device can also adjust the authentication manner according to the available authentication factor associated with the user, and the available authentication capability and the available collection capability associated with the available authentication factor. For example, the decision unit of the smart speaker decides that the at least one authentication manner is the 3D face authentication manner according to the security risk level of the first service, but the collection capability of the 3D face associated with the householder Alisa is not available, and then the decision manner is adjusted to use the voiceprint authentication and the pulse authentication.

[0372] Further, in other possible implementations, the processor of the first electronic device can determine the at least one authentication manner according to the security risk level of the first service and the authentication factors associated with the user, and the available authentication capabilities and the available collection capabilities associated with the authentication factors. For example, as shown in Embodiment One, the door opening service is a high security level operation, and the available authentication factors associated with the user Alisa include 3D face, touch screen behavior, and fingerprint, etc. Assuming that the collection capability of the available 3D face associated with the user Alisa is unavailable, the processor of the smart speaker can determine to use voiceprint authentication and pulse authentication.

[0373] In a possible embodiment, the first electronic device can further filter electronic devices far away from the user location according to the user location, and / or the first electronic device can further filter electronic devices not applicable to the current service according to the service scenario.

[0374] In another possible embodiment, the first electronic device can further filter electronic devices not meeting the security requirements according to the security level of the device and the current security state. For example, filter electronic devices with Trojan viruses.

[0375] In a possible embodiment, the first electronic device can also determine the authentication manner of the first service according to a preset configuration table. That is, the preset configuration table is configured with the prior constraint conditions preset by the developer, that is, different authentication combination manners corresponding to different first services are artificially configured in the preset configuration table, such as fingerprint authentication and face authentication corresponding to the door opening operation. Since the preset configuration table is configured with the security risk level in advance, the first electronic device can no longer determine the security risk level according to the first service.

[0376] It should be noted that in the implementation manner one of the embodiments of the present application, the electronic device 200 can synchronize the resources of the authentication factors, the collection capabilities, and the authentication capabilities with other electronic devices in the device group network through the mobile communication module 250 and / or the wireless communication module 260, so that the multiple devices in the device group network can perform the authentication of the user identity in cooperation after each device performs its own function. The collection capability refers to the ability of the electronic device to collect the authentication factors for identifying the user identity. The authentication capability refers to the ability of the electronic device to authenticate the collected authentication factors to obtain the authentication result. Different authentication factors can correspond to different collection capabilities, and different authentication factors can correspond to different authentication capabilities. After the above-mentioned resource synchronization between multiple devices, the synchronized resource information can be stored in the internal storage 221, can be uploaded to the connected cloud server, can be stored in the device (hereinafter referred to as the hub device) for realizing resource integration in the multiple device group, or can be stored in the external storage device connected to the device, and the embodiments of the present application do not limit the same.

[0377] Referring to FIG. 5 , FIG. 5 A structural schematic diagram of a communication apparatus 500 is shown. The communication apparatus 500 can include an acquisition unit 501, an authentication unit 502, a resource management unit 503, a decision unit 504, and a scheduling unit 505. Among them:

[0378] The acquisition unit 501 is configured to acquire an authentication factor.

[0379] Specifically, the communication apparatus 500 can include at least one acquisition unit 501, wherein one acquisition unit 501 can be configured to acquire at least one type of authentication factor (hereinafter referred to as one authentication factor). The embodiments of the present application take one acquisition unit acquiring one authentication factor as an example for description. The authentication factor can be a fingerprint, a face, a heart rate, a pulse, a behavior habit, or a device connection state, etc. For example, the acquisition unit of the face can be configured to acquire the face, and the acquisition unit of the face can refer to the camera 293 shown in FIG. 2 The acquisition unit of the gait can be configured to acquire the gait, and the acquisition unit of the gait can refer to the camera 293 shown in FIG. 2 The acquisition unit of the pulse can be configured to acquire the pulse, and the acquisition unit of the pulse can be the pulse sensor 280N shown in FIG. 2 The acquisition unit of the heart rate can be configured to acquire the heart rate, and the acquisition unit of the heart rate can refer to the heart rate sensor 280P shown in FIG. 2 The acquisition unit of the touch screen behavior can be configured to acquire the touch screen behavior, and the acquisition unit of the touch screen behavior can refer to the display screen 294 shown in FIG. 2 The acquisition unit of the trusted device can be configured to acquire the connection state and / or the wearing state of the wearable device.

[0380] The authentication unit 502 is configured to authenticate according to the authentication factor, and generate an authentication result. The authentication unit 502 is generally an authentication service in software implementation, integrated in the operating system. The authentication service can be a process running in the computer, and the computer program corresponding to the authentication service can be stored in the internal storage 221.

[0381] The communication apparatus 500 can comprise at least one authentication unit 502, wherein one authentication unit 502 can be configured to authenticate at least one authentication factor to obtain an authentication result. Embodiments of the present application take one authentication unit authenticating one authentication factor as an example for illustration. For example, the authentication unit of a face can be configured to authenticate a face to obtain an authentication result of the face; the authentication unit of a gait can be configured to authenticate gait information to obtain an authentication result of the gait; the authentication unit of a pulse can be configured to authenticate a collected pulse to obtain an authentication result of the pulse; the authentication unit of a heart rate can be configured to authenticate a collected heart rate to obtain an authentication result of the heart rate; the authentication unit of a touch screen behavior can be configured to authenticate collected touch screen behavior information to obtain an authentication result of the touch screen behavior; and the authentication unit of a trusted device can be configured to authenticate a connection state and / or a wearing state of a collected wearable device to obtain an authentication result of the trusted device.

[0382] The resource management unit 503 is configured to invoke a synchronization service mechanism to synchronize resources between the apparatus and other devices in the device group network, generate a resource pool, or maintain or manage the resource pool. The resource management unit 503 comprises a resource pool, and the resources in the resource pool can be authentication factors (or information of the authentication factors), collection capabilities of the devices, authentication capabilities of the devices, and the like. The resource management unit 503 can refer to FIG. 2 The processor 210 shown in FIG. 10, and the resource pool in the resource management unit 503 can refer to a resource pool stored in the internal memory 221.

[0383] Specifically, the collection unit 501 can actively report (this operation can be referred to as registration hereinafter) the collected authentication factors (or information of the collected authentication factors) and the collection capabilities of the devices to the resource management unit 503. In addition, the resource management unit 503 can also actively acquire the collected authentication factors (or information of the collected authentication factors) and the collection capabilities from the collection unit 501.

[0384] The authentication unit 502 can actively report (this operation can be referred to as registration hereinafter) the authentication capabilities to the resource management unit 503. In addition, the resource management unit 503 can also actively acquire the authentication capabilities from the device where the authentication unit 502 is located.

[0385] Exemplarily, the resource pool maintained by the resource management unit 503 can be as shown in Table 2.

[0386] Table 2

[0387]

[0388] In a possible implementation, considering that devices in the device networking can belong to different users, different devices store authentication factors of different users, or the same device in the device networking can be used by different users, and the same device can store templates of authentication factors of different users, the resource management unit 503 further manages information of templates of authentication factors associated with each user. It should be understood that it is necessary to associate, in advance, the template of the authentication factor of each user stored by each device in the device networking. Specifically, a possible association manner can be that a user selects a template of an authentication factor of a user from a device, and then a corresponding relationship is established between the selected template of the authentication factor and the user identifier. Another possible association manner can be that, when a device receives a newly entered template of an authentication factor (such as a secret template or a template of a biological feature of a user), a corresponding relationship is established between a biological feature template (such as a fingerprint feature template) that has been entered by the user and the newly entered template of the authentication factor. The biological feature template (such as the fingerprint feature template) that has been entered by the user has a one-to-one corresponding relationship with the user identifier, and the newly entered template of the feature by the user has a corresponding relationship with the biological feature template that has been entered by the user. Therefore, the newly entered template of the feature by the user also has a corresponding relationship with the user identifier. In this way, the resource management unit 503 can obtain the template of the authentication factor corresponding to the user identifier by querying the user identifier, so as to generate the information of the templates of the authentication factors associated with each user.

[0389] Exemplarily, the template of the authentication factor of each user managed by the resource management unit 503 can be as shown in Table 3.

[0390] Table 3

[0391]

[0392] It should be noted that the resource pool and the authentication factor association relationship maintained by the resource management unit 503 can be dynamically changed. For example, when a device in the device networking is powered off or offline, the authentication capability and the collection capability related to the device are converted into an unavailable state. For another example, when the software version of a device is upgraded, the device can add a new authentication capability. For another example, when the set of devices in the device networking changes (for example, a third electronic device is deleted), the authentication factor, the authentication capability, and the collection capability of the third electronic device are no longer included in the authentication resource pool.

[0393] The decision unit 504 is configured to determine an authentication combination manner that meets a security risk level by using a decision strategy based on the resources in the resource pool maintained by the resource management unit 503. The decision unit 504 can refer to the processor 210 shown in FIG. 2, that is, the actions performed by the decision unit are run and processed by the processor 210. FIG. 2 The decision unit 504 is configured to determine an authentication combination manner that meets a security risk level by using a decision strategy based on the resources in the resource pool maintained by the resource management unit 503. The decision unit 504 can refer to the processor 210 shown in FIG. 2, that is, the actions performed by the decision unit are run and processed by the processor 210.

[0394] The decision strategy of the decision unit 504 can include, but is not limited to, at least one of the following: decision strategy 1, preferentially using the authentication factor stored by the device, for example, when the resource pool maintained by the resource management unit 503 of the device includes a template of touch screen behavior, and the device has collected the touch screen behavior of the user in the historical use stage, the touch screen behavior is preferentially used as the authentication factor for authentication; decision strategy 2, preferentially using the collection unit of the user's non-aware (or having non-interrupt operation characteristics) to collect the authentication factor, for example, when the resource pool maintained by the resource management unit 503 of the device includes a template of the user's face, the collection unit of the face of the user is preferentially used to collect the face of the user; decision strategy 3, preferentially using the authentication unit of the user's non-aware (or having non-interrupt operation characteristics) to perform authentication, for example, when the resource pool maintained by the resource management unit 503 of the device includes a template of the user's face and the device has collected the face of the user, the authentication unit of the face of the user is preferentially used to perform authentication on the face of the user; decision strategy 4, preferentially collecting the authentication factor on the collection unit of the user's near-end device; decision strategy 5, preferentially performing authentication on the authentication unit of the user's near-end device. For example, when the user is in the living room, the device (such as a smart sound box) in the living room is preferentially used to collect the voice of the user or perform voiceprint authentication, rather than using the device in the bedroom to complete the collection or authentication.

[0395] Exemplarily, in one possible case, the decision strategy can be a pre-established mapping table, the mapping table including one or more authentication combination modes, and each authentication combination mode being identified with a corresponding security risk level, and the decision unit 504 can select the authentication combination mode corresponding to the risk level of the current service from the mapping table. In another possible case, the decision strategy can be a pre-established mapping table, the mapping table including one or more authentication modes and scores of the authentication modes, and the decision strategy further pre-configures index scores corresponding to various risk levels, and the decision unit 504 selects the authentication combination mode whose total score of the authentication modes can meet the index score according to the index score corresponding to the risk level of the current service.

[0396] The scheduling unit 505 is configured to determine the target authentication factor to be acquired according to the authentication combination mode determined by the decision unit 504, and determine the target collection unit corresponding to the target authentication factor and the target authentication unit corresponding to the target authentication factor. The scheduling unit 505 schedules the target collection unit to collect the target authentication factor, and schedules the target authentication unit to authenticate the collected target authentication factor to generate an authentication result. The target collection unit is a collection unit for collecting the target authentication factor, and the target authentication unit is an authentication unit for authenticating the target authentication factor. In software implementation, the scheduling unit 505 schedules specific open interfaces, such as scheduling a function interface exposed by a camera to acquire a face image, or scheduling a function interface of a face authentication service to acquire an authentication result of the face. The scheduling unit 505 can refer to the processor 210 shown in FIG. 8. FIG. 2

[0397] The decision unit 504 is further configured to generate a final aggregated authentication result according to the authentication result acquired from the at least one target authentication unit.

[0398] It should be noted that the embodiments of the present application do not limit the integration manner of the above-mentioned units in the electronic device. The above-mentioned units can be integrated in one electronic device, or part of the units can be integrated in one electronic device. For different types of electronic devices, some electronic devices can not have a secure execution environment, i.e., no authentication capability, so that the collection unit is integrated but the authentication unit is not integrated. Some electronic devices can be restricted by hardware components, for example, a smart speaker has no camera and no fingerprint sensor, so that the authentication unit is integrated but the collection unit is not integrated. Some electronic devices have both hardware and a secure execution environment, so that both the collection unit and the authentication unit are integrated.

[0399] In one possible case, the collection unit 501, the authentication unit 502, the resource management unit 503, the decision unit 504, and the scheduling unit 505 can be integrated in each electronic device in the device networking.

[0400] In another possible case, the resource management unit 503 and the at least one authentication unit 502 are integrated in a third electronic device in the device networking, the resource management unit 503 and the at least one collection unit 501 are integrated in a second electronic device in the device networking, and the resource management unit 503, the decision unit 504, and the scheduling unit 505 are integrated in a first electronic device in the device networking.

[0401] Exemplarily, as shown in FIG. 9, the collection unit 501, the authentication unit 502, the resource management unit 503, the decision unit 504, and the scheduling unit 505 can be integrated in each electronic device in the device networking. FIG. 6A ​As shown, the first electronic device is a hub device with decision-making capability, generally the hub device has a secure execution environment and / or belongs to a normally open device, the first electronic device includes a resource management unit 503, a decision unit 504 and a scheduling unit 505, the second electronic device is an electronic device with collection capability, the second electronic device includes at least one collection unit 501 and a resource management unit 503, and the third electronic device is an electronic device with authentication capability, the third electronic device includes at least one authentication unit 502 and a resource management unit 503. Specifically, if there is no unified data synchronization service in the operating system of the electronic device, a synchronization service function can be added to the resource management unit, and the resource synchronization process between devices can include the following steps:

[0402] S601a, at least one collection unit on the second electronic device sends registration information to the resource management unit of the second electronic device.

[0403] Exemplarily, the collection unit can correspond to a camera 293, a sensor module 280, a microphone 270C, etc. The resource management unit can correspond to the processor 210 described above. FIG. 2 During the boot-up process of the second electronic device, the camera, the sensor and other collection units notify the processor of the state of each collection unit, so that the processor 210 determines the collection units in the available state, and then saves the state information of the collection units in the available state to the internal memory 221.

[0404] Exemplarily, the registration information can be the collection capability of the second electronic device, the collected authentication factor or the information of the collected authentication factor, etc. For example, the registration information can include state information and an index of heart rate, and the state information indicates that the second electronic device has the heart rate collection capability.

[0405] S602a, the resource management unit of the second electronic device saves the authentication factor and the collection capability of the local device.

[0406] Exemplarily, the resource management unit of the second electronic device saves the authentication factor and the collection capability of the local device to a storage unit, such as the internal memory 221. The internal memory 221 in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. The non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory of the system and method described herein is intended to include, but not be limited to, these and any other suitable types of memory.

[0407] S603a, the resource management unit of the second electronic device calls the synchronization service to synchronize data with the resource management unit of the first electronic device.

[0408] That is, the resource management unit of the second electronic device sends the information currently maintained to the first electronic device, so that the information on the second electronic device is synchronized to the resource management unit of the first electronic device. For example, the state information and the index of the heart rate of the second electronic device are sent to the resource management unit of the first electronic device, so that the resource management unit on the second electronic device and the resource management unit on the second electronic device both save the same state information and the index of the heart rate.

[0409] S604a, at least one authentication unit on the third electronic device sends registration information to the resource management unit of the third electronic device.

[0410] Exemplarily, the registration information can be an authentication capability of the third electronic device, and the registration information can include state information indicating that the third electronic device has an authentication capability of heart rate.

[0411] S605a, the resource management unit of the third electronic device maintains the local authentication capability.

[0412] S606a, the resource management unit of the third electronic device reports the authentication capability, and the resource management unit of the third electronic device calls the synchronization service and synchronizes data with the resource management unit of the first electronic device.

[0413] That is, the resource management unit of the third electronic device synchronizes the currently maintained information to the resource management unit of the first electronic device. For example, the state information of the third electronic device is synchronized to the resource management unit of the first electronic device.

[0414] S607a, the resource management unit of the first electronic device maintains a resource pool including authentication factors, collection capabilities, and authentication capabilities.

[0415] S608a, the resource management unit of the first electronic device calls the synchronization service and synchronizes the resource pool to the resource management unit of the second electronic device.

[0416] S609a, the resource management unit of the first electronic device calls the synchronization service and synchronizes the resource pool to the resource management unit of the third electronic device.

[0417] That is, the resource management unit of the first electronic device manages the authentication factors, collection capabilities, and authentication capabilities of the authentication units of the plurality of electronic devices in the device networking, for example, the resource management unit of the first electronic device completes resource aggregation between devices. After resource aggregation, any device in the device networking can obtain the information of the collection unit or the authentication unit deployed by any other device in the device networking from the resource management unit of the first electronic device.

[0418] It should be noted that the above S601a to S603a can also occur after S604a to S606a, or the above S601a to S603a can be executed in parallel with S604a to S606a, and the present embodiment does not limit this.

[0419] Optionally, the devices can synchronize resources through a connected network (such as a cloud server therein). The synchronization mechanism of the synchronization service can be, but is not limited to, at least one of the following: timing synchronization (for example, synchronization once every minute), trigger synchronization (for example, synchronization once in response to a user operation), and update synchronization (for example, synchronization once when the information of the collection unit or the authentication unit changes).

[0420] Optionally, if a unified data synchronization service is set in the operating system of each electronic device, the resource management unit can not need to add a synchronization service function, and the existing data synchronization service can be used to realize resource synchronization. For details, please refer to FIG. 6A The examples are described.

[0421] As shown in FIG. 6B The first electronic device is a hub device with decision-making capability, and the first electronic device includes a resource management unit 503, a decision unit 504, and a scheduling unit 505. The second electronic device is an electronic device with collection capability, and the second electronic device includes at least one collection unit 501. The third electronic device is an electronic device with authentication capability, and the third electronic device includes at least one authentication unit 502. The resource synchronization process between devices can include the following steps:

[0422] S601b, at least one collection unit on the second electronic device sends first registration information to the resource management unit of the first electronic device.

[0423] Exemplarily, the first registration information can be the collection capability of the second electronic device, the collected authentication factor, or the information of the collected authentication factor, etc. For example, the first registration information can include state information and an index of heart rate, and the state information indicates that the second electronic device has heart rate collection capability.

[0424] S602b, at least one authentication unit of the third electronic device sends second registration information to the resource management unit of the first electronic device.

[0425] Exemplarily, the second registration information can be the collection capability of the second electronic device, the collected authentication factor, or the information of the collected authentication factor, etc. For example, the second registration information can include state information and an index of heart rate, and the state information indicates that the second electronic device has heart rate collection capability.

[0426] S603b, the first electronic device locally maintains a resource pool including authentication factors, collection capabilities, and authentication capabilities.

[0427] That is, the resource management unit of the first electronic device manages the authentication factors of multiple electronic devices in the device networking, the collection capabilities of the collection units, and the authentication capabilities of the authentication units, that is, the resource management unit of the first electronic device completes the resource aggregation between devices. After the resource aggregation, any device in the device networking can obtain the information of the collection unit or the authentication unit deployed by any other device in the device networking from the resource management unit of the first electronic device.

[0428] For example, in combination with FIG. 1B , the resource management unit of the first electronic device can obtain the information of the collection unit or the authentication unit deployed by the second electronic device from the resource management unit of the first electronic device. FIG. 1BIn the device network shown, camera 12 actively reports the collected facial biometric templates to smart TV 13, along with information about the face acquisition unit, confirming that the acquisition unit is in an available state. Alternatively, FIG. 1B In the illustrated device network, camera 12 actively reports instruction information to smart TV 13. This instruction information indicates that camera 12 has stored a facial biometric template and that the face acquisition unit of camera 12 is in an available state. After receiving the reported information, resource management unit 503 of smart TV 13 maintains or updates the resource pool, which includes the facial biometric template of camera 12 (or includes the instruction information indicating that camera 12 has stored a facial biometric template) and that the face acquisition unit of camera 12 is in an available state.

[0429] The methods provided in the embodiments of this application are described below by way of example. Each embodiment is based on... FIG. 1B The following explanation uses a smart home system as an example.

[0430] Example 1

[0431] Example 1 involves FIG. 7A to FIG. 8 .like FIG. 7A In the scenario shown, the smart lock, camera, and smart speaker are wirelessly connected. When a user returns from outside, they open the door. Upon receiving the user's opening action, the smart lock, camera, and smart speaker work together to authenticate the user's identity.

[0432] See FIG. 7B As shown, the specific process of the authentication method in this scenario includes the following steps.

[0433] The S701 smart door lock receives user input and collects the user's fingerprint.

[0434] For example, such as FIG. 7A As shown, when a user returns from outside, they open the door by touching the fingerprint sensor on the door lock with their finger. The fingerprint acquisition unit on the door lock (such as the fingerprint sensor) collects the user's fingerprint and triggers the generation of an authentication request. This authentication request is used to request identity authentication, and it includes the collected fingerprint. It should be noted that the following steps are illustrated using the door opening operation as an example of fingerprint unlocking and the authentication request including the user's fingerprint.

[0435] S702, the smart door lock sends an authentication request to the smart speaker, which includes the user's fingerprint.

[0436] In other words, in this scenario, the smart speaker acts as a central device, used to coordinate the network devices in the smart home system to collaboratively authenticate the user's identity.

[0437] S703, the smart speaker authenticates the fingerprint, and generates an authentication result of the fingerprint.

[0438] Specifically, the smart speaker is provided with an authentication unit of the fingerprint, the authentication unit of the fingerprint in the smart speaker acquires a template of the fingerprint, authenticates the fingerprint by using the template of the fingerprint, if the authentication is passed, the generated authentication result of the fingerprint includes information that the fingerprint authentication is passed, and optionally, the authentication result can also include an identifier of a target user corresponding to the authentication-passed fingerprint, if the authentication is not passed, the authentication result includes information that the fingerprint authentication is not passed. Exemplarily, the smart speaker serves as a hub device, the authentication unit of the fingerprint in the smart speaker can first authenticate the fingerprint by using an existing fingerprint template, if the authentication is passed, the generated authentication result of the fingerprint includes that the authentication is passed, and a target user corresponding to the fingerprint in the authentication request is the householder Alisa.

[0439] S704, the smart speaker judges whether the authentication result of the fingerprint is passed or not, when the authentication result is not passed, subsequent S714 is executed; when the authentication result is passed, subsequent S705 is executed.

[0440] S705, when the authentication result of the fingerprint is passed, the smart speaker can also determine a target user corresponding to the fingerprint, and judge whether the target user has a permission to execute the door opening business or not, when the judgment result is yes, the unlocking function is executed, or in other words, S706 is executed, otherwise, S714 is executed.

[0441] Exemplarily, the smart speaker can determine that the householder Alisa has the permission to execute the door opening business by querying a resource pool, such as querying Table 4 below.

[0442] Table 4

[0443]

[0444] S706, the smart speaker determines, by using a pre-set decision strategy, that a target authentication factor associated with the target user is a 3D face, a target authentication capability related to the target authentication factor is an authentication capability of the 3D face on the smart speaker, and a target acquisition capability is an acquisition capability of the 3D face on the camera.

[0445] The specific content of the decision strategy can refer to the above FIG. 5 The decision strategy 1 to the decision strategy 4 of the corresponding decision unit 504.

[0446] In detail, the decision unit of the smart speaker can determine, by querying the resource management unit, that the target authentication factor associated with the target user is a 3D face, and that the target authentication unit related to the target authentication factor is a 3D face authentication unit, and that the target collection unit is a 3D face collection unit, by using the decision strategy.

[0447] In an implementation manner, the resource management unit of the smart speaker can pre-store the resource pool according to the above FIG. 4 The resource management unit of the smart speaker can synchronize the collection capability and the authentication capability of the smart door lock and the camera according to the method steps shown in the table 4. For example, after the synchronization, the resource pool maintained by the resource management unit of the smart speaker includes the collection capability of the smart door lock with the fingerprint, the collection capability of the camera with the 3D face, and the authentication unit of the smart speaker with the 3D face and the fingerprint.

[0448] For example, the smart speaker queries the authentication factor associated with the householder Alisa from the resource management unit, and the query result is shown in the table 5.

[0449] Table 5

[0450]

[0451] Further, the smart speaker as the hub device can first determine that the risk level corresponding to the door opening operation is a high risk level according to the table 6.

[0452] Table 6

[0453]

[0454] Then, the smart speaker determines the authentication factor associated with the householder Alisa, and in the case that the fingerprint door lock has collected the user fingerprint in the S701, the decision strategy is used to preferentially select the authentication mode using the existing fingerprint, and then superimpose the collection mode of the 3D face of the user without awareness and the authentication mode of the 3D face, and finally determine to use the authentication combination mode of the 3D face + fingerprint corresponding to the high security level to authenticate the user identity, that is, the decision unit of the smart speaker determines that the target authentication factor associated with the target user is a 3D face, and that the target authentication unit related to the target authentication factor is a 3D face authentication unit, and that the target collection unit is a 3D face collection unit, by using the decision strategy.

[0455] For example, the decision strategy of the smart speaker for determining the authentication combination mode corresponding to the risk level requirement can include:

[0456] Decision strategy 1: a mapping table is established in advance, and the decision strategy of the authentication combination mode corresponding to the risk level requirement is determined according to the mapping table. The mapping table can rely on the developers to exhaust all possible authentication combination modes, and configure the corresponding risk level and operation for each authentication combination mode. The definition source and allocation basis of the mapping table are: a, experience value; b, experimental test results, such as testing each combination with a large data sample. The device integration mapping table can be pre-installed in the device at the beginning of research and development, or downloaded from the server.

[0457] Decision strategy 2: a precondition can be set, that is, the minimum score required by FAR and FRR is allocated for different risk levels of high, medium and low first, and then the score sum of all combinations of the currently available authentication modes is calculated according to the formula of summing up the scores of various authentication modes, and the authentication combination mode greater than or equal to the minimum score is selected. For example: the currently available authentication modes are: 2D face authentication, voiceprint authentication and fingerprint authentication, and each authentication mode has a quantitative score to describe the credibility of authentication, that is, the score of voiceprint is 60; the score of fingerprint is 80; the score of 3D face is 95, and the authentication combination mode that can meet the minimum score of the currently available combination mode is calculated. Authentication combination scheme 1) face + voiceprint; authentication combination scheme 2) face + fingerprint; authentication combination scheme 3) voiceprint + fingerprint. Assuming that it is a high-risk operation: the minimum score required is 160, so the decision strategy decides to use authentication combination scheme 2) to perform authentication of high-risk level business.

[0458] Then the smart speaker queries the following table 7 in the resource management unit to determine that 3D face has available authentication units and available collection units, and fingerprint has available authentication units, and finally determines the target authentication factor as fingerprint and 3D face, the target collection unit as the collection unit of fingerprint and the collection unit of 3D face, and the target authentication unit as the authentication unit of fingerprint and the authentication unit of 3D face. For FIG. 7A In the example shown, it is finally determined to use the authentication combination mode of fingerprint + 3D face, the fingerprint collection unit of the smart door lock is used to collect fingerprint, the 3D face collection unit of the camera is used to collect 3D face, the fingerprint authentication unit of the smart speaker is used to authenticate fingerprint, and the 3D face authentication unit of the smart speaker is used to authenticate 3D face.

[0459] Table 7

[0460]

[0461] Optionally, when there are multiple available collection units of the fingerprint (or the 3D face), or multiple available authentication units of the fingerprint (or the 3D face), the smart speaker further filters inappropriate collection units and / or authentication units according to a business scenario and / or a user location. For example, the current business is a door opening operation business, so the fingerprint collection unit arranged on the door is preferentially selected to collect the fingerprint of the user, or the camera arranged on the door is preferentially selected to collect the 3D face of the user, instead of selecting the smart home device in the room of the user to collect the fingerprint and the 3D face.

[0462] S707, the smart speaker sends a collection instruction to the camera, where the collection instruction is used to instruct to collect the 3D face.

[0463] S708, the camera collects the face image.

[0464] S709, the camera sends the collected face image to the smart speaker.

[0465] It should be noted that in the method embodiment, the smart speaker can also obtain the 3D face from the camera, that is, the camera can actively report, or the smart speaker can actively obtain from the camera.

[0466] S710, the smart speaker authenticates the face image to generate an authentication result of the 3D face.

[0467] That is, the authentication unit of the smart speaker authenticates the 3D face collected by the camera by using the stored 3D face template to generate an authentication result of the 3D face.

[0468] S711, the smart speaker determines whether the authentication result of the face is passed, and when the authentication is passed, S712 is performed, otherwise S714 is performed.

[0469] S712, when the face authentication is passed, the smart speaker sends an unlocking instruction to the smart door lock.

[0470] For example, when the final authentication result is passed, the processor of the smart speaker sends a door opening instruction to the smart door lock, and when the final authentication result is failed, the processor of the smart speaker sends a door opening rejection instruction to the smart door lock.

[0471] S713, the smart door lock controls the door lock to be opened according to the received unlocking instruction.

[0472] S714, when the fingerprint authentication is not passed, the target user does not have the permission to perform the door opening business, or the face authentication is not passed, the smart door lock sends an instruction to reject the unlocking to the smart door lock.

[0473] S715, the intelligent door lock controls the door lock not to open according to the received instruction of refusing to open the door lock.

[0474] From the above embodiment, because the security level of the door opening service belongs to a high security level, the intelligent door lock, the intelligent sound box and the camera cooperate to authenticate the user's fingerprint and 3D face, and because the reliability of the authentication result of the fingerprint and the authentication result of the 3D face is high, the security problem caused by simply using the user's fingerprint for identity authentication can be improved, and the reliability of the authentication result is improved.

[0475] In a possible embodiment, in S701 described above, when the intelligent door lock has the authentication capability of the fingerprint, the intelligent door lock can first authenticate the user's fingerprint, generate the authentication result of the fingerprint, and when the authentication is successful, execute the subsequent steps, otherwise, do not execute the subsequent steps.

[0476] In a possible embodiment, if the fingerprint sensor of the intelligent door lock is damaged, so that the user's fingerprint cannot be normally collected, the intelligent sound box can authenticate the identity of the user according to the authentication of the 3D face, and when the authentication is passed, the door is successfully opened.

[0477] In a possible embodiment, if the battery of the intelligent door lock is exhausted, so that the user's fingerprint cannot be normally collected, the user can choose to issue a voice wake-up instruction "Xiaoyi Xiaoyi, please open the door", as shown in FIG. 7C The microphone arranged on the door can send the collected wake-up voice of the user to the intelligent sound box, and the intelligent sound box performs voiceprint authentication. It should be noted that the microphone and the intelligent door lock are powered independently. Alternatively, the indoor intelligent sound box collects the wake-up voice of the user, and the intelligent sound box performs voiceprint authentication. In addition, after the voiceprint authentication is passed, the 3D face of the user can also be collected according to the above method to perform 3D face authentication, and finally the authentication result of the 3D face and the authentication result of the voiceprint are used to instruct the intelligent door lock to open the door or refuse to open the door.

[0478] In a possible embodiment, as shown in FIG. 7D If the camera on the door lock collects the faces of the users in the set area outside the door, the collection result includes the faces of multiple users, and part of the face authentication is passed, but part of the face authentication is not passed, in one possible case, the intelligent sound box can instruct the intelligent door lock to directly open the door, and in another possible case, in order to improve the security, the intelligent sound box can further send the collected face image to the user's mobile phone for the user to confirm whether to open the door, or the intelligent sound box instructs the camera on the door lock to send the collected face image to the user's mobile phone. As shown in FIG. 8 As shown in FIG. 8The interface 800 shown in (a) displays notifications related to smart living applications, including a request to open the door and asks the user to confirm. When the user taps to open the notification, the phone displays the following... FIG. 8 The interface 810 shown in Figure (b) displays an image 811 and a prompt box 812, which includes an open control 813 and a reject control 814. When the user determines that the current user is a trusted user based on the image 811, they can click to operate the open control 813; otherwise, they can click to operate the reject control 814. This method can further improve the reliability and security of the authentication results.

[0479] Example 2

[0480] Example 2 involves FIG. 9A and FIG. 9B .like FIG. 9A In the scenario shown, a wireless connection is established between the smart TV and the smart speaker. When the user operates the smart TV and issues the voice wake-up command "Hey Hey Hey, open the weather app", it triggers the user's identity authentication.

[0481] See FIG. 9B As shown, the specific process of the authentication method in this scenario includes the following steps.

[0482] The S901 smart speaker collects the user's wake-up voice, such as "Xiaoyi Xiaoyi, open the weather app".

[0483] For example, the smart speaker collects sounds from the surrounding environment in real time and processes the sounds in real time to obtain the user's wake-up voice.

[0484] S902, the smart speaker determines that opening the weather app is a low-security-risk operation, and then uses a decision-making strategy to determine that the authentication method corresponding to this operation can be voiceprint authentication.

[0485] The specific details of the decision-making strategy can be found in the text above. FIG. 5 The corresponding decision-making unit 504 has decision-making strategies 1 to 4.

[0486] Specifically, in one possible scenario, the smart speaker's decision-making unit maintains a preset mapping table. This mapping table can be an exhaustive list of all possible authentication methods by the developers, and each operation is configured with a corresponding risk and security level. For example, as shown in Table 8 below, the mapping table is configured with the risk and security levels corresponding to different wake-up voice commands or operations, as well as the authentication trust level requirements.

[0487] Table 8

[0488]

[0489] As shown in Table 8 above, when a user issues the wake-up voice command "Open the weather app", the risk security level corresponding to this service is Level 1. The authentication method for this operation needs to meet the authentication trust level requirements of Level 1. Specifically, the authentication method can be voiceprint authentication.

[0490] The S903 smart speaker performs voiceprint authentication on the user's wake-up voice and generates the voiceprint authentication result.

[0491] For example, the scheduling unit of the smart speaker schedules the voiceprint authentication unit of the smart speaker to perform voiceprint authentication on the user's wake-up command according to the authentication method determined by the decision unit, and generates an authentication result.

[0492] S904: The smart speaker determines whether the voiceprint authentication result is successful. If the authentication is successful, proceed to S905; otherwise, proceed to S906.

[0493] S905: When the authentication result is authentication failure, the smart speaker will determine not to instruct the smart TV to open the weather app.

[0494] For example, a smart speaker can also respond via voice if a user's authentication fails.

[0495] S906: When the authentication result is successful, the smart speaker instructs the smart TV to open the weather app.

[0496] As can be seen, in this embodiment, when the user's operation is a low-security-risk operation, the electronic device can use a voiceprint authentication method corresponding to the security-risk level of the operation for authentication.

[0497] Example 3

[0498] Example 3 involves FIG. 10A and FIG. 10B .like FIG. 10A In the scenario shown, a wireless connection is established between the smart TV, smart speaker, and smart band. When the user operates the smart TV and issues the wake-up voice command "Hey Celia, open the gallery app," the user's identity is authenticated.

[0499] See FIG. 10B As shown, the specific process of the authentication method in this scenario includes the following steps.

[0500] S1001, the smart speaker collects the user's wake-up voice, where the user's wake-up voice is "Xiaoyi Xiaoyi, open the gallery application".

[0501] S1002, the smart speaker determines that the operation of opening the gallery application belongs to the operation of the medium security risk level, and then the smart speaker determines that the authentication mode corresponding to the operation can be the authentication combination mode of voiceprint authentication and pulse authentication by using the decision strategy.

[0502] The specific content of the decision strategy can refer to the above FIG. 5 The decision strategy 1 to the decision strategy 4 of the corresponding decision unit 504.

[0503] Specifically, in one possible case, the decision unit of the smart speaker can determine, according to the maintained preset mapping table, that when the wake-up voice of the operation is “opening the gallery application”, it is determined that the risk security level corresponding to the operation is the third level, and the authentication mode for the operation needs to meet the third level authentication trust level requirement, specifically, the authentication mode can select voiceprint authentication + pulse authentication.

[0504] S1003, the smart speaker performs voiceprint authentication on the wake-up voice of the user, and generates an authentication result of the voiceprint.

[0505] Exemplarily, the scheduling unit of the smart speaker instructs the voiceprint authentication unit of the smart speaker to perform voiceprint authentication on the wake-up instruction of the user according to the authentication mode determined by the decision unit.

[0506] S1004, the smart speaker performs authentication on the pulse of the user by using the collected pulse information previously obtained from the smart bracelet, and generates an authentication result of the pulse.

[0507] Exemplarily, the scheduling unit of the smart speaker obtains the collected pulse information from the resource management unit, and performs authentication on the pulse of the user by using the pulse authentication unit in the smart speaker.

[0508] S1005, the smart speaker aggregates the authentication result of the voiceprint and the authentication result of the pulse to generate a final authentication result.

[0509] Exemplarily, the decision unit of the smart speaker obtains the authentication result of the voiceprint from the voiceprint authentication unit of the smart speaker, and obtains the authentication result of the pulse from the pulse authentication unit, aggregates the two authentication results to generate a final authentication result. The specific aggregation method can be that if any one or more authentication results fails, the authentication result fails; if all authentication results pass, the authentication result passes.

[0510] S1006, the smart speaker determines whether the final authentication result is authentication pass or not, if the authentication passes, S1007 is executed, otherwise, S1008 is executed.

[0511] S1007, when the authentication result is authentication failure, it is determined that the smart television is not instructed to open the weather application.

[0512] For example, a smart speaker can also respond via voice if a user's authentication fails.

[0513] S1008: When the authentication result is successful, the smart speaker instructs the smart TV to open the Gallery app.

[0514] Optionally, when the smart TV receives an instruction to open the gallery app, it can open and display pictures stored on local or external storage.

[0515] As can be seen, in this embodiment, when the user's operation is of medium security risk level, the electronic device can use a combination of voiceprint authentication and pulse authentication corresponding to the security risk level of the operation for authentication.

[0516] Example 4

[0517] Example 4 involves FIG. 11A and FIG. 11B .like FIG. 11A In the scenario shown, a smart TV is connected to an external storage drive containing sensitive user data. The smart TV, mobile phone, and smart speaker establish a wireless connection. When the user operates the smart TV and issues a voice wake-up command, "Hey Celia, open the safe app," user authentication is triggered.

[0518] See FIG. 11B As shown, the specific process of the authentication method in this scenario includes the following steps.

[0519] S1101, the smart speaker collects the user's wake-up voice, where the user's wake-up voice is "Xiaoyi Xiaoyi, open the safe app".

[0520] In the safe application, the data may come from a storage disk, which may contain sensitive user data such as financial statements and medical examination results.

[0521] S1102, the smart speaker determines that the operation of opening the safe application is a high-security-risk operation. Then, the smart speaker uses a decision-making strategy to determine that the authentication method corresponding to this operation can be a combination of 3D face authentication and voiceprint authentication.

[0522] The specific details of the decision-making strategy can be found in the text above. FIG. 5 The corresponding decision-making unit 504 has decision-making strategies 1 to 4.

[0523] Specifically, in one possible case, the decision unit of the smart speaker can determine, according to the maintained preset mapping table, that the risk security level corresponding to the wake-up voice of the operation of "opening the safe application" is the fourth level, and the authentication manner for the operation needs to meet the fourth authentication trust level requirement, and specifically, the authentication manner can be 3D face authentication + voiceprint authentication.

[0524] In S1103, the smart speaker performs voiceprint authentication on the wake-up voice of the user, and generates an authentication result of the voiceprint.

[0525] Exemplarily, the scheduling unit of the smart speaker instructs the voiceprint authentication unit of the smart speaker to perform voiceprint authentication on the wake-up instruction of the user according to the authentication manner determined by the decision unit, the voiceprint authentication unit of the smart speaker generates an authentication result of the voiceprint, and then the decision unit of the smart speaker acquires the authentication result of the voiceprint from the voiceprint authentication unit.

[0526] In S1104, the smart speaker instructs the smart television to capture a face image.

[0527] Exemplarily, the scheduling unit of the smart speaker instructs the camera of the smart television to capture a face image according to the authentication manner determined by the decision unit.

[0528] In S1105, the camera of the smart television captures a face image.

[0529] Exemplarily, in one possible case, the camera of the smart television captures the face image of the user without being perceived by the user; in another possible case, the smart television can display prompt information on the display screen, the prompt information being used to prompt the user to stand in the shooting range of the camera of the smart television, such as standing in front of the smart television and facing the smart television, so as to accurately capture the face image of the user by the camera.

[0530] In S1106, the smart television sends the captured face image to the smart speaker.

[0531] In S1107, the smart speaker acquires the face image from the smart television, authenticates the face of the user, and generates an authentication result of the face.

[0532] Exemplarily, the face authentication unit of the smart speaker authenticates the face image, and generates an authentication result of the 3D face.

[0533] In S1108, the smart speaker aggregates the authentication result of the voiceprint and the authentication result of the 3D face, and generates a final authentication result.

[0534] Exemplarily, the decision unit of the smart speaker obtains the voiceprint authentication result from the voiceprint authentication unit of the smart speaker, and obtains the 3D face authentication result from the face authentication unit, aggregates the two authentication results, and generates a final authentication result. The specific aggregation method can be that if any one or more authentication results fails, the authentication result fails; if all authentication results pass, the authentication result passes.

[0535] S1109, the smart speaker determines whether the final authentication result is authentication pass, if yes, executes S1110, otherwise, executes S1111.

[0536] S1110, when the authentication result is authentication failure, the smart speaker determines not to instruct the smart TV to open the safe application.

[0537] Exemplarily, the smart speaker can also reply that the user authentication fails, and instruct the smart TV to refuse to open the safe application.

[0538] S1111, when the authentication result is authentication pass, the smart speaker instructs the smart TV to open the safe application.

[0539] It can be seen that in this embodiment, when the operation of the user is an operation of a high security risk level, the electronic device can use the authentication combination mode of voiceprint authentication and 3D face authentication corresponding to the security risk level of the operation for authentication.

[0540] Embodiment Five

[0541] Embodiment Five relates to FIG. 12A and FIG. 12B . As shown in the scenario FIG. 12A , the microwave oven, the smart speaker and the mobile phone establish a wireless connection, the user operates the microwave oven, and when the user issues the voice wake-up instruction "Xiaoyi Xiaoyi, microwave oven high fire heating for five minutes", identity authentication of the user is triggered.

[0542] Referring to FIG. 12B , the specific process of the authentication method in this scenario includes the following steps.

[0543] S1201, the smart speaker collects the wake-up voice of the user, wherein the wake-up voice of the user is Xiaoyi Xiaoyi, microwave oven high fire heating for five minutes.

[0544] S1202, the smart speaker determines that the operation of microwave oven high fire heating for five minutes belongs to an operation of a high security risk level, and then the smart speaker determines that the authentication mode corresponding to the operation can be the authentication combination mode of fingerprint authentication and voiceprint authentication by using a decision strategy.

[0545] The specific content of the decision strategy can refer to the above FIG. 5Corresponding decision policy 1 to decision policy 4 of the decision unit 504.

[0546] Specifically, in one possible case, the decision unit of the smart speaker can determine, according to the maintained preset mapping table, that the corresponding risk safety level of the operation involving the microwave oven is the fourth level, and the authentication mode for the operation needs to meet the fourth authentication trust level requirement, and specifically, the authentication mode can select fingerprint authentication + voiceprint authentication.

[0547] S1203, the smart speaker performs voiceprint authentication on the wake-up voice of the user, and generates an authentication result of the voiceprint.

[0548] Exemplarily, the scheduling unit of the smart speaker instructs the voiceprint authentication unit of the smart speaker to perform voiceprint authentication on the wake-up instruction of the user according to the authentication mode determined by the decision unit, the voiceprint authentication unit of the smart speaker generates an authentication result of the voiceprint, and then the decision unit of the smart speaker acquires the authentication result of the voiceprint from the voiceprint authentication unit.

[0549] S1204, the smart speaker instructs the mobile phone to collect the fingerprint of the user.

[0550] S1205, the mobile phone receives the fingerprint input by the user.

[0551] Exemplarily, the smart life application in the mobile phone displays prompt information to prompt the user to input the fingerprint, and the user actively touches the fingerprint sensor after receiving the prompt, and the fingerprint sensor in the mobile phone collects the fingerprint of the user.

[0552] Optionally, the above S1205 can also be performed by the smart speaker and the mobile phone, for example, the smart speaker issues voice prompt information to prompt the user to input the fingerprint on the mobile phone, and then the user operates on the fingerprint sensor of the mobile phone, and the fingerprint collection unit in the mobile phone collects the fingerprint of the user.

[0553] S1206, the mobile phone sends the collected fingerprint to the smart speaker.

[0554] S1207, the mobile phone authenticates the fingerprint input by the user, and generates an authentication result of the fingerprint.

[0555] Exemplarily, the fingerprint authentication unit in the mobile phone authenticates the received fingerprint, and generates an authentication result of the fingerprint.

[0556] S1208, the smart speaker aggregates the authentication result of the voiceprint and the authentication result of the fingerprint, and generates a final authentication result.

[0557] S1209, the smart speaker determines whether the final authentication result is authentication passed, if the authentication is passed, S1210 is executed, otherwise, S1211 is executed.

[0558] S1210, when the authentication result is authentication failure, the smart speaker determines not to instruct the microwave oven to start microwave oven heating.

[0559] Exemplarily, the smart speaker can also voice reply that the user authentication is not passed, and does not instruct the microwave oven.

[0560] S1211, when the authentication result is authentication passed, the smart speaker instructs the microwave oven to start microwave oven heating for five minutes.

[0561] It can be seen that in this embodiment, when the operation of the user is an operation of a high security risk level, the electronic device can use the authentication combination mode of the voiceprint authentication and the fingerprint authentication corresponding to the security risk level of the operation to perform authentication.

[0562] In a possible embodiment, before performing the above-mentioned S1203, it can be further judged whether the user corresponding to the voiceprint after the authentication is passed has the operation permission of the microwave oven. When there is the operation permission, the subsequent steps are further performed, otherwise, the subsequent steps are not performed. Exemplarily, if the user corresponding to the voiceprint after the authentication is passed is the householder Alisa, the subsequent steps can be performed; if the user corresponding to the voiceprint after the authentication is passed is a child, the subsequent steps are not performed, and the microwave oven is instructed to refuse to start microwave oven heating or the user is prompted that the authentication is failed.

[0563] In a possible embodiment, the collection ability / authentication ability on the unsafe device can be further filtered by considering the security level of the device and the current security state. Assuming that in the scenario shown in embodiment five, the collection ability / authentication ability of the smart speaker, the smart phone, and the current device state are as shown in Table 9.

[0564] Table 9

[0565] Unit name Authentication method Current state Device where located identification Current device state Voiceprint authentication unit Voiceprint Available Smart speaker Trojan horse threat Voiceprint authentication unit Voiceprint Available Mobile phone Safe Fingerprint authentication unit Fingerprint Available Mobile phone Safe

[0566] From Table 9, it can be seen that the security state of the smart speaker does not meet the requirement of the authentication because of the existence of the Trojan threat, and therefore the voiceprint authentication unit on the smart speaker is filtered out, and the voiceprint and the fingerprint are authenticated by using the smart phone. The above-mentioned S1203 can be: the smart phone acquires the collection wake-up voice from the smart speaker, the voiceprint authentication unit of the smart phone performs voiceprint authentication on the wake-up voice, and generates an authentication result of the voiceprint. Optionally, the above-mentioned S1207 can be: the smart phone acquires the authentication result of the fingerprint from the fingerprint authentication unit of the smart phone, and acquires the authentication result of the voiceprint from the voiceprint authentication unit, aggregates the authentication result of the voiceprint and the authentication result of the fingerprint, and generates a final authentication result.

[0567] In a possible embodiment, the inappropriate collection capability / authentication capability can be further filtered according to a business scenario or a current location of the user. Assuming that in the scenario shown in Embodiment Five, the collection capability and authentication capability of the smart speaker and the smart phone, and the current device location are as shown in Table 10.

[0568] Table 10

[0569] Unit name Authentication method Current state Device where located identification Current device location Voiceprint authentication unit Voiceprint Available Smart speaker Living room Voiceprint authentication unit Voiceprint Available Mobile phone Bedroom Fingerprint authentication unit Fingerprint Available Mobile phone Bedroom

[0570] As can be seen from Table 10, if the current location of the user is in the bedroom, the smart speaker is relatively far away from the user, and the user can select to collect the voiceprint of the user by using the smart phone and collect the fingerprint of the user by using the smart phone according to the current location of the user, and finally complete the fingerprint authentication and voiceprint authentication on the smart phone.

[0571] It should be understood that the embodiment needs to determine the location of the device and the location of the user in advance. One possible implementation manner of determining the location of the device can be that the user can actively label the location of the fixed device such as the smart television, the smart speaker and the camera, and when the user starts to use, the location of the device can be labeled in the application.

[0572] In addition, there are various ways to determine the location of the user. One possible implementation manner of determining the location of the user can be that the image collection device is provided with a user location detection module, and the user location detection module updates the current location of the user according to the real-time collected image. For example, the baby room has a monitoring camera, and the bedroom can collect images in real time. When the monitoring camera of the baby room shoots the user, the current location of the user is updated to the baby room. For example, the smart screen in the living room is provided with a camera, and the smart screen shoots the user, and the current location of the user is updated to the living room. In other possible cases, since the bedroom can not be provided with a camera, if the smart screen does not detect the user, the user can be prompted to come to the living room for authentication when the user initiates the authentication.

[0573] Alternatively, another way to determine the location of the user can be that the user location detection module in the electronic device can continuously perceive the user signal or periodically perceive the user information, and when the user is perceived, the current location of the device is determined as the current location of the user. In addition, the devices in the device networking can also synchronize the perceived user location to other devices, so as to determine the current location of the user by other devices.

[0574] Based on the above embodiments, it can be seen that the authentication method provided by the embodiments can realize that at least two authentication factors provided by the electronic devices are used to jointly authenticate the same service, that is, multiple authentication factors on multiple electronic devices are used to superimpose authentication of the same service, for example, for a high-security level door opening service, a camera and a door lock are called to jointly perform face authentication and fingerprint authentication to ensure the reliability of the authentication result and improve the authentication security level of the device.

[0575] Implementation mode two

[0576] Based on the above FIG. 3 As shown in the steps, in S301, the first electronic device receives an authentication request, including: the first electronic device receives a target operation, the target operation being used to trigger generation of an authentication request. In S302, the first electronic device determines a specific mode of an authentication mode corresponding to the first service, which can be: the first electronic device first queries a correspondence between the target operation and a target security value, determines a target security value required for executing the target operation, and the target operation is used to trigger execution of the first service; the first electronic device determines M1 authentication devices, M1 being a positive integer, and the M1 authentication devices being devices having the capability of authenticating user information, and the M1 authentication devices being included in M electronic devices. In S303, the first electronic device schedules the M electronic devices to authenticate the first service according to the authentication mode, including: the first electronic device acquires an authentication result of at least one authentication device of the M1 authentication devices; determines a total authentication security value according to a correspondence between an authentication mode of the at least one authentication device and an authentication security value and the authentication result; if the total authentication security value is not less than the target security value, the authentication is passed, otherwise, the authentication is not passed. Optionally, in the case of passing the authentication, the method further includes: the first electronic device triggers the operation device to execute the target operation.

[0577] In view of the fact that in the prior art, the user will perform some relatively high-sensitive operations (such as a lock opening operation and a payment operation, etc.), which usually require relatively strict identity authentication, if the user can only perform face authentication through a weak authentication mode (such as 2D face) possessed by the device itself, the security of the authentication result is likely to be low. In comparison with the prior art, the authentication mode provided by the implementation mode two can trigger the operation device to execute the target operation in the case that the total authentication security value is not less than the target security value required for executing the target operation, thereby providing the first service with an authentication level required for identity authentication, and thereby improving the security of the identity authentication.

[0578] It should be noted that, for the sake of understanding the following, some concepts related to the implementation mode two will be introduced first as follows:

[0579] (a) a correspondence relationship between a root key storage environment of the authentication device and a score of the root key storage environment

[0580] The root key can refer to a key for encrypting storage of an authentication credential. The higher the security level of the root key storage environment, the higher the score of the root key storage environment of the authentication device.

[0581] The root key storage environment of one authentication device can include an inside Secure Element (inSE) level, a trusted Execution Environment (TEE) level, a white box, and key segmentation.

[0582] The white box in the embodiments of the present application can refer to white box cryptography technology, the main design idea of which is to confuse the cryptographic algorithm so that an attacker cannot know the specific algorithm running process, so that the root key can be hidden in the software implementing the white box cryptography technology, and the entire algorithm execution process is represented using a lookup table, so that the attacker cannot obtain any information about the root key from the software or the cryptographic operation process, effectively realizing protection of the root key.

[0583] In the key segmentation technology in the embodiments of the present application, key components constituting the root key are stored in the system in a scattered manner, and the root key is dynamically generated by the key components only when needed, and the root key needs all the key components, and each key component is independently saved in a logical entity, and each component needs to be saved in a scattered manner. This method can solve the problem of "hard coding" of the root key, and can ensure the security of the root key to a certain extent.

[0584] Table 11: Correspondence relationship between the root key storage environment of the terminal device and the score of the root key storage environment

[0585] Root key storage environment Score (points) of root key storage environment inSE level 100 TEE level 90 White box 20 Key segmentation 10

[0586] (b) a correspondence relationship between the authentication device, the authentication mode, and the authentication security value

[0587] In the embodiments of the present application, based on the score of the root key storage environment of the authentication device and the score of the authentication mode, a correspondence relationship between the authentication device, the authentication mode, and the authentication security value can be established. Table 12 exemplarily shows an example of a correspondence relationship between the authentication device, the authentication mode, and the authentication security, in which the authentication security value can be calculated according to a first calculation rule. In a possible implementation manner, the first calculation rule includes weighted addition of the score of the root key storage environment and the score of the authentication mode. In Table 12, the weight corresponding to the score of the root key storage environment is set to 0.3, and the weight of the score of the authentication mode is set to 0.7.

[0588] Table 12 correspondence between authentication device, authentication mode and authentication security value

[0589]

[0590] The authentication security value in the embodiments of the present application can be understood as the authentication security level of the authentication device. When the authentication security value corresponding to the authentication device and the authentication mode is higher, the authentication security level of the authentication device using the authentication mode for authentication is higher, and vice versa, the authentication security level of the authentication device using the authentication mode for authentication is lower.

[0591] (c) operating device

[0592] In the embodiments of the present application, the terminal device receiving the user's request operation is referred to as the operating device.

[0593] The operating device can not have the ability to authenticate user information, or have the ability to authenticate user information.

[0594] For example, the user requests to perform a payment operation on a smart TV, and the device provided by the embodiments of the present application can call the smart TV to perform face recognition on the user. As can be seen in this example, the smart TV belongs to the operating device, and the smart TV needs to perform 2D face recognition on the user, so the smart TV is also an authentication device.

[0595] (d) correspondence between operation and security value

[0596] The correspondence between the operation and the security value is used to indicate the security value required for an operation. Only when the obtained authentication security value is not less than the security value required for an operation, or the total authentication security value calculated according to the obtained multiple authentication security values is not less than the security value required for the operation, is the authentication for the operation considered successful, and the operation can be executed, otherwise, the authentication for the operation is considered unsuccessful, and the operation cannot be executed.

[0597] In one possible implementation, the correspondence between the operation and the security value can be pre-set. Specifically, when the device provided by the embodiments of the present application is a server deployed in the cloud, the correspondence between the operation and the security value can be stored on the server in the cloud, when the device provided by the embodiments of the present application is a router, the correspondence between the operation and the security value can be stored on the router, and when the device provided by the embodiments of the present application is a terminal device, the correspondence between the operation and the security value can be stored on the terminal device. In another possible implementation, the correspondence between the operation and the security value can also be set by the user.

[0598] A security value can be a score or a level. Table 13 of this application's embodiments illustrates the correspondence between several operations and security values, using a security value as a score as an example. As shown in Table 13, highly sensitive operations such as payment and unlocking can be set with higher security values ​​(e.g., 95, 90, 85, etc.). Moderately sensitive operations such as unlocking the screen and logging into an account can be set with relatively moderate security values ​​(e.g., 75). Operations involving user type identification can be set with lower security values ​​(e.g., 20).

[0599] Taking the first row of Table 13 as an example, in one application scenario, before a user watches a smart TV, the smart TV needs to perform a "user type identification" operation (this operation can be initiated by the user or automatically triggered after the smart TV is turned on). The purpose of this operation is to allow the smart TV to play TV programs according to the user type. For example, if the user is a parent, a TV program guide corresponding to the parent is provided, with no time limit; if the user is a child, a TV program guide corresponding to the child is provided, and the program automatically turns off after 20 minutes. Compared to operations such as payment and unlocking, this operation does not require a high level of security, so a lower security value can be set, such as 20 points in Table 13. As shown in Table 13, small-amount payment operations can be defined as payments of less than 300 yuan, and large-amount payment operations can be defined as payments of not less than 300 yuan.

[0600] Table 13 Correspondence between Operation and Safety Values

[0601]

[0602]

[0603] The authentication method provided in the embodiments of this application will be described below in conjunction with practical application scenarios.

[0604] Based on the above, FIG. 13 An exemplary flowchart of an authentication method provided in an embodiment of this application is shown below. The following section will illustrate this method in the context of a user requesting a small-amount payment on a smart TV. FIG. 13 Let me introduce it. FIG. 13 The authentication scheme shown is illustrated using the device provided in the embodiment of this application as the server, and the operating device has authentication capabilities as an example. FIG. 13 Because the operating equipment has authentication capabilities, therefore in FIG. 13 The equipment operated by the lieutenant general is also identified as certified equipment b2.

[0605] It should be noted that, FIG. 13 The authentication scheme shown uses the device provided in the embodiment of this application as an example to illustrate the server. The following...FIG. 13 The execution entity "server" in the text can also be replaced with the "device" provided in this application embodiment. When the device provided in this application embodiment is a router, the relevant scheme executed by the device is similar to the scheme executed when the device is a server, and it may be necessary to... FIG. 13 The execution entity involved in this process, "server," has been replaced with "router," and will not be elaborated upon further here.

[0606] like FIG. 13 As shown, the method includes:

[0607] S1300, the operating device receives a request from the user to perform a target operation on the operating device.

[0608] In the scenario of a user requesting a small payment on a smart TV, in the S1300, the operating device is a smart TV, such as... FIG. 15A As shown, a user wants to watch a show on a smart TV. The video app on the smart TV is in children's mode. The smart TV displays, "This show requires payment to watch. You can purchase the entire series for 10 yuan. Do you want to buy?" If the user clicks "Buy Now," the smart TV receives a request to perform a "10 yuan payment operation." In other words, in this scenario, the target operation is: "a 10 yuan payment operation."

[0609] S1301, the operating device generates a first authentication request and sends it to the server. The first authentication request is used to request the server to authenticate the target operation. The first authentication request may include first indication information, which is used to indicate the target operation.

[0610] Correspondingly, the server receives the first authentication request.

[0611] In the scenario of a user requesting a small payment on a smart TV, in step S1301, the smart TV sends a first authentication request to the server. This first authentication request is used to request authentication for the "payment operation of 10 yuan".

[0612] S1302, the server determines the security value corresponding to the target operation based on the preset correspondence between operations and security values. For ease of description in this embodiment, the security value corresponding to the target operation is referred to as the target security value. The preset correspondence between operations and security values ​​can be as shown in Table 14 above.

[0613] In the case of the user requesting a small payment operation on the smart TV, the target operation is a "10 yuan payment operation", and in Table 13, if the security value corresponding to the small payment operation less than 300 yuan is defined as 85 points, the server can determine the security value corresponding to the "10 yuan payment operation" as 85 points according to Table 13 by querying the preset correspondence between the operation and the security value ("10 yuan payment operation" belongs to the "small payment operation" less than 300 yuan in Table 13).

[0614] S1303, in the case that the operation device can support authentication of the user information, the server determines one or more authentication security values corresponding to the operation device according to the correspondence between the authentication device, the authentication manner and the authentication security value.

[0615] Optionally, the operation device can send the authentication manners supported by itself and the root key storage environment of itself to the server before S1303, so that the server establishes the correspondence between the operation device, the authentication manner and the authentication security value. In one possible implementation, the operation device sends the authentication manners supported by itself and the root key storage environment of itself to the server when initially accessing the network, so that the server stores them. In another possible implementation, the server can query whether the operation device has authentication capability after receiving the first authentication request after S1302 and before S1303. In the case that the operation device has authentication capability, the operation device sends the authentication manners supported by itself and the root key storage environment to the server. For example, the operation device (smart TV) has 2D face recognition capability, and has reported its capability to the server before S1303.

[0616] It should be noted that one operation device can have one or more authentication capabilities, and accordingly, the server can obtain all the authentication manners supported by the operation device and determine the authentication security value corresponding to each authentication manner.

[0617] In the case of the user requesting a small payment operation on the smart TV, the smart TV sends the authentication manners supported by itself and the root key storage environment to the server before S1303. Therefore, in S1303, it can be determined that the authentication manner adopted by the smart TV is 2D face recognition, and the root key storage environment is TEE, and the corresponding authentication security value is 76 points.

[0618] S1304, the server judges whether the authentication security value corresponding to the operation device is less than the target security value.

[0619] In S1304, the following cases are divided.

[0620] In the first case, the operation device supports one authentication manner.

[0621] In this case, if the authentication security value corresponding to the operation device is less than the target security value, S1305 is executed. If not, S1416 in the following FIG. 14 may be executed (this part will be described later, and will not be described here).

[0622] In the second case, the operation device supports multiple authentication modes.

[0623] In the case where the operation device supports multiple authentication modes, in the first possible implementation, if it is found that the maximum value of all authentication security values corresponding to the operation device is less than the target security value, it can be determined that the authentication security value corresponding to the operation device is less than the target security value, and S1305 is executed. If not, that is, at least one of the multiple authentication modes supported by the operation device can meet the authentication of the target operation, S1416 in the following FIG. 14 may be executed.

[0624] In the case where the operation device supports multiple authentication modes, in the second possible implementation, the server can calculate the multiple authentication security values corresponding to the operation device by comprehensively considering the multiple authentication modes supported by the operation device. If the result is less than the target security value, it can be determined that the authentication security value corresponding to the operation device is less than the target security value, and S1305 is executed. If not, S1416 in the following FIG. 14 may be executed. The calculation of the multiple authentication security values can refer to the description of S1310 in the following, and will not be described here.

[0625] In the case where the operation device supports multiple authentication modes, in the third possible implementation, if the multiple authentication modes supported by the operation device include a password authentication mode and a biometric authentication mode, in one possible implementation, the multiple authentication security values corresponding to the biometric authentication mode of the operation device can be calculated. If the result is less than the target security value, it can be determined that the authentication security value corresponding to the operation device is less than the target security value, and S1305 is executed. If not, S1416 in the following FIG. 14S1416. In this way, the user can be authenticated only by the biometric authentication manner, and the operation of requiring the user to input a password can be avoided, and the convenience of user authentication is improved. The calculation of the plurality of authentication security values can refer to the description of S1310 in the following content, and will not be described here. Further, in this case, in subsequent S1306, if the operation device is determined as one of the M1 authentication devices, the indication information indicating the biometric authentication manner of the operation device can be carried in the second authentication request sent to the operation device, so that the operation device can authenticate the user information only by the biometric authentication manner indicated in the second authentication request.

[0626] In a possible implementation manner, the server can also not perform the above S1303 to S1304, that is, after receiving the first authentication request of S1301, the server directly performs S1305.

[0627] Taking the first case as an example, in the scenario of the user requesting a small payment operation on the smart television, in S1304, the smart television only supports one authentication manner, that is, 2D face recognition, and the authentication security value of the smart television is 76, which is less than the target security value of 85, and S1305 is performed.

[0628] S1305, the server determines M1 authentication devices, M1 is a positive integer, and the M1 authentication devices can be all or part of the M authentication devices in the method embodiment shown in the method embodiment. FIG. 3

[0629] ​Optionally, each authentication device can send the authentication method supported by itself and the root key storage environment of itself to the server before S1305, so that the server establishes the correspondence between the authentication device, the authentication method and the authentication security value (such as the above table 12). In one possible implementation, each authentication device can send a first message to the server, each authentication device reports a first message, and the first authentication device carries indication information indicating the authentication method supported by the first authentication device in the first message reported by the first authentication device. The M1 authentication devices include the first authentication device, and it can also be understood that one of the M1 authentication devices is referred to as the first authentication device. For example, each authentication device can send the authentication method supported by itself to the server when initially accessing the network (for example, each authentication device sends the authentication method supported by itself by reporting a first message), and optionally, each authentication device can also report the root key storage environment of itself to the server (for example, the root key storage environment of the first device can also be carried by the first message reported by the first device), so that the server stores it. In another possible implementation, after S1302, before S1305, the device sends a query request to the first authentication device, the query request is used to query the authentication method supported by the first authentication device; the device receives the query response returned by the first authentication device, and the query response carries indication information indicating the authentication method supported by the first authentication device. Optionally, after receiving the first authentication request, the server queries the authentication method supported by each authentication device (for example, by a query request). Optionally, the root key storage environment of each authentication device can also be queried (for example, by sending a query request to each authentication device, in this example, the query request is also used to query the root key storage environment of the authentication device). For example, the authentication device (smart speaker) has voiceprint recognition capability, and has reported its capability to the server before S1305.

[0630] In S1305, in one possible implementation, the M1 authentication devices can be all authentication devices in a communication reachable state that can be searched by the current server. For example, there are K authentication devices registered in the server in advance, K is an integer not less than M1, and then the M1 authentication devices are part or all of the K authentication devices. There are many ways to select M1 authentication devices from K authentication devices, which will be described in detail in the subsequent content, and will not be described here.

[0631] In combination with the scenario that the user requests to perform a small payment operation on the smart TV, before S1305, the server has obtained the authentication manner and root key storage environment of the smart TV, and obtained the authentication manner and root key storage environment of the smart speaker. In S1305, the authentication devices currently searchable by the server in a communicable state are: the smart speaker and the smart TV (possibly other devices are in a state of being powered off, damaged, etc.). In this case, the server can determine the smart TV and the smart speaker as M1 authentication devices, and perform S1306. FIG. 13 The authentication device b1 is a smart speaker. The authentication device b2 is a smart TV.

[0632] In S1306, the server sends a second authentication request to each of the M1 authentication devices. The second authentication request is used to request the authentication device to authenticate the user information.

[0633] Correspondingly, each of the M1 authentication devices receives the second authentication request sent by the server.

[0634] For the second authentication request received by one authentication device, when the authentication device can support multiple authentication manners, in one possible implementation manner, the server can determine the authentication manner adopted by the authentication device, and carry indication information indicating the authentication manner in the second authentication request, so that the authentication device adopts the authentication manner indicated in the second authentication request to perform authentication. The server can determine the authentication manner adopted by the authentication device, which will be introduced in the subsequent content, and will not be described here.

[0635] In another possible implementation manner, the second authentication request does not carry the indication information indicating the authentication manner, and the authentication device decides by itself which authentication manner to adopt to perform authentication, or the authentication device adopts all the authentication manners supported by itself to perform authentication. The authentication device decides by itself which authentication manner to adopt is similar to the method that the server determines which authentication manner to adopt by the authentication device, and in this case, the authentication security value corresponding to the authentication manner of the authentication device needs to exist on the authentication device. Alternatively, the calculation rule of the authentication security value can also be stored, so that the authentication device can calculate the corresponding authentication security value according to the calculation rule of the authentication security value and the authentication manner and the root key storage environment of the authentication device. In the embodiment of the application, after the hardware and / or software of the authentication device are updated, the authentication security value or the calculation rule of the authentication security value stored by the authentication device can be updated.

[0636] In combination with the scenario that the user requests to perform a small payment operation on the smart TV, for example, the server sends a second authentication request to the smart speaker and the smart TV respectively, and the second authentication request does not carry the indication information indicating the authentication manner.

[0637] S1307, the authentication device receiving the second authentication request sent by the server, authenticating the user information, and generating a second authentication response.

[0638] In S1307, an authentication device needs to obtain the user's information first, and then authenticate the user information. Specifically, there are many ways for an authentication device to obtain user information, which can be collected by the authentication device itself, such as collecting the user's face information through the camera of the smart TV. Of course, it can also be collected by other devices and transmitted to the authentication device through the network, for example, the server can dispatch the camera in the room to collect the user's face information, and send the face information to the smart TV.

[0639] In combination with the scenario that the user requests to perform a small payment operation on the smart TV, as shown in FIG. 15B The smart TV receives the second authentication request sent by the server, and since the second authentication request does not carry the indication information for indicating the authentication mode, the smart TV decides to use which authentication mode by itself. Since the smart TV only supports one 2D face recognition authentication mode, the smart TV decides to use the 2D face recognition authentication mode to authenticate the user. When the smart TV uses the 2D face authentication mode to authenticate the user, it will display the prompt "Please look at the camera" on the display screen. When the user looks at the camera of the smart TV, the display screen of the smart TV will display the face information of the user collected by the camera. The smart TV can prestore the face information of the user for authentication, and the smart TV will compare the collected face information of the user with the stored face information of the user for authentication. If the comparison is successful, it is determined that the authentication is successful, otherwise, it is determined that the authentication fails. After completing the authentication, the smart TV generates a second authentication response, and indicates in the second authentication response whether the authentication is successful or fails.

[0640] In another aspect, the smart speaker receives the second authentication request sent by the server, and since the second authentication request does not carry the indication information for indicating the authentication mode, the smart speaker decides by itself which authentication mode to adopt. Since the smart speaker only supports one voiceprint recognition authentication mode, the smart speaker decides to adopt the voiceprint recognition authentication mode to authenticate the user. When the smart speaker adopts the voiceprint recognition mode to authenticate the user, the smart speaker will issue a sound "Please confirm whether to agree to pay? Please answer agree or disagree", and the user can answer "agree", and the smart speaker authenticates the collected voiceprint information "agree", on the one hand, to determine that the user answers "agree" rather than "disagree", and on the other hand, to determine whether the voiceprint information of the user matches the voiceprint information of the user previously stored in the smart speaker for authentication. If the smart speaker determines that the voiceprint information of the user matches the voiceprint information of the user previously stored for authentication, and performs semantic analysis on the voiceprint information input by the user to determine that the user inputs "agree", it is determined that the authentication is successful; otherwise, the authentication fails. After completing the authentication, the smart speaker generates a second authentication response, and indicates in the second authentication response whether the authentication is successful or fails.

[0641] S1308, for one of the M1 authentication devices, the authentication device returns a second authentication response to the server. The second authentication response can carry an identifier of the authentication device, an authentication mode adopted by the authentication device, and indication information indicating whether the authentication is successful. Optionally, when the authentication device only supports one authentication mode, the second authentication response can also not carry the indication information for indicating the authentication mode adopted by the authentication device. Optionally, when the second authentication request carries the authentication information indicating the authentication mode, the second authentication response returned by the authentication device can also not carry the indication information for indicating the authentication mode adopted by the authentication device.

[0642] It is possible that each of the M1 authentication devices returns one or more second authentication responses (for example, one authentication device adopts two authentication modes for authentication, and can return one second authentication response carrying the authentication results of the two authentication modes, or can also return two second authentication responses, one second authentication response carrying the authentication result corresponding to one authentication mode), and it is also possible that some of the M1 authentication devices return the second authentication response, such as some authentication devices not returning the second authentication response due to link failure or other reasons.

[0643] For the second authentication response returned by the at least one authentication device, in an example implementation, the second authentication response is sent by the at least one authentication device to the apparatus after the authentication device completes the authentication of the user information. When the authentication device completes the authentication of the user information, the second authentication response returned by the authentication device indicates the authentication result, which can be either an authentication success or an authentication failure.

[0644] In another example implementation, the second authentication response is sent by the at least one authentication device to the apparatus after the authentication device fails to complete the authentication of the user information within a predetermined time. In this case, the second authentication response returned by the authentication device indicates the authentication result as an authentication failure. For example, the predetermined time can be a time period starting from the receipt of the second authentication request, such as 10 seconds or 2 minutes from the receipt of the second authentication request. When the authentication device fails to complete the authentication of the user information within 10 seconds or 2 minutes from the receipt of the second authentication request, it is determined that the authentication result is an authentication failure, and the second authentication response is sent to the apparatus, which is used to indicate the authentication result as an authentication failure.

[0645] In a possible scenario, the authentication device receives the second authentication request, but the user fails to complete the identity authentication in the authentication device, or the authentication device fails to complete the authentication of the user information within the predetermined time. In this case, the authentication device does not return the second authentication response or returns the second authentication response indicating the authentication result as an authentication failure.

[0646] In the scenario of the user requesting a small payment operation on the smart television, in the above S1307, taking the example that both the smart television and the smart speaker have completed the authentication successfully, the second authentication response returned by the smart speaker can include the indication information indicating the authentication success and the identifier of the smart speaker. Optionally, the second authentication response returned by the smart speaker can further include the indication information indicating that the smart speaker adopts the voiceprint recognition as the authentication manner. The second authentication response returned by the smart television can include the indication information indicating the authentication success and the identifier of the smart television. Optionally, the second authentication response returned by the smart television can further include the indication information indicating that the smart television adopts the 2D face recognition as the authentication manner.

[0647] For example, if the authentication manner adopted by each authentication device has been specified in the second authentication request, the second authentication response can not carry the indication information indicating the authentication manner adopted by the authentication device. That is, the second authentication response returned by the smart speaker includes the indication information indicating the authentication success and the identifier of the smart speaker. The second authentication response returned by the smart television includes the indication information indicating the authentication success and the identifier of the smart television.

[0648] In a possible implementation, in S1308, for an authentication device, the second authentication response returned by the authentication device can carry an authentication security value corresponding to the authentication device. In this case, the correspondence between the authentication mode and the authentication security value of the authentication device, or the calculation rule of the authentication mode and the authentication security value, needs to be stored on the authentication device, and the server does not need to perform S1309 and directly performs step 210. For example, the second authentication response returned by the smart speaker is: authentication success, identification of the smart speaker, and the authentication security value is 20 points; the second authentication response returned by the smart television is: authentication success, identification of the smart television, and the authentication security value is 76 points. In the embodiment of the application, the format of the message in the second authentication response is not limited.

[0649] In the case where the authentication security value is not carried in the second authentication response, the server performs S1309.

[0650] In S1309, the server determines the authentication security values corresponding to the M1 authentication devices according to the preset correspondence between the authentication devices, the authentication modes and the authentication security values, and the second authentication responses.

[0651] For one second authentication response returned by one authentication device, if the second authentication response indicates authentication success, one authentication security value corresponding to the authentication device is determined according to the preset correspondence between the authentication devices, the authentication modes and the authentication security values. If the second authentication response indicates authentication failure, the authentication security value corresponding to the authentication device is determined to be 0 points. If one authentication device does not return a second authentication response, the authentication security value corresponding to the authentication device is 0 points.

[0652] In combination with the scenario that the user requests to perform a small payment operation on the smart television, in S1309, the server learns from the second authentication response returned by the smart speaker that the voiceprint authentication of the smart speaker is successful, and can query from Table 12 that the authentication security value corresponding to the smart speaker is 20 points. The server learns from the second authentication response returned by the smart television that the 2D face recognition of the smart speaker is successful, and can query from Table 12 that the authentication security value corresponding to the smart television is 76 points.

[0653] In a possible mode, if the second authentication response returned by any of the M1 devices in S1308 already carries the authentication security value corresponding to the authentication mode adopted by the authentication device, the server can obtain the authentication security values of the M1 authentication devices, perform step 210, and does not need to query according to the preset correspondence between the authentication devices, the authentication modes and the authentication security values.

[0654] In S1310, the server calculates the total authentication security value according to the authentication security values corresponding to the M1 authentication devices.

[0655] In S1310, the server can calculate the total authentication security value according to a second calculation rule. There are various methods to calculate the total authentication security value, which are illustrated below.

[0656] Example one, such as two authentication security values, the total authentication security value can be calculated according to formula (1):

[0657]

[0658] In formula (1), x is one authentication security value, y is another authentication security value, and z is the total authentication security value. In this example, formula (1) can also be said to be an example of a second calculation rule.

[0659] In combination with the scenario that the user requests a small payment operation on the smart TV, in S1310, the two authentication security values are 76 points and 20 points, respectively, and the total authentication security value can be calculated by substituting formula (1) as:

[0660]

[0661] Other methods for calculating the total authentication security value are also provided in the embodiments of the present application, for example:

[0662] Example two, if there are more than two authentication security values, one possible calculation scheme, or an example of a possible second calculation rule, is to calculate the total authentication security value by using the above formula (1) in a loop, for example, there are three authentication security values, two of which are calculated according to formula (1) to obtain the result, and further, the result and the third authentication security value are substituted into the above formula (1) for calculation, and the value obtained is the total authentication security value.

[0663] For example, there are three authentication security values, which are 76 points, 20 points and 20 points, 76 points and 20 points are taken as the values of parameters x and y in the above formula (1), and the result is 86, and 86 and 20 are substituted into formula (1) again, and the value obtained is the total authentication security value:

[0664]

[0665] The above content respectively illustrates the scheme for calculating the total authentication security value in the case of two authentication security values and three authentication security values, and if there are four or more authentication security values, the above case of three authentication security values can be referred to, and no further description is given.

[0666] Example three, such as multiple authentication security values, the total authentication security value can be calculated according to formula (2):

[0667]

[0668] In formula (2), i is a variable, i takes values in turn, Fi is the i th authentication security value, j is the total number of authentication security values, a1, a2, n, c and M1 are constants, a1 and a2 can be the same or different, and the specific values can be taken according to actual conditions, * is multiplication, and z is the total authentication security value. In this example, it can also be said that formula (2) is an example of a second calculation rule.

[0669] In addition to the schemes provided in the above examples one and two, there are many other schemes for determining the total authentication security value, such as adding multiple authentication security values and then multiplying by a preset value. For example, two authentication security values are 76 points and 20 points, and the total authentication security value is: (76+20)*0.95=91.2.

[0670] The above examples one to five show several ways of calculating the total authentication security value from multiple authentication security values, which are only examples and do not have a limiting meaning.

[0671] In the scenario of the user requesting a small payment operation on the smart TV, the server calculates the total authentication security value to be 86 points using formula (1) as an example.

[0672] S1311, the server determines whether the total authentication security value is less than the target security value required for the target operation.

[0673] If the total authentication security value is not less than the target security value required for the target operation, S1312 is performed; if the total authentication security value is less than the target security value required for the target operation, S1314 is performed.

[0674] In the scenario of the user requesting a small payment operation on the smart TV, the total authentication security value calculated by formula (1) is 86 points, which is greater than the target security value of 85 points in S1311, so S1312 is performed.

[0675] S1312, the server returns a first authentication success response to the operation device.

[0676] Correspondingly, the operation device receives the first authentication success response, and the first authentication success response carries indication information indicating authentication success.

[0677] In the scenario of the user requesting a small payment operation on the smart TV, the server returns a first authentication success response to the smart TV in S1312.

[0678] S1313, the operation device performs the target operation when receiving the first authentication success response.

[0679] In combination with the scenario that the user requests to perform a small payment operation on the smart television, in S1313, the smart television performs the "10 yuan payment operation" requested by the user upon receiving the first authentication success response. As shown in FIG. 15C

[0680] S1314, the server returns a first authentication failure response to the operation device.

[0681] Correspondingly, the operation device receives the first authentication failure response, and the first authentication failure response carries indication information indicating authentication failure.

[0682] S1315, the operation device rejects to perform the target operation upon receiving the first authentication failure response.

[0683] As can be seen from the scenario that the user requests to perform a small payment operation on the smart television, if only the smart television is used to perform 2D face recognition on the user, the corresponding authentication security value is only 76, which is lower than the required 85 for the target operation, that is, the authentication capability of the smart television is insufficient to meet the small payment operation, and the security is poor. And the user may refuse to use the smart television for payment operation due to security considerations, resulting in payment failure. However, in the scheme provided by the present application, the authentication of the user information can be performed by one or more authentication devices through one or more authentication manners, so that the authentication capability of the operation device itself can be reduced, thereby reducing the requirement for a single terminal device, and thus the manufacturing cost of the operation device can be reduced. On the other hand, when the device provided by the present application is a router, and the router and the operation device and the authentication device belong to the same local area network, the interaction of signaling between the router and the operation device and the router and the authentication device can be transmitted through the local area network, and the transmission speed can be greatly improved, thereby speeding up the data processing process. FIG. 13

[0684] Exemplarily shows FIG. 14 one possible implementation manner in which the authentication security value corresponding to the operation device is determined to be not less than the target security value in step 1304 in the method 1300. FIG. 13 It should be noted that

[0685] FIG. 14 ​​The authentication scheme shown is introduced by taking the device provided by the embodiment of the application as a server, and the execution subject "server" in the following FIG. 14 may be replaced by the "device" provided by the embodiment of the application. When the device provided by the embodiment of the application is a router, the device performs a related scheme similar to the scheme performed when the device is a server, and the execution subject "server" involved in FIG. 14 may be replaced by "router", which will not be described here.

[0686] As shown in FIG. 14 , the authentication method includes the following steps:

[0687] S1400 to S1404 are the same as S1300 to S1304 described above.

[0688] When it is determined in the above step 1404 that the authentication security value corresponding to the operation device is not less than the target security value, step 1416 is performed.

[0689] In step 1416, the server sends a third authentication request to the operation device.

[0690] Correspondingly, the operation device receives the third authentication request sent by the server.

[0691] In the first case, the operation device supports one authentication mode.

[0692] In this case, the third authentication request is used to request the operation device to authenticate the user, and can carry indication information indicating the authentication mode adopted, or can not carry indication information indicating the authentication mode.

[0693] In the second case, the operation device supports multiple authentication modes.

[0694] In the case where the operation device supports multiple authentication modes, in one possible implementation manner, the third authentication request can carry indication information indicating all authentication modes supported by the operation device, or can not carry indication information indicating the authentication mode. The operation device adopts all authentication modes supported by itself for authentication.

[0695] In the case where the operation device supports multiple authentication modes, in another possible implementation manner, the server determines that the operation device adopts part of the authentication modes supported by itself, and the third authentication request carries indication information indicating the authentication mode adopted by the operation device.

[0696] The server determines which authentication mode or modes the operation device adopts, and there are the following possible cases:

[0697] Option 1: If the authentication security value corresponding to an authentication method supported by the operating device is greater than the target security value, then that authentication method shall be determined as the authentication method required by the operating device.

[0698] Option 2: The server determines the multiple authentication methods to be used by the operating device, and these multiple authentication methods meet the condition that "the total authentication security value corresponding to the multiple authentication methods is greater than the target security value". The total authentication security value corresponding to the multiple authentication methods can be calculated using the above formula (2).

[0699] Optionally, in Scheme 2, if the operating device supports multiple authentication methods including both password authentication and multiple biometric authentication methods, then multiple biometric authentication methods can be used for authentication. This can avoid the user entering a password, simplify the user's operation, and improve user convenience.

[0700] In cases where the operating device supports multiple authentication methods, the third authentication request sent by the server may not carry indication information for indicating the authentication method. The operating device can determine the authentication method itself, and the determination process can be similar to the above-mentioned scheme where the server determines the authentication method used by the device. In this case, the authentication security value corresponding to the authentication method of the operating device needs to be stored on the operating device, or the rules for calculating the authentication security value need to be stored on the operating device.

[0701] Step 1417: The device is operated to authenticate the user information and determine whether the authentication is successful; if it fails, proceed to step 1418; if it succeeds, proceed to step 1419.

[0702] Step 1418: The operating device refuses to perform the target operation.

[0703] Step 1419: Operate the equipment to perform the target operation.

[0704] pass FIG. 14 As can be seen from the scheme shown, if the operating device has authentication capabilities and these capabilities can meet the requirements of the target operation, then the operating device can perform authentication. This simplifies the authentication process and improves the convenience of operation.

[0705] As another possible embodiment, the apparatus provided in this application embodiment can also be an authentication device. FIG. 16 An exemplary illustration shows a schematic diagram of an authentication method flow for an authentication device provided in an embodiment of this application, such as... FIG. 16 As shown in the embodiment of this application, the device provided is on authentication device b1, and the method includes:

[0706] S1600 to S1605 can be referred to the above. FIG. 13The part from step 1300 to step 1305 in the foregoing method 1300 can be performed by the apparatus, and the subject performing the part from step 1300 to step 1305 is changed from "the server" to "the authentication device b1" or "the apparatus", and details are not described herein again.

[0707] It is to be noted that, in S1608, since the apparatus provided in the embodiment of the present application is the authentication device b1, the apparatus does not need to send the second authentication request to the authentication device b1, the authentication device b1 authenticates the user information, and generates the second authentication response. The authentication device b1 does not need to return the second authentication response to the apparatus. Based on this, in S1609, the apparatus receives the second authentication response returned by the authentication device other than the authentication device b1.

[0708] In S1607, the authentication device (the authentication device b2) receiving the second authentication request sent by the authentication device b1 authenticates the user information, and generates the second authentication response.

[0709] In S1608, the authentication device b1 authenticates the user information, and generates the second authentication response.

[0710] It is to be noted that, in S1608, since the apparatus provided in the embodiment of the present application is the authentication device b1, the apparatus does not need to send the second authentication request to the authentication device b1, the authentication device b1 authenticates the user information, and generates the second authentication response. The authentication device b1 does not need to return the second authentication response to the apparatus. Based on this, in S1609, the apparatus receives the second authentication response returned by the authentication device other than the authentication device b1.

[0711] S1610 to S1616 can refer to the related content of the foregoing FIG. 13 The part from step 1309 to step 1315 in the foregoing method 1300 can be performed by the apparatus, and the subject performing the part from step 1309 to step 1315 is changed from "the server" to "the authentication device b1" or "the apparatus", and details are not described herein again.

[0712] It is to be noted that, FIG. 16 Only the flowchart of the authentication method when the apparatus provided in the embodiment of the present application is the authentication device b1 is shown, and the possible implementation manners of each step in the chart can refer to the related content of the foregoing FIG. 13 , and details are not described herein again.

[0713] The related steps can refer to the related content of the foregoing FIG. 13 , and details are not described herein again. It can be seen from FIG. 16 that, when the apparatus provided in the embodiment of the present application is the authentication device, the authentication device authenticates the user information, and generates the second authentication response, compared with the foregoing FIG. 13The difference between the scheme shown is that when the device determines the authentication device as one of the M1 authentication devices, then no second authentication request needs to be sent to the authentication device through step 1606, and after the authentication device authenticates the user information, no second authentication response needs to be returned to the device, but the authentication result of the authentication device is obtained by the authentication device. In this way, since the device provided in the embodiment of the application is an authentication device, the signaling interaction between the authentication device and the device can be reduced, thereby saving resources and speeding up the scheme execution process.

[0714] As a possible embodiment, the device provided in the embodiment of the application can be a server or a router, and the device can also be an operation device, FIG. 17 An authentication method flow diagram of the device provided in the embodiment of the application as an operation device is exemplarily shown as follows: FIG. 17 As shown, when the device provided in the embodiment of the application is an operation device, and the operation device has authentication capability. The method comprises:

[0715] S1720 can refer to the part of step 1300 in the foregoing FIG. 13 , and the execution subject "server" needs to be replaced with "operation device" or "the device", and other contents will not be repeated here.

[0716] Since the device provided in the embodiment of the application is an operation device, the operation device does not need to send a first authentication request to the server. After S1720, S1721 to S1723 executed by the device can refer to the part of steps 1302 to 1304 in the foregoing FIG. 13 , the execution subject "server" is replaced with "operation device" or "the device", and other contents will not be repeated here.

[0717] When it is determined in S1723 that the authentication security value corresponding to the operation device is not less than the target security value, since the device provided in the embodiment of the application is an operation device, the device does not need to return a third authentication request to the operation device, but the device directly executes S1732. Wherein, S1732 can refer to the part of step 1317 in the foregoing FIG. 13 , the execution subject "server" is replaced with "operation device" or "the device", and other contents will not be repeated here.

[0718] S1724 can refer to the part of step 1305 in the foregoing FIG. 13 , and will not be repeated here.

[0719] Since the device provided in the embodiment of the application is an operation device, and in FIG. 17In this case, the operation device also belongs to one of the M1 authentication devices. Therefore, the second authentication request does not need to be sent to the operation device. Based on this, in S1725, the apparatus sends the second authentication request to each of the M1 authentication devices except the operation device. The second authentication request is used to request the authentication device to authenticate the user information.

[0720] As shown in FIG. 17 , the operation device sends the second authentication request to the authentication device b1.

[0721] In S1726, the authentication device (the authentication device b1) receiving the second authentication request sent by the operation device authenticates the user information and generates a second authentication response.

[0722] In S1727, when the operation device is one of the M1 authentication devices, the operation device authenticates the user information and generates a second authentication response.

[0723] It should be noted that in S1727, since the apparatus provided by the embodiment of the present application is the operation device, the apparatus does not need to send the second authentication request to the operation device again, the operation device authenticates the user information and generates a second authentication response. And the operation device does not need to perform the step of returning the second authentication response to the apparatus. In S1728, the operation device receives the second authentication response returned by the authentication device other than the operation device among the M1 authentication devices.

[0724] S1729 to S1731 can refer to the part of the foregoing FIG. 13 steps 1309 to 1311, the subject "server" is replaced by "operation device" or "the apparatus", and other contents are not described here.

[0725] Since the apparatus provided by the embodiment of the present application is the operation device, after judging whether the total authentication security value is less than the target security value in S1731, the step of returning the first authentication response (the first authentication response refers to the first authentication success response or the second authentication failure response) to the operation device does not need to be performed. Instead, when the apparatus judges that the total authentication security value is not less than the target security value required for the target operation in S1731, S1734 is performed; if the total authentication security value is less than the target security value required for the target operation, S1733 is performed.

[0726] In S1733, the operation device refuses to perform the target operation.

[0727] In S1734, the operation device performs the target operation.

[0728] It should be noted that FIG. 17Only the flowchart of the authentication method when the device provided by the embodiments of the present application is the operation device is exemplified, and the possible implementation manners of each step in the figure can be referred to the foregoing related content of the server, the execution subject is replaced by the operation device or the device, and other content will not be described here again. FIG. 13

[0729] As can be seen from the above flow, when the device provided by the embodiments of the present application is the operation device, the difference from the scheme shown in the foregoing FIG. 13 is that the operation device does not need to send the first authentication request to the server, but the operation device can determine the target security value required for performing the target operation after step 1700. On the other hand, when the device determines the M1 authentication devices, if the operation device is confirmed as one of the M1 authentication devices, it also does not need to send the second authentication request to the operation device, and after the operation device authenticates the user information, it also does not need to return the second authentication response to the device, but the operation device obtains the authentication result of the operation device. Thirdly, after the device confirms the relationship between the total authentication security value and the target security value, it also does not need to feed back to the operation device whether the authentication is successful, but the operation device determines whether the authentication is successful according to the total authentication security value and the target security value, and then decides whether to perform the target operation. In this way, since the device provided by the embodiments of the present application is the operation device, the signaling interaction between the operation device and the device can be reduced, thereby saving resources and speeding up the scheme execution flow.

[0730] In the above step 205, the device provided by the embodiments of the present application can first determine the M1 authentication devices. The specific manner of how to determine the M1 authentication devices will be introduced below by taking the device provided by the embodiments of the present application as the server as an example, and the manner of determining the M1 authentication devices when the device is the router or the terminal device is similar to the following content, the execution subject "server" is replaced by "the device", and other content will not be described here again.

[0731] There are the following several manners for the device to determine the M1 authentication devices.

[0732] Manner one, the second authentication request is sent to all the authentication devices registered on the server in the above step 206. For example, K authentication devices are registered on the server in advance, and K is a positive integer not less than M1. In the manner one, the M1 authentication devices are the K authentication devices. Some of the K authentication devices can be in a non-communication reachable state, such as a smart television not being started. The authentication devices not online in the K authentication devices can not respond to the second authentication request.

[0733] ​In the second mode, the server sends a first message to K authentication devices or to K authentication devices in an online state (e.g., searchable via a network search) to query whether the authentication devices are in a communication reachable state. The first message can carry an identifier of the server.

[0734] A first message response is received, and an authentication device corresponding to the first message response is determined as one of the M1 authentication devices. The first message response can carry an identifier of the authentication device sending the first response. That is, in the second mode, M1 authentication devices in a communication reachable state are queried via the first message, and then a second authentication request is sent to the M1 authentication devices.

[0735] Optionally, in addition to the second mode, the state of M1 authentication devices in a communication reachable state among K authentication devices can be queried in various manners. For example, a terminal device provided in an embodiment of the present application can query authentication devices in a same local area network as the terminal device, and the queried authentication devices are the M1 authentication devices mentioned above. For another example, a terminal device provided in an embodiment of the present application can query authentication devices in a same local area network as the terminal device, and send a first message to the queried authentication devices. An authentication device receiving a first message response is determined as one of the M1 authentication devices mentioned above.

[0736] In the third mode, K authentication devices can be provided with priorities. For example, the priorities can be set according to user preferences, or the priorities can be sorted according to authentication security values (e.g., the higher the highest authentication security value corresponding to an authentication device, the higher the priority of the authentication device), and the like. The server sends a first message to K authentication devices in sequence according to the priorities of the K authentication devices.

[0737] A first message response is received, and an authentication device corresponding to the first message response is determined as one of the M1 authentication devices, until M1...

Claims

1. An authentication method, characterized in that, The authentication method is performed by a first electronic device, and the method includes: Receive an authentication request, the authentication request being used to request authentication of the first service; Determine the risk and security level corresponding to the first business; Determine the available authentication factors corresponding to M electronic devices and the available acquisition capabilities associated with the available authentication factors, where M is a positive integer; Based on the risk and security level, the available authentication factors, and the available data collection capabilities associated with the available authentication factors, determine the authentication method that meets the risk and security level; According to the authentication method, M electronic devices are scheduled to authenticate the first service; Obtain the authentication results of the M electronic devices; The final authentication result is determined based on the authentication results of the M electronic devices.

2. The method according to claim 1, characterized in that, Also includes: When the authentication request includes biometrics, the biometrics are identified to determine the user corresponding to the biometrics; It is determined that the user has the permission to execute the first service.

3. The method according to claim 1 or 2, characterized in that, The available authentication factors are associated with the user.

4. An electronic device, characterized in that, The electronic device includes a processor and a memory; The memory stores program instructions; The processor is used to execute the program instructions stored in the memory, causing the electronic device to perform: Receive an authentication request, the authentication request being used to request authentication of the first service; Determine the risk and security level corresponding to the first business; Determine the available authentication factors corresponding to M electronic devices and the available acquisition capabilities associated with the available authentication factors, where M is a positive integer; Based on the risk and security level, the available authentication factors, and the available data collection capabilities associated with the available authentication factors, determine the authentication method that meets the risk and security level; Based on the risk and security level, determine the authentication method that meets the risk and security level; According to the authentication method, M electronic devices are scheduled to authenticate the first service; Obtain the authentication results of the M electronic devices; The final authentication result is determined based on the authentication results of the M electronic devices.

5. The electronic device according to claim 4, characterized in that, The processor is used to execute the program instructions stored in the memory, causing the electronic device to also perform: When the authentication request includes biometrics, the biometrics are identified to determine the user corresponding to the biometrics; It is determined that the user has the permission to execute the first service.

6. The electronic device according to claim 4 or 5, characterized in that, The available authentication factors are associated with the user.

7. A data association method, characterized in that, Applied to a first electronic device, the method includes: Receive the user's first operation, which is used to request the input of a first feature template; In response to the first operation, the user's identity is authenticated using an existing second feature template, wherein the second feature template is associated with the user's user identifier; Once authentication is successful, the user-entered first feature template will be received. Establish the association between the first feature template and the user identifier.

8. The method according to claim 7, characterized in that, Also includes: The system receives a second user action, which triggers the association of the entered third feature template with the user identifier. In response to the second operation, an association is established between the third feature template and the user identifier.

9. The method according to claim 8, characterized in that, Before receiving the user's second action, it also includes: Receive feature information input by the user; The feature information input by the user is matched with at least one feature template in the first electronic device to determine the third feature template that matches the feature input by the user.

10. The method according to claim 8 or 9, characterized in that, Also includes: Obtain the usage constraints corresponding to the third feature template; Establish the association between the third feature template and the usage constraints.

11. An electronic device, characterized in that, The electronic device includes a processor and a memory; The memory stores program instructions; The processor is used to execute the program instructions stored in the memory, causing the electronic device to perform: Receive the user's first operation, which is used to request the input of a first feature template; In response to the first operation, the user's identity is authenticated using an existing second feature template, wherein the second feature template is associated with the user's user identifier; Once authentication is successful, the user-entered first feature template will be received. Establish the association between the first feature template and the user identifier.

12. The electronic device according to claim 11, characterized in that, The processor is used to execute the program instructions stored in the memory, causing the electronic device to also perform: The system receives a second user action, which triggers the association of the entered third feature template with the user identifier. In response to the second operation, an association is established between the third feature template and the user identifier.

13. The electronic device according to claim 12, characterized in that, Before receiving the user's second operation, the processor executes the program instructions stored in the memory, causing the electronic device to further perform: Receive feature information input by the user; The feature information input by the user is matched with at least one feature template in the electronic device to determine the third feature template that matches the feature input by the user.

14. The electronic device according to claim 12 or 13, characterized in that, The processor is used to execute the program instructions stored in the memory, causing the electronic device to also perform: Obtain the usage constraints corresponding to the third feature template; Establish the association between the third feature template and the usage constraints.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes program instructions that, when executed on an electronic device, cause the electronic device to perform the method as described in any one of claims 1-3 or 7-10.

Citation Information

Patent Citations

  • Insurance data processing method, device and equipment and computer storage medium

    CN109670968A

  • Method and device for providing service to plurality of terminals in network- based environment

    WO2013100549A1