A password resetting method, device and electronic equipment

By establishing a trust relationship between the first and second electronic devices and utilizing the PAKE protocol and password reset credentials, the problem of data loss caused by users forgetting their lock screen password is solved, achieving a secure lock screen password reset that does not affect the user experience.

CN114692105BActive Publication Date: 2026-01-23HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011628404.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-31
Publication Date
2026-01-23
Estimated Expiration
2040-12-31

AI Technical Summary

Technical Problem

When users forget their electronic device's lock screen password and become unable to use the device, existing technologies can lead to data loss when resetting the password by restoring factory settings, which affects user experience and is not secure enough.

Method used

By establishing a trust relationship between the first electronic device and the second electronic device, and using end-to-end authentication based on the PAKE protocol, the lock screen password of the first electronic device is reset using the authentication content of the second electronic device, including generating and verifying password reset credentials, thus ensuring the security of the authentication process and the user experience.

Benefits of technology

It effectively avoids data loss, improves device security and user experience, enhances the security of the password reset process, and reduces the risk of non-owner users resetting the lock screen password.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114692105B_ABST
    Figure CN114692105B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a password resetting method, a user inputs first authentication content through a prompt of a first electronic device, and in a case where the first authentication content of the first electronic device matches second authentication content of an associated second electronic device, the first electronic device can allow and prompt the user to reset a lock screen password. Since the second electronic device is a device having an association relationship with the first electronic device, when the user forgets the lock screen password, the lock screen password can be reset by authenticating the second electronic device, which not only effectively avoids the problem of loss of user data due to the need to reset the lock screen password similar to factory resetting, but also enhances the security of the device. In addition, the user authenticates the second electronic device by inputting authentication content on the first electronic device, which facilitates the user currently holding the first electronic device to operate, and can improve the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security, and more specifically, to a method, apparatus, and electronic device for resetting a password. Background Technology

[0002] Electronic devices can be secured by setting a lock screen password. Once a lock screen password is set, users will need to enter the password to unlock the device when they turn on or wake the screen again.

[0003] In some scenarios, users frequently forget their lock screen passwords, rendering their electronic devices unusable after multiple failed attempts. To restore functionality, most current technologies employ a process similar to a factory reset, deleting all data stored on the device except for pre-installed applications, thus restoring it to its original system state. This allows users to reset their lock screen password and use the device normally. However, this method results in data loss, severely impacting the user experience.

[0004] Therefore, there is a need for a technology that can reset passwords, which can not only protect electronic devices but also reduce data loss. Summary of the Invention

[0005] This application provides a method for resetting a password. By associating a first electronic device with a second electronic device and establishing a trust relationship, when a user forgets the lock screen password of the first electronic device, the lock screen password of the first electronic device can be reset by authenticating the second electronic device. This not only effectively avoids the problem of user data loss caused by the need for a factory reset to reset the lock screen password, but also enhances the security of the device.

[0006] Firstly, a method for resetting a password is provided, characterized by comprising:

[0007] The first electronic device responds to the user's first action and prompts the user to enter the first authentication information;

[0008] The first electronic device detects that the user inputs the first authentication content;

[0009] If the first authentication content matches the second authentication content on the associated second electronic device, the first electronic device prompts the user to reset the lock screen password of the first electronic device.

[0010] The method for password resetting provided by the embodiments of the present application can reset the lock screen password by authenticating the second electronic device when the user forgets the lock screen password, because the second electronic device is a device having an association relationship with the first electronic device. Not only can the method effectively avoid the problem of loss of user data caused by the need to reset the lock screen password similar to factory resetting, but also enhances the security of the device. In addition, the second electronic device is authenticated by matching the authentication content on the first electronic device with the authentication content on the second electronic device. This two-end authentication method used on the two devices can improve the security of the authentication process. In addition, the user authenticates the second electronic device by inputting the authentication content on the first electronic device, which is convenient for the user currently holding the first electronic device to operate, and can improve the user experience.

[0011] In combination with the first aspect, in some implementations of the first aspect, the first electronic device and the second electronic device can perform device authentication based on a password authenticated key exchange (PAKE) protocol according to the respective authentication content obtained. That is, the first electronic device performs device authentication based on the PAKE protocol based on the first authentication content, and the second electronic device performs device authentication based on the PAKE protocol based on the second authentication content. If the results obtained by the two devices match, the authentication is successful.

[0012] The device authentication between devices based on the PAKE protocol of the embodiments of the present application means that the authentication content is not transmitted between the devices, each device uses the same numerical algorithm for the authentication content, and if the calculation results obtained by each device match, it is considered that the authentication content of each device matches, and the authentication of the device is successful.

[0013] This device authentication method can effectively improve the security of the authentication process because the authentication content is not transmitted.

[0014] In combination with the first aspect, in some implementations of the first aspect, the first electronic device prompts the user to reset the lock screen password of the first electronic device in the case that the first authentication content matches the second authentication content of the associated second electronic device, and the method comprises the following steps.

[0015] In the case that the first authentication content matches the second authentication content, the first electronic device receives a first password resetting credential sent by the second electronic device, and the first password resetting credential is used to authorize the user to reset the lock screen password of the first electronic device.

[0016] In the case that the first password resetting credential is authenticated, the first electronic device prompts the user to reset the lock screen password of the first electronic device.

[0017] The method for password resetting provided in the embodiments of the present application is that, after the authentication of the second electronic device is completed, the first electronic device further verifies the first password resetting credential sent by the second electronic device, and only after the first password resetting credential is verified, the lock screen password is reset, which is equivalent to providing further security guarantee in the process of resetting the password, and further improves the security of the process of resetting the password. For example, the situation that the lock screen password of the first electronic device is modified when the authentication of the second electronic device is passed in the process of communication between the first electronic device and the imitated second electronic device can be avoided.

[0018] With reference to the first aspect, in some implementations of the first aspect, the reminding the user to reset the lock screen password of the first electronic device in the case that the first password resetting credential is verified includes:

[0019] In the case that the first password resetting credential and the second password resetting credential match, the first electronic device reminds the user to reset the lock screen password of the first electronic device, and the second password resetting credential is generated by the first electronic device.

[0020] The first password resetting credential and the second password resetting credential are both generated based on the same password resetting key.

[0021] With reference to the first aspect, in some implementations of the first aspect, the first authentication content is the lock screen password of the second electronic device, and the second authentication content is the lock screen password of the second electronic device stored on the second electronic device.

[0022] The method for password resetting provided in the embodiments of the present application is that, since the first electronic device and the second electronic device are associated, the owner of the first electronic device knows the lock screen password of the second electronic device, and other users who are not the owner do not necessarily know the lock screen password of the second electronic device, therefore, by taking the lock screen password of the associated second electronic device as the authentication content of the authentication device, the risk that other users who are not the owner reset the lock screen password after obtaining the first electronic device can be reduced with high probability.

[0023] With reference to the first aspect, in some implementations of the first aspect, the first authentication content is an authentication code, and the second authentication content is an authentication code generated on the second electronic device.

[0024] The method for password resetting provided in the embodiments of the present application is that, by inputting the authentication code generated on the second electronic device on the first electronic device to perform device authentication, since the authentication code is randomly generated and the authentication codes generated at different times are different, the security of the device authentication process can be ensured as much as possible, and the user experience is improved.

[0025] With reference to the first aspect, in some implementations of the first aspect, in response to the first authentication content and the second authentication content associated with the second electronic device matching, the first electronic device prompts a user to reset a lock screen password of the first electronic device, including:

[0026] in response to the first duration being less than or equal to a preset duration and the first authentication content and the second authentication content matching, the first electronic device prompting the user to reset the lock screen password of the first electronic device; wherein,

[0027] the first duration is a duration between an unlocking time of the second electronic device and a time when the first electronic device detects the user inputting the first authentication content; or,

[0028] the first duration is a duration between the unlocking time of the second electronic device and a time when the second electronic device generates the second authentication content.

[0029] Generally, if the user who gets the second electronic device is the owner of the second electronic device, the second electronic device can be unlocked in a short time, so that the second electronic device can generate an authentication code in a short time, and the user can input the authentication code on the first electronic device in a short time. The embodiments of the present application set a preset duration. In the case that the first duration related to the unlocking time of the second electronic device is less than or equal to the preset duration and the authentication code detected by the first electronic device and the authentication code generated by the second electronic device match, it is considered that the second electronic device authentication is passed. Otherwise, in the case that the first duration is greater than the first preset duration, it is considered that the second electronic device authentication fails. The first duration is a duration between the unlocking time of the second electronic device and a time when the first electronic device detects the user inputting the first authentication content, or the first duration is a duration between the unlocking time of the second electronic device and a time when the second electronic device generates the second authentication content. In this way, the security of the authentication process of the second electronic device can be improved, and the problem of poor security caused by the user who is not the owner of the second electronic device taking the second electronic device to authenticate the second electronic device can be avoided.

[0030] With reference to the first aspect, in some implementations of the first aspect, in response to the first authentication content and the second authentication content associated with the second electronic device matching, the first electronic device prompts a user to reset a lock screen password of the first electronic device, including:

[0031] the first electronic device displays a first device list in response to the first operation of the user, the first device list including the second electronic device;

[0032] the first electronic device prompts the user to input the first authentication content in response to detecting the user selecting the second electronic device.

[0033] The method for password resetting provided in the embodiments of the present application can allow the user to select whether to authenticate the second electronic device by himself or herself by displaying the first device list to the user, thereby improving the user experience.

[0034] With reference to the first aspect, in some implementations of the first aspect, the first electronic device, in response to the first operation of the user, prompts the user to input the first authentication content, including:

[0035] The first electronic device, in response to the first operation of the user, prompts the user to perform the biometric authentication.

[0036] The first electronic device, after detecting that the biometric authentication of the user is passed, prompts the user to input the first authentication content.

[0037] The method for password resetting provided in the embodiments of the present application can improve the user experience and the security by authenticating the device to reset the lock screen password only after the biometric authentication of the user is passed, thereby avoiding the risk that the other user of the owner of the first electronic device resets the lock screen password after obtaining the first electronic device.

[0038] With reference to the first aspect, in some implementations of the first aspect, before the first electronic device, in response to the first operation of the user, prompts the user to input the first authentication content, the method further includes:

[0039] The first electronic device sends a device association request to the second electronic device.

[0040] After the authentication of the second electronic device is passed, an association relationship is established between the first electronic device and the second electronic device, and the first electronic device sends the first password resetting credential to the second electronic device.

[0041] With reference to the first aspect, in some implementations of the first aspect, before the first electronic device sends the device association request to the second electronic device, the method further includes:

[0042] The first electronic device displays a second device list, the second device list including at least one trusted device, and the at least one trusted device including the second electronic device; and

[0043] The first electronic device sends a device association request to the second electronic device, including:

[0044] The first electronic device, in response to detecting the operation of the user selecting the second electronic device, sends the device association request to the second electronic device.

[0045] With reference to the first aspect, in some implementations of the first aspect, the second electronic device is a device having the same account as the first electronic device; or, the second electronic device is a device that establishes a connection with the first electronic device through near field communication.

[0046] According to a second aspect, a method for password resetting is provided, including:

[0047] The first electronic device generates first authentication content in response to a first operation of a user.

[0048] In a case where the first authentication content matches second authentication content on an associated second electronic device, the first electronic device prompts the user to reset a lock screen password of the first electronic device.

[0049] The method for password resetting provided by the embodiments of the present application can reset the lock screen password by authenticating the second electronic device when the user forgets the lock screen password, because the second electronic device is a device having an association with the first electronic device. This can effectively avoid the problem of loss of user data caused by the need to reset the lock screen password similar to factory resetting, and enhances the security of the device. In addition, the second electronic device is authenticated by whether the authentication content on the first electronic device matches the authentication content on the second electronic device, which can enhance the security of the authentication process by using two-end authentication on the two devices.

[0050] With reference to the second aspect, in some implementations of the second aspect, the first electronic device and the second electronic device can perform device authentication based on a PAKE protocol according to the authentication content obtained by each device. That is, the first electronic device performs device authentication based on the PAKE protocol based on the first authentication content, and the second electronic device performs device authentication based on the PAKE protocol based on the second authentication content. If the results obtained by the two devices match, the authentication is successful.

[0051] With reference to the second aspect, in some implementations of the second aspect, in a case where the first authentication content matches second authentication content on an associated second electronic device, the first electronic device prompts the user to reset a lock screen password of the first electronic device, including:

[0052] In a case where the first authentication content matches the second authentication content, the first electronic device receives a first password resetting credential sent by the second electronic device, the first password resetting credential being used to authorize the user to reset the lock screen password of the first electronic device.

[0053] In a case where the first password resetting credential is authenticated, the first electronic device prompts the user to reset the lock screen password of the first electronic device.

[0054] The method for password resetting provided in the embodiments of the present application is that, after the authentication of the second electronic device is completed, the first electronic device further verifies the first password resetting credential sent by the second electronic device, and only after the first password resetting credential is verified, the lock screen password is reset, which is equivalent to providing further security guarantee in the process of resetting the password, and further improves the security of the process of resetting the password. For example, the situation that the lock screen password of the first electronic device is modified when the authentication of the second electronic device is passed in the process of communication between the first electronic device and the imitated second electronic device can be avoided.

[0055] With reference to the second aspect, in some implementations of the second aspect, the reminding the user to reset the lock screen password of the first electronic device in the case that the first password resetting credential is authenticated comprises:

[0056] In the case that the first password resetting credential and the second password resetting credential match, the first electronic device reminds the user to reset the lock screen password of the first electronic device, and the second password resetting credential is generated by the first electronic device.

[0057] The first password resetting credential and the second password resetting credential are both generated based on the same password resetting key.

[0058] With reference to the second aspect, in some implementations of the second aspect, the second authentication content is content input by the user and detected by the second electronic device.

[0059] In addition, by inputting the authentication content generated on the first electronic device on the second electronic device for device authentication, since the authentication content on the first electronic device is randomly generated and the authentication content generated at different times is different, the security of the device authentication process can be ensured as much as possible, and the user experience is improved.

[0060] With reference to the second aspect, in some implementations of the second aspect, the first electronic device generates the first authentication content in response to a first operation of the user, and the method comprises:

[0061] The first electronic device displays a first device list in response to a first operation of the user, and the first device list comprises the second electronic device.

[0062] The first electronic device generates the first authentication content in response to detecting an operation of the user selecting the second electronic device.

[0063] The method for password resetting provided in the embodiments of the present application displays the first device list to the user, which can allow the user to select whether to authenticate the second electronic device by himself, and improves the user experience.

[0064] With reference to the second aspect, in some implementations of the second aspect, the first electronic device generates the first authentication content in response to a first operation of the user, including:

[0065] The first electronic device prompts the user to perform the biometric authentication in response to a first operation of the user;

[0066] The first electronic device generates the first authentication content after detecting that the biometric authentication of the user is passed.

[0067] With reference to the second aspect, in some implementations of the second aspect, the second electronic device is a device having the same account as the first electronic device; or,

[0068] The second electronic device is a device that establishes a connection with the first electronic device through near field communication.

[0069] The method for password resetting provided by the embodiments of the present application can start the authentication of the device to reset the lock screen password only after the biometric authentication of the user is passed, which can improve the user experience and improve the security, and avoid the risk that other users of the owner of the first electronic device reset the lock screen password after obtaining the first electronic device.

[0070] The third aspect provides a method for password resetting, including:

[0071] The second electronic device receives a password resetting request sent by an associated first electronic device;

[0072] The second electronic device sends a first password resetting credential to the first electronic device after the authentication of the second electronic device is passed in response to the password resetting request, the first password resetting credential being used to authorize the user to reset the lock screen password of the first electronic device.

[0073] The method for password resetting provided by the embodiments of the present application can reset the lock screen password of the first electronic device only after the authentication of the second electronic device is passed, because the second electronic device is a device associated with the first electronic device, when the user forgets the lock screen password, which can not only effectively avoid the problem of loss of user data caused by the need to reset the lock screen password similar to factory resetting, but also ensure the security of the password resetting process as much as possible. Moreover, after the authentication of the second electronic device is completed, the second electronic device can send a first password resetting credential to the first electronic device, the first password resetting credential being used to authorize the user to reset the lock screen password of the first electronic device, which can make the first electronic device further verify the first password resetting credential, and only after the first password resetting credential is passed, the lock screen password is reset, further improving the security of the password resetting process, for example, the case that the lock screen password of the first electronic device can be modified after the authentication of the second electronic device is passed in the communication process between the first electronic device and the imitated second electronic device can be avoided.

[0074] With reference to the third aspect, in some implementations of the third aspect, in response to the password reset request, the second electronic device sends, after the first authentication content on the first electronic device and the second authentication content on the second electronic device match, the first password reset credential to the first electronic device.

[0075] In response to the password reset request, the second electronic device sends, in a case where the first authentication content on the first electronic device and the second authentication content on the second electronic device match, the first password reset credential to the first electronic device.

[0076] The method for password reset provided by the embodiments of the present application authenticates the second electronic device by whether the authentication content on the first electronic device and the authentication content on the second electronic device match, and considers that the authentication of the second electronic device is passed in a case where the authentication content of the two electronic devices match. This two-end authentication method used on the two devices can improve the security of the authentication process.

[0077] With reference to the third aspect, in some implementations of the third aspect, the first authentication content is content input by a user detected by the first electronic device.

[0078] The method for password reset provided by the embodiments of the present application authenticates the second electronic device by the user inputting the authentication content on the first electronic device, which is convenient for the user currently holding the first electronic device to operate, and can improve the user experience.

[0079] With reference to the third aspect, in some implementations of the third aspect, the first authentication content is a lock screen password of the second electronic device, and the second authentication content is the lock screen password of the second electronic device stored on the second electronic device.

[0080] The method for password reset provided by the embodiments of the present application, since the first electronic device and the second electronic device are associated, the owner of the first electronic device knows the lock screen password of the second electronic device, and other users who are not the owner do not necessarily know the lock screen password of the second electronic device. Therefore, by taking the lock screen password of the associated second electronic device as the authentication content of the authentication device, the risk of resetting the lock screen password by other users who are not the owner after obtaining the first electronic device can be reduced with high probability.

[0081] With reference to the third aspect, in some implementations of the third aspect, the first authentication content is an authentication code, and the second authentication content is an authentication code generated by the second electronic device.

[0082] The method for password resetting provided in the embodiments of the present application can perform device authentication by inputting the authentication code generated on the second electronic device on the first electronic device. Since the authentication code is randomly generated and different authentication codes generated at different times are different, the security of the device authentication process can be ensured as much as possible, and the user experience is improved.

[0083] With reference to the third aspect, in some implementations of the third aspect, in response to the password resetting request, the second electronic device sends the first password resetting credential to the first electronic device if the first authentication content on the first electronic device and the second authentication content on the second electronic device match, including:

[0084] In a case where the first time length is less than or equal to a preset time length and the first authentication content and the second authentication content match, the second electronic device sends the first password resetting credential to the first electronic device; and

[0085] The first time length is a time length between the unlocking time of the second electronic device and the time when the first electronic device detects that the user inputs the first authentication content; or

[0086] The first time length is a time length between the unlocking time of the second electronic device and the time when the second electronic device generates the second authentication content.

[0087] Generally, if the user who obtains the second electronic device is the owner of the second electronic device, the second electronic device can be unlocked in a short time. In this way, the second electronic device can generate the authentication code in a short time, and the user can input the authentication code on the first electronic device in a short time. The embodiments of the present application set a preset time length. In a case where the first time length related to the unlocking time of the second electronic device is less than or equal to the preset time length and the authentication code detected by the first electronic device and the authentication code generated on the second electronic device match, it is considered that the second electronic device passes the authentication. Otherwise, in a case where the first time length is greater than the first preset time length, it is considered that the second electronic device fails the authentication. The first time length is a time length between the unlocking time of the second electronic device and the time when the first electronic device detects that the user inputs the first authentication content, or the first time length is a time length between the unlocking time of the second electronic device and the time when the second electronic device generates the second authentication content. In this way, the security of the authentication process of the second electronic device can be improved, and the problem of poor security caused by the authentication of the second electronic device by other users who are not the owner of the second electronic device can be avoided.

[0088] With reference to the third aspect, in some implementations of the third aspect, the first authentication content is content generated by the first electronic device, and the second authentication content is content input by the user and detected by the second electronic device.

[0089] With reference to the third aspect, in some implementations of the third aspect, before the second electronic device receives the password reset request sent by the associated first electronic device, the method further includes:

[0090] The second electronic device receives a device association request sent by the first electronic device.

[0091] After the authentication of the second electronic device is passed, an association relationship is established between the first electronic device and the second electronic device, and the second electronic device receives the first password reset credential sent by the first electronic device.

[0092] With reference to the third aspect, in some implementations of the third aspect, the second electronic device is a device having the same account as the first electronic device; or,

[0093] The second electronic device is a device that establishes a connection with the first electronic device through near field communication.

[0094] With reference to the third aspect, in some implementations of the third aspect, the password reset request includes an identifier of the first electronic device.

[0095] A fourth aspect provides a password reset method, including:

[0096] The first electronic device sends a password reset request to an associated second electronic device in response to a first operation of a user.

[0097] After the authentication of the second electronic device is passed, the first electronic device receives a first password reset credential sent by the second electronic device in response to the password reset request, and the first password reset credential is used to authorize the user to reset the lock screen password of the first electronic device.

[0098] In the case where the authentication of the first password reset credential is passed, the first electronic device prompts the user to reset the lock screen password of the first electronic device.

[0099] With reference to the fourth aspect, in some implementations of the fourth aspect, in the case where the authentication of the first password reset credential is passed, the first electronic device prompts the user to reset the lock screen password of the first electronic device, including:

[0100] In the case where the first password reset credential and a second password reset credential match, the first electronic device prompts the user to reset the lock screen password of the first electronic device, and the second password reset credential is generated by the first electronic device.

[0101] With reference to the fourth aspect, in some implementations of the fourth aspect, after the authentication of the second electronic device is passed, the first electronic device receives a first password reset credential sent by the second electronic device in response to the password reset request, including:

[0102] In a case where the first authentication content on the first electronic device and the second authentication content on the second electronic device match, the first electronic device receives the first password reset credential.

[0103] With reference to the fourth aspect, in some implementations of the fourth aspect, before the first electronic device receives the first password reset credential in a case where the first authentication content on the first electronic device and the second authentication content on the second electronic device match, the method further includes:

[0104] The first electronic device prompts a user to input the first authentication content in response to a first operation of the user;

[0105] The first electronic device detects that the user inputs the first authentication content.

[0106] With reference to the fourth aspect, in some implementations of the fourth aspect, the first authentication content is a lock screen password of the second electronic device, and the second authentication content is the lock screen password of the second electronic device stored on the second electronic device.

[0107] With reference to the fourth aspect, in some implementations of the fourth aspect, the first authentication content is an authentication code, and the second authentication content is an authentication code generated by the second electronic device.

[0108] With reference to the fourth aspect, in some implementations of the fourth aspect, the first electronic device receives the first password reset credential in a case where the first authentication content on the first electronic device and the second authentication content on the second electronic device match, including:

[0109] In a case where the first time length is less than or equal to a preset time length and the first authentication content and the second authentication content match, the first electronic device receives the first password reset credential; wherein,

[0110] The first time length is a time length between an unlocking time of the second electronic device and a time when the first electronic device detects that the user inputs the first authentication content; or,

[0111] The first time length is a time length between an unlocking time of the second electronic device and a time when the second electronic device generates the second authentication content.

[0112] In some implementations of the fourth aspect, in conjunction with the fourth aspect, the second authentication content is content of a user input detected by the second electronic device; and

[0113] In a case where the first authentication content on the first electronic device and the second authentication content on the second electronic device match, before the first electronic device receives the first password reset credential, the method further includes:

[0114] The first electronic device generates the first authentication content in response to a first operation of a user.

[0115] In some implementations of the fourth aspect, in conjunction with the fourth aspect, the first electronic device sends a password reset request to an associated second electronic device in response to a first operation of a user, including:

[0116] The first electronic device displays a first device list in response to a first operation of a user, the first device list including the second electronic device;

[0117] The first electronic device sends the password reset request to the second electronic device in response to detecting an operation of a user selecting the second electronic device.

[0118] In some implementations of the fourth aspect, in conjunction with the fourth aspect, the first electronic device sends a password reset request to an associated second electronic device in response to a first operation of a user, including:

[0119] The first electronic device prompts a user for biometric authentication in response to a first operation of a user.

[0120] The first electronic device sends the password reset request to the second electronic device after detecting that the biometric authentication of the user is passed.

[0121] In some implementations of the fourth aspect, in conjunction with the fourth aspect, before the first electronic device sends a password reset request to an associated second electronic device in response to a first operation of a user, the method further includes:

[0122] The first electronic device sends a device association request to the second electronic device.

[0123] An association relationship is established between the first electronic device and the second electronic device after the authentication of the second electronic device is passed, and the first electronic device sends the first password reset credential to the second electronic device.

[0124] In some implementations of the fourth aspect, in conjunction with the fourth aspect, before the first electronic device sends a device association request to the second electronic device, the method further includes:

[0125] The first electronic device displays a second device list, the second device list including at least one trusted device, the at least one trusted device including the second electronic device;

[0126] The first electronic device sends a device association request to the second electronic device, including:

[0127] The first electronic device sends the device association request to the second electronic device after detecting that a user selects the second electronic device.

[0128] With reference to the fourth aspect, in some implementations of the fourth aspect, the second electronic device is a device having the same account as the first electronic device; or,

[0129] The second electronic device is a device that establishes a connection with the first electronic device through near field communication.

[0130] With reference to the fourth aspect, in some implementations of the fourth aspect, the password reset request includes an identifier of the first electronic device.

[0131] The fifth aspect provides a device for password resetting, the device including: a reminding unit configured to remind a user to input first authentication content in response to a first operation of the user; a detecting unit configured to detect that the user inputs the first authentication content; and the reminding unit is further configured to remind the user to reset a lock screen password of the first electronic device in a case where the first authentication content matches second authentication content on an associated second electronic device.

[0132] The sixth aspect provides a device for password resetting, the device including: a processing unit configured to generate first authentication content in response to a first operation of a user; and a reminding unit configured to remind the user to reset a lock screen password of the first electronic device in a case where the first authentication content matches second authentication content on an associated second electronic device.

[0133] The seventh aspect provides a device for password resetting, the device including: a sending unit configured to send a password reset request to an associated second electronic device in response to a first operation of a user; a receiving unit configured to receive a first password reset credential sent by the second electronic device in response to the password reset request after authentication of the second electronic device is passed, the first password reset credential being used to authorize the user to reset a lock screen password of the first electronic device; and a reminding unit configured to remind the user to reset the lock screen password of the first electronic device in a case where authentication of the first password reset credential is passed.

[0134] In an eighth aspect, a device for password resetting is provided, the device comprising: a receiving unit configured to receive a password resetting request sent by an associated first electronic device; and a sending unit configured to, in response to the password resetting request, send a first password resetting credential to the first electronic device after authentication of the second electronic device is passed, the first password resetting credential being used to authorize a user to reset a lock screen password of the first electronic device.

[0135] In a ninth aspect, an electronic device is provided, comprising: one or more processors; a memory; and one or more computer programs. The one or more computer programs are stored in the memory and comprise instructions which, when executed by the electronic device, cause the electronic device to perform the method in any possible implementation of the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0136] In a tenth aspect, a chip is provided, comprising a processor configured to invoke and run instructions stored in a memory, so that an electronic device in which the chip is installed performs the method in any possible implementation of the first aspect, the second aspect, the third aspect, or the fourth aspect. Exemplarily, the chip can be a secure chip.

[0137] In an eleventh aspect, a computer storage medium is provided, comprising: a processor coupled to a memory, the memory being configured to store programs or instructions which, when executed by the processor, cause the device to perform the method in any possible implementation of the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0138] In a twelfth aspect, the present application provides a computer program product which, when running on an electronic device, causes the electronic device to perform the method in any possible implementation of the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0139] It can be understood that the electronic device, the chip, the computer storage medium, and the computer program product provided above are all used to perform the corresponding method provided above, and thus the beneficial effects achieved thereby can refer to the beneficial effects of the corresponding method provided above, which will not be described herein again. BRIEF DESCRIPTION OF DRAWINGS

[0140] Figure 1 is a schematic structural diagram of a terminal device provided by an embodiment of the present application.

[0141] Figure 2 is a software structural block diagram of an electronic device provided by an embodiment of the present application.

[0142] Figure 3 is a set of GUIs provided by an embodiment of the present application.

[0143] Figures 4 to 18 is another group of GUIs provided by embodiments of the present application.

[0144] Figure 19 is a schematic flowchart of a process for associating a security device provided by embodiments of the present application.

[0145] Figure 20 is a schematic flowchart of a process for resetting a lock screen password provided by embodiments of the present application.

[0146] Figure 21 is a schematic flowchart of a method for password resetting provided by embodiments of the present application.

[0147] Figure 22 is another schematic flowchart of a method for password resetting provided by embodiments of the present application.

[0148] Figures 23 to 26 is a schematic block diagram of an apparatus for password resetting provided by embodiments of the present application.

[0149] Figure 27 is a schematic structural diagram of an apparatus for password resetting provided by embodiments of the present application. DETAILED DESCRIPTION

[0150] The technical solutions in the present application will be described below with reference to the drawings.

[0151] The method provided by embodiments of the present application can be applied to electronic devices with display screens, such as mobile phones, tablet computers, wearable devices, vehicle-mounted devices, augmented reality (AR) / virtual reality (VR) devices, notebook computers, ultra-mobile personal computers (UMPCs), netbooks, personal digital assistants (PDAs), and the like. Embodiments of the present application do not make any limitation on the specific type of electronic device.

[0152] Exemplarily, Figure 1A structural diagram of the electronic device 100 is shown. The electronic device 100 can include a processor 110, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a sensor module 180, a key 190, a motor 191, an indicator 192, a display screen 194, and the like. The sensor module 180 can include a pressure sensor 180A, a gyro sensor 180B, an acceleration sensor 180E, a distance sensor 180F, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, and the like.

[0153] It can be understood that the structure shown in the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 can include more or fewer components than shown, or combine certain components, or split certain components, or different arrangement of components. The components shown can be implemented in hardware, software, or a combination of software and hardware.

[0154] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), and the like. Different processing units can be independent devices, or can be integrated in one or more processors.

[0155] The controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to instruction operation codes and timing signals to complete the control of fetching instructions and executing instructions. A memory can also be provided in the processor 110 for storing instructions and data.

[0156] In some embodiments, the memory in the processor 110 is a cache memory. The memory can save instructions or data that the processor 110 has just used or repeatedly uses. If the processor 110 needs to use the instructions or data again, it can be directly called from the memory. This avoids repeated access and reduces the waiting time of the processor 110, thus improving the efficiency of the system.

[0157] In the embodiments of the present application, the processor 110 can reset the lock screen password of the electronic device through other components.

[0158] In some embodiments, after detecting the relevant operation of the user, the processor 110 can remind the user to input the authentication content related to the associated electronic device through the output device such as the display screen 194, for example, the authentication content can be the lock screen password of the associated electronic device or the authentication content randomly generated and output by the associated electronic device, in addition, the processor 110 can also detect the authentication content input by the user through the input device such as the display screen 194, in the case that the authentication content on the electronic device 100 configured with the processor 110 and the authentication content on the associated electronic device match, the processor 110 can remind the user to reset the lock screen password of the electronic device through the output device such as the display screen 194.

[0159] Exemplarily, the input device can include any device that can receive a signal, for example, the input device can include the display screen 194 or the microphone 170C.

[0160] Exemplarily, the output device can include any device that can output a signal, for example, the output device can include the display screen 194 or the speaker 170A.

[0161] In other embodiments, the processor 110 can generate authentication content after detecting the relevant operation of the user, and output the authentication content through the output device, so as to facilitate the user to input the authentication content on the associated electronic device, in the case that the authentication content on the electronic device 100 and the authentication content on the associated electronic device match, the processor 110 can remind the user to reset the lock screen password of the electronic device through the output device.

[0162] In other embodiments, the processor 110 can perform device authentication on the authentication content on the electronic device 100 and the authentication content on the associated electronic device through a password authenticated key exchange (PAKE) protocol.

[0163] In other embodiments, the processor 110 can also perform biometric authentication on the user through the sensor module 180.

[0164] The wireless communication function of the electronic device 100 can be realized through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor, etc.

[0165] In the embodiments of the present application, the wireless communication function of the electronic device 100 can implement functions such as sending a password reset request, sending an identifier of the electronic device 100, and receiving a password reset credential. The antenna 1 and the antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example: the antenna 1 can be multiplexed as a diversity antenna of a wireless local area network. In some other embodiments, the antennas can be used in combination with a tuning switch.

[0166] The mobile communication module 150 can provide a solution including 2G / 3G / 4G / 5G wireless communication applied to the electronic device 100. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), and the like. The mobile communication module 150 can receive electromagnetic waves by the antenna 1, and perform filtering, amplification, and the like on the received electromagnetic waves, and transmit the processed electromagnetic waves to the modem processor for demodulation. The mobile communication module 150 can also amplify the signals modulated by the modem processor, and convert the signals into electromagnetic waves radiated by the antenna 1. In some embodiments, at least part of the functional modules of the mobile communication module 150 can be disposed in the processor 110. In some embodiments, at least part of the functional modules of the mobile communication module 150 and at least part of the modules of the processor 110 can be disposed in the same device.

[0167] The modem processor can include a modulator and a demodulator. The modulator is used to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate a received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. The low-frequency baseband signal processed by the baseband processor is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to the loudspeaker 170A and the microphone 170B), or displays an image or a video through the display screen 194. In some embodiments, the modem processor can be an independent device. In some other embodiments, the modem processor can be independent of the processor 110, and disposed in the same device as the mobile communication module 150 or other functional modules.

[0168] The wireless communication module 160 can provide a solution for wireless communication including wireless local area networks (WLAN) (e.g., wireless fidelity (Wi-Fi) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, etc. applied to the electronic device 100. The wireless communication module 160 can be one or more devices that integrate at least one communication processing module. The wireless communication module 160 receives an electromagnetic wave via the antenna 2, frequency-modulates and filters the electromagnetic wave signal, and transmits the processed signal to the processor 110. The wireless communication module 160 can also receive a signal to be transmitted from the processor 110, frequency-modulate it, amplify it, and radiate it as an electromagnetic wave via the antenna 2.

[0169] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include a global positioning system (GPS), a global navigation satellite system (GLONASS), a beidu navigation satellite system (BDS), a quasi-zenith satellite system (QZSS), and / or a satellite based augmentation systems (SBAS).

[0170] The electronic device 100 implements a display function through a GPU, a display screen 194, and an application processor, etc. The GPU is a microprocessor for image processing, which is connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs, which execute program instructions to generate or change display information.

[0171] In the embodiments of the present application, the display screen 194 can output a GUI related to resetting the lock screen password, for example, the following Figures 3 to 18The GUI shown. In addition, the display screen 194 can also allow the user to input operations related to resetting the lock screen password. The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can adopt a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diode (QLED), etc. In some embodiments, the electronic device 100 can include 1 or N display screens 194, N being a positive integer greater than 1.

[0172] The electronic device 100 can realize audio functions through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the earphone interface 170D, and the application processor, etc. For example, music playing, recording, etc.

[0173] The audio module 170 is used to convert digital audio information into analog audio signals output, and is also used to convert analog audio input into digital audio signals. The audio module 170 can also be used to encode and decode audio signals. In some embodiments, the audio module 170 can be arranged in the processor 110, or part of the functions of the audio module 170 can be arranged in the processor 110.

[0174] The speaker 170A, also known as a "loudspeaker", is used to convert audio electrical signals into sound signals. The electronic device 100 can listen to music or listen to hands-free calls through the speaker 170A.

[0175] In the embodiments of the present application, the processor 110 can output audio information related to resetting the lock screen password through the speaker 170A.

[0176] For example, the speaker 170A can output the authentication code generated by the electronic device 100.

[0177] For another example, the speaker 170A can also remind the user to input the authentication content.

[0178] For another example, the speaker 170A can also remind the user to input the lock screen password of the electronic device.

[0179] The receiver 170B, also called "earpiece", is used to convert audio electrical signals into sound signals. When the electronic device 100 answers a phone call or a voice message, the user can answer the voice by placing the receiver 170B close to the ear.

[0180] The microphone 170C, also called "microphone", "sounder", is used to convert sound signals into electrical signals. When making a phone call or sending a voice message, the user can make a sound by placing the mouth close to the microphone 170C, and input the sound signal into the microphone 170C. The electronic device 100 can be provided with at least one microphone 170C. In some other embodiments, the electronic device 100 can be provided with two microphones 170C, in addition to collecting sound signals, the noise reduction function can also be realized. In some other embodiments, the electronic device 100 can also be provided with three, four or more microphones 170C, in addition to collecting sound signals, noise reduction, the sound source can also be identified, and the directional recording function can also be realized.

[0181] In the embodiments of the present application, the processor 110 can input the audio information related to resetting the lock screen password through the microphone 170C.

[0182] For example, the user can input the authentication code through the microphone 170C.

[0183] For another example, the user can input the device associated with the electronic device 100 through the microphone 170C.

[0184] The pressure sensor 180A is used to sense the pressure signal, and can convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A can be provided on the display screen 194. There are many types of pressure sensors 180A, such as resistive pressure sensors, inductive pressure sensors, capacitive pressure sensors, etc. The capacitive pressure sensor can include at least two parallel plates with conductive material. When a force acts on the pressure sensor 180A, the capacitance between the electrodes changes. The electronic device 100 determines the intensity of the pressure according to the change of the capacitance. When a touch operation acts on the display screen 194, the electronic device 100 detects the intensity of the touch operation according to the pressure sensor 180A. The electronic device 100 can also calculate the position of the touch according to the detection signal of the pressure sensor 180A. In some embodiments, the touch operation acting on the same touch position but with different touch operation intensities can correspond to different operation instructions. For example: when a touch operation with a touch operation intensity less than a first pressure threshold value acts on the short message application icon, the instruction of viewing the short message is executed. When a touch operation with a touch operation intensity greater than or equal to the first pressure threshold value acts on the short message application icon, the instruction of creating a new short message is executed.

[0185] The gyroscope sensor 180B can be used to determine the motion posture of the electronic device 100. In some embodiments, the angular velocity of the electronic device 100 around three axes (i.e., x, y, and z axes) can be determined by the gyroscope sensor 180B. The gyroscope sensor 180B can be used for anti-shake photography. For example, when the shutter is pressed, the gyroscope sensor 180B detects the angle of shaking of the electronic device 100, calculates the distance that the lens module needs to compensate according to the angle, and lets the lens offset the shaking of the electronic device 100 by reverse movement to achieve anti-shake. The gyroscope sensor 180B can also be used for navigation and motion sensing game scenarios.

[0186] The acceleration sensor 180E can detect the magnitude of acceleration of the electronic device 100 in various directions (generally three axes). When the electronic device 100 is stationary, the magnitude and direction of gravity can be detected. The acceleration sensor 180E can also be used to identify the posture of the electronic device, which can be used for switching between landscape and portrait modes, pedometers, and other applications.

[0187] The distance sensor 180F is used to measure distance. The electronic device 100 can measure distance by infrared or laser. In some embodiments, when taking a scene, the electronic device 100 can use the distance sensor 180F to measure distance to achieve fast focusing.

[0188] The fingerprint sensor 180H is used to collect fingerprints. The electronic device 100 can use the collected fingerprint characteristics to implement fingerprint unlocking, access application locking, fingerprint photography, fingerprint call answering, and the like.

[0189] The temperature sensor 180J is used to detect temperature. In some embodiments, the electronic device 100 uses the temperature detected by the temperature sensor 180J to implement temperature processing strategies. For example, when the temperature reported by the temperature sensor 180J exceeds a threshold, the electronic device 100 reduces the performance of the processor located near the temperature sensor 180J to reduce power consumption and implement thermal protection. In other embodiments, when the temperature is lower than another threshold, the electronic device 100 heats the battery 142 to avoid abnormal shutdown of the electronic device 100 caused by low temperature. In other embodiments, when the temperature is lower than yet another threshold, the electronic device 100 performs voltage boosting on the output voltage of the battery 142 to avoid abnormal shutdown caused by low temperature.

[0190] Touch sensor 180K, also referred to as "touch panel". Touch sensor 180K can be disposed on display screen 194, and touch sensor 180K and display screen 194 together form a touch screen, also referred to as "touch panel". Touch sensor 180K is configured to detect touch operations applied to or near the touch sensor 180K. The touch sensor can pass the detected touch operation to the application processor to determine the touch event type. Visual output related to the touch operation can be provided through display screen 194. In other embodiments, touch sensor 180K can also be disposed on the surface of electronic device 100, which is different from the position where display screen 194 is disposed.

[0191] Keys 190 include power on key, volume key, and the like. Keys 190 can be mechanical keys. They can also be touch keys. Electronic device 100 can receive key input and generate key signal input related to user settings and function control of electronic device 100.

[0192] Motor 191 can generate vibration prompts. Motor 191 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations applied to different applications (such as taking pictures, playing audio, etc.) can correspond to different vibration feedback effects. Touch operations applied to different regions of display screen 194 can also correspond to different vibration feedback effects. Different application scenarios (such as time reminders, receiving messages, alarms, games, etc.) can also correspond to different vibration feedback effects. Touch vibration feedback effects can also be customizable.

[0193] Indicator 192 can be an indicator light, which can be used to indicate charging status, power change, and can also be used to indicate messages, missed calls, notifications, and the like.

[0194] The software system of electronic device 100 can adopt a layered architecture, an event-driven architecture, a microkernel architecture, a microservice architecture, or a cloud architecture. The embodiments of the present application take the Android system with a layered architecture as an example to exemplarily illustrate the software structure of electronic device 100.

[0195] Figure 2 is a software structure block diagram of electronic device 100 according to an embodiment of the present application. The layered architecture divides the software into several layers, and each layer has a clear role and division of labor. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom, application layer, application framework layer, Android runtime and system library, and kernel layer. The application layer can include a series of application packages.

[0196] As Figure 2As shown, the application package can include camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, short message, etc. applications.

[0197] The application framework layer provides application programming interface (API) and programming framework for the applications of the application layer. The application framework layer includes some pre-defined functions.

[0198] As shown, the application framework layer can include window manager, content provider, view system, phone manager, resource manager, notification manager, etc. Figure 2

[0199] The window manager is used to manage window programs. The window manager can acquire the size of the display screen, determine whether there is a status bar, lock the screen, and intercept the screen, etc.

[0200] The content provider is used to store and acquire data, and make the data accessible by the applications. The data can include video, image, audio, dialed and received calls, browsing history and bookmarks, phonebook, etc.

[0201] The view system includes visual controls, such as controls for displaying text, controls for displaying pictures, etc. The view system can be used to build applications. A display interface can be composed of one or more views. For example, a display interface including a short message notification icon can include a view for displaying text and a view for displaying pictures.

[0202] The phone manager is used to provide the communication function of the electronic device 100. For example, the management of call status (including call connection, call hang-up, etc.).

[0203] The resource manager provides various resources for the applications, such as localized strings, icons, pictures, layout files, video files, etc.

[0204] The notification manager makes the applications able to display notification information in the status bar, which can be used to convey the type of messages that can automatically disappear after a short stay without user interaction. For example, the notification manager is used to inform the completion of download, message reminder, etc. The notification manager can also be a notification in the form of a chart or a scroll bar text appearing in the top status bar of the system, such as the notification of the application running in the background, and can also be a notification in the form of a dialogue window appearing on the screen. For example, the text information is prompted in the status bar, a prompt sound is emitted, the electronic device vibrates, the indicator light flashes, etc.

[0205] The Android runtime includes the core library and the virtual machine. The Android runtime is responsible for the scheduling and management of the Android system. ​

[0206] The core library includes two parts: one part is a function function that needs to be called by the java language, and the other part is the core library of Android.

[0207] The application layer and the application framework layer run in the virtual machine. The virtual machine executes the java files of the application layer and the application framework layer into binary files. The virtual machine is used to perform functions such as management of the object life cycle, stack management, thread management, security and exception management, and garbage collection.

[0208] The system library can include a plurality of functional modules. For example: a surface manager, media libraries, a three-dimensional graphics processing library (for example: OpenGL ES), a 2D graphics engine (for example: SGL), and the like.

[0209] The surface manager is used to manage the display subsystem, and provides a plurality of applications with the fusion of 2D and 3D layers.

[0210] The media library supports a plurality of commonly used audio, video format playback and recording, and static image files, and the like. The media library can support a plurality of audio and video coding formats, for example: MPEG4, H.264, MP3, AAC, AMR, JPG, PNG, and the like.

[0211] The three-dimensional graphics processing library is used to implement three-dimensional graphics drawing, image rendering, synthesis, and layer processing, and the like.

[0212] The 2D graphics engine is a drawing engine for 2D drawing.

[0213] The kernel layer is a layer between hardware and software. The kernel layer at least includes a display driver, a camera driver, an audio driver, and a sensor driver.

[0214] The embodiment of the application provides a password resetting scheme, by associating a first electronic device with a second electronic device, a trust relationship is established, when a user forgets the lock screen password of the first electronic device, the lock screen password of the first electronic device can be reset by authenticating the second electronic device, not only can effectively avoid the problem of loss of user data caused by the need to reset the lock screen password similar to factory reset, but also enhances the security of the device.

[0215] In the embodiment of the application, the electronic device (for example, the second electronic device) associated with the first electronic device can be referred to as the security device of the first electronic device.

[0216] The embodiments of the present application mainly relate to two processes of associating a security device and resetting a lock screen password. In the process of associating a security device, the first electronic device needs to authenticate the second electronic device to establish a trust relationship between the two, and take the second electronic device as the security device of the first electronic device. In the process of resetting the lock screen password, in view of the fact that the security device has been set for the first electronic device, when the user forgets the lock screen password of the first electronic device, the lock screen password is reset by authenticating the security device.

[0217] The lock screen password in the embodiments of the present application can include, but is not limited to, a numerical password, a pattern password, and a mixed password formed by combining a numerical password and a pattern password.

[0218] The embodiments of the present application can authenticate the second electronic device by authenticating content, wherein the authentication content includes, but is not limited to, the lock screen password of the second electronic device, an authentication code, and other authentication-related content of the device.

[0219] In an example, the authentication code can be a string composed of any number of characters, for example, a string composed of 4 or 6 characters, wherein the string can be a combination of letters, numbers or symbols, or all letters, numbers or symbols.

[0220] In another example, the authentication code can be a two-dimensional code containing the above-mentioned string.

[0221] In the following, the graphical user interface (GUI) of the embodiments of the present application is described in detail. Figures 3 to 18 The graphical user interface (GUI) of the embodiments of the present application is described in detail.

[0222] For ease of description, the first electronic device is referred to as device A, and the second electronic device is referred to as device B; in addition, it is assumed that both device A and device B are mobile phones.

[0223] Figure 3 is a set of graphical user interfaces (GUIs) provided by the embodiments of the present application, and shows the process of authenticating device B by inputting the lock screen password of device B on device A to associate a security device after successfully setting the lock screen password of device A. Figure 4 is another set of GUIs provided by the embodiments of the present application, and shows the process of authenticating device B by inputting the lock screen password of device B on device A to reset the lock screen password.

[0224] Referring to (a) in Figure 3 In (a), the user inputs the lock screen password of device A on device A to set the lock screen password.

[0225] Referring to (b) in Figure 3In (b) of FIG. 3, after the device A confirms that the user completes the input of the lock screen password, the device A displays a message prompt box 301, which includes a message for prompting the user that the lock screen password of the device A is set successfully, a message for prompting the user whether the trusted device needs to be set, a cancel control 3011 and a confirmation control 3012. The user clicks the confirmation control 3012 to confirm that the trusted device of the device A needs to be set.

[0226] Reference is made to Figure 3 In (c) of FIG. 3, after the device A detects that the user clicks the confirmation control 3012, the device A can display a trusted device selection box 302, which includes a trusted device list, a cancel control 3021 and a confirmation control 3022.

[0227] The trusted device list includes at least one trusted device, for example, the trusted device list includes the device B, the device C and the device D, which can be the candidate trusted device. The user can select one of the trusted devices (for example, the device B) as the trusted device, and can click the selected device B and the confirmation control 3022. After the device A detects that the user selects the device B and clicks the confirmation control 3022 of the device B, the device A can display a GUI as shown in (d) of FIG. 3. Figure 3

[0228] The trusted device of the embodiments of the present application is any device that can establish a trust relationship with the device A.

[0229] In an example, the trusted device can be a device that can establish a connection with the device A through near field communication, which includes but is not limited to Wi-Fi, Bluetooth (BT), near field communication (NFC) and other near field communication technologies.

[0230] In another example, the trusted device can be a device that has the same account as the device A, for example, the trusted device has the same Huawei account as the device A.

[0231] In another example, in order to improve the security protection and increase the trust degree of the device, the trusted device can be a device that has a certain secure operating environment or security capability. For example, the security capability of the device can be confirmed by the security level of the device. If the device has the security capability above a certain level, the device has the security capability and can be the trusted device of the device A. If the device has no security capability or has low security capability below a certain level, the device cannot be the trusted device of the device A.

[0232] Reference is made to Figure 3 ​(d) of FIG. 11B, after device A detects the user's operation of confirming control 3022 of device B, a message reminder box 303 can be displayed on device A, the message reminder box 303 including a reminder message (e.g., please enter the lock screen password of device B) for reminding the user to enter the lock screen password of device B, a password display box 3031, and a password input box 3032. The user enters the lock screen password of device B through password input box 3032, and at the same time, the lock screen password of device B is displayed in password display box 3031.

[0233] Reference is made to Figure 3 (e) of FIG. 11B, after device A detects the user's operation of entering the lock screen password of device B and confirms that the lock screen password is correct, a reminder message is displayed on device A, the reminder message being for reminding the user that the secret protection device is set successfully.

[0234] By means of Figure 3 the GUI, the user can input the lock screen password of device B on device A through the related reminder to authenticate device B, so as to establish a trust relationship between device A and device B, and in the case that the user forgets the lock screen password of device A in the future, the lock screen password of device A can be reset through the authentication of device B.

[0235] When device A is in a lock screen state, after device A detects the user's operation of clicking the forgotten password control on the lock screen interface, or after device A detects that the number of times of entering the incorrect lock screen password by the user reaches a preset value, device A can display the GUI shown in Figure 4 (a) to (c) of FIG. 12A.

[0236] Reference is made to Figure 4 (a) of FIG. 12A, a message reminder box 401 is displayed in device A, the message reminder box 401 including a message (e.g., please authenticate the secret protection device to reset the lock screen password) for reminding the user to authenticate the secret protection device and a control 4011. The user clicks control 4011 to perform device authentication on the already associated device B.

[0237] Reference is made to Figure 4 (b) of FIG. 12A, after device A detects the user's operation of clicking control 4011, a message reminder box 402 can be displayed on device A, the message reminder box 402 including a message (e.g., please enter the lock screen password of device B) for reminding the user to enter the lock screen password of device B, a password display box 4021, and a password input box 4022. The user enters the lock screen password of device B through password input box 4022, and at the same time, the lock screen password of device B is displayed in password display box 4021.

[0238] Reference is made to Figure 4(c) in FIG. 4, after device A detects the operation of inputting the lock screen password of device B by the user and confirms that the lock screen password is correct, a message prompt box 403 is displayed, the message prompt box 403 including a message (e.g., authentication successful!) for prompting the user that the authentication of device B is successful. The message prompt box 403 can also include a password display box 4031 and a password input box 4032, the user resetting the lock screen password of device A through the password input box 4032, and meanwhile, the password display box 4031 can display the reset lock screen password of device A.

[0239] In the embodiments of the present application, device A can be associated with device B trusted to establish a trust relationship, in the case that the user forgets the lock screen password of device A, the user can input the lock screen password of device B on device A through relevant prompting to authenticate device B, so as to reset the lock screen password of device A. In this way, the security of the process of resetting the lock screen password is improved, and the problem of data loss caused by resetting the lock screen password in a manner similar to factory resetting is avoided, thereby improving the user experience.

[0240] Figure 5 FIG. 5 is another set of GUIs provided by the embodiments of the present application, showing the process of authenticating device B by inputting the lock screen password of device B on device B to associate the security device after the user successfully sets the lock screen password of device A. Figure 6 FIG. 6 is another set of GUIs provided by the embodiments of the present application, showing the process of authenticating device B by inputting the lock screen password of device B on device B to reset the lock screen password.

[0241] Referring to Figure 5 (a) in FIG. 4, the user inputs the lock screen password of device A in device A for setting the lock screen password.

[0242] Referring to Figure 5 (b) in FIG. 4, after device A confirms that the user completes the input of the lock screen password, a message prompt box 501 is displayed on device A, the message prompt box 501 including a message for prompting the user that the setting of the lock screen password of device A is successful, a message for prompting the user whether to set the security device of device A, a cancel control 5011 and a confirmation control 5012. The user clicks the confirmation control 5012 to confirm that the security device of device A needs to be set.

[0243] Referring to Figure 5In (c) of FIG. 5, after device A detects the user's operation of clicking the confirmation control 5012, device A can display a trusted device selection box 502, which includes a trusted device list, a cancel control 5021, and a confirmation control 5022. The user selects device B as the security device and clicks the confirmation control 5022. In addition, after device A detects the user's operation of clicking the confirmation control 5022 of device B, device A can send a device association request to device B. After device B receives the request, a message prompt box 503 is displayed on device B, which includes a prompt message (e.g., please enter the lock screen password of device B) for prompting the user to enter the lock screen password of device B, a password display box 5031, and a password input box 5032. The user enters the lock screen password of device B through the password input box 5032, and at the same time, the lock screen password of device B is displayed in the password display box 5031.

[0244] Referring to Figure 5 In (d) of FIG. 5, after device A and device B both confirm that the lock screen password of device B entered by the user is correct, device A displays a prompt message for prompting the user that the security device setting is successful, and the message prompt box 503 of device B disappears, and device B returns to the desktop background as shown in (d) of FIG. 5. Figure 5

[0245] Through the GUI of the application, the user enters the lock screen password of device B on device B through the relevant prompt to establish the trust relationship between device A and device B, so that in the case that the user forgets the lock screen password of device A in the future, the lock screen password of device A can be reset through authentication of device B. Figure 5

[0246] When device A is in a locked state, after device A detects the user's operation of clicking the password forgetting control on the lock screen interface, or after device A detects that the number of times of entering the incorrect lock screen password by the user reaches a preset value, device A and device B can display the GUI as shown in (a) to (b) of FIG. 6. Figure 6

[0247] Referring to Figure 6 ​​​In (a) of FIG. 6, the device A displays a message prompt box 601, which includes a message (e.g., please authenticate the security device to reset the lock screen password) and a control 6011 for reminding the user to authenticate the security device. The user clicks the control 6011 to authenticate the already-associated device B. After detecting the operation of the control 6011 by the user, the device A sends a password reset request to the device B to inform the device A that the lock screen password needs to be reset. After receiving the password reset request, the device B displays a message prompt box 602, which includes a message (e.g., please enter the lock screen password of the device B), a password display box 6021, and a password input box 6022 for reminding the user to enter the lock screen password of the device B. The user enters the lock screen password of the device B through the password input box 6022, and the password display box 6021 displays the lock screen password of the device B.

[0248] Reference Figure 6 In (b) of FIG. 6, after the device A and the device B confirm that the lock screen password of the device B input by the user is correct, the device A displays a message prompt box 603, which includes a message (e.g., authentication successful!) for reminding the user that the authentication of the device B is successful. The message prompt box 603 can also include a password display box 6031 and a password input box 6032, and the user resets the lock screen password of the device A through the password input box 6032, and the password display box 6031 displays the reset lock screen password of the device A. The message prompt box 602 of the device B disappears, and the device B returns to the desktop background as shown in (b) of FIG. 6. Figure 6

[0249] In the embodiments of the present application, the device A can be associated with the trusted device B to establish a trust relationship. In the case that the user forgets the lock screen password of the device A, the user can input the lock screen password of the device B on the device B through the related reminders of the device A and the device B to authenticate the device B, so as to reset the lock screen password of the device A. In this way, the security of the process of resetting the lock screen password of the device A is improved, and the problem of data loss caused by resetting the lock screen password in the manner of factory resetting is avoided, thereby improving the user experience.

[0250] The above Figures 3 to 6 are all the association of the security device and the resetting of the lock screen password through the input of the lock screen password of the security device.

[0251] In some embodiments, in the process of associating the security device and resetting the lock screen password, the lock screen password of the security device can be input on the same device (as shown in Figure 3 and 4 ). Figure 5 and 6 ).

[0252] ​In some embodiments, the lock screen password of the security device can be input on different devices in the process of associating the security device and resetting the lock screen password. For example, the security device is associated based on the way of inputting the lock screen password of the security device on device A as shown in Figure 3 For another example, the lock screen password is reset based on the way of inputting the lock screen password of the security device on device B as shown in Figure 6 For yet another example, the security device is associated based on the way of inputting the lock screen password of the security device on the security device as shown in Figure 5 For yet another example, the lock screen password is reset based on the way of inputting the lock screen password of the security device on device A as shown in Figure 4

[0253] It should be understood that, Figures 3 to 6 For yet another example, the security device is associated based on the way of inputting the lock screen password of the security device on the security device as shown in

[0254] Figure 7 is another set of GUIs provided by the embodiments of the present application, and shows the process of authenticating device B by inputting the authentication code displayed on device B on device A to associate the security device after the user successfully sets the lock screen password of device A. Figure 8 is another set of GUIs provided by the embodiments of the present application, and shows the process of authenticating device B by inputting the authentication code displayed on device B on device A to reset the lock screen password. In addition, the authentication code in the form of a string is used to illustrate the GUIs for the convenience of description.

[0255] Referring to (a) in Figure 7 , the user inputs the lock screen password of device A in device A for the setting of the lock screen password.

[0256] Referring to (b) in Figure 7 , after device A confirms that the user finishes inputting the lock screen password, device A displays a message prompt box 701, which includes a message for prompting the user that the setting of the lock screen password of device A is successful, a message for prompting the user whether to set a security device for device A, a cancel control 7011 and a confirmation control 7012. The user confirms that a security device needs to be set for device A and clicks the confirmation control 7012.

[0257] Referring to (c) in Figure 7 , after device A detects the operation of the user clicking the confirmation control 7012, device A can display a trusted device selection box 702, which includes a trusted device list, a cancel control 7021 and a confirmation control 7022. The user selects device B as the security device and clicks the confirmation control 7022. ​

[0258] refer to Figure 7 In step (d), after device A detects the user's operation on the confirmation control 7022 of device B, device A can display a message reminder box 704. The message reminder box 704 includes a reminder message prompting the user to enter an authentication code, an authentication code display box 7041, and an authentication code input box 7042. The user enters the authentication code displayed on device B through the authentication code input box 7042, and the authentication code is simultaneously displayed in the authentication code display box 3031. Furthermore, after device A detects the user's operation on the confirmation control 7022 of device B, device A can send a device association request to device B. Upon receiving this request, device B can display a message reminder box 703, which includes an authentication code (e.g., authentication code 078521).

[0259] It should be understood that the authentication code is randomly generated, and the authentication code generated each time a security device is associated can be different, which can improve security.

[0260] In one example, reference Figure 7 In step (e), after device A detects the user's input authentication code and confirms its correctness, device A displays a notification message to remind the user that the security device has been successfully set up. Device B then reverts to the previous state. Figure 7 The desktop background shown in (e) is shown in the image.

[0261] pass Figure 7 The GUI allows users to input an authentication code displayed on device B via prompts on device A, establishing a trust relationship between device A and device B. This allows users to reset the lock screen password of device A by authenticating device B if they forget it later.

[0262] When device A is in lock screen mode, after device A detects that the user clicks the "Forgot Password" control on the lock screen, or after device A detects that the number of times the user has entered an incorrect lock screen password has reached a preset value, devices A and B may display the following: Figure 8 The GUIs shown in (a) to (c) are shown in the image.

[0263] refer to Figure 8 In (a), device A displays a message notification box 801, which includes a message reminding the user to authenticate a security device (e.g., please authenticate a security device to reset the lock screen password) and a control 8011. The user clicks the control 8011 to authenticate the associated device B.

[0264] refer to Figure 8In (b) of FIG. 8, after device A detects the user's operation on the control 8011, device A can send a password reset request to device B, and device B displays a message prompt box 802, which includes an authentication code (for example, authentication code 078521). In addition, after device A detects the user's operation on the control 8011, a message prompt box 803 can be displayed on device A, which includes a prompt message for reminding the user to input the authentication code, an authentication code display box 8031, and an authentication code input box 8032. The user inputs the authentication code displayed on device B through the authentication code input box 8032, and the authentication code is displayed in the authentication code display box 8031 at the same time.

[0265] It should be understood that the authentication code is randomly generated, and the authentication code generated each time the security device is authenticated can be different. In addition, the authentication code generated in the process of associating the security device with device A and the authentication code generated in the process of authenticating the security device can also be different, which can improve security.

[0266] Reference is made to Figure 8 In (c) of FIG. 8, after device A and device B confirm that the authentication code input by the user is correct, device A displays a message prompt box 804, which includes a message (for example, authentication success!) for reminding the user that the authentication of device B is successful. The message prompt box 804 can also include an authentication code display box 8041 and an authentication code input box 8042, through which the user resets the lock screen password of device A, and the authentication code display box 8041 can display the reset lock screen password of device A. The message prompt box 802 of device B disappears, and device B returns to the desktop background as shown in (c) of FIG. 8. Figure 8 In (c) of FIG. 8, after device A and device B confirm that the authentication code input by the user is correct, device A displays a message prompt box 804, which includes a message (for example, authentication success!) for reminding the user that the authentication of device B is successful. The message prompt box 804 can also include an authentication code display box 8041 and an authentication code input box 8042, through which the user resets the lock screen password of device A, and the authentication code display box 8041 can display the reset lock screen password of device A. The message prompt box 802 of device B disappears, and device B returns to the desktop background as shown in (c) of FIG. 8.

[0267] In the embodiments of the present application, device A can be associated with trusted device B to establish a trust relationship. In the case that the user forgets the lock screen password of device A, the user can input the authentication code displayed on device B on device A to authenticate device B and reset the lock screen password of device A through the related prompts of device A and device B. In this way, the security of the process of resetting the lock screen password of device A is improved, and the problem of data loss caused by resetting the lock screen password in a manner similar to factory reset is avoided, thereby improving the user experience.

[0268] Figure 9 FIG. 9 is another set of GUIs provided by the embodiments of the present application, which show the process of authenticating device B by inputting the authentication code displayed on device A on device B to associate the security device after the user successfully sets the lock screen password of device A. Figure 10 FIG. 10 is another set of GUIs provided by the embodiments of the present application, which show the process of authenticating device B by inputting the authentication code displayed on device A on device B to reset the lock screen password.

[0269] Based on the reminder of the device A, the user completes the operations of (a) and (b) in Figure 7 , and the GUI as shown in (c) of Figure 9 may be displayed.

[0270] Referring to (a) of Figure 9 , after the device A detects the operation that the user clicks the confirmation control of the device A needing to set the security device, the device A can display a trusted device selection box 901, the trusted device selection box 901 including a trusted device list, a cancel control 9011 and a confirmation control 9012, the user clicks the confirmation control 9012 of the device B to confirm to select the device B as the security device.

[0271] Referring to (b) of Figure 9 , after the device A detects the operation of the user on the confirmation control 9012 of the device B, the device A can display a message reminder box 902, the message reminder box 902 including an authentication code (for example, authentication code 078521). In addition, after the device A detects the operation of the user on the confirmation control 9012 of the device B, the device A can send a device association request to the device B, the device B receives the request, the device B displays a message reminder box 903, the message reminder box 903 including a reminder message for reminding the user to input the authentication code, an authentication code display box 9031 and an authentication code input box 9032. The user inputs the authentication code displayed on the device A through the authentication code input box 9032, and at the same time, the authentication code is displayed in the authentication code display box 9031.

[0272] After the device A and the device B detect that the authentication code input by the user on the device B is correct, the device A and the device B can display the GUI as shown in (e) of Figure 7 .

[0273] Through the GUI of Figure 9 , the device A and the device B input the authentication code displayed on the device A on the device B through the related reminders, so as to establish the trust relationship between the device A and the device B, so that in the case that the user forgets the lock screen password of the device A in the future, the lock screen password of the device A can be reset through the authentication of the device B.

[0274] The device A is in a lock screen state, after the device A detects the operation that the user clicks the password forgetting control on the lock screen interface, or after the device A detects that the number of times of inputting the wrong lock screen password by the user reaches a preset value, the device A and the device B can display the GUI as shown in (a) to (b) of Figure 10 .

[0275] Referring to Figure 10In (a), a message notification box 1010 is displayed on device A. The message notification box 1010 includes a message reminding the user to authenticate the security device (e.g., please authenticate the security device to reset the lock screen password) and a control 1011. The user clicks the control 1011 to authenticate the already associated device B.

[0276] refer to Figure 10 In (b) of the above, after device A detects a user's operation on control 1011, device A can display a message reminder box 1020, which includes an authentication code (e.g., authentication code 076452). Furthermore, after device A detects a user's operation on device B's confirmation control 1011, device A can send a password reset request to device B, and device B can display a message reminder box 1030, which includes a reminder message prompting the user to enter an authentication code, an authentication code display box 1031, and an authentication code input box 1032. The user enters the authentication code displayed on device A through the authentication code input box 1032, and the authentication code is simultaneously displayed in the authentication code display box 1031.

[0277] After devices A and B detect that the authentication code entered by the user on device B is correct, it means that the authentication for device B is successful, and device A can display as follows: Figure 8 In (c) of the GUI, device B is restored to the state shown. Figure 8 The desktop background shown in (c) is shown in the image.

[0278] In this embodiment, device A can be associated with a trusted device B to establish a trust relationship. If a user forgets the lock screen password for device A, the user can authenticate device B by entering the authentication code displayed on device A on device B, based on the relevant prompts from both devices A and B, thereby resetting the lock screen password for device A. This improves the security of resetting the lock screen password for device A while avoiding data loss caused by resetting the lock screen password using a method similar to a factory reset, thus enhancing the user experience.

[0279] It should be understood that the above Figures 7 to 10 The examples shown all demonstrate how to associate security devices and reset lock screen passwords by entering an authentication code.

[0280] In one embodiment, during the process of associating a security device and resetting the lock screen password, the lock screen password of the security device can be entered on the same device (e.g., ...). Figure 7 and 8 As shown, Figure 9 and 10 (As shown).

[0281] In another embodiment, authentication codes can be entered on different devices during the process of associating security devices and resetting lock screen passwords. For example, based on Figure 7The way of inputting the authentication code displayed on the device A on the security device to associate the security device is shown, based on Figure 10 The way of inputting the authentication code displayed on the device A on the security device to reset the lock screen password is shown. For another example, based on Figure 9 The way of inputting the authentication code displayed on the device A on the security device to associate the security device is shown, based on Figure 8 The way of inputting the authentication code displayed on the device A on the security device to reset the lock screen password is shown.

[0282] Figure 11 Another set of GUIs provided by the embodiments of the present application is shown, which is the process of establishing the trust relationship between the device A and the device B by displaying the same authentication code on the device A and the device B after the user successfully sets the lock screen password of the device A. Figure 12 Another set of GUIs provided by the embodiments of the present application is shown, which is the process of authenticating the device B to reset the lock screen password by displaying the same authentication code on the device A and the device B.

[0283] Based on the prompt of the device A, the user completes the operations of (a) and (b) in Figure 7 After the user completes the operations of (a) and (b) in Figure 11 The GUIs of (a) and (b) in

[0284] Referring to (a) in Figure 11 After the device A detects the operation of the user clicking the confirmation control of the security device of the device A, the device A can display the trusted device selection box 1110, which includes the trusted device list, the cancel control 1111 and the confirmation control 1112. The user clicks the confirmation control 1112 of the device B to confirm to select the device B as the security device.

[0285] Referring to (b) in Figure 11 After the device A detects the operation of the user clicking the confirmation control 1112 of the device B, the device A can display the message prompt box 1120, and the device B can display the message prompt box 1130. The message prompt box 1120 includes the authentication request, the cancel control 1121 and the confirmation control 1122, and the authentication request includes the authentication code (for example, the authentication code is: 078521). The message prompt box 1130 includes the authentication request, the cancel control 1131 and the confirmation control 1132, and the authentication request includes the same authentication code as the device A (for example, the authentication code is: 078521). When the user confirms that the authentication codes displayed on the device A and the device B are the same, the confirmation control 1122 of the device A and the confirmation control 1132 of the device B can be clicked. In this way, after the device A detects the operation of the user clicking the confirmation control 1122, the message prompt box 1120 disappears, and the device A displays the GUIs of (a) and (b) in Figure 7In the GUI of (e), and after device B detects the user's operation on the confirmation control 1132, the message notification box 1130 disappears, and device B displays as shown in the image. Figure 7 The GUI of (e) in the middle.

[0286] pass Figure 11 The GUI allows devices A and B to display the same authentication code via relevant prompts, establishing a trust relationship between them.

[0287] In this way, if a user forgets the lock screen password of device A later, the lock screen password of device A can be reset by authenticating device B.

[0288] When device A is in lock screen mode, after device A detects that the user clicks the "Forgot Password" control on the lock screen, or after device A detects that the number of times the user has entered an incorrect lock screen password has reached a preset value, devices A and B may display the following: Figure 12 The GUIs shown in (a) to (b) are shown in the image.

[0289] refer to Figure 12 In (a), a message notification box 1210 is displayed on device A. The message notification box 1210 includes a message reminding the user to authenticate the security device (e.g., please authenticate the security device to reset the lock screen password) and a control 1211. The user clicks the control 1211 to authenticate the already associated device B.

[0290] refer to Figure 12 In (b) of the above, after device A detects a user's operation on control 1211, device A can display a message alert box 1220. Message alert box 1220 includes an authentication request, a cancellation control 1221, and a confirmation control 1222. The authentication request includes an authentication code (e.g., the authentication code is 078521). Furthermore, after device A detects a user's operation on control 1211, device A can send a password reset request to device B. Device B displays a message alert box 1230, which includes an authentication request, a cancellation control 1231, and a confirmation control 1232. The authentication request includes the same authentication code as device A (e.g., the authentication code is 078521). When the user confirms that the authentication codes displayed on device A and device B are the same, they can click the confirmation control 1222 on device A and the confirmation control 1232 on device B. Thus, after device A detects a user's operation on confirmation control 1222, message alert box 1220 disappears, and device A displays... Figure 8 In (c) of the GUI, and after device B detects the user's operation on the confirmation control 1232, the message notification box 1230 disappears, and device B displays as shown. Figure 8 The GUI of (c) in the middle.

[0291] In this embodiment, device A can be associated with a trusted device B to establish a trust relationship. If a user forgets the lock screen password for device A, the user can use the relevant prompts to operate device A to authenticate device B by displaying the same authentication code on both device A and device B, thereby resetting the lock screen password for device A. This ensures the security of device A while avoiding data loss caused by resetting the lock screen password using a method similar to a factory reset, thus improving the user experience.

[0292] The authentication code shown in the GUI above is displayed as a string. It should be understood that the authentication code in this embodiment can also be a QR code containing a string. In embodiments where the authentication code is a QR code, the security device and the lock screen password are associated by one device displaying the QR code and another device scanning the QR code.

[0293] by Figure 7 and Figure 8 For example, users based on Figure 7 Following the GUI prompts in (a), (b), and (c), clicking the confirmation control 7022 in the Trusted Device selection box will cause Device A to detect the user's action on the confirmation control 7022. Device B will then display a QR code, which the user can scan using the QR code scanning window on Device B. Alternatively, Device A can display a QR code, which the user can scan using the QR code scanning window on Device A. After successful scanning, both Device A and Device B can display... Figure 7 The GUI in (e) of the diagram. Similarly, during the process of resetting the lock screen password, the user... Figure 8 Following the GUI prompt in (a), clicking control 8011 will cause device A to detect the user's action on control 8011. Device B will then display a QR code, which the user can scan using a QR code scanning window. Alternatively, device A can display a QR code, which the user can scan using a QR code scanning window. After successful scanning, both devices A and B can display... Figure 8 The GUI of (c) in the middle.

[0294] In this embodiment of the application, both the process of associating a security device and resetting the lock screen password involve authenticating the security device. Different authentication methods can be used in these two processes to authenticate the security device. For example, the above... Figures 3 to 12 The authentication and security devices that use QR code scanning as described above can be combined in any way.

[0295] In some embodiments, the security device can be authenticated by entering the lock screen password of the security device during the process of associating the security device, and the security device can be authenticated by entering an authentication code during the process of resetting the lock screen password.

[0296] In an example, device A can authenticate device B based on the GUI shown in Figure 3 or Figure 5 to associate device B, and can authenticate device B based on the GUI shown in Figure 8 or Figure 10 to reset the lock screen password.

[0297] In another embodiment, the authentication code input method can be used to authenticate the security device during the process of associating the security device, and the lock screen password input method can be used to authenticate the security device during the process of resetting the lock screen password.

[0298] In an example, device A can authenticate device B based on the GUI shown in Figure 7 or Figure 9 to associate device B, and can authenticate device B based on the GUI shown in Figure 4 or Figure 6 to reset the lock screen password.

[0299] In another embodiment, the authentication code input method can be used to authenticate the security device during the process of associating the security device, and the lock screen password input method can be used to authenticate the security device during the process of resetting the lock screen password.

[0300] In an example, device A can authenticate device B based on the GUI shown in Figure 11 to associate device B, and can authenticate device B based on the GUI shown in Figure 4 or Figure 6 to reset the lock screen password.

[0301] In another embodiment, the authentication code input method can be used to authenticate the security device during the process of associating the security device, and the lock screen password input method can be used to authenticate the security device during the process of resetting the lock screen password.

[0302] In an example, device A can authenticate device B based on the GUI shown in Figure 11 to associate device B, and can authenticate device B based on the GUI shown in Figure 8 or Figure 10 to reset the lock screen password.

[0303] Figure 13 is another set of GUIs provided by the embodiments of the present application, and shows the process of authenticating the security device after the biological authentication during the process of resetting the lock screen password, which can further improve the security of the process. It is assumed that device A has associated device B, and device B is the security device.

[0304] Reference is made to Figure 13In (a) of FIG. 13, the device A is in a locked screen state, and a message prompt box 1310 is displayed in the device A, the message prompt box 1310 including a message (e.g., please perform fingerprint identification) for reminding the user to perform fingerprint identification and a fingerprint identification area 1311, on which the user presses a finger.

[0305] It should be understood that the device A realizes the biometric authentication through the fingerprint identification only as an example, and the device A can also realize the biometric authentication through other biometric identification modes such as face recognition, iris recognition, and / or voice recognition, and the embodiments of the present application are not limited in this regard.

[0306] Reference is made to Figure 13 In (b) of FIG. 13, after detecting the operation of the user pressing the fingerprint identification area 1311, the device A displays a message prompt box 1320, the message prompt box 1320 including a message (e.g., please authenticate the security device to reset the lock screen password) for reminding the user to authenticate the security device and a control 1321. The user clicks the control 1321 to authenticate the device B that has been associated.

[0307] After detecting the operation of the user clicking the control 1321, the device A can display the GUI shown in (b) and (c) of FIG. 14, or the device A and the device B can display the GUI shown in (b) and (c) of FIG. 15, or the device A and the device B can display the GUI shown in (b) of FIG. 16, or the device A and the device B can display the GUI shown in (b) of FIG. 17, or the device A and the device B can display the GUI shown in (b) of FIG. 18. Figure 4 Figure 6 After detecting the operation of the user clicking the control 1321, the device A can display the GUI shown in (b) and (c) of FIG. 14, or the device A and the device B can display the GUI shown in (b) and (c) of FIG. 15, or the device A and the device B can display the GUI shown in (b) of FIG. 16, or the device A and the device B can display the GUI shown in (b) of FIG. 17, or the device A and the device B can display the GUI shown in (b) of FIG. 18. Figure 8 Figure 10 After detecting the operation of the user clicking the control 1321, the device A can display the GUI shown in (b) and (c) of FIG. 14, or the device A and the device B can display the GUI shown in (b) and (c) of FIG. 15, or the device A and the device B can display the GUI shown in (b) of FIG. 16, or the device A and the device B can display the GUI shown in (b) of FIG. 17, or the device A and the device B can display the GUI shown in (b) of FIG. 18. Figure 12 After detecting the operation of the user clicking the control 1321, the device A can display the GUI shown in (b) and (c) of FIG. 14, or the device A and the device B can display the GUI shown in (b) and (c) of FIG. 15, or the device A and the device B can display the GUI shown in (b) of FIG. 16, or the device A and the device B can display the GUI shown in (b) of FIG. 17, or the device A and the device B can display the GUI shown in (b) of FIG. 18.

[0308] The above

[0309] shown in FIG. 13 are all the GUIs for associating one security device to reset the lock screen password of the device A, and as an example but not limitation, the device A can also authenticate multiple security devices to associate the security devices and reset the lock screen password, please refer to the two groups of GUIs shown in FIG. 14 and FIG. 15. Figures 3 to 13 Figure 14 Figure 15 The above

[0310] Figure 14 shown in FIG. 13 are all the GUIs for associating one security device to reset the lock screen password of the device A, and as an example but not limitation, the device A can also authenticate multiple security devices to associate the security devices and reset the lock screen password, please refer to the two groups of GUIs shown in FIG. 14 and FIG. 15. Figure 15 ​​​​The process of resetting the lock screen password of device A by authenticating multiple trusted devices is shown. For ease of description, the description is made in the way that the lock screen password of device B is input on device A.

[0311] Referring to Figure 14 (a) to (d), the user authenticates device B to associate the trusted device, and the detailed description can refer to the description of (a) to (d) in Figure 3 , which will not be repeated.

[0312] Referring to Figure 14 (e), after device A detects that the user inputs the lock screen password of device B and confirms that the lock screen password is correct, a message prompt box 1450 is displayed, the message prompt box 1450 including a prompt message for prompting the user that device B is successfully set, a prompt message for prompting the user whether other trusted devices need to be set, a cancel control 1451, and a confirmation control 1452. If the user needs to set multiple trusted devices, the user clicks the confirmation control 1452.

[0313] Referring to Figure 14 (f), after device A detects that the user clicks the confirmation control 1452, a trusted device selection box 1460 is displayed again, the trusted device selection box 1460 including a trusted device list, a cancel control 1461, and a confirmation control 1462.

[0314] In an example, the trusted device list includes at least one trusted device (e.g., device B, device C, and device D), which can include a trusted device that has been set as a trusted device (e.g., device B) and a trusted device that has not been set as a trusted device (e.g., device C and device D), as shown in (f) in Figure 14 .

[0315] In another example, the at least one trusted device in the trusted device list can only include trusted devices that have not been set as trusted devices (e.g., device C and device D).

[0316] The user can select one of the un-set trusted devices as a trusted device, click the option of device C that needs to be selected and the confirmation control 1462, and after device A detects that the user selects device C and the operation of the confirmation control 3022 of device C, the GUI as shown in (g) to (i) in Figure 14 may be displayed.

[0317] Referring to Figure 14In (g) of FIG. 14, after device A detects the user's operation of confirming control 1462 of device C, a message prompt box 1470 can be displayed on device A, the message prompt box 1470 including a prompt message (e.g., please enter the lock screen password of device C) for prompting the user to enter the lock screen password of device B, a password display box 1471, and a password input box 1472. The user enters the lock screen password of device C through password input box 1472, and at the same time, the lock screen password of device C is displayed in password display box 1471.

[0318] Referring to Figure 14 In (h) of FIG. 14, after device A detects the user's operation of entering the lock screen password of device C and confirms that the lock screen password is correct, a message prompt box 1480 is displayed, the message prompt box 1480 including a prompt message for prompting the user that device B is successfully set, a prompt message for prompting the user whether the user still needs to set other security device, a cancel control 1481, and a confirm control 1482. The user does not need to set other security device, and clicks cancel control 1481.

[0319] Referring to Figure 14 In (i) of FIG. 14, after device A detects the user's operation of cancel control 1481, a prompt message is displayed, the prompt message for prompting the user that the security device is successfully set.

[0320] Referring to Figure 14 In (a) of FIG. 15, device A is in a lock screen state, and a message prompt box 1510 is displayed in device A, the message prompt box 1510 including a message (e.g., please authenticate the security device to reset the lock screen password) for prompting the user to authenticate the security device, a control 1511, and a control 1522. The control 1511 is a control for authenticating device B that has been associated, and the control 1522 is a control for authenticating device C that has been associated. The user clicks control 1511 to select to authenticate device B.

[0321] Referring to Figure 15 In (b) of FIG. 15, after device A detects the user's operation of clicking control 1511, a message prompt box 1520 can be displayed on device A, the message prompt box 1520 including a message (e.g., please enter the lock screen password of device B) for prompting the user to enter the lock screen password of device B, a password display box 1521, and a password input box 1522. The user enters the lock screen password of device B through password input box 1522, and at the same time, the lock screen password of device B is displayed in password display box 1521.

[0322] Referring to Figure 15In step (c), after device A detects the user's input of the lock screen password of device B and confirms that the lock screen password is correct, a message reminder box 1530 is displayed. The message reminder box 1530 includes a message to remind the user that device B has been successfully authenticated (e.g., authentication successful!) and a message to remind the user to continue authenticating the security device (e.g., please continue authenticating the security device).

[0323] In one example, the message notification box 1530 may also display controls 1531 and 1532. Control 1531 is used to authenticate the associated device B, and control 1532 is used to authenticate the associated device C.

[0324] In another example, since device B has been successfully authenticated, message notification box 1530 can also display controls for unauthenticated devices. For example, message notification box 1530 can also display control 1532 for device C.

[0325] In this way, users can continue to authenticate their security devices by clicking control 1532.

[0326] refer to Figure 15 In step (d), after device A detects the user's click on control 1532, device A can display a message notification box 1540. The message notification box 1540 includes a message reminding the user to enter the lock screen password of device C (e.g., please enter the lock screen password of device C), a password display box 1541, and a password input box 1542. The user enters the lock screen password of device C through the password input box 1542, and at the same time, the lock screen password of device C is displayed in the password display box 1541.

[0327] refer to Figure 15 In step (e), after device A detects the user's input of the lock screen password for device C and confirms that the lock screen password is correct, a message notification box 1550 is displayed. The message notification box 1550 includes a message to remind the user that the authentication of device C has been successful (e.g., authentication successful!). The message notification box 1550 may also include a password display box 1551 and a password input box 1552. The user resets the lock screen password of device A through the password input box 1552, and at the same time, the password display box 1551 can display the reset lock screen password of device A.

[0328] It should be understood that Figure 15 The illustration shows the process of device A authenticating all associated security devices to reset the lock screen password. This is an example, not a limitation. While device A is in a locked state and needs to reset the lock screen password, device A can also authenticate some of the associated security devices. This embodiment does not impose any limitations. For example, if device A is associated with device B and device C, and only one device needs to be authenticated, in... Figure 15In (a) and (b), the user selects device B for authentication. Once device B completes the authentication, device A can directly display the results. Figure 15 (e) in the middle.

[0329] exist Figure 15 As shown, after successfully setting the lock screen password for device A and linking it to the security device, users can trigger device A to set a lock screen password to link to the security device in various different scenarios.

[0330] In some embodiments, a user can associate a security device after successfully setting the lock screen password for device A initially. For example, when a user buys a new device A, they set the lock screen password for device A upon first powering it on.

[0331] In other embodiments, the user can actively update the lock screen password in the settings of device A and then associate it with a security device. Figures 3 to 15 The GUI shown is used to illustrate this embodiment.

[0332] refer to Figure 16 In (a), the GUI is the desktop of device A. This GUI includes multiple application icons; for example, these applications may include App1, App2, and settings. Users can click on the application icons to access the corresponding application's functions. When device A detects that the user has clicked icon 1610 on the desktop, it can activate the relevant settings functions of device A, displaying, as shown in (a). Figure 16 The GUI shown in (b) is shown in the image.

[0333] refer to Figure 16 (b) shows the settings interface for device A. This GUI includes multiple function options, such as display and brightness, sound and vibration, notifications, biometrics and password, applications, and battery. Users can configure fingerprint, facial recognition, and lock screen password settings via biometrics and password. When device A detects that the user has clicked on the biometrics and password function 1620, it displays the following... Figure 16 The GUI shown in (c) is shown in the image.

[0334] refer to Figure 16 (c) In this context, the GUI is the settings interface for the biometric and password functions of device A. This GUI includes multiple function options under the biometric and password functions, such as fingerprint, face recognition, changing the lock screen password under the lock screen password function, disabling the lock screen password function, security lock screen settings, and smart unlock. When device A detects that the user clicks the "change lock screen password" function 1630, it displays the following... Figure 16 The GUI shown in (d) is shown in the image.

[0335] refer to Figure 16(d) in FIG. 10B, the GUI includes a password input box. The user inputs a new lock screen password in the password input box, and when the device A detects the operation of the user inputting the lock screen password, displays the GUI of (e) in FIG. 10B. Figure 16

[0336] Reference is made to Figure 16 (e) in FIG. 10B, the GUI includes a message prompt box 1640, which includes a message for prompting the user that the lock screen password of the device A is set successfully, a message for prompting the user whether to set a security device, a cancel control 1641 and a confirmation control 1642. The user confirms that the security device needs to be set for the device A, and clicks the confirmation control 1642.

[0337] After the device A detects the operation of the user clicking the confirmation control 1642, displays the GUI of (c) to (e) in FIG. 10B, the GUI of (c) to (d) in FIG. 10C, the GUI of (c) to (e) in FIG. 10D, the GUI of (a) to (b) in FIG. 10E, the GUI of (a) to (b) in FIG. 10F or the GUI of (c) to (i) in FIG. 10G, thereby completing the process of associating the security device. Figure 16 Figure 3 Figure 5 Figure 7 Figure 9 Figure 11

[0338] The above, Figure 14 FIG. 10H shows the process of associating the security device after the device A successfully sets the lock screen password in the scenario, and the embodiments of the present application can also associate the security device in other scenarios. Hereinafter, in combination with Figures 3 to 16 and Figure 17 , the GUI of the device A associating the security device in other scenarios is described.

[0339] Figure 18 FIG. 11 is another set of GUIs provided by the embodiments of the present application, which shows the process of associating the security device in at least one device displayed in the multi-device control center of the device A.

[0340] Reference is made to Figure 17 (a) in FIG. 11, which is the desktop of the device A. The GUI includes a plurality of application icons, for example, the plurality of applications can include App1, App2 and Settings, and the user can click the application icon to realize the function of the corresponding application. When the device A detects the operation of the user clicking the Settings icon 1710 on the desktop, the related function of setting the device A can be started, and the GUI shown in (b) in FIG. 11 is displayed. Figure 17

[0341] Reference is made to Figure 17 ​​​​​​​​(b) shows the settings interface for device A. This GUI includes multiple function options, such as WLAN, Bluetooth, mobile network, more connections, desktop, and wallpaper. Users can use the "more connections" option to enable communication between multiple devices. When device A detects that the user has clicked the "more connections" function 1720, it displays the following... Figure 17 The GUI shown in (c) is shown in the image.

[0342] refer to Figure 17 (c) shows the GUI, which is the settings interface for more connectivity features on device A. This GUI includes multiple function options under "More Connectivity Features," such as multi-device collaboration, NFC, Huawei Share, Huawei HiCar, and screen mirroring. When device A detects that the user has clicked on the multi-device collaboration feature 1730, it displays the following... Figure 17 The GUI shown in (d) is shown in the image.

[0343] refer to Figure 17 (d) In this context, the GUI is the settings interface for the multi-device collaboration function. The GUI includes a graphical operation 1741 for accessing the multi-device control center, a text description 1742, and a control 1743 for enabling the multi-device collaboration function. The user clicks the control 1743 to enable the multi-device collaboration function.

[0344] After the multi-device collaboration function is enabled, the user can operate the display on device A. Figure 17 The GUIs (e) to (g) in the document are used to associate security devices.

[0345] refer to Figure 17 In (e), this GUI is the desktop of device A. This GUI includes multiple application icons, such as App1, App2, and a settings icon. When the user swipes up from the bottom left edge of the screen, and device A detects this swipe, device A enters the multi-device control center, displaying... Figure 17 The GUI shown in (f) is shown in the image.

[0346] refer to Figure 17 In section (f), the GUI is the interface for the multi-device control center of device A. This GUI includes at least one trusted device, such as device B, device C, and device D. This at least one trusted device can be considered as a list of trusted devices for device A, serving as candidate security devices for device A. Users can select any device as a security device by clicking the corresponding control. For example, if a user selects device B and clicks control 1750 corresponding to device B, device A, after detecting the user's operation on control 1750 of device B, will display the following... Figure 17 The GUI of (g) in the middle.

[0347] refer to Figure 17 In (g), the GUI includes at least one functional option corresponding to device B, including the option to set device B as a secure device, a cancel control 1761, a confirm control 1762, and may also include other functional options such as option 1 or option 2. The user selects the option to set device B as a secure device and clicks the confirm control 1762.

[0348] After device A detects that the user has enabled the function to set device B as a secure device and clicked the confirmation control 1762, it can display the following: Figure 3 The GUI shown in (d) to (e) is, or, displayed as shown in Figure 5 In (c) the GUI of device B and such Figure 5 The GUI shown in (d) is, or, displayed as shown in Figure 7 The GUI shown in (d) to (e) is, or, displayed as shown in Figure 9 The GUI shown in (b) is, or, as shown in [the diagram], a display of... Figure 11 The GUI shown in (b) is shown in the image.

[0349] Figure 18 This is another set of GUIs provided in the embodiments of this application, showing the process of associating a security device under the associated security device function option in the settings interface.

[0350] refer to Figure 18 In (a), the GUI is the desktop of device A. This GUI includes multiple application icons; for example, these applications may include App1, App2, and Settings. When device A detects that the user clicks the Settings icon 1810 on the desktop, it can launch the relevant functions for setting device A, displaying, as shown in (a). Figure 18 The GUI shown in (b) is shown in the image.

[0351] refer to Figure 18 (b) shows the settings interface for device A. This GUI includes multiple function options, such as display and brightness, sound and vibration, notifications, biometrics and password, applications, and battery. Users can configure fingerprint, facial recognition, and lock screen password settings via biometrics and password. When device A detects that the user has clicked on the biometrics and password function 1820, it displays the following... Figure 18 The GUI shown in (c) is shown in the image.

[0352] refer to Figure 18(c) in FIG. 6, which is a setting interface of the biometric and password function of device A. The GUI includes a plurality of function options under the biometric and password function, which includes the fingerprint, face recognition, change lock screen password under the lock screen password function, associated security device function, and security lock screen setting function under the close lock screen password function, smart unlock, and the like. When device A detects the operation of the user clicking the associated security device function 1830, a GUI as shown in Figure 18 (d) in FIG. 6 is displayed.

[0353] Referring to Figure 18 (d) in FIG. 6, which is a setting interface of the associated security device function of device A. The GUI includes a trusted device list, which includes at least one trusted device, for example, the trusted device list includes device B, device C, and device D. When device A detects the operation of the user on the control 1841 of device B, a GUI as shown in Figure 18 (e) in FIG. 6 is displayed.

[0354] Referring to Figure 18 (e) in FIG. 6, the GUI includes a message prompt box 1850, which includes a prompt message (e.g., please enter the lock screen password of device B) for prompting the user to input the lock screen password of device B, a password display box 1851, and a password input box 1852. The user inputs the lock screen password of device B through the password input box 1852, and at the same time, the password display box 1851 displays the lock screen password of device B. When device A detects the operation of the user inputting the lock screen password of device B and confirms that the lock screen password is correct, a GUI as shown in Figure 18 (f) in FIG. 6 is displayed.

[0355] Referring to Figure 18 (f) in FIG. 6, the GUI includes a prompt message for prompting the user that the security device setting is successful.

[0356] It should be understood that after device A detects the operation of the user on the control 1841 of device B, not only the GUI as shown in Figure 5 (e) to (f) in FIG. 6 can be displayed, but also the GUI of device B in Figure 5 (c) and the GUI as shown in Figure 7 (d) in FIG. 6 can be displayed, or the GUI as shown in Figure 9 (d) to (e) in FIG. 6 can be displayed, or the GUI as shown in Figure 11 (b) in FIG. 6 can be displayed, or the GUI as shown in Figures 3 to 18 (b) in FIG. 6 can be displayed.

[0357] The GUI of the process of device A associating a security device and resetting a lock screen password is described above in combination with Figure 19 The GUI of the process of device A associating a security device and resetting a lock screen password is described below in combination withFigure 20 and Figure 19 The above process is implemented internally between device A and the security device. In addition, the above process is described with the security device as device B as an example.

[0358] Figure 19 FIG. 19 is a schematic flowchart of a method 1900 of associating a security device according to an embodiment of the present application.

[0359] It should be understood that device A can start to associate a security device under various triggering conditions to perform the method shown in FIG. 18 with device B. Figure 3

[0360] In an example, as shown in (a) to (b) in FIG. 17, device A can start to associate a security device after device A successfully sets a lock screen password. Figure 17

[0361] In another example, as shown in (e) in FIG. 17, device A can start to associate a security device after detecting that a user calls an operation of a multi-device control center. Figure 18

[0362] In another example, as shown in (a) to (c) in FIG. 17, device A can start to associate a security device after detecting that a user calls an operation of an association security device function in settings. Figure 3

[0363] In S1910, device A finds at least one trusted device.

[0364] Device A can find a trusted device based on, for example, the above various triggering conditions.

[0365] As described above, a trusted device is any device that can establish a trust relationship with device A. In an example, a trusted device can be a device that can establish a connection with device A through near field communication. A trusted device can also be a device that has the same account as device A. For specific descriptions, reference can be made to the above description.

[0366] In some embodiments, in order to improve security protection and increase the trustworthiness of a device, a trusted device can be a device that has a certain secure operating environment or security capability.

[0367] Optionally, in embodiments in which a display screen of a device is required to display or input authentication content such as an authentication code, a lock screen password of the device, etc., a trusted device can also be a device that has a display screen.

[0368] An example is that device A finds a trusted device in a near field environment of near field communication.

[0369] ​​​​For example, when device A discovers devices in its vicinity in a near-field environment, it can determine whether a device can be considered a trusted device by checking the security level of the surrounding devices. For instance, the surrounding devices can send their security information to device A. Device A then determines the security level of each device based on this information. This security information may include whether the device has a secure operating environment, whether it supports different levels of security functions, etc. Optionally, the security information may also include whether the device has a display screen. At a certain security level or above, if a device has security capabilities or a display screen, it can be considered a trusted device of device A. Below a certain security level, if a device lacks security capabilities, has low security capabilities, or does not have a display screen, it cannot be considered a trusted device of device A.

[0370] In S1920, device A outputs at least one trusted device.

[0371] After device A has found trusted devices, it can output at least one trusted device through an output device such as a display screen or microphone, so that the user can select one or more trusted devices as security devices from the at least one trusted device.

[0372] For ease of description, this application will be illustrated by taking as an example that a user selects a trusted device as a security device and that security device is device B.

[0373] like Figure 17 As shown in (c) in the text, or, as in Figure 18 As shown in (f) and (g) in the figure, or, as in Figure 3 As shown in (d), device A displays at least one trusted device on its screen, and the user selects device B as the security device from the at least one trusted device based on the prompts from device A.

[0374] In S1930, after device A detects that the user has selected device B, device B is authenticated.

[0375] Device A detects the user's selection of Device B, meaning the user has chosen Device B as the security device. Following this action, Device B is authenticated by verifying the authentication content on either Device A or Device B. After successful authentication of Device B, a connection is established between Device A and Device B, sharing a session key. This means that Device A and Device B can transmit data using the shared key.

[0376] In some embodiments, device B can be authenticated by entering the lock screen password of device B on device A.

[0377] In one example, such as Figure 5As shown in (d) in FIG. 3, after device A detects the operation of selecting device B as the security device, a message prompt box 303 is displayed on device A, and the message prompt box 303 includes a password input box 3032 to remind the user to input the lock screen password of device B. Device A detects the lock screen password input by the user in the password input box 3032, and if the lock screen password input in device A is the same as the lock screen password of device B, the authentication of device B is passed, a trusted relationship is established between device A and device B, and the security device setting of device A is successful.

[0378] For example, device A and device B can perform device authentication based on a password authenticated key exchange (PAKE) protocol according to the respective obtained lock screen passwords, and if the calculation results obtained by the two devices are the same, the authentication is successful. That is, device A performs device authentication based on the PAKE protocol based on the detected lock screen password, and device B performs device authentication based on the PAKE protocol based on the lock screen password stored in device B.

[0379] The device authentication between devices based on the PAKE protocol in the embodiments of the present application means that the authentication content is not transmitted between the devices, the same numerical algorithm is used for the authentication content by each device, and if the calculation results obtained by each device are the same, it is considered that the authentication content of each device is the same, and the authentication of the device is successful. This way of device authentication can effectively improve the security of the authentication process because the authentication content is not transmitted.

[0380] In the above example, device A detects the input lock screen password, device A uses a numerical algorithm to calculate the detected lock screen password, device B itself stores the lock screen password of device B, after device A detects the operation of selecting device B as the security device, device A can send a device association request to device B, device B receives the request, and device B uses the same numerical algorithm as device A to calculate the locally stored lock screen password; if the calculation results are the same, it is considered that the input lock screen password is correct, and the authentication of device B is passed.

[0381] The above-mentioned device authentication between device A and device B based on the PAKE protocol based on the lock screen password of device B is only illustrative, and device B can also be authenticated in other ways.

[0382] For example, device A can send the detected lock screen password to device B, device B compares the received lock screen password with the locally stored lock screen password, and if they are the same, device B can send a confirmation message to device A, so that the authentication of device B is passed. However, the security of this device authentication is relatively low.

[0383] For example, during the process of associating a lock screen password, if device A enters the lock screen password of device B to authenticate the device, device A can save the lock screen password of device B to device A during this process. During the process of resetting the lock screen password, device A can compare the detected lock screen password of device B with the locally stored lock screen password of device B. If the two are the same, the authentication of device B is successful.

[0384] In other embodiments, device B can be authenticated by entering the device B's lock screen password on device B.

[0385] In one example, such as Figure 7 As shown in (c), after device A detects the user's selection of device B as a security device, device A can send a device association request to device B. Upon receiving the request, device B displays a message notification box 503, which includes a password input box 5032. Device B detects the lock screen password entered by the user in the password input box 5032 and compares the detected lock screen password with the lock screen password stored on device B. If they match, it confirms that the user's entered lock screen password for device B is correct, and device B can send a confirmation message to device A to inform the user that the entered lock screen password for device B is correct. In this way, device B's authentication is successful, a trusted relationship is established between device A and device B, and device A's security device setup is successful.

[0386] In other embodiments, device B can be authenticated by entering an authentication code generated on device B on device A. In one example, such as... Figure 9 As shown in (d), after device A detects that the user has selected device B as a security device, device A can send a device association request to device B. Upon receiving this request, device B randomly generates an authentication code (e.g., authentication code 078521) and displays this code to the user. Furthermore, after device A detects that the user has selected device B as a security device, device A displays a message reminder box 704, which includes an authentication code input box 7042, to remind the user to enter an authentication code. Device A detects the authentication code entered by the user in the authentication code input box 7042. If the authentication code entered by device A is the same as the authentication code generated by device B, then device B's authentication is successful, a trusted relationship is established between device A and device B, and device A's security device setup is successful.

[0387] For example, device A and device B can perform device authentication based on the PAKE protocol using their respective authentication codes. If the results obtained by the two devices are the same, the authentication is successful. That is, device A performs device authentication based on the detected authentication code, and device B performs device authentication based on the randomly generated authentication code. A detailed description of device authentication based on the PAKE protocol between devices can be found above and will not be repeated here.

[0388] In this example, device A detects the input authentication code, device B generates the authentication code, device A and device B perform calculation on the authentication code obtained respectively by using the same numerical algorithm, and if the calculation results are the same, it is considered that the input authentication code is correct, and the authentication of device B is passed.

[0389] To further improve the security, in the process of authenticating device B, a preset time length related to the unlocking time of device B can be set, which can be used as the unlocking protection time after device B is unlocked. If device A or device B performs relevant operations within the preset time length after device B is unlocked, the security of the authentication process of device B can be improved, and the problem of poor security caused by authenticating device B by other users who are not the owner of device B can be avoided.

[0390] Exemplarily, the unlocking time of device B can be the time when device B is unlocked the screen of device B last time.

[0391] In this example, device A detects the input authentication code, device B generates the authentication code, device A and device B perform calculation on the authentication code obtained respectively by using the same numerical algorithm, and if the calculation results are the same, it is considered that the input authentication code is correct, and the authentication of device B is passed.

[0392] It should be understood that the above device authentication method based on the authentication code and the PAKE protocol of device A and device B is only illustrative, and device B can also be authenticated by other methods.

[0393] In some embodiments, device A can send the detected authentication code to device B, and device B compares the received authentication code with the authentication code on device B. If they are the same, device B can send a confirmation message to device A, so that the authentication of device B is passed. However, the security of this device authentication is low.

[0394] In some embodiments, device A can send the detected authentication code to device B, and device B compares the received authentication code with the authentication code on device B. If they are the same, device B can send a confirmation message to device A, so that the authentication of device B is passed. However, the security of this device authentication is low.

[0395] In some embodiments, device A can send the detected authentication code to device B, and device B compares the received authentication code with the authentication code on device B. If they are the same, device B can send a confirmation message to device A, so that the authentication of device B is passed. However, the security of this device authentication is low. Figure 11As shown in (b) of FIG. 9, after device A detects the operation of selecting device B as the security device, device A randomly generates an authentication code, and displays the authentication code to the user. Device A can send a device association request to device B. After receiving the request, device B displays a message prompt box 903, which includes an authentication code input box 9032. Device B detects the authentication code input by the user in the authentication code input box 9032. If the authentication code input in device B is the same as the authentication code generated by device A, the authentication of device B is passed, device A and device B establish a trusted relationship, and the security device setting of device A is successful.

[0396] For example, device A and device B can perform device authentication based on the PAKE protocol according to the authentication codes obtained respectively. If the results obtained by the two devices are the same, the authentication is successful. That is, device B performs device authentication based on the PAKE protocol based on the detected authentication code, and device A performs device authentication based on the PAKE protocol based on the randomly generated authentication code. For specific description of device authentication based on the PAKE protocol between devices, reference can be made to the description above, which will not be repeated here.

[0397] In this example, device B detects the input authentication code, device A generates the authentication code, and device A and device B perform calculation on the authentication codes obtained respectively using the same numerical algorithm. If the calculation results of the two are the same, it is considered that the input authentication code is correct, and the authentication of device B is passed.

[0398] The above-mentioned device authentication of device A and device B based on the PAKE protocol based on the authentication code is only illustrative, and device B can also be authenticated by other manners.

[0399] For example, device B can send the detected authentication code to device A, and device A compares the received authentication code with the authentication code on device A. If the two are the same, device A can send a confirmation message to device B, so that the authentication of device B is passed. However, the security of this device authentication is low.

[0400] For example, device A can send the displayed authentication code to device B, and device B compares the detected authentication code with the received authentication code. If the two are the same, device B can send a confirmation message to device A, so that the authentication of device B is passed. However, the security of this device authentication is low.

[0401] In other embodiments, device B can be authenticated by outputting the same authentication code as device A on device B.

[0402] In an example, as shown in FIG. 10, after device A detects the operation of selecting device B as the security device, device A randomly generates an authentication code, and displays the authentication code to the user. Device A can send a device association request to device B. After receiving the request, device B displays a message prompt box 1003, which includes an authentication code input box 10032. Device B detects the authentication code input by the user in the authentication code input box 10032. If the authentication code input in device B is the same as the authentication code generated by device A, the authentication of device B is passed, device A and device B establish a trusted relationship, and the security device setting of device A is successful. Figure 20As shown in (b) in FIG. 19, after device A detects the operation of the user selecting device B as the security device, device A randomly generates an authentication code (e.g., authentication code 078521) and displays the authentication code to the user, and device A can send the authentication code to device B, and device B displays the authentication code on device B after receiving the authentication code. After the user sees the same authentication code on device B as on device A, the user confirms that the authentication of device B is passed by clicking the confirmation control on each device.

[0403] In S1940, device A generates a password reset key, which is used to reset the lock screen password of device A.

[0404] In this step, device A can generate and activate the password reset key in a trusted environment. It should be understood that step S1940 and step S1910 can be executed under the same trigger condition.

[0405] It should also be understood that step S1940 and steps S1910, S1920, S1930 also have no sequence, and the internal logic implementation is subject to.

[0406] For example, step S1940 can be executed simultaneously with any one of steps S1910, S1920, S1930, before any one of steps S1910, S1920, S1930, or after any one of steps S1910, S1920, S1930.

[0407] In S1950, device A sends first information to device B, the first information including the identity of device A and a first password reset credential calculated based on the password reset key.

[0408] After the authentication of device B is passed, device A sends the first information to device B.

[0409] After receiving the first information, device B saves the identity of device A and the first password reset credential.

[0410] Exemplarily, the first password reset credential can be a credential calculated by signing the password reset key. In order to improve security, the calculation process can be irreversible, that is, the first password reset credential can be calculated by the password reset key, but the password reset key cannot be calculated by the first password reset credential.

[0411] The password reset key and the first password reset credential are both used for resetting the lock screen password of the device A, and can be understood as a business identification credential allowing the device A to perform password reset, and can also be understood as a condition for the device A to determine that the device B is a security device of the device A. In a subsequent process of resetting the password, after receiving the first password reset credential sent by the device B, the device A can determine that the device B is indeed a security device of the device A and indeed needs to reset the password, so that the device A can reset the lock screen password of the device A.

[0412] In the security field, in order to increase security, the transmitted information can be encrypted for protection.

[0413] In the embodiments of the present application, the lock screen password of the device B can be used to encrypt the first password reset credential and / or the identifier of the device A, so that the security of the password reset key can be further improved, and a stranger can be avoided from triggering the reset of the lock screen password in a subsequent process of resetting the lock screen password.

[0414] Of course, the first password reset credential and / or the identifier of the device A can also be encrypted by other content in the embodiments of the present application.

[0415] In addition, the device A stores the identifier of the device B, so as to facilitate the transmission of information between the device A and the device B in the future.

[0416] Figure 4 is a schematic flowchart of the method for resetting the lock screen password of the device A provided by the embodiments of the present application.

[0417] In S2010, the device A sends a password reset request to the associated device B in response to a first operation of a user, and the password reset request is used to request to reset the lock screen password of the device A. The device B receives the password reset request.

[0418] In an example, the password reset request includes the identifier of the device A.

[0419] In order to increase security, the password reset request can be information encrypted by a session key. For example, the identifier of the device A is encrypted by the session key and sent to the device B through the password reset request.

[0420] In an example, the device A is in a lock screen state, and the first operation can be an operation of the user clicking a forgotten password control on a lock screen interface.

[0421] In another example, the device A is in a lock screen state, and the first operation can be an operation of the user inputting an incorrect lock screen password for a number of times reaching a preset value.

[0422] The device A sends the password reset request to the device B in response to the first operation of the user after detecting the first operation of the user.

[0423] In some embodiments, the device A, in response to the first operation of the user, sends a password reset request to the associated second electronic device, including:

[0424] The device A, in response to the first operation of the user, displays a first device list, and the first device list includes the device B.

[0425] The device A, in response to detecting the operation of the user selecting the device B, sends a password reset request to the device B.

[0426] In an example, as shown in (a) of FIG. 1, the device A is in a lock screen state, after the device A detects the first operation, the device A, in response to the first operation, displays a first device list including the device B, the user selects the device B, for example, the user clicks a control for authenticating the device B, the device A, in response to the operation of the user selecting the device B, the device B sends a password reset request to the device A. Figure 15

[0427] In embodiments in which the device A has associated multiple devices, the first device list can also include multiple devices, and the user selects the device B from the multiple devices for authentication. As shown in (a) of FIG. 1, the first device list includes not only the device B but also the device C. Figure 13

[0428] In other embodiments, since the device B has been associated before, after detecting the first operation, the device A does not need to display the device list, and the device A can automatically select the device B as the authentication device required for security, and directly send a password reset request to the device B.

[0429] In other embodiments, the device A, in response to the first operation of the user, sends a password reset request to the associated device B, including:

[0430] The device A, in response to the first operation of the user, prompts the user to perform biometric authentication.

[0431] The device A, after detecting that the biometric authentication of the user is passed, sends a password reset request to the device B.

[0432] That is, the device A can first perform biometric authentication on the user, and after the biometric authentication is successful, send a password reset request to the device B, which can improve the user experience and improve security.

[0433] The biometric authentication method of the embodiments of the present application can include but is not limited to fingerprint recognition, face recognition, iris recognition, and / or voice recognition and other biometric recognition methods. Multiple biometric authentication methods can be used in combination or individually, and the embodiments of the present application do not make any limitation.

[0434] ​​In the process of biological authentication, as shown in (a) of Figure 4 , a biological authentication area such as a fingerprint identification area 1311 can be displayed on the device A, and the user can perform biological identification by aligning or pressing the biological authentication area.

[0435] In some embodiments, the device A sends a password reset request to the associated device B in response to the first operation of the user, including:

[0436] The device A prompts the user to perform biological authentication in response to the first operation of the user;

[0437] The device A displays a first device list after detecting that the biological authentication of the user is passed, and the first device list includes the device B.

[0438] The device A sends a password reset request to the device B in response to detecting that the user selects the device B.

[0439] That is, after the device A detects the first operation of the user, the biological authentication is performed first, and then the first device list is displayed for the user to select the device to be authenticated, and the device A sends a password reset request to the device B in response to detecting that the user selects the device B.

[0440] In S2020, the device B is authenticated.

[0441] In this step, the authentication of the device B is completed by verifying the authentication content on the device A or the device B.

[0442] In some embodiments, the authentication of the device B is passed when the first authentication content on the device A matches the second authentication content on the device B.

[0443] Exemplarily, the device A and the device B can perform device authentication based on the PAKE protocol according to the authentication content obtained by each device, and if the results obtained by the two devices are the same, the authentication is successful. That is, the device A performs device authentication based on the PAKE protocol based on the first authentication content, and the device B performs device authentication based on the PAKE protocol based on the second authentication content.

[0444] The device authentication between the devices based on the PAKE protocol in the embodiments of the present application means that the authentication content is not transmitted between the devices, each device uses the same numerical algorithm for the authentication content, and if the calculation results obtained by each device are the same, it is considered that the authentication content of each device matches, and the authentication of the device is successful. The device authentication method can effectively improve the security of the authentication process because the authentication content is not transmitted.

[0445] The device authentication between the device A and the device B based on the PAKE protocol described above is only illustrative, and the device B can also be authenticated by other methods.

[0446] For example, device A can send the first authentication content to device B, device B compares the received first authentication content with the second authentication content of device B, if the two match, device B can send a confirmation message to device A, so that the authentication of device B is passed. However, the security of such device authentication is low.

[0447] In some embodiments, the first authentication content is the content of the user input detected by device A, and the second authentication content is the content stored on device B or the content generated on device B.

[0448] In an example, the first authentication content is the lock screen password of device B input by the user detected by device A, and the second authentication content is the lock screen password of device B stored on device B.

[0449] For example, as shown in (b) of FIG. 8A, after detecting the first operation of the user, device A displays a message prompt box 802 in response to the first operation of the user, the message prompt box 802 includes a password input box 8022 to prompt the user to input the lock screen password of device B. The user inputs the lock screen password of device B in the password input box 8022, and device A detects the lock screen password input by the user. If the lock screen password input in device A matches the lock screen password stored in device B, the authentication of device B is passed. Figure 8 In another example, the first authentication content is the authentication code input by the user detected by device A, and the second authentication content is the authentication code generated by device B.

[0450] For example, as shown in (b) of FIG. 8A, after detecting the first operation of the user, device A displays a message prompt box 802 in response to the first operation of the user, the message prompt box 802 includes a password input box 8022 to prompt the user to input the lock screen password of device B. The user inputs the lock screen password of device B in the password input box 8022, and device A detects the lock screen password input by the user. If the lock screen password input in device A matches the lock screen password stored in device B, the authentication of device B is passed.

[0451] Figure 10 To further improve security, a preset time period can be set, which is related to the unlocking time of device B. The preset time period can be used as the unlocking protection time after device B is unlocked. If device B performs related operations within the preset time period after being unlocked, the security of the authentication process of device B can be improved, and the problem of poor security caused by other users who are not the owner of device B authenticating device B after obtaining device B can be avoided.

[0452] To further improve security, a preset time period can be set, which is related to the unlocking time of device B. The preset time period can be used as the unlocking protection time after device B is unlocked. If device B performs related operations within the preset time period after being unlocked, the security of the authentication process of device B can be improved, and the problem of poor security caused by other users who are not the owner of device B authenticating device B after obtaining device B can be avoided.

[0453] ​Exemplarily, the unlocking time of the device B can be a time at which the device B unlocks the screen of the device B last time.

[0454] In the process of authenticating the device B, in a case that a first duration related to the unlocking time of the device B is less than or equal to a preset duration, and the first authentication content and the second authentication content match, the authentication of the device B is passed. In a case that the first duration is greater than the preset duration, the authentication of the device B fails.

[0455] In a possible implementation, the first duration can be a duration between the unlocking time of the device B and a time at which the device A detects the user input authentication code, and the preset duration can be set to be longer. In a case that the first duration is less than or equal to the preset duration, and in a case that the authentication code detected by the device A and the authentication code generated on the device B match, the authentication of the device B is passed; in a case that the first duration is greater than the preset duration, it can be considered that the authentication code input by the user is invalid, and the authentication of the device B fails.

[0456] Exemplarily, in the process of authenticating the device B based on the PAKE protocol, a timer with a preset duration can be set in the device B, the timer is started after the device B is unlocked, the device B can receive, from the device A, a time at which the device A detects the authentication code, the device B obtains the first duration based on the unlocking time of the device B and the time at which the device A detects the authentication code, in a case that the first duration is less than or equal to the preset duration, the device B calculates the authentication code generated by the device B, and if the calculation result obtained by the device B is same as a calculation result obtained by the device A based on the detected authentication code, the authentication of the device B is passed. In a case that the first duration is greater than the preset duration, the device B does not calculate the authentication code, and the authentication of the device B fails.

[0457] Generally, if the user who takes the device B is the owner of the device B, the device B can be unlocked in a short time, so that the device B can generate the authentication code in a short time, and the user can input the authentication code on the device A in a short time. Embodiments of the present application set a preset duration, in a case that a first duration between the unlocking time of the device B and a time at which the device A detects the user input authentication code is less than or equal to the preset duration, and in a case that the authentication code detected by the device A and the authentication code generated on the device B match, it is considered that the authentication of the device B is passed, otherwise, in a case that the first duration is greater than the preset duration, it is considered that the authentication of the device B fails. In this way, the security of the authentication process of the device B can be improved, and the problem of poor security caused by authenticating the device B by other users who are not the owner of the device B can be avoided.

[0458] In another possible implementation, the first duration is the time between the unlocking time of device B and the time when device B generates the authentication code. The preset duration can be set to be relatively short. If the first duration is less than or equal to the preset duration, and the authentication code detected by device A matches the authentication code generated on device B, device B's authentication is successful. If the first duration is greater than the preset duration, the authentication code generated by device B can be considered invalid, and device B's authentication fails.

[0459] For example, during the authentication of device B based on the PAKE protocol, device B can be configured with a timer of a preset duration. After device B is unlocked, the timer starts. Device B can obtain a first duration based on the unlocking time and the time it takes to generate the authentication code. If the first duration is less than or equal to the preset duration, device B calculates the authentication code generated on device B. If the calculation result obtained by device B is the same as the calculation result obtained by device A based on the detected authentication code, then device B's authentication is successful. If the first duration is greater than the preset duration, device B does not calculate the authentication code, and device B's authentication fails.

[0460] Generally, if the user who obtains device B is the owner of device B, device B can be unlocked in a short time. Thus, device B can also generate an authentication code in a short time. This embodiment sets a preset time interval. Device B is considered authenticated only if the first time interval between unlocking device B and generating the authentication code is less than this preset time interval, and if the authentication code detected by device A matches the authentication code generated on device B. Otherwise, if the first time interval is greater than the preset time interval, device B is considered to have failed to authenticate. This improves the security of device B's authentication process and avoids security issues caused by unauthorized users authenticating device B.

[0461] In another example, the first authentication content is the authentication code generated by device A, and the second authentication content is the authentication code entered by the user detected by device B.

[0462] For example, such as Figure 6 As shown in (b), after detecting the user's first operation, device A, in response to the first operation, randomly generates an authentication code (e.g., authentication code 076452) and displays the authentication code to the user. After receiving a password reset request, device B displays a message reminder box 1030, which includes an authentication code input box 1032, to remind the user to enter an authentication code. Device B detects the authentication code entered by the user in the authentication code input box 1032. If the authentication code entered by device B matches the authentication code generated by device A, then device B's authentication is successful.

[0463] In some embodiments, the device B can be authenticated by inputting the lock screen password of the device B on the device B.

[0464] In an example, as shown in (a) of FIG. 6, after the device B receives the password reset request sent by the device A, a message prompt box 602 is displayed on the device B, and the message prompt box 602 includes a password input box 6022. The device B detects the lock screen password input by the user in the password input box 6022, compares the detected lock screen password with the lock screen password stored by the device B, and if they are the same, it is confirmed that the lock screen password of the device B input by the user is correct. The device B can send a confirmation message to the device A to inform the user that the lock screen password of the device B input by the user is correct. In this way, the authentication of the device B is passed. Figure 4

[0465] In S2030, after the device B is authenticated successfully, the device B sends a first password reset credential to the device A. The device A receives the first password reset credential.

[0466] The first password reset credential is a password reset credential sent by the device A to the device B in the process of associating the security device (for example, the method 1900), and the first password reset credential is generated based on the password reset key.

[0467] In S2040, in the case where the first password reset credential is authenticated successfully, the device A prompts the user to reset the lock screen password of the device A.

[0468] In some embodiments, the device A compares the received first password reset credential with a second password reset credential generated on the device A, and in the case where the first password reset credential and the second password reset credential match, the device A prompts the user to reset the lock screen password. The second password reset credential is generated based on the password reset key.

[0469] In an example, the second password reset credential can be a password reset credential calculated by the device A in the process of associating the security device (for example, the method 1900), and the device A saves the password reset credential obtained in the process to the local for use in the subsequent process of resetting the lock screen password.

[0470] In another example, the second password reset credential can also be a password reset credential recalculated by the device A based on the password reset key in the process of resetting the lock screen password. The device A compares the first password reset credential with the second password reset credential, and if the first password reset credential and the second password reset credential match, the device A considers that the credential sent by the device B is correct, and the device B is indeed the security device of the device A, and then the device A prompts the user to reset the lock screen password.

[0471] In order to improve the user experience, the user can be prompted to reset the lock screen password through the display interface of the display screen, as shown in​Figure 21 The GUI shown in (c) is shown in the image.

[0472] During the lock screen password reset process, after device B completes authentication, device A further verifies the first password reset credential sent by device B. Only after the first password reset credential is verified does the lock screen password reset. This provides an additional security guarantee for the password reset process, further enhancing its security. For example, it prevents situations where a counterfeit device B can easily modify device A's lock screen password by successfully authenticating the counterfeit device B during communication with device A.

[0473] Of course, in this embodiment of the application, if the authentication of device B is completed in S2020, steps S2030 and S2040 can be skipped, and device A can reset the lock screen password. However, this solution has poor security.

[0474] To further enhance security during the password reset process, if the first information, including the first password reset credential and the identifier of device A, sent by device A to device B during the device association process is encrypted by the lock screen password of device B, in step S2020, device B should be authenticated by entering the lock screen password of device B on either device A or device B. After device B is successfully authenticated, the first information is decrypted using the lock screen password of device B to obtain the identifier of device A and the first password reset credential. Thus, in the subsequent step S2030, device B can send the decrypted first password reset credential to device A.

[0475] Therefore, after successfully authenticating device B using device B's lock screen password, the lock screen password of device B is used to decrypt the first information sent by device A, which includes device A's identifier and the first password reset credential. This adds a layer of security to the decryption of the first information and further enhances the security of the password reset process.

[0476] It should be understood that the password reset method in this application embodiment can be executed not only in the locked screen state, but also in the unlocked state.

[0477] For example, the settings interface of device A may include a function option to reset the lock screen password. After detecting the first operation of the user clicking the function option to reset the lock screen password, device A starts to execute S2010 to S2040.

[0478] Figure 20 This is a schematic flowchart illustrating a password reset method provided in an embodiment of this application. The method is executed by a first electronic device, which can be device A as described above, and a second electronic device associated with the first electronic device can be device B as described above. The method shown is... Figure 4The method 2000 shown in the process of authenticating the second electronic device by inputting the first authentication content related to the second authentication content of the second electronic device on the first electronic device to remind the user to reset the lock screen password.

[0479] In S2110, the first electronic device prompts the user to input the first authentication content in response to the first operation of the user.

[0480] In an example, the first electronic device is in a lock screen state, and the first operation can be an operation of the user clicking a forget password control on the lock screen interface.

[0481] In another example, the first electronic device is in a lock screen state, and the first operation can be an operation of the user inputting an incorrect lock screen password a number of times reaching a preset value.

[0482] In another example, the first electronic device is in an unlocked state, and the first electronic device can include a function option of resetting the lock screen password in the setting interface of the first electronic device, and the first operation can be an operation of the user clicking the function option of resetting the lock screen password.

[0483] Exemplarily, the first authentication content can be a lock screen password of the associated second electronic device, and the first authentication content can also be an authentication code, which will be described in detail below.

[0484] In some embodiments, the first electronic device prompts the user to input the first authentication content in response to the first operation of the user, including:

[0485] The first electronic device displays a first device list including the second electronic device in response to the first operation of the user.

[0486] The first electronic device prompts the user to input the first authentication content in response to detecting an operation of the user selecting the second electronic device.

[0487] In an example, as shown in (a) of FIG. 13, Figure 4 In an example, as shown in (a) of FIG. 13, Figure 15 In an example, as shown in (a) of FIG. 13,

[0488] In the embodiment in which the first electronic device has associated with multiple devices, the first device list can further include multiple devices, and the user selects the second electronic device for authentication from the multiple devices. As shown in (a) of FIG. 10, the first device list includes not only the second electronic device (e.g., device B), but also device C. Figure 4

[0489] In this way, by displaying the first device list to the user, the user can be allowed to choose whether to need to authenticate the second electronic device by himself, and the user experience is improved.

[0490] In some other embodiments, since the second electronic device has been associated before, after detecting the first operation of the user, the first electronic device does not need to display the device list, and directly prompts the user to input the first authentication content. As shown in (b) of FIG. 10, after detecting the first operation, the user can be directly prompted to input the first authentication content through the message prompt box 402. Figure 13

[0491] In some other embodiments, the first electronic device, in response to the first operation of the user, prompts the user to input the first authentication content, including:

[0492] The first electronic device, in response to the first operation of the user, prompts the user to perform biometric authentication;

[0493] The first electronic device, after detecting that the biometric authentication of the user is passed, prompts the user to input the first authentication content.

[0494] That is, the first electronic device can first perform biometric authentication on the user, and after the biometric authentication is successful, prompts the user to input the first authentication content.

[0495] The method for password resetting provided in the embodiments of the present application can start to authenticate the device to reset the lock screen password only after the biometric authentication of the user is passed, which can improve the user experience and improve the security, and avoid the risk that other users of the owner of the first electronic device reset the lock screen password after obtaining the first electronic device.

[0496] The biometric authentication manner of the embodiments of the present application can include but is not limited to fingerprint recognition, face recognition, iris recognition, and / or voice recognition and other biometric recognition manners, and multiple biometric authentication manners can be used in combination or individually, which are not limited in the embodiments of the present application.

[0497] In the biometric authentication process, as shown in (a) of FIG. 11, the first electronic device can display a biometric authentication area such as a fingerprint recognition area 1311, and the user can perform biometric recognition by aligning or pressing the biometric authentication area. Figure 4

[0498] ​​​In some embodiments, the first electronic device, in response to detecting the first operation of the user, prompts the user to input the first authentication content, including:

[0499] The first electronic device, in response to the first operation of the user, prompts the user to perform biometric authentication.

[0500] The first electronic device displays a first device list including the second electronic device after detecting that the biometric authentication of the user is passed.

[0501] The first electronic device, in response to detecting that the user selects the second electronic device, prompts the user to input the first authentication content.

[0502] That is, after the first electronic device detects the first operation of the user, the biometric authentication is performed first, and then the first device list is displayed for the user to select the device to be authenticated. After the first electronic device detects that the user selects the second electronic device, the first electronic device prompts the user to input the first authentication content in response to the operation.

[0503] In S2120, the first electronic device detects that the user inputs the first authentication content.

[0504] In S2130, the first electronic device prompts the user to reset the lock screen password of the first electronic device if the first authentication content matches the second authentication content on the associated second electronic device.

[0505] In this step, if the first authentication content matches the second authentication content, it is considered that the authentication of the second electronic device is passed, and the first electronic device can prompt the user to reset the lock screen password.

[0506] In some embodiments, the first electronic device and the second electronic device can perform device authentication based on the PAKE protocol according to the authentication content obtained respectively. If the results obtained by the two devices are the same, the authentication is successful. That is, the first electronic device performs device authentication based on the PAKE protocol based on the first authentication content, and the second electronic device performs device authentication based on the PAKE protocol based on the second authentication content. For the way of performing device authentication based on the PAKE protocol, please refer to the description above, which will not be repeated here.

[0507] In the implementation, after the first electronic device detects the first operation input by the user, the first electronic device can send a password reset request to the second electronic device to make the second electronic device perform related actions, and finally realize the password reset of the first electronic device.

[0508] Exemplarily, the password reset request includes an identifier of the first electronic device.

[0509] In some embodiments, the first authentication content is the lock screen password of the second electronic device, and the second authentication content is the lock screen password of the second electronic device stored on the second electronic device.

[0510] In one example, such as Figure 4 As shown in (b), after detecting the user's first operation, the first electronic device (e.g., device A) responds by displaying a message reminder box 402 to prompt the user to enter the lock screen password of the second electronic device (e.g., device B). The message reminder box 402 includes a password input box 4022. The user enters the lock screen password of the second electronic device in the password input box 4022. The first electronic device detects the lock screen password entered by the user. If the lock screen password entered in the first electronic device matches the lock screen password stored in the second electronic device, the authentication of the second electronic device is successful. Figure 8 As shown in (c), the first electronic device prompts the user to reset the lock screen password of the first electronic device.

[0511] The password reset method provided in this application embodiment is effective because the first electronic device and the second electronic device are already associated. The owner of the first electronic device knows the lock screen password of the second electronic device, while other users who are not the owner may not know the lock screen password of the second electronic device. Therefore, by using the lock screen password of the associated second electronic device as the authentication content of the authentication device, the risk of other users who are not the owner resetting the lock screen password after obtaining the first electronic device can be greatly reduced.

[0512] In other embodiments, the first authentication content is an authentication code, and the second authentication content is an authentication code generated on the second electronic device.

[0513] In one example, such as Figure 8 As shown in (b), after detecting the user's first operation, the first electronic device (e.g., device A) responds to the user's first operation by displaying a message reminder box 803 to prompt the user to enter an authentication code. The message reminder box 803 includes an authentication code input box 8032. After receiving a password reset request, the second electronic device (e.g., device B) randomly generates an authentication code (e.g., authentication code 076452) and displays it to the user. The first electronic device detects the authentication code entered by the user in the authentication code input box 8032. If the authentication code entered by the first electronic device matches the authentication code generated by the second electronic device, the authentication by the second electronic device is successful. Figure 19 As shown in (c), the first electronic device prompts the user to reset the lock screen password of the first electronic device.

[0514] In the embodiment where both the first authentication content and the second authentication content are authentication codes, in one possible implementation, in the case where the first authentication content and the second authentication content on the associated second electronic device match, the first electronic device prompts the user to reset the lock screen password of the first electronic device, including:

[0515] In the case where the first duration related to the unlocking time of the second electronic device is less than or equal to a preset duration, and the first authentication content and the second authentication content match, the first electronic device prompts the user to reset the lock screen password of the first electronic device.

[0516] That is, only in the case where the first duration is less than or equal to the preset duration, and the first authentication content and the second authentication content match, the authentication of the second electronic device passes, and the lock screen password can be reset. In the case where the first duration is greater than the preset duration, the authentication of the second electronic device fails.

[0517] The preset duration can be used as the unlocking protection time after the second electronic device is unlocked. The first electronic device or the second electronic device needs to perform a related operation within the preset duration after the second electronic device is unlocked, so as to possibly pass the authentication, otherwise, the authentication fails.

[0518] In an example, the first duration is the duration between the unlocking time of the second electronic device and the time when the first electronic device detects that the user inputs the first authentication content.

[0519] In this embodiment, the preset duration can be set to be longer. In the case where the first duration is less than or equal to the preset duration, and the authentication code detected by the first electronic device and the authentication code generated on the second electronic device match, the authentication of the second electronic device passes; in the case where the first duration is greater than the preset duration, the authentication code input by the user can be considered invalid, and the authentication of the second electronic device fails.

[0520] Generally, if the user who takes the second electronic device is the owner of the second electronic device, the second electronic device can be unlocked in a short time, so that the second electronic device can generate the authentication code in a short time, and the user can input the authentication code on the first electronic device in a short time. The embodiment of the application sets a preset time length. When the first time length between the unlocking time of the second electronic device and the time when the first electronic device detects that the user inputs the authentication code is less than or equal to the preset time length, and the authentication code detected by the first electronic device matches the authentication code generated on the second electronic device, it is considered that the second electronic device passes the authentication. Otherwise, when the first time length is greater than the preset time length, it is considered that the second electronic device fails the authentication. In this way, the security of the authentication process of the second electronic device can be improved, and the problem of poor security caused by the authentication of the second electronic device by a user other than the owner of the second electronic device can be avoided.

[0521] In another example, the first time length is the time length between the unlocking time of the second electronic device and the time when the second electronic device generates the second authentication content.

[0522] In this embodiment, the preset time length can be set to be relatively short. When the first time length is less than or equal to the preset time length, and the authentication code detected by the first electronic device matches the authentication code generated on the second electronic device, the second electronic device passes the authentication. When the first time length is greater than the preset time length, it is considered that the authentication code generated by the second electronic device is invalid, and the second electronic device fails the authentication.

[0523] Generally, if the user who takes the second electronic device is the owner of the second electronic device, the second electronic device can be unlocked in a short time, so that the second electronic device can also generate the authentication code in a short time. The embodiment of the application sets a preset time length. When the first time length between the unlocking time of the second electronic device and the time when the second electronic device generates the authentication code is less than the preset time length, and the authentication code detected by the first electronic device matches the authentication code generated on the second electronic device, it is considered that the second electronic device passes the authentication. Otherwise, when the first time length is greater than the preset time length, it is considered that the second electronic device fails the authentication. In this way, the security of the authentication process of the second electronic device can be improved, and the problem of poor security caused by the authentication of the second electronic device by a user other than the owner of the second electronic device can be avoided.

[0524] Before S2110, the method further includes:

[0525] The first electronic device sends a device association request to the second electronic device;

[0526] After the second electronic device is authenticated, an association is established between the first electronic device and the second electronic device, and the first electronic device sends the first password reset credential to the second electronic device.

[0527] This step establishes a connection between the first and second electronic devices before resetting the lock screen password. Figure 3 The method shown is the technical solution described in 1900.

[0528] After the second electronic device is authenticated, an association is established between the first and second electronic devices. The first and second electronic devices can share a session key and transmit data through the shared key.

[0529] After the second electronic device is authenticated, the first electronic device generates a password reset key. For example, the first electronic device performs a signature calculation on the password reset key to obtain a first password reset credential, and sends this first password reset key to the second electronic device so that the lock screen password can be reset based on this first password reset credential during the password reset process. To improve security, this calculation process can be irreversible; that is, the first password reset credential can be calculated from the password reset key, but the password reset key cannot be calculated from the first password reset credential.

[0530] In this step, the second electronic device can be authenticated by entering authentication content on the first electronic device or the second electronic device. For a specific description, please refer to the relevant description of authenticating the second electronic device in step S1930 above, or refer to the relevant description of authenticating the second electronic device by entering the first authentication content of the first electronic device and the second authentication content of the second electronic device above. It will not be repeated here.

[0531] In some embodiments, before the first electronic device sends a device association request to the second electronic device, the method further includes:

[0532] The first electronic device displays a second device list, the second device list including at least one trusted device, the at least one trusted device including the second electronic device; and...

[0533] The first electronic device sends a device association request to the second electronic device, including:

[0534] In response to detecting that a user has selected the second electronic device, the first electronic device sends a device association request to the second electronic device.

[0535] In one example, such as Figure 3 As shown in (a) to (b), the first electronic device (e.g., device A) can display [the following text is missing] after the first electronic device successfully sets a lock screen password.Figure 18 The second device list includes a second electronic device (e.g., device B), device C, and device D, the user selects the second electronic device, and the first electronic device sends a device association request after detecting the operation of the user selecting the second electronic device.

[0536] In another example, as shown in (c) of 18, the first electronic device (e.g., device A) can display a second device list as shown in (d) of 18 after detecting the operation of the user setting the association security device function, the second device list including a second electronic device (e.g., device B), device C, and device D, the user selecting the second electronic device, and the first electronic device sending a device association request after detecting the operation of the user selecting the second electronic device. Figure 17 In another example, as shown in (e) of 18, the first electronic device (e.g., device A) can display a second device list as shown in (f) of 18 after detecting the operation of the user invoking the multi-device control center, the second device list including a second electronic device (e.g., device B), device C, and device D, the user selecting the second electronic device, and the first electronic device sending a device association request after detecting the operation of the user selecting the second electronic device and selecting a function option of the second electronic device as a security device.

[0537] Figure 17 Figure 17 Figure 22

[0538] The trusted device of the first electronic device of the embodiments of the present application is any device that can establish a trust relationship with the first electronic device.

[0539] In an example, the trusted device can be a device that can establish a connection with the first electronic device through near field communication.

[0540] In another example, the trusted device is a device that has the same account as the first electronic device.

[0541] Based on the first password reset credential sent by the first electronic device to the second electronic device, in some embodiments, the first electronic device prompts the user to reset the lock screen password of the first electronic device in the case that the first authentication content and the associated second authentication content on the second electronic device match, including:

[0542] In the case that the first authentication content and the second authentication content match, the first electronic device receives the first password reset credential sent by the second electronic device, the first password reset credential being used to authorize the user to reset the lock screen password of the first electronic device; ​​​​

[0543] In a case that the first password reset credential is authenticated, the first electronic device prompts a user to reset the lock screen password of the first electronic device.

[0544] That is, in a case that the first authentication content and the second authentication content match, the authentication of the second electronic device is passed, the second electronic device confirms the password reset request, sends the first password reset credential to the first electronic device, the first electronic device receives the first password reset credential and authenticates the first password reset credential, in a case that the first password reset credential is authenticated, prompts the user to reset the lock screen password.

[0545] The method for password reset provided by the embodiments of the present application, after the authentication of the second electronic device is completed, the first electronic device further verifies the first password reset credential sent by the second electronic device, and only in a case that the first password reset credential is passed, the lock screen password is reset, which is equivalent to providing further security guarantee in the process of resetting the password, and further improves the security of the process of resetting the password. For example, the case that the lock screen password of the first electronic device is modified in a case that the authentication of the counterfeit second electronic device is passed in the communication process between the counterfeit second electronic device and the first electronic device can be avoided.

[0546] In some embodiments, in a case that the first password reset credential is authenticated, the first electronic device prompts a user to reset the lock screen password of the first electronic device, including:

[0547] In a case that the first password reset credential and the second password reset credential match, the first electronic device prompts a user to reset the lock screen password of the first electronic device, and the second password reset credential is generated by the first electronic device.

[0548] That is, the first electronic device compares the second password reset credential and the first password reset credential, in a case that the first password reset credential and the second password reset credential match, the first password reset credential is authenticated, the first electronic device can allow the user to reset the lock screen password, and prompts the user to reset the lock screen password.

[0549] The first password reset credential and the second password reset credential are both generated based on the same password reset key, and the password reset key can be generated in the process of associating the second electronic device.

[0550] In an example, the second password reset credential can be a password reset credential calculated by the first electronic device in the process of associating the second electronic device, and the first electronic device saves the obtained password reset credential to the local, and uses it in the subsequent process of resetting the lock screen password.

[0551] In another example, the second password reset credential can also be a password reset credential recalculated by the first electronic device based on the password reset key during the process of resetting the lock screen password.

[0552] Figure 20 This is another illustrative flowchart of the password reset method provided in this application embodiment. The method is executed by a first electronic device, which can be the first electronic device mentioned above, and a second electronic device associated with the first electronic device can be the second electronic device mentioned above. The method shown is... Figure 10 The method 2000 shown is a process of authenticating a second electronic device by inputting second authentication content related to the first authentication content of the first electronic device on the second electronic device to prompt the user to reset the lock screen password.

[0553] In S2210, the first electronic device generates first authentication content in response to the user's first operation.

[0554] In one example, the first electronic device is in a locked state, and the first operation could be the user clicking the "Forgot Password" control on the lock screen.

[0555] In another example, the first electronic device is in a locked state, and the first operation could be the operation that the number of times the user enters the wrong lock screen password reaches a preset value.

[0556] In another example, the first electronic device is in an unlocked state, and the settings interface of the first electronic device may include a function option to reset the lock screen password. The first operation may be the user clicking the function option to reset the lock screen password.

[0557] For example, the first authentication content can be a randomly generated authentication code, or any other content that can be used for authentication.

[0558] In some embodiments, the first electronic device generates first authentication content in response to a first user action, including:

[0559] In response to a user's first operation, the first electronic device displays a first device list, which includes the second electronic device.

[0560] The first electronic device generates the first authentication content in response to detecting that the user has selected the second electronic device.

[0561] In one example, such as Figure 10 As shown in (a), after detecting a first user action, the first electronic device (e.g., device A) responds to the first action by displaying a first device list including a second electronic device (e.g., device B). The user selects the second electronic device, for example, by clicking a control to authenticate the second electronic device.Figure 15 As shown in (b) of FIG. 13, in response to the operation of the user selecting the second electronic device, the first electronic device randomly generates an authentication code (for example, authentication code 076452) and displays the authentication code to the user.

[0562] In the embodiment in which the first electronic device has associated a plurality of devices, the plurality of devices can also be included in the first device list, and the user selects the second electronic device for authentication from the plurality of devices. As shown in (a) of FIG. 14, the first device list includes not only the second electronic device (for example, device B) but also device C. Figure 10

[0563] In other embodiments, since the second electronic device has been associated before, after detecting the first operation of the user, the first electronic device does not need to display the device list and directly generates the first authentication content. As shown in (b) of FIG. 15, after detecting the first operation, the first authentication content can be directly generated and displayed to the user. Figure 13

[0564] In other embodiments, the first electronic device generates the first authentication content in response to the first operation of the user, including:

[0565] The first electronic device prompts the user to perform biological authentication in response to the first operation of the user;

[0566] The first electronic device generates the first authentication content after detecting that the biological authentication of the user is passed.

[0567] That is, the first electronic device can first perform biological authentication on the user, and after the biological authentication is successful, prompt the user to input the first authentication content.

[0568] The method for password resetting provided by the embodiments of the present application can start to authenticate the device to reset the lock screen password only after the biological authentication of the user is passed, which can improve user experience and security, and avoid the risk of resetting the lock screen password by other users of the owner of the first electronic device.

[0569] The biological authentication method of the embodiments of the present application can include but is not limited to fingerprint recognition, face recognition, iris recognition, and / or voice recognition and other biological recognition methods. The multiple biological authentication methods can be used in combination or individually, and the embodiments of the present application do not make any limitation.

[0570] In the biological authentication process, as shown in (a) of FIG. 16, a biological authentication area such as a fingerprint recognition area 1611 can be displayed on the first electronic device, and the user can perform biological recognition by aligning or pressing the biological authentication area. Figure 10 In the biological authentication process, as shown in (a) of FIG. 16, a biological authentication area such as a fingerprint recognition area 1611 can be displayed on the first electronic device, and the user can perform biological recognition by aligning or pressing the biological authentication area. ​

[0571] In some embodiments, the first electronic device, in response to detecting the first operation of the user, generates the first authentication content, including:

[0572] The first electronic device, in response to the first operation of the user, prompts the user to perform the biometric authentication.

[0573] The first electronic device displays a first device list including the second electronic device after detecting that the biometric authentication of the user is passed.

[0574] The first electronic device, in response to detecting that the user selects the second electronic device, generates the first authentication content.

[0575] That is, after the first electronic device detects the first operation of the user, the biometric authentication is performed first, and then the first device list is displayed for the user to select the device to be authenticated. After the first electronic device detects that the user selects the second electronic device, the first electronic device prompts the user to input the first authentication content in response to the operation.

[0576] In S2220, in the case where the first authentication content and the second authentication content on the associated second electronic device match, the first electronic device prompts the user to reset the lock screen password of the first electronic device.

[0577] In this step, in the case where the first authentication content and the second authentication content match, it is considered that the authentication of the second electronic device is passed, and then the first electronic device can prompt the user to reset the lock screen password.

[0578] In some embodiments, the first electronic device and the second electronic device can perform device authentication based on the PAKE protocol according to the authentication content obtained respectively. If the results obtained by the two devices are the same, the authentication is successful. That is, the first electronic device performs device authentication based on the PAKE protocol based on the first authentication content, and the second electronic device performs device authentication based on the PAKE protocol based on the second authentication content. The way of performing device authentication based on the PAKE protocol can be referred to the description above, and will not be repeated here.

[0579] In the implementation, after the first electronic device detects the first operation input by the user, the first electronic device can send a password reset request to the second electronic device to make the second electronic device perform related actions, and finally achieve the password reset of the first electronic device.

[0580] Exemplarily, the password reset request includes the identifier of the first electronic device.

[0581] In some embodiments, the second authentication content is the content input by the user and detected by the second electronic device.

[0582] In an example, as Figure 23As shown in (b) of FIG. 10, after detecting the first operation of the user, the first electronic device (e.g., device A) randomly generates a second authentication content (e.g., authentication code 076452) in response to the first operation, and displays the second authentication content to the user. After receiving the password reset request sent by the first electronic device, the second electronic device (e.g., device B) displays a message prompt box 1030 to prompt the user to input the second authentication content. The second electronic device detects the second authentication content input by the user, and if the second authentication content input by the user in the second electronic device matches the second authentication content generated by the first electronic device, the authentication of the second electronic device is passed.

[0583] Before S2220, the method further includes:

[0584] The first electronic device sends a device association request to the second electronic device.

[0585] After the authentication of the second electronic device is passed, an association relationship is established between the first electronic device and the second electronic device, and the first electronic device sends the first password reset credential to the second electronic device.

[0586] In some embodiments, before the first electronic device sends a device association request to the second electronic device, the method further includes:

[0587] The first electronic device displays a second device list, and the second device list includes at least one trusted device, and the at least one trusted device includes the second electronic device; and

[0588] The first electronic device sends a device association request to the second electronic device, including:

[0589] The first electronic device sends the device association request to the second electronic device in response to detecting an operation of the user selecting the second electronic device.

[0590] After the authentication of the second electronic device is passed, an association relationship is established between the first electronic device and the second electronic device, and the first electronic device and the second electronic device can share a session key to transmit data through the shared key.

[0591] For specific descriptions of authenticating the second electronic device, the first password reset credential, the trusted device, and the first electronic device sending the device association request to the second electronic device in response to detecting an operation of the user selecting the second electronic device, reference can be made to the related descriptions above, and no longer be repeated.

[0592] Based on the first password reset credential sent by the first electronic device to the second electronic device, in some embodiments,

[0593] In a case where the first authentication content matches the second authentication content on the second electronic device, the first electronic device prompts the user to reset a lock screen password of the first electronic device, including:

[0594] In a case where the first authentication content matches the second authentication content, the first electronic device receives a first password reset credential sent by the second electronic device, the first password reset credential being used to authorize the user to reset a lock screen password of the first electronic device.

[0595] In a case where the first password reset credential is authenticated, the first electronic device prompts the user to reset the lock screen password of the first electronic device.

[0596] In some embodiments, in the case where the first password reset credential is authenticated, the first electronic device prompts the user to reset the lock screen password of the first electronic device, including:

[0597] In a case where the first password reset credential matches a second password reset credential, the first electronic device prompts the user to reset the lock screen password of the first electronic device, the second password reset credential being generated by the first electronic device.

[0598] Figure 21 A schematic block diagram of an apparatus 2300 for password resetting is shown. The apparatus 2300 can be arranged in the first electronic device to implement the technical solutions performed by the first electronic device in the method 2100. Figure 21 The apparatus 2300 includes a prompting unit 2310 configured to, in response to a first operation of a user, prompt the user to input first authentication content; a detecting unit 2320 configured to detect that the user inputs the first authentication content; and the prompting unit 2310 is further configured to, in a case where the first authentication content matches second authentication content on a second electronic device associated with the first authentication content, prompt the user to reset a lock screen password of the first electronic device.

[0599] The prompting unit 2310 can be specifically configured to perform steps S2110 and S2130 in the method 2100, and the detecting unit 2320 can be specifically configured to perform step S2120 in the method 2100.

[0600] It should be understood that the specific processes of the respective units in performing the above respective steps have been described in detail in the embodiments of the method 2100 shown in the method 2100. Figure 24 The embodiments of the method 2100 have been described in detail, and for brevity, will not be described here.

[0601] Figure 22 A schematic block diagram of an apparatus 2400 for password resetting is shown. The apparatus 2400 can be arranged in the first electronic device to implement the technical solutions performed by the first electronic device in the method 2100. Figure 22The method 2200 shown is a technical solution executed by a first electronic device. The apparatus 2400 includes a processing unit 2410 configured to generate a first authentication content in response to a first operation of a user; and a reminding unit 2420 configured to remind the user to reset a lock screen password of the first electronic device in a case where the first authentication content matches a second authentication content on an associated second electronic device.

[0602] The processing unit 2410 is specifically configured to execute step S2210 in the method 2200, and the reminding unit 2420 is specifically configured to execute step S2220 in the method 2200.

[0603] It should be understood that the specific process by which each unit executes the corresponding steps described above is described in detail above. Figure 25 The embodiments of the method 2200 have been described in detail above, and thus are not described here for simplicity.

[0604] Figure 20 A schematic block diagram of an apparatus 2500 for password resetting is shown. The apparatus 2500 can be disposed in the first electronic device described above, to implement the method 2200. Figure 20 The method 2000 shown is a technical solution executed by a first electronic device. The apparatus 2500 includes a sending unit 2510 configured to send, to an associated second electronic device, a password resetting request in response to a first operation of a user; a receiving unit 2520 configured to receive, after authentication of the second electronic device is passed, a first password resetting credential sent by the second electronic device in response to the password resetting request, the first password resetting credential being used to authorize the user to reset a lock screen password of the first electronic device; and a reminding unit 2530 configured to remind the user to reset the lock screen password of the first electronic device in a case where the first password resetting credential is authenticated.

[0605] The sending unit 2510 is specifically configured to execute step S2010 in the method 2000, the receiving unit 2520 is specifically configured to execute step S2030 in the method 2000, and the reminding unit 2530 is specifically configured to execute step S2040 in the method 2000.

[0606] It should be understood that the specific process by which each unit executes the corresponding steps described above is described in detail above. Figure 26 The embodiments of the method 2000 have been described in detail above, and thus are not described here for simplicity.

[0607] Figure 20 A schematic block diagram of an apparatus 2600 for password resetting is shown. The apparatus 2600 can be disposed in the second electronic device described above, to implement the method 2000. Figure 20The method 2000 shown in the technical solutions performed by the second electronic device. The device 2600 includes: a receiving unit 2610 configured to receive a password reset request sent by an associated first electronic device; and a sending unit 2620 configured to, in response to the password reset request, send a first password reset credential to the first electronic device after authentication of the second electronic device is passed, the first password reset credential being used to authorize a user to reset a lock screen password of the first electronic device.

[0608] The receiving unit 2610 can be specifically configured to perform step S2010 in the method 2000, and the sending unit 2620 can be specifically configured to perform step S2030 in the method 2000.

[0609] It should be understood that the specific process of each unit performing the corresponding steps described above is described in detail in the above Figure 27 The embodiments of the method 2000 have been described in detail, and for brevity, will not be repeated here.

[0610] Figure 27 A schematic structural diagram of an electronic device 2700 provided by an embodiment of the present application is shown. As shown in the figure, ​ As shown, the electronic device includes one or more processors 2710 and one or more memories 2720, the one or more memories 2720 storing one or more computer programs including instructions. When the instructions are run by the one or more processors 2710, the first electronic device performs the technical solutions in the above embodiments; or, when the instructions are run by the one or more processors 2710, the second electronic device performs the technical solutions in the above embodiments. The implementation principles and technical effects are similar to those of the above method-related embodiments, and will not be repeated here.

[0611] An embodiment of the present application provides a computer program product, when the computer program product is run on a first electronic device, the first electronic device performs the technical solutions in the above embodiments; or, when the computer program product is run on a second electronic device, the second electronic device performs the technical solutions in the above embodiments. The implementation principles and technical effects are similar to those of the above method-related embodiments, and will not be repeated here.

[0612] An embodiment of the present application provides a readable storage medium, the readable storage medium contains instructions, when the instructions are run on a first electronic device, the first electronic device performs the technical solutions in the above embodiments; or, when the instructions are run on a second electronic device, the second electronic device performs the technical solutions in the above embodiments. The implementation principles and technical effects are similar, and will not be repeated here.

[0613] The chip is used for executing instructions, and when the chip is running, the technical solutions in the above embodiments are executed. The implementation principles and technical effects are similar, and will not be described here. In an example, the chip can be a security chip.

[0614] It should be understood that, in the embodiments of the present application, the terms "first", "second" are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. The features limited by "first", "second" can explicitly or implicitly include one or more of the features.

[0615] In the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. "At least part of the element" means part or all of the element. "And / or" describes the association between the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. The character " / " generally represents a "or" relationship between the associated objects before and after it.

[0616] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solutions. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0617] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.

[0618] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed mutual objects can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0619] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e., may be located in one place, or may be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0620] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.

[0621] When the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application can be embodied in the form of software products, and the computer software products are stored in a storage medium, including a plurality of instructions for making a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0622] The same or similar parts in each embodiment of the present application can be mutually referred to. In the various embodiments of the present application, and the various embodiments / implementation methods / implementation methods in each embodiment, if there is no special description and logical conflict, the terms and / or descriptions of different embodiments, and the various embodiments / implementation methods / implementation methods in each embodiment are consistent and can be mutually referred to, and the technical features of different embodiments, and the various embodiments / implementation methods / implementation methods in each embodiment can be combined to form new embodiments, embodiments, implementation methods, or implementation methods according to their inherent logical relationship. The above-described embodiments of the present application do not constitute a limitation on the protection scope of the present application.

[0623] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for resetting a password, characterized in that, include: In response to the user's first operation, the first electronic device prompts the user to enter first authentication content. The first operation includes at least one of the following: when the first electronic device is in a locked state, the user clicks the "Forgot Password" control on the lock screen interface; the user enters an incorrect lock screen password a preset number of times; and when the first electronic device is in an unlocked state, the user clicks the "Reset Lock Screen Password" function option. The first electronic device detects that the user inputs the first authentication content on the first electronic device; If the first authentication content matches the second authentication content on the associated second electronic device, the first electronic device prompts the user to reset the lock screen password of the first electronic device; Wherein, the first authentication content is the lock screen password of the second electronic device, and the second authentication content is the lock screen password of the second electronic device stored on the second electronic device; The second electronic device is a device with the same account as the first electronic device; and / or, the second electronic device is a device that establishes a connection with the first electronic device via near-field communication.

2. The method according to claim 1, characterized in that, When the first authentication content matches the second authentication content on the associated second electronic device, the first electronic device prompts the user to reset the lock screen password of the first electronic device, including: If the first authentication content and the second authentication content match, the first electronic device receives the first password reset credential sent by the second electronic device. The first password reset credential is used to authorize the user to reset the lock screen password of the first electronic device. If the first password reset credential is successfully authenticated, the first electronic device will prompt the user to reset the lock screen password of the first electronic device.

3. The method according to claim 2, characterized in that, When the first password reset credential authentication is successful, the first electronic device prompts the user to reset the lock screen password of the first electronic device, including: If the first password reset credential and the second password reset credential match, the first electronic device prompts the user to reset the lock screen password of the first electronic device. The second password reset credential is generated by the first electronic device.

4. The method according to any one of claims 1 to 3, characterized in that, When the first authentication content matches the second authentication content on the associated second electronic device, the first electronic device prompts the user to reset the lock screen password of the first electronic device, including: If the first duration is less than or equal to a preset duration, and the first authentication content matches the second authentication content, the first electronic device prompts the user to reset the lock screen password of the first electronic device; wherein, The first duration is the time between the unlocking time of the second electronic device and the time when the first electronic device detects the user's input of the first authentication content; or, The first duration is the time between the unlocking time of the second electronic device and the time when the second electronic device generates the second authentication content.

5. The method according to any one of claims 1 to 3, characterized in that, The first electronic device responds to the user's first operation by prompting the user to enter first authentication information, including: In response to a user's first operation, the first electronic device displays a first device list, which includes the second electronic device. In response to detecting that the user has selected the second electronic device, the first electronic device prompts the user to enter the first authentication information.

6. The method according to any one of claims 1 to 3, characterized in that, The first electronic device responds to the user's first operation by prompting the user to enter first authentication information, including: The first electronic device responds to the user's first operation by prompting the user to perform biometric authentication; After detecting that the user's biometric authentication has been successful, the first electronic device prompts the user to enter the authentication information.

7. The method according to claim 2 or 3, characterized in that, Before the first electronic device prompts the user to enter first authentication information in response to the user's first operation, the method further includes: The first electronic device sends a device association request to the second electronic device; After the second electronic device is successfully authenticated, an association is established between the first electronic device and the second electronic device, and the first electronic device sends the first password reset credential to the second electronic device.

8. The method according to claim 7, characterized in that, Before the first electronic device sends a device association request to the second electronic device, the method further includes: The first electronic device displays a second device list, the second device list including at least one trusted device, the at least one trusted device including the second electronic device; and... The first electronic device sends a device association request to the second electronic device, including: In response to detecting that the user has selected the second electronic device, the first electronic device sends the device association request to the second electronic device.

9. An electronic device, characterized in that, include: One or more processors; One or more memory units; The one or more memories store one or more computer programs, the one or more computer programs including instructions that, when executed by the one or more processors, cause the electronic device to perform the method as described in any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that, Includes computer instructions that, when executed on an electronic device, cause the electronic device to perform the method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Combined Authorization Process

    US20170012974A1

  • Method and system for performing user authentication

    US20200358760A1